-RoboCat
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
Run by Tidd at 10:41:00 on 2012-03-22
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6132.4467 [GMT -7:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mStart Page = hxxp://www.yahoo.com
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
mWinlogon: Userinit=userinit.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Somoto Toolbar: {c3721e85-f0ac-4b7e-ae4c-3e738011dc9d} - C:\Program Files (x86)\somototoolbar\vmntemplateX.dll
BHO: ooVoo toolbar, powered by Ask.com: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
TB: Somoto Toolbar: {c3721e85-f0ac-4b7e-ae4c-3e738011dc9d} - C:\Program Files (x86)\somototoolbar\vmntemplateX.dll
TB: ooVoo toolbar, powered by Ask.com: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [ooVoo] C\ooVoo.exe /minimized
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
mRun: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [CTRegRun] C:\Windows\CTRegRun.EXE
mRun: [<NO NAME>]
mRun: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Tidd\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\DIGITA~1.LNK - C:\Program Files (x86)\Digital Line Detect\DLG.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
LSP: C:\Windows\system32\wpclsp.dll
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} -
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {9E89BECE-D23F-4782-8397-242E78C042D1} -
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 71.9.127.107 68.190.192.35 24.205.224.36
TCP: Interfaces\{435D33C9-523A-4A5F-B26D-1FA350A51756} : DhcpNameServer = 71.9.127.107 68.190.192.35 24.205.224.36
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO-X64: 0x1 - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Somoto Toolbar: {c3721e85-f0ac-4b7e-ae4c-3e738011dc9d} - C:\Program Files (x86)\somototoolbar\vmntemplateX.dll
BHO-X64: Somoto Toolbar - No File
BHO-X64: ooVoo toolbar, powered by Ask.com: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO-X64: Ask Toolbar BHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
TB-X64: Somoto Toolbar: {c3721e85-f0ac-4b7e-ae4c-3e738011dc9d} - C:\Program Files (x86)\somototoolbar\vmntemplateX.dll
TB-X64: ooVoo toolbar, powered by Ask.com: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun-x64: [CTRegRun] C:\Windows\CTRegRun.EXE
mRun-x64: [(Default)]
mRun-x64: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
mRun-x64: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Tidd\AppData\Roaming\Mozilla\Firefox\Profiles\tz61g7pw.default\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\GameTreat Player\npExentControl.dll
FF - plugin: C:\Program Files (x86)\GameTreat Player\npExentWidget.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-5-29 88576]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 X5XSEx_Pr146;X5XSEx_Pr146;C:\Program Files (x86)\GameTreat Player\X5XSEx.sys [2011-11-12 55328]
R3 CAXHWBS2;CAXHWBS2;C:\Windows\system32\DRIVERS\CAXHWBS2.sys --> C:\Windows\system32\DRIVERS\CAXHWBS2.sys [?]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\system32\Drivers\nx6000.sys --> C:\Windows\system32\Drivers\nx6000.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-20 136176]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;\??\C:\Windows\system32\drivers\BVRPMPR5a64.SYS --> C:\Windows\system32\drivers\BVRPMPR5a64.SYS [?]
S3 fssfltr;FssFltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-20 136176]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;\??\C:\Windows\system32\drivers\hitmanpro36.sys --> C:\Windows\system32\drivers\hitmanpro36.sys [?]
S3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-12-3 89920]
S4 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-3-21 652360]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-03-22 17:30:27 -------- d-----w- C:\Windows\en
2012-03-22 17:26:44 18328 ----a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-03-22 17:22:52 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\6963a41c1cd085002\MeshBetaRemover.exe
2012-03-22 17:21:11 -------- d-----w- C:\Users\Tidd\AppData\Local\{1AD63F1A-FA9C-40A8-99AA-8440BE0A4859}
2012-03-22 17:21:06 -------- d-----w- C:\Users\Tidd\AppData\Local\{2591D317-6078-43DB-9492-AE47625FB469}
2012-03-22 15:36:38 -------- d-----w- C:\Users\Tidd\AppData\Local\{F388E106-B71C-4F20-B28B-C0333C0A6449}
2012-03-22 15:36:35 -------- d-----w- C:\Users\Tidd\AppData\Local\{B814D818-0D34-4D3F-8788-D051F3053DF2}
2012-03-22 00:45:37 -------- d-----w- C:\Users\Tidd\AppData\Local\{EBDAB504-6866-4D5A-87A8-A1E86C9DFB57}
2012-03-22 00:45:23 -------- d-----w- C:\Users\Tidd\AppData\Local\{3D56ACAE-221C-4714-B256-C955537C624B}
2012-03-21 22:45:26 -------- d-----w- C:\Malwarebytes
2012-03-21 21:32:23 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-03-21 21:24:01 -------- d-----w- C:\Users\Tidd\AppData\Local\visi_coupon
2012-03-21 21:23:22 -------- d-----w- C:\Users\Tidd\AppData\Local\{C3722A40-8D98-482E-9821-28D1679F38C4}
2012-03-21 21:23:20 -------- d-----w- C:\Users\Tidd\AppData\Local\{8E8154A3-CD7B-4821-A968-6B2B08B3C43D}
2012-03-21 17:30:41 27424 ----a-w- C:\Windows\System32\drivers\hitmanpro36.sys
2012-03-21 16:57:44 -------- d-----w- C:\Users\Tidd\AppData\Local\{CBD29C03-3CD7-459F-8E87-7530F6E01F71}
2012-03-21 16:57:34 -------- d-----w- C:\Users\Tidd\AppData\Local\{FA46A71F-4B45-46F8-A3A6-E8F6AD56BD1E}
2012-03-21 15:47:09 476904 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2012-03-21 15:47:09 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-03-21 15:40:39 -------- d-----w- C:\Users\Tidd\AppData\Local\{1E38A23E-52B5-4731-9511-E976D99C11A6}
2012-03-21 15:40:38 -------- d-----w- C:\Users\Tidd\AppData\Local\{F4DEC780-7E0C-4857-98B0-2CF0B604D474}
2012-03-20 17:36:34 8643640 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D9EB8860-85ED-4AFC-8CD9-4FBC9C273E3C}\mpengine.dll
2012-03-20 17:29:15 -------- d-----w- C:\Mozilla
2012-03-19 02:32:30 -------- d-----w- C:\Users\Tidd\AppData\Local\{9B8FADD9-BEE8-41C3-A875-B9D4301D8F35}
2012-03-19 02:32:25 -------- d-----w- C:\Users\Tidd\AppData\Local\{A02C2350-D1EE-49D8-B62F-2BCE2C89D723}
2012-03-18 00:35:53 -------- d-----w- C:\Users\Tidd\AppData\Local\{8E2C97C9-0388-41A5-82CE-115B3A49235C}
2012-03-18 00:35:48 -------- d-----w- C:\Users\Tidd\AppData\Local\{F459D931-BC05-4ABB-9059-284E685F41FB}
2012-03-17 22:45:24 592824 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
2012-03-17 22:45:24 44472 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
2012-03-16 15:59:14 -------- d-----w- C:\Users\Tidd\AppData\Local\{FE3B8F0D-26F6-4C9E-B483-4272FECAA2B0}
2012-03-16 15:59:13 -------- d-----w- C:\Users\Tidd\AppData\Local\{AB712F74-0513-4159-8848-1E92FE70327E}
2012-03-15 16:38:56 -------- d-----w- C:\Users\Tidd\AppData\Local\{F2A6226D-0A06-4EE2-BD26-901BE1104744}
2012-03-15 16:38:47 -------- d-----w- C:\Users\Tidd\AppData\Local\{B316C185-F978-47C9-9525-211F956EEF60}
2012-03-14 20:02:56 -------- d-----w- C:\Users\Tidd\AppData\Local\{A8F9FDBD-E5BC-4165-86C5-FF6BD02595CF}
2012-03-14 20:02:54 -------- d-----w- C:\Users\Tidd\AppData\Local\{84761E58-AEB9-46DD-93FF-063CCD9159E7}
2012-03-14 15:28:14 -------- d-----w- C:\Users\Tidd\AppData\Local\{293C2EE9-FBA5-4D9C-B1B7-8F9516B46185}
2012-03-14 15:28:00 -------- d-----w- C:\Users\Tidd\AppData\Local\{13CFC7DA-E007-406C-A829-FA65B1C6A962}
2012-03-13 19:15:47 708096 ----a-w- C:\Windows\System32\rdpencom.dll
2012-03-13 19:15:47 613376 ----a-w- C:\Windows\SysWow64\rdpencom.dll
2012-03-13 19:15:47 209920 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-03-12 17:42:29 -------- d-----w- C:\Users\Tidd\AppData\Local\{F87BEE6E-3AC5-4774-9F03-118DD5842251}
2012-03-12 17:42:22 -------- d-----w- C:\Users\Tidd\AppData\Local\{702C3769-48FA-4DD6-AA13-CB09DB6815DC}
2012-03-12 05:07:21 -------- d-----w- C:\Users\Tidd\AppData\Local\{8CB62B0F-6763-45F5-96FC-4908C86F8669}
2012-03-12 05:07:13 -------- d-----w- C:\Users\Tidd\AppData\Local\{F065FB56-BA2F-40DE-905C-E4DC24A994E8}
2012-03-09 17:53:46 -------- d-----w- C:\Users\Tidd\AppData\Local\{B8C6F65F-D6E3-409A-804C-0B5D9E014BB4}
2012-03-09 17:53:37 -------- d-----w- C:\Users\Tidd\AppData\Local\{B975DB03-684F-4E20-AD94-22D64D3A52ED}
2012-03-08 22:24:34 -------- d-----w- C:\Users\Tidd\AppData\Local\{5DF2CD0F-88BF-4CDE-A603-D9ED73502423}
2012-03-08 22:24:09 -------- d-----w- C:\Users\Tidd\AppData\Local\{E7DB8500-C0E5-46C2-B7CE-3D3E9770480E}
2012-03-08 22:04:00 12872 ----a-w- C:\Windows\System32\bootdelete.exe
2012-03-08 21:54:40 -------- d-----w- C:\ProgramData\HitmanPro
2012-03-08 21:51:22 -------- d-----w- C:\Users\Tidd\AppData\Local\{A138A228-9377-4307-A68F-C684F90007ED}
2012-03-08 21:51:20 -------- d-----w- C:\Users\Tidd\AppData\Local\{75DD4BA3-8544-4970-AE08-D76F5003BD86}
2012-03-08 20:36:12 -------- d-----w- C:\Users\Tidd\AppData\Local\{A4A13614-0700-41FF-83C5-BE8A41CB6C25}
2012-03-08 20:36:02 -------- d-----w- C:\Users\Tidd\AppData\Local\{459CF018-D7D8-4001-B29E-DF01BE650AAE}
2012-03-08 17:35:08 -------- d-----w- C:\Users\Tidd\AppData\Roaming\Malwarebytes
2012-03-08 17:35:03 -------- d-----w- C:\ProgramData\Malwarebytes
2012-03-08 17:35:03 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-03-08 16:29:21 -------- d-----w- C:\Users\Tidd\AppData\Local\{DEA08810-7D39-4111-A93F-502ACBED4ADE}
2012-03-08 16:29:09 -------- d-----w- C:\Users\Tidd\AppData\Local\{0E8B0D13-638A-4F59-8CC2-4928DC78C25C}
2012-03-07 15:51:15 -------- d-----w- C:\Users\Tidd\AppData\Local\{65F2D18E-6070-4C45-8B0E-FF6E94B62B4F}
2012-03-07 15:51:06 -------- d-----w- C:\Users\Tidd\AppData\Local\{82461ED0-EFBB-4B24-B77D-83A0184AC7FE}
2012-03-03 15:46:38 -------- d-----w- C:\Users\Tidd\AppData\Local\{D9B7D8A6-68BF-4B6B-9770-2B1B373B3546}
2012-03-03 15:46:29 -------- d-----w- C:\Users\Tidd\AppData\Local\{EEF987D4-D330-45AD-A1B4-73ECBE87ABF1}
2012-03-03 01:46:11 -------- d-----w- C:\Users\Tidd\AppData\Local\{5418EFB1-14E6-4822-B132-92B217DF479B}
2012-03-03 01:46:04 -------- d-----w- C:\Users\Tidd\AppData\Local\{49E68CED-E9EB-4027-AF75-33D8803A00A5}
2012-02-29 17:34:04 -------- d-----w- C:\Users\Tidd\AppData\Local\{1A76D418-4FCB-4059-9E17-B55CF8E2B78D}
2012-02-29 17:34:02 -------- d-----w- C:\Users\Tidd\AppData\Local\{A3A9D52D-9446-494C-B07A-6A0549EBBE03}
2012-02-25 19:14:43 -------- d-----w- C:\Users\Tidd\AppData\Local\{A5C603FB-A487-44B1-A63B-A4D76CD67DD3}
2012-02-25 19:14:36 -------- d-----w- C:\Users\Tidd\AppData\Local\{2FC7BBED-257E-493F-9191-6213E27FE293}
2012-02-25 15:43:46 -------- d-----w- C:\Users\Tidd\AppData\Local\{A98C2680-BDCD-49C1-8DA6-39CC47B65365}
2012-02-25 15:43:29 -------- d-----w- C:\Users\Tidd\AppData\Local\{1EA26FC1-9EBC-4A49-BDFE-5DF257C0AC57}
2012-02-24 15:45:41 -------- d-----w- C:\Users\Tidd\AppData\Local\{36E152FD-AF48-4743-B862-17925D77B307}
2012-02-24 15:45:30 -------- d-----w- C:\Users\Tidd\AppData\Local\{C2F43CB2-A173-4801-BA17-85D129738941}
2012-02-23 02:40:31 -------- d-----w- C:\Users\Tidd\AppData\Local\{EB61D6B4-C8A2-4654-A20D-E3D5A53B9AA0}
2012-02-23 02:40:24 -------- d-----w- C:\Users\Tidd\AppData\Local\{DB185797-D240-4ED6-8088-C0BC67F1A3E5}
2012-02-22 15:47:37 -------- d-----w- C:\Users\Tidd\AppData\Local\{2F690312-D759-43F5-AE7F-761C14325DC2}
2012-02-22 15:47:20 -------- d-----w- C:\Users\Tidd\AppData\Local\{0F061FC7-E7D6-4040-A8CB-FABCB89073BC}
.
==================== Find3M ====================
.
2012-02-23 17:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-02-19 03:00:40 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-14 16:49:43 327680 ----a-w- C:\Windows\System32\d3d10_1core.dll
2012-02-14 16:49:43 196096 ----a-w- C:\Windows\System32\d3d10_1.dll
2012-02-14 15:45:30 219648 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll
2012-02-14 15:45:30 160768 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
2012-02-13 14:38:31 2002944 ----a-w- C:\Windows\System32\d3d10warp.dll
2012-02-13 14:12:08 1172480 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2012-02-13 14:06:48 834048 ----a-w- C:\Windows\System32\d2d1.dll
2012-02-13 14:03:11 1555968 ----a-w- C:\Windows\System32\DWrite.dll
2012-02-13 13:47:57 683008 ----a-w- C:\Windows\SysWow64\d2d1.dll
2012-02-13 13:44:40 1068544 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-02-02 15:34:25 2765824 ----a-w- C:\Windows\System32\win32k.sys
2012-01-03 14:25:21 404992 ----a-w- C:\Windows\System32\drivers\afd.sys
.
============= FINISH: 10:41:29.47 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top










