.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Sandra at 0:01:58,57 on di 17-05-2011
Internet Explorer: 8.0.7601.17514
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.31.1043.18.3071.1692
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Creative\Sound Blaster Play\Surround Mixer\CTSysVol.exe
C:\Program Files (x86)\Creative\Sound Blaster Play\Volume Panel\VolPanlu.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\DllHost.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\mspaint.exe
C:\Windows\system32\mspaint.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Sandra\Desktop\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.nl/
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: “C:\Program Files (x86)\Skype\Phone\Skype.exe” /nosplash /minimized
uRun: “C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe” /background
uRun: C:\Windows\System32\StikyNot.exe
mRun: C:\Program Files (x86)\Creative\Sound Blaster Play\Surround Mixer\CTSysVol.exe /r
mRun: “C:\Program Files (x86)\Creative\Sound Blaster Play\Volume Panel\VolPanlu.exe” /r
mRun: “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun: “C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe”
mRun: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun: “C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”
mRun: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Free YouTube to MP3 Converter - C:\Users\Sandra\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{AA58ED58-01DD-4d91-8333-CF10577473F7}
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
mRun-x64: “c:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
R2 AMD Reservation Manager;AMD Reservation Manager;C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Updateservice (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
S3 gupdatem;Google Update-service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys
S3 twtyfilt;twtyfilt;C:\Windows\System32\drivers\twtyfilt.sys
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
.
=============== Created Last 30 ================
.
2012-05-02 08:17:09 ——– d—–w- C:\Users\Sandra\AppData\Local\Diagnostics
2012-05-02 01:51:22 ——– d—–w- C:\Windows\SysWow64\Wat
2012-05-02 01:51:22 ——– d—–w- C:\Windows\System32\Wat
2012-05-02 01:14:18 294912 —-a-w- C:\Windows\System32\browserchoice.exe
2012-05-02 00:03:45 8802128 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-16 21:53:59 ——– d—–w- C:\Users\Sandra\AppData\Local\{3B04898F-8371-4CEA-AE23-9EAEFDB3E695}
2011-05-16 09:53:37 ——– d—–w- C:\Users\Sandra\AppData\Local\{884FED8F-1692-456A-AF5F-15697DF6456F}
2011-05-16 09:52:08 ——– d—–w- C:\Program Files (x86)\Lavalys
2011-05-15 21:53:00 ——– d—–w- C:\Users\Sandra\AppData\Local\{EE22868C-3EFF-4F1C-88DA-3CF0703EBF5F}
2011-05-15 10:07:36 8802128 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{E32DA728-5CA6-4E38-A9FE-083DB2B061AA}\mpengine.dll
2011-05-15 09:52:25 ——– d—–w- C:\Users\Sandra\AppData\Local\{45F97D4B-F76F-4E5D-88FD-9B9E7349A3E5}
2011-05-14 22:52:34 ——– d—–w- C:\Program Files\CCleaner
2011-05-14 22:51:51 3063136 —-a-w- C:\Users\Sandra\ccsetup306.exe
2011-05-14 22:12:33 ——– d—–w- C:\Users\Sandra\AppData\Roaming\Reviversoft
2011-05-14 22:12:16 18240 —-a-w- C:\Windows\System32\roboot64.exe
2011-05-14 22:11:18 4707608 —-a-w- C:\Users\Sandra\RegistryReviverSetup.exe
2011-05-14 20:49:59 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-05-14 20:49:59 ——– d—–w- C:\PROGRA~3\Spybot - Search & Destroy
2011-05-14 20:49:10 16409960 —-a-w- C:\Users\Sandra\spybotsd162.exe
2011-05-14 19:30:14 388096 —-a-r- C:\Users\Sandra\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-14 18:23:19 ——– d—–w- C:\Users\Sandra\AppData\Local\{1105DFED-CAA1-4A9D-AB91-C9003FEDDA13}
2011-05-14 05:24:13 ——– d—–w- C:\Users\Sandra\AppData\Local\{41168AF2-1349-44CF-87D8-FB8F312AA032}
2011-05-13 21:28:47 ——– d—–w- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-05-13 21:27:51 ——– d—–w- C:\Program Files\DivX
2011-05-13 21:26:30 ——– d—–w- C:\Program Files (x86)\DivX
2011-05-13 21:20:50 ——– d—–w- C:\PROGRA~3\DivX
2011-05-13 21:09:12 287024 —-a-w- C:\Users\Sandra\SoftonicDownloader_voor_xvid-codec.exe
2011-05-13 21:07:24 652794 —-a-w- C:\Users\Sandra\XviD-1.2.2-07062009.exe
2011-05-13 09:02:07 ——– d—–w- C:\Users\Sandra\AppData\Local\{015F84BB-8476-49EE-A158-0A70C89D4729}
2011-05-12 19:36:10 ——– d—–w- C:\Users\Sandra\AppData\Local\{F134E12C-43D4-48FF-B49A-414006031049}
2011-05-12 07:35:47 ——– d—–w- C:\Users\Sandra\AppData\Local\{ADD1B4D1-CDD7-4975-A1E0-1CD209415D21}
2011-05-11 19:35:12 ——– d—–w- C:\Users\Sandra\AppData\Local\{FACBA4F9-3711-411F-9A9E-4582AE0198B2}
2011-05-11 17:25:09 ——– d—–w- C:\Program Files (x86)\Trend Micro
2011-05-11 17:23:52 1402880 —-a-w- C:\Users\Sandra\HiJackThis.msi
2011-05-11 07:35:01 ——– d—–w- C:\Users\Sandra\AppData\Local\{E5585D25-A48E-4FE6-8136-3A7C4CF99B6A}
2011-05-11 06:02:11 5562240 —-a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-11 06:02:09 3967872 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-11 06:02:09 3912576 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-11 06:01:46 52736 —-a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-11 06:01:46 343040 —-a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-11 06:01:46 325120 —-a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-11 06:01:45 98816 —-a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-11 06:01:45 7936 —-a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-11 06:01:45 25600 —-a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-10 19:12:43 ——– d—–w- C:\Users\Sandra\AppData\Local\{9402D9B0-1209-437D-AFBA-3FDE99D6F38A}
2011-05-10 07:12:07 ——– d—–w- C:\Users\Sandra\AppData\Local\{02966891-539E-407F-8D2C-49B0FD5BF7CE}
2011-05-09 19:11:29 ——– d—–w- C:\Users\Sandra\AppData\Local\{82B71CC2-7552-4929-B532-BEC039546E05}
2011-05-09 07:06:54 ——– d—–w- C:\Users\Sandra\AppData\Local\{39CE57EB-D025-4914-AAE1-07BF1E666D66}
2011-05-08 08:14:40 ——– d—–w- C:\Users\Sandra\AppData\Local\{10EDB30E-03A1-4F97-8C19-D2F681F044CF}
2011-05-07 20:14:04 ——– d—–w- C:\Users\Sandra\AppData\Local\{866425F1-777D-4D14-99C3-E289C079E55B}
2011-05-07 08:13:41 ——– d—–w- C:\Users\Sandra\AppData\Local\{9F0851CE-0D0E-485D-AC1C-5230821599EC}
2011-05-06 20:13:05 ——– d—–w- C:\Users\Sandra\AppData\Local\{90395F74-1FA3-4998-BE4C-ACBAD8439B79}
2011-05-06 08:12:43 ——– d—–w- C:\Users\Sandra\AppData\Local\{A134A032-9854-46E3-BBC5-2273E1AF8ED8}
2011-05-05 20:12:08 ——– d—–w- C:\Users\Sandra\AppData\Local\{CEA67B5B-46ED-4B76-B29F-9FA44C6CB843}
2011-05-05 08:11:27 ——– d—–w- C:\Users\Sandra\AppData\Local\{41E07416-7F77-41D1-AB83-90D1D282B87D}
2011-05-04 20:11:04 ——– d—–w- C:\Users\Sandra\AppData\Local\{369CE14F-715F-410D-B7F2-BC2892C835C1}
2011-05-04 08:10:39 ——– d—–w- C:\Users\Sandra\AppData\Local\{1090EB0C-CA70-4FE9-AD09-81DC44A900A3}
2011-05-03 18:07:47 ——– d—–w- C:\Users\Sandra\AppData\Local\{06E6825B-5598-4DC0-BFDD-4BF0F0C285D7}
2011-05-03 06:07:34 ——– d—–w- C:\Users\Sandra\AppData\Local\{C66AC453-FA2C-41AC-AA28-B5FC928BCC14}
2011-05-02 14:58:08 ——– d—–w- C:\Users\Sandra\AppData\Local\{4405A86C-637A-4C36-B3AB-FC0AAC1E1453}
2011-05-02 02:57:46 ——– d—–w- C:\Users\Sandra\AppData\Local\{6D4B25DA-6313-4E88-BF62-F7B930A368A2}
2011-05-01 14:57:24 ——– d—–w- C:\Users\Sandra\AppData\Local\{FF92134C-43E7-431C-948B-8A36016DB2E9}
2011-05-01 02:56:48 ——– d—–w- C:\Users\Sandra\AppData\Local\{A0305CD4-55BF-405F-8E56-FD3935A2778C}
2011-04-30 17:52:26 178800 —-a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll
2011-04-30 17:51:40 ——– d—–w- C:\Program Files (x86)\BoontyGames
2011-04-30 17:51:13 ——– d—–w- C:\Boonty
2011-04-30 14:56:12 ——– d—–w- C:\Users\Sandra\AppData\Local\{4D9AAC8B-13CD-411F-B070-89661A073584}
2011-04-30 02:55:36 ——– d—–w- C:\Users\Sandra\AppData\Local\{AF1E907D-5873-4798-AC5F-FF17CB00CABD}
2011-04-29 14:55:13 ——– d—–w- C:\Users\Sandra\AppData\Local\{074C92FD-188C-450F-84BB-B1DC85C183D1}
2011-04-29 02:54:45 ——– d—–w- C:\Users\Sandra\AppData\Local\{00413BAE-F310-4E14-8D6B-E8569F693246}
2011-04-28 14:13:50 ——– d—–w- C:\Users\Sandra\AppData\Local\{33F24567-2E16-40CB-BEA1-AC0684B11D3F}
2011-04-28 01:21:44 ——– d—–w- C:\Users\Sandra\AppData\Local\{FEB3F404-EDB9-4E14-97FA-0F2E39FB1452}
2011-04-27 08:08:30 ——– d—–w- C:\Users\Sandra\AppData\Local\{83BF435B-6860-4171-AFF6-C96DB7993E7A}
2011-04-27 07:08:42 ——– d—–w- C:\Windows\System32\appmgmt
2011-04-27 04:33:05 2871808 —-a-w- C:\Windows\explorer.exe
2011-04-27 04:33:05 2616320 —-a-w- C:\Windows\SysWow64\explorer.exe
2011-04-27 04:33:03 870912 —-a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-04-27 04:33:03 1465344 —-a-w- C:\Windows\System32\XpsPrint.dll
2011-04-26 20:07:54 ——– d—–w- C:\Users\Sandra\AppData\Local\{1C15889C-BE62-4EAD-BD4C-B029A66570F2}
2011-04-26 08:07:32 ——– d—–w- C:\Users\Sandra\AppData\Local\{00470244-0CF7-4315-AAF0-0B44C7C54973}
2011-04-25 20:06:57 ——– d—–w- C:\Users\Sandra\AppData\Local\{74979984-6328-4C17-9CA5-FF6DD64E8801}
2011-04-25 08:06:46 ——– d—–w- C:\Users\Sandra\AppData\Local\{13F15B68-15D4-4593-B06D-30B695169C45}
2011-04-24 19:25:32 ——– d—–w- C:\Users\Sandra\AppData\Local\{8B917515-3B1E-4EC3-914B-1362402779D6}
2011-04-24 07:25:09 ——– d—–w- C:\Users\Sandra\AppData\Local\{94E6344F-0AF9-4284-9181-5514A74BC1DF}
2011-04-23 19:24:32 ——– d—–w- C:\Users\Sandra\AppData\Local\{3B10B440-E04A-40F7-88E0-0C655A9DC968}
2011-04-23 07:24:09 ——– d—–w- C:\Users\Sandra\AppData\Local\{DBFC34C6-DC75-4C02-9433-6BC094A908D1}
2011-04-22 19:23:46 ——– d—–w- C:\Users\Sandra\AppData\Local\{5F9A2237-6E1F-48F8-BB5F-7F6BA358A520}
2011-04-22 07:23:32 ——– d—–w- C:\Users\Sandra\AppData\Local\{FFA2883F-6604-4200-84CF-EEF7D4B83E08}
2011-04-21 17:50:27 ——– d—–w- C:\Users\Sandra\AppData\Local\{57F540C5-CA28-47B0-B864-2CF23167C274}
2011-04-21 05:50:03 ——– d—–w- C:\Users\Sandra\AppData\Local\{3845BB7A-DAED-47FB-8572-9B53AFE4C2B8}
2011-04-20 17:49:29 ——– d—–w- C:\Users\Sandra\AppData\Local\{7113CE90-631C-4578-BC25-ABEA463D0052}
2011-04-20 05:49:05 ——– d—–w- C:\Users\Sandra\AppData\Local\{E1C94580-92DB-428B-B053-F4BCC7F15398}
2011-04-19 11:14:23 ——– d—–w- C:\Users\Sandra\AppData\Local\{04638436-1D60-4C2B-BA0A-B4DF2051047E}
2011-04-18 23:14:12 ——– d—–w- C:\Users\Sandra\AppData\Local\{D86A549E-2ECE-41CC-B8FC-DE0AAAF89965}
2011-04-18 08:40:20 ——– d—–w- C:\Users\Sandra\AppData\Local\{C12E3B6C-126F-43D6-9A6F-F2595A218019}
2011-04-17 20:39:45 ——– d—–w- C:\Users\Sandra\AppData\Local\{447E3380-A7C2-4B95-B0E4-6F21FC558F17}
2011-04-17 08:39:22 ——– d—–w- C:\Users\Sandra\AppData\Local\{C14DBAA6-C0DE-4214-8B69-8FE60F8E9C51}
.
==================== Find3M ====================
.
2011-03-30 06:40:47 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll
2011-03-30 06:40:46 175616 —-a-w- C:\Windows\System32\msclmd.dll
2011-03-11 06:41:37 189824 —-a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 —-a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 —-a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 —-a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 —-a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 —-a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 —-a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 —-a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 —-a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 —-a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 —-a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 —-a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 —-a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 —-a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-08 06:29:32 976896 —-a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 —-a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 06:31:44 1188864 —-a-w- C:\Windows\System32\wininet.dll
2011-03-07 05:33:13 981504 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-03-07 04:24:34 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2011-03-07 03:52:25 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-03-04 06:19:28 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19:27 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24:16 183296 —-a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 —-a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 —-a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52:08 3135488 —-a-w- C:\Windows\System32\win32k.sys
2011-02-27 18:23:41 3196328 —-a-w- C:\Users\Sandra\ventrilo-3.0.5-Windows-i386.exe
2011-02-24 06:15:44 476160 —-a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-02-24 05:38:54 288256 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-02-23 04:56:31 158208 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-02-23 04:56:27 467456 —-a-w- C:\Windows\System32\drivers\srv.sys
2011-02-23 04:56:03 411648 —-a-w- C:\Windows\System32\drivers\srv2.sys
2011-02-23 04:55:47 167936 —-a-w- C:\Windows\System32\drivers\srvnet.sys
2011-02-23 04:55:12 287744 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-02-23 04:55:12 128000 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-02-23 04:55:04 90624 —-a-w- C:\Windows\System32\drivers\bowser.sys
2011-02-19 12:05:15 1139200 —-a-w- C:\Windows\System32\FntCache.dll
2011-02-19 12:04:37 1544192 —-a-w- C:\Windows\System32\DWrite.dll
2011-02-19 12:04:17 902656 —-a-w- C:\Windows\System32\d2d1.dll
2011-02-19 12:03:46 46080 —-a-w- C:\Windows\System32\atmlib.dll
2011-02-19 09:00:32 367616 —-a-w- C:\Windows\System32\atmfd.dll
2011-02-19 06:30:51 1076736 —-a-w- C:\Windows\SysWow64\DWrite.dll
2011-02-19 06:30:50 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll
2011-02-19 06:30:46 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2011-02-19 04:34:54 294912 —-a-w- C:\Windows\SysWow64\atmfd.dll
2011-02-18 10:56:44 613376 —-a-w- C:\Windows\System32\vbscript.dll
2011-02-18 10:51:16 31232 —-a-w- C:\Windows\System32\prevhost.exe
2011-02-18 05:43:28 428032 —-a-w- C:\Windows\SysWow64\vbscript.dll
2011-02-18 05:39:44 31232 —-a-w- C:\Windows\SysWow64\prevhost.exe
2011-02-16 07:56:59 19149864 —-a-w- C:\Users\Sandra\Rift_BETA_Patcher_setup.exe
.
============= FINISH: 0:02:39,94 ===============