.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Theo at 12:00:05 on 2011-09-28
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3325.1836 [GMT 1:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft LifeChat\LifeChat.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = <local>;*.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.4.6.22.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [LifeChat] "c:\program files\microsoft lifechat\LifeChat.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
StartupFolder: c:\users\theo\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Se&nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.4.6.22.dll/206
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{01166B69-3C18-406B-8135-E7DFA986093B} : DhcpNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\theo\appdata\roaming\mozilla\firefox\profiles\q15h6s1j.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 53939
FF - prefs.js: network.proxy.type - 4
FF - component: c:\users\theo\appdata\roaming\mozilla\firefox\profiles\q15h6s1j.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension.dll
FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\theo\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\theo\appdata\roaming\mozilla\firefox\profiles\q15h6s1j.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\users\theo\appdata\roaming\mozilla\firefox\profiles\q15h6s1j.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: TVU Web Player:
firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\drivers\SCMNdisP.sys [2010-1-10 21728]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl44cf84af;MpKsl44cf84af;c:\programdata\microsoft\microsoft antimalware\definition updates\{922372b2-1058-427d-a323-31dfebd9c6a9}\MpKsl44cf84af.sys [2011-9-28 28752]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R2 AERTFilters;Andrea RT Filters Service;c:\program files\realtek\audio\hda\AERTSrv.exe [2009-7-4 81920]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-6-28 21992]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-12-18 155648]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-6-7 240232]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
R3 pxldipog;pxldipog;c:\users\theo\appdata\local\temp\pxldipog.sys [2011-9-28 100864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gbegew;NVIDIA Display Srv;c:\windows\system32\gbegew.exe [2011-9-27 38912]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-4 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-3-4 135664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\dellsu~1\hwdiag\bin\PCD5SRVC.pkms [2008-11-5 22904]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v2.sys [2007-12-26 288768]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2007-12-26 288768]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-09-28 10:10:32 -------- d-----w- c:\users\theo\appdata\local\{1670AECF-2D5F-4E7D-922A-0B052B0EA579}
2011-09-28 10:10:00 -------- d-----w- c:\users\theo\appdata\local\{2FB47DB9-9AD8-4871-9E62-9F56D56F0605}
2011-09-28 10:09:31 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{922372b2-1058-427d-a323-31dfebd9c6a9}\MpKsl44cf84af.sys
2011-09-28 10:09:24 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{922372b2-1058-427d-a323-31dfebd9c6a9}\offreg.dll
2011-09-27 19:16:10 -------- d-----w- c:\users\theo\appdata\local\Adobe
2011-09-27 16:43:27 -------- d-----w- c:\users\theo\appdata\local\{200A26C3-ED57-45A1-B9DB-0435EE194784}
2011-09-27 16:43:14 -------- d-----w- c:\users\theo\appdata\local\{ABB95063-75E0-4388-A824-3CF9B471D228}
2011-09-27 16:42:54 -------- d-----w- c:\users\theo\appdata\local\Apple Computer
2011-09-27 16:37:51 439632 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{30b64643-d692-4a5d-8813-7db929ddf7ce}\gapaengine.dll
2011-09-27 16:37:45 7269712 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{922372b2-1058-427d-a323-31dfebd9c6a9}\mpengine.dll
2011-09-27 16:32:08 -------- d-----w- c:\program files\Microsoft Security Client
2011-09-27 16:31:51 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2011-09-27 16:18:26 -------- d-----w- c:\users\theo\appdata\roaming\QuickScan
2011-09-27 15:56:03 -------- d-sh--w- C:\$RECYCLE.BIN
2011-09-27 15:50:13 38912 ----a-w- c:\windows\system32\gbegew.exe
2011-09-27 15:04:08 -------- d-----w- C:\ComboFix
2011-09-27 11:20:36 -------- d-----w- c:\program files\LeagueOfLegends
2011-09-27 11:15:57 -------- d-----w- c:\users\theo\appdata\local\PMB Files
2011-09-27 11:15:42 -------- d-----w- c:\programdata\PMB Files
2011-09-27 00:27:03 208896 ----a-w- c:\windows\MBR.exe
2011-09-27 00:27:02 98816 ----a-w- c:\windows\sed.exe
2011-09-27 00:27:02 518144 ----a-w- c:\windows\SWREG.exe
2011-09-27 00:27:02 256000 ----a-w- c:\windows\PEV.exe
2011-09-26 21:23:12 -------- d-----w- c:\users\theo\appdata\local\{F41CE8B4-FD8E-4266-86A6-CEA476305902}
2011-09-26 21:22:48 -------- d-----w- c:\users\theo\appdata\local\{75AE3CB7-217A-4AFA-BD83-3249AB1602E9}
2011-09-26 16:15:20 -------- d-----w- c:\users\theo\appdata\local\{9CB6E8B9-0D81-457B-AC38-0E2EA13FDD57}
2011-09-26 16:15:01 -------- d-----w- c:\users\theo\appdata\local\{05D29A35-B1E1-47B3-9171-EB0ACC6C2F17}
2011-09-23 17:46:50 -------- d-----w- c:\users\theo\appdata\local\Spotify
2011-09-23 17:46:48 -------- d-----w- c:\users\theo\appdata\roaming\Spotify
2011-09-23 03:17:03 -------- d-----w- c:\users\theo\appdata\local\{B971B3B8-19EB-4BB7-9C0E-D8CE9A80C4E2}
2011-09-23 03:16:41 -------- d-----w- c:\users\theo\appdata\local\{CA5A3D8D-3D9C-418B-B630-C8274D3CC9D7}
2011-09-21 05:33:07 -------- d-----w- c:\users\theo\appdata\local\{2A0DDE97-D592-4521-A0B1-AD21355B1A36}
2011-09-21 05:32:46 -------- d-----w- c:\users\theo\appdata\local\{F6ECA60A-813E-4654-B5DB-9567FAAAB8DA}
2011-09-20 14:11:59 -------- d-----w- c:\users\theo\appdata\local\{2C878E57-B375-4AA5-8C3D-B7A67B2F5C41}
2011-09-20 14:11:41 -------- d-----w- c:\users\theo\appdata\local\{2B0ABFAA-2FCF-4931-A025-0749BF0F3F44}
2011-09-20 10:22:10 -------- d-----w- c:\users\theo\appdata\local\{E509769F-7370-4413-8854-A50806F2ECF7}
2011-09-19 13:06:30 -------- d-----w- c:\users\theo\appdata\local\{0F48F7C2-8FC4-423C-BAC8-3077A6DCCD76}
2011-09-19 13:06:08 -------- d-----w- c:\users\theo\appdata\local\{FDE01B69-458D-4C52-9F9E-7756FAF0555F}
2011-09-18 22:23:40 -------- d-----w- c:\users\theo\appdata\local\{59075ACD-82C9-4EA5-8EFE-7E6E06112BCD}
2011-09-18 22:19:53 -------- d-----w- c:\users\theo\appdata\local\{48A8C448-C682-4280-9E35-7ABBE4DF2E68}
2011-09-16 04:27:08 -------- d-----w- c:\users\theo\appdata\local\{95CFF71D-705F-46C8-A11B-26C538BBEFEE}
2011-09-16 04:26:51 -------- d-----w- c:\users\theo\appdata\local\{4A0CF688-B0DF-4E5B-9A79-FAF2ED6D33DA}
2011-09-15 15:03:07 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-09-15 02:03:29 -------- d-----w- c:\users\theo\appdata\local\{7B03AFD9-695C-4F32-8522-A46B9CCF9E5D}
2011-09-15 02:03:08 -------- d-----w- c:\users\theo\appdata\local\{B4CDF735-E57B-47D5-A77D-2A33B27E2824}
2011-09-09 18:36:53 -------- d-----w- c:\users\theo\appdata\local\{68F5182F-73B8-420F-A544-9D1BA6B12C0B}
2011-09-09 18:36:35 -------- d-----w- c:\users\theo\appdata\local\{FF5461E5-0B25-41B7-B692-7C876A751E35}
2011-09-03 00:38:40 -------- d-----w- c:\users\theo\appdata\local\{34B29834-5D5A-4B73-B645-3EDCE5CD820E}
2011-09-02 12:38:08 -------- d-----w- c:\users\theo\appdata\local\{A8FA1EFA-C0D9-426F-BFDD-C1805F1FD9E2}
2011-09-02 12:37:44 -------- d-----w- c:\users\theo\appdata\local\{595BAD9F-BAD1-4934-9907-9D8B417A3285}
2011-09-01 16:16:36 -------- d-----w- c:\users\theo\appdata\local\{D996F74F-BECC-4898-BA73-B5C5280A2DBF}
2011-09-01 02:22:57 -------- d-----w- c:\users\theo\appdata\local\{3B0185EC-38D9-4413-AEBF-E006F54EECB7}
2011-09-01 02:22:31 -------- d-----w- c:\users\theo\appdata\local\{DC971BA3-D7D4-47D0-AB1C-5626A37E67D9}
.
==================== Find3M ====================
.
2011-08-31 16:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-23 21:14:38 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-22 02:54:43 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-11 13:25:35 2048 ----a-w- c:\windows\system32\tzres.dll
2011-07-06 15:31:47 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
.
============= FINISH: 12:06:31.68 ===============