Somehow i got infected with some sort of russian made spyware. Doesnt seem to hijack my browser or anything malicious aside from using up ram and cycles.
I have already attempted to delete the files up.exe, Skybound.Gecko.dll, safesurf.exe, surfguard.exe, and the folder "f" from teh windows/system32/drivers folder (i found a report on google saying some sites created these files and directories). Sometimes they stay deleted until i reboot , and i have already disabled the files from loading via msconfig. They seem reappear after reboots, but seem to re download themselves or recopy themselves from another directory most of the time.
DDS Log
DDS (Ver_10-03-17.01) - NTFSx86
Run by Owner at 15:51:09.68 on Mon 08/30/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.626 [GMT -4:00]
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated)
{E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
============== Running Processes ===============
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
D:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
D:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\SetPointP\SetPoint.exe
svchost.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\ctfmon.exe
C:\FRAPS\FRAPS.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
D:\Documents and Settings\Casey Kline\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Stardock\Impulse\Now\ImpulseNow.exe
C:\Program Files\BW Monitor\BWMonitor.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
D:\WINDOWS\system32\system\svchost.exe
D:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\WINDOWS\system32\drivers\safesurf.exe
D:\WINDOWS\system32\drivers\surfguard.exe
C:\DOWNLOADS\PROCESSEXPLORER\PROCEXP.EXE
C:\Downloads\dds.scr
D:\WINDOWS\system32\SearchProtocolHost.exe
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program
files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program
files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} -
c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program
files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [AtiTrayTools] "c:\program files\ray adams\ati tray tools\atitray.exe"
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
uRun: [Google Update] "d:\documents and settings\casey kline\local settings\application
data\google\update\GoogleUpdate.exe" /c
uRun: [TpScrex] c:\programdata\tpscrex\TpScrex.exe /somering
uRun: [Fraps] c:\fraps\FRAPS.EXE
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader
9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [jsafesurf] d:\windows\system32\drivers\safesurf.exe
StartupFolder: d:\docume~1\caseyk~1\startm~1\programs\startup\dropbox.lnk - d:\documents
and settings\casey kline\application data\dropbox\bin\Dropbox.exe
StartupFolder: d:\docume~1\caseyk~1\startm~1\programs\startup\impuls~1.lnk - c:\program
files\stardock\impulse\now\ImpulseNow.exe
StartupFolder: d:\docume~1\caseyk~1\startm~1\programs\startup\shortc~1.lnk - c:\program
files\bw monitor\BWMonitor.exe
StartupFolder: d:\docume~1\caseyk~1\startm~1\programs\startup\shortc~2.lnk -
d:\windows\system32\taskmgr.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program
files\windows desktop search\WindowsSearch.exe
IE: &NeoTrace It! - c:\progra~1\neotra~1\NTXcontext.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} -
c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -
hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?
1277092124018
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program
files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
d:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} -
c:\program files\windows desktop search\MSNLNamespaceMgr.dll
IFEO: taskmgr.exe - "c:\downloads\processexplorer\PROCEXP.EXE"
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - d:\docume~1\caseyk~1\applic~1\mozilla\firefox\profiles\vfhp6q8h.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\mozilla
firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - component: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\piclens@cooliris.com\components\c
oolirisstub.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf379
16a7}\plugins\np_gp.dll
FF - plugin: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\csweblauncher@cyberstep.com\plugi
ns\npCsWebLauncher.dll
FF - plugin: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\kos@dontblynk.com\platform\winnt_
x86-msvc\plugins\NPSting.dll
FF - plugin: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\piclens@cooliris.com\plugins\npco
olirisplugin.dll
FF - plugin: d:\documents and settings\casey kline\local settings\application
data\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant:
{20a82645-c095-46ed-80e3-08825760534b} - d:\windows\microsoft.net\framework\v3.5\windows
presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla
firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla
firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js
- pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows",
false);
c:\program files\mozilla firefox\greprefs\all.js -
pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js -
pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai",
true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm",
false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type",
5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size",
4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug",
false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight",
2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize",
1);
c:\program files\mozilla firefox\greprefs\all.js -
pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js -
pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight",
25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight",
5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref",
true);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js -
pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js -
pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js -
pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name",
"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description",
"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add",
"addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled",
false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 atitray;atitray;c:\program files\ray adams\ati tray tools\atitray.sys [2009-11-25 19232]
R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [2009-9-11 108792]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-9-11 735960]
R2 LBeepKE;Logitech Beep Suppression Driver;d:\windows\system32\drivers\LBeepKE.sys
[2010-6-20 10448]
R2 Win_Updater;Win32 Updater;d:\windows\system32\system\svchost.exe [2010-8-21 1405440]
R3 WDC_SAM;WD SCSI Pass Thru driver;d:\windows\system32\drivers\wdcsam.sys [2010-6-21
11520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN
v4.0.30319_X86;d:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18
130384]
S3 cpuz130;cpuz130;\??\d:\docume~1\caseyk~1\locals~1\temp\cpuz130\cpuz_x32.sys -->
d:\docume~1\caseyk~1\locals~1\temp\cpuz130\cpuz_x32.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache
4.0.0.0;d:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18
753504]
=============== Created Last 30 ================
2010-08-30 17:56:22 0 d-----w- d:\docume~1\alluse~1\applic~1\Spybot -
Search & Destroy
2010-08-30 17:56:22 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-30 17:42:03 19456 ----a-w- d:\windows\system32\drivers\surfguard.exe
2010-08-30 17:39:32 0 d-----w- d:\windows\system32\drivers\f
2010-08-30 17:39:31 16896 ----a-w- d:\windows\system32\drivers\up.exe
2010-08-30 17:39:16 211968 ----a-w- d:\windows\system32\drivers\safesurf.exe
2010-08-30 13:31:09 158720 ----a-w-
d:\windows\system32\drivers\skybound.gecko.dll
2010-08-28 04:54:13 0 d-----w- c:\program files\Microsoft Games for
Windows - LIVE
2010-08-28 03:05:44 0 d-----w- d:\windows\system32\xlive
2010-08-28 03:01:33 107888 ----a-w- d:\windows\system32\CmdLineExt.dll
2010-08-27 23:11:45 0 d-----w- d:\windows\usgwmt
2010-08-27 22:01:01 0 d-sh--w- d:\docume~1\alluse~1\applic~1\SecuROM
2010-08-27 21:27:35 0 d-----w- c:\program files\2K Games
2010-08-27 20:55:52 0 d-----w- d:\windows\pss
2010-08-27 19:41:59 0 d-----w- d:\windows\system32\appmgmt
2010-08-27 00:52:08 0 d-----w- d:\docume~1\alluse~1\applic~1\Caelum
2010-08-27 00:50:56 4286 ----a-w- d:\windows\system32\ico.ico
2010-08-27 00:50:52 0 d-----w- d:\windows\system32\system
2010-08-27 00:50:46 0 d-----w- d:\windows\system32\webem
2010-08-24 18:35:46 0 d-----w- c:\program files\common files\Futuremark
Shared
2010-08-24 03:21:33 0 d-----w-
d:\docume~1\caseyk~1\applic~1\ArtificialStudios
2010-08-24 03:17:12 0 d-----w- c:\program files\Artificial Studios
2010-08-23 03:01:42 0 d-----w- d:\documents and settings\casey kline\oni
2010-08-20 23:40:09 0 d-----w- c:\program files\Apophysis 2.0
2010-08-20 17:34:43 0 d-----w- c:\program files\Alien Skin
2010-08-19 21:23:15 0 d-----w- d:\docume~1\alluse~1\applic~1\NOMBZ Save
Data
2010-08-19 20:37:00 0 d-----w- c:\program files\ReflexiveArcade
2010-08-19 18:55:03 28 ----a-w- d:\windows\pdf995.ini
2010-08-19 18:43:48 59 ----a-w- d:\windows\wpd99.drv
2010-08-19 18:43:48 51716 ----a-w- d:\windows\system32\pdf995mon.dll
2010-08-19 18:43:48 249856 ----a-w- d:\windows\system32\pdfmona.dll
2010-08-19 18:43:48 0 d-----w- d:\docume~1\alluse~1\applic~1\pdf995
2010-08-19 18:43:45 0 d-----w- c:\program files\pdf995
2010-08-16 14:52:58 0 d-----w- c:\program files\MSECache
2010-08-15 23:44:29 0 d-----w- c:\program files\oZone3D
2010-08-15 22:13:33 0 d-----w- d:\docume~1\caseyk~1\applic~1\URSE Games
2010-08-15 21:22:06 0 d-----w- d:\docume~1\alluse~1\applic~1\Trymedia
2010-08-15 21:20:35 0 d-----w- d:\windows\system32\weber
2010-08-15 16:02:14 817664 ----a-w- d:\windows\system32\Help64.exe
2010-08-12 18:05:29 0 d-----w- d:\docume~1\caseyk~1\applic~1\runic games
2010-08-12 17:48:53 0 d-----w- c:\program files\Alcohol Soft
2010-08-12 17:31:16 721904 ----a-w- d:\windows\system32\drivers\sptd.sys
2010-08-10 20:25:58 0 d-----w- d:\docume~1\caseyk~1\applic~1\Jumb-O-Fun
Games
2010-08-10 20:19:39 4096 ----a-w- d:\windows\d3dx.dat
2010-08-10 18:30:06 0 d-----w- c:\program files\common files\Blizzard
Entertainment
2010-08-10 15:41:08 0 d-----w- d:\windows\Uninstall
2010-08-10 15:40:52 0 d-----w- c:\program files\3D Realms
2010-08-05 19:33:06 0 d-----w- c:\program files\GamersFirst
2010-08-05 19:21:55 0 d-----w- d:\docume~1\caseyk~1\applic~1\JAM Software
2010-08-05 19:21:46 0 d-----w- c:\program files\JAM Software
2010-08-04 03:42:33 0 d-----w- d:\docume~1\caseyk~1\applic~1\AnvSoft
2010-08-04 03:42:19 0 d-----w- c:\program files\AnvSoft
==================== Find3M ====================
2010-08-23 03:14:02 156672 ----a-w- d:\windows\system32\rmc_fixasf.exe
2010-08-23 03:13:57 237568 ----a-w- d:\windows\system32\rmc_rtspdl.dll
2010-07-17 09:00:04 423656 ----a-w- d:\windows\system32\deployJava1.dll
2010-07-16 04:38:54 392704 ----a-w- d:\windows\system32\ICH.exe
2010-07-15 16:01:12 42612 ----a-w- d:\windows\fonts\Horst Roman Gothic.ttf
2010-07-15 14:10:20 17896 ----a-w- d:\windows\fonts\paola.ttf
2010-06-30 12:31:35 149504 ----a-w- d:\windows\system32\schannel.dll
2010-06-25 13:14:52 151552 ----a-w- d:\windows\system32\nvRegDev.dll
2010-06-24 12:22:03 916480 ----a-w- d:\windows\system32\wininet.dll
2010-06-23 13:44:04 1851904 ----a-w- d:\windows\system32\win32k.sys
2010-06-21 02:08:43 21640 ----a-w- d:\windows\system32\emptyregdb.dat
2010-06-17 14:03:00 80384 ----a-w- d:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- d:\windows\system32\msxml3.dll
2010-06-02 08:55:30 74072 ----a-w- d:\windows\system32\XAPOFX1_5.dll
2010-06-02 08:55:30 527192 ----a-w- d:\windows\system32\XAudio2_7.dll
2010-06-02 08:55:30 239960 ----a-w- d:\windows\system32\xactengine3_7.dll
============= FINISH: 15:51:52.51 ===============
I have already attempted to delete the files up.exe, Skybound.Gecko.dll, safesurf.exe, surfguard.exe, and the folder "f" from teh windows/system32/drivers folder (i found a report on google saying some sites created these files and directories). Sometimes they stay deleted until i reboot , and i have already disabled the files from loading via msconfig. They seem reappear after reboots, but seem to re download themselves or recopy themselves from another directory most of the time.
DDS Log
DDS (Ver_10-03-17.01) - NTFSx86
Run by Owner at 15:51:09.68 on Mon 08/30/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.626 [GMT -4:00]
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated)
{E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
============== Running Processes ===============
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
D:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
D:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\SetPointP\SetPoint.exe
svchost.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\ctfmon.exe
C:\FRAPS\FRAPS.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
D:\Documents and Settings\Casey Kline\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Stardock\Impulse\Now\ImpulseNow.exe
C:\Program Files\BW Monitor\BWMonitor.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
D:\WINDOWS\system32\system\svchost.exe
D:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\WINDOWS\system32\drivers\safesurf.exe
D:\WINDOWS\system32\drivers\surfguard.exe
C:\DOWNLOADS\PROCESSEXPLORER\PROCEXP.EXE
C:\Downloads\dds.scr
D:\WINDOWS\system32\SearchProtocolHost.exe
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program
files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program
files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} -
c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program
files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [AtiTrayTools] "c:\program files\ray adams\ati tray tools\atitray.exe"
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
uRun: [Google Update] "d:\documents and settings\casey kline\local settings\application
data\google\update\GoogleUpdate.exe" /c
uRun: [TpScrex] c:\programdata\tpscrex\TpScrex.exe /somering
uRun: [Fraps] c:\fraps\FRAPS.EXE
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader
9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [jsafesurf] d:\windows\system32\drivers\safesurf.exe
StartupFolder: d:\docume~1\caseyk~1\startm~1\programs\startup\dropbox.lnk - d:\documents
and settings\casey kline\application data\dropbox\bin\Dropbox.exe
StartupFolder: d:\docume~1\caseyk~1\startm~1\programs\startup\impuls~1.lnk - c:\program
files\stardock\impulse\now\ImpulseNow.exe
StartupFolder: d:\docume~1\caseyk~1\startm~1\programs\startup\shortc~1.lnk - c:\program
files\bw monitor\BWMonitor.exe
StartupFolder: d:\docume~1\caseyk~1\startm~1\programs\startup\shortc~2.lnk -
d:\windows\system32\taskmgr.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program
files\windows desktop search\WindowsSearch.exe
IE: &NeoTrace It! - c:\progra~1\neotra~1\NTXcontext.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} -
c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -
hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?
1277092124018
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program
files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
d:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} -
c:\program files\windows desktop search\MSNLNamespaceMgr.dll
IFEO: taskmgr.exe - "c:\downloads\processexplorer\PROCEXP.EXE"
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - d:\docume~1\caseyk~1\applic~1\mozilla\firefox\profiles\vfhp6q8h.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\mozilla
firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - component: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\piclens@cooliris.com\components\c
oolirisstub.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf379
16a7}\plugins\np_gp.dll
FF - plugin: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\csweblauncher@cyberstep.com\plugi
ns\npCsWebLauncher.dll
FF - plugin: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\kos@dontblynk.com\platform\winnt_
x86-msvc\plugins\NPSting.dll
FF - plugin: d:\documents and settings\casey kline\application
data\mozilla\firefox\profiles\vfhp6q8h.default\extensions\piclens@cooliris.com\plugins\npco
olirisplugin.dll
FF - plugin: d:\documents and settings\casey kline\local settings\application
data\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant:
{20a82645-c095-46ed-80e3-08825760534b} - d:\windows\microsoft.net\framework\v3.5\windows
presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla
firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla
firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js
- pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows",
false);
c:\program files\mozilla firefox\greprefs\all.js -
pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js -
pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai",
true);
c:\program files\mozilla firefox\greprefs\all.js -
pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm",
false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type",
5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size",
4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug",
false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight",
2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize",
1);
c:\program files\mozilla firefox\greprefs\all.js -
pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js -
pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight",
25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight",
5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref",
true);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js -
pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js -
pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js -
pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name",
"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description",
"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add",
"addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled",
false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js -
pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 atitray;atitray;c:\program files\ray adams\ati tray tools\atitray.sys [2009-11-25 19232]
R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [2009-9-11 108792]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-9-11 735960]
R2 LBeepKE;Logitech Beep Suppression Driver;d:\windows\system32\drivers\LBeepKE.sys
[2010-6-20 10448]
R2 Win_Updater;Win32 Updater;d:\windows\system32\system\svchost.exe [2010-8-21 1405440]
R3 WDC_SAM;WD SCSI Pass Thru driver;d:\windows\system32\drivers\wdcsam.sys [2010-6-21
11520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN
v4.0.30319_X86;d:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18
130384]
S3 cpuz130;cpuz130;\??\d:\docume~1\caseyk~1\locals~1\temp\cpuz130\cpuz_x32.sys -->
d:\docume~1\caseyk~1\locals~1\temp\cpuz130\cpuz_x32.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache
4.0.0.0;d:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18
753504]
=============== Created Last 30 ================
2010-08-30 17:56:22 0 d-----w- d:\docume~1\alluse~1\applic~1\Spybot -
Search & Destroy
2010-08-30 17:56:22 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-30 17:42:03 19456 ----a-w- d:\windows\system32\drivers\surfguard.exe
2010-08-30 17:39:32 0 d-----w- d:\windows\system32\drivers\f
2010-08-30 17:39:31 16896 ----a-w- d:\windows\system32\drivers\up.exe
2010-08-30 17:39:16 211968 ----a-w- d:\windows\system32\drivers\safesurf.exe
2010-08-30 13:31:09 158720 ----a-w-
d:\windows\system32\drivers\skybound.gecko.dll
2010-08-28 04:54:13 0 d-----w- c:\program files\Microsoft Games for
Windows - LIVE
2010-08-28 03:05:44 0 d-----w- d:\windows\system32\xlive
2010-08-28 03:01:33 107888 ----a-w- d:\windows\system32\CmdLineExt.dll
2010-08-27 23:11:45 0 d-----w- d:\windows\usgwmt
2010-08-27 22:01:01 0 d-sh--w- d:\docume~1\alluse~1\applic~1\SecuROM
2010-08-27 21:27:35 0 d-----w- c:\program files\2K Games
2010-08-27 20:55:52 0 d-----w- d:\windows\pss
2010-08-27 19:41:59 0 d-----w- d:\windows\system32\appmgmt
2010-08-27 00:52:08 0 d-----w- d:\docume~1\alluse~1\applic~1\Caelum
2010-08-27 00:50:56 4286 ----a-w- d:\windows\system32\ico.ico
2010-08-27 00:50:52 0 d-----w- d:\windows\system32\system
2010-08-27 00:50:46 0 d-----w- d:\windows\system32\webem
2010-08-24 18:35:46 0 d-----w- c:\program files\common files\Futuremark
Shared
2010-08-24 03:21:33 0 d-----w-
d:\docume~1\caseyk~1\applic~1\ArtificialStudios
2010-08-24 03:17:12 0 d-----w- c:\program files\Artificial Studios
2010-08-23 03:01:42 0 d-----w- d:\documents and settings\casey kline\oni
2010-08-20 23:40:09 0 d-----w- c:\program files\Apophysis 2.0
2010-08-20 17:34:43 0 d-----w- c:\program files\Alien Skin
2010-08-19 21:23:15 0 d-----w- d:\docume~1\alluse~1\applic~1\NOMBZ Save
Data
2010-08-19 20:37:00 0 d-----w- c:\program files\ReflexiveArcade
2010-08-19 18:55:03 28 ----a-w- d:\windows\pdf995.ini
2010-08-19 18:43:48 59 ----a-w- d:\windows\wpd99.drv
2010-08-19 18:43:48 51716 ----a-w- d:\windows\system32\pdf995mon.dll
2010-08-19 18:43:48 249856 ----a-w- d:\windows\system32\pdfmona.dll
2010-08-19 18:43:48 0 d-----w- d:\docume~1\alluse~1\applic~1\pdf995
2010-08-19 18:43:45 0 d-----w- c:\program files\pdf995
2010-08-16 14:52:58 0 d-----w- c:\program files\MSECache
2010-08-15 23:44:29 0 d-----w- c:\program files\oZone3D
2010-08-15 22:13:33 0 d-----w- d:\docume~1\caseyk~1\applic~1\URSE Games
2010-08-15 21:22:06 0 d-----w- d:\docume~1\alluse~1\applic~1\Trymedia
2010-08-15 21:20:35 0 d-----w- d:\windows\system32\weber
2010-08-15 16:02:14 817664 ----a-w- d:\windows\system32\Help64.exe
2010-08-12 18:05:29 0 d-----w- d:\docume~1\caseyk~1\applic~1\runic games
2010-08-12 17:48:53 0 d-----w- c:\program files\Alcohol Soft
2010-08-12 17:31:16 721904 ----a-w- d:\windows\system32\drivers\sptd.sys
2010-08-10 20:25:58 0 d-----w- d:\docume~1\caseyk~1\applic~1\Jumb-O-Fun
Games
2010-08-10 20:19:39 4096 ----a-w- d:\windows\d3dx.dat
2010-08-10 18:30:06 0 d-----w- c:\program files\common files\Blizzard
Entertainment
2010-08-10 15:41:08 0 d-----w- d:\windows\Uninstall
2010-08-10 15:40:52 0 d-----w- c:\program files\3D Realms
2010-08-05 19:33:06 0 d-----w- c:\program files\GamersFirst
2010-08-05 19:21:55 0 d-----w- d:\docume~1\caseyk~1\applic~1\JAM Software
2010-08-05 19:21:46 0 d-----w- c:\program files\JAM Software
2010-08-04 03:42:33 0 d-----w- d:\docume~1\caseyk~1\applic~1\AnvSoft
2010-08-04 03:42:19 0 d-----w- c:\program files\AnvSoft
==================== Find3M ====================
2010-08-23 03:14:02 156672 ----a-w- d:\windows\system32\rmc_fixasf.exe
2010-08-23 03:13:57 237568 ----a-w- d:\windows\system32\rmc_rtspdl.dll
2010-07-17 09:00:04 423656 ----a-w- d:\windows\system32\deployJava1.dll
2010-07-16 04:38:54 392704 ----a-w- d:\windows\system32\ICH.exe
2010-07-15 16:01:12 42612 ----a-w- d:\windows\fonts\Horst Roman Gothic.ttf
2010-07-15 14:10:20 17896 ----a-w- d:\windows\fonts\paola.ttf
2010-06-30 12:31:35 149504 ----a-w- d:\windows\system32\schannel.dll
2010-06-25 13:14:52 151552 ----a-w- d:\windows\system32\nvRegDev.dll
2010-06-24 12:22:03 916480 ----a-w- d:\windows\system32\wininet.dll
2010-06-23 13:44:04 1851904 ----a-w- d:\windows\system32\win32k.sys
2010-06-21 02:08:43 21640 ----a-w- d:\windows\system32\emptyregdb.dat
2010-06-17 14:03:00 80384 ----a-w- d:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- d:\windows\system32\msxml3.dll
2010-06-02 08:55:30 74072 ----a-w- d:\windows\system32\XAPOFX1_5.dll
2010-06-02 08:55:30 527192 ----a-w- d:\windows\system32\XAudio2_7.dll
2010-06-02 08:55:30 239960 ----a-w- d:\windows\system32\xactengine3_7.dll
============= FINISH: 15:51:52.51 ===============