rick232011
Topic Starter
Cant remove spyware cease 2011. Deleted from add/remove and from registry. Malware bytes and windows malicious does not pick it up.
DDS (Ver_2011-06-12.02) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by [removed] at 21:01:23 on 2011-06-22
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2814.1127 [GMT -4:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\TOSHIBA\IVP\ISM\ivpsvmgr.exe
C:\Program Files\Windows Doctor\WindowsDoctor.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\svchost.exe -k defragsvc
C:\Windows\system32\dfrgui.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Skytel] Skytel.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1 [removed]
TCP: Interfaces\{02F894CC-F5C6-4C06-8632-E9CCE59C9135} : DhcpNameServer = 192.168.1.1 [removed]
TCP: Interfaces\{541D686F-A9FB-4E98-B429-3DE98AC642C6} : DhcpNameServer = 192.168.1.1 [removed]
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2011-5-14 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2011-5-14 744568]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20110616.003\BHDrvx86.sys [2011-6-16 810616]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2009-9-8 65584]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20110622.001\IDSvix86.sys [2011-6-22 367736]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2011-5-14 136312]
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\n360\0501000.01d\symnets.sys [2011-5-14 296568]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2008-4-17 40960]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-6-4 366640]
R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccSvcHst.exe [2011-5-14 130008]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-5-22 105592]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-5-5 7168]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-10-14 22712]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-3-21 362600]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\toshiba\smartfacev\SmartFaceVWatchSrv.exe [2008-4-24 73728]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2009-4-17 20384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-7 135664]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-22 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-5-5 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-7 135664]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2009-4-17 954368]
S3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\drivers\RTL8192su.sys [2010-7-8 603240]
S3 SVRPEDRV;SVRPEDRV;c:\windows\system32\sysprep\PEDRV.SYS [2008-5-16 9216]
S3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2011-4-2 54136]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-5-27 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-5-24 1343400]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2011-06-20 02:37:39 ——– d—–w- c:\program files\Windows Doctor
2011-06-18 20:40:31 ——– d—–w- c:\users\rick11\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-06-16 02:32:28 ——– d—–w- c:\users\rick11\appdata\local\NPE
2011-06-14 23:34:04 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-14 23:15:04 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-06-14 23:15:04 141104 —-a-w- c:\program files\internet explorer\sqmapi.dll
2011-06-14 23:15:03 1797632 —-a-w- c:\windows\system32\jscript9.dll
2011-06-14 22:54:36 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-06-14 22:54:35 338944 —-a-w- c:\windows\system32\drivers\afd.sys
2011-06-14 22:54:35 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-14 22:54:32 311808 —-a-w- c:\windows\system32\drivers\srv.sys
2011-06-14 22:54:32 310272 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-06-14 22:54:32 114688 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-14 22:54:19 741376 —-a-w- c:\windows\system32\inetcomm.dll
2011-06-14 22:54:12 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-14 22:54:12 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-14 22:54:12 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-12 17:41:33 ——– d—–w- c:\program files\iTunes
2011-06-12 17:41:33 ——– d—–w- c:\program files\iPod
2011-06-04 18:54:19 ——– d—–w- c:\program files\Belkin
2011-06-04 18:53:37 ——– d—–w- c:\windows\{26F3D17D-4FF9-46D5-9255-A1F9FF6BD7E4}
2011-06-04 18:45:41 ——– d—–w- c:\users\rick11\appdata\local\Diagnostics
2011-05-28 14:56:47 ——– d—–w- c:\windows\system32\SPReview
2011-05-27 21:45:25 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-05-27 21:44:25 52224 —-a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2011-05-27 21:44:24 11776 —-a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-05-27 21:44:19 3215872 —-a-w- c:\windows\system32\mstscax.dll
2011-05-27 21:42:45 1171456 —-a-w- c:\windows\system32\d3d10warp.dll
2011-05-27 21:42:33 954752 —-a-w- c:\windows\system32\mfc40.dll
2011-05-27 21:42:32 954288 —-a-w- c:\windows\system32\mfc40u.dll
2011-05-27 21:42:20 1159168 —-a-w- c:\windows\system32\sysmain.dll
2011-05-27 21:42:11 423936 —-a-w- c:\windows\system32\secproc_isv.dll
2011-05-27 21:42:06 327168 —-a-w- c:\windows\system32\RMActivate_isv.exe
2011-05-27 21:42:05 428032 —-a-w- c:\windows\system32\secproc.dll
2011-05-27 21:42:00 322048 —-a-w- c:\windows\system32\RMActivate.exe
2011-05-27 21:40:59 517120 —-a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2011-05-27 21:39:59 80256 —-a-w- c:\windows\system32\drivers\amdsata.sys
2011-05-27 21:38:59 86528 —-a-w- c:\windows\system32\isoburn.exe
2011-05-27 21:37:41 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-05-27 21:37:41 363008 —-a-w- c:\windows\system32\wbemcomn.dll
2011-05-25 04:16:46 ——– d—–w- c:\windows\Panther
2011-05-25 04:02:31 ——– d–h–w- C:\$WINDOWS.~Q
2011-05-25 03:51:19 ——– d–h–w- C:\$INPLACE.~TR
2011-05-25 03:34:07 219136 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-05-25 03:34:07 161792 —-a-w- c:\windows\system32\d3d10_1.dll
2011-05-25 03:34:06 805376 —-a-w- c:\windows\system32\FntCache.dll
2011-05-25 03:34:06 1076736 —-a-w- c:\windows\system32\DWrite.dll
2011-05-25 03:34:05 739840 —-a-w- c:\windows\system32\d2d1.dll
2011-05-25 03:23:24 ——– d—–w- c:\users\rick11\appdata\local\ElevatedDiagnostics
2011-05-25 03:10:32 ——– d—–w- c:\windows\system32\Wat
2011-05-25 02:39:36 31232 —-a-w- c:\windows\system32\prevhost.exe
2011-05-25 02:39:14 870912 —-a-w- c:\windows\system32\XpsPrint.dll
2011-05-25 02:38:23 802304 —-a-w- c:\windows\system32\WFS.exe
2011-05-25 02:38:23 191488 —-a-w- c:\windows\system32\FXSCOVER.exe
2011-05-25 02:38:13 2333184 —-a-w- c:\windows\system32\win32k.sys
2011-05-25 02:38:08 70656 —-a-w- c:\windows\system32\fontsub.dll
2011-05-25 02:38:08 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-05-25 02:38:08 294912 —-a-w- c:\windows\system32\atmfd.dll
2011-05-25 02:38:06 28672 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-05-25 02:38:06 132608 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-05-25 02:38:01 542208 —-a-w- c:\windows\system32\kerberos.dll
2011-05-25 02:32:57 123904 —-a-w- c:\windows\system32\poqexec.exe
2011-05-25 02:31:15 1164288 —-a-w- c:\windows\system32\mfc42u.dll
2011-05-25 02:31:15 1137664 —-a-w- c:\windows\system32\mfc42.dll
2011-05-25 02:30:50 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-05-25 02:30:45 850944 —-a-w- c:\windows\system32\sbe.dll
2011-05-25 02:30:45 642048 —-a-w- c:\windows\system32\CPFilters.dll
2011-05-25 02:30:45 534528 —-a-w- c:\windows\system32\EncDec.dll
2011-05-25 02:30:44 199680 —-a-w- c:\windows\system32\mpg2splt.ax
2011-05-25 02:30:11 2616320 —-a-w- c:\windows\explorer.exe
2011-05-25 02:29:45 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-25 02:29:45 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-05-25 02:29:22 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-05-25 02:29:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-25 02:12:37 728448 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-05-25 02:12:37 219008 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-05-25 02:12:37 107520 —-a-w- c:\windows\system32\cdd.dll
2011-05-25 02:00:27 ——– d-sh–w- C:\Recovery
2011-05-25 01:43:05 ——– d—–w- c:\windows\system32\wbem\Performance
2011-05-25 00:22:09 ——– d—–w- c:\windows\system32\RTCOM
2011-05-25 00:21:43 ——– d—–w- c:\program files\Synaptics
2011-05-25 00:21:29 0 —-a-w- c:\windows\ativpsrm.bin
2011-05-24 03:59:49 20992 —-a-w- c:\windows\jestertb.dll
.
==================== Find3M ====================
.
2011-05-29 13:11:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 13:11:20 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-28 17:54:50 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-05-14 04:33:52 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-05-10 12:06:08 4517664 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-05-10 12:06:08 42496 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-05-04 08:52:22 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-25 19:19:55 1700352 —-a-w- c:\windows\system32\gdiplus.dll
2011-04-06 20:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 20:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-31 03:00:09 516216 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys
2011-03-31 03:00:09 50168 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys
.
============= FINISH: 21:02:07.32 ===============