Hi
Needs some help getting rid of this one, nasty to kill as keeps loading itself back in. Tried killing via msconfig and reg, also tried killing the files once i killed the processes but something i am missing keeps loading it back in.
Any help you can give on this one would be great guys
Cheers
Attached the attach file also, forgot that one
DDS (Ver_10-03-17.01) - NTFSX64
Run by Maxybo at 1:04:11.79 on 04/10/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.6135.4360 [GMT 1:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\system\svchost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Startup.exe
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Core.exe
E:\itunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.HookHost.exe
C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.HookHost64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskmgr.exe
C:\Windows\regedit.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\SysWOW64\drivers\safesurf.exe
C:\Windows\SysWOW64\drivers\surfguard.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Maxybo\Desktop\Removal\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - "c:\program files\bitdefender\bitdefender 2010\antispam32\IEToolbar.dll"
uRun: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
mRun: [MSIAfterburner] "c:\program files (x86)\msi afterburner\MSIAfterburnerWrapper.exe" /s
mRun: [Matrox PowerDesk] "c:\program files (x86)\matrox graphics\powerdesk\Matrox.PDesk.Startup.exe"
mRun: [iTunesHelper] "e:\itunes\iTunesHelper.exe"
mRun: [jsafesurf] c:\windows\syswow64\drivers\safesurf.exe
dRunOnce: [FlashPlayerUpdate] c:\windows\syswow64\macromed\flash\FlashUtil10i_Plugin.exe -update plugin
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab
TB-X64: BitDefender Toolbar: {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - "c:\program files\bitdefender\bitdefender 2010\IEToolbar.dll"
mRun-x64: [BitDefender Antiphishing Helper 32] "c:\program files\bitdefender\bitdefender 2010\antispam32\IEShow.exe"
mRun-x64: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2010\IEShow.exe"
mRun-x64: [BDAgent] "c:\program files\bitdefender\bitdefender 2010\bdagent.exe"
================= FIREFOX ===================
FF - ProfilePath - c:\users\maxybo\appdata\roaming\mozilla\firefox\profiles\3djj8rmt.default\
FF - prefs.js: browser.startup.homepage - www.google.co.uk
FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff2.dll
FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.6.dll
FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.dll
FF - plugin: c:\program files (x86)\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files (x86)\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files (x86)\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\windows\syswow64\macromed\flash\NPSWF32.dll
FF - plugin: e:\itunes\mozilla plugins\npitunes.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\windows\system32\drivers\BdfNdisf6.sys [2009-10-19 88144]
R1 bdfwfpf;bdfwfpf;c:\program files\common files\bitdefender\bitdefender firewall\bdfwfpf.sys [2010-1-4 89680]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 59904]
R2 BDVEDISK;BDVEDISK;c:\program files\bitdefender\bitdefender 2010\bdvedisk.sys [2010-1-19 103944]
R2 Matrox.Pdesk3.ServicesHost;Matrox.Pdesk3.ServicesHost;c:\program files (x86)\matrox graphics\powerdesk\Matrox.PDesk.Services.exe [2010-5-21 3645256]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-9-10 369256]
R2 Win_Updater;Win32 Updater;c:\windows\syswow64\system\svchost.exe [2010-8-21 1405440]
R3 BDFM;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-1-29 163936]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2010-5-5 202840]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2010-5-5 1417304]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2010-5-5 94808]
R3 RTCore64;RTCore64;c:\program files (x86)\msi afterburner\RTCore64.sys [2010-6-7 14648]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-12-19 314400]
R3 SaiH0762;SaiH0762;c:\windows\system32\drivers\SaiH0762.sys [2008-2-15 178304]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-8-17 30336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2009-10-19 278224]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2010-9-4 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2010-5-5 202840]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2010-5-5 1417304]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2010-5-5 94808]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-10-3 16776]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-10-3 9096]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-9-18 155752]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys [2010-4-19 50688]
=============== Created Last 30 ================
2010-10-03 22:51:53 0 d-----w- c:\users\maxybo\appdata\roaming\Malwarebytes
2010-10-03 22:51:46 24664 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-03 22:51:46 0 d-----w- c:\programdata\Malwarebytes
2010-10-03 22:51:46 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2010-10-03 22:38:42 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-10-03 22:38:42 0 d-----w- c:\program files (x86)\Spybot - Search & Destroy
2010-10-03 22:10:29 9096 ----a-w- c:\windows\system32\EuGdiDrv.sys
2010-10-03 22:10:29 86408 ----a-w- c:\windows\syswow64\setupempdrv03.exe
2010-10-03 22:10:29 8456 ----a-w- c:\windows\syswow64\EuGdiDrv.sys
2010-10-03 22:10:29 2209920 ----a-w- c:\windows\system32\BootMan.exe
2010-10-03 22:10:29 1774720 ----a-w- c:\windows\syswow64\BootMan.exe
2010-10-03 22:10:29 16776 ----a-w- c:\windows\system32\epmntdrv.sys
2010-10-03 22:10:29 14848 ----a-w- c:\windows\syswow64\EuEpmGdi.dll
2010-10-03 22:10:29 14216 ----a-w- c:\windows\syswow64\epmntdrv.sys
2010-10-03 22:10:29 11264 ----a-w- c:\windows\system32\EuEpmGdi.dll
2010-10-03 22:10:29 100232 ----a-w- c:\windows\system32\setupempdrvx64.exe
2010-10-03 22:10:24 0 d-----w- c:\program files (x86)\EASEUS
2010-09-28 20:27:02 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-28 20:26:59 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-09-28 20:26:59 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-25 12:52:44 0 ----a-w- c:\windows\syswow64\DotNet.exe
2010-09-25 12:13:01 0 d-----w- c:\users\maxybo\Tracing
2010-09-25 12:10:56 0 d-----w- c:\program files (x86)\Microsoft
2010-09-25 12:10:44 0 d-----w- c:\program files (x86)\Windows Live SkyDrive
2010-09-25 12:01:54 0 d-----w- c:\program files (x86)\common files\Windows Live
2010-09-25 10:49:09 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01007.Wdf
2010-09-24 17:12:58 0 d-----w- c:\programdata\Codemasters
2010-09-24 17:12:44 17686528 ----a-w- c:\windows\syswow64\mkl_blueripple.dll
2010-09-24 17:12:44 1380352 ----a-w- c:\windows\syswow64\rapture3d_oal.dll
2010-09-24 17:12:43 0 d-----w- c:\program files (x86)\BRS
2010-09-24 17:12:40 0 d-----w- c:\windows\syswow64\xlive
2010-09-24 17:12:39 0 d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2010-09-23 09:33:38 0 d-----w- c:\windows\syswow64\directx
2010-09-22 19:51:12 0 d-----w- c:\users\maxybo\appdata\roaming\NVIDIA
2010-09-22 19:50:33 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-09-22 19:50:33 467984 ----a-w- c:\windows\syswow64\d3dx10_39.dll
2010-09-22 19:50:33 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-09-22 19:50:33 1493528 ----a-w- c:\windows\syswow64\D3DCompiler_39.dll
2010-09-22 19:50:32 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-09-22 19:50:32 3851784 ----a-w- c:\windows\syswow64\D3DX9_39.dll
2010-09-22 19:50:29 0 d-----w- c:\windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP
2010-09-22 19:50:29 0 d-----w- c:\program files (x86)\common files\Wise Installation Wizard
2010-09-21 20:14:57 0 d-----w- c:\users\maxybo\appdata\roaming\Atlus
2010-09-20 19:18:04 0 d-----w- c:\program files (x86)\common files\Steam
2010-09-19 19:14:30 0 d-----w- c:\programdata\Fugazo
2010-09-19 19:13:10 4286 ----a-w- c:\windows\syswow64\ico.ico
2010-09-19 19:13:10 0 d-----w- c:\windows\syswow64\system
2010-09-19 19:13:09 0 d-----w- c:\windows\syswow64\webem
2010-09-19 00:14:17 0 d-----w- c:\program files\iTunes
2010-09-19 00:14:17 0 d-----w- c:\program files\iPod
2010-09-19 00:14:05 0 d-----w- c:\program files\common files\Apple
2010-09-19 00:14:02 0 d-----w- c:\program files\Bonjour
2010-09-19 00:14:02 0 d-----w- c:\program files (x86)\Bonjour
2010-09-18 16:44:44 0 d-----w- c:\programdata\NVIDIA
2010-09-18 15:30:04 0 d-----w- c:\programdata\Sun
2010-09-18 15:29:56 423656 ----a-w- c:\windows\syswow64\deployJava1.dll
2010-09-18 15:29:56 153376 ----a-w- c:\windows\syswow64\javaws.exe
2010-09-18 15:29:56 145184 ----a-w- c:\windows\syswow64\javaw.exe
2010-09-18 15:29:56 145184 ----a-w- c:\windows\syswow64\java.exe
2010-09-14 20:56:50 2058752 ----a-w- c:\windows\syswow64\iertutil.dll
2010-09-14 20:56:46 558592 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-13 20:52:27 0 d-----w- c:\programdata\eSellerate
2010-09-10 23:55:12 5792360 ----a-w- c:\windows\system32\nvcpl.dll
2010-09-10 23:55:00 990312 ----a-w- c:\windows\system32\nvvsvc.exe
2010-09-10 23:55:00 61032 ----a-w- c:\windows\system32\nvshext.dll
2010-09-10 23:55:00 2570344 ----a-w- c:\windows\system32\nvsvc64.dll
2010-09-10 23:55:00 1881704 ----a-w- c:\windows\system32\nvsvcr.dll
2010-09-10 23:55:00 116328 ----a-w- c:\windows\system32\nvmctray.dll
2010-09-08 10:17:46 94208 ----a-w- c:\windows\syswow64\QuickTimeVR.qtx
2010-09-08 10:17:46 69632 ----a-w- c:\windows\syswow64\QuickTime.qts
2010-09-06 19:04:08 0 d-----w- c:\program files\Hewlett-Packard
2010-09-06 19:04:07 0 ----a-w- c:\windows\HPMProp.INI
2010-09-06 19:03:56 0 d-----w- c:\programdata\Hewlett-Packard
2010-09-05 18:57:27 0 d-----w- c:\program files (x86)\Microsoft Games
2010-09-04 19:09:20 788 ----a-w- c:\windows\system32\DVCState-{00000008-00000000-00000001-00001102-00000005-00231102}.rfx
2010-09-04 19:09:20 61256 ----a-w- c:\windows\system32\BMXStateBkp-{00000008-00000000-00000001-00001102-00000005-00231102}.rfx
2010-09-04 19:09:20 61256 ----a-w- c:\windows\system32\BMXState-{00000008-00000000-00000001-00001102-00000005-00231102}.rfx
2010-09-04 19:08:31 0 d--h--w- c:\program files (x86)\Creative Installation Information
2010-09-04 19:08:31 0 d-----w- c:\program files (x86)\common files\Creative
2010-09-04 19:08:26 0 d-----w- c:\program files (x86)\common files\Creative Labs Shared
2010-09-04 19:08:19 0 d-----w- c:\program files\Creative
2010-09-04 19:08:15 0 d-----w- c:\program files (x86)\Creative
2010-09-04 19:08:07 107008 ----a-w- c:\windows\system32\cttele64.dll
2010-09-04 19:07:33 0 d-----w- c:\windows\system32\Data
2010-09-04 16:24:58 0 d-----w- C:\Games
2010-09-04 16:20:23 0 d-----w- c:\users\maxybo\appdata\roaming\YoudaGames
==================== Find3M ====================
2010-09-24 17:12:43 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2010-09-24 17:12:43 445016 ----a-w- c:\windows\syswow64\wrap_oal.dll
2010-09-07 20:09:02 29288 ----a-w- c:\windows\system32\nvhdap64.dll
2010-09-07 20:08:55 155752 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2010-09-07 20:08:54 1308776 ----a-w- c:\windows\system32\nvgenco64.dll
2010-09-04 19:08:05 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2010-09-04 19:08:05 109144 ----a-w- c:\windows\syswow64\OpenAL32.dll
2010-08-09 18:53:57 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-08-08 19:35:44 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-08-03 12:54:48 178800 ----a-w- c:\windows\syswow64\CmdLineExt_x64.dll
2010-07-31 19:12:02 737280 ----a-w- c:\windows\iun6002.exe
2010-07-30 19:32:45 286720 ----a-w- c:\windows\iun506.exe
2010-07-29 06:30:34 82944 ----a-w- c:\windows\syswow64\iccvid.dll
2010-07-27 17:55:50 95520 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 17:55:50 69408 ----a-w- c:\windows\system32\jdns_sd.dll
2010-07-27 17:55:50 237856 ----a-w- c:\windows\system32\dnssdX.dll
2010-07-27 17:55:50 119584 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-27 17:44:10 91424 ----a-w- c:\windows\syswow64\dnssd.dll
2010-07-27 17:44:10 75040 ----a-w- c:\windows\syswow64\jdns_sd.dll
2010-07-27 17:44:10 197920 ----a-w- c:\windows\syswow64\dnssdX.dll
2010-07-27 17:44:10 107808 ----a-w- c:\windows\syswow64\dns-sd.exe
2010-07-27 14:03:24 12867584 ----a-w- c:\windows\syswow64\shell32.dll
2010-07-09 22:38:00 930272 ----a-w- c:\windows\system32\dpinst.exe
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 1:04:20.74 ===============
Needs some help getting rid of this one, nasty to kill as keeps loading itself back in. Tried killing via msconfig and reg, also tried killing the files once i killed the processes but something i am missing keeps loading it back in.
Any help you can give on this one would be great guys

Cheers
Attached the attach file also, forgot that one

DDS (Ver_10-03-17.01) - NTFSX64
Run by Maxybo at 1:04:11.79 on 04/10/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.6135.4360 [GMT 1:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\system\svchost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Startup.exe
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Core.exe
E:\itunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.HookHost.exe
C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.HookHost64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskmgr.exe
C:\Windows\regedit.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\SysWOW64\drivers\safesurf.exe
C:\Windows\SysWOW64\drivers\surfguard.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Maxybo\Desktop\Removal\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - "c:\program files\bitdefender\bitdefender 2010\antispam32\IEToolbar.dll"
uRun: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
mRun: [MSIAfterburner] "c:\program files (x86)\msi afterburner\MSIAfterburnerWrapper.exe" /s
mRun: [Matrox PowerDesk] "c:\program files (x86)\matrox graphics\powerdesk\Matrox.PDesk.Startup.exe"
mRun: [iTunesHelper] "e:\itunes\iTunesHelper.exe"
mRun: [jsafesurf] c:\windows\syswow64\drivers\safesurf.exe
dRunOnce: [FlashPlayerUpdate] c:\windows\syswow64\macromed\flash\FlashUtil10i_Plugin.exe -update plugin
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab
TB-X64: BitDefender Toolbar: {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - "c:\program files\bitdefender\bitdefender 2010\IEToolbar.dll"
mRun-x64: [BitDefender Antiphishing Helper 32] "c:\program files\bitdefender\bitdefender 2010\antispam32\IEShow.exe"
mRun-x64: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2010\IEShow.exe"
mRun-x64: [BDAgent] "c:\program files\bitdefender\bitdefender 2010\bdagent.exe"
================= FIREFOX ===================
FF - ProfilePath - c:\users\maxybo\appdata\roaming\mozilla\firefox\profiles\3djj8rmt.default\
FF - prefs.js: browser.startup.homepage - www.google.co.uk
FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff2.dll
FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.6.dll
FF - component: c:\program files\bitdefender\bitdefender 2010\bdaphffext\components\bdaphff3.dll
FF - plugin: c:\program files (x86)\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files (x86)\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files (x86)\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\windows\syswow64\macromed\flash\NPSWF32.dll
FF - plugin: e:\itunes\mozilla plugins\npitunes.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\windows\system32\drivers\BdfNdisf6.sys [2009-10-19 88144]
R1 bdfwfpf;bdfwfpf;c:\program files\common files\bitdefender\bitdefender firewall\bdfwfpf.sys [2010-1-4 89680]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 59904]
R2 BDVEDISK;BDVEDISK;c:\program files\bitdefender\bitdefender 2010\bdvedisk.sys [2010-1-19 103944]
R2 Matrox.Pdesk3.ServicesHost;Matrox.Pdesk3.ServicesHost;c:\program files (x86)\matrox graphics\powerdesk\Matrox.PDesk.Services.exe [2010-5-21 3645256]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-9-10 369256]
R2 Win_Updater;Win32 Updater;c:\windows\syswow64\system\svchost.exe [2010-8-21 1405440]
R3 BDFM;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-1-29 163936]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2010-5-5 202840]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2010-5-5 1417304]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2010-5-5 94808]
R3 RTCore64;RTCore64;c:\program files (x86)\msi afterburner\RTCore64.sys [2010-6-7 14648]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-12-19 314400]
R3 SaiH0762;SaiH0762;c:\windows\system32\drivers\SaiH0762.sys [2008-2-15 178304]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-8-17 30336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2009-10-19 278224]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2010-9-4 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2010-5-5 202840]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2010-5-5 1417304]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2010-5-5 94808]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-10-3 16776]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-10-3 9096]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-9-18 155752]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys [2010-4-19 50688]
=============== Created Last 30 ================
2010-10-03 22:51:53 0 d-----w- c:\users\maxybo\appdata\roaming\Malwarebytes
2010-10-03 22:51:46 24664 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-03 22:51:46 0 d-----w- c:\programdata\Malwarebytes
2010-10-03 22:51:46 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2010-10-03 22:38:42 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-10-03 22:38:42 0 d-----w- c:\program files (x86)\Spybot - Search & Destroy
2010-10-03 22:10:29 9096 ----a-w- c:\windows\system32\EuGdiDrv.sys
2010-10-03 22:10:29 86408 ----a-w- c:\windows\syswow64\setupempdrv03.exe
2010-10-03 22:10:29 8456 ----a-w- c:\windows\syswow64\EuGdiDrv.sys
2010-10-03 22:10:29 2209920 ----a-w- c:\windows\system32\BootMan.exe
2010-10-03 22:10:29 1774720 ----a-w- c:\windows\syswow64\BootMan.exe
2010-10-03 22:10:29 16776 ----a-w- c:\windows\system32\epmntdrv.sys
2010-10-03 22:10:29 14848 ----a-w- c:\windows\syswow64\EuEpmGdi.dll
2010-10-03 22:10:29 14216 ----a-w- c:\windows\syswow64\epmntdrv.sys
2010-10-03 22:10:29 11264 ----a-w- c:\windows\system32\EuEpmGdi.dll
2010-10-03 22:10:29 100232 ----a-w- c:\windows\system32\setupempdrvx64.exe
2010-10-03 22:10:24 0 d-----w- c:\program files (x86)\EASEUS
2010-09-28 20:27:02 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-28 20:26:59 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-09-28 20:26:59 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-25 12:52:44 0 ----a-w- c:\windows\syswow64\DotNet.exe
2010-09-25 12:13:01 0 d-----w- c:\users\maxybo\Tracing
2010-09-25 12:10:56 0 d-----w- c:\program files (x86)\Microsoft
2010-09-25 12:10:44 0 d-----w- c:\program files (x86)\Windows Live SkyDrive
2010-09-25 12:01:54 0 d-----w- c:\program files (x86)\common files\Windows Live
2010-09-25 10:49:09 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01007.Wdf
2010-09-24 17:12:58 0 d-----w- c:\programdata\Codemasters
2010-09-24 17:12:44 17686528 ----a-w- c:\windows\syswow64\mkl_blueripple.dll
2010-09-24 17:12:44 1380352 ----a-w- c:\windows\syswow64\rapture3d_oal.dll
2010-09-24 17:12:43 0 d-----w- c:\program files (x86)\BRS
2010-09-24 17:12:40 0 d-----w- c:\windows\syswow64\xlive
2010-09-24 17:12:39 0 d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2010-09-23 09:33:38 0 d-----w- c:\windows\syswow64\directx
2010-09-22 19:51:12 0 d-----w- c:\users\maxybo\appdata\roaming\NVIDIA
2010-09-22 19:50:33 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-09-22 19:50:33 467984 ----a-w- c:\windows\syswow64\d3dx10_39.dll
2010-09-22 19:50:33 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-09-22 19:50:33 1493528 ----a-w- c:\windows\syswow64\D3DCompiler_39.dll
2010-09-22 19:50:32 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-09-22 19:50:32 3851784 ----a-w- c:\windows\syswow64\D3DX9_39.dll
2010-09-22 19:50:29 0 d-----w- c:\windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP
2010-09-22 19:50:29 0 d-----w- c:\program files (x86)\common files\Wise Installation Wizard
2010-09-21 20:14:57 0 d-----w- c:\users\maxybo\appdata\roaming\Atlus
2010-09-20 19:18:04 0 d-----w- c:\program files (x86)\common files\Steam
2010-09-19 19:14:30 0 d-----w- c:\programdata\Fugazo
2010-09-19 19:13:10 4286 ----a-w- c:\windows\syswow64\ico.ico
2010-09-19 19:13:10 0 d-----w- c:\windows\syswow64\system
2010-09-19 19:13:09 0 d-----w- c:\windows\syswow64\webem
2010-09-19 00:14:17 0 d-----w- c:\program files\iTunes
2010-09-19 00:14:17 0 d-----w- c:\program files\iPod
2010-09-19 00:14:05 0 d-----w- c:\program files\common files\Apple
2010-09-19 00:14:02 0 d-----w- c:\program files\Bonjour
2010-09-19 00:14:02 0 d-----w- c:\program files (x86)\Bonjour
2010-09-18 16:44:44 0 d-----w- c:\programdata\NVIDIA
2010-09-18 15:30:04 0 d-----w- c:\programdata\Sun
2010-09-18 15:29:56 423656 ----a-w- c:\windows\syswow64\deployJava1.dll
2010-09-18 15:29:56 153376 ----a-w- c:\windows\syswow64\javaws.exe
2010-09-18 15:29:56 145184 ----a-w- c:\windows\syswow64\javaw.exe
2010-09-18 15:29:56 145184 ----a-w- c:\windows\syswow64\java.exe
2010-09-14 20:56:50 2058752 ----a-w- c:\windows\syswow64\iertutil.dll
2010-09-14 20:56:46 558592 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-13 20:52:27 0 d-----w- c:\programdata\eSellerate
2010-09-10 23:55:12 5792360 ----a-w- c:\windows\system32\nvcpl.dll
2010-09-10 23:55:00 990312 ----a-w- c:\windows\system32\nvvsvc.exe
2010-09-10 23:55:00 61032 ----a-w- c:\windows\system32\nvshext.dll
2010-09-10 23:55:00 2570344 ----a-w- c:\windows\system32\nvsvc64.dll
2010-09-10 23:55:00 1881704 ----a-w- c:\windows\system32\nvsvcr.dll
2010-09-10 23:55:00 116328 ----a-w- c:\windows\system32\nvmctray.dll
2010-09-08 10:17:46 94208 ----a-w- c:\windows\syswow64\QuickTimeVR.qtx
2010-09-08 10:17:46 69632 ----a-w- c:\windows\syswow64\QuickTime.qts
2010-09-06 19:04:08 0 d-----w- c:\program files\Hewlett-Packard
2010-09-06 19:04:07 0 ----a-w- c:\windows\HPMProp.INI
2010-09-06 19:03:56 0 d-----w- c:\programdata\Hewlett-Packard
2010-09-05 18:57:27 0 d-----w- c:\program files (x86)\Microsoft Games
2010-09-04 19:09:20 788 ----a-w- c:\windows\system32\DVCState-{00000008-00000000-00000001-00001102-00000005-00231102}.rfx
2010-09-04 19:09:20 61256 ----a-w- c:\windows\system32\BMXStateBkp-{00000008-00000000-00000001-00001102-00000005-00231102}.rfx
2010-09-04 19:09:20 61256 ----a-w- c:\windows\system32\BMXState-{00000008-00000000-00000001-00001102-00000005-00231102}.rfx
2010-09-04 19:08:31 0 d--h--w- c:\program files (x86)\Creative Installation Information
2010-09-04 19:08:31 0 d-----w- c:\program files (x86)\common files\Creative
2010-09-04 19:08:26 0 d-----w- c:\program files (x86)\common files\Creative Labs Shared
2010-09-04 19:08:19 0 d-----w- c:\program files\Creative
2010-09-04 19:08:15 0 d-----w- c:\program files (x86)\Creative
2010-09-04 19:08:07 107008 ----a-w- c:\windows\system32\cttele64.dll
2010-09-04 19:07:33 0 d-----w- c:\windows\system32\Data
2010-09-04 16:24:58 0 d-----w- C:\Games
2010-09-04 16:20:23 0 d-----w- c:\users\maxybo\appdata\roaming\YoudaGames
==================== Find3M ====================
2010-09-24 17:12:43 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2010-09-24 17:12:43 445016 ----a-w- c:\windows\syswow64\wrap_oal.dll
2010-09-07 20:09:02 29288 ----a-w- c:\windows\system32\nvhdap64.dll
2010-09-07 20:08:55 155752 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2010-09-07 20:08:54 1308776 ----a-w- c:\windows\system32\nvgenco64.dll
2010-09-04 19:08:05 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2010-09-04 19:08:05 109144 ----a-w- c:\windows\syswow64\OpenAL32.dll
2010-08-09 18:53:57 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-08-08 19:35:44 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-08-03 12:54:48 178800 ----a-w- c:\windows\syswow64\CmdLineExt_x64.dll
2010-07-31 19:12:02 737280 ----a-w- c:\windows\iun6002.exe
2010-07-30 19:32:45 286720 ----a-w- c:\windows\iun506.exe
2010-07-29 06:30:34 82944 ----a-w- c:\windows\syswow64\iccvid.dll
2010-07-27 17:55:50 95520 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 17:55:50 69408 ----a-w- c:\windows\system32\jdns_sd.dll
2010-07-27 17:55:50 237856 ----a-w- c:\windows\system32\dnssdX.dll
2010-07-27 17:55:50 119584 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-27 17:44:10 91424 ----a-w- c:\windows\syswow64\dnssd.dll
2010-07-27 17:44:10 75040 ----a-w- c:\windows\syswow64\jdns_sd.dll
2010-07-27 17:44:10 197920 ----a-w- c:\windows\syswow64\dnssdX.dll
2010-07-27 17:44:10 107808 ----a-w- c:\windows\syswow64\dns-sd.exe
2010-07-27 14:03:24 12867584 ----a-w- c:\windows\syswow64\shell32.dll
2010-07-09 22:38:00 930272 ----a-w- c:\windows\system32\dpinst.exe
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 1:04:20.74 ===============
Last edited by a moderator: