joemamma
2011-07-15, 04:04
100% CPU when booting normally. No problems when in safe mode. I have run malware bytes in safe mode, it removed 37 infeections. I have run it again and it finds nothing. Microsfot security essentials finds nothing.
DDS (Ver_2011-07-14.01) - NTFS_x86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by Barb at 20:56:18 on 2011-07-14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1271.880 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://login.yahoo.com/
uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
uProxyOverride = <local>;*.local
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Real.com: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [Dell Wireless Manager UI] c:\windows\system32\WLTRAY
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
StartupFolder: c:\docume~1\barb\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-System: EnableProfileQuota = dword:1
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {1BA7BD5D-2BE1-4C06-A53F-632BD1C003BA} - hxxps://vpn.johnseastern.com/ISBinstaller.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
TCP: NameServer = 65.32.5.111 65.32.5.112
TCP: Interfaces\{2EB84B37-4CD4-4635-B607-506356D57A2E} : DHCPNameServer = 65.32.5.111 65.32.5.112
Filter: text/html - {500dadd4-30cc-4243-ad52-3e4cd414c023} -
Handler: ipp - <Clsid value has no data>
Handler: msdaipp - <Clsid value has no data>
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "c:\program files\outlook express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "c:\program files\outlook express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
IFEO: Your Image File Name Here without a path - ntsd -d
.
============= SERVICES / DRIVERS ===============
.
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys --> c:\windows\system32\drivers\ctxusbm.sys [?]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-7-24 24652]
S2 wsnm;VMware View Client Service;c:\program files\vmware\vmware view\client\bin\wsnm.exe [2009-7-2 151552]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [2011-7-10 30576]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-10 14336]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [2009-6-15 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2009-6-3 174720]
.
=============== Created Last 30 ================
.
2011-07-14 22:28:38 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-07-14 01:42:01 139264 ----a-w- c:\windows\system32\igfxres.dll
2011-07-12 00:24:03 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-07-12 00:23:24 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d2fbb9c7-5b5a-4d05-b413-0dc80a361cea}\mpengine.dll
2011-07-11 23:46:36 -------- d-----w- C:\Intel
2011-07-11 22:59:25 666 ----a-w- c:\windows\speed.reg
2011-07-11 22:48:27 42858 ----a-w- c:\windows\system32\hsfci014.dll
2011-07-11 22:48:27 1033728 ----a-w- c:\windows\system32\drivers\HSF_DPV.SYS
2011-07-11 22:40:53 733184 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iKernel.dll
2011-07-11 22:40:53 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\ctor.dll
2011-07-11 22:40:53 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\DotNetInstaller.exe
2011-07-11 22:40:53 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iscript.dll
2011-07-11 22:40:53 180356 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iGdi.dll
2011-07-11 22:40:53 172032 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iuser.dll
2011-07-11 22:40:52 303104 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\setup.dll
2011-07-11 00:22:52 78704 ----a-w- c:\windows\system32\nx6000res.dll
2011-07-11 00:22:52 636784 ----a-w- c:\windows\system32\LCCoin36.dll
2011-07-11 00:22:52 514416 ----a-w- c:\windows\system32\LcProxy2.ax
2011-07-11 00:22:52 30576 ----a-w- c:\windows\system32\drivers\nx6000.sys
2011-07-11 00:22:22 -------- d-----w- c:\program files\Microsoft LifeCam
2011-07-11 00:21:54 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-07-11 00:21:47 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-07-11 00:21:19 -------- d-----w- c:\windows\Logs
2011-07-10 17:20:12 -------- d-----w- c:\program files\CONEXANT
2011-07-10 13:52:04 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-10 13:45:21 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-09 19:46:41 954368 ------w- c:\windows\system32\dllcache\mfc40.dll
2011-07-09 19:46:37 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2011-07-09 19:46:33 978944 ------w- c:\windows\system32\dllcache\mfc42.dll
2011-07-09 19:29:47 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2011-07-09 19:27:28 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-07-09 19:24:43 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-07-09 19:14:22 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-07-09 14:53:00 33664 ----a-w- c:\windows\system32\drivers\BCMWLNPF.SYS
2011-07-09 14:52:59 86016 ----a-w- c:\windows\system32\preflib.dll
2011-07-09 14:52:57 69632 ----a-w- c:\windows\system32\bcmwlpkt.dll
2011-07-09 14:52:56 757760 ----a-w- c:\windows\system32\bcm1xsup.dll
2011-07-09 14:52:56 2129920 ----a-w- c:\windows\system32\WLBCGCBPRO731.DLL
2011-07-08 02:13:12 16384 ----a-w- c:\windows\system32\ipsink.ax
2011-07-08 02:13:12 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2011-07-08 02:12:55 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2011-07-08 02:12:47 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2011-07-08 02:12:39 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2011-07-08 02:12:30 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2011-07-08 02:12:21 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2011-07-08 02:12:11 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2011-07-08 02:09:14 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2011-07-08 02:09:07 91136 ----a-w- c:\windows\system32\kswdmcap.ax
2011-07-08 02:09:07 61952 ----a-w- c:\windows\system32\kstvtune.ax
2011-07-08 02:09:07 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2011-07-08 02:09:07 20992 ----a-w- c:\windows\system32\dshowext.ax
2011-07-08 02:09:06 43008 ----a-w- c:\windows\system32\ksxbar.ax
2011-07-07 02:58:59 69120 ------w- c:\windows\system32\wlanapi.dll
2011-07-07 02:58:58 32866 ------w- c:\windows\slrundll.exe
2011-07-07 02:58:57 -------- d-----w- c:\windows\system32\scripting
2011-07-07 02:58:56 -------- d-----w- c:\windows\l2schemas
2011-07-07 02:58:55 -------- d-----w- c:\windows\system32\en
2011-07-07 02:58:55 -------- d-----w- c:\windows\system32\bits
2011-07-07 02:48:42 19569 ----a-w- c:\windows\003014_.tmp
2011-07-07 02:48:32 36096 ----a-w- c:\windows\system32\drivers\intelppm.sys
2011-07-07 02:48:32 36096 ----a-w- c:\windows\system32\dllcache\intelppm.sys
2011-07-07 02:43:00 -------- d-----w- c:\windows\EHome
2011-07-07 01:02:06 -------- d-----w- c:\windows\system32\XPSViewer
2011-07-07 01:00:44 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-07-07 01:00:26 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-07-07 01:00:26 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-07-07 01:00:26 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-07-07 01:00:26 575488 ------w- c:\windows\system32\xpsshhdr.dll
2011-07-07 01:00:26 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-07-07 01:00:26 1676288 ------w- c:\windows\system32\xpssvcs.dll
2011-07-07 01:00:26 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2011-07-07 01:00:26 117760 ------w- c:\windows\system32\prntvpt.dll
2011-07-07 01:00:25 -------- d-----w- C:\26e0381c782f070f733610226a8ba6
2011-07-07 00:51:41 -------- d-----w- c:\program files\MSXML 6.0
2011-07-05 18:15:11 -------- d-----w- c:\program files\Zone Labs
2011-07-05 18:15:11 -------- d-----w- c:\documents and settings\barb\application data\ZoneLabs
2011-07-04 22:52:14 -------- d-----w- c:\documents and settings\barb\local settings\application data\LogMeIn
2011-07-04 22:52:14 -------- d-----w- c:\documents and settings\all users\application data\LogMeIn
.
==================== Find3M ====================
.
2011-07-09 19:15:42 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-06 23:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-22 21:27:25 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-22 21:27:25 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07:50 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-26 11:07:50 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-04-25 16:11:12 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
2011-04-18 17:18:50 165648 ----a-w- c:\windows\system32\drivers\MpFilter.sys
.
============= FINISH: 20:57:38.93 ===============
DDS (Ver_2011-07-14.01) - NTFS_x86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by Barb at 20:56:18 on 2011-07-14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1271.880 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://login.yahoo.com/
uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
uProxyOverride = <local>;*.local
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Real.com: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [Dell Wireless Manager UI] c:\windows\system32\WLTRAY
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
StartupFolder: c:\docume~1\barb\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-System: EnableProfileQuota = dword:1
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {1BA7BD5D-2BE1-4C06-A53F-632BD1C003BA} - hxxps://vpn.johnseastern.com/ISBinstaller.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
TCP: NameServer = 65.32.5.111 65.32.5.112
TCP: Interfaces\{2EB84B37-4CD4-4635-B607-506356D57A2E} : DHCPNameServer = 65.32.5.111 65.32.5.112
Filter: text/html - {500dadd4-30cc-4243-ad52-3e4cd414c023} -
Handler: ipp - <Clsid value has no data>
Handler: msdaipp - <Clsid value has no data>
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "c:\program files\outlook express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "c:\program files\outlook express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
IFEO: Your Image File Name Here without a path - ntsd -d
.
============= SERVICES / DRIVERS ===============
.
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys --> c:\windows\system32\drivers\ctxusbm.sys [?]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-7-24 24652]
S2 wsnm;VMware View Client Service;c:\program files\vmware\vmware view\client\bin\wsnm.exe [2009-7-2 151552]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [2011-7-10 30576]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-10 14336]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [2009-6-15 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2009-6-3 174720]
.
=============== Created Last 30 ================
.
2011-07-14 22:28:38 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-07-14 01:42:01 139264 ----a-w- c:\windows\system32\igfxres.dll
2011-07-12 00:24:03 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-07-12 00:23:24 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d2fbb9c7-5b5a-4d05-b413-0dc80a361cea}\mpengine.dll
2011-07-11 23:46:36 -------- d-----w- C:\Intel
2011-07-11 22:59:25 666 ----a-w- c:\windows\speed.reg
2011-07-11 22:48:27 42858 ----a-w- c:\windows\system32\hsfci014.dll
2011-07-11 22:48:27 1033728 ----a-w- c:\windows\system32\drivers\HSF_DPV.SYS
2011-07-11 22:40:53 733184 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iKernel.dll
2011-07-11 22:40:53 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\ctor.dll
2011-07-11 22:40:53 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\DotNetInstaller.exe
2011-07-11 22:40:53 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iscript.dll
2011-07-11 22:40:53 180356 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iGdi.dll
2011-07-11 22:40:53 172032 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iuser.dll
2011-07-11 22:40:52 303104 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\setup.dll
2011-07-11 00:22:52 78704 ----a-w- c:\windows\system32\nx6000res.dll
2011-07-11 00:22:52 636784 ----a-w- c:\windows\system32\LCCoin36.dll
2011-07-11 00:22:52 514416 ----a-w- c:\windows\system32\LcProxy2.ax
2011-07-11 00:22:52 30576 ----a-w- c:\windows\system32\drivers\nx6000.sys
2011-07-11 00:22:22 -------- d-----w- c:\program files\Microsoft LifeCam
2011-07-11 00:21:54 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-07-11 00:21:47 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-07-11 00:21:19 -------- d-----w- c:\windows\Logs
2011-07-10 17:20:12 -------- d-----w- c:\program files\CONEXANT
2011-07-10 13:52:04 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-10 13:45:21 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-09 19:46:41 954368 ------w- c:\windows\system32\dllcache\mfc40.dll
2011-07-09 19:46:37 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2011-07-09 19:46:33 978944 ------w- c:\windows\system32\dllcache\mfc42.dll
2011-07-09 19:29:47 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2011-07-09 19:27:28 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-07-09 19:24:43 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-07-09 19:14:22 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-07-09 14:53:00 33664 ----a-w- c:\windows\system32\drivers\BCMWLNPF.SYS
2011-07-09 14:52:59 86016 ----a-w- c:\windows\system32\preflib.dll
2011-07-09 14:52:57 69632 ----a-w- c:\windows\system32\bcmwlpkt.dll
2011-07-09 14:52:56 757760 ----a-w- c:\windows\system32\bcm1xsup.dll
2011-07-09 14:52:56 2129920 ----a-w- c:\windows\system32\WLBCGCBPRO731.DLL
2011-07-08 02:13:12 16384 ----a-w- c:\windows\system32\ipsink.ax
2011-07-08 02:13:12 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2011-07-08 02:12:55 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2011-07-08 02:12:47 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2011-07-08 02:12:39 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2011-07-08 02:12:30 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2011-07-08 02:12:21 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2011-07-08 02:12:11 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2011-07-08 02:09:14 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2011-07-08 02:09:07 91136 ----a-w- c:\windows\system32\kswdmcap.ax
2011-07-08 02:09:07 61952 ----a-w- c:\windows\system32\kstvtune.ax
2011-07-08 02:09:07 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2011-07-08 02:09:07 20992 ----a-w- c:\windows\system32\dshowext.ax
2011-07-08 02:09:06 43008 ----a-w- c:\windows\system32\ksxbar.ax
2011-07-07 02:58:59 69120 ------w- c:\windows\system32\wlanapi.dll
2011-07-07 02:58:58 32866 ------w- c:\windows\slrundll.exe
2011-07-07 02:58:57 -------- d-----w- c:\windows\system32\scripting
2011-07-07 02:58:56 -------- d-----w- c:\windows\l2schemas
2011-07-07 02:58:55 -------- d-----w- c:\windows\system32\en
2011-07-07 02:58:55 -------- d-----w- c:\windows\system32\bits
2011-07-07 02:48:42 19569 ----a-w- c:\windows\003014_.tmp
2011-07-07 02:48:32 36096 ----a-w- c:\windows\system32\drivers\intelppm.sys
2011-07-07 02:48:32 36096 ----a-w- c:\windows\system32\dllcache\intelppm.sys
2011-07-07 02:43:00 -------- d-----w- c:\windows\EHome
2011-07-07 01:02:06 -------- d-----w- c:\windows\system32\XPSViewer
2011-07-07 01:00:44 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-07-07 01:00:26 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-07-07 01:00:26 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-07-07 01:00:26 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-07-07 01:00:26 575488 ------w- c:\windows\system32\xpsshhdr.dll
2011-07-07 01:00:26 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-07-07 01:00:26 1676288 ------w- c:\windows\system32\xpssvcs.dll
2011-07-07 01:00:26 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2011-07-07 01:00:26 117760 ------w- c:\windows\system32\prntvpt.dll
2011-07-07 01:00:25 -------- d-----w- C:\26e0381c782f070f733610226a8ba6
2011-07-07 00:51:41 -------- d-----w- c:\program files\MSXML 6.0
2011-07-05 18:15:11 -------- d-----w- c:\program files\Zone Labs
2011-07-05 18:15:11 -------- d-----w- c:\documents and settings\barb\application data\ZoneLabs
2011-07-04 22:52:14 -------- d-----w- c:\documents and settings\barb\local settings\application data\LogMeIn
2011-07-04 22:52:14 -------- d-----w- c:\documents and settings\all users\application data\LogMeIn
.
==================== Find3M ====================
.
2011-07-09 19:15:42 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-06 23:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-22 21:27:25 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-22 21:27:25 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07:50 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-26 11:07:50 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-04-25 16:11:12 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
2011-04-18 17:18:50 165648 ----a-w- c:\windows\system32\drivers\MpFilter.sys
.
============= FINISH: 20:57:38.93 ===============