About 3-5 days ago I noticed that spam was being sent from my email. It was also around this time when I noticed that the startup times on my computer had gotten slower. I ran a scan using Avast! and managed to remove some malware. I also scanned with Malwarebytes Anti-Malware and it couldn't find anything. However the startup times are still long so I suspect that my desktop could still be infected.
I have pasted/attached the requested logs below. Any assistance would be greatly appreicated. Thanks.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1
Run by Jason at 12:56:13 on 2012-07-29
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.61.1033.18.4094.1981 [GMT 10:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k regsvc
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\conime.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [AdobeBridge]
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
mRun: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
LSP: C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - hxxp://nxcache.nexon.net/mabinogi/renderer/mabiweb.2010.5.03.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab
TCP: Interfaces\{BF14688D-ABC9-4D80-8AEA-06B481F015F3} : NameServer = 10.11.12.1,212.159.11.150
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB-X64: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - No File
mRun-x64: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun-x64: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
mRun-x64: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
AppInit_DLLs-X64: C:\Windows\SysWOW64\guard32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\siuio95h.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com/
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\Users\Jason\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-5-12 44808]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-6-29 1262912]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-4-4 382272]
R2 vmci;VMware vmci;\??\C:\Windows\system32\drivers\vmci.sys --> C:\Windows\system32\drivers\vmci.sys [?]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2010-1-22 563760]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [2009-6-26 119296]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 GEST Service;GEST Service for program management.;C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe [2009-2-12 68136]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-6-9 136176]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-6-7 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-9 250056]
S3 CamDrL64;Logitech QuickCam Pro 3000(PID_08B0);C:\Windows\system32\DRIVERS\CamDrL64.sys --> C:\Windows\system32\DRIVERS\CamDrL64.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;E:\Dragon Age\bin_ship\daupdatersvc.service.exe [2009-12-16 25832]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-2-14 1038088]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-6-9 136176]
S3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\system32\DRIVERS\LVUSBS64.sys --> C:\Windows\system32\DRIVERS\LVUSBS64.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-27 113120]
S3 nmwcdcx64;Nokia USB Generic;C:\Windows\system32\drivers\ccdcmbox64.sys --> C:\Windows\system32\drivers\ccdcmbox64.sys [?]
S3 nmwcdx64;Nokia USB Phone Parent;C:\Windows\system32\drivers\ccdcmbx64.sys --> C:\Windows\system32\drivers\ccdcmbx64.sys [?]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-21 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-12-4 89920]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-07-29 02:17:20 -------- d-----w- C:\ProgramData\Comodo
2012-07-29 02:17:05 -------- d-----w- C:\Program Files\COMODO
2012-07-29 01:06:06 -------- d-----w- C:\Users\Jason\AppData\Local\{8C330598-BC7E-47F3-AE5B-524207B2969F}
2012-07-29 01:05:56 -------- d-----w- C:\Users\Jason\AppData\Local\{A0F58596-64FD-47ED-8E1D-F48A028D45F7}
2012-07-28 04:00:02 -------- d-----w- C:\Users\Jason\AppData\Local\{AB672EE9-66E7-441D-956F-4CDC9C1DEDF1}
2012-07-28 03:59:51 -------- d-----w- C:\Users\Jason\AppData\Local\{DF3A5DA8-0F07-4C0D-A869-22ECFDCA8C4A}
2012-07-27 08:20:55 9133488 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6261DEF6-F7DC-4624-A1E5-CA0D66C2ACCB}\mpengine.dll
2012-07-27 08:16:36 -------- d-----w- C:\Users\Jason\AppData\Local\{8B687A59-4643-4D23-819D-F961243F3853}
2012-07-27 08:16:24 -------- d-----w- C:\Users\Jason\AppData\Local\{5A110C1A-9672-460F-A83D-E7966DFF8AFF}
2012-07-26 08:19:32 -------- d-----w- C:\Users\Jason\AppData\Local\{164D58B2-BC54-479E-ACCF-87E82FE68233}
2012-07-26 08:19:21 -------- d-----w- C:\Users\Jason\AppData\Local\{AC9CD2BD-74B9-44BF-BC32-68576A76D742}
2012-07-25 08:17:44 -------- d-----w- C:\Users\Jason\AppData\Local\{210936BD-BC52-465B-A90A-1BF8C3B879E2}
2012-07-25 08:17:32 -------- d-----w- C:\Users\Jason\AppData\Local\{B939E1AF-AF91-4298-897A-269A81205482}
2012-07-24 07:17:50 -------- d-----w- C:\Users\Jason\AppData\Local\{BDFF1358-CCE0-4938-A912-D1CD635E7BA9}
2012-07-24 07:17:39 -------- d-----w- C:\Users\Jason\AppData\Local\{BFED695D-AE3D-4AD2-BA0D-D3B27BB2541B}
2012-07-23 08:04:55 -------- d-----w- C:\Users\Jason\AppData\Local\{4794B32C-3191-4234-AC14-BB6D86D2B413}
2012-07-23 08:04:43 -------- d-----w- C:\Users\Jason\AppData\Local\{346C7DC2-8776-41A4-9DCE-C6746A334424}
2012-07-22 12:09:43 -------- d-----w- C:\Users\Jason\AppData\Local\{74FD8E43-D293-4BC7-A161-A90994EA1765}
2012-07-22 12:09:31 -------- d-----w- C:\Users\Jason\AppData\Local\{49609040-5864-4165-B6A0-319570C9A1F7}
2012-07-22 00:09:15 -------- d-----w- C:\Users\Jason\AppData\Local\{1226F52D-8988-478A-9059-27F5788906A8}
2012-07-22 00:08:58 -------- d-----w- C:\Users\Jason\AppData\Local\{8B7D702C-60A4-42F5-8E9C-F1B1C4BBD946}
2012-07-21 00:46:44 -------- d-----w- C:\Users\Jason\AppData\Local\{11D25D1C-B1E4-4E7E-AE44-66F2D503510D}
2012-07-21 00:46:33 -------- d-----w- C:\Users\Jason\AppData\Local\{0AD4A4E8-57B0-4D15-AD76-E8B592E93351}
2012-07-20 12:46:06 -------- d-----w- C:\Users\Jason\AppData\Local\{66B9B3A7-AE0D-4210-8186-285BFCD04CA4}
2012-07-20 12:45:53 -------- d-----w- C:\Users\Jason\AppData\Local\{FA97AA3B-EA8D-4BAC-95E2-E0D88DD7CCC9}
2012-07-20 00:45:38 -------- d-----w- C:\Users\Jason\AppData\Local\{4F54C401-62CD-44C8-9CFB-9B64DB897A34}
2012-07-20 00:45:26 -------- d-----w- C:\Users\Jason\AppData\Local\{4B2D5DD4-2595-463C-BDFB-8283354FCCF4}
2012-07-19 07:27:50 -------- d-----w- C:\Users\Jason\AppData\Local\{F71A8E0B-6A10-44F8-90C9-6E0684965488}
2012-07-19 07:27:39 -------- d-----w- C:\Users\Jason\AppData\Local\{C038F7E5-9130-49F9-9E1A-59407A937D13}
2012-07-18 08:59:40 -------- d-----w- C:\Users\Jason\AppData\Local\{4D9F6DD6-8A84-4032-9C07-88E3B33AFD26}
2012-07-18 08:59:17 -------- d-----w- C:\Users\Jason\AppData\Local\{F3840ABA-104A-4253-9F68-E5EE0F6A5248}
2012-07-17 10:01:44 -------- d-----w- C:\Users\Jason\AppData\Local\{F9D78697-F7C1-4F06-9051-9352CE5EC6BB}
2012-07-17 10:01:31 -------- d-----w- C:\Users\Jason\AppData\Local\{066A8974-3AA8-4C1C-BCE2-8DDD5A51DD3A}
2012-07-16 22:01:19 -------- d-----w- C:\Users\Jason\AppData\Local\{95F9BDB5-1FD5-4176-8C80-008085E86076}
2012-07-16 22:01:06 -------- d-----w- C:\Users\Jason\AppData\Local\{23159FEA-4F9D-4A0A-9DD8-6F2289264531}
2012-07-16 10:00:41 -------- d-----w- C:\Users\Jason\AppData\Local\{6F487267-B0F3-43B9-9606-3451C8049FEA}
2012-07-16 10:00:29 -------- d-----w- C:\Users\Jason\AppData\Local\{DBD701A7-BCA7-4E27-A511-5D5EBB749BAE}
2012-07-15 12:48:26 -------- d-----w- C:\Users\Jason\AppData\Local\{A4F4232A-6E8F-42FF-8205-7F5BB81A2B9E}
2012-07-15 12:48:13 -------- d-----w- C:\Users\Jason\AppData\Local\{D27B5768-52AF-4F85-95E6-5A229C699073}
2012-07-15 00:48:00 -------- d-----w- C:\Users\Jason\AppData\Local\{410DBC27-E598-4699-B496-94A051AABC41}
2012-07-15 00:47:49 -------- d-----w- C:\Users\Jason\AppData\Local\{C97D79CF-75AC-48AB-AD14-CA0795482715}
2012-07-14 12:47:24 -------- d-----w- C:\Users\Jason\AppData\Local\{3A23E1C7-D2FE-489A-9020-E899CA6F1DAA}
2012-07-14 12:47:13 -------- d-----w- C:\Users\Jason\AppData\Local\{BD4E662A-1A69-48CF-B7C4-EF94A67680DD}
2012-07-14 00:53:40 -------- d-----w- C:\Program Files (x86)\Microsoft XNA
2012-07-14 00:46:40 -------- d-----w- C:\Users\Jason\AppData\Local\{4A183CCC-1212-4249-B426-3DE416C1D0CE}
2012-07-14 00:46:29 -------- d-----w- C:\Users\Jason\AppData\Local\{1BC7E56B-79CF-4D90-BA14-604C0DDC2B49}
2012-07-13 09:00:57 -------- d-----w- C:\Users\Jason\AppData\Local\{5F60908C-A75C-4F26-86A7-C49DFA18061E}
2012-07-13 09:00:45 -------- d-----w- C:\Users\Jason\AppData\Local\{7D09ECF8-FEA4-4772-9704-E32E55CDBFCD}
2012-07-12 09:34:34 2769408 ----a-w- C:\Windows\System32\win32k.sys
2012-07-12 08:52:58 974848 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2012-07-12 08:52:56 708608 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2012-07-12 08:52:22 1797120 ----a-w- C:\Windows\System32\msxml6.dll
2012-07-12 08:52:21 1869824 ----a-w- C:\Windows\System32\msxml3.dll
2012-07-12 08:52:21 1401856 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-07-12 08:52:21 1248768 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-07-12 08:51:48 516480 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-07-12 08:51:48 347136 ----a-w- C:\Windows\System32\schannel.dll
2012-07-12 08:51:48 278528 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-07-12 08:51:48 254464 ----a-w- C:\Windows\System32\ncrypt.dll
2012-07-12 08:51:48 204288 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-07-12 08:51:47 77312 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-07-12 08:42:56 -------- d-----w- C:\Users\Jason\AppData\Local\{127915E5-9F1F-4E3C-879C-7419C59CB0F6}
2012-07-12 08:42:43 -------- d-----w- C:\Users\Jason\AppData\Local\{8FBC14BC-B5AE-4C86-B5CF-9D8242008091}
2012-07-11 11:43:28 -------- d-----w- C:\Users\Jason\AppData\Local\{C1ED80A8-FF5A-4D0C-97F4-DE53D7FD842B}
2012-07-11 11:43:17 -------- d-----w- C:\Users\Jason\AppData\Local\{8354C3D3-46BA-4779-BEE0-D1F6FA9789EA}
2012-07-10 10:21:07 -------- d-----w- C:\af3e8974be320ed59df12484a71aa964
2012-07-10 10:15:39 -------- d-----w- C:\Users\Jason\AppData\Local\{596D0C97-672B-439C-8414-6996877B48F2}
2012-07-10 10:15:28 -------- d-----w- C:\Users\Jason\AppData\Local\{04585D03-5FBD-46DE-B8A7-D9D236589791}
2012-07-09 11:00:31 -------- d-----w- C:\Users\Jason\AppData\Local\{05A89411-1A35-49F8-8A79-418EACEA7F30}
2012-07-09 11:00:20 -------- d-----w- C:\Users\Jason\AppData\Local\{7CCA2F3D-DC3F-4C5D-AFF8-741152FE2A13}
2012-07-08 11:35:47 -------- d-----w- C:\Users\Jason\AppData\Local\{3CD08E61-5AE1-48A5-94EC-4C4F8AAFEF1D}
2012-07-08 11:35:35 -------- d-----w- C:\Users\Jason\AppData\Local\{C571DEA5-9D9A-4B44-A1A6-BA6DC06AFBF5}
2012-07-08 04:16:17 -------- d-----w- C:\Users\Jason\AppData\Local\etax2012
2012-07-08 04:14:57 -------- d-----w- C:\Program Files (x86)\etax2012
2012-07-07 23:35:23 -------- d-----w- C:\Users\Jason\AppData\Local\{F2D9691E-F109-4232-B14D-EAA0F3F351B0}
2012-07-07 23:35:11 -------- d-----w- C:\Users\Jason\AppData\Local\{29B3EC29-635B-4E79-93F8-5A36816C13CF}
2012-07-07 02:12:30 -------- d-----w- C:\Users\Jason\AppData\Local\{92B16EF3-E38B-44F4-BA67-8FFB9B82C04C}
2012-07-07 02:12:10 -------- d-----w- C:\Users\Jason\AppData\Local\{BA5E4680-424D-4D0A-B50C-855D3566148C}
2012-07-06 09:59:35 -------- d-----w- C:\Users\Jason\AppData\Local\{5AEDA521-195E-411C-A69E-BA6BC93E04DF}
2012-07-06 09:59:23 -------- d-----w- C:\Users\Jason\AppData\Local\{EA7A2900-E38E-4E90-8ED1-00F66F5FEA7D}
2012-07-05 10:00:39 -------- d-----w- C:\Users\Jason\AppData\Local\{5E353423-7E25-47D6-91F5-3F2EF14768E2}
2012-07-05 10:00:28 -------- d-----w- C:\Users\Jason\AppData\Local\{3E1BE410-A396-46F3-806D-1F0E048A4E35}
2012-07-04 08:57:19 -------- d-----w- C:\Users\Jason\AppData\Local\{F01E0919-CDF9-4A0B-A676-97892A844C2D}
2012-07-04 08:57:02 -------- d-----w- C:\Users\Jason\AppData\Local\{84CDA704-C789-4843-9689-C0C0B9408EE3}
2012-07-03 09:29:02 -------- d-----w- C:\Users\Jason\AppData\Local\{0EF56292-BEEB-487B-929D-0CCFA3C62C14}
2012-07-03 09:28:51 -------- d-----w- C:\Users\Jason\AppData\Local\{BE94AFDC-F339-41C1-AF50-D08605A8C014}
2012-07-02 09:31:56 -------- d-----w- C:\Users\Jason\AppData\Local\{C583E280-497F-46C7-A527-90F86A39DAFC}
2012-07-02 09:31:42 -------- d-----w- C:\Users\Jason\AppData\Local\{C3568691-FDF0-4896-9B19-5F7A5BB8C71C}
2012-07-01 01:07:37 -------- d-----w- C:\Users\Jason\AppData\Local\{4966E160-0AEC-4124-9A00-4A0E414F5165}
2012-07-01 01:07:25 -------- d-----w- C:\Users\Jason\AppData\Local\{0E3CBCBA-B30B-481B-9823-44903190A2D3}
2012-06-30 11:37:55 -------- d-----w- C:\Users\Jason\AppData\Local\{2C6E00FF-4863-4359-A626-F223F2667634}
2012-06-30 11:37:44 -------- d-----w- C:\Users\Jason\AppData\Local\{5DB5994A-AB24-43EC-B0A8-C0B6450D2329}
2012-06-29 23:37:03 -------- d-----w- C:\Users\Jason\AppData\Local\{F357AD00-C196-4E7F-8EC5-85086563EA8F}
2012-06-29 23:36:51 -------- d-----w- C:\Users\Jason\AppData\Local\{66AD6E9F-BDC8-4A0D-9F20-D780FB1484FF}
2012-06-29 09:56:18 889664 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-06-29 09:56:18 63296 ----a-w- C:\Windows\System32\nvshext.dll
2012-06-29 09:56:18 3149632 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-06-29 09:56:17 6122816 ----a-w- C:\Windows\System32\nvcpl.dll
2012-06-29 09:56:17 118080 ----a-w- C:\Windows\System32\nvmctray.dll
2012-06-29 09:54:38 68928 ----a-w- C:\Windows\System32\OpenCL.dll
2012-06-29 09:54:38 61248 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2012-06-29 09:54:27 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2012-06-29 09:48:56 -------- d-----w- C:\Users\Jason\AppData\Local\{15FC832F-5433-4127-BECB-9D45440F5877}
2012-06-29 09:48:26 -------- d-----w- C:\Users\Jason\AppData\Local\{4338123B-817E-4A2D-A2D7-7CDD7E8BF197}
.
==================== Find3M ====================
.
2012-07-29 02:23:19 24072 ----a-w- C:\Windows\gdrv.sys
2012-07-27 13:17:43 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-27 13:17:43 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-03 16:21:52 958400 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2012-07-03 16:21:52 71064 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-07-03 16:21:32 41224 ----a-w- C:\Windows\avastSS.scr
2012-07-03 03:46:44 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-30 05:17:38 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2012-06-30 05:17:38 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 22:12:13 88576 ----a-w- C:\Windows\SysWow64\wudriver.dll
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 05:19:42 171904 ----a-w- C:\Windows\SysWow64\wuwebv.dll
2012-06-02 05:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 05:12:20 33792 ----a-w- C:\Windows\SysWow64\wuapp.exe
2012-05-31 02:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-05-01 14:29:44 209920 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
.
============= FINISH: 12:56:56.34 ===============

Sign In
Create Account
This topic is locked

Back to top

















