DDS (Ver_10-12-12.02) - NTFS_AMD64 Run by Admin at 20:05:44,37 on 19.02.2011 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.47.1044.18.3956.2205 [GMT 1:00] AV: AVG Internet Security 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Internet Security 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B} ============== Running Processes =============== C:\PROGRA~2\AVG\AVG10\avgchsva.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe C:\Program Files (x86)\AVG\AVG10\avgfws.exe C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe C:\Program Files (x86)\AVG\AVG10\avgam.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe C:\Program Files (x86)\AVG\AVG10\avgnsa.exe C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe C:\Program Files (x86)\AVG\AVG10\avgemca.exe C:\Windows\system32\conhost.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files (x86)\Windows Sidebar\sidebar.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe C:\Program Files (x86)\Launch Manager\LManager.exe C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Windows\system32\conhost.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\DllHost.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\msiexec.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Program Files (x86)\AVG\AVG10\avgui.exe C:\Program Files (x86)\AVG\AVG10\avgrsa.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Users\Admin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\taskeng.exe C:\Program Files\WinRAR.exe C:\Users\Admin\AppData\Local\Temp\Rar$EX00.522\RootkitBuster.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Admin\Downloads\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0414&m=easynote_tj75&r=2736081029b6l0470z1k5f4591y32r uDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0414&m=easynote_tj75&r=2736081029b6l0470z1k5f4591y32r mDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0414&m=easynote_tj75&r=2736081029b6l0470z1k5f4591y32r mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0414&m=easynote_tj75&r=2736081029b6l0470z1k5f4591y32r BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO: Påloggingshjelp for Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [Camera Assistant Software] "C:\Program Files (x86)\Video Web Camera\traybar.exe" mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe mRun: [RemoteControl8] "c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" mRun: [PDVD8LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} - hxxp://dl.pplive.com/PluginSetup.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} {9030D464-4C02-4ABF-8ECC-5164760863C6} {AA58ED58-01DD-4d91-8333-CF10577473F7} {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} {DBC80044-A445-435b-BC74-9C25C1C588A9} {2318C2B1-4965-11d4-9B18-009027A5CD4F} mRun-x64: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe mRun-x64: [PLFSetI] C:\Windows\PLFSetI.exe mRun-x64: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe mRun-x64: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon ================= FIREFOX =================== FF - ProfilePath - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\okgsxtim.default\ FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll FF - component: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\okgsxtim.default\extensions\firesheep@codebutler.com\platform\WINNT_x86-msvc\components\mozpopen.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Admin\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox FF - Ext: Firesheep: firesheep@codebutler.com - %profile%\extensions\firesheep@codebutler.com ============= SERVICES / DRIVERS =============== R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288] R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-8-30 55024] R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2010-7-12 57696] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-12-8 308304] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040] R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-11-12 382032] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904] R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-8 169312] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-3-11 202752] R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG10\avgfws.exe [2010-11-22 3226632] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400] R2 ePowerSvc;Acer ePower Service;C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [2010-3-11 844320] R2 Greg_Service;GRegService;C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe [2009-8-28 1150496] R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2009-9-25 62720] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648] R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2009-11-2 13784] R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-3-11 2320920] R2 Updater Service;Updater Service;C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-11-5 240160] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-19 157264] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920] R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-3-11 56344] R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-3-11 151936] R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2009-8-6 320040] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-11-29 11856] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-14 17920] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Googles oppdateringstjeneste (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-9-6 135664] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864] S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864] S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-8-30 1255736] =============== Created Last 30 ================ 2011-02-19 18:55:45 388096 ----a-r- C:\Users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-02-19 18:55:45 -------- d-----w- C:\Program Files (x86)\Trend Micro 2011-02-14 22:46:13 521448 ----a-w- C:\Windows\System32\deployJava1.dll 2011-02-14 19:44:30 -------- d-----w- C:\Users\Admin\AppData\Local\Mozilla 2011-02-14 19:42:57 -------- d-----w- C:\Program Files (x86)\WinPcap 2011-02-11 17:01:35 -------- d-----w- C:\Users\Admin\fontconfig 2011-02-11 17:00:33 -------- d-----w- C:\Program Files (x86)\PS3 Media Server 2011-02-10 10:37:59 5510528 ----a-w- C:\Windows\System32\ntoskrnl.exe 2011-02-10 10:37:59 3957120 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-02-10 10:37:59 3901824 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-02-10 10:37:59 1739176 ----a-w- C:\Windows\System32\ntdll.dll 2011-02-10 10:37:59 1293120 ----a-w- C:\Windows\SysWow64\ntdll.dll 2011-02-10 10:37:57 46080 ----a-w- C:\Windows\System32\atmlib.dll 2011-02-10 10:37:57 366080 ----a-w- C:\Windows\System32\atmfd.dll 2011-02-10 10:37:57 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll 2011-02-10 10:37:57 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll 2011-01-30 13:57:00 103864 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll 2011-01-30 11:49:19 -------- d-----w- C:\Program Files (x86)\Common Files\PPLiveNetwork 2011-01-29 22:33:13 -------- d-----w- C:\Users\Admin\AppData\Local\LogiShrd 2011-01-21 23:45:49 53248 ----a-r- C:\Users\Admin\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2011-01-21 23:45:29 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys 2011-01-21 23:42:48 -------- d-----w- C:\Users\Admin\AppData\Roaming\Logishrd ==================== Find3M ==================== 2011-01-26 06:53:10 982912 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2011-01-26 06:53:10 265088 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys 2011-01-26 06:31:20 144384 ----a-w- C:\Windows\System32\cdd.dll 2011-01-05 06:20:30 612352 ----a-w- C:\Windows\System32\vbscript.dll 2011-01-05 05:37:33 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll 2011-01-05 04:00:16 3127808 ----a-w- C:\Windows\System32\win32k.sys 2010-12-21 06:16:27 97280 ----a-w- C:\Windows\System32\wscsvc.dll 2010-12-21 06:16:27 62976 ----a-w- C:\Windows\System32\wscapi.dll 2010-12-21 06:16:16 214016 ----a-w- C:\Windows\System32\winsrv.dll 2010-12-21 06:16:14 442880 ----a-w- C:\Windows\System32\winhttp.dll 2010-12-21 06:16:14 1197056 ----a-w- C:\Windows\System32\wininet.dll 2010-12-21 06:16:09 258048 ----a-w- C:\Windows\System32\WebClnt.dll 2010-12-21 06:15:55 264192 ----a-w- C:\Windows\System32\upnp.dll 2010-12-21 06:15:31 15360 ----a-w- C:\Windows\System32\slwga.dll 2010-12-21 06:13:03 2003968 ----a-w- C:\Windows\System32\msxml6.dll 2010-12-21 06:13:03 1880576 ----a-w- C:\Windows\System32\msxml3.dll 2010-12-21 06:10:22 100864 ----a-w- C:\Windows\System32\davclnt.dll 2010-12-21 05:38:24 51200 ----a-w- C:\Windows\SysWow64\wscapi.dll 2010-12-21 05:38:22 981504 ----a-w- C:\Windows\SysWow64\wininet.dll 2010-12-21 05:38:22 350720 ----a-w- C:\Windows\SysWow64\winhttp.dll 2010-12-21 05:38:21 204800 ----a-w- C:\Windows\SysWow64\WebClnt.dll 2010-12-21 05:38:19 204288 ----a-w- C:\Windows\SysWow64\upnp.dll 2010-12-21 05:38:16 14336 ----a-w- C:\Windows\SysWow64\slwga.dll 2010-12-21 05:36:17 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll 2010-12-21 05:36:16 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll 2010-12-21 05:34:12 80384 ----a-w- C:\Windows\SysWow64\davclnt.dll 2010-12-18 06:11:41 57856 ----a-w- C:\Windows\System32\licmgr10.dll 2010-12-18 06:11:34 714752 ----a-w- C:\Windows\System32\kerberos.dll 2010-12-18 05:29:40 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll 2010-12-18 05:29:31 541184 ----a-w- C:\Windows\SysWow64\kerberos.dll 2010-12-18 04:55:03 482816 ----a-w- C:\Windows\System32\html.iec 2010-12-18 04:20:55 386048 ----a-w- C:\Windows\SysWow64\html.iec 2010-12-18 04:13:40 1638912 ----a-w- C:\Windows\System32\mshtml.tlb 2010-12-18 03:47:59 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2010-12-14 13:43:40 34624 ----a-w- C:\Windows\System32\TURegOpt.exe 2010-12-14 13:39:18 25920 ----a-w- C:\Windows\System32\authuitu.dll 2010-12-14 13:39:16 21312 ----a-w- C:\Windows\SysWow64\authuitu.dll 2010-12-14 13:39:14 36160 ----a-w- C:\Windows\System32\uxtuneup.dll 2010-12-14 13:39:10 29504 ----a-w- C:\Windows\SysWow64\uxtuneup.dll 2010-12-08 03:12:36 308304 ----a-w- C:\Windows\System32\drivers\avgldx64.sys 2010-03-15 09:28:32 130560 ----a-w- C:\Program Files\Uninstall.exe 2010-03-15 09:28:22 166400 ----a-w- C:\Program Files\RarExt.dll 2010-03-15 09:28:22 141824 ----a-w- C:\Program Files\RarExt32.dll 2010-03-15 09:28:03 74240 ----a-w- C:\Program Files\Zip.SFX 2010-03-15 09:28:02 92672 ----a-w- C:\Program Files\Default.SFX 2010-03-15 09:28:02 91136 ----a-w- C:\Program Files\Zip64.SFX 2010-03-15 09:27:54 120320 ----a-w- C:\Program Files\Default64.SFX 2010-03-15 09:27:00 69632 ----a-w- C:\Program Files\WinCon.SFX 2010-03-15 09:26:59 90112 ----a-w- C:\Program Files\WinCon64.SFX 2010-03-15 09:26:52 262656 ----a-w- C:\Program Files\UnRAR.exe 2010-03-15 09:26:46 398336 ----a-w- C:\Program Files\Rar.exe 2010-03-15 09:26:36 1090560 ----a-w- C:\Program Files\WinRAR.exe ============= FINISH: 20:06:32,12 ===============