DaveLeland
2011-01-17, 05:37
I believe there is a variation of the W32.Troresba worm on my PC and probably on the others in my home network. I am a newbie
to malware removal, so I have already done most of the things you asked us not to do. That said, System Restore is off, there
are no backups on this machine, my XP directory and the rest of my machine is as clean as I can make it.
Spybot, and several other anti-malware programs fail to find w32.? Other than a slow boot which fails to finish, my chief clue
are the folders Xerox, and sub-folder nwwia. I delete them and they are recreated. I replaced them with system file checker-
same results. I may have stopped the worm temporarily by using the administrator account in safe mode, deleting them, and
re-creating them myself, changing to very limited rights, and making them read-only. I used a lower case X for Xerox, so I
could tell if anything changed. So far, they have remained the same. I noticed that MSI ran briefly on startup, but it is not
shown in the DDS as a running process. I believe it failed to deliver its payload for the above reason. Note: the event log
shows msiexec.exe was restored after it terminated unexpectedly- see top two event log entries in attach.txt. I found MSI
running with the Anti-Spy Info program, and was able to read the text in the executable. The text lead me to believe, that it
was busy acting as user S-1-5-18 for various tasks which seemed inappropriate. There are now three users in the registry with
only Administrator and My account showing in the User manager. There are many duplicate entrys in the registry, which may
account for some of the slow startup.
I ran dds twice- once long after boot(DDS.txt, Attach.txt), and once as fast as I could click on DDS(DDS1.txt, Attach1.txt).
Notable differences are:
DDS1: DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} - file:///E:/DOCUME~1/davel/LOCALS~1/Temp/IXP001.TMP/setup.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
DDS: Not there
DDS1: DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -
DDS: Not there
I believe this is enough to get started--- Not enough time or space to write everything.
Any help would be very much appreciated.
Thanks,
Dave
ZZZZZZZZZZZZZZ begin DDS ZZZZZZZZZZZZZZZZZZ
DDS (Ver_10-12-12.02) - NTFSx86
Run by davel at 16:53:33.31 on Sun 01/16/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2676 [GMT -8:00]
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
============== Running Processes ===============
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
E:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
E:\WINDOWS\system32\spoolsv.exe
svchost.exe
svchost.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
E:\WINDOWS\system32\dllhost.exe
E:\WINDOWS\system32\dllhost.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Microsoft IntelliType Pro\type32.exe
E:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Program Files\Microsoft Security Client\msseces.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\WINDOWS\RTHDCPL.EXE
E:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Windows Live\Toolbar\wltuser.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Documents and Settings\davel\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - e:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - e:\program files\windows live\toolbar\wltcore.dll
TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
TB: {D593DE91-7B41-45C2-830E-E9A99AB142AA} - No File
mRun: [type32] "e:\program files\microsoft intellitype pro\type32.exe"
mRun: [IntelliPoint] "e:\program files\microsoft intellipoint\ipoint.exe"
mRun: [MSC] "e:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [NvCplDaemon] RUNDLL32.EXE e:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE e:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [nwiz] e:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [Adobe ARM] "e:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "e:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "e:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
dRun: [DWQueuedReporting] "e:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-explorer: MaxRecentDocs = 99 (0x63)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: HideShutdownScripts = 0 (0x0)
IE: Append Link Target to Existing PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - e:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - e:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\progra~1\micros~4\office11\REFIEBAR.DLL
Trusted Zone: 977music.com
Trusted Zone: amazon.com\www
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\www.msi
Trusted Zone: divx.com\www
Trusted Zone: ebay.com\signin
Trusted Zone: facebook.com\login
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: ipride.com\www
Trusted Zone: live.com\workspace.office
Trusted Zone: microsoft.com\*.update
Trusted Zone: nwmls.com
Trusted Zone: rapmls.com
Trusted Zone: windowsupdate.com\download
Trusted Zone: yahoo.com\login
Trusted Zone: yahoo.com\www
DPF: PUFLITE - hxxp://davidleland.point2agent.com/Office/ColpaControls/Photo/Control/PUFLITE.CAB
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {12545791-AC9A-44B2-8964-0DA216C4A4E5} - hxxp://www.partserver.de/partserver/viewer/cnsweb3d/cnsweb3d.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} - file:///E:/DOCUME~1/davel/LOCALS~1/Temp/IXP001.TMP/setup.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261081771046
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxps://register.facebook.com/controls/contactx.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1261081761125
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
AppInit_DLLs: e:\progra~1\google\google~4\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;e:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R2 fssfltr;FssFltr;e:\windows\system32\drivers\fssfltr_tdi.sys [2009-3-31 54760]
R3 AV88BASE;Cx2388x Base Driver;e:\windows\system32\drivers\av88base.sys [2007-4-13 423936]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;e:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [2011-1-10 1691480]
S3 brfilt;Brother MFC Filter Driver;e:\windows\system32\drivers\brfilt.sys [2008-12-1 2944]
S3 BrSerWDM;Brother WDM Serial driver;e:\windows\system32\drivers\BrSerWdm.sys [2003-3-14 61952]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;e:\windows\system32\drivers\brusbmdm.sys [2008-12-1 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;e:\windows\system32\drivers\brusbscn.sys [2008-12-1 10368]
S3 cpuz132;cpuz132; [x]
S3 DlinkUDSMBus;DlinkUDSMBus;e:\windows\system32\drivers\dlinkudsmbus.sys --> e:\windows\system32\drivers\DlinkUDSMBus.sys [?]
S3 fsssvc;Windows Live Family Safety Service;e:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;e:\program files\google\google desktop search\GoogleDesktop.exe [2009-5-4 30192]
S3 RTL8167;Realtek 8167 NT Driver;e:\windows\system32\drivers\Rt86win7.sys [2011-1-10 233472]
S3 WinRM;Windows Remote Management (WS-Management);e:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;e:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 gupdate;Google Update Service (gupdate);"e:\program files\google\update\googleupdate.exe" /svc --> e:\program files\google\update\GoogleUpdate.exe [?]
=============== Created Last 30 ================
2011-01-16 21:21:00 388096 -c--a-r- e:\docume~1\davel\applic~1\microsoft\installer\{0761c9a8-8f3a-4216-b4a7-b7afbf24a24a}\HiJackThis.exe
2011-01-16 21:20:59 -------- dc----w- e:\program files\TrendMicro
2011-01-15 09:26:02 6273872 -c--a-w- e:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{8db8ca81-f66e-4ad1-a343-fecef2901221}\mpengine.dll
2011-01-15 08:56:20 12800 -c--a-w- e:\windows\system32\dllcache\mrinfo.exe
2011-01-15 08:53:54 450560 -c--a-w- e:\windows\system32\dllcache\infosoft.dll
2011-01-14 23:54:15 -------- dc----w- e:\docume~1\alluse~1\applic~1\AntiSpyInfo
2011-01-14 23:54:08 -------- dc----w- e:\program files\Anti-Spy.Info
2011-01-14 23:22:24 116224 -c--a-w- e:\windows\system32\dllcache\xrxwiadr.dll
2011-01-14 23:22:21 23040 -c--a-w- e:\windows\system32\dllcache\xrxwbtmp.dll
2011-01-14 23:22:20 18944 -c--a-w- e:\windows\system32\dllcache\xrxscnui.dll
2011-01-14 23:22:18 27648 -c--a-w- e:\windows\system32\dllcache\xrxftplt.exe
2011-01-14 23:22:15 4608 -c--a-w- e:\windows\system32\dllcache\xrxflnch.exe
2011-01-14 23:22:01 99865 -c--a-w- e:\windows\system32\dllcache\xlog.exe
2011-01-14 23:20:57 19016 -c--a-w- e:\windows\system32\dllcache\w926nd.sys
2011-01-14 23:19:58 50688 -c--a-w- e:\windows\system32\dllcache\umaxscan.dll
2011-01-14 23:18:59 4992 -c--a-w- e:\windows\system32\dllcache\toside.sys
2011-01-14 23:17:58 10240 -c--a-w- e:\windows\system32\dllcache\swpidflt.dll
2011-01-14 23:16:59 7040 -c--a-w- e:\windows\system32\dllcache\snyaitmc.sys
2011-01-14 23:15:59 150144 -c--a-w- e:\windows\system32\dllcache\sis6306v.dll
2011-01-14 23:14:59 495616 -c--a-w- e:\windows\system32\dllcache\sblfx.dll
2011-01-14 23:13:58 19584 -c--a-w- e:\windows\system32\dllcache\rasirda.sys
2011-01-14 23:12:59 92416 -c--a-w- e:\windows\system32\dllcache\phildec.sys
2011-01-14 23:11:59 28032 -c--a-w- e:\windows\system32\dllcache\ovcd.sys
2011-01-14 23:10:59 39264 -c--a-w- e:\windows\system32\dllcache\neo20xx.sys
2011-01-14 23:09:58 35200 -c--a-w- e:\windows\system32\dllcache\msgame.sys
2011-01-14 23:08:59 727786 -c--a-w- e:\windows\system32\dllcache\ltck000c.sys
2011-01-14 23:07:58 23552 -c--a-w- e:\windows\system32\dllcache\irmk7.sys
2011-01-14 23:06:58 38528 -c--a-w- e:\windows\system32\dllcache\ibmvcap.sys
2011-01-14 23:05:59 19456 -c--a-w- e:\windows\system32\dllcache\hr1w.dll
2011-01-14 23:04:32 442240 -c--a-w- e:\windows\system32\dllcache\fpnpbase.sys
2011-01-14 23:04:30 441728 -c--a-w- e:\windows\system32\dllcache\fpcmbase.sys
2011-01-14 23:04:29 444416 -c--a-w- e:\windows\system32\dllcache\fpcibase.sys
2011-01-14 23:04:28 34173 -c--a-w- e:\windows\system32\dllcache\forehe.sys
2011-01-14 23:04:26 71680 -c--a-w- e:\windows\system32\dllcache\fnfilter.dll
2011-01-14 23:04:19 27165 -c--a-w- e:\windows\system32\dllcache\fetnd5.sys
2011-01-14 23:04:15 22090 -c--a-w- e:\windows\system32\dllcache\fem556n5.sys
2011-01-14 23:03:21 24618 -c--a-w- e:\windows\system32\dllcache\fa410nd5.sys
2011-01-14 23:03:19 16074 -c--a-w- e:\windows\system32\dllcache\fa312nd5.sys
2011-01-14 23:03:18 11850 -c--a-w- e:\windows\system32\dllcache\f3ab18xj.sys
2011-01-14 23:03:16 12362 -c--a-w- e:\windows\system32\dllcache\f3ab18xi.sys
2011-01-14 23:03:14 7040 -c--a-w- e:\windows\system32\dllcache\exabyte2.sys
2011-01-14 23:03:13 16998 -c--a-w- e:\windows\system32\dllcache\ex10.sys
2011-01-14 23:03:08 45568 -c--a-w- e:\windows\system32\dllcache\esunib.dll
2011-01-14 23:03:07 45568 -c--a-w- e:\windows\system32\dllcache\esuni.dll
2011-01-14 23:03:04 34816 -c--a-w- e:\windows\system32\dllcache\esuimg.dll
2011-01-14 23:00:59 629952 -c--a-w- e:\windows\system32\dllcache\eqn.sys
2011-01-14 22:59:59 103044 -c--a-w- e:\windows\system32\dllcache\digidxb.sys
2011-01-14 22:58:52 8192 -c--a-w- e:\windows\system32\dllcache\changer.sys
2011-01-14 22:57:53 13824 -c--a-w- e:\windows\system32\dllcache\bulltlp3.sys
2011-01-14 22:56:55 10880 -c--a-w- e:\windows\system32\dllcache\admjoy.sys
2011-01-14 17:17:24 6273872 -c--a-w- e:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-01-13 14:49:31 -------- dc----w- e:\program files\Sdelete
2011-01-13 08:57:42 222080 -c----w- e:\windows\system32\MpSigStub.exe
2011-01-13 08:56:13 -------- dc----w- e:\program files\Microsoft Security Client
2011-01-11 07:36:30 -------- dc----w- e:\windows\system32\RTCOM
2011-01-11 07:25:50 -------- dc----w- e:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2011-01-11 07:25:04 240592 -c--a-w- e:\windows\system32\nvdrsdb0.bin
2011-01-11 07:25:00 240592 -c--a-w- e:\windows\system32\nvdrsdb1.bin
2011-01-11 07:25:00 1 -c--a-w- e:\windows\system32\nvdrssel.bin
2011-01-11 07:24:47 888424 -c--a-w- e:\windows\system32\nvdispco32.dll
2011-01-11 07:24:47 813672 -c--a-w- e:\windows\system32\nvgenco32.dll
2011-01-11 07:24:47 61440 -c--a-w- e:\windows\system32\OpenCL.dll
2011-01-11 07:24:47 4882432 -c--a-w- e:\windows\system32\nvcuda.dll
2011-01-11 07:24:47 2932840 -c--a-w- e:\windows\system32\nvcuvid.dll
2011-01-11 07:24:47 2666600 -c--a-w- e:\windows\system32\nvcuvenc.dll
2011-01-11 07:24:47 2293194 -c--a-w- e:\windows\system32\nvdata.bin
2011-01-11 07:24:47 14532608 -c--a-w- e:\windows\system32\nvoglnt.dll
2011-01-11 07:24:46 1462272 -c--a-w- e:\windows\system32\nvapi.dll
2011-01-11 07:24:46 13012992 -c--a-w- e:\windows\system32\nvcompiler.dll
2011-01-11 07:24:33 -------- dc----w- e:\program files\NVIDIA Corporation
2011-01-11 07:04:23 -------- dc----w- e:\program files\ATI
2011-01-11 06:57:23 105088 -c--a-r- e:\windows\system32\drivers\Rtnicxp.sys
2011-01-11 06:55:38 273512 -c--a-w- e:\windows\system32\drivers\Rtenicxp.sys
2011-01-11 06:55:33 -------- dc----w- e:\program files\Realtek
2011-01-11 06:12:28 94208 -c--a-w- e:\windows\system32\RTNUninst32.dll
2011-01-11 06:12:28 73728 -c--a-w- e:\windows\system32\RtNicProp32.dll
2011-01-11 06:12:28 233472 -c--a-w- e:\windows\system32\drivers\Rt86win7.sys
2011-01-11 06:00:01 -------- d-----w- E:\MSI7280newer
2011-01-11 05:21:23 -------- d-----w- E:\MSI7280
2010-12-21 01:30:24 -------- dc----w- e:\program files\Spybot - Search & Destroy
2010-12-20 21:56:46 98392 -c--a-w- e:\windows\system32\drivers\SBREDrv.sys
2010-12-20 21:55:57 -------- dc----w- e:\docume~1\davel\locals~1\applic~1\Sunbelt Software
2010-12-20 21:54:50 -------- dc----w- e:\program files\Lavasoft
==================== Find3M ====================
2010-12-02 03:35:18 4280320 -c--a-w- e:\windows\system32\GPhotos.scr
2010-12-02 00:44:11 60416 -c--a-w- e:\windows\ALCFDRTM.VER
2010-11-18 18:12:44 81920 -c--a-w- e:\windows\system32\isign32.dll
2010-11-13 02:53:06 472808 -c--a-w- e:\windows\system32\deployJava1.dll
2010-11-13 00:34:10 73728 -c--a-w- e:\windows\system32\javacpl.cpl
2010-11-09 14:52:35 249856 -c--a-w- e:\windows\system32\odbc32.dll
2010-11-06 00:26:58 916480 -c--a-w- e:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 -c--a-w- e:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 -c----w- e:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 -c--a-w- e:\windows\system32\html.iec
2010-10-28 13:13:22 290048 -c--a-w- e:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 -c--a-w- e:\windows\system32\win32k.sys
============= FINISH: 16:54:30.68 ===============
ZZZZZZZZZZZZZZZZZZZZZZ begin DDS1 ZZZZZZZZZZZZZZZZZZZZZZZ
DDS (Ver_10-12-12.02) - NTFSx86
Run by davel at 18:49:07.40 on Sun 01/16/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2711 [GMT -8:00]
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
============== Running Processes ===============
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
E:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
E:\WINDOWS\system32\spoolsv.exe
svchost.exe
svchost.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
E:\WINDOWS\system32\dllhost.exe
E:\WINDOWS\system32\wuauclt.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\dllhost.exe
E:\Program Files\Microsoft IntelliType Pro\type32.exe
E:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Program Files\Microsoft Security Client\msseces.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\WINDOWS\RTHDCPL.EXE
E:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
E:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
E:\Documents and Settings\davel\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - e:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - e:\program files\windows live\toolbar\wltcore.dll
TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
TB: {D593DE91-7B41-45C2-830E-E9A99AB142AA} - No File
mRun: [type32] "e:\program files\microsoft intellitype pro\type32.exe"
mRun: [IntelliPoint] "e:\program files\microsoft intellipoint\ipoint.exe"
mRun: [MSC] "e:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [NvCplDaemon] RUNDLL32.EXE e:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE e:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [nwiz] e:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [Adobe ARM] "e:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "e:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "e:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
dRun: [DWQueuedReporting] "e:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-explorer: MaxRecentDocs = 99 (0x63)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: HideShutdownScripts = 0 (0x0)
IE: Append Link Target to Existing PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - e:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - e:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\progra~1\micros~4\office11\REFIEBAR.DLL
Trusted Zone: 977music.com
Trusted Zone: amazon.com\www
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\www.msi
Trusted Zone: divx.com\www
Trusted Zone: ebay.com\signin
Trusted Zone: facebook.com\login
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: ipride.com\www
Trusted Zone: live.com\workspace.office
Trusted Zone: microsoft.com\*.update
Trusted Zone: nwmls.com
Trusted Zone: rapmls.com
Trusted Zone: windowsupdate.com\download
Trusted Zone: yahoo.com\login
Trusted Zone: yahoo.com\www
DPF: PUFLITE - hxxp://davidleland.point2agent.com/Office/ColpaControls/Photo/Control/PUFLITE.CAB
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {12545791-AC9A-44B2-8964-0DA216C4A4E5} - hxxp://www.partserver.de/partserver/viewer/cnsweb3d/cnsweb3d.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} - file:///E:/DOCUME~1/davel/LOCALS~1/Temp/IXP001.TMP/setup.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261081771046
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxps://register.facebook.com/controls/contactx.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1261081761125
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
AppInit_DLLs: e:\progra~1\google\google~4\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;e:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R2 fssfltr;FssFltr;e:\windows\system32\drivers\fssfltr_tdi.sys [2009-3-31 54760]
R3 AV88BASE;Cx2388x Base Driver;e:\windows\system32\drivers\av88base.sys [2007-4-13 423936]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;e:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [2011-1-10 1691480]
S3 brfilt;Brother MFC Filter Driver;e:\windows\system32\drivers\brfilt.sys [2008-12-1 2944]
S3 BrSerWDM;Brother WDM Serial driver;e:\windows\system32\drivers\BrSerWdm.sys [2003-3-14 61952]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;e:\windows\system32\drivers\brusbmdm.sys [2008-12-1 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;e:\windows\system32\drivers\brusbscn.sys [2008-12-1 10368]
S3 cpuz132;cpuz132; [x]
S3 DlinkUDSMBus;DlinkUDSMBus;e:\windows\system32\drivers\dlinkudsmbus.sys --> e:\windows\system32\drivers\DlinkUDSMBus.sys [?]
S3 fsssvc;Windows Live Family Safety Service;e:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;e:\program files\google\google desktop search\GoogleDesktop.exe [2009-5-4 30192]
S3 RTL8167;Realtek 8167 NT Driver;e:\windows\system32\drivers\Rt86win7.sys [2011-1-10 233472]
S3 WinRM;Windows Remote Management (WS-Management);e:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;e:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 gupdate;Google Update Service (gupdate);"e:\program files\google\update\googleupdate.exe" /svc --> e:\program files\google\update\GoogleUpdate.exe [?]
=============== Created Last 30 ================
2011-01-16 21:21:00 388096 -c--a-r- e:\docume~1\davel\applic~1\microsoft\installer\{0761c9a8-8f3a-4216-b4a7-b7afbf24a24a}\HiJackThis.exe
2011-01-16 21:20:59 -------- dc----w- e:\program files\TrendMicro
2011-01-15 09:26:02 6273872 -c--a-w- e:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{8db8ca81-f66e-4ad1-a343-fecef2901221}\mpengine.dll
2011-01-15 08:56:20 12800 -c--a-w- e:\windows\system32\dllcache\mrinfo.exe
2011-01-15 08:53:54 450560 -c--a-w- e:\windows\system32\dllcache\infosoft.dll
2011-01-14 23:54:15 -------- dc----w- e:\docume~1\alluse~1\applic~1\AntiSpyInfo
2011-01-14 23:54:08 -------- dc----w- e:\program files\Anti-Spy.Info
2011-01-14 23:22:24 116224 -c--a-w- e:\windows\system32\dllcache\xrxwiadr.dll
2011-01-14 23:22:21 23040 -c--a-w- e:\windows\system32\dllcache\xrxwbtmp.dll
2011-01-14 23:22:20 18944 -c--a-w- e:\windows\system32\dllcache\xrxscnui.dll
2011-01-14 23:22:18 27648 -c--a-w- e:\windows\system32\dllcache\xrxftplt.exe
2011-01-14 23:22:15 4608 -c--a-w- e:\windows\system32\dllcache\xrxflnch.exe
2011-01-14 23:22:01 99865 -c--a-w- e:\windows\system32\dllcache\xlog.exe
2011-01-14 23:20:57 19016 -c--a-w- e:\windows\system32\dllcache\w926nd.sys
2011-01-14 23:19:58 50688 -c--a-w- e:\windows\system32\dllcache\umaxscan.dll
2011-01-14 23:18:59 4992 -c--a-w- e:\windows\system32\dllcache\toside.sys
2011-01-14 23:17:58 10240 -c--a-w- e:\windows\system32\dllcache\swpidflt.dll
2011-01-14 23:16:59 7040 -c--a-w- e:\windows\system32\dllcache\snyaitmc.sys
2011-01-14 23:15:59 150144 -c--a-w- e:\windows\system32\dllcache\sis6306v.dll
2011-01-14 23:14:59 495616 -c--a-w- e:\windows\system32\dllcache\sblfx.dll
2011-01-14 23:13:58 19584 -c--a-w- e:\windows\system32\dllcache\rasirda.sys
2011-01-14 23:12:59 92416 -c--a-w- e:\windows\system32\dllcache\phildec.sys
2011-01-14 23:11:59 28032 -c--a-w- e:\windows\system32\dllcache\ovcd.sys
2011-01-14 23:10:59 39264 -c--a-w- e:\windows\system32\dllcache\neo20xx.sys
2011-01-14 23:09:58 35200 -c--a-w- e:\windows\system32\dllcache\msgame.sys
2011-01-14 23:08:59 727786 -c--a-w- e:\windows\system32\dllcache\ltck000c.sys
2011-01-14 23:07:58 23552 -c--a-w- e:\windows\system32\dllcache\irmk7.sys
2011-01-14 23:06:58 38528 -c--a-w- e:\windows\system32\dllcache\ibmvcap.sys
2011-01-14 23:05:59 19456 -c--a-w- e:\windows\system32\dllcache\hr1w.dll
2011-01-14 23:04:32 442240 -c--a-w- e:\windows\system32\dllcache\fpnpbase.sys
2011-01-14 23:04:30 441728 -c--a-w- e:\windows\system32\dllcache\fpcmbase.sys
2011-01-14 23:04:29 444416 -c--a-w- e:\windows\system32\dllcache\fpcibase.sys
2011-01-14 23:04:28 34173 -c--a-w- e:\windows\system32\dllcache\forehe.sys
2011-01-14 23:04:26 71680 -c--a-w- e:\windows\system32\dllcache\fnfilter.dll
2011-01-14 23:04:19 27165 -c--a-w- e:\windows\system32\dllcache\fetnd5.sys
2011-01-14 23:04:15 22090 -c--a-w- e:\windows\system32\dllcache\fem556n5.sys
2011-01-14 23:03:21 24618 -c--a-w- e:\windows\system32\dllcache\fa410nd5.sys
2011-01-14 23:03:19 16074 -c--a-w- e:\windows\system32\dllcache\fa312nd5.sys
2011-01-14 23:03:18 11850 -c--a-w- e:\windows\system32\dllcache\f3ab18xj.sys
2011-01-14 23:03:16 12362 -c--a-w- e:\windows\system32\dllcache\f3ab18xi.sys
2011-01-14 23:03:14 7040 -c--a-w- e:\windows\system32\dllcache\exabyte2.sys
2011-01-14 23:03:13 16998 -c--a-w- e:\windows\system32\dllcache\ex10.sys
2011-01-14 23:03:08 45568 -c--a-w- e:\windows\system32\dllcache\esunib.dll
2011-01-14 23:03:07 45568 -c--a-w- e:\windows\system32\dllcache\esuni.dll
2011-01-14 23:03:04 34816 -c--a-w- e:\windows\system32\dllcache\esuimg.dll
2011-01-14 23:00:59 629952 -c--a-w- e:\windows\system32\dllcache\eqn.sys
2011-01-14 22:59:59 103044 -c--a-w- e:\windows\system32\dllcache\digidxb.sys
2011-01-14 22:58:52 8192 -c--a-w- e:\windows\system32\dllcache\changer.sys
2011-01-14 22:57:53 13824 -c--a-w- e:\windows\system32\dllcache\bulltlp3.sys
2011-01-14 22:56:55 10880 -c--a-w- e:\windows\system32\dllcache\admjoy.sys
2011-01-14 17:17:24 6273872 -c--a-w- e:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-01-13 14:49:31 -------- dc----w- e:\program files\Sdelete
2011-01-13 08:57:42 222080 -c----w- e:\windows\system32\MpSigStub.exe
2011-01-13 08:56:13 -------- dc----w- e:\program files\Microsoft Security Client
2011-01-11 07:36:30 -------- dc----w- e:\windows\system32\RTCOM
2011-01-11 07:25:50 -------- dc----w- e:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2011-01-11 07:25:04 240592 -c--a-w- e:\windows\system32\nvdrsdb0.bin
2011-01-11 07:25:00 240592 -c--a-w- e:\windows\system32\nvdrsdb1.bin
2011-01-11 07:25:00 1 -c--a-w- e:\windows\system32\nvdrssel.bin
2011-01-11 07:24:47 888424 -c--a-w- e:\windows\system32\nvdispco32.dll
2011-01-11 07:24:47 813672 -c--a-w- e:\windows\system32\nvgenco32.dll
2011-01-11 07:24:47 61440 -c--a-w- e:\windows\system32\OpenCL.dll
2011-01-11 07:24:47 4882432 -c--a-w- e:\windows\system32\nvcuda.dll
2011-01-11 07:24:47 2932840 -c--a-w- e:\windows\system32\nvcuvid.dll
2011-01-11 07:24:47 2666600 -c--a-w- e:\windows\system32\nvcuvenc.dll
2011-01-11 07:24:47 2293194 -c--a-w- e:\windows\system32\nvdata.bin
2011-01-11 07:24:47 14532608 -c--a-w- e:\windows\system32\nvoglnt.dll
2011-01-11 07:24:46 1462272 -c--a-w- e:\windows\system32\nvapi.dll
2011-01-11 07:24:46 13012992 -c--a-w- e:\windows\system32\nvcompiler.dll
2011-01-11 07:24:33 -------- dc----w- e:\program files\NVIDIA Corporation
2011-01-11 07:04:23 -------- dc----w- e:\program files\ATI
2011-01-11 06:57:23 105088 -c--a-r- e:\windows\system32\drivers\Rtnicxp.sys
2011-01-11 06:55:38 273512 -c--a-w- e:\windows\system32\drivers\Rtenicxp.sys
2011-01-11 06:55:33 -------- dc----w- e:\program files\Realtek
2011-01-11 06:12:28 94208 -c--a-w- e:\windows\system32\RTNUninst32.dll
2011-01-11 06:12:28 73728 -c--a-w- e:\windows\system32\RtNicProp32.dll
2011-01-11 06:12:28 233472 -c--a-w- e:\windows\system32\drivers\Rt86win7.sys
2011-01-11 06:00:01 -------- d-----w- E:\MSI7280newer
2011-01-11 05:21:23 -------- d-----w- E:\MSI7280
2010-12-21 01:30:24 -------- dc----w- e:\program files\Spybot - Search & Destroy
2010-12-20 21:56:46 98392 -c--a-w- e:\windows\system32\drivers\SBREDrv.sys
2010-12-20 21:55:57 -------- dc----w- e:\docume~1\davel\locals~1\applic~1\Sunbelt Software
2010-12-20 21:54:50 -------- dc----w- e:\program files\Lavasoft
==================== Find3M ====================
2010-12-02 03:35:18 4280320 -c--a-w- e:\windows\system32\GPhotos.scr
2010-12-02 00:44:11 60416 -c--a-w- e:\windows\ALCFDRTM.VER
2010-11-18 18:12:44 81920 -c--a-w- e:\windows\system32\isign32.dll
2010-11-13 02:53:06 472808 -c--a-w- e:\windows\system32\deployJava1.dll
2010-11-13 00:34:10 73728 -c--a-w- e:\windows\system32\javacpl.cpl
2010-11-09 14:52:35 249856 -c--a-w- e:\windows\system32\odbc32.dll
2010-11-06 00:26:58 916480 -c--a-w- e:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 -c--a-w- e:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 -c----w- e:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 -c--a-w- e:\windows\system32\html.iec
2010-10-28 13:13:22 290048 -c--a-w- e:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 -c--a-w- e:\windows\system32\win32k.sys
============= FINISH: 18:55:46.45 ===============
to malware removal, so I have already done most of the things you asked us not to do. That said, System Restore is off, there
are no backups on this machine, my XP directory and the rest of my machine is as clean as I can make it.
Spybot, and several other anti-malware programs fail to find w32.? Other than a slow boot which fails to finish, my chief clue
are the folders Xerox, and sub-folder nwwia. I delete them and they are recreated. I replaced them with system file checker-
same results. I may have stopped the worm temporarily by using the administrator account in safe mode, deleting them, and
re-creating them myself, changing to very limited rights, and making them read-only. I used a lower case X for Xerox, so I
could tell if anything changed. So far, they have remained the same. I noticed that MSI ran briefly on startup, but it is not
shown in the DDS as a running process. I believe it failed to deliver its payload for the above reason. Note: the event log
shows msiexec.exe was restored after it terminated unexpectedly- see top two event log entries in attach.txt. I found MSI
running with the Anti-Spy Info program, and was able to read the text in the executable. The text lead me to believe, that it
was busy acting as user S-1-5-18 for various tasks which seemed inappropriate. There are now three users in the registry with
only Administrator and My account showing in the User manager. There are many duplicate entrys in the registry, which may
account for some of the slow startup.
I ran dds twice- once long after boot(DDS.txt, Attach.txt), and once as fast as I could click on DDS(DDS1.txt, Attach1.txt).
Notable differences are:
DDS1: DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} - file:///E:/DOCUME~1/davel/LOCALS~1/Temp/IXP001.TMP/setup.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
DDS: Not there
DDS1: DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -
DDS: Not there
I believe this is enough to get started--- Not enough time or space to write everything.
Any help would be very much appreciated.
Thanks,
Dave
ZZZZZZZZZZZZZZ begin DDS ZZZZZZZZZZZZZZZZZZ
DDS (Ver_10-12-12.02) - NTFSx86
Run by davel at 16:53:33.31 on Sun 01/16/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2676 [GMT -8:00]
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
============== Running Processes ===============
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
E:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
E:\WINDOWS\system32\spoolsv.exe
svchost.exe
svchost.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
E:\WINDOWS\system32\dllhost.exe
E:\WINDOWS\system32\dllhost.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Microsoft IntelliType Pro\type32.exe
E:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Program Files\Microsoft Security Client\msseces.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\WINDOWS\RTHDCPL.EXE
E:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Windows Live\Toolbar\wltuser.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Documents and Settings\davel\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - e:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - e:\program files\windows live\toolbar\wltcore.dll
TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
TB: {D593DE91-7B41-45C2-830E-E9A99AB142AA} - No File
mRun: [type32] "e:\program files\microsoft intellitype pro\type32.exe"
mRun: [IntelliPoint] "e:\program files\microsoft intellipoint\ipoint.exe"
mRun: [MSC] "e:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [NvCplDaemon] RUNDLL32.EXE e:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE e:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [nwiz] e:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [Adobe ARM] "e:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "e:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "e:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
dRun: [DWQueuedReporting] "e:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-explorer: MaxRecentDocs = 99 (0x63)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: HideShutdownScripts = 0 (0x0)
IE: Append Link Target to Existing PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - e:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - e:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\progra~1\micros~4\office11\REFIEBAR.DLL
Trusted Zone: 977music.com
Trusted Zone: amazon.com\www
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\www.msi
Trusted Zone: divx.com\www
Trusted Zone: ebay.com\signin
Trusted Zone: facebook.com\login
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: ipride.com\www
Trusted Zone: live.com\workspace.office
Trusted Zone: microsoft.com\*.update
Trusted Zone: nwmls.com
Trusted Zone: rapmls.com
Trusted Zone: windowsupdate.com\download
Trusted Zone: yahoo.com\login
Trusted Zone: yahoo.com\www
DPF: PUFLITE - hxxp://davidleland.point2agent.com/Office/ColpaControls/Photo/Control/PUFLITE.CAB
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {12545791-AC9A-44B2-8964-0DA216C4A4E5} - hxxp://www.partserver.de/partserver/viewer/cnsweb3d/cnsweb3d.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} - file:///E:/DOCUME~1/davel/LOCALS~1/Temp/IXP001.TMP/setup.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261081771046
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxps://register.facebook.com/controls/contactx.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1261081761125
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
AppInit_DLLs: e:\progra~1\google\google~4\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;e:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R2 fssfltr;FssFltr;e:\windows\system32\drivers\fssfltr_tdi.sys [2009-3-31 54760]
R3 AV88BASE;Cx2388x Base Driver;e:\windows\system32\drivers\av88base.sys [2007-4-13 423936]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;e:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [2011-1-10 1691480]
S3 brfilt;Brother MFC Filter Driver;e:\windows\system32\drivers\brfilt.sys [2008-12-1 2944]
S3 BrSerWDM;Brother WDM Serial driver;e:\windows\system32\drivers\BrSerWdm.sys [2003-3-14 61952]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;e:\windows\system32\drivers\brusbmdm.sys [2008-12-1 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;e:\windows\system32\drivers\brusbscn.sys [2008-12-1 10368]
S3 cpuz132;cpuz132; [x]
S3 DlinkUDSMBus;DlinkUDSMBus;e:\windows\system32\drivers\dlinkudsmbus.sys --> e:\windows\system32\drivers\DlinkUDSMBus.sys [?]
S3 fsssvc;Windows Live Family Safety Service;e:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;e:\program files\google\google desktop search\GoogleDesktop.exe [2009-5-4 30192]
S3 RTL8167;Realtek 8167 NT Driver;e:\windows\system32\drivers\Rt86win7.sys [2011-1-10 233472]
S3 WinRM;Windows Remote Management (WS-Management);e:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;e:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 gupdate;Google Update Service (gupdate);"e:\program files\google\update\googleupdate.exe" /svc --> e:\program files\google\update\GoogleUpdate.exe [?]
=============== Created Last 30 ================
2011-01-16 21:21:00 388096 -c--a-r- e:\docume~1\davel\applic~1\microsoft\installer\{0761c9a8-8f3a-4216-b4a7-b7afbf24a24a}\HiJackThis.exe
2011-01-16 21:20:59 -------- dc----w- e:\program files\TrendMicro
2011-01-15 09:26:02 6273872 -c--a-w- e:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{8db8ca81-f66e-4ad1-a343-fecef2901221}\mpengine.dll
2011-01-15 08:56:20 12800 -c--a-w- e:\windows\system32\dllcache\mrinfo.exe
2011-01-15 08:53:54 450560 -c--a-w- e:\windows\system32\dllcache\infosoft.dll
2011-01-14 23:54:15 -------- dc----w- e:\docume~1\alluse~1\applic~1\AntiSpyInfo
2011-01-14 23:54:08 -------- dc----w- e:\program files\Anti-Spy.Info
2011-01-14 23:22:24 116224 -c--a-w- e:\windows\system32\dllcache\xrxwiadr.dll
2011-01-14 23:22:21 23040 -c--a-w- e:\windows\system32\dllcache\xrxwbtmp.dll
2011-01-14 23:22:20 18944 -c--a-w- e:\windows\system32\dllcache\xrxscnui.dll
2011-01-14 23:22:18 27648 -c--a-w- e:\windows\system32\dllcache\xrxftplt.exe
2011-01-14 23:22:15 4608 -c--a-w- e:\windows\system32\dllcache\xrxflnch.exe
2011-01-14 23:22:01 99865 -c--a-w- e:\windows\system32\dllcache\xlog.exe
2011-01-14 23:20:57 19016 -c--a-w- e:\windows\system32\dllcache\w926nd.sys
2011-01-14 23:19:58 50688 -c--a-w- e:\windows\system32\dllcache\umaxscan.dll
2011-01-14 23:18:59 4992 -c--a-w- e:\windows\system32\dllcache\toside.sys
2011-01-14 23:17:58 10240 -c--a-w- e:\windows\system32\dllcache\swpidflt.dll
2011-01-14 23:16:59 7040 -c--a-w- e:\windows\system32\dllcache\snyaitmc.sys
2011-01-14 23:15:59 150144 -c--a-w- e:\windows\system32\dllcache\sis6306v.dll
2011-01-14 23:14:59 495616 -c--a-w- e:\windows\system32\dllcache\sblfx.dll
2011-01-14 23:13:58 19584 -c--a-w- e:\windows\system32\dllcache\rasirda.sys
2011-01-14 23:12:59 92416 -c--a-w- e:\windows\system32\dllcache\phildec.sys
2011-01-14 23:11:59 28032 -c--a-w- e:\windows\system32\dllcache\ovcd.sys
2011-01-14 23:10:59 39264 -c--a-w- e:\windows\system32\dllcache\neo20xx.sys
2011-01-14 23:09:58 35200 -c--a-w- e:\windows\system32\dllcache\msgame.sys
2011-01-14 23:08:59 727786 -c--a-w- e:\windows\system32\dllcache\ltck000c.sys
2011-01-14 23:07:58 23552 -c--a-w- e:\windows\system32\dllcache\irmk7.sys
2011-01-14 23:06:58 38528 -c--a-w- e:\windows\system32\dllcache\ibmvcap.sys
2011-01-14 23:05:59 19456 -c--a-w- e:\windows\system32\dllcache\hr1w.dll
2011-01-14 23:04:32 442240 -c--a-w- e:\windows\system32\dllcache\fpnpbase.sys
2011-01-14 23:04:30 441728 -c--a-w- e:\windows\system32\dllcache\fpcmbase.sys
2011-01-14 23:04:29 444416 -c--a-w- e:\windows\system32\dllcache\fpcibase.sys
2011-01-14 23:04:28 34173 -c--a-w- e:\windows\system32\dllcache\forehe.sys
2011-01-14 23:04:26 71680 -c--a-w- e:\windows\system32\dllcache\fnfilter.dll
2011-01-14 23:04:19 27165 -c--a-w- e:\windows\system32\dllcache\fetnd5.sys
2011-01-14 23:04:15 22090 -c--a-w- e:\windows\system32\dllcache\fem556n5.sys
2011-01-14 23:03:21 24618 -c--a-w- e:\windows\system32\dllcache\fa410nd5.sys
2011-01-14 23:03:19 16074 -c--a-w- e:\windows\system32\dllcache\fa312nd5.sys
2011-01-14 23:03:18 11850 -c--a-w- e:\windows\system32\dllcache\f3ab18xj.sys
2011-01-14 23:03:16 12362 -c--a-w- e:\windows\system32\dllcache\f3ab18xi.sys
2011-01-14 23:03:14 7040 -c--a-w- e:\windows\system32\dllcache\exabyte2.sys
2011-01-14 23:03:13 16998 -c--a-w- e:\windows\system32\dllcache\ex10.sys
2011-01-14 23:03:08 45568 -c--a-w- e:\windows\system32\dllcache\esunib.dll
2011-01-14 23:03:07 45568 -c--a-w- e:\windows\system32\dllcache\esuni.dll
2011-01-14 23:03:04 34816 -c--a-w- e:\windows\system32\dllcache\esuimg.dll
2011-01-14 23:00:59 629952 -c--a-w- e:\windows\system32\dllcache\eqn.sys
2011-01-14 22:59:59 103044 -c--a-w- e:\windows\system32\dllcache\digidxb.sys
2011-01-14 22:58:52 8192 -c--a-w- e:\windows\system32\dllcache\changer.sys
2011-01-14 22:57:53 13824 -c--a-w- e:\windows\system32\dllcache\bulltlp3.sys
2011-01-14 22:56:55 10880 -c--a-w- e:\windows\system32\dllcache\admjoy.sys
2011-01-14 17:17:24 6273872 -c--a-w- e:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-01-13 14:49:31 -------- dc----w- e:\program files\Sdelete
2011-01-13 08:57:42 222080 -c----w- e:\windows\system32\MpSigStub.exe
2011-01-13 08:56:13 -------- dc----w- e:\program files\Microsoft Security Client
2011-01-11 07:36:30 -------- dc----w- e:\windows\system32\RTCOM
2011-01-11 07:25:50 -------- dc----w- e:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2011-01-11 07:25:04 240592 -c--a-w- e:\windows\system32\nvdrsdb0.bin
2011-01-11 07:25:00 240592 -c--a-w- e:\windows\system32\nvdrsdb1.bin
2011-01-11 07:25:00 1 -c--a-w- e:\windows\system32\nvdrssel.bin
2011-01-11 07:24:47 888424 -c--a-w- e:\windows\system32\nvdispco32.dll
2011-01-11 07:24:47 813672 -c--a-w- e:\windows\system32\nvgenco32.dll
2011-01-11 07:24:47 61440 -c--a-w- e:\windows\system32\OpenCL.dll
2011-01-11 07:24:47 4882432 -c--a-w- e:\windows\system32\nvcuda.dll
2011-01-11 07:24:47 2932840 -c--a-w- e:\windows\system32\nvcuvid.dll
2011-01-11 07:24:47 2666600 -c--a-w- e:\windows\system32\nvcuvenc.dll
2011-01-11 07:24:47 2293194 -c--a-w- e:\windows\system32\nvdata.bin
2011-01-11 07:24:47 14532608 -c--a-w- e:\windows\system32\nvoglnt.dll
2011-01-11 07:24:46 1462272 -c--a-w- e:\windows\system32\nvapi.dll
2011-01-11 07:24:46 13012992 -c--a-w- e:\windows\system32\nvcompiler.dll
2011-01-11 07:24:33 -------- dc----w- e:\program files\NVIDIA Corporation
2011-01-11 07:04:23 -------- dc----w- e:\program files\ATI
2011-01-11 06:57:23 105088 -c--a-r- e:\windows\system32\drivers\Rtnicxp.sys
2011-01-11 06:55:38 273512 -c--a-w- e:\windows\system32\drivers\Rtenicxp.sys
2011-01-11 06:55:33 -------- dc----w- e:\program files\Realtek
2011-01-11 06:12:28 94208 -c--a-w- e:\windows\system32\RTNUninst32.dll
2011-01-11 06:12:28 73728 -c--a-w- e:\windows\system32\RtNicProp32.dll
2011-01-11 06:12:28 233472 -c--a-w- e:\windows\system32\drivers\Rt86win7.sys
2011-01-11 06:00:01 -------- d-----w- E:\MSI7280newer
2011-01-11 05:21:23 -------- d-----w- E:\MSI7280
2010-12-21 01:30:24 -------- dc----w- e:\program files\Spybot - Search & Destroy
2010-12-20 21:56:46 98392 -c--a-w- e:\windows\system32\drivers\SBREDrv.sys
2010-12-20 21:55:57 -------- dc----w- e:\docume~1\davel\locals~1\applic~1\Sunbelt Software
2010-12-20 21:54:50 -------- dc----w- e:\program files\Lavasoft
==================== Find3M ====================
2010-12-02 03:35:18 4280320 -c--a-w- e:\windows\system32\GPhotos.scr
2010-12-02 00:44:11 60416 -c--a-w- e:\windows\ALCFDRTM.VER
2010-11-18 18:12:44 81920 -c--a-w- e:\windows\system32\isign32.dll
2010-11-13 02:53:06 472808 -c--a-w- e:\windows\system32\deployJava1.dll
2010-11-13 00:34:10 73728 -c--a-w- e:\windows\system32\javacpl.cpl
2010-11-09 14:52:35 249856 -c--a-w- e:\windows\system32\odbc32.dll
2010-11-06 00:26:58 916480 -c--a-w- e:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 -c--a-w- e:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 -c----w- e:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 -c--a-w- e:\windows\system32\html.iec
2010-10-28 13:13:22 290048 -c--a-w- e:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 -c--a-w- e:\windows\system32\win32k.sys
============= FINISH: 16:54:30.68 ===============
ZZZZZZZZZZZZZZZZZZZZZZ begin DDS1 ZZZZZZZZZZZZZZZZZZZZZZZ
DDS (Ver_10-12-12.02) - NTFSx86
Run by davel at 18:49:07.40 on Sun 01/16/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2711 [GMT -8:00]
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
============== Running Processes ===============
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
E:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
E:\WINDOWS\system32\spoolsv.exe
svchost.exe
svchost.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
E:\WINDOWS\system32\dllhost.exe
E:\WINDOWS\system32\wuauclt.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\dllhost.exe
E:\Program Files\Microsoft IntelliType Pro\type32.exe
E:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Program Files\Microsoft Security Client\msseces.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\WINDOWS\RTHDCPL.EXE
E:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
E:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
E:\Documents and Settings\davel\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - e:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - e:\program files\windows live\toolbar\wltcore.dll
TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
TB: {D593DE91-7B41-45C2-830E-E9A99AB142AA} - No File
mRun: [type32] "e:\program files\microsoft intellitype pro\type32.exe"
mRun: [IntelliPoint] "e:\program files\microsoft intellipoint\ipoint.exe"
mRun: [MSC] "e:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [NvCplDaemon] RUNDLL32.EXE e:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE e:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [nwiz] e:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [Adobe ARM] "e:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "e:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "e:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
dRun: [DWQueuedReporting] "e:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-explorer: MaxRecentDocs = 99 (0x63)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: HideShutdownScripts = 0 (0x0)
IE: Append Link Target to Existing PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - e:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - e:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - e:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\progra~1\micros~4\office11\REFIEBAR.DLL
Trusted Zone: 977music.com
Trusted Zone: amazon.com\www
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\www.msi
Trusted Zone: divx.com\www
Trusted Zone: ebay.com\signin
Trusted Zone: facebook.com\login
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: ipride.com\www
Trusted Zone: live.com\workspace.office
Trusted Zone: microsoft.com\*.update
Trusted Zone: nwmls.com
Trusted Zone: rapmls.com
Trusted Zone: windowsupdate.com\download
Trusted Zone: yahoo.com\login
Trusted Zone: yahoo.com\www
DPF: PUFLITE - hxxp://davidleland.point2agent.com/Office/ColpaControls/Photo/Control/PUFLITE.CAB
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {12545791-AC9A-44B2-8964-0DA216C4A4E5} - hxxp://www.partserver.de/partserver/viewer/cnsweb3d/cnsweb3d.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} - file:///E:/DOCUME~1/davel/LOCALS~1/Temp/IXP001.TMP/setup.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261081771046
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxps://register.facebook.com/controls/contactx.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1261081761125
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
AppInit_DLLs: e:\progra~1\google\google~4\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;e:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R2 fssfltr;FssFltr;e:\windows\system32\drivers\fssfltr_tdi.sys [2009-3-31 54760]
R3 AV88BASE;Cx2388x Base Driver;e:\windows\system32\drivers\av88base.sys [2007-4-13 423936]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;e:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [2011-1-10 1691480]
S3 brfilt;Brother MFC Filter Driver;e:\windows\system32\drivers\brfilt.sys [2008-12-1 2944]
S3 BrSerWDM;Brother WDM Serial driver;e:\windows\system32\drivers\BrSerWdm.sys [2003-3-14 61952]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;e:\windows\system32\drivers\brusbmdm.sys [2008-12-1 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;e:\windows\system32\drivers\brusbscn.sys [2008-12-1 10368]
S3 cpuz132;cpuz132; [x]
S3 DlinkUDSMBus;DlinkUDSMBus;e:\windows\system32\drivers\dlinkudsmbus.sys --> e:\windows\system32\drivers\DlinkUDSMBus.sys [?]
S3 fsssvc;Windows Live Family Safety Service;e:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;e:\program files\google\google desktop search\GoogleDesktop.exe [2009-5-4 30192]
S3 RTL8167;Realtek 8167 NT Driver;e:\windows\system32\drivers\Rt86win7.sys [2011-1-10 233472]
S3 WinRM;Windows Remote Management (WS-Management);e:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;e:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 gupdate;Google Update Service (gupdate);"e:\program files\google\update\googleupdate.exe" /svc --> e:\program files\google\update\GoogleUpdate.exe [?]
=============== Created Last 30 ================
2011-01-16 21:21:00 388096 -c--a-r- e:\docume~1\davel\applic~1\microsoft\installer\{0761c9a8-8f3a-4216-b4a7-b7afbf24a24a}\HiJackThis.exe
2011-01-16 21:20:59 -------- dc----w- e:\program files\TrendMicro
2011-01-15 09:26:02 6273872 -c--a-w- e:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{8db8ca81-f66e-4ad1-a343-fecef2901221}\mpengine.dll
2011-01-15 08:56:20 12800 -c--a-w- e:\windows\system32\dllcache\mrinfo.exe
2011-01-15 08:53:54 450560 -c--a-w- e:\windows\system32\dllcache\infosoft.dll
2011-01-14 23:54:15 -------- dc----w- e:\docume~1\alluse~1\applic~1\AntiSpyInfo
2011-01-14 23:54:08 -------- dc----w- e:\program files\Anti-Spy.Info
2011-01-14 23:22:24 116224 -c--a-w- e:\windows\system32\dllcache\xrxwiadr.dll
2011-01-14 23:22:21 23040 -c--a-w- e:\windows\system32\dllcache\xrxwbtmp.dll
2011-01-14 23:22:20 18944 -c--a-w- e:\windows\system32\dllcache\xrxscnui.dll
2011-01-14 23:22:18 27648 -c--a-w- e:\windows\system32\dllcache\xrxftplt.exe
2011-01-14 23:22:15 4608 -c--a-w- e:\windows\system32\dllcache\xrxflnch.exe
2011-01-14 23:22:01 99865 -c--a-w- e:\windows\system32\dllcache\xlog.exe
2011-01-14 23:20:57 19016 -c--a-w- e:\windows\system32\dllcache\w926nd.sys
2011-01-14 23:19:58 50688 -c--a-w- e:\windows\system32\dllcache\umaxscan.dll
2011-01-14 23:18:59 4992 -c--a-w- e:\windows\system32\dllcache\toside.sys
2011-01-14 23:17:58 10240 -c--a-w- e:\windows\system32\dllcache\swpidflt.dll
2011-01-14 23:16:59 7040 -c--a-w- e:\windows\system32\dllcache\snyaitmc.sys
2011-01-14 23:15:59 150144 -c--a-w- e:\windows\system32\dllcache\sis6306v.dll
2011-01-14 23:14:59 495616 -c--a-w- e:\windows\system32\dllcache\sblfx.dll
2011-01-14 23:13:58 19584 -c--a-w- e:\windows\system32\dllcache\rasirda.sys
2011-01-14 23:12:59 92416 -c--a-w- e:\windows\system32\dllcache\phildec.sys
2011-01-14 23:11:59 28032 -c--a-w- e:\windows\system32\dllcache\ovcd.sys
2011-01-14 23:10:59 39264 -c--a-w- e:\windows\system32\dllcache\neo20xx.sys
2011-01-14 23:09:58 35200 -c--a-w- e:\windows\system32\dllcache\msgame.sys
2011-01-14 23:08:59 727786 -c--a-w- e:\windows\system32\dllcache\ltck000c.sys
2011-01-14 23:07:58 23552 -c--a-w- e:\windows\system32\dllcache\irmk7.sys
2011-01-14 23:06:58 38528 -c--a-w- e:\windows\system32\dllcache\ibmvcap.sys
2011-01-14 23:05:59 19456 -c--a-w- e:\windows\system32\dllcache\hr1w.dll
2011-01-14 23:04:32 442240 -c--a-w- e:\windows\system32\dllcache\fpnpbase.sys
2011-01-14 23:04:30 441728 -c--a-w- e:\windows\system32\dllcache\fpcmbase.sys
2011-01-14 23:04:29 444416 -c--a-w- e:\windows\system32\dllcache\fpcibase.sys
2011-01-14 23:04:28 34173 -c--a-w- e:\windows\system32\dllcache\forehe.sys
2011-01-14 23:04:26 71680 -c--a-w- e:\windows\system32\dllcache\fnfilter.dll
2011-01-14 23:04:19 27165 -c--a-w- e:\windows\system32\dllcache\fetnd5.sys
2011-01-14 23:04:15 22090 -c--a-w- e:\windows\system32\dllcache\fem556n5.sys
2011-01-14 23:03:21 24618 -c--a-w- e:\windows\system32\dllcache\fa410nd5.sys
2011-01-14 23:03:19 16074 -c--a-w- e:\windows\system32\dllcache\fa312nd5.sys
2011-01-14 23:03:18 11850 -c--a-w- e:\windows\system32\dllcache\f3ab18xj.sys
2011-01-14 23:03:16 12362 -c--a-w- e:\windows\system32\dllcache\f3ab18xi.sys
2011-01-14 23:03:14 7040 -c--a-w- e:\windows\system32\dllcache\exabyte2.sys
2011-01-14 23:03:13 16998 -c--a-w- e:\windows\system32\dllcache\ex10.sys
2011-01-14 23:03:08 45568 -c--a-w- e:\windows\system32\dllcache\esunib.dll
2011-01-14 23:03:07 45568 -c--a-w- e:\windows\system32\dllcache\esuni.dll
2011-01-14 23:03:04 34816 -c--a-w- e:\windows\system32\dllcache\esuimg.dll
2011-01-14 23:00:59 629952 -c--a-w- e:\windows\system32\dllcache\eqn.sys
2011-01-14 22:59:59 103044 -c--a-w- e:\windows\system32\dllcache\digidxb.sys
2011-01-14 22:58:52 8192 -c--a-w- e:\windows\system32\dllcache\changer.sys
2011-01-14 22:57:53 13824 -c--a-w- e:\windows\system32\dllcache\bulltlp3.sys
2011-01-14 22:56:55 10880 -c--a-w- e:\windows\system32\dllcache\admjoy.sys
2011-01-14 17:17:24 6273872 -c--a-w- e:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-01-13 14:49:31 -------- dc----w- e:\program files\Sdelete
2011-01-13 08:57:42 222080 -c----w- e:\windows\system32\MpSigStub.exe
2011-01-13 08:56:13 -------- dc----w- e:\program files\Microsoft Security Client
2011-01-11 07:36:30 -------- dc----w- e:\windows\system32\RTCOM
2011-01-11 07:25:50 -------- dc----w- e:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2011-01-11 07:25:04 240592 -c--a-w- e:\windows\system32\nvdrsdb0.bin
2011-01-11 07:25:00 240592 -c--a-w- e:\windows\system32\nvdrsdb1.bin
2011-01-11 07:25:00 1 -c--a-w- e:\windows\system32\nvdrssel.bin
2011-01-11 07:24:47 888424 -c--a-w- e:\windows\system32\nvdispco32.dll
2011-01-11 07:24:47 813672 -c--a-w- e:\windows\system32\nvgenco32.dll
2011-01-11 07:24:47 61440 -c--a-w- e:\windows\system32\OpenCL.dll
2011-01-11 07:24:47 4882432 -c--a-w- e:\windows\system32\nvcuda.dll
2011-01-11 07:24:47 2932840 -c--a-w- e:\windows\system32\nvcuvid.dll
2011-01-11 07:24:47 2666600 -c--a-w- e:\windows\system32\nvcuvenc.dll
2011-01-11 07:24:47 2293194 -c--a-w- e:\windows\system32\nvdata.bin
2011-01-11 07:24:47 14532608 -c--a-w- e:\windows\system32\nvoglnt.dll
2011-01-11 07:24:46 1462272 -c--a-w- e:\windows\system32\nvapi.dll
2011-01-11 07:24:46 13012992 -c--a-w- e:\windows\system32\nvcompiler.dll
2011-01-11 07:24:33 -------- dc----w- e:\program files\NVIDIA Corporation
2011-01-11 07:04:23 -------- dc----w- e:\program files\ATI
2011-01-11 06:57:23 105088 -c--a-r- e:\windows\system32\drivers\Rtnicxp.sys
2011-01-11 06:55:38 273512 -c--a-w- e:\windows\system32\drivers\Rtenicxp.sys
2011-01-11 06:55:33 -------- dc----w- e:\program files\Realtek
2011-01-11 06:12:28 94208 -c--a-w- e:\windows\system32\RTNUninst32.dll
2011-01-11 06:12:28 73728 -c--a-w- e:\windows\system32\RtNicProp32.dll
2011-01-11 06:12:28 233472 -c--a-w- e:\windows\system32\drivers\Rt86win7.sys
2011-01-11 06:00:01 -------- d-----w- E:\MSI7280newer
2011-01-11 05:21:23 -------- d-----w- E:\MSI7280
2010-12-21 01:30:24 -------- dc----w- e:\program files\Spybot - Search & Destroy
2010-12-20 21:56:46 98392 -c--a-w- e:\windows\system32\drivers\SBREDrv.sys
2010-12-20 21:55:57 -------- dc----w- e:\docume~1\davel\locals~1\applic~1\Sunbelt Software
2010-12-20 21:54:50 -------- dc----w- e:\program files\Lavasoft
==================== Find3M ====================
2010-12-02 03:35:18 4280320 -c--a-w- e:\windows\system32\GPhotos.scr
2010-12-02 00:44:11 60416 -c--a-w- e:\windows\ALCFDRTM.VER
2010-11-18 18:12:44 81920 -c--a-w- e:\windows\system32\isign32.dll
2010-11-13 02:53:06 472808 -c--a-w- e:\windows\system32\deployJava1.dll
2010-11-13 00:34:10 73728 -c--a-w- e:\windows\system32\javacpl.cpl
2010-11-09 14:52:35 249856 -c--a-w- e:\windows\system32\odbc32.dll
2010-11-06 00:26:58 916480 -c--a-w- e:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 -c--a-w- e:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 -c----w- e:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 -c--a-w- e:\windows\system32\html.iec
2010-10-28 13:13:22 290048 -c--a-w- e:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 -c--a-w- e:\windows\system32\win32k.sys
============= FINISH: 18:55:46.45 ===============