Firefox has been redirecting links since yesterday and i know it is a virus or malware of some sort because avast detected it but before i could get it off, the blue screen popped up and dumped files then restarted.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5202
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
11/28/2010 3:24:06 PM
mbam-log-2010-11-28 (15-24-06).txt
Scan type: Quick scan
Objects scanned: 146146
Time elapsed: 5 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x01 0x3E 0x15 0x9A ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x6C 0x9F 0xB9 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xB5 0x88 0xED 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7F 0xD3 0xCC 0xFB ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x01 0x3E 0x15 0x9A ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x6C 0x9F 0xB9 0x43 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xB5 0x88 0xED 0x24 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7F 0xD3 0xCC 0xFB ...
---- EOF - GMER 1.0.15 ----
DDS (Ver_10-11-27.01)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/22/2009 4:08:28 PM
System Uptime: 11/28/2010 3:24:58 PM (1 hours ago)
Motherboard: PEGATRON CORPORATION | | VIOLET
Processor: AMD Phenom(tm) 9650 Quad-Core Processor | CPU 1 | 1196/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 582 GiB total, 165.052 GiB free.
D: is FIXED (NTFS) - 14 GiB total, 1.59 GiB free.
E: is FIXED (NTFS) - 228 GiB total, 26.945 GiB free.
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (FAT32) - 5 GiB total, 2.117 GiB free.
K: is Removable
L: is CDROM ()
M: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP190: 11/27/2010 10:45:47 PM - Installed TSR Launcher
RP191: 11/28/2010 3:00:11 AM - Windows Update
==== Installed Programs ======================
µTorrent
ABC Amber LIT Converter
Acrobat.com
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2
Adobe Reader 9.4.1
Adobe Shockwave Player 11.5
Apple Application Support
Apple Software Update
avast! Free Antivirus
AviSynth 2.5
Before You Know It 3.6 Deluxe
Byki
Byki Express
Combined Community Codec Pack 2009-09-09
CyberLink DVD Suite Deluxe
Default Manager
DirectX for Managed Code Update (Summer 2004)
DVDFab 8.0.5.0 (18/11/2010)
EA Download Manager
Enhanced Multimedia Keyboard Solution
eReader
ffdshow [rev 2583] [2009-01-05]
Gravity
Haali Media Splitter
HijackThis 2.0.2
HP Active Support Library
HP Advisor
HP Customer Experience Enhancements
HP Games
HP MediaSmart Demo
HP MediaSmart DVD
HP MediaSmart Music/Photo/Video
HP Picasso Media Center Add-In
HP Recovery Manager RSS
HP Remote Solution
HP Total Care Setup
HP Update
HPAsset component for HP Active Support Library
Human Japanese 2.0
Java Auto Updater
Java(TM) 6 Update 22
LabelPrint
LightScribe System Software
LimeWire 5.3.6
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Choice Guard
Microsoft Live Search Toolbar
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007 Trial
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Microsoft WSE 3.0 Runtime
Mobipocket Reader 6.2
Mozilla Firefox (3.5.6)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
PictureMover
Power2Go
PowerDirector
Python 2.6 pywin32-212
Python 2.6.1
QuickTime
ReadWrite Kanji Version 1.5
RealMedia (remove only)
Realtek High Definition Audio Driver
Rosetta Stone V3
Safari
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB978380)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft Office Excel 2007 (KB978382)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Sothink Movie DVD Maker
TeLL me More CJ
The Sims™ 3
The Sims™ 3 Ambitions
The Sims™ 3 High-End Loft Stuff
The Sims™ 3 Late Night
The Sims™ 3 World Adventures
TSR Launcher
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office InfoPath 2007 (KB976416)
Windows Installer Clean Up
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Media Player Firefox Plugin
WinRAR archiver
==== End Of File ===========================
DDS (Ver_10-11-27.01) - NTFS_AMD64
Run by Sache' at 16:27:24.06 on Sun 11/28/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.7935.6214 [GMT -6:00]
SP: BitDefender Antispyware *enabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\rundll32.exe
C:\Windows\System32\nvraidservice.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~1\HEWLET~1\HPREMO~1\HPREMO~1.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Hewlett-Packard\KBD\kbd.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Sache'\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
uStart Page = hxxp://www.ask.com?o=15772&l=dis
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files (x86)\whitesmoketoolbar\whitesmoketoolbarX.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
TB: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files (x86)\whitesmoketoolbar\whitesmoketoolbarX.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [UpdatePSTShortCut] "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
mRun: [UpdatePDIRShortCut] "c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
mRun: [UpdateP2GoShortCut] "c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
mRun: [UpdateLBPShortCut] "c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [TSMAgent] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
mRun: [Microsoft Default Manager] "c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE
mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [DVDAgent] "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
mRun: [CLMLServer for HP TouchSmart] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
mRun: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
Trusted Zone: juno.com
DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} - hxxps://www.hpwindows7upgrade.arvato.com/north_america/Endcustomer/HPProdDetect.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} - hxxp://www.worldwinner.com/games/v54/wwspades/wwspades.cab
TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll
mRun-x64: [NVRaidService] C:\Windows\system32\nvraidservice.exe
mRun-x64: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
mRun-x64: [HP Remote Software] C:\Program Files\Hewlett-Packard\HP Remote\HP REMOTE V1.0.5.exe
mRunOnce-x64: [PCDrProfiler] "C:\Program Files\PC-Doctor for Windows\RunProfiler.exe" -r
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Sache'\AppData\Roaming\Mozilla\Firefox\Profiles\ks50in09.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: C:\Program Files (x86)\Mozilla Firefox\components\FFComm.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: LOOP for Firefox: fireloop@drawloop.com - C:\Users\Sache'\AppData\Roaming\Mozilla\Firefox\Profiles\ks50in09.default\extensions\fireloop@drawloop.com
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Users\Sache'\AppData\Roaming\Mozilla\Firefox\Profiles\ks50in09.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - C:\Users\Sache'\AppData\Roaming\Mozilla\Firefox\Profiles\ks50in09.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2010-4-7 121936]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2010-4-7 22096]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2010-4-7 63568]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-5-8 40384]
R3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\Windows\System32\drivers\wg111v2.sys [2007-12-26 340992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 avast! Mail Scanner;avast! Mail Scanner;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-5-8 40384]
S3 avast! Web Scanner;avast! Web Scanner;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-5-8 40384]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-31 1255736]
=============== Created Last 30 ================
2010-11-28 21:16:22 -------- dc----w- C:\Users\Sache'\Shaggy - The Boombastic Collection - Best Of + c0vers
2010-11-28 21:07:22 -------- dc----w- C:\Users\Sache'\AppData\Roaming\WhiteSmokeTranslator
2010-11-28 11:33:37 -------- dc----w- C:\Program Files (x86)\whitesmoketoolbar
2010-11-28 04:46:12 -------- dc----w- C:\Program Files (x86)\The Sims Resource
2010-11-27 22:19:54 -------- dc----w- C:\Program Files (x86)\Trend Micro
2010-11-27 22:11:19 -------- dc----w- C:\Users\Sache'\AppData\Roaming\Malwarebytes
2010-11-27 22:11:13 38224 -c--a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-11-27 22:11:12 24664 -c--a-w- C:\Windows\System32\drivers\mbam.sys
2010-11-27 22:11:12 -------- dc----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-11-27 22:11:12 -------- dc----w- C:\PROGRA~3\Malwarebytes
2010-11-27 21:53:36 -------- dc----w- C:\Users\Sache'\AppData\Roaming\Registry Mechanic
2010-11-27 21:33:26 16384 -c--a-w- C:\Windows\cftm.exe
2010-11-27 21:33:08 939543 -c--a-w- C:\Windows\plugincontainers.exe
2010-11-25 05:51:49 -------- dc----w- C:\PROGRA~3\Trymedia
2010-11-25 05:51:07 -------- dc----w- C:\Windows\Mystic Emporium
2010-11-25 04:19:15 -------- dc----w- C:\Program Files (x86)\Common Files\SWF Studio
2010-11-25 04:19:14 -------- dcsh--w- C:\Users\Sache'\AppData\Local\.#
2010-11-25 02:11:08 -------- dc----w- C:\Program Files (x86)\Gravity
2010-11-25 01:36:04 43680 -c--a-w- C:\Windows\System32\drivers\lirsgt.sys
2010-11-25 01:36:04 314016 -c--a-w- C:\Windows\System32\drivers\atksgt.sys
2010-11-24 21:02:31 99384 -c--a-w- C:\Users\Sache'\AppData\Roaming\inst.exe
2010-11-24 21:02:31 82816 -c--a-w- C:\Windows\System32\drivers\pcouffin.sys
2010-11-24 21:02:31 82816 -c--a-w- C:\Users\Sache'\AppData\Roaming\pcouffin.sys
2010-11-24 21:02:21 -------- dc----w- C:\Program Files (x86)\DVDFab 8
2010-11-21 20:22:41 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2010-11-21 20:22:05 641536 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2010-11-21 20:22:04 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2010-11-21 20:22:04 258560 ----a-w- C:\Windows\System32\mpg2splt.ax
2010-11-21 20:22:03 552960 ----a-w- C:\Windows\System32\msdri.dll
2010-11-21 20:22:03 288256 ----a-w- C:\Windows\System32\MSNP.ax
2010-11-21 20:22:03 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2010-11-21 20:22:03 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2010-11-21 20:21:58 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2010-11-21 20:21:58 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2010-11-21 20:21:57 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2010-11-21 09:05:19 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2010-11-21 09:05:19 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2010-11-21 09:05:19 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2010-11-21 09:05:19 444752 ----a-w- C:\Windows\System32\mscoree.dll
2010-11-21 09:05:19 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2010-11-21 09:05:19 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2010-11-21 09:05:19 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2010-11-21 09:05:19 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2010-11-21 09:05:19 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2010-11-21 09:05:19 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2010-11-21 07:19:29 -------- dc----w- C:\Users\Sache'\[Kira-Fansub] My-HiME Complete (BD H264 1280x960 24fps AAC 2.0J)
2010-11-21 05:44:52 -------- dc----w- C:\Users\Sache'\Heroic age [Complete Eps 1- 26][Eng Subs]
2010-11-20 22:46:35 -------- dc----w- C:\games
2010-11-20 13:00:35 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2010-11-20 13:00:35 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2010-11-20 13:00:34 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2010-11-20 13:00:34 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-11-20 12:24:51 4582912 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2010-11-20 12:24:50 4247040 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2010-11-20 12:24:50 2085376 ----a-w- C:\Windows\System32\ole32.dll
2010-11-20 12:24:50 1413632 ----a-w- C:\Windows\SysWow64\ole32.dll
2010-11-20 12:24:26 1896832 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2010-11-20 12:24:24 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2010-11-20 12:24:24 2048 ----a-w- C:\Windows\System32\tzres.dll
2010-11-20 12:22:54 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-11-20 12:22:54 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-11-20 12:21:42 148992 ----a-w- C:\Windows\System32\t2embed.dll
2010-11-20 12:21:42 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-11-20 12:21:00 340992 ----a-w- C:\Windows\System32\schannel.dll
2010-11-20 12:21:00 224256 ----a-w- C:\Windows\SysWow64\schannel.dll
2010-11-20 12:20:58 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-11-20 12:20:58 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2010-11-20 12:15:14 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-11-20 12:15:14 463360 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-11-20 12:15:14 402944 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-11-20 12:15:14 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2010-11-20 12:15:14 161792 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-11-20 12:15:13 3123712 ----a-w- C:\Windows\System32\win32k.sys
2010-11-20 12:15:12 483840 ----a-w- C:\Windows\System32\StructuredQuery.dll
2010-11-20 12:15:12 363520 ----a-w- C:\Windows\SysWow64\StructuredQuery.dll
2010-11-20 11:13:54 558592 ----a-w- C:\Windows\System32\spoolsv.exe
2010-11-20 11:08:13 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-11-20 11:08:13 1024512 ----a-w- C:\Windows\System32\wmpmde.dll
2010-11-20 10:54:47 82944 ----a-w- C:\Windows\SysWow64\iccvid.dll
2010-11-20 09:28:44 -------- dc----w- C:\Windows\SysWow64\Adobe
2010-11-19 02:19:28 -------- dc----w- C:\Program Files (x86)\Belkin
2010-11-06 17:37:34 103864 -c--a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2010-11-06 17:37:34 103864 -c--a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
==================== Find3M ====================
2010-11-21 20:23:06 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-11-21 20:23:06 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-11-21 09:01:17 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-11-21 09:01:17 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2010-11-21 09:01:17 482816 ----a-w- C:\Windows\System32\html.iec
2010-11-21 09:01:17 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2010-11-21 09:01:17 386048 ----a-w- C:\Windows\SysWow64\html.iec
2010-11-21 09:01:17 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-11-21 09:01:17 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2010-11-21 09:01:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
2010-09-15 10:50:37 472808 -c--a-w- C:\Windows\SysWow64\deployJava1.dll
============= FINISH: 16:28:15.02 ===============
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5202
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
11/28/2010 3:24:06 PM
mbam-log-2010-11-28 (15-24-06).txt
Scan type: Quick scan
Objects scanned: 146146
Time elapsed: 5 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x01 0x3E 0x15 0x9A ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x6C 0x9F 0xB9 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xB5 0x88 0xED 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7F 0xD3 0xCC 0xFB ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x01 0x3E 0x15 0x9A ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x6C 0x9F 0xB9 0x43 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xB5 0x88 0xED 0x24 ...
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7F 0xD3 0xCC 0xFB ...
---- EOF - GMER 1.0.15 ----
DDS (Ver_10-11-27.01)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/22/2009 4:08:28 PM
System Uptime: 11/28/2010 3:24:58 PM (1 hours ago)
Motherboard: PEGATRON CORPORATION | | VIOLET
Processor: AMD Phenom(tm) 9650 Quad-Core Processor | CPU 1 | 1196/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 582 GiB total, 165.052 GiB free.
D: is FIXED (NTFS) - 14 GiB total, 1.59 GiB free.
E: is FIXED (NTFS) - 228 GiB total, 26.945 GiB free.
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (FAT32) - 5 GiB total, 2.117 GiB free.
K: is Removable
L: is CDROM ()
M: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP190: 11/27/2010 10:45:47 PM - Installed TSR Launcher
RP191: 11/28/2010 3:00:11 AM - Windows Update
==== Installed Programs ======================
µTorrent
ABC Amber LIT Converter
Acrobat.com
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2
Adobe Reader 9.4.1
Adobe Shockwave Player 11.5
Apple Application Support
Apple Software Update
avast! Free Antivirus
AviSynth 2.5
Before You Know It 3.6 Deluxe
Byki
Byki Express
Combined Community Codec Pack 2009-09-09
CyberLink DVD Suite Deluxe
Default Manager
DirectX for Managed Code Update (Summer 2004)
DVDFab 8.0.5.0 (18/11/2010)
EA Download Manager
Enhanced Multimedia Keyboard Solution
eReader
ffdshow [rev 2583] [2009-01-05]
Gravity
Haali Media Splitter
HijackThis 2.0.2
HP Active Support Library
HP Advisor
HP Customer Experience Enhancements
HP Games
HP MediaSmart Demo
HP MediaSmart DVD
HP MediaSmart Music/Photo/Video
HP Picasso Media Center Add-In
HP Recovery Manager RSS
HP Remote Solution
HP Total Care Setup
HP Update
HPAsset component for HP Active Support Library
Human Japanese 2.0
Java Auto Updater
Java(TM) 6 Update 22
LabelPrint
LightScribe System Software
LimeWire 5.3.6
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Choice Guard
Microsoft Live Search Toolbar
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007 Trial
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Microsoft WSE 3.0 Runtime
Mobipocket Reader 6.2
Mozilla Firefox (3.5.6)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
PictureMover
Power2Go
PowerDirector
Python 2.6 pywin32-212
Python 2.6.1
QuickTime
ReadWrite Kanji Version 1.5
RealMedia (remove only)
Realtek High Definition Audio Driver
Rosetta Stone V3
Safari
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB978380)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft Office Excel 2007 (KB978382)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Sothink Movie DVD Maker
TeLL me More CJ
The Sims™ 3
The Sims™ 3 Ambitions
The Sims™ 3 High-End Loft Stuff
The Sims™ 3 Late Night
The Sims™ 3 World Adventures
TSR Launcher
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office InfoPath 2007 (KB976416)
Windows Installer Clean Up
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Media Player Firefox Plugin
WinRAR archiver
==== End Of File ===========================
DDS (Ver_10-11-27.01) - NTFS_AMD64
Run by Sache' at 16:27:24.06 on Sun 11/28/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.7935.6214 [GMT -6:00]
SP: BitDefender Antispyware *enabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\rundll32.exe
C:\Windows\System32\nvraidservice.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~1\HEWLET~1\HPREMO~1\HPREMO~1.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Hewlett-Packard\KBD\kbd.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Sache'\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=93&bd=Pavilion&pf=cndt
uStart Page = hxxp://www.ask.com?o=15772&l=dis
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files (x86)\whitesmoketoolbar\whitesmoketoolbarX.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
TB: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - C:\Program Files (x86)\whitesmoketoolbar\whitesmoketoolbarX.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [UpdatePSTShortCut] "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
mRun: [UpdatePDIRShortCut] "c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
mRun: [UpdateP2GoShortCut] "c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
mRun: [UpdateLBPShortCut] "c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [TSMAgent] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
mRun: [Microsoft Default Manager] "c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE
mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [DVDAgent] "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
mRun: [CLMLServer for HP TouchSmart] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
mRun: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
Trusted Zone: juno.com
DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} - hxxps://www.hpwindows7upgrade.arvato.com/north_america/Endcustomer/HPProdDetect.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} - hxxp://www.worldwinner.com/games/v54/wwspades/wwspades.cab
TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll
mRun-x64: [NVRaidService] C:\Windows\system32\nvraidservice.exe
mRun-x64: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
mRun-x64: [HP Remote Software] C:\Program Files\Hewlett-Packard\HP Remote\HP REMOTE V1.0.5.exe
mRunOnce-x64: [PCDrProfiler] "C:\Program Files\PC-Doctor for Windows\RunProfiler.exe" -r
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Sache'\AppData\Roaming\Mozilla\Firefox\Profiles\ks50in09.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: C:\Program Files (x86)\Mozilla Firefox\components\FFComm.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: LOOP for Firefox: fireloop@drawloop.com - C:\Users\Sache'\AppData\Roaming\Mozilla\Firefox\Profiles\ks50in09.default\extensions\fireloop@drawloop.com
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Users\Sache'\AppData\Roaming\Mozilla\Firefox\Profiles\ks50in09.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - C:\Users\Sache'\AppData\Roaming\Mozilla\Firefox\Profiles\ks50in09.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2010-4-7 121936]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2010-4-7 22096]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2010-4-7 63568]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-5-8 40384]
R3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\Windows\System32\drivers\wg111v2.sys [2007-12-26 340992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 avast! Mail Scanner;avast! Mail Scanner;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-5-8 40384]
S3 avast! Web Scanner;avast! Web Scanner;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-5-8 40384]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-31 1255736]
=============== Created Last 30 ================
2010-11-28 21:16:22 -------- dc----w- C:\Users\Sache'\Shaggy - The Boombastic Collection - Best Of + c0vers
2010-11-28 21:07:22 -------- dc----w- C:\Users\Sache'\AppData\Roaming\WhiteSmokeTranslator
2010-11-28 11:33:37 -------- dc----w- C:\Program Files (x86)\whitesmoketoolbar
2010-11-28 04:46:12 -------- dc----w- C:\Program Files (x86)\The Sims Resource
2010-11-27 22:19:54 -------- dc----w- C:\Program Files (x86)\Trend Micro
2010-11-27 22:11:19 -------- dc----w- C:\Users\Sache'\AppData\Roaming\Malwarebytes
2010-11-27 22:11:13 38224 -c--a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-11-27 22:11:12 24664 -c--a-w- C:\Windows\System32\drivers\mbam.sys
2010-11-27 22:11:12 -------- dc----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-11-27 22:11:12 -------- dc----w- C:\PROGRA~3\Malwarebytes
2010-11-27 21:53:36 -------- dc----w- C:\Users\Sache'\AppData\Roaming\Registry Mechanic
2010-11-27 21:33:26 16384 -c--a-w- C:\Windows\cftm.exe
2010-11-27 21:33:08 939543 -c--a-w- C:\Windows\plugincontainers.exe
2010-11-25 05:51:49 -------- dc----w- C:\PROGRA~3\Trymedia
2010-11-25 05:51:07 -------- dc----w- C:\Windows\Mystic Emporium
2010-11-25 04:19:15 -------- dc----w- C:\Program Files (x86)\Common Files\SWF Studio
2010-11-25 04:19:14 -------- dcsh--w- C:\Users\Sache'\AppData\Local\.#
2010-11-25 02:11:08 -------- dc----w- C:\Program Files (x86)\Gravity
2010-11-25 01:36:04 43680 -c--a-w- C:\Windows\System32\drivers\lirsgt.sys
2010-11-25 01:36:04 314016 -c--a-w- C:\Windows\System32\drivers\atksgt.sys
2010-11-24 21:02:31 99384 -c--a-w- C:\Users\Sache'\AppData\Roaming\inst.exe
2010-11-24 21:02:31 82816 -c--a-w- C:\Windows\System32\drivers\pcouffin.sys
2010-11-24 21:02:31 82816 -c--a-w- C:\Users\Sache'\AppData\Roaming\pcouffin.sys
2010-11-24 21:02:21 -------- dc----w- C:\Program Files (x86)\DVDFab 8
2010-11-21 20:22:41 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2010-11-21 20:22:05 641536 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2010-11-21 20:22:04 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2010-11-21 20:22:04 258560 ----a-w- C:\Windows\System32\mpg2splt.ax
2010-11-21 20:22:03 552960 ----a-w- C:\Windows\System32\msdri.dll
2010-11-21 20:22:03 288256 ----a-w- C:\Windows\System32\MSNP.ax
2010-11-21 20:22:03 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2010-11-21 20:22:03 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2010-11-21 20:21:58 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2010-11-21 20:21:58 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2010-11-21 20:21:57 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2010-11-21 09:05:19 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2010-11-21 09:05:19 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2010-11-21 09:05:19 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2010-11-21 09:05:19 444752 ----a-w- C:\Windows\System32\mscoree.dll
2010-11-21 09:05:19 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2010-11-21 09:05:19 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2010-11-21 09:05:19 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2010-11-21 09:05:19 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2010-11-21 09:05:19 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2010-11-21 09:05:19 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2010-11-21 07:19:29 -------- dc----w- C:\Users\Sache'\[Kira-Fansub] My-HiME Complete (BD H264 1280x960 24fps AAC 2.0J)
2010-11-21 05:44:52 -------- dc----w- C:\Users\Sache'\Heroic age [Complete Eps 1- 26][Eng Subs]
2010-11-20 22:46:35 -------- dc----w- C:\games
2010-11-20 13:00:35 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2010-11-20 13:00:35 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2010-11-20 13:00:34 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2010-11-20 13:00:34 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-11-20 12:24:51 4582912 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2010-11-20 12:24:50 4247040 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2010-11-20 12:24:50 2085376 ----a-w- C:\Windows\System32\ole32.dll
2010-11-20 12:24:50 1413632 ----a-w- C:\Windows\SysWow64\ole32.dll
2010-11-20 12:24:26 1896832 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2010-11-20 12:24:24 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2010-11-20 12:24:24 2048 ----a-w- C:\Windows\System32\tzres.dll
2010-11-20 12:22:54 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-11-20 12:22:54 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-11-20 12:21:42 148992 ----a-w- C:\Windows\System32\t2embed.dll
2010-11-20 12:21:42 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-11-20 12:21:00 340992 ----a-w- C:\Windows\System32\schannel.dll
2010-11-20 12:21:00 224256 ----a-w- C:\Windows\SysWow64\schannel.dll
2010-11-20 12:20:58 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-11-20 12:20:58 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2010-11-20 12:15:14 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-11-20 12:15:14 463360 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-11-20 12:15:14 402944 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-11-20 12:15:14 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2010-11-20 12:15:14 161792 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-11-20 12:15:13 3123712 ----a-w- C:\Windows\System32\win32k.sys
2010-11-20 12:15:12 483840 ----a-w- C:\Windows\System32\StructuredQuery.dll
2010-11-20 12:15:12 363520 ----a-w- C:\Windows\SysWow64\StructuredQuery.dll
2010-11-20 11:13:54 558592 ----a-w- C:\Windows\System32\spoolsv.exe
2010-11-20 11:08:13 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-11-20 11:08:13 1024512 ----a-w- C:\Windows\System32\wmpmde.dll
2010-11-20 10:54:47 82944 ----a-w- C:\Windows\SysWow64\iccvid.dll
2010-11-20 09:28:44 -------- dc----w- C:\Windows\SysWow64\Adobe
2010-11-19 02:19:28 -------- dc----w- C:\Program Files (x86)\Belkin
2010-11-06 17:37:34 103864 -c--a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2010-11-06 17:37:34 103864 -c--a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
==================== Find3M ====================
2010-11-21 20:23:06 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-11-21 20:23:06 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-11-21 09:01:17 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-11-21 09:01:17 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2010-11-21 09:01:17 482816 ----a-w- C:\Windows\System32\html.iec
2010-11-21 09:01:17 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2010-11-21 09:01:17 386048 ----a-w- C:\Windows\SysWow64\html.iec
2010-11-21 09:01:17 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-11-21 09:01:17 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2010-11-21 09:01:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
2010-09-15 10:50:37 472808 -c--a-w- C:\Windows\SysWow64\deployJava1.dll
============= FINISH: 16:28:15.02 ===============