What can I possibly do to stop it from coming back? It seems the free tools aren't finding the exact source file and it only detects a copy that's why it keeps coming back.
NOTE:
I failed to do the GMER part of the Preparation Guide because at some point of the scanning, it seems to send me to a Blue Screen of Death.
DDS.txt Contents:
DDS (Ver_10-03-17.01) - NTFSx86
Run by KDK08 at 14:59:19.23 on Fri 09/03/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.73 [GMT 8:00]
============== Running Processes ===============
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\KDK08\Local Settings\Application Data\Meebo\Meebo Notifier\MeeboNotifier.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\WINDOWS\Status Report.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Wakoopa\Wakoopa.exe
E:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Documents and Settings\KDK08\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
E:\Mozilla\Firefox\firefox.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\procexp.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Documents and Settings\KDK08\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\KDK08\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\KDK08\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\KDK08\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
E:\Downloads\USBWebserver v8_en\usbwebserver.exe
E:\Downloads\USBWebserver v8_en\apache\bin\httpd_usbwv8.exe
E:\Downloads\USBWebserver v8_en\mysql\bin\mysqld_usbwv8.exe
E:\Downloads\USBWebserver v8_en\apache\bin\httpd_usbwv8.exe
E:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
E:\Mozilla\Firefox\plugin-container.exe
C:\Program Files\TechSmith\Jing\Jing.exe
E:\Downloads\dds.scr
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uSearch Page =
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
uInternet Settings,ProxyOverride = *.local 127.0.0.1
uSearchAssistant =
mSearchAssistant =
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\program files\java\jre6\bin\jp2ssv.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\kdk08\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Meebo Notifier] "c:\documents and settings\kdk08\local settings\application data\meebo\meebo notifier\MeeboNotifier.exe" /startup
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Tonido] "e:\downloads\tonidolite\tonido\launcher.exe" /nobrowser
uRun: [ITCSI Status Report Alerter] c:\windows\Status Report.exe
uRun: [Wakoopa] c:\program files\wakoopa\Wakoopa.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Everything] "c:\program files\everything\Everything.exe" -startup
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
StartupFolder: c:\docume~1\kdk08\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\kdk08\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\kdk08\startm~1\programs\startup\realde~1.lnk - c:\program files\real desktop\Real Desktop.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: Add to &Evernote - c:\program files\evernote\evernote3.5\enbar.dll/2000
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEEE} - c:\program files\evernote\evernote3.5\enbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AutorunsDisabled - LogonDll.dll
Notify: avgrsstarter - avgrsstx.dll
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\kdk08\applic~1\mozilla\firefox\profiles\djfojgwa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1593115&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.http - 93.62.4.207
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\kdk08\application data\mozilla\firefox\profiles\djfojgwa.default\extensions\{2be03c91-756d-4d3e-b861-e34e5fd84df1}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\kdk08\application data\mozilla\firefox\profiles\djfojgwa.default\extensions\{2be03c91-756d-4d3e-b861-e34e5fd84df1}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\kdk08\application data\mozilla\firefox\profiles\djfojgwa.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\kdk08\application data\mozilla\firefox\profiles\djfojgwa.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\kdk08\application data\mozilla\firefox\profiles\djfojgwa.default\extensions\graabr@graabr.com\components\cgraabr.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\google\google gears\firefox\lib\ff36\gears.dll
FF - component: e:\mozilla\firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\kdk08\application data\mozilla\firefox\profiles\djfojgwa.default\extensions\{abad4342-3fda-4ccf-80ac-b6d0eecaca07}\plugins\npvivoxvoiceplugin.dll
FF - plugin: c:\documents and settings\kdk08\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: e:\mozilla\firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: e:\program files\java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: e:\program files\java\jre6\bin\new_plugin\npjp2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - e:\mozilla\firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truee:\mozilla\firefox\greprefs\all.js - pref("ui.use_native_colors", true);
e:\mozilla\firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
e:\mozilla\firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
e:\mozilla\firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
e:\mozilla\firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
e:\mozilla\firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
e:\mozilla\firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
e:\mozilla\firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
e:\mozilla\firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
e:\mozilla\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
e:\mozilla\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
e:\mozilla\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
e:\mozilla\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
e:\mozilla\firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
e:\mozilla\firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
e:\mozilla\firefox\greprefs\all.js - pref("network.proxy.type", 5);
e:\mozilla\firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
e:\mozilla\firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
e:\mozilla\firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
e:\mozilla\firefox\greprefs\all.js - pref("svg.smil.enabled", false);
e:\mozilla\firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
e:\mozilla\firefox\greprefs\all.js - pref("browser.formfill.debug", false);
e:\mozilla\firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
e:\mozilla\firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
e:\mozilla\firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
e:\mozilla\firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
e:\mozilla\firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
e:\mozilla\firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
e:\mozilla\firefox\greprefs\all.js - pref("accelerometer.enabled", true);
e:\mozilla\firefox\greprefs\all.js - pref("html5.enable", false);
e:\mozilla\firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
e:\mozilla\firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
e:\mozilla\firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
e:\mozilla\firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
e:\mozilla\firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
e:\mozilla\firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
e:\mozilla\firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
e:\mozilla\firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
e:\mozilla\firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
e:\mozilla\firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
e:\mozilla\firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
e:\mozilla\firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
e:\mozilla\firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
e:\mozilla\firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 DeepFrz;DeepFrz;c:\windows\system32\drivers\DeepFrz.sys [2006-11-29 127896]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-8-6 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-8-6 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-8-6 243024]
R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2010-7-4 119016]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-23 136176]
S2 sknusrtso;Support Update;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 xpbidvlbf;Boot Support;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2010-8-4 100480]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S4 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-8-6 921952]
S4 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-8-6 308136]
S4 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\kdk08\locals~1\temp\ycue.tmp --> c:\docume~1\kdk08\locals~1\temp\YCUE.tmp [?]
S4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S4 XDva281;XDva281;\??\c:\windows\system32\xdva281.sys --> c:\windows\system32\XDva281.sys [?]
S4 XDva326;XDva326;\??\c:\windows\system32\xdva326.sys --> c:\windows\system32\XDva326.sys [?]
S4 XDva332;XDva332;\??\c:\windows\system32\xdva332.sys --> c:\windows\system32\XDva332.sys [?]
S4 XDva337;XDva337;\??\c:\windows\system32\xdva337.sys --> c:\windows\system32\XDva337.sys [?]
S4 XDva344;XDva344;\??\c:\windows\system32\xdva344.sys --> c:\windows\system32\XDva344.sys [?]
S4 XDva347;XDva347;\??\c:\windows\system32\xdva347.sys --> c:\windows\system32\XDva347.sys [?]
S4 XDva349;XDva349;\??\c:\windows\system32\xdva349.sys --> c:\windows\system32\XDva349.sys [?]
=============== Created Last 30 ================
2010-09-03 02:32:19 0 d-----w- c:\windows\system32\KB905474
2010-09-03 02:25:00 150 ----a-w- c:\windows\system32\spupdsvc.inf
2010-09-03 02:13:59 0 d-----w- c:\windows\ServicePackFiles
2010-09-03 02:07:19 0 d-----w- c:\windows\ie8updates
2010-09-02 10:34:08 0 d-----w- c:\windows\system32\CatRoot_bak
2010-09-02 10:23:46 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-09-02 10:23:46 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-09-02 10:20:12 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-09-02 10:19:41 726528 ------w- c:\windows\system32\SET758.tmp
2010-09-02 10:08:22 1172480 ------w- c:\windows\system32\SET3B0.tmp
2010-09-02 09:58:54 332800 ----a-w- c:\windows\system32\SET14C.tmp
2010-09-02 09:55:48 0 d-----w- c:\windows\system32\PreInstall
2010-09-02 09:50:01 0 d-----w- c:\windows\system32\SoftwareDistribution
2010-09-01 06:40:40 0 d-----w- c:\docume~1\alluse~1\applic~1\TinyPic Media Manager
2010-09-01 06:40:34 0 d-----w- c:\docume~1\alluse~1\applic~1\TinyPic
2010-09-01 06:40:03 0 d-----w- c:\program files\Haali
2010-09-01 06:40:00 547 ----a-w- c:\windows\system32\ff_vfw.dll.manifest
2010-09-01 06:39:59 57344 ----a-w- c:\windows\system32\ff_vfw.dll
2010-09-01 06:39:58 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2010-09-01 06:39:56 0 d-----w- c:\program files\ffdshow
2010-09-01 06:39:42 0 d-----w- c:\program files\TinyPic
2010-09-01 06:36:21 0 d-----w- c:\program files\Wakoopa
2010-09-01 05:45:46 0 d-----w- c:\documents and settings\kdk08\.bluemelon
2010-09-01 02:20:53 0 d-----w- c:\docume~1\kdk08\applic~1\Real Desktop
2010-09-01 02:20:43 0 d-----w- c:\program files\Real Desktop
2010-08-31 08:09:19 301313 ----a-w- c:\windows\Status Report.exe
2010-08-31 07:07:15 0 d-----w- c:\docume~1\kdk08\applic~1\Malwarebytes
2010-08-31 07:07:05 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-31 07:07:03 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-31 07:07:03 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-08-31 07:07:02 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-27 03:13:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Messenger Plus!
2010-08-27 03:12:43 0 d-----w- c:\program files\Messenger Plus! Live
2010-08-26 03:38:52 0 d-----w- c:\program files\WinHTTrack
2010-08-25 09:16:38 0 d-----w- c:\docume~1\kdk08\applic~1\Easy Duplicate Finder
2010-08-25 09:16:38 0 d-----w- c:\docume~1\alluse~1\applic~1\Easy Duplicate Finder
2010-08-25 09:16:37 0 d-----w- c:\program files\Easy Duplicate Finder
2010-08-25 01:46:27 0 d-----w- c:\windows\system32\NtmsData
2010-08-24 07:22:42 0 d-----w- c:\program files\Veoh Networks
2010-08-20 05:52:16 0 d-----w- c:\program files\vbSkinner Pro 2
2010-08-20 05:52:10 193024 ------w- c:\windows\Setup1.exe
2010-08-20 05:52:09 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-08-19 08:03:40 0 d-----w- c:\program files\Evernote
2010-08-18 03:16:47 1712128 ----a-w- c:\windows\system32\GdiPlus.dll
2010-08-18 03:16:05 0 d-----w- c:\program files\Pass4sure Test Environment
2010-08-16 04:44:03 0 d-----w- c:\documents and settings\kdk08\Tracing
2010-08-16 04:41:17 0 d-----w- c:\program files\Windows Live SkyDrive
2010-08-16 01:59:26 0 d-----w- c:\program files\WinSCP
2010-08-13 05:32:47 436 ----a-w- c:\documents and settings\kdk08\SciTE.session
2010-08-13 04:31:06 0 d-----w- c:\program files\AutoIt3
2010-08-12 08:11:58 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-08-12 08:11:58 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-08-12 08:11:14 0 d-----w- c:\program files\iPod
2010-08-12 08:11:10 0 d-----w- c:\program files\iTunes
2010-08-12 08:11:10 0 d-----w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-12 08:09:11 0 d-----w- c:\program files\Bonjour
2010-08-12 02:05:56 0 d-----w- c:\docume~1\kdk08\applic~1\TeamViewer
2010-08-12 02:05:49 0 d-----w- c:\program files\TeamViewer
2010-08-11 08:22:33 134122 ----a-w- c:\windows\ColorPic Uninstaller.exe
2010-08-11 08:22:33 0 d-----w- c:\program files\ColorPic 4.1
2010-08-11 04:51:45 0 d-----w- c:\program files\Lame for Audacity
2010-08-11 04:46:03 0 d-----w- c:\program files\Audacity
2010-08-11 03:09:37 0 d-----w- c:\program files\OpenOffice.org 3
2010-08-11 02:50:56 0 d-----w- c:\program files\VS Revo Group
2010-08-11 02:49:23 0 d-----w- c:\program files\Everything
2010-08-10 07:52:16 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-08-10 07:50:53 0 d-----r- c:\program files\Skype
2010-08-10 04:35:05 0 d-----w- C:\logs
2010-08-10 04:35:04 0 d-----w- c:\documents and settings\kdk08\ChikkaDefault
2010-08-10 04:34:56 0 d-----w- c:\program files\Chikka Messenger
2010-08-09 08:16:03 0 d-----w- c:\docume~1\kdk08\applic~1\IcoFX
2010-08-09 08:16:00 0 d-----w- c:\program files\IcoFX 1.6
2010-08-09 06:36:36 0 d--h--w- c:\windows\PIF
2010-08-09 04:28:53 0 d-----w- c:\docume~1\kdk08\applic~1\Vivox
2010-08-06 08:53:30 0 d-----w- c:\docume~1\kdk08\applic~1\SQLyog
2010-08-06 08:53:22 0 d-----w- c:\program files\SQLyog Community
2010-08-06 06:43:04 179 ----a-w- c:\documents and settings\kdk08\.jupload.properties
2010-08-06 06:24:55 634 ----a-w- c:\windows\system32\MAPISVC.INF
2010-08-06 06:24:20 0 d-----w- c:\program files\Kroll Ontrack
2010-08-06 04:26:07 0 d-----w- c:\docume~1\alluse~1\applic~1\regid.1986-12.com.adobe
2010-08-06 04:16:13 0 d--h--w- C:\$AVG
2010-08-06 04:01:51 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-08-06 04:01:40 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-06 04:01:32 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-06 04:01:09 0 d-----w- c:\windows\system32\drivers\Avg
2010-08-06 03:57:19 0 d-----w- c:\program files\AVG
2010-08-06 03:56:53 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-08-06 03:42:28 0 d-----r- C:\Sandbox
2010-08-06 03:41:38 3312 ----a-w- c:\windows\Sandboxie.ini
2010-08-06 03:41:32 0 d-----w- c:\program files\Sandboxie
2010-08-06 03:34:22 0 d-----w- c:\program files\VirusTotalUploader2
2010-08-06 01:52:28 0 d-----w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
2010-08-06 01:52:27 0 d-----w- c:\program files\McAfee Security Scan
2010-08-05 08:11:09 0 d-----w- c:\program files\common files\Macrovision Shared
2010-08-05 06:49:16 0 d-----w- c:\docume~1\alluse~1\applic~1\Blumentals
2010-08-05 06:48:55 0 d-----w- c:\program files\Easy GIF Animator Pro 5.1
2010-08-05 06:36:31 0 d-----w- c:\docume~1\kdk08\applic~1\Dropbox
2010-08-05 06:21:34 0 d-----w- c:\program files\uTorrent
2010-08-05 06:21:22 0 d-----w- c:\docume~1\kdk08\applic~1\uTorrent
2010-08-05 03:35:12 0 d-----w- c:\docume~1\kdk08\applic~1\Meebo
2010-08-05 03:04:20 0 d-----w- c:\program files\JDownloader
2010-08-05 01:54:47 0 --sha-r- C:\khx
2010-08-05 01:46:29 0 --sha-r- C:\khq
==================== Find3M ====================
2010-08-13 03:48:28 117184 ----a-w- c:\windows\fonts\sand.ttf
2010-08-02 02:55:52 316280 ----a-w- c:\windows\system32\Tcpview.exe
2010-07-28 07:47:44 479096 ----a-w- c:\windows\system32\ADExplorer.exe
2010-07-28 07:47:44 199544 ----a-w- c:\windows\system32\Tcpvcon.exe
2010-07-28 07:47:44 1765752 ----a-w- c:\windows\system32\disk2vhd.exe
2010-07-21 16:35:56 703352 ----a-w- c:\windows\system32\autoruns.exe
2010-07-21 16:35:54 585080 ----a-w- c:\windows\system32\autorunsc.exe
2010-07-21 16:35:54 287096 ----a-w- c:\windows\system32\procdump.exe
2010-06-22 01:31:36 135544 ----a-w- c:\windows\system32\Autologon.exe
2010-06-21 15:39:42 564600 ----a-w- c:\windows\system32\RamMap.exe
2010-06-07 08:16:56 3887480 ----a-w- c:\windows\system32\procexp.exe
2010-06-07 08:16:54 220024 ----a-w- c:\windows\system32\sigcheck.exe
2009-03-21 14:18:57 168961 --sha-r- c:\windows\system32\yffzc.dll
============= FINISH: 14:59:58.37 ===============