Used Malwarebyte. First time found a series of fakealert files (the log file was destoryed)
Recovered Hardrive but virus was not removed. Sumehow it restored itself.
I believe the restore disk is infected.
Malwarebyte scans revealed the following:
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Combofix scans revealed the following:
c:\recycler\S-1-5-21-2952099033-2881960656-2168609194-1003
c:\windows\system32\_000006_.tmp.dll
D:\Autorun.inf
Current Status of System:
--No Internet Connection
--Fake Windows Security Center Appears in the System Tray
--When attempt to access Security Center, fake scans appear on the screen
--I cannot access ANY Safe Mode. I can only boot directly into windows.
I will make no further changes until instructed.
--------------------------------
DDS (Ver_09-12-01.01) - NTFSx86
Run by Owner at 14:27:48.67 on Wed 02/17/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.199 [GMT -6:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files\McAfee Online Backup\MOBKbackup.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.emachines.com/
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20100216214720.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [VTTimer] VTTimer.exe
mRun: [VTTrayp] VTtrayp.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\instal~1.lnk - c:\program files\sifxinst\SIFXINST.EXE
IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1266279042343
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\0diykrkn.default\
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-1-5 385536]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-2-16 82952]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2010-2-16 54776]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-2-16 271480]
R2 McMPFSvc;McAfee Personal Firewall;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-2-16 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-2-16 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-2-16 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-2-16 170144]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-2-16 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-2-16 141792]
R2 MOBKbackup;McAfee Online Backup;c:\program files\mcafee online backup\MOBKbackup.exe [2010-2-5 229688]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-2-16 55456]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-2-16 152320]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-2-16 51688]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-2-16 312584]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-2-16 88480]
S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager;c:\progra~1\mcafee.com\agent\mcupdmgr.exe --> c:\progra~1\mcafee.com\agent\mcupdmgr.exe [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-2-16 88480]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-2-16 83496]
=============== Created Last 30 ================
2010-02-17 19:00:36 0 d-----w- c:\windows\system32\scripting
2010-02-17 19:00:35 0 d-----w- c:\windows\l2schemas
2010-02-17 19:00:34 0 d-----w- c:\windows\system32\en
2010-02-17 19:00:34 0 d-----w- c:\windows\system32\bits
2010-02-17 18:55:51 0 d-----w- c:\windows\network diagnostic
2010-02-17 18:42:51 0 d-----w- c:\windows\EHome
2010-02-17 06:26:04 0 d-sha-r- C:\cmdcons
2010-02-17 05:42:59 98816 ----a-w- c:\windows\sed.exe
2010-02-17 05:42:59 77312 ----a-w- c:\windows\MBR.exe
2010-02-17 05:42:59 261632 ----a-w- c:\windows\PEV.exe
2010-02-17 05:42:59 161792 ----a-w- c:\windows\SWREG.exe
2010-02-17 03:49:37 0 d-----w- c:\program files\McAfeeMOBK
2010-02-17 03:49:16 54776 ----a-w- c:\windows\system32\drivers\MOBK.sys
2010-02-17 03:48:56 0 d-----w- c:\program files\McAfee Online Backup
2010-02-17 03:47:18 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-02-17 03:47:13 88480 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2010-02-17 03:47:13 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-02-17 03:47:13 82952 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2010-02-17 03:47:12 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-02-17 03:47:12 51688 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-02-17 03:47:12 312584 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-02-17 03:47:12 152320 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-02-17 03:47:06 0 d-----w- c:\program files\common files\Mcafee
2010-02-17 03:47:02 0 d-----w- c:\program files\McAfee.com
2010-02-17 03:46:34 0 d-----w- c:\program files\McAfee
2010-02-17 03:15:38 2 ----a-w- c:\windows\msoffice.ini
2010-02-17 02:48:18 0 d-----w- c:\docume~1\owner\applic~1\Malwarebytes
2010-02-17 02:48:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-17 02:48:06 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-17 02:48:05 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-17 02:48:04 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-17 01:19:46 0 ----a-w- c:\documents and settings\owner\defogger_reenable
2010-02-17 01:15:15 0 d-----w- c:\program files\Trend Micro
2010-02-16 22:06:59 73832 ------w- c:\windows\system32\slcoinst.dll
2010-02-16 22:05:58 76800 ------w- c:\windows\system32\msshavmsg.dll
2010-02-16 22:04:59 20992 ------w- c:\windows\system32\faxpatch.exe
2010-02-16 21:31:37 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2010-02-16 21:31:36 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-02-16 20:39:01 0 d-----w- c:\windows\pss
2010-02-16 03:43:42 0 d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-16 03:33:55 0 d-sh--w- c:\documents and settings\owner\PrivacIE
2010-02-16 01:42:36 0 d-sh--w- c:\documents and settings\owner\IETldCache
2010-02-16 01:29:21 0 d-----w- c:\docume~1\owner\applic~1\McAfee
2010-02-16 01:27:24 45056 ----a-w- c:\windows\_detmp.2
2010-02-16 01:27:24 44470 ----a-w- c:\windows\_detmp.1
2010-02-16 01:20:48 69120 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-02-16 01:20:31 0 d-----w- c:\windows\ie8updates
2010-02-16 01:20:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-02-16 01:20:13 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-02-16 01:20:13 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-02-16 01:20:13 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-02-16 01:20:13 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-02-16 01:20:12 11070464 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-02-16 01:18:37 0 dc-h--w- c:\windows\ie8
2010-02-16 01:01:07 0 d-----w- c:\windows\ServicePackFiles
2010-02-16 00:54:30 0 d-----w- c:\program files\MSXML 4.0
2010-02-16 00:32:50 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-02-16 00:32:50 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-02-16 00:32:15 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-02-16 00:28:35 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-02-16 00:28:34 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-02-16 00:26:34 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-16 00:13:01 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-02-16 00:09:37 0 d-s---w- c:\documents and settings\owner\UserData
2010-02-16 00:07:34 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-02-16 00:05:36 0 d-----w- c:\docume~1\owner\applic~1\Symantec
2010-02-16 00:04:52 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-02-16 00:04:30 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-02-16 00:00:41 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-02-15 23:59:44 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-02-15 23:59:42 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-02-15 23:54:12 0 d-----w- c:\windows\system32\PreInstall
2010-02-15 23:38:01 0 d-----w- c:\windows\system32\SoftwareDistribution
2010-02-15 23:04:16 8192 ----a-w- c:\windows\REGLOCS.OLD
2010-02-15 23:02:11 0 d-----w- c:\docume~1\owner\applic~1\AOL
2010-02-15 23:02:05 0 ----a-w- c:\windows\system32\Gateway_T3306__CK859H0008009.MRK
2010-02-15 23:01:58 333 ----a-w- c:\windows\system32\$ncsp$.inf
2010-02-15 22:53:50 0 d-----w- c:\docume~1\alluse~1\applic~1\McAfee.com
2010-02-15 22:53:17 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-02-15 22:52:42 0 d--h--w- c:\windows\$hf_mig$
2010-02-15 22:52:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-02-15 22:51:13 0 d-----w- c:\windows\RegisteredPackages
2010-02-15 22:51:02 67072 ----a-w- c:\windows\POWERCFG.EXE
2010-02-15 22:50:24 0 d-----w- c:\program files\Realtek Sound Manager
2010-02-15 22:50:24 0 d-----w- c:\program files\AvRack
2010-02-15 22:48:48 0 d-----w- c:\program files\Microsoft Money 2005
2010-02-15 22:48:25 0 d-----w- c:\docume~1\owner\applic~1\You've Got Pictures Screensaver
2010-02-15 22:48:23 0 d-----w- c:\program files\common files\Nullsoft
2010-02-15 22:48:09 86016 ----a-w- c:\windows\unvise32qt.exe
2010-02-15 22:48:03 0 d-----w- c:\windows\system32\QuickTime
2010-02-15 22:47:54 0 d-----w- c:\program files\common files\Real
2010-02-15 22:47:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Viewpoint
2010-02-15 22:47:41 0 d-----w- c:\program files\Viewpoint
2010-02-15 22:47:40 0 d-----w- c:\docume~1\alluse~1\applic~1\Pure Networks
2010-02-15 22:47:37 0 d-----w- c:\program files\Pure Networks
2010-02-15 22:46:39 1151 ---ha-w- C:\IPH.PH
2010-02-15 22:46:38 0 d-----w- c:\program files\common files\AOL
2010-02-15 22:46:31 0 d-----w- c:\program files\MSN Encarta Plus
2010-02-15 22:46:08 0 d-----w- c:\docume~1\alluse~1\applic~1\Napster
2010-02-15 22:46:03 0 d-----w- c:\program files\Napster
2010-02-15 22:45:45 4 ----a-w- c:\windows\Pix11.dat
2010-02-15 22:45:05 0 d-----w- c:\program files\Microsoft Digital Image 2006
2010-02-15 22:44:34 0 d-----w- c:\program files\VIA
2010-02-15 22:44:22 20480 ----a-w- c:\windows\system32\Marker32.exe
2010-02-15 22:44:20 0 d-----w- c:\program files\SIFXINST
2010-02-15 22:43:57 49265 ----a-w- c:\windows\system32\jpicpl32.cpl
2010-02-15 22:42:59 2238 ----a-w- c:\windows\system32\32-aol.ico
2010-02-15 22:42:59 1406 ----a-w- c:\windows\system32\16-aol.ico
2010-02-15 22:42:56 471300 ----a-w- c:\windows\wallpe.exe
2010-02-15 22:42:56 30056 ----a-w- c:\windows\system32\oemlogo.bmp
2010-02-15 22:41:22 376 ----a-w- c:\windows\ODBC.INI
2010-02-15 22:41:18 28040 ----a-w- c:\windows\system32\mdimon.dll
2010-02-15 22:40:50 0 d-----w- c:\program files\Microsoft ActiveSync
2010-02-15 22:40:29 0 d-----w- c:\windows\SHELLNEW
2010-02-15 22:39:38 65280 ----a-w- c:\windows\system32\drivers\Rtlnic51.sys
2010-02-15 22:34:18 0 d-----w- c:\program files\Symantec
2010-02-15 22:34:15 0 d-----w- c:\docume~1\alluse~1\applic~1\Symantec
2010-02-15 22:34:11 0 d-----w- c:\program files\common files\Symantec Shared
2010-02-15 22:34:07 3126 ----a-w- c:\windows\emachines_32.bmp
2010-02-15 22:33:52 0 d-----w- c:\program files\BigFix
2010-02-15 22:31:01 27904 ----a-w- c:\windows\system32\drivers\VIAAGP1.SYS
2010-02-15 22:30:50 0 d-----w- c:\windows\system32\ReinstallBackups
2010-02-15 22:28:43 0 d-----w- c:\program files\common files\New Boundary
2010-02-15 22:28:43 0 d-----w- c:\docume~1\alluse~1\applic~1\Prism Deploy
2010-02-15 22:25:55 0 d-----w- c:\windows\system32\URTTemp
2010-02-15 22:25:49 2 --sh--r- C:\USER
2010-02-15 22:25:27 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-02-15 22:25:22 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-02-15 22:24:45 0 d-----w- c:\program files\CONEXANT
2010-02-15 22:24:43 46464 ----a-w- c:\windows\system32\drivers\gagp30kx.sys
2010-02-15 22:24:23 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys
2010-02-15 22:24:13 7168 ----a-w- c:\windows\system32\hccoin.dll
2010-02-15 22:24:13 30208 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-02-15 22:21:01 60 ----a-w- c:\windows\system32\SYSDRV.DAT
2010-02-15 22:20:59 0 d-----w- c:\windows\creator
2010-02-15 22:19:26 86016 ----a-w- c:\windows\system32\mdmxsdk.dll
2010-02-15 22:19:26 685056 ----a-w- c:\windows\system32\drivers\HSF_CNXT.sys
2010-02-15 22:19:26 13059 ----a-w- c:\windows\system32\drivers\mdmxsdk.sys
2010-02-15 22:19:26 1041536 ----a-w- c:\windows\system32\drivers\HSF_DP.sys
2010-02-15 22:19:25 39018 ----a-w- c:\windows\system32\HSFCI011.dll
2010-02-15 22:19:25 220032 ----a-w- c:\windows\system32\drivers\HSFHWBS2.sys
2010-02-15 22:19:25 129045 ----a-w- c:\windows\system32\drivers\HSFProf.cty
2010-02-15 22:19:25 0 d-----w- c:\windows\SMINST
2010-02-15 22:19:21 0 d-----w- c:\windows\I386
2010-02-15 22:19:05 483840 ----a-w- c:\windows\system32\wzcsvc.dll
2010-02-15 22:19:04 52736 ----a-w- c:\windows\system32\wzcsapi.dll
2010-02-15 22:19:01 13824 ----a-w- c:\windows\system32\wowfaxui.dll
2010-02-15 22:17:58 69699 ----a-w- c:\windows\system32\usrcoina.dll
2010-02-15 22:16:58 55296 ----a-w- c:\windows\system32\dvdplay.exe
2010-02-15 22:15:18 47104 ----a-w- c:\windows\system32\cnbjmon.dll
2010-02-13 02:54:59 68096 ----a-w- c:\windows\system32\webclnt.dll
2010-02-13 02:53:59 838432 -c--a-w- c:\windows\system32\dllcache\mswdat10.dll
2010-02-13 02:52:59 9728 -c--a-w- c:\windows\system32\dllcache\label.exe
2010-02-13 02:51:59 96480 -c--a-w- c:\windows\system32\dllcache\cdm.dll
2010-02-06 03:14:48 0 ----a-w- c:\windows\MOBK.flt
2010-02-06 03:14:48 0 ----a-w- c:\windows\MOBK.blk
==================== Find3M ====================
2010-02-15 22:47:58 8552 ----a-w- c:\windows\system32\drivers\asctrm.sys
2010-01-06 00:04:02 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-01-06 00:04:02 385536 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-12-31 16:50:03 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14:05 916480 ------w- c:\windows\system32\wininet.dll
2009-12-16 18:43:27 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08:23 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-11-27 17:11:44 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:11:44 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 16:07:35 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07:35 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07:34 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07:34 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07:34 11264 ----a-w- c:\windows\system32\msrle32.dll
============= FINISH: 14:29:16.82 ===============