I began with a full Malwarebytes scan once again. It detected several infections, which I resolved. The occasional ad still appeared in Firefox, though. During this attempt and before, AVG was sometimes warning me about an infection in netbt.sys. Curious, I made a copy of the file and deleted it. The file reappeared a few moments later. I tried this with a different .sys file and it did not reappear. I replaced the latter .sys file and tried using Malwarebytes's FileASSASSIN tool to delete netbt.sys. This worked, and I then replaced the file with one I downloaded on a separate PC. After this I ran another full Malwarebytes scan the next day. It found nothing, but the next time I turned on my PC it could not connect to the internet. I tried a few minor connection tests to confirm it was a major problem, and finally did some searching on a separate PC. I managed to find that it was an infection that stopped my DHCP service from starting. I tried using ComboFix on the recommendation of a friend, before I really knew what this site (which I got the program from, of course) was. I ran ComboFix, it scanned my PC and found a rootkit "inserted into the TCP/IP stack." It finished its scan and restarted my PC, at which point I simply had to restart my DHCP service to get the internet running again.
Now the internet worked fine, but ComboFix also discovered a file called msgsvc.dll that was infected. It said that it had replaced it, but a second ComboFix scan later that day reported the same thing. Additionally, AVG warnings about a "Trojan horse Crypt.ANVH" appear every few days or so. Attempting to let AVG remove it clearly does nothing, despite it reporting success. Malwarebytes currently reports nothing with a full scan, and neither does TDSSkiller while scanning for rootkits. All that is left is this msgsvc.dll and the trojan, as far as I know. I experience no more ads while browsing the internet, but I encounter a strange annoyance. Often, when I have been typing in a text box on a website (or possibly simply browsing without typing, I am not sure), then go to click the address bar and type in a website, the address bar does not recognize that I have clicked it until I minimize Firefox and reopen it, at which point the address bar is highlighted as if it has been clicked. Not sure if that is Firefox itself or something to do with my infection.
Finally, my apologies for using ComboFix before being asked to, but I was not aware of the nature of the program. I have removed it using Run and "combofix /uninstall". Why does AVG recognize parts of Combofix as malware? Is it because of how powerful the program is?
Thank you in advance.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_27
Run by Owner at 17:56:51 on 2012-02-05
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2044.764 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\libusbd-nt.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\nHancer\nHancerService.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\AirLink101\AWLH6075\Common\RalinkRegistryWriter.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\SpeedItup Free\speeditupfree.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.484\gmer.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://thestar.com/
uInternet Settings,ProxyOverride = local;127.0.0.1:9421;
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll
TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuz1.dll
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [DS3 Tool] c:\program files\motioninjoy\ds3\DS3_Tool.exe -mini
uRun: [LogitechSoftwareUpdate] "c:\program files\logitech\video\ManifestEngine.exe" boot
uRun: [Akamai NetSession Interface] "c:\documents and settings\owner\local settings\application data\akamai\netsession_win.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [Smart File Advisor] "c:\program files\smart file advisor\sfa.exe" /checkassoc
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" --auto-start
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
mRun: [SpeetItUpFree] "c:\program files\speeditup free\speeditupfree.exe"
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\airlin~1.lnk - c:\program files\airlink101\awlh6075\common\RaUI.exe
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1260984248055
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1260984243898
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
TCP: Interfaces\{61BB25A8-6C94-483D-A004-C0EAC68FCF51} : DhcpNameServer = 192.168.2.1
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\10.0.6\ViProtocol.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\59vxf8y7.default\
FF - prefs.js: browser.startup.homepage - hxxp://z10.invisionfree.com/RockmanChaosNetwork/index.php?act=idx|http://z10.invisionfree.com/RockmanChaosNetwork/index.php?showtopic=4811&st=0&#last|http://www.onemanga.com/|http://www.2kgames.com/index.php?p=support_patches|http://www.rarlab.com/download.htm
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\firefox\profiles\59vxf8y7.default\extensions\csweblauncher@cyberstep.com\plugins\npCsWebLauncher.dll
FF - plugin: c:\documents and settings\owner\application data\mozilla\firefox\profiles\59vxf8y7.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\windows\system32\npOGPPlugin.dll
FF - plugin: c:\windows\system32\npptools.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2012-1-25 56208]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 295248]
R1 RapportCerberus_34302;RapportCerberus_34302;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\34302\RapportCerberus32_34302.sys [2011-12-15 228208]
R1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2012-1-25 71440]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2012-1-25 164112]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2010-2-26 123280]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2010-2-26 41680]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2001-8-23 14336]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2011-8-15 1361288]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-12-26 2253120]
R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\airlink101\awlh6075\common\RalinkRegistryWriter.exe [2009-12-17 75040]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2012-1-25 931640]
R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2009-12-23 370688]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\10.0.6\ToolbarUpdater.exe [2012-1-23 909152]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-3 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-3 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-3 16720]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2011-4-17 33792]
R3 RapportIaso;RapportIaso;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportms\28896\RapportIaso.sys [2011-8-12 21520]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2009-12-17 966912]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2010-2-12 99152]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2010-2-12 110096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2009-12-16 547744]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-5-16 1025352]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\drivers\MijXfilt.sys [2011-5-20 97552]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 RAPIProtocol;Ralink RAPI Protocol Driver;c:\windows\system32\drivers\RAPIProtocol.sys [2009-12-17 16512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 XDva359;XDva359;\??\c:\windows\system32\xdva359.sys --> c:\windows\system32\XDva359.sys [?]
S3 XDva391;XDva391;\??\c:\windows\system32\xdva391.sys --> c:\windows\system32\XDva391.sys [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-7-22 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
.
=============== Created Last 30 ================
.
2073-10-27 14:55:34 2404352 ----a-w- c:\program files\microsoft games\halo custom edition\haloce.exe
2073-10-27 14:55:34 1835008 ----a-w- c:\program files\microsoft games\halo custom edition\haloceded.exe
2073-10-27 14:55:34 1118208 ----a-w- c:\program files\microsoft games\halo custom edition\Strings.dll
2012-02-05 17:26:44 -------- d-----w- c:\documents and settings\owner\application data\AVG
2012-02-05 16:57:09 -------- d-----w- c:\program files\SpeedItup Free
2012-02-05 16:56:59 -------- d-----w- c:\program files\Free Offers from Freeze.com
2012-02-05 16:56:57 9216 ----a-r- c:\documents and settings\owner\application data\microsoft\installer\{7426428e-71d4-452c-ba13-b14e5eb52859}\Icon7426428E16.exe
2012-02-05 16:38:23 -------- d-----w- c:\documents and settings\all users\application data\SpeedyPC
2012-02-05 16:38:22 -------- d-----w- c:\program files\SpeedyPC
2012-02-03 21:04:19 -------- d-----w- c:\documents and settings\owner\application data\Malwarebytes
2012-02-03 21:04:16 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-02-03 21:04:15 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-03 21:04:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-03 20:08:54 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2012-02-03 19:55:27 -------- d-sha-r- C:\cmdcons
2012-02-03 19:55:24 -------- d-----w- c:\windows\setup.pss
2012-02-03 19:55:11 -------- d-----w- c:\windows\setupupd
2012-02-03 16:08:04 -------- d-----w- C:\Combo-Fix
2012-02-03 12:11:51 -------- d-----w- C:\TDSSKiller_Quarantine
2012-02-03 04:27:57 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-02-03 04:27:57 -------- d-----w- c:\windows\system32\wbem\Repository
2012-02-03 02:49:06 162816 -c--a-w- c:\windows\system32\dllcache\netbt.sys
2012-02-03 02:49:06 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2012-01-29 03:28:16 79256 ----a-w- c:\windows\system32\npOGPPlugin.dll
2012-01-29 03:28:15 271768 ----a-w- c:\windows\system32\OGPIEPlugin.ocx
2012-01-29 03:28:09 -------- d-----w- c:\program files\OGPlanet
2012-01-25 15:16:44 56208 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
2012-01-18 21:16:20 -------- d-----w- c:\documents and settings\owner\application data\BigHugeEngine
2012-01-18 19:58:01 -------- d--h--w- c:\program files\common files\EAInstaller
2012-01-18 04:06:18 -------- d-----w- c:\program files\Origin Games
2012-01-18 04:06:07 -------- d-----w- c:\documents and settings\owner\local settings\application data\Origin
2012-01-18 04:06:00 -------- d-----w- c:\documents and settings\owner\application data\Origin
2012-01-18 04:03:18 -------- d-----w- c:\documents and settings\all users\application data\Origin
2012-01-18 04:03:14 -------- d-----w- c:\documents and settings\all users\application data\Electronic Arts
2012-01-18 04:02:36 -------- d-----w- c:\program files\Origin
2012-01-14 05:55:19 -------- d-----w- c:\documents and settings\owner\application data\.doomseeker
2012-01-10 21:41:42 62848 ----a-w- c:\windows\system32\drivers\rspndr.sys
2012-01-10 21:16:48 -------- d-----w- c:\documents and settings\all users\application data\SecTaskMan
2012-01-10 21:16:29 -------- d-----w- c:\program files\Security Task Manager
.
==================== Find3M ====================
.
2011-12-27 00:35:06 285176 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-12-27 00:35:06 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-12-27 00:35:01 285176 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-11-25 21:56:26 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:29:56 1868544 ----a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35:08 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:20:51 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:20:51 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-14 12:20:40 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-30 18:30:47 2000000000 ----a-w- c:\program files\Hellgate Global.part1.exe
2011-01-19 05:38:07 424403 ----a-w- c:\program files\ROMSetup.exe
2011-01-19 05:38:07 287135628 ----a-w- c:\program files\ROMSetup-8.bin
2011-01-19 05:30:02 1073741824 ----a-w- c:\program files\ROMSetup-7.bin
2011-01-19 05:01:02 1073741824 ----a-w- c:\program files\ROMSetup-6.bin
2011-01-19 04:35:05 1073741824 ----a-w- c:\program files\ROMSetup-5.bin
2011-01-19 04:08:13 1073741824 ----a-w- c:\program files\ROMSetup-4.bin
2011-01-19 03:40:19 1073741824 ----a-w- c:\program files\ROMSetup-3.bin
2011-01-19 03:12:27 1073741824 ----a-w- c:\program files\ROMSetup-2.bin
2011-01-19 02:45:00 1073317376 ----a-w- c:\program files\ROMSetup-1.bin
2011-01-14 01:30:47 451279679 ----a-w- c:\program files\ProjectBlackout_Install.exe
2010-11-19 01:24:19 2349951226 ----a-w- c:\program files\VindictusSetupV110.exe
2010-03-07 07:17:00 681984000 ----a-w- c:\program files\dndsetup-6.bin
2010-03-07 07:17:00 531452879 ----a-w- c:\program files\dndsetup-7.bin
2010-03-07 07:16:59 681984000 ----a-w- c:\program files\dndsetup-3.bin
2010-03-07 07:16:59 681984000 ----a-w- c:\program files\dndsetup-2.bin
2010-03-07 07:16:59 681478144 ----a-w- c:\program files\dndsetup-1.bin
2010-03-07 07:16:52 681984000 ----a-w- c:\program files\dndsetup-4.bin
2010-03-07 07:16:25 681984000 ----a-w- c:\program files\dndsetup-5.bin
2003-10-02 20:47:24 610304 ----a-w- c:\program files\Kicks.exe
2002-02-19 04:00:00 28672 ----a-w- c:\program files\jHexen.exe
2002-02-19 04:00:00 28672 ----a-w- c:\program files\jHeretic.exe
2002-02-19 04:00:00 28672 ----a-w- c:\program files\jDoom.exe
.
============= FINISH: 17:57:13.12 ===============
Attached File(s)
-
attach.txt (22.5K)
Number of downloads: 2 -
ark.log (39.68K)
Number of downloads: 3

Help
This topic is locked


Back to top












