Just re-read the post haha, noticed about attached documents won't be read. Here's the pasted ones.
GMER log:
GMER 1.0.15.15570 -
http://www.gmer.net
Rootkit scan 2011-04-19 20:40:18
Windows 6.1.7601 Service Pack 1
Running: 77qqqhdz.exe
---- Files - GMER 1.0.15 ----
File C:\## aswSnx private storage 0 bytes
File C:\## aswSnx private storage\r131 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba} 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\attrib 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data\Applications 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data\Applications\Windows 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk 8192 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log 1048576 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00D5F.log 1048576 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00D60.log 1048576 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00D61.log 1048576 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Default 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Default\AppData 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Default\AppData\Local 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Default\AppData\Local\Microsoft 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Default\AppData\Local\Microsoft\Windows 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Google 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Google\Chrome 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Google\Chrome\User Data 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Google\Chrome\User Data\Default 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Google\Chrome\User Data\Default\Cache 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\History 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\History\History.IE5 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 16384 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8R3FIZ18 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8R3FIZ18\desktop.ini 67 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 49152 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JNEYZ0JD 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JNEYZ0JD\desktop.ini 67 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PEIH52PS 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PEIH52PS\desktop.ini 67 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XYKUQ61H 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XYKUQ61H\desktop.ini 67 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini 67 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Local\Temp 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\LocalLow 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\LocalLow\Sun 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\LocalLow\Sun\Java 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\LocalLow\Sun\Java\Deployment 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\LocalLow\Sun\Java\Deployment\cache 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming\Macromedia 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming\Macromedia\Flash Player 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming\Microsoft 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming\Microsoft\Windows 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming\Microsoft\Windows\Cookies 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming\Microsoft\Windows\Cookies\index.dat 16384 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming\Microsoft\Windows\IETldCache 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Users\Taylor\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat 16384 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\system32 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\system32\config 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\system32\config\systemprofile 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\system32\config\systemprofile\AppData 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\system32\config\systemprofile\AppData\Local 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\system32\config\systemprofile\AppData\Local\Microsoft 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files 0 bytes
File C:\## aswSnx private storage\r131\TFC.exe_{4f396aba-6acf-11e0-99ff-a4badbc553ba}\image\Windows\Temp 0 bytes
File C:\## aswSnx private storage\snx_rhive 262144 bytes
File C:\## aswSnx private storage\snx_rhive.LOG1 25600 bytes
File C:\## aswSnx private storage\snx_rhive.LOG2 0 bytes
File C:\## aswSnx private storage\snx_rhive{f6441f25-6a8c-11e0-82a8-a4badbc553ba}.TM.blf 65536 bytes
File C:\## aswSnx private storage\snx_rhive{f6441f25-6a8c-11e0-82a8-a4badbc553ba}.TMContainer00000000000000000001.regtrans-ms 524288 bytes
File C:\## aswSnx private storage\snx_rhive{f6441f25-6a8c-11e0-82a8-a4badbc553ba}.TMContainer00000000000000000002.regtrans-ms 524288 bytes
File C:\## aswSnx private storage\webStorage 0 bytes
File C:\## aswSnx private storage\webStorage\attrib 0 bytes
File C:\## aswSnx private storage\webStorage\image 0 bytes
File C:\## aswSnx private storage\webStorage\image\rkill.log 633 bytes
File C:\## aswSnx private storage\webStorage\image\Users 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Explorer 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl 16384 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\History 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\History\History.IE5 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 16384 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CMCNQUY9 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CMCNQUY9\desktop.ini 67 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DFVXZHP9 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DFVXZHP9\desktop.ini 67 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EEJPHA4D 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EEJPHA4D\desktop.ini 67 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 32768 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P776KH7Y 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P776KH7Y\desktop.ini 67 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\curo.reg 220 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\extra.dat 472 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\h 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\h\explorer.exe 1536 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\h\iexplore.exe 1536 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\lmro.reg 600 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\lmroe.reg 74 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\nircmd.chm 38015 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\nircmd.exe 31232 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\nircmdc.exe 30720 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\nird 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\nird\iexplore.exe 31232 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\pev.exe 255488 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\prep.bat 68 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\procs 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\procs\explorer.exe 255488 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\procs\iexplore.exe 255488 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\procs\proc.dat 11031 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\proxycheck.exe 302187 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\rkill.bat 5003 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\rkill.reg 3087 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\s.inf 1081 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\sed.exe 98816 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\serv.dat 190 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\sh.vbs 313 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\swreg.exe 161792 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\userinit.exe 31232 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\winlogon.exe 31232 bytes executable
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Local\Temp\RarSFX0\wl.txt 323 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Roaming 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Roaming\Microsoft 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Roaming\Microsoft\Windows 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Roaming\Microsoft\Windows\IETldCache 0 bytes
File C:\## aswSnx private storage\webStorage\image\Users\Taylor\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat 16384 bytes
File C:\## aswSnx private storage\webStorage\image\Windows 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\INF 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\INF\setupapi.app.log 3066458 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\Prefetch 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\Prefetch\CONHOST.EXE-0C6456FB.pf 15660 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\Rescache 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\Rescache\rc0007 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\Rescache\rc0007\rescache.hit 4192 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\System32 0 bytes
File C:\## aswSnx private storage\webStorage\image\Windows\System32\DriverStore 0 bytes
File C:\## aswSnx private storage\webStorage\snx_fs.dat 11202 bytes
---- EOF - GMER 1.0.15 ----
DDS Log:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Taylor at 21:14:46.58 on Tue 04/19/2011
Internet Explorer: 9.0.8080.16413
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3032.1697 [GMT -4:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\ico.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\Pelmiced.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\vds.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\Taylor\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
mRun-x64: [Apoint] C:\Program Files\DellTPad\Apoint.exe
mRun-x64: [Mouse Suite 98 Daemon] ICO.EXE
Hosts: 127.0.0.1
www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-7-2 55856]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2011-2-22 505176]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2010-7-2 280408]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2010-7-2 22360]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2010-7-2 64344]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-3-24 42184]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664]
R2 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2009-10-7 191000]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-26 1153368]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-5-28 705856]
R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2009-10-7 30232]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-5-3 215552]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-4-24 721768]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-4-24 269672]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-4-24 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-4-24 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe --> C:\Program Files\Dell\DellDock\DockLogin.exe [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-24 136176]
S2 McShield;McAfee Real-time Scanner;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe --> C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [?]
S3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\System32\drivers\LVUSBS64.sys [2008-7-26 50072]
S3 McSysmon;McAfee SystemGuards;C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe --> C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-1 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-2-18 51712]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-6-4 1255736]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;C:\Program Files\Zune\WMZuneComm.exe [2010-9-24 306416]
.
=============== Created Last 30 ================
.
2011-04-19 15:03:07 -------- d-----w- C:\Users\Taylor\AppData\Roaming\Malwarebytes
2011-04-19 15:03:02 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-19 15:03:01 -------- d-----w- C:\PROGRA~3\Malwarebytes
2011-04-19 15:02:56 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-04-19 15:02:56 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-04-15 01:52:14 8424784 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{FE7F8EAF-F550-4F8A-84D1-A90DE552CE59}\mpengine.dll
2011-04-14 02:49:57 -------- d-----w- C:\PROGRA~3\LogMeIn
2011-04-14 02:49:47 -------- d-----w- C:\Program Files (x86)\LogMeIn
2011-03-26 20:07:28 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-03-26 20:07:28 -------- d-----w- C:\PROGRA~3\Spybot - Search & Destroy
.
==================== Find3M ====================
.
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-03 06:24:16 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52:08 3135488 ----a-w- C:\Windows\System32\win32k.sys
2011-03-01 07:50:25 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-03-01 07:50:25 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-02-24 06:15:44 476160 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-02-24 05:38:54 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-02-23 13:57:01 505176 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-02-23 13:55:05 64344 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-02-23 04:56:31 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-02-23 04:56:27 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-02-23 04:56:03 411648 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-02-23 04:55:47 167936 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-02-23 04:55:12 287744 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-02-23 04:55:12 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-02-23 04:55:04 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-02-22 23:29:58 20364702 ----a-w- C:\vlc-1.1.7-win32.exe
2011-02-21 22:27:50 40648 ----a-w- C:\Windows\avastSS.scr
2011-02-19 12:05:15 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2011-02-19 12:04:37 1544192 ----a-w- C:\Windows\System32\DWrite.dll
2011-02-19 12:04:17 902656 ----a-w- C:\Windows\System32\d2d1.dll
2011-02-19 12:03:46 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-02-19 09:00:32 367616 ----a-w- C:\Windows\System32\atmfd.dll
2011-02-19 06:30:51 1076736 ----a-w- C:\Windows\SysWow64\DWrite.dll
2011-02-19 06:30:50 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2011-02-19 06:30:46 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-02-19 04:34:54 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-02-18 21:36:58 51712 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys
2011-02-18 21:36:58 4184352 ----a-w- C:\Windows\System32\usbaaplrc.dll
2011-02-12 11:34:16 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-02-05 17:10:16 642944 ----a-w- C:\Windows\System32\winload.efi
2011-02-05 17:10:08 20352 ----a-w- C:\Windows\System32\kdusb.dll
2011-02-05 17:10:08 19328 ----a-w- C:\Windows\System32\kd1394.dll
2011-02-05 17:10:08 17792 ----a-w- C:\Windows\System32\kdcom.dll
2011-02-05 17:06:41 605552 ----a-w- C:\Windows\System32\winload.exe
2011-02-05 17:06:41 566208 ----a-w- C:\Windows\System32\winresume.efi
2011-02-05 17:06:41 518672 ----a-w- C:\Windows\System32\winresume.exe
2011-02-03 01:40:23 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-02-02 22:11:20 270720 ------w- C:\Windows\System32\MpSigStub.exe
2009-08-20 08:13:26 9815040 ----a-w- C:\Program Files\openofficeorg31.msi
2009-03-26 10:36:32 451928 ----a-w- C:\Program Files\setup.exe
2002-03-11 09:06:30 1822520 ----a-w- C:\Program Files\instmsiw.exe
2002-03-11 08:45:04 1708856 ----a-w- C:\Program Files\instmsia.exe
.
============= FINISH: 21:15:31.18 ===============
Note as well, I'm using my desktop to do all of my internet access, downloading, etc. while the laptops network is messed up. This is going to be a doozy to fix I'm thinking.