We'll try this again. Let me know if you received all this, thank you for your help.
Logfile of HijackThis v1.99.1
Scan saved at 5:45:42 PM, on 8/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ca.my.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} (Panasonic Network Camera) -
http://81.130.200.130/SysCamInst.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 8195464601O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://www.wrexham.gov.uk/webcam/AxisCamControl.binO16 - DPF: {96816368-C1E3-414D-A193-63C3CC921990} (MJPEGRender Control) -
http://eilandonan.remotemanager.co.uk/c ... Render.ocxO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
DDS (Ver_09-07-30.01) - NTFSx86
Run by User at 17:39:08.76 on Tue 08/04/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.317 [GMT -4:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\User\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page =
hxxp://ca.my.yahoo.com/BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} -
hxxp://81.130.200.130/SysCamInst.cabDPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
hxxp://update.microsoft.com/windowsupda ... 8195464601DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} -
hxxp://www.wrexham.gov.uk/webcam/AxisCamControl.binDPF: {96816368-C1E3-414D-A193-63C3CC921990} -
hxxp://eilandonan.remotemanager.co.uk/c ... Render.ocxDPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://download.macromedia.com/pub/shoc ... wflash.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabNotify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-7-22 11608]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-7-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-7-28 72944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-7-22 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-7-22 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-7-22 55640]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\drivers\NtApm.sys [2009-7-21 9344]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-7-28 7408]
=============== Created Last 30 ================
2009-08-02 20:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-08-02 20:07 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-08-02 20:07 <DIR> --d----- c:\docume~1\user\applic~1\SUPERAntiSpyware.com
2009-08-02 20:06 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-08-02 09:02 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SecTaskMan
2009-08-02 09:02 <DIR> --d----- c:\program files\Security Task Manager
2009-08-02 08:39 <DIR> --d----- c:\program files\Trend Micro
2009-08-01 16:32 221,184 a------- c:\windows\system32\wmpns.dll
2009-08-01 09:10 <DIR> --d----- c:\program files\CCleaner
2009-07-28 17:39 410,984 a------- c:\windows\system32\deploytk.dll
2009-07-28 17:39 73,728 a------- c:\windows\system32\javacpl.cpl
2009-07-26 21:17 <DIR> --d----- c:\documents and settings\user\Tracing
2009-07-26 21:15 <DIR> --d----- c:\program files\Microsoft
2009-07-26 21:15 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-07-26 20:56 459,264 -c------ c:\windows\system32\dllcache\msfeeds.dll
2009-07-26 20:56 380,928 -c------ c:\windows\system32\dllcache\ieapfltr.dll
2009-07-26 20:56 268,288 -c------ c:\windows\system32\dllcache\iertutil.dll
2009-07-26 20:56 52,224 -c------ c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-26 20:56 63,488 -c------ c:\windows\system32\dllcache\icardie.dll
2009-07-26 20:56 13,824 -c------ c:\windows\system32\dllcache\ieudinit.exe
2009-07-26 20:56 2,452,872 -c------ c:\windows\system32\dllcache\ieapfltr.dat
2009-07-26 20:56 991,232 -c------ c:\windows\system32\dllcache\ieframe.dll.mui
2009-07-26 20:56 6,067,200 -c------ c:\windows\system32\dllcache\ieframe.dll
2009-07-25 18:04 268,648 a------- c:\windows\system32\mucltui.dll
2009-07-25 18:04 208,744 a------- c:\windows\system32\muweb.dll
2009-07-25 18:04 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-07-25 06:14 <DIR> --d----- c:\program files\common files\Windows Live
2009-07-24 22:26 488 a------- C:\hpfr5550.xml
2009-07-24 22:23 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
2009-07-24 22:23 25,856 a------- c:\windows\system32\drivers\usbprint.sys
2009-07-24 22:23 15,104 ac------ c:\windows\system32\dllcache\usbscan.sys
2009-07-24 22:23 15,104 a------- c:\windows\system32\drivers\usbscan.sys
2009-07-24 22:21 <DIR> --d----- c:\program files\common files\Hewlett-Packard
2009-07-24 22:14 19,558 a------- c:\windows\hpoins01.dat
2009-07-24 22:14 16,606 -------- c:\windows\hpomdl01.dat
2009-07-24 22:13 <DIR> --d----- c:\temp\HP All-in-One Series Web Release
2009-07-24 22:13 <DIR> --d----- C:\temp
2009-07-24 07:12 <DIR> --d----- c:\docume~1\user\applic~1\Malwarebytes
2009-07-24 07:12 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-24 07:12 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-24 07:12 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-24 07:12 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-23 13:25 <DIR> --d----- c:\windows\pss
2009-07-23 13:11 21,504 ac------ c:\windows\system32\dllcache\hidserv.dll
2009-07-23 13:11 21,504 a------- c:\windows\system32\hidserv.dll
2009-07-23 13:11 14,592 ac------ c:\windows\system32\dllcache\kbdhid.sys
2009-07-23 13:11 14,592 a------- c:\windows\system32\drivers\kbdhid.sys
2009-07-23 13:10 32,128 ac------ c:\windows\system32\dllcache\usbccgp.sys
2009-07-23 13:10 32,128 a------- c:\windows\system32\drivers\usbccgp.sys
2009-07-22 10:09 32,656 a------- c:\windows\system32\msonpmon.dll
2009-07-22 10:00 <DIR> --d----- c:\windows\SHELLNEW
2009-07-22 09:01 55,640 a------- c:\windows\system32\drivers\avgntflt.sys
2009-07-22 09:01 <DIR> --d----- c:\program files\Avira
2009-07-22 09:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-07-21 13:46 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat
2009-07-21 13:34 <DIR> --d----- c:\windows\system32\XPSViewer
2009-07-21 13:34 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-21 13:34 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-21 13:34 117,760 -------- c:\windows\system32\prntvpt.dll
2009-07-21 13:33 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
2009-07-21 13:33 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
2009-07-21 13:33 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-07-21 13:33 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-07-21 13:33 <DIR> --d----- C:\763444c5766d0ff90a85b8ef2ca157
2009-07-21 13:27 <DIR> --d----- c:\windows\system32\URTTemp
2009-07-21 13:05 284,160 -c------ c:\windows\system32\dllcache\pdh.dll
2009-07-21 13:05 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-07-21 13:05 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-07-21 13:05 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-07-21 13:05 110,592 -c------ c:\windows\system32\dllcache\services.exe
2009-07-21 13:05 729,088 -c------ c:\windows\system32\dllcache\lsasrv.dll
2009-07-21 13:05 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-07-21 13:05 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-07-21 13:05 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-07-21 13:05 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-21 13:04 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-21 13:04 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-21 13:04 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-07-21 13:04 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-07-21 13:04 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-07-21 13:04 333,952 -c------ c:\windows\system32\dllcache\srv.sys
2009-07-21 13:03 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-07-21 13:02 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll
2009-07-21 13:02 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2009-07-21 13:02 331,776 -c------ c:\windows\system32\dllcache\msadce.dll
2009-07-21 13:02 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2009-07-21 13:01 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-07-21 13:01 203,136 -c------ c:\windows\system32\dllcache\rmcast.sys
2009-07-21 13:00 <DIR> --d----- c:\windows\system32\PreInstall
2009-07-21 13:00 <DIR> --d-h--- c:\windows\$hf_mig$
2009-07-21 12:58 31,768 a------- c:\windows\system32\wucltui.dll.mui
2009-07-21 12:58 23,576 a------- c:\windows\system32\wuaucpl.cpl.mui
2009-07-21 12:58 18,456 a------- c:\windows\system32\wuaueng.dll.mui
2009-07-21 12:58 23,576 a------- c:\windows\system32\wuapi.dll.mui
2009-07-21 12:58 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2009-07-21 12:57 <DIR> --dsh--- c:\documents and settings\user\UserData
2009-07-21 12:54 316,640 a------- c:\windows\WMSysPr9.prx
2009-07-21 12:54 <DIR> --d----- c:\windows\system32\wbem\AutoRecover
2009-07-21 12:52 <DIR> --ds---- c:\windows\system32\Microsoft
2009-07-21 12:01 2,113,536 -------- c:\windows\system32\dxdiagn.dll
2009-07-21 11:58 <DIR> --d----- c:\windows\ServicePackFiles
2009-07-21 11:58 33,792 ac------ c:\windows\system32\dllcache\custsat.dll
2009-07-21 11:54 19,569 a------- c:\windows\002620_.tmp
2009-07-21 11:53 <DIR> --d----- c:\windows\system32\ReinstallBackups
2009-07-21 11:53 26,488 a------- c:\windows\system32\spupdsvc.exe
2009-07-21 11:50 <DIR> --d----- c:\windows\EHome
2009-07-21 11:40 13,646 a------- c:\windows\system32\wpa.bak
2009-07-21 11:31 <DIR> --dsh--- c:\windows\Installer
2009-07-21 11:31 <DIR> --d----- c:\documents and settings\User
2009-07-21 11:30 8,192 a------- c:\windows\REGLOCS.OLD
2009-07-21 11:27 229,439 ac------ c:\windows\system32\dllcache\multibox.dll
2009-07-21 11:26 108,827 ac------ c:\windows\system32\dllcache\hanja.lex
2009-07-21 11:25 94,720 ac------ c:\windows\system32\dllcache\certmap.ocx
2009-07-21 11:25 <DIR> --d----- c:\windows\system32\xircom
2009-07-21 11:25 <DIR> --d----- c:\windows\system32\wbem\snmp
2009-07-21 11:25 <DIR> --d----- C:\DELL
2009-07-21 11:21 24,576 a------- c:\windows\system32\xpsp1hfm.exe
2009-07-21 11:19 2,577 a------- c:\windows\system32\CONFIG.NT
2009-07-21 11:19 0 a------- c:\windows\control.ini
2009-07-21 11:19 25,065 a------- c:\windows\system32\wmpscheme.xml
2009-07-21 11:19 23,392 a------- c:\windows\system32\nscompat.tlb
2009-07-21 11:19 16,832 a------- c:\windows\system32\amcompat.tlb
2009-07-21 11:19 299,552 a------- c:\windows\WMSysPrx.prx
2009-07-21 11:18 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-07-21 11:18 488 a---hr-- c:\windows\system32\WindowsLogon.manifest
2009-07-21 11:18 488 a---hr-- c:\windows\system32\logonui.exe.manifest
2009-07-21 11:18 <DIR> --ds---- c:\windows\Downloaded Program Files
2009-07-21 11:18 <DIR> --d--r-- c:\windows\Offline Web Pages
2009-07-21 11:17 749 a---hr-- c:\windows\WindowsShell.Manifest
2009-07-21 11:17 749 a---hr-- c:\windows\system32\wuaucpl.cpl.manifest
2009-07-21 11:17 749 a---hr-- c:\windows\system32\sapi.cpl.manifest
2009-07-21 11:17 749 a---hr-- c:\windows\system32\nwc.cpl.manifest
2009-07-21 11:17 749 a---hr-- c:\windows\system32\ncpa.cpl.manifest
2009-07-21 11:17 749 a---hr-- c:\windows\system32\cdplayer.exe.manifest
2009-07-21 11:17 4,399,505 ac------ c:\windows\system32\dllcache\nls302en.lex
2009-07-21 11:17 <DIR> --d----- c:\windows\system32\DirectX
2009-07-21 11:16 <DIR> --d----- c:\program files\common files\MSSoap
2009-07-21 11:15 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-07-21 11:15 <DIR> --d----- c:\program files\Online Services
2009-07-21 11:14 <DIR> --d----- c:\program files\Messenger
2009-07-21 11:14 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-07-21 11:14 <DIR> --d----- c:\program files\Windows NT
2009-07-21 07:07 <DIR> --d----- c:\program files\common files\ODBC
2009-07-21 07:06 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-07-21 07:06 <DIR> --d--r-- c:\documents and settings\all users\Documents
==================== Find3M ====================
2009-07-21 12:04 80,943 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-21 11:15 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-06-29 12:12 827,392 a------- c:\windows\system32\wininet.dll
2009-06-29 12:12 17,408 a------- c:\windows\system32\corpol.dll
2009-06-29 12:12 78,336 -------- c:\windows\system32\ieencode.dll
2009-06-16 10:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-03 15:09 1,291,264 a------- c:\windows\system32\quartz.dll
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll