Tommyrocket
Posts: 31 +0
For about a year now, my computer has been experiencing crashes from explorer.exe, and drwatsonpostmortem debugger. Every other start up also often doesn't include things like my NVidia control panel and other sound control services. I believe these startup issues started with IObit's registry fixing application.
Other than that, I also believe it to be a virus of some sort. If anything, I need help pinpointing and fixing what slows my computer down so much.
I've followed the preliminary instructions and have gotten logs from both MBAM and DDS (DDS.txt and attach.txt).
-------------------------------------------------------------------------
MBAM
Malwarebytes Anti-Malware (PRO) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.12.03.01
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Thomas G :: THOMAS [administrator]
Protection: Disabled
12/2/2012 11:13:57 PM
mbam-log-2012-12-02 (23-13-57).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 246115
Time elapsed: 3 minute(s), 50 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
-------------------------------------------------------------------------
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 7.0.6000.17106 BrowserJavaVersion: 10.9.2
Run by Thomas G at 22:38:46 on 2012-12-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1343 [GMT -7:00]
.
FW: Outpost Firewall Pro *Disabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Palm, Inc\novacomd\x86\novacomd.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
K:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: FGCatchUrl: {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - c:\program files\flashget\jccatch.dll
BHO: ³×À̹ö Åø¹Ù µµ¿ì¹Ì: {67C41E9E-2EBF-4F2B-AF74-314F0D793172} - c:\program files\naver\navertoolbar\NaverTB_3_5_3_40.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CPrintEnhancer Object: {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - c:\program files\hp\smart web printing\SmartWebPrinting.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - c:\documents and settings\thomas g\application data\flashgetbho\FlashGetBHO3.dll
BHO: CSolidBrowserObj Object: {BD08A9D5-0E5C-4f42-99A3-C0CB5E860557} - c:\windows\system32\solidstatenetworks\solidstateion\solidax.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: FlashGet GetFlash Class: {F156768E-81EF-470C-9057-481BA8380DBA} - c:\program files\flashget\getflash.dll
TB: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: ??? ??(&N): {D09CFF09-A42A-4EDC-9804-E61224F59CA1} - c:\program files\naver\navertoolbar\NaverTB_3_5_3_40.dll
TB: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - c:\program files\daemon tools toolbar\DTToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [OutpostFeedBack] "c:\program files\agnitum\outpost firewall pro\feedback.exe" /dumps_startup
mRun: [OutpostMonitor] "c:\progra~1\agnitum\outpos~1\op_mon.exe" /tray /noservice
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [EVGAPrecision] "c:\program files\evga precision\EVGAPrecision.exe" /s
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
dRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear
uPolicies-Explorer: NoDriveTypeAutoRun = dword:153
mPolicies-Explorer: NoDriveTypeAutoRun = dword:153
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm
IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm
IE: Blocking access to the document address by AliveProxy - c:\program files\ais aliveproxy server\aisBlockDocument.html
IE: Blocking access to the image address by AliveProxy - c:\program files\ais aliveproxy server\aisBlockImage.html
IE: Blocking access to the link address by AliveProxy - c:\program files\ais aliveproxy server\aisBlockLink.html
IE: Cut proxy addresses from selected text by AliveProxy - c:\program files\ais aliveproxy server\aisCutProxyFromSelectedTåxt.html
IE: Download All By FlashGet3 - c:\documents and settings\thomas g\application data\flashgetbho\GetAllUrl.htm
IE: Download By FlashGet3 - c:\documents and settings\thomas g\application data\flashgetbho\GetUrl.htm
IE: ??? ?? - <no file>
IE: ??? ????? - <no file>
IE: ??? ??? ?? - <no file>
IE: ??? ?? ?? - <no file>
IE: ??? ????? ???? - <no file>
IE: ??? ?? ?? - <no file>
IE: {44627E97-789B-40d4-B5C2-58BD171129A1} - {A1A7E22D-1587-4230-8F16-081C68D21448}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: k:\program files\verysoft\allproxy lite\ProxyLSP.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1324969771015
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} - hxxp://www.playwhat.com/solidPlugin/solidstateion.cab
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxp://mhf.hangame.com/common/activex/HanSetup1040.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} - hxxp://hancdn.hangame.com/pub/plii/real/PubPlugin.cab
TCP: Interfaces\{80CAD54F-0692-4308-A402-3DA65C33C61D} : DHCPNameServer = 192.168.1.1
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: LMIinit - LMIinit.dll
AppInit_DLLs= c:\progra~1\agnitum\outpos~1\wl_hook.dll TeknoGods.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\thomas g\application data\mozilla\firefox\profiles\a3l9rx7l.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\thomas g\application data\mozilla\firefox\profiles\a3l9rx7l.default\extensions\{db9127a2-3381-41ec-82b3-1b6ed4c6f29a}\components\FlashgetXpi.dll
FF - plugin: c:\documents and settings\all users\application data\nexon\ngm\npnxgame.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\thomas g\application data\mozilla\firefox\profiles\a3l9rx7l.default\extensions\battlefieldplay4free@ea.com\plugins\npBP4FUpdater.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\gamespy\comrade\npcomrade.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_110.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2012-10-17 16:10; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF - ExtSQL: !HIDDEN! 2009-09-02 03:00; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R1 ntiowp;ntiowp;c:\windows\system32\drivers\ntiowp.sys [2006-10-20 12352]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [2010-9-12 714752]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-4-12 20968]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2010-12-2 10448]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-10-16 47640]
R2 MBAMScheduler;MBAMScheduler;k:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-12-2 399432]
R2 NovacomD;Palm Novacom;c:\program files\palm, inc\novacomd\x86\novacomd.exe [2010-10-21 61440]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [2010-9-12 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2010-9-12 256792]
R3 ASWFilt;ASWFilt;c:\windows\system32\filt\ASWFilt.dll [2010-9-12 33920]
S1 SysTool;SysTool Overclocking Utility;c:\windows\system32\drivers\SysTool.sys [2006-11-10 24064]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\agnitum\outpos~1\acs.exe [2010-9-12 1312584]
S2 Apache2.2;Apache2.2;"k:\xampp\apache\bin\httpd.exe" -k runservice --> k:\xampp\apache\bin\httpd.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\logmein\x86\rainfo.sys --> c:\program files\logmein\x86\RaInfo.sys [?]
S2 MBAMService;MBAMService;k:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-12-2 676936]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-5-20 1691480]
S3 apf001;apf001;c:\program files\softnyxgame\gunboundis\apf001.sys [2011-7-13 10872]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 JRSKD24;JRSKD24;c:\windows\system32\JRSKD24.SYS [2010-8-4 37688]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-2 22856]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 rak;rak;c:\windows\system32\rakion.sys [2009-12-21 60928]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2012-1-24 27064]
S3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\tmpassthru.sys --> c:\windows\system32\drivers\TMPassthru.sys [?]
S3 vtany;vtany;\??\c:\windows\vtany.sys --> c:\windows\vtany.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 xhunter1;xhunter1;\??\c:\windows\xhunter1.sys --> c:\windows\xhunter1.sys [?]
S3 xsherlock;xsherlock;c:\windows\system32\xsherlock.xem [2012-11-12 666720]
S4 AllProxyService;AllProxy Service;k:\program files\verysoft\allproxy lite\AllProxyService.exe [2011-2-18 428424]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-5-19 90296]
.
=============== File Associations ===============
.
FileExt: .js: JSFile=c:\windows\system32\Notepad.exe %1 [default=Edit - 'Open' doesn't exist]
.
=============== Created Last 30 ================
.
2012-12-03 04:19:44 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-03 03:35:44 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-12-03 03:31:53 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-12-03 03:31:53 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-11-23 05:44:35 -------- d-----w- c:\documents and settings\all users\application data\NVIDIA Corporation
2012-11-22 07:37:43 -------- d-----w- c:\documents and settings\all users\application data\Caphyon
2012-11-21 09:53:58 -------- d-----w- c:\documents and settings\thomas g\local settings\application data\Sun
2012-11-21 09:52:52 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-11-21 07:37:59 -------- d-----w- c:\program files\Sony Online Entertainment
2012-11-12 13:14:10 666720 ----a-w- c:\windows\system32\xsherlock.xem
2012-11-12 12:49:29 -------- d-----w- c:\windows\DEA314C409294250BC9298E4C105F28D.TMP
.
==================== Find3M ====================
.
2012-11-29 13:39:41 1102088 ----a-w- c:\windows\system32\nvdrsdb1.bin
2012-11-29 13:39:41 1102088 ----a-w- c:\windows\system32\nvdrsdb0.bin
2012-11-29 13:39:41 1 ----a-w- c:\windows\system32\nvdrssel.bin
2012-11-22 05:32:54 139936 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-11-22 05:32:41 281808 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-11-22 05:32:41 281808 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-11-17 05:54:41 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-17 05:54:41 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-25 02:34:52 281808 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-24 22:32:24 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-24 22:32:20 473072 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-24 20:51:47 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-23 14:28:00 888168 ----a-w- c:\windows\system32\nvdispgenco32.dll
2012-09-23 14:28:00 7446528 ----a-w- c:\windows\system32\nvcuda.dll
2012-09-23 14:28:00 5947392 ----a-w- c:\windows\system32\nvopencl.dll
2012-09-23 14:28:00 4494208 ----a-w- c:\windows\system32\nv4_disp.dll
2012-09-23 14:28:00 2578792 ----a-w- c:\windows\system32\nvcuvid.dll
2012-09-23 14:28:00 2376704 ----a-w- c:\windows\system32\nvapi.dll
2012-09-23 14:28:00 19103744 ----a-w- c:\windows\system32\nvoglnt.dll
2012-09-23 14:28:00 1866088 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-09-23 14:28:00 17551360 ----a-w- c:\windows\system32\nvcompiler.dll
2012-09-23 14:28:00 12557728 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-09-23 14:28:00 1009512 ----a-w- c:\windows\system32\nvdispco32.dll
2012-09-23 13:04:24 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-09-23 13:04:12 15512424 ----a-w- c:\windows\system32\nvcpl.dll
2012-09-23 13:04:11 164200 ----a-w- c:\windows\system32\nvsvc32.exe
2012-09-23 13:04:11 143720 ----a-w- c:\windows\system32\nvcolor.exe
2012-09-23 13:04:11 108392 ----a-w- c:\windows\system32\nvmctray.dll
.
============= FINISH: 22:39:42.39 ===============
Other than that, I also believe it to be a virus of some sort. If anything, I need help pinpointing and fixing what slows my computer down so much.
I've followed the preliminary instructions and have gotten logs from both MBAM and DDS (DDS.txt and attach.txt).
-------------------------------------------------------------------------
MBAM
Malwarebytes Anti-Malware (PRO) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.12.03.01
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Thomas G :: THOMAS [administrator]
Protection: Disabled
12/2/2012 11:13:57 PM
mbam-log-2012-12-02 (23-13-57).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 246115
Time elapsed: 3 minute(s), 50 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
-------------------------------------------------------------------------
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 7.0.6000.17106 BrowserJavaVersion: 10.9.2
Run by Thomas G at 22:38:46 on 2012-12-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1343 [GMT -7:00]
.
FW: Outpost Firewall Pro *Disabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Palm, Inc\novacomd\x86\novacomd.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
K:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: FGCatchUrl: {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - c:\program files\flashget\jccatch.dll
BHO: ³×À̹ö Åø¹Ù µµ¿ì¹Ì: {67C41E9E-2EBF-4F2B-AF74-314F0D793172} - c:\program files\naver\navertoolbar\NaverTB_3_5_3_40.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CPrintEnhancer Object: {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - c:\program files\hp\smart web printing\SmartWebPrinting.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - c:\documents and settings\thomas g\application data\flashgetbho\FlashGetBHO3.dll
BHO: CSolidBrowserObj Object: {BD08A9D5-0E5C-4f42-99A3-C0CB5E860557} - c:\windows\system32\solidstatenetworks\solidstateion\solidax.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: FlashGet GetFlash Class: {F156768E-81EF-470C-9057-481BA8380DBA} - c:\program files\flashget\getflash.dll
TB: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: ??? ??(&N): {D09CFF09-A42A-4EDC-9804-E61224F59CA1} - c:\program files\naver\navertoolbar\NaverTB_3_5_3_40.dll
TB: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - c:\program files\daemon tools toolbar\DTToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [OutpostFeedBack] "c:\program files\agnitum\outpost firewall pro\feedback.exe" /dumps_startup
mRun: [OutpostMonitor] "c:\progra~1\agnitum\outpos~1\op_mon.exe" /tray /noservice
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [EVGAPrecision] "c:\program files\evga precision\EVGAPrecision.exe" /s
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
dRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear
uPolicies-Explorer: NoDriveTypeAutoRun = dword:153
mPolicies-Explorer: NoDriveTypeAutoRun = dword:153
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm
IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm
IE: Blocking access to the document address by AliveProxy - c:\program files\ais aliveproxy server\aisBlockDocument.html
IE: Blocking access to the image address by AliveProxy - c:\program files\ais aliveproxy server\aisBlockImage.html
IE: Blocking access to the link address by AliveProxy - c:\program files\ais aliveproxy server\aisBlockLink.html
IE: Cut proxy addresses from selected text by AliveProxy - c:\program files\ais aliveproxy server\aisCutProxyFromSelectedTåxt.html
IE: Download All By FlashGet3 - c:\documents and settings\thomas g\application data\flashgetbho\GetAllUrl.htm
IE: Download By FlashGet3 - c:\documents and settings\thomas g\application data\flashgetbho\GetUrl.htm
IE: ??? ?? - <no file>
IE: ??? ????? - <no file>
IE: ??? ??? ?? - <no file>
IE: ??? ?? ?? - <no file>
IE: ??? ????? ???? - <no file>
IE: ??? ?? ?? - <no file>
IE: {44627E97-789B-40d4-B5C2-58BD171129A1} - {A1A7E22D-1587-4230-8F16-081C68D21448}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: k:\program files\verysoft\allproxy lite\ProxyLSP.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1324969771015
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} - hxxp://www.playwhat.com/solidPlugin/solidstateion.cab
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxp://mhf.hangame.com/common/activex/HanSetup1040.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} - hxxp://hancdn.hangame.com/pub/plii/real/PubPlugin.cab
TCP: Interfaces\{80CAD54F-0692-4308-A402-3DA65C33C61D} : DHCPNameServer = 192.168.1.1
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: LMIinit - LMIinit.dll
AppInit_DLLs= c:\progra~1\agnitum\outpos~1\wl_hook.dll TeknoGods.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\thomas g\application data\mozilla\firefox\profiles\a3l9rx7l.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\thomas g\application data\mozilla\firefox\profiles\a3l9rx7l.default\extensions\{db9127a2-3381-41ec-82b3-1b6ed4c6f29a}\components\FlashgetXpi.dll
FF - plugin: c:\documents and settings\all users\application data\nexon\ngm\npnxgame.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\thomas g\application data\mozilla\firefox\profiles\a3l9rx7l.default\extensions\battlefieldplay4free@ea.com\plugins\npBP4FUpdater.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\gamespy\comrade\npcomrade.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_110.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2012-10-17 16:10; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF - ExtSQL: !HIDDEN! 2009-09-02 03:00; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R1 ntiowp;ntiowp;c:\windows\system32\drivers\ntiowp.sys [2006-10-20 12352]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [2010-9-12 714752]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-4-12 20968]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2010-12-2 10448]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-10-16 47640]
R2 MBAMScheduler;MBAMScheduler;k:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-12-2 399432]
R2 NovacomD;Palm Novacom;c:\program files\palm, inc\novacomd\x86\novacomd.exe [2010-10-21 61440]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [2010-9-12 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2010-9-12 256792]
R3 ASWFilt;ASWFilt;c:\windows\system32\filt\ASWFilt.dll [2010-9-12 33920]
S1 SysTool;SysTool Overclocking Utility;c:\windows\system32\drivers\SysTool.sys [2006-11-10 24064]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\agnitum\outpos~1\acs.exe [2010-9-12 1312584]
S2 Apache2.2;Apache2.2;"k:\xampp\apache\bin\httpd.exe" -k runservice --> k:\xampp\apache\bin\httpd.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\logmein\x86\rainfo.sys --> c:\program files\logmein\x86\RaInfo.sys [?]
S2 MBAMService;MBAMService;k:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-12-2 676936]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-5-20 1691480]
S3 apf001;apf001;c:\program files\softnyxgame\gunboundis\apf001.sys [2011-7-13 10872]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 JRSKD24;JRSKD24;c:\windows\system32\JRSKD24.SYS [2010-8-4 37688]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-2 22856]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 rak;rak;c:\windows\system32\rakion.sys [2009-12-21 60928]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2012-1-24 27064]
S3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\tmpassthru.sys --> c:\windows\system32\drivers\TMPassthru.sys [?]
S3 vtany;vtany;\??\c:\windows\vtany.sys --> c:\windows\vtany.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 xhunter1;xhunter1;\??\c:\windows\xhunter1.sys --> c:\windows\xhunter1.sys [?]
S3 xsherlock;xsherlock;c:\windows\system32\xsherlock.xem [2012-11-12 666720]
S4 AllProxyService;AllProxy Service;k:\program files\verysoft\allproxy lite\AllProxyService.exe [2011-2-18 428424]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-5-19 90296]
.
=============== File Associations ===============
.
FileExt: .js: JSFile=c:\windows\system32\Notepad.exe %1 [default=Edit - 'Open' doesn't exist]
.
=============== Created Last 30 ================
.
2012-12-03 04:19:44 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-03 03:35:44 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-12-03 03:31:53 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-12-03 03:31:53 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-11-23 05:44:35 -------- d-----w- c:\documents and settings\all users\application data\NVIDIA Corporation
2012-11-22 07:37:43 -------- d-----w- c:\documents and settings\all users\application data\Caphyon
2012-11-21 09:53:58 -------- d-----w- c:\documents and settings\thomas g\local settings\application data\Sun
2012-11-21 09:52:52 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-11-21 07:37:59 -------- d-----w- c:\program files\Sony Online Entertainment
2012-11-12 13:14:10 666720 ----a-w- c:\windows\system32\xsherlock.xem
2012-11-12 12:49:29 -------- d-----w- c:\windows\DEA314C409294250BC9298E4C105F28D.TMP
.
==================== Find3M ====================
.
2012-11-29 13:39:41 1102088 ----a-w- c:\windows\system32\nvdrsdb1.bin
2012-11-29 13:39:41 1102088 ----a-w- c:\windows\system32\nvdrsdb0.bin
2012-11-29 13:39:41 1 ----a-w- c:\windows\system32\nvdrssel.bin
2012-11-22 05:32:54 139936 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-11-22 05:32:41 281808 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-11-22 05:32:41 281808 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-11-17 05:54:41 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-17 05:54:41 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-25 02:34:52 281808 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-24 22:32:24 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-24 22:32:20 473072 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-24 20:51:47 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-23 14:28:00 888168 ----a-w- c:\windows\system32\nvdispgenco32.dll
2012-09-23 14:28:00 7446528 ----a-w- c:\windows\system32\nvcuda.dll
2012-09-23 14:28:00 5947392 ----a-w- c:\windows\system32\nvopencl.dll
2012-09-23 14:28:00 4494208 ----a-w- c:\windows\system32\nv4_disp.dll
2012-09-23 14:28:00 2578792 ----a-w- c:\windows\system32\nvcuvid.dll
2012-09-23 14:28:00 2376704 ----a-w- c:\windows\system32\nvapi.dll
2012-09-23 14:28:00 19103744 ----a-w- c:\windows\system32\nvoglnt.dll
2012-09-23 14:28:00 1866088 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-09-23 14:28:00 17551360 ----a-w- c:\windows\system32\nvcompiler.dll
2012-09-23 14:28:00 12557728 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-09-23 14:28:00 1009512 ----a-w- c:\windows\system32\nvdispco32.dll
2012-09-23 13:04:24 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-09-23 13:04:12 15512424 ----a-w- c:\windows\system32\nvcpl.dll
2012-09-23 13:04:11 164200 ----a-w- c:\windows\system32\nvsvc32.exe
2012-09-23 13:04:11 143720 ----a-w- c:\windows\system32\nvcolor.exe
2012-09-23 13:04:11 108392 ----a-w- c:\windows\system32\nvmctray.dll
.
============= FINISH: 22:39:42.39 ===============