Acheronn
Topic Starter
FixMBR was the only option here. The FIX button was greyed out after the scan. I did nothing but save the log.
##############################################
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-03 10:49:30
—————————–
10:49:30.631 OS Version: Windows x64 6.1.7601 Service Pack 1
10:49:30.631 Number of processors: 4 586 0x2A07
10:49:30.631 ComputerName: STEPHEN-HP UserName: Stephen
10:49:31.146 Initialize success
10:53:58.857 AVAST engine defs: 12080201
10:54:58.870 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
10:54:58.870 Disk 0 Vendor: Intel___ 1.0. Size: 476937MB BusType: 8
10:54:58.886 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-1
10:54:58.886 Disk 1 Vendor: Intel___ 1.0. Size: 4096MB BusType: 8
10:54:58.886 Disk 0 MBR read successfully
10:54:58.902 Disk 0 MBR scan
10:54:58.902 Disk 0 Windows 7 default MBR code
10:54:58.902 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
10:54:58.902 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 456629 MB offset 409600
10:54:58.917 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 19999 MB offset 935585792
10:54:58.917 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 108 MB offset 976543744
10:54:58.917 Disk 0 scanning C:\Windows\system32\drivers
10:55:03.051 Service scanning
10:55:11.600 Modules scanning
10:55:11.616 Disk 0 trace - called modules:
10:55:11.631 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
10:55:11.631 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80050ea060]
10:55:11.631 3 CLASSPNP.SYS[fffff88001a5143f] -> nt!IofCallDriver -> [0xfffffa8004f8bb10]
10:55:11.631 5 hpdskflt.sys[fffff88001ddd189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0xfffffa8004bae050]
10:55:12.068 AVAST engine scan C:\Windows
10:55:13.066 AVAST engine scan C:\Windows\system32
10:56:37.979 AVAST engine scan C:\Windows\system32\drivers
10:56:42.519 AVAST engine scan C:\Users\Stephen
10:57:40.644 File: C:\Users\Stephen\Old Files\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8B7CO0E\Installer.playbryte-iwt[1] **INFECTED** Win32:Trojan-gen
10:57:41.346 File: C:\Users\Stephen\Old Files\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJGM8XBJ\VLC_Setup.exe **INFECTED** Win32:Rootkit-gen [Rtk]
10:59:54.836 File: C:\Users\Stephen\Old Files\AppData\LocalLow\Playbryte\Assemblies\1\BrowserObjects.dll **INFECTED** MSIL:BHO-A [Trj]
10:59:54.867 File: C:\Users\Stephen\Old Files\AppData\LocalLow\Playbryte\Assemblies\1\Inline.dll **INFECTED** MSIL:BHO-B [Trj]
11:04:01.238 AVAST engine scan C:\ProgramData
11:05:18.068 Scan finished successfully
11:08:25.610 Disk 0 MBR has been saved successfully to "C:\Users\Stephen\Documents\MBR.dat"
11:08:25.626 The log file has been saved successfully to "C:\Users\Stephen\Documents\aswMBR.txt"
################################################################################
####################################################################
DDS Log:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by [removed] at 12:03:26 on 2012-08-03
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3996.1952 [GMT 10:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Windows\SysWOW64\irstrtsv.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe
C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Boost Mobile Wireless Broadband\Boost Mobile Wireless Broadband.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Glance27\Glance.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
c:\program files (x86)\teamviewer\version7\TeamViewer_Desktop.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_2_202_197_ActiveX.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\svchost.exe -k AxInstSVGroup
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll"
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [Mobile Partner] "C:\Program Files (x86)\Boost Mobile Wireless Broadband\Boost Mobile Wireless Broadband.exe"
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Glance.lnk - C:\Program Files (x86)\Glance27\Glance.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
Trusted Zone: samsungsetup.com\www
TCP: Interfaces\{4E12AEE6-86B3-4ED6-A08A-3C5B76BBC570} : DhcpNameServer = 10.0.0.138
TCP: Interfaces\{9FBBB31C-479D-44B5-BCCB-2221878B96EC} : DhcpNameServer = [removed]
TCP: Interfaces\{A80FB3A3-A282-44A6-8C3C-56E9F32904E5} : NameServer = 211.29.132.12 61.88.88.88
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll"
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun-x64: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
.
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\system32\drivers\iusb3hcs.sys –> C:\Windows\system32\drivers\iusb3hcs.sys [?]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-10 86072]
R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-17 682040]
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe –> C:\Windows\system32\Hpservice.exe [?]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-6 35200]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-5-4 13592]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-3 628448]
R2 irstrtsv;Intel® Rapid Start Technology Service;C:\Windows\SysWOW64\irstrtsv.exe [2012-5-4 193536]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-5-4 161560]
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-6-21 2666880]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-5-4 363800]
R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.EXE [2012-2-14 240408]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\system32\drivers\bcbtums.sys –> C:\Windows\system32\drivers\bcbtums.sys [?]
R3 btwampfl;btwampfl Bluetooth filter driver;\??\C:\Windows\system32\drivers\btwampfl.sys –> C:\Windows\system32\drivers\btwampfl.sys [?]
R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\system32\DRIVERS\btwdpan.sys –> C:\Windows\system32\DRIVERS\btwdpan.sys [?]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys –> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys –> C:\Windows\system32\DRIVERS\clwvd.sys [?]
R3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\system32\DRIVERS\ewusbnet.sys –> C:\Windows\system32\DRIVERS\ewusbnet.sys [?]
R3 glancedrv;glancedrv;C:\Windows\system32\DRIVERS\glancedrv.sys –> C:\Windows\system32\DRIVERS\glancedrv.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 irstrtdv;Intel® Rapid Start Technology Driver;C:\Windows\system32\drivers\irstrtdv.sys –> C:\Windows\system32\drivers\irstrtdv.sys [?]
R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\system32\drivers\iusb3hub.sys –> C:\Windows\system32\drivers\iusb3hub.sys [?]
R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\system32\drivers\iusb3xhc.sys –> C:\Windows\system32\drivers\iusb3xhc.sys [?]
R3 MEIx64;Intel® Management Engine Interface ;C:\Windows\system32\drivers\HECIx64.sys –> C:\Windows\system32\drivers\HECIx64.sys [?]
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\system32\DRIVERS\RtsBaStor.sys –> C:\Windows\system32\DRIVERS\RtsBaStor.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 SmbDrv;SmbDrv;C:\Windows\system32\drivers\Smb_driver.sys –> C:\Windows\system32\drivers\Smb_driver.sys [?]
S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.EXE [2012-2-14 193816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-28 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-25 253600]
S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-2-22 276248]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-28 116648]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS –> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS –> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS –> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-08-03 02:02:49 ——– d—–w- C:\Program Files (x86)\ESET
2012-08-03 02:02:30 ——– d–h–w- C:\Windows\AxInstSV
2012-08-03 01:39:58 ——– d-sh–w- C:\$RECYCLE.BIN
2012-08-03 01:14:56 98816 —-a-w- C:\Windows\sed.exe
2012-08-03 01:14:56 518144 —-a-w- C:\Windows\SWREG.exe
2012-08-03 01:14:56 256000 —-a-w- C:\Windows\PEV.exe
2012-08-03 01:14:56 208896 —-a-w- C:\Windows\MBR.exe
2012-08-03 00:38:44 69000 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F757F831-C14C-4594-889C-03033D632EB1}\offreg.dll
2012-08-02 22:48:44 9133488 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F757F831-C14C-4594-889C-03033D632EB1}\mpengine.dll
2012-08-02 02:05:59 ——– d—–w- C:\Users\Stephen\AppData\Local\LogMeIn Rescue Applet
2012-08-01 03:44:38 9133488 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-18 23:25:43 336208 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-07-11 05:13:14 3148800 —-a-w- C:\Windows\System32\win32k.sys
2012-07-10 23:10:47 2048 —-a-w- C:\Windows\SysWow64\msxml3r.dll
2012-07-04 23:21:56 927800 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-07-04 23:21:56 927800 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{36FCE286-60DE-4CDC-8485-3F1DAC3A4D2E}\gapaengine.dll
.
==================== Find3M ====================
.
2012-06-06 06:06:16 2004480 —-a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 —-a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 —-a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 —-a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 —-a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 —-a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 —-a-w- C:\Windows\System32\wudriver.dll
2012-06-02 12:12:17 2311680 —-a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:50:10 458704 —-a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 —-a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 —-a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 —-a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 05:19:42 186752 —-a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 05:15:12 36864 —-a-w- C:\Windows\System32\wuapp.exe
2012-06-02 04:40:42 22016 —-a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 —-a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 —-a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll
.
============= FINISH: 12:03:42.42 ===============
Your Help Much Appreciated!