This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

RootKit.0Acess [Closed]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okay so i have an inspiron dell laptop N5110 and recently ive been running MBAM and ive been getting this one virus named "RootKit.0access, with the file locating from C:\Windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\U and inside these files i get "00000001.@" , "800000cb.@" , and "80000000.@" and im not exactly sure what to do,. I got it maybe a week ago and i run scans usually everyday and its there. i've tried to quartine it and it says that its been removed and i restart it and everything and when i do the next scan it is still there.. I really need some help with this to get this off my computer because i have work to do.. im not really sure how it is infecting the computer, but i know that its something bad and want to get it off ASAP. So once this started popping up then MBAM every now and then (maybe once or twice every two days) would say that they detected that a virus or something named something along the lines of "Sifefref" or something like that (I cant rememebr, i havent seen it in a while) where doing it so i pressed quaratine to that. Then three days ago i downloaded AVG software and it came back with something called Trojan Dropper Generic (along the lines of that) and the infected area was in my service.exe files, and after looking online, i found out about the : "Hi, I have found a soultion to the problem. 1. Go to start, type "cmd" to open the command prompt 2. Type or copy & paste "sfc /scanfile=c:\windows\system32\services.exe" and press enter 3. Restart your computer This will replace the infected services.exe with the original. If it dosen't work try it in safe mode." And i tried this and it seemed to got rid of that problem but it could still be lingering on because i read that usually a few hours later they receive the same notice along with Trojan Dropper Generic28.Udx. So Im wondering how can i get this Rootkit.0access of my computer and make sure everything is okay. Btw MBAM didnt detect the stuff AVG detected in my service.exe files. It kept popping up as a AVG resident Shield protecter and only gave me the option to ignore it if that is any help. Can someone please get back to me asap about this problem. Thank you for your time :)
Hello troy645 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Please include the following in your next post :

DDS.txt
Attach.txt
aswMBR log


Thanks

Satchfan
Thank you for your response :) I have done the first part of what you asked: The DTT: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 11:10:36 on 2012-07-05 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6050.3993 [GMT -5:00] . AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} . ============== Running Processes =============== . C:\PROGRA~2\AVG\AVG2012\avgrsa.exe C:\windows\system32\wininit.exe C:\windows\system32\lsm.exe C:\windows\system32\svchost.exe -k DcomLaunch C:\windows\system32\svchost.exe -k RPCSS C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV64.exe C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k NetworkService C:\windows\system32\WLANExt.exe C:\windows\system32\conhost.exe C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe C:\windows\System32\spoolsv.exe C:\Program Files\IDT\WDM\AESTSr64.exe C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe C:\windows\system32\svchost.exe -k bthsvcs C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe C:\windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Windows\system32\mfevtps.exe C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE C:\windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe C:\Program Files (x86)\AVG\AVG2012\avgemca.exe C:\windows\system32\wbem\unsecapp.exe C:\windows\system32\wbem\wmiprvse.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe C:\windows\system32\taskhost.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe C:\windows\System32\vds.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Windows\System32\rundll32.exe C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe C:\windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\DellTPad\HidFind.exe C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\DellTPad\Apntex.exe C:\windows\system32\conhost.exe C:\Program Files\mcafee.com\agent\mcagent.exe C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\AVG\AVG2012\avgtray.exe C:\Program Files (x86)\AVG Secure Search\vprot.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\windows\system32\sppsvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\windows\system32\notepad.exe C:\windows\system32\SearchProtocolHost.exe C:\windows\system32\SearchFilterHost.exe C:\windows\system32\DllHost.exe C:\windows\SysWOW64\cmd.exe C:\windows\system32\conhost.exe C:\windows\SysWOW64\cscript.exe C:\windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120624234614.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [Facebook Update] "C:\Users\Sharon\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver uRun: [Google Update] "C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe" /c mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot mRun: [] mRun: [RoxWatchTray] "c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" mRun: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" mRun: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900 mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey mRun: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" –startup mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd; to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{5F5BDC92-DD1F-41C8-9D0E-B0ADE2D29057} : DhcpNameServer = 192.168.1.254 TCP: Interfaces\{5F5BDC92-DD1F-41C8-9D0E-B0ADE2D29057}\E4544574541425 : DhcpNameServer = 192.168.1.1 Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\msc\McSnIePl.dll Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO-X64: AVG Do Not Track - No File BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120624234614.dll BHO-X64: scriptproxy - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun-x64: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot mRun-x64: [(Default)] mRun-x64: [RoxWatchTray] "c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" mRun-x64: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" mRun-x64: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900 mRun-x64: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey mRun-x64: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" –startup mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" mRunOnce-x64: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\tq0hgxhu.default\ FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9401a445-8a01-44cc-b106-5cdf2656f309%7D∣=f362b1fafabf47d0a3d09da204caaaa8-e7b31230b0bd0cc9828c2f5b36ab6c108378784e&ds;=AVG&v;=11.1.0.12⟨=en≺=fr&d;=2012-07-02%2019%3A23%3A00&sap;=ku&q;= FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\npsitesafety.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Sharon\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll FF - plugin: C:\Users\Sharon\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHA;AVGIDSHA;C:\windows\system32\DRIVERS\avgidsha.sys –> C:\windows\system32\DRIVERS\avgidsha.sys [?] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\windows\system32\DRIVERS\avgrkx64.sys –> C:\windows\system32\DRIVERS\avgrkx64.sys [?] R0 mfehidk;McAfee Inc. mfehidk;C:\windows\system32\drivers\mfehidk.sys –> C:\windows\system32\drivers\mfehidk.sys [?] R0 mfewfpk;McAfee Inc. mfewfpk;C:\windows\system32\drivers\mfewfpk.sys –> C:\windows\system32\drivers\mfewfpk.sys [?] R0 PxHlpa64;PxHlpa64;C:\windows\system32\Drivers\PxHlpa64.sys –> C:\windows\system32\Drivers\PxHlpa64.sys [?] R1 Avgldx64;AVG AVI Loader Driver;C:\windows\system32\DRIVERS\avgldx64.sys –> C:\windows\system32\DRIVERS\avgldx64.sys [?] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\windows\system32\DRIVERS\avgmfx64.sys –> C:\windows\system32\DRIVERS\avgmfx64.sys [?] R1 Avgtdia;AVG TDI Driver;C:\windows\system32\DRIVERS\avgtdia.sys –> C:\windows\system32\DRIVERS\avgtdia.sys [?] R1 mfenlfk;McAfee NDIS Light Filter;C:\windows\system32\DRIVERS\mfenlfk.sys –> C:\windows\system32\DRIVERS\mfenlfk.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys –> C:\windows\system32\DRIVERS\vwififlt.sys [?] R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2012-2-24 89600] R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-9-15 1166848] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-6-13 5161080] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288] R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-5-12 249648] R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-5-19 921664] R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-5-19 995392] R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-6-3 134928] R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2011-6-14 498688] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-6-17 654408] R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-27 249936] R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-27 249936] R2 McShield;McAfee McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2012-2-24 199272] R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2012-2-24 208536] R2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" –> C:\Windows\system32\mfevtps.exe [?] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400] R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-25 2823000] R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2012-2-24 689472] R2 TurboB;Turbo Boost UI Monitor driver;C:\windows\system32\DRIVERS\TurboB.sys –> C:\windows\system32\DRIVERS\TurboB.sys [?] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-2-24 2655768] R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-7-2 935008] R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2011-6-14 986112] R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:\windows\system32\DRIVERS\AMPPAL.sys –> C:\windows\system32\DRIVERS\AMPPAL.sys [?] R3 AVGIDSDriver;AVGIDSDriver;C:\windows\system32\DRIVERS\avgidsdrivera.sys –> C:\windows\system32\DRIVERS\avgidsdrivera.sys [?] R3 AVGIDSFilter;AVGIDSFilter;C:\windows\system32\DRIVERS\avgidsfiltera.sys –> C:\windows\system32\DRIVERS\avgidsfiltera.sys [?] R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-5-19 1335360] R3 bpenum;Intel® Centrino® WiMAX Enumerator;C:\windows\system32\DRIVERS\bpenum.sys –> C:\windows\system32\DRIVERS\bpenum.sys [?] R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\windows\system32\DRIVERS\bpmp.sys –> C:\windows\system32\DRIVERS\bpmp.sys [?] R3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;C:\windows\system32\Drivers\bpusb.sys –> C:\windows\system32\Drivers\bpusb.sys [?] R3 btmaudio;Intel Bluetooth Audio Service;C:\windows\system32\drivers\btmaud.sys –> C:\windows\system32\drivers\btmaud.sys [?] R3 btmaux;Intel Bluetooth Auxiliary Service;C:\windows\system32\DRIVERS\btmaux.sys –> C:\windows\system32\DRIVERS\btmaux.sys [?] R3 btmhsf;btmhsf;C:\windows\system32\DRIVERS\btmhsf.sys –> C:\windows\system32\DRIVERS\btmhsf.sys [?] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\windows\system32\DRIVERS\CtClsFlt.sys –> C:\windows\system32\DRIVERS\CtClsFlt.sys [?] R3 iBtFltCoex;iBtFltCoex;C:\windows\system32\DRIVERS\iBtFltCoex.sys –> C:\windows\system32\DRIVERS\iBtFltCoex.sys [?] R3 IntcDAud;Intel® Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys –> C:\windows\system32\DRIVERS\IntcDAud.sys [?] R3 iwdbus;IWD Bus Enumerator;C:\windows\system32\DRIVERS\iwdbus.sys –> C:\windows\system32\DRIVERS\iwdbus.sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\windows\system32\drivers\mbam.sys –> C:\windows\system32\drivers\mbam.sys [?] R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys –> C:\windows\system32\DRIVERS\HECIx64.sys [?] R3 mfeavfk;McAfee Inc. mfeavfk;C:\windows\system32\drivers\mfeavfk.sys –> C:\windows\system32\drivers\mfeavfk.sys [?] R3 mfefirek;McAfee Inc. mfefirek;C:\windows\system32\drivers\mfefirek.sys –> C:\windows\system32\drivers\mfefirek.sys [?] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-9-15 340240] R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\windows\system32\DRIVERS\NETwNs64.sys –> C:\windows\system32\DRIVERS\NETwNs64.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys –> C:\windows\system32\DRIVERS\Rt64win7.sys [?] R3 tihub3;TI USB3 Hub Service;C:\windows\system32\DRIVERS\tihub3.sys –> C:\windows\system32\DRIVERS\tihub3.sys [?] R3 tixhci;TI XHCI Service;C:\windows\system32\DRIVERS\tixhci.sys –> C:\windows\system32\DRIVERS\tixhci.sys [?] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys –> C:\windows\system32\DRIVERS\vwifimp.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2011-10-26 162816] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-2-24 13336] S2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-27 249936] S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:\windows\system32\DRIVERS\amppal.sys –> C:\windows\system32\DRIVERS\amppal.sys [?] S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-6-7 191752] S3 cfwids;McAfee Inc. cfwids;C:\windows\system32\drivers\cfwids.sys –> C:\windows\system32\drivers\cfwids.sys [?] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\windows\system32\drivers\intelaud.sys –> C:\windows\system32\drivers\intelaud.sys [?] S3 McAWFwk;McAfee Activation Service;C:\PROGRA~1\mcafee\msc\mcawfwk.exe [2012-2-24 224704] S3 mferkdet;McAfee Inc. mferkdet;C:\windows\system32\drivers\mferkdet.sys –> C:\windows\system32\drivers\mferkdet.sys [?] S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-6-23 113120] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUStor.sys –> C:\windows\system32\Drivers\RtsUStor.sys [?] S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;C:\windows\system32\DRIVERS\gtkdrv.sys –> C:\windows\system32\DRIVERS\gtkdrv.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys –> C:\windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys –> C:\windows\system32\drivers\TsUsbGD.sys [?] S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe –> C:\windows\system32\Wat\WatAdminSvc.exe [?] S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-27 249936] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-07-05 16:05:03 ——– d—–w- C:\Users\Sharon\AppData\Local\{1D51459F-0123-41F6-ACF5-6899A4FD19E7} 2012-07-05 16:04:51 ——– d—–w- C:\Users\Sharon\AppData\Local\{53F3CB2E-79AE-41A3-B823-70DC2032D182} 2012-07-05 02:15:00 ——– d—–w- C:\Users\Sharon\AppData\Local\{58887A1F-0F04-4301-B34C-7473737F29B2} 2012-07-05 02:14:45 ——– d—–w- C:\Users\Sharon\AppData\Local\{D8439C08-6758-4F1C-A996-7B07AF9ACCB4} 2012-07-05 00:12:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{DDA5F728-0951-4666-922E-6544F8BF3047} 2012-07-05 00:11:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{386C2E17-6880-436B-9A9F-A8A2EFC41440} 2012-07-03 23:20:43 ——– d—–w- C:\Users\Sharon\AppData\Local\{2052B2E6-8AE8-4848-A83D-687BD2CF649E} 2012-07-03 23:20:28 ——– d—–w- C:\Users\Sharon\AppData\Local\{FAED87C5-41AB-41D7-9523-35E6534D0226} 2012-07-03 22:58:28 ——– d—–w- C:\Users\Sharon\AppData\Local\{87328003-CD53-48D4-ADF5-CB5BC3E0B07C} 2012-07-03 22:58:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{5A99F755-6447-4C4B-B18D-697B767C4C2D} 2012-07-03 22:21:09 ——– d—–w- C:\Users\Sharon\AppData\Local\{8F126BD3-3CF7-4AF0-9B8C-00B665E56076} 2012-07-03 22:20:55 ——– d—–w- C:\Users\Sharon\AppData\Local\{1ECE33E8-F6EF-4930-95F5-1EF6A508BE5E} 2012-07-03 01:11:18 ——– d—–w- C:\Users\Sharon\AppData\Local\{D5A2F808-0C84-4E1A-BD6C-972EA5341702} 2012-07-03 01:11:04 ——– d—–w- C:\Users\Sharon\AppData\Local\{CF09F17B-9264-4A5D-9B6A-BD3CD9E554B4} 2012-07-03 00:23:36 ——– d—–w- C:\Users\Sharon\AppData\Roaming\AVG2012 2012-07-03 00:23:12 ——– d—–w- C:\Users\Sharon\AppData\Local\AVG Secure Search 2012-07-03 00:22:58 ——– d—–w- C:\ProgramData\AVG Secure Search 2012-07-03 00:22:57 ——– d—–w- C:\Program Files (x86)\Common Files\AVG Secure Search 2012-07-03 00:22:56 ——– d—–w- C:\Program Files (x86)\AVG Secure Search 2012-07-03 00:22:30 ——– d—–w- C:\windows\SysWow64\drivers\AVG 2012-07-03 00:22:02 ——– d–h–w- C:\$AVG 2012-07-03 00:22:02 ——– d—–w- C:\windows\System32\drivers\AVG 2012-07-03 00:22:02 ——– d—–w- C:\ProgramData\AVG2012 2012-07-03 00:21:25 ——– d—–w- C:\Program Files (x86)\AVG 2012-07-03 00:18:42 ——– d–h–w- C:\ProgramData\Common Files 2012-07-03 00:18:28 ——– d—–w- C:\ProgramData\MFAData 2012-07-02 22:29:48 ——– d—–w- C:\Users\Sharon\AppData\Local\{E5D2FB26-EC4C-4F86-8828-10DB20069B47} 2012-07-02 22:29:35 ——– d—–w- C:\Users\Sharon\AppData\Local\{0046811C-24DB-4129-818C-B2F64D70673D} 2012-07-02 22:06:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{C4050F7F-8010-4FFA-B828-6B2F5CDF0CE6} 2012-07-02 22:06:23 ——– d—–w- C:\Users\Sharon\AppData\Local\{88EABE12-FCDB-4EA8-989A-9A0B6007AED8} 2012-07-02 19:04:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{421C5ED0-FB6B-4D98-9BBB-1690BE915803} 2012-07-02 19:04:23 ——– d—–w- C:\Users\Sharon\AppData\Local\{4BC33703-6859-491E-A95B-2F9767376401} 2012-07-02 03:43:25 ——– d—–w- C:\Users\Sharon\AppData\Local\{192CA469-3F8E-48A0-95B2-AE82EB8C623F} 2012-07-02 03:43:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{EC94A50D-A5D6-45A8-BCFF-C90209FA5E4E} 2012-06-30 14:58:44 ——– d—–w- C:\Users\Sharon\AppData\Local\{F614BE76-3375-4BE0-9529-35AA721EC2D0} 2012-06-30 14:58:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{093A7F4A-8DD5-4E7B-AD11-D4582F9E76BB} 2012-06-30 05:39:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{519B7431-8BA8-405C-839C-5275EC0B457B} 2012-06-30 05:39:34 ——– d—–w- C:\Users\Sharon\AppData\Local\{EA73FE63-7334-4647-8963-A4295CFCF13F} 2012-06-30 03:53:33 ——– d—–w- C:\Users\Sharon\AppData\Local\{C96822F8-8386-4598-8085-CD6590F0D1D6} 2012-06-30 03:53:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{3EBD2C33-42D7-48C5-9D4D-A10D25236C16} 2012-06-29 02:29:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{8E27097A-CDA5-4C4F-A70C-D3C15ECE9B21} 2012-06-29 02:29:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{71160F1C-82D8-4512-88F2-0798539FC4EA} 2012-06-29 00:57:13 ——– d—–w- C:\Users\Sharon\AppData\Local\{FCDD5032-A3CB-43E3-8C2C-C77ECCAA3918} 2012-06-29 00:57:00 ——– d—–w- C:\Users\Sharon\AppData\Local\{5D869540-304D-43AA-91E2-FC874FF5F4E4} 2012-06-28 23:46:37 ——– d—–w- C:\Users\Sharon\AppData\Local\{280EAB94-22BA-448C-A5EA-D38826ABBD79} 2012-06-28 23:46:24 ——– d—–w- C:\Users\Sharon\AppData\Local\{C772FFB2-DB02-4EC4-9FB2-EBC3F03867D9} 2012-06-28 23:25:08 ——– d—–w- C:\Users\Sharon\AppData\Local\{FD6AE4EA-3364-4533-807F-E11FBAC9BF71} 2012-06-28 23:24:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{D7A34F2B-9BD4-4C81-808D-BB11D3956D5C} 2012-06-28 22:37:15 ——– d—–w- C:\Users\Sharon\AppData\Local\{A0B056AF-9F0B-403E-9297-8851E38D02D9} 2012-06-28 22:37:01 ——– d—–w- C:\Users\Sharon\AppData\Local\{5B0CF90F-1B5C-4C3A-B464-BE924CBE3436} 2012-06-28 16:34:43 ——– d—–w- C:\Users\Sharon\AppData\Local\{1D93E761-CE87-45A9-BB97-831A3DDDE51E} 2012-06-28 16:34:29 ——– d—–w- C:\Users\Sharon\AppData\Local\{8BD35391-6A7A-4128-B64F-F0F214769B16} 2012-06-28 00:26:01 ——– d—–w- C:\Users\Sharon\AppData\Local\{17225318-DD2C-4A38-84B5-5EE8CAB66402} 2012-06-28 00:16:58 ——– d—–w- C:\Users\Sharon\AppData\Local\{9E35A8D8-2BA3-419D-BA99-F4860EB628BC} 2012-06-27 20:14:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{FEE9F2A8-672D-4CCF-AC8A-D238CB8A8A2B} 2012-06-27 20:13:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{18D465C2-6673-4970-967A-CC121FBDA9E4} 2012-06-27 13:00:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{4BDEA4C0-158D-4364-A3C1-366274AC02AC} 2012-06-27 13:00:40 ——– d—–w- C:\Users\Sharon\AppData\Local\{35E0E83E-6F49-4B90-A438-B2F40323338B} 2012-06-26 21:35:55 ——– d—–w- C:\Users\Sharon\AppData\Local\{85A7267C-1F41-4C2A-868F-4D021B960BC1} 2012-06-26 21:35:38 ——– d—–w- C:\Users\Sharon\AppData\Local\{41E069CC-934C-4501-8E35-C93824D021E3} 2012-06-26 01:50:15 ——– d—–w- C:\Users\Sharon\AppData\Local\{74AE281C-CF70-43E0-90BA-C3EC5A810C82} 2012-06-26 01:50:03 ——– d—–w- C:\Users\Sharon\AppData\Local\{EE1EA039-AA2D-4907-8FE7-5BBD99E1EAA4} 2012-06-25 18:58:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{4C06B52B-7808-4A59-9C9E-F860C2BF4E77} 2012-06-25 18:58:40 ——– d—–w- C:\Users\Sharon\AppData\Local\{DDF3228E-A75B-46E8-842E-7B4683D0FA47} 2012-06-25 04:46:14 28760 —-a-w- C:\Program Files (x86)\Mozilla Firefox\ScriptFF.dll 2012-06-25 03:39:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{84BA9879-3635-4625-A80A-A8703099B795} 2012-06-25 03:39:34 ——– d—–w- C:\Users\Sharon\AppData\Local\{E7E49314-BD24-44C6-8A1C-7D7FB82B278E} 2012-06-24 23:41:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{403409B7-6BAF-4C72-BF7A-BC3FE39F64DA} 2012-06-24 23:41:08 ——– d—–w- C:\Users\Sharon\AppData\Local\{CC26DD6B-7CE0-46D5-A657-0F2E964E100D} 2012-06-24 17:39:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{8B59543C-4F00-4571-87FB-5E7B8C55510F} 2012-06-24 17:39:20 ——– d—–w- C:\Users\Sharon\AppData\Local\{C60A2436-E285-425D-AE19-9362BDCDBC35} 2012-06-24 05:53:32 ——– d—–w- C:\Users\Sharon\AppData\Local\Macromedia 2012-06-24 04:32:43 ——– d—–w- C:\Users\Sharon\AppData\Local\{DBACAB4A-B6C9-4360-AA26-7CCBF5690DA4} 2012-06-24 04:32:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{AD6F9339-2DCD-4394-A621-6CF64A227B1A} 2012-06-23 22:45:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{7B1E485C-5E59-4D31-A9D5-1B87D4D00096} 2012-06-23 22:45:40 ——– d—–w- C:\Users\Sharon\AppData\Local\{D6A41E4C-B3C3-4A23-9BB7-748098FAFF32} 2012-06-23 20:49:05 ——– d—–w- C:\Users\Sharon\AppData\Local\{D7615484-A6AA-480A-A070-AF77BBC3C6DB} 2012-06-23 20:48:54 ——– d—–w- C:\Users\Sharon\AppData\Local\{E364412C-41DC-44D5-92F2-0046776C0058} 2012-06-23 20:16:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{11DBAA36-C0F9-4696-912E-5FD1FA106DEC} 2012-06-23 20:16:19 ——– d—–w- C:\Users\Sharon\AppData\Local\{E6C2BDC0-1DCB-4139-9C82-18E0A377A9D1} 2012-06-23 19:55:43 ——– d—–w- C:\Users\Sharon\AppData\Local\{9E1E02F9-2351-418A-A70F-B9CFA5C203B7} 2012-06-23 19:55:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{B9467569-85AD-429B-8CAF-749CF028D44D} 2012-06-22 19:29:32 ——– d—–w- C:\Users\Sharon\AppData\Local\{C443DB6F-0B52-4092-BFCD-A1490E5218D9} 2012-06-22 19:29:20 ——– d—–w- C:\Users\Sharon\AppData\Local\{08BF3389-F865-419F-A490-EE2AEDAB1842} 2012-06-22 18:04:48 ——– d—–w- C:\Users\Sharon\AppData\Local\{FE455531-D480-42E5-AE3A-18EEF9447C9E} 2012-06-22 18:04:35 ——– d—–w- C:\Users\Sharon\AppData\Local\{206042FC-AD26-415C-9101-39459464E3AF} 2012-06-22 15:16:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{B3B761A6-AEF1-45EC-8027-999EF20FA7CF} 2012-06-22 15:16:20 ——– d—–w- C:\Users\Sharon\AppData\Local\{828AF7E4-53FD-4413-AFA3-24AD3CF2D86C} 2012-06-22 02:15:41 ——– d—–w- C:\Users\Sharon\AppData\Local\{A99453CD-8DD2-41BA-AB5E-6A029936BF25} 2012-06-22 02:15:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{6016AD79-2B72-4A50-8F59-FE5D36DA2B94} 2012-06-22 00:41:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{1E0A29A3-1175-4E70-8191-F83A8328893E} 2012-06-22 00:40:57 ——– d—–w- C:\Users\Sharon\AppData\Local\{6F3FC865-7C4F-45C6-9216-25E9E2CD4217} 2012-06-21 23:53:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{117DA3CB-DCB0-4C62-B7DA-8C875CC8E8FF} 2012-06-21 23:53:44 ——– d—–w- C:\Users\Sharon\AppData\Local\{616EFABB-886F-4D1E-906D-FDF86E0D4B03} 2012-06-21 22:38:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{AB880034-396A-4016-8F84-43C61E7F93E5} 2012-06-21 22:38:09 ——– d—–w- C:\Users\Sharon\AppData\Local\{5DBBDCD3-F156-4B81-BB39-CDBC67C564EB} 2012-06-21 15:17:29 ——– d—–w- C:\Users\Sharon\AppData\Local\{F91A55C1-FC27-46BD-8D4F-65BCA36CA565} 2012-06-21 15:17:17 ——– d—–w- C:\Users\Sharon\AppData\Local\{8A7DAA3F-FE0A-4107-812B-3FCCDA156C19} 2012-06-21 04:57:47 ——– d—–w- C:\Users\Sharon\AppData\Local\{4C22D5CB-1556-4795-979E-30B260C4827F} 2012-06-21 04:57:35 ——– d—–w- C:\Users\Sharon\AppData\Local\{6053ACE7-F945-4390-96D2-0ECDD8BD9849} 2012-06-21 03:22:27 ——– d—–w- C:\Users\Sharon\AppData\Local\{BE946F1F-AB50-48DA-8D32-B703159DB2C4} 2012-06-21 03:22:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{51F9F383-8B67-4C15-AFA7-3A63730DA91B} 2012-06-21 01:00:32 ——– d—–w- C:\Users\Sharon\AppData\Local\{DC4F5021-207A-4FF0-8986-FF424771B82A} 2012-06-21 01:00:17 ——– d—–w- C:\Users\Sharon\AppData\Local\{607A69ED-4FF3-4BEB-87AE-1E3DE8C978A4} 2012-06-20 22:34:24 ——– d—–w- C:\Users\Sharon\AppData\Local\{DD536831-CE4F-4FE9-8914-603D7CB275D4} 2012-06-20 22:34:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{8DEABA06-6918-4679-A42C-2B7B9962369A} 2012-06-20 20:47:06 ——– d—–w- C:\Users\Sharon\AppData\Local\{B2E1C023-3E45-4EC6-BFE6-C377BFC551B5} 2012-06-20 20:46:55 ——– d—–w- C:\Users\Sharon\AppData\Local\{301ACA47-C716-4035-9C26-21B53A86E04E} 2012-06-20 14:05:06 ——– d—–w- C:\Users\Sharon\AppData\Local\{CD45AAAF-3CD5-428D-A0FD-B5CC8FD9B0F0} 2012-06-20 14:04:54 ——– d—–w- C:\Users\Sharon\AppData\Local\{C4A91117-9B75-4F3C-B063-A0949411AD65} 2012-06-20 13:35:30 ——– d—–w- C:\Users\Sharon\AppData\Local\{1395217D-255E-416B-B6CE-B0A7E226DACC} 2012-06-20 13:35:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{4DBC3039-9492-451D-BC70-A4CEE8F902C8} 2012-06-19 16:15:49 2622464 —-a-w- C:\windows\System32\wucltux.dll 2012-06-19 16:15:37 99840 —-a-w- C:\windows\System32\wudriver.dll 2012-06-19 16:15:20 36864 —-a-w- C:\windows\System32\wuapp.exe 2012-06-19 16:15:20 186752 —-a-w- C:\windows\System32\wuwebv.dll 2012-06-18 20:20:10 ——– d—–w- C:\Users\Sharon\AppData\Roaming\OpenOffice.org 2012-06-18 20:19:11 ——– d—–w- C:\Program Files (x86)\OpenOffice.org 3 2012-06-18 17:21:16 ——– d—–w- C:\Users\Sharon\AppData\Local\{CC2AC9A4-3F6E-4FC0-9F07-FE000E01A49B} 2012-06-17 19:37:27 ——– d—–w- C:\Users\Sharon\AntiVirus 2012-06-17 18:43:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{CB32ACC5-3C2D-4A51-9CC7-8C1BEBED971B} 2012-06-17 18:36:26 ——– d—–w- C:\Users\Sharon\AppData\Roaming\Malwarebytes 2012-06-17 18:36:14 ——– d—–w- C:\ProgramData\Malwarebytes 2012-06-17 18:36:12 24904 —-a-w- C:\windows\System32\drivers\mbam.sys 2012-06-17 18:36:12 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-06-17 18:16:38 ——– d—–w- C:\Program Files (x86)\GridinSoft Trojan Killer 2012-06-17 03:59:23 ——– d-sh–w- C:\windows\System32\%APPDATA% 2012-06-17 03:48:48 ——– d—–w- C:\ProgramData\B7E858A700047CF10023A3B1B4EB2367 2012-06-17 03:38:35 426184 —-a-w- C:\windows\SysWow64\FlashPlayerApp.exe 2012-06-15 01:24:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{C83B6ADA-0539-4078-9E3C-584DE3C13302} 2012-06-14 22:56:05 ——– d—–w- C:\Users\Sharon\AppData\Local\{EF4DA002-8968-45F8-93EE-C8F25FAB411A} 2012-06-14 22:55:40 ——– d—–w- C:\Users\Sharon\AppData\Local\{A790F4FD-6164-40F4-9ADC-EE218C20BE07} 2012-06-14 20:43:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{F395F5C8-C48F-4FDA-B18D-1223C8F2CBB5} 2012-06-14 20:43:47 ——– d—–w- C:\Users\Sharon\AppData\Local\{216392F0-02FD-4045-BE6A-0B72EA24CA44} 2012-06-14 18:41:26 ——– d—–w- C:\Users\Sharon\AppData\Local\{958EBD29-48C8-4580-9B9D-358AFDFEE468} 2012-06-14 18:41:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{2703D1E0-C918-49C5-AB5D-00FC79F87E2A} 2012-06-14 17:02:47 ——– d—–w- C:\Users\Sharon\AppData\Local\{29ED9A85-4A27-4189-AC81-A045ABEC3760} 2012-06-14 17:02:35 ——– d—–w- C:\Users\Sharon\AppData\Local\{AC95B816-15C5-4FCD-B653-869D1E94773C} 2012-06-14 16:18:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{14642D57-C4AF-4BCD-9378-9BB9754AD4B8} 2012-06-14 16:17:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{643C4377-C288-440E-8708-A637985AB62F} 2012-06-14 15:53:07 ——– d—–w- C:\Users\Sharon\AppData\Local\{EB1A2371-765D-4A9E-A5F1-6CC76F2E9B79} 2012-06-14 15:52:47 ——– d—–w- C:\Users\Sharon\AppData\Local\{0B46EF89-A371-43BD-ABCE-838D1FD6F86F} 2012-06-14 13:14:29 ——– d—–w- C:\Users\Sharon\AppData\Local\{23D0BCFD-BF7D-4360-AEF6-1E76F2D33554} 2012-06-14 13:14:13 ——– d—–w- C:\Users\Sharon\AppData\Local\{8942A9F9-CB88-46B9-8387-247C48A47575} 2012-06-14 03:30:20 ——– d—–w- C:\Users\Sharon\AppData\Local\{C1C2EDA2-D5F6-4CD0-B9FE-4E4153EFB4C2} 2012-06-14 03:29:49 ——– d—–w- C:\Users\Sharon\AppData\Local\{4377E31B-5A02-4B64-BC1D-4D062FDDAC66} 2012-06-14 02:41:37 ——– d—–w- C:\Users\Sharon\AppData\Local\{440DF3B2-3A6C-4CF3-9354-B77C1C1D0C73} 2012-06-14 02:41:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{B84CC66F-CCF8-4554-BC63-2AF4AC5906AB} 2012-06-13 22:27:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{5C01D92B-F437-4472-88A7-863228006A7D} 2012-06-13 22:27:42 ——– d—–w- C:\Users\Sharon\AppData\Local\{9E629835-7334-4428-8830-D7293A52FB14} 2012-06-13 19:54:55 ——– d—–w- C:\Users\Sharon\AppData\Local\{37E3AEB2-BD53-455D-85DE-74B034C994DF} 2012-06-13 19:54:27 ——– d—–w- C:\Users\Sharon\AppData\Local\{710C3CE2-698F-49E5-A4DB-C4B0C7C50C6B} 2012-06-13 01:10:58 ——– d—–w- C:\Users\Sharon\AppData\Local\{35EA0513-9AA8-48BF-85CC-7A6DFA12321F} 2012-06-13 01:10:44 ——– d—–w- C:\Users\Sharon\AppData\Local\{3E3330AC-FCB7-4D77-ABC3-D9EC0FA6540E} 2012-06-12 04:08:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{2BA4ADC4-9003-4532-ADF1-4E39AD9A1F2C} 2012-06-12 04:07:50 ——– d—–w- C:\Users\Sharon\AppData\Local\{9C946E6E-5207-4357-B354-798BD82324B6} 2012-06-12 02:26:11 ——– d—–w- C:\Users\Sharon\AppData\Local\{C02E85C3-F1B5-4603-B57B-F2E5611E4576} 2012-06-12 02:25:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{A250E257-948C-4B66-98D3-A58215A4687D} 2012-06-12 01:53:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{35B80242-F46A-4C2B-8BD6-3BBB7B7BE3AE} 2012-06-12 01:53:01 ——– d—–w- C:\Users\Sharon\AppData\Local\{E9FE0D79-86E0-45E0-8CDF-3C7B1CF4E556} 2012-06-11 18:32:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{1AE8E8B1-B916-4B9B-890C-3EBCC74B60E6} 2012-06-11 18:32:37 ——– d—–w- C:\Users\Sharon\AppData\Local\{54C88B2F-E9A2-4FE9-B27E-0F023F136F84} 2012-06-11 14:50:23 ——– d—–w- C:\Users\Sharon\AppData\Local\{B65FD40B-DD08-40A4-AF90-19D8F4C60DD4} 2012-06-11 14:50:09 ——– d—–w- C:\Users\Sharon\AppData\Local\{E6DD8EBF-9934-4F0D-B892-57EB8410777A} 2012-06-11 11:46:38 ——– d—–w- C:\Users\Sharon\AppData\Local\{3E36CEEB-2B83-43F0-9D31-E14BA07C58BA} 2012-06-11 11:45:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{ACF5A9F6-E003-4EC4-A92C-D945C3025271} 2012-06-11 03:59:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{A2C2A5AF-8465-4472-B989-994D03EEB732} 2012-06-11 03:59:02 ——– d—–w- C:\Users\Sharon\AppData\Local\{C331C5DA-91E5-47E9-8C97-57CD8A83FAFE} 2012-06-11 02:03:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{FD189E14-53DC-4F54-9E1E-1321D9CC2132} 2012-06-11 02:03:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{B6E146DF-EFB6-49E7-9826-30E55C16536E} 2012-06-10 22:01:54 ——– d—–w- C:\Users\Sharon\AppData\Local\{30B65B93-0ACB-4682-9AD6-926BAD570F26} 2012-06-10 22:01:39 ——– d—–w- C:\Users\Sharon\AppData\Local\{D4B4F734-1854-41B8-A552-4557023F702D} 2012-06-10 20:31:06 ——– d—–w- C:\Users\Sharon\AppData\Local\{B3CA0888-89E9-492A-B3BE-94EE3ECB5F06} 2012-06-10 20:30:30 ——– d—–w- C:\Users\Sharon\AppData\Local\{7E5B040C-FE07-4F70-9437-47E247F9B09E} 2012-06-10 13:28:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{85C2A51D-6086-4E4E-9877-C8FFE5849642} 2012-06-10 13:27:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{6F9C3DCD-AC14-413F-BB75-0BCC973EE5CC} 2012-06-10 04:38:06 ——– d—–w- C:\Users\Sharon\AppData\Local\{D41097C7-7D3D-4FD8-BCF1-12B7DEC10F05} 2012-06-10 04:37:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{0C3810AD-7953-4E2C-A075-FECCBE4B7CEA} 2012-06-10 01:16:00 ——– d—–w- C:\Users\Sharon\AppData\Local\{9F7C2A27-04E9-4AB1-BA87-1295D40875A7} 2012-06-10 01:15:33 ——– d—–w- C:\Users\Sharon\AppData\Local\{05B32715-24D5-4482-B7A2-57FFFC7AAE6F} 2012-06-09 05:14:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{9A409EA1-0BC6-4E64-BFE6-F8DB9F8E8428} 2012-06-09 02:19:11 ——– d—–w- C:\Users\Sharon\AppData\Local\{4A3F2546-ACDF-4C5F-B42E-606E539AFA1D} 2012-06-09 02:18:58 ——– d—–w- C:\Users\Sharon\AppData\Local\{44F0753E-744C-42F6-83FC-D96B4B9EED7E} 2012-06-09 00:00:19 ——– d—–w- C:\Users\Sharon\AppData\Local\{56A00A78-11A0-4984-BD8E-FB1ABEBF2952} 2012-06-08 23:59:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{6E41C1C5-093E-4A69-A190-61BCFF6B4A5D} 2012-06-08 15:14:08 ——– d—–w- C:\Users\Sharon\AppData\Local\{405B78FB-F3F0-4F00-BA7E-D0AB1F5D70A2} 2012-06-08 15:13:54 ——– d—–w- C:\Users\Sharon\AppData\Local\{4F50FF10-4715-4DAC-962D-68E26B903760} 2012-06-07 18:35:48 ——– d—–w- C:\Users\Sharon\AppData\Local\{F62C6F14-C506-4602-BADA-A73C21CBEA0A} 2012-06-07 18:35:37 ——– d—–w- C:\Users\Sharon\AppData\Local\{38DEBAED-B4D0-4AD4-83EA-98A3C16B777E} 2012-06-07 16:13:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{9216584E-A645-4AE5-A759-7F4F5410D874} 2012-06-07 16:13:07 ——– d—–w- C:\Users\Sharon\AppData\Local\{D39509F2-83A2-4267-B229-7BF7C8B5EE9E} 2012-06-07 15:05:08 ——– d—–w- C:\Users\Sharon\AppData\Local\{1CB243EE-9E15-4D4F-B89A-24077A960F9D} 2012-06-07 15:04:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{7D3C8462-0CF9-4741-A87E-656496CD269B} 2012-06-07 03:16:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{D92C5BCE-3145-4F6A-B5FB-C116A6C9B2E3} 2012-06-07 03:16:07 ——– d—–w- C:\Users\Sharon\AppData\Local\{35F22146-16CA-4606-9541-8E8B69FDB5F7} 2012-06-07 02:06:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{83E375AB-4BB6-41AF-B9AC-FB26C9C92F30} 2012-06-07 02:06:41 ——– d—–w- C:\Users\Sharon\AppData\Local\{52D5B2CB-438A-40A3-B4B1-613EB84F932C} 2012-06-07 01:30:25 ——– d—–w- C:\Users\Sharon\AppData\Local\{A09C51FA-47FC-4862-A76C-BE78CEADAC36} 2012-06-07 01:30:11 ——– d—–w- C:\Users\Sharon\AppData\Local\{12D65B97-5C1D-408C-B144-D1C17467474C} 2012-06-06 21:53:04 ——– d—–w- C:\Users\Sharon\AppData\Roaming\Macrovision 2012-06-06 21:52:13 ——– d—–w- C:\Users\Sharon\AppData\Roaming\Roxio Burn 2012-06-06 21:23:48 ——– d—–w- C:\Users\Sharon\AppData\Local\{CC9764A2-9D4A-4035-A60C-FD1E14C41A56} 2012-06-06 21:23:28 ——– d—–w- C:\Users\Sharon\AppData\Local\{B2EBA2A0-4CA9-4B5F-A58C-1030888A2299} 2012-06-06 20:20:29 ——– d—–w- C:\Users\Sharon\AppData\Local\{1D61C60C-2AAD-4443-AF53-91852537B1C4} 2012-06-06 20:20:05 ——– d—–w- C:\Users\Sharon\AppData\Local\{BC036FFE-6012-4EB2-BDDC-152586CE62A4} 2012-06-06 16:46:27 ——– d—–w- C:\Users\Sharon\AppData\Local\{02FD9B1E-FDC4-46AC-9867-DB3F823DBE18} 2012-06-06 16:46:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{24D49C00-145F-4250-ACF7-4C4BD2CEFC42} 2012-06-06 14:16:11 ——– d—–w- C:\Users\Sharon\AppData\Local\{2302DB1A-0178-4E55-BDE9-9BE60DC3C859} 2012-06-06 14:15:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{FADBE00C-62AE-4B13-A312-765942761D07} 2012-06-06 13:11:19 ——– d—–w- C:\Users\Sharon\AppData\Local\{124C5D11-F53D-4DF6-A04C-CAB152742576} 2012-06-06 13:11:07 ——– d—–w- C:\Users\Sharon\AppData\Local\{4A6A056F-9BF0-4C79-B8C9-BE629942A9C8} 2012-06-06 03:13:01 ——– d—–w- C:\Users\Sharon\AppData\Local\{74354BB8-D864-40BA-8C9D-1F6D46D2176B} 2012-06-06 03:12:45 ——– d—–w- C:\Users\Sharon\AppData\Local\{0A5075BD-C67E-489C-8879-1064744D95EF} 2012-06-06 00:11:04 ——– d—–w- C:\Users\Sharon\AppData\Local\{95FE3E88-C696-4A1D-926A-3F88990201BB} 2012-06-06 00:10:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{54199534-94C7-4C14-A370-5CBF4C98380D} 2012-06-05 20:12:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{24F9949C-4E01-467F-A3F3-ED71EEB0F14D} 2012-06-05 20:12:24 ——– d—–w- C:\Users\Sharon\AppData\Local\{D29FF131-4EAA-4199-8E11-338E73537F2F} 2012-06-05 19:26:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{B6FA592E-D90F-4384-9E91-07E68EE24D09} 2012-06-05 19:26:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{36119E21-05A8-49D7-8598-3B6D573947BF} 2012-06-05 16:36:21 ——– d—–w- C:\Users\Sharon\AppData\Local\{FDAEFB58-C45F-4460-AF16-1440AE58EA60} 2012-06-05 16:35:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{CAEFF514-2A9A-4EF9-8550-C9E1B5372FC5} 2012-06-05 16:12:16 ——– d—–w- C:\Users\Sharon\AppData\Local\{10E34BE7-CFBC-4C1D-BCAB-F082A00D87C1} 2012-06-05 16:11:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{9F8DFC1F-0221-404B-BB77-A9A8FC145147} . ==================== Find3M ==================== . 2012-06-17 03:50:09 70344 —-a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-04-19 09:50:26 28480 —-a-w- C:\windows\System32\drivers\avgidsha.sys . ============= FINISH: 11:21:43.79 =============== ATTACH . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 4/15/2012 2:46:37 PM System Uptime: 7/5/2012 11:03:14 AM (0 hours ago) . Motherboard: Dell Inc. | | 034W60 Processor: Intel® Core™ i5-2450M CPU @ 2.50GHz | CPU 1 | 2501/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 684 GiB total, 634.52 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP13: 6/7/2012 2:25:46 PM - Scheduled Checkpoint RP14: 6/16/2012 10:34:56 PM - Installed Safari RP15: 6/18/2012 3:17:24 PM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 RP16: 6/18/2012 3:18:56 PM - Installed OpenOffice.org 3.4 RP17: 6/19/2012 11:15:03 AM - Windows Update RP18: 6/26/2012 12:52:43 PM - Configured Microsoft Office Home and Student 2010 RP19: 6/26/2012 12:54:16 PM - Configured Microsoft Office Home and Student 2010 RP20: 7/2/2012 7:21:00 PM - Installed AVG 2012 RP21: 7/2/2012 7:21:32 PM - Installed AVG 2012 RP22: 7/3/2012 5:35:39 PM - Restore Operation . ==== Installed Programs ====================== . Adobe AIR Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X MUI Advanced Audio FX Engine Apple Application Support Apple Software Update Bejeweled 2 Deluxe Best Buy Connect Bing Bar Blackhawk Striker 2 Blio Bounce Symphony Build-a-lot 2 Cake Mania Chuzzle Deluxe Cozi D3DX10 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Dell DataSafe Local Backup Dell DataSafe Local Backup - Support Software Dell DataSafe Online Dell Digital Delivery Dell Getting Started Guide Dell MusicStage Dell PhotoStage Dell Product Registration Dell Stage Dell VideoStage Dell Webcam Central Diner Dash 2 Restaurant Rescue DirectX 9 Runtime Dora's World Adventure eBay Escape Whisper Valley ™ Facebook Video Calling 1.2.0.159 Farm Frenzy FATE Final Drive Fury Final Drive Nitro Google Chrome High-Definition Video Playback IDT Audio Intel PROSet Wireless Intel® Control Center Intel® Management Engine Components Intel® Processor Graphics Intel® Rapid Storage Technology Intel® WiDi Java Auto Updater Java™ 7 Update 1 Jewel Quest Jewel Quest Solitaire 2 Junk Mail filter update Luxor Malwarebytes Anti-Malware version 1.61.0.1400 McAfee SecurityCenter Mesh Runtime Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Home and Student 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Single Image 2010 Microsoft Office Word MUI (English) 2010 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mozilla Firefox 13.0.1 (x86 en-US) Mozilla Maintenance Service MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Namco All-Stars PAC-MAN Nero 10 Movie ThemePack Basic Nero Control Center 10 Nero ControlCenter 10 Help (CHM) Nero Core Components 10 Nero Update OpenOffice.org 3.4 Penguins! PhotoShowExpress Plants vs. Zombies - Game of the Year PlayReady PC Runtime x86 Poker Superstars III Polar Bowler Polar Golfer QuickTime Realtek Ethernet Controller Driver Realtek USB 2.0 Card Reader Roxio Activation Module Roxio BackOnTrack Roxio Burn Roxio Creator Starter Roxio Express Labeler 3 Safari Samantha Swift Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) Security Update for Microsoft Visio Viewer 2010 (KB2597170) 32-Bit Edition Skype™ 5.5 Sonic CinePlayer Decoder Pack SyncUP TI USB 3.0 Host Controller Driver TI USB3 Host Driver Trojan Killer Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2600217) Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update Installer for WildTangent Games App Virtual Villagers 4 - The Tree of Life Visual Studio 2008 x64 Redistributables Wedding Dash - Ready, Aim, Love! WildTangent Games WildTangent Games App (Dell Games) Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Zinio Reader 4 Zuma Deluxe . ==== Event Viewer Messages From Past Week ======== . 7/5/2012 11:06:30 AM, Error: Service Control Manager [7003] - The McAfee Personal Firewall Service service depends the following service: MpsSvc. This service might not be installed. 7/5/2012 11:06:15 AM, Error: Service Control Manager [7034] - The Intel® Rapid Storage Technology service terminated unexpectedly. It has done this 1 time(s). 7/5/2012 11:06:11 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Dell Digital Delivery Service service to connect. 7/5/2012 11:06:11 AM, Error: Service Control Manager [7000] - The Dell Digital Delivery Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/5/2012 11:04:49 AM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891 7/5/2012 11:04:49 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891 7/5/2012 11:03:54 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed. 7/5/2012 11:03:52 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed. 7/5/2012 11:03:50 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service. 7/4/2012 7:18:47 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Security with the following error: Access is denied. 7/3/2012 4:46:48 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} 7/3/2012 4:43:03 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. 7/3/2012 4:43:02 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 7/3/2012 4:43:01 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\windows\System32\IWMSSvc.dll Error Code: 21 7/3/2012 4:43:01 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 7/3/2012 4:42:56 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 7/3/2012 4:42:48 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 7/3/2012 4:42:46 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 discache spldr Wanarpv6 7/3/2012 4:42:42 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. . ==== End Of File =========================== And then the aswMBR log is having a problem going through. I downloaded it like you asked and it started going and it paused/froze and so i exited it and started again and it stopped at the exact same spot. So im not exactly sure why it did that so i saved the log as far as it went and its attacted with this. I hope this isnt a bad setback. And thank you for your response and for helping me.

Attachments:

I tried it again and this time i got this but once again it froze at something like appdata/bing/bar or something like that :/ Im not really sure what to do at this point,.. File is attached below.
Many apologies but my computer isn't working at present. I'll check the log and get back to you as soon as I'm able. Satchfan
My hard drive has really died so I have asked other members of the malware team to take over. I apologise again for the delay and hope someone will reply to you soon. Satchfan
Hi,

Please run the following:


download Farbar Recovery Scan Tool and save it to a flash drive.
(you need the 64bit version)
Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to the disclaimer.

[*]Place a check next to List Drivers MD5 as well as the default check marks that are already there

[*]Press Scan button.

[*]type exit and reboot the computer normally

[*]FRST will make a log (FRST.txt) on the flash drive, please copy and paste the log in your reply.

Sorry to say this but im not exactly sure if i can do all of this because i am not really handy with computers, could you rephrase this to make it easier for me to understand? Thank you
let me know what part you are having difficulty with and I'll be happy to explain as best I can, print off the instructions so you have them with you when you are following the instructions


before we go this route as it is a little advanced, let's try running this tool:

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.


let me know if you have any questions before you follow those instructions

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI