I'm a Windows 7 64-bit user. Google is redirecting to random sites, and Windows Security Center is permanently disabled. I fixed a similar problem on a different computer by using System Restore, but no previous restore points were available on this machine, which was probably caused by the infection. I'm usually a do-it-yourself guy, but I'm beyond stumped. Also, McAfee has been completely uninstalled (before running DDS), although DDS shows it being "enabled/updated." I will leave the computer completely alone until I receive directions. Thank you for your time.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by jskipper at 13:57:11 on 2011-11-10
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8126.6896 [GMT -6:00]
.
AV: McAfee® Total Protection™ Service *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee® Total Protection™ Service *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
StartupFolder: C:\Users\jskipper\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTORU~1\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTORU~1\TDMNOT~1.LNK - C:\Program Files (x86)\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 10.26.41.6 10.26.41.5
TCP: Interfaces\{153ED8B4-1128-4A61-8FBA-F1B839D7BEB6} : DhcpNameServer = 10.26.41.6 10.26.41.5
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\jskipper\AppData\Roaming\Mozilla\Firefox\Profiles\zmdbkt1k.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\jskipper\AppData\Roaming\Mozilla\Firefox\Profiles\zmdbkt1k.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-8-19 13336]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-8 366152]
R2 Sentinel64;Sentinel64;C:\Windows\system32\Drivers\Sentinel64.sys --> C:\Windows\system32\Drivers\Sentinel64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atipmdag.sys --> C:\Windows\system32\DRIVERS\atipmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\system32\DRIVERS\e1k62x64.sys --> C:\Windows\system32\DRIVERS\e1k62x64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
.scr=DWGTrueViewScriptFile
.
=============== Created Last 30 ================
.
2011-11-10 19:05:31 -------- d-sh--w- C:\$RECYCLE.BIN
2011-11-10 16:05:34 306 ----a-w- C:\Windows\myClean.bat
2011-11-10 15:57:58 -------- d-----w- C:\Users\jskipper\AppData\Local\Akamai
2011-11-10 14:18:56 18816 ------w- C:\Windows\SysWow64\SAVRKBootTasks.sys
2011-11-09 21:35:34 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-11-09 21:25:02 5848 ----a-w- C:\backup.reg
2011-11-09 20:35:56 -------- d-----w- C:\Program Files (x86)\CCleaner
2011-11-09 20:24:46 -------- d-----w- C:\Users\jskipper\AppData\Local\Apps
2011-11-09 20:06:58 -------- d-----w- C:\Program Files\Microsoft IntelliPoint
2011-11-09 19:45:43 -------- d-----w- C:\Program Files (x86)\ESET
2011-11-09 19:25:04 -------- d-----w- C:\Windows\System32\wbem\Logs
2011-11-09 17:08:11 8570192 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{7426A330-834C-4452-8E38-5E4B56EAA0D5}\mpengine.dll
2011-11-09 16:38:52 256000 ----a-w- C:\Windows\PEV.exe
2011-11-09 16:32:19 98816 ----a-w- C:\Windows\sed.exe
2011-11-09 16:32:19 518144 ----a-w- C:\Windows\SWREG.exe
2011-11-09 16:32:19 208896 ----a-w- C:\Windows\MBR.exe
2011-11-09 16:02:56 -------- d-----w- C:\Program Files (x86)\Temp File Cleaner
2011-11-09 16:01:05 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 16:01:05 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 16:01:03 1923952 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 16:01:00 3144704 ----a-w- C:\Windows\System32\win32k.sys
2011-11-09 15:01:41 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-11-09 14:52:54 -------- d-----w- C:\Program Files (x86)\Sophos
2011-11-09 14:48:09 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-11-09 14:48:05 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-11-08 23:10:37 -------- d-----w- C:\Users\jskipper\AppData\Roaming\Malwarebytes
2011-11-08 23:10:33 -------- d-----w- C:\ProgramData\Malwarebytes
2011-11-08 23:10:29 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-11-08 23:10:28 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-08 15:40:58 -------- d-----w- C:\Users\jskipper\AppData\Local\{6D1764E0-DB19-468B-99CD-36A2D5A17899}
2011-11-08 15:40:46 -------- d-----w- C:\Users\jskipper\AppData\Local\{950835BC-69D3-4425-9FF8-C3621B8934D7}
2011-11-07 22:17:33 62464 --sha-r- C:\Windows\SysWow64\wpdwcnl.dll
2011-11-07 15:36:20 -------- d-----w- C:\Users\jskipper\AppData\Local\{2995EF5D-9089-4170-8C22-2BF6C013A196}
2011-11-07 15:36:08 -------- d-----w- C:\Users\jskipper\AppData\Local\{376E66A4-4D6D-4499-A972-04EA12520DC2}
2011-11-04 18:42:03 -------- d-----w- C:\Users\jskipper\AppData\Local\{6B13D7B9-C166-4032-8B35-279701755CA9}
2011-11-04 18:41:51 -------- d-----w- C:\Users\jskipper\AppData\Local\{AEDCDBC4-A920-40EA-9BC0-611A52893383}
2011-11-04 13:37:15 -------- d-----w- C:\Users\jskipper\AppData\Local\{D1DD24D3-DC89-4D23-9104-35778BD3052A}
2011-11-03 13:21:09 -------- d-----w- C:\Users\jskipper\AppData\Local\{365D5C98-23A8-4C15-9124-E896D2F5900F}
2011-11-03 13:20:58 -------- d-----w- C:\Users\jskipper\AppData\Local\{649560FF-25DC-481C-82E4-CB08F1F36A49}
2011-11-02 14:46:35 -------- d-----w- C:\Users\jskipper\AppData\Local\{3963373D-DDC7-4008-80BD-174F70C2FDB5}
2011-11-02 14:46:23 -------- d-----w- C:\Users\jskipper\AppData\Local\{507E055D-68C7-4B34-83D9-ECA7B417089C}
2011-11-02 02:46:11 -------- d-----w- C:\Users\jskipper\AppData\Local\{2F6685E5-499B-4B3C-A233-36456387EABD}
2011-11-02 02:46:01 -------- d-----w- C:\Users\jskipper\AppData\Local\{CAC6036A-C036-4806-8AC0-5772A8F6AD77}
2011-11-01 14:45:50 -------- d-----w- C:\Users\jskipper\AppData\Local\{48527742-0181-4D49-9766-9B21DA094951}
2011-11-01 14:45:39 -------- d-----w- C:\Users\jskipper\AppData\Local\{692C5CFE-99CD-48C7-BD08-8076AE56B2BA}
2011-11-01 02:45:27 -------- d-----w- C:\Users\jskipper\AppData\Local\{BE93B446-D15A-4281-9999-DC8B4AB38743}
2011-11-01 02:45:13 -------- d-----w- C:\Users\jskipper\AppData\Local\{CF3CF705-41A4-4C09-BD5B-EC2F41D0D054}
2011-10-31 14:44:59 -------- d-----w- C:\Users\jskipper\AppData\Local\{FCB8EE08-9A41-46B9-AB6C-9AB4D30E4D49}
2011-10-31 14:44:47 -------- d-----w- C:\Users\jskipper\AppData\Local\{F4494733-5E24-4630-9B7D-95AC2D9E6025}
2011-10-28 13:42:02 -------- d-----w- C:\Users\jskipper\AppData\Local\{141AFAA1-9C0E-4C66-8969-6DAAECDEAA5F}
2011-10-28 13:41:51 -------- d-----w- C:\Users\jskipper\AppData\Local\{984466FD-E8C6-434F-BA3E-DC54D4D2A956}
2011-10-25 13:58:14 -------- d-----w- C:\Users\jskipper\AppData\Local\{72176EE5-A927-4B7B-BA14-7BD9739D6D66}
2011-10-25 13:58:04 -------- d-----w- C:\Users\jskipper\AppData\Local\{93B4DBE1-71AD-46A3-9591-8787064D7425}
2011-10-24 20:44:35 -------- d-----w- C:\Program Files (x86)\quindar
2011-10-24 13:24:34 -------- d-----w- C:\Users\jskipper\AppData\Local\{D4EF2D39-7B9A-45D4-95A2-C405C2EBDF0C}
2011-10-24 13:24:23 -------- d-----w- C:\Users\jskipper\AppData\Local\{421811F1-5C06-44C9-BA57-03A64DEFD645}
2011-10-21 13:40:08 -------- d-----w- C:\Users\jskipper\AppData\Local\{B6FEE1C7-B045-4797-BCE0-C4AABF0CBFCF}
2011-10-21 13:39:52 -------- d-----w- C:\Users\jskipper\AppData\Local\{51C23D8A-E097-4CEE-82EC-D2592D719C04}
2011-10-20 13:27:07 -------- d-----w- C:\Users\jskipper\AppData\Local\{AF6B0B8D-4057-4F17-ADFC-F5AD50FC86AB}
2011-10-20 13:26:51 -------- d-----w- C:\Users\jskipper\AppData\Local\{36AAB35C-FCA4-4EB4-AE00-7883BBE94B18}
2011-10-19 13:42:08 -------- d-----w- C:\Users\jskipper\AppData\Local\{2FB58467-04E8-408B-8B3A-31E7F1686D06}
2011-10-19 13:41:53 -------- d-----w- C:\Users\jskipper\AppData\Local\{77F35523-AF84-4102-AA55-DDB9B9C53166}
2011-10-18 14:45:29 -------- d-----w- C:\Program Files (x86)\SEL
2011-10-18 14:45:01 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2011-10-18 13:46:55 -------- d-----w- C:\Users\jskipper\AppData\Local\{237345A0-C20A-45C8-850B-8EF642D52C0F}
2011-10-18 13:46:40 -------- d-----w- C:\Users\jskipper\AppData\Local\{B0C49D3F-6A85-4226-9DE1-D2B89ACB1DD5}
2011-10-18 01:46:24 -------- d-----w- C:\Users\jskipper\AppData\Local\{2953DC35-1AB1-486A-B0CD-547F3716F974}
2011-10-18 01:46:07 -------- d-----w- C:\Users\jskipper\AppData\Local\{4DCA6442-9F8C-4C5E-B2F9-CF2751A77E66}
2011-10-17 13:45:51 -------- d-----w- C:\Users\jskipper\AppData\Local\{631BFFE6-C839-4259-A8E0-ED60FAEE3042}
2011-10-17 13:45:34 -------- d-----w- C:\Users\jskipper\AppData\Local\{8C645DDB-6D88-4F70-B3FD-8EB242420B6F}
2011-10-17 01:45:18 -------- d-----w- C:\Users\jskipper\AppData\Local\{941CD9E3-F1ED-441A-A119-481B3FD4231E}
2011-10-17 01:45:01 -------- d-----w- C:\Users\jskipper\AppData\Local\{651F60F8-EC03-43CE-9B97-EC72A01F06A5}
2011-10-17 00:55:32 18139008 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
2011-10-16 13:44:49 -------- d-----w- C:\Users\jskipper\AppData\Local\{FEEB117B-30D3-4FBD-9B1C-C608EF898390}
2011-10-16 13:44:34 -------- d-----w- C:\Users\jskipper\AppData\Local\{8DAD65D6-42F7-4C32-A205-9954D4596EAB}
2011-10-16 01:44:18 -------- d-----w- C:\Users\jskipper\AppData\Local\{B3ECF71C-7352-4925-A17B-5DBF62ACD35A}
2011-10-16 01:44:01 -------- d-----w- C:\Users\jskipper\AppData\Local\{55A9A96F-06FF-4519-BD5E-6C17147A8898}
2011-10-15 13:43:45 -------- d-----w- C:\Users\jskipper\AppData\Local\{1C2221DE-6ED6-4953-B2D2-D5C1465B0F34}
2011-10-15 13:43:30 -------- d-----w- C:\Users\jskipper\AppData\Local\{48905502-CEA1-47B4-8391-62183B931A08}
2011-10-15 01:43:13 -------- d-----w- C:\Users\jskipper\AppData\Local\{12BE9A0D-A183-40F4-AA4C-3C98CBE7B878}
2011-10-15 01:42:56 -------- d-----w- C:\Users\jskipper\AppData\Local\{69450B11-DE37-4649-B8AE-5183FFC770E7}
2011-10-14 13:42:38 -------- d-----w- C:\Users\jskipper\AppData\Local\{7C44FECE-CC56-4243-B5F4-F61680D00DBD}
2011-10-14 13:42:23 -------- d-----w- C:\Users\jskipper\AppData\Local\{4A3DDBEE-F42B-42BA-82B7-7546021F5334}
2011-10-12 13:29:40 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-10-12 13:29:39 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-12 13:29:38 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-10-12 13:29:37 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-10-12 13:28:54 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-12 13:28:53 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-12 13:28:52 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-12 13:28:52 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-12 13:24:46 -------- d-----w- C:\Users\jskipper\AppData\Local\{2F8AB1EE-6552-4B1B-B859-876962AEB55B}
2011-10-12 13:24:28 -------- d-----w- C:\Users\jskipper\AppData\Local\{E49E9A7E-4901-4D51-B183-00CD6E9AED37}
.
==================== Find3M ====================
.
2011-09-01 05:24:07 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 13:57:23.67 ===============
Attached File(s)
-
Attach.txt (35.02K)
Number of downloads: 2
This post has been edited by jeremyws1: 10 November 2011 - 03:15 PM

Help
This topic is locked

Back to top

textbox. Do not include the word Code
.








