PDA

View Full Version : Billeo



Jack421
2011-05-27, 13:29
I noticed a Billeo program from hijack this log file in my computer that seems out of place, should I delete it or what should I do with this problem?
I am also doing a general malware check up on my computer!

.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_25
Run by Megatron at 9:30:39 on 2011-05-26
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.958.221 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Online Armor Firewall *Enabled* {32E71E58-6AAE-2557-2ABD-EA739069CE41}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Emsisoft Anti-Malware\a2service.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Online Armor\OAcat.exe
C:\Program Files\Online Armor\oasrv.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\COMODO\COMODO Programs Manager\CPMService.exe
C:\Prey\platform\windows\cronsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Online Armor\oaui.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Online Armor\OAhlp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Users\Megatron\Downloads\Software\Report Tools\dds.scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
uRun: [DriverMax]
uRun: [DriverMax_RESTART]
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [hpqSRMon]
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [<NO NAME>]
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [@OnlineArmor GUI] "c:\program files\online armor\oaui.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Add animation to IncrediMail Style Box - c:\program files\incredimail\bin\resources\WebMenuImg.htm
IE: Add to Evernote 4.0 - c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
LSP: c:\program files\trafficcompressor\TCompLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
TCP: {6F943519-7881-438D-8857-621C25992B48} = 156.154.70.22,156.154.71.22
TCP: {88671F84-611F-4E3A-A09C-6719F683C026} = 156.154.70.22,156.154.71.22
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\online~2\oaevent.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\megatron\appdata\roaming\mozilla\firefox\profiles\v7iza886.default\
FF - prefs.js: browser.search.defaulturl - hxxp://plasmoo.com/index.htm?SearchMashine=true&amp;q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_fs&search=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 cumon;cumon;c:\windows\system32\drivers\cumon.sys [2011-5-25 227872]
R0 Evdd;evdd;c:\windows\system32\drivers\evdd.sys [2011-5-25 19816]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-5-20 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-5-20 307928]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2011-5-25 205864]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [2011-5-25 39048]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2011-5-25 25192]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\emsisoft anti-malware\a2service.exe [2011-5-20 2860800]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-5-20 352656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-5-20 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-5-20 53592]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-5-20 42184]
R2 CPMService;COMODO Programs Manager Service;c:\program files\comodo\comodo programs manager\CPMservice.exe [2010-7-22 79304]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-5-15 21992]
R2 CronService;Cron Service for Prey;c:\prey\platform\windows\cronsvc.exe [2011-2-15 19968]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 OAcat;Online Armor Helper Service;c:\program files\online armor\oacat.exe [2011-5-25 381512]
R2 SvcOnlineArmor;Online Armor;c:\program files\online armor\oasrv.exe [2011-5-25 4326472]
R3 OAnet;OnlineArmor Service;c:\windows\system32\drivers\OAnet.sys [2011-5-25 29312]
R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2011-3-24 126696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 a2acc;a2acc;c:\program files\emsisoft anti-malware\a2accx86.sys [2011-5-20 73728]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-5-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2011-5-14 20080]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2011.sp2\RpcAgentSrv.exe [2011-5-18 93848]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== File Associations ===============
.
.txt=GetDiz.TextFile
.
=============== Created Last 30 ================
.
2011-05-26 15:50:44 -------- d-----w- c:\users\megatron\appdata\roaming\EurekaLog
2011-05-26 07:38:07 -------- d-----w- c:\users\megatron\appdata\local\Innovative Solutions
2011-05-26 07:38:07 -------- d-----w- c:\programdata\Innovative Solutions
2011-05-26 07:37:07 -------- d-----w- c:\program files\Innovative Solutions
2011-05-26 07:34:24 -------- d-----w- c:\users\megatron\appdata\local\Comodo
2011-05-26 05:40:17 -------- d-----w- C:\Prey
2011-05-26 04:40:32 -------- d-----w- c:\users\megatron\appdata\roaming\OnlineArmor
2011-05-26 04:40:32 -------- d-----w- c:\programdata\OnlineArmor
2011-05-26 04:39:14 39048 ----a-w- c:\windows\system32\drivers\oahlp32.sys
2011-05-26 04:39:14 25192 ----a-w- c:\windows\system32\drivers\OAmon.sys
2011-05-26 04:39:13 29312 ----a-w- c:\windows\system32\drivers\OAnet.sys
2011-05-26 04:39:13 205864 ----a-w- c:\windows\system32\drivers\OADriver.sys
2011-05-26 04:39:02 -------- d-----w- c:\program files\Online Armor
2011-05-25 10:04:07 29 ----a-w- c:\windows\system32\TempWmicBatchFile.bat
2011-05-25 08:45:27 227872 ----a-w- c:\windows\system32\drivers\cumon.sys
2011-05-25 08:44:45 19816 ----a-w- c:\windows\system32\drivers\evdd.sys
2011-05-25 08:40:51 -------- d-----w- c:\program files\COMODO
2011-05-25 08:35:11 388096 ----a-r- c:\users\megatron\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-05-25 08:35:09 -------- d-----w- c:\program files\Trend Micro
2011-05-25 07:43:07 -------- d-----w- c:\program files\OpenVPN Technologies
2011-05-25 04:35:02 -------- d-----w- c:\program files\KompoZer-0.8a4
2011-05-25 04:34:13 -------- d-----w- c:\program files\Nvu
2011-05-25 04:10:44 -------- d-----w- c:\users\megatron\appdata\roaming\Nvu
2011-05-25 04:01:20 -------- d-----w- c:\users\megatron\appdata\roaming\KompoZer
2011-05-25 03:51:41 -------- d-----w- c:\program files\gnucash
2011-05-25 03:43:47 -------- d-----w- C:\2nd Story Software
2011-05-25 02:59:26 -------- d-----w- c:\users\megatron\appdata\roaming\ooVoo Details
2011-05-25 02:57:00 -------- d-----w- c:\program files\ooVoo
2011-05-24 23:00:16 -------- d-----w- c:\users\megatron\appdata\roaming\dBpoweramp
2011-05-24 21:58:43 -------- d-----w- c:\users\megatron\appdata\roaming\PhotoScape
2011-05-24 21:39:15 -------- d-----w- c:\programdata\Canneverbe Limited
2011-05-24 21:39:14 -------- d-----w- c:\users\megatron\appdata\roaming\Canneverbe Limited
2011-05-24 09:07:46 -------- d-----w- c:\program files\AIMP2 Tools
2011-05-24 08:38:23 -------- d-----w- c:\program files\Event Log Explorer
2011-05-24 07:54:08 -------- d-----w- c:\users\megatron\appdata\roaming\Digsby
2011-05-24 07:54:08 -------- d-----w- c:\users\megatron\appdata\local\Digsby
2011-05-24 07:54:08 -------- d-----w- c:\programdata\Digsby
2011-05-24 07:53:25 -------- d-----w- c:\program files\Digsby Donates
2011-05-24 07:52:34 -------- d-----w- c:\program files\Digsby
2011-05-24 07:48:36 -------- d-----w- c:\program files\ratDVD
2011-05-24 07:46:27 -------- d-----w- c:\programdata\Spamihilator
2011-05-24 07:44:57 -------- d-----w- c:\users\megatron\appdata\roaming\Spamihilator
2011-05-24 07:44:20 -------- d-----w- c:\program files\Spamihilator
2011-05-24 05:39:25 -------- d-----r- c:\users\megatron\Dropbox
2011-05-24 05:36:17 -------- d-----w- c:\users\megatron\appdata\roaming\Dropbox
2011-05-24 05:34:20 -------- d-----w- C:\PMAIL
2011-05-24 05:09:57 231248 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-05-24 05:09:01 -------- d-----w- c:\program files\TrueCrypt
2011-05-24 05:03:54 -------- d-----w- c:\programdata\Skype Extras
2011-05-24 03:56:34 -------- d-----r- c:\program files\Skype
2011-05-24 02:54:41 -------- d-----w- c:\program files\Evernote
2011-05-23 23:51:33 -------- d-----w- c:\users\megatron\appdata\local\Evernote
2011-05-23 23:38:29 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2011-05-23 23:37:56 431672 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-05-23 23:37:13 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-05-23 23:36:57 -------- d-----w- c:\users\megatron\appdata\roaming\DAEMON Tools Lite
2011-05-23 23:36:57 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-05-23 23:35:01 -------- d-----w- c:\users\megatron\appdata\roaming\mIRC
2011-05-23 23:34:58 -------- d-----w- c:\program files\mIRC
2011-05-23 21:37:05 -------- d-----w- c:\users\megatron\appdata\roaming\Trillian
2011-05-23 21:32:10 -------- d-----w- c:\users\megatron\appdata\roaming\Tor
2011-05-23 21:31:57 -------- d-----w- c:\program files\Vidalia Bundle
2011-05-23 21:30:54 -------- d-----w- c:\programdata\Viper
2011-05-23 21:30:54 -------- d-----w- c:\program files\Kerigwa
2011-05-23 21:29:25 -------- d-----w- c:\program files\Inno Setup 5
2011-05-23 21:22:46 -------- d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2011-05-23 10:48:37 -------- d-----w- c:\users\megatron\appdata\local\IM
2011-05-23 10:47:58 -------- d-----w- c:\programdata\IncrediMail
2011-05-23 10:47:58 -------- d-----w- c:\programdata\IM
2011-05-23 10:47:58 -------- d-----w- c:\program files\IncrediMail
2011-05-23 10:39:07 -------- d-----w- c:\program files\Qualcomm
2011-05-23 10:39:06 48640 ----a-r- c:\windows\system32\INETWH32.DLL
2011-05-23 10:39:06 317952 ----a-r- c:\windows\system32\Roboex32.dll
2011-05-23 10:39:06 1712128 ----a-r- c:\windows\system32\gdiplus.dll
2011-05-23 10:33:25 -------- d-----w- c:\users\megatron\appdata\roaming\DVDVideoSoftIEHelpers
2011-05-23 10:30:17 -------- d-----w- c:\program files\common files\Plasmoo
2011-05-23 10:29:40 -------- d-----w- c:\users\megatron\appdata\roaming\DVDVideoSoft
2011-05-23 10:28:35 -------- d-----w- c:\program files\common files\DVDVideoSoft
2011-05-23 10:28:23 -------- d-----w- c:\program files\DVDVideoSoft
2011-05-23 09:49:33 -------- d-----w- c:\program files\KeePass Password Safe
2011-05-23 09:24:25 -------- d-----w- c:\users\megatron\appdata\local\Google
2011-05-23 09:21:10 -------- d-----w- c:\program files\FreeMind
2011-05-23 09:16:00 -------- d-----w- c:\program files\e-Sword
2011-05-23 09:16:00 -------- d-----w- c:\program files\common files\EzTools
2011-05-23 09:12:38 -------- d-----w- c:\program files\FrostWire
2011-05-23 09:02:36 -------- d-----w- c:\program files\Nmap
2011-05-23 08:59:51 -------- d-----w- c:\program files\GIMP-2.0
2011-05-23 08:53:48 -------- d-----w- c:\program files\Pidgin
2011-05-23 08:15:42 -------- d-----w- c:\users\megatron\appdata\roaming\IrfanView
2011-05-23 08:15:37 -------- d-----w- c:\program files\IrfanView
2011-05-23 08:06:17 -------- d-----w- c:\program files\Paint.NET
2011-05-23 08:05:35 -------- d-----w- c:\users\megatron\appdata\local\Paint.NET
2011-05-23 07:58:43 -------- d-----w- c:\program files\PicPick
2011-05-23 07:54:13 -------- d-----w- c:\program files\Sandboxie
2011-05-23 07:49:45 -------- d-----w- c:\users\megatron\appdata\roaming\inkscape
2011-05-23 07:30:56 -------- d-----w- c:\program files\Inkscape
2011-05-23 07:28:56 -------- d-----w- c:\program files\IcoFX 1.6
2011-05-23 07:26:31 -------- d-----w- c:\users\megatron\appdata\local\eMule
2011-05-23 07:26:27 -------- d-----w- c:\program files\eMule
2011-05-23 07:22:42 -------- d-----w- c:\program files\Dynamic Draw Project
2011-05-23 07:14:22 -------- d-----w- c:\program files\DVD Shrink
2011-05-23 07:12:15 -------- d-----w- c:\program files\Nsasoft
2011-05-23 07:09:41 -------- d-----w- c:\users\megatron\appdata\roaming\MailWasherFree
2011-05-23 07:09:41 -------- d-----w- c:\program files\FireTrust
2011-05-23 07:07:52 -------- d-----w- c:\program files\Astonsoft
2011-05-23 07:01:57 -------- d-----w- c:\program files\DC++
2011-05-23 06:41:32 -------- d-----w- c:\users\megatron\appdata\roaming\Blender Foundation
2011-05-23 06:41:21 -------- d-----w- c:\program files\Blender Foundation
2011-05-23 06:39:20 -------- d-----w- c:\users\megatron\appdata\roaming\TeraCopy
2011-05-23 06:38:18 -------- d-----w- c:\program files\Mz Ultimate Tools
2011-05-23 06:35:26 -------- d-----w- c:\program files\PhotoScape
2011-05-23 06:32:03 -------- d-----w- c:\program files\Mixxx
2011-05-23 06:28:44 -------- d-----w- c:\program files\Foxit Software
2011-05-23 06:25:17 -------- d-----w- c:\programdata\AppSnap
2011-05-23 06:25:09 -------- d-----w- c:\program files\AppSnap
2011-05-23 05:49:47 -------- d-----w- c:\program files\TeraCopy
2011-05-23 05:44:38 -------- d-----w- C:\Python32
2011-05-23 05:40:50 -------- d-----w- c:\users\megatron\appdata\roaming\XMind
2011-05-23 05:40:25 -------- d-----w- c:\program files\XMind
2011-05-23 05:37:57 -------- d-----w- c:\program files\clrmamepro
2011-05-23 05:36:17 -------- d-----w- c:\program files\Romcenter
2011-05-23 03:11:26 -------- d-----w- c:\program files\Freeciv-2.1.9-win32
2011-05-21 10:01:38 -------- d-----w- c:\users\megatron\appdata\roaming\SoftMaker
2011-05-21 09:57:32 -------- d-----w- c:\program files\SoftMaker Viewer
2011-05-21 09:57:00 98344 ----a-w- c:\windows\unTMV.exe
2011-05-21 09:33:38 652296 ----a-w- c:\programdata\microsoft\ehome\packages\sportstemplate\sportstemplatecore\Microsoft.MediaCenter.Sports.UI.dll
2011-05-21 09:26:26 749832 ----a-w- c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight\SpotlightResources.dll
2011-05-21 09:22:33 416128 ----a-w- c:\programdata\microsoft\ehome\packages\nettv\browse\NetTVResources.dll
2011-05-21 08:38:52 -------- d-----w- c:\program files\TrafficCompressor
2011-05-21 08:33:29 -------- d-----w- c:\users\megatron\appdata\roaming\Outertech
2011-05-21 08:28:28 -------- d-----w- c:\users\megatron\appdata\roaming\OpenOffice.org
2011-05-21 08:23:14 -------- d-----w- c:\program files\OpenOffice.org 3
2011-05-21 08:18:32 -------- d-----w- c:\users\megatron\appdata\roaming\CBS Interactive
2011-05-21 08:17:10 -------- d-----w- c:\program files\NETEagle
2011-05-21 08:15:39 -------- d-----w- c:\program files\ScummVM
2011-05-21 08:14:59 -------- d-----w- c:\program files\DOSBox-0.74
2011-05-21 06:52:19 -------- d-----w- c:\users\megatron\appdata\roaming\PeaZip
2011-05-21 06:49:39 -------- d-----w- c:\program files\IZArc
2011-05-21 06:48:40 -------- d-----w- c:\program files\PeaZip
2011-05-21 06:45:44 -------- d-----w- c:\programdata\IObit
2011-05-21 06:23:44 -------- d-----w- c:\program files\ESET
2011-05-21 06:09:55 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2011-05-21 06:03:11 -------- d-----w- c:\users\megatron\appdata\roaming\SUPERAntiSpyware.com
2011-05-21 06:03:11 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-05-21 06:02:54 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-05-21 05:57:59 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2011-05-21 05:57:57 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2011-05-21 05:57:54 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2011-05-21 05:57:54 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2011-05-21 05:57:50 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2011-05-21 05:55:13 70992 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2011-05-21 05:55:13 514384 ----a-w- c:\windows\system32\XAudio2_3.dll
2011-05-21 05:55:12 235856 ----a-w- c:\windows\system32\xactengine3_3.dll
2011-05-21 05:55:11 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2011-05-21 05:55:10 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2011-05-21 05:55:09 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2011-05-21 05:51:58 261480 ----a-w- c:\windows\system32\xactengine2_7.dll
2011-05-21 05:51:56 443752 ----a-w- c:\windows\system32\d3dx10_33.dll
2011-05-21 05:51:55 1123696 ----a-w- c:\windows\system32\D3DCompiler_33.dll
2011-05-21 05:51:52 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2011-05-21 05:51:49 255848 ----a-w- c:\windows\system32\xactengine2_6.dll
2011-05-21 05:51:47 251672 ----a-w- c:\windows\system32\xactengine2_5.dll
2011-05-21 05:51:46 440080 ----a-w- c:\windows\system32\d3dx10.dll
2011-05-21 05:51:44 237848 ----a-w- c:\windows\system32\xactengine2_4.dll
2011-05-21 05:51:44 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
2011-05-21 05:51:35 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2011-05-21 05:49:02 -------- d--h--w- c:\windows\msdownld.tmp
2011-05-21 05:48:39 -------- d-----w- c:\windows\system32\directx
2011-05-21 05:23:18 -------- d-----w- c:\program files\GetDiz
2011-05-21 05:12:50 -------- d-----w- c:\program files\common files\DivX Shared
2011-05-21 05:12:06 -------- d-----w- c:\program files\DivX
2011-05-21 05:06:24 -------- d-----w- c:\programdata\DivX
2011-05-21 05:01:14 -------- d-----w- c:\program files\NCH Software
2011-05-21 05:01:08 -------- d-----w- c:\users\megatron\appdata\roaming\NCH Software
2011-05-21 04:59:32 -------- d-----w- c:\users\megatron\appdata\roaming\AccurateRip
2011-05-21 04:59:30 6904040 ----a-w- c:\windows\system32\SpoonUninstall.exe
2011-05-21 04:59:02 -------- d-----w- c:\program files\Illustrate
2011-05-21 04:50:41 -------- d-----w- c:\users\megatron\appdata\roaming\IObit
2011-05-21 04:50:20 -------- d-----w- c:\program files\IObit
2011-05-21 04:43:50 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-05-21 04:43:50 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2011-05-21 04:42:31 -------- d-----w- c:\program files\iPod
2011-05-21 04:42:06 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-05-21 04:42:06 -------- d-----w- c:\program files\iTunes
2011-05-21 03:21:34 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-21 03:21:31 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-05-21 03:20:29 40112 ----a-w- c:\windows\avastSS.scr
2011-05-21 03:20:08 -------- d-----w- c:\programdata\AVAST Software
2011-05-21 03:20:08 -------- d-----w- c:\program files\AVAST Software
2011-05-21 03:08:57 -------- d-----w- c:\users\megatron\appdata\roaming\enchant
2011-05-21 03:08:54 -------- d-----w- c:\users\megatron\AbiSuite
2011-05-21 02:13:52 -------- d-----w- c:\program files\AbiWord
2011-05-21 01:49:29 -------- d-----w- c:\windows\en
2011-05-21 01:32:52 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-05-21 01:22:14 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-05-21 00:31:17 -------- d-----w- c:\users\megatron\appdata\roaming\kikin
2011-05-21 00:31:17 -------- d-----w- c:\programdata\boost_interprocess
2011-05-21 00:11:23 -------- d-----w- c:\windows\PCHEALTH
2011-05-20 23:50:42 -------- d-----w- c:\program files\Microsoft
2011-05-20 23:50:13 469256 ----a-w- c:\program files\common files\windows live\.cache\a793f8c31cc174804\InstallManager_WLE_WLE.exe
2011-05-20 23:44:30 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-05-20 23:44:30 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-05-20 23:44:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-05-20 23:44:24 15712 ----a-w- c:\program files\common files\windows live\.cache\d90391f31cc174703\MeshBetaRemover.exe
2011-05-20 23:44:20 94040 ----a-w- c:\program files\common files\windows live\.cache\d67ce7131cc174702\DSETUP.dll
2011-05-20 23:44:20 525656 ----a-w- c:\program files\common files\windows live\.cache\d67ce7131cc174702\DXSETUP.exe
2011-05-20 23:44:20 1691480 ----a-w- c:\program files\common files\windows live\.cache\d67ce7131cc174702\dsetup32.dll
2011-05-20 23:43:35 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2011-05-20 23:43:11 94040 ----a-w- c:\program files\common files\windows live\.cache\aca00b731cc174701\DSETUP.dll
2011-05-20 23:43:11 525656 ----a-w- c:\program files\common files\windows live\.cache\aca00b731cc174701\DXSETUP.exe
2011-05-20 23:43:11 1691480 ----a-w- c:\program files\common files\windows live\.cache\aca00b731cc174701\dsetup32.dll
2011-05-20 23:38:52 -------- d-----w- c:\users\megatron\appdata\local\Windows Live
2011-05-20 23:38:50 -------- d-----w- c:\program files\common files\Windows Live
2011-05-20 23:36:52 754688 ----a-w- c:\windows\system32\webservices.dll
2011-05-20 07:19:23 1071088 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2011-05-20 07:19:20 -------- d-----w- c:\program files\SpywareBlaster
2011-05-18 23:14:06 -------- d-----w- c:\users\megatron\appdata\local\Apple Computer
2011-05-18 21:56:38 -------- d-----w- c:\users\megatron\appdata\roaming\Songbird2
2011-05-18 21:56:38 -------- d-----w- c:\users\megatron\appdata\local\Songbird2
2011-05-18 21:48:40 -------- d-----w- c:\users\megatron\appdata\roaming\COWON
2011-05-18 21:43:22 -------- d-----w- c:\program files\common files\COWON
2011-05-18 21:43:20 -------- d-----w- c:\program files\JetAudio
2011-05-18 08:39:04 -------- d-----w- c:\program files\Songbird
2011-05-18 08:34:59 -------- d-----w- c:\program files\SiSoftware
2011-05-18 08:33:19 -------- d-----w- c:\program files\RAMDisk
2011-05-18 08:31:58 -------- d-----w- c:\program files\Lavalys
2011-05-18 08:31:26 -------- d-----w- c:\program files\Handbrake
2011-05-18 07:53:35 -------- d-----w- c:\program files\The KMPlayer
2011-05-18 07:52:34 -------- d-----w- c:\program files\Winamp Detect
2011-05-18 07:51:56 -------- d-----w- c:\program files\common files\PX Storage Engine
2011-05-17 00:42:37 -------- d-----w- c:\users\megatron\appdata\local\WindowsUpdate
2011-05-16 23:37:40 -------- d-----w- c:\users\megatron\appdata\roaming\HpUpdate
2011-05-16 23:37:30 -------- d-----w- c:\windows\Hewlett-Packard
2011-05-16 23:10:20 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2011-05-16 23:10:20 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2011-05-16 22:46:33 -------- d-----w- c:\windows\pss
2011-05-16 22:35:47 -------- d-----w- c:\users\megatron\appdata\roaming\Malwarebytes
2011-05-16 22:33:43 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-16 22:33:33 -------- d-----w- c:\programdata\Malwarebytes
2011-05-16 22:33:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-16 22:33:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-16 22:15:59 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-05-16 18:57:21 115920 ----a-w- c:\windows\system32\MSINET.OCX
2011-05-16 18:57:20 -------- d-----w- c:\program files\EULAlyzer
2011-05-16 18:55:50 -------- d-----w- c:\program files\Doc Scrubber
2011-05-16 18:54:34 -------- d-----w- C:\audiograbber
2011-05-16 18:36:37 -------- d-----w- c:\users\megatron\appdata\roaming\WinPatrol
2011-05-16 18:35:43 -------- d-----w- c:\programdata\InstallMate
2011-05-16 18:35:43 -------- d-----w- c:\program files\BillP Studios
2011-05-16 18:31:43 -------- d-----w- c:\users\megatron\appdata\roaming\AnvSoft
2011-05-16 18:31:22 -------- d-----w- c:\program files\AnvSoft
2011-05-16 03:44:10 -------- d-----w- c:\users\megatron\appdata\local\Eraser 6
2011-05-16 03:16:40 -------- d-----w- c:\program files\Windows Portable Devices
2011-05-16 03:12:47 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2011-05-16 03:12:46 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-05-16 03:12:45 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2011-05-16 03:11:48 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2011-05-16 03:11:44 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2011-05-16 03:11:44 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2011-05-16 03:11:44 252928 ----a-w- c:\windows\system32\dxdiag.exe
2011-05-16 03:11:44 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2011-05-16 03:11:44 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2011-05-16 03:11:43 519680 ----a-w- c:\windows\system32\d3d11.dll
2011-05-16 03:09:11 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-05-16 03:09:10 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-05-16 03:09:10 234496 ----a-w- c:\windows\system32\oleacc.dll
2011-05-16 02:58:13 797696 ----a-w- c:\windows\system32\FntCache.dll
2011-05-16 02:58:13 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-05-16 02:58:12 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-05-16 02:38:09 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-05-16 02:26:41 -------- d-----w- c:\program files\Eraser
2011-05-16 02:16:11 -------- d-----w- c:\program files\Speccy
2011-05-16 01:58:09 -------- d-----w- c:\windows\system32\eu-ES
2011-05-16 01:58:09 -------- d-----w- c:\windows\system32\ca-ES
2011-05-16 01:58:05 -------- d-----w- c:\windows\system32\vi-VN
2011-05-16 01:15:07 -------- d-----w- c:\windows\system32\EventProviders
2011-05-16 01:11:59 9090560 ----a-w- c:\program files\movie maker\OmdBase.dll
2011-05-16 01:10:59 852992 ----a-w- c:\windows\system32\mcmde.dll
2011-05-16 01:09:42 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2011-05-16 01:09:42 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-05-16 01:09:42 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-05-16 01:09:42 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2011-05-16 01:09:42 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2011-05-16 01:09:42 265728 ----a-w- c:\windows\system32\wbem\esscli.dll
2011-05-16 01:09:42 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2011-05-16 01:09:40 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2011-05-16 01:09:37 218624 ----a-w- c:\windows\system32\wdscore.dll
2011-05-16 01:09:37 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2011-05-16 01:09:22 247808 ----a-w- c:\windows\system32\drvstore.dll
2011-05-15 23:49:43 -------- d-----w- c:\program files\SpeedFan
2011-05-15 23:43:54 -------- d-----w- c:\program files\Unlocker
2011-05-15 23:43:01 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x32.sys
2011-05-15 23:42:56 -------- d-----w- c:\program files\CPUID
2011-05-15 23:22:04 94208 ----a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
2011-05-15 23:22:04 140864 ----a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
2011-05-15 23:21:57 -------- d-----w- c:\program files\Real Alternative
2011-05-15 22:52:37 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-05-15 22:52:36 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-05-15 22:52:36 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-05-15 22:52:35 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-05-15 22:52:34 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-05-15 22:40:32 125952 ----a-w- c:\windows\system32\srvsvc.dll
2011-05-15 22:40:31 17920 ----a-w- c:\windows\system32\netevent.dll
2011-05-15 22:37:01 377344 ----a-w- c:\windows\system32\winhttp.dll
2011-05-15 22:15:14 -------- d-----w- c:\program files\Audacity
2011-05-15 22:05:48 -------- d-----w- c:\users\megatron\appdata\local\Apple
2011-05-15 22:04:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-05-15 22:04:36 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-05-15 22:00:24 475648 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.scr
2011-05-15 22:00:24 1061888 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.exe
2011-05-15 22:00:23 -------- d-----w- c:\program files\MyDefrag v4.3.1
2011-05-15 21:51:57 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-05-15 21:51:56 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-15 10:58:02 -------- d-----w- c:\users\megatron\appdata\roaming\AIMP
2011-05-15 10:44:27 -------- d-----w- c:\program files\AIMP2
2011-05-15 10:35:43 -------- d-----w- c:\users\megatron\appdata\local\Seven Zip
2011-05-15 10:34:47 -------- d-----w- c:\program files\VS Revo Group
2011-05-15 10:33:20 -------- d-----w- c:\program files\CCleaner
2011-05-15 09:51:50 -------- d-----w- c:\windows\system32\Adobe
2011-05-15 08:48:45 -------- d-----w- c:\program files\Defraggler
2011-05-15 08:38:01 -------- d-----w- c:\users\megatron\appdata\local\Adobe
2011-05-15 06:30:47 -------- d-----w- c:\program files\VideoLAN
2011-05-15 05:59:56 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2011-05-15 05:12:08 7680 ----a-w- c:\program files\internet explorer\iecompat.dll
2011-05-15 05:09:24 265720 ----a-w- c:\program files\internet explorer\msdbg2.dll
2011-05-15 05:09:23 355832 ----a-w- c:\program files\internet explorer\pdm.dll
2011-05-15 04:26:12 24064 ----a-w- c:\windows\system32\nshhttp.dll
2011-05-15 04:26:07 411648 ----a-w- c:\windows\system32\drivers\http.sys
2011-05-15 04:26:07 30720 ----a-w- c:\windows\system32\httpapi.dll
2011-05-15 04:24:25 -------- d-----w- c:\program files\MSXML 4.0
2011-05-15 04:19:58 145408 ----a-w- c:\windows\system32\WsmAuto.dll
2011-05-15 04:19:57 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2011-05-15 04:19:57 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
2011-05-15 04:19:57 241152 ----a-w- c:\windows\system32\winrscmd.dll
2011-05-15 04:19:57 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2011-05-15 04:19:57 1181696 ----a-w- c:\windows\system32\WsmSvc.dll
2011-05-15 04:09:15 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-05-15 04:09:14 7680 ----a-w- c:\windows\system32\spwmp.dll
2011-05-15 04:09:14 4096 ----a-w- c:\windows\system32\msdxm.ocx
2011-05-15 04:09:14 4096 ----a-w- c:\windows\system32\dxmasf.dll
2011-05-15 04:09:14 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2011-05-15 04:09:14 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2011-05-15 04:09:13 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2011-05-15 04:08:49 128000 ----a-w- c:\windows\system32\spoolsv.exe
2011-05-15 04:08:45 413696 ----a-w- c:\windows\system32\odbc32.dll
2011-05-15 04:08:44 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-05-15 04:08:44 253952 ----a-w- c:\program files\common files\system\ado\msadox.dll
2011-05-15 04:08:43 57344 ----a-w- c:\program files\common files\system\msadc\msadcs.dll
2011-05-15 04:08:43 241664 ----a-w- c:\program files\common files\system\ado\msadomd.dll
2011-05-15 04:08:43 180224 ----a-w- c:\program files\common files\system\msadc\msadco.dll
2011-05-15 04:08:31 1696256 ----a-w- c:\windows\system32\gameux.dll
2011-05-15 04:08:19 3602320 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-15 04:08:18 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-05-15 04:08:16 1205080 ----a-w- c:\windows\system32\ntdll.dll
2011-05-15 04:07:43 105984 ----a-w- c:\windows\system32\netiohlp.dll
2011-05-15 04:07:42 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2011-05-15 04:07:42 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2011-05-15 04:07:42 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2011-05-15 04:07:42 19968 ----a-w- c:\windows\system32\ARP.EXE
2011-05-15 04:07:42 10240 ----a-w- c:\windows\system32\finger.exe
2011-05-15 04:07:41 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2011-05-15 04:07:41 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2011-05-15 04:05:37 1616384 ----a-w- c:\program files\windows mail\msoe.dll
2011-05-15 04:05:11 502272 ----a-w- c:\windows\system32\usp10.dll
2011-05-15 04:05:07 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-05-15 04:05:06 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-05-15 04:05:06 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-05-15 04:05:06 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-05-15 04:04:17 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-05-15 04:03:44 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2011-05-15 04:03:44 518144 ----a-w- c:\windows\system32\RMActivate.exe
2011-05-15 04:03:43 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2011-05-15 04:03:43 471552 ----a-w- c:\windows\system32\secproc.dll
2011-05-15 04:03:42 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2011-05-15 04:03:42 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2011-05-15 04:03:41 332288 ----a-w- c:\windows\system32\msdrm.dll
2011-05-15 04:03:41 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2011-05-15 04:03:41 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2011-05-15 04:00:38 6656 ----a-w- c:\windows\system32\kbd106n.dll
2011-05-15 03:57:58 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2011-05-15 03:57:50 43520 ----a-w- c:\windows\system32\msdxm.tlb
2011-05-15 03:57:50 18432 ----a-w- c:\windows\system32\amcompat.tlb
2011-05-15 03:57:40 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2011-05-15 03:57:39 499712 ----a-w- c:\windows\system32\kerberos.dll
2011-05-15 03:57:38 175104 ----a-w- c:\windows\system32\wdigest.dll
2011-05-15 03:57:36 72704 ----a-w- c:\windows\system32\secur32.dll
2011-05-15 03:57:36 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2011-05-15 03:57:35 9728 ----a-w- c:\windows\system32\lsass.exe
2011-05-15 03:56:04 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2011-05-15 03:56:04 24576 ----a-w- c:\windows\system32\mfpmp.exe
2011-05-15 03:56:04 2048 ----a-w- c:\windows\system32\mferror.dll
2011-05-15 03:55:55 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-05-15 03:55:54 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-05-15 03:55:09 160256 ----a-w- c:\windows\system32\wkssvc.dll
2011-05-15 03:55:00 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-05-15 03:55:00 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-05-15 03:53:26 601600 ----a-w- c:\windows\system32\schedsvc.dll
2011-05-15 03:53:25 352768 ----a-w- c:\windows\system32\taskschd.dll
2011-05-15 03:53:25 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-05-15 03:53:24 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-05-15 03:53:24 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-05-15 03:53:19 157184 ----a-w- c:\windows\system32\t2embed.dll
2011-05-15 03:53:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
2011-05-15 03:52:48 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-05-15 03:52:27 -------- d-----w- c:\users\megatron\dwhelper
2011-05-15 03:52:11 305152 ----a-w- c:\windows\system32\drivers\srv.sys
2011-05-15 03:52:11 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-05-15 03:52:11 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-05-15 03:52:07 71680 ----a-w- c:\windows\system32\atl.dll
2011-05-15 03:49:37 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2011-05-15 03:49:24 623616 ----a-w- c:\windows\system32\localspl.dll
2011-05-15 03:47:36 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-05-15 03:47:36 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-05-15 03:47:35 63488 ----a-w- c:\windows\system32\tscupgrd.exe
2011-05-15 03:47:35 53248 ----a-w- c:\windows\system32\tsgqec.dll
2011-05-15 03:47:35 136192 ----a-w- c:\windows\system32\aaclient.dll
2011-05-15 03:47:03 714240 ----a-w- c:\windows\system32\timedate.cpl
2011-05-15 03:46:29 10926592 ----a-w- c:\program files\movie maker\MOVIEMK.dll
2011-05-15 03:46:26 23040 ----a-w- c:\program files\movie maker\WMM2EXT.dll
2011-05-15 03:46:26 195072 ----a-w- c:\program files\movie maker\WMM2AE.dll
2011-05-15 03:46:26 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe
2011-05-15 03:44:45 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-05-15 03:44:36 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-05-15 03:44:36 322560 ----a-w- c:\windows\system32\sbe.dll
2011-05-15 03:44:36 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2011-05-15 03:44:36 153088 ----a-w- c:\windows\system32\sbeio.dll
2011-05-15 03:44:25 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-15 03:44:21 867328 ----a-w- c:\windows\system32\wmpmde.dll
2011-05-15 03:44:10 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2011-05-15 03:44:07 62464 ----a-w- c:\windows\system32\l3codeca.acm
2011-05-15 03:44:07 220672 ----a-w- c:\windows\system32\l3codecp.acm
2011-05-15 03:44:01 243712 ----a-w- c:\windows\system32\rastls.dll
2011-05-15 03:43:58 355328 ----a-w- c:\windows\system32\WSDApi.dll
2011-05-15 03:43:55 36864 ----a-w- c:\windows\system32\rtutils.dll
2011-05-15 03:43:50 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-05-15 03:43:49 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2011-05-15 03:43:40 81920 ----a-w- c:\windows\system32\consent.exe
2011-05-15 03:43:27 2048 ----a-w- c:\windows\system32\tzres.dll
2011-05-15 03:42:42 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2011-05-15 03:42:28 531968 ----a-w- c:\windows\system32\comctl32.dll
2011-05-15 03:42:02 60928 ----a-w- c:\windows\system32\msasn1.dll
2011-05-15 03:35:59 -------- d-----w- c:\program files\FileHippo.com
2011-05-15 03:30:48 1418752 ----a-w- c:\program files\windows media player\setup_wm.exe
2011-05-15 03:30:47 310784 ----a-w- c:\windows\system32\unregmp2.exe
2011-05-15 03:22:16 2421760 ----a-w- c:\windows\system32\wucltux.dll
2011-05-15 03:21:40 87552 ----a-w- c:\windows\system32\wudriver.dll
2011-05-15 03:21:18 33792 ----a-w- c:\windows\system32\wuapp.exe
2011-05-15 03:21:18 171608 ----a-w- c:\windows\system32\wuwebv.dll
2011-05-15 03:17:12 -------- d-----w- c:\users\megatron\appdata\roaming\Abine
2011-05-15 03:15:06 -------- d-----w- c:\users\megatron\appdata\local\Mozilla
2011-05-15 02:49:22 -------- d-----w- c:\program files\uTorrent
2011-05-15 02:49:20 98304 ----a-w- c:\windows\system32\cabview.dll
2011-05-15 02:47:19 -------- d-----w- c:\users\megatron\appdata\roaming\uTorrent
2011-05-15 02:44:34 172032 ----a-w- c:\windows\system32\wintrust.dll
2011-05-15 02:30:59 2730536 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2011-05-15 02:30:46 7071056 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{96bad026-61ae-4bf2-a978-452c242d1ba8}\mpengine.dll
2011-05-15 02:30:41 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-15 02:29:56 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-12 21:53:04 -------- d-----w- c:\users\megatron\appdata\local\Hewlett-Packard
2011-05-12 03:16:34 -------- d-----w- C:\Westwood
2011-05-12 03:15:16 299520 ----a-w- c:\windows\uninst.exe
2011-05-12 03:06:17 -------- d-----w- c:\programdata\LightScribe
2011-05-12 02:38:13 -------- d-----w- c:\users\megatron\appdata\local\QuickPlay
2011-05-12 02:37:55 -------- d-----w- c:\users\megatron\appdata\roaming\Symantec
2011-05-12 02:36:49 -------- d-----w- c:\users\megatron\appdata\local\VirtualStore
2011-05-12 02:33:08 -------- d-----w- c:\program files\Yahoo!
2011-05-12 02:31:24 -------- d-----w- c:\users\megatron\appdata\local\Downloaded Installations
2011-05-12 02:25:35 -------- d-----w- c:\program files\HPQ
2011-05-12 02:20:49 -------- d-sh--we C:\Documents and Settings
.
==================== Find3M ====================
.
2011-03-29 08:00:00 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2011-03-24 19:35:18 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2011-03-24 19:28:12 631808 ----a-w- c:\windows\system32\xvidcore.dll
2011-03-19 19:00:38 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-03-10 17:03:51 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03:51 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-03-05 10:47:16 122368 ----a-w- c:\windows\system32\lagarith.dll
2011-03-03 18:29:52 2712064 ----a-w- c:\windows\system32\x264vfw.dll
2011-03-03 15:40:07 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40:05 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40:05 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40:04 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-03-02 10:43:46 175616 ----a-w- c:\windows\system32\unrar.dll
.
============= FINISH: 9:34:00.29 ===============

Edit
Previously: http://forums.spybot.info/showthread.php?t=61914

Torrents/P2P: File Sharing, otherwise known as Peer To Peer. (P2P) (http://forums.spybot.info/showthread.php?t=282)

Forum FAQ: "BEFORE You POST"(Please read this Procedure Before Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Removed logs not requested in FAQ.

shelf life
2011-06-04, 01:32
hi Jack421,

I dont see anything relating to billeo in the log, maybe I am missing it. In any case if your AV and antimalware apps come up clean then its probably not much to worry about, unless its this. (https://www.billeo.com/) Personally i have a distrust of any toolbar.