hankorstanje
2010-09-03, 07:43
cannot install anny virus or mallware program
cannot restore system cause is disabled and not can set it on
cannot vissit many pages on internet that related to virus or malware
cannot go to save mode (get blue screen)
hope some one can help
dds log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Admin at 11:19:57.78 on Fri 09/03/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.874.66.1033.18.991.557 [GMT 7:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k eapsvcs
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\System32\vssvc.exe
svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Admin\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.varietypc.net/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mWinlogon: SfcDisable=-99 (0xffffff9d)
mWinlogon: Taskman=c:\recycler\s-1-5-21-5538345198-8284663007-870835812-9357\syscr.exe
uWinlogon: Shell=c:\recycler\s-1-5-21-5538345198-8284663007-870835812-9357\syscr.exe,explorer.exe,c:\documents and settings\admin\application data\ltzqai.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMBgMonitor.exe"
mRun: [ctfmon.exe] ctfmon.exe
mRun: [<NO NAME>]
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [conime.exe] conime.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [patches] 1
mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe"
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\admin\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
mPolicies-explorer: NoRun = 1 (0x1)
dPolicies-explorer: NoFolderOptions = 1 (0x1)
dPolicies-explorer: NoRun = 1 (0x1)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: ส่&งออกไปยัง Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1283100731125
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
IFEO: a2guard.exe - ntsd -d
IFEO: a2service.exe - ntsd -d
IFEO: a2start.exe - ntsd -d
IFEO: Ad-Aware.exe - ntsd -d
IFEO: Ad-AwareAdmin.exe - ntsd -d
Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 126.85.73.118 msnfix.changelog.fr
Hosts: 126.85.73.118 www.incodesolutions.com
Hosts: 126.85.73.118 virusinfo.prevx.com
Hosts: 126.85.73.118 download.bleepingcomputer.com
Hosts: 126.85.73.118 www.dazhizhu.cn
Note: multiple HOSTS entries found. Please refer to Attach.txt
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\vx4j6fj3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.varietypc.net
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBook.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBookDB.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpNeoLogger.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSaturn.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartSelect.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSWPOperation.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPLogging.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTC.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTL.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXREStub.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/09/21 00:53:30];c:\program files\cyberlink\powerdvd9\000.fcl [2009-8-28 87536]
R2 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
R2 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [2003-4-8 820133]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-8 135664]
S3 vmmouse;VMware Pointing Device;c:\windows\system32\drivers\vmmouse.sys [2009-9-19 11696]
=============== Created Last 30 ================
2010-09-03 04:19:42 0 d--h--w- c:\windows\PIF
2010-08-31 02:51:57 0 d-----w- c:\windows\system32\NtmsData
2010-08-30 10:45:37 135680 ----a-w- c:\windows\system32\cpe17_taskmgr.exe
2010-08-30 10:27:16 0 d-----w- c:\windows\system32\appmgmt
2010-08-30 10:21:36 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-30 08:31:29 0 d-----w- c:\windows\system32\msmq
2010-08-30 08:31:26 0 d-----w- C:\Inetpub
2010-08-30 07:06:58 0 d-----w- c:\docume~1\admin\applic~1\Windows Search
2010-08-29 20:14:22 0 d-----w- c:\windows\system32\winrm
2010-08-29 20:14:16 0 dc-h--w- c:\windows\$968930Uinstall_KB968930$
2010-08-29 20:02:16 0 d-----w- c:\program files\Windows Desktop Search
2010-08-29 20:01:24 98304 ------w- c:\windows\system32\dllcache\nlhtml.dll
2010-08-29 20:01:24 29696 ------w- c:\windows\system32\dllcache\mimefilt.dll
2010-08-29 20:01:24 192000 ------w- c:\windows\system32\dllcache\offfilt.dll
2010-08-29 19:59:21 0 d-----w- c:\windows\system32\URTTEMP
2010-08-29 19:56:21 16896 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-08-29 19:47:01 0 d-----w- c:\windows\SiS
2010-08-29 19:46:53 0 d-----w- c:\program files\SiS7012
2010-08-29 19:46:40 0 d-----w- c:\windows\system32\ReinstallBackups
2010-08-29 18:56:33 1089593 ------w- c:\windows\system32\dllcache\ntprint.cat
2010-08-29 18:24:53 0 d-----w- c:\windows\ie8updates
2010-08-29 18:23:06 0 d-----w- c:\program files\MSXML 4.0
2010-08-29 18:06:21 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-08-29 18:06:21 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-08-29 18:06:20 599040 ------w- c:\windows\system32\dllcache\msfeeds.dll
2010-08-29 18:06:14 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-08-29 18:06:10 1986560 ------w- c:\windows\system32\dllcache\iertutil.dll
2010-08-29 18:06:09 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-29 18:03:56 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2010-08-29 18:03:56 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2010-08-29 17:56:34 0 d-----w- c:\windows\system32\XPSViewer
2010-08-29 17:54:55 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-08-29 17:54:55 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-08-29 17:54:55 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-08-29 17:54:55 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-08-29 17:54:55 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-08-29 17:54:55 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-08-29 17:54:55 117760 ------w- c:\windows\system32\prntvpt.dll
2010-08-29 17:54:52 354304 ------w- c:\windows\system32\dllcache\srv.sys
2010-08-29 17:53:00 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-08-29 17:52:44 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-08-29 17:51:22 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-08-29 17:48:35 2189952 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-08-29 17:48:35 2146304 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-08-29 17:48:34 2024448 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-08-29 17:48:32 2066816 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-08-29 17:29:08 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-08-29 17:15:16 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-08-29 17:11:54 80896 ------w- c:\windows\system32\dllcache\tlntsess.exe
2010-08-29 17:11:53 76288 ------w- c:\windows\system32\dllcache\telnet.exe
2010-08-29 17:09:56 128512 ------w- c:\windows\system32\dllcache\dhtmled.ocx
2010-08-29 17:03:48 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2010-08-29 17:03:47 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2010-08-29 17:03:47 35328 ------w- c:\windows\system32\dllcache\sc.exe
2010-08-29 17:03:46 110592 ------w- c:\windows\system32\dllcache\services.exe
2010-08-29 17:03:45 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2010-08-29 17:03:43 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-08-29 17:03:43 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2010-08-29 17:03:42 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2010-08-29 17:03:42 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2010-08-29 16:59:30 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2010-08-29 16:58:07 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-08-29 16:58:06 1206508 ------w- c:\windows\system32\dllcache\sysmain.sdb
2010-08-29 16:58:05 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2010-08-29 16:57:57 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2010-08-29 16:57:16 253952 ------w- c:\windows\system32\dllcache\es.dll
2010-08-29 16:55:33 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-08-29 16:55:33 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2010-08-29 16:55:25 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2010-08-29 16:54:25 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-08-29 16:54:25 215920 ----a-w- c:\windows\system32\muweb.dll
2010-08-29 16:54:25 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2010-08-29 16:52:41 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2010-08-29 15:51:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-08-29 15:25:00 0 d-----w- c:\program files\Yahoo!
2010-08-18 09:04:20 0 d-----w- c:\docume~1\alluse~1\applic~1\WEBREG
2010-08-18 08:49:59 0 d-----w- c:\windows\Cache
2010-08-18 08:49:57 0 d-----w- c:\program files\Coupons
2010-08-18 08:49:47 0 d-----w- c:\program files\HP Photo Creations
2010-08-18 08:49:47 0 d-----w- c:\docume~1\alluse~1\applic~1\HP Photo Creations
2010-08-18 08:49:30 0 d-----w- c:\docume~1\admin\applic~1\HpUpdate
2010-08-18 08:44:49 0 d-----w- c:\program files\common files\HP
2010-08-18 08:43:35 0 d-----w- c:\program files\common files\Hewlett-Packard
2010-08-18 08:42:05 0 d-----w- c:\program files\HP
2010-08-18 08:40:10 450 ------w- c:\windows\hpomdl45.dat
2010-08-18 08:40:10 170555 ----a-w- c:\windows\hpoins45.dat
2010-08-18 08:37:42 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-08-18 08:37:39 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2010-08-18 08:36:38 123904 ----a-w- c:\windows\system32\hpf3l70v.dll
2010-08-18 08:36:37 452408 ----a-r- c:\windows\system32\hpzids01.dll
2010-08-18 08:36:27 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2010-08-18 08:36:23 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-08-18 08:35:46 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-08-18 08:35:45 372736 ----a-r- c:\windows\system32\hppldcoi.dll
2010-08-18 08:35:45 315392 ----a-r- c:\windows\system32\hposc_d02a.dll
2010-08-18 08:35:44 589824 ----a-r- c:\windows\system32\hpost_d02b.dll
2010-08-18 08:35:42 712704 ----a-r- c:\windows\system32\hposwia_d02b.dll
2010-08-18 08:35:41 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-08-16 12:13:57 0 d-----w- c:\program files\FreeTime
2010-08-10 13:44:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
==================== Find3M ====================
2010-08-07 03:11:30 98304 ----a-w- c:\windows\DUMP1dd8.tmp
2010-08-05 20:06:42 98304 ----a-w- c:\windows\DUMP249f.tmp
2010-08-05 10:50:13 98304 ----a-w- c:\windows\DUMP2441.tmp
2010-08-04 10:03:31 98304 ----a-w- c:\windows\DUMP1d4c.tmp
2010-08-04 10:00:18 98304 ----a-w- c:\windows\DUMP1d7a.tmp
2010-08-04 09:59:00 98304 ----a-w- c:\windows\DUMP1e26.tmp
2010-08-04 09:31:09 98304 ----a-w- c:\windows\DUMP2376.tmp
2010-08-04 09:15:05 98304 ----a-w- c:\windows\DUMP2412.tmp
2010-08-04 09:13:56 98304 ----a-w- c:\windows\DUMP2403.tmp
2010-08-04 09:12:34 98304 ----a-w- c:\windows\DUMP24ae.tmp
2010-08-04 09:09:27 98304 ----a-w- c:\windows\DUMP25c7.tmp
2010-08-04 09:08:04 98304 ----a-w- c:\windows\DUMP2402.tmp
2010-07-27 06:30:35 8462336 ------w- c:\windows\system32\dllcache\shell32.dll
2010-07-08 02:20:18 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-07-08 02:20:17 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-30 12:31:35 149504 ------w- c:\windows\system32\dllcache\schannel.dll
2010-06-29 14:02:16 98304 -c--a-w- c:\windows\DUMP1da9.tmp
2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:22:03 916480 ------w- c:\windows\system32\dllcache\wininet.dll
2010-06-24 12:22:02 1210368 ------w- c:\windows\system32\dllcache\urlmon.dll
2010-06-24 12:22:01 611840 ------w- c:\windows\system32\dllcache\mstime.dll
2010-06-24 12:22:01 5951488 ------w- c:\windows\system32\dllcache\mshtml.dll
2010-06-24 12:22:01 206848 ------w- c:\windows\system32\dllcache\occache.dll
2010-06-24 12:21:59 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll
2010-06-24 12:21:58 184320 ------w- c:\windows\system32\dllcache\iepeers.dll
2010-06-24 12:21:55 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll
2010-06-24 10:51:58 11077120 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-23 13:44:04 1851904 ------w- c:\windows\system32\dllcache\win32k.sys
2010-06-23 12:08:09 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-14 07:41:45 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2010-06-13 04:01:07 304520 -c--a-w- c:\program files\hjsplit.zip
2010-06-13 03:40:28 6814720 ----a-w- c:\program files\GOMPLAYERENSETUP.EXE
2009-09-18 16:06:48 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009091820090919\index.dat
============= FINISH: 11:20:31.71 ===============
cannot restore system cause is disabled and not can set it on
cannot vissit many pages on internet that related to virus or malware
cannot go to save mode (get blue screen)
hope some one can help
dds log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Admin at 11:19:57.78 on Fri 09/03/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.874.66.1033.18.991.557 [GMT 7:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k eapsvcs
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\System32\vssvc.exe
svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Admin\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.varietypc.net/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mWinlogon: SfcDisable=-99 (0xffffff9d)
mWinlogon: Taskman=c:\recycler\s-1-5-21-5538345198-8284663007-870835812-9357\syscr.exe
uWinlogon: Shell=c:\recycler\s-1-5-21-5538345198-8284663007-870835812-9357\syscr.exe,explorer.exe,c:\documents and settings\admin\application data\ltzqai.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMBgMonitor.exe"
mRun: [ctfmon.exe] ctfmon.exe
mRun: [<NO NAME>]
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [conime.exe] conime.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [patches] 1
mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe"
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\admin\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
mPolicies-explorer: NoRun = 1 (0x1)
dPolicies-explorer: NoFolderOptions = 1 (0x1)
dPolicies-explorer: NoRun = 1 (0x1)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: ส่&งออกไปยัง Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1283100731125
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
IFEO: a2guard.exe - ntsd -d
IFEO: a2service.exe - ntsd -d
IFEO: a2start.exe - ntsd -d
IFEO: Ad-Aware.exe - ntsd -d
IFEO: Ad-AwareAdmin.exe - ntsd -d
Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 126.85.73.118 msnfix.changelog.fr
Hosts: 126.85.73.118 www.incodesolutions.com
Hosts: 126.85.73.118 virusinfo.prevx.com
Hosts: 126.85.73.118 download.bleepingcomputer.com
Hosts: 126.85.73.118 www.dazhizhu.cn
Note: multiple HOSTS entries found. Please refer to Attach.txt
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\vx4j6fj3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.varietypc.net
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBook.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBookDB.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpNeoLogger.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSaturn.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartSelect.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSWPOperation.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPLogging.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTC.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTL.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXREStub.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/09/21 00:53:30];c:\program files\cyberlink\powerdvd9\000.fcl [2009-8-28 87536]
R2 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
R2 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [2003-4-8 820133]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-8 135664]
S3 vmmouse;VMware Pointing Device;c:\windows\system32\drivers\vmmouse.sys [2009-9-19 11696]
=============== Created Last 30 ================
2010-09-03 04:19:42 0 d--h--w- c:\windows\PIF
2010-08-31 02:51:57 0 d-----w- c:\windows\system32\NtmsData
2010-08-30 10:45:37 135680 ----a-w- c:\windows\system32\cpe17_taskmgr.exe
2010-08-30 10:27:16 0 d-----w- c:\windows\system32\appmgmt
2010-08-30 10:21:36 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-30 08:31:29 0 d-----w- c:\windows\system32\msmq
2010-08-30 08:31:26 0 d-----w- C:\Inetpub
2010-08-30 07:06:58 0 d-----w- c:\docume~1\admin\applic~1\Windows Search
2010-08-29 20:14:22 0 d-----w- c:\windows\system32\winrm
2010-08-29 20:14:16 0 dc-h--w- c:\windows\$968930Uinstall_KB968930$
2010-08-29 20:02:16 0 d-----w- c:\program files\Windows Desktop Search
2010-08-29 20:01:24 98304 ------w- c:\windows\system32\dllcache\nlhtml.dll
2010-08-29 20:01:24 29696 ------w- c:\windows\system32\dllcache\mimefilt.dll
2010-08-29 20:01:24 192000 ------w- c:\windows\system32\dllcache\offfilt.dll
2010-08-29 19:59:21 0 d-----w- c:\windows\system32\URTTEMP
2010-08-29 19:56:21 16896 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-08-29 19:47:01 0 d-----w- c:\windows\SiS
2010-08-29 19:46:53 0 d-----w- c:\program files\SiS7012
2010-08-29 19:46:40 0 d-----w- c:\windows\system32\ReinstallBackups
2010-08-29 18:56:33 1089593 ------w- c:\windows\system32\dllcache\ntprint.cat
2010-08-29 18:24:53 0 d-----w- c:\windows\ie8updates
2010-08-29 18:23:06 0 d-----w- c:\program files\MSXML 4.0
2010-08-29 18:06:21 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-08-29 18:06:21 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-08-29 18:06:20 599040 ------w- c:\windows\system32\dllcache\msfeeds.dll
2010-08-29 18:06:14 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-08-29 18:06:10 1986560 ------w- c:\windows\system32\dllcache\iertutil.dll
2010-08-29 18:06:09 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-29 18:03:56 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2010-08-29 18:03:56 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2010-08-29 17:56:34 0 d-----w- c:\windows\system32\XPSViewer
2010-08-29 17:54:55 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-08-29 17:54:55 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-08-29 17:54:55 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-08-29 17:54:55 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-08-29 17:54:55 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-08-29 17:54:55 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-08-29 17:54:55 117760 ------w- c:\windows\system32\prntvpt.dll
2010-08-29 17:54:52 354304 ------w- c:\windows\system32\dllcache\srv.sys
2010-08-29 17:53:00 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-08-29 17:52:44 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-08-29 17:51:22 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-08-29 17:48:35 2189952 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-08-29 17:48:35 2146304 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-08-29 17:48:34 2024448 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-08-29 17:48:32 2066816 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-08-29 17:29:08 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-08-29 17:15:16 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-08-29 17:11:54 80896 ------w- c:\windows\system32\dllcache\tlntsess.exe
2010-08-29 17:11:53 76288 ------w- c:\windows\system32\dllcache\telnet.exe
2010-08-29 17:09:56 128512 ------w- c:\windows\system32\dllcache\dhtmled.ocx
2010-08-29 17:03:48 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2010-08-29 17:03:47 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2010-08-29 17:03:47 35328 ------w- c:\windows\system32\dllcache\sc.exe
2010-08-29 17:03:46 110592 ------w- c:\windows\system32\dllcache\services.exe
2010-08-29 17:03:45 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2010-08-29 17:03:43 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-08-29 17:03:43 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2010-08-29 17:03:42 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2010-08-29 17:03:42 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2010-08-29 16:59:30 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2010-08-29 16:58:07 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-08-29 16:58:06 1206508 ------w- c:\windows\system32\dllcache\sysmain.sdb
2010-08-29 16:58:05 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2010-08-29 16:57:57 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2010-08-29 16:57:16 253952 ------w- c:\windows\system32\dllcache\es.dll
2010-08-29 16:55:33 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-08-29 16:55:33 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2010-08-29 16:55:25 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2010-08-29 16:54:25 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-08-29 16:54:25 215920 ----a-w- c:\windows\system32\muweb.dll
2010-08-29 16:54:25 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2010-08-29 16:52:41 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2010-08-29 15:51:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-08-29 15:25:00 0 d-----w- c:\program files\Yahoo!
2010-08-18 09:04:20 0 d-----w- c:\docume~1\alluse~1\applic~1\WEBREG
2010-08-18 08:49:59 0 d-----w- c:\windows\Cache
2010-08-18 08:49:57 0 d-----w- c:\program files\Coupons
2010-08-18 08:49:47 0 d-----w- c:\program files\HP Photo Creations
2010-08-18 08:49:47 0 d-----w- c:\docume~1\alluse~1\applic~1\HP Photo Creations
2010-08-18 08:49:30 0 d-----w- c:\docume~1\admin\applic~1\HpUpdate
2010-08-18 08:44:49 0 d-----w- c:\program files\common files\HP
2010-08-18 08:43:35 0 d-----w- c:\program files\common files\Hewlett-Packard
2010-08-18 08:42:05 0 d-----w- c:\program files\HP
2010-08-18 08:40:10 450 ------w- c:\windows\hpomdl45.dat
2010-08-18 08:40:10 170555 ----a-w- c:\windows\hpoins45.dat
2010-08-18 08:37:42 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-08-18 08:37:39 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2010-08-18 08:36:38 123904 ----a-w- c:\windows\system32\hpf3l70v.dll
2010-08-18 08:36:37 452408 ----a-r- c:\windows\system32\hpzids01.dll
2010-08-18 08:36:27 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2010-08-18 08:36:23 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-08-18 08:35:46 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-08-18 08:35:45 372736 ----a-r- c:\windows\system32\hppldcoi.dll
2010-08-18 08:35:45 315392 ----a-r- c:\windows\system32\hposc_d02a.dll
2010-08-18 08:35:44 589824 ----a-r- c:\windows\system32\hpost_d02b.dll
2010-08-18 08:35:42 712704 ----a-r- c:\windows\system32\hposwia_d02b.dll
2010-08-18 08:35:41 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-08-16 12:13:57 0 d-----w- c:\program files\FreeTime
2010-08-10 13:44:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
==================== Find3M ====================
2010-08-07 03:11:30 98304 ----a-w- c:\windows\DUMP1dd8.tmp
2010-08-05 20:06:42 98304 ----a-w- c:\windows\DUMP249f.tmp
2010-08-05 10:50:13 98304 ----a-w- c:\windows\DUMP2441.tmp
2010-08-04 10:03:31 98304 ----a-w- c:\windows\DUMP1d4c.tmp
2010-08-04 10:00:18 98304 ----a-w- c:\windows\DUMP1d7a.tmp
2010-08-04 09:59:00 98304 ----a-w- c:\windows\DUMP1e26.tmp
2010-08-04 09:31:09 98304 ----a-w- c:\windows\DUMP2376.tmp
2010-08-04 09:15:05 98304 ----a-w- c:\windows\DUMP2412.tmp
2010-08-04 09:13:56 98304 ----a-w- c:\windows\DUMP2403.tmp
2010-08-04 09:12:34 98304 ----a-w- c:\windows\DUMP24ae.tmp
2010-08-04 09:09:27 98304 ----a-w- c:\windows\DUMP25c7.tmp
2010-08-04 09:08:04 98304 ----a-w- c:\windows\DUMP2402.tmp
2010-07-27 06:30:35 8462336 ------w- c:\windows\system32\dllcache\shell32.dll
2010-07-08 02:20:18 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-07-08 02:20:17 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-30 12:31:35 149504 ------w- c:\windows\system32\dllcache\schannel.dll
2010-06-29 14:02:16 98304 -c--a-w- c:\windows\DUMP1da9.tmp
2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:22:03 916480 ------w- c:\windows\system32\dllcache\wininet.dll
2010-06-24 12:22:02 1210368 ------w- c:\windows\system32\dllcache\urlmon.dll
2010-06-24 12:22:01 611840 ------w- c:\windows\system32\dllcache\mstime.dll
2010-06-24 12:22:01 5951488 ------w- c:\windows\system32\dllcache\mshtml.dll
2010-06-24 12:22:01 206848 ------w- c:\windows\system32\dllcache\occache.dll
2010-06-24 12:21:59 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll
2010-06-24 12:21:58 184320 ------w- c:\windows\system32\dllcache\iepeers.dll
2010-06-24 12:21:55 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll
2010-06-24 10:51:58 11077120 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-23 13:44:04 1851904 ------w- c:\windows\system32\dllcache\win32k.sys
2010-06-23 12:08:09 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-14 07:41:45 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2010-06-13 04:01:07 304520 -c--a-w- c:\program files\hjsplit.zip
2010-06-13 03:40:28 6814720 ----a-w- c:\program files\GOMPLAYERENSETUP.EXE
2009-09-18 16:06:48 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009091820090919\index.dat
============= FINISH: 11:20:31.71 ===============