DDS (Ver_09-03-16.01) - NTFSx86
Run by Arthur at 11:54:49.41 on Sat 05/09/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.367.116 [GMT -4:00]
AV: Norton Internet Security *On-access scanning enabled* (Outdated)
AV: AntiVir Desktop *On-access scanning enabled* (Updated)
FW: Norton Internet Security *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Arthur.VANDELAY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Arthur.VANDELAY\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/ig?hl=en
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.0\UIBHO.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Google Update] "c:\documents and settings\arthur.vandelay\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
uPolicies-explorer: NoSimpleStartMenu = 0 (0x0)
uPolicies-explorer: NoThemesTab = 0 (0x0)
uPolicies-explorer: NoWindowsUpdate = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-explorer: NoFolderOptions = 1 (0x1)
dPolicies-system: DisableRegistryTools = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227222424972
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\arthur~1.van\applic~1\mozilla\firefox\profiles\0mjyd55f.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\arthur.vandelay\application data\mozilla\firefox\profiles\0mjyd55f.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\arthur.vandelay\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-8 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-8 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-8 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-8 55640]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2006-9-26 66048]
S2 gupdate1c9cf6055108bf0;Google Update Service (gupdate1c9cf6055108bf0);c:\program files\google\update\GoogleUpdate.exe [2009-5-7 133104]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys --> c:\windows\system32\drivers\wg111v2.sys [?]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2008-11-20 13532]
=============== Created Last 30 ================
2009-05-09 10:10 --d----- c:\program files\Avenger
2009-05-08 19:24 55,640 a------- c:\windows\system32\drivers\avgntflt.sys
2009-05-08 19:24 --d----- c:\docume~1\alluse~1.win\applic~1\Avira
2009-05-08 19:22 --d----- c:\program files\Avira
2009-05-08 18:36 --d----- c:\program files\Trend Micro
2009-05-07 11:28 202 a------- C:\43214354.bat
2009-05-02 18:45 --d----- c:\docume~1\arthur~1.van\applic~1\Blitware
2009-05-01 19:22 a-dshr-- C:\cmdcons
2009-05-01 19:19 161,792 a------- c:\windows\SWREG.exe
2009-05-01 19:19 98,816 a------- c:\windows\sed.exe
2009-05-01 13:36 --d----- c:\docume~1\arthur~1.van\applic~1\Malwarebytes
2009-05-01 13:36 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-05-01 13:36 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-01 13:35 --d----- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2009-05-01 13:35 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-05-01 01:25 65,954 a------- c:\windows\Prairie Wind.bmp
2009-05-01 01:25 65,832 a------- c:\windows\Santa Fe Stucco.bmp
2009-05-01 01:25 26,680 a------- c:\windows\River Sumida.bmp
2009-05-01 01:25 26,582 a------- c:\windows\Greenstone.bmp
2009-05-01 01:25 17,362 a------- c:\windows\Rhododendron.bmp
2009-05-01 01:25 17,336 a------- c:\windows\Gone Fishing.bmp
2009-05-01 01:25 17,062 a------- c:\windows\Coffee Bean.bmp
2009-05-01 01:25 16,730 a------- c:\windows\FeatherTexture.bmp
2009-05-01 01:25 9,522 a------- c:\windows\Zapotec.bmp
2009-05-01 01:25 65,978 a------- c:\windows\Soap Bubbles.bmp
2009-05-01 01:25 1,272 a------- c:\windows\Blue Lace 16.bmp
2009-05-01 00:09 10,520 a------- c:\windows\system32\avgrsstx.dll.old
2009-05-01 00:07 --d----- c:\program files\AVG
2009-04-30 23:34 --d----- c:\program files\XP Security Console
2009-04-30 22:42 --d----- c:\docume~1\alluse~1.win\applic~1\SecTaskMan
2009-04-30 13:34 16 a------- c:\windows\system32\coh.cache
2009-04-30 13:29 10,635 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-04-30 13:29 806 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-04-30 13:04 --d----- c:\program files\Norton Internet Security
2009-04-30 11:46 5,369 ---sh--- c:\windows\system32\rutobuki.exe
2009-04-30 11:45 5,369 ---sh--- c:\windows\system32\buhiwuna.dll
2009-04-16 23:44 284,160 -c------ c:\windows\system32\dllcache\pdh.dll
2009-04-16 23:43 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-04-16 23:43 110,592 -c------ c:\windows\system32\dllcache\services.exe
2009-04-16 23:43 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-04-16 23:43 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 23:43 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 23:43 729,088 -c------ c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 23:43 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-04-16 23:43 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-04-16 23:42 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-16 23:42 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 23:42 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
==================== Find3M ====================
2009-04-30 14:12 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-30 14:12 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2009-04-29 10:26 2,068 a------- c:\windows\system32\d3d9caps.dat
2009-03-06 10:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-02 20:18 826,368 a------- c:\windows\system32\wininet.dll
2009-02-20 14:09 78,336 a------- c:\windows\system32\ieencode.dll
2009-02-09 08:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 08:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 08:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 08:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 07:13 1,846,784 a------- c:\windows\system32\win32k.sys
2006-02-16 00:08 243 ---sh--- c:\program files\desktop.ini
2002-09-11 10:26 63,730 a------- c:\program files\viewsonicinstruct_xp.pdf
2001-05-20 21:10 23,357 ac--h--- c:\program files\folder.htt
============= FINISH: 11:55:51.75 ===============
Run by Arthur at 11:54:49.41 on Sat 05/09/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.367.116 [GMT -4:00]
AV: Norton Internet Security *On-access scanning enabled* (Outdated)
AV: AntiVir Desktop *On-access scanning enabled* (Updated)
FW: Norton Internet Security *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Arthur.VANDELAY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Arthur.VANDELAY\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/ig?hl=en
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.0\UIBHO.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Google Update] "c:\documents and settings\arthur.vandelay\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
uPolicies-explorer: NoSimpleStartMenu = 0 (0x0)
uPolicies-explorer: NoThemesTab = 0 (0x0)
uPolicies-explorer: NoWindowsUpdate = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-explorer: NoFolderOptions = 1 (0x1)
dPolicies-system: DisableRegistryTools = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227222424972
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\arthur~1.van\applic~1\mozilla\firefox\profiles\0mjyd55f.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\arthur.vandelay\application data\mozilla\firefox\profiles\0mjyd55f.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\arthur.vandelay\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-8 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-8 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-8 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-8 55640]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2006-9-26 66048]
S2 gupdate1c9cf6055108bf0;Google Update Service (gupdate1c9cf6055108bf0);c:\program files\google\update\GoogleUpdate.exe [2009-5-7 133104]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys --> c:\windows\system32\drivers\wg111v2.sys [?]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2008-11-20 13532]
=============== Created Last 30 ================
2009-05-09 10:10
2009-05-08 19:24 55,640 a------- c:\windows\system32\drivers\avgntflt.sys
2009-05-08 19:24
2009-05-08 19:22
2009-05-08 18:36
2009-05-07 11:28 202 a------- C:\43214354.bat
2009-05-02 18:45
2009-05-01 19:22
2009-05-01 19:19 161,792 a------- c:\windows\SWREG.exe
2009-05-01 19:19 98,816 a------- c:\windows\sed.exe
2009-05-01 13:36
2009-05-01 13:36 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-05-01 13:36 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-01 13:35
2009-05-01 13:35
2009-05-01 01:25 65,954 a------- c:\windows\Prairie Wind.bmp
2009-05-01 01:25 65,832 a------- c:\windows\Santa Fe Stucco.bmp
2009-05-01 01:25 26,680 a------- c:\windows\River Sumida.bmp
2009-05-01 01:25 26,582 a------- c:\windows\Greenstone.bmp
2009-05-01 01:25 17,362 a------- c:\windows\Rhododendron.bmp
2009-05-01 01:25 17,336 a------- c:\windows\Gone Fishing.bmp
2009-05-01 01:25 17,062 a------- c:\windows\Coffee Bean.bmp
2009-05-01 01:25 16,730 a------- c:\windows\FeatherTexture.bmp
2009-05-01 01:25 9,522 a------- c:\windows\Zapotec.bmp
2009-05-01 01:25 65,978 a------- c:\windows\Soap Bubbles.bmp
2009-05-01 01:25 1,272 a------- c:\windows\Blue Lace 16.bmp
2009-05-01 00:09 10,520 a------- c:\windows\system32\avgrsstx.dll.old
2009-05-01 00:07
2009-04-30 23:34
2009-04-30 22:42
2009-04-30 13:34 16 a------- c:\windows\system32\coh.cache
2009-04-30 13:29 10,635 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-04-30 13:29 806 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-04-30 13:04
2009-04-30 11:46 5,369 ---sh--- c:\windows\system32\rutobuki.exe
2009-04-30 11:45 5,369 ---sh--- c:\windows\system32\buhiwuna.dll
2009-04-16 23:44 284,160 -c------ c:\windows\system32\dllcache\pdh.dll
2009-04-16 23:43 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-04-16 23:43 110,592 -c------ c:\windows\system32\dllcache\services.exe
2009-04-16 23:43 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-04-16 23:43 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 23:43 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 23:43 729,088 -c------ c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 23:43 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-04-16 23:43 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-04-16 23:42 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-16 23:42 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 23:42 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
==================== Find3M ====================
2009-04-30 14:12 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-30 14:12 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2009-04-29 10:26 2,068 a------- c:\windows\system32\d3d9caps.dat
2009-03-06 10:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-02 20:18 826,368 a------- c:\windows\system32\wininet.dll
2009-02-20 14:09 78,336 a------- c:\windows\system32\ieencode.dll
2009-02-09 08:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 08:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 08:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 08:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 07:13 1,846,784 a------- c:\windows\system32\win32k.sys
2006-02-16 00:08 243 ---sh--- c:\program files\desktop.ini
2002-09-11 10:26 63,730 a------- c:\program files\viewsonicinstruct_xp.pdf
2001-05-20 21:10 23,357 ac--h--- c:\program files\folder.htt
============= FINISH: 11:55:51.75 ===============