Chikeeto
Topic Starter
Hello,
I recently seemed to have installed a Trojan Horse (backdoor??) on my computer.
I've run AVG and found it on there and then emptied the AVG's virus vault but this seems ineffective?
It now won't let me access Google Chrome or Spybot- Search and Destroy.
When turning on my computer today the vista bar the top of my screen containing my desktop shortcuts is now not showing up.
There have also been pop ups claiming to be Microsoft that wanted you to accept it, in the style of the User Account Control pop ups.
It didn't allow you to cancel it and so when I accepted it it turned to User Account Control off. I turned it on again straight away but I don't know if this is of any imporatance.
I'm sorry if my description here isn't that great, I'm really have no knowledge of computuers and how to deal with these things.
Any help would be great or if any extra infomation is needed (:
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 18:39:16.54 on 06/07/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2006.661 [GMT 1:00]
.
AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}
SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\Pen_Tablet.exe
C:\Windows\system32\Wacom_Tablet.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\Wacom_Tablet.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\iTunesHelper.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Cazzimodo\Documents\Chikeeto's\Data\SpotifyWebHelper.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Cazzimodo\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client;=dell-usuk&channel;=uk&ibd;=3081119
uInternet Settings,ProxyOverride = *.local
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Google Update] "c:\users\cazzimodo\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Exetender] "c:\program files\free ride games\GPlayer.exe" /runonstartup
uRun: [Facebook Update] "c:\users\cazzimodo\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [Spotify Web Helper] "c:\users\cazzimodo\documents\chikeeto's\data\SpotifyWebHelper.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [QrjEjeex] c:\users\cazzimodo\appdata\local\ilrryeuh\qrjejeex.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Dell Webcam Central] "c:\program files\dell webcam\dell webcam central\WebcamDell.exe" /mode2
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\iTunesHelper.exe"
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
StartupFolder: c:\users\cazzim~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe
StartupFolder: c:\users\cazzim~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.207\SSScheduler.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.8.05.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUplden-gb.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\10.0.6\ViProtocol.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\cazzim~1\appdata\roaming\mozilla\firefox\profiles\mujlpshm.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.msn.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B3ed1ed09-536e-4385-a872-ae321c84fb7f%7D∣=55e481a82585f07cebe73cfb4df89ed7-3c586feca70c5e74c334782c57fba0110f1190c3&ds;=AVG&v;=10.0.0.7⟨=us≺=fr&d;=2011-12-10%2014%3A33%3A45&sap;=ku&q;=
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla plugins\npitunes.dll
FF - plugin: c:\program files\tabletplugins\npwacom.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\cazzimodo\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_262.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-25 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-25 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-7 108552]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-11-19 112128]
R3 itecir;ITECIR Infrared Receiver;c:\windows\system32\drivers\itecir.sys [2008-11-19 54784]
R3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2008-11-19 203264]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2008-11-19 144672]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2008-11-19 277632]
.
=============== Created Last 30 ================
.
2012-07-06 16:10:49 6762896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{6ee4cc8d-4183-43fc-916a-860561ad2213}\mpengine.dll
2012-07-04 20:48:18 421200 —-a-w- c:\program files\mozilla firefox\msvcp100.dll
2012-07-04 20:48:17 770384 —-a-w- c:\program files\mozilla firefox\msvcr100.dll
2012-07-01 11:50:03 ——– d—–w- c:\users\cazzim~1\appdata\local\Macromedia
2012-07-01 11:47:34 ——– d—–w- c:\progra~2\McAfee Security Scan
2012-07-01 11:47:15 ——– d—–w- c:\program files\McAfee Security Scan
2012-07-01 11:47:05 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-01 11:47:05 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-01 01:33:43 56200 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{f87a2154-cd98-47bb-8e98-596c59967ac4}\offreg.dll
2012-06-29 16:59:41 6762896 ——w- c:\progra~2\microsoft\windows defender\definition updates\{f87a2154-cd98-47bb-8e98-596c59967ac4}\mpengine.dll
2012-06-22 18:44:14 16864 —-a-w- c:\program files\mozilla firefox\plugin-container.exe
2012-06-22 08:49:52 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2012-06-22 08:49:49 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-06-22 08:49:49 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-06-22 08:49:49 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-06-22 08:49:49 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-06-22 08:49:49 1069056 —-a-w- c:\windows\system32\DWrite.dll
2012-06-22 03:39:25 ——– d—–w- c:\program files\Windows Portable Devices
2012-06-22 03:07:49 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2012-06-22 03:07:48 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2012-06-22 03:07:48 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2012-06-22 02:56:16 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-22 02:55:31 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-22 02:54:52 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-22 02:54:52 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-22 02:51:50 5120 —-a-w- c:\windows\system32\wmi.dll
2012-06-22 02:51:50 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-06-22 02:51:49 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-06-22 02:51:49 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-06-22 02:38:00 307200 —-a-w- c:\program files\internet explorer\iediagcmd.exe
2012-06-22 02:38:00 161792 —-a-w- c:\windows\system32\msls31.dll
2012-06-22 02:38:00 140920 —-a-w- c:\program files\internet explorer\sqmapi.dll
2012-06-22 02:38:00 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-06-22 02:38:00 107008 —-a-w- c:\program files\internet explorer\iecleanup.exe
2012-06-22 02:36:01 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2012-06-22 02:36:01 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2012-06-22 02:36:01 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2012-06-22 02:36:01 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2012-06-22 02:36:00 98816 —-a-w- c:\windows\system32\mfps.dll
2012-06-22 02:36:00 2873344 —-a-w- c:\windows\system32\mf.dll
2012-06-22 02:34:45 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2012-06-22 02:34:45 252928 —-a-w- c:\windows\system32\dxdiag.exe
2012-06-22 02:34:45 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2012-06-22 02:34:44 519680 —-a-w- c:\windows\system32\d3d11.dll
2012-06-22 02:34:43 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2012-06-22 02:34:43 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-06-22 02:34:43 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-06-21 07:58:09 984064 —-a-w- c:\windows\system32\crypt32.dll
2012-06-21 07:58:09 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-06-21 07:58:09 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-06-21 07:58:01 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2012-06-21 07:58:01 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2012-06-21 07:58:01 293376 —-a-w- c:\windows\system32\psisdecd.dll
2012-06-21 07:58:01 217088 —-a-w- c:\windows\system32\psisrndr.ax
2012-06-21 07:58:00 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-06-21 07:58:00 189952 —-a-w- c:\windows\system32\winmm.dll
2012-06-21 07:57:33 429056 —-a-w- c:\windows\system32\EncDec.dll
2012-06-21 07:57:21 964608 —-a-w- c:\program files\windows journal\JNWDRV.dll
2012-06-21 07:57:21 1404928 —-a-w- c:\program files\common files\microsoft shared\ink\InkObj.dll
2012-06-21 07:57:21 1218048 —-a-w- c:\program files\windows journal\NBDoc.DLL
2012-06-21 07:57:20 983040 —-a-w- c:\program files\windows journal\JNTFiltr.dll
2012-06-21 07:57:20 936960 —-a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2012-06-21 07:57:20 47104 —-a-w- c:\program files\windows journal\PDIALOG.exe
2012-06-21 07:57:18 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-21 07:57:17 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-21 07:57:16 66560 —-a-w- c:\windows\system32\packager.dll
2012-06-21 07:57:13 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-06-21 07:55:51 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2012-06-21 07:55:46 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2012-06-21 07:55:46 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2012-06-21 07:55:46 238080 —-a-w- c:\windows\system32\oleacc.dll
2012-06-21 07:55:45 563712 —-a-w- c:\windows\system32\oleaut32.dll
2012-06-21 07:55:15 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-21 07:55:14 2045440 —-a-w- c:\windows\system32\win32k.sys
2012-06-21 07:55:10 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-06-21 07:55:09 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-21 07:55:06 707584 —-a-w- c:\program files\common files\system\wab32.dll
2012-06-21 07:41:15 231424 —-a-w- c:\windows\system32\msshsq.dll
2012-06-21 07:32:56 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-06-21 02:24:23 ——– d—–w- c:\windows\system32\eu-ES
2012-06-21 02:24:23 ——– d—–w- c:\windows\system32\ca-ES
2012-06-21 02:24:17 ——– d—–w- c:\windows\system32\vi-VN
2012-06-20 10:18:02 ——– d—–w- c:\users\cazzim~1\appdata\local\ilrryeuh
.
==================== Find3M ====================
.
2012-06-22 02:35:59 586240 —-a-w- c:\windows\system32\stobject.dll
2012-06-22 02:35:59 209920 —-a-w- c:\windows\system32\mfplat.dll
2012-06-22 02:35:56 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2012-06-22 02:35:55 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2012-06-22 02:35:54 478720 —-a-w- c:\windows\system32\dxgi.dll
2012-06-22 02:35:54 37376 —-a-w- c:\windows\system32\cdd.dll
2012-06-22 02:35:54 258048 —-a-w- c:\windows\system32\winspool.drv
2012-06-22 02:35:54 189952 —-a-w- c:\windows\system32\d3d10core.dll
2012-06-22 02:35:54 1029120 —-a-w- c:\windows\system32\d3d10.dll
2012-06-22 02:35:53 847360 —-a-w- c:\windows\system32\OpcServices.dll
2012-06-22 02:35:53 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2012-06-22 02:35:53 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2012-06-22 02:35:52 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2012-04-15 15:46:59 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-03-27 04:09:30 293736 —-a-w- c:\program files\iTunesOutlookAddIn.dll
2012-03-27 04:09:24 421736 —-a-w- c:\program files\iTunesHelper.exe
2012-03-27 04:09:24 124776 —-a-w- c:\program files\iTunesMiniPlayer.dll
2012-03-27 04:09:22 156520 —-a-w- c:\program files\iTunesHelper.dll
2012-03-27 04:09:20 402792 —-a-w- c:\program files\iTunesAdmin.dll
2012-03-27 04:09:16 9777000 —-a-w- c:\program files\iTunes.exe
2012-03-27 04:09:06 21006696 —-a-w- c:\program files\iTunes.dll
2012-03-27 04:09:02 797208 —-a-w- c:\program files\gnsdk_sdkmanager.dll
2012-03-27 04:09:02 649576 —-a-w- c:\program files\iPodUpdaterExt.dll
2012-03-27 04:09:02 3029528 —-a-w- c:\program files\gnsdk_dsp.dll
2012-03-27 04:09:02 281112 —-a-w- c:\program files\gnsdk_submit.dll
2012-03-27 04:09:02 240152 —-a-w- c:\program files\gnsdk_musicid.dll
2012-03-06 19:44:32 112488 —-a-w- c:\program files\ITDetector.ocx
.
============= FINISH: 18:41:02.73 ===============