For the past few weeks I've noticed that iexplore.exe starts itself & runs in background without any intervention.
I often "sleep" my laptop rather than perform a full shut-down. When I open the laptop, log in again, and check the processes in Windows Task Manager I invariably find 2 (sometimes 3) instances of iexplore.exe running in the background. It is only possible to get rid of these by clicking 'End Process Tree' on what I assume is the "master process". If the "wrong" instance is ended, another is immediately spawned.
I do NOT have any other symptoms of malware or virus infection, but I am very suspicious these processes.
(I do not generally use IExplorer - preferring Firefox & Chrome).
I am running Windows 7 Home Premium, Service Pack 1, 64bit O/S.
I hope you can help me work out if I am infected with something or not.
Thanks
Adam
==================================
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
Run by Adam at 20:31:02 on 2012-05-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4056.2598 [GMT 1:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\vsnp2uvc.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\adirasx64.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\tsnp2uvc.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\vssvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://uk.yahoo.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120430132149.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [adiras] C:\Windows\adirasx64.exe
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [snp2uvc] C:\Windows\vsnp2uvc.exe
mRun: [tsnp2uvc] C:\Windows\tsnp2uvc.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
StartupFolder: C:\Users\Adam\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\METOFF~1.LNK - C:\Program Files (x86)\Met Office Desktop Widget\Met Office Desktop Widget.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://kitchenplanner.ikea.com/gb/Core/Player/2020PlayerAX_Win32.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D66C8D36-766B-46F0-865F-F0746ABE55A3} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{E6A1CB54-D46A-4854-AA78-1E6320F5217E} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{E6A1CB54-D46A-4854-AA78-1E6320F5217E}\2456C6B696E6534376 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{E6A1CB54-D46A-4854-AA78-1E6320F5217E}\265616E6379656 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{E6A1CB54-D46A-4854-AA78-1E6320F5217E}\34F6F6B696E6760234F6 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{E6A1CB54-D46A-4854-AA78-1E6320F5217E}\3716E68616D60213E213 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{E6A1CB54-D46A-4854-AA78-1E6320F5217E}\849676866796C6C656 : DhcpNameServer = 192.168.1.254
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64: Search Helper - No File
BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120430132149.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB-X64: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - No File
mRun-x64: [adiras] C:\Windows\adirasx64.exe
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun-x64: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
mRun-x64: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [snp2uvc] C:\Windows\vsnp2uvc.exe
mRun-x64: [tsnp2uvc] C:\Windows\tsnp2uvc.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\39nctjgr.default\
FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
FF - plugin: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Adam\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\39nctjgr.default\extensions\2020Player@2020Technologies.com\plugins\NP2020Player.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 RapportKE64;RapportKE64;C:\Windows\system32\Drivers\RapportKE64.sys --> C:\Windows\system32\Drivers\RapportKE64.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
R1 RapportCerberus_34302;RapportCerberus_34302;C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus64_34302.sys [2011-12-17 397520]
R1 RapportEI64;RapportEI64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2012-5-4 55056]
R1 RapportPG64;RapportPG64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2012-5-4 297008]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 {1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7};Power Control [2009/11/20 15:07:36];C:\Program Files (x86)\CyberLink\PowerDVD DX\000.fcl [2009-11-20 146928]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe [2009-11-20 89600]
R2 FreeAgentGoNext Service;Seagate Service;C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-5-1 181544]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]
R2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2010-8-25 199272]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2010-8-25 210584]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-8-25 162192]
R2 RapportMgmtService;Rapport Management Service;C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2012-5-4 976696]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2009-9-2 648432]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys --> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
R3 OA009Ufd;Creative Camera OA009 Upper Filter Driver;C:\Windows\system32\DRIVERS\OA009Ufd.sys --> C:\Windows\system32\DRIVERS\OA009Ufd.sys [?]
R3 OA009Vid;Creative Camera OA009 Function Driver;C:\Windows\system32\DRIVERS\OA009Vid.sys --> C:\Windows\system32\DRIVERS\OA009Vid.sys [?]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe --> C:\Program Files\Dell\DellDock\DockLogin.exe [?]
S2 ELOADER;General Purpose USB Driver (adildrx64.sys);C:\Windows\System32\drivers\adildrx64.sys [2009-11-4 58264]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-5 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-27 257696]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-5 136176]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-11 129976]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-05-20 20:38:24 -------- d-----w- C:\Users\Adam\AppData\Local\{E6A5E466-E1BA-45A5-8C07-D4274BF338AC}
2012-05-20 20:38:12 -------- d-----w- C:\Users\Adam\AppData\Local\{C26216E2-FAB3-4414-B314-3860B3E61FFD}
2012-05-20 17:25:57 -------- d-----w- C:\Users\Adam\AppData\Local\{860A0CFC-E3AC-499D-8905-538F509CD44A}
2012-05-20 08:14:20 -------- d-----w- C:\Users\Adam\AppData\Local\{FFC036E4-4950-48DD-82F3-9BE683C35D1E}
2012-05-20 08:14:09 -------- d-----w- C:\Users\Adam\AppData\Local\{E2D1F4CF-06A2-4507-B355-BB206777D017}
2012-05-19 12:39:47 -------- d-----w- C:\Users\Adam\AppData\Local\{A62198AE-1357-4376-9812-D2C8BAD5831C}
2012-05-19 12:39:36 -------- d-----w- C:\Users\Adam\AppData\Local\{AE3B9719-6606-4C73-9FE9-0A2024624FCB}
2012-05-18 21:47:16 -------- d-----w- C:\Users\Adam\AppData\Local\{2C4AFE22-D47F-4AFC-9418-B2A2700A8C93}
2012-05-18 21:47:04 -------- d-----w- C:\Users\Adam\AppData\Local\{F15342F3-F173-44B2-BCAA-9EDA3936D828}
2012-05-18 18:45:14 -------- d-----w- C:\Users\Adam\AppData\Local\{A90F8319-D327-44DA-889E-44D9956C77F3}
2012-05-18 18:45:02 -------- d-----w- C:\Users\Adam\AppData\Local\{8CB06F5D-D6EA-422A-A9D9-0611F3586E96}
2012-05-17 21:08:31 -------- d-----w- C:\Users\Adam\AppData\Local\{7DB7E61D-E1B1-4F21-AA8F-05C2A67FE9BF}
2012-05-17 21:08:19 -------- d-----w- C:\Users\Adam\AppData\Local\{EFFD32BF-634B-4C4A-90CD-E133AD1558A3}
2012-05-16 20:03:50 -------- d-----w- C:\Users\Adam\AppData\Local\{BDE85949-F8FC-49D7-B51E-C668F7098DB5}
2012-05-16 20:03:39 -------- d-----w- C:\Users\Adam\AppData\Local\{8B78A9E7-1E2E-462A-A21B-E88BF31A1D96}
2012-05-15 19:38:43 -------- d-----w- C:\Users\Adam\AppData\Local\{7F9292F6-6668-4B9B-B82E-375E4D10BBF9}
2012-05-15 19:38:31 -------- d-----w- C:\Users\Adam\AppData\Local\{4990E7A8-6135-40F8-950F-FB907BC2222F}
2012-05-14 22:48:44 -------- d-----w- C:\Users\Adam\AppData\Local\{69358EFD-A443-4B4D-B6C1-04721577B22B}
2012-05-14 22:48:32 -------- d-----w- C:\Users\Adam\AppData\Local\{D4C227B8-B478-443D-9B75-C7CECA943ED5}
2012-05-13 17:53:08 -------- d-----w- C:\Users\Adam\AppData\Local\{8A920490-4251-433B-803D-28BE482E17B4}
2012-05-13 17:52:56 -------- d-----w- C:\Users\Adam\AppData\Local\{5A5DB219-B3CE-4CC4-99FB-C9373A4D809C}
2012-05-13 16:14:51 -------- d-----w- C:\Users\Adam\AppData\Roaming\RealNetworks
2012-05-13 16:10:23 11776 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
2012-05-13 16:10:06 -------- d-----w- C:\Program Files (x86)\Common Files\xing shared
2012-05-13 16:09:51 150696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
2012-05-13 16:09:44 129144 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
2012-05-12 21:21:03 -------- d-----w- C:\Users\Adam\AppData\Local\{D0AA6929-B500-4F04-ABC8-772CACB88D97}
2012-05-12 21:20:51 -------- d-----w- C:\Users\Adam\AppData\Local\{B8D2891F-EBDA-482C-8755-0857C040AD24}
2012-05-12 19:23:40 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2012-05-12 19:23:39 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-05-12 19:23:35 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-12 19:23:33 3146240 ----a-w- C:\Windows\System32\win32k.sys
2012-05-12 19:23:32 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-12 19:23:32 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-12 19:22:58 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-05-12 19:22:42 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-05-12 19:22:37 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2012-05-12 19:22:37 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-12 19:22:36 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-05-12 19:22:36 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2012-05-12 19:22:35 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2012-05-11 22:46:55 -------- d-----w- C:\Users\Adam\AppData\Local\{E8CAB4F8-83DA-44BB-9BC8-0B092D91650A}
2012-05-11 22:46:43 -------- d-----w- C:\Users\Adam\AppData\Local\{134592F9-EF32-430C-8B9C-7FFDF20BE5DA}
2012-05-11 21:47:26 -------- d-----w- C:\Users\Adam\AppData\Local\{6A812E04-DE9A-4209-8EB4-A1EADDB40E58}
2012-05-11 21:47:14 -------- d-----w- C:\Users\Adam\AppData\Local\{956AAC3F-4164-420C-9115-E2110F5F9AA4}
2012-05-10 19:16:49 -------- d-----w- C:\Users\Adam\AppData\Local\{A4719051-E389-4DF0-BAF0-FA12FCAFFA2E}
2012-05-10 19:16:37 -------- d-----w- C:\Users\Adam\AppData\Local\{17AA7B58-9ECF-4AEA-8220-5F0D69831829}
2012-05-09 21:18:47 -------- d-----w- C:\Users\Adam\AppData\Local\{0532105C-4EB4-4075-AC02-2CA34F97A50B}
2012-05-09 21:18:35 -------- d-----w- C:\Users\Adam\AppData\Local\{589DEA25-39AC-4CA6-AD48-2BEE7C5C3B55}
2012-05-09 06:41:25 -------- d-----w- C:\Users\Adam\AppData\Local\{67A8D9D6-5E7E-47B7-B7BB-44FA337988A0}
2012-05-09 06:41:13 -------- d-----w- C:\Users\Adam\AppData\Local\{9F3C70C6-2718-4D57-8B54-2047B788E0F3}
2012-05-08 22:06:07 -------- d-----w- C:\Users\Adam\AppData\Local\{0AC277D3-4DE7-4DD6-83A5-5A72AA28D8BC}
2012-05-08 22:05:56 -------- d-----w- C:\Users\Adam\AppData\Local\{9B07EB3D-7999-46DC-85BF-24A0837E1198}
2012-05-08 18:11:18 -------- d-----w- C:\Users\Adam\AppData\Local\{385F98F5-705B-4F6F-8E3D-B60FE45C454E}
2012-05-08 18:11:05 -------- d-----w- C:\Users\Adam\AppData\Local\{610794AB-9119-40AE-9999-B89D8C1D073B}
2012-05-06 20:12:48 -------- d-----w- C:\Users\Adam\AppData\Local\{86B335DE-BF23-47C1-8882-2B2E6DF5D731}
2012-05-06 20:12:36 -------- d-----w- C:\Users\Adam\AppData\Local\{981F8762-8926-4E3C-91B7-A1521FCF7F60}
2012-05-06 19:33:57 -------- d-----w- C:\Users\Adam\AppData\Local\{12870CAF-B50B-48FC-9A82-DC0B7AA113DF}
2012-05-06 19:33:45 -------- d-----w- C:\Users\Adam\AppData\Local\{D5465BF1-57A4-4724-8BB4-32957B9C8E8C}
2012-05-06 12:53:35 -------- d-----w- C:\Users\Adam\AppData\Local\{EC5CD142-E414-432F-B553-22865337C4E4}
2012-05-06 12:53:24 -------- d-----w- C:\Users\Adam\AppData\Local\{313081A4-454F-4DB4-A522-4978180CC960}
2012-05-06 11:31:37 -------- d-----w- C:\Users\Adam\AppData\Local\{1FA61EF0-33A6-41E3-B242-9ACDFB4164B6}
2012-05-06 11:31:25 -------- d-----w- C:\Users\Adam\AppData\Local\{7CAE2F85-F437-4392-8451-36DA1496306D}
2012-05-05 23:50:25 -------- d-----w- C:\Users\Adam\AppData\Local\{E0521F8E-DFF4-403D-BA0B-A6D05945BD7F}
2012-05-05 23:50:14 -------- d-----w- C:\Users\Adam\AppData\Local\{D00600E7-C84B-4F17-A53A-5DC52ED9078A}
2012-05-05 12:54:32 -------- d-----w- C:\Users\Adam\AppData\Local\{216AC0A0-E829-4FA1-8741-933B145848AC}
2012-05-05 12:54:21 -------- d-----w- C:\Users\Adam\AppData\Local\{3B84A4F6-BF5B-4F57-A48F-87CC3497E28B}
2012-05-01 21:00:10 -------- d-----w- C:\Users\Adam\AppData\Local\{2838C640-65C0-496F-BFC5-D11A45503693}
2012-05-01 20:59:58 -------- d-----w- C:\Users\Adam\AppData\Local\{EAC3D6FC-9E97-4BDA-93F2-8F8D5650EFEB}
2012-05-01 12:35:18 -------- d-----w- C:\Users\Adam\AppData\Local\{3D703785-5D42-4D00-861A-B80CBEA764E0}
2012-05-01 12:35:06 -------- d-----w- C:\Users\Adam\AppData\Local\{139EAF1D-E670-40FD-A72C-4B2820BE9B43}
2012-04-30 20:01:25 -------- d-----w- C:\Users\Adam\AppData\Local\{0C4D93F8-D52F-4D29-B670-DAC3B65361C5}
2012-04-30 20:01:13 -------- d-----w- C:\Users\Adam\AppData\Local\{D67F857C-6402-4A9B-BC0F-C47F2404F070}
2012-04-30 12:21:46 29272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\ScriptFF.dll
2012-04-30 12:16:47 -------- d-----w- C:\Users\Adam\AppData\Local\{CA55CD29-EACB-49B7-A5AC-9E8E6345A9A3}
2012-04-30 12:16:35 -------- d-----w- C:\Users\Adam\AppData\Local\{F6C2C241-0453-43AF-9A30-84711D261074}
2012-04-28 12:41:26 -------- d-----w- C:\Users\Adam\AppData\Local\{83847269-0189-45D8-8EBE-00E33E2CA6A4}
2012-04-28 12:41:14 -------- d-----w- C:\Users\Adam\AppData\Local\{3AD4345E-ED36-4464-A098-191BC84EF0D0}
2012-04-28 12:35:44 -------- d-----w- C:\Users\Adam\AppData\Local\{68A4BAE8-1A25-4787-90D6-384F6D125D74}
2012-04-28 12:35:32 -------- d-----w- C:\Users\Adam\AppData\Local\{AA64FD0E-0F32-4783-B6ED-FFCC15C6BF40}
2012-04-27 20:48:19 -------- d-----w- C:\Users\Adam\AppData\Local\{94DE0371-FAA1-4EA6-8F0B-7E49AF34648D}
2012-04-27 20:48:07 -------- d-----w- C:\Users\Adam\AppData\Local\{7BC3D872-2F55-4154-8E94-170C0482A3D4}
2012-04-27 20:43:06 -------- d-----w- C:\Users\Adam\AppData\Local\{B1D8F777-C573-450E-9018-287BEFCC2E6C}
2012-04-27 20:42:53 -------- d-----w- C:\Users\Adam\AppData\Local\{755AE9CB-903E-4662-96CF-6A5CCB250797}
2012-04-27 16:04:20 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-04-26 23:48:13 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-04-26 23:05:16 -------- d-----w- C:\Users\Adam\AppData\Local\{6C720341-5370-4418-9B4C-BD9050A1A79E}
2012-04-26 23:05:03 -------- d-----w- C:\Users\Adam\AppData\Local\{AAEEA3B6-83AE-4F9E-9532-7AEB8C8454A0}
2012-04-26 16:58:31 -------- d-----w- C:\Users\Adam\AppData\Local\{0F4D69FE-FAA0-4D98-922F-F411918FB6A2}
2012-04-25 18:42:59 -------- d-----w- C:\Users\Adam\AppData\Local\{6F9AB053-6DE5-44AF-8D12-97EC957639D3}
2012-04-25 18:42:47 -------- d-----w- C:\Users\Adam\AppData\Local\{3F255200-FD16-49FA-8752-6D3BB57CE4D9}
2012-04-25 08:46:37 -------- d-----w- C:\Users\Adam\AppData\Local\{AF0BB2FC-8087-462D-979C-E0497B174B38}
2012-04-25 08:46:26 -------- d-----w- C:\Users\Adam\AppData\Local\{9B3945DF-15F7-42C9-9C3C-4B74D11E8832}
2012-04-24 13:59:32 -------- d-----w- C:\Users\Adam\AppData\Local\{7C9CB261-5992-494B-BD6A-39590C2CA480}
2012-04-24 13:59:21 -------- d-----w- C:\Users\Adam\AppData\Local\{6FB62739-5DB2-4501-8F19-B1925431DF7E}
2012-04-24 12:43:30 -------- d-----w- C:\Users\Adam\AppData\Local\{2CEE93E6-1565-4701-86DF-D680392B0A35}
2012-04-24 12:43:18 -------- d-----w- C:\Users\Adam\AppData\Local\{323FCF97-6B37-46BC-A83B-F3A2D97CADA6}
2012-04-23 20:21:22 -------- d-----w- C:\Users\Adam\AppData\Local\{AE3DEDC0-5F23-4C1B-9329-C93560E42C88}
2012-04-23 20:21:10 -------- d-----w- C:\Users\Adam\AppData\Local\{A439587D-9555-4B7F-B336-A1BA24E90204}
2012-04-21 21:55:52 -------- d-----w- C:\Users\Adam\AppData\Local\{BBB0843B-4D7E-401E-AD46-A0BA0AC9579C}
2012-04-21 21:55:41 -------- d-----w- C:\Users\Adam\AppData\Local\{FF6C76A9-94FD-4231-B4CF-1B01B02F126D}
.
==================== Find3M ====================
.
2012-05-13 16:09:30 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2012-05-13 16:09:30 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll
2012-05-05 13:04:29 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-04 07:41:12 101360 ----a-w- C:\Windows\System32\drivers\RapportKE64.sys
2012-04-28 08:13:10 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-03-22 19:12:12 4435968 ----a-w- C:\Windows\SysWow64\GPhotos.scr
2012-03-01 06:46:16 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-03-01 06:38:27 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-03-01 06:33:50 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-03-01 06:28:47 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-03-01 05:37:41 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-03-01 05:33:23 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-03-01 05:29:16 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-02-28 06:56:48 2311168 ----a-w- C:\Windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 ----a-w- C:\Windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-02-28 01:18:55 1799168 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-02-22 12:29:46 75936 ----a-w- C:\Windows\System32\drivers\mfenlfk.sys
2012-02-22 12:29:46 65264 ----a-w- C:\Windows\System32\drivers\cfwids.sys
2012-02-22 12:29:46 647208 ----a-w- C:\Windows\System32\drivers\mfehidk.sys
2012-02-22 12:29:46 487296 ----a-w- C:\Windows\System32\drivers\mfefirek.sys
2012-02-22 12:29:46 289664 ----a-w- C:\Windows\System32\drivers\mfewfpk.sys
2012-02-22 12:29:46 229528 ----a-w- C:\Windows\System32\drivers\mfeavfk.sys
2012-02-22 12:29:46 160792 ----a-w- C:\Windows\System32\drivers\mfeapfk.sys
2012-02-22 12:29:46 10248 ----a-w- C:\Windows\System32\drivers\mfeclnk.sys
2012-02-22 12:29:46 100912 ----a-w- C:\Windows\System32\drivers\mferkdet.sys
.
============= FINISH: 20:32:26.04 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top










