A long, long time ago, I got a pretty nasty virus. It opened up a fake antivirus software, prompting me to purchase it. Again, this was a long time ago. I don't remember what it was called, as I got rid of it almost immediately. My computer would run no .exe besides iexplorer.exe, so I ran it in safe mode and had to run several different antivirus softwares and go into the folder where it was hiding in order to remove it.
Problem is, since the incident, there have been.. an insane amount of svchost.exe processes, and also SearchIndexer.exe has been going nonstop as well. Normally, I would shrug it off - however, it's taking up a lot of RAM..
The first svchost.exe is taking up 1.5GB. The second one is taking up 1.2GB. Search Indexer is taking up only .5GB but I'd really like that .5 back, you know?
I'm also having a littttle bit of trouble with the DDS file. You see, it's been running for about ten minutes now and hasn't budged. The little progress dots are showing up at the bottom of it but it seems to be stuck. I have a HijackThis! file if that would be helpful but it's not looking good for the DDS log. I even restarted it, and am still running into the same problem.
All antivirus scanners I'm using (Spybot S&D, MBAM, and.. SuperAntiSpyware?) come up inconclusive, finding nothing.
Holy crap, it took about fifteen minutes but it finally finished.
DDS (Ver_10-10-10.03) - NTFS_AMD64
Run by Owner at 15:16:48.50 on Mon 10/18/2010
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.8183.6159 [GMT -4:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\conime.exe
C:\Windows\system32\taskmgr.exe
C:\Users\Owner\Documents\lalala\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyServer = http=58.138.142.145:80
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
TB: Search Toolbar: {0c8413c1-fad1-446c-8584-be50576f863e} - C:\Program Files (x86)\Search Toolbar\tbcore3.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
uRun: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask .exe" -atboottime
mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mExplorerRun: [jgyo0w] C:\Users\Owner\AppData\Local\Temp\19aqp.exe
StartupFolder: C:\Users\Owner\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\RAINME~1.LNK - C:\Program Files\Rainmeter\Rainmeter.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D9CDEFE3-51BB-4737-A12C-53D9814A148C} - hxxps://mail.jhsph.edu/owa/MWScripts/AttachView/1.5/DAX.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
TB-X64: {0C8413C1-FAD1-446C-8584-BE50576F863E} - No File
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
STS-X64: Windows DreamScene: {E31004D1-A431-41B8-826F-E902F9D95C81} - %SystemRoot%\System32\DreamScene.dll
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wojx14r6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2612669&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - about:robots
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir=2706&query=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Users\Owner\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\Owner\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
============= SERVICES / DRIVERS ===============
R0 ahcix64s;ahcix64s;C:\Windows\System32\drivers\ahcix64s.sys [2010-2-28 227856]
R0 amdide64;amdide64;C:\Windows\System32\drivers\amdide64.sys [2009-4-2 10632]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/04/02 21:20:41];C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2009-2-28 146928]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2008-1-20 27648]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-2-28 211968]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-1-16 1153368]
R2 TeamViewer5;TeamViewer 5;C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-7-6 173352]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\System32\drivers\vrtaucbl.sys [2010-7-1 77352]
R3 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\System32\drivers\ManyCam_x64.sys [2008-3-13 27136]
R3 rt61x64;Linksys Wireless-G PCI Adapter Driver;C:\Windows\System32\drivers\WMP54Gv41x64.sys [2009-8-12 362496]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2010-7-4 139880]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2010-3-1 27704]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;C:\Windows\System32\drivers\BVRPMPR5a64.SYS [2010-8-31 35840]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-10-20 89920]
=============== Created Last 30 ================
2010-10-18 01:26:14 388096 ----a-r- C:\Users\Owner\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-18 01:26:13 -------- d-----w- C:\Program Files (x86)\Trend Micro
2010-10-15 15:38:52 -------- d-----w- C:\Program Files (x86)\MSECache
2010-10-14 23:13:16 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-10-14 23:13:16 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-10-14 23:13:11 408064 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2010-10-14 23:13:11 339968 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2010-10-14 23:13:11 1915904 ----a-w- C:\Windows\System32\ole32.dll
2010-10-14 23:13:11 1316864 ----a-w- C:\Windows\SysWow64\ole32.dll
2010-10-14 23:13:10 189952 ----a-w- C:\Windows\System32\t2embed.dll
2010-10-14 23:13:10 157184 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-10-14 23:13:09 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-10-14 23:13:09 531968 ----a-w- C:\Windows\SysWow64\comctl32.dll
2010-10-14 23:13:08 316928 ----a-w- C:\Windows\System32\msshsq.dll
2010-10-14 23:13:08 231424 ----a-w- C:\Windows\SysWow64\msshsq.dll
2010-10-13 19:10:54 -------- d-----w- C:\Windows\SysWow64\RTCOM
2010-10-13 19:10:54 -------- d-----w- C:\Program Files\Realtek
2010-10-06 23:01:01 141612 ----a-w- C:\Windows\SysWow64\drivers\dump_wmimmc.sys
2010-10-06 22:44:02 -------- d-----w- C:\Ntreev USA
2010-10-03 21:15:08 -------- d-----w- C:\Users\Owner\AppData\Local\CrashRpt
2010-10-03 21:14:33 -------- d-----w- C:\Users\Owner\AppData\Local\Procaster
2010-10-03 21:14:33 -------- d-----w- C:\Program Files (x86)\Livestream Procaster
2010-09-30 23:09:28 -------- d-----w- C:\Program Files (x86)\Steam
2010-09-28 18:54:33 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2010-09-28 18:54:33 2048 ----a-w- C:\Windows\System32\tzres.dll
2010-09-25 23:39:19 -------- d-----w- C:\Users\Owner\AppData\Roaming\IMVU
2010-09-25 23:39:07 -------- d-----w- C:\Users\Owner\AppData\Roaming\IMVUClient
2010-09-23 18:42:38 23512 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\browserdirprovider.dll
2010-09-23 18:42:38 138712 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\brwsrcmp.dll
2010-09-23 01:26:35 -------- d-----w- C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 6
2010-09-22 22:10:52 103864 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2010-09-20 21:15:50 -------- d-----w- C:\PROGRA~3\WEBREG
2010-09-20 21:14:51 -------- d-----w- C:\Users\Owner\AppData\Roaming\Printer Info Cache
2010-09-20 21:04:03 -------- d-----w- C:\Program Files (x86)\Common Files\Hewlett-Packard
2010-09-20 21:03:40 -------- d-----w- C:\Program Files (x86)\Common Files\HP
2010-09-20 21:01:00 -------- d-----w- C:\Program Files (x86)\HP
2010-09-20 20:59:49 861184 ----a-w- C:\Windows\System32\SET65B6.tmp
2010-09-20 20:59:49 730624 ----a-w- C:\Windows\System32\hpotscl1.dll
2010-09-20 20:59:49 498176 ----a-w- C:\Windows\System32\hpovst01.dll
2010-09-20 20:59:49 338432 ----a-w- C:\Windows\System32\hpzids40.dll
2010-09-19 00:02:16 -------- d-----w- C:\Users\Owner\AppData\Local\Google
==================== Find3M ====================
2010-10-13 19:09:53 525792 ----a-w- C:\Windows\DIFxAPI.dll
2010-10-06 00:00:24 2048104 ----a-w- C:\Windows\System32\RtPgEx64.dll
2010-10-06 00:00:24 1146984 ----a-w- C:\Windows\System32\RTSnMg64.cpl
2010-10-06 00:00:14 332392 ----a-w- C:\Windows\System32\RtlCPAPI64.dll
2010-10-06 00:00:14 2511464 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys
2010-10-06 00:00:02 149608 ----a-w- C:\Windows\System32\RtkCfg64.dll
2010-10-05 23:59:50 601704 ----a-w- C:\Windows\System32\RtkApi64.dll
2010-10-05 23:59:50 2625640 ----a-w- C:\Windows\System32\RtkAPO64.dll
2010-10-05 23:59:50 1215592 ----a-w- C:\Windows\System32\RTCOM64.dll
2010-10-05 23:59:40 79976 ----a-w- C:\Windows\System32\RCoInst64.dll
2010-10-05 23:59:40 477800 ----a-w- C:\Windows\System32\RCoRes64.dat
2010-09-29 17:11:02 1251944 ----a-w- C:\Windows\RtlExUpd.dll
2010-09-27 13:34:30 318808 ----a-w- C:\Windows\System32\MaxxAudioAPO20.dll
2010-09-16 23:35:08 474336 ----a-w- C:\Windows\System32\DTSVoiceClarityDLL64.dll
2010-09-16 23:35:06 489696 ----a-w- C:\Windows\System32\DTSSymmetryDLL64.dll
2010-09-16 23:35:02 1325792 ----a-w- C:\Windows\System32\DTSS2SpeakerDLL64.dll
2010-09-16 23:34:58 1178336 ----a-w- C:\Windows\System32\DTSS2HeadphoneDLL64.dll
2010-09-16 23:34:56 315616 ----a-w- C:\Windows\System32\DTSNeoPCDLL64.dll
2010-09-16 23:34:52 268512 ----a-w- C:\Windows\System32\DTSLimiterDLL64.dll
2010-09-16 23:34:48 124640 ----a-w- C:\Windows\System32\DTSLFXAPO64.dll
2010-09-16 23:34:46 123616 ----a-w- C:\Windows\System32\DTSGFXAPONS64.dll
2010-09-16 23:34:42 124128 ----a-w- C:\Windows\System32\DTSGFXAPO64.dll
2010-09-16 23:34:38 265440 ----a-w- C:\Windows\System32\DTSGainCompensatorDLL64.dll
2010-09-16 23:34:36 1110240 ----a-w- C:\Windows\System32\DTSBoostDLL64.dll
2010-09-16 23:34:32 503520 ----a-w- C:\Windows\System32\DTSBassEnhancementDLL64.dll
2010-09-13 14:32:37 8147968 ----a-w- C:\Windows\System32\wmploc.DLL
2010-09-13 13:56:41 8147456 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-09-12 21:35:13 47616 ---ha-w- C:\Windows\SysWow64\charkeng.dll
2010-09-08 19:23:12 1032192 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 18:00:22 120208 ----a-w- C:\Windows\System32\SFSS_APO.dll
2010-09-08 17:50:13 485376 ----a-w- C:\Windows\System32\html.iec
2010-09-08 17:23:42 78336 ----a-w- C:\Windows\SysWow64\ieencode.dll
2010-09-08 17:07:35 834048 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 16:43:11 86528 ----a-w- C:\Windows\System32\ieencode.dll
2010-09-08 15:23:27 389632 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-06 18:28:38 179712 ----a-w- C:\Windows\System32\srvsvc.dll
2010-09-06 18:28:38 12288 ----a-w- C:\Windows\System32\sscore.dll
2010-09-06 18:27:03 17920 ----a-w- C:\Windows\System32\netevent.dll
2010-09-06 16:20:29 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-09-06 16:19:06 17920 ----a-w- C:\Windows\SysWow64\netevent.dll
2010-09-06 15:34:14 451584 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-09-06 15:33:51 175104 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-09-06 15:33:49 145920 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-09-03 11:47:54 338336 ----a-w- C:\Windows\System32\FMAPO64.dll
2010-08-31 14:57:39 2753024 ----a-w- C:\Windows\System32\win32k.sys
2010-08-20 16:57:50 1090048 ----a-w- C:\Windows\System32\wmpmde.dll
2010-08-20 16:05:07 867328 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-08-17 14:54:20 273920 ----a-w- C:\Windows\System32\spoolsv.exe
2010-08-10 16:14:20 343040 ----a-w- C:\Windows\System32\schannel.dll
2010-08-10 15:53:15 274944 ----a-w- C:\Windows\SysWow64\schannel.dll
2010-08-04 19:04:39 150 ----a-w- C:\Windows\SysWow64\133755.BAT
2010-07-22 20:48:58 220496 ----a-w- C:\Windows\System32\SFNHK64.dll
2010-07-22 20:48:50 78160 ----a-w- C:\Windows\System32\SFAPO64.dll
2010-07-22 20:48:44 81232 ----a-w- C:\Windows\System32\SFCOM64.dll
2010-07-22 20:48:26 74064 ----a-w- C:\Windows\SysWow64\SFCOM.dll
2010-07-22 20:37:14 200800 ----a-w- C:\Windows\System32\AERTAC64.dll
============= FINISH: 15:29:29.25 ===============
Problem is, since the incident, there have been.. an insane amount of svchost.exe processes, and also SearchIndexer.exe has been going nonstop as well. Normally, I would shrug it off - however, it's taking up a lot of RAM..
The first svchost.exe is taking up 1.5GB. The second one is taking up 1.2GB. Search Indexer is taking up only .5GB but I'd really like that .5 back, you know?
I'm also having a littttle bit of trouble with the DDS file. You see, it's been running for about ten minutes now and hasn't budged. The little progress dots are showing up at the bottom of it but it seems to be stuck. I have a HijackThis! file if that would be helpful but it's not looking good for the DDS log. I even restarted it, and am still running into the same problem.
All antivirus scanners I'm using (Spybot S&D, MBAM, and.. SuperAntiSpyware?) come up inconclusive, finding nothing.
Holy crap, it took about fifteen minutes but it finally finished.
DDS (Ver_10-10-10.03) - NTFS_AMD64
Run by Owner at 15:16:48.50 on Mon 10/18/2010
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.8183.6159 [GMT -4:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\conime.exe
C:\Windows\system32\taskmgr.exe
C:\Users\Owner\Documents\lalala\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyServer = http=58.138.142.145:80
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
TB: Search Toolbar: {0c8413c1-fad1-446c-8584-be50576f863e} - C:\Program Files (x86)\Search Toolbar\tbcore3.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
uRun: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask .exe" -atboottime
mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mExplorerRun: [jgyo0w] C:\Users\Owner\AppData\Local\Temp\19aqp.exe
StartupFolder: C:\Users\Owner\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\RAINME~1.LNK - C:\Program Files\Rainmeter\Rainmeter.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D9CDEFE3-51BB-4737-A12C-53D9814A148C} - hxxps://mail.jhsph.edu/owa/MWScripts/AttachView/1.5/DAX.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
TB-X64: {0C8413C1-FAD1-446C-8584-BE50576F863E} - No File
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
STS-X64: Windows DreamScene: {E31004D1-A431-41B8-826F-E902F9D95C81} - %SystemRoot%\System32\DreamScene.dll
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wojx14r6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2612669&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - about:robots
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir=2706&query=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Users\Owner\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\Owner\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
============= SERVICES / DRIVERS ===============
R0 ahcix64s;ahcix64s;C:\Windows\System32\drivers\ahcix64s.sys [2010-2-28 227856]
R0 amdide64;amdide64;C:\Windows\System32\drivers\amdide64.sys [2009-4-2 10632]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/04/02 21:20:41];C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2009-2-28 146928]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2008-1-20 27648]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-2-28 211968]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-1-16 1153368]
R2 TeamViewer5;TeamViewer 5;C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-7-6 173352]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\System32\drivers\vrtaucbl.sys [2010-7-1 77352]
R3 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\System32\drivers\ManyCam_x64.sys [2008-3-13 27136]
R3 rt61x64;Linksys Wireless-G PCI Adapter Driver;C:\Windows\System32\drivers\WMP54Gv41x64.sys [2009-8-12 362496]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2010-7-4 139880]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2010-3-1 27704]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;C:\Windows\System32\drivers\BVRPMPR5a64.SYS [2010-8-31 35840]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-10-20 89920]
=============== Created Last 30 ================
2010-10-18 01:26:14 388096 ----a-r- C:\Users\Owner\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-18 01:26:13 -------- d-----w- C:\Program Files (x86)\Trend Micro
2010-10-15 15:38:52 -------- d-----w- C:\Program Files (x86)\MSECache
2010-10-14 23:13:16 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-10-14 23:13:16 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-10-14 23:13:11 408064 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2010-10-14 23:13:11 339968 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2010-10-14 23:13:11 1915904 ----a-w- C:\Windows\System32\ole32.dll
2010-10-14 23:13:11 1316864 ----a-w- C:\Windows\SysWow64\ole32.dll
2010-10-14 23:13:10 189952 ----a-w- C:\Windows\System32\t2embed.dll
2010-10-14 23:13:10 157184 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-10-14 23:13:09 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-10-14 23:13:09 531968 ----a-w- C:\Windows\SysWow64\comctl32.dll
2010-10-14 23:13:08 316928 ----a-w- C:\Windows\System32\msshsq.dll
2010-10-14 23:13:08 231424 ----a-w- C:\Windows\SysWow64\msshsq.dll
2010-10-13 19:10:54 -------- d-----w- C:\Windows\SysWow64\RTCOM
2010-10-13 19:10:54 -------- d-----w- C:\Program Files\Realtek
2010-10-06 23:01:01 141612 ----a-w- C:\Windows\SysWow64\drivers\dump_wmimmc.sys
2010-10-06 22:44:02 -------- d-----w- C:\Ntreev USA
2010-10-03 21:15:08 -------- d-----w- C:\Users\Owner\AppData\Local\CrashRpt
2010-10-03 21:14:33 -------- d-----w- C:\Users\Owner\AppData\Local\Procaster
2010-10-03 21:14:33 -------- d-----w- C:\Program Files (x86)\Livestream Procaster
2010-09-30 23:09:28 -------- d-----w- C:\Program Files (x86)\Steam
2010-09-28 18:54:33 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2010-09-28 18:54:33 2048 ----a-w- C:\Windows\System32\tzres.dll
2010-09-25 23:39:19 -------- d-----w- C:\Users\Owner\AppData\Roaming\IMVU
2010-09-25 23:39:07 -------- d-----w- C:\Users\Owner\AppData\Roaming\IMVUClient
2010-09-23 18:42:38 23512 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\browserdirprovider.dll
2010-09-23 18:42:38 138712 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\brwsrcmp.dll
2010-09-23 01:26:35 -------- d-----w- C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 6
2010-09-22 22:10:52 103864 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2010-09-20 21:15:50 -------- d-----w- C:\PROGRA~3\WEBREG
2010-09-20 21:14:51 -------- d-----w- C:\Users\Owner\AppData\Roaming\Printer Info Cache
2010-09-20 21:04:03 -------- d-----w- C:\Program Files (x86)\Common Files\Hewlett-Packard
2010-09-20 21:03:40 -------- d-----w- C:\Program Files (x86)\Common Files\HP
2010-09-20 21:01:00 -------- d-----w- C:\Program Files (x86)\HP
2010-09-20 20:59:49 861184 ----a-w- C:\Windows\System32\SET65B6.tmp
2010-09-20 20:59:49 730624 ----a-w- C:\Windows\System32\hpotscl1.dll
2010-09-20 20:59:49 498176 ----a-w- C:\Windows\System32\hpovst01.dll
2010-09-20 20:59:49 338432 ----a-w- C:\Windows\System32\hpzids40.dll
2010-09-19 00:02:16 -------- d-----w- C:\Users\Owner\AppData\Local\Google
==================== Find3M ====================
2010-10-13 19:09:53 525792 ----a-w- C:\Windows\DIFxAPI.dll
2010-10-06 00:00:24 2048104 ----a-w- C:\Windows\System32\RtPgEx64.dll
2010-10-06 00:00:24 1146984 ----a-w- C:\Windows\System32\RTSnMg64.cpl
2010-10-06 00:00:14 332392 ----a-w- C:\Windows\System32\RtlCPAPI64.dll
2010-10-06 00:00:14 2511464 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys
2010-10-06 00:00:02 149608 ----a-w- C:\Windows\System32\RtkCfg64.dll
2010-10-05 23:59:50 601704 ----a-w- C:\Windows\System32\RtkApi64.dll
2010-10-05 23:59:50 2625640 ----a-w- C:\Windows\System32\RtkAPO64.dll
2010-10-05 23:59:50 1215592 ----a-w- C:\Windows\System32\RTCOM64.dll
2010-10-05 23:59:40 79976 ----a-w- C:\Windows\System32\RCoInst64.dll
2010-10-05 23:59:40 477800 ----a-w- C:\Windows\System32\RCoRes64.dat
2010-09-29 17:11:02 1251944 ----a-w- C:\Windows\RtlExUpd.dll
2010-09-27 13:34:30 318808 ----a-w- C:\Windows\System32\MaxxAudioAPO20.dll
2010-09-16 23:35:08 474336 ----a-w- C:\Windows\System32\DTSVoiceClarityDLL64.dll
2010-09-16 23:35:06 489696 ----a-w- C:\Windows\System32\DTSSymmetryDLL64.dll
2010-09-16 23:35:02 1325792 ----a-w- C:\Windows\System32\DTSS2SpeakerDLL64.dll
2010-09-16 23:34:58 1178336 ----a-w- C:\Windows\System32\DTSS2HeadphoneDLL64.dll
2010-09-16 23:34:56 315616 ----a-w- C:\Windows\System32\DTSNeoPCDLL64.dll
2010-09-16 23:34:52 268512 ----a-w- C:\Windows\System32\DTSLimiterDLL64.dll
2010-09-16 23:34:48 124640 ----a-w- C:\Windows\System32\DTSLFXAPO64.dll
2010-09-16 23:34:46 123616 ----a-w- C:\Windows\System32\DTSGFXAPONS64.dll
2010-09-16 23:34:42 124128 ----a-w- C:\Windows\System32\DTSGFXAPO64.dll
2010-09-16 23:34:38 265440 ----a-w- C:\Windows\System32\DTSGainCompensatorDLL64.dll
2010-09-16 23:34:36 1110240 ----a-w- C:\Windows\System32\DTSBoostDLL64.dll
2010-09-16 23:34:32 503520 ----a-w- C:\Windows\System32\DTSBassEnhancementDLL64.dll
2010-09-13 14:32:37 8147968 ----a-w- C:\Windows\System32\wmploc.DLL
2010-09-13 13:56:41 8147456 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-09-12 21:35:13 47616 ---ha-w- C:\Windows\SysWow64\charkeng.dll
2010-09-08 19:23:12 1032192 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 18:00:22 120208 ----a-w- C:\Windows\System32\SFSS_APO.dll
2010-09-08 17:50:13 485376 ----a-w- C:\Windows\System32\html.iec
2010-09-08 17:23:42 78336 ----a-w- C:\Windows\SysWow64\ieencode.dll
2010-09-08 17:07:35 834048 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 16:43:11 86528 ----a-w- C:\Windows\System32\ieencode.dll
2010-09-08 15:23:27 389632 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-06 18:28:38 179712 ----a-w- C:\Windows\System32\srvsvc.dll
2010-09-06 18:28:38 12288 ----a-w- C:\Windows\System32\sscore.dll
2010-09-06 18:27:03 17920 ----a-w- C:\Windows\System32\netevent.dll
2010-09-06 16:20:29 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-09-06 16:19:06 17920 ----a-w- C:\Windows\SysWow64\netevent.dll
2010-09-06 15:34:14 451584 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-09-06 15:33:51 175104 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-09-06 15:33:49 145920 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-09-03 11:47:54 338336 ----a-w- C:\Windows\System32\FMAPO64.dll
2010-08-31 14:57:39 2753024 ----a-w- C:\Windows\System32\win32k.sys
2010-08-20 16:57:50 1090048 ----a-w- C:\Windows\System32\wmpmde.dll
2010-08-20 16:05:07 867328 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-08-17 14:54:20 273920 ----a-w- C:\Windows\System32\spoolsv.exe
2010-08-10 16:14:20 343040 ----a-w- C:\Windows\System32\schannel.dll
2010-08-10 15:53:15 274944 ----a-w- C:\Windows\SysWow64\schannel.dll
2010-08-04 19:04:39 150 ----a-w- C:\Windows\SysWow64\133755.BAT
2010-07-22 20:48:58 220496 ----a-w- C:\Windows\System32\SFNHK64.dll
2010-07-22 20:48:50 78160 ----a-w- C:\Windows\System32\SFAPO64.dll
2010-07-22 20:48:44 81232 ----a-w- C:\Windows\System32\SFCOM64.dll
2010-07-22 20:48:26 74064 ----a-w- C:\Windows\SysWow64\SFCOM.dll
2010-07-22 20:37:14 200800 ----a-w- C:\Windows\System32\AERTAC64.dll
============= FINISH: 15:29:29.25 ===============
Last edited by a moderator: