Hello,
I get a virus alert on Avira AntiVirus when I scan my windows temp file with Sunbelt Counterspy and only when I scan with Counterspy. No other program picks it up. Everytime, it comes up I hit remove, but when I check the events folder it says Allow Access. I have delete this many times always reappearing. Here is the message from Avira.
Virus or unwanted program 'TR/Crypt.XPACK.Gen [trojan]'
detected in file 'C:\WINDOWS\Temp\SBS_VE_AMBR_20110014053417.625_ 921.
Action performed: Allow access
I also have been experiencing BSOD when I am online gaming and doing P2P bittorrenting. I have no idea if this is related. Also I am unable to do a full scan with GMER but able to do the scan with C drive checked and sections checked. Also have access to window install disc. Any help is appreciated.
DDS (Ver_10-12-12.02) - NTFSx86
Run by Dan at 9:53:01.21 on Fri 01/14/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.920 [GMT -6:00]
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Pro Firewall *Enabled*
============== Running Processes ===============
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\PROGRA~1\Enigma Software Group\SpyHunter\SH4Service.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Dan\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [CTHelper] "CTHELPER.EXE"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [nwiz] "c:\program files\nvidia corporation\nview\nwiz.exe" /installquiet
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\windows search.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://go.microsoft.com/fwlink/?LinkId=82580
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1284142087625
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.3.16.0.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\dan\applic~1\mozilla\firefox\profiles\vb2c74un.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\documents and settings\dan\application data\mozilla\firefox\profiles\vb2c74un.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
FF - component: c:\documents and settings\dan\application data\mozilla\firefox\profiles\vb2c74un.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - component: c:\documents and settings\dan\application data\mozilla\firefox\profiles\vb2c74un.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\documents and settings\dan\application data\mozilla\firefox\profiles\vb2c74un.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\dan\application data\mozilla\firefox\profiles\vb2c74un.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\dan\application data\mozilla\firefox\profiles\vb2c74un.default\extensions\battlefieldheroespatcher@ea.com\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Battlefield Heroes Updater:
battlefieldheroespatcher@ea.com - %profile%\extensions\battlefieldheroespatcher@ea.com
FF - Ext: Adobe DLM (powered by getPlus(R)): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-10-13 237632]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2010-10-13 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2010-10-13 656320]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-12-6 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-12-6 68880]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-1-7 11608]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2010-10-13 247824]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2010-10-12 21464]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-5-13 98392]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2010-10-8 528128]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-1-7 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-1-7 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-1-7 61960]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-11-13 20328]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2010-10-12 69976]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\enigma software group\spyhunter\SH4Service.exe [2010-11-5 327000]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]
R3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link DGE-5xx Gigabit Ethernet Adapter;c:\windows\system32\drivers\m4cxw2k3.sys [2010-11-16 298752]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2010-10-9 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxLiveShare10.exe [2007-8-24 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe [2007-8-24 166384]
S2 SBAMSvc;CounterSpy Antispyware;c:\program files\sunbelt software\counterspy\SBAMSvc.exe [2010-8-20 2763080]
S2 SBPIMSvc;SB Recovery Service;c:\program files\sunbelt software\counterspy\SBPIMSvc.exe [2010-8-20 181584]
S2 SessionLauncher;SessionLauncher;c:\docume~1\dan\locals~1\temp\dx9\sessionlauncher.exe --> c:\docume~1\dan\locals~1\temp\dx9\SessionLauncher.exe [?]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-10-10 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]
S3 esgiguard;esgiguard;c:\program files\enigma software group\spyhunter\esgiguard.sys [2010-1-27 5248]
S3 jswmidin;jswmidin;\??\c:\docume~1\dan\locals~1\temp\jswmidin.sys --> c:\docume~1\dan\locals~1\temp\jswmidin.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\3.tmp --> c:\windows\system32\3.tmp [?]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2003-3-31 14336]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2011-1-4 19056]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2010-10-13 70536]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2010-10-9 72176]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2007-8-24 1083888]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2010-10-13 366840]
S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2010-10-13 1145816]
S3 SkLaggProtocol;Marvell Link Aggregation Protocol;c:\windows\system32\drivers\yk51x86l.sys [2009-9-22 60928]
S3 SkVlanProtocol;Marvell VLAN Protocol;c:\windows\system32\drivers\yk51x86v.sys [2009-8-27 20992]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-12-6 33552]
S3 ThreatFire;ThreatFire;c:\program files\pc tools security\tfengine\tfservice.exe service --> c:\program files\pc tools security\tfengine\TFService.exe service [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2003-3-31 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-01-14 15:43:25 -------- d-----w- C:\SMCLpav
2011-01-14 01:03:26 -------- dc-h--w- c:\docume~1\alluse~1\applic~1\{346564C3-1CD0-440B-AE7A-F644B66D2026}
2011-01-14 01:01:12 -------- d-----w- c:\docume~1\alluse~1\applic~1\Webroot
2011-01-14 01:01:07 -------- d-----w- c:\docume~1\dan\locals~1\applic~1\PackageAware
2011-01-13 23:38:39 110080 ----a-r- c:\docume~1\dan\applic~1\microsoft\installer\{41ebc322-660f-4d16-a0df-53147210cbdb}\IconF7A21AF7.exe
2011-01-13 23:38:39 110080 ----a-r- c:\docume~1\dan\applic~1\microsoft\installer\{41ebc322-660f-4d16-a0df-53147210cbdb}\IconD7F16134.exe
2011-01-13 23:38:33 -------- d-----w- C:\sh4ldr
2011-01-13 23:38:33 -------- d-----w- c:\program files\Enigma Software Group
2011-01-13 23:38:14 -------- d-----w- c:\windows\41EBC322660F4D16A0DF53147210CBDB.TMP
2011-01-13 23:38:09 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2011-01-13 22:27:56 -------- d-----w- c:\docume~1\dan\applic~1\Malwarebytes
2011-01-13 22:27:48 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-13 22:27:47 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-01-13 22:27:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-13 22:27:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-13 11:31:01 -------- d-----w- c:\docume~1\alluse~1\applic~1\CA
2011-01-12 22:37:55 -------- d-----w- c:\program files\ESET
2011-01-12 22:19:45 -------- d-----w- c:\docume~1\alluse~1\applic~1\F-Secure
2011-01-12 21:58:31 -------- d-----w- c:\docume~1\dan\applic~1\QuickScan
2011-01-12 21:46:01 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-01-12 11:23:16 -------- d-----w- c:\docume~1\dan\applic~1\Panda Security
2011-01-12 10:56:06 -------- d-----w- c:\docume~1\alluse~1\applic~1\Panda Security
2011-01-11 22:11:16 -------- d-----w- c:\program files\Panda Security
2011-01-11 11:13:45 -------- d-sh--w- C:\found.000
2011-01-08 12:59:12 -------- d-----w- c:\docume~1\dan\locals~1\applic~1\PCHealth
2011-01-07 19:44:40 -------- d-----w- c:\docume~1\dan\applic~1\Avira
2011-01-07 19:22:18 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-01-07 19:22:17 -------- d-----w- c:\program files\Avira
2011-01-07 19:22:17 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2011-01-07 13:13:45 -------- d-----w- c:\windows\system32\winrm
2011-01-07 13:13:39 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2011-01-07 13:13:16 -------- d-----w- c:\docume~1\dan\applic~1\Windows Desktop Search
2011-01-03 17:41:49 -------- d-----w- c:\docume~1\dan\applic~1\ZoomBrowser EX
2011-01-03 11:46:37 -------- d-----w- c:\docume~1\dan\applic~1\CameraWindowDC
2011-01-03 11:46:36 -------- d-----w- c:\docume~1\dan\applic~1\CANON INC
2011-01-03 11:35:35 -------- d-----w- c:\docume~1\alluse~1\applic~1\ZoomBrowser
2011-01-03 11:34:32 -------- d-----w- c:\program files\common files\Canon
2011-01-03 11:30:41 5632 ----a-w- c:\windows\system32\ptpusb.dll
2011-01-03 11:30:40 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-12-31 18:19:55 240592 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-12-31 18:19:51 240592 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-12-31 18:19:51 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-12-31 18:19:41 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-12-31 18:19:41 4882432 ----a-w- c:\windows\system32\nvcuda.dll
2010-12-31 18:19:41 2932840 ----a-w- c:\windows\system32\nvcuvid.dll
2010-12-31 18:19:41 2666600 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-12-31 18:19:41 2293194 ----a-w- c:\windows\system32\nvdata.bin
2010-12-31 18:19:41 14532608 ----a-w- c:\windows\system32\nvoglnt.dll
2010-12-31 18:19:40 1462272 ----a-w- c:\windows\system32\nvapi.dll
2010-12-31 18:19:40 13012992 ----a-w- c:\windows\system32\nvcompiler.dll
2010-12-31 16:34:24 888424 ----a-w- c:\windows\system32\nvdispco32.dll
2010-12-31 16:33:45 -------- d-----w- C:\NVIDIA
2010-12-31 16:02:18 -------- d-----w- c:\program files\Phyxion.net
2010-12-31 15:55:23 813672 ----a-w- c:\windows\system32\nvgenco32.dll
2010-12-31 15:37:39 -------- d-----w- c:\program files\NVIDIA Corporation
2010-12-30 16:37:42 -------- d-----w- c:\program files\common files\COWON
2010-12-30 16:37:40 -------- d-----w- c:\program files\JetAudio
2010-12-30 15:55:24 -------- d-----w- c:\program files\Broderbund
2010-12-30 15:47:57 -------- d-----w- C:\ROMEO_AND_JULIET
2010-12-30 02:40:23 -------- d-----w- c:\program files\Reality Pump
2010-12-29 22:59:40 -------- d-----w- c:\docume~1\dan\applic~1\Windows Search
2010-12-29 22:46:07 -------- d-----w- c:\windows\system32\XPSViewer
2010-12-29 22:45:35 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-12-29 22:45:15 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-12-29 22:45:15 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-12-29 22:45:15 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-12-29 22:45:15 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-12-29 22:45:15 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-12-29 22:45:15 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-12-29 22:45:15 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-12-29 22:45:15 117760 ------w- c:\windows\system32\prntvpt.dll
2010-12-29 22:45:15 -------- d-----w- C:\a0467d73ef5f36dc8b
2010-12-29 22:41:26 -------- d-----w- c:\program files\Windows Desktop Search
2010-12-29 22:41:25 -------- d-----w- c:\windows\system32\GroupPolicy
2010-12-29 22:40:45 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-12-29 02:52:33 -------- d-----w- c:\program files\common files\Symantec Shared
2010-12-29 02:52:26 -------- d-----w- c:\docume~1\alluse~1\applic~1\Norton
2010-12-29 02:52:24 -------- d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-12-28 12:43:51 -------- d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2010-12-18 13:35:27 -------- d-----w- c:\program files\Sophos
2010-12-16 20:48:50 -------- d-----w- c:\docume~1\dan\applic~1\Reviversoft
2010-12-16 20:48:32 -------- d-----w- c:\program files\Reviversoft
==================== Find3M ====================
2011-01-09 13:19:00 234536 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-01-09 13:19:00 234536 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-12-14 23:22:45 0 ----a-w- c:\windows\nsd6.tmp
2010-12-14 11:19:15 0 ----a-w- c:\windows\nsy20.tmp
2010-12-14 11:18:37 0 ----a-w- c:\windows\nsu1C.tmp
2010-12-14 11:18:24 0 ----a-w- c:\windows\nsv18.tmp
2010-12-14 11:17:37 0 ----a-w- c:\windows\nsy14.tmp
2010-12-14 11:17:28 0 ----a-w- c:\windows\nst10.tmp
2010-12-11 14:54:39 90112 ----a-w- c:\windows\DUMP5da0.tmp
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-14 14:28:31 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-14 14:28:31 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-13 19:15:25 22 --sha-w- c:\windows\Sys3390 SettingsCollection.bin
2010-11-13 19:15:25 22 --sha-w- c:\docume~1\dan\applic~1\Sys6925.Config Collection.sys
2010-11-09 14:52:35 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26:58 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 ----a-w- c:\windows\system32\html.iec
2010-10-28 13:13:22 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-10-19 21:03:03 138056 ----a-w- c:\docume~1\dan\applic~1\PnkBstrK.sys
2010-10-19 21:02:37 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-10-19 21:02:37 2427248 ----a-w- c:\windows\system32\pbsvc_heroes.exe
2010-10-16 18:55:00 6359552 ----a-w- c:\windows\system32\nv4_disp.dll
2010-10-16 18:04:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-10-16 18:04:16 277608 ----a-w- c:\windows\system32\nvmccs.dll
2010-10-16 18:04:16 13851752 ----a-w- c:\windows\system32\nvcpl.dll
2010-10-16 18:04:16 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-10-16 18:04:14 156776 ----a-w- c:\windows\system32\nvsvc32.exe
2010-10-16 18:04:14 145000 ----a-w- c:\windows\system32\nvcolor.exe
============= FINISH: 9:55:27.64 ===============