DDS.txt and Attach.txt
Logs for step 5 - DDS
1st log - DDS.txt
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Adelle at 0:43:06.84 on 26/04/2007
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2038.642 [GMT 1:00]
.
AV: BitDefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: BitDefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
FW: BitDefender Firewall *Enabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Acer\ALaunch\ALaunchSvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe
C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxeacoms.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe
C:\Program Files\Lexmark S300-S400 Series\ezprint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Users\Adelle\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wuauclt.exe
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\Program Files\BitDefender\BitDefender 2011\downloader.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Adelle\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.co.uk/
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\windows\system32\ActiveToolBand.dll
BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - c:\program files\lexmark printable web\bho.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2011\IEToolbar.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Acer Tour Reminder]
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [kdx] c:\program files\kontiki\KHost.exe -all
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe
mRun: [eAudio] "c:\acer\empowering technology\eaudio\eAudio.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PLFSet] rundll32.exe c:\windows\PLFSet.dll,PLFDefSetting
mRun: [eRecoveryService]
mRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
mRun: [WarReg_PopUp] c:\acer\wr_popup\WarReg_PopUp.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SetPanel] c:\acer\apanel\APanel.cmd
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Skytel] Skytel.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [lxeamon.exe] "c:\program files\lexmark s300-s400 series\lxeamon.exe"
mRun: [EzPrint] "c:\program files\lexmark s300-s400 series\ezprint.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2011\ieshow.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2011\bdagent.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\users\adelle\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://bq.kp.2020.net/planner/Core/Player/2020PlayerAX_Win32.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BA3BAF69-72B1-4BCE-BE96-A4D304EAFBB4} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader4.cab?20080821050326
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\adelle\appdata\roaming\mozilla\firefox\profiles\pdunb77m.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - component: c:\program files\bitdefender\bitdefender 2011\bdaphffext\components\bdaphff3.6.dll
FF - component: c:\program files\bitdefender\bitdefender 2011\bdaphffext\components\bdaphff3.dll
FF - plugin: c:\program files\picasa2\npPicasa3.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: BitDefender Antiphishing Toolbar:
FFToolbar@bitdefender.com - c:\program files\bitdefender\bitdefender 2011\bdaphffext
.
============= SERVICES / DRIVERS ===============
.
R1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2010-8-20 72784]
R1 Bdvedisk;BDVEDISK;c:\windows\system32\drivers\bdvedisk.sys [2010-1-19 85128]
R2 ALaunchService;ALaunch Service;c:\acer\alaunch\ALaunchSvc.exe [2007-8-14 50688]
R2 lxea_device;lxea_device;c:\windows\system32\lxeacoms.exe -service --> c:\windows\system32\lxeacoms.exe -service [?]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-8-24 92008]
R2 Updatesrv;BitDefender Desktop Update Service;c:\program files\bitdefender\bitdefender 2011\updatesrv.exe [2011-2-11 43936]
R3 BDFM;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-5-13 152528]
S2 lxeaCATSCustConnectService;lxeaCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxeaserv.exe [2010-6-12 98984]
S3 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2010-11-29 535824]
S3 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2010-11-29 1066232]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-13 179712]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-9-14 36608]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-12-9 30192]
S3 Update Server;BitDefender Update Server v2;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2010-11-30 307544]
S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\drivers\winbondcir.sys [2007-8-13 43008]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-7-2 16896]
.
=============== Created Last 30 ================
.
2011-03-03 21:28:47 -------- d-----w- c:\windows\system32\eu-ES
2011-03-03 21:28:47 -------- d-----w- c:\windows\system32\ca-ES
2011-03-03 21:28:46 -------- d-----w- c:\windows\system32\vi-VN
2011-03-03 21:23:18 -------- d-----w- c:\windows\system32\SPReview
2011-03-03 21:10:08 -------- d-----w- C:\b237a96ad754431ced00c8
2011-03-03 21:06:39 928768 ----a-w- c:\windows\system32\scavenge.dll
2011-03-03 21:06:18 57856 ----a-w- c:\windows\system32\compcln.exe
2011-03-03 21:05:49 -------- d-----w- C:\2fb4a2328009cbb64ab0517fb20c1221
2011-03-03 21:03:59 463872 ----a-w- c:\windows\system32\IasMigReader.exe
2011-03-03 21:02:59 53248 ----a-w- c:\windows\system32\tsgqec.dll
2011-03-03 20:57:54 -------- d-----w- c:\windows\system32\EventProviders
2011-03-03 05:04:16 -------- d-----w- c:\users\adelle\appdata\roaming\scb1pcxueuwkvgpcqpjhkuximvpomhw
2011-03-02 20:15:07 -------- d-----w- c:\progra~2\BDLogging
2011-03-01 22:46:38 784136 ----a-w- c:\progra~2\microsoft\ehome\packages\mcespotlight\mcespotlight\SpotlightResources.dll
2011-03-01 22:42:28 -------- d-----w- c:\users\adelle\appdata\roaming\BitDefender
2011-03-01 22:41:44 -------- d-----w- c:\program files\MSSOAP
2011-03-01 22:41:44 -------- d-----w- c:\program files\common files\MSSoap
2011-03-01 22:41:28 -------- d-----w- c:\program files\BitDefender
2011-03-01 22:22:07 -------- d-----w- c:\users\adelle\appdata\roaming\QuickScan
2011-03-01 22:21:22 -------- d-----w- c:\program files\common files\BitDefender
2011-03-01 22:21:22 -------- d-----w- c:\progra~2\BitDefender
2011-03-01 22:21:05 308152 ----a-w- c:\windows\system32\drivers\Trufos.sys
2011-03-01 22:21:00 327368 ----a-w- c:\windows\system32\drivers\bdfsfltr.sys
2011-03-01 22:20:59 978249 ----a-w- c:\progra~2\bdinstall.bin
2011-02-26 01:31:19 -------- d-----w- c:\progra~2\mMmOeBn06308
2011-02-05 18:21:19 -------- d-----w- c:\program files\iPod
2011-02-05 18:21:16 -------- d-----w- c:\program files\iTunes
2011-02-05 18:16:10 -------- d-----w- c:\program files\Bonjour
2011-02-05 18:12:52 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-02-05 18:12:52 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-02-05 18:12:52 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-02-05 18:12:52 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-02-05 18:12:52 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-02-05 18:12:52 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-02-05 18:12:52 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-01-19 21:47:27 -------- d-----w- c:\program files\Garmin
2011-01-19 21:44:27 -------- d-----w- c:\users\adelle\appdata\roaming\GARMIN
2011-01-01 22:37:17 -------- d-----w- C:\Kontiki
2010-12-14 18:51:20 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-12-14 18:51:20 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-11-29 17:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 17:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-29 13:12:20 1066232 ----a-w- c:\windows\system32\drivers\avckf.sys
2010-11-29 13:12:14 535824 ----a-w- c:\windows\system32\drivers\avc3.sys
2010-10-12 18:05:40 -------- d-----w- c:\program files\BBC iPlayer Desktop
2010-10-11 21:18:17 -------- d-----w- c:\progra~2\TomTom
2010-10-11 21:18:00 -------- d-----w- c:\users\adelle\appdata\roaming\TomTom
2010-10-11 21:18:00 -------- d-----w- c:\users\adelle\appdata\local\TomTom
2010-10-11 21:17:54 -------- d-----w- c:\program files\TomTom International B.V
2010-10-11 21:17:38 -------- d-----w- c:\program files\TomTom HOME 2
2010-10-07 12:23:02 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-10-07 12:23:02 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-10-07 12:23:02 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-10-07 12:23:02 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-09-14 20:31:22 -------- d-----w- c:\program files\MarkAnyContentSAFER
2010-09-14 19:47:28 90624 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-09-14 19:47:22 21632 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-09-14 19:46:22 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2010-09-14 19:45:57 36608 ----a-w- c:\windows\system32\FsUsbExDisk.Sys
2010-09-14 19:45:57 233472 ----a-w- c:\windows\system32\FsUsbExService.Exe
2010-09-14 19:45:57 110592 ----a-w- c:\windows\system32\FsUsbExDevice.Dll
2010-09-14 19:45:45 -------- d-----w- c:\users\adelle\appdata\roaming\Samsung
2010-09-14 19:45:19 -------- d-----w- c:\program files\PC Connectivity Solution
2010-08-20 14:41:58 72784 ----a-w- c:\windows\system32\drivers\BdfNdisf6.sys
2010-07-20 19:40:30 -------- d-----w- c:\progra~2\Lexmark S300-S400 Series
2010-07-08 09:37:14 101544 ----a-w- c:\program files\common files\LinkInstaller.exe
2010-06-12 17:49:53 -------- d-----w- c:\progra~2\Ezprint
2010-06-12 17:39:09 -------- d-----w- c:\progra~2\Lx_cats
2010-06-12 17:37:51 157696 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\lxeadrpp.dll
2010-06-12 17:33:09 40960 ----a-w- c:\windows\system32\lxeavs.dll
2010-06-12 17:33:04 438272 ----a-w- c:\windows\system32\lxeacoin.dll
2010-06-12 17:32:59 983121 ----a-w- c:\windows\system32\lxk_gf.dll
2010-06-12 17:32:59 86016 ----a-w- c:\windows\system32\lxeagcfg.dll
2010-06-12 17:32:59 294912 ----a-w- c:\windows\system32\lxeacui.dll
2010-06-12 17:32:59 110592 ----a-w- c:\windows\system32\lxeacuir.dll
2010-06-12 17:31:15 -------- d-----w- c:\program files\Lexmark Tools for Office
2010-06-12 17:31:05 372736 ----a-w- c:\windows\system32\LXEAwupd.dll
2010-06-12 17:31:05 213672 ----a-w- c:\windows\system32\LXEAwupd.exe
2010-06-12 17:30:25 -------- d-----w- c:\program files\Lexmark
2010-06-12 17:30:17 -------- d-----w- c:\program files\Lexmark Toolbar
2010-06-12 17:30:13 -------- d-----w- c:\program files\Lexmark Printable Web
2010-06-12 17:25:49 -------- d-----w- c:\program files\Lexmark S300-S400 Series
2010-06-12 17:25:48 299008 ----a-w- c:\windows\system32\LXEAsm.dll
2010-06-12 17:25:48 23552 ----a-w- c:\windows\system32\LXEAsmr.dll
2010-06-03 02:41:44 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-13 15:52:30 106456 ----a-w- c:\windows\system32\drivers\bdhv.sys
2010-05-13 15:52:04 152528 ----a-w- c:\windows\system32\drivers\bdfm.sys
2010-04-04 21:25:16 -------- d-----w- c:\progra~2\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-03-22 21:54:51 -------- d-----w- c:\windows\system32\20-20 Technologies
2010-01-19 18:32:40 85128 ----a-w- c:\windows\system32\drivers\bdvedisk.sys
2010-01-04 18:43:32 -------- d-----w- C:\Marketing notes - Adelle
2009-12-23 18:20:01 -------- d-----w- c:\progra~2\McAfee Security Scan
2009-12-23 18:20:00 -------- d-----w- c:\program files\McAfee Security Scan
2009-12-21 22:59:40 -------- d-----w- c:\users\adelle\appdata\roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
2009-11-26 20:25:27 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-26 20:25:27 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-26 20:24:46 -------- d-----w- c:\progra~2\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-24 19:37:50 -------- d-----w- c:\users\adelle\Tracing
2009-11-24 19:31:45 -------- d-----w- c:\program files\Microsoft Office Communicator
2009-11-24 19:17:26 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-24 19:16:34 -------- d-----w- c:\users\adelle\appdata\local\Microsoft Help
2009-08-15 17:09:11 -------- d-----w- c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-17 15:48:14 9344 ----a-w- c:\windows\system32\drivers\grmnusb.sys
2009-04-17 15:48:14 18304 ----a-w- c:\windows\system32\drivers\grmngen.sys
2008-12-24 20:54:41 -------- d-----w- c:\program files\NoAdware
2008-12-09 22:09:17 2560 ------w- c:\windows\system32\drivers\cdralw2k.sys
2008-12-09 22:09:17 2432 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2008-12-09 22:09:08 -------- d-----w- c:\program files\Picasa2
2008-12-09 22:08:20 -------- d-----w- c:\program files\Western Digital
2008-11-20 19:19:06 43872 ----a-w- c:\windows\system32\drivers\pxhelp20.sys
2008-11-01 18:37:02 -------- d-----w- C:\PerfLogs
2008-11-01 18:14:10 3834960 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{ac9cd8a6-c3aa-4fb1-a208-6b290f558cc8}\mpengine.dll
2008-10-28 19:43:06 37888 ----a-w- c:\windows\system32\printcom.dll
2008-10-26 21:25:32 -------- d-----w- c:\users\adelle\appdata\local\Google
2008-10-26 21:24:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2008-10-17 20:50:58 129536 ----a-w- c:\program files\internet explorer\sqmapi.dll
2008-09-20 20:45:22 3834960 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\backup\mpengine.dll
2008-08-22 20:04:07 1524736 ----a-w- c:\windows\system32\wucltux.dll
2008-08-22 20:03:31 83456 ----a-w- c:\windows\system32\wudriver.dll
2008-08-22 20:03:04 31232 ----a-w- c:\windows\system32\wuapp.exe
2008-08-22 20:03:04 163904 ----a-w- c:\windows\system32\wuwebv.dll
2008-08-14 19:55:42 61440 ----a-w- c:\windows\system32\winipsec.dll
2008-08-14 19:55:42 272896 ----a-w- c:\windows\system32\polstore.dll
2008-07-29 12:08:06 669184 ----a-w- c:\program files\common files\microsoft shared\vc\msdia90.dll
2008-07-25 22:36:17 -------- d-----w- c:\users\adelle\appdata\local\Apple Computer
2008-07-25 22:32:50 -------- d-----w- c:\users\adelle\appdata\local\Apple
2008-07-19 23:50:35 -------- d-----w- c:\users\adelle\appdata\roaming\ZoomBrowser EX
2008-07-18 20:04:36 -------- d-----w- c:\users\adelle\appdata\local\CANON_INC
2008-07-18 19:48:05 -------- d-----w- c:\users\adelle\appdata\local\Adobe
2008-07-18 19:42:54 -------- d-----w- c:\progra~2\ZoomBrowser
2008-07-18 19:41:15 -------- d-----w- c:\program files\Canon
2008-07-18 19:39:59 -------- d-----w- c:\program files\common files\Canon
2008-07-05 23:31:56 -------- d-----w- C:\Peter
2008-07-02 18:17:03 2730536 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\default\MpEngine.dll
2008-07-02 18:15:59 76288 ----a-w- c:\windows\system32\wevtfwd.dll
2008-07-02 18:14:59 88576 ----a-w- c:\windows\system32\ntdsapi.dll
2008-07-02 18:13:59 78848 ----a-w- c:\windows\system32\olecli32.dll
2008-07-02 18:12:56 89088 ----a-w- c:\windows\system32\wiafbdrv.dll
2008-07-02 18:12:33 102400 ----a-w- c:\windows\system32\wbem\mofinstall.dll
2008-07-02 18:12:32 357888 ----a-w- c:\windows\system32\wbemcomn.dll
2008-07-02 18:12:27 139264 ----a-w- c:\windows\system32\SmiInstaller.dll
2008-07-02 18:11:57 35328 ----a-w- c:\windows\system32\mspatcha.dll
2008-07-02 18:11:57 305152 ----a-w- c:\windows\system32\msdelta.dll
2008-07-02 18:11:57 258560 ----a-w- c:\windows\system32\dpx.dll
2008-07-02 18:11:46 6656 ----a-w- c:\windows\system32\kbd106.dll
2008-06-30 22:48:24 -------- d-----w- c:\program files\Kontiki
2008-06-30 22:48:24 -------- d-----w- c:\progra~2\Kontiki
2008-06-30 22:48:13 -------- d-----w- C:\logs3
2008-06-30 22:47:40 -------- d-----w- c:\windows\Downloaded Installations
2008-06-15 16:18:18 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2008-06-12 18:01:04 -------- d-----w- c:\users\adelle\Pete's pictures
2008-05-28 21:51:47 -------- d-----w- c:\progra~2\Forge of Games
2008-05-28 21:30:40 -------- d--h--w- c:\windows\PIF
2008-05-28 21:10:46 6656 ----a-w- c:\windows\system32\kbd106n.dll
2008-05-28 21:05:05 -------- d-----w- c:\program files\MSXML 4.0
2008-05-28 20:52:14 -------- d-----w- c:\users\adelle\appdata\local\PowerCinema
2008-05-28 20:13:42 -------- d-----w- c:\users\adelle\appdata\roaming\Acer
2008-05-28 20:13:34 -------- d--h--w- c:\users\adelle\appdata\local\acer eNM
2008-05-28 20:13:18 -------- d-----w- c:\users\adelle\appdata\local\PlayMovie
2008-05-28 20:11:20 -------- d-----w- c:\program files\Yahoo!
2008-05-28 20:11:01 -------- d-----w- c:\users\adelle\appdata\local\VirtualStore
2008-05-28 20:09:18 -------- d-----w- c:\windows\system32\ENU
2008-05-28 20:09:16 936728 ----a-w- c:\windows\system32\imsmudlg.exe
2007-10-25 16:26:10 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2007-10-01 04:33:08 3 ----a-w- c:\windows\AFirst.cmd
2007-10-01 04:33:08 17100352 ----a-w- c:\windows\eRy.exe
2007-10-01 04:33:07 86016 ----a-w- c:\windows\Hide.exe
2007-10-01 04:32:50 336 ----a-w- c:\windows\ACERTOURREMINDERRUN.REG
2007-10-01 04:32:50 294 ----a-w- c:\windows\offline.reg
2007-10-01 04:32:47 65536 ----a-w- c:\windows\SetSpkDefault.exe
2007-10-01 04:32:30 931 ----a-w- c:\windows\CLEANUP.CMD
2007-10-01 04:32:30 55808 ----a-w- c:\windows\devcon.exe
2007-10-01 03:59:48 368640 ----a-w- c:\windows\system32\CheckD2DSystem.exe
2007-10-01 03:59:48 327680 ----a-w- c:\windows\system32\Remove_eRecovery.exe
2007-10-01 03:59:48 16384 ----a-w- c:\windows\system32\LauncheRyAgentUser.exe
2007-10-01 03:59:48 16384 ----a-w- c:\windows\system32\ClearEvent.exe
2007-10-01 03:58:06 83554304 ----a-w- c:\windows\system32\acer.scr
2007-10-01 03:57:54 71965372 ----a-w- c:\windows\system32\acer.exe
2007-10-01 03:57:44 -------- d-----w- c:\program files\Acer Inc
2007-10-01 03:57:42 -------- d-----w- c:\windows\ACER
2007-10-01 03:50:01 -------- d-----w- C:\CLSetup
2007-10-01 03:45:04 1706800 ----a-w- c:\windows\system32\gdiplus.dll
2007-10-01 03:42:53 172032 ----a-w- c:\windows\system32\igfxres.dll
2007-10-01 03:42:45 -------- d-sh--w- C:\$RECYCLE.BIN
2007-10-01 03:39:04 -------- d-----w- c:\program files\SUYIN
2007-10-01 03:39:04 -------- d-----w- c:\program files\ACER Crystal Eye webcam
2007-10-01 03:38:29 286720 ----a-w- c:\windows\system32\vsnp2uvc.dll
2007-10-01 03:38:29 172032 ----a-w- c:\windows\system32\rsnp2uvc.dll
2007-10-01 03:38:29 -------- d-----w- c:\windows\SUYIN NB Cam
2007-10-01 03:38:28 53248 ----a-w- c:\windows\system32\csnp2uvc.dll
2007-10-01 03:38:28 -------- d-----w- c:\program files\common files\snp2uvc
2007-10-01 03:36:45 -------- d-----w- c:\windows\system32\x64
2007-10-01 03:36:45 -------- d-----w- c:\windows\system32\Lang
2007-10-01 03:36:44 399896 ----a-w- c:\windows\system32\igxpun.exe
2007-10-01 03:36:44 319456 ----a-w- c:\windows\system32\difxapi.dll
2007-08-24 17:08:24 1275392 ----a-w- c:\windows\system32\msxml4.dll
2007-08-14 01:29:38 1024 ---h--r- c:\windows\system32\NTIBUN4.dll
2007-08-14 01:28:29 91136 ----a-r- c:\windows\system32\msls2.dll
2007-08-14 01:27:20 31744 ----a-r- c:\windows\system32\hlp95en.dll
2007-08-14 01:27:05 90112 ----a-r- c:\windows\system32\eNetHook.dll
2007-08-14 01:19:28 1822520 ----a-r- c:\windows\instmsiw.exe
2007-08-14 00:28:26 -------- d-----w- c:\program files\Norton Internet Security
2007-08-14 00:25:54 -------- d-----w- c:\program files\Symantec
2007-08-14 00:25:53 -------- d-----w- c:\progra~2\Symantec
2007-08-14 00:21:08 -------- d-----w- c:\progra~2\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2007-08-14 00:21:05 -------- d-----w- c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2007-08-14 00:19:02 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2007-08-14 00:19:02 32592 ----a-w- c:\windows\system32\msonpmon.dll
2007-08-14 00:18:30 -------- d-----w- c:\windows\PCHEALTH
2007-08-14 00:12:24 8704 ----a-w- c:\windows\system32\drivers\TVicPort64.sys
2007-08-14 00:12:24 76584 ----a-w- c:\windows\system32\drivers\int15.sys
2007-08-14 00:12:24 6080 ----a-w- c:\windows\system32\drivers\zntport.sys
2007-08-14 00:12:24 15656 ----a-w- c:\windows\system32\drivers\int15_64.sys
2007-08-14 00:12:24 14544 ----a-w- c:\windows\system32\drivers\TVicPort.sys
2007-08-14 00:12:24 13096 ----a-w- c:\windows\system32\drivers\zntport64.sys
2007-08-14 00:11:46 65536 ----a-w- c:\windows\system32\NATTraversal.dll
2007-08-14 00:07:42 -------- d-----w- c:\windows\system32\i386
2007-08-14 00:06:52 53248 ----a-w- c:\windows\system32\Interop.Shell32.dll
2007-08-14 00:06:49 772096 ----a-w- c:\windows\system32\Acer.Empowering.Windows.Forms.dll
2007-08-14 00:06:49 331776 ----a-w- c:\windows\system32\ScrollBarLib.dll
2007-08-14 00:05:38 -------- d-----w- C:\MyWorks
2007-08-14 00:04:32 82432 ----a-w- c:\windows\system32\msxml4r.dll
2007-08-14 00:04:32 44544 ----a-w- c:\windows\system32\msxml4a.dll
2007-08-14 00:03:32 89088 ----a-w- c:\windows\system32\atl71.dll
2007-08-14 00:03:18 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2007-08-14 00:03:18 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2007-08-14 00:03:18 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2007-08-14 00:03:18 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2007-08-14 00:03:15 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2007-08-14 00:00:28 757760 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2007-08-14 00:00:28 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2007-08-14 00:00:28 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2007-08-14 00:00:28 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2007-08-14 00:00:28 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2007-08-14 00:00:28 204800 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2007-08-14 00:00:28 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2007-08-13 23:59:54 225280 ----a-w- c:\windows\setup.exe
2007-08-13 23:59:53 323584 ----a-w- c:\windows\AEITAddInRdr.dll
2007-08-13 23:59:53 2728960 ----a-w- c:\windows\Adobe Reader 7.0.msi
2007-08-13 23:56:13 -------- d-----w- c:\program files\common files\NewTech Infosystems
2007-08-13 23:56:10 -------- d-----w- c:\program files\NewTech Infosystems
2007-08-13 23:55:54 6144 ----a-w- c:\windows\system32\drivers\NTIDrvr.sys
2007-08-13 23:50:35 -------- d-----w- c:\program files\Acer GameZone
2007-08-13 23:44:14 8704 ----a-w- c:\windows\system32\hccoin.dll
2007-08-13 23:18:44 -------- d-----w- c:\program files\Winbond Electronics
2007-08-13 23:07:37 -------- d-----w- C:\Intel
2007-08-13 23:05:47 -------- d-sh--w- c:\windows\Installer
2007-08-13 23:05:46 23 ----a-w- c:\progra~2\microsoft\crypto\rsa\machinekeys\$Acer$.cmd
2007-08-13 23:00:08 -------- d-----w- c:\program files\CONEXANT
2007-08-13 22:51:11 -------- d-----w- c:\windows\Panther
2007-08-13 22:50:54 -------- d-sh--w- C:\Boot
2007-08-13 22:50:28 277784 ----a-w- c:\windows\system32\drivers\iaStor.sys
2007-08-13 22:48:22 183056 ----a-w- c:\windows\UNINST32.EXE
2007-08-13 22:47:20 1060424 ----a-w- c:\windows\system32\WdfCoInstaller01000.dll
2007-08-13 22:47:19 196608 ----a-w- c:\windows\system32\SynCtrl.dll
2007-08-13 22:47:19 185392 ----a-w- c:\windows\system32\drivers\SynTP.sys
2007-08-13 22:47:19 163840 ----a-w- c:\windows\system32\SynCOM.dll
2007-08-13 22:47:19 143360 ----a-w- c:\windows\system32\SynTPAPI.dll
2007-08-13 22:47:19 110592 ----a-w- c:\windows\system32\SynTPCo4.dll
2007-08-13 22:46:11 -------- d-----w- C:\Acer
2007-06-03 11:05:42 1216512 ----a-w- c:\windows\system32\Treasures of the Deep.scr
2007-06-03 10:58:26 61440 ----a-w- c:\windows\system32\Big Kahuna Reef 2.scr
2007-04-26 17:02:15 -------- d-----w- c:\users\adelle\appdata\roaming\Malwarebytes
2007-04-26 17:02:05 -------- d-----w- c:\progra~2\Malwarebytes
2007-04-26 17:02:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2007-04-26 00:18:50 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-04-25 23:34:44 16680 ----a-w- c:\windows\system32\drivers\PSDNServ.sys
2007-04-25 23:34:40 60712 ----a-w- c:\windows\system32\drivers\psdvdisk.sys
2007-04-25 23:34:38 20776 ----a-w- c:\windows\system32\drivers\psdfilter.sys
2007-04-25 23:33:22 299008 ----a-w- c:\windows\system32\ActiveToolBand.dll
2007-04-25 23:33:22 266240 ----a-w- c:\windows\system32\NotesExtmngr.dll
2007-04-25 23:32:50 204800 ----a-w- c:\windows\system32\NotesActnMenu.dll
2007-04-25 23:32:46 86016 ----a-w- c:\windows\system32\MSNSpook.dll
2007-04-25 23:32:32 274432 ----a-w- c:\windows\system32\OAddin.dll
2007-04-25 23:31:52 892928 ----a-w- c:\windows\system32\HiTRUST.EDS.Windows.Forms.dll
2007-04-25 23:31:38 258048 ----a-w- c:\windows\system32\FingerprintLibrary.dll
2007-04-25 23:31:20 122880 ----a-w- c:\windows\system32\ADMIN_CLASS_LIB.dll
2007-04-25 23:31:00 28672 ----a-w- c:\windows\system32\BatchCrypto.dll
2007-04-25 23:30:52 73728 ----a-w- c:\windows\system32\APISlice.dll
2007-04-25 23:30:46 121344 ----a-w- c:\windows\system32\PSDUtil.dll
2007-04-25 23:30:44 63488 ----a-w- c:\windows\system32\ShowErrMsg.dll
2007-04-25 23:30:40 286720 ----a-w- c:\windows\system32\sysenv.dll
2007-04-25 23:30:32 151552 ----a-w- c:\windows\system32\eDStoolbar.dll
2007-04-25 23:30:20 315392 ----a-w- c:\windows\system32\eDSshellExt.dll
2007-04-25 23:08:01 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2007-04-25 23:07:56 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
.
==================== Find3M ====================
.
2010-01-07 15:08:23 324264 ----a-w- c:\windows\system32\lxeaih.exe
2010-01-07 15:08:22 598696 ----a-w- c:\windows\system32\lxeacoms.exe
2010-01-07 15:08:21 373416 ----a-w- c:\windows\system32\lxeacfg.exe
2009-12-09 13:47:48 643072 ----a-w- c:\windows\system32\lxeapmui.dll
2009-12-09 13:43:13 1048576 ----a-w- c:\windows\system32\lxeaserv.dll
2009-12-09 13:41:21 688128 ----a-w- c:\windows\system32\lxeahbn3.dll
2009-12-09 13:40:11 847872 ----a-w- c:\windows\system32\lxeausb1.dll
2009-12-09 13:37:32 356352 ----a-w- c:\windows\system32\LXEAhcp.dll
2009-12-09 13:36:47 372736 ----a-w- c:\windows\system32\lxeacomm.dll
2009-12-09 13:36:31 577536 ----a-w- c:\windows\system32\lxealmpm.dll
2009-12-09 13:35:48 344064 ----a-w- c:\windows\system32\lxeaiesc.dll
2009-12-09 13:35:43 802816 ----a-w- c:\windows\system32\lxeacomc.dll
2009-12-09 13:35:30 364544 ----a-w- c:\windows\system32\lxeainpa.dll
2009-11-26 02:52:00 86186 ----a-w- c:\windows\system32\LXEAcfg.dll
2009-11-09 02:06:50 106496 ----a-w- c:\windows\system32\lxeainsr.dll
2009-11-09 02:06:48 36864 ----a-w- c:\windows\system32\lxeacur.dll
2009-11-09 02:06:38 57344 ----a-w- c:\windows\system32\lxeajswr.dll
2009-11-09 02:06:24 262144 ----a-w- c:\windows\system32\lxeainsb.dll
2009-11-09 02:06:21 90112 ----a-w- c:\windows\system32\lxeacub.dll
2009-11-09 02:06:12 208896 ----a-w- c:\windows\system32\lxeagrd.dll
2009-11-09 02:06:05 253952 ----a-w- c:\windows\system32\lxeacu.dll
2009-11-09 02:05:53 323584 ----a-w- c:\windows\system32\lxeains.dll
2009-04-10 23:33:20 986600 ----a-w- c:\windows\system32\winload.exe
2009-04-10 23:33:20 926184 ----a-w- c:\windows\system32\winresume.exe
2009-04-10 23:33:04 614376 ----a-w- c:\windows\system32\ci.dll
2009-04-10 23:32:54 50664 ----a-w- c:\windows\system32\PSHED.DLL
2009-04-10 23:32:50 438744 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2009-04-10 23:32:50 3601896 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-04-10 23:32:50 3549672 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-04-10 23:32:48 245736 ----a-w- c:\windows\system32\clfs.sys
2009-04-10 23:32:48 177128 ----a-w- c:\windows\system32\halmacpi.dll
2009-04-10 23:32:44 140776 ----a-w- c:\windows\system32\halacpi.dll
2009-04-10 23:32:28 19944 ----a-w- c:\windows\system32\kdusb.dll
2009-04-10 23:32:28 17896 ----a-w- c:\windows\system32\kd1394.dll
2009-04-10 23:32:28 17384 ----a-w- c:\windows\system32\kdcom.dll
2009-04-10 23:27:54 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2009-04-10 23:23:04 89088 ----a-w- c:\windows\system32\pintlgnt.ime
2009-04-10 23:23:04 125952 ----a-w- c:\windows\system32\tintlgnt.ime
2009-04-10 23:23:04 124928 ----a-w- c:\windows\system32\quick.ime
2009-04-10 23:23:04 124928 ----a-w- c:\windows\system32\qintlgnt.ime
2009-04-10 23:23:04 124928 ----a-w- c:\windows\system32\phon.ime
2009-04-10 23:23:00 413696 ----a-w- c:\windows\system32\imkr80.ime
2009-04-10 23:22:58 883712 ----a-w- c:\windows\system32\IMJP10.IME
2009-04-10 23:22:58 124928 ----a-w- c:\windows\system32\cintlgnt.ime
2009-04-10 23:22:54 124928 ----a-w- c:\windows\system32\chajei.ime
2009-04-10 23:22:24 7168 ----a-w- c:\windows\system32\f3ahvoas.dll
2009-04-10 23:21:48 37376 ----a-w- c:\windows\system32\cdd.dll
2009-04-10 22:04:32 389632 ----a-w- c:\windows\system32\html.iec
2009-04-10 22:03:44 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-04-10 22:03:42 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-04-10 21:57:28 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-04-10 21:55:00 2048 ----a-w- c:\windows\system32\mferror.dll
2009-04-10 21:39:58 16384 ----a-w- c:\windows\system32\iscsilog.dll
2009-04-10 21:36:12 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2009-04-10 21:27:18 2560 ----a-w- c:\windows\system32\msimsg.dll
2009-04-10 21:24:18 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-04-10 21:23:24 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-04-10 21:12:44 617984 ----a-w- c:\windows\system32\adtschema.dll
2009-04-10 18:59:54 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2009-04-10 18:59:52 107612 ----a-w- c:\windows\system32\StructuredQuerySchema.bin
2009-04-02 20:12:31 385024 ----a-w- c:\windows\system32\LXEAinst.dll
2009-03-29 21:42:22 93512 ----a-w- c:\windows\system32\dfshim.dll
2009-03-29 21:42:22 80720 ----a-w- c:\windows\system32\mscories.dll
2009-03-29 21:42:22 278848 ----a-w- c:\windows\system32\mscoree.dll
2009-03-29 21:42:22 155456 ----a-w- c:\windows\system32\mscorier.dll
2009-02-18 11:39:58 92918 ----a-w- c:\windows\system32\slmgr.vbs
2009-02-18 11:39:22 779136 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-02-18 11:39:22 41344 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-02-18 11:39:22 35680 ----a-w- c:\windows\system32\TsWpfWrp.exe
2009-02-18 11:39:22 323952 ----a-w- c:\windows\system32\PresentationHost.exe
2009-02-18 11:39:22 102816 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-02-18 11:38:48 99680 ----a-w- c:\windows\system32\infocardapi.dll
2009-02-18 11:38:48 9048 ----a-w- c:\windows\system32\icardres.dll
2009-02-18 11:38:48 619864 ----a-w- c:\windows\system32\icardagt.exe
2009-02-18 11:38:48 35168 ----a-w- c:\windows\system32\infocardcpl.cpl
2008-11-01 18:28:50 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2008-11-01 18:28:47 82432 ----a-w- c:\windows\system32\axaltocm.dll
2008-01-19 07:42:51 94776 ----a-w- c:\windows\system32\MigAutoPlay.exe
2008-01-19 07:41:34 24120 ----a-w- c:\windows\system32\BOOTVID.DLL
2008-01-19 07:38:45 103936 ----a-w- c:\windows\system32\NAPHLPR.DLL
2008-01-19 07:38:44 46080 ----a-w- c:\windows\system32\NAPCRYPT.DLL
2008-01-19 07:38:11 4595712 ----a-w- c:\windows\system32\AuthFWSnapin.dll
2008-01-19 07:38:02 155704 ----a-w- c:\windows\system32\dssenh.dll
2008-01-19 07:36:58 91136 ----a-w- c:\windows\system32\wbem\WmiPerfClass.dll
2008-01-19 07:35:59 296960 ----a-w- c:\windows\system32\ntshrui.dll
2008-01-19 07:34:57 215040 ----a-w- c:\windows\system32\msdtcuiu.dll
2008-01-19 07:33:59 17408 ----a-w- c:\windows\system32\corpol.dll
2008-01-19 07:32:59 5714432 ----a-w- c:\windows\system32\logon.scr
2008-01-19 07:32:59 221184 ----a-w- c:\windows\system32\Mystify.scr
2008-01-19 07:32:59 220672 ----a-w- c:\windows\system32\Ribbons.scr
2008-01-19 07:32:58 879616 ----a-w- c:\windows\system32\Bubbles.scr
2008-01-19 07:32:57 691200 ----a-w- c:\windows\system32\TabletPC.cpl
2008-01-19 07:32:57 442368 ----a-w- c:\windows\system32\joy.cpl
2008-01-19 07:32:57 337408 ----a-w- c:\windows\system32\intl.cpl
2008-01-19 07:32:57 242688 ----a-w- c:\windows\system32\sysdm.cpl
2008-01-19 07:32:57 163328 ----a-w- c:\windows\system32\powercfg.cpl
2008-01-19 07:32:57 1370624 ----a-w- c:\windows\system32\Aurora.scr
2008-01-19 07:32:56 368640 ----a-w- c:\windows\system32\desk.cpl
2008-01-19 07:32:56 2249216 ----a-w- c:\windows\system32\Firewall.cpl
2008-01-19 07:31:43 7680 ----a-w- c:\windows\system32\spwizres.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 6.0.6002 Disk: TOSHIBA_ rev.DL05 -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x86D4D735]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x86d53990]; MOV EAX, [0x86d53a0c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x8244C912] -> \Device\Harddisk0\DR0[0x867B5528]
3 CLASSPNP[0x887B88B3] -> ntkrnlpa!IofCallDriver[0x8244C912] -> [0x855E49E0]
5 acpi[0x82A986BC] -> ntkrnlpa!IofCallDriver[0x8244C912] -> [0x855E5030]
\Driver\iaStor[0x868B8BD0] -> IRP_MJ_CREATE -> 0x86D4D735
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x132; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskTOSHIBA_MK1637GSX_______________________DL050J__#4&4d93025&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 0:46:08.62 ===============