Spikec74
Topic Starter
Good Morning all,
I've seen someone else post about this problem, and my clock changed it's date to 2016 also. I do have an MP3 player, but I've never connected it to anyone else's computer, just mine. Also, on startup I get a pop-up that says my system has recovered from a serious error, would you like to send report? I click yes, then the little pop-up with C:\SUD\SSOW\sep.exe appears, and then another one that says something about C:\WINDOWS ? ? ? ? ? ? ? \winsysdriver.exe Restart. Those question marks refer to the path that I can't remember.
So here's everything that you guys had new people do:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/27 06:12
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF68E6000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8A97000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF568E000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
——————-
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf87ee470
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf87ee520
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf87ee5c0
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf87ee660
==EOF==
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 6:06:30.79 on Fri 11/27/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.43 [GMT -5:00]
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Documents and Settings\Spike\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uExplorerRun: [Microsoft Windows Operating System] c:\windows\system32\winsysdriver.exe
mExplorerRun: [Microsoft Windows Operating System] c:\windows\system32\winsysdriver.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\spike\applic~1\mozilla\firefox\profiles\wvl2fd3k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2009-10-16 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-10-16 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-16 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-10-16 28424]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-16 360584]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-10-16 906520]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-10-16 285392]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2009-10-22 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2009-10-22 5832712]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-11-11 604488]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-10-16 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2009-10-16 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2009-10-16 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2009-10-16 25736]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-10-16 30104]
=============== Created Last 30 ================
2009-11-27 05:29 1,110 ac—— c:\documents and settings\spike\cc_20091127_052940.reg
2009-11-27 05:26 -cd—– c:\docume~1\spike\applic~1\ScanSpyware
2009-11-24 00:03 842 ac—— c:\documents and settings\spike\cc_20091124_000322.reg
2009-11-23 23:19 -cd—– C:\stdtsa
2009-11-23 22:57 -cd—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-11-23 03:00 164 ac—— c:\documents and settings\spike\cc_20091123_030031.reg
2009-11-20 22:16 -cd—– c:\docume~1\alluse~1\applic~1\AIM
2009-11-20 22:16 -cd—– c:\program files\AIM
2009-11-20 22:14 -cd—– c:\program files\common files\Software Update Utility
2009-11-18 22:18 -cdshr– C:\SUD
2009-11-18 15:27 19,764 ac—— c:\documents and settings\spike\cc_20091118_152651.reg
2009-11-18 03:41 2,328,832 ac—— c:\windows\system32\TUKernel.exe
2009-11-17 21:04 73,728 ac—— c:\windows\system32\javacpl.cpl
2009-11-17 21:04 411,368 ac—— c:\windows\system32\deploytk.dll
2009-11-17 09:46 29,000 ac—— c:\windows\system32\uxtuneup.dll
2009-11-17 09:46 361,288 ac—— c:\windows\system32\TuneUpDefragService.exe
2009-11-11 23:11 -cd—– c:\program files\VideoLAN
2009-11-11 22:53 -cd—– c:\program files\Yahoo!
2009-11-11 22:29 604,488 ac—— c:\windows\system32\TUProgSt.exe
2009-11-11 22:23 5,370 ac—— c:\documents and settings\spike\cc_20091111_222255.reg
2009-11-10 00:57 1,144 ac—— c:\documents and settings\spike\cc_20091110_005659.reg
2009-11-10 00:56 82 ac—— c:\documents and settings\spike\cc_20091110_005654.reg
2009-11-10 00:28 28,196 ac—— c:\documents and settings\spike\cc_20091110_002846.reg
2009-11-10 00:08 844 ac—— c:\documents and settings\spike\cc_20091110_000823.reg
2009-11-09 14:41 4,960 ac—— c:\documents and settings\spike\cc_20091109_144141.reg
2009-11-09 14:32 4,180 ac—— c:\documents and settings\spike\cc_20091109_143207.reg
2009-11-09 04:21 -cd—– c:\program files\common files\Blizzard Entertainment
2009-11-09 02:27 -cd—– c:\program files\common files\AOL
2009-11-09 02:26 920 ac–h— C:\IPH.PH
2009-11-09 01:58 1,278 ac—— c:\documents and settings\spike\cc_20091109_015801.reg
2009-11-08 02:52 -cd—– C:\Inetpub
2009-11-05 16:06 23,546 ac—— c:\documents and settings\spike\cc_20091105_160558.reg
2009-11-05 15:58 34,109 ac—— c:\windows\system32\nvapps.xml
2009-11-05 15:57 14,757 ac—— c:\windows\system32\nvdisp.nvu
2009-11-05 15:57 176,128 ac—— c:\windows\system32\nvudisp.exe
2009-11-05 15:55 -cd—– C:\NVIDIA
2009-11-05 15:36 107,596 ac—— C:\toolkit_widget.gif
2009-11-04 12:32 616 ac—— c:\documents and settings\spike\cc_20091104_123255.reg
2009-11-03 17:05 4,574 ac—— c:\documents and settings\spike\cc_20091103_170519.reg
2009-10-31 19:12 -cd—– c:\program files\Windows Media Connect 2
2009-10-31 19:02 -cd—– c:\windows\system32\LogFiles
2009-10-30 14:31 6,512 ac—— c:\documents and settings\spike\cc_20091030_153127.reg
2009-10-30 07:06 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat
2009-10-29 11:46 -cd—– c:\windows\system32\XPSViewer
2009-10-29 11:41 117,760 -c—— c:\windows\system32\prntvpt.dll
2009-10-29 11:41 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-10-29 11:41 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-10-29 11:41 575,488 -c—— c:\windows\system32\xpsshhdr.dll
2009-10-29 11:41 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2009-10-29 11:41 1,676,288 -c—— c:\windows\system32\xpssvcs.dll
2009-10-29 11:41 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2009-10-29 11:41 -cd—– C:\43147a0d89a6323a2740f170
==================== Find3M ====================
2009-11-10 09:27 360,584 ac—— c:\windows\system32\drivers\avgtdix.sys
2009-11-04 00:22 1,956 ac—— c:\windows\system32\d3d8caps.dat
2009-10-27 22:31 1,278 ac—— c:\documents and settings\spike\cc_20091027_233058.reg
2009-10-26 18:39 6,696 ac—— c:\documents and settings\spike\cc_20091026_193933.reg
2009-10-22 14:14 25,608 ac—— c:\windows\system32\drivers\AVGIDSxx.sys
2009-10-22 14:13 30,104 ac—— c:\windows\system32\drivers\avgfwdx.sys
2009-10-22 14:13 50,968 ac—— c:\windows\system32\avgfwdx.dll
2009-10-22 14:11 161,800 ac—— c:\windows\system32\drivers\avgrkx86.sys
2009-10-22 01:52 86,327 ac—— c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-10-16 15:46 152,904 ac—— c:\windows\system32\vghd.scr
2009-10-16 14:09 3,460 ac—— c:\documents and settings\spike\cc_20091016_150911.reg
2009-10-16 13:53 12,464 ac—— c:\windows\system32\avgrsstx.dll
2009-10-16 13:53 333,192 ac—— c:\windows\system32\drivers\avgldx86.sys
2009-10-15 01:35 21,640 ac—— c:\windows\system32\emptyregdb.dat
2009-09-25 00:37 667,136 ac—— c:\windows\system32\wininet.dll
2009-09-25 00:37 81,920 ac—— c:\windows\system32\ieencode.dll
2009-09-11 09:18 136,192 ac—— c:\windows\system32\msv1_0.dll
2009-09-04 16:03 58,880 ac—— c:\windows\system32\msasn1.dll
2006-08-01 18:55 581,632 ac-shr– c:\windows\system32\plugin.dat
2006-06-20 14:37 1,224,704 ac-shr– c:\windows\system32\winsysdriver.exe
============= FINISH: 6:07:55.24 ===============
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
Thank you guys in advance for any help you can give me, and I'm not shutting my computer off in the meantime, lol.
Spike