HarryG
Topic Starter
A friend asked me to look into why they were not able to connect to the Internet for the past two weeks. Took me two days to finally get it connected. I could ping other machines on my network. The machine showed I had a connection, but could not connect via IE7 or Firefox. They have NOD32 Antivirus. Have not heard of this antivirus, is it any good. I usually use AVG or Comodo. I ran Norton_Removal_Tool.exe and it fixed my connection. So, I want to find and delete all the other junk on this box (if any).
The things I have done so far:
Spybot S&D
Ad-Aware
ATF Cleaner
Malwarebytes' Anti-Malware
Rebooted machine.
Then I ran all the steps in the "Welcome New Members" post and am posting/attaching the requested reports along with the Malwarebytes' report. Thank you in advance for your help!
Malwarebytes' Anti-Malware 1.40
Database version: 2684
Windows 5.1.2600 Service Pack 3
8/23/2009 4:12:37 PM
mbam-log-2009-08-23 (16-12-37).txt
Scan type: Quick Scan
Objects scanned: 102499
Time elapsed: 3 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d8c924bf-9feb-4d1f-a400-416aa336de82} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d8c924bf-9feb-4d1f-a400-416aa336de82} (Adware.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Save (Adware.WhenUSave) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Mozilla Firefox\Components\SaveComponent.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\win70.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\Save\SaveUninst.exe (Adware.WhenUSave) -> Quarantined and deleted successfully.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/23 16:58
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF39A0000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79BB000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xBA8F1000 Size: 49152 File Visible: No Signed: -
Status: -
Name: xyjels.sys
Image Path: xyjels.sys
Address: 0xF7487000 Size: 61440 File Visible: No Signed: -
Status: -
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:51:39.79 on Sun 08/23/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.391 [GMT -4:00]
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Kodak\AiO\center\KodakSvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mom\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Page =
uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0509&m=el1200-06w
uSearch Bar =
mDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0509&m=el1200-06w
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=0&o=xph&d=0509&m=el1200-06w
mSearch Bar = about:blank
mSearchAssistant =
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
TB: Mirar: {d8c924be-9feb-4d1f-a400-416aa336de82} - c:\windows\system32\win7078.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: &Save Branding Window: {2c5a7a51-7e8d-497e-852a-d63ad9014e14} - %SystemRoot%\system32\shdocvw.dll
uRun: [Save] c:\documents and settings\mom\application data\save\Save.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [LaunchApp]
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe
mRun: [Conime] %windir%\system32\conime.exe
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\imon.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\mom\applic~1\mozilla\firefox\profiles\7pfxp4ze.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-20 64160]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-8-8 15424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\aio\center\KodakSvc.exe [2008-12-1 28672]
R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2009-8-8 552064]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-7 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\EKDiscovery.exe [2008-10-10 274432]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
=============== Created Last 30 ================
2009-08-23 15:56 –d—– c:\docume~1\mom\applic~1\Malwarebytes
2009-08-23 15:56 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-23 15:56 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-23 15:56 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-23 15:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-23 11:03 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-08-21 00:52 116,224 ac—— c:\windows\system32\dllcache\xrxwiadr.dll
2009-08-21 00:50 53,760 ac—— c:\windows\system32\dllcache\wiamsmud.dll
2009-08-21 00:49 249,402 ac—— c:\windows\system32\dllcache\vinwm.sys
2009-08-21 00:48 94,720 ac—— c:\windows\system32\dllcache\umaxud32.dll
2009-08-21 00:47 159,232 ac—— c:\windows\system32\dllcache\tridkbm.sys
2009-08-21 00:46 17,129 ac—— c:\windows\system32\dllcache\tdkcd31.sys
2009-08-21 00:45 155,648 ac—— c:\windows\system32\dllcache\stlnprop.dll
2009-08-21 00:44 9,600 ac—— c:\windows\system32\dllcache\sonymc.sys
2009-08-21 00:43 91,294 ac—— c:\windows\system32\dllcache\skfpwin.sys
2009-08-21 00:42 36,480 ac—— c:\windows\system32\dllcache\sfmanm.sys
2009-08-21 00:41 61,504 ac—— c:\windows\system32\dllcache\s3sav3dm.sys
2009-08-21 00:40 79,104 ac—— c:\windows\system32\dllcache\rocket.sys
2009-08-21 00:39 35,328 ac—— c:\windows\system32\dllcache\psisload.dll
2009-08-21 00:38 29,769 ac—— c:\windows\system32\dllcache\pcntn5m.sys
2009-08-21 00:37 43,689 ac—— c:\windows\system32\dllcache\otceth5.sys
2009-08-21 00:36 132,695 ac—— c:\windows\system32\dllcache\netwlan5.sys
2009-08-21 00:35 19,968 ac—— c:\windows\system32\dllcache\mxicfg.dll
2009-08-21 00:34 12,160 ac—— c:\windows\system32\dllcache\mouhid.sys
2009-08-21 00:33 802,683 ac—— c:\windows\system32\dllcache\ltsm.sys
2009-08-21 00:32 18,688 ac—— c:\windows\system32\dllcache\irsir.sys
2009-08-21 00:31 141,056 ac—— c:\windows\system32\dllcache\icam3.sys
2009-08-21 00:30 115,807 ac—— c:\windows\system32\dllcache\hsf_fsks.sys
2009-08-21 00:29 2,688 ac—— c:\windows\system32\dllcache\hidswvd.sys
2009-08-21 00:28 27,165 ac—— c:\windows\system32\dllcache\fetnd5.sys
2009-08-21 00:27 53,248 ac—— c:\windows\system32\dllcache\eqndiag.exe
2009-08-21 00:26 8,704 ac—— c:\windows\system32\dllcache\dot4scan.sys
2009-08-21 00:25 179,584 ac—— c:\windows\system32\dllcache\dac2w2k.sys
2009-08-21 00:24 7,680 ac—— c:\windows\system32\dllcache\cd20xrnt.sys
2009-08-21 00:23 26,624 ac—— c:\windows\system32\dllcache\ativxbar.sys
2009-08-21 00:22 7,424 ac—— c:\windows\system32\dllcache\adicvls.sys
2009-08-20 23:58 3,948 a——- c:\windows\system32\drivers\nvphy.bin
2009-08-20 23:58 442,368 a——- c:\windows\system32\nvunrm.exe
2009-08-20 23:58 5,836 a——- c:\windows\system32\nvnrm.nvu
2009-08-20 23:53 230,629 a——- c:\windows\system32\Autorun.ini
2009-08-20 23:52 950,272 a——- c:\windows\system32\drivers\nvnrm.sys
2009-08-20 23:52 54,016 a——- c:\windows\system32\drivers\NVENETFD.sys
2009-08-20 23:52 22,016 a——- c:\windows\system32\drivers\nvnetbus.sys
2009-08-20 23:52 35,840 a——- c:\windows\system32\nvconrm.dll
2009-08-20 23:52 199,168 a——- c:\windows\system32\fdco1.dll
2009-08-20 23:52 9,216 a——- c:\windows\system32\bdco1.dll
2009-08-20 23:51 –d—– c:\windows\system32\autorun
2009-08-20 23:26 442,368 a——- c:\windows\system32\NVUSMU.EXE
2009-08-20 22:53 –d—– c:\docume~1\mom\applic~1\AVG8
2009-08-20 20:10 15,688 a——- c:\windows\system32\lsdelete.exe
2009-08-20 19:50 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-08-20 19:50 -cd-h— c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-20 19:50 –d—– c:\program files\Lavasoft
2009-08-20 18:46 265 a——- c:\windows\wininit.ini
2009-08-20 18:28 –d—– c:\program files\Spybot - Search & Destroy
2009-08-20 18:28 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-08-20 18:17 –d—– c:\windows\pss
2009-08-19 20:17 –d—– c:\program files\common files\Nova Development
2009-08-19 20:12 –d—– c:\program files\Nova Development
2009-08-19 19:54 –d—– c:\windows\system32\XPSViewer
2009-08-19 19:53 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-19 19:53 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-19 19:53 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-19 19:53 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-08-19 19:53 117,760 ——– c:\windows\system32\prntvpt.dll
2009-08-19 19:53 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2009-08-19 19:53 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-08-16 14:39 16 a——- c:\windows\popcinfo.dat
2009-08-16 12:38 –d—– c:\docume~1\mom\applic~1\WildTangent
2009-08-13 21:14 –d—– c:\documents and settings\mom\Option
2009-08-13 20:25 –d—– c:\windows\system32\wbem\Repository
2009-08-13 20:24 –d—– c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-08-09 19:04 –d—– c:\program files\Mozilla Firefox(2)
2009-08-08 11:12 512,096 a——- c:\windows\system32\drivers\amon.sys
2009-08-08 11:12 298,104 a——- c:\windows\system32\imon.dll
2009-08-08 11:12 15,424 a——- c:\windows\system32\drivers\nod32drv.sys
2009-08-08 11:12 –d—– c:\program files\ESET
2009-08-06 16:15 –d—– c:\program files\KingsIsle Entertainment
2009-07-27 18:13 –d—– c:\program files\Unity
2009-07-25 23:38 1,071 a——- c:\windows\AWMODEM.INF
==================== Find3M ====================
2009-08-13 21:56 143,028 a——- c:\windows\pchealth\helpctr\config\cache\Personal_32_1033.dat
2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-12 15:21 233,472 a——- c:\windows\system32\wmpdxm.dll
2009-06-29 12:12 827,392 a——- c:\windows\system32\wininet.dll
2009-06-29 12:12 78,336 a——- c:\windows\system32\ieencode.dll
2009-06-29 12:12 17,408 a——- c:\windows\system32\corpol.dll
2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll
2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll
2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll
2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll
2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll
2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-10 12:19 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-30 17:51 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-10-28 21:14 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat
============= FINISH: 16:52:12.53 ===============