amysan
Topic Starter
Everytime I run spybot, win32pornpopup is in the list. I select fix the problem, but every day when I scan it's back again. I haven't had too many problems, haven't had porn popping up but it feels like pnot in control of my computer. My mouse does things of it's own accord, so please excuse any typos. I'm running winsdows 7 and firefox. Here my DDS log:
DDS (Ver_10-03-17.01) - NTFSX64
Run by [removed] at 7:46:19.90 on Mon 07/05/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3032.1085 [GMT -4:00]
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files (x86)\X3watch\x3watch.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~2\MOZILL~1\FIREFOX.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Amy\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
uWindow Title = Internet Explorer provided by Dell
mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\roboform.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files (x86)\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files (x86)\windows live\toolbar\wltcore.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\roboform.dll
uRun: [RoboForm] "c:\program files (x86)\siber systems\ai roboform\RoboTaskBarIcon.exe"
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\NPSWF32_FlashUtil.exe -p
mRun: [PDVDDXSrv] "c:\program files (x86)\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Dell Webcam Central] "c:\program files (x86)\dell webcam\dell webcam central\WebcamDell2.exe" /mode2
mRun: [Desktop Disc Tool] "c:\program files (x86)\roxio\roxio burn\RoxioBurnLauncher.exe"
mRun: [DellSupportCenter] "c:\program files (x86)\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe"
mRun: [Google Desktop Search] "c:\program files (x86)\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [BrMfcWnd] c:\program files (x86)\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files (x86)\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe"
StartupFolder: c:\users\amy\appdata\roaming\micros~1\windows\startm~1\programs\startup\gigatr~1.lnk - c:\program files (x86)\gigatribe\gigatribe.exe
StartupFolder: c:\users\amy\appdata\roaming\micros~1\windows\startm~1\programs\startup\x3watch.lnk - c:\program files (x86)\x3watch\x3watch.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Evernote - c:\program files (x86)\evernote\evernote3\enbar.dll/2000
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office14\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: S&end to OneNote - c:\progra~2\micros~2\office14\ONBttnIE.dll/105
IE: Save Forms - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files (x86)\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files (x86)\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office11\REFIEBAR.DLL
IE: {E0B8C461-F8FB-49b4-8373-FE32E9252800} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEE1} - c:\program files (x86)\evernote\evernote3\enbar.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\program files (x86)\cozi express\CoziProtocolHandler.dll
AppInit_DLLs: c:\progra~2\google\google~1\GO36F4~1.DLL
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
mRun-x64: [Apoint] c:\program files\delltpad\Apoint.exe
mRun-x64: [SysTrayApp] c:\program files\idt\wdm\sttray64.exe
mRun-x64: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun-x64: [Persistence] c:\windows\system32\igfxpers.exe
mRun-x64: [Broadcom Wireless Manager UI] c:\program files\dell\dell wireless wlan card\WLTRAY.exe
mRun-x64: [QuickSet] c:\program files\dell\quickset\QuickSet.exe
mRun-x64: [IAAnotif] c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe
mRun-x64: [WD Anywhere Backup] c:\program files\wd\wd anywhere backup\MemeoLauncher2.exe –silent
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\amy\appdata\roaming\mozilla\firefox\profiles\62ov0738.default\
FF - prefs.js: browser.startup.homepage - hxxp://feedsifter.com/create.php|http://ebaysellingcoach.blogspot.com/2009/02/thrift-store-items-to-sell-on-ebay-huge.html|http://www.safbaby.com/12-things-your-child-should-avoid-in-2010|http://www.tammysrecipes.com/homemade_wheat_bread|http://www.tammysrecipes.com/node/2814|http://www.tammysrecipes.com/node/2813|http://explorershomeschoolassociation.schools.officelive.com/formembers.aspx|http://www.qg.com/smartools/ebook/hosted.rails?issue=a4279e3e57b643f28460820e93a13a9915aa227f95bb46818508820e93a13a99|http://www.4himkids.com/index.html|http://homeschoolcentral.webs.com/elementarygradeschedule.htm|http://www.facebook.com/home.php|http://traininghappyhearts.blogspot.com/2010/05/step-three-music-and-movement-area.html|http://blog.cookingwithtraderjoes.com/|http://www.localharvest.org/search.jsp?m&lat=42.240869&lon=-83.719353&scale=10&ty=-1&p=3|http://www.localharvest.org/csa/M27365|http://www.locavorious.com/|http://www.bzzagent.com/member/Surveys.do|http://www.happinessprojecttoolbox.com/inspiration_boards.html|http://www.eatwellguide.org/search/advanced|http://www.eatwild.com/|http://www.eatwellguide.org/listing/detail/23966|http://similarminds.com/cgi-bin/similarminds.pl|http://www.abcjesuslovesme.com/4-year-old-curriculum|http://www.skipmcgrath.com/newsletters/current.shtml|http://annarbor.craigslist.org/gms/|http://www.annarbor.com/vielmetti/links-berrypicking-strawberries-2010/|http://feedsifter.com/create.php|http://ebaysellingcoach.blogspot.com/2009/02/thrift-store-items-to-sell-on-ebay-huge.html|http://www.safbaby.com/12-things-your-child-should-avoid-in-2010|http://www.tammysrecipes.com/homemade_wheat_bread|http://www.tammysrecipes.com/node/2814|http://www.tammysrecipes.com/node/2813|http://explorershomeschoolassociation.schools.officelive.com/formembers.aspx|http://www.qg.com/smartools/ebook/hosted.rails?issue=a4279e3e57b643f28460820e93a13a9915aa227f95bb46818508820e93a13a99|http://www.4himkids.com/index.html|http://homeschoolcentral.webs.com/elementarygradeschedule.htm|http://www.facebook.com/?ref=home|http://traininghappyhearts.blogspot.com/2010/05/step-three-music-and-movement-area.html|http://blog.cookingwithtraderjoes.com/|http://www.localharvest.org/search.jsp?m&lat=42.240869&lon=-83.719353&scale=10&ty=-1&p=3|http://www.localharvest.org/csa/M27365|http://www.locavorious.com/|http://www.bzzagent.com/member/Surveys.do|http://www.happinessprojecttoolbox.com/inspiration_boards.html|http://www.eatwellguide.org/search/advanced|http://www.eatwild.com/|http://www.eatwellguide.org/listing/detail/23966|http://groups.yahoo.com/group/a2unschooling/|http://www.debralynndadd.com/|http://debraslist.com/list.php?topic=Textiles|http://www.currclick.com/product_info.php?products_id=33839&it=1&SRC=Newsletter|http://science.nasa.gov/science-news/science-at-nasa/2010/07jun_journeytothestars/|http://www.auctionbytes.com/cab/abn/y10/m06/i07/s01|http://www.mysilentteam.com/public/83.cfm|http://www.homeschool-curriculum-for-life.com/
FF - component: c:\program files (x86)\evernote\evernote3\fftbclipper\components\enbar3.dll
FF - component: c:\program files (x86)\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\users\amy\appdata\roaming\mozilla\firefox\profiles\62ov0738.default\extensions\{22119944-ed35-4ab1-910b-e619ea06a115}\components\rfproxy_19.dll
FF - component: c:\users\amy\appdata\roaming\mozilla\firefox\profiles\62ov0738.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll
FF - component: c:\users\amy\appdata\roaming\mozilla\firefox\profiles\62ov0738.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCore.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;c:\windows\system32\drivers\PxHlpa64.sys [2010-1-11 55280]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-1-19 121936]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 59904]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-1-19 20048]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-1-19 61008]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-2 40384]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2009-6-9 155648]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\wd\wd anywhere backup\MemeoBackgroundService.exe [2008-11-7 25824]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-2 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-2 40384]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [2010-1-11 172704]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-1-11 215552]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x64.sys [2010-1-11 393728]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2010-1-19 1153368]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\google\google desktop search\GoogleDesktop.exe [2010-1-20 30192]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-10 1255736]
=============== Created Last 30 ================
2010-07-02 11:55:10 38848 —-a-w- c:\windows\avastSS.scr
2010-06-22 22:46:38 0 d—–w- c:\users\amy\appdata\roaming\Reallusion
2010-06-22 22:07:49 0 d—–w- c:\programdata\Creative
==================== Find3M ====================
2010-06-28 20:57:12 165032 —-a-w- c:\windows\syswow64\aswBoot.exe
2010-06-28 20:33:00 61008 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-06-03 02:41:44 3600384 —-a-w- c:\windows\syswow64\GPhotos.scr
2010-05-29 20:23:33 153376 —-a-w- c:\windows\syswow64\javaws.exe
2010-05-29 20:23:32 145184 —-a-w- c:\windows\syswow64\javaw.exe
2010-05-29 20:23:31 145184 —-a-w- c:\windows\syswow64\java.exe
2010-05-29 20:23:30 411368 —-a-w- c:\windows\syswow64\deployJava1.dll
2010-05-29 19:41:48 7024 ——w- C:\bootsqm.dat
2010-05-21 18:14:28 270208 ——w- c:\windows\system32\MpSigStub.exe
2010-03-25 20:53:30 5668864 —-a-w- c:\program files (x86)\auctionsage.exe
2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 –sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 –sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-01-11 20:55:09 75 –sh–r- c:\windows\CT4CET.bin
2009-06-10 20:44:08 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2010-01-22 08:22:55 245760 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-04-02 12:32:47 245760 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-01-19 06:55:42 32768 –sha-w- c:\windows\temp\cookies\index.dat
2010-01-19 06:55:42 16384 –sha-w- c:\windows\temp\history\history.ie5\index.dat
2010-01-19 06:55:42 49152 –sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat
2009-07-14 01:39:53 398848 –sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 7:47:54.42 ===============