twc500
2011-09-10, 13:18
Having some issues with browser search redirects. S&D found Win32.AVKillsvc.e - I can only remove it in Safe Mode and it continues to return. Over the past few days, my son has added Avast!, Malwarebytes, SuperAntiSpyware to try and clean it out - but it only shows up in S&D.
Please let me know if there is any additional information I can provide. Thanks in advance for your assistence!
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by tdks Crowder at 5:18:24 on 2011-09-10
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2013 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe
c:\hp\HPEZBTN\HPBtnSrv.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\ZuneLauncher.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames2.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\hp\kbd\kbd.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = local;*.local
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
uRun: [BTBFirstRun] C:\Program Files (x86)\Hewlett-Packard\SDP\hprun.exe
uRun: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] C:\HP\KBD\KbdStub.EXE
mRun: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [QuickTime Task] "C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
StartupFolder: C:\Users\TDKSCR~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\REGIST~1.LNK - C:\Program Files (x86)\Steam\steamapps\common\assassins creed\Register\RegistrationReminder.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
LSP: mswsock.dll
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {23A2712A-7A4F-4D0C-822C-D7BA9974447B} - hxxps://registration.rr.com/RegHelper.cab
DPF: {2703049B-D81D-4763-A3C6-AF8932FCBD8F} - hxxps://am.hrblock.com/ActivexComponent/CheckFileStatus.CAB
DPF: {3A52566B-6018-485B-B713-8B9FF660D8E8} - hxxp://dvr.mailender.com/webdvr2.4.9.2_0.0.0.0.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {6F750203-1362-4815-A476-88533DE61D0C} - hxxp://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} - hxxp://offers.e-centives.com/cif/download/bin/actxcab.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
TCP: Interfaces\{5699578E-7FB8-42EF-B610-3841AFC3622F} : DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
TCP: Interfaces\{A867BC74-A81B-4049-BF6E-D06D5204C3BF} : DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2
BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-X64: 0x1 - No File
BHO-X64: HP Print Clips: {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB-X64: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
mRun-x64: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun-x64: [KBD] C:\HP\KBD\KbdStub.EXE
mRun-x64: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [QuickTime Task] "C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\components\coFFPlgn.dll
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\components\IPSFFPl.dll
FF - component: C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - component: C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
FF - component: C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\tdks Crowder\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
FF - plugin: C:\Users\tdks Crowder\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin2.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin3.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin4.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin5.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin6.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin7.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2008-1-20 21504]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-9-1 44768]
R2 DAUpdaterSvc;Dragon Age: Origins - Content Updater;C:\Program Files (x86)\Steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe [2010-12-27 25832]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 HPBtnSrv;HP Chasis Button Service;C:\hp\HPEZBTN\HPBtnSrv.exe [2008-2-22 198240]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-9-1 366640]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;C:\Program Files (x86)\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-3-12 86016]
R2 mi-raysat_3dsmax2010_64;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 64-bit 64-bit;C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe [2009-3-12 86016]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-7-23 2218600]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-9-3 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-4-7 378472]
R3 CAXHWBS2;CAXHWBS2;C:\Windows\system32\DRIVERS\CAXHWBS2.sys --> C:\Windows\system32\DRIVERS\CAXHWBS2.sys [?]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys --> C:\Windows\system32\drivers\HCW85BDA.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 netr7364;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr7364.sys --> C:\Windows\system32\DRIVERS\netr7364.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-30 135664]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-11-3 1030600]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-30 135664]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-8-7 89920]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x64\msvsmon.exe [2005-9-23 4476096]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-09-10 09:01:12 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{A3D5EEFE-EF2D-4CE1-9A88-3865DF14BFFF}
2011-09-10 08:35:08 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{DAEDB556-B094-41B2-9422-6DDB5C40FA37}
2011-09-10 08:34:44 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{A8438258-54D1-4C1B-A052-EABD807E6CF6}
2011-09-09 21:53:48 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{43B6DC40-A777-4069-9932-37CB043DE012}\mpengine.dll
2011-09-09 20:13:13 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{5AD560E5-5717-4B26-8250-5C78EABDF5A0}
2011-09-09 20:12:53 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{2F4D34E8-FB84-4AAD-BE00-671A12523BA0}
2011-09-09 11:32:11 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{5A8EFB3D-990D-4DE8-931F-DDAE97949888}
2011-09-09 11:31:52 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{B8E700A5-03E1-4B5F-841D-60E71C4D8D02}
2011-09-08 11:34:34 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{E4F8CE96-0F8F-4EC2-B5B2-463E1F7CB2B6}
2011-09-08 11:34:14 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{6B483089-396F-40F6-9A2E-F977D97716A8}
2011-09-08 04:16:20 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{A4E72C9F-70D6-44A4-BEE6-1B2229B7D192}
2011-09-08 04:15:59 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{1816919E-9808-4553-BE1D-3219687C7417}
2011-09-07 11:35:28 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{096B3BD4-2F34-4138-B613-C8BA5799B9C3}
2011-09-07 11:35:09 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{957BA671-6535-4AF2-B2A2-BAB2256A3319}
2011-09-06 23:22:27 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{EB30F509-E071-4369-9271-3D0C07F946A9}
2011-09-06 23:22:06 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{320EB5CC-E687-43DA-A2F4-4167AE93C33B}
2011-09-06 12:29:55 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{68CE42F8-A987-4588-ACBD-BC190428F168}
2011-09-06 12:29:34 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{42DDA249-F384-43FD-992D-891A90398D88}
2011-09-05 18:37:10 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{208C3534-CDF1-49E7-A049-D74352B3A2D6}
2011-09-05 16:53:56 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{2E34C2CE-1834-4B68-9273-AE358E8650AB}
2011-09-05 13:29:33 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{D4DCD22E-843F-45BA-BAA1-E7AA8D20B12E}
2011-09-05 13:29:08 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8888CA5C-F342-404C-9FAB-F79777315A14}
2011-09-04 12:50:17 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{1516BBE3-F218-4CBB-AA39-FF7968A787BE}
2011-09-04 12:49:56 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8B7B549F-FEAF-43CC-9557-8698E947C040}
2011-09-03 15:46:58 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{1C7814A6-E9AC-42E7-94C3-EB0548A527C4}
2011-09-03 15:46:38 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8FE6C1EA-C253-4FAC-A2CA-A52C497086D8}
2011-09-03 15:40:48 0 ---ha-w- C:\Users\tdks Crowder\AppData\Local\BIT257A.tmp
2011-09-03 14:35:01 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{2B1B0109-9329-4C85-A7A7-9CAA2F6CDDC6}
2011-09-03 14:34:40 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{F7679B4E-A3FD-4FA2-ABFB-C6FD704546AF}
2011-09-03 12:27:07 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-09-03 12:27:07 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-09-03 11:48:55 388096 ----a-r- C:\Users\tdks Crowder\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-03 11:48:54 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-09-03 11:44:50 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{03AA2363-0E0A-4756-993B-7F34D171A892}
2011-09-03 11:44:27 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{AC8B1C19-1984-46DA-8C8F-4095D3742F02}
2011-09-02 22:28:40 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{5865E48E-5451-4EC5-A1E0-3D834F9A37AE}
2011-09-02 22:28:21 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{1AEFBFD2-CE7A-47C2-9F61-57E72711D421}
2011-09-02 18:05:04 525792 ----a-w- C:\Windows\DIFxAPI.dll
2011-09-02 16:00:03 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\SUPERAntiSpyware.com
2011-09-02 15:59:47 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-09-02 15:59:47 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-09-02 07:05:05 -------- d-----w- C:\Program Files\CCleaner
2011-09-02 05:44:57 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{7853F4A8-7BB9-4F27-AE64-504CD3D8DA28}
2011-09-02 00:47:44 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{C1262D04-A80F-4C2C-A920-246B36DFC809}
2011-09-02 00:47:24 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{92C1B108-D212-4246-B81A-5DB8DDD4DF72}
2011-09-02 00:32:07 65368 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-09-02 00:32:07 601944 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-09-02 00:31:59 41184 ----a-w- C:\Windows\avastSS.scr
2011-09-02 00:31:53 -------- d-----w- C:\ProgramData\AVAST Software
2011-09-02 00:31:53 -------- d-----w- C:\Program Files\AVAST Software
2011-09-01 17:58:49 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\Malwarebytes
2011-09-01 17:58:45 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-09-01 17:58:44 -------- d-----w- C:\ProgramData\Malwarebytes
2011-09-01 17:58:42 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-09-01 17:58:42 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-09-01 17:44:50 0 ---ha-w- C:\Users\tdks Crowder\AppData\Local\BIT4E01.tmp
2011-09-01 17:44:13 0 ---ha-w- C:\Users\tdks Crowder\AppData\Local\BITBDA3.tmp
2011-09-01 07:40:37 -------- d-----we C:\Windows\system64
2011-08-30 23:07:05 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{B0662B53-D854-48F2-898D-19280BFEB74B}
2011-08-30 23:06:55 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{B1A210B4-D9F2-41DB-BDF2-2D4C726D8511}
2011-08-30 08:46:12 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{3A2E8D85-8A5B-429D-A29F-8E95C42F5E8D}
2011-08-30 08:46:00 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{ADDC9AD0-6460-404D-B99F-9ED3082980AC}
2011-08-29 10:18:07 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{EBE9D8C2-6ED3-4B26-9911-C917A4B6FF7F}
2011-08-29 10:17:57 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{57430A50-0003-4BDF-9AC5-CFF998B7FC12}
2011-08-26 13:12:53 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{98596A08-1E47-4AC5-B189-55C1737F18E3}
2011-08-26 13:12:42 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{A341932A-DB98-4F42-89A0-5D524868DC49}
2011-08-25 10:18:53 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{67D8F73F-F45F-4068-B9AB-AA3A1F1275A2}
2011-08-24 16:24:06 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-24 16:24:06 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-24 11:33:35 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8C66FD12-7854-4E2A-945C-4A0DAF718244}
2011-08-24 11:33:25 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{F74F4913-D14D-427B-9595-5650DD1C54D5}
2011-08-19 07:40:21 -------- d-----w- C:\Users\tdks Crowder\riotsGamesLogs
2011-08-19 07:29:50 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\LolClient
2011-08-19 06:24:18 -------- d-----w- C:\Riot Games
2011-08-19 05:55:24 -------- d-----w- C:\Program Files (x86)\LeagueOfLegends
2011-08-18 20:25:38 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{5DD5884C-FD76-4108-A1B3-B10DCFAF3F45}
2011-08-18 20:25:25 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{3EAC0275-3A0E-44FC-A388-CBEBCC83DDC7}
2011-08-18 20:14:56 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{7616E970-54B1-49E3-B6A7-86233A659BA6}
2011-08-18 20:14:42 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{BD73A831-A774-4DE1-BAE7-F0979D356C87}
2011-08-16 23:43:37 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-08-16 23:43:37 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-08-14 16:09:17 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8C464AA0-E910-46F8-8E14-C46E71D308B4}
2011-08-14 16:09:07 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{2D0BAFD2-2954-4DF6-9824-38796C7591DF}
2011-08-14 05:40:09 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\Ubisoft Game Launcher
2011-08-13 23:07:03 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\Braid
2011-08-13 15:54:09 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\Crayon Physics Deluxe
2011-08-12 21:05:16 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\Lazy 8 Studios
2011-08-12 15:05:05 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{4751B4DC-C0D9-49DF-9A2B-2849BDB951B5}
2011-08-12 15:04:54 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{7A4F6057-3843-49D0-9E1F-58B563EE2907}
2011-08-11 21:39:10 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\runic games
2011-08-11 13:06:03 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{4A4E59CF-9ED0-4D72-8A25-5305904B411C}
2011-08-11 13:05:53 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{C28C9584-C45C-4061-99BD-D1180434DE80}
.
==================== Find3M ====================
.
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-06 15:49:23 275456 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-06-20 08:45:17 4699536 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-17 20:14:30 1427344 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-06-17 16:16:33 451072 ----a-w- C:\Windows\System32\winsrv.dll
2010-01-07 19:27:16 997184 ----a-w- C:\Program Files (x86)\ZuneDBApi.dll
2010-01-07 19:27:16 644928 ----a-w- C:\Program Files (x86)\UIX.renderapi.dll
2010-01-07 19:27:16 550720 ----a-w- C:\Program Files (x86)\UIXcontrols.dll
2010-01-07 19:27:16 1517376 ----a-w- C:\Program Files (x86)\UIX.dll
2010-01-07 19:27:16 1066816 ----a-w- C:\Program Files (x86)\ZuneShell.dll
2010-01-07 19:13:34 191488 ----a-w- C:\Program Files (x86)\l3codecp.acm
2009-12-16 15:50:16 796672 ----a-w- C:\Program Files (x86)\msvcr80.dll
2009-12-16 15:50:16 1061376 ----a-w- C:\Program Files (x86)\msvcp80.dll
2007-10-02 18:12:44 1642568 ----a-w- C:\Program Files (x86)\msidcrl40.dll
.
============= FINISH: 5:20:41.90 ===============
Here is what is flagged by Spybot ...
Win32.AVKillsvc.e: [SBI $ACD9F3FA] Data (File, nothing done)
C:\Windows\Temp\{E9C1E0AC-C9B2-4c85-94DE-9C1518918D02}.tlb
Properties.size=3596
Properties.md5=AA065968ED3616112AF21B51EF2F5CBB
Properties.filedate=1315645136
Properties.filedatetext=2011-09-10 04:58:56
Please let me know if there is any additional information I can provide. Thanks in advance for your assistence!
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by tdks Crowder at 5:18:24 on 2011-09-10
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2013 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe
c:\hp\HPEZBTN\HPBtnSrv.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\ZuneLauncher.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames2.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\hp\kbd\kbd.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = local;*.local
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
uRun: [BTBFirstRun] C:\Program Files (x86)\Hewlett-Packard\SDP\hprun.exe
uRun: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] C:\HP\KBD\KbdStub.EXE
mRun: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [QuickTime Task] "C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
StartupFolder: C:\Users\TDKSCR~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\REGIST~1.LNK - C:\Program Files (x86)\Steam\steamapps\common\assassins creed\Register\RegistrationReminder.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
LSP: mswsock.dll
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {23A2712A-7A4F-4D0C-822C-D7BA9974447B} - hxxps://registration.rr.com/RegHelper.cab
DPF: {2703049B-D81D-4763-A3C6-AF8932FCBD8F} - hxxps://am.hrblock.com/ActivexComponent/CheckFileStatus.CAB
DPF: {3A52566B-6018-485B-B713-8B9FF660D8E8} - hxxp://dvr.mailender.com/webdvr2.4.9.2_0.0.0.0.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {6F750203-1362-4815-A476-88533DE61D0C} - hxxp://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} - hxxp://offers.e-centives.com/cif/download/bin/actxcab.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
TCP: Interfaces\{5699578E-7FB8-42EF-B610-3841AFC3622F} : DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
TCP: Interfaces\{A867BC74-A81B-4049-BF6E-D06D5204C3BF} : DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2
BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-X64: 0x1 - No File
BHO-X64: HP Print Clips: {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB-X64: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
mRun-x64: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun-x64: [KBD] C:\HP\KBD\KbdStub.EXE
mRun-x64: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [QuickTime Task] "C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\components\coFFPlgn.dll
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\components\IPSFFPl.dll
FF - component: C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - component: C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
FF - component: C:\Users\tdks Crowder\AppData\Roaming\Mozilla\Firefox\Profiles\hidfubyi.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\tdks Crowder\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
FF - plugin: C:\Users\tdks Crowder\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin2.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin3.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin4.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin5.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin6.dll
FF - plugin: C:\Users\tdks Crowder\Documents\Kevins Stuff\QT\Plugins\npqtplugin7.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2008-1-20 21504]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-9-1 44768]
R2 DAUpdaterSvc;Dragon Age: Origins - Content Updater;C:\Program Files (x86)\Steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe [2010-12-27 25832]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 HPBtnSrv;HP Chasis Button Service;C:\hp\HPEZBTN\HPBtnSrv.exe [2008-2-22 198240]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-9-1 366640]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;C:\Program Files (x86)\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-3-12 86016]
R2 mi-raysat_3dsmax2010_64;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 64-bit 64-bit;C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe [2009-3-12 86016]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-7-23 2218600]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-9-3 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-4-7 378472]
R3 CAXHWBS2;CAXHWBS2;C:\Windows\system32\DRIVERS\CAXHWBS2.sys --> C:\Windows\system32\DRIVERS\CAXHWBS2.sys [?]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys --> C:\Windows\system32\drivers\HCW85BDA.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 netr7364;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr7364.sys --> C:\Windows\system32\DRIVERS\netr7364.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-30 135664]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-11-3 1030600]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-30 135664]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-8-7 89920]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x64\msvsmon.exe [2005-9-23 4476096]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-09-10 09:01:12 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{A3D5EEFE-EF2D-4CE1-9A88-3865DF14BFFF}
2011-09-10 08:35:08 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{DAEDB556-B094-41B2-9422-6DDB5C40FA37}
2011-09-10 08:34:44 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{A8438258-54D1-4C1B-A052-EABD807E6CF6}
2011-09-09 21:53:48 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{43B6DC40-A777-4069-9932-37CB043DE012}\mpengine.dll
2011-09-09 20:13:13 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{5AD560E5-5717-4B26-8250-5C78EABDF5A0}
2011-09-09 20:12:53 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{2F4D34E8-FB84-4AAD-BE00-671A12523BA0}
2011-09-09 11:32:11 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{5A8EFB3D-990D-4DE8-931F-DDAE97949888}
2011-09-09 11:31:52 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{B8E700A5-03E1-4B5F-841D-60E71C4D8D02}
2011-09-08 11:34:34 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{E4F8CE96-0F8F-4EC2-B5B2-463E1F7CB2B6}
2011-09-08 11:34:14 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{6B483089-396F-40F6-9A2E-F977D97716A8}
2011-09-08 04:16:20 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{A4E72C9F-70D6-44A4-BEE6-1B2229B7D192}
2011-09-08 04:15:59 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{1816919E-9808-4553-BE1D-3219687C7417}
2011-09-07 11:35:28 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{096B3BD4-2F34-4138-B613-C8BA5799B9C3}
2011-09-07 11:35:09 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{957BA671-6535-4AF2-B2A2-BAB2256A3319}
2011-09-06 23:22:27 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{EB30F509-E071-4369-9271-3D0C07F946A9}
2011-09-06 23:22:06 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{320EB5CC-E687-43DA-A2F4-4167AE93C33B}
2011-09-06 12:29:55 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{68CE42F8-A987-4588-ACBD-BC190428F168}
2011-09-06 12:29:34 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{42DDA249-F384-43FD-992D-891A90398D88}
2011-09-05 18:37:10 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{208C3534-CDF1-49E7-A049-D74352B3A2D6}
2011-09-05 16:53:56 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{2E34C2CE-1834-4B68-9273-AE358E8650AB}
2011-09-05 13:29:33 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{D4DCD22E-843F-45BA-BAA1-E7AA8D20B12E}
2011-09-05 13:29:08 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8888CA5C-F342-404C-9FAB-F79777315A14}
2011-09-04 12:50:17 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{1516BBE3-F218-4CBB-AA39-FF7968A787BE}
2011-09-04 12:49:56 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8B7B549F-FEAF-43CC-9557-8698E947C040}
2011-09-03 15:46:58 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{1C7814A6-E9AC-42E7-94C3-EB0548A527C4}
2011-09-03 15:46:38 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8FE6C1EA-C253-4FAC-A2CA-A52C497086D8}
2011-09-03 15:40:48 0 ---ha-w- C:\Users\tdks Crowder\AppData\Local\BIT257A.tmp
2011-09-03 14:35:01 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{2B1B0109-9329-4C85-A7A7-9CAA2F6CDDC6}
2011-09-03 14:34:40 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{F7679B4E-A3FD-4FA2-ABFB-C6FD704546AF}
2011-09-03 12:27:07 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-09-03 12:27:07 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-09-03 11:48:55 388096 ----a-r- C:\Users\tdks Crowder\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-03 11:48:54 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-09-03 11:44:50 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{03AA2363-0E0A-4756-993B-7F34D171A892}
2011-09-03 11:44:27 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{AC8B1C19-1984-46DA-8C8F-4095D3742F02}
2011-09-02 22:28:40 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{5865E48E-5451-4EC5-A1E0-3D834F9A37AE}
2011-09-02 22:28:21 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{1AEFBFD2-CE7A-47C2-9F61-57E72711D421}
2011-09-02 18:05:04 525792 ----a-w- C:\Windows\DIFxAPI.dll
2011-09-02 16:00:03 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\SUPERAntiSpyware.com
2011-09-02 15:59:47 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-09-02 15:59:47 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-09-02 07:05:05 -------- d-----w- C:\Program Files\CCleaner
2011-09-02 05:44:57 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{7853F4A8-7BB9-4F27-AE64-504CD3D8DA28}
2011-09-02 00:47:44 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{C1262D04-A80F-4C2C-A920-246B36DFC809}
2011-09-02 00:47:24 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{92C1B108-D212-4246-B81A-5DB8DDD4DF72}
2011-09-02 00:32:07 65368 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-09-02 00:32:07 601944 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-09-02 00:31:59 41184 ----a-w- C:\Windows\avastSS.scr
2011-09-02 00:31:53 -------- d-----w- C:\ProgramData\AVAST Software
2011-09-02 00:31:53 -------- d-----w- C:\Program Files\AVAST Software
2011-09-01 17:58:49 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\Malwarebytes
2011-09-01 17:58:45 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-09-01 17:58:44 -------- d-----w- C:\ProgramData\Malwarebytes
2011-09-01 17:58:42 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-09-01 17:58:42 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-09-01 17:44:50 0 ---ha-w- C:\Users\tdks Crowder\AppData\Local\BIT4E01.tmp
2011-09-01 17:44:13 0 ---ha-w- C:\Users\tdks Crowder\AppData\Local\BITBDA3.tmp
2011-09-01 07:40:37 -------- d-----we C:\Windows\system64
2011-08-30 23:07:05 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{B0662B53-D854-48F2-898D-19280BFEB74B}
2011-08-30 23:06:55 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{B1A210B4-D9F2-41DB-BDF2-2D4C726D8511}
2011-08-30 08:46:12 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{3A2E8D85-8A5B-429D-A29F-8E95C42F5E8D}
2011-08-30 08:46:00 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{ADDC9AD0-6460-404D-B99F-9ED3082980AC}
2011-08-29 10:18:07 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{EBE9D8C2-6ED3-4B26-9911-C917A4B6FF7F}
2011-08-29 10:17:57 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{57430A50-0003-4BDF-9AC5-CFF998B7FC12}
2011-08-26 13:12:53 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{98596A08-1E47-4AC5-B189-55C1737F18E3}
2011-08-26 13:12:42 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{A341932A-DB98-4F42-89A0-5D524868DC49}
2011-08-25 10:18:53 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{67D8F73F-F45F-4068-B9AB-AA3A1F1275A2}
2011-08-24 16:24:06 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-24 16:24:06 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-24 11:33:35 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8C66FD12-7854-4E2A-945C-4A0DAF718244}
2011-08-24 11:33:25 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{F74F4913-D14D-427B-9595-5650DD1C54D5}
2011-08-19 07:40:21 -------- d-----w- C:\Users\tdks Crowder\riotsGamesLogs
2011-08-19 07:29:50 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\LolClient
2011-08-19 06:24:18 -------- d-----w- C:\Riot Games
2011-08-19 05:55:24 -------- d-----w- C:\Program Files (x86)\LeagueOfLegends
2011-08-18 20:25:38 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{5DD5884C-FD76-4108-A1B3-B10DCFAF3F45}
2011-08-18 20:25:25 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{3EAC0275-3A0E-44FC-A388-CBEBCC83DDC7}
2011-08-18 20:14:56 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{7616E970-54B1-49E3-B6A7-86233A659BA6}
2011-08-18 20:14:42 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{BD73A831-A774-4DE1-BAE7-F0979D356C87}
2011-08-16 23:43:37 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-08-16 23:43:37 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-08-14 16:09:17 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{8C464AA0-E910-46F8-8E14-C46E71D308B4}
2011-08-14 16:09:07 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{2D0BAFD2-2954-4DF6-9824-38796C7591DF}
2011-08-14 05:40:09 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\Ubisoft Game Launcher
2011-08-13 23:07:03 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\Braid
2011-08-13 15:54:09 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\Crayon Physics Deluxe
2011-08-12 21:05:16 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\Lazy 8 Studios
2011-08-12 15:05:05 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{4751B4DC-C0D9-49DF-9A2B-2849BDB951B5}
2011-08-12 15:04:54 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{7A4F6057-3843-49D0-9E1F-58B563EE2907}
2011-08-11 21:39:10 -------- d-----w- C:\Users\tdks Crowder\AppData\Roaming\runic games
2011-08-11 13:06:03 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{4A4E59CF-9ED0-4D72-8A25-5305904B411C}
2011-08-11 13:05:53 -------- d-----w- C:\Users\tdks Crowder\AppData\Local\{C28C9584-C45C-4061-99BD-D1180434DE80}
.
==================== Find3M ====================
.
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-06 15:49:23 275456 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-06-20 08:45:17 4699536 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-17 20:14:30 1427344 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-06-17 16:16:33 451072 ----a-w- C:\Windows\System32\winsrv.dll
2010-01-07 19:27:16 997184 ----a-w- C:\Program Files (x86)\ZuneDBApi.dll
2010-01-07 19:27:16 644928 ----a-w- C:\Program Files (x86)\UIX.renderapi.dll
2010-01-07 19:27:16 550720 ----a-w- C:\Program Files (x86)\UIXcontrols.dll
2010-01-07 19:27:16 1517376 ----a-w- C:\Program Files (x86)\UIX.dll
2010-01-07 19:27:16 1066816 ----a-w- C:\Program Files (x86)\ZuneShell.dll
2010-01-07 19:13:34 191488 ----a-w- C:\Program Files (x86)\l3codecp.acm
2009-12-16 15:50:16 796672 ----a-w- C:\Program Files (x86)\msvcr80.dll
2009-12-16 15:50:16 1061376 ----a-w- C:\Program Files (x86)\msvcp80.dll
2007-10-02 18:12:44 1642568 ----a-w- C:\Program Files (x86)\msidcrl40.dll
.
============= FINISH: 5:20:41.90 ===============
Here is what is flagged by Spybot ...
Win32.AVKillsvc.e: [SBI $ACD9F3FA] Data (File, nothing done)
C:\Windows\Temp\{E9C1E0AC-C9B2-4c85-94DE-9C1518918D02}.tlb
Properties.size=3596
Properties.md5=AA065968ED3616112AF21B51EF2F5CBB
Properties.filedate=1315645136
Properties.filedatetext=2011-09-10 04:58:56