petemerrill
New member
Hi There,
Hope you can help. It's fair to say I've had a bit of a nightmare with malware of late. Got infected with the security suite a little while ago, I thought I'd managed to clean it, but Spybot is telling me I'm infected with WIN32.delf.uc. Tried cleaning it but it seem to keep getting reported in spybot (could it be a false positive?)
In the hope that you might be able to offer some advice....I've downloaded and run ERUNT as required and I've attached the attach.txt DDS report and pasted DDS.txt below. Hope you can help.
Kind regards
Pete
DDS (Ver_10-03-17.01) - NTFSx86
Run by Pete at 22:33:15.14 on 21/08/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.473 [GMT 1:00]
AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Paladin Antivirus *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\WINDOWS\system32\hasplms.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\ZyXEL\M-302\M-302.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Pete\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyServer = http=127.0.0.1:6522
uInternet Settings,ProxyOverride = <local>
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
TB: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\pete\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\Internet.lnk -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\zyxelm~1.lnk - c:\program files\zyxel\m-302\M-302.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mypix.com/importer/newconf/aurigma5.8.1.0/ImageUploader5.cab
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1209970709062
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-8-15 218592]
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2010-8-5 58984]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-8-20 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-8-20 59664]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-26 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-26 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-26 243024]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2010-8-15 233136]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-3-1 390528]
R1 RapportCerberus_18130;RapportCerberus_18130;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\18130\RapportCerberus_18130.sys [2010-8-5 34536]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-8-5 168936]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-17 308136]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-8-15 112592]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-8-5 763112]
R3 AR5513;ZyXEL 802.11g Wireless Adapter Service;c:\windows\system32\drivers\ar5513.sys [2008-5-6 358464]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-31 135664]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2010-8-15 63360]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-8-15 366840]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-8-15 1142224]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-8-20 33552]
S3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]
=============== Created Last 30 ================
2010-08-20 00:11:55 59664 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2010-08-20 00:11:55 51984 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2010-08-20 00:11:55 33552 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2010-08-16 18:36:13 3244 ----a-w- c:\windows\system32\wbem\Outlook_01cb3d71e6fa39da.mof
2010-08-16 06:06:27 138496 ----a-w- c:\windows\system32\drivers\AFD.SYS
2010-08-16 00:34:12 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-16 00:34:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-08-15 23:44:57 0 d-----w- c:\windows\system32\MpEngineStore
2010-08-15 10:29:58 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat
2010-08-15 10:29:58 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-08-15 10:29:43 0 d-----w- c:\program files\Spyware Doctor
2010-08-15 10:29:43 0 d-----w- c:\program files\common files\PC Tools
2010-08-15 10:29:43 0 d-----w- c:\docume~1\pete\applic~1\PC Tools
2010-08-15 10:29:43 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
2010-08-15 08:59:58 0 d-----w- c:\windows\system32\Registry Patrol
2010-08-15 08:59:53 0 d-----w- c:\program files\Registry Patrol
2010-08-15 08:59:46 0 d-----w- c:\program files\CCleaner
2010-08-15 00:45:45 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-08-15 00:45:39 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-08-15 00:45:38 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-08-15 00:45:33 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-08-15 00:45:28 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-08-15 00:45:07 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2010-08-15 00:45:02 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-08-15 00:45:00 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-08-15 00:44:56 19200 -c--a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-08-15 00:44:54 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-08-15 00:44:52 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2010-08-15 00:44:35 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-08-15 00:44:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-08-15 00:44:26 34890 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-08-15 00:44:14 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys
2010-08-15 00:44:06 53760 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll
2010-08-15 00:42:55 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys
2010-08-15 00:41:59 94720 -c--a-w- c:\windows\system32\dllcache\umaxud32.dll
2010-08-15 00:41:55 28160 -c--a-w- c:\windows\system32\dllcache\umaxu40.dll
2010-08-15 00:41:50 26624 -c--a-w- c:\windows\system32\dllcache\umaxu22.dll
2010-08-15 00:41:46 69632 -c--a-w- c:\windows\system32\dllcache\umaxu12.dll
2010-08-15 00:41:42 50688 -c--a-w- c:\windows\system32\dllcache\umaxscan.dll
2010-08-15 00:41:36 22912 -c--a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-08-15 00:41:32 50176 -c--a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-08-15 00:41:27 47616 -c--a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-08-15 00:41:23 211968 -c--a-w- c:\windows\system32\dllcache\um54scan.dll
2010-08-15 00:41:18 216064 -c--a-w- c:\windows\system32\dllcache\um34scan.dll
2010-08-15 00:41:14 36736 -c--a-w- c:\windows\system32\dllcache\ultra.sys
2010-08-15 00:41:09 11520 -c--a-w- c:\windows\system32\dllcache\twotrack.sys
2010-08-15 00:41:02 166784 -c--a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-08-15 00:39:57 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2010-08-15 00:39:53 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-08-15 00:39:52 149376 -c--a-w- c:\windows\system32\dllcache\tffsport.sys
2010-08-15 00:39:46 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys
2010-08-15 00:39:43 37961 -c--a-w- c:\windows\system32\dllcache\tdk100b.sys
2010-08-15 00:39:36 30464 -c--a-w- c:\windows\system32\dllcache\tbatm155.sys
2010-08-15 00:39:30 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys
2010-08-15 00:39:26 36640 -c--a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-08-15 00:39:22 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll
2010-08-15 00:39:14 32640 -c--a-w- c:\windows\system32\dllcache\symc8xx.sys
2010-08-15 00:39:10 16256 -c--a-w- c:\windows\system32\dllcache\symc810.sys
2010-08-15 00:39:06 30688 -c--a-w- c:\windows\system32\dllcache\sym_u3.sys
2010-08-15 00:39:01 28384 -c--a-w- c:\windows\system32\dllcache\sym_hi.sys
2010-08-15 00:37:59 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-08-15 00:37:53 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys
2010-08-15 00:37:49 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll
2010-08-15 00:37:45 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys
2010-08-15 00:37:41 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys
2010-08-15 00:37:36 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys
2010-08-15 00:37:33 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll
2010-08-15 00:37:28 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys
2010-08-15 00:37:24 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys
2010-08-15 00:37:22 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys
2010-08-15 00:37:18 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys
2010-08-15 00:37:08 58368 -c--a-w- c:\windows\system32\dllcache\smiminib.sys
2010-08-15 00:37:03 147200 -c--a-w- c:\windows\system32\dllcache\smidispb.dll
2010-08-15 00:35:59 50432 -c--a-w- c:\windows\system32\dllcache\sisv.sys
2010-08-15 00:34:57 6912 -c--a-w- c:\windows\system32\dllcache\seaddsmc.sys
2010-08-15 00:33:57 41216 -c--a-w- c:\windows\system32\dllcache\s3mt3d.sys
2010-08-15 00:32:55 86097 -c--a-w- c:\windows\system32\dllcache\reslog32.dll
2010-08-15 00:32:43 19584 -c--a-w- c:\windows\system32\dllcache\rasirda.sys
2010-08-15 00:32:36 714762 -c--a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2010-08-15 00:32:31 899146 -c--a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-08-15 00:32:26 41472 -c--a-w- c:\windows\system32\dllcache\qvusd.dll
2010-08-15 00:32:21 3328 -c--a-w- c:\windows\system32\dllcache\qv2kux.sys
2010-08-15 00:32:09 49024 -c--a-w- c:\windows\system32\dllcache\ql1280.sys
2010-08-15 00:32:05 40448 -c--a-w- c:\windows\system32\dllcache\ql1240.sys
2010-08-15 00:32:02 45312 -c--a-w- c:\windows\system32\dllcache\ql12160.sys
2010-08-15 00:30:57 19840 -c--a-w- c:\windows\system32\dllcache\philtune.sys
2010-08-15 00:29:57 44544 -c--a-w- c:\windows\system32\dllcache\ovui2.dll
2010-08-15 00:28:53 51552 -c--a-w- c:\windows\system32\dllcache\ntgrip.sys
2010-08-15 00:27:57 13664 -c--a-w- c:\windows\system32\dllcache\n9i128.sys
2010-08-15 00:26:57 35200 -c--a-w- c:\windows\system32\dllcache\msgame.sys
2010-08-15 00:25:59 58880 -c--a-w- c:\windows\system32\dllcache\m3092dc.dll
2010-08-15 00:24:53 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-08-15 00:23:59 13056 -c--a-w- c:\windows\system32\dllcache\inport.sys
2010-08-15 00:22:59 9216 -c--a-w- c:\windows\system32\dllcache\ibmsgnet.dll
2010-08-15 00:21:59 150239 -c--a-w- c:\windows\system32\dllcache\hsf_amos.sys
2010-08-15 00:20:58 17408 -c--a-w- c:\windows\system32\dllcache\gpr400.sys
2010-08-15 00:19:58 12362 -c--a-w- c:\windows\system32\dllcache\f3ab18xi.sys
2010-08-15 00:18:59 171520 -c--a-w- c:\windows\system32\dllcache\el99xn51.sys
2010-08-15 00:17:58 6729 -c--a-w- c:\windows\system32\dllcache\disrvci.dll
2010-08-15 00:16:59 72832 -c--a-w- c:\windows\system32\dllcache\cwbwdm.sys
2010-08-15 00:15:59 171264 -c--a-w- c:\windows\system32\dllcache\camdrv30.sys
2010-08-15 00:14:56 26624 -c--a-w- c:\windows\system32\dllcache\ativxbar.sys
2010-08-15 00:13:30 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-08-13 08:39:49 2853 ----a-w- c:\windows\erapujaxa.dll
2010-08-12 23:31:03 2853 ----a-w- c:\windows\epetiqefameteqa.dll
2010-08-12 22:52:53 2853 ----a-w- c:\windows\ekurojewujo.dll
2010-08-12 22:43:37 1098 ----a-w- c:\windows\Dyanagoga.dat
2010-08-12 22:43:37 0 ----a-w- c:\windows\Thacihu.bin
2010-08-12 22:41:13 0 d-----w- c:\docume~1\pete\applic~1\7ED0FF19829AB0E75B0EA13A4045FD63
2010-08-05 18:19:28 58984 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
2010-08-03 22:33:45 0 d-----w- c:\program files\iPod
==================== Find3M ====================
2010-08-15 17:03:55 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-07-17 12:06:44 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-17 12:06:41 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-17 12:06:32 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-02-23 22:35:56 16384 --sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat
2008-10-05 15:59:23 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100520081006\index.dat
============= FINISH: 22:34:11.73 ===============
Hope you can help. It's fair to say I've had a bit of a nightmare with malware of late. Got infected with the security suite a little while ago, I thought I'd managed to clean it, but Spybot is telling me I'm infected with WIN32.delf.uc. Tried cleaning it but it seem to keep getting reported in spybot (could it be a false positive?)
In the hope that you might be able to offer some advice....I've downloaded and run ERUNT as required and I've attached the attach.txt DDS report and pasted DDS.txt below. Hope you can help.
Kind regards
Pete
DDS (Ver_10-03-17.01) - NTFSx86
Run by Pete at 22:33:15.14 on 21/08/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.473 [GMT 1:00]
AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Paladin Antivirus *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\WINDOWS\system32\hasplms.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\ZyXEL\M-302\M-302.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Pete\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyServer = http=127.0.0.1:6522
uInternet Settings,ProxyOverride = <local>
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
TB: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\pete\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\Internet.lnk -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\zyxelm~1.lnk - c:\program files\zyxel\m-302\M-302.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mypix.com/importer/newconf/aurigma5.8.1.0/ImageUploader5.cab
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1209970709062
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-8-15 218592]
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2010-8-5 58984]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-8-20 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-8-20 59664]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-26 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-26 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-26 243024]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2010-8-15 233136]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-3-1 390528]
R1 RapportCerberus_18130;RapportCerberus_18130;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\18130\RapportCerberus_18130.sys [2010-8-5 34536]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-8-5 168936]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-17 308136]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-8-15 112592]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-8-5 763112]
R3 AR5513;ZyXEL 802.11g Wireless Adapter Service;c:\windows\system32\drivers\ar5513.sys [2008-5-6 358464]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-31 135664]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2010-8-15 63360]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-8-15 366840]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-8-15 1142224]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-8-20 33552]
S3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]
=============== Created Last 30 ================
2010-08-20 00:11:55 59664 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2010-08-20 00:11:55 51984 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2010-08-20 00:11:55 33552 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2010-08-16 18:36:13 3244 ----a-w- c:\windows\system32\wbem\Outlook_01cb3d71e6fa39da.mof
2010-08-16 06:06:27 138496 ----a-w- c:\windows\system32\drivers\AFD.SYS
2010-08-16 00:34:12 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-16 00:34:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-08-15 23:44:57 0 d-----w- c:\windows\system32\MpEngineStore
2010-08-15 10:29:58 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat
2010-08-15 10:29:58 63360 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-08-15 10:29:43 0 d-----w- c:\program files\Spyware Doctor
2010-08-15 10:29:43 0 d-----w- c:\program files\common files\PC Tools
2010-08-15 10:29:43 0 d-----w- c:\docume~1\pete\applic~1\PC Tools
2010-08-15 10:29:43 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
2010-08-15 08:59:58 0 d-----w- c:\windows\system32\Registry Patrol
2010-08-15 08:59:53 0 d-----w- c:\program files\Registry Patrol
2010-08-15 08:59:46 0 d-----w- c:\program files\CCleaner
2010-08-15 00:45:45 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-08-15 00:45:39 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-08-15 00:45:38 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-08-15 00:45:33 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-08-15 00:45:28 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-08-15 00:45:07 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2010-08-15 00:45:02 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-08-15 00:45:00 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-08-15 00:44:56 19200 -c--a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-08-15 00:44:54 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-08-15 00:44:52 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2010-08-15 00:44:35 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-08-15 00:44:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-08-15 00:44:26 34890 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-08-15 00:44:14 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys
2010-08-15 00:44:06 53760 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll
2010-08-15 00:42:55 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys
2010-08-15 00:41:59 94720 -c--a-w- c:\windows\system32\dllcache\umaxud32.dll
2010-08-15 00:41:55 28160 -c--a-w- c:\windows\system32\dllcache\umaxu40.dll
2010-08-15 00:41:50 26624 -c--a-w- c:\windows\system32\dllcache\umaxu22.dll
2010-08-15 00:41:46 69632 -c--a-w- c:\windows\system32\dllcache\umaxu12.dll
2010-08-15 00:41:42 50688 -c--a-w- c:\windows\system32\dllcache\umaxscan.dll
2010-08-15 00:41:36 22912 -c--a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-08-15 00:41:32 50176 -c--a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-08-15 00:41:27 47616 -c--a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-08-15 00:41:23 211968 -c--a-w- c:\windows\system32\dllcache\um54scan.dll
2010-08-15 00:41:18 216064 -c--a-w- c:\windows\system32\dllcache\um34scan.dll
2010-08-15 00:41:14 36736 -c--a-w- c:\windows\system32\dllcache\ultra.sys
2010-08-15 00:41:09 11520 -c--a-w- c:\windows\system32\dllcache\twotrack.sys
2010-08-15 00:41:02 166784 -c--a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-08-15 00:39:57 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2010-08-15 00:39:53 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-08-15 00:39:52 149376 -c--a-w- c:\windows\system32\dllcache\tffsport.sys
2010-08-15 00:39:46 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys
2010-08-15 00:39:43 37961 -c--a-w- c:\windows\system32\dllcache\tdk100b.sys
2010-08-15 00:39:36 30464 -c--a-w- c:\windows\system32\dllcache\tbatm155.sys
2010-08-15 00:39:30 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys
2010-08-15 00:39:26 36640 -c--a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-08-15 00:39:22 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll
2010-08-15 00:39:14 32640 -c--a-w- c:\windows\system32\dllcache\symc8xx.sys
2010-08-15 00:39:10 16256 -c--a-w- c:\windows\system32\dllcache\symc810.sys
2010-08-15 00:39:06 30688 -c--a-w- c:\windows\system32\dllcache\sym_u3.sys
2010-08-15 00:39:01 28384 -c--a-w- c:\windows\system32\dllcache\sym_hi.sys
2010-08-15 00:37:59 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-08-15 00:37:53 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys
2010-08-15 00:37:49 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll
2010-08-15 00:37:45 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys
2010-08-15 00:37:41 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys
2010-08-15 00:37:36 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys
2010-08-15 00:37:33 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll
2010-08-15 00:37:28 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys
2010-08-15 00:37:24 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys
2010-08-15 00:37:22 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys
2010-08-15 00:37:18 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys
2010-08-15 00:37:08 58368 -c--a-w- c:\windows\system32\dllcache\smiminib.sys
2010-08-15 00:37:03 147200 -c--a-w- c:\windows\system32\dllcache\smidispb.dll
2010-08-15 00:35:59 50432 -c--a-w- c:\windows\system32\dllcache\sisv.sys
2010-08-15 00:34:57 6912 -c--a-w- c:\windows\system32\dllcache\seaddsmc.sys
2010-08-15 00:33:57 41216 -c--a-w- c:\windows\system32\dllcache\s3mt3d.sys
2010-08-15 00:32:55 86097 -c--a-w- c:\windows\system32\dllcache\reslog32.dll
2010-08-15 00:32:43 19584 -c--a-w- c:\windows\system32\dllcache\rasirda.sys
2010-08-15 00:32:36 714762 -c--a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2010-08-15 00:32:31 899146 -c--a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-08-15 00:32:26 41472 -c--a-w- c:\windows\system32\dllcache\qvusd.dll
2010-08-15 00:32:21 3328 -c--a-w- c:\windows\system32\dllcache\qv2kux.sys
2010-08-15 00:32:09 49024 -c--a-w- c:\windows\system32\dllcache\ql1280.sys
2010-08-15 00:32:05 40448 -c--a-w- c:\windows\system32\dllcache\ql1240.sys
2010-08-15 00:32:02 45312 -c--a-w- c:\windows\system32\dllcache\ql12160.sys
2010-08-15 00:30:57 19840 -c--a-w- c:\windows\system32\dllcache\philtune.sys
2010-08-15 00:29:57 44544 -c--a-w- c:\windows\system32\dllcache\ovui2.dll
2010-08-15 00:28:53 51552 -c--a-w- c:\windows\system32\dllcache\ntgrip.sys
2010-08-15 00:27:57 13664 -c--a-w- c:\windows\system32\dllcache\n9i128.sys
2010-08-15 00:26:57 35200 -c--a-w- c:\windows\system32\dllcache\msgame.sys
2010-08-15 00:25:59 58880 -c--a-w- c:\windows\system32\dllcache\m3092dc.dll
2010-08-15 00:24:53 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-08-15 00:23:59 13056 -c--a-w- c:\windows\system32\dllcache\inport.sys
2010-08-15 00:22:59 9216 -c--a-w- c:\windows\system32\dllcache\ibmsgnet.dll
2010-08-15 00:21:59 150239 -c--a-w- c:\windows\system32\dllcache\hsf_amos.sys
2010-08-15 00:20:58 17408 -c--a-w- c:\windows\system32\dllcache\gpr400.sys
2010-08-15 00:19:58 12362 -c--a-w- c:\windows\system32\dllcache\f3ab18xi.sys
2010-08-15 00:18:59 171520 -c--a-w- c:\windows\system32\dllcache\el99xn51.sys
2010-08-15 00:17:58 6729 -c--a-w- c:\windows\system32\dllcache\disrvci.dll
2010-08-15 00:16:59 72832 -c--a-w- c:\windows\system32\dllcache\cwbwdm.sys
2010-08-15 00:15:59 171264 -c--a-w- c:\windows\system32\dllcache\camdrv30.sys
2010-08-15 00:14:56 26624 -c--a-w- c:\windows\system32\dllcache\ativxbar.sys
2010-08-15 00:13:30 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-08-13 08:39:49 2853 ----a-w- c:\windows\erapujaxa.dll
2010-08-12 23:31:03 2853 ----a-w- c:\windows\epetiqefameteqa.dll
2010-08-12 22:52:53 2853 ----a-w- c:\windows\ekurojewujo.dll
2010-08-12 22:43:37 1098 ----a-w- c:\windows\Dyanagoga.dat
2010-08-12 22:43:37 0 ----a-w- c:\windows\Thacihu.bin
2010-08-12 22:41:13 0 d-----w- c:\docume~1\pete\applic~1\7ED0FF19829AB0E75B0EA13A4045FD63
2010-08-05 18:19:28 58984 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
2010-08-03 22:33:45 0 d-----w- c:\program files\iPod
==================== Find3M ====================
2010-08-15 17:03:55 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-07-17 12:06:44 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-17 12:06:41 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-17 12:06:32 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-02-23 22:35:56 16384 --sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat
2008-10-05 15:59:23 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100520081006\index.dat
============= FINISH: 22:34:11.73 ===============