DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 23:16:06.56 on Sun 04/18/2010 Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_19 Microsoft� Windows Vista� Home Premium 6.0.6002.2.1252.1.1033.18.1470.595 [GMT -4:00] SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k apphost C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\inetsrv\inetinfo.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k iissvcs C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\rundll32.exe C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AVG\AVG9\avgtray.exe C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\System32\mobsync.exe C:\Windows\system32\taskeng.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Users\admin\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uStart Page = https://mycampus.southuniversity.edu/portal/server.pt? uDefault_Page_URL = hxxp://www.msn.com uInternet Settings,ProxyOverride = *.local uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: ALOT Toolbar Helper: {14ceeaff-96dd-4101-ae37-d5ecdc23c3f6} - c:\program files\alot\bin\bho\alotBHO.dll BHO: PriceGongBHO Class: {1631550f-191d-4826-b069-d9439253d926} - c:\program files\pricegong\2.1.0\PriceGongIE.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Shop to Win 2: {20fec4e7-f7b7-438b-8191-33d2efc5ebea} - c:\program files\shop to win 2\ShoppingBHO.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [SpeedItUpEX] c:\program files\speeditup free\SpeedItUp.exe -MINI uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messen~1\YahooMessenger.exe" -quiet uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1150595.exe -Update -1150595 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; OfficeLiveConnector.1.4; .NET CLR 3.0.30729; OfficeLivePatch.1.3; MSN Optimized;US)" -"http://mofunzone.com/popups/driversed.shtml" mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0379.0\mswinext.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [TMRUBottedTray] "c:\program files\trend micro\rubotted\TMRUBottedTray.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\users\admin\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} - hxxp://www.igl.net/clo/install/CLOActiveXInstallerProj1.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll AppInit_DLLs: avgrsstx.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\users\admin\appdata\roaming\mozilla\firefox\profiles\yeptl9ox.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p= FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - component: c:\program files\microsoft\search enhancement pack\search helper\firefoxextension\searchhelperextension\components\SEPsearchhelperff.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-25 216200] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-25 29512] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-25 242696] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-1-5 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 66632] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-14 916760] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-14 308064] R2 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2010-4-8 582992] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 12872] R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2010-4-8 206608] S3 Flash1;Flash1;c:\swsetup\sp43666\winphlash\FLASH1.sys [2006-3-1 3456] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-12-27 21504] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-10-10 54632] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864] S3 ST50220;Sonix ST50220 USB Video Camera Driver;c:\windows\system32\drivers\ST50220.sys [2010-4-3 26752] S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2010-4-8 206608] S3 WMSvc;Web Management Service;c:\windows\system32\inetsrv\WMSvc.exe [2008-12-27 11264] =============== Created Last 30 ================ 2010-04-15 01:11:50 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2010-04-15 01:11:50 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-04-15 01:11:50 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-04-15 01:11:44 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys 2010-04-15 01:11:42 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys 2010-04-15 01:11:42 200704 ----a-w- c:\windows\system32\iphlpsvc.dll 2010-04-15 01:11:01 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-04-15 01:11:01 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-04-15 01:10:54 420352 ----a-w- c:\windows\system32\vbscript.dll 2010-04-15 01:10:19 62464 ----a-w- c:\windows\system32\l3codeca.acm 2010-04-15 01:10:18 220672 ----a-w- c:\windows\system32\l3codecp.acm 2010-04-15 01:08:10 172032 ----a-w- c:\windows\system32\wintrust.dll 2010-04-15 01:07:17 98304 ----a-w- c:\windows\system32\cabview.dll 2010-04-08 13:19:21 206608 ----a-w- c:\windows\system32\drivers\TMPassthru.sys 2010-04-08 13:19:20 0 d-----w- c:\program files\Trend Micro 2010-04-08 13:05:21 1074232 ----a-w- c:\program files\RootkitBuster_2.80.1077.zip 2010-04-08 13:04:43 532480 ----a-w- c:\program files\cwshredder.exe 2010-04-08 13:04:19 6509608 ----a-w- c:\program files\RUBotted.exe 2010-04-08 13:03:40 1840232 ----a-w- c:\program files\HousecallLauncher.exe 2010-04-08 12:52:10 401720 ----a-w- c:\program files\HijackThis.exe 2010-04-07 18:48:43 80190 ----a-w- c:\programdata\nvModes.dat 2010-04-04 01:38:21 0 d-----w- c:\program files\HP 1.3MP Webcam 2010-04-04 00:46:14 0 d-----w- c:\program files\Rhapsody 2010-04-04 00:34:25 221215 ------w- c:\windows\system32\Divxdec.ax 2010-04-04 00:34:25 0 d-----w- c:\programdata\CyberLink 2010-04-04 00:31:37 89088 ------w- c:\windows\system32\atl71.dll 2010-04-04 00:31:37 1060864 ------w- c:\windows\system32\MFC71.dll 2010-04-04 00:31:37 1047552 ------w- c:\windows\system32\MFC71u.dll 2010-04-03 23:35:40 0 d-----w- c:\programdata\Hewlett-Packard 2010-04-03 23:34:06 0 d-----w- c:\users\admin\appdata\roaming\hpqLog 2010-04-03 23:06:35 0 d-----w- c:\windows\system32\Hauppauge 2010-04-03 23:06:34 258104 ----a-w- c:\windows\system32\hcwpnp32.dll 2010-04-03 23:06:30 98360 ----a-w- c:\windows\system32\hcwi2c32.dll 2010-04-03 23:06:30 36921 ----a-w- c:\windows\system32\hcwutl32_priv.dll 2010-04-03 23:06:30 36921 ----a-w- c:\windows\system32\hcwutl32.dll 2010-04-03 22:54:15 0 d-----w- c:\windows\nvtmpinst 2010-04-03 22:40:31 26752 ----a-w- c:\windows\system32\drivers\ST50220.sys 2010-04-03 22:35:46 0 d-----w- C:\System.sav 2010-04-03 19:54:35 632 --sha-r- c:\users\admin\ntuser.pol 2010-03-20 20:40:36 48128 ----a-w- c:\windows\system32\drivers\rimmptsk.sys 2010-03-20 20:40:36 44544 ----a-w- c:\windows\system32\drivers\rimsptsk.sys 2010-03-20 20:40:36 38400 ----a-w- c:\windows\system32\drivers\rixdptsk.sys 2010-03-20 20:40:35 172032 ----a-w- c:\windows\system32\rixdicon.dll ==================== Find3M ==================== 2010-04-09 03:39:15 411368 ----a-w- c:\windows\system32\deploytk.dll 2010-04-08 13:22:33 86016 ----a-w- c:\windows\inf\infstor.dat 2010-04-08 13:22:33 51200 ----a-w- c:\windows\inf\infpub.dat 2010-04-08 13:22:33 143360 ----a-w- c:\windows\inf\infstrng.dat 2010-04-03 22:19:47 13025 ----a-w- c:\users\admin\appdata\roaming\nvModes.dat 2010-03-30 04:46:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-30 04:45:52 20824 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-15 00:40:21 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2010-03-15 00:40:19 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2010-03-15 00:40:07 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2010-02-23 06:39:13 916480 ----a-w- c:\windows\system32\wininet.dll 2010-02-23 06:33:45 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-02-23 06:33:45 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-02-23 04:55:36 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2010-02-20 23:06:41 24064 ----a-w- c:\windows\system32\nshhttp.dll 2010-02-20 23:05:14 30720 ----a-w- c:\windows\system32\httpapi.dll 2010-02-20 22:30:35 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2010-02-20 20:53:34 411648 ----a-w- c:\windows\system32\drivers\http.sys 2010-02-18 20:47:43 121432 ---ha-w- c:\windows\system32\mlfcache.dat 2010-01-25 12:00:35 471552 ----a-w- c:\windows\system32\secproc_isv.dll 2010-01-25 12:00:35 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2010-01-25 12:00:35 152064 ----a-w- c:\windows\system32\secproc_ssp.dll 2010-01-25 12:00:22 471552 ----a-w- c:\windows\system32\secproc.dll 2010-01-25 11:58:52 332288 ----a-w- c:\windows\system32\msdrm.dll 2010-01-25 08:21:20 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe 2010-01-25 08:21:20 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2010-01-25 08:21:18 518144 ----a-w- c:\windows\system32\RMActivate.exe 2010-01-25 08:21:18 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe 2010-01-23 09:26:13 2048 ----a-w- c:\windows\system32\tzres.dll 2010-01-20 01:17:46 665600 ----a-w- c:\windows\inf\drvindex.dat 2009-01-05 00:12:11 174 --sha-w- c:\program files\desktop.ini 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-10-24 22:30:31 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat ============= FINISH: 23:18:39.81 ===============