Downloaded the "free youtube downloader" from cnet and now this buzqo keeps messing with my search engine in google chrome, firefox, and IE. I've tried kaspersky, malware removal, etc.
Please help!
Let me know if you need any more information!
Thank you!
-Jim
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385
Run by [removed] at 19:39:23 on 2011-12-16
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3894.1138 [GMT -5:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\Alienware\Command Center\AlienFusionService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Alienware\Command Center\AlienSense\FATrayAlert.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe
C:\Program Files\Alienware\Command Center\AlienFXHook64Mngr.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Alienware\Command Center\AlienFusionController.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbengine.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = www.dell.com
uInternet Settings,ProxyOverride = *.local;192.168.*.*
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: SSOIEAddonBHO Class: {da5bce70-d057-4d63-943d-5f3927ec59f1} - C:\Program Files\Alienware\Command Center\AlienSense\FAIESSO.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [Google Update] "C:\Users\Rawr\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Facebook Update] "C:\Users\Rawr\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
mRun: [FAStartup]
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\Rawr\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PDANET~1.LNK - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/s ... wflash.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{BDA2A005-4FD8-42A5-8EA2-DC61D538BF1B} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{BDA2A005-4FD8-42A5-8EA2-DC61D538BF1B}\038364850343030373237333 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{BDA2A005-4FD8-42A5-8EA2-DC61D538BF1B}\2496E676 : DhcpNameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{E6EADE37-256F-48C3-BF90-316EDC3C857E} : DhcpNameServer = [removed] [removed]
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO-X64: IEVkbdBHO - No File
BHO-X64: StartNow Toolbar Helper: {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
BHO-X64: StartNow Toolbar Helper - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: SSOIEAddonBHO Class: {DA5BCE70-D057-4D63-943D-5F3927EC59F1} - C:\Program Files\Alienware\Command Center\AlienSense\FAIESSO.dll
BHO-X64: SSOIEAddonBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
BHO-X64: link filter bho - No File
TB-X64: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun-x64: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
mRun-x64: [FAStartup]
mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce-x64: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R0 EMSC;COMPAL Embedded System Control;C:\Windows\System32\drivers\EMSC.sys [2009-6-26 13680]
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-3-22 98208]
R2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2010-5-21 14648]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-2 365336]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2011-5-27 166400]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2011-5-27 128512]
R2 FAService;FAService;C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe [2010-4-4 2409800]
R2 MotoHelper;MotoHelper Service;C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2011-8-10 227184]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-4-4 1997416]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-3-17 378984]
R2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [2011-5-20 210144]
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys --> C:\Windows\system32\DRIVERS\Accelern.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 DAdderFltr;DeathAdder Mouse;C:\Windows\system32\drivers\dadder.sys --> C:\Windows\system32\drivers\dadder.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 pneteth;PdaNet Broadband;C:\Windows\system32\DRIVERS\pneteth.sys --> C:\Windows\system32\DRIVERS\pneteth.sys [?]
S0 johci;JMicron 1394 Filter Driver;C:\Windows\system32\DRIVERS\johci.sys --> C:\Windows\system32\DRIVERS\johci.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-6-29 136176]
S3 BTCFilterService;USB Networking Driver Filter Service;C:\Windows\system32\DRIVERS\motfilt.sys --> C:\Windows\system32\DRIVERS\motfilt.sys [?]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-6-29 136176]
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
S3 motandroidusb;Mot ADB Interface Driver;C:\Windows\system32\Drivers\motoandroid.sys --> C:\Windows\system32\Drivers\motoandroid.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\system32\DRIVERS\motccgp.sys --> C:\Windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;C:\Windows\system32\DRIVERS\motccgpfl.sys --> C:\Windows\system32\DRIVERS\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;C:\Windows\system32\DRIVERS\motodrv.sys --> C:\Windows\system32\DRIVERS\motodrv.sys [?]
S3 Motousbnet;Motorola USB Networking Driver Service;C:\Windows\system32\DRIVERS\Motousbnet.sys --> C:\Windows\system32\DRIVERS\Motousbnet.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-12-17 00:26:57 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-12-17 00:26:41 -------- d-----w- C:\Users\Rawr\AppData\Roaming\Malwarebytes
2011-12-17 00:26:22 -------- d-----w- C:\ProgramData\Malwarebytes
2011-12-17 00:26:18 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-17 00:26:17 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-16 18:15:55 -------- d-----w- C:\Users\Rawr\AppData\Local\{D10C53F2-357D-4918-8817-3D3FD9DB38AC}
2011-12-16 18:15:45 -------- d-----w- C:\Users\Rawr\AppData\Local\{1DC551F0-326D-4A7D-B040-65CEF2E2F401}
2011-12-16 06:51:26 -------- d-----w- C:\Program Files (x86)\Free YouTube Downloader
2011-12-16 06:25:43 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA8D278A-6CA0-4DFA-AA95-BC9DFBA54C71}\mpengine.dll
2011-12-16 06:25:43 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA8D278A-6CA0-4DFA-AA95-BC9DFBA54C71}\offreg.dll
2011-12-16 06:15:21 -------- d-----w- C:\Users\Rawr\AppData\Local\{8A171006-56A2-4230-AF00-B923B740EF93}
2011-12-15 12:09:09 -------- d-----w- C:\Users\Rawr\AppData\Local\{4DBBF984-B48A-4FD6-BD75-ABAC297E62E4}
2011-12-15 12:08:59 -------- d-----w- C:\Users\Rawr\AppData\Local\{84F065AD-9C01-4763-B4A0-C41BC606C4F8}
2011-12-15 04:26:57 3141632 ----a-w- C:\Windows\System32\win32k.sys
2011-12-15 04:26:55 723456 ----a-w- C:\Windows\System32\EncDec.dll
2011-12-15 04:26:55 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-15 04:26:51 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-12-15 04:26:51 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-12-14 22:54:28 -------- d-----w- C:\Users\Rawr\AppData\Local\{5960A182-D553-42FE-8206-C753A38BDBE5}
2011-12-14 22:54:18 -------- d-----w- C:\Users\Rawr\AppData\Local\{39C0458F-F23B-44D1-8C35-BBFB4F79A5D5}
2011-12-14 05:50:47 -------- d-----w- C:\Users\Rawr\AppData\Local\{20702A78-74B7-4AC6-BD64-C21B344A747C}
2011-12-14 05:50:37 -------- d-----w- C:\Users\Rawr\AppData\Local\{61BC73B9-FFEE-470B-850A-7246C27BAD7E}
2011-12-13 23:43:05 -------- d-----w- C:\Users\Rawr\AppData\Roaming\mIRC
2011-12-13 23:43:05 -------- d-----w- C:\Program Files (x86)\mIRC
2011-12-13 05:17:10 -------- d-----w- C:\Users\Rawr\AppData\Local\{CB040899-3864-4813-8BF2-56F7D1F9FC9C}
2011-12-13 05:17:01 -------- d-----w- C:\Users\Rawr\AppData\Local\{8899484D-A67E-4B3E-9CD6-09EF8E2C5990}
2011-12-12 22:44:40 -------- d-----w- C:\Program Files (x86)\StartNow Toolbar
2011-12-12 22:43:51 -------- d-----w- C:\Users\Rawr\AppData\Local\TempDIR
2011-12-12 17:16:35 -------- d-----w- C:\Users\Rawr\AppData\Local\{59ED4CEE-4042-4AD8-9BF9-C599DF62B320}
2011-12-12 17:16:25 -------- d-----w- C:\Users\Rawr\AppData\Local\{25C4E587-B47B-4C72-A761-E1BFBC019C9E}
2011-12-11 20:15:08 -------- d-----w- C:\Users\Rawr\AppData\Local\{F62AFFF7-6F04-4BB5-9298-BDAAEE946CC2}
2011-12-11 20:14:58 -------- d-----w- C:\Users\Rawr\AppData\Local\{5B4DD06C-7D49-4B42-95A0-95CEDC26DB5F}
2011-12-11 08:14:32 -------- d-----w- C:\Users\Rawr\AppData\Local\{8895B98A-6CDD-41B7-9901-84F4DF61C98F}
2011-12-10 20:59:26 -------- d-----w- C:\Windows\SysWow64\aliedit
2011-12-10 20:59:17 -------- d-----w- C:\Program Files (x86)\Trademanager
2011-12-10 20:56:09 -------- d-----w- C:\Users\Rawr\AppData\Local\Alibaba
2011-12-10 20:14:06 -------- d-----w- C:\Users\Rawr\AppData\Local\{23B0B1A4-0095-423E-96DD-12BA735096BB}
2011-12-10 20:13:54 -------- d-----w- C:\Users\Rawr\AppData\Local\{AEC09A48-D433-4130-95FC-B99ABE1A576A}
2011-12-09 22:40:51 -------- d-----w- C:\Users\Rawr\AppData\Local\{D9B02C0F-3ED4-4FCA-9264-939E1ACD1A94}
2011-12-09 22:40:39 -------- d-----w- C:\Users\Rawr\AppData\Local\{37D85586-E3D8-4164-97B7-2BD5F502B5F1}
2011-12-09 03:04:50 -------- d-----w- C:\Users\Rawr\AppData\Local\{6CCC16ED-FFD3-41F8-937C-F49C93B04B7E}
2011-12-09 03:04:40 -------- d-----w- C:\Users\Rawr\AppData\Local\{BF578B44-B6FD-4577-B7EE-734B770AB356}
2011-12-07 18:36:40 -------- d-----w- C:\Users\Rawr\AppData\Local\{1AA95B1B-D7A6-49FE-AD04-87CAD513824B}
2011-12-07 18:36:30 -------- d-----w- C:\Users\Rawr\AppData\Local\{3FB90128-5DEC-4E04-A531-A2450F41B079}
2011-12-07 02:10:08 -------- d-----r- C:\Program Files (x86)\Skype
2011-12-06 23:47:00 -------- d-----w- C:\Users\Rawr\AppData\Local\{FED9ACC0-27ED-41E3-90D3-83C25E96A8CD}
2011-12-06 23:46:50 -------- d-----w- C:\Users\Rawr\AppData\Local\{83828103-7123-40ED-9A01-FB4D485D9679}
2011-12-06 11:46:22 -------- d-----w- C:\Users\Rawr\AppData\Local\{45B189D3-C6B5-45FA-90D9-ACBDF2FE1134}
2011-12-06 11:46:07 -------- d-----w- C:\Users\Rawr\AppData\Local\{B841B295-5F8C-4AC6-ACE3-582F1A365ED6}
2011-12-05 16:57:30 -------- d-----w- C:\Users\Rawr\AppData\Local\{655529BA-01EE-4CA9-8091-F5078DA47BB0}
2011-12-05 16:57:19 -------- d-----w- C:\Users\Rawr\AppData\Local\{18C65620-90FA-4918-A126-90265C5CD2ED}
2011-12-04 04:41:12 -------- d-----w- C:\Users\Rawr\AppData\Local\{FFF4A02A-71A7-472C-A833-0B869A85B39D}
2011-12-04 04:41:00 -------- d-----w- C:\Users\Rawr\AppData\Local\{92461499-E83E-4D14-9E59-2542B980121F}
2011-12-03 16:40:29 -------- d-----w- C:\Users\Rawr\AppData\Local\{9413723E-520C-473F-979B-10ADC67FBFC1}
2011-12-03 16:40:18 -------- d-----w- C:\Users\Rawr\AppData\Local\{5152B4D0-D313-48A7-B3DA-8A5461596E65}
2011-12-02 00:11:55 -------- d-----w- C:\Users\Rawr\AppData\Local\{9AC79F06-A576-46B3-8DF2-C9290CC77937}
2011-12-02 00:11:45 -------- d-----w- C:\Users\Rawr\AppData\Local\{36CA4DBE-5209-4E68-B399-AC5AFEF8853C}
2011-11-30 19:51:00 -------- d-----w- C:\Users\Rawr\AppData\Local\{A80153E0-3033-43CD-92B7-4F96F3DE6B5D}
2011-11-30 19:50:50 -------- d-----w- C:\Users\Rawr\AppData\Local\{679F18A5-D1CA-4287-A9AE-9DC9EAFC07EB}
2011-11-30 07:50:25 -------- d-----w- C:\Users\Rawr\AppData\Local\{F9DBD983-7D43-45D6-B370-FD10736C2D1C}
2011-11-29 19:50:02 -------- d-----w- C:\Users\Rawr\AppData\Local\{FDEE681A-D0C1-41E4-88C1-271F730CA6C5}
2011-11-29 19:49:52 -------- d-----w- C:\Users\Rawr\AppData\Local\{E17CC0A7-D817-43EC-8E80-97CE779894AA}
2011-11-29 04:34:48 -------- d-----w- C:\Users\Rawr\AppData\Local\{53E2EE5A-96F2-4D9D-924C-D9D3CF9DAEEC}
2011-11-29 04:34:38 -------- d-----w- C:\Users\Rawr\AppData\Local\{576D266C-40A0-4AE2-9F8F-49D77AED86F5}
2011-11-28 07:09:26 -------- d-----w- C:\Users\Rawr\AppData\Local\{EAF19100-C236-4CB5-99FF-430A3D8CB4BB}
2011-11-28 07:09:14 -------- d-----w- C:\Users\Rawr\AppData\Local\{B50C8C63-227E-4940-BA92-322837D1075E}
2011-11-27 19:08:49 -------- d-----w- C:\Users\Rawr\AppData\Local\{023E165A-753F-41CA-8397-4D099D986DEF}
2011-11-27 19:08:39 -------- d-----w- C:\Users\Rawr\AppData\Local\{83FD9828-3ED7-4969-B0C2-41B84204FF9E}
2011-11-25 07:57:21 -------- d-----w- C:\Users\Rawr\AppData\Local\{3AB6BB62-BFB8-461F-9636-A1C9EBFA2F86}
2011-11-25 07:57:05 -------- d-----w- C:\Users\Rawr\AppData\Local\{36FE037D-04BC-4593-85BE-339EB99E73B8}
2011-11-22 18:38:39 -------- d-----w- C:\Users\Rawr\AppData\Local\{08ABCF46-CC68-463E-95C5-4E99DA68AB43}
2011-11-22 18:38:29 -------- d-----w- C:\Users\Rawr\AppData\Local\{8468E2D7-313C-40A4-9AAD-E87F3DAA2FE4}
2011-11-22 07:54:21 -------- d-----w- C:\Users\Rawr\AppData\Local\Chromium
2011-11-19 03:28:15 -------- d-----w- C:\Users\Rawr\AppData\Local\{2036E232-B515-4329-BF9B-44094B5930AB}
2011-11-19 03:28:05 -------- d-----w- C:\Users\Rawr\AppData\Local\{508467E1-115E-4B6B-9C25-DF5FD49388AC}
2011-11-18 15:27:53 -------- d-----w- C:\Users\Rawr\AppData\Local\{20CE0B3E-6843-4901-A6D1-604D7CA38047}
2011-11-18 15:27:43 -------- d-----w- C:\Users\Rawr\AppData\Local\{0B07017F-A0E2-49A9-93DD-2F1AC75509B4}
2011-11-18 03:27:31 -------- d-----w- C:\Users\Rawr\AppData\Local\{03695703-568E-4AAA-A474-12D7E7316796}
2011-11-18 03:27:21 -------- d-----w- C:\Users\Rawr\AppData\Local\{5F72E6CE-67CA-44DF-B51D-5DED110BB5EA}
2011-11-17 15:27:09 -------- d-----w- C:\Users\Rawr\AppData\Local\{4A54C7C8-9A1C-4B74-824E-95A693EA7C4A}
2011-11-17 03:26:46 -------- d-----w- C:\Users\Rawr\AppData\Local\{422D039F-9991-4C6B-875B-4673BC9A4C67}
2011-11-17 03:26:36 -------- d-----w- C:\Users\Rawr\AppData\Local\{553CCE14-1E79-4E2C-9D76-DDC25C28ADF0}
.
==================== Find3M ====================
.
2011-11-13 20:09:07 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-05 05:26:29 1197568 ----a-w- C:\Windows\System32\wininet.dll
2011-11-05 05:23:10 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2011-11-05 04:35:50 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-05 04:34:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2011-11-05 04:07:32 482816 ----a-w- C:\Windows\System32\html.iec
2011-11-05 03:28:41 386048 ----a-w- C:\Windows\SysWow64\html.iec
2011-11-05 03:25:44 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-05 02:55:38 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:19:07 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2011-09-29 16:24:44 1897328 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-09-23 05:34:05 140096 ------r- C:\Windows\SysWow64\COMDLG32.OCX
.
============= FINISH: 19:41:29.30 ===============
Please help!
Let me know if you need any more information!
Thank you!
-Jim
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385
Run by [removed] at 19:39:23 on 2011-12-16
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3894.1138 [GMT -5:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\Alienware\Command Center\AlienFusionService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Alienware\Command Center\AlienSense\FATrayAlert.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe
C:\Program Files\Alienware\Command Center\AlienFXHook64Mngr.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Alienware\Command Center\AlienFusionController.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbengine.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rawr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = www.dell.com
uInternet Settings,ProxyOverride = *.local;192.168.*.*
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: SSOIEAddonBHO Class: {da5bce70-d057-4d63-943d-5f3927ec59f1} - C:\Program Files\Alienware\Command Center\AlienSense\FAIESSO.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [Google Update] "C:\Users\Rawr\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Facebook Update] "C:\Users\Rawr\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
mRun: [FAStartup]
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\Rawr\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PDANET~1.LNK - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/s ... wflash.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{BDA2A005-4FD8-42A5-8EA2-DC61D538BF1B} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{BDA2A005-4FD8-42A5-8EA2-DC61D538BF1B}\038364850343030373237333 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{BDA2A005-4FD8-42A5-8EA2-DC61D538BF1B}\2496E676 : DhcpNameServer = 192.168.2.1 192.168.2.1
TCP: Interfaces\{E6EADE37-256F-48C3-BF90-316EDC3C857E} : DhcpNameServer = [removed] [removed]
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO-X64: IEVkbdBHO - No File
BHO-X64: StartNow Toolbar Helper: {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
BHO-X64: StartNow Toolbar Helper - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: SSOIEAddonBHO Class: {DA5BCE70-D057-4D63-943D-5F3927EC59F1} - C:\Program Files\Alienware\Command Center\AlienSense\FAIESSO.dll
BHO-X64: SSOIEAddonBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
BHO-X64: link filter bho - No File
TB-X64: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun-x64: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
mRun-x64: [FAStartup]
mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce-x64: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R0 EMSC;COMPAL Embedded System Control;C:\Windows\System32\drivers\EMSC.sys [2009-6-26 13680]
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-3-22 98208]
R2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2010-5-21 14648]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-2 365336]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2011-5-27 166400]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2011-5-27 128512]
R2 FAService;FAService;C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe [2010-4-4 2409800]
R2 MotoHelper;MotoHelper Service;C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2011-8-10 227184]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-4-4 1997416]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-3-17 378984]
R2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [2011-5-20 210144]
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys --> C:\Windows\system32\DRIVERS\Accelern.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 DAdderFltr;DeathAdder Mouse;C:\Windows\system32\drivers\dadder.sys --> C:\Windows\system32\drivers\dadder.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 pneteth;PdaNet Broadband;C:\Windows\system32\DRIVERS\pneteth.sys --> C:\Windows\system32\DRIVERS\pneteth.sys [?]
S0 johci;JMicron 1394 Filter Driver;C:\Windows\system32\DRIVERS\johci.sys --> C:\Windows\system32\DRIVERS\johci.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-6-29 136176]
S3 BTCFilterService;USB Networking Driver Filter Service;C:\Windows\system32\DRIVERS\motfilt.sys --> C:\Windows\system32\DRIVERS\motfilt.sys [?]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-6-29 136176]
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
S3 motandroidusb;Mot ADB Interface Driver;C:\Windows\system32\Drivers\motoandroid.sys --> C:\Windows\system32\Drivers\motoandroid.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\system32\DRIVERS\motccgp.sys --> C:\Windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;C:\Windows\system32\DRIVERS\motccgpfl.sys --> C:\Windows\system32\DRIVERS\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;C:\Windows\system32\DRIVERS\motodrv.sys --> C:\Windows\system32\DRIVERS\motodrv.sys [?]
S3 Motousbnet;Motorola USB Networking Driver Service;C:\Windows\system32\DRIVERS\Motousbnet.sys --> C:\Windows\system32\DRIVERS\Motousbnet.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-12-17 00:26:57 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-12-17 00:26:41 -------- d-----w- C:\Users\Rawr\AppData\Roaming\Malwarebytes
2011-12-17 00:26:22 -------- d-----w- C:\ProgramData\Malwarebytes
2011-12-17 00:26:18 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-17 00:26:17 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-16 18:15:55 -------- d-----w- C:\Users\Rawr\AppData\Local\{D10C53F2-357D-4918-8817-3D3FD9DB38AC}
2011-12-16 18:15:45 -------- d-----w- C:\Users\Rawr\AppData\Local\{1DC551F0-326D-4A7D-B040-65CEF2E2F401}
2011-12-16 06:51:26 -------- d-----w- C:\Program Files (x86)\Free YouTube Downloader
2011-12-16 06:25:43 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA8D278A-6CA0-4DFA-AA95-BC9DFBA54C71}\mpengine.dll
2011-12-16 06:25:43 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA8D278A-6CA0-4DFA-AA95-BC9DFBA54C71}\offreg.dll
2011-12-16 06:15:21 -------- d-----w- C:\Users\Rawr\AppData\Local\{8A171006-56A2-4230-AF00-B923B740EF93}
2011-12-15 12:09:09 -------- d-----w- C:\Users\Rawr\AppData\Local\{4DBBF984-B48A-4FD6-BD75-ABAC297E62E4}
2011-12-15 12:08:59 -------- d-----w- C:\Users\Rawr\AppData\Local\{84F065AD-9C01-4763-B4A0-C41BC606C4F8}
2011-12-15 04:26:57 3141632 ----a-w- C:\Windows\System32\win32k.sys
2011-12-15 04:26:55 723456 ----a-w- C:\Windows\System32\EncDec.dll
2011-12-15 04:26:55 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-15 04:26:51 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-12-15 04:26:51 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-12-14 22:54:28 -------- d-----w- C:\Users\Rawr\AppData\Local\{5960A182-D553-42FE-8206-C753A38BDBE5}
2011-12-14 22:54:18 -------- d-----w- C:\Users\Rawr\AppData\Local\{39C0458F-F23B-44D1-8C35-BBFB4F79A5D5}
2011-12-14 05:50:47 -------- d-----w- C:\Users\Rawr\AppData\Local\{20702A78-74B7-4AC6-BD64-C21B344A747C}
2011-12-14 05:50:37 -------- d-----w- C:\Users\Rawr\AppData\Local\{61BC73B9-FFEE-470B-850A-7246C27BAD7E}
2011-12-13 23:43:05 -------- d-----w- C:\Users\Rawr\AppData\Roaming\mIRC
2011-12-13 23:43:05 -------- d-----w- C:\Program Files (x86)\mIRC
2011-12-13 05:17:10 -------- d-----w- C:\Users\Rawr\AppData\Local\{CB040899-3864-4813-8BF2-56F7D1F9FC9C}
2011-12-13 05:17:01 -------- d-----w- C:\Users\Rawr\AppData\Local\{8899484D-A67E-4B3E-9CD6-09EF8E2C5990}
2011-12-12 22:44:40 -------- d-----w- C:\Program Files (x86)\StartNow Toolbar
2011-12-12 22:43:51 -------- d-----w- C:\Users\Rawr\AppData\Local\TempDIR
2011-12-12 17:16:35 -------- d-----w- C:\Users\Rawr\AppData\Local\{59ED4CEE-4042-4AD8-9BF9-C599DF62B320}
2011-12-12 17:16:25 -------- d-----w- C:\Users\Rawr\AppData\Local\{25C4E587-B47B-4C72-A761-E1BFBC019C9E}
2011-12-11 20:15:08 -------- d-----w- C:\Users\Rawr\AppData\Local\{F62AFFF7-6F04-4BB5-9298-BDAAEE946CC2}
2011-12-11 20:14:58 -------- d-----w- C:\Users\Rawr\AppData\Local\{5B4DD06C-7D49-4B42-95A0-95CEDC26DB5F}
2011-12-11 08:14:32 -------- d-----w- C:\Users\Rawr\AppData\Local\{8895B98A-6CDD-41B7-9901-84F4DF61C98F}
2011-12-10 20:59:26 -------- d-----w- C:\Windows\SysWow64\aliedit
2011-12-10 20:59:17 -------- d-----w- C:\Program Files (x86)\Trademanager
2011-12-10 20:56:09 -------- d-----w- C:\Users\Rawr\AppData\Local\Alibaba
2011-12-10 20:14:06 -------- d-----w- C:\Users\Rawr\AppData\Local\{23B0B1A4-0095-423E-96DD-12BA735096BB}
2011-12-10 20:13:54 -------- d-----w- C:\Users\Rawr\AppData\Local\{AEC09A48-D433-4130-95FC-B99ABE1A576A}
2011-12-09 22:40:51 -------- d-----w- C:\Users\Rawr\AppData\Local\{D9B02C0F-3ED4-4FCA-9264-939E1ACD1A94}
2011-12-09 22:40:39 -------- d-----w- C:\Users\Rawr\AppData\Local\{37D85586-E3D8-4164-97B7-2BD5F502B5F1}
2011-12-09 03:04:50 -------- d-----w- C:\Users\Rawr\AppData\Local\{6CCC16ED-FFD3-41F8-937C-F49C93B04B7E}
2011-12-09 03:04:40 -------- d-----w- C:\Users\Rawr\AppData\Local\{BF578B44-B6FD-4577-B7EE-734B770AB356}
2011-12-07 18:36:40 -------- d-----w- C:\Users\Rawr\AppData\Local\{1AA95B1B-D7A6-49FE-AD04-87CAD513824B}
2011-12-07 18:36:30 -------- d-----w- C:\Users\Rawr\AppData\Local\{3FB90128-5DEC-4E04-A531-A2450F41B079}
2011-12-07 02:10:08 -------- d-----r- C:\Program Files (x86)\Skype
2011-12-06 23:47:00 -------- d-----w- C:\Users\Rawr\AppData\Local\{FED9ACC0-27ED-41E3-90D3-83C25E96A8CD}
2011-12-06 23:46:50 -------- d-----w- C:\Users\Rawr\AppData\Local\{83828103-7123-40ED-9A01-FB4D485D9679}
2011-12-06 11:46:22 -------- d-----w- C:\Users\Rawr\AppData\Local\{45B189D3-C6B5-45FA-90D9-ACBDF2FE1134}
2011-12-06 11:46:07 -------- d-----w- C:\Users\Rawr\AppData\Local\{B841B295-5F8C-4AC6-ACE3-582F1A365ED6}
2011-12-05 16:57:30 -------- d-----w- C:\Users\Rawr\AppData\Local\{655529BA-01EE-4CA9-8091-F5078DA47BB0}
2011-12-05 16:57:19 -------- d-----w- C:\Users\Rawr\AppData\Local\{18C65620-90FA-4918-A126-90265C5CD2ED}
2011-12-04 04:41:12 -------- d-----w- C:\Users\Rawr\AppData\Local\{FFF4A02A-71A7-472C-A833-0B869A85B39D}
2011-12-04 04:41:00 -------- d-----w- C:\Users\Rawr\AppData\Local\{92461499-E83E-4D14-9E59-2542B980121F}
2011-12-03 16:40:29 -------- d-----w- C:\Users\Rawr\AppData\Local\{9413723E-520C-473F-979B-10ADC67FBFC1}
2011-12-03 16:40:18 -------- d-----w- C:\Users\Rawr\AppData\Local\{5152B4D0-D313-48A7-B3DA-8A5461596E65}
2011-12-02 00:11:55 -------- d-----w- C:\Users\Rawr\AppData\Local\{9AC79F06-A576-46B3-8DF2-C9290CC77937}
2011-12-02 00:11:45 -------- d-----w- C:\Users\Rawr\AppData\Local\{36CA4DBE-5209-4E68-B399-AC5AFEF8853C}
2011-11-30 19:51:00 -------- d-----w- C:\Users\Rawr\AppData\Local\{A80153E0-3033-43CD-92B7-4F96F3DE6B5D}
2011-11-30 19:50:50 -------- d-----w- C:\Users\Rawr\AppData\Local\{679F18A5-D1CA-4287-A9AE-9DC9EAFC07EB}
2011-11-30 07:50:25 -------- d-----w- C:\Users\Rawr\AppData\Local\{F9DBD983-7D43-45D6-B370-FD10736C2D1C}
2011-11-29 19:50:02 -------- d-----w- C:\Users\Rawr\AppData\Local\{FDEE681A-D0C1-41E4-88C1-271F730CA6C5}
2011-11-29 19:49:52 -------- d-----w- C:\Users\Rawr\AppData\Local\{E17CC0A7-D817-43EC-8E80-97CE779894AA}
2011-11-29 04:34:48 -------- d-----w- C:\Users\Rawr\AppData\Local\{53E2EE5A-96F2-4D9D-924C-D9D3CF9DAEEC}
2011-11-29 04:34:38 -------- d-----w- C:\Users\Rawr\AppData\Local\{576D266C-40A0-4AE2-9F8F-49D77AED86F5}
2011-11-28 07:09:26 -------- d-----w- C:\Users\Rawr\AppData\Local\{EAF19100-C236-4CB5-99FF-430A3D8CB4BB}
2011-11-28 07:09:14 -------- d-----w- C:\Users\Rawr\AppData\Local\{B50C8C63-227E-4940-BA92-322837D1075E}
2011-11-27 19:08:49 -------- d-----w- C:\Users\Rawr\AppData\Local\{023E165A-753F-41CA-8397-4D099D986DEF}
2011-11-27 19:08:39 -------- d-----w- C:\Users\Rawr\AppData\Local\{83FD9828-3ED7-4969-B0C2-41B84204FF9E}
2011-11-25 07:57:21 -------- d-----w- C:\Users\Rawr\AppData\Local\{3AB6BB62-BFB8-461F-9636-A1C9EBFA2F86}
2011-11-25 07:57:05 -------- d-----w- C:\Users\Rawr\AppData\Local\{36FE037D-04BC-4593-85BE-339EB99E73B8}
2011-11-22 18:38:39 -------- d-----w- C:\Users\Rawr\AppData\Local\{08ABCF46-CC68-463E-95C5-4E99DA68AB43}
2011-11-22 18:38:29 -------- d-----w- C:\Users\Rawr\AppData\Local\{8468E2D7-313C-40A4-9AAD-E87F3DAA2FE4}
2011-11-22 07:54:21 -------- d-----w- C:\Users\Rawr\AppData\Local\Chromium
2011-11-19 03:28:15 -------- d-----w- C:\Users\Rawr\AppData\Local\{2036E232-B515-4329-BF9B-44094B5930AB}
2011-11-19 03:28:05 -------- d-----w- C:\Users\Rawr\AppData\Local\{508467E1-115E-4B6B-9C25-DF5FD49388AC}
2011-11-18 15:27:53 -------- d-----w- C:\Users\Rawr\AppData\Local\{20CE0B3E-6843-4901-A6D1-604D7CA38047}
2011-11-18 15:27:43 -------- d-----w- C:\Users\Rawr\AppData\Local\{0B07017F-A0E2-49A9-93DD-2F1AC75509B4}
2011-11-18 03:27:31 -------- d-----w- C:\Users\Rawr\AppData\Local\{03695703-568E-4AAA-A474-12D7E7316796}
2011-11-18 03:27:21 -------- d-----w- C:\Users\Rawr\AppData\Local\{5F72E6CE-67CA-44DF-B51D-5DED110BB5EA}
2011-11-17 15:27:09 -------- d-----w- C:\Users\Rawr\AppData\Local\{4A54C7C8-9A1C-4B74-824E-95A693EA7C4A}
2011-11-17 03:26:46 -------- d-----w- C:\Users\Rawr\AppData\Local\{422D039F-9991-4C6B-875B-4673BC9A4C67}
2011-11-17 03:26:36 -------- d-----w- C:\Users\Rawr\AppData\Local\{553CCE14-1E79-4E2C-9D76-DDC25C28ADF0}
.
==================== Find3M ====================
.
2011-11-13 20:09:07 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-05 05:26:29 1197568 ----a-w- C:\Windows\System32\wininet.dll
2011-11-05 05:23:10 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2011-11-05 04:35:50 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-05 04:34:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2011-11-05 04:07:32 482816 ----a-w- C:\Windows\System32\html.iec
2011-11-05 03:28:41 386048 ----a-w- C:\Windows\SysWow64\html.iec
2011-11-05 03:25:44 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-05 02:55:38 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:19:07 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2011-09-29 16:24:44 1897328 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-09-23 05:34:05 140096 ------r- C:\Windows\SysWow64\COMDLG32.OCX
.
============= FINISH: 19:41:29.30 ===============



(Selecting Uninstall application on close if you so wish)