It had a number of P2P apps installed on it and has had zero maintenance for months. Here's how I proceeded.
Steps followed:
1. Installed Malwarebytes but the program failed to when an update was attempted. Was able to get it installed and run. No corrections made.
2. Ran Vipre - Lots and LOTS of red lines on the log screen.
3. Installed Spybot S&D and ran. No corrections made.
At 'C:\' found 'FSQWR.BMP' a picture of an NTFS.SYS BSOD at address: 0x00000050 (0xFD3094C2)) & FSQWR.LNK, (Remove System Tool Virus retained)
'Gen-Gullo' found in Restore point,
'TrafficNinjaBiz' found in Restore point.
4. Uninstalled Norton 360 (subscription expired 90+ days ago) and Installed and Ran AVG anti-all freeware.
C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\kp.lproj\QuickTimeAudioSupportLocvalized.dll
Ok, about this time I felt I was not dealing with a deep infection but the system had a spectrum of other problems. Also realized I wanted to resolve the matter up without having to spend an lot of time at doing it.
As the system was still functional and not to bogged down to operate, I want ahead and;
5. P2P software uninstalled without difficulty: Limewire, Napster & Morphus.
6. Ran Windows Update. First installed was SP3, followed by 41 others.
7. Once updated I disabled 'RESTORE' and rebooted to clean the infections identified in the Restore file system, then restarted Restore.
Reviewed the Registry and found oddly noted entries. Have a JPG of the oddity and will pass it to you when you want to see it.
8. Updated and ran Spybot S&D and found no infection.
9. Ran HijackThis - Saved log file but made no changes.
10.Ran Vipre and a bunch of infected elements were found. Have log XML & CSV files.
11. Tried to run Root Repeal and errored out immediately with the error message:
Error Code = 0xc000001
Extended Info (0x00000a0)
Device Control Error
Error Code 0x1e7
12. Ran SmithfraudFix and cleaned the infection.
13. Ran Defogger.exe and disabled CD emulation software.
14. Ran DDS Tool (DDS.txt attached - holding attach.txt until requested. Each file was under 17kb.)
15. Ran GMER and it failed immediately with the error message:
16. At this moment I am waiting for the second run of GMER to complete.
OTHER things noticed:
\Temporary Internet Files\Content.IE5 was loaded with about 25 folders each looked to have the same style and format of randomly created names like this; QXGR83DG
DDS.txt Contents:
DDS (Ver_10-12-12.02) - NTFSx86
Run by Bri at 0:19:19.35 on Fri 03/25/2011
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.345 [GMT -7:00]
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Documents and Settings\Bri\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.bing.com/?pc=Z039&form=ZGAPHP
uInternet Connection Wizard,ShellNext = hxxp://www.sony.com/vaiopeople
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Yahooo Search Protection: {25bc7718-0bfa-40ea-b381-4b2d9732d686} - c:\program files\yahoo!\search protection\ysp.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.4.12.6.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aol\aol search enhancement\AOLSearch.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: {EF56413F-9398-4DF5-BC88-6FC3B227D5C5} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe
uRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messen~1\YahooMessenger.exe" -quiet
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [AzMixerSel] c:\program files\realtek\installshield\AzMixerSel.exe
mRun: [VAIO Recovery] c:\windows\sonysys\vaio recovery\PartSeal.exe
mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe
mRun: [VAIO Update 2] "c:\program files\sony\vaio update 2\VAIOUpdt.exe" /Stationary
mRun: [SonyPowerCfg] "c:\program files\sony\vaio power management\SPMgr.exe"
mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
mExplorerRun: [mscover] c:\docume~1\bri\locals~1\temp\mscover.exe
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Transfer by Image Converter 2 Plus - c:\program files\sony\image converter 2\menu.htm
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.4.12.6.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - c:\program files\yahoo!\search protection\ysp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: trymedia.com
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
Notify: VESWinlogon - VESWinlogon.dll
Notify: WRNotifier - WRLogonNTF.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [2011-3-24 18816]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-9-14 1174664]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-3 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-3 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-3 26192]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-8-10 226304]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S2 CWMonitor;Symantec Crimeware Protection Driver;\??\c:\program files\common files\symantec shared\coshared\cw\1.0\monitor.sys --> c:\program files\common files\symantec shared\coshared\cw\1.0\Monitor.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-1 136176]
S3 JYSZZLHSIHQ;JYSZZLHSIHQ;c:\docume~1\bri\locals~1\temp\jyszzlhsihq.exe --> c:\docume~1\bri\locals~1\temp\JYSZZLHSIHQ.exe [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\f.tmp --> c:\windows\system32\F.tmp [?]
=============== Created Last 30 ================
2011-03-25 05:32:51 -------- d-sh--r- C:\cmdcons
2011-03-25 05:30:41 -------- d-----w- c:\windows\setup.pss
2011-03-25 04:29:59 -------- d-----w- c:\program files\ProcessExplorer
2011-03-25 03:46:34 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
2011-03-25 02:59:23 -------- d-----w- c:\program files\Sophos
2011-03-24 20:33:15 -------- d-----w- C:\Retrreivced my Docs fromNortonBackup
2011-03-24 20:11:11 -------- d-----w- c:\program files\common files\L&H
2011-03-24 20:10:47 -------- d-----w- c:\program files\Microsoft ActiveSync
2011-03-24 20:09:11 -------- d-----w- c:\windows\SHELLNEW
2011-03-24 18:25:41 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-03-24 18:25:30 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-03-24 18:24:43 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-03-24 18:24:43 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2011-03-24 18:24:43 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-03-24 18:24:15 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-03-24 17:42:35 -------- d-----w- c:\windows\system32\scripting
2011-03-24 17:42:28 -------- d-----w- c:\windows\l2schemas
2011-03-24 17:42:26 -------- d-----w- c:\windows\system32\en
2011-03-24 17:42:26 -------- d-----w- c:\windows\system32\bits
2011-03-24 15:46:13 69120 ------w- c:\windows\system32\wlanapi.dll
2011-03-24 15:46:05 25471 ------w- c:\windows\system32\drivers\watv10nt.sys
2011-03-24 15:46:05 22271 ------w- c:\windows\system32\drivers\watv06nt.sys
2011-03-24 15:46:05 14208 ------w- c:\windows\system32\drivers\wacompen.sys
2011-03-24 15:46:05 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys
2011-03-24 15:46:05 11871 ------w- c:\windows\system32\drivers\wadv09nt.sys
2011-03-24 15:46:05 11807 ------w- c:\windows\system32\drivers\wadv07nt.sys
2011-03-24 15:46:05 11295 ------w- c:\windows\system32\drivers\wadv08nt.sys
2011-03-24 15:46:01 42240 ------w- c:\windows\system32\drivers\viaagp.sys
2011-03-24 15:46:01 28672 ------w- c:\windows\system32\vidcap.ax
2011-03-24 15:46:01 11325 ------w- c:\windows\system32\drivers\vchnt5.dll
2011-03-24 15:44:55 397056 ------w- c:\windows\system32\s3gnb.dll
2011-03-24 15:43:58 1327320 ------w- c:\program files\msn\msncorefiles\install\msnsusii.exe
2011-03-24 15:43:51 11053008 ------w- c:\program files\msn\msncorefiles\install\msn9components\msncli.exe
2011-03-24 15:43:25 397312 ------w- c:\windows\system32\mmcex.dll
2011-03-24 15:43:25 33792 ------w- c:\windows\system32\mmcperf.exe
2011-03-24 15:43:25 106496 ------w- c:\windows\system32\mmcfxcommon.dll
2011-03-24 15:43:24 184320 ------w- c:\windows\system32\microsoft.managementconsole.dll
2011-03-24 15:42:50 37376 ------w- c:\windows\system32\l2gpstore.dll
2011-03-24 15:42:42 61440 ------w- c:\windows\system32\kmsvc.dll
2011-03-24 15:42:40 6144 ------w- c:\windows\system32\kbdpash.dll
2011-03-24 15:42:40 6144 ------w- c:\windows\system32\kbdnepr.dll
2011-03-24 15:42:40 6144 ------w- c:\windows\system32\kbdiultn.dll
2011-03-24 15:42:39 6144 ------w- c:\windows\system32\kbdbhc.dll
2011-03-24 15:42:05 10752 ------w- c:\windows\system32\smtpapi.dll
2011-03-24 15:42:04 9728 ------w- c:\windows\system32\rwnh.dll
2011-03-24 15:40:49 12800 ------w- c:\windows\system32\credssp.dll
2011-03-24 15:39:59 136192 ------w- c:\windows\system32\aaclient.dll
2011-03-24 15:08:51 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2011-03-24 07:19:19 -------- d--h--w- C:\$AVG
2011-03-24 06:38:55 -------- d-----w- c:\docume~1\bri\applic~1\AVG10
2011-03-24 06:37:16 -------- d--h--w- c:\docume~1\alluse~1\applic~1\Common Files
2011-03-24 06:34:58 -------- d-----w- c:\windows\system32\drivers\AVG
2011-03-24 06:34:58 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG10
2011-03-24 06:34:13 -------- d-----w- c:\program files\AVG
2011-03-24 06:30:22 -------- d-----w- c:\docume~1\alluse~1\applic~1\MFAData
2011-03-24 03:07:38 -------- d-----w- c:\docume~1\bri\applic~1\SUPERAntiSpyware.com
2011-03-24 03:07:38 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2011-03-24 03:07:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-03-24 02:21:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-24 02:21:35 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-03-23 15:39:42 -------- d-----w- c:\docume~1\bri\applic~1\Malwarebytes
2011-03-23 15:39:35 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-23 15:39:34 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-03-23 15:39:31 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-23 15:39:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-05 05:18:51 -------- d-----w- c:\docume~1\alluse~1\applic~1\dOkKmBi06510
2011-02-28 01:01:49 -------- d-----w- c:\program files\Search Toolbar
2011-02-28 01:01:48 -------- d-----w- c:\program files\FoxTabVideoConverter
==================== Find3M ====================
2011-03-25 06:29:19 2996 ----a-w- c:\windows\system32\tmp.reg
2011-02-05 01:48:32 456192 ----a-w- c:\windows\system32\encdec.dll
2011-02-05 01:48:30 291840 ----a-w- c:\windows\system32\sbe.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
============= FINISH: 0:21:02.34 ===============
Lastly, Thanks for taking the time to review the posting. I'll await your reply.

Help
This topic is locked


Back to top
button.










