MalBytes
Malwarebytes' Anti-Malware 1.44
Database version: 3833
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
3/7/2010 2:01:32 PM
mbam-log-2010-03-07 (14-01-32).txt
Scan type: Quick Scan
Objects scanned: 109373
Time elapsed: 8 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit quick scan 2010-03-07 14:08:18
Windows 6.0.6001 Service Pack 1
Running: p0zfj4r8.exe; Driver: C:\Users\STEPHA~1\AppData\Local\Temp\kwtiruob.sys
—- System - GMER 1.0.15 —-
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateFile [0x82DACC50]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateProcess [0x82DACC7A]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x82DACCA2]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x82DACC64]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetContextThread [0x82DACC3C]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetInformationProcess [0x82DACC28]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x82DACCD1]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x82DACCB8]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x82DACC8E]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetInformationProcess
—- Devices - GMER 1.0.15 —-
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
—- EOF - GMER 1.0.15 —-
DDS
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:20:55.10 on Sun 03/07/2010
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1915.954 [GMT -5:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter3.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Toshiba Registration\Registration.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchFilterHost.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Stephanie\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = att.my.yahoo.com
uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\TOSCDSPD.exe
uRun: [951738463] c:\program files\toshiba registration\registration.exe /r "c:\program files\toshiba registration\Registration.rpd"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [jswtrayutil] "c:\program files\jumpstart\jswtrayutil.exe"
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NDSTray.exe] NDSTray.exe
mRun: [cfFncEnabler.exe] cfFncEnabler.exe
mRun: [ToshibaServiceStation] c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe /hide:60
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
============= SERVICES / DRIVERS ===============
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2010-3-6 20384]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2008-4-17 40960]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2010-3-6 203280]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-8-18 7168]
R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2007-2-10 29178224]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-21 30192]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2010-3-6 954368]
=============== Created Last 30 ================
2010-03-07 14:12 205,621,459 a——- c:\windows\MEMORY.DMP
2010-03-07 11:36 –d—– c:\program files\Enigma Software Group
2010-03-07 11:06 –d—– c:\users\stepha~1\appdata\roaming\Malwarebytes
2010-03-07 11:06 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-07 11:06 –d—– c:\programdata\Malwarebytes
2010-03-07 11:06 –d—– c:\progra~2\Malwarebytes
2010-03-07 11:06 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-07 11:06 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-07 10:54 –d—– c:\users\stepha~1\appdata\roaming\WinBatch
2010-03-06 22:29 225,280 a——- c:\windows\system32\net_rim_plazmic_flint_dialog.dll
2010-03-06 22:29 –d—– c:\users\stepha~1\appdata\roaming\Research In Motion
2010-03-06 22:28 –d-h— c:\program files\Zero G Registry
2010-03-06 22:28 –d-h— c:\users\stephanie\InstallAnywhere
2010-03-06 21:14 –d—– c:\programdata\InstallShield
2010-03-06 21:14 –d—– c:\programdata\Sonic
2010-03-06 21:12 –d—– c:\program files\common files\PX Storage Engine
2010-03-06 21:11 –d—– c:\program files\common files\Sonic Shared
2010-03-06 21:11 –d—– c:\programdata\Roxio
2010-03-06 21:11 –d—– c:\program files\Roxio
2010-03-06 21:10 0 a—h— c:\windows\system32\drivers\Msft_Kernel_SynTP_01007.Wdf
2010-03-06 21:06 27,136 a——- c:\windows\system32\drivers\RimSerial.sys
2010-03-06 21:06 –d—– c:\programdata\Research In Motion
2010-03-06 21:06 –d—– c:\progra~2\Research In Motion
2010-03-06 21:06 –d—– c:\program files\common files\Research In Motion
2010-03-06 21:06 –d—– c:\program files\Research In Motion
2010-03-06 21:04 24,064 a——- c:\windows\system32\nshhttp.dll
2010-03-06 21:04 411,136 a——- c:\windows\system32\drivers\http.sys
2010-03-06 21:04 31,232 a——- c:\windows\system32\httpapi.dll
2010-03-06 20:57 4 —shr– c:\windows\system32\drivers\taishop.sys
2010-03-06 20:48 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-03-06 20:48 97,800 a——- c:\windows\system32\infocardapi.dll
2010-03-06 20:48 37,384 a——- c:\windows\system32\infocardcpl.cpl
2010-03-06 20:48 622,080 a——- c:\windows\system32\icardagt.exe
2010-03-06 20:48 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2010-03-06 20:48 11,264 a——- c:\windows\system32\icardres.dll
2010-03-06 20:48 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2010-03-06 20:48 326,160 a——- c:\windows\system32\PresentationHost.exe
2010-03-06 20:43 96,760 a——- c:\windows\system32\dfshim.dll
2010-03-06 20:43 282,112 a——- c:\windows\system32\mscoree.dll
2010-03-06 20:43 41,984 a——- c:\windows\system32\netfxperf.dll
2010-03-06 20:43 158,720 a——- c:\windows\system32\mscorier.dll
2010-03-06 20:43 83,968 a——- c:\windows\system32\mscories.dll
2010-03-06 20:38 279,376 a——- c:\windows\system32\drivers\tos_sps32.sys
2010-03-06 20:38 3,426,072 a——- c:\windows\system32\d3dx9_32.dll
2010-03-06 20:37 –d—– c:\program files\common files\Toshiba Shared
2010-03-06 20:31 20,384 a——- c:\windows\system32\drivers\jswpslwf.sys
2010-03-06 20:31 –d—– c:\program files\Jumpstart
2010-03-06 20:29 919,552 a——- c:\windows\system32\drivers\athr.sys
2010-03-06 20:29 516,096 a——- c:\windows\system32\S64CPA.exe
2010-03-06 20:29 393,216 a——- c:\windows\system32\athihvs.dll
2010-03-06 20:29 53,248 a——- c:\windows\system32\athihvui.dll
2010-03-06 20:29 –d—– c:\windows\system32\nn-NO
2010-03-06 20:29 –d—– c:\program files\Atheros
2010-03-06 20:29 –d—– c:\program files\Cisco
2010-03-06 20:29 –d—– c:\programdata\Atheros
2010-03-06 20:29 –d—– c:\progra~2\Atheros
2010-03-06 20:28 0 a—h— c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2010-03-06 20:27 –d—– c:\program files\Synaptics
2010-03-06 20:25 –d—– c:\windows\system32\ENU
2010-03-06 20:25 1,034,776 a——- c:\windows\system32\imsmudlg.exe
2010-03-06 20:25 312,344 a——- c:\windows\system32\drivers\iaStor.sys
2010-03-06 20:24 128,113 a——- c:\windows\system32\csellang.ini
2010-03-06 20:24 77,824 a——- c:\windows\system32\tosmreg.exe
2010-03-06 20:24 45,056 a——- c:\windows\system32\csellang.dll
2010-03-06 20:24 10,150 a——- c:\windows\system32\tosmreg.ini
2010-03-06 20:24 7,671 a——- c:\windows\system32\cseltbl.ini
2010-03-06 20:24 491,520 a——- c:\windows\system32\cselect.exe
2010-03-06 20:24 –d—– c:\program files\ltmoh
2010-03-06 20:23 –d—– c:\windows\Options
2010-03-06 20:23 553 a——- c:\windows\USetup.iss
2010-03-06 20:21 319,456 a——- c:\windows\DIFxAPI.dll
2010-03-06 20:20 523,776 a——- c:\windows\system32\RMActivate_isv.exe
2010-03-06 20:20 511,488 a——- c:\windows\system32\RMActivate.exe
2010-03-06 20:20 472,576 a——- c:\windows\system32\secproc_isv.dll
2010-03-06 20:20 472,064 a——- c:\windows\system32\secproc.dll
2010-03-06 20:20 347,136 a——- c:\windows\system32\RMActivate_ssp.exe
2010-03-06 20:20 346,624 a——- c:\windows\system32\RMActivate_ssp_isv.exe
2010-03-06 20:20 329,216 a——- c:\windows\system32\msdrm.dll
2010-03-06 20:20 151,040 a——- c:\windows\system32\secproc_ssp_isv.dll
2010-03-06 20:20 151,040 a——- c:\windows\system32\secproc_ssp.dll
2010-03-06 20:20 12,240,896 a——- c:\windows\system32\NlsLexicons0007.dll
2010-03-06 20:20 2,644,480 a——- c:\windows\system32\NlsLexicons0009.dll
2010-03-06 20:20 801,280 a——- c:\windows\system32\NaturalLanguage6.dll
2010-03-06 20:18 61,440 a——- c:\windows\system32\msasn1.dll
2010-03-06 20:18 996,352 a——- c:\windows\system32\WMNetMgr.dll
2010-03-06 20:18 94,720 a——- c:\windows\system32\logagent.exe
2010-03-06 20:17 2,868,224 a——- c:\windows\system32\mf.dll
2010-03-06 20:17 784,896 a——- c:\windows\system32\rpcrt4.dll
2010-03-06 20:17 313,344 a——- c:\windows\system32\wmpdxm.dll
2010-03-06 20:17 43,520 a——- c:\windows\system32\msdxm.tlb
2010-03-06 20:17 18,432 a——- c:\windows\system32\amcompat.tlb
2010-03-06 20:17 2,927,104 a——- c:\windows\explorer.exe
2010-03-06 20:17 147,456 a——- c:\windows\system32\Faultrep.dll
2010-03-06 20:17 125,952 a——- c:\windows\system32\wersvc.dll
2010-03-06 20:17 2,048 a——- c:\windows\system32\tzres.dll
2010-03-06 20:16 714,240 a——- c:\windows\system32\timedate.cpl
2010-03-06 20:16 897,624 a——- c:\windows\system32\drivers\tcpip.sys
2010-03-06 20:16 303,616 a——- c:\windows\system32\wmpeffects.dll
2010-03-06 20:16 281,600 a——- c:\windows\system32\raschap.dll
2010-03-06 20:16 244,224 a——- c:\windows\system32\rastls.dll
2010-03-06 20:14 2,066,432 a——- c:\windows\system32\mstscax.dll
2010-03-06 20:14 72,192 a——- c:\windows\system32\drivers\pacer.sys
2010-03-06 20:14 15,360 a——- c:\windows\system32\pacerprf.dll
2010-03-06 20:14 1,645,568 a——- c:\windows\system32\connect.dll
2010-03-06 20:14 2,501,921 a——- c:\windows\system32\wlan.tmf
2010-03-06 20:14 513,024 a——- c:\windows\system32\wlansvc.dll
2010-03-06 20:14 302,592 a——- c:\windows\system32\wlansec.dll
2010-03-06 20:14 293,376 a——- c:\windows\system32\wlanmsm.dll
2010-03-06 20:14 127,488 a——- c:\windows\system32\L2SecHC.dll
2010-03-06 20:14 144,896 a——- c:\windows\system32\drivers\srv2.sys
2010-03-06 20:14 71,680 a——- c:\windows\system32\atl.dll
2010-03-06 20:12 241,152 a——- c:\windows\system32\PortableDeviceApi.dll
2010-03-06 20:12 –d—– c:\windows\PCHEALTH
2010-03-06 20:10 –d—– c:\programdata\Microsoft Help
2010-03-06 20:08 1,334,272 a——- c:\windows\system32\msxml6.dll
2010-03-06 20:07 604,672 a——- c:\windows\system32\WMSPDMOD.DLL
2010-03-06 20:04 –dsh— C:\$RECYCLE.BIN
2010-03-06 20:03 1,314,816 a——- c:\windows\system32\quartz.dll
2010-03-06 20:03 123,904 a——- c:\windows\system32\msvfw32.dll
2010-03-06 20:03 91,136 a——- c:\windows\system32\avifil32.dll
2010-03-06 20:03 82,944 a——- c:\windows\system32\mciavi32.dll
2010-03-06 20:03 65,024 a——- c:\windows\system32\avicap32.dll
2010-03-06 20:03 50,176 a——- c:\windows\system32\iyuv_32.dll
2010-03-06 20:03 31,744 a——- c:\windows\system32\msvidc32.dll
2010-03-06 20:03 22,528 a——- c:\windows\system32\msyuv.dll
2010-03-06 20:03 13,312 a——- c:\windows\system32\msrle32.dll
2010-03-06 20:03 11,776 a——- c:\windows\system32\tsbyuv.dll
2010-03-06 20:03 212,992 a——- c:\windows\system32\drivers\mrxsmb10.sys
2010-03-06 20:03 105,472 a——- c:\windows\system32\drivers\mrxsmb.sys
2010-03-06 19:56 9,532 a——- c:\windows\system32\Config.MPF
2010-03-06 19:55 –d—– c:\programdata\SiteAdvisor
2010-03-06 19:54 79,816 a——- c:\windows\system32\drivers\mfeavfk.sys
2010-03-06 19:54 40,552 a——- c:\windows\system32\drivers\mfesmfk.sys
2010-03-06 19:54 35,272 a——- c:\windows\system32\drivers\mfebopk.sys
2010-03-06 19:54 130,424 a——- c:\windows\system32\drivers\Mpfp.sys
2010-03-06 19:53 –d—– c:\program files\McAfee.com
2010-03-06 19:53 –d—– c:\program files\common files\McAfee
2010-03-06 19:53 –d—– c:\program files\McAfee
2010-03-06 19:51 34,248 a——- c:\windows\system32\drivers\mferkdk.sys
2010-03-06 19:44 –d—– c:\programdata\McAfee
2010-03-06 19:35 422 a——- c:\windows\system32\mapisvc.inf
2010-03-06 19:32 –d—– c:\program files\Microsoft Small Business
2010-03-06 19:29 –d—– c:\program files\Microsoft SQL Server
2010-03-06 19:03 2,421,760 a——- c:\windows\system32\wucltux.dll
2010-03-06 19:03 87,552 a——- c:\windows\system32\wudriver.dll
2010-03-06 19:03 171,608 a——- c:\windows\system32\wuwebv.dll
2010-03-06 19:03 33,792 a——- c:\windows\system32\wuapp.exe
2010-03-06 19:01 –d—– c:\users\stepha~1\appdata\roaming\Symantec
2010-03-06 19:01 16 —shr– c:\windows\system32\drivers\fbd.sys
2010-03-06 19:00 –d—– c:\users\Stephanie
2010-03-06 18:46 –d—– C:\DOCS
==================== Find3M ====================
2010-03-07 03:32 86,016 a——- c:\windows\inf\infstrng.dat
2010-03-07 03:32 51,200 a——- c:\windows\inf\infpub.dat
2010-03-06 21:10 86,016 a——- c:\windows\inf\infstor.dat
2010-03-06 20:21 315,392 a——- c:\windows\HideWin.exe
2009-12-18 08:05 833,024 a——- c:\windows\system32\wininet.dll
2009-12-18 08:01 78,336 a——- c:\windows\system32\ieencode.dll
2009-12-18 05:14 26,624 a——- c:\windows\system32\ieUnatt.exe
2008-08-18 13:36 665,600 a——- c:\windows\inf\drvindex.dat
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 14:22:23.40 ===============