Jump to content
mschwartztech

trojan.dropper.bcminer and ZeroAccess Wont Stay Gone

Recommended Posts

I have run a full scan with MalwareBytes' Anti-Malware (in safe mode) - it finds Trojan.dropper.BCMiner (1 file). McAfee Total Protection finds "ZeroAccess" (3 files). Both claim to "clean" the infections but after reboot they are back. I have rebuilt the MBR with recovery console (per McAfee) but still no luck.

Attached ate DDS.txt and Attach.txt per your instructions. Help would be greatly appreciated!

Thanks!

Attach.txt

DDS.txt

Share this post


Link to post
Share on other sites

Hi and welcome to Malwarebytes.

In the future, please post all logs directly into your reply instead of attaching them unless otherwise indicated. With that said, please update MBAM, run a Quick Scan, and post its log.

Next, run DDS again and post DDS.txt directly in your reply.

Share this post


Link to post
Share on other sites

Sorry for the delay. Running quick scan now, but I did not get email notification that there was a reply to this topic. How can I make sure I do not miss future replies?

Will post MBAM and DDS result shortly...

Mike

Share this post


Link to post
Share on other sites

MBAM log below, followed by DDS.txt... Thanks! It is asking me to reboot - should I?

Malwarebytes Anti-Malware (PRO) 1.61.0.1400

www.malwarebytes.org

Database version: v2012.07.09.14

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Jim :: DESKTOP-FRIPP [administrator]

Protection: Enabled

7/9/2012 7:53:15 PM

mbam-log-2012-07-09 (19-53-15).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 354857

Time elapsed: 25 minute(s), 35 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 1

C:\Users\Jim\AppData\Roaming\wsfmi.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 1

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|wsfmi (Trojan.Agent) -> Data: rundll32.exe "C:\Users\Jim\AppData\Roaming\wsfmi.dll",fGetBrowserUrlEncoding -> Quarantined and deleted successfully.

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 1

C:\Users\Jim\AppData\Roaming\wsfmi.dll (Trojan.Agent) -> Delete on reboot.

(end)

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30

Run by Jim at 20:20:36 on 2012-07-09

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7935.5632 [GMT -4:00]

.

AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\Dell\DellDock\DockLogin.exe

C:\Windows\system32\atieclxx.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

C:\Windows\system32\mfevtps.exe

C:\Program Files\Microsoft LifeCam\MSCamS64.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

C:\Windows\system32\rundll32.exe

C:\Windows\system32\rundll32.exe

C:\Windows\SysWOW64\rundll32.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe

C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\WUDFHost.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe

C:\Windows\vVX3000.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe

C:\Program Files\Dell\Printer Software\ErrorApp\DKab1err.EXE

C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe

c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe

C:\Windows\system32\DKabcoms.exe

C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe

C:\Program Files\McAfee.com\Agent\mcagent.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Dell\DellDock\DellDock.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingApp.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingBar.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingSurrogate.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingSurrogate.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingSurrogate.exe

C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\SysWOW64\rundll32.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\SeaPort.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

c:\PROGRA~2\mcafee\SITEAD~1\saui.exe

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\AUDIODG.EXE

C:\Windows\notepad.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://google.com/

uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120623103522.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll"

TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File

TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File

uRun: [DKab1err] C:\Program Files\Dell\Printer Software\ErrorApp\DKab1err.exe

uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

uRun: [sdedro] rundll32.exe "C:\Users\Jim\AppData\Roaming\sdedro.dll",AllocADsMem

uRunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p

mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\vdeck.exe

mRun: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"

mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript

StartupFolder: C:\Users\Jim\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NKBMON~1.LNK - C:\Program Files (x86)\Nikon\PictureProject\NkbMonitor.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL

LSP: mswsock.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{5B730DED-8713-4362-9B4A-3ABA56709CA9} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{7FB70350-38E6-41B1-91A2-27C2A0EBF09E} : DhcpNameServer = 192.168.1.1

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll

Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll

Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll

BHO-X64: McAfee Phishing Filter - No File

BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120623103522.dll

BHO-X64: scriptproxy - No File

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll"

TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File

TB-X64: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File

mRun-x64: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\vdeck.exe

mRun-x64: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

mRun-x64: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"

mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

mRunOnce-x64: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\wl7yj5l6.default\

FF - prefs.js: browser.search.selectedEngine - Secure Search

FF - prefs.js: browser.startup.homepage - google.com

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=

FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll

FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\wl7yj5l6.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll

.

---- FIREFOX POLICIES ----

FF - user.js: yahoo.homepage.dontask - true

.

============= SERVICES / DRIVERS ===============

.

R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]

R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]

R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]

R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]

R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-9-30 375176]

R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2010-1-27 15928]

R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\Windows\system32\drivers\LMIRfsDriver.sys --> C:\Windows\system32\drivers\LMIRfsDriver.sys [?]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-6 654408]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

R2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2011-3-16 199272]

R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2011-3-16 210584]

R2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" --> C:\Windows\system32\mfevtps.exe [?]

R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2009-12-11 705856]

R3 athur;Wireless Network Adapter Service;C:\Windows\system32\DRIVERS\athurx.sys --> C:\Windows\system32\DRIVERS\athurx.sys [?]

R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\SeaPort.EXE [2012-2-20 240408]

R3 dkab_device;dkab_device;C:\Windows\system32\DKabcoms.exe -service --> C:\Windows\system32\DKabcoms.exe -service [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]

R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\system32\drivers\viahduaa.sys --> C:\Windows\system32\drivers\viahduaa.sys [?]

S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BBSvc.EXE [2012-2-20 193816]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-2 257224]

S3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]

S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]

S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]

S3 mfebopk;McAfee Inc. mfebopk;C:\Windows\system32\drivers\mfebopk.sys --> C:\Windows\system32\drivers\mfebopk.sys [?]

S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]

S3 mferkdk;McAfee Inc. mferkdk;C:\Windows\system32\drivers\mferkdk.sys --> C:\Windows\system32\drivers\mferkdk.sys [?]

S3 mfesmfk;McAfee Inc. mfesmfk;C:\Windows\system32\drivers\mfesmfk.sys --> C:\Windows\system32\drivers\mfesmfk.sys [?]

S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-6 113120]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

.

=============== Created Last 30 ================

.

2012-07-09 20:39:43 1930240 ----a-w- C:\Windows\System32\drivers\athurx.sys

2012-07-09 20:39:43 1930240 ----a-w- C:\Windows\System32\athurx.sys

2012-07-09 20:39:36 -------- d-----w- C:\ProgramData\TP-LINK

2012-07-09 20:35:30 -------- d-----w- C:\Users\Jim\AppData\Local\{8BB253BD-CA05-11E1-8270-B8AC6F996F26}

2012-07-09 20:35:06 410624 ----a-w- C:\Users\Jim\AppData\Roaming\sdedro.dll

2012-07-09 20:34:54 -------- d-----w- C:\Users\Jim\AppData\Local\{2408029A-2922-4874-A06A-3A3C0081482F}

2012-07-09 20:33:17 -------- d-----w- C:\Users\Jim\AppData\Local\{BDA7E011-F5D0-4C68-ADBC-13D16E7AECF7}

2012-07-07 17:32:32 -------- d-----w- C:\Users\Jim\AppData\Local\{302A67CC-1AC6-4BE4-B494-3E85C224C7DC}

2012-07-07 00:05:46 -------- d-----w- C:\Users\Jim\AppData\Local\{D247962C-C57A-4ED6-B14C-8CF08C1FD3F1}

2012-07-07 00:05:34 -------- d-----w- C:\Users\Jim\AppData\Local\{5049C643-4979-47F8-899F-5C2EFFD3AD3A}

2012-07-05 09:58:59 -------- d-----w- C:\Users\Jim\AppData\Local\{BF23E48E-D68A-4472-A4D1-4BFF518AE192}

2012-07-05 09:58:49 -------- d-----w- C:\Users\Jim\AppData\Local\{95CDB118-9FB7-4E59-A6F3-E2D35FAC7347}

2012-07-05 09:58:39 -------- d-----w- C:\Users\Jim\AppData\Local\{1DB78542-9A50-40B7-9822-6C9430C3A565}

2012-07-04 21:04:45 -------- d-----w- C:\Users\Jim\AppData\Local\{798782FF-61F5-4F1F-BB59-D50487923B76}

2012-07-04 21:04:35 -------- d-----w- C:\Users\Jim\AppData\Local\{45A195E6-5726-4D70-AD5A-2EF79BAF7A21}

2012-07-04 21:04:25 -------- d-----w- C:\Users\Jim\AppData\Local\{55C21E77-99FE-4928-89F5-0F18B807B057}

2012-07-04 21:04:15 -------- d-----w- C:\Users\Jim\AppData\Local\{A8BD7BFD-0504-4F6E-AF2C-36D4EC71C57A}

2012-07-04 09:03:38 -------- d-----w- C:\Users\Jim\AppData\Local\{F028D109-1CB8-45E0-8306-8E3FBDFC9CFC}

2012-07-04 09:03:28 -------- d-----w- C:\Users\Jim\AppData\Local\{5887D61C-2EB3-4528-8773-E5DD370C3C47}

2012-07-03 21:30:29 1409 ----a-w- C:\Windows\QTFont.for

2012-07-03 10:01:28 -------- d-----w- C:\Users\Jim\AppData\Local\{3031119A-CE84-4EDA-B977-775DB47BCA54}

2012-07-03 10:01:18 -------- d-----w- C:\Users\Jim\AppData\Local\{328C8F5E-4CDA-4724-AD1B-2A942D398845}

2012-07-03 10:01:08 -------- d-----w- C:\Users\Jim\AppData\Local\{863A316C-086B-4D11-9FF6-B9A28F4FB717}

2012-07-03 10:00:58 -------- d-----w- C:\Users\Jim\AppData\Local\{3C62CB00-C572-4A43-B128-B47D056188EA}

2012-07-02 22:00:32 -------- d-----w- C:\Users\Jim\AppData\Local\{CF1CD375-13E9-4419-A31A-76EF3CB4BBF3}

2012-07-02 22:00:20 -------- d-----w- C:\Users\Jim\AppData\Local\{3C40169D-F0FC-4D70-ACE1-057D77F735DD}

2012-07-02 22:00:09 -------- d-----w- C:\Users\Jim\AppData\Local\{37CFEF78-3E8B-4884-959C-451F1783A75A}

2012-07-02 21:59:57 -------- d-----w- C:\Users\Jim\AppData\Local\{4A18F7E2-3D18-45A2-BD90-4A3B6709BEC0}

2012-07-02 17:33:48 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%

2012-07-02 17:25:19 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-07-02 17:16:02 132608 ------w- C:\Users\Jim\AppData\Roaming\wsfmi.dll

2012-07-02 09:59:32 -------- d-----w- C:\Users\Jim\AppData\Local\{79B60FE8-3B5F-42A2-88FE-C37CF8AA7F79}

2012-07-02 09:59:22 -------- d-----w- C:\Users\Jim\AppData\Local\{CA3F7BD2-3077-4424-A359-122183C1C160}

2012-07-02 09:59:12 -------- d-----w- C:\Users\Jim\AppData\Local\{82B6767A-9F8A-4338-928A-440A91CCBB47}

2012-07-02 09:59:01 -------- d-----w- C:\Users\Jim\AppData\Local\{C7E415DD-E93E-4E7F-A488-E48243027C7E}

2012-07-01 21:58:49 -------- d-----w- C:\Users\Jim\AppData\Local\{667BC2C4-1DC1-4F4C-9526-E70FF4570E72}

2012-07-01 21:58:39 -------- d-----w- C:\Users\Jim\AppData\Local\{28A2117A-18E1-4BC9-8726-C39EB5C9A9EE}

2012-07-01 21:58:29 -------- d-----w- C:\Users\Jim\AppData\Local\{A911C7F7-AFF7-436C-A840-69FB15CCE4FE}

2012-07-01 21:58:19 -------- d-----w- C:\Users\Jim\AppData\Local\{B49E8241-F6A3-40C2-8EDB-DEE582DF7461}

2012-07-01 09:58:06 -------- d-----w- C:\Users\Jim\AppData\Local\{06E9ABF3-A0D7-4E76-9736-508EB3A62B3A}

2012-07-01 09:57:56 -------- d-----w- C:\Users\Jim\AppData\Local\{A8C8D714-5F4B-48AB-A9B3-50DDDB3A046F}

2012-07-01 09:57:47 -------- d-----w- C:\Users\Jim\AppData\Local\{174C4A15-6ED7-4272-A31A-56E2B267BC9A}

2012-07-01 09:57:36 -------- d-----w- C:\Users\Jim\AppData\Local\{82BF1563-9DFC-4FC7-9B52-1F86ED6F8569}

2012-06-30 21:43:44 -------- d-----w- C:\Users\Jim\AppData\Local\{847EECCE-A6CA-45BE-8135-A106B5C703BF}

2012-06-30 21:43:34 -------- d-----w- C:\Users\Jim\AppData\Local\{86E89153-DF49-4053-91D4-0C3D2ED7D90E}

2012-06-30 21:43:23 -------- d-----w- C:\Users\Jim\AppData\Local\{B69FC4A9-2991-4FC5-99D8-9EC9EECD4D76}

2012-06-30 09:43:11 -------- d-----w- C:\Users\Jim\AppData\Local\{19B7022B-D9AB-4C06-8748-86DB89E81AB9}

2012-06-30 09:43:01 -------- d-----w- C:\Users\Jim\AppData\Local\{556311DC-8990-49F5-86D0-6969BAE68CF4}

2012-06-30 09:42:51 -------- d-----w- C:\Users\Jim\AppData\Local\{B93620CC-605E-45F7-A162-7297F95935B9}

2012-06-30 09:42:41 -------- d-----w- C:\Users\Jim\AppData\Local\{9DA84734-9F22-4DDF-91F6-86B16ABB74C6}

2012-06-29 21:16:39 -------- d-----w- C:\Users\Jim\AppData\Local\{FAB7B59D-437A-47E6-BBE9-9EC1490555E4}

2012-06-29 21:16:29 -------- d-----w- C:\Users\Jim\AppData\Local\{83D39AA9-9201-47F5-8B89-A57555BEE5DB}

2012-06-29 21:16:19 -------- d-----w- C:\Users\Jim\AppData\Local\{B7208114-8CB3-4425-916C-2FE32788B026}

2012-06-29 21:16:09 -------- d-----w- C:\Users\Jim\AppData\Local\{ECB0062B-B1AC-42EC-BBF6-2F398E6A304C}

2012-06-29 09:15:56 -------- d-----w- C:\Users\Jim\AppData\Local\{2E8337C3-03E2-4C89-8049-FBF4B66F69AB}

2012-06-29 09:15:46 -------- d-----w- C:\Users\Jim\AppData\Local\{F5CA8462-F4AA-48D0-B3C9-85418D858DE3}

2012-06-29 09:15:36 -------- d-----w- C:\Users\Jim\AppData\Local\{FE6C0B13-F5AB-46C4-A6EA-B619EE367E51}

2012-06-29 09:15:26 -------- d-----w- C:\Users\Jim\AppData\Local\{53DA760F-DD99-48DE-84E6-E671281704F7}

2012-06-28 19:23:50 -------- d-----w- C:\Users\Jim\AppData\Local\{BE7B8CEA-7CE7-44BD-B9D5-D5CB5D018098}

2012-06-28 19:23:38 -------- d-----w- C:\Users\Jim\AppData\Local\{857DCEAC-31C9-4768-9237-400906B10DCF}

2012-06-27 10:19:06 -------- d-----w- C:\Users\Jim\AppData\Local\{669CCF41-C46A-4FA2-B1A7-76F1DB87BF17}

2012-06-27 10:18:56 -------- d-----w- C:\Users\Jim\AppData\Local\{82E9B785-FF95-4EE2-927C-8E954CE63095}

2012-06-27 10:18:47 -------- d-----w- C:\Users\Jim\AppData\Local\{FA46A6B4-CF0C-4BFD-8C3D-318E0F9A5F08}

2012-06-27 10:18:36 -------- d-----w- C:\Users\Jim\AppData\Local\{E7950C88-DBDC-48ED-A939-A2F9DAC0C7F6}

2012-06-26 22:18:24 -------- d-----w- C:\Users\Jim\AppData\Local\{5EF6EC21-1B57-4C29-A6B9-5D9178819E2B}

2012-06-26 22:18:14 -------- d-----w- C:\Users\Jim\AppData\Local\{CDC65215-4ECD-4AE2-9E0E-C965307068DE}

2012-06-26 22:18:04 -------- d-----w- C:\Users\Jim\AppData\Local\{90AE2DC4-05B6-427A-8C7F-1F92EAF2DDBD}

2012-06-26 22:17:54 -------- d-----w- C:\Users\Jim\AppData\Local\{37F3FC4A-0C25-4302-B5E9-9E952122DBB7}

2012-06-26 10:17:42 -------- d-----w- C:\Users\Jim\AppData\Local\{531DA80F-DC70-4568-A978-38813A09CB5D}

2012-06-26 10:17:32 -------- d-----w- C:\Users\Jim\AppData\Local\{4F60C31A-2FDD-4EE1-8B56-786E1258D5A4}

2012-06-26 10:17:22 -------- d-----w- C:\Users\Jim\AppData\Local\{9BE37599-AF55-4ECB-A6F8-BB53B7437ABF}

2012-06-26 10:17:12 -------- d-----w- C:\Users\Jim\AppData\Local\{F9078040-0473-4437-BDBC-7D94742C3ED8}

2012-06-25 22:16:45 -------- d-----w- C:\Users\Jim\AppData\Local\{6F68042E-9F0B-4262-9437-9041E58C5CC6}

2012-06-25 22:16:36 -------- d-----w- C:\Users\Jim\AppData\Local\{3DC8164B-0C54-47A0-902C-400279908DD6}

2012-06-25 22:16:26 -------- d-----w- C:\Users\Jim\AppData\Local\{642E28C3-0E57-406D-A5B2-B97AAF52CF3A}

2012-06-25 22:16:16 -------- d-----w- C:\Users\Jim\AppData\Local\{10969509-7151-479B-8A54-38B3030EE207}

2012-06-25 10:16:02 -------- d-----w- C:\Users\Jim\AppData\Local\{DE555CEF-07CF-42F4-8110-D524C747ABAF}

2012-06-25 10:15:52 -------- d-----w- C:\Users\Jim\AppData\Local\{42CBE74B-DE9E-4CC6-84C5-897844DD9C47}

2012-06-25 10:15:41 -------- d-----w- C:\Users\Jim\AppData\Local\{7C2FF2EF-D906-4100-8A1B-4C44FE610E8F}

2012-06-25 10:15:31 -------- d-----w- C:\Users\Jim\AppData\Local\{CB1E6A5B-AB38-474D-9C79-69C29D6B2AD3}

2012-06-24 22:15:17 -------- d-----w- C:\Users\Jim\AppData\Local\{1CF9FCA6-B792-4B92-917E-B3C199BF1FEB}

2012-06-24 22:15:07 -------- d-----w- C:\Users\Jim\AppData\Local\{FB7419AA-178A-4122-BDBF-4F2490BBD3FD}

2012-06-24 22:14:57 -------- d-----w- C:\Users\Jim\AppData\Local\{D18DCE12-35EF-421D-B78F-650720276A67}

2012-06-24 22:14:46 -------- d-----w- C:\Users\Jim\AppData\Local\{320C6628-5D0A-41F5-B0D4-39D463C21188}

2012-06-24 10:14:32 -------- d-----w- C:\Users\Jim\AppData\Local\{614F63A3-9857-4168-9BAC-4DB867C2B092}

2012-06-24 10:14:22 -------- d-----w- C:\Users\Jim\AppData\Local\{8CD3086D-684D-4120-89F3-73376E3CE215}

2012-06-24 10:14:12 -------- d-----w- C:\Users\Jim\AppData\Local\{DC806D6A-2A1C-4881-B60C-C54D3511B5BF}

2012-06-24 10:14:02 -------- d-----w- C:\Users\Jim\AppData\Local\{38DE5258-DA4B-4792-8C00-44637B76ACEE}

2012-06-23 22:13:49 -------- d-----w- C:\Users\Jim\AppData\Local\{FCB3DAEA-7F61-4520-8860-C23097449FA4}

2012-06-23 22:13:40 -------- d-----w- C:\Users\Jim\AppData\Local\{14934CE5-94E0-4B21-B0A9-161573CFB64B}

2012-06-23 22:13:30 -------- d-----w- C:\Users\Jim\AppData\Local\{7F4B93A1-EA66-41B1-B02B-A76958323131}

2012-06-23 22:13:19 -------- d-----w- C:\Users\Jim\AppData\Local\{74D13C49-57B3-461F-9F6B-5BD64A773525}

2012-06-23 14:35:21 29312 ----a-w- C:\Program Files (x86)\Mozilla Firefox\ScriptFF.dll

2012-06-23 10:12:54 -------- d-----w- C:\Users\Jim\AppData\Local\{0FF5E2E1-82F2-474A-A5E6-805019B7305B}

2012-06-23 10:12:44 -------- d-----w- C:\Users\Jim\AppData\Local\{FBEF6620-7554-4C1C-97C2-018A929D6C0E}

2012-06-23 10:12:34 -------- d-----w- C:\Users\Jim\AppData\Local\{FAE87E16-C3E9-42E0-A453-322219FCF159}

2012-06-23 10:12:23 -------- d-----w- C:\Users\Jim\AppData\Local\{EA5A36A2-923E-4A97-93B0-170FC2404F0C}

2012-06-22 22:12:07 -------- d-----w- C:\Users\Jim\AppData\Local\{0621AB9D-B743-4C11-9F71-55E89B7B4CC8}

2012-06-22 22:11:57 -------- d-----w- C:\Users\Jim\AppData\Local\{4B5756C7-8DE4-4E5F-BD3A-E5C68800F3EE}

2012-06-22 22:11:47 -------- d-----w- C:\Users\Jim\AppData\Local\{63D4EC3F-9DE2-4500-BEF0-CDCDDB390A71}

2012-06-22 22:11:36 -------- d-----w- C:\Users\Jim\AppData\Local\{3A47C7C1-6438-42A5-B7E7-8120BABE36B8}

2012-06-22 14:01:36 2622464 ----a-w- C:\Windows\System32\wucltux.dll

2012-06-22 14:01:17 99840 ----a-w- C:\Windows\System32\wudriver.dll

2012-06-22 14:01:06 36864 ----a-w- C:\Windows\System32\wuapp.exe

2012-06-22 14:01:06 186752 ----a-w- C:\Windows\System32\wuwebv.dll

2012-06-22 10:11:23 -------- d-----w- C:\Users\Jim\AppData\Local\{026655D0-C879-466C-B96E-5FDBEEB9A973}

2012-06-22 10:11:13 -------- d-----w- C:\Users\Jim\AppData\Local\{8EDA6068-9456-4C44-AD2C-9607550C8C13}

2012-06-22 10:11:03 -------- d-----w- C:\Users\Jim\AppData\Local\{B6C83D6A-2A3F-4D35-A8B4-3F3CA67BFBCE}

2012-06-22 10:10:53 -------- d-----w- C:\Users\Jim\AppData\Local\{B36A188D-A119-42F9-B356-E140F7821ECA}

2012-06-21 22:02:02 -------- d-----w- C:\Users\Jim\AppData\Local\{CC9FEB8E-6004-47D7-8AF6-389834C1B218}

2012-06-21 22:01:52 -------- d-----w- C:\Users\Jim\AppData\Local\{7545BA4C-089C-48D4-9A9E-A865C630EF3E}

2012-06-21 22:01:42 -------- d-----w- C:\Users\Jim\AppData\Local\{F0786781-926C-42AC-9A1F-7F5D9D054863}

2012-06-21 22:01:32 -------- d-----w- C:\Users\Jim\AppData\Local\{F7D9B3B0-F3D3-41BC-A9DA-F4DBDDC768C5}

2012-06-21 10:01:19 -------- d-----w- C:\Users\Jim\AppData\Local\{9E701D4C-FB56-4D81-BCE1-639E3AD28413}

2012-06-21 10:01:09 -------- d-----w- C:\Users\Jim\AppData\Local\{60A5B4F5-A539-482F-8CE1-BA729ABEF9E6}

2012-06-21 10:00:59 -------- d-----w- C:\Users\Jim\AppData\Local\{A18AEB6D-678C-4BF5-AA9E-927E8E735526}

2012-06-21 10:00:48 -------- d-----w- C:\Users\Jim\AppData\Local\{4CDAF182-F5BF-4B66-8D8D-7EC5B54650AE}

2012-06-20 22:00:35 -------- d-----w- C:\Users\Jim\AppData\Local\{64D9BC8A-7B95-4604-9636-FE1A22BCADFD}

2012-06-20 22:00:26 -------- d-----w- C:\Users\Jim\AppData\Local\{8E9E58E8-2BAE-4060-AE80-4D20E4B70607}

2012-06-20 22:00:16 -------- d-----w- C:\Users\Jim\AppData\Local\{5AC1A18A-4957-4B42-B945-8CAAA491074D}

2012-06-20 22:00:05 -------- d-----w- C:\Users\Jim\AppData\Local\{A2E1BC49-9376-4271-8327-9E8BB07354DA}

2012-06-20 09:59:52 -------- d-----w- C:\Users\Jim\AppData\Local\{54D1D32A-3B5C-47EF-8621-454B8A0C4379}

2012-06-20 09:59:42 -------- d-----w- C:\Users\Jim\AppData\Local\{36B2893D-5C43-4EB4-8691-95946F714F77}

2012-06-20 09:59:32 -------- d-----w- C:\Users\Jim\AppData\Local\{36BDBD36-D46C-40A3-B269-598B84C716ED}

2012-06-20 09:59:22 -------- d-----w- C:\Users\Jim\AppData\Local\{09AA3329-C772-4BD8-9B4A-34A28B37C539}

2012-06-19 21:59:09 -------- d-----w- C:\Users\Jim\AppData\Local\{6EFA92D2-33A8-4F6B-B99B-C1405CDE353C}

2012-06-19 21:58:59 -------- d-----w- C:\Users\Jim\AppData\Local\{8D94488B-7CDD-4A35-9ED4-5653AFB236F6}

2012-06-19 21:58:49 -------- d-----w- C:\Users\Jim\AppData\Local\{DB93FCE3-C9C2-46A5-B9F6-DE749C4DE9A3}

2012-06-19 21:58:39 -------- d-----w- C:\Users\Jim\AppData\Local\{F2508D26-AA85-42E8-816D-A66FB8B71A25}

2012-06-19 09:58:26 -------- d-----w- C:\Users\Jim\AppData\Local\{DDE450DA-1144-441A-9BF8-A502823999B8}

2012-06-19 09:58:11 -------- d-----w- C:\Users\Jim\AppData\Local\{77A6DA84-1BE8-433E-9CEC-8CF3559E364A}

2012-06-19 09:58:01 -------- d-----w- C:\Users\Jim\AppData\Local\{7D61D658-F10C-4DDE-813E-99B5393DA17D}

2012-06-19 09:57:51 -------- d-----w- C:\Users\Jim\AppData\Local\{5A6EFCF0-6426-40F7-8469-1DE4BF9AB421}

2012-06-18 20:48:39 -------- d-----w- C:\Users\Jim\AppData\Local\{41124E82-350A-4C97-B96A-6A5FDBCCC7B0}

2012-06-15 10:21:36 -------- d-----w- C:\Users\Jim\AppData\Local\{036FE00A-0B93-493A-B8AD-468D73BCAA3A}

2012-06-14 22:21:10 -------- d-----w- C:\Users\Jim\AppData\Local\{92E29338-8DD9-473D-A726-D3BF3283807E}

2012-06-14 22:21:00 -------- d-----w- C:\Users\Jim\AppData\Local\{2A206F11-3D75-4E3F-941A-BF84B5E06D62}

2012-06-14 22:20:49 -------- d-----w- C:\Users\Jim\AppData\Local\{FFDF7FC4-545F-43C1-B949-B0CABB6B7B95}

2012-06-14 10:20:37 -------- d-----w- C:\Users\Jim\AppData\Local\{8A3472D1-8406-4372-8B03-4071C353ADA7}

2012-06-14 10:20:27 -------- d-----w- C:\Users\Jim\AppData\Local\{D032C956-0F0D-426C-BB08-F9FEB7A8122A}

2012-06-14 10:20:18 -------- d-----w- C:\Users\Jim\AppData\Local\{216E44BF-85FD-470C-A680-95444C56D4FE}

2012-06-14 10:20:07 -------- d-----w- C:\Users\Jim\AppData\Local\{F0E6876B-2987-400C-94E0-0B0F587D8249}

2012-06-13 22:18:44 -------- d-----w- C:\Users\Jim\AppData\Local\{AC47E3CB-F71E-4C85-A8AE-4174420A5CFE}

2012-06-13 22:18:34 -------- d-----w- C:\Users\Jim\AppData\Local\{9EA43A07-456B-409F-A841-34A8227E5F47}

2012-06-13 22:18:24 -------- d-----w- C:\Users\Jim\AppData\Local\{20255A2D-5D7A-4BE9-8DF1-FC7F8BCA6843}

2012-06-13 22:18:14 -------- d-----w- C:\Users\Jim\AppData\Local\{AC0ACD8C-6449-4672-8389-2981A1C70CF7}

2012-06-13 10:18:02 -------- d-----w- C:\Users\Jim\AppData\Local\{DD72D4E6-AA0C-437A-874C-9030AAEE0551}

2012-06-13 10:17:52 -------- d-----w- C:\Users\Jim\AppData\Local\{160C51AD-E48E-4D1D-903B-EA094597FE8E}

2012-06-13 10:17:42 -------- d-----w- C:\Users\Jim\AppData\Local\{0002B321-7BEA-4F1C-AF20-D25D7120CF7F}

2012-06-13 10:17:32 -------- d-----w- C:\Users\Jim\AppData\Local\{B4C174F8-6D90-4D29-9889-A88425F447E6}

2012-06-13 07:00:59 754808 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe

2012-06-12 22:17:07 -------- d-----w- C:\Users\Jim\AppData\Local\{3DF335C3-022C-4827-8348-3AEAB89F28F0}

2012-06-12 22:16:57 -------- d-----w- C:\Users\Jim\AppData\Local\{6243EE71-0B17-4D21-B7C0-DCB6F12CF8A0}

2012-06-12 22:16:47 -------- d-----w- C:\Users\Jim\AppData\Local\{4EFC2179-6A53-4437-8296-55382BFDD68B}

2012-06-12 22:16:37 -------- d-----w- C:\Users\Jim\AppData\Local\{D3C54576-77F5-422C-B87B-62A264E9050A}

2012-06-12 14:36:05 770384 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr100.dll

2012-06-12 14:36:05 421200 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp100.dll

2012-06-12 10:16:23 -------- d-----w- C:\Users\Jim\AppData\Local\{1554D5FE-322A-49AE-9D8A-A1DD53781F3E}

2012-06-12 10:16:13 -------- d-----w- C:\Users\Jim\AppData\Local\{02526C25-1FCE-4A71-BF44-6524FC1CDC9D}

2012-06-12 10:16:04 -------- d-----w- C:\Users\Jim\AppData\Local\{B5FBD0AB-313E-4FF5-B0A5-F951EA31800F}

2012-06-12 10:15:53 -------- d-----w- C:\Users\Jim\AppData\Local\{8C7DE440-80BA-4FF3-BFCB-17387D46FB54}

2012-06-11 22:15:40 -------- d-----w- C:\Users\Jim\AppData\Local\{42713BFE-C9F2-4B78-B6A8-A76F5CDE5ABD}

2012-06-11 22:15:30 -------- d-----w- C:\Users\Jim\AppData\Local\{35829E33-DA99-4CE6-B6D8-054C796D994E}

2012-06-11 22:15:21 -------- d-----w- C:\Users\Jim\AppData\Local\{1BAD6F56-62E2-473E-A24E-37E863960D6B}

2012-06-11 22:15:10 -------- d-----w- C:\Users\Jim\AppData\Local\{4FA93D46-F06D-480B-A499-2C16E3D9B80A}

2012-06-11 10:14:58 -------- d-----w- C:\Users\Jim\AppData\Local\{7A67DFF1-6606-4960-833F-37093453BCB4}

2012-06-11 10:14:48 -------- d-----w- C:\Users\Jim\AppData\Local\{17B8374A-0EF1-4F96-A188-36720B465FEB}

2012-06-11 10:14:39 -------- d-----w- C:\Users\Jim\AppData\Local\{9834E12C-E567-487D-9572-176118B24C85}

2012-06-11 10:14:29 -------- d-----w- C:\Users\Jim\AppData\Local\{FC3677F5-4AFA-44E1-8C18-5E5BA4E59C1F}

2012-06-10 22:14:17 -------- d-----w- C:\Users\Jim\AppData\Local\{D0EB6389-3B00-461B-86E9-1F92E21E44C6}

2012-06-10 22:14:07 -------- d-----w- C:\Users\Jim\AppData\Local\{638F8D31-064E-47F7-B529-A0F6E6409B02}

2012-06-10 22:13:57 -------- d-----w- C:\Users\Jim\AppData\Local\{F6C1513F-48CB-414A-8691-B4B6D3F8B07F}

2012-06-10 22:13:47 -------- d-----w- C:\Users\Jim\AppData\Local\{D007F00D-8FFC-4786-9B58-7D3EACDD0F20}

2012-06-10 10:13:35 -------- d-----w- C:\Users\Jim\AppData\Local\{D9EC099B-E8B2-4EA1-A0A0-C8D76F638048}

2012-06-10 10:13:25 -------- d-----w- C:\Users\Jim\AppData\Local\{6578F04E-4D78-49DE-9818-549246002E08}

2012-06-10 10:13:15 -------- d-----w- C:\Users\Jim\AppData\Local\{280302DF-5B80-4D48-8F56-D5D2F32E68F4}

2012-06-10 10:13:05 -------- d-----w- C:\Users\Jim\AppData\Local\{37D38E42-055F-4FB2-9A0F-FEE61EE37F4E}

.

==================== Find3M ====================

.

2012-07-02 17:25:19 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-21 20:45:13 87456 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll

2012-05-21 20:45:13 34688 ----a-w- C:\Windows\System32\LMIport.dll

2012-05-21 20:45:12 80768 ----a-w- C:\Windows\System32\LMIinit.dll

2012-05-18 02:06:48 2311680 ----a-w- C:\Windows\System32\jscript9.dll

2012-05-18 01:59:14 1392128 ----a-w- C:\Windows\System32\wininet.dll

2012-05-18 01:58:39 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2012-05-18 01:55:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2012-05-18 01:51:30 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2012-05-17 22:45:37 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll

2012-05-17 22:35:47 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2012-05-17 22:35:39 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2012-05-17 22:29:45 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2012-05-17 22:24:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2012-05-15 01:32:33 3146752 ----a-w- C:\Windows\System32\win32k.sys

2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe

2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll

2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys

2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll

2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll

2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe

2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll

2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll

2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll

2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll

2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll

2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll

.

============= FINISH: 20:21:21.68 ===============

Share this post


Link to post
Share on other sites

Hello again!

ComboFix Log below, followed by new DDS.txt...

ComboFix 12-07-08.03 - Jim 07/09/2012 20:35:17.1.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7935.6277 [GMT -4:00]

Running from: c:\users\Jim\Downloads\ComboFix.exe

AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NkbMonitor.exe.lnk

c:\users\Jim\AppData\Roaming\sdedro.dll

c:\users\Jim\GoToAssistDownloadHelper.exe

.

Infected copy of c:\windows\system32\Services.exe was found and disinfected

Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

.

.

((((((((((((((((((((((((( Files Created from 2012-06-10 to 2012-07-10 )))))))))))))))))))))))))))))))

.

.

2012-07-10 00:42 . 2012-07-10 00:42 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp

2012-07-10 00:42 . 2012-07-10 00:42 -------- d-----w- c:\users\Karen\AppData\Local\temp

2012-07-10 00:42 . 2012-07-10 00:42 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-07-09 20:39 . 2011-04-20 07:07 1930240 ----a-w- c:\windows\system32\drivers\athurx.sys

2012-07-09 20:39 . 2011-04-20 07:07 1930240 ----a-w- c:\windows\system32\athurx.sys

2012-07-09 20:39 . 2012-07-09 20:39 -------- d-----w- c:\programdata\TP-LINK

2012-07-09 20:35 . 2012-07-09 20:35 -------- d-----w- c:\users\Jim\AppData\Local\{8BB253BD-CA05-11E1-8270-B8AC6F996F26}

2012-07-03 21:30 . 2012-07-03 21:30 1409 ----a-w- c:\windows\QTFont.for

2012-07-02 17:33 . 2012-07-02 17:33 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%

2012-07-02 17:25 . 2012-07-02 17:25 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-06-23 14:35 . 2012-05-25 21:09 29312 ----a-w- c:\program files (x86)\Mozilla Firefox\ScriptFF.dll

2012-06-22 14:01 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll

2012-06-22 14:01 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe

2012-06-22 14:01 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll

2012-06-22 14:01 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll

2012-06-22 14:01 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll

2012-06-22 14:01 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll

2012-06-22 14:01 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll

2012-06-22 14:01 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll

2012-06-22 14:01 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe

2012-06-13 07:00 . 2012-05-18 02:51 754808 ----a-w- c:\program files\Internet Explorer\iexplore.exe

2012-06-12 14:36 . 2012-06-12 14:36 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll

2012-06-12 14:36 . 2012-06-12 14:36 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-07-02 17:25 . 2011-06-13 13:20 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-21 20:45 . 2010-09-06 14:32 34688 ----a-w- c:\windows\system32\LMIport.dll

2012-05-21 20:45 . 2010-09-06 14:32 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll

2012-05-21 20:45 . 2010-09-06 14:32 80768 ----a-w- c:\windows\system32\LMIinit.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DKab1err"="c:\program files\Dell\Printer Software\ErrorApp\DKab1err.exe" [2006-10-21 521112]

"sdedro"="c:\windows\System32\rundll32.exe" [2009-07-14 44544]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\vdeck.exe" [2009-06-01 2170880]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-06-15 98304]

"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]

"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]

"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-19 494064]

"DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]

"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118624]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]

"c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-09-25 560128]

.

c:\users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-02 257224]

R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.364.0\SeaPort.exe [2012-02-20 240408]

R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]

R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-19 113120]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-22 1255736]

R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]

S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-06-15 203264]

S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.364.0\BBSvc.exe [2012-02-20 193816]

S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]

S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-05-21 375176]

S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-01-27 15928]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584]

S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-20 162192]

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856]

S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys [2011-04-20 1930240]

S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]

S3 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe [2006-10-21 476568]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]

S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-11-17 294400]

S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-05-27 1206784]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - WS2IFSL

*Deregistered* - mfeavfk01

.

Contents of the 'Scheduled Tasks' folder

.

2012-07-10 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-02 17:25]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"VX3000"="c:\windows\vVX3000.exe" [2009-07-01 762224]

"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-01-27 57928]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x0

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://google.com/

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

FF - ProfilePath - c:\users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\wl7yj5l6.default\

FF - prefs.js: browser.search.selectedEngine - Secure Search

FF - prefs.js: browser.startup.homepage - google.com

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=

FF - user.js: yahoo.homepage.dontask - true

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

Toolbar-Locked - (no file)

.

.

.

------------------------ Other Running Processes ------------------------

.

c:\windows\SysWOW64\rundll32.exe

c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe

c:\program files (x86)\Dell DataSafe Local Backup\Toaster.exe

c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe

.

**************************************************************************

.

Completion time: 2012-07-09 21:01:09 - machine was rebooted

ComboFix-quarantined-files.txt 2012-07-10 01:01

.

Pre-Run: 653,569,257,472 bytes free

Post-Run: 658,095,841,280 bytes free

.

- - End Of File - - 40EB96A5B2F009901B02AAE0417F0583

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30

Run by Jim at 21:03:42 on 2012-07-09

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7935.6062 [GMT -4:00]

.

AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\AUDIODG.EXE

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\Dell\DellDock\DockLogin.exe

C:\Windows\system32\atieclxx.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BBSvc.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

C:\Windows\system32\mfevtps.exe

C:\Program Files\Microsoft LifeCam\MSCamS64.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

C:\Windows\system32\rundll32.exe

C:\Windows\system32\rundll32.exe

C:\Windows\SysWOW64\rundll32.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe

C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe

C:\Windows\System32\vds.exe

C:\Windows\system32\WUDFHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\rundll32.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Dell\Printer Software\ErrorApp\DKab1err.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\SftVss64.exe

C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe

C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe

C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe

C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe

C:\Program Files\McAfee.com\Agent\mcagent.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Windows\system32\DKabcoms.exe

C:\Windows\servicing\TrustedInstaller.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe

C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\Windows\system32\taskeng.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Windows\system32\taskhost.exe

c:\PROGRA~2\mcafee\SITEAD~1\saui.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://google.com/

uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120623103522.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll"

TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File

TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File

uRun: [DKab1err] C:\Program Files\Dell\Printer Software\ErrorApp\DKab1err.exe

uRun: [sdedro] "C:\Windows\System32\rundll32.exe" "C:\Users\Jim\AppData\Roaming\sdedro.dll",AllocADsMem

mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\vdeck.exe

mRun: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"

mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

StartupFolder: C:\Users\Jim\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{5B730DED-8713-4362-9B4A-3ABA56709CA9} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{7FB70350-38E6-41B1-91A2-27C2A0EBF09E} : DhcpNameServer = 192.168.1.1

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll

Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll

Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll

BHO-X64: McAfee Phishing Filter - No File

BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120623103522.dll

BHO-X64: scriptproxy - No File

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BingExt.dll"

TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File

TB-X64: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File

mRun-x64: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\vdeck.exe

mRun-x64: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

mRun-x64: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"

mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\wl7yj5l6.default\

FF - prefs.js: browser.search.selectedEngine - Secure Search

FF - prefs.js: browser.startup.homepage - google.com

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=

FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll

FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\wl7yj5l6.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll

.

---- FIREFOX POLICIES ----

FF - user.js: yahoo.homepage.dontask - true

.

============= SERVICES / DRIVERS ===============

.

R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]

R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]

R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]

R2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\BBSvc.EXE [2012-2-20 193816]

R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]

R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-9-30 375176]

R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2010-1-27 15928]

R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\Windows\system32\drivers\LMIRfsDriver.sys --> C:\Windows\system32\drivers\LMIRfsDriver.sys [?]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-6 654408]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

R2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2011-3-16 199272]

R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2011-3-16 210584]

R2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" --> C:\Windows\system32\mfevtps.exe [?]

R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2009-12-11 705856]

R3 athur;Wireless Network Adapter Service;C:\Windows\system32\DRIVERS\athurx.sys --> C:\Windows\system32\DRIVERS\athurx.sys [?]

R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]

R3 dkab_device;dkab_device;C:\Windows\system32\DKabcoms.exe -service --> C:\Windows\system32\DKabcoms.exe -service [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]

R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\system32\drivers\viahduaa.sys --> C:\Windows\system32\drivers\viahduaa.sys [?]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-2 257224]

S3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.364.0\SeaPort.EXE [2012-2-20 240408]

S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]

S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]

S3 mfebopk;McAfee Inc. mfebopk;C:\Windows\system32\drivers\mfebopk.sys --> C:\Windows\system32\drivers\mfebopk.sys [?]

S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]

S3 mferkdk;McAfee Inc. mferkdk;C:\Windows\system32\drivers\mferkdk.sys --> C:\Windows\system32\drivers\mferkdk.sys [?]

S3 mfesmfk;McAfee Inc. mfesmfk;C:\Windows\system32\drivers\mfesmfk.sys --> C:\Windows\system32\drivers\mfesmfk.sys [?]

S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-6 113120]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-6-1 249936]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

.

=============== Created Last 30 ================

.

2012-07-10 00:56:31 -------- d-sh--w- C:\$RECYCLE.BIN

2012-07-10 00:33:50 98816 ----a-w- C:\Windows\sed.exe

2012-07-10 00:33:50 518144 ----a-w- C:\Windows\SWREG.exe

2012-07-10 00:33:50 256000 ----a-w- C:\Windows\PEV.exe

2012-07-10 00:33:50 208896 ----a-w- C:\Windows\MBR.exe

2012-07-09 20:39:43 1930240 ----a-w- C:\Windows\System32\drivers\athurx.sys

2012-07-09 20:39:43 1930240 ----a-w- C:\Windows\System32\athurx.sys

2012-07-09 20:39:36 -------- d-----w- C:\ProgramData\TP-LINK

2012-07-09 20:35:30 -------- d-----w- C:\Users\Jim\AppData\Local\{8BB253BD-CA05-11E1-8270-B8AC6F996F26}

2012-07-09 20:34:54 -------- d-----w- C:\Users\Jim\AppData\Local\{2408029A-2922-4874-A06A-3A3C0081482F}

2012-07-09 20:33:17 -------- d-----w- C:\Users\Jim\AppData\Local\{BDA7E011-F5D0-4C68-ADBC-13D16E7AECF7}

2012-07-07 17:32:32 -------- d-----w- C:\Users\Jim\AppData\Local\{302A67CC-1AC6-4BE4-B494-3E85C224C7DC}

2012-07-07 00:05:46 -------- d-----w- C:\Users\Jim\AppData\Local\{D247962C-C57A-4ED6-B14C-8CF08C1FD3F1}

2012-07-07 00:05:34 -------- d-----w- C:\Users\Jim\AppData\Local\{5049C643-4979-47F8-899F-5C2EFFD3AD3A}

2012-07-05 09:58:59 -------- d-----w- C:\Users\Jim\AppData\Local\{BF23E48E-D68A-4472-A4D1-4BFF518AE192}

2012-07-05 09:58:49 -------- d-----w- C:\Users\Jim\AppData\Local\{95CDB118-9FB7-4E59-A6F3-E2D35FAC7347}

2012-07-05 09:58:39 -------- d-----w- C:\Users\Jim\AppData\Local\{1DB78542-9A50-40B7-9822-6C9430C3A565}

2012-07-04 21:04:45 -------- d-----w- C:\Users\Jim\AppData\Local\{798782FF-61F5-4F1F-BB59-D50487923B76}

2012-07-04 21:04:35 -------- d-----w- C:\Users\Jim\AppData\Local\{45A195E6-5726-4D70-AD5A-2EF79BAF7A21}

2012-07-04 21:04:25 -------- d-----w- C:\Users\Jim\AppData\Local\{55C21E77-99FE-4928-89F5-0F18B807B057}

2012-07-04 21:04:15 -------- d-----w- C:\Users\Jim\AppData\Local\{A8BD7BFD-0504-4F6E-AF2C-36D4EC71C57A}

2012-07-04 09:03:38 -------- d-----w- C:\Users\Jim\AppData\Local\{F028D109-1CB8-45E0-8306-8E3FBDFC9CFC}

2012-07-04 09:03:28 -------- d-----w- C:\Users\Jim\AppData\Local\{5887D61C-2EB3-4528-8773-E5DD370C3C47}

2012-07-03 21:30:29 1409 ----a-w- C:\Windows\QTFont.for

2012-07-03 10:01:28 -------- d-----w- C:\Users\Jim\AppData\Local\{3031119A-CE84-4EDA-B977-775DB47BCA54}

2012-07-03 10:01:18 -------- d-----w- C:\Users\Jim\AppData\Local\{328C8F5E-4CDA-4724-AD1B-2A942D398845}

2012-07-03 10:01:08 -------- d-----w- C:\Users\Jim\AppData\Local\{863A316C-086B-4D11-9FF6-B9A28F4FB717}

2012-07-03 10:00:58 -------- d-----w- C:\Users\Jim\AppData\Local\{3C62CB00-C572-4A43-B128-B47D056188EA}

2012-07-02 22:00:32 -------- d-----w- C:\Users\Jim\AppData\Local\{CF1CD375-13E9-4419-A31A-76EF3CB4BBF3}

2012-07-02 22:00:20 -------- d-----w- C:\Users\Jim\AppData\Local\{3C40169D-F0FC-4D70-ACE1-057D77F735DD}

2012-07-02 22:00:09 -------- d-----w- C:\Users\Jim\AppData\Local\{37CFEF78-3E8B-4884-959C-451F1783A75A}

2012-07-02 21:59:57 -------- d-----w- C:\Users\Jim\AppData\Local\{4A18F7E2-3D18-45A2-BD90-4A3B6709BEC0}

2012-07-02 17:33:48 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%

2012-07-02 17:25:19 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-07-02 09:59:32 -------- d-----w- C:\Users\Jim\AppData\Local\{79B60FE8-3B5F-42A2-88FE-C37CF8AA7F79}

2012-07-02 09:59:22 -------- d-----w- C:\Users\Jim\AppData\Local\{CA3F7BD2-3077-4424-A359-122183C1C160}

2012-07-02 09:59:12 -------- d-----w- C:\Users\Jim\AppData\Local\{82B6767A-9F8A-4338-928A-440A91CCBB47}

2012-07-02 09:59:01 -------- d-----w- C:\Users\Jim\AppData\Local\{C7E415DD-E93E-4E7F-A488-E48243027C7E}

2012-07-01 21:58:49 -------- d-----w- C:\Users\Jim\AppData\Local\{667BC2C4-1DC1-4F4C-9526-E70FF4570E72}

2012-07-01 21:58:39 -------- d-----w- C:\Users\Jim\AppData\Local\{28A2117A-18E1-4BC9-8726-C39EB5C9A9EE}

2012-07-01 21:58:29 -------- d-----w- C:\Users\Jim\AppData\Local\{A911C7F7-AFF7-436C-A840-69FB15CCE4FE}

2012-07-01 21:58:19 -------- d-----w- C:\Users\Jim\AppData\Local\{B49E8241-F6A3-40C2-8EDB-DEE582DF7461}

2012-07-01 09:58:06 -------- d-----w- C:\Users\Jim\AppData\Local\{06E9ABF3-A0D7-4E76-9736-508EB3A62B3A}

2012-07-01 09:57:56 -------- d-----w- C:\Users\Jim\AppData\Local\{A8C8D714-5F4B-48AB-A9B3-50DDDB3A046F}

2012-07-01 09:57:47 -------- d-----w- C:\Users\Jim\AppData\Local\{174C4A15-6ED7-4272-A31A-56E2B267BC9A}

2012-07-01 09:57:36 -------- d-----w- C:\Users\Jim\AppData\Local\{82BF1563-9DFC-4FC7-9B52-1F86ED6F8569}

2012-06-30 21:43:44 -------- d-----w- C:\Users\Jim\AppData\Local\{847EECCE-A6CA-45BE-8135-A106B5C703BF}

2012-06-30 21:43:34 -------- d-----w- C:\Users\Jim\AppData\Local\{86E89153-DF49-4053-91D4-0C3D2ED7D90E}

2012-06-30 21:43:23 -------- d-----w- C:\Users\Jim\AppData\Local\{B69FC4A9-2991-4FC5-99D8-9EC9EECD4D76}

2012-06-30 09:43:11 -------- d-----w- C:\Users\Jim\AppData\Local\{19B7022B-D9AB-4C06-8748-86DB89E81AB9}

2012-06-30 09:43:01 -------- d-----w- C:\Users\Jim\AppData\Local\{556311DC-8990-49F5-86D0-6969BAE68CF4}

2012-06-30 09:42:51 -------- d-----w- C:\Users\Jim\AppData\Local\{B93620CC-605E-45F7-A162-7297F95935B9}

2012-06-30 09:42:41 -------- d-----w- C:\Users\Jim\AppData\Local\{9DA84734-9F22-4DDF-91F6-86B16ABB74C6}

2012-06-29 21:16:39 -------- d-----w- C:\Users\Jim\AppData\Local\{FAB7B59D-437A-47E6-BBE9-9EC1490555E4}

2012-06-29 21:16:29 -------- d-----w- C:\Users\Jim\AppData\Local\{83D39AA9-9201-47F5-8B89-A57555BEE5DB}

2012-06-29 21:16:19 -------- d-----w- C:\Users\Jim\AppData\Local\{B7208114-8CB3-4425-916C-2FE32788B026}

2012-06-29 21:16:09 -------- d-----w- C:\Users\Jim\AppData\Local\{ECB0062B-B1AC-42EC-BBF6-2F398E6A304C}

2012-06-29 09:15:56 -------- d-----w- C:\Users\Jim\AppData\Local\{2E8337C3-03E2-4C89-8049-FBF4B66F69AB}

2012-06-29 09:15:46 -------- d-----w- C:\Users\Jim\AppData\Local\{F5CA8462-F4AA-48D0-B3C9-85418D858DE3}

2012-06-29 09:15:36 -------- d-----w- C:\Users\Jim\AppData\Local\{FE6C0B13-F5AB-46C4-A6EA-B619EE367E51}

2012-06-29 09:15:26 -------- d-----w- C:\Users\Jim\AppData\Local\{53DA760F-DD99-48DE-84E6-E671281704F7}

2012-06-28 19:23:50 -------- d-----w- C:\Users\Jim\AppData\Local\{BE7B8CEA-7CE7-44BD-B9D5-D5CB5D018098}

2012-06-28 19:23:38 -------- d-----w- C:\Users\Jim\AppData\Local\{857DCEAC-31C9-4768-9237-400906B10DCF}

2012-06-27 10:19:06 -------- d-----w- C:\Users\Jim\AppData\Local\{669CCF41-C46A-4FA2-B1A7-76F1DB87BF17}

2012-06-27 10:18:56 -------- d-----w- C:\Users\Jim\AppData\Local\{82E9B785-FF95-4EE2-927C-8E954CE63095}

2012-06-27 10:18:47 -------- d-----w- C:\Users\Jim\AppData\Local\{FA46A6B4-CF0C-4BFD-8C3D-318E0F9A5F08}

2012-06-27 10:18:36 -------- d-----w- C:\Users\Jim\AppData\Local\{E7950C88-DBDC-48ED-A939-A2F9DAC0C7F6}

2012-06-26 22:18:24 -------- d-----w- C:\Users\Jim\AppData\Local\{5EF6EC21-1B57-4C29-A6B9-5D9178819E2B}

2012-06-26 22:18:14 -------- d-----w- C:\Users\Jim\AppData\Local\{CDC65215-4ECD-4AE2-9E0E-C965307068DE}

2012-06-26 22:18:04 -------- d-----w- C:\Users\Jim\AppData\Local\{90AE2DC4-05B6-427A-8C7F-1F92EAF2DDBD}

2012-06-26 22:17:54 -------- d-----w- C:\Users\Jim\AppData\Local\{37F3FC4A-0C25-4302-B5E9-9E952122DBB7}

2012-06-26 10:17:42 -------- d-----w- C:\Users\Jim\AppData\Local\{531DA80F-DC70-4568-A978-38813A09CB5D}

2012-06-26 10:17:32 -------- d-----w- C:\Users\Jim\AppData\Local\{4F60C31A-2FDD-4EE1-8B56-786E1258D5A4}

2012-06-26 10:17:22 -------- d-----w- C:\Users\Jim\AppData\Local\{9BE37599-AF55-4ECB-A6F8-BB53B7437ABF}

2012-06-26 10:17:12 -------- d-----w- C:\Users\Jim\AppData\Local\{F9078040-0473-4437-BDBC-7D94742C3ED8}

2012-06-25 22:16:45 -------- d-----w- C:\Users\Jim\AppData\Local\{6F68042E-9F0B-4262-9437-9041E58C5CC6}

2012-06-25 22:16:36 -------- d-----w- C:\Users\Jim\AppData\Local\{3DC8164B-0C54-47A0-902C-400279908DD6}

2012-06-25 22:16:26 -------- d-----w- C:\Users\Jim\AppData\Local\{642E28C3-0E57-406D-A5B2-B97AAF52CF3A}

2012-06-25 22:16:16 -------- d-----w- C:\Users\Jim\AppData\Local\{10969509-7151-479B-8A54-38B3030EE207}

2012-06-25 10:16:02 -------- d-----w- C:\Users\Jim\AppData\Local\{DE555CEF-07CF-42F4-8110-D524C747ABAF}

2012-06-25 10:15:52 -------- d-----w- C:\Users\Jim\AppData\Local\{42CBE74B-DE9E-4CC6-84C5-897844DD9C47}

2012-06-25 10:15:41 -------- d-----w- C:\Users\Jim\AppData\Local\{7C2FF2EF-D906-4100-8A1B-4C44FE610E8F}

2012-06-25 10:15:31 -------- d-----w- C:\Users\Jim\AppData\Local\{CB1E6A5B-AB38-474D-9C79-69C29D6B2AD3}

2012-06-24 22:15:17 -------- d-----w- C:\Users\Jim\AppData\Local\{1CF9FCA6-B792-4B92-917E-B3C199BF1FEB}

2012-06-24 22:15:07 -------- d-----w- C:\Users\Jim\AppData\Local\{FB7419AA-178A-4122-BDBF-4F2490BBD3FD}

2012-06-24 22:14:57 -------- d-----w- C:\Users\Jim\AppData\Local\{D18DCE12-35EF-421D-B78F-650720276A67}

2012-06-24 22:14:46 -------- d-----w- C:\Users\Jim\AppData\Local\{320C6628-5D0A-41F5-B0D4-39D463C21188}

2012-06-24 10:14:32 -------- d-----w- C:\Users\Jim\AppData\Local\{614F63A3-9857-4168-9BAC-4DB867C2B092}

2012-06-24 10:14:22 -------- d-----w- C:\Users\Jim\AppData\Local\{8CD3086D-684D-4120-89F3-73376E3CE215}

2012-06-24 10:14:12 -------- d-----w- C:\Users\Jim\AppData\Local\{DC806D6A-2A1C-4881-B60C-C54D3511B5BF}

2012-06-24 10:14:02 -------- d-----w- C:\Users\Jim\AppData\Local\{38DE5258-DA4B-4792-8C00-44637B76ACEE}

2012-06-23 22:13:49 -------- d-----w- C:\Users\Jim\AppData\Local\{FCB3DAEA-7F61-4520-8860-C23097449FA4}

2012-06-23 22:13:40 -------- d-----w- C:\Users\Jim\AppData\Local\{14934CE5-94E0-4B21-B0A9-161573CFB64B}

2012-06-23 22:13:30 -------- d-----w- C:\Users\Jim\AppData\Local\{7F4B93A1-EA66-41B1-B02B-A76958323131}

2012-06-23 22:13:19 -------- d-----w- C:\Users\Jim\AppData\Local\{74D13C49-57B3-461F-9F6B-5BD64A773525}

2012-06-23 14:35:21 29312 ----a-w- C:\Program Files (x86)\Mozilla Firefox\ScriptFF.dll

2012-06-23 10:12:54 -------- d-----w- C:\Users\Jim\AppData\Local\{0FF5E2E1-82F2-474A-A5E6-805019B7305B}

2012-06-23 10:12:44 -------- d-----w- C:\Users\Jim\AppData\Local\{FBEF6620-7554-4C1C-97C2-018A929D6C0E}

2012-06-23 10:12:34 -------- d-----w- C:\Users\Jim\AppData\Local\{FAE87E16-C3E9-42E0-A453-322219FCF159}

2012-06-23 10:12:23 -------- d-----w- C:\Users\Jim\AppData\Local\{EA5A36A2-923E-4A97-93B0-170FC2404F0C}

2012-06-22 22:12:07 -------- d-----w- C:\Users\Jim\AppData\Local\{0621AB9D-B743-4C11-9F71-55E89B7B4CC8}

2012-06-22 22:11:57 -------- d-----w- C:\Users\Jim\AppData\Local\{4B5756C7-8DE4-4E5F-BD3A-E5C68800F3EE}

2012-06-22 22:11:47 -------- d-----w- C:\Users\Jim\AppData\Local\{63D4EC3F-9DE2-4500-BEF0-CDCDDB390A71}

2012-06-22 22:11:36 -------- d-----w- C:\Users\Jim\AppData\Local\{3A47C7C1-6438-42A5-B7E7-8120BABE36B8}

2012-06-22 14:01:36 2622464 ----a-w- C:\Windows\System32\wucltux.dll

2012-06-22 14:01:17 99840 ----a-w- C:\Windows\System32\wudriver.dll

2012-06-22 14:01:06 36864 ----a-w- C:\Windows\System32\wuapp.exe

2012-06-22 14:01:06 186752 ----a-w- C:\Windows\System32\wuwebv.dll

2012-06-22 10:11:23 -------- d-----w- C:\Users\Jim\AppData\Local\{026655D0-C879-466C-B96E-5FDBEEB9A973}

2012-06-22 10:11:13 -------- d-----w- C:\Users\Jim\AppData\Local\{8EDA6068-9456-4C44-AD2C-9607550C8C13}

2012-06-22 10:11:03 -------- d-----w- C:\Users\Jim\AppData\Local\{B6C83D6A-2A3F-4D35-A8B4-3F3CA67BFBCE}

2012-06-22 10:10:53 -------- d-----w- C:\Users\Jim\AppData\Local\{B36A188D-A119-42F9-B356-E140F7821ECA}

2012-06-21 22:02:02 -------- d-----w- C:\Users\Jim\AppData\Local\{CC9FEB8E-6004-47D7-8AF6-389834C1B218}

2012-06-21 22:01:52 -------- d-----w- C:\Users\Jim\AppData\Local\{7545BA4C-089C-48D4-9A9E-A865C630EF3E}

2012-06-21 22:01:42 -------- d-----w- C:\Users\Jim\AppData\Local\{F0786781-926C-42AC-9A1F-7F5D9D054863}

2012-06-21 22:01:32 -------- d-----w- C:\Users\Jim\AppData\Local\{F7D9B3B0-F3D3-41BC-A9DA-F4DBDDC768C5}

2012-06-21 10:01:19 -------- d-----w- C:\Users\Jim\AppData\Local\{9E701D4C-FB56-4D81-BCE1-639E3AD28413}

2012-06-21 10:01:09 -------- d-----w- C:\Users\Jim\AppData\Local\{60A5B4F5-A539-482F-8CE1-BA729ABEF9E6}

2012-06-21 10:00:59 -------- d-----w- C:\Users\Jim\AppData\Local\{A18AEB6D-678C-4BF5-AA9E-927E8E735526}

2012-06-21 10:00:48 -------- d-----w- C:\Users\Jim\AppData\Local\{4CDAF182-F5BF-4B66-8D8D-7EC5B54650AE}

2012-06-20 22:00:35 -------- d-----w- C:\Users\Jim\AppData\Local\{64D9BC8A-7B95-4604-9636-FE1A22BCADFD}

2012-06-20 22:00:26 -------- d-----w- C:\Users\Jim\AppData\Local\{8E9E58E8-2BAE-4060-AE80-4D20E4B70607}

2012-06-20 22:00:16 -------- d-----w- C:\Users\Jim\AppData\Local\{5AC1A18A-4957-4B42-B945-8CAAA491074D}

2012-06-20 22:00:05 -------- d-----w- C:\Users\Jim\AppData\Local\{A2E1BC49-9376-4271-8327-9E8BB07354DA}

2012-06-20 09:59:52 -------- d-----w- C:\Users\Jim\AppData\Local\{54D1D32A-3B5C-47EF-8621-454B8A0C4379}

2012-06-20 09:59:42 -------- d-----w- C:\Users\Jim\AppData\Local\{36B2893D-5C43-4EB4-8691-95946F714F77}

2012-06-20 09:59:32 -------- d-----w- C:\Users\Jim\AppData\Local\{36BDBD36-D46C-40A3-B269-598B84C716ED}

2012-06-20 09:59:22 -------- d-----w- C:\Users\Jim\AppData\Local\{09AA3329-C772-4BD8-9B4A-34A28B37C539}

2012-06-19 21:59:09 -------- d-----w- C:\Users\Jim\AppData\Local\{6EFA92D2-33A8-4F6B-B99B-C1405CDE353C}

2012-06-19 21:58:59 -------- d-----w- C:\Users\Jim\AppData\Local\{8D94488B-7CDD-4A35-9ED4-5653AFB236F6}

2012-06-19 21:58:49 -------- d-----w- C:\Users\Jim\AppData\Local\{DB93FCE3-C9C2-46A5-B9F6-DE749C4DE9A3}

2012-06-19 21:58:39 -------- d-----w- C:\Users\Jim\AppData\Local\{F2508D26-AA85-42E8-816D-A66FB8B71A25}

2012-06-19 09:58:26 -------- d-----w- C:\Users\Jim\AppData\Local\{DDE450DA-1144-441A-9BF8-A502823999B8}

2012-06-19 09:58:11 -------- d-----w- C:\Users\Jim\AppData\Local\{77A6DA84-1BE8-433E-9CEC-8CF3559E364A}

2012-06-19 09:58:01 -------- d-----w- C:\Users\Jim\AppData\Local\{7D61D658-F10C-4DDE-813E-99B5393DA17D}

2012-06-19 09:57:51 -------- d-----w- C:\Users\Jim\AppData\Local\{5A6EFCF0-6426-40F7-8469-1DE4BF9AB421}

2012-06-18 20:48:39 -------- d-----w- C:\Users\Jim\AppData\Local\{41124E82-350A-4C97-B96A-6A5FDBCCC7B0}

2012-06-15 10:21:36 -------- d-----w- C:\Users\Jim\AppData\Local\{036FE00A-0B93-493A-B8AD-468D73BCAA3A}

2012-06-14 22:21:10 -------- d-----w- C:\Users\Jim\AppData\Local\{92E29338-8DD9-473D-A726-D3BF3283807E}

2012-06-14 22:21:00 -------- d-----w- C:\Users\Jim\AppData\Local\{2A206F11-3D75-4E3F-941A-BF84B5E06D62}

2012-06-14 22:20:49 -------- d-----w- C:\Users\Jim\AppData\Local\{FFDF7FC4-545F-43C1-B949-B0CABB6B7B95}

2012-06-14 10:20:37 -------- d-----w- C:\Users\Jim\AppData\Local\{8A3472D1-8406-4372-8B03-4071C353ADA7}

2012-06-14 10:20:27 -------- d-----w- C:\Users\Jim\AppData\Local\{D032C956-0F0D-426C-BB08-F9FEB7A8122A}

2012-06-14 10:20:18 -------- d-----w- C:\Users\Jim\AppData\Local\{216E44BF-85FD-470C-A680-95444C56D4FE}

2012-06-14 10:20:07 -------- d-----w- C:\Users\Jim\AppData\Local\{F0E6876B-2987-400C-94E0-0B0F587D8249}

2012-06-13 22:18:44 -------- d-----w- C:\Users\Jim\AppData\Local\{AC47E3CB-F71E-4C85-A8AE-4174420A5CFE}

2012-06-13 22:18:34 -------- d-----w- C:\Users\Jim\AppData\Local\{9EA43A07-456B-409F-A841-34A8227E5F47}

2012-06-13 22:18:24 -------- d-----w- C:\Users\Jim\AppData\Local\{20255A2D-5D7A-4BE9-8DF1-FC7F8BCA6843}

2012-06-13 22:18:14 -------- d-----w- C:\Users\Jim\AppData\Local\{AC0ACD8C-6449-4672-8389-2981A1C70CF7}

2012-06-13 10:18:02 -------- d-----w- C:\Users\Jim\AppData\Local\{DD72D4E6-AA0C-437A-874C-9030AAEE0551}

2012-06-13 10:17:52 -------- d-----w- C:\Users\Jim\AppData\Local\{160C51AD-E48E-4D1D-903B-EA094597FE8E}

2012-06-13 10:17:42 -------- d-----w- C:\Users\Jim\AppData\Local\{0002B321-7BEA-4F1C-AF20-D25D7120CF7F}

2012-06-13 10:17:32 -------- d-----w- C:\Users\Jim\AppData\Local\{B4C174F8-6D90-4D29-9889-A88425F447E6}

2012-06-13 07:00:59 754808 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe

2012-06-12 22:17:07 -------- d-----w- C:\Users\Jim\AppData\Local\{3DF335C3-022C-4827-8348-3AEAB89F28F0}

2012-06-12 22:16:57 -------- d-----w- C:\Users\Jim\AppData\Local\{6243EE71-0B17-4D21-B7C0-DCB6F12CF8A0}

2012-06-12 22:16:47 -------- d-----w- C:\Users\Jim\AppData\Local\{4EFC2179-6A53-4437-8296-55382BFDD68B}

2012-06-12 22:16:37 -------- d-----w- C:\Users\Jim\AppData\Local\{D3C54576-77F5-422C-B87B-62A264E9050A}

2012-06-12 14:36:05 770384 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr100.dll

2012-06-12 14:36:05 421200 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp100.dll

2012-06-12 10:16:23 -------- d-----w- C:\Users\Jim\AppData\Local\{1554D5FE-322A-49AE-9D8A-A1DD53781F3E}

2012-06-12 10:16:13 -------- d-----w- C:\Users\Jim\AppData\Local\{02526C25-1FCE-4A71-BF44-6524FC1CDC9D}

2012-06-12 10:16:04 -------- d-----w- C:\Users\Jim\AppData\Local\{B5FBD0AB-313E-4FF5-B0A5-F951EA31800F}

2012-06-12 10:15:53 -------- d-----w- C:\Users\Jim\AppData\Local\{8C7DE440-80BA-4FF3-BFCB-17387D46FB54}

2012-06-11 22:15:40 -------- d-----w- C:\Users\Jim\AppData\Local\{42713BFE-C9F2-4B78-B6A8-A76F5CDE5ABD}

2012-06-11 22:15:30 -------- d-----w- C:\Users\Jim\AppData\Local\{35829E33-DA99-4CE6-B6D8-054C796D994E}

2012-06-11 22:15:21 -------- d-----w- C:\Users\Jim\AppData\Local\{1BAD6F56-62E2-473E-A24E-37E863960D6B}

2012-06-11 22:15:10 -------- d-----w- C:\Users\Jim\AppData\Local\{4FA93D46-F06D-480B-A499-2C16E3D9B80A}

2012-06-11 10:14:58 -------- d-----w- C:\Users\Jim\AppData\Local\{7A67DFF1-6606-4960-833F-37093453BCB4}

2012-06-11 10:14:48 -------- d-----w- C:\Users\Jim\AppData\Local\{17B8374A-0EF1-4F96-A188-36720B465FEB}

2012-06-11 10:14:39 -------- d-----w- C:\Users\Jim\AppData\Local\{9834E12C-E567-487D-9572-176118B24C85}

2012-06-11 10:14:29 -------- d-----w- C:\Users\Jim\AppData\Local\{FC3677F5-4AFA-44E1-8C18-5E5BA4E59C1F}

2012-06-10 22:14:17 -------- d-----w- C:\Users\Jim\AppData\Local\{D0EB6389-3B00-461B-86E9-1F92E21E44C6}

2012-06-10 22:14:07 -------- d-----w- C:\Users\Jim\AppData\Local\{638F8D31-064E-47F7-B529-A0F6E6409B02}

2012-06-10 22:13:57 -------- d-----w- C:\Users\Jim\AppData\Local\{F6C1513F-48CB-414A-8691-B4B6D3F8B07F}

2012-06-10 22:13:47 -------- d-----w- C:\Users\Jim\AppData\Local\{D007F00D-8FFC-4786-9B58-7D3EACDD0F20}

2012-06-10 10:13:35 -------- d-----w- C:\Users\Jim\AppData\Local\{D9EC099B-E8B2-4EA1-A0A0-C8D76F638048}

2012-06-10 10:13:25 -------- d-----w- C:\Users\Jim\AppData\Local\{6578F04E-4D78-49DE-9818-549246002E08}

2012-06-10 10:13:15 -------- d-----w- C:\Users\Jim\AppData\Local\{280302DF-5B80-4D48-8F56-D5D2F32E68F4}

2012-06-10 10:13:05 -------- d-----w- C:\Users\Jim\AppData\Local\{37D38E42-055F-4FB2-9A0F-FEE61EE37F4E}

.

==================== Find3M ====================

.

2012-07-02 17:25:19 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-21 20:45:13 87456 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll

2012-05-21 20:45:13 34688 ----a-w- C:\Windows\System32\LMIport.dll

2012-05-21 20:45:12 80768 ----a-w- C:\Windows\System32\LMIinit.dll

2012-05-18 02:06:48 2311680 ----a-w- C:\Windows\System32\jscript9.dll

2012-05-18 01:59:14 1392128 ----a-w- C:\Windows\System32\wininet.dll

2012-05-18 01:58:39 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2012-05-18 01:55:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2012-05-18 01:51:30 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2012-05-17 22:45:37 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll

2012-05-17 22:35:47 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2012-05-17 22:35:39 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2012-05-17 22:29:45 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2012-05-17 22:24:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2012-05-15 01:32:33 3146752 ----a-w- C:\Windows\System32\win32k.sys

2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe

2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll

2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys

2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll

2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll

2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe

2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll

2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll

2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll

2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll

2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll

2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll

.

============= FINISH: 21:04:16.37 ===============

Share this post


Link to post
Share on other sites

Hi,

Please go to VirusTotal, and upload the following file(s) for analysis:

c:\windows\System32\rundll32.exe

Post the results in your reply.

Also zip up that file and attach it to your reply.

Share this post


Link to post
Share on other sites

Having trouble posting results - when I copy/paste results it says I cannot use that image extension in this forum. Here is the zipped rundll32 file, and it shows 26 Devil, 36 Angel - Detection ratio 0/42

rundll32.zip

Share this post


Link to post
Share on other sites

Hi,

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1

Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :filefind
    rundll32.exe


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

Share this post


Link to post
Share on other sites

Here are the results...

SystemLook 30.07.11 by jpshortstuff

Log created at 22:16 on 09/07/2012 by Jim

Administrator - Elevation successful

WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.

========== filefind ==========

Searching for "rundll32.exe"

C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\rundll32.exe --a---- 199240 bytes [20:59 08/06/2012] [19:56 04/04/2012] 097D0E812D7A9A3101CE46CB2BE0474D

C:\Windows\System32\rundll32.exe --a---- 44544 bytes [23:41 13/07/2009] [01:14 14/07/2009] 51138BEEA3E2C21EC44D0932C71762A8

C:\Windows\SysWOW64\rundll32.exe --a---- 44544 bytes [23:41 13/07/2009] [01:14 14/07/2009] 51138BEEA3E2C21EC44D0932C71762A8

C:\Windows\winsxs\amd64_microsoft-windows-rundll32_31bf3856ad364e35_6.1.7600.16385_none_33fa4336c49b998b\rundll32.exe --a---- 45568 bytes [23:57 13/07/2009] [01:39 14/07/2009] DD81D91FF3B0763C392422865C9AC12E

C:\Windows\winsxs\x86_microsoft-windows-rundll32_31bf3856ad364e35_6.1.7600.16385_none_d7dba7b30c3e2855\rundll32.exe --a---- 44544 bytes [23:41 13/07/2009] [01:14 14/07/2009] 51138BEEA3E2C21EC44D0932C71762A8

-= EOF =-

Share this post


Link to post
Share on other sites

Hi,

Next, please open Notepad - don't use any other text editor than notepad or the script will fail.

Copy/paste the text in the quotebox below into Notepad:

KILLALL::

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"sdedro"=-

Save this as CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

CFScriptB-4.gif

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

-screen317

Share this post


Link to post
Share on other sites

Unfortunatly I have lost contact with this machine after dragging CFScript.txt onto the ComboFix application. The window popped up saying it was creating a restore point, then I was disonnected (I was remote controlling with LogMeIn). I will have to resume troubleshooting when I can get physically back to the machine tomorrow morning - about 8AM EST... Sorry. I hope someone will be available to resume troubleshooting this issue tomorrow.

Thanks for all your help so far... Not sure why ComboFix would have caused the machine to go permanently offline. All the other restarts did not cause an issue - I could just log back in after a couple of minutes...

- Mike

Share this post


Link to post
Share on other sites

ComboFix disconnects the computer from the Internet. Let me know when you're physically in front of it..

Share this post


Link to post
Share on other sites

Posting from another machine...

Caqn no longer launch browsers (or anything else) from infected machine. Last ComboFix generated a log but when I launched Firefox or Internet Explorer to post to this forum I get the following errors:

Illegal operation attempted on a registry key that has been marked for deletion (no choice but to click OK) then...

Can't open this item. It may have been moved, renamed or deleted. Do you want to remove this item? (Yes or No) - I chose No...

Any suggestions on what to do next?

Thanks!

- Mike

Share this post


Link to post
Share on other sites

OK - managed to get Firefox to launch by navigating to the app and running as administrator. Here is the result of the CFScript.txt dragged onto ComboFix.

I could not run DDS - get the error: "Illegal operation attempted on a registry key that has been marked for deletion"

ComboFix 12-07-08.03 - Jim 07/09/2012 22:35:13.2.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7935.6106 [GMT -4:00]

Running from: c:\users\Jim\Downloads\ComboFix.exe

Command switches used :: c:\users\Jim\Desktop\CFScript.txt

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

Y:\AUTORUN.INF

.

.

((((((((((((((((((((((((( Files Created from 2012-06-10 to 2012-07-10 )))))))))))))))))))))))))))))))

.

.

2012-07-10 02:41 . 2012-07-10 02:41 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp

2012-07-10 02:41 . 2012-07-10 02:41 -------- d-----w- c:\users\Karen\AppData\Local\temp

2012-07-10 02:41 . 2012-07-10 02:41 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-07-09 20:39 . 2011-04-20 07:07 1930240 ----a-w- c:\windows\system32\drivers\athurx.sys

2012-07-09 20:39 . 2011-04-20 07:07 1930240 ----a-w- c:\windows\system32\athurx.sys

2012-07-09 20:39 . 2012-07-09 20:39 -------- d-----w- c:\programdata\TP-LINK

2012-07-09 20:35 . 2012-07-09 20:35 -------- d-----w- c:\users\Jim\AppData\Local\{8BB253BD-CA05-11E1-8270-B8AC6F996F26}

2012-07-03 21:30 . 2012-07-03 21:30 1409 ----a-w- c:\windows\QTFont.for

2012-07-02 17:33 . 2012-07-02 17:33 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%

2012-07-02 17:25 . 2012-07-02 17:25 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-06-23 14:35 . 2012-05-25 21:09 29312 ----a-w- c:\program files (x86)\Mozilla Firefox\ScriptFF.dll

2012-06-22 14:01 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll

2012-06-22 14:01 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe

2012-06-22 14:01 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll

2012-06-22 14:01 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll

2012-06-22 14:01 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll

2012-06-22 14:01 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll

2012-06-22 14:01 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll

2012-06-22 14:01 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll

2012-06-22 14:01 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe

2012-06-13 07:00 . 2012-05-18 02:51 754808 ----a-w- c:\program files\Internet Explorer\iexplore.exe

2012-06-12 14:36 . 2012-06-12 14:36 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll

2012-06-12 14:36 . 2012-06-12 14:36 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-07-02 17:25 . 2011-06-13 13:20 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-21 20:45 . 2010-09-06 14:32 34688 ----a-w- c:\windows\system32\LMIport.dll

2012-05-21 20:45 . 2010-09-06 14:32 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll

2012-05-21 20:45 . 2010-09-06 14:32 80768 ----a-w- c:\windows\system32\LMIinit.dll

.

.

((((((((((((((((((((((((((((( SnapShot@2012-07-10_00.56.31 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-12-20 13:22 . 2012-07-10 11:47 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-12-20 13:22 . 2012-07-10 00:25 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-12-20 13:22 . 2012-07-10 11:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-12-20 13:22 . 2012-07-10 00:25 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2012-07-10 00:25 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:54 . 2012-07-10 11:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2012-07-10 11:47 . 2012-07-10 11:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2012-07-10 00:55 . 2012-07-10 00:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-10 11:47 . 2012-07-10 11:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-07-10 00:55 . 2012-07-10 00:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2009-07-14 04:54 . 2012-07-10 00:55 573440 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-07-14 04:54 . 2012-07-10 00:25 573440 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-12-22 11:49 . 2012-07-10 11:46 295722 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin

- 2009-07-14 02:36 . 2012-07-10 00:30 624162 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2012-07-10 01:00 624162 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2012-07-10 01:00 106538 c:\windows\system32\perfc009.dat

- 2009-07-14 02:36 . 2012-07-10 00:30 106538 c:\windows\system32\perfc009.dat

- 2009-07-14 04:54 . 2012-07-10 00:25 3719168 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-07-14 04:54 . 2012-07-10 00:55 3719168 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2012-07-10 00:25 16187392 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:54 . 2012-07-10 00:55 16187392 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DKab1err"="c:\program files\Dell\Printer Software\ErrorApp\DKab1err.exe" [2006-10-21 521112]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\vdeck.exe" [2009-06-01 2170880]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-06-15 98304]

"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]

"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]

"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-19 494064]

"DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]

"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118624]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]

"c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-09-25 560128]

.

c:\users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-02 257224]

R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.364.0\SeaPort.exe [2012-02-20 240408]

R3 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe [2006-10-21 476568]

R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]

R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-19 113120]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-22 1255736]

R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]

S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-06-15 203264]

S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.364.0\BBSvc.exe [2012-02-20 193816]

S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]

S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-05-21 375176]

S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2010-01-27 15928]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584]

S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-20 162192]

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856]

S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys [2011-04-20 1930240]

S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]

S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-11-17 294400]

S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-05-27 1206784]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - mfeavfk01

.

Contents of the 'Scheduled Tasks' folder

.

2012-07-10 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-02 17:25]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"VX3000"="c:\windows\vVX3000.exe" [2009-07-01 762224]

"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2010-01-27 57928]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://google.com/

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

FF - ProfilePath - c:\users\Jim\AppData\Roaming\Mozilla\Firefox\Profiles\wl7yj5l6.default\

FF - prefs.js: browser.search.selectedEngine - Secure Search

FF - prefs.js: browser.startup.homepage - google.com

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=

FF - user.js: yahoo.homepage.dontask - true

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,

0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70

"{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8,

89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b

"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,

1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7

"{27B4851A-3207-45A2-B947-BE8AFE6163AB}"=hex:51,66,7a,6c,4c,1d,38,12,74,86,a7,

23,35,7c,cc,00,c6,51,fd,ca,fb,3f,27,bf

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,

72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57

"{7DB2D5A0-7241-4E79-B68D-6309F01C5231}"=hex:51,66,7a,6c,4c,1d,38,12,ce,d6,a1,

79,73,3c,17,0b,c9,9b,20,49,f5,42,16,25

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,

9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d

"{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,

b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb

"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,

d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,

fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17

"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,

b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:cf,2b,8b,4c,82,58,cd,01

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\windows\SysWOW64\rundll32.exe

c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe

c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

c:\program files (x86)\Dell DataSafe Local Backup\Toaster.exe

c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe

.

**************************************************************************

.

Completion time: 2012-07-10 07:52:25 - machine was rebooted

ComboFix-quarantined-files.txt 2012-07-10 11:52

ComboFix2.txt 2012-07-10 01:01

.

Pre-Run: 658,104,496,128 bytes free

Post-Run: 658,063,884,288 bytes free

.

- - End Of File - - D7D930B04BF67FAC5C01E2EF97C23721

Share this post


Link to post
Share on other sites

Hi,

Simply reboot and that error will go away.

Can you zip up and attach this folder please; attach it here:

C:\Qoobox\Quarantine

Share this post


Link to post
Share on other sites

Hi,

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

Share this post


Link to post
Share on other sites

ESET Online Scanner detected 4 infected files - results below. Will make another post with results of Security Check shortly...

ESETSmartInstaller@High as CAB hook log:

OnlineScanner64.ocx - registred OK

OnlineScanner.ocx - registred OK

This was all that was in log.txt at Program Files(x86) ESET\ESET Online Scanner\

There was no directory called Eset Online Scanner in Program Files.

Unfortunately I closed the results window before searching for the log file, but 2 of the threats were Trojan.Dropper variants, one was a Java Exploit and I cannot remember the 3rd one...

Share this post


Link to post
Share on other sites

Security Check Log below...

Results of screen317's Security Check version 0.99.42

Windows 7 Service Pack 1 x64 (UAC is enabled)

Internet Explorer 9

``````````````Antivirus/Firewall Check:``````````````

Windows Firewall Enabled!

McAfee Anti-Virus and Anti-Spyware

WMI entry may not exist for antivirus; attempting automatic update.

`````````Anti-malware/Other Utilities Check:`````````

Malwarebytes Anti-Malware version 1.61.0.1400

Java 6 Update 30

Java version out of Date!

Adobe Flash Player 10 Flash Player out of Date!

Adobe Reader 9 Adobe Reader out of Date!

Mozilla Firefox (13.0.1)

````````Process Check: objlist.exe by Laurent````````

Malwarebytes Anti-Malware mbamservice.exe

Malwarebytes Anti-Malware mbamgui.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C: 0%

````````````````````End of Log``````````````````````

Share this post


Link to post
Share on other sites

Hi,

Run TFC by OldTimer to clear temporary files:

  • Please download TFC from here and save it to your desktop.
  • Close any open programs and Internet browsers.
  • Double click TFC.exe to run it and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning.
  • Please be patient as clearing out temp files may take a while.
  • Once it completes you may be prompted to restart your computer, please do so.
  • Once it's finished you may delete TFC.exe from your Desktop or save it for later use for the cleaning of temporary files.

Navigate to Start --> Run, and type Combofix /uninstall in the box that appears. Click OK afterward. Notice the space between the X and the /uninstall

This uninstalls all of ComboFix's components.

Delete SecurityCheck.

After that, navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following program (if present):

Java™ 6 Update 30

Adobe Flash Player 10

Adobe Reader 9

Restart your computer.

Get the latest version of Java, Adobe Reader, and Adobe Flash Player.

Reboot.

Let me know what issues remain.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.