DDS (Ver_09-12-01.01) - NTFSX64 Run by Niklas at 15:26:15,65 on 20.02.2010 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.47.1033.18.6135.3992 [GMT 1:00] SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} ============== Running Processes =============== X:\Windows\system32\wininit.exe X:\Windows\system32\lsm.exe X:\Windows\system32\svchost.exe -k DcomLaunch X:\Windows\system32\svchost.exe -k RPCSS X:\Program Files\Microsoft Security Essentials\MsMpEng.exe X:\Windows\system32\atiesrxx.exe X:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted X:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted X:\Windows\system32\svchost.exe -k netsvcs X:\Windows\system32\svchost.exe -k LocalService X:\Windows\system32\svchost.exe -k NetworkService X:\Windows\system32\atieclxx.exe X:\Windows\System32\spoolsv.exe X:\Windows\system32\svchost.exe -k LocalServiceNoNetwork X:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe X:\Windows\system32\taskhost.exe X:\Windows\system32\taskeng.exe X:\Windows\system32\Dwm.exe X:\Windows\Explorer.EXE C:\Fraps\fraps.exe X:\Program Files (x86)\Bonjour\mDNSResponder.exe X:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation X:\Windows\system32\ftusbsrv.exe X:\Windows\system32\ftusbsrvc.exe X:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe X:\Windows\SysWOW64\PnkBstrA.exe X:\Program Files\Microsoft Security Essentials\msseces.exe X:\Program Files (x86)\Skype\Phone\Skype.exe X:\Program Files\Windows Sidebar\sidebar.exe X:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe X:\Program Files (x86)\DisplayFusion\DisplayFusion.exe X:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe X:\Users\Niklas\AppData\Local\Temp\svchstx.exe X:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe X:\Program Files\Logitech\SetPoint II\SetPointII.exe X:\Program Files (x86)\SpeedFan\speedfan.exe X:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE X:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe X:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe X:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe X:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe X:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe X:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe X:\Windows\system32\wbem\wmiprvse.exe X:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe X:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted X:\Windows\system32\SearchIndexer.exe X:\Program Files\Windows Media Player\wmpnetwk.exe X:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Spill\Steam\Steam.exe C:\Fraps\fraps64.dat X:\Users\Niklas\Desktop\Programmer\Realtemp\RealTemp.exe X:\Windows\system32\taskmgr.exe X:\Users\Niklas\AppData\Local\Google\Chrome\Application\chrome.exe X:\Users\Niklas\AppData\Local\Google\Chrome\Application\chrome.exe X:\Users\Niklas\AppData\Local\Google\Chrome\Application\chrome.exe X:\Users\Niklas\AppData\Local\Google\Chrome\Application\chrome.exe X:\Users\Niklas\AppData\Local\Google\Chrome\Application\chrome.exe X:\Users\Niklas\AppData\Local\Google\Chrome\Application\chrome.exe X:\Users\Niklas\AppData\Local\Google\Chrome\Application\chrome.exe X:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe X:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe X:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe X:\Program Files (x86)\Spotify\spotify.exe X:\Users\Niklas\AppData\Local\Google\Chrome\Application\chrome.exe X:\Program Files (x86)\DisplayFusion\DisplayFusionHookx86.exe C:\Downloads\Chrome_Downloads\dds.scr X:\Windows\system32\conhost.exe ============== Pseudo HJT Report =============== BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - x:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - x:\program files (x86)\bitcomet\tools\BitCometBHO_1.4.1.10.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - x:\progra~2\spybot~1\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - x:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - x:\program files (x86)\java\jre6\bin\jp2ssv.dll uRun: [Skype] "x:\program files (x86)\skype\phone\Skype.exe" /nosplash /minimized uRun: [Sidebar] x:\program files\windows sidebar\sidebar.exe /autoRun uRun: [DAEMON Tools Lite] "x:\program files (x86)\daemon tools lite\DTLite.exe" -autorun uRun: [Steam] "c:\spill\steam\steam.exe" -silent uRun: [DisplayFusion] "x:\program files (x86)\displayfusion\DisplayFusion.exe" uRun: [SpybotSD TeaTimer] x:\program files (x86)\spybot - search & destroy\TeaTimer.exe mRun: [MSIAfterburner] "x:\program files (x86)\msi afterburner\MSIAfterburnerWrapper.exe" /s mRun: [Adobe Reader Speed Launcher] "x:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "x:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "x:\program files (x86)\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "x:\program files (x86)\common files\java\java update\jusched.exe" mRun: [RTSS] "x:\program files (x86)\msi afterburner\bundle\osdserver\RTSSWrapper.exe" /s mRun: [StartCCC] "x:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun uExplorerRun: [Policies] x:\users\niklas\appdata\roaming\install\Microsoft.exe mExplorerRun: [Policies] x:\users\niklas\appdata\roaming\install\Microsoft.exe StartupFolder: x:\progra~3\micros~1\windows\startm~1\programs\startup\logmei~1.lnk - x:\program files (x86)\logmein hamachi\hamachi-2-ui.exe StartupFolder: x:\progra~3\micros~1\windows\startm~1\programs\startup\setpoi~1.lnk - x:\program files\logitech\setpoint ii\SetPointII.exe StartupFolder: x:\progra~3\micros~1\windows\startm~1\programs\startup\speedfan.lnk - x:\program files (x86)\speedfan\speedfan.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: &D&ownload alle med BitComet - x:\program files (x86)\bitcomet\BitComet.exe/AddAllLink.htm IE: &L&ast Ned &med BitComet - x:\program files (x86)\bitcomet\BitComet.exe/AddLink.htm IE: &L&ast Ned all video med BitComet - x:\program files (x86)\bitcomet\BitComet.exe/AddVideo.htm IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://x:\program files (x86)\bitcomet\tools\BitCometBHO_1.4.1.10.dll/206 IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - x:\progra~2\spybot~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab mRun-x64: [MSSE] "x:\program files\microsoft security essentials\msseces.exe" -hide Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - x:\users\niklas\appdata\roaming\mozilla\firefox\profiles\9j8ev0jr.default\ FF - plugin: x:\users\niklas\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll ---- FIREFOX POLICIES ---- x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); x:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false); x:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); x:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); x:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); x:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); x:\program files (x86)\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); x:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 MpFilter;Microsoft Malware Protection Driver;x:\windows\system32\drivers\MpFilter.sys [2009-6-18 164720] R2 AMD External Events Utility;AMD External Events Utility;x:\windows\system32\atiesrxx.exe [2009-11-25 202752] R2 ftusbsrv;USB over Network (Server) service;x:\windows\system32\ftusbsrv.exe [2009-12-1 1384448] R2 ftusbsrvc;USB over Network (Client) service;x:\windows\system32\ftusbsrvc.exe [2009-12-1 1282048] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;x:\program files (x86)\logmein hamachi\hamachi-2.exe [2009-10-29 1767816] R2 SBSDWSCService;SBSD Security Center Service;x:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2010-2-13 1153368] R2 TeamViewer5;TeamViewer 5;x:\program files (x86)\teamviewer\version5\TeamViewer_Service.exe [2010-2-11 172328] R3 ftusbhub;Virtual USB Bus;x:\windows\system32\drivers\ftusbbus.sys [2009-12-1 41976] R3 ftusbload;ftusbload;x:\windows\system32\drivers\ftusbload.sys [2009-12-1 42488] R3 MpNWMon;Microsoft Malware Protection Network Driver;x:\windows\system32\drivers\MpNWMon.sys [2009-6-18 40832] R3 RTCore64;RTCore64;x:\program files (x86)\msi afterburner\RTCore64.sys [2009-11-12 14648] R3 RTL8167;Realtek 8167 NT Driver;x:\windows\system32\drivers\Rt64win7.sys [2009-6-10 187392] R3 WinRing0_1_2_0;WinRing0_1_2_0;x:\users\niklas\desktop\programmer\realtemp\WinRing0x64.sys [2010-1-6 14544] S3 amdkmdag;amdkmdag;x:\windows\system32\drivers\atipmdag.sys [2009-12-11 6228480] S3 amdkmdap;amdkmdap;x:\windows\system32\drivers\atikmpag.sys [2009-12-11 160256] S3 ENTECH64;ENTECH64;x:\windows\system32\drivers\Entech64.sys [2010-1-6 12744] S3 ftusb;ftusb;x:\windows\system32\drivers\ftusb.sys [2009-12-1 19960] S3 USBAAPL64;Apple Mobile USB Driver;x:\windows\system32\drivers\usbaapl64.sys [2009-8-28 49152] =============== Created Last 30 ================ 2010-02-19 22:11:00 0 d-sh--w- x:\programdata\SecuROM 2010-02-19 20:42:41 0 d-----w- x:\windows\pss 2010-02-19 13:20:44 0 d-----w- x:\program files (x86)\CAPCOM 2010-02-17 21:36:00 0 d-----w- x:\programdata\GARMIN 2010-02-17 18:05:59 0 d-----w- x:\users\niklas\appdata\roaming\TeamViewer 2010-02-17 18:05:49 0 d-----w- x:\program files (x86)\TeamViewer 2010-02-17 18:02:14 0 d-----w- x:\program files\USB over Network (Client) 2010-02-17 18:00:44 0 d-----w- x:\program files\USB over Network (Server) 2010-02-17 18:00:44 0 d-----w- x:\program files (x86)\common files\FabulaTech 2010-02-16 17:37:44 0 d-----w- x:\programdata\ATI 2010-02-16 17:36:03 0 d-----w- x:\program files (x86)\ATI 2010-02-16 17:35:35 0 d-----w- x:\program files (x86)\ATI Technologies 2010-02-16 17:35:31 0 d-----w- x:\program files\ATI Technologies 2010-02-16 17:35:27 0 d-----w- x:\program files\ATI 2010-02-14 19:34:29 0 d-----w- x:\program files (x86)\Garmin GPS Plugin 2010-02-14 19:31:46 0 d-----w- x:\users\niklas\appdata\roaming\GARMIN 2010-02-14 19:26:45 0 d-----w- x:\program files\DIFX 2010-02-14 19:26:45 0 d-----w- x:\program files (x86)\Garmin 2010-02-14 18:25:18 0 d-----w- x:\users\niklas\appdata\roaming\CopyTransPhoto 2010-02-14 18:24:42 0 d-----w- x:\users\niklas\appdata\roaming\WindSolutions 2010-02-14 18:24:42 0 d-----w- x:\programdata\WindSolutions 2010-02-14 18:14:00 0 d-----w- x:\program files\iPod 2010-02-14 18:13:59 0 d-----w- x:\program files\iTunes 2010-02-14 18:13:59 0 d-----w- x:\program files (x86)\iTunes 2010-02-14 12:50:03 0 d-----w- x:\users\niklas\Unigine Tropics 2010-02-14 12:43:58 0 d-----w- x:\program files (x86)\Unigine 2010-02-13 21:46:10 0 d-----w- x:\programdata\Spybot - Search & Destroy 2010-02-13 21:46:10 0 d-----w- x:\program files (x86)\Spybot - Search & Destroy 2010-02-12 21:37:27 0 d-----w- x:\programdata\Azureus 2010-02-12 21:37:26 0 d-----w- x:\users\niklas\appdata\roaming\Azureus 2010-02-12 21:37:13 0 d-----w- x:\program files (x86)\Vuze 2010-02-12 13:39:41 0 d-----w- x:\users\niklas\appdata\roaming\Bioshock2 2010-02-12 13:28:06 0 d-----w- x:\program files (x86)\2K Games 2010-02-11 18:25:28 0 d-----w- x:\program files (x86)\Lavalys 2010-02-11 06:56:58 109080 ----a-w- x:\windows\syswow64\OpenAL32.dll 2010-02-10 19:57:14 0 d-----w- x:\users\niklas\appdata\roaming\DisplayFusion 2010-02-10 19:55:25 0 d-----w- x:\program files (x86)\DisplayFusion 2010-02-10 17:31:58 0 d-----w- x:\users\niklas\appdata\roaming\BitComet 2010-02-10 17:31:37 0 d-----w- x:\program files (x86)\BitComet 2010-02-10 06:41:47 0 d-----w- x:\users\niklas\appdata\roaming\Malwarebytes 2010-02-10 06:41:43 0 d-----w- x:\programdata\Malwarebytes 2010-02-10 06:41:42 22104 ----a-w- x:\windows\system32\drivers\mbam.sys 2010-02-10 06:41:42 0 d-----w- x:\program files (x86)\Malwarebytes' Anti-Malware 2010-02-10 01:49:56 285696 ----a-w- x:\windows\system32\drivers\mrxsmb10.sys 2010-02-07 10:08:10 0 d-----w- x:\windows\syswow64\install 2010-02-05 20:02:50 0 ---ha-w- x:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2010-02-05 20:02:50 0 ---ha-w- x:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf 2010-02-05 20:02:43 0 d-----w- x:\program files\Logitech 2010-02-05 20:02:41 0 d-----w- x:\program files\common files\Logishrd 2010-02-05 20:02:40 0 d-----w- x:\programdata\LogiShrd 2010-02-05 20:01:40 0 d-----w- x:\program files (x86)\SystemRequirementsLab 2010-02-05 19:49:11 0 d-----w- x:\users\niklas\appdata\roaming\system23 2010-02-05 15:46:11 0 d-----w- x:\program files (x86)\Pocket Tanks Deluxe 2010-02-04 20:13:56 159744 ----a-w- x:\users\niklas\appdata\roaming\Winject1.exe 2010-01-29 19:01:01 2434856 ----a-w- x:\windows\syswow64\pbsvc_bc2.exe 2010-01-29 18:23:40 0 dc-h--w- x:\programdata\{5794CDCB-FAB7-4C15-9069-4D8AC02592DE} 2010-01-27 20:07:39 389632 ----a-w- x:\windows\system32\winlogon.exe 2010-01-27 20:07:39 2870272 ----a-w- x:\windows\explorer.exe 2010-01-27 20:07:39 2614272 ----a-w- x:\windows\syswow64\explorer.exe 2010-01-26 18:01:33 0 d-----r- x:\users\niklas\Virtual Machines 2010-01-26 17:59:12 0 d-----w- x:\program files (x86)\Windows Virtual PC 2010-01-26 17:54:23 15872 ----a-w- x:\windows\system32\vpchbuspipe.dll 2010-01-26 17:54:22 95232 ----a-w- x:\windows\system32\drivers\vpcusb.sys 2010-01-26 17:54:22 66304 ----a-w- x:\windows\system32\drivers\vpcnfltr.sys 2010-01-26 17:54:22 359552 ----a-w- x:\windows\system32\drivers\vpcvmm.sys 2010-01-26 17:54:22 187904 ----a-w- x:\windows\system32\drivers\vpchbus.sys 2010-01-26 17:54:21 936448 ----a-w- x:\windows\system32\vmsal.exe 2010-01-26 17:54:21 793600 ----a-w- x:\windows\syswow64\vmsal.exe 2010-01-26 17:54:21 562176 ----a-w- x:\windows\system32\VMCPropertyHandler.dll 2010-01-26 17:54:21 4513792 ----a-w- x:\windows\system32\vpc.exe 2010-01-26 17:54:21 2262016 ----a-w- x:\windows\system32\VPCWizard.exe 2010-01-26 17:54:21 1369600 ----a-w- x:\windows\system32\VPCSettings.exe 2010-01-26 17:54:21 1209856 ----a-w- x:\windows\system32\VMWindow.exe 2010-01-26 17:03:44 0 d-----w- x:\users\niklas\.VirtualBox 2010-01-26 17:03:30 193232 ----a-w- x:\windows\system32\drivers\VBoxDrv.sys 2010-01-26 17:03:28 53264 ----a-w- x:\windows\system32\drivers\VBoxUSBMon.sys 2010-01-25 14:37:37 669184 ----a-w- x:\windows\syswow64\pbsvc.exe 2010-01-25 14:37:35 0 dc-h--w- x:\programdata\{0151C9FC-719D-4459-B1E2-4685CC6E62A8} 2010-01-23 22:23:32 0 d-----w- x:\program files (x86)\Timeline Interactive 2010-01-23 12:02:37 0 d-----w- x:\programdata\Sun 2010-01-23 12:02:32 411368 ----a-w- x:\windows\syswow64\deploytk.dll 2010-01-23 12:02:32 153376 ----a-w- x:\windows\syswow64\javaws.exe 2010-01-23 12:02:32 145184 ----a-w- x:\windows\syswow64\javaw.exe 2010-01-23 12:02:32 145184 ----a-w- x:\windows\syswow64\java.exe 2010-01-23 09:03:08 17686528 ----a-w- x:\windows\syswow64\mkl_blueripple.dll 2010-01-23 09:03:08 1347584 ----a-w- x:\windows\syswow64\rapture3d_oal.dll 2010-01-22 17:01:24 215128 ----a-w- x:\windows\syswow64\PnkBstrB.xtr 2010-01-22 06:17:17 5961728 ----a-w- x:\windows\syswow64\mshtml.dll 2010-01-22 06:17:17 10976768 ----a-w- x:\windows\syswow64\ieframe.dll 2010-01-22 06:17:16 977920 ----a-w- x:\windows\syswow64\wininet.dll 2010-01-22 06:17:16 64512 ----a-w- x:\windows\syswow64\msfeedsbs.dll 2010-01-22 06:17:16 381440 ----a-w- x:\windows\syswow64\iedkcs32.dll 2010-01-22 06:17:16 1224704 ----a-w- x:\windows\syswow64\urlmon.dll 2010-01-22 06:17:16 1192960 ----a-w- x:\windows\system32\wininet.dll ==================== Find3M ==================== 2010-02-20 08:36:35 74516 ----a-w- x:\windows\system32\perfc014.dat 2010-02-20 08:36:35 449518 ----a-w- x:\windows\system32\perfh014.dat 2010-02-19 16:54:54 215128 ----a-w- x:\windows\syswow64\PnkBstrB.exe 2010-02-13 02:05:45 75064 ----a-w- x:\windows\syswow64\PnkBstrA.exe 2010-02-11 06:56:58 122904 ----a-w- x:\windows\system32\OpenAL32.dll 2010-01-24 21:35:30 57104 ----a-w- x:\windows\fonts\lokicola.ttf 2010-01-24 21:34:29 55636 ----a-w- x:\windows\fonts\interdimensional.ttf 2010-01-24 21:33:05 46584 ----a-w- x:\windows\fonts\ikarus.ttf 2010-01-24 21:32:33 55016 ----a-w- x:\windows\fonts\mechanicalfun.ttf 2010-01-24 21:32:30 47596 ----a-w- x:\windows\fonts\plastique.ttf 2010-01-19 09:05:57 424960 ----a-w- x:\windows\system32\secproc.dll 2010-01-19 09:05:57 422912 ----a-w- x:\windows\system32\secproc_isv.dll 2010-01-19 09:05:57 121856 ----a-w- x:\windows\system32\secproc_ssp_isv.dll 2010-01-19 09:05:57 121856 ----a-w- x:\windows\system32\secproc_ssp.dll 2010-01-19 09:00:44 305152 ----a-w- x:\windows\system32\RMActivate_ssp_isv.exe 2010-01-19 09:00:43 357888 ----a-w- x:\windows\system32\RMActivate_isv.exe 2010-01-19 09:00:37 356352 ----a-w- x:\windows\system32\RMActivate.exe 2010-01-19 09:00:37 306688 ----a-w- x:\windows\system32\RMActivate_ssp.exe 2010-01-18 23:29:31 85504 ----a-w- x:\windows\syswow64\secproc_ssp_isv.dll 2010-01-18 23:29:31 85504 ----a-w- x:\windows\syswow64\secproc_ssp.dll 2010-01-18 23:29:31 365568 ----a-w- x:\windows\syswow64\secproc_isv.dll 2010-01-18 23:29:30 369152 ----a-w- x:\windows\syswow64\secproc.dll 2010-01-18 23:28:33 324608 ----a-w- x:\windows\syswow64\RMActivate_isv.exe 2010-01-18 23:28:33 277504 ----a-w- x:\windows\syswow64\RMActivate_ssp_isv.exe 2010-01-18 23:28:30 320512 ----a-w- x:\windows\syswow64\RMActivate.exe 2010-01-18 23:28:30 280064 ----a-w- x:\windows\syswow64\RMActivate_ssp.exe 2010-01-16 08:53:21 466520 ----a-w- x:\windows\system32\wrap_oal.dll 2010-01-16 08:53:21 445016 ----a-w- x:\windows\syswow64\wrap_oal.dll 2010-01-16 08:53:03 0 ---ha-w- x:\windows\system32\drivers\Msft_Kernel_xusb21_01009.Wdf 2010-01-14 10:12:06 212352 ------w- x:\windows\system32\MpSigStub.exe 2010-01-12 05:25:01 178800 ----a-w- x:\windows\syswow64\CmdLineExt_x64.dll 2010-01-12 05:19:06 1524 ----a-w- x:\windows\syswow64\ealregsnapshot1.reg 2010-01-09 19:38:50 64352 ----a-w- x:\program files (x86)\Удалить s0beit.exe 2010-01-09 19:38:50 2397 ----a-w- x:\program files (x86)\Uninstall.ini 2010-01-08 21:43:10 0 ---ha-w- x:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf 2010-01-08 03:38:28 157696 ----a-w- x:\windows\system32\drivers\mrxsmb.sys 2010-01-06 23:36:45 0 ---ha-w- x:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-01-06 15:34:57 834544 ----a-w- x:\windows\system32\drivers\sptd.sys 2010-01-06 15:02:01 36156 ----a-w- x:\windows\system32\perfd014.dat 2010-01-06 15:02:01 36156 ----a-w- x:\windows\inf\perflib\0414\perfd.dat 2010-01-06 15:02:01 36156 ----a-w- x:\windows\inf\perflib\0414\perfc.dat 2010-01-06 15:02:01 298300 ----a-w- x:\windows\system32\perfi014.dat 2010-01-06 15:02:01 298300 ----a-w- x:\windows\inf\perflib\0414\perfi.dat 2010-01-06 15:02:01 298300 ----a-w- x:\windows\inf\perflib\0414\perfh.dat 2009-12-19 09:50:56 14848 ----a-w- x:\windows\system32\tsbyuv.dll 2009-12-19 09:49:47 1572352 ----a-w- x:\windows\system32\quartz.dll 2009-12-19 09:47:56 25088 ----a-w- x:\windows\system32\msyuv.dll 2009-12-19 09:47:53 38912 ----a-w- x:\windows\system32\msvidc32.dll 2009-12-19 09:47:46 16384 ----a-w- x:\windows\system32\msrle32.dll 2009-12-19 09:46:35 54272 ----a-w- x:\windows\system32\iyuv_32.dll 2009-12-19 09:02:52 12288 ----a-w- x:\windows\syswow64\tsbyuv.dll 2009-12-19 09:02:48 1328640 ----a-w- x:\windows\syswow64\quartz.dll 2009-12-19 09:02:46 22016 ----a-w- x:\windows\syswow64\msyuv.dll 2009-12-19 09:02:45 31744 ----a-w- x:\windows\syswow64\msvidc32.dll 2009-12-19 09:02:45 13312 ----a-w- x:\windows\syswow64\msrle32.dll 2009-12-19 09:02:40 84480 ----a-w- x:\windows\syswow64\mciavi32.dll 2009-12-19 09:02:39 50176 ----a-w- x:\windows\syswow64\iyuv_32.dll 2009-12-19 09:02:01 91648 ----a-w- x:\windows\syswow64\avifil32.dll 2009-12-17 14:27:28 454 ----a-w- x:\program files (x86)\m0d_s0beit_sa_setup.log 2009-12-17 14:24:16 73480 ----a-w- x:\program files (x86)\speedo.png 2009-12-17 14:21:28 40076 ----a-w- x:\program files (x86)\m0d_s0beit_sa.ini 2009-12-15 23:36:16 324096 ----a-w- x:\program files (x86)\d3d9.dll 2009-12-11 20:35:34 400384 ----a-w- x:\windows\syswow64\aticfx32.dll 2009-12-11 20:34:46 434176 ----a-w- x:\windows\system32\aticfx64.dll 2009-12-11 20:11:30 55296 ----a-w- x:\windows\system32\coinst.dll 2009-12-11 19:51:26 14848 ----a-w- x:\windows\system32\atig6pxx.dll 2009-12-11 19:51:22 12800 ----a-w- x:\windows\syswow64\atiglpxx.dll 2009-12-11 19:51:22 12800 ----a-w- x:\windows\system32\atiglpxx.dll 2009-12-11 19:51:18 16896 ----a-w- x:\windows\system32\atig6txx.dll 2009-12-11 19:51:12 15360 ----a-w- x:\windows\syswow64\atigktxx.dll 2009-12-11 19:50:34 35840 ----a-w- x:\windows\system32\atiuxp64.dll 2009-12-11 19:50:28 27136 ----a-w- x:\windows\syswow64\atiuxpag.dll 2009-12-11 19:50:20 28160 ----a-w- x:\windows\system32\atiu9p64.dll 2009-12-11 19:50:12 20480 ----a-w- x:\windows\syswow64\atiu9pag.dll 2009-12-01 13:02:24 138240 ----a-w- x:\windows\system32\ftusbsrv.dll 2009-12-01 13:02:12 156672 ----a-w- x:\windows\system32\ftusbcln.dll 2009-12-01 13:00:54 1282048 ----a-w- x:\windows\system32\ftusbsrvc.exe 2009-12-01 12:59:50 1384448 ----a-w- x:\windows\system32\ftusbsrv.exe 2009-12-01 12:58:40 41976 ----a-w- x:\windows\system32\ftusbbus.sys 2009-11-30 17:02:40 171144 ----a-w- x:\windows\syswow64\xliveinstall.dll 2009-11-30 17:02:38 72840 ----a-w- x:\windows\syswow64\xliveinstallhost.exe 2009-11-25 03:18:02 446464 ----a-w- x:\windows\system32\ATIDEMGX.dll 2009-11-25 03:17:52 446976 ----a-w- x:\windows\system32\atieclxx.exe 2009-11-25 03:17:16 202752 ----a-w- x:\windows\system32\atiesrxx.exe 2009-11-25 03:15:54 120320 ----a-w- x:\windows\system32\atitmm64.dll 2009-11-25 03:15:36 421376 ----a-w- x:\windows\system32\atipdl64.dll 2009-11-25 03:15:28 356352 ----a-w- x:\windows\syswow64\atipdlxx.dll 2009-11-25 03:15:14 274432 ----a-w- x:\windows\syswow64\Oemdspif.dll 2009-11-25 03:15:06 12288 ----a-w- x:\windows\system32\atimuixx.dll 2009-11-25 03:15:02 59392 ----a-w- x:\windows\system32\atiedu64.dll 2009-11-25 03:14:58 43520 ----a-w- x:\windows\syswow64\ati2edxx.dll 2009-11-25 03:12:12 3055616 ----a-w- x:\windows\syswow64\atidxx32.dll 2009-11-25 03:04:30 3661824 ----a-w- x:\windows\system32\atidxx64.dll 2009-11-25 03:02:20 17625088 ----a-w- x:\windows\system32\atio6axx.dll 2009-11-25 02:55:58 3617792 ----a-w- x:\windows\syswow64\atiumdag.dll 2009-11-25 02:50:14 4683776 ----a-w- x:\windows\system32\atiumd64.dll 2009-11-25 02:44:56 13487616 ----a-w- x:\windows\syswow64\atioglxx.dll 2009-11-25 02:43:54 2601984 ----a-w- x:\windows\system32\atiumd6a.dll 2009-11-25 02:37:58 2899968 ----a-w- x:\windows\syswow64\atiumdva.dll 2009-11-25 02:25:46 53248 ----a-w- x:\windows\system32\atimpc64.dll 2009-06-10 20:44:08 9633792 --sha-r- x:\windows\fonts\StaticCache.dat 2009-07-14 01:39:53 398848 --sha-w- x:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe 2009-07-14 01:14:45 396800 --sha-w- x:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 15:26:31,07 ===============