louisleelol
New member
Hello.
I've had the Google Redirect Virus for quite a while now, and until now, I have ignored it. But now, I think I need to delete this virus once and for all.
As I expected from reading others' stories across the web, virus scanners all show up with nothing. Will it be possible to remove this virus?
Thank you.
DDS:
DDS (Ver_10-12-12.02) - NTFSx86
Run by Louis at 16:58:30.93 on 13/01/2011
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.559 [GMT -8:00]
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Vongo\VongoService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Vongo\Tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Louis\Downloads\dds(2).scr
C:\Windows\system32\conime.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
uURLSearchHooks: H - No File
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\ctbr.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\ctbr.dll
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vongot~1.lnk - c:\windows\installer\{8c3ae2d1-854d-4650-a73d-c7cc7ee36b80}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\crawler\ctbr.dll
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\louis\appdata\roaming\mozilla\firefox\profiles\64rute6x.default\
FF - prefs.js: browser.startup.homepage - www.bing.com
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: BetterPrivacy: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} - %profile%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: YouTube to MP3:
- %profile%\extensions\youtube2mp3@mondayx.de
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-1-9 1153368]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480]
=============== Created Last 30 ================
2011-01-13 06:19:08 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{b017665c-368e-4013-b11c-1a392374dbc5}\mpengine.dll
2011-01-13 06:17:49 409600 ----a-w- c:\windows\system32\odbc32.dll
2011-01-13 06:17:48 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-01-13 06:17:48 57344 ----a-w- c:\program files\common files\system\msadc\msadcs.dll
2011-01-13 06:17:48 253952 ----a-w- c:\program files\common files\system\ado\msadox.dll
2011-01-13 06:17:48 241664 ----a-w- c:\program files\common files\system\ado\msadomd.dll
2011-01-13 06:17:48 180224 ----a-w- c:\program files\common files\system\msadc\msadco.dll
2011-01-13 06:17:41 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-01-12 07:03:58 -------- d-----w- c:\users\louis\appdata\local\Apple Computer
2011-01-12 06:42:43 80896 ----a-w- c:\windows\system32\MSNP.ax
2011-01-12 06:42:43 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2011-01-12 06:42:40 428544 ----a-w- c:\windows\system32\EncDec.dll
2011-01-12 06:42:40 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-01-12 06:42:40 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-01-12 06:33:30 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-01-12 06:33:30 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2011-01-12 06:31:38 -------- d-----w- c:\program files\iPod
2011-01-12 06:31:33 -------- d-----w- c:\program files\iTunes
2011-01-12 06:31:33 -------- d-----w- c:\progra~2\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-01-12 06:25:15 -------- d-----w- c:\users\louis\appdata\local\Apple
2011-01-12 06:22:43 -------- d-----w- c:\program files\Bonjour
2011-01-12 06:21:09 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-01-12 06:21:09 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-01-12 06:21:09 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-01-12 06:21:09 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-01-12 06:21:09 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-01-11 04:47:29 303616 ----a-w- c:\windows\system32\drivers\srv.sys
2011-01-11 04:47:28 17920 ----a-w- c:\windows\system32\netevent.dll
2011-01-11 04:47:28 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-01-11 04:47:28 125952 ----a-w- c:\windows\system32\srvsvc.dll
2011-01-11 04:47:28 101888 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-01-11 04:47:06 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-01-11 04:47:05 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2011-01-11 04:46:00 501760 ----a-w- c:\windows\system32\usp10.dll
2011-01-11 04:45:57 66048 ----a-w- c:\program files\windows mail\wabmig.exe
2011-01-11 04:45:57 515584 ----a-w- c:\program files\windows mail\wab.exe
2011-01-11 04:45:57 33280 ----a-w- c:\program files\windows mail\wabfind.dll
2011-01-11 04:45:55 274432 ----a-w- c:\windows\system32\schannel.dll
2011-01-11 04:44:11 1616384 ----a-w- c:\program files\windows mail\msoe.dll
2011-01-11 04:44:07 81920 ----a-w- c:\windows\system32\iccvid.dll
2011-01-11 04:44:04 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2011-01-11 04:44:03 15360 ----a-w- c:\windows\system32\pacerprf.dll
2011-01-11 04:44:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2011-01-11 04:42:57 1314816 ----a-w- c:\windows\system32\quartz.dll
2011-01-11 04:42:35 603648 ----a-w- c:\windows\system32\schedsvc.dll
2011-01-11 04:42:35 357376 ----a-w- c:\windows\system32\taskschd.dll
2011-01-11 04:42:35 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-01-11 04:42:35 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-01-11 04:42:35 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-01-11 04:40:51 81920 ----a-w- c:\windows\system32\consent.exe
2011-01-11 04:40:40 72704 ----a-w- c:\windows\system32\fontsub.dll
2011-01-11 04:40:40 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-11 04:40:40 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-01-11 04:40:28 1257472 ----a-w- c:\windows\system32\msxml3.dll
2011-01-11 04:40:08 147456 ----a-w- c:\windows\system32\Faultrep.dll
2011-01-11 04:40:08 125952 ----a-w- c:\windows\system32\wersvc.dll
2011-01-11 04:38:44 2048 ----a-w- c:\windows\system32\tzres.dll
2011-01-11 04:37:18 135168 ----a-w- c:\windows\system32\wshom.ocx
2011-01-11 04:37:17 90112 ----a-w- c:\windows\system32\wshext.dll
2011-01-11 04:37:17 155648 ----a-w- c:\windows\system32\wscript.exe
2011-01-11 04:37:17 135168 ----a-w- c:\windows\system32\cscript.exe
2011-01-11 04:37:16 180224 ----a-w- c:\windows\system32\scrobj.dll
2011-01-11 04:37:16 172032 ----a-w- c:\windows\system32\scrrun.dll
2011-01-11 04:33:01 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-01-11 04:09:38 738816 ----a-w- c:\windows\system32\inetcomm.dll
2011-01-11 04:05:30 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-01-11 04:04:36 531968 ----a-w- c:\windows\system32\comctl32.dll
2011-01-10 06:37:47 -------- d-----w- C:\PerfLogs
2011-01-10 03:35:06 -------- d-----w- c:\users\louis\appdata\local\Mozilla
2011-01-10 03:34:01 553696 ----a-w- c:\program files\mozilla firefox\uninstall\helper.exe
2011-01-10 03:17:46 -------- d-----w- c:\program files\SpywareBlaster
2011-01-10 02:46:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-10 02:46:16 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-01-10 02:40:02 -------- d-----w- c:\users\louis\appdata\roaming\SUPERAntiSpyware.com
2011-01-10 02:40:02 -------- d-----w- c:\progra~2\SUPERAntiSpyware.com
2011-01-10 02:38:24 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-01-07 04:24:35 -------- d-----w- c:\windows\pss
2011-01-07 03:49:43 -------- d-sh--w- C:\$RECYCLE.BIN
2011-01-07 03:36:13 98816 ----a-w- c:\windows\sed.exe
2011-01-07 03:36:13 89088 ----a-w- c:\windows\MBR.exe
2011-01-07 03:36:13 256512 ----a-w- c:\windows\PEV.exe
2011-01-07 03:36:13 161792 ----a-w- c:\windows\SWREG.exe
2011-01-07 03:35:51 -------- d-----w- C:\ComboFix
2011-01-06 05:00:20 1879120 ----a-w- c:\windows\system32\btscan.exe
2011-01-06 04:09:51 -------- d-----w- c:\program files\common files\AhnLab
2011-01-06 04:08:48 -------- d-----w- c:\program files\AhnLab
2011-01-06 03:59:42 -------- d-----w- c:\program files\Crawler
2011-01-06 03:59:33 -------- d-----w- c:\progra~2\AhnLab
2011-01-05 07:18:06 1541120 ----a-w- c:\windows\system32\onex.dll
2011-01-05 07:18:05 2623488 ----a-w- c:\windows\system32\SLsvc.exe
2011-01-05 07:18:04 2730536 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\default\MpEngine.dll
2011-01-05 07:16:59 69120 ----a-w- c:\windows\system32\drivers\rassstp.sys
2011-01-05 07:15:59 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-01-05 07:14:59 691200 ----a-w- c:\windows\system32\TabletPC.cpl
2011-01-05 07:13:59 15872 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-01-04 07:02:55 89600 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
2011-01-03 07:12:21 378368 ----a-w- c:\windows\system32\winhttp.dll
2011-01-03 07:09:57 269312 ----a-w- c:\windows\system32\es.dll
2011-01-03 02:03:29 -------- d-----w- c:\users\louis\appdata\local\Adobe
2011-01-02 23:50:00 248448 ----a-w- c:\windows\system32\PROUnstl.exe
2011-01-02 23:21:49 -------- d-----w- c:\progra~2\ESTsoft
2011-01-02 23:21:46 -------- d-----w- c:\users\louis\appdata\roaming\ESTsoft
2011-01-02 23:21:46 -------- d-----w- c:\program files\ESTsoft
2011-01-02 10:26:54 23552 ----a-w- c:\windows\system32\lpk.dll
2011-01-02 10:26:53 10240 ----a-w- c:\windows\system32\dciman32.dll
2011-01-02 10:24:16 72704 ----a-w- c:\windows\system32\admparse.dll
2011-01-02 10:24:10 48128 ----a-w- c:\windows\system32\mshtmler.dll
2011-01-02 10:24:04 129536 ----a-w- c:\program files\internet explorer\sqmapi.dll
2011-01-02 10:21:57 61440 ----a-w- c:\windows\system32\winipsec.dll
2011-01-02 10:21:57 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2011-01-02 10:21:57 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2011-01-02 10:21:57 272896 ----a-w- c:\windows\system32\polstore.dll
2011-01-02 10:17:33 94720 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2011-01-02 10:17:33 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2011-01-02 10:17:33 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2011-01-02 10:14:09 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2011-01-02 10:14:09 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2011-01-02 10:14:09 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2011-01-02 10:14:09 19968 ----a-w- c:\windows\system32\ARP.EXE
2011-01-02 10:14:09 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2011-01-02 10:14:09 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2011-01-02 10:14:09 104960 ----a-w- c:\windows\system32\netiohlp.dll
2011-01-02 10:14:09 10240 ----a-w- c:\windows\system32\finger.exe
2011-01-02 10:09:19 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2011-01-02 10:09:18 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2011-01-02 10:09:18 64512 ----a-w- c:\windows\system32\wlanapi.dll
2011-01-02 10:09:17 513024 ----a-w- c:\windows\system32\wlansvc.dll
2011-01-02 10:09:17 302592 ----a-w- c:\windows\system32\wlansec.dll
2011-01-02 10:09:17 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2011-01-02 10:09:17 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2011-01-02 10:07:45 2048 ----a-w- c:\windows\system32\msxml3r.dll
2011-01-02 10:07:44 2048 ----a-w- c:\windows\system32\msxml6r.dll
2011-01-02 10:07:44 1399296 ----a-w- c:\windows\system32\msxml6.dll
2011-01-02 10:06:12 213504 ----a-w- c:\windows\system32\msv1_0.dll
2011-01-02 10:04:39 78848 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-01-02 10:04:39 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-01-02 10:04:38 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-01-02 10:01:52 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-02 10:01:52 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2011-01-02 10:01:52 2868224 ----a-w- c:\windows\system32\mf.dll
2011-01-02 10:01:52 24576 ----a-w- c:\windows\system32\mfpmp.exe
2011-01-02 10:01:52 2048 ----a-w- c:\windows\system32\mferror.dll
2011-01-02 09:54:40 430080 ----a-w- c:\windows\system32\vbscript.dll
2011-01-02 09:53:17 71680 ----a-w- c:\windows\system32\atl.dll
2011-01-02 09:50:41 296960 ----a-w- c:\windows\system32\gdi32.dll
2011-01-02 09:45:15 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2011-01-02 09:45:15 38912 ----a-w- c:\windows\system32\xolehlp.dll
2011-01-02 09:43:54 160256 ----a-w- c:\windows\system32\wkssvc.dll
2011-01-02 09:42:29 53248 ----a-w- c:\windows\system32\tsgqec.dll
2011-01-02 09:42:29 2066432 ----a-w- c:\windows\system32\mstscax.dll
2011-01-02 09:42:29 136192 ----a-w- c:\windows\system32\aaclient.dll
2011-01-02 09:41:07 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2011-01-02 09:37:17 714240 ----a-w- c:\windows\system32\timedate.cpl
2011-01-02 09:31:43 23040 ----a-w- c:\program files\movie maker\WMM2EXT.dll
2011-01-02 09:31:43 195072 ----a-w- c:\program files\movie maker\WMM2AE.dll
2011-01-02 09:28:41 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-01-02 09:28:41 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-01-02 09:25:53 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-01-02 09:23:30 636928 ----a-w- c:\windows\system32\localspl.dll
2011-01-02 09:19:45 2927104 ----a-w- c:\windows\explorer.exe
2011-01-02 09:18:39 8704 ----a-w- c:\windows\system32\hccoin.dll
2011-01-02 09:18:38 15872 ----a-w- c:\windows\system32\hcrstco.dll
2011-01-02 09:16:24 171520 ----a-w- c:\windows\system32\wintrust.dll
2011-01-02 09:15:05 499712 ----a-w- c:\windows\system32\kerberos.dll
2011-01-02 09:15:05 175104 ----a-w- c:\windows\system32\wdigest.dll
2011-01-02 09:15:04 9728 ----a-w- c:\windows\system32\lsass.exe
2011-01-02 09:15:04 72704 ----a-w- c:\windows\system32\secur32.dll
2011-01-02 09:15:04 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2011-01-02 09:15:04 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2011-01-02 09:10:59 6781440 ----a-w- c:\windows\system32\NlsLexicons0019.dll
2011-01-02 09:06:29 6656 ----a-w- c:\windows\system32\kbd106n.dll
2011-01-02 09:06:24 988216 ----a-w- c:\windows\system32\winload.exe
2011-01-02 09:06:24 927288 ----a-w- c:\windows\system32\winresume.exe
2011-01-02 09:06:24 40960 ----a-w- c:\windows\system32\srclient.dll
2011-01-02 09:06:23 46592 ----a-w- c:\windows\system32\setbcdlocale.dll
2011-01-02 09:06:23 378368 ----a-w- c:\windows\system32\srcore.dll
2011-01-02 09:06:23 318464 ----a-w- c:\windows\system32\rstrui.exe
2011-01-02 09:06:23 19000 ----a-w- c:\windows\system32\kd1394.dll
2011-01-02 09:06:23 14848 ----a-w- c:\windows\system32\srdelayed.exe
2011-01-02 09:06:22 615992 ----a-w- c:\windows\system32\ci.dll
2011-01-02 09:03:52 551424 ----a-w- c:\windows\system32\rpcss.dll
2011-01-02 09:03:51 666624 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-02 09:03:51 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-02 09:03:50 615424 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-01-02 09:03:50 499200 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2011-01-02 09:03:50 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2011-01-02 09:03:50 129024 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2011-01-02 09:03:49 98304 ----a-w- c:\windows\system32\iasrecst.dll
2011-01-02 09:03:49 54784 ----a-w- c:\windows\system32\iasads.dll
2011-01-02 09:03:49 44032 ----a-w- c:\windows\system32\iasdatastore.dll
2011-01-02 09:03:49 183296 ----a-w- c:\windows\system32\sdohlp.dll
2011-01-02 09:03:49 17408 ----a-w- c:\windows\system32\iashost.exe
2011-01-02 09:02:40 62464 ----a-w- c:\windows\system32\l3codeca.acm
2011-01-02 09:02:40 220672 ----a-w- c:\windows\system32\l3codecp.acm
2011-01-02 09:00:23 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2011-01-02 09:00:23 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2011-01-02 09:00:23 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2011-01-02 08:58:19 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2011-01-02 08:56:14 24064 ----a-w- c:\windows\system32\amxread.dll
2011-01-02 08:56:14 13824 ----a-w- c:\windows\system32\apilogen.dll
2011-01-02 08:53:34 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2011-01-02 08:53:33 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2011-01-02 08:53:33 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2011-01-02 08:45:28 98304 ----a-w- c:\windows\system32\cabview.dll
2011-01-02 08:42:41 443392 ----a-w- c:\windows\system32\win32spl.dll
2011-01-02 08:42:41 37888 ----a-w- c:\windows\system32\printcom.dll
2011-01-02 08:39:50 14848 ----a-w- c:\windows\system32\wshrm.dll
2011-01-02 08:39:50 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2011-01-02 08:38:36 43520 ----a-w- c:\windows\system32\msdxm.tlb
2011-01-02 08:38:36 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2011-01-02 08:38:36 18432 ----a-w- c:\windows\system32\amcompat.tlb
2011-01-02 08:37:29 511488 ----a-w- c:\windows\system32\RMActivate.exe
2011-01-02 08:37:29 472064 ----a-w- c:\windows\system32\secproc.dll
2011-01-02 08:37:29 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2011-01-02 08:37:29 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2011-01-02 08:37:29 329216 ----a-w- c:\windows\system32\msdrm.dll
2011-01-02 08:37:29 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2011-01-02 08:37:29 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
2011-01-02 08:37:28 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2011-01-02 08:37:28 472576 ----a-w- c:\windows\system32\secproc_isv.dll
2011-01-02 08:28:17 97800 ----a-w- c:\windows\system32\infocardapi.dll
2011-01-02 08:28:17 622080 ----a-w- c:\windows\system32\icardagt.exe
2011-01-02 08:28:17 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2011-01-02 08:28:17 11264 ----a-w- c:\windows\system32\icardres.dll
2011-01-02 08:28:13 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2011-01-02 08:28:12 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2011-01-02 08:03:13 83968 ----a-w- c:\windows\system32\mscories.dll
2011-01-02 08:03:13 158720 ----a-w- c:\windows\system32\mscorier.dll
2011-01-02 07:45:33 1695744 ----a-w- c:\windows\system32\gameux.dll
2011-01-02 07:44:59 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2011-01-02 07:44:59 94720 ----a-w- c:\windows\system32\logagent.exe
2011-01-02 07:44:08 84480 ----a-w- c:\windows\system32\INETRES.dll
2011-01-02 07:43:44 61440 ----a-w- c:\windows\system32\msasn1.dll
2011-01-02 07:43:17 1645568 ----a-w- c:\windows\system32\connect.dll
2011-01-02 07:42:39 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2011-01-02 07:41:46 411136 ----a-w- c:\windows\system32\drivers\http.sys
2011-01-02 07:41:46 31232 ----a-w- c:\windows\system32\httpapi.dll
2011-01-02 07:41:45 24064 ----a-w- c:\windows\system32\nshhttp.dll
2011-01-02 07:39:35 281600 ----a-w- c:\windows\system32\raschap.dll
2011-01-02 07:39:35 244224 ----a-w- c:\windows\system32\rastls.dll
2011-01-02 07:39:14 351232 ----a-w- c:\windows\system32\WSDApi.dll
2011-01-02 07:38:39 -------- d-----w- c:\program files\MSXML 4.0
2011-01-02 07:35:48 91136 ----a-w- c:\windows\system32\avifil32.dll
2011-01-02 07:35:48 82944 ----a-w- c:\windows\system32\mciavi32.dll
2011-01-02 07:35:48 65024 ----a-w- c:\windows\system32\avicap32.dll
2011-01-02 07:35:48 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2011-01-02 07:35:48 31744 ----a-w- c:\windows\system32\msvidc32.dll
2011-01-02 07:35:48 22528 ----a-w- c:\windows\system32\msyuv.dll
2011-01-02 07:35:48 13312 ----a-w- c:\windows\system32\msrle32.dll
2011-01-02 07:35:48 123904 ----a-w- c:\windows\system32\msvfw32.dll
2011-01-02 07:35:48 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2011-01-02 07:35:16 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2011-01-02 07:34:33 7680 ----a-w- c:\windows\system32\spwmp.dll
2011-01-02 07:34:32 4096 ----a-w- c:\windows\system32\msdxm.ocx
2011-01-02 07:34:32 4096 ----a-w- c:\windows\system32\dxmasf.dll
2011-01-02 07:34:32 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2011-01-02 07:34:31 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2011-01-02 07:34:29 310784 ----a-w- c:\windows\system32\unregmp2.exe
2011-01-02 07:34:29 1418752 ----a-w- c:\program files\windows media player\setup_wm.exe
2011-01-02 03:30:38 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\backup\mpengine.dll
2011-01-02 03:30:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-01-02 03:16:59 -------- d-----w- c:\users\louis\Tracing
2011-01-02 02:53:11 -------- d-----w- c:\program files\Microsoft
2011-01-02 02:52:38 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-01-02 01:46:12 -------- d-----w- c:\program files\RocketDock
2011-01-02 01:26:51 -------- d-----w- c:\program files\JRE
2011-01-02 01:26:36 -------- d-----w- c:\program files\OpenOffice.org 3
2011-01-02 01:25:57 411368 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-02 00:54:54 -------- d-----w- c:\progra~2\Alwil Software
2011-01-01 23:36:52 -------- d-----w- c:\program files\CCleaner
2011-01-01 23:35:06 -------- d-----w- c:\program files\common files\Windows Live
2011-01-01 07:22:55 -------- d-----w- c:\users\louis\appdata\local\Google
2011-01-01 07:18:08 -------- d-----w- c:\users\louis\appdata\local\Deployment
2011-01-01 07:18:08 -------- d-----w- c:\users\louis\appdata\local\Apps
2011-01-01 05:29:04 2421760 ----a-w- c:\windows\system32\wucltux.dll
2011-01-01 05:28:16 87552 ----a-w- c:\windows\system32\wudriver.dll
2011-01-01 05:27:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2011-01-01 05:27:44 171608 ----a-w- c:\windows\system32\wuwebv.dll
2011-01-01 04:24:48 -------- d-----w- c:\users\louis\appdata\local\Hewlett-Packard
2011-01-01 04:24:25 -------- d-----w- c:\users\louis\appdata\local\QuickPlay
2011-01-01 04:21:40 757760 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2011-01-01 04:21:40 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2011-01-01 04:21:40 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2011-01-01 04:21:40 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2011-01-01 04:21:40 204800 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2011-01-01 04:21:38 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2011-01-01 04:21:38 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2011-01-01 03:58:34 -------- d-----w- c:\users\louis\appdata\local\VirtualStore
2011-01-01 03:39:12 -------- d-sh--we C:\Documents and Settings
==================== Find3M ====================
2011-01-10 05:24:09 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2011-01-10 05:24:06 82432 ----a-w- c:\windows\system32\axaltocm.dll
2011-01-02 09:10:59 11722752 ----a-w- c:\windows\system32\NlsLexicons0001.dll
2011-01-02 08:56:14 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2011-01-02 07:45:35 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2010-11-30 01:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-30 01:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-10-20 17:45:29 833024 ----a-w- c:\windows\system32\wininet.dll
2010-10-20 17:41:28 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-10-20 16:16:50 389632 ----a-w- c:\windows\system32\html.iec
2010-10-20 15:51:56 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2010-10-18 13:56:44 2037248 ----a-w- c:\windows\system32\win32k.sys
============= FINISH: 17:04:15.13 ===============
Oops, forgot Attach.zip.
I've had the Google Redirect Virus for quite a while now, and until now, I have ignored it. But now, I think I need to delete this virus once and for all.
As I expected from reading others' stories across the web, virus scanners all show up with nothing. Will it be possible to remove this virus?
Thank you.
DDS:
DDS (Ver_10-12-12.02) - NTFSx86
Run by Louis at 16:58:30.93 on 13/01/2011
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.559 [GMT -8:00]
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Vongo\VongoService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Vongo\Tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Louis\Downloads\dds(2).scr
C:\Windows\system32\conime.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
uURLSearchHooks: H - No File
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\ctbr.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\ctbr.dll
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vongot~1.lnk - c:\windows\installer\{8c3ae2d1-854d-4650-a73d-c7cc7ee36b80}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\crawler\ctbr.dll
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\louis\appdata\roaming\mozilla\firefox\profiles\64rute6x.default\
FF - prefs.js: browser.startup.homepage - www.bing.com
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: BetterPrivacy: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} - %profile%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: YouTube to MP3:
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-1-9 1153368]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480]
=============== Created Last 30 ================
2011-01-13 06:19:08 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{b017665c-368e-4013-b11c-1a392374dbc5}\mpengine.dll
2011-01-13 06:17:49 409600 ----a-w- c:\windows\system32\odbc32.dll
2011-01-13 06:17:48 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-01-13 06:17:48 57344 ----a-w- c:\program files\common files\system\msadc\msadcs.dll
2011-01-13 06:17:48 253952 ----a-w- c:\program files\common files\system\ado\msadox.dll
2011-01-13 06:17:48 241664 ----a-w- c:\program files\common files\system\ado\msadomd.dll
2011-01-13 06:17:48 180224 ----a-w- c:\program files\common files\system\msadc\msadco.dll
2011-01-13 06:17:41 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-01-12 07:03:58 -------- d-----w- c:\users\louis\appdata\local\Apple Computer
2011-01-12 06:42:43 80896 ----a-w- c:\windows\system32\MSNP.ax
2011-01-12 06:42:43 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2011-01-12 06:42:40 428544 ----a-w- c:\windows\system32\EncDec.dll
2011-01-12 06:42:40 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-01-12 06:42:40 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-01-12 06:33:30 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-01-12 06:33:30 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2011-01-12 06:31:38 -------- d-----w- c:\program files\iPod
2011-01-12 06:31:33 -------- d-----w- c:\program files\iTunes
2011-01-12 06:31:33 -------- d-----w- c:\progra~2\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-01-12 06:25:15 -------- d-----w- c:\users\louis\appdata\local\Apple
2011-01-12 06:22:43 -------- d-----w- c:\program files\Bonjour
2011-01-12 06:21:09 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-01-12 06:21:09 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-01-12 06:21:09 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-01-12 06:21:09 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-01-12 06:21:09 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-01-11 04:47:29 303616 ----a-w- c:\windows\system32\drivers\srv.sys
2011-01-11 04:47:28 17920 ----a-w- c:\windows\system32\netevent.dll
2011-01-11 04:47:28 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-01-11 04:47:28 125952 ----a-w- c:\windows\system32\srvsvc.dll
2011-01-11 04:47:28 101888 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-01-11 04:47:06 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-01-11 04:47:05 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2011-01-11 04:46:00 501760 ----a-w- c:\windows\system32\usp10.dll
2011-01-11 04:45:57 66048 ----a-w- c:\program files\windows mail\wabmig.exe
2011-01-11 04:45:57 515584 ----a-w- c:\program files\windows mail\wab.exe
2011-01-11 04:45:57 33280 ----a-w- c:\program files\windows mail\wabfind.dll
2011-01-11 04:45:55 274432 ----a-w- c:\windows\system32\schannel.dll
2011-01-11 04:44:11 1616384 ----a-w- c:\program files\windows mail\msoe.dll
2011-01-11 04:44:07 81920 ----a-w- c:\windows\system32\iccvid.dll
2011-01-11 04:44:04 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2011-01-11 04:44:03 15360 ----a-w- c:\windows\system32\pacerprf.dll
2011-01-11 04:44:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2011-01-11 04:42:57 1314816 ----a-w- c:\windows\system32\quartz.dll
2011-01-11 04:42:35 603648 ----a-w- c:\windows\system32\schedsvc.dll
2011-01-11 04:42:35 357376 ----a-w- c:\windows\system32\taskschd.dll
2011-01-11 04:42:35 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-01-11 04:42:35 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-01-11 04:42:35 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-01-11 04:40:51 81920 ----a-w- c:\windows\system32\consent.exe
2011-01-11 04:40:40 72704 ----a-w- c:\windows\system32\fontsub.dll
2011-01-11 04:40:40 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-11 04:40:40 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-01-11 04:40:28 1257472 ----a-w- c:\windows\system32\msxml3.dll
2011-01-11 04:40:08 147456 ----a-w- c:\windows\system32\Faultrep.dll
2011-01-11 04:40:08 125952 ----a-w- c:\windows\system32\wersvc.dll
2011-01-11 04:38:44 2048 ----a-w- c:\windows\system32\tzres.dll
2011-01-11 04:37:18 135168 ----a-w- c:\windows\system32\wshom.ocx
2011-01-11 04:37:17 90112 ----a-w- c:\windows\system32\wshext.dll
2011-01-11 04:37:17 155648 ----a-w- c:\windows\system32\wscript.exe
2011-01-11 04:37:17 135168 ----a-w- c:\windows\system32\cscript.exe
2011-01-11 04:37:16 180224 ----a-w- c:\windows\system32\scrobj.dll
2011-01-11 04:37:16 172032 ----a-w- c:\windows\system32\scrrun.dll
2011-01-11 04:33:01 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-01-11 04:09:38 738816 ----a-w- c:\windows\system32\inetcomm.dll
2011-01-11 04:05:30 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-01-11 04:04:36 531968 ----a-w- c:\windows\system32\comctl32.dll
2011-01-10 06:37:47 -------- d-----w- C:\PerfLogs
2011-01-10 03:35:06 -------- d-----w- c:\users\louis\appdata\local\Mozilla
2011-01-10 03:34:01 553696 ----a-w- c:\program files\mozilla firefox\uninstall\helper.exe
2011-01-10 03:17:46 -------- d-----w- c:\program files\SpywareBlaster
2011-01-10 02:46:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-10 02:46:16 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-01-10 02:40:02 -------- d-----w- c:\users\louis\appdata\roaming\SUPERAntiSpyware.com
2011-01-10 02:40:02 -------- d-----w- c:\progra~2\SUPERAntiSpyware.com
2011-01-10 02:38:24 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-01-07 04:24:35 -------- d-----w- c:\windows\pss
2011-01-07 03:49:43 -------- d-sh--w- C:\$RECYCLE.BIN
2011-01-07 03:36:13 98816 ----a-w- c:\windows\sed.exe
2011-01-07 03:36:13 89088 ----a-w- c:\windows\MBR.exe
2011-01-07 03:36:13 256512 ----a-w- c:\windows\PEV.exe
2011-01-07 03:36:13 161792 ----a-w- c:\windows\SWREG.exe
2011-01-07 03:35:51 -------- d-----w- C:\ComboFix
2011-01-06 05:00:20 1879120 ----a-w- c:\windows\system32\btscan.exe
2011-01-06 04:09:51 -------- d-----w- c:\program files\common files\AhnLab
2011-01-06 04:08:48 -------- d-----w- c:\program files\AhnLab
2011-01-06 03:59:42 -------- d-----w- c:\program files\Crawler
2011-01-06 03:59:33 -------- d-----w- c:\progra~2\AhnLab
2011-01-05 07:18:06 1541120 ----a-w- c:\windows\system32\onex.dll
2011-01-05 07:18:05 2623488 ----a-w- c:\windows\system32\SLsvc.exe
2011-01-05 07:18:04 2730536 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\default\MpEngine.dll
2011-01-05 07:16:59 69120 ----a-w- c:\windows\system32\drivers\rassstp.sys
2011-01-05 07:15:59 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-01-05 07:14:59 691200 ----a-w- c:\windows\system32\TabletPC.cpl
2011-01-05 07:13:59 15872 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-01-04 07:02:55 89600 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
2011-01-03 07:12:21 378368 ----a-w- c:\windows\system32\winhttp.dll
2011-01-03 07:09:57 269312 ----a-w- c:\windows\system32\es.dll
2011-01-03 02:03:29 -------- d-----w- c:\users\louis\appdata\local\Adobe
2011-01-02 23:50:00 248448 ----a-w- c:\windows\system32\PROUnstl.exe
2011-01-02 23:21:49 -------- d-----w- c:\progra~2\ESTsoft
2011-01-02 23:21:46 -------- d-----w- c:\users\louis\appdata\roaming\ESTsoft
2011-01-02 23:21:46 -------- d-----w- c:\program files\ESTsoft
2011-01-02 10:26:54 23552 ----a-w- c:\windows\system32\lpk.dll
2011-01-02 10:26:53 10240 ----a-w- c:\windows\system32\dciman32.dll
2011-01-02 10:24:16 72704 ----a-w- c:\windows\system32\admparse.dll
2011-01-02 10:24:10 48128 ----a-w- c:\windows\system32\mshtmler.dll
2011-01-02 10:24:04 129536 ----a-w- c:\program files\internet explorer\sqmapi.dll
2011-01-02 10:21:57 61440 ----a-w- c:\windows\system32\winipsec.dll
2011-01-02 10:21:57 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2011-01-02 10:21:57 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2011-01-02 10:21:57 272896 ----a-w- c:\windows\system32\polstore.dll
2011-01-02 10:17:33 94720 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2011-01-02 10:17:33 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2011-01-02 10:17:33 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2011-01-02 10:14:09 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2011-01-02 10:14:09 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2011-01-02 10:14:09 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2011-01-02 10:14:09 19968 ----a-w- c:\windows\system32\ARP.EXE
2011-01-02 10:14:09 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2011-01-02 10:14:09 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2011-01-02 10:14:09 104960 ----a-w- c:\windows\system32\netiohlp.dll
2011-01-02 10:14:09 10240 ----a-w- c:\windows\system32\finger.exe
2011-01-02 10:09:19 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2011-01-02 10:09:18 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2011-01-02 10:09:18 64512 ----a-w- c:\windows\system32\wlanapi.dll
2011-01-02 10:09:17 513024 ----a-w- c:\windows\system32\wlansvc.dll
2011-01-02 10:09:17 302592 ----a-w- c:\windows\system32\wlansec.dll
2011-01-02 10:09:17 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2011-01-02 10:09:17 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2011-01-02 10:07:45 2048 ----a-w- c:\windows\system32\msxml3r.dll
2011-01-02 10:07:44 2048 ----a-w- c:\windows\system32\msxml6r.dll
2011-01-02 10:07:44 1399296 ----a-w- c:\windows\system32\msxml6.dll
2011-01-02 10:06:12 213504 ----a-w- c:\windows\system32\msv1_0.dll
2011-01-02 10:04:39 78848 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-01-02 10:04:39 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-01-02 10:04:38 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-01-02 10:01:52 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-02 10:01:52 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2011-01-02 10:01:52 2868224 ----a-w- c:\windows\system32\mf.dll
2011-01-02 10:01:52 24576 ----a-w- c:\windows\system32\mfpmp.exe
2011-01-02 10:01:52 2048 ----a-w- c:\windows\system32\mferror.dll
2011-01-02 09:54:40 430080 ----a-w- c:\windows\system32\vbscript.dll
2011-01-02 09:53:17 71680 ----a-w- c:\windows\system32\atl.dll
2011-01-02 09:50:41 296960 ----a-w- c:\windows\system32\gdi32.dll
2011-01-02 09:45:15 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2011-01-02 09:45:15 38912 ----a-w- c:\windows\system32\xolehlp.dll
2011-01-02 09:43:54 160256 ----a-w- c:\windows\system32\wkssvc.dll
2011-01-02 09:42:29 53248 ----a-w- c:\windows\system32\tsgqec.dll
2011-01-02 09:42:29 2066432 ----a-w- c:\windows\system32\mstscax.dll
2011-01-02 09:42:29 136192 ----a-w- c:\windows\system32\aaclient.dll
2011-01-02 09:41:07 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2011-01-02 09:37:17 714240 ----a-w- c:\windows\system32\timedate.cpl
2011-01-02 09:31:43 23040 ----a-w- c:\program files\movie maker\WMM2EXT.dll
2011-01-02 09:31:43 195072 ----a-w- c:\program files\movie maker\WMM2AE.dll
2011-01-02 09:28:41 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-01-02 09:28:41 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-01-02 09:25:53 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-01-02 09:23:30 636928 ----a-w- c:\windows\system32\localspl.dll
2011-01-02 09:19:45 2927104 ----a-w- c:\windows\explorer.exe
2011-01-02 09:18:39 8704 ----a-w- c:\windows\system32\hccoin.dll
2011-01-02 09:18:38 15872 ----a-w- c:\windows\system32\hcrstco.dll
2011-01-02 09:16:24 171520 ----a-w- c:\windows\system32\wintrust.dll
2011-01-02 09:15:05 499712 ----a-w- c:\windows\system32\kerberos.dll
2011-01-02 09:15:05 175104 ----a-w- c:\windows\system32\wdigest.dll
2011-01-02 09:15:04 9728 ----a-w- c:\windows\system32\lsass.exe
2011-01-02 09:15:04 72704 ----a-w- c:\windows\system32\secur32.dll
2011-01-02 09:15:04 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2011-01-02 09:15:04 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2011-01-02 09:10:59 6781440 ----a-w- c:\windows\system32\NlsLexicons0019.dll
2011-01-02 09:06:29 6656 ----a-w- c:\windows\system32\kbd106n.dll
2011-01-02 09:06:24 988216 ----a-w- c:\windows\system32\winload.exe
2011-01-02 09:06:24 927288 ----a-w- c:\windows\system32\winresume.exe
2011-01-02 09:06:24 40960 ----a-w- c:\windows\system32\srclient.dll
2011-01-02 09:06:23 46592 ----a-w- c:\windows\system32\setbcdlocale.dll
2011-01-02 09:06:23 378368 ----a-w- c:\windows\system32\srcore.dll
2011-01-02 09:06:23 318464 ----a-w- c:\windows\system32\rstrui.exe
2011-01-02 09:06:23 19000 ----a-w- c:\windows\system32\kd1394.dll
2011-01-02 09:06:23 14848 ----a-w- c:\windows\system32\srdelayed.exe
2011-01-02 09:06:22 615992 ----a-w- c:\windows\system32\ci.dll
2011-01-02 09:03:52 551424 ----a-w- c:\windows\system32\rpcss.dll
2011-01-02 09:03:51 666624 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-02 09:03:51 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-02 09:03:50 615424 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-01-02 09:03:50 499200 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2011-01-02 09:03:50 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2011-01-02 09:03:50 129024 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2011-01-02 09:03:49 98304 ----a-w- c:\windows\system32\iasrecst.dll
2011-01-02 09:03:49 54784 ----a-w- c:\windows\system32\iasads.dll
2011-01-02 09:03:49 44032 ----a-w- c:\windows\system32\iasdatastore.dll
2011-01-02 09:03:49 183296 ----a-w- c:\windows\system32\sdohlp.dll
2011-01-02 09:03:49 17408 ----a-w- c:\windows\system32\iashost.exe
2011-01-02 09:02:40 62464 ----a-w- c:\windows\system32\l3codeca.acm
2011-01-02 09:02:40 220672 ----a-w- c:\windows\system32\l3codecp.acm
2011-01-02 09:00:23 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2011-01-02 09:00:23 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2011-01-02 09:00:23 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2011-01-02 08:58:19 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2011-01-02 08:56:14 24064 ----a-w- c:\windows\system32\amxread.dll
2011-01-02 08:56:14 13824 ----a-w- c:\windows\system32\apilogen.dll
2011-01-02 08:53:34 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2011-01-02 08:53:33 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2011-01-02 08:53:33 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2011-01-02 08:45:28 98304 ----a-w- c:\windows\system32\cabview.dll
2011-01-02 08:42:41 443392 ----a-w- c:\windows\system32\win32spl.dll
2011-01-02 08:42:41 37888 ----a-w- c:\windows\system32\printcom.dll
2011-01-02 08:39:50 14848 ----a-w- c:\windows\system32\wshrm.dll
2011-01-02 08:39:50 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2011-01-02 08:38:36 43520 ----a-w- c:\windows\system32\msdxm.tlb
2011-01-02 08:38:36 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2011-01-02 08:38:36 18432 ----a-w- c:\windows\system32\amcompat.tlb
2011-01-02 08:37:29 511488 ----a-w- c:\windows\system32\RMActivate.exe
2011-01-02 08:37:29 472064 ----a-w- c:\windows\system32\secproc.dll
2011-01-02 08:37:29 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2011-01-02 08:37:29 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2011-01-02 08:37:29 329216 ----a-w- c:\windows\system32\msdrm.dll
2011-01-02 08:37:29 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2011-01-02 08:37:29 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
2011-01-02 08:37:28 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2011-01-02 08:37:28 472576 ----a-w- c:\windows\system32\secproc_isv.dll
2011-01-02 08:28:17 97800 ----a-w- c:\windows\system32\infocardapi.dll
2011-01-02 08:28:17 622080 ----a-w- c:\windows\system32\icardagt.exe
2011-01-02 08:28:17 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2011-01-02 08:28:17 11264 ----a-w- c:\windows\system32\icardres.dll
2011-01-02 08:28:13 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2011-01-02 08:28:12 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2011-01-02 08:03:13 83968 ----a-w- c:\windows\system32\mscories.dll
2011-01-02 08:03:13 158720 ----a-w- c:\windows\system32\mscorier.dll
2011-01-02 07:45:33 1695744 ----a-w- c:\windows\system32\gameux.dll
2011-01-02 07:44:59 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2011-01-02 07:44:59 94720 ----a-w- c:\windows\system32\logagent.exe
2011-01-02 07:44:08 84480 ----a-w- c:\windows\system32\INETRES.dll
2011-01-02 07:43:44 61440 ----a-w- c:\windows\system32\msasn1.dll
2011-01-02 07:43:17 1645568 ----a-w- c:\windows\system32\connect.dll
2011-01-02 07:42:39 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2011-01-02 07:41:46 411136 ----a-w- c:\windows\system32\drivers\http.sys
2011-01-02 07:41:46 31232 ----a-w- c:\windows\system32\httpapi.dll
2011-01-02 07:41:45 24064 ----a-w- c:\windows\system32\nshhttp.dll
2011-01-02 07:39:35 281600 ----a-w- c:\windows\system32\raschap.dll
2011-01-02 07:39:35 244224 ----a-w- c:\windows\system32\rastls.dll
2011-01-02 07:39:14 351232 ----a-w- c:\windows\system32\WSDApi.dll
2011-01-02 07:38:39 -------- d-----w- c:\program files\MSXML 4.0
2011-01-02 07:35:48 91136 ----a-w- c:\windows\system32\avifil32.dll
2011-01-02 07:35:48 82944 ----a-w- c:\windows\system32\mciavi32.dll
2011-01-02 07:35:48 65024 ----a-w- c:\windows\system32\avicap32.dll
2011-01-02 07:35:48 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2011-01-02 07:35:48 31744 ----a-w- c:\windows\system32\msvidc32.dll
2011-01-02 07:35:48 22528 ----a-w- c:\windows\system32\msyuv.dll
2011-01-02 07:35:48 13312 ----a-w- c:\windows\system32\msrle32.dll
2011-01-02 07:35:48 123904 ----a-w- c:\windows\system32\msvfw32.dll
2011-01-02 07:35:48 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2011-01-02 07:35:16 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2011-01-02 07:34:33 7680 ----a-w- c:\windows\system32\spwmp.dll
2011-01-02 07:34:32 4096 ----a-w- c:\windows\system32\msdxm.ocx
2011-01-02 07:34:32 4096 ----a-w- c:\windows\system32\dxmasf.dll
2011-01-02 07:34:32 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2011-01-02 07:34:31 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2011-01-02 07:34:29 310784 ----a-w- c:\windows\system32\unregmp2.exe
2011-01-02 07:34:29 1418752 ----a-w- c:\program files\windows media player\setup_wm.exe
2011-01-02 03:30:38 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\backup\mpengine.dll
2011-01-02 03:30:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-01-02 03:16:59 -------- d-----w- c:\users\louis\Tracing
2011-01-02 02:53:11 -------- d-----w- c:\program files\Microsoft
2011-01-02 02:52:38 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-01-02 01:46:12 -------- d-----w- c:\program files\RocketDock
2011-01-02 01:26:51 -------- d-----w- c:\program files\JRE
2011-01-02 01:26:36 -------- d-----w- c:\program files\OpenOffice.org 3
2011-01-02 01:25:57 411368 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-02 00:54:54 -------- d-----w- c:\progra~2\Alwil Software
2011-01-01 23:36:52 -------- d-----w- c:\program files\CCleaner
2011-01-01 23:35:06 -------- d-----w- c:\program files\common files\Windows Live
2011-01-01 07:22:55 -------- d-----w- c:\users\louis\appdata\local\Google
2011-01-01 07:18:08 -------- d-----w- c:\users\louis\appdata\local\Deployment
2011-01-01 07:18:08 -------- d-----w- c:\users\louis\appdata\local\Apps
2011-01-01 05:29:04 2421760 ----a-w- c:\windows\system32\wucltux.dll
2011-01-01 05:28:16 87552 ----a-w- c:\windows\system32\wudriver.dll
2011-01-01 05:27:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2011-01-01 05:27:44 171608 ----a-w- c:\windows\system32\wuwebv.dll
2011-01-01 04:24:48 -------- d-----w- c:\users\louis\appdata\local\Hewlett-Packard
2011-01-01 04:24:25 -------- d-----w- c:\users\louis\appdata\local\QuickPlay
2011-01-01 04:21:40 757760 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2011-01-01 04:21:40 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2011-01-01 04:21:40 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2011-01-01 04:21:40 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2011-01-01 04:21:40 204800 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2011-01-01 04:21:38 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2011-01-01 04:21:38 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2011-01-01 03:58:34 -------- d-----w- c:\users\louis\appdata\local\VirtualStore
2011-01-01 03:39:12 -------- d-sh--we C:\Documents and Settings
==================== Find3M ====================
2011-01-10 05:24:09 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2011-01-10 05:24:06 82432 ----a-w- c:\windows\system32\axaltocm.dll
2011-01-02 09:10:59 11722752 ----a-w- c:\windows\system32\NlsLexicons0001.dll
2011-01-02 08:56:14 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2011-01-02 07:45:35 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2010-11-30 01:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-30 01:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-10-20 17:45:29 833024 ----a-w- c:\windows\system32\wininet.dll
2010-10-20 17:41:28 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-10-20 16:16:50 389632 ----a-w- c:\windows\system32\html.iec
2010-10-20 15:51:56 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2010-10-18 13:56:44 2037248 ----a-w- c:\windows\system32\win32k.sys
============= FINISH: 17:04:15.13 ===============
Oops, forgot Attach.zip.