swatspeedman
New member
I recently got what I believe to be the google redirect virus. I found a forum on this site about it and decided I must post one myself as the results differ for each person. I AM ONLY 15! if i do not know what you are on about that isn't my fault, i am very basic with this stuff (system restore etc) and may be hard to work with as I can be lacking in the common sense sector.
I am trying my best to help but malware removal is new to me. I have installed malware bytes already.
Sorry if I posted this wrong.
DDS -
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 7.0.6002.18005
Run by Scott at 22:33:56 on 2011-05-20
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3066.1346 [GMT 1:00]
.
AV: BullGuard Antivirus *Enabled/Updated* {504FFF66-3028-EB7E-2E60-62B19ADD791C}
SP: BullGuard Antispyware *Enabled/Updated* {EB2E1E82-1612-E4F0-14D0-59C3E15A33A1}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: BullGuard Firewall *Enabled* {68747E43-7A47-EA26-053F-CB84640E3E67}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\SvcHost.exe -k BullGuard_Main
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\SPBA\upeksvr.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\SvcHost.exe -k BullGuard_LowPriv
C:\Windows\System32\SvcHost.exe -k BullGuard
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxducoms.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Users\Scott\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Scott\Desktop\dds.scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vp32&d=0410&m=aspire_6930g
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vp32&d=0410&m=aspire_6930g
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: MediaBar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - MediaBar
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: BGAntiphishingBHO Class: {fc872b94-35e3-4b94-b028-184a2a1c7cce} - c:\program files\bullguard ltd\bullguard\antiphishing\ie\BGAntiphishingIEBHO.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll
TB: MediaBar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} -
TB: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe
mRun: [eDataSecurity Loader] c:\program files\acer\empowering technology\edatasecurity\x86\eDSloader.exe
mRun: [eAudio] "c:\program files\acer\empowering technology\eaudio\eAudio.exe"
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE
mRun: [ZPdtWzdVitaKey MC3000] "c:\program files\acer\acer bio protection\PdtWzd.exe" show
mRun: [ArcadeDeluxeAgent] "c:\program files\acer arcade deluxe\acer arcade deluxe\ArcadeDeluxeAgent.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [NPSStartup]
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [CLMLServer] "c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe"
mRun: [PlayMovie] "c:\program files\acer arcade deluxe\playmovie\PMVService.exe"
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Skytel] Skytel.exe
mRun: [BullGuard] "c:\program files\bullguard ltd\bullguard\BullGuard.exe" -boot
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files\acer\acer bio protection\PwdBank.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - c:\program files\bullguard ltd\bullguard\antiphishing\ie\BGAntiphishingIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\BGLsp.dll
LSP: c:\windows\system32\wpclsp.dll
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://intranet.mencap.org.uk/dana-cached/sc/JuniperSetupClient.cab
TCP: {4951123C-F3EA-4F04-92DA-F1A3612D76A8} = 156.154.70.22,156.154.71.22
TCP: {DC06C32F-7B81-4409-AF34-2FB3A7DC6BD3} = 156.154.70.22,156.154.71.22
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
AppInit_DLLs: BgGamingMonitor.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
LSA: Notification Packages = scecli c:\program files\acer\acer bio protection\PwdFilter
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\scott\appdata\roaming\mozilla\firefox\profiles\ntpx762i.default\
FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\scott\appdata\roaming\mozilla\firefox\profiles\ntpx762i.default\extensions\battlefieldheroespatcher@ea.com\plugins\npBFHUpdater.dll
.
============= SERVICES / DRIVERS ===============
.
R? BgRaSvc;BgRaSvc
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? FsUsbExDisk;FsUsbExDisk
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? MEMSWEEP2;MEMSWEEP2
R? Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service
R? netr28u;Belkin USB Wireless LAN Card Driver for Vista
R? osppsvc;Office Software Protection Platform
R? ssadbus;SAMSUNG Android USB Composite Device driver (WDM)
R? ssadmdfl;SAMSUNG Android USB Modem (Filter)
R? ssadmdm;SAMSUNG Android USB Modem Drivers
R? SynasUSB;SynasUSB
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
R? WSDPrintDevice;WSD Print Support via UMB
R? ZMGHPAudioSrv;ZOOM G Series High Performance Audio Driver Service
S? {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};Power Control [2011/02/28 21:02:16]
S? afw;Agnitum Firewall Driver
S? afwcore;afwcore
S? AlfaFF;AlfaFF File System mini-filter
S? BdSpy;BdSpy
S? BsBrowser;BullGuard antiphishing service
S? BsFileScan;BullGuard on-access service
S? BsFire;BullGuard firewall service
S? BsMailProxy;BullGuard e-mail monitoring service
S? BsMain;BullGuard main service
S? BsScanner;BullGuard scanning service
S? BsUpdate;BullGuard update service
S? BUNAgentSvc;NTI Backup Now 5 Agent Service
S? CLHNService;CLHNService
S? ETService;Empowering Technology Service
S? IGBASVC;iGroupTec Service
S? lxdu_device;lxdu_device
S? NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit
S? NTIBackupSvc;NTI Backup Now 5 Backup Service
S? NTIPPKernel;NTIPPKernel
S? NTISchedulerSvc;NTI Backup Now 5 Scheduler Service
S? NVHDA;Service for NVIDIA High Definition Audio Driver
S? SBSDWSCService;SBSD Security Center Service
S? winbondcir;Winbond IR Transceiver
.
=============== Created Last 30 ================
.
2011-05-20 17:00:55 -------- d-----w- c:\users\scott\Adobe After Effects CS4
2011-05-17 12:46:38 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-13 16:30:22 -------- d-----w- c:\program files\ESET
2011-05-13 15:17:22 -------- d-----w- c:\users\scott\appdata\roaming\Malwarebytes
2011-05-13 15:17:12 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-13 15:17:11 -------- d-----w- c:\programdata\Malwarebytes
2011-05-13 15:17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-13 15:17:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-12 19:20:14 -------- d-----w- c:\users\scott\appdata\roaming\BullGuard
2011-05-12 19:14:50 -------- d-----w- c:\programdata\BullGuard
2011-05-12 19:14:20 -------- d-----w- c:\program files\BullGuard Ltd
2011-05-12 18:02:40 -------- d-----w- c:\program files\Sophos
2011-05-12 17:29:50 2 --shatr- c:\windows\winstart.bat
2011-05-12 17:26:45 -------- d-----w- c:\program files\UnHackMe
2011-05-10 19:34:12 -------- d-----w- c:\program files\RocketDock
2011-05-09 21:36:43 -------- d-----w- c:\windows\system32\eu-ES
2011-05-09 21:36:43 -------- d-----w- c:\windows\system32\ca-ES
2011-05-09 21:36:37 -------- d-----w- c:\windows\system32\vi-VN
2011-05-09 19:10:54 -------- d-----w- c:\users\scott\appdata\roaming\SPORE
2011-05-09 19:04:40 1216 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2011-05-09 19:04:14 -------- d-----w- c:\users\scott\appdata\local\Downloaded Installations
2011-05-09 18:23:36 -------- d-----w- c:\windows\system32\EventProviders
2011-05-07 12:31:46 -------- d-----w- c:\program files\common files\Macrovision Shared
2011-05-07 12:26:57 -------- d-----w- c:\users\scott\appdata\local\Adobe
2011-05-06 10:30:36 7071056 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{50afdad7-925e-459b-8a90-90c38d4e72a7}\mpengine.dll
2011-05-04 19:09:29 -------- d-----w- c:\program files\uTorrent
2011-05-04 19:08:19 -------- d-----w- c:\users\scott\appdata\roaming\uTorrent
2011-05-02 16:00:41 -------- d-----w- C:\.jagex_cache_32
2011-05-02 01:06:50 -------- d-----w- c:\users\scott\appdata\local\TechSmith
2011-05-02 01:00:34 411480 ----a-w- c:\windows\system32\tsccvid.dll
2011-05-02 01:00:25 -------- d-----w- c:\windows\system32\QuickTime
2011-05-02 00:59:04 -------- d-----w- c:\program files\common files\TechSmith Shared
2011-05-01 10:12:51 784136 ----a-w- c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight\SpotlightResources.dll
2011-04-30 17:02:44 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-04-30 17:02:43 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-24 14:55:06 -------- d-----w- c:\program files\iPod
2011-04-24 14:50:39 -------- d-----w- c:\program files\Bonjour
.
==================== Find3M ====================
.
2011-05-12 19:28:54 122744 ----a-w- c:\windows\system32\BdInstHk.dll
2011-05-12 19:27:33 58592 ----a-w- c:\windows\system32\drivers\BdSpy.sys
2011-04-09 21:56:35 139080 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-04-09 21:56:24 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-04-09 21:56:24 270240 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-04-09 21:41:53 138056 ----a-w- c:\users\scott\appdata\roaming\PnkBstrK.sys
2011-04-09 21:41:43 189248 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-04-09 21:41:36 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-04-06 15:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-02 17:54:27 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-04-02 17:54:27 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-03-24 19:33:06 2892 ----a-w- c:\windows\system32\audcon.sys
2011-03-10 17:03:51 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03:51 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:42:03 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 15:40:07 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40:05 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40:05 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40:04 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-03-03 13:25:11 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-03-02 15:44:27 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-02-22 13:24:10 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-02-22 13:24:02 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-02-22 13:23:59 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-22 13:23:55 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
.
============= FINISH: 22:36:54.79 ===============
I am trying my best to help but malware removal is new to me. I have installed malware bytes already.
Sorry if I posted this wrong.
DDS -
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 7.0.6002.18005
Run by Scott at 22:33:56 on 2011-05-20
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3066.1346 [GMT 1:00]
.
AV: BullGuard Antivirus *Enabled/Updated* {504FFF66-3028-EB7E-2E60-62B19ADD791C}
SP: BullGuard Antispyware *Enabled/Updated* {EB2E1E82-1612-E4F0-14D0-59C3E15A33A1}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: BullGuard Firewall *Enabled* {68747E43-7A47-EA26-053F-CB84640E3E67}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\SvcHost.exe -k BullGuard_Main
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\SPBA\upeksvr.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\SvcHost.exe -k BullGuard_LowPriv
C:\Windows\System32\SvcHost.exe -k BullGuard
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxducoms.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Users\Scott\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Scott\Desktop\dds.scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vp32&d=0410&m=aspire_6930g
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vp32&d=0410&m=aspire_6930g
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: MediaBar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - MediaBar
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: BGAntiphishingBHO Class: {fc872b94-35e3-4b94-b028-184a2a1c7cce} - c:\program files\bullguard ltd\bullguard\antiphishing\ie\BGAntiphishingIEBHO.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll
TB: MediaBar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} -
TB: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe
mRun: [eDataSecurity Loader] c:\program files\acer\empowering technology\edatasecurity\x86\eDSloader.exe
mRun: [eAudio] "c:\program files\acer\empowering technology\eaudio\eAudio.exe"
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE
mRun: [ZPdtWzdVitaKey MC3000] "c:\program files\acer\acer bio protection\PdtWzd.exe" show
mRun: [ArcadeDeluxeAgent] "c:\program files\acer arcade deluxe\acer arcade deluxe\ArcadeDeluxeAgent.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [NPSStartup]
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [CLMLServer] "c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe"
mRun: [PlayMovie] "c:\program files\acer arcade deluxe\playmovie\PMVService.exe"
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Skytel] Skytel.exe
mRun: [BullGuard] "c:\program files\bullguard ltd\bullguard\BullGuard.exe" -boot
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files\acer\acer bio protection\PwdBank.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - c:\program files\bullguard ltd\bullguard\antiphishing\ie\BGAntiphishingIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\BGLsp.dll
LSP: c:\windows\system32\wpclsp.dll
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://intranet.mencap.org.uk/dana-cached/sc/JuniperSetupClient.cab
TCP: {4951123C-F3EA-4F04-92DA-F1A3612D76A8} = 156.154.70.22,156.154.71.22
TCP: {DC06C32F-7B81-4409-AF34-2FB3A7DC6BD3} = 156.154.70.22,156.154.71.22
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
AppInit_DLLs: BgGamingMonitor.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
LSA: Notification Packages = scecli c:\program files\acer\acer bio protection\PwdFilter
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\scott\appdata\roaming\mozilla\firefox\profiles\ntpx762i.default\
FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\scott\appdata\roaming\mozilla\firefox\profiles\ntpx762i.default\extensions\battlefieldheroespatcher@ea.com\plugins\npBFHUpdater.dll
.
============= SERVICES / DRIVERS ===============
.
R? BgRaSvc;BgRaSvc
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? FsUsbExDisk;FsUsbExDisk
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? MEMSWEEP2;MEMSWEEP2
R? Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service
R? netr28u;Belkin USB Wireless LAN Card Driver for Vista
R? osppsvc;Office Software Protection Platform
R? ssadbus;SAMSUNG Android USB Composite Device driver (WDM)
R? ssadmdfl;SAMSUNG Android USB Modem (Filter)
R? ssadmdm;SAMSUNG Android USB Modem Drivers
R? SynasUSB;SynasUSB
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
R? WSDPrintDevice;WSD Print Support via UMB
R? ZMGHPAudioSrv;ZOOM G Series High Performance Audio Driver Service
S? {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};Power Control [2011/02/28 21:02:16]
S? afw;Agnitum Firewall Driver
S? afwcore;afwcore
S? AlfaFF;AlfaFF File System mini-filter
S? BdSpy;BdSpy
S? BsBrowser;BullGuard antiphishing service
S? BsFileScan;BullGuard on-access service
S? BsFire;BullGuard firewall service
S? BsMailProxy;BullGuard e-mail monitoring service
S? BsMain;BullGuard main service
S? BsScanner;BullGuard scanning service
S? BsUpdate;BullGuard update service
S? BUNAgentSvc;NTI Backup Now 5 Agent Service
S? CLHNService;CLHNService
S? ETService;Empowering Technology Service
S? IGBASVC;iGroupTec Service
S? lxdu_device;lxdu_device
S? NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit
S? NTIBackupSvc;NTI Backup Now 5 Backup Service
S? NTIPPKernel;NTIPPKernel
S? NTISchedulerSvc;NTI Backup Now 5 Scheduler Service
S? NVHDA;Service for NVIDIA High Definition Audio Driver
S? SBSDWSCService;SBSD Security Center Service
S? winbondcir;Winbond IR Transceiver
.
=============== Created Last 30 ================
.
2011-05-20 17:00:55 -------- d-----w- c:\users\scott\Adobe After Effects CS4
2011-05-17 12:46:38 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-13 16:30:22 -------- d-----w- c:\program files\ESET
2011-05-13 15:17:22 -------- d-----w- c:\users\scott\appdata\roaming\Malwarebytes
2011-05-13 15:17:12 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-13 15:17:11 -------- d-----w- c:\programdata\Malwarebytes
2011-05-13 15:17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-13 15:17:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-12 19:20:14 -------- d-----w- c:\users\scott\appdata\roaming\BullGuard
2011-05-12 19:14:50 -------- d-----w- c:\programdata\BullGuard
2011-05-12 19:14:20 -------- d-----w- c:\program files\BullGuard Ltd
2011-05-12 18:02:40 -------- d-----w- c:\program files\Sophos
2011-05-12 17:29:50 2 --shatr- c:\windows\winstart.bat
2011-05-12 17:26:45 -------- d-----w- c:\program files\UnHackMe
2011-05-10 19:34:12 -------- d-----w- c:\program files\RocketDock
2011-05-09 21:36:43 -------- d-----w- c:\windows\system32\eu-ES
2011-05-09 21:36:43 -------- d-----w- c:\windows\system32\ca-ES
2011-05-09 21:36:37 -------- d-----w- c:\windows\system32\vi-VN
2011-05-09 19:10:54 -------- d-----w- c:\users\scott\appdata\roaming\SPORE
2011-05-09 19:04:40 1216 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2011-05-09 19:04:14 -------- d-----w- c:\users\scott\appdata\local\Downloaded Installations
2011-05-09 18:23:36 -------- d-----w- c:\windows\system32\EventProviders
2011-05-07 12:31:46 -------- d-----w- c:\program files\common files\Macrovision Shared
2011-05-07 12:26:57 -------- d-----w- c:\users\scott\appdata\local\Adobe
2011-05-06 10:30:36 7071056 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{50afdad7-925e-459b-8a90-90c38d4e72a7}\mpengine.dll
2011-05-04 19:09:29 -------- d-----w- c:\program files\uTorrent
2011-05-04 19:08:19 -------- d-----w- c:\users\scott\appdata\roaming\uTorrent
2011-05-02 16:00:41 -------- d-----w- C:\.jagex_cache_32
2011-05-02 01:06:50 -------- d-----w- c:\users\scott\appdata\local\TechSmith
2011-05-02 01:00:34 411480 ----a-w- c:\windows\system32\tsccvid.dll
2011-05-02 01:00:25 -------- d-----w- c:\windows\system32\QuickTime
2011-05-02 00:59:04 -------- d-----w- c:\program files\common files\TechSmith Shared
2011-05-01 10:12:51 784136 ----a-w- c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight\SpotlightResources.dll
2011-04-30 17:02:44 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-04-30 17:02:43 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-24 14:55:06 -------- d-----w- c:\program files\iPod
2011-04-24 14:50:39 -------- d-----w- c:\program files\Bonjour
.
==================== Find3M ====================
.
2011-05-12 19:28:54 122744 ----a-w- c:\windows\system32\BdInstHk.dll
2011-05-12 19:27:33 58592 ----a-w- c:\windows\system32\drivers\BdSpy.sys
2011-04-09 21:56:35 139080 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-04-09 21:56:24 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-04-09 21:56:24 270240 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-04-09 21:41:53 138056 ----a-w- c:\users\scott\appdata\roaming\PnkBstrK.sys
2011-04-09 21:41:43 189248 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-04-09 21:41:36 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-04-06 15:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-02 17:54:27 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-04-02 17:54:27 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-03-24 19:33:06 2892 ----a-w- c:\windows\system32\audcon.sys
2011-03-10 17:03:51 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03:51 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:42:03 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 15:40:07 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40:05 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40:05 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40:04 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-03-03 13:25:11 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-03-02 15:44:27 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-02-22 13:24:10 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-02-22 13:24:02 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-02-22 13:23:59 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-22 13:23:55 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
.
============= FINISH: 22:36:54.79 ===============