Okay so i have an inspiron dell laptop N5110 and recently ive been running MBAM and ive been getting this one virus named "RootKit.0access, with the file locating from C:\Windows\Installer\{3b99f81f-31d5-dbab-1bcf-87d0107a285a}\U and inside these files i get "00000001.@" , "800000cb.@" , and "80000000.@" and im not exactly sure what to do,. I got it maybe a week ago and i run scans usually everyday and its there. i've tried to quartine it and it says that its been removed and i restart it and everything and when i do the next scan it is still there.. I really need some help with this to get this off my computer because i have work to do.. im not really sure how it is infecting the computer, but i know that its something bad and want to get it off ASAP. So once this started popping up then MBAM every now and then (maybe once or twice every two days) would say that they detected that a virus or something named something along the lines of "Sifefref" or something like that (I cant rememebr, i havent seen it in a while) where doing it so i pressed quaratine to that. Then three days ago i downloaded AVG software and it came back with something called Trojan Dropper Generic (along the lines of that) and the infected area was in my service.exe files, and after looking online, i found out about the :
"Hi, I have found a soultion to the problem.
1. Go to start, type "cmd" to open the command prompt
2. Type or copy & paste "sfc /scanfile=c:\windows\system32\services.exe" and press enter
3. Restart your computer
This will replace the infected services.exe with the original.
If it dosen't work try it in safe mode."
And i tried this and it seemed to got rid of that problem but it could still be lingering on because i read that usually a few hours later they receive the same notice along with Trojan Dropper Generic28.Udx. So Im wondering how can i get this Rootkit.0access of my computer and make sure everything is okay. Btw MBAM didnt detect the stuff AVG detected in my service.exe files. It kept popping up as a AVG resident Shield protecter and only gave me the option to ignore it if that is any help. Can someone please get back to me asap about this problem.
Thank you for your time
Hello
troy645 and welcome to the
WTT forum.
My name is
Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier: please follow all instructions in the order posted please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear all logs/reports, etc. must be posted in Notepad . Please ensure that word wrap is un checked . In Notepad click Format , uncheck Word wrap if it is checked if you don't understand something, please don't hesitate to ask for clarification before proceeding the fixes are specific to your problem and should only be used for this issue on this machine. please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed! IMPORTANT :
Please
DO NOT install/uninstall any programs unless asked to.
Please
DO NOT run any scans other than those requested
===================================================
Run DDS
Please download DDS by sUBs from one of the following links and save it to your desktop.
DDS.scr
DDS.pif
disable any script blocking protection (How to Disable your Security Programs ) double click DDS icon to run the tool (may take up to 3 minutes to run) when done, DDS.txt will open. after a few moments, attach.txt will open in a second window. save both reports to your desktop. Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================
Run aswMBR download aswMBR.exe to your desktop. double click aswMBR.exe to run it if asked, accept the AVAST virus definition download click the "Scan" button to start scan on completion of the scan click Save log , save it to your desktop and post in your next reply
Please include the following in your next post :
DDS.txt
Attach.txt
aswMBR log
Thanks
Satchfan
Thank you for your response
I have done the first part of what you asked: The DTT:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 11:10:36 on 2012-07-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6050.3993 [GMT -5:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\windows\System32\spoolsv.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\windows\system32\wbem\unsecapp.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
C:\windows\System32\vds.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\DellTPad\Apntex.exe
C:\windows\system32\conhost.exe
C:\Program Files\mcafee.com\agent\mcagent.exe
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\windows\system32\sppsvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\windows\system32\notepad.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\DllHost.exe
C:\windows\SysWOW64\cmd.exe
C:\windows\system32\conhost.exe
C:\windows\SysWOW64\cscript.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120624234614.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Facebook Update] "C:\Users\Sharon\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [Google Update] "C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot
mRun: []
mRun: [RoxWatchTray] "c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900
mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" –startup
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{5F5BDC92-DD1F-41C8-9D0E-B0ADE2D29057} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{5F5BDC92-DD1F-41C8-9D0E-B0ADE2D29057}\E4544574541425 : DhcpNameServer = 192.168.1.1
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\msc\McSnIePl.dll
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO-X64: AVG Do Not Track - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120624234614.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe /boot
mRun-x64: [(Default)]
mRun-x64: [RoxWatchTray] "c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun-x64: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun-x64: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900
mRun-x64: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" –startup
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRunOnce-x64: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\tq0hgxhu.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9401a445-8a01-44cc-b106-5cdf2656f309%7D∣=f362b1fafabf47d0a3d09da204caaaa8-e7b31230b0bd0cc9828c2f5b36ab6c108378784e&ds;=AVG&v;=11.1.0.12⟨=en≺=fr&d;=2012-07-02%2019%3A23%3A00&sap;=ku&q;=
FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Sharon\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Sharon\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\windows\system32\DRIVERS\avgidsha.sys –> C:\windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\windows\system32\DRIVERS\avgrkx64.sys –> C:\windows\system32\DRIVERS\avgrkx64.sys [?]
R0 mfehidk;McAfee Inc. mfehidk;C:\windows\system32\drivers\mfehidk.sys –> C:\windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\windows\system32\drivers\mfewfpk.sys –> C:\windows\system32\drivers\mfewfpk.sys [?]
R0 PxHlpa64;PxHlpa64;C:\windows\system32\Drivers\PxHlpa64.sys –> C:\windows\system32\Drivers\PxHlpa64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\windows\system32\DRIVERS\avgldx64.sys –> C:\windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\windows\system32\DRIVERS\avgmfx64.sys –> C:\windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\windows\system32\DRIVERS\avgtdia.sys –> C:\windows\system32\DRIVERS\avgtdia.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\windows\system32\DRIVERS\mfenlfk.sys –> C:\windows\system32\DRIVERS\mfenlfk.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys –> C:\windows\system32\DRIVERS\vwififlt.sys [?]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2012-2-24 89600]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-9-15 1166848]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-6-13 5161080]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-5-12 249648]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-5-19 921664]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-5-19 995392]
R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-6-3 134928]
R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2011-6-14 498688]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-6-17 654408]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-27 249936]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-27 249936]
R2 McShield;McAfee McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2012-2-24 199272]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2012-2-24 208536]
R2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" –> C:\Windows\system32\mfevtps.exe [?]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-25 2823000]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2012-2-24 689472]
R2 TurboB;Turbo Boost UI Monitor driver;C:\windows\system32\DRIVERS\TurboB.sys –> C:\windows\system32\DRIVERS\TurboB.sys [?]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-2-24 2655768]
R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-7-2 935008]
R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2011-6-14 986112]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:\windows\system32\DRIVERS\AMPPAL.sys –> C:\windows\system32\DRIVERS\AMPPAL.sys [?]
R3 AVGIDSDriver;AVGIDSDriver;C:\windows\system32\DRIVERS\avgidsdrivera.sys –> C:\windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\windows\system32\DRIVERS\avgidsfiltera.sys –> C:\windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-5-19 1335360]
R3 bpenum;Intel® Centrino® WiMAX Enumerator;C:\windows\system32\DRIVERS\bpenum.sys –> C:\windows\system32\DRIVERS\bpenum.sys [?]
R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\windows\system32\DRIVERS\bpmp.sys –> C:\windows\system32\DRIVERS\bpmp.sys [?]
R3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;C:\windows\system32\Drivers\bpusb.sys –> C:\windows\system32\Drivers\bpusb.sys [?]
R3 btmaudio;Intel Bluetooth Audio Service;C:\windows\system32\drivers\btmaud.sys –> C:\windows\system32\drivers\btmaud.sys [?]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\windows\system32\DRIVERS\btmaux.sys –> C:\windows\system32\DRIVERS\btmaux.sys [?]
R3 btmhsf;btmhsf;C:\windows\system32\DRIVERS\btmhsf.sys –> C:\windows\system32\DRIVERS\btmhsf.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\windows\system32\DRIVERS\CtClsFlt.sys –> C:\windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 iBtFltCoex;iBtFltCoex;C:\windows\system32\DRIVERS\iBtFltCoex.sys –> C:\windows\system32\DRIVERS\iBtFltCoex.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys –> C:\windows\system32\DRIVERS\IntcDAud.sys [?]
R3 iwdbus;IWD Bus Enumerator;C:\windows\system32\DRIVERS\iwdbus.sys –> C:\windows\system32\DRIVERS\iwdbus.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\windows\system32\drivers\mbam.sys –> C:\windows\system32\drivers\mbam.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys –> C:\windows\system32\DRIVERS\HECIx64.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\windows\system32\drivers\mfeavfk.sys –> C:\windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\windows\system32\drivers\mfefirek.sys –> C:\windows\system32\drivers\mfefirek.sys [?]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-9-15 340240]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\windows\system32\DRIVERS\NETwNs64.sys –> C:\windows\system32\DRIVERS\NETwNs64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys –> C:\windows\system32\DRIVERS\Rt64win7.sys [?]
R3 tihub3;TI USB3 Hub Service;C:\windows\system32\DRIVERS\tihub3.sys –> C:\windows\system32\DRIVERS\tihub3.sys [?]
R3 tixhci;TI XHCI Service;C:\windows\system32\DRIVERS\tixhci.sys –> C:\windows\system32\DRIVERS\tixhci.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys –> C:\windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2011-10-26 162816]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-2-24 13336]
S2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-27 249936]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:\windows\system32\DRIVERS\amppal.sys –> C:\windows\system32\DRIVERS\amppal.sys [?]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-6-7 191752]
S3 cfwids;McAfee Inc. cfwids;C:\windows\system32\drivers\cfwids.sys –> C:\windows\system32\drivers\cfwids.sys [?]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\windows\system32\drivers\intelaud.sys –> C:\windows\system32\drivers\intelaud.sys [?]
S3 McAWFwk;McAfee Activation Service;C:\PROGRA~1\mcafee\msc\mcawfwk.exe [2012-2-24 224704]
S3 mferkdet;McAfee Inc. mferkdet;C:\windows\system32\drivers\mferkdet.sys –> C:\windows\system32\drivers\mferkdet.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-6-23 113120]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUStor.sys –> C:\windows\system32\Drivers\RtsUStor.sys [?]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;C:\windows\system32\DRIVERS\gtkdrv.sys –> C:\windows\system32\DRIVERS\gtkdrv.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys –> C:\windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys –> C:\windows\system32\drivers\TsUsbGD.sys [?]
S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe –> C:\windows\system32\Wat\WatAdminSvc.exe [?]
S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-27 249936]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-07-05 16:05:03 ——– d—–w- C:\Users\Sharon\AppData\Local\{1D51459F-0123-41F6-ACF5-6899A4FD19E7}
2012-07-05 16:04:51 ——– d—–w- C:\Users\Sharon\AppData\Local\{53F3CB2E-79AE-41A3-B823-70DC2032D182}
2012-07-05 02:15:00 ——– d—–w- C:\Users\Sharon\AppData\Local\{58887A1F-0F04-4301-B34C-7473737F29B2}
2012-07-05 02:14:45 ——– d—–w- C:\Users\Sharon\AppData\Local\{D8439C08-6758-4F1C-A996-7B07AF9ACCB4}
2012-07-05 00:12:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{DDA5F728-0951-4666-922E-6544F8BF3047}
2012-07-05 00:11:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{386C2E17-6880-436B-9A9F-A8A2EFC41440}
2012-07-03 23:20:43 ——– d—–w- C:\Users\Sharon\AppData\Local\{2052B2E6-8AE8-4848-A83D-687BD2CF649E}
2012-07-03 23:20:28 ——– d—–w- C:\Users\Sharon\AppData\Local\{FAED87C5-41AB-41D7-9523-35E6534D0226}
2012-07-03 22:58:28 ——– d—–w- C:\Users\Sharon\AppData\Local\{87328003-CD53-48D4-ADF5-CB5BC3E0B07C}
2012-07-03 22:58:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{5A99F755-6447-4C4B-B18D-697B767C4C2D}
2012-07-03 22:21:09 ——– d—–w- C:\Users\Sharon\AppData\Local\{8F126BD3-3CF7-4AF0-9B8C-00B665E56076}
2012-07-03 22:20:55 ——– d—–w- C:\Users\Sharon\AppData\Local\{1ECE33E8-F6EF-4930-95F5-1EF6A508BE5E}
2012-07-03 01:11:18 ——– d—–w- C:\Users\Sharon\AppData\Local\{D5A2F808-0C84-4E1A-BD6C-972EA5341702}
2012-07-03 01:11:04 ——– d—–w- C:\Users\Sharon\AppData\Local\{CF09F17B-9264-4A5D-9B6A-BD3CD9E554B4}
2012-07-03 00:23:36 ——– d—–w- C:\Users\Sharon\AppData\Roaming\AVG2012
2012-07-03 00:23:12 ——– d—–w- C:\Users\Sharon\AppData\Local\AVG Secure Search
2012-07-03 00:22:58 ——– d—–w- C:\ProgramData\AVG Secure Search
2012-07-03 00:22:57 ——– d—–w- C:\Program Files (x86)\Common Files\AVG Secure Search
2012-07-03 00:22:56 ——– d—–w- C:\Program Files (x86)\AVG Secure Search
2012-07-03 00:22:30 ——– d—–w- C:\windows\SysWow64\drivers\AVG
2012-07-03 00:22:02 ——– d–h–w- C:\$AVG
2012-07-03 00:22:02 ——– d—–w- C:\windows\System32\drivers\AVG
2012-07-03 00:22:02 ——– d—–w- C:\ProgramData\AVG2012
2012-07-03 00:21:25 ——– d—–w- C:\Program Files (x86)\AVG
2012-07-03 00:18:42 ——– d–h–w- C:\ProgramData\Common Files
2012-07-03 00:18:28 ——– d—–w- C:\ProgramData\MFAData
2012-07-02 22:29:48 ——– d—–w- C:\Users\Sharon\AppData\Local\{E5D2FB26-EC4C-4F86-8828-10DB20069B47}
2012-07-02 22:29:35 ——– d—–w- C:\Users\Sharon\AppData\Local\{0046811C-24DB-4129-818C-B2F64D70673D}
2012-07-02 22:06:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{C4050F7F-8010-4FFA-B828-6B2F5CDF0CE6}
2012-07-02 22:06:23 ——– d—–w- C:\Users\Sharon\AppData\Local\{88EABE12-FCDB-4EA8-989A-9A0B6007AED8}
2012-07-02 19:04:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{421C5ED0-FB6B-4D98-9BBB-1690BE915803}
2012-07-02 19:04:23 ——– d—–w- C:\Users\Sharon\AppData\Local\{4BC33703-6859-491E-A95B-2F9767376401}
2012-07-02 03:43:25 ——– d—–w- C:\Users\Sharon\AppData\Local\{192CA469-3F8E-48A0-95B2-AE82EB8C623F}
2012-07-02 03:43:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{EC94A50D-A5D6-45A8-BCFF-C90209FA5E4E}
2012-06-30 14:58:44 ——– d—–w- C:\Users\Sharon\AppData\Local\{F614BE76-3375-4BE0-9529-35AA721EC2D0}
2012-06-30 14:58:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{093A7F4A-8DD5-4E7B-AD11-D4582F9E76BB}
2012-06-30 05:39:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{519B7431-8BA8-405C-839C-5275EC0B457B}
2012-06-30 05:39:34 ——– d—–w- C:\Users\Sharon\AppData\Local\{EA73FE63-7334-4647-8963-A4295CFCF13F}
2012-06-30 03:53:33 ——– d—–w- C:\Users\Sharon\AppData\Local\{C96822F8-8386-4598-8085-CD6590F0D1D6}
2012-06-30 03:53:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{3EBD2C33-42D7-48C5-9D4D-A10D25236C16}
2012-06-29 02:29:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{8E27097A-CDA5-4C4F-A70C-D3C15ECE9B21}
2012-06-29 02:29:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{71160F1C-82D8-4512-88F2-0798539FC4EA}
2012-06-29 00:57:13 ——– d—–w- C:\Users\Sharon\AppData\Local\{FCDD5032-A3CB-43E3-8C2C-C77ECCAA3918}
2012-06-29 00:57:00 ——– d—–w- C:\Users\Sharon\AppData\Local\{5D869540-304D-43AA-91E2-FC874FF5F4E4}
2012-06-28 23:46:37 ——– d—–w- C:\Users\Sharon\AppData\Local\{280EAB94-22BA-448C-A5EA-D38826ABBD79}
2012-06-28 23:46:24 ——– d—–w- C:\Users\Sharon\AppData\Local\{C772FFB2-DB02-4EC4-9FB2-EBC3F03867D9}
2012-06-28 23:25:08 ——– d—–w- C:\Users\Sharon\AppData\Local\{FD6AE4EA-3364-4533-807F-E11FBAC9BF71}
2012-06-28 23:24:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{D7A34F2B-9BD4-4C81-808D-BB11D3956D5C}
2012-06-28 22:37:15 ——– d—–w- C:\Users\Sharon\AppData\Local\{A0B056AF-9F0B-403E-9297-8851E38D02D9}
2012-06-28 22:37:01 ——– d—–w- C:\Users\Sharon\AppData\Local\{5B0CF90F-1B5C-4C3A-B464-BE924CBE3436}
2012-06-28 16:34:43 ——– d—–w- C:\Users\Sharon\AppData\Local\{1D93E761-CE87-45A9-BB97-831A3DDDE51E}
2012-06-28 16:34:29 ——– d—–w- C:\Users\Sharon\AppData\Local\{8BD35391-6A7A-4128-B64F-F0F214769B16}
2012-06-28 00:26:01 ——– d—–w- C:\Users\Sharon\AppData\Local\{17225318-DD2C-4A38-84B5-5EE8CAB66402}
2012-06-28 00:16:58 ——– d—–w- C:\Users\Sharon\AppData\Local\{9E35A8D8-2BA3-419D-BA99-F4860EB628BC}
2012-06-27 20:14:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{FEE9F2A8-672D-4CCF-AC8A-D238CB8A8A2B}
2012-06-27 20:13:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{18D465C2-6673-4970-967A-CC121FBDA9E4}
2012-06-27 13:00:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{4BDEA4C0-158D-4364-A3C1-366274AC02AC}
2012-06-27 13:00:40 ——– d—–w- C:\Users\Sharon\AppData\Local\{35E0E83E-6F49-4B90-A438-B2F40323338B}
2012-06-26 21:35:55 ——– d—–w- C:\Users\Sharon\AppData\Local\{85A7267C-1F41-4C2A-868F-4D021B960BC1}
2012-06-26 21:35:38 ——– d—–w- C:\Users\Sharon\AppData\Local\{41E069CC-934C-4501-8E35-C93824D021E3}
2012-06-26 01:50:15 ——– d—–w- C:\Users\Sharon\AppData\Local\{74AE281C-CF70-43E0-90BA-C3EC5A810C82}
2012-06-26 01:50:03 ——– d—–w- C:\Users\Sharon\AppData\Local\{EE1EA039-AA2D-4907-8FE7-5BBD99E1EAA4}
2012-06-25 18:58:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{4C06B52B-7808-4A59-9C9E-F860C2BF4E77}
2012-06-25 18:58:40 ——– d—–w- C:\Users\Sharon\AppData\Local\{DDF3228E-A75B-46E8-842E-7B4683D0FA47}
2012-06-25 04:46:14 28760 —-a-w- C:\Program Files (x86)\Mozilla Firefox\ScriptFF.dll
2012-06-25 03:39:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{84BA9879-3635-4625-A80A-A8703099B795}
2012-06-25 03:39:34 ——– d—–w- C:\Users\Sharon\AppData\Local\{E7E49314-BD24-44C6-8A1C-7D7FB82B278E}
2012-06-24 23:41:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{403409B7-6BAF-4C72-BF7A-BC3FE39F64DA}
2012-06-24 23:41:08 ——– d—–w- C:\Users\Sharon\AppData\Local\{CC26DD6B-7CE0-46D5-A657-0F2E964E100D}
2012-06-24 17:39:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{8B59543C-4F00-4571-87FB-5E7B8C55510F}
2012-06-24 17:39:20 ——– d—–w- C:\Users\Sharon\AppData\Local\{C60A2436-E285-425D-AE19-9362BDCDBC35}
2012-06-24 05:53:32 ——– d—–w- C:\Users\Sharon\AppData\Local\Macromedia
2012-06-24 04:32:43 ——– d—–w- C:\Users\Sharon\AppData\Local\{DBACAB4A-B6C9-4360-AA26-7CCBF5690DA4}
2012-06-24 04:32:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{AD6F9339-2DCD-4394-A621-6CF64A227B1A}
2012-06-23 22:45:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{7B1E485C-5E59-4D31-A9D5-1B87D4D00096}
2012-06-23 22:45:40 ——– d—–w- C:\Users\Sharon\AppData\Local\{D6A41E4C-B3C3-4A23-9BB7-748098FAFF32}
2012-06-23 20:49:05 ——– d—–w- C:\Users\Sharon\AppData\Local\{D7615484-A6AA-480A-A070-AF77BBC3C6DB}
2012-06-23 20:48:54 ——– d—–w- C:\Users\Sharon\AppData\Local\{E364412C-41DC-44D5-92F2-0046776C0058}
2012-06-23 20:16:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{11DBAA36-C0F9-4696-912E-5FD1FA106DEC}
2012-06-23 20:16:19 ——– d—–w- C:\Users\Sharon\AppData\Local\{E6C2BDC0-1DCB-4139-9C82-18E0A377A9D1}
2012-06-23 19:55:43 ——– d—–w- C:\Users\Sharon\AppData\Local\{9E1E02F9-2351-418A-A70F-B9CFA5C203B7}
2012-06-23 19:55:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{B9467569-85AD-429B-8CAF-749CF028D44D}
2012-06-22 19:29:32 ——– d—–w- C:\Users\Sharon\AppData\Local\{C443DB6F-0B52-4092-BFCD-A1490E5218D9}
2012-06-22 19:29:20 ——– d—–w- C:\Users\Sharon\AppData\Local\{08BF3389-F865-419F-A490-EE2AEDAB1842}
2012-06-22 18:04:48 ——– d—–w- C:\Users\Sharon\AppData\Local\{FE455531-D480-42E5-AE3A-18EEF9447C9E}
2012-06-22 18:04:35 ——– d—–w- C:\Users\Sharon\AppData\Local\{206042FC-AD26-415C-9101-39459464E3AF}
2012-06-22 15:16:31 ——– d—–w- C:\Users\Sharon\AppData\Local\{B3B761A6-AEF1-45EC-8027-999EF20FA7CF}
2012-06-22 15:16:20 ——– d—–w- C:\Users\Sharon\AppData\Local\{828AF7E4-53FD-4413-AFA3-24AD3CF2D86C}
2012-06-22 02:15:41 ——– d—–w- C:\Users\Sharon\AppData\Local\{A99453CD-8DD2-41BA-AB5E-6A029936BF25}
2012-06-22 02:15:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{6016AD79-2B72-4A50-8F59-FE5D36DA2B94}
2012-06-22 00:41:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{1E0A29A3-1175-4E70-8191-F83A8328893E}
2012-06-22 00:40:57 ——– d—–w- C:\Users\Sharon\AppData\Local\{6F3FC865-7C4F-45C6-9216-25E9E2CD4217}
2012-06-21 23:53:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{117DA3CB-DCB0-4C62-B7DA-8C875CC8E8FF}
2012-06-21 23:53:44 ——– d—–w- C:\Users\Sharon\AppData\Local\{616EFABB-886F-4D1E-906D-FDF86E0D4B03}
2012-06-21 22:38:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{AB880034-396A-4016-8F84-43C61E7F93E5}
2012-06-21 22:38:09 ——– d—–w- C:\Users\Sharon\AppData\Local\{5DBBDCD3-F156-4B81-BB39-CDBC67C564EB}
2012-06-21 15:17:29 ——– d—–w- C:\Users\Sharon\AppData\Local\{F91A55C1-FC27-46BD-8D4F-65BCA36CA565}
2012-06-21 15:17:17 ——– d—–w- C:\Users\Sharon\AppData\Local\{8A7DAA3F-FE0A-4107-812B-3FCCDA156C19}
2012-06-21 04:57:47 ——– d—–w- C:\Users\Sharon\AppData\Local\{4C22D5CB-1556-4795-979E-30B260C4827F}
2012-06-21 04:57:35 ——– d—–w- C:\Users\Sharon\AppData\Local\{6053ACE7-F945-4390-96D2-0ECDD8BD9849}
2012-06-21 03:22:27 ——– d—–w- C:\Users\Sharon\AppData\Local\{BE946F1F-AB50-48DA-8D32-B703159DB2C4}
2012-06-21 03:22:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{51F9F383-8B67-4C15-AFA7-3A63730DA91B}
2012-06-21 01:00:32 ——– d—–w- C:\Users\Sharon\AppData\Local\{DC4F5021-207A-4FF0-8986-FF424771B82A}
2012-06-21 01:00:17 ——– d—–w- C:\Users\Sharon\AppData\Local\{607A69ED-4FF3-4BEB-87AE-1E3DE8C978A4}
2012-06-20 22:34:24 ——– d—–w- C:\Users\Sharon\AppData\Local\{DD536831-CE4F-4FE9-8914-603D7CB275D4}
2012-06-20 22:34:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{8DEABA06-6918-4679-A42C-2B7B9962369A}
2012-06-20 20:47:06 ——– d—–w- C:\Users\Sharon\AppData\Local\{B2E1C023-3E45-4EC6-BFE6-C377BFC551B5}
2012-06-20 20:46:55 ——– d—–w- C:\Users\Sharon\AppData\Local\{301ACA47-C716-4035-9C26-21B53A86E04E}
2012-06-20 14:05:06 ——– d—–w- C:\Users\Sharon\AppData\Local\{CD45AAAF-3CD5-428D-A0FD-B5CC8FD9B0F0}
2012-06-20 14:04:54 ——– d—–w- C:\Users\Sharon\AppData\Local\{C4A91117-9B75-4F3C-B063-A0949411AD65}
2012-06-20 13:35:30 ——– d—–w- C:\Users\Sharon\AppData\Local\{1395217D-255E-416B-B6CE-B0A7E226DACC}
2012-06-20 13:35:10 ——– d—–w- C:\Users\Sharon\AppData\Local\{4DBC3039-9492-451D-BC70-A4CEE8F902C8}
2012-06-19 16:15:49 2622464 —-a-w- C:\windows\System32\wucltux.dll
2012-06-19 16:15:37 99840 —-a-w- C:\windows\System32\wudriver.dll
2012-06-19 16:15:20 36864 —-a-w- C:\windows\System32\wuapp.exe
2012-06-19 16:15:20 186752 —-a-w- C:\windows\System32\wuwebv.dll
2012-06-18 20:20:10 ——– d—–w- C:\Users\Sharon\AppData\Roaming\OpenOffice.org
2012-06-18 20:19:11 ——– d—–w- C:\Program Files (x86)\OpenOffice.org 3
2012-06-18 17:21:16 ——– d—–w- C:\Users\Sharon\AppData\Local\{CC2AC9A4-3F6E-4FC0-9F07-FE000E01A49B}
2012-06-17 19:37:27 ——– d—–w- C:\Users\Sharon\AntiVirus
2012-06-17 18:43:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{CB32ACC5-3C2D-4A51-9CC7-8C1BEBED971B}
2012-06-17 18:36:26 ——– d—–w- C:\Users\Sharon\AppData\Roaming\Malwarebytes
2012-06-17 18:36:14 ——– d—–w- C:\ProgramData\Malwarebytes
2012-06-17 18:36:12 24904 —-a-w- C:\windows\System32\drivers\mbam.sys
2012-06-17 18:36:12 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-17 18:16:38 ——– d—–w- C:\Program Files (x86)\GridinSoft Trojan Killer
2012-06-17 03:59:23 ——– d-sh–w- C:\windows\System32\%APPDATA%
2012-06-17 03:48:48 ——– d—–w- C:\ProgramData\B7E858A700047CF10023A3B1B4EB2367
2012-06-17 03:38:35 426184 —-a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2012-06-15 01:24:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{C83B6ADA-0539-4078-9E3C-584DE3C13302}
2012-06-14 22:56:05 ——– d—–w- C:\Users\Sharon\AppData\Local\{EF4DA002-8968-45F8-93EE-C8F25FAB411A}
2012-06-14 22:55:40 ——– d—–w- C:\Users\Sharon\AppData\Local\{A790F4FD-6164-40F4-9ADC-EE218C20BE07}
2012-06-14 20:43:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{F395F5C8-C48F-4FDA-B18D-1223C8F2CBB5}
2012-06-14 20:43:47 ——– d—–w- C:\Users\Sharon\AppData\Local\{216392F0-02FD-4045-BE6A-0B72EA24CA44}
2012-06-14 18:41:26 ——– d—–w- C:\Users\Sharon\AppData\Local\{958EBD29-48C8-4580-9B9D-358AFDFEE468}
2012-06-14 18:41:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{2703D1E0-C918-49C5-AB5D-00FC79F87E2A}
2012-06-14 17:02:47 ——– d—–w- C:\Users\Sharon\AppData\Local\{29ED9A85-4A27-4189-AC81-A045ABEC3760}
2012-06-14 17:02:35 ——– d—–w- C:\Users\Sharon\AppData\Local\{AC95B816-15C5-4FCD-B653-869D1E94773C}
2012-06-14 16:18:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{14642D57-C4AF-4BCD-9378-9BB9754AD4B8}
2012-06-14 16:17:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{643C4377-C288-440E-8708-A637985AB62F}
2012-06-14 15:53:07 ——– d—–w- C:\Users\Sharon\AppData\Local\{EB1A2371-765D-4A9E-A5F1-6CC76F2E9B79}
2012-06-14 15:52:47 ——– d—–w- C:\Users\Sharon\AppData\Local\{0B46EF89-A371-43BD-ABCE-838D1FD6F86F}
2012-06-14 13:14:29 ——– d—–w- C:\Users\Sharon\AppData\Local\{23D0BCFD-BF7D-4360-AEF6-1E76F2D33554}
2012-06-14 13:14:13 ——– d—–w- C:\Users\Sharon\AppData\Local\{8942A9F9-CB88-46B9-8387-247C48A47575}
2012-06-14 03:30:20 ——– d—–w- C:\Users\Sharon\AppData\Local\{C1C2EDA2-D5F6-4CD0-B9FE-4E4153EFB4C2}
2012-06-14 03:29:49 ——– d—–w- C:\Users\Sharon\AppData\Local\{4377E31B-5A02-4B64-BC1D-4D062FDDAC66}
2012-06-14 02:41:37 ——– d—–w- C:\Users\Sharon\AppData\Local\{440DF3B2-3A6C-4CF3-9354-B77C1C1D0C73}
2012-06-14 02:41:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{B84CC66F-CCF8-4554-BC63-2AF4AC5906AB}
2012-06-13 22:27:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{5C01D92B-F437-4472-88A7-863228006A7D}
2012-06-13 22:27:42 ——– d—–w- C:\Users\Sharon\AppData\Local\{9E629835-7334-4428-8830-D7293A52FB14}
2012-06-13 19:54:55 ——– d—–w- C:\Users\Sharon\AppData\Local\{37E3AEB2-BD53-455D-85DE-74B034C994DF}
2012-06-13 19:54:27 ——– d—–w- C:\Users\Sharon\AppData\Local\{710C3CE2-698F-49E5-A4DB-C4B0C7C50C6B}
2012-06-13 01:10:58 ——– d—–w- C:\Users\Sharon\AppData\Local\{35EA0513-9AA8-48BF-85CC-7A6DFA12321F}
2012-06-13 01:10:44 ——– d—–w- C:\Users\Sharon\AppData\Local\{3E3330AC-FCB7-4D77-ABC3-D9EC0FA6540E}
2012-06-12 04:08:12 ——– d—–w- C:\Users\Sharon\AppData\Local\{2BA4ADC4-9003-4532-ADF1-4E39AD9A1F2C}
2012-06-12 04:07:50 ——– d—–w- C:\Users\Sharon\AppData\Local\{9C946E6E-5207-4357-B354-798BD82324B6}
2012-06-12 02:26:11 ——– d—–w- C:\Users\Sharon\AppData\Local\{C02E85C3-F1B5-4603-B57B-F2E5611E4576}
2012-06-12 02:25:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{A250E257-948C-4B66-98D3-A58215A4687D}
2012-06-12 01:53:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{35B80242-F46A-4C2B-8BD6-3BBB7B7BE3AE}
2012-06-12 01:53:01 ——– d—–w- C:\Users\Sharon\AppData\Local\{E9FE0D79-86E0-45E0-8CDF-3C7B1CF4E556}
2012-06-11 18:32:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{1AE8E8B1-B916-4B9B-890C-3EBCC74B60E6}
2012-06-11 18:32:37 ——– d—–w- C:\Users\Sharon\AppData\Local\{54C88B2F-E9A2-4FE9-B27E-0F023F136F84}
2012-06-11 14:50:23 ——– d—–w- C:\Users\Sharon\AppData\Local\{B65FD40B-DD08-40A4-AF90-19D8F4C60DD4}
2012-06-11 14:50:09 ——– d—–w- C:\Users\Sharon\AppData\Local\{E6DD8EBF-9934-4F0D-B892-57EB8410777A}
2012-06-11 11:46:38 ——– d—–w- C:\Users\Sharon\AppData\Local\{3E36CEEB-2B83-43F0-9D31-E14BA07C58BA}
2012-06-11 11:45:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{ACF5A9F6-E003-4EC4-A92C-D945C3025271}
2012-06-11 03:59:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{A2C2A5AF-8465-4472-B989-994D03EEB732}
2012-06-11 03:59:02 ——– d—–w- C:\Users\Sharon\AppData\Local\{C331C5DA-91E5-47E9-8C97-57CD8A83FAFE}
2012-06-11 02:03:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{FD189E14-53DC-4F54-9E1E-1321D9CC2132}
2012-06-11 02:03:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{B6E146DF-EFB6-49E7-9826-30E55C16536E}
2012-06-10 22:01:54 ——– d—–w- C:\Users\Sharon\AppData\Local\{30B65B93-0ACB-4682-9AD6-926BAD570F26}
2012-06-10 22:01:39 ——– d—–w- C:\Users\Sharon\AppData\Local\{D4B4F734-1854-41B8-A552-4557023F702D}
2012-06-10 20:31:06 ——– d—–w- C:\Users\Sharon\AppData\Local\{B3CA0888-89E9-492A-B3BE-94EE3ECB5F06}
2012-06-10 20:30:30 ——– d—–w- C:\Users\Sharon\AppData\Local\{7E5B040C-FE07-4F70-9437-47E247F9B09E}
2012-06-10 13:28:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{85C2A51D-6086-4E4E-9877-C8FFE5849642}
2012-06-10 13:27:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{6F9C3DCD-AC14-413F-BB75-0BCC973EE5CC}
2012-06-10 04:38:06 ——– d—–w- C:\Users\Sharon\AppData\Local\{D41097C7-7D3D-4FD8-BCF1-12B7DEC10F05}
2012-06-10 04:37:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{0C3810AD-7953-4E2C-A075-FECCBE4B7CEA}
2012-06-10 01:16:00 ——– d—–w- C:\Users\Sharon\AppData\Local\{9F7C2A27-04E9-4AB1-BA87-1295D40875A7}
2012-06-10 01:15:33 ——– d—–w- C:\Users\Sharon\AppData\Local\{05B32715-24D5-4482-B7A2-57FFFC7AAE6F}
2012-06-09 05:14:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{9A409EA1-0BC6-4E64-BFE6-F8DB9F8E8428}
2012-06-09 02:19:11 ——– d—–w- C:\Users\Sharon\AppData\Local\{4A3F2546-ACDF-4C5F-B42E-606E539AFA1D}
2012-06-09 02:18:58 ——– d—–w- C:\Users\Sharon\AppData\Local\{44F0753E-744C-42F6-83FC-D96B4B9EED7E}
2012-06-09 00:00:19 ——– d—–w- C:\Users\Sharon\AppData\Local\{56A00A78-11A0-4984-BD8E-FB1ABEBF2952}
2012-06-08 23:59:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{6E41C1C5-093E-4A69-A190-61BCFF6B4A5D}
2012-06-08 15:14:08 ——– d—–w- C:\Users\Sharon\AppData\Local\{405B78FB-F3F0-4F00-BA7E-D0AB1F5D70A2}
2012-06-08 15:13:54 ——– d—–w- C:\Users\Sharon\AppData\Local\{4F50FF10-4715-4DAC-962D-68E26B903760}
2012-06-07 18:35:48 ——– d—–w- C:\Users\Sharon\AppData\Local\{F62C6F14-C506-4602-BADA-A73C21CBEA0A}
2012-06-07 18:35:37 ——– d—–w- C:\Users\Sharon\AppData\Local\{38DEBAED-B4D0-4AD4-83EA-98A3C16B777E}
2012-06-07 16:13:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{9216584E-A645-4AE5-A759-7F4F5410D874}
2012-06-07 16:13:07 ——– d—–w- C:\Users\Sharon\AppData\Local\{D39509F2-83A2-4267-B229-7BF7C8B5EE9E}
2012-06-07 15:05:08 ——– d—–w- C:\Users\Sharon\AppData\Local\{1CB243EE-9E15-4D4F-B89A-24077A960F9D}
2012-06-07 15:04:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{7D3C8462-0CF9-4741-A87E-656496CD269B}
2012-06-07 03:16:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{D92C5BCE-3145-4F6A-B5FB-C116A6C9B2E3}
2012-06-07 03:16:07 ——– d—–w- C:\Users\Sharon\AppData\Local\{35F22146-16CA-4606-9541-8E8B69FDB5F7}
2012-06-07 02:06:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{83E375AB-4BB6-41AF-B9AC-FB26C9C92F30}
2012-06-07 02:06:41 ——– d—–w- C:\Users\Sharon\AppData\Local\{52D5B2CB-438A-40A3-B4B1-613EB84F932C}
2012-06-07 01:30:25 ——– d—–w- C:\Users\Sharon\AppData\Local\{A09C51FA-47FC-4862-A76C-BE78CEADAC36}
2012-06-07 01:30:11 ——– d—–w- C:\Users\Sharon\AppData\Local\{12D65B97-5C1D-408C-B144-D1C17467474C}
2012-06-06 21:53:04 ——– d—–w- C:\Users\Sharon\AppData\Roaming\Macrovision
2012-06-06 21:52:13 ——– d—–w- C:\Users\Sharon\AppData\Roaming\Roxio Burn
2012-06-06 21:23:48 ——– d—–w- C:\Users\Sharon\AppData\Local\{CC9764A2-9D4A-4035-A60C-FD1E14C41A56}
2012-06-06 21:23:28 ——– d—–w- C:\Users\Sharon\AppData\Local\{B2EBA2A0-4CA9-4B5F-A58C-1030888A2299}
2012-06-06 20:20:29 ——– d—–w- C:\Users\Sharon\AppData\Local\{1D61C60C-2AAD-4443-AF53-91852537B1C4}
2012-06-06 20:20:05 ——– d—–w- C:\Users\Sharon\AppData\Local\{BC036FFE-6012-4EB2-BDDC-152586CE62A4}
2012-06-06 16:46:27 ——– d—–w- C:\Users\Sharon\AppData\Local\{02FD9B1E-FDC4-46AC-9867-DB3F823DBE18}
2012-06-06 16:46:14 ——– d—–w- C:\Users\Sharon\AppData\Local\{24D49C00-145F-4250-ACF7-4C4BD2CEFC42}
2012-06-06 14:16:11 ——– d—–w- C:\Users\Sharon\AppData\Local\{2302DB1A-0178-4E55-BDE9-9BE60DC3C859}
2012-06-06 14:15:56 ——– d—–w- C:\Users\Sharon\AppData\Local\{FADBE00C-62AE-4B13-A312-765942761D07}
2012-06-06 13:11:19 ——– d—–w- C:\Users\Sharon\AppData\Local\{124C5D11-F53D-4DF6-A04C-CAB152742576}
2012-06-06 13:11:07 ——– d—–w- C:\Users\Sharon\AppData\Local\{4A6A056F-9BF0-4C79-B8C9-BE629942A9C8}
2012-06-06 03:13:01 ——– d—–w- C:\Users\Sharon\AppData\Local\{74354BB8-D864-40BA-8C9D-1F6D46D2176B}
2012-06-06 03:12:45 ——– d—–w- C:\Users\Sharon\AppData\Local\{0A5075BD-C67E-489C-8879-1064744D95EF}
2012-06-06 00:11:04 ——– d—–w- C:\Users\Sharon\AppData\Local\{95FE3E88-C696-4A1D-926A-3F88990201BB}
2012-06-06 00:10:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{54199534-94C7-4C14-A370-5CBF4C98380D}
2012-06-05 20:12:36 ——– d—–w- C:\Users\Sharon\AppData\Local\{24F9949C-4E01-467F-A3F3-ED71EEB0F14D}
2012-06-05 20:12:24 ——– d—–w- C:\Users\Sharon\AppData\Local\{D29FF131-4EAA-4199-8E11-338E73537F2F}
2012-06-05 19:26:46 ——– d—–w- C:\Users\Sharon\AppData\Local\{B6FA592E-D90F-4384-9E91-07E68EE24D09}
2012-06-05 19:26:22 ——– d—–w- C:\Users\Sharon\AppData\Local\{36119E21-05A8-49D7-8598-3B6D573947BF}
2012-06-05 16:36:21 ——– d—–w- C:\Users\Sharon\AppData\Local\{FDAEFB58-C45F-4460-AF16-1440AE58EA60}
2012-06-05 16:35:59 ——– d—–w- C:\Users\Sharon\AppData\Local\{CAEFF514-2A9A-4EF9-8550-C9E1B5372FC5}
2012-06-05 16:12:16 ——– d—–w- C:\Users\Sharon\AppData\Local\{10E34BE7-CFBC-4C1D-BCAB-F082A00D87C1}
2012-06-05 16:11:52 ——– d—–w- C:\Users\Sharon\AppData\Local\{9F8DFC1F-0221-404B-BB77-A9A8FC145147}
.
==================== Find3M ====================
.
2012-06-17 03:50:09 70344 —-a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-19 09:50:26 28480 —-a-w- C:\windows\System32\drivers\avgidsha.sys
.
============= FINISH: 11:21:43.79 ===============
ATTACH
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 4/15/2012 2:46:37 PM
System Uptime: 7/5/2012 11:03:14 AM (0 hours ago)
.
Motherboard: Dell Inc. | | 034W60
Processor: Intel® Core™ i5-2450M CPU @ 2.50GHz | CPU 1 | 2501/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 684 GiB total, 634.52 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP13: 6/7/2012 2:25:46 PM - Scheduled Checkpoint
RP14: 6/16/2012 10:34:56 PM - Installed Safari
RP15: 6/18/2012 3:17:24 PM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
RP16: 6/18/2012 3:18:56 PM - Installed OpenOffice.org 3.4
RP17: 6/19/2012 11:15:03 AM - Windows Update
RP18: 6/26/2012 12:52:43 PM - Configured Microsoft Office Home and Student 2010
RP19: 6/26/2012 12:54:16 PM - Configured Microsoft Office Home and Student 2010
RP20: 7/2/2012 7:21:00 PM - Installed AVG 2012
RP21: 7/2/2012 7:21:32 PM - Installed AVG 2012
RP22: 7/3/2012 5:35:39 PM - Restore Operation
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X MUI
Advanced Audio FX Engine
Apple Application Support
Apple Software Update
Bejeweled 2 Deluxe
Best Buy Connect
Bing Bar
Blackhawk Striker 2
Blio
Bounce Symphony
Build-a-lot 2
Cake Mania
Chuzzle Deluxe
Cozi
D3DX10
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Digital Delivery
Dell Getting Started Guide
Dell MusicStage
Dell PhotoStage
Dell Product Registration
Dell Stage
Dell VideoStage
Dell Webcam Central
Diner Dash 2 Restaurant Rescue
DirectX 9 Runtime
Dora's World Adventure
eBay
Escape Whisper Valley ™
Facebook Video Calling 1.2.0.159
Farm Frenzy
FATE
Final Drive Fury
Final Drive Nitro
Google Chrome
High-Definition Video Playback
IDT Audio
Intel PROSet Wireless
Intel® Control Center
Intel® Management Engine Components
Intel® Processor Graphics
Intel® Rapid Storage Technology
Intel® WiDi
Java Auto Updater
Java™ 7 Update 1
Jewel Quest
Jewel Quest Solitaire 2
Junk Mail filter update
Luxor
Malwarebytes Anti-Malware version 1.61.0.1400
McAfee SecurityCenter
Mesh Runtime
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 13.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Namco All-Stars PAC-MAN
Nero 10 Movie ThemePack Basic
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero Update
OpenOffice.org 3.4
Penguins!
PhotoShowExpress
Plants vs. Zombies - Game of the Year
PlayReady PC Runtime x86
Poker Superstars III
Polar Bowler
Polar Golfer
QuickTime
Realtek Ethernet Controller Driver
Realtek USB 2.0 Card Reader
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
Safari
Samantha Swift
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Security Update for Microsoft Visio Viewer 2010 (KB2597170) 32-Bit Edition
Skype™ 5.5
Sonic CinePlayer Decoder Pack
SyncUP
TI USB 3.0 Host Controller Driver
TI USB3 Host Driver
Trojan Killer
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update Installer for WildTangent Games App
Virtual Villagers 4 - The Tree of Life
Visual Studio 2008 x64 Redistributables
Wedding Dash - Ready, Aim, Love!
WildTangent Games
WildTangent Games App (Dell Games)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Zinio Reader 4
Zuma Deluxe
.
==== Event Viewer Messages From Past Week ========
.
7/5/2012 11:06:30 AM, Error: Service Control Manager [7003] - The McAfee Personal Firewall Service service depends the following service: MpsSvc. This service might not be installed.
7/5/2012 11:06:15 AM, Error: Service Control Manager [7034] - The Intel® Rapid Storage Technology service terminated unexpectedly. It has done this 1 time(s).
7/5/2012 11:06:11 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Dell Digital Delivery Service service to connect.
7/5/2012 11:06:11 AM, Error: Service Control Manager [7000] - The Dell Digital Delivery Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/5/2012 11:04:49 AM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891
7/5/2012 11:04:49 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891
7/5/2012 11:03:54 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
7/5/2012 11:03:52 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
7/5/2012 11:03:50 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
7/4/2012 7:18:47 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Security with the following error: Access is denied.
7/3/2012 4:46:48 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
7/3/2012 4:43:03 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
7/3/2012 4:43:02 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
7/3/2012 4:43:01 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\windows\System32\IWMSSvc.dll Error Code: 21
7/3/2012 4:43:01 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
7/3/2012 4:42:56 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
7/3/2012 4:42:48 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
7/3/2012 4:42:46 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 discache spldr Wanarpv6
7/3/2012 4:42:42 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
.
==== End Of File ===========================
And then the aswMBR log is having a problem going through. I downloaded it like you asked and it started going and it paused/froze and so i exited it and started again and it stopped at the exact same spot. So im not exactly sure why it did that so i saved the log as far as it went and its attacted with this. I hope this isnt a bad setback. And thank you for your response and for helping me.
I tried it again and this time i got this but once again it froze at something like appdata/bing/bar or something like that :/ Im not really sure what to do at this point,.. File is attached below.
Many apologies but my computer isn't working at present. I'll check the log and get back to you as soon as I'm able. Satchfan
My hard drive has really died so I have asked other members of the malware team to take over.
I apologise again for the delay and hope someone will reply to you soon.
Satchfan
Hi,
Please run the following:
download Farbar Recovery Scan Tool and save it to a flash drive.
(you need the 64bit version)
Plug the flashdrive into the infected PC.
Enter
System Recovery Options .
To enter System Recovery Options from the Advanced Boot Options:
Restart the computer. As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears. Use the arrow keys to select the Repair your computer menu item. Choose your language settings, and then click Next . Select the operating system you want to repair, and then click Next . Select your user account and click Next .
To enter System Recovery Options by using Windows installation disc:
Insert the installation disc. Restart your computer. If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings. Click Repair your computer . Choose your language settings, and then click Next . Select the operating system you want to repair, and then click Next . Select your user account an click Next .
On the System Recovery Options menu you will get the following options: Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[*]Select
Command Prompt [*]In the command window type in
notepad and press
Enter .
[*]The notepad opens. Under File menu select
Open .
[*]Select "Computer" and find your flash drive letter and close the notepad.
[*]In the command window type
e :\frst.exe (for x64 bit version type
e :\frst64) and press
Enter Note: Replace letter
e with the drive letter of your flash drive.
[*]The tool will start to run.
[*]When the tool opens click
Yes to the disclaimer.
[*]Place a check next to List Drivers MD5 as well as the default check marks that are already there
[*]Press
Scan button.
[*]type exit and reboot the computer normally
[*]FRST will make a log (FRST.txt) on the flash drive, please copy and paste the log in your reply.
Sorry to say this but im not exactly sure if i can do all of this because i am not really handy with computers, could you rephrase this to make it easier for me to understand? Thank you
let me know what part you are having difficulty with and I'll be happy to explain as best I can, print off the instructions so you have them with you when you are following the instructions
before we go this route as it is a little advanced, let's try running this tool:
Refer to the
ComboFix User's Guide
Download ComboFix from the following location:
Link
* IMPORTANT !!! Place ComboFix.exe on your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
You can get help on disabling your protection programs here
Double click on ComboFix.exe & follow the prompts. Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal. When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
———————————————————————————————
Ensure your AntiVirus and AntiSpyware applications are re-enabled.
———————————————————————————————
NOTE: If you encounter a message
"illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
let me know if you have any questions before you follow those instructions
do you still need help with your machine?
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic