I received notification via Microsoft Security Essentials that it had found the virus Backdoor:Win32/Cycbot.B on my machine but had removed it. It then shows up in the Virus scanner's history as returning and "Allowed". I followed some steps to remove it, using Hitman and Malwarebytes and it says it has been removed. The only sign that something is still around is that, after I boot, the Proxy server is consistently being set to 127.0.0.1:62990.
Any help you can give would be very much appreciated.
Brian
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Brian at 22:54:57.38 on Thu 04/14/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.6134 [GMT -4:00]
.
AV: COMODO Antivirus *Enabled/Outdated* {675CEE69-9702-A524-3989-6D7CC8BF3695}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: COMODO Defense+ *Enabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\tcpsvcs.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Brian\Downloads\HitmanPro35_x64.exe
C:\Windows\system32\DllHost.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Brian\Downloads\HijackThis.exe
C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe
C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Brian\Downloads\dds (1).scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = file:///C:/Data/desktop/bookmarks.html
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun: [Trend Micro RUBotted V2.0 Beta] C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: {31911651-0598-46FD-8D0F-E1B1C9F3D3F1} = 192.168.10.15,8.8.8.8
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~2\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~2\DAP\dapie.dll
AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Download Accelerator Plus Integration: {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files (x86)\DAP\DAPIELoader64.dll
BHO-X64: Download Accelerator Plus Integration - No File
mRun-x64: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
mRun-x64: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
AppInit_DLLs-X64: C:\Windows\System32\guard64.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\93fflqhi.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 53737
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files (x86)\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\nppl3260.dll
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\nprpjplug.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Brian\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
FF - Ext: Firecookie: firecookie@janodvarko.cz - %profile%\extensions\firecookie@janodvarko.cz
FF - Ext: Download Youtube Videos +: video.downloader.plugin@ffpimp.com - %profile%\extensions\video.downloader.plugin@ffpimp.com
FF - Ext: Download Accelerator Plus (DAP) extension: {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08} - C:\Program Files (x86)\DAP\DAPFireFox
.
============= SERVICES / DRIVERS ===============
.
R0 pavboot;pavboot;C:\Windows\System32\drivers\pavboot64.sys [2011-4-13 33800]
R1 cmderd;COMODO Internet Security Eradication Driver;C:\Windows\System32\drivers\cmderd.sys [2011-1-6 14184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2011-1-6 250008]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2011-1-6 39888]
R1 ExpanDrive;ExpanDrive;C:\Windows\System32\drivers\ExpanDrive.sys [2009-3-5 226120]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2010-10-24 188928]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
R2 RUBotSrv;Trend Micro RUBotted Service;C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2011-4-14 439632]
R3 hitmanpro35;Hitman Pro 3.5 Support Driver;C:\Windows\System32\drivers\hitmanpro35.sys [2011-4-13 19528]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2010-10-24 40832]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\System32\drivers\nx6000.sys [2010-8-27 36720]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2010-10-24 72064]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
R4 CLPSLS;COMODO livePCsupport Service;C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2010-11-19 158112]
R4 HP LaserJet Service;HP LaserJet Service;C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-25 145920]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 MEMSWEEP2;MEMSWEEP2;C:\Windows\System32\D2DA.tmp [2011-4-13 6144]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-4-13 20992]
S3 tap0801;TAP-Win32 Adapter V8;C:\Windows\System32\drivers\tap0801.sys [2005-4-13 30720]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-4-13 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-2-18 51712]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;C:\Program Files\Zune\WMZuneComm.exe [2010-11-11 306416]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files (x86)\Microsoft SQL Server\100\Shared\sqladhlp.exe [2008-7-10 47128]
S4 OpenSSHServer;Openssh SSHD;C:\Program Files (x86)\ICW\bin\cygrunsrv.exe [2009-5-13 68096]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-7-10 369688]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-04-15 02:39:58 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-04-14 18:37:33 8424784 ----a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{A4560B20-9798-4BB3-ADE8-FCFBAACA5F4F}\mpengine.dll
2011-04-13 20:28:56 -------- d-----w- C:\Program Files (x86)\WinPcap
2011-04-13 18:51:04 -------- d-----w- C:\Program Files (x86)\CleanUp!
2011-04-13 18:47:12 33800 ----a-w- C:\Windows\System32\drivers\pavboot64.sys
2011-04-13 18:46:47 -------- d-----w- C:\Program Files (x86)\Panda Security
2011-04-13 17:50:46 -------- d-----w- C:\Windows\System32\SPReview
2011-04-13 17:16:43 6144 ------w- C:\Windows\System32\D2DA.tmp
2011-04-13 17:15:15 6144 ------w- C:\Windows\System32\7B48.tmp
2011-04-13 17:15:09 -------- d-----w- C:\Program Files (x86)\Sophos
2011-04-13 17:12:27 -------- d-----w- C:\RkUnhooker
2011-04-13 14:05:13 12872 ----a-w- C:\Windows\System32\bootdelete.exe
2011-04-13 14:01:46 19528 ----a-w- C:\Windows\System32\drivers\hitmanpro35.sys
2011-04-13 14:01:29 -------- d-----w- C:\PROGRA~3\Hitman Pro
2011-04-13 07:41:51 -------- d-----w- C:\Windows\System32\EventProviders
2011-04-13 07:35:11 48976 ----a-w- C:\Windows\System32\netfxperf.dll
2011-04-13 07:35:11 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2011-04-13 07:35:02 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2011-04-13 07:33:59 800256 ----a-w- C:\Windows\System32\usp10.dll
2011-04-13 07:32:59 82944 ----a-w- C:\Windows\SysWow64\thumbcache.dll
2011-04-13 07:31:53 323072 ----a-w- C:\Windows\SysWow64\drvstore.dll
2011-04-13 07:31:52 257024 ----a-w- C:\Windows\SysWow64\dpx.dll
2011-04-13 07:31:44 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2011-04-13 07:31:44 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2011-04-13 07:29:54 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2011-04-13 07:29:54 524288 ----a-w- C:\Windows\System32\wmicmiplugin.dll
2011-04-13 07:29:54 1225216 ----a-w- C:\Windows\System32\wbem\wbemcore.dll
2011-04-13 07:29:49 933376 ----a-w- C:\Windows\System32\SmiEngine.dll
2011-04-13 07:29:46 199168 ----a-w- C:\Windows\System32\PkgMgr.exe
2011-04-13 07:29:33 422912 ----a-w- C:\Windows\System32\drvstore.dll
2011-04-13 07:29:33 399872 ----a-w- C:\Windows\System32\dpx.dll
2011-04-13 07:17:33 -------- d-----w- C:\Users\Brian\AppData\Roaming\SUPERAntiSpyware.com
2011-04-13 07:17:33 -------- d-----w- C:\PROGRA~3\SUPERAntiSpyware.com
2011-04-13 07:17:04 -------- d-----w- C:\PROGRA~3\!SASCORE
2011-04-13 07:17:00 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-04-13 06:47:25 -------- d-----w- C:\$RECYCLE.BIN
2011-04-13 06:18:22 98816 ----a-w- C:\Windows\sed.exe
2011-04-13 06:18:22 89088 ----a-w- C:\Windows\MBR.exe
2011-04-13 06:18:22 256512 ----a-w- C:\Windows\PEV.exe
2011-04-13 06:18:22 161792 ----a-w- C:\Windows\SWREG.exe
2011-04-13 06:01:23 -------- d-----w- C:\VritualRoot
2011-04-13 05:41:17 -------- d-----w- C:\Program Files\COMODO
2011-04-13 05:41:16 1700352 ----a-w- C:\Windows\SysWow64\gdiplus.dll
2011-04-13 05:41:16 1060864 ----a-w- C:\Windows\SysWow64\mfc71.dll
2011-04-13 05:24:44 -------- d-----w- C:\PROGRA~3\Comodo
2011-04-13 05:16:03 -------- d-----w- C:\Users\Brian\AppData\Roaming\Malwarebytes
2011-04-13 05:15:29 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-13 05:15:29 -------- d-----w- C:\PROGRA~3\Malwarebytes
2011-04-13 05:15:26 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-04-13 05:15:26 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-04-13 02:43:36 -------- d-----w- C:\Users\Brian\AppData\Local\ElevatedDiagnostics
2011-04-11 23:59:03 -------- d-----w- C:\Program Files\LSI SoftModem
2011-04-11 21:21:55 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2011-04-11 21:21:55 723968 ----a-w- C:\Windows\System32\EncDec.dll
2011-04-11 21:21:54 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
2011-04-11 21:21:54 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2011-04-11 21:21:54 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-04-11 21:21:54 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2011-04-11 21:21:54 1118720 ----a-w- C:\Windows\System32\sbe.dll
2011-04-11 21:21:53 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2011-04-11 21:21:52 715776 ----a-w- C:\Windows\System32\kerberos.dll
2011-04-11 21:21:52 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
2011-04-11 21:21:49 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2011-04-11 21:21:49 100864 ----a-w- C:\Windows\System32\fontsub.dll
2011-04-10 20:43:10 -------- d-----w- C:\Users\Brian\dwhelper
2011-04-08 22:10:42 472808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-04-08 21:32:22 -------- d-----w- C:\Program Files (x86)\Vim
2011-04-08 16:41:08 -------- d-----w- C:\Program Files (x86)\Tensons
2011-04-08 16:26:44 -------- d-----w- C:\PROGRA~3\SpeedBit
2011-04-08 16:26:29 -------- d-----w- C:\Program Files (x86)\Common Files\SpeedBit
2011-04-08 16:26:28 84480 ----a-w- C:\Windows\SysWow64\EasyHook32.dll
2011-04-08 16:26:23 172032 ----a-w- C:\Windows\SysWow64\AniGIF.ocx
2011-04-08 16:26:03 -------- d-----w- C:\Program Files (x86)\DAP
2011-04-05 13:16:04 601424 ------w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{1EA055AD-71B3-404F-BE28-BB57456AD83A}\gapaengine.dll
2011-04-04 13:55:47 -------- d-----w- C:\PROGRA~3\SnmpSoft
2011-04-04 13:53:51 -------- d-----w- C:\Program Files (x86)\Syslog Watcher 2
2011-04-04 13:34:17 -------- d-----w- C:\PROGRA~3\UltiDev
2011-04-04 13:33:52 -------- d-----w- C:\Program Files\Microsoft Synchronization Services
2011-04-04 13:33:52 -------- d-----w- C:\Program Files\Microsoft SQL Server Compact Edition
2011-04-04 13:33:22 -------- d-----w- C:\Program Files (x86)\Microsoft ASP.NET
2011-04-04 13:33:00 -------- d-----w- C:\Program Files (x86)\SolarWinds
2011-04-04 02:13:18 -------- d-----w- C:\Users\Brian\AppData\Roaming\NVIDIA
2011-04-03 04:50:35 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2011-04-03 04:50:33 -------- d-----w- C:\Program Files (x86)\Steam
2011-04-03 04:50:04 -------- d-----w- C:\Windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2011-04-03 04:49:48 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2011-04-03 03:48:47 -------- d-----w- C:\Users\Brian\AppData\Roaming\HpUpdate
2011-04-03 03:48:31 27704 ------w- C:\Windows\System32\hppfaxprintermon5.dll
2011-04-03 03:48:31 22072 ------w- C:\Windows\System32\hppfaxprintermonui5.dll
2011-04-03 03:40:21 193592 ----a-w- C:\Windows\System32\hppdcompio.dll
2011-04-03 03:40:21 167480 ----a-w- C:\Windows\SysWow64\hppccompio.dll
2011-04-03 03:40:17 176640 ----a-w- C:\Windows\System32\hpcpn103.dll
2011-04-03 03:40:16 305664 ----a-w- C:\Windows\SysWow64\hpcc3103.dll
2011-04-03 03:07:43 976440 ----a-w- C:\Windows\System32\hpxp1410_x64.dll
2011-04-03 03:07:43 751160 ----a-w- C:\Windows\SysWow64\hpptsp08.dll
2011-04-03 03:07:43 1150520 ----a-w- C:\Windows\System32\hpptsp08_x64.dll
2011-04-03 03:07:42 217656 ----a-w- C:\Windows\System32\hppscancoins64.dll
2011-04-03 03:06:56 -------- d-----w- C:\CM1410_MFP_Series_Basic_Solution
2011-04-03 01:55:17 -------- d-----w- C:\Program Files (x86)\Microsoft
2011-04-03 01:55:16 -------- d-----w- C:\Program Files (x86)\MSN Toolbar
2011-04-03 01:54:54 -------- d-----w- C:\Program Files (x86)\MSN Toolbar Installer
2011-04-03 01:54:53 -------- d-sh--w- C:\Windows\ftpcache
2011-04-03 01:54:45 -------- d-----w- C:\Users\Brian\AppData\Local\HP
2011-04-03 01:53:57 608 --sha-w- C:\Windows\System32\winzvprt5.sys
2011-04-03 01:53:57 -------- d-----w- C:\Program Files\HP
2011-04-03 01:51:58 -------- d-----w- C:\Users\Brian\AppData\Roaming\Hewlett-Packard Company
2011-04-03 01:50:30 323584 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\hpcpp103.dll
2011-04-03 01:49:34 318264 ----a-w- C:\Windows\System32\hpbcoins64.dll
2011-04-03 01:49:18 491008 ----a-w- C:\Windows\SysWow64\hpcdmc32.dll
2011-04-03 01:48:02 -------- d-----w- C:\Program Files (x86)\HP
2011-03-30 16:00:47 -------- d-----w- C:\Program Files (x86)\WMR11
2011-03-25 06:39:38 601424 ------w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-03-18 21:41:24 -------- d-----w- C:\Program Files (x86)\Fast Image Resizer
2011-03-16 04:46:10 -------- d-----w- C:\Cavedog
2011-03-16 04:45:45 306688 ----a-w- C:\Windows\IsUninst.exe
2011-03-16 04:21:35 -------- d-----w- C:\Users\Brian\AppData\Local\THQ
2011-03-16 04:04:52 -------- d-----w- C:\Program Files (x86)\THQ
.
==================== Find3M ====================
.
2011-04-13 17:59:41 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-04-13 17:59:41 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-03 06:24:16 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52:08 3135488 ----a-w- C:\Windows\System32\win32k.sys
2011-02-23 04:56:31 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-02-23 04:56:27 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-02-23 04:56:03 411648 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-02-23 04:55:47 167936 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-02-23 04:55:12 287744 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-02-23 04:55:12 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-02-23 04:55:04 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-02-19 12:03:46 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-02-19 09:00:32 367616 ----a-w- C:\Windows\System32\atmfd.dll
2011-02-19 06:30:46 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-02-19 04:34:54 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-02-18 21:36:58 51712 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys
2011-02-18 21:36:58 4184352 ----a-w- C:\Windows\System32\usbaaplrc.dll
2011-02-12 11:34:16 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-02-05 17:10:16 642944 ----a-w- C:\Windows\System32\winload.efi
2011-02-05 17:10:08 20352 ----a-w- C:\Windows\System32\kdusb.dll
2011-02-05 17:10:08 19328 ----a-w- C:\Windows\System32\kd1394.dll
2011-02-05 17:10:08 17792 ----a-w- C:\Windows\System32\kdcom.dll
2011-02-05 17:06:41 605552 ----a-w- C:\Windows\System32\winload.exe
2011-02-05 17:06:41 566208 ----a-w- C:\Windows\System32\winresume.efi
2011-02-05 17:06:41 518672 ----a-w- C:\Windows\System32\winresume.exe
2011-02-03 01:40:23 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
.
============= FINISH: 22:57:42.66 ===============
Attached File(s)
-
Attach.zip (5.36K)
Number of downloads: 0

Help
This topic is locked

Back to top












