Jerry125
Topic Starter
Hi, I have unfortunately been infected with Trojan Horse Hider.MPR. It was picked up immediately by AVG, and although it says it is removed when I click remove all, both AVG and Malware Bytes Anti-Malware keep reporting problems if I scan again. And upon booting up I am always met with the same alert from AVG. I have not had issues getting on websites that are sometimes reported so I am hopeful not too much damage has been done yet. I also tried running both AVG and MBAM in windows safe mode and even though they both reported it gone after I removed it once, upon booting up normally it returns. Rebooting from a succesful scan to safe mode leads to nothing being found, but its obviously still there.
Below is the DDS report. Let me know if you need anything else. Thanks in advance
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 21:35:05.86 on 05/11/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3582.2300 [GMT 0:00]
.
AV: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Napster\napster.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\AVG Secure Search\ScriptHelperInstaller\12.2.6\ScriptHelper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\CORE-STATIC\CCC.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Administrator\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://home.bt.yahoo.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: GoldMember Toolbar: {0fc64d74-ea76-49a3-b606-7801b5013798} - c:\program files\goldmember\tbGold.dll
mURLSearchHooks: GoldMember Toolbar: {0fc64d74-ea76-49a3-b606-7801b5013798} - c:\program files\goldmember\tbGold.dll
mURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\users\administrator\appdata\local\yrsnltir\hxhavtri.exe
BHO: GoldMember Toolbar: {0fc64d74-ea76-49a3-b606-7801b5013798} - c:\program files\goldmember\tbGold.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\12.2.5.34\AVG Secure Search_toolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: GoldMember Toolbar: {0fc64d74-ea76-49a3-b606-7801b5013798} - c:\program files\goldmember\tbGold.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\12.2.5.34\AVG Secure Search_toolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Creative Detector] "c:\program files\creative\mediasource\detector\CTDetect.exe" /R
uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [HxhAvtri] c:\users\administrator\appdata\local\yrsnltir\hxhavtri.exe
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729; OfficeLiveConnector.1.5; OfficeLivePatch.1.3; .NET4.0C; Creative AutoUpdate v1.40.01)" -"http://www8.agame.com/games/shockwave/h/horse_eventing_2/horse_eventing2_girlsgogames_co_uk.html"
mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [ROC_ROC_JULY_P1] "c:\program files\avg secure search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
mRun: [ROC_ROC_NT] "c:\program files\avg secure search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\startup\hxhavtri.exe
StartupFolder: c:\users\admini~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\photof~1.lnk - c:\program files\panasonic\photofunstudio\PhAutoRun.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\12.2.6\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\admini~1\appdata\roaming\mozilla\firefox\profiles\pr5p6i5w.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bf4dcc625-59e9-40ac-89f7-21591b3ab011%7D&mid=83c158a0f9bbc20850ad0e0872672375-4bc975ad2489380ad3122a27b680006ed5881374&ds=AVG&v=11.1.0.12&lang=en&pr=fr&d=2012-04-28%2011%3A29%3A23&sap=ku&q=
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff10.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff11.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff12.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff13.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff5.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff6.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff7.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff8.dll
FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff9.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\11.2.0\npsitesafety.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\administrator\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-9-21 55008]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 177376]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-10-5 93536]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-9-14 35552]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2009-2-3 63096]
R1 atitray;atitray;c:\program files\ray adams\ati tray tools\atitray.sys [2011-3-27 20384]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-9-13 177504]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-9-21 19936]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-10-2 159712]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-9-21 164832]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2012-8-29 27496]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-7-27 63960]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-2-15 163328]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-10-2 5783672]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-10-2 193568]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\program files\common files\avg secure search\vtoolbarupdater\12.2.6\ToolbarUpdater.exe [2012-8-29 722528]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2012-2-15 9182208]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2012-2-15 264704]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2011-12-5 83472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-7 250808]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2009-11-14 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2009-11-14 79360]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe [2011-6-2 25832]
S3 nenum13E;nenum13E;c:\users\admini~1\appdata\local\temp\nenum13E.sys [2011-1-2 31744]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
SUnknown Micorsoft Windows Service;Micorsoft Windows Service; [x]
.
=============== Created Last 30 ================
.
2072-04-03 13:13:14 607296 ——w- c:\program files\microsoft games\age of empires iii\deformerdllyD.dll
2067-05-21 20:35:22 106496 —-a-w- c:\program files\microsoft games\impossible creatures\Filesystem.dll
2012-11-05 20:42:11 ——– d—–w- c:\users\admini~1\appdata\local\{896A7C47-D14C-4C05-9D87-0404D0988D29}
2012-11-05 20:07:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2012-11-05 20:07:35 ——– d—–w- c:\progra~2\Spybot - Search & Destroy
2012-11-05 20:03:01 ——– d—–w- c:\users\admini~1\appdata\roaming\LavasoftStatistics
2012-11-05 20:02:21 ——– d—–w- c:\users\admini~1\appdata\roaming\Ad-Aware Antivirus
2012-11-05 19:41:35 203120 —-a-w- c:\windows\system32\drivers\PCTSD.sys
2012-11-05 19:41:35 ——– d—–w- c:\program files\common files\PC Tools
2012-11-05 19:40:52 ——– d—–w- c:\progra~2\PC Tools
2012-11-05 19:40:51 ——– d—–w- c:\users\admini~1\appdata\roaming\TestApp
2012-11-05 19:30:32 ——– d—–w- c:\program files\Enigma Software Group
2012-11-05 19:29:54 ——– d—–w- c:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP
2012-11-05 19:18:49 ——– d—–w- c:\users\admini~1\appdata\roaming\SpeedyPC Software
2012-11-05 19:18:49 ——– d—–w- c:\users\admini~1\appdata\roaming\DriverCure
2012-11-05 19:18:37 ——– d—–w- c:\progra~2\SpeedyPC Software
2012-11-04 20:58:53 ——– d—–w- c:\users\admini~1\appdata\local\{1F8B201A-026A-46C9-A78D-AA4B1638DC6C}
2012-11-04 19:18:58 ——– d—–w- c:\users\admini~1\appdata\local\yrsnltir
2012-11-04 08:42:52 ——– d—–w- c:\users\admini~1\appdata\local\{3588CFCE-C95E-4FA6-B0C6-293441FC2E52}
2012-11-03 10:26:38 ——– d—–w- c:\users\admini~1\appdata\local\{19B6AC01-D0EB-41CE-AE62-F1A271F56F9C}
2012-11-02 09:15:25 ——– d—–w- c:\users\admini~1\appdata\local\{010F65DF-3C3D-4BC7-BCE5-5E35F6C3C45D}
2012-11-01 12:45:57 ——– d—–w- c:\users\admini~1\appdata\local\{246916A8-9E89-40AE-B602-757CC602877C}
2012-11-01 09:06:04 ——– d—–w- c:\users\admini~1\appdata\local\{52C25F90-C724-41D2-821B-1CCE7DE8F2B0}
2012-11-01 08:43:47 ——– d—–w- c:\users\admini~1\appdata\local\{9AC4DEF3-AEC8-4123-90AC-31FAF1834005}
2012-10-31 14:36:26 ——– d—–w- c:\users\admini~1\appdata\local\{DCF21C74-61D0-488C-9E14-6E7211E6C377}
2012-10-30 09:36:05 ——– d—–w- c:\users\admini~1\appdata\local\{4B5115AD-FD7E-4D03-B36A-BF6371198162}
2012-10-29 05:54:31 ——– d—–w- c:\users\admini~1\appdata\local\{380AA61B-8719-4D5F-9ABE-D94538CFA24A}
2012-10-28 19:25:40 ——– d—–w- c:\users\admini~1\appdata\local\{897CD980-EE1E-4A98-B4DB-69DFEF88FB0E}
2012-10-27 21:47:01 ——– d—–w- c:\users\admini~1\appdata\local\{6072D39D-39C8-4DF8-A5D6-CDE978A763F5}
2012-10-27 09:46:25 ——– d—–w- c:\users\admini~1\appdata\local\{18BED22C-7398-4496-89B2-471047931B37}
2012-10-26 08:11:26 ——– d—–w- c:\users\admini~1\appdata\local\{9C5747C5-9D46-417E-BF3F-7529A773633D}
2012-10-25 11:32:14 ——– d—–w- c:\users\admini~1\appdata\local\{A505E34F-8EB0-402D-93AA-ED9F0EA2ED92}
2012-10-25 07:54:12 ——– d—–w- c:\users\admini~1\appdata\local\{3D85A6B5-4CA3-40D0-90B4-D427CA2FD24F}
2012-10-24 08:26:39 ——– d—–w- c:\users\admini~1\appdata\local\{8C311797-94DF-434D-AADE-C468DA461C5A}
2012-10-23 09:03:53 ——– d—–w- c:\users\admini~1\appdata\local\{FE82CFE6-A9C5-4783-A52F-62F823E3BBDE}
2012-10-22 08:14:04 ——– d—–w- c:\users\admini~1\appdata\local\{F0D9049B-9235-476C-AB55-9EA5B58B50CF}
2012-10-21 07:43:54 ——– d—–w- c:\users\admini~1\appdata\local\{58FE7224-5CD3-4F0D-9041-E937EE54D2DB}
2012-10-20 10:07:41 ——– d—–w- c:\users\admini~1\appdata\local\{93FF91D7-94FE-42A0-B0FB-1184F1B493F8}
2012-10-20 06:55:03 ——– d—–w- c:\users\admini~1\appdata\local\{5DF2335C-0F6A-40C4-888F-D8B84D02FF08}
2012-10-19 14:16:22 ——– d—–w- c:\users\admini~1\appdata\local\{0785D2AD-77F4-4E35-8FAB-6023BB7BBED3}
2012-10-18 21:50:59 ——– d—–w- c:\users\admini~1\appdata\local\{511F87C2-2C53-41E0-9B0D-7204620BB7F0}
2012-10-18 09:04:38 ——– d—–w- c:\users\admini~1\appdata\local\{25C23D01-0C72-4A16-981A-23B360708B9E}
2012-10-17 08:28:34 ——– d—–w- c:\users\admini~1\appdata\local\{048077EF-FF11-495C-BD09-34CBA39CABE4}
2012-10-16 14:33:02 ——– d—–w- c:\users\admini~1\appdata\local\{70454EFE-2D4C-479F-A498-38A247D8FC31}
2012-10-16 07:10:03 ——– d—–w- c:\users\admini~1\appdata\local\{605425D3-E364-44AA-8708-BC33DB1A20D4}
2012-10-15 07:57:50 ——– d—–w- c:\users\admini~1\appdata\local\{EC68A1B2-FC01-4CA2-9E91-F7A559CE1FCE}
2012-10-14 09:39:13 ——– d—–w- c:\users\admini~1\appdata\local\{05C798E2-7E52-4AFA-8FEC-10361B87EE8B}
2012-10-14 07:56:48 ——– d—–w- c:\users\admini~1\appdata\local\{C5E17C35-2126-4F3D-9F1D-B6D37944BE4A}
2012-10-13 12:50:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-13 12:49:02 ——– d—–w- c:\program files\iPod
2012-10-13 12:49:01 ——– d—–w- c:\progra~2\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-13 09:57:29 ——– d—–w- c:\users\admini~1\appdata\local\{B87D7276-A6E4-4D72-B5CE-9F75A3CF4CFD}
2012-10-12 08:48:48 ——– d—–w- c:\users\admini~1\appdata\local\{8A1BA2D4-DE99-4564-BCD4-4B52B5E049B4}
2012-10-11 09:29:53 ——– d—–w- c:\users\admini~1\appdata\local\{FC28620A-9B1D-4096-B34C-3096C4B2D8E9}
2012-10-10 09:19:49 985088 —-a-w- c:\windows\system32\crypt32.dll
2012-10-10 09:19:49 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-10-10 09:19:49 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 09:19:44 172544 —-a-w- c:\windows\system32\wintrust.dll
2012-10-10 09:19:43 2048 —-a-w- c:\windows\system32\tzres.dll
2012-10-10 09:19:39 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-10 09:19:39 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-10-10 09:10:43 ——– d—–w- c:\users\admini~1\appdata\local\{F70BE33E-E552-418C-9409-D59E2D0ADA3C}
2012-10-09 09:09:37 ——– d—–w- c:\users\admini~1\appdata\local\{4D07CA71-4FEA-4448-B39B-0A9809102807}
2012-10-08 09:28:25 ——– d—–w- c:\users\admini~1\appdata\local\{77FAE026-4D5F-4B81-82C0-1DAD50BDD55F}
2012-10-07 07:44:28 ——– d—–w- c:\users\admini~1\appdata\local\{B9A11CD3-D19F-42EB-8C8A-8E79C4430338}
.
==================== Find3M ====================
.
2012-10-09 11:38:10 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-09 11:38:10 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-09 19:47:28 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll
2012-08-24 06:59:17 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 06:51:27 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 06:51:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 06:47:26 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 06:47:12 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 06:43:58 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-08-21 12:01:22 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2012-08-14 18:58:36 21840 —-atw- c:\windows\system32\SIntfNT.dll
2012-08-14 18:58:36 17212 —-atw- c:\windows\system32\SIntf32.dll
2012-08-14 18:58:36 12067 —-atw- c:\windows\system32\SIntf16.dll
.
============= FINISH: 21:36:06.40 ===============