Hi, I have recently got some sort of virus or malware from surfing a video streaming website (I think...).
since then:
- I did get the blue screen, but one of the anti virus programs must have fixed that error.
- i havnt been able to run various programs, such as windows "disk cleanup". That seems to just disappear when i try to scan the C: drive but if I scan the E: drive it runs fine.
- Other programs, mainly anti virus software seem to just crash when scanning or fixing problems. Some work some don't. but the thing is, obviouslly none of them work otherwise i wouldnt still have this problem dry.gif .
- A few windows updates wont fully install, such as a security update and windows live update. (They successfully install but on reboot they appear ready for installation again???)
- svchost.exe could be a problem, many virus scanners have found it but never fixed. and svchost fix wizard found something wrong with "invalid data 2 at value start of the key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" and "system DLLs re-registration is pending". These were the erros it found but i cannot fix because it COSTS MONEY!
- when browsing internet, i get alot of random pop ups!
- now my sound doesnt work on the internet. like when im listening to on-line music or you tube videos.
BASICALLY! Nothing works, i would tell you everything I have done since this happened, but I couldnt possibly do that because i have done so much. I have been browsing these forums and alot of other forums for the answers, but I still have the same issues!!
But yeah I have tried alot of anti virus programs, AVG, kaspersky, malwarebytes etc... you name it i have probably tried it!
Although there are a few programs I have yet to use such as: combofix
a main error I get is when i install a program, use it, and then when i try to re-use it i get a similar message to: "cannot find file, path... inavlid privileges" (something like that anyway) and then the program would have to be reinstalled to try and use it again.
I'm not sure if this a virus or what???? Help please!!!
Oh and its that bad that i cant even use hijackthis, because every time i do it crashes then i cant open the program and get this error: "Windows cannot access the specified device, path, or file. You may not have the apporpriate permissions to access the item." AND I AM AN ADMINISTRATOR as i am the only one on this computer! also i wasnt able to use the rootrepeal.exe, that also crashed when scanning.
although i did manage to get the DDS working, here it is (with attached file too):
-----------------------------------------------------------------
DDS (Ver_09-10-26.01) - NTFSx86
Run by owner at 23:01:20.21 on 06/11/2009
Internet Explorer: 8.0.6001.18828 BrowserJavaVersion: 1.6.0_04
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.44.1033.18.2047.1184 [GMT 0:00]
AV: Kaspersky Anti-Virus *On-access scanning enabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Kaspersky Anti-Virus *enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Sunbelt CounterSpy *enabled* (Updated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\drivers\CDAC11BA.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\CTsvcCDA.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\lxbkcoms.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\msiexec.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Users\owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
ustart page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [VolPanel] "c:\program files\creative\sbaudigy\volume panel\VolPanlu.exe" /r
mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
uPolicies-explorer: NoThemesTab = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoColorChoice = 0 (0x0)
uPolicies-system: NoSizeChoice = 0 (0x0)
uPolicies-system: NoVisualStyleChoice = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: NoThemesTab = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: NoColorChoice = 0 (0x0)
mPolicies-system: NoSizeChoice = 0 (0x0)
mPolicies-system: NoVisualStyleChoice = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15109/CTPID.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: WBSrv - c:\program files\stardock\object desktop\windowblinds\wbsrv.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
{8053af4f-f35d-4ec6-a411-039efb515cd8}
{eba0f461-d69f-4be7-9f08-467e81ef96f3}
LSA: Authentication Packages = msv1_0 c:\windows\system32\byXQJBTM
================= FIREFOX ===================
FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\u3z6rx53.default\
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\u3z6rx53.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\u3z6rx53.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-10-26 30280]
R2 lxbk_device;lxbk_device;c:\windows\system32\lxbkcoms.exe -service --> c:\windows\system32\lxbkcoms.exe -service [?]
R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2009-10-26 51656]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2008-9-12 69168]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
R3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2009-10-26 24368]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\drivers\SiSGB6.sys [2002-1-9 46592]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; [x]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2009-9-10 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2009-9-10 79360]
S3 emuumidi;E-MU USB-MIDI Driver;c:\windows\system32\drivers\emuumidi.sys [2006-4-12 37120]
S3 ExterminateIt;ExterminateIt;c:\windows\system32\drivers\extit.sys [2009-10-28 22016]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-11 21504]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2008-9-11 21504]
=============== Created Last 30 ================
2009-11-06 22:42:55 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2009-11-06 22:32:06 0 d-----w- c:\program files\EA SPORTS
2009-11-06 22:04:12 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-06 22:04:10 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-06 22:04:10 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-06 20:20:06 396288 ----a-w- C:\HijackThis.exe
2009-11-06 18:39:50 0 d-----w- c:\programdata\McAfee
2009-11-06 18:39:30 0 d-----w- c:\programdata\McAfee Security Scan
2009-11-06 18:38:56 0 d-----w- c:\programdata\NOS
2009-11-06 18:01:17 0 d-----w- C:\AVGTemp
2009-11-06 01:47:47 0 d-----w- c:\program files\AVG
2009-11-06 01:47:46 0 d-----w- c:\programdata\avg9
2009-11-06 00:25:12 0 d-----w- C:\VundoFix Backups
2009-11-05 20:35:40 0 d-----w- c:\users\owner\appdata\roaming\True Sword
2009-11-05 20:35:32 0 d-----w- c:\program files\Windows Cannot Find Fix Wizard
2009-11-04 09:59:54 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2009-11-03 11:58:08 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-11-03 11:58:08 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-11-03 11:58:07 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-11-03 11:58:06 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-11-03 11:58:06 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-11-03 11:58:06 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-11-03 11:58:05 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2009-11-03 11:58:05 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2009-11-03 11:58:04 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2009-11-02 18:20:52 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-02 18:14:13 0 d-----w- c:\users\owner\.housecall6.6
2009-11-01 16:03:02 116675 ----a-w- C:\BdUninstallTool2009.11.01-04.03.02.reg
2009-11-01 11:52:01 0 d-----w- c:\program files\Uniblue
2009-10-31 16:22:08 0 d-----w- c:\program files\common files\MSSoap
2009-10-31 12:43:57 0 d-----w- c:\program files\Trend Micro
2009-10-30 19:40:48 0 ----a-w- c:\windows\system32\SBRC.dat
2009-10-30 19:32:26 0 d-----w- c:\program files\Sunbelt Software
2009-10-30 17:23:04 0 d-----w- c:\temp\ja-jp
2009-10-30 17:23:04 0 d-----w- c:\temp\fr-fr
2009-10-30 17:23:04 0 d-----w- c:\temp\es-es
2009-10-30 17:23:03 99840 ----a-w- c:\temp\sdbapiu.dll
2009-10-30 17:23:03 298160 ----a-w- c:\temp\spinstall.exe
2009-10-30 17:23:03 2560 ----a-w- c:\temp\acres.dll
2009-10-30 17:23:03 190464 ----a-w- c:\temp\sperror.dll
2009-10-30 17:23:03 164352 ----a-w- c:\temp\spwizui.dll
2009-10-30 17:23:03 13312 ----a-w- c:\temp\spcmsg.dll
2009-10-30 17:23:03 112640 ----a-w- c:\temp\spreview.exe
2009-10-30 17:23:03 0 d-----w- c:\temp\readme
2009-10-30 17:23:03 0 d-----w- c:\temp\eula
2009-10-30 17:23:03 0 d-----w- c:\temp\en-us
2009-10-30 17:23:03 0 d-----w- c:\temp\de-de
2009-10-30 17:01:34 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2009-10-30 17:01:26 0 d-----w- c:\users\owner\appdata\roaming\SUPERAntiSpyware.com
2009-10-30 17:01:26 0 d-----w- C:\SUPERAntiSpyware
2009-10-30 15:05:57 365230920 ----a-w- c:\temp\Windows6.0-KB948465-X86.exe
2009-10-30 03:10:58 0 d-----w- c:\users\owner\appdata\roaming\Malwarebytes
2009-10-30 03:10:45 0 d-----w- c:\programdata\Malwarebytes
2009-10-30 00:52:57 108336 ----a-w- c:\windows\system32\mswinsck.ocx
2009-10-30 00:28:37 0 d-----w- c:\program files\common files\Windows Live
2009-10-30 00:27:04 0 d-----w- c:\program files\Microsoft
2009-10-30 00:26:18 0 d-----w- c:\program files\Enigma Software Group
2009-10-29 18:40:00 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-29 18:39:33 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-29 18:39:28 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-29 18:39:28 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-29 14:43:50 0 d-----w- c:\users\owner\appdata\roaming\Uniblue
2009-10-29 13:59:34 0 d-----w- c:\programdata\RegAce
2009-10-29 12:52:59 81920 ----a-w- c:\windows\eSellerateControl350.dll
2009-10-29 12:52:59 356352 ----a-w- c:\windows\eSellerateEngine.dll
2009-10-29 12:52:59 0 d-----w- c:\program files\Svchost Fix Wizard
2009-10-29 02:13:06 54044 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-29 02:13:06 4519968 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-28 19:22:39 0 d-----w- c:\programdata\PC Tools
2009-10-28 17:39:27 22016 ----a-w- c:\windows\system32\drivers\extit.sys
2009-10-28 02:12:54 0 d-----w- c:\program files\Windows Portable Devices
2009-10-28 01:48:27 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-10-28 01:47:50 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-28 01:44:19 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-28 01:42:15 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-28 01:42:14 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-28 01:42:14 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-28 01:40:09 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-28 01:40:07 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-27 03:20:45 891392 ----a-w- c:\windows\system32\jkkKdebc.dll
2009-10-27 03:09:11 42 ----a-w- c:\windows\system32\RegistryEasy.lie
2009-10-27 01:01:27 0 d-----w- c:\program files\MSECACHE
2009-10-27 00:50:22 891392 ----a-w- c:\windows\system32\pmnLefdA.dll
2009-10-27 00:06:38 0 d-----w- c:\program files\SUPERAntiSpyware
2009-10-26 23:38:16 52624 ----a-w- c:\windows\system32\PxSecure.dll
2009-10-26 23:38:15 51656 ----a-w- c:\windows\system32\drivers\pxrts.sys
2009-10-26 23:38:15 30280 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-10-26 23:38:15 24368 ----a-w- c:\windows\system32\drivers\pxkbf.sys
2009-10-26 23:38:15 0 d-----w- c:\program files\Prevx
2009-10-26 23:38:09 50 ----a-w- c:\windows\wininit.ini
2009-10-26 17:03:58 524288 --sha-w- c:\users\owner\ntuser.dat{b11b8d22-c24d-11de-b212-00028a55ed6b}.TMContainer00000000000000000002.regtrans-ms
2009-10-26 17:03:57 65536 --sha-w- c:\users\owner\ntuser.dat{b11b8d22-c24d-11de-b212-00028a55ed6b}.TM.blf
2009-10-26 17:03:57 524288 --sha-w- c:\users\owner\ntuser.dat{b11b8d22-c24d-11de-b212-00028a55ed6b}.TMContainer00000000000000000001.regtrans-ms
2009-10-25 16:35:34 673280 ----a-w- c:\windows\isRS-000.tmp
2009-10-25 13:33:09 0 ----a-w- c:\windows\win32k.sys
2009-10-21 09:19:14 891392 --sh--r- C:\nds0q.exe
2009-10-16 06:50:54 3930 ----a-w- c:\windows\system32\ludap17.ini
2009-10-16 02:11:56 1168896 ----a-w- c:\windows\system32\drivers\P17.sys
2009-10-15 22:22:39 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-10-15 22:22:37 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-10-15 22:22:37 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-10-15 22:22:37 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-10-15 22:22:37 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-10-15 22:22:36 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-10-15 22:22:36 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-10-15 22:22:35 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-10-15 22:22:33 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2009-10-15 22:22:33 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2009-10-15 22:22:32 238088 ----a-w- c:\windows\system32\xactengine3_2.dll
2009-10-14 10:19:17 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-14 10:19:09 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 10:19:09 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-08 09:29:18 0 d-----w- c:\users\owner\appdata\roaming\EA
==================== Find3M ====================
2009-11-06 18:13:58 86016 ----a-w- c:\windows\inf\infpub.dat
2009-11-06 18:13:58 143360 ----a-w- c:\windows\inf\infstor.dat
2009-11-06 18:13:57 143360 ----a-w- c:\windows\inf\infstrng.dat
2009-10-31 12:08:55 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-10-31 12:08:55 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-10-28 02:12:49 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-01 01:02:17 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02:04 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02:00 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01:59 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01:59 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01:56 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01:56 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01:56 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01:56 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01:54 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-09-25 16:41:26 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-09-25 16:41:26 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-09-25 16:41:26 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-09-25 16:41:26 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-09-25 16:41:26 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-09-25 16:41:26 696320 ----a-w- c:\windows\system32\DivX.dll
2009-09-25 02:10:10 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07:08 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04:32 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49:22 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48:08 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38:29 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36:13 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35:31 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33:25 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33:15 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33:01 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32:59 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31:53 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31:26 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31:21 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31:19 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31:16 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31:15 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30:23 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30:23 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27:25 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27:04 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27:04 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27:04 1064448 ----a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54:55 258048 ----a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54:53 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54:52 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-14 09:29:50 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-11 17:14:41 118784 ----a-w- c:\windows\dsdxirmv.exe
2009-09-10 02:01:02 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2009-09-10 02:00:54 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2009-09-10 02:00:36 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2009-09-04 11:41:59 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 00:27:49 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-27 05:22:28 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17:43 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17:43 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42:29 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-26 02:17:50 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-08-25 02:31:18 613503 ----a-w- c:\windows\system32\APOIM32.exe
2009-08-17 22:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 15:53:34 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49:20 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49:18 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49:18 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49:15 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49:14 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49:14 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49:13 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48:02 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-13 07:19:42 144384 ----a-w- c:\windows\system32\OemSpiE.dll
2008-09-13 14:58:06 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-06-09 11:37:33 485864 --sha-w- c:\windows\system32\MTBJQXyb.ini2
============= FINISH: 23:05:14.65 ===============
Attached Files
Edited by Orange Blossom, 06 November 2009 - 07:12 PM.