Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Suspect virus that is undetected

$
0
0
It seems that IE 8 is not loading pages well.
As I navigate through websites, I get stuttering and have to wait for the page to load.
I am getting many instances where I have unresponsive pages. This is escalating to 10 or more times a day and on various websites.
A couple of days ago, I was getting strange popups on ebay and facebook, but I removed some strange programs from my computer and that seemed to help with that.
I have done all that I know to do.
Malware bytes shows no infection.
Avast boot scan did not show anything.
Chkdsk did not show anything wrong.

When I try to run GMER per your first instructions, I get a blue screen with AD_Pod_Header in the title line. This happened 3 times.
I do NOT have access to a Windows install disc or a boot CD.
Here are the other programs you wanted.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.25.2
Run by user at 11:09:12 on 2013-08-23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1411 [GMT -5:00]
.
AV: PC Tools AntiVirus Free *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *Enabled*
.
============== Running Processes ================
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\dleecoms.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Documents and Settings\user\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Documents and Settings\user\Local Settings\Application Data\Akamai\netsession_win.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://att.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AutoStartNPSAgent] c:\program files\samsung\samsung new pc studio\NPSAgent.exe
uRun: [Akamai NetSession Interface] "c:\documents and settings\user\local settings\application data\akamai\netsession_win.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [IJNetworkScannerSelectorEX] c:\program files\canon\ij network scanner selector ex\CNMNSST.exe /FORCE
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [CanonQuickMenu] c:\program files\canon\quick menu\CNQMMAIN.EXE /logon
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\user\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:322
uPolicies-Explorer: NoDriveAutoRun = dword:67108847
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: {3BD6B998-8288-4DB0-8972-6DF7D3FCED3E} - c:\program files\freshdevices\freshdownload\fd.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: GenealogyBrowser.Cab - hxxp://209.90.101.200/cabs/zinst.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {3E90FFF5-1347-45B9-91F6-DA47926E9697} - hxxp://www.newhomebasedccr.com/test/PlaNetSysInfo.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1244099467437
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1348162100343
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} - hxxp://xserv.dell.com/DellDriverScanner/DellSystem.CAB
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 64.40.221.11 64.40.221.12
TCP: Interfaces\{CBB559DE-9C3A-49BD-9B3F-90D946A2F858} : DHCPNameServer = 64.40.221.11 64.40.221.12
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\program files\windows defender\MpShHook.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko10.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko11.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko12.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko19.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko5.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko6.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko7.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko8.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCoreGecko9.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{cf45c54f-801c-41b5-ac77-57f2bf418edc}\components\RadioWMPCoreGecko19.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{cf45c54f-801c-41b5-ac77-57f2bf418edc}\components\RadioWMPCoreGecko5.dll
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\bryhm25j.default\extensions\{cf45c54f-801c-41b5-ac77-57f2bf418edc}\components\RadioWMPCoreGecko6.dll
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlhtml5videoshim.dll
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dll
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\npdlplugin.dll
FF - plugin: c:\documents and settings\user\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\amazon\mp3 downloader\npAmazonMP3DownloaderPlugin101752.dll
FF - plugin: c:\program files\java\jre7\bin\npjpi170_21.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nprpplugin.dll
FF - plugin: c:\program files\musicnotes\npmusicn.dll
FF - plugin: c:\program files\musicnotes\NPSibelius.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-2-28 49376]
R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-2-28 175176]
R0 phylock;phylock;c:\windows\system32\drivers\phylock.sys [2008-8-26 11904]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-10-11 770344]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-10-11 369584]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\dddsk.sys [2011-8-6 22312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-10-11 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-2-28 66336]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-10-11 46808]
R2 dlee_device;dlee_device;c:\windows\system32\dleecoms.exe -service --> c:\windows\system32\dleecoms.exe -service [?]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2012-7-4 238952]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2013-4-16 39056]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2012-7-4 36608]
S0 cerc6;cerc6; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 dleeCATSCustConnectService;dleeCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dleeserv.exe [2013-2-24 193192]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [2012-7-4 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [2012-7-4 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [2012-7-4 123648]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-4-18 754856]
.
=============== File Associations ===============
.
ShellExec: PhotoPlus Starter Edition.exe: open=c:\progra~1\serif\photop~1\3.0\program\PHOTOP~1.EXE "%1"
.
=============== Created Last 30 ================
.
2013-08-23 15:39:22 7166848 ----a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{bf8218b1-9299-4e3e-95e0-a866773b1db6}\mpengine.dll
2013-08-20 20:37:48 -------- d-----w- c:\documents and settings\user\local settings\application data\webkit
2013-08-20 06:20:53 -------- d-----w- c:\documents and settings\user\local settings\application data\gtk-2.0
2013-08-20 06:14:13 -------- d-----w- c:\documents and settings\user\local settings\application data\gegl-0.2
2013-08-20 06:14:13 -------- d-----w- c:\documents and settings\user\.gimp-2.8
2013-08-18 18:43:48 -------- d-----w- c:\program files\common files\Adobe Systems Shared
2013-08-18 05:32:31 -------- d-----w- c:\program files\Paint.NET
2013-08-18 05:27:37 -------- d-----w- c:\program files\MyPC Backup
2013-08-18 00:46:32 -------- d-----w- c:\program files\GIMP 2
2013-08-18 00:25:21 -------- d-----w- c:\documents and settings\user\local settings\application data\SySaver
2013-08-18 00:11:51 22 ----a-w- c:\windows\system32\syoepk_lib0.dll
2013-08-18 00:05:01 -------- d-----w- c:\program files\Photo Pos Pro
2013-08-17 23:20:08 -------- d-----w- c:\documents and settings\user\application data\Serif
2013-08-17 23:07:40 -------- d-----w- c:\program files\Serif
2013-08-17 19:30:54 696320 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll
2013-08-17 19:30:54 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2013-08-17 19:30:54 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2013-08-17 19:30:54 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2013-08-17 19:30:54 155648 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2013-08-17 19:30:53 163972 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll
2013-08-17 19:30:52 282756 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll
2013-08-17 19:30:46 -------- d-----w- c:\program files\PSCS2
2013-08-15 17:07:55 -------- d-----w- c:\windows\system32\MRT
2013-08-05 21:44:13 -------- d--h--w- c:\documents and settings\all users\application data\CanonIJMIG
2013-08-05 21:41:39 -------- d--h--w- c:\documents and settings\all users\application data\CanonIJScan
2013-08-03 06:06:02 -------- d-----w- C:\PhSp_CS2_UE_Ret
2013-08-01 23:33:57 -------- d--h--w- c:\documents and settings\all users\application data\CanonIJEGV
2013-07-30 21:22:00 -------- d-----w- c:\documents and settings\user\application data\Bidgood Svcs
2013-07-30 21:21:59 -------- d-----w- c:\program files\Picture Resize
2013-07-27 22:31:52 -------- d-----w- c:\documents and settings\user\application data\ZoomBrowser EX
2013-07-27 22:29:15 -------- d-----w- c:\documents and settings\user\local settings\application data\CANON_INC
2013-07-25 20:15:17 -------- d-----w- c:\documents and settings\all users\application data\ZoomBrowser
2013-07-25 20:12:14 -------- d-----w- c:\program files\common files\Canon
.
==================== Find3M ====================
.
2013-07-26 02:47:17 920064 ----a-w- c:\windows\system32\wininet.dll
2013-07-26 02:47:13 43520 ------w- c:\windows\system32\licmgr10.dll
2013-07-26 02:47:12 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-07-25 15:52:59 385024 ------w- c:\windows\system32\html.iec
2013-07-24 14:46:00 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-24 14:46:00 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-07-10 10:37:53 406016 ------w- c:\windows\system32\usp10.dll
2013-07-04 03:03:25 2149888 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 02:08:30 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-28 20:20:47 261427152 ----a-w- C:\Image(2).bin
2013-06-27 21:23:38 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-06-27 21:23:38 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-06-25 21:13:44 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-06-25 21:13:41 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-06-25 21:13:40 867240 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-06-25 21:13:40 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-04 07:23:02 562688 ------w- c:\windows\system32\qedit.dll
2013-06-04 01:40:45 1876736 ----a-w- c:\windows\system32\win32k.sys
2013-05-28 01:59:37 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2013-05-28 00:41:07 6144 ----a-w- c:\windows\system32\xpsp4res.dll
2012-10-08 05:26:22 2962440 ----a-w- c:\program files\AmazonMP3DownloaderInstall.exe
.
============= FINISH: 11:10:29.35 ===============

Attached Files
File Type: zip attach.zip (6.4 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles