. DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24 Run by [removed] at 13:06:04 on 2011-07-02 Microsoft� Windows Vista� Home Basic 6.0.6002.2.1252.1.1033.18.3006.1630 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} AV: AVG Anti-Virus 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\AVG\AVG10\avgam.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Windows\system32\svchost.exe -k HPService C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files\AVG\AVG10\avgtray.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Users\joe2.Joede-PC\Desktop\Virus Removal Tool\setup_9.0.0.722_01.07.2011_19-08\setup_9.0.0.722_01.07.2011_19-08.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uSearch Page = uStart Page = hxxp://www.bigseekpro.com/anyvideo2dvd/{2F8B4016-5CB3-4774-BC75-3AEFEBA9D4A8} uSearch Bar = mStart Page = hxxp://www.bigseekpro.com/anyvideo2dvd/{2F8B4016-5CB3-4774-BC75-3AEFEBA9D4A8} uInternet Settings,ProxyOverride = *.local mSearchAssistant = uURLSearchHooks: H - No File mURLSearchHooks: H - No File BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\acdaemon.exe mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBJAC0ATgA3AEEAOABCAC0AWgAzAEoAQQBZAC0AUwA4ADkAOQBSAC0ATgBBAFMARwBWAC0ATgBHAEoARQBSAA"&"inst=NwA2AC0ANQAxADAANQA3ADMAMAAzADEALQBVADkAMAArADEALQBUAFAAKwAxAC0AWABPADMANgArADEALQBTAFQAMQArADIALQBUAEIAOQArADIALQBOADEARAArADEALQBQAEwAKwA5AC0AQwBJAEEAOQAwACsAMgA"&"prod=94"&"ver=9.0.894 StartupFolder: c:\users\joe2~1.joe\appdata\roaming\micros~1\windows\startm~1\programs\startup\setup_~1.lnk - c:\users\joe2.joede-pc\desktop\virus removal tool\setup_9.0.0.722_01.07.2011_19-08\startup.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll Trusted Zone: melissadata.com\www Trusted Zone: soberrecovery.com\www Trusted Zone: webex.com DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255139612355 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1255140066743 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} - hxxp://support.microsoft.com/mats/DiagWebControl.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{4788D85D-5742-4232-A4C4-CA1AC1493CE0} : DhcpNameServer = [removed] [removed] Handler: AutorunsDisabled\grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll LSA: Authentication Packages = msv1_0 c:\windows\system32\opnnmNgG Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\users\joe2.joede-pc\appdata\roaming\mozilla\firefox\profiles\wc39d57t.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q= FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll FF - component: c:\users\joe2.joede-pc\appdata\roaming\mozilla\firefox\profiles\wc39d57t.default\extensions\[removed]\components\zoteroWinWordIntegration.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\tracker software\pdf viewer\npPDFXCviewNPPlugin.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\users\joe2.joede-pc\appdata\roaming\mozilla\plugins\npatgpc.dll . ============= SERVICES / DRIVERS =============== . R0 00429732;00429732 Boot Guard Driver;c:\windows\system32\drivers\00429732.sys [2011-7-1 37392] R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592] R0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\drivers\nvamacpi.sys [2011-6-4 24680] R1 00429731;00429731;c:\windows\system32\drivers\00429731.sys [2011-7-1 128016] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 297168] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\rsdrv.sys [2011-3-3 22312] R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264] R1 MpKslaaac50c4;MpKslaaac50c4;c:\programdata\microsoft\microsoft antimalware\definition updates\{906731ad-4a37-46b2-a877-47c6d17b538f}\MpKslaaac50c4.sys [2011-7-2 28752] R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2009-10-30 98392] R1 setup_9.0.0.722_01.07.2011_19-08drv;setup_9.0.0.722_01.07.2011_19-08drv;c:\windows\system32\drivers\0042973.sys [2011-7-1 311312] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952] R2 AERTFilters;Andrea RT Filters Service;c:\program files\realtek\audio\hda\AERTSrv.exe [2011-6-4 81920] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-5-2 12672] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-3-28 21504] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-5-22 809296] R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2008-2-23 615312] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134480] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 28624] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360] R3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2008-3-28 987648] R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2008-3-28 251904] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2010-4-18 84832] S3 atidgllk;atidgllk;c:\dell\drivers\r169419\atidgllk.sys [2008-2-9 12048] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-5-28 984392] S3 AWEAlloc;AWE Memory Allocation Driver;c:\windows\system32\drivers\awealloc.sys [2010-4-17 15184] S3 FIXUSTOR;FIXUSTOR;c:\windows\system32\drivers\fixustor.sys [2010-4-14 12800] S3 ImDisk;ImDisk Virtual Disk Driver;c:\windows\system32\drivers\imdisk.sys [2010-4-17 28760] S3 ImDskSvc;ImDisk Virtual Disk Driver Helper;c:\windows\system32\imdsksvc.exe [2010-4-17 10240] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 wrssweep;Webroots Volume Access Driver;c:\program files\webroot\washer\wrSSweep.sys [2011-3-2 21904] . =============== File Associations =============== . regfile="regedit.exe "%1"" txtfile=%SystemRoot%\NOTEPAD.EXE %1 . =============== Created Last 30 ================ . 2011-07-02 16:42:18 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{906731ad-4a37-46b2-a877-47c6d17b538f}\MpKslaaac50c4.sys 2011-07-02 16:38:10 388096 ----a-r- c:\users\joe2.joede-pc\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-07-02 01:48:55 7074640 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{906731ad-4a37-46b2-a877-47c6d17b538f}\mpengine.dll 2011-07-02 00:50:31 -------- d-----w- c:\users\joe2.joede-pc\appdata\local\HP 2011-07-02 00:15:57 316928 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\hpfpp092.dll 2011-07-02 00:07:58 -------- d-----w- c:\program files\common files\HP 2011-07-02 00:07:14 -------- d-----w- c:\windows\hpoj4500g510n-z 2011-07-02 00:06:20 716288 ----a-w- c:\windows\system32\hpwwiax9.dll 2011-07-02 00:06:20 593920 ----a-w- c:\windows\system32\hpwtscl5.dll 2011-07-02 00:06:20 372736 ----a-w- c:\windows\system32\hppldcoi.dll 2011-07-02 00:06:20 315392 ----a-w- c:\windows\system32\hpwvst01.dll 2011-07-02 00:05:56 452408 ----a-w- c:\windows\system32\hpzids01.dll 2011-07-02 00:05:52 122880 ----a-w- c:\windows\system32\hpf3l092.dll 2011-07-01 18:08:57 -------- d-----w- c:\programdata\Kaspersky Lab 2011-07-01 18:08:13 37392 ----a-w- c:\windows\system32\drivers\00429732.sys 2011-07-01 18:08:13 311312 ----a-w- c:\windows\system32\drivers\0042973.sys 2011-07-01 18:08:13 128016 ----a-w- c:\windows\system32\drivers\00429731.sys 2011-07-01 16:52:36 -------- d-----w- c:\program files\HP 2011-07-01 16:34:47 -------- d-----w- C:\HPAiOScrubber 2011-06-29 03:06:26 276992 ----a-w- c:\windows\system32\schannel.dll 2011-06-25 15:17:45 -------- d-----w- c:\windows\system32\wbem\Logs 2011-06-25 03:12:34 2106216 ----a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll 2011-06-25 03:12:33 1998168 ----a-w- c:\program files\mozilla firefox\d3dx9_43.dll 2011-06-24 15:00:35 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-20 23:40:42 -------- d-----w- c:\programdata\ErrorEND 2011-06-16 19:59:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2011-06-16 19:59:04 141104 ----a-w- c:\program files\internet explorer\sqmapi.dll 2011-06-16 19:59:03 1797632 ----a-w- c:\windows\system32\jscript9.dll 2011-06-16 16:51:38 -------- d-----w- c:\users\joe2.joede-pc\appdata\roaming\EurekaLog 2011-06-16 13:52:19 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys 2011-06-16 13:52:17 273408 ----a-w- c:\windows\system32\drivers\afd.sys 2011-06-16 13:52:13 146432 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-06-16 13:52:13 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-16 13:52:11 563712 ----a-w- c:\windows\system32\oleaut32.dll 2011-06-16 13:52:08 739328 ----a-w- c:\windows\system32\inetcomm.dll 2011-06-16 13:52:03 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-16 13:52:03 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-16 13:52:03 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-16 13:51:59 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat 2011-06-14 13:52:59 -------- d-----w- c:\users\joe2.joede-pc\appdata\local\Temp 2011-06-12 18:02:05 -------- d-----w- c:\users\joe2.joede-pc\appdata\local\VS Revo Group 2011-06-12 17:44:05 -------- d-----w- c:\program files\Unlocker 2011-06-09 02:52:51 -------- d-----w- c:\programdata\dB01803OoMmG01803 2011-06-09 02:09:24 -------- d-----w- c:\users\joe2.joede-pc\appdata\roaming\Systweak 2011-06-06 16:55:30 183696 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2011-06-06 16:55:30 183696 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2011-06-04 12:05:48 72704 ----a-w- c:\windows\system32\CmdRtr.DLL 2011-06-04 12:05:48 146432 ----a-w- c:\windows\system32\APOMngr.DLL 2011-06-04 10:40:40 729600 ----a-w- c:\windows\system32\cohelper.dll . ==================== Find3M ==================== . 2011-06-04 12:04:15 319456 ----a-w- c:\windows\DIFxAPI.dll 2011-05-30 10:54:26 800 ---ha-w- C:\aaw7boot.cmd 2011-05-29 16:36:20 387600 ----a-w- c:\windows\system32\FTBSaver.scr 2011-05-29 13:11:30 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 13:11:20 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-04-15 01:28:18 134480 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys 2011-04-05 04:59:56 297168 ----a-w- c:\windows\system32\drivers\avgtdix.sys . ============= FINISH: 13:09:57.28 ===============