Hello Spybot community,
I am new to the forums but not new to Spybot. I have used this wonderful tool for years with great success keeping my computer super clean.
Recently, I came across a fairly nasty bug. Sabkutil. After it blocked Spybot from running / updating, I did some searches online and saw references to 2006 or other years. I even downloaded the uninstaller for SuperAntiSpyware to make sure it wasnt an orphan'd file.
I have tried several things to get rid of this bug Kaspersky nor MBAM can get rid of it, even in safe mode. Any help you can provide I would greatly appreciate.
Thank you again for your time. I will post the DDS file in a second post behind this one as requested by the forum sticky.
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by C at 9:49:37.53 on Sun 04/03/2011
Internet Explorer: 8.0.7601.17514
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2047.797 [GMT -5:00]
.
AV: Kaspersky Internet Security *Enabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky Internet Security *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
FW: Kaspersky Internet Security *Enabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtblfs.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\C\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
BHO: QuickNet: {ea5ca8b6-9b9c-4994-a7a1-947b6c631be7} - QuickNet BHO
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
StartupFolder: C:\Users\C\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\ievkbd.dll
BHO-X64: IEVkbdBHO - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll
BHO-X64: link filter bho - No File
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll,C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-2 365336]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-2-23 378984]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-11-23 1974080]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-3-31 155752]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-8-19 11856]
R3 VaneFltr;Lachesis Mouse Driver;C:\Windows\System32\drivers\Lachesis.sys [2007-8-17 30336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-25 136176]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-11-9 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-3-21 130976]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 30969208]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-1-21 413800]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-8 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-10-23 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-04-03 14:11:02 -------- d-----w- C:\Users\C\AppData\Local\{B4E1ADDB-2C6A-4BC8-9650-D06C485C2987}
2011-04-02 03:43:30 -------- d-----w- C:\Users\C\AppData\Local\{EB808FAD-E006-4115-ADA8-292705989B5F}
2011-04-01 13:47:07 -------- d-----w- C:\Users\C\AppData\Local\{DF8239AE-C3A3-4F2B-A44A-96D8738C7EA1}
2011-04-01 13:46:38 8424784 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{F43F1B90-82FC-414D-A674-CDC677D1F519}\mpengine.dll
2011-04-01 04:24:04 -------- d-----w- C:\PROGRA~3\NVIDIA Corporation
2011-04-01 03:23:49 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab
2011-04-01 03:23:49 -------- d-----w- C:\PROGRA~3\Kaspersky Lab
2011-04-01 03:22:31 -------- d-----w- C:\PROGRA~3\Kaspersky Lab Setup Files
2011-03-31 21:27:12 -------- d-----w- C:\Users\C\AppData\Local\{440AF234-055A-4515-8A58-C5244A20B349}
2011-03-31 02:54:33 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2011-03-31 00:37:15 -------- d-----w- C:\PROGRA~3\Malwarebytes
2011-03-31 00:37:11 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-03-30 15:56:35 9548 ----a-w- C:\Windows\System32\drivers\nvphy.bin
2011-03-30 15:56:35 729600 ----a-w- C:\Windows\System32\cohelper.dll
2011-03-30 05:15:26 -------- d-----w- C:\Program Files (x86)\RIFT Game
2011-03-30 03:49:49 -------- d-----w- C:\Program Files (x86)\oZone3D
2011-03-29 03:27:37 -------- d-----w- C:\Program Files (x86)\SpeedFan
2011-03-29 03:16:31 -------- d-sh--w- C:\$RECYCLE.BIN
2011-03-29 03:08:37 98816 ----a-w- C:\Windows\sed.exe
2011-03-29 03:08:37 89088 ----a-w- C:\Windows\MBR.exe
2011-03-29 03:08:37 256512 ----a-w- C:\Windows\PEV.exe
2011-03-29 03:08:37 161792 ----a-w- C:\Windows\SWREG.exe
2011-03-28 17:32:00 89088 ----a-w- C:\Windows\System32\CmdRtr64.DLL
2011-03-28 17:32:00 73728 ----a-w- C:\Windows\SysWow64\CmdRtr.DLL
2011-03-28 17:32:00 214528 ----a-w- C:\Windows\System32\APOMgr64.DLL
2011-03-28 17:32:00 166912 ----a-w- C:\Windows\SysWow64\APOMngr.DLL
2011-03-28 01:00:00 -------- d-----w- C:\Users\C\AppData\Local\IsolatedStorage
2011-03-28 00:59:59 -------- d-----w- C:\Users\C\AppData\Local\Futuremark_Corporation
2011-03-28 00:56:52 -------- d-----w- C:\Program Files\Futuremark
2011-03-27 21:53:45 34624 ----a-w- C:\Windows\System32\TURegOpt.exe
2011-03-27 21:53:44 36160 ----a-w- C:\Windows\System32\uxtuneup.dll
2011-03-27 21:53:44 29504 ----a-w- C:\Windows\SysWow64\uxtuneup.dll
2011-03-27 21:53:44 25920 ----a-w- C:\Windows\System32\authuitu.dll
2011-03-27 21:53:44 21312 ----a-w- C:\Windows\SysWow64\authuitu.dll
2011-03-27 21:53:41 -------- d-----w- C:\Users\C\AppData\Roaming\TuneUp Software
2011-03-27 21:52:40 -------- d-----w- C:\Program Files (x86)\TuneUp Utilities 2011
2011-03-27 21:48:01 -------- d-----w- C:\PROGRA~3\TuneUp Software
2011-03-27 05:08:04 34560 ----a-w- C:\Windows\SysWow64\drivers\Normandy.sys
2011-03-27 02:13:43 -------- d-----w- C:\Program Files\EVGA
2011-03-26 03:11:24 11264 ----a-w- C:\Windows\SysWow64\INRES.DLL
2011-03-26 03:11:24 10752 ----a-w- C:\Windows\System32\INRES.DLL
2011-03-23 23:57:53 -------- d-----w- C:\Windows\System32\appmgmt
2011-03-23 14:44:57 -------- d-----w- C:\Users\C\AppData\Roaming\SuperAdBlocker.com
2011-03-23 14:44:49 -------- d-----w- C:\Windows\SysWow64\URTTemp
2011-03-23 14:44:48 -------- d--h--w- C:\Program Files (x86)\SuperAdBlocker.com
2011-03-22 02:31:16 -------- d-----w- C:\Users\C\AppData\Roaming\NVIDIA
2011-03-22 02:22:33 -------- d-----w- C:\PROGRA~3\Futuremark
2011-03-22 02:14:43 -------- d--h--w- C:\Program Files (x86)\Futuremark
2011-03-20 14:48:27 20480 ----a-w- C:\Windows\System32\drivers\usbicp.sys
2011-03-10 06:25:40 -------- d-----w- C:\Windows\Downloaded Installations
2011-03-09 13:34:16 -------- d--h--w- C:\Program Files (x86)\Microsoft Synchronization Services
2011-03-09 03:44:20 -------- d-----w- C:\Windows\System32\SPReview
2011-03-09 03:43:27 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
2011-03-09 03:43:27 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
2011-03-09 03:38:17 1940480 ------w- C:\Windows\System32\Sens_oal.dll
2011-03-09 03:37:45 729088 ---ha-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-03-09 03:37:45 69715 ---ha-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-03-09 03:37:45 5632 ---ha-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-03-09 03:37:45 266240 ---ha-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-03-09 03:37:45 192512 ---ha-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-03-09 03:37:45 188548 ---ha-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-03-09 03:37:44 311428 ---ha-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-03-09 03:18:58 444752 ----a-w- C:\Windows\System32\mscoree.dll
2011-03-09 03:17:59 1009152 ----a-w- C:\Windows\System32\mcmde.dll
2011-03-09 03:16:59 81920 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadcs.dll
2011-03-09 03:15:57 209920 ----a-w- C:\Windows\SysWow64\PkgMgr.exe
2011-03-09 03:15:57 189952 ----a-w- C:\Windows\SysWow64\wdscore.dll
2011-03-09 03:14:58 323072 ----a-w- C:\Windows\SysWow64\drvstore.dll
2011-03-09 03:14:58 257024 ----a-w- C:\Windows\SysWow64\dpx.dll
2011-03-09 03:14:55 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2011-03-09 03:14:55 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2011-03-09 03:14:05 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2011-03-09 03:14:05 524288 ----a-w- C:\Windows\System32\wmicmiplugin.dll
2011-03-09 03:14:05 1225216 ----a-w- C:\Windows\System32\wbem\wbemcore.dll
2011-03-09 03:13:59 933376 ----a-w- C:\Windows\System32\SmiEngine.dll
2011-03-09 03:13:57 199168 ----a-w- C:\Windows\System32\PkgMgr.exe
2011-03-09 03:13:29 422912 ----a-w- C:\Windows\System32\drvstore.dll
2011-03-09 03:13:28 399872 ----a-w- C:\Windows\System32\dpx.dll
.
==================== Find3M ====================
.
2011-03-09 03:49:40 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-03-09 03:49:39 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-02-24 23:21:10 2753512 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys
2011-02-23 06:38:58 795752 ----a-w- C:\Windows\System32\easyUpdatusAPIU64.dll
2011-02-23 06:38:52 6143080 ----a-w- C:\Windows\System32\nvcpl.dll
2011-02-23 06:38:36 3156072 ----a-w- C:\Windows\System32\nvsvc64.dll
2011-02-23 06:38:26 117864 ----a-w- C:\Windows\System32\nvmctray.dll
2011-02-23 06:38:24 61032 ----a-w- C:\Windows\System32\nvshext.dll
2011-02-23 06:38:24 1005160 ----a-w- C:\Windows\System32\nvvsvc.exe
2011-02-22 20:52:00 2075712 ----a-w- C:\Windows\System32\FMAPO64.dll
2011-02-22 18:20:24 820224 ----a-w- C:\Windows\System32\RCoRes64.dat
2011-02-22 16:16:26 2369128 ----a-w- C:\Windows\System32\RtPgEx64.dll
2011-02-21 16:42:50 525792 ----a-w- C:\Windows\DIFxAPI.dll
2011-02-19 12:05:15 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2011-02-19 12:04:37 1544192 ----a-w- C:\Windows\System32\DWrite.dll
2011-02-19 12:04:17 902656 ----a-w- C:\Windows\System32\d2d1.dll
2011-02-19 06:30:51 1076736 ----a-w- C:\Windows\SysWow64\DWrite.dll
2011-02-19 06:30:50 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2011-02-18 15:49:40 2839656 ----a-w- C:\Windows\System32\RtkAPO64.dll
2011-02-17 19:03:54 648296 ----a-w- C:\Windows\System32\RtkApi64.dll
2011-02-16 18:11:28 84072 ----a-w- C:\Windows\System32\RCoInst64.dll
2011-02-11 19:39:00 1247848 ----a-w- C:\Windows\System32\RTCOM64.dll
2011-02-09 20:56:00 1284712 ----a-w- C:\Windows\RtlExUpd.dll
2011-02-02 23:11:20 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-01-21 12:36:02 74272 ----a-w- C:\Windows\System32\RtNicProp64.dll
2011-01-21 12:36:02 413800 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2011-01-21 12:36:02 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
2011-01-07 12:17:52 475648 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-01-07 12:17:52 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-01-07 12:14:11 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-01-07 09:51:01 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-01-07 09:20:44 366592 ----a-w- C:\Windows\System32\atmfd.dll
2011-01-07 07:46:34 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-01-07 07:46:34 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-01-07 07:45:57 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-01-07 06:01:22 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-01-07 05:43:36 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-01-05 10:34:00 612864 ----a-w- C:\Windows\System32\vbscript.dll
2011-01-05 06:56:24 3129344 ----a-w- C:\Windows\System32\win32k.sys
2011-01-05 05:55:55 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
.
============= FINISH: 9:50:38.53 ===============