This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Vista Guardian Firewall 2010

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Last night I kept getting a pop up for a fake antivirus spyware vista guardian firewall 2010. I was able to close it out under the system task manager under "av.exe" but if I open any program it opens right back up. This is the second time I've had a virus like this. The first time was an vista antivirus. I had to use the MBAM and combofix to fix. I think I may have eliminated the virus by following the directions in the "Are you infected" guide. The pop-ups have stopped but I was hoping someone could let me know if you see anything that stands out. These are the steps I have taken: 1. I ran ATF cleaner 2. Did a system restore 3. Ran ERUNT 4. Scanned and resolved 6 viruses with MBAM 5. Tried running GMER Rootkit Scanner. It stops after 2 minutes or so on DeviceHarddiskVolumeShadowCopy1 and says Windows is closing the program. 6. Ran DDS and received both reports Here are the reports from MBAM and DDS Malwarebytes' Anti-Malware 1.44 Database version: 3838 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 3/8/2010 5:28:21 PM mbam-log-2010-03-08 (17-28-21).txt Scan type: Quick Scan Objects scanned: 106000 Time elapsed: 5 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\BMIMZMHMFM (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> Quarantined and deleted successfully. Folders Infected: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:44:17.00 on Mon 03/08/2010 Internet Explorer: 7.0.6002.18005 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1917.1102 [GMT -6:00] Thanks, George SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Spyware Terminator *disabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\taskeng.exe C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\OEM02Mon.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\System32\mobsync.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\The Drurys\Downloads\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2014090 uInternet Settings,ProxyServer = http=127.0.0.1:5555 uInternet Settings,ProxyOverride = uURLSearchHooks: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - c:\program files\softonic_english\tbSoft.dll mURLSearchHooks: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - c:\program files\softonic_english\tbSoft.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\toolbar\ctbr.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.8.0.41\IPSBHO.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - c:\program files\softonic_english\tbSoft.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll TB: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - c:\program files\softonic_english\tbSoft.dll TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\toolbar\ctbr.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\users\thedru~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Crawler Search - tbr:iemenu IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\crawler\toolbar\ctbr.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\thedru~1\appdata\roaming\mozilla\firefox\profiles\bcio392c.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - component: c:\program files\crawler\toolbar\firefox\components\xcomm.dll FF - component: c:\program files\crawler\toolbar\firefox\components\xshared.dll FF - component: c:\program files\crawler\toolbar\firefox\components\xsupport.dll FF - component: c:\program files\crawler\toolbar\firefox\components\xwsg.dll FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll FF - plugin: c:\users\the drurys\appdata\roaming\move networks\plugins\npqmp071505000011.dll FF - plugin: c:\users\the drurys\appdata\roaming\move networks\plugins\npqmp071701000002.dll FF - plugin: c:\users\the drurys\program files\dna\plugins\npbtdna.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1008000.029\SymEFA.sys [2010-1-27 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1008000.029\BHDrvx86.sys [2010-1-27 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1008000.029\cchpx86.sys [2010-1-27 482432] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100305.002\IDSvix86.sys [2010-3-8 343088] R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-2-4 142592] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-1-20 73728] R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.8.0.41\ccSvcHst.exe [2010-1-27 117640] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-27 102448] R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2008-1-20 235520] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2008-1-20 7424] R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nav\1008000.029\symndisv.sys [2010-1-27 48688] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-14 135664] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-17 21504] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-1-20 29744] =============== Created Last 30 ================ 2010-03-08 17:20 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-08 17:20 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-03-08 17:20 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-03-07 22:48 289,123,470 a——- c:\windows\MEMORY.DMP 2010-03-07 21:38 a-d—– c:\users\thedru~1\appdata\roaming\LimeWire 2010-03-07 21:38 –d—– c:\program files\LimeWire 2010-03-07 11:11 2,048 a——- c:\windows\system32\tzres.dll 2010-03-07 11:10 471,552 a——- c:\windows\system32\secproc_isv.dll 2010-03-07 11:10 526,336 a——- c:\windows\system32\RMActivate_isv.exe 2010-03-07 11:10 471,552 a——- c:\windows\system32\secproc.dll 2010-03-07 11:10 518,144 a——- c:\windows\system32\RMActivate.exe 2010-03-07 11:10 347,136 a——- c:\windows\system32\RMActivate_ssp.exe 2010-03-07 11:10 346,624 a——- c:\windows\system32\RMActivate_ssp_isv.exe 2010-03-07 11:10 332,288 a——- c:\windows\system32\msdrm.dll 2010-03-07 11:10 152,576 a——- c:\windows\system32\secproc_ssp_isv.dll 2010-03-07 11:10 152,064 a——- c:\windows\system32\secproc_ssp.dll 2010-03-07 11:09 1,696,256 a——- c:\windows\system32\gameux.dll 2010-03-07 11:09 28,672 a——- c:\windows\system32\Apphlpdm.dll 2010-03-07 11:09 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2010-03-06 15:25 –d—– c:\program files\DVDFab 7 2010-02-27 09:53 –d—– c:\program files\QuickPar 2010-02-27 09:50 a-d—– c:\users\thedru~1\appdata\roaming\NewsLeecher 2010-02-23 17:27 –d—– c:\program files\DVDFab 6 2010-02-23 17:24 87,608 a——- c:\users\thedru~1\appdata\roaming\inst.exe 2010-02-14 19:13 904,776 a——- c:\windows\system32\drivers\tcpip.sys 2010-02-14 19:13 30,720 a——- c:\windows\system32\drivers\tcpipreg.sys 2010-02-14 19:13 302,080 a——- c:\windows\system32\drivers\srv.sys 2010-02-14 19:13 98,816 a——- c:\windows\system32\drivers\srvnet.sys 2010-02-14 19:12 1,314,816 a——- c:\windows\system32\quartz.dll 2010-02-14 19:12 82,944 a——- c:\windows\system32\mciavi32.dll 2010-02-14 19:12 50,176 a——- c:\windows\system32\iyuv_32.dll 2010-02-14 19:12 31,744 a——- c:\windows\system32\msvidc32.dll 2010-02-14 19:12 22,528 a——- c:\windows\system32\msyuv.dll 2010-02-14 19:12 13,312 a——- c:\windows\system32\msrle32.dll 2010-02-14 19:12 12,288 a——- c:\windows\system32\tsbyuv.dll 2010-02-14 19:12 123,904 a——- c:\windows\system32\msvfw32.dll 2010-02-14 19:12 91,136 a——- c:\windows\system32\avifil32.dll 2010-02-14 19:11 105,984 a——- c:\windows\system32\drivers\mrxsmb.sys 2010-02-14 19:11 212,992 a——- c:\windows\system32\drivers\mrxsmb10.sys 2010-02-12 20:18 –d—– C:\New Folder 2010-02-08 16:49 –d-h— c:\programdata\CanonBJ 2010-02-08 16:43 106,496 a——- c:\windows\system32\cnco160.dll 2010-02-08 16:43 1,302,528 a——- c:\windows\system32\CNCC160.DLL 2010-02-08 16:43 135,168 a——- c:\windows\system32\CNCL160.DLL 2010-02-08 16:43 69,632 a——- c:\windows\system32\CNCI160.DLL 2010-02-08 16:33 –d—– c:\program files\Canon ==================== Find3M ==================== 2010-03-06 15:26 51,200 a——- c:\windows\inf\infpub.dat 2010-03-06 15:26 143,360 a——- c:\windows\inf\infstrng.dat 2010-03-06 15:25 47,360 a——- c:\users\thedru~1\appdata\roaming\pcouffin.sys 2010-02-08 16:48 86,016 a——- c:\windows\inf\infstor.dat 2010-02-04 06:22 142,592 a——- c:\windows\system32\drivers\sp_rsdrv2.sys 2010-01-06 09:38 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2010-01-06 09:38 2,159,616 a——- c:\windows\apppatch\AcGenral.dll 2010-01-06 09:38 542,720 a——- c:\windows\apppatch\AcLayers.dll 2010-01-06 09:38 458,752 a——- c:\windows\apppatch\AcSpecfc.dll 2009-12-18 07:01 78,336 a——- c:\windows\system32\ieencode.dll 2009-12-16 05:44 834,048 a——- c:\windows\system32\wininet.dll 2009-12-09 22:54 261,632 a——- c:\windows\PEV.exe 2009-11-26 22:19 665,600 a——- c:\windows\inf\drvindex.dat 2008-07-02 20:43 174 a–sh— c:\program files\desktop.ini 2008-05-23 17:00 25,600 a——- c:\users\the drurys\usbsermptxp.sys 2008-05-23 17:00 22,768 a——- c:\users\the drurys\usbsermpt.sys 2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2008-01-20 04:37 80 a–shr– c:\windows\CT4CET.bin 2008-01-20 12:11 8,192 a–sh— c:\windows\users\default\NTUSER.DAT ============= FINISH: 17:46:17.70 =============== Thanks, George

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI