ATTACH.txt
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/5/2010 1:39:49 PM
System Uptime: 8/12/2010 7:54:00 AM (0 hours ago)
Motherboard: ECS | | A740GM-M
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4600+ | CPU 1 | 2400/200mhz
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4600+ | CPU 1 | 2400/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 37 GiB total, 30.345 GiB free.
D: is FIXED (NTFS) - 37 GiB total, 29.617 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_1057&DEV_5608&SUBSYS_00001057&REV_00\4&2966AB86&0&00A4
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_1057&DEV_5608&SUBSYS_00001057&REV_00\4&2966AB86&0&00A4
Service:
==== System Restore Points ===================
RP10: 8/8/2010 9:33:19 AM - clean
RP11: 8/10/2010 8:33:17 AM - ComboFix created restore point
RP12: 8/11/2010 10:49:14 AM - System Checkpoint
==== Installed Programs ======================
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira AntiVir Personal - Free Antivirus
Bonjour
CCleaner
EPSON Printer Software
ESET Online Scanner v3
IDT Audio
iTunes
Java Auto Updater
Java(TM) 6 Update 21
July 2010
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.6.

NVIDIA Drivers
NVIDIA PhysX
QuickTime
QuickTime Alternative 1.67
Software Update for Web Folders
Tumble Bugs
VLC media player 1.0.1
Vtune 7.6
WinRAR archiver
==== Event Viewer Messages From Past Week ========
8/7/2010 7:12:06 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
8/7/2010 6:41:16 PM, error: Service Control Manager [7000] - The Cardex service failed to start due to the following error: Cannot create a file when that file already exists.
8/7/2010 11:41:08 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001E908BB2E5 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
8/6/2010 1:55:30 PM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 001E908BB2E5 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
8/5/2010 2:38:01 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
8/5/2010 2:38:01 PM, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\JAKEEA~1\LOCALS~1\Temp\RarSFX0\redist.dll. Reference error message: The operation completed successfully. .
8/5/2010 2:38:01 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
8/5/2010 1:42:47 PM, information: Windows File Protection [64032] - Windows File Protection is not active on this system.
8/5/2010 1:39:57 PM, error: Setup [60055] - Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information.
8/10/2010 8:34:24 AM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s).
8/10/2010 8:34:24 AM, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).
8/10/2010 8:34:24 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
8/10/2010 8:34:24 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
8/10/2010 8:34:24 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
8/10/2010 8:34:24 AM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
8/10/2010 8:34:24 AM, error: Service Control Manager [7034] - The Audio Service service terminated unexpectedly. It has done this 1 time(s).
8/10/2010 8:34:24 AM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
8/10/2010 8:34:24 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/10/2010 6:54:12 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
8/10/2010 6:54:01 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
==== End Of File ===========================
DDS.txt
DDS (Ver_10-03-17.01) - NTFSx86
Run by jakee anghag at 7:57:40.57 on Thu 08/12/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.517 [GMT 1:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Vtune\TBPanel.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBHP.EXE
D:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\idt\ecsxpv_5762_010208\wdm\STacSV.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\jakee anghag\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [TBPanel] c:\program files\vtune\TBPanel.exe /A
uRun: [EPSON Stylus C59 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatibhp.exe /fu "c:\docume~1\jakeea~1\locals~1\temp\E_S63.tmp" /EF "HKCU"
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime alternative\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\jakeea~1\startm~1\programs\startup\limewi~1.lnk - d:\program files\limewire\LimeWire.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jakeea~1\applic~1\mozilla\firefox\profiles\df4t9ird.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-8-5 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-8-5 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-8-5 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-8-5 60936]
R2 Yonline;Yonline;c:\windows\system32\drivers\Yonline.ahc [2010-8-7 40832]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2010-8-5 37376]
=============== Created Last 30 ================
2010-08-11 06:05:14 0 d-----w- c:\program files\ESET
2010-08-10 21:05:14 4096 ----a-w- c:\windows\d3dx.dat
2010-08-10 21:05:11 0 d-----w- c:\docume~1\jakeea~1\applic~1\Wildfire
2010-08-10 21:04:35 0 d-----w- c:\program files\ReflexiveArcade
2010-08-10 17:37:11 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-10 17:37:09 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-10 16:42:03 25 ----a-w- c:\windows\popcinfot.dat
2010-08-10 07:34:02 0 d-sha-r- C:\cmdcons
2010-08-10 07:33:01 0 d-----w- C:\ComboFix
2010-08-10 07:18:06 98816 ----a-w- c:\windows\sed.exe
2010-08-10 07:18:06 77312 ----a-w- c:\windows\MBR.exe
2010-08-10 07:18:06 256512 ----a-w- c:\windows\PEV.exe
2010-08-10 07:18:06 161792 ----a-w- c:\windows\SWREG.exe
2010-08-09 01:13:17 0 d-----w- c:\docume~1\jakeea~1\applic~1\MozillaControl
2010-08-09 01:13:12 0 d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2010-08-09 01:07:21 0 d-----w- c:\program files\VideoLAN
2010-08-09 01:07:07 0 d-----w- c:\program files\Graboid
2010-08-08 14:38:52 25 ----a-w- c:\program files\popcinfot.dat
2010-08-08 14:38:01 0 d-----w- c:\docume~1\alluse~1\applic~1\PopCap Games
2010-08-08 14:25:26 0 d-----w- c:\program files\Plants vs. Zombies
2010-08-07 18:07:49 0 d-----w- c:\docume~1\alluse~1\applic~1\EPSON
2010-08-07 18:07:46 49152 ----a-w- c:\windows\system32\E_DCINST.DLL
2010-08-07 18:07:45 75264 ----a-w- c:\windows\system32\E_FLBBHP.DLL
2010-08-07 18:07:45 62976 ----a-w- c:\windows\system32\E_FD4BBHP.DLL
2010-08-07 18:07:20 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-08-07 18:06:46 0 d-----w- c:\program files\EPSON
2010-08-07 17:22:53 0 d-----w- C:\Rooter$
2010-08-07 17:10:18 0 d-----w- c:\docume~1\jakeea~1\applic~1\Malwarebytes
2010-08-07 17:10:09 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-07 17:10:09 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-08-07 16:19:01 0 d-----w- c:\windows\system32\NtmsData
2010-08-07 13:59:07 40832 ----a-w- c:\windows\system32\drivers\Yonline.ahc
2010-08-05 21:06:26 0 d-----w- c:\windows\pss
2010-08-05 19:22:52 96 ---ha-w- c:\windows\system32\HsInfo.dat
2010-08-05 19:20:24 0 d-----w- c:\program files\Level Up Games
2010-08-05 13:39:30 0 d-----w- c:\program files\Avira
2010-08-05 13:39:30 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-08-05 13:27:30 0 d-----w- c:\program files\common files\ODBC
2010-08-05 13:27:03 0 d-----r- c:\documents and settings\all users\Documents
2010-08-05 13:24:43 0 d-----w- c:\program files\iPod
2010-08-05 13:24:41 0 d-----w- c:\program files\iTunes
2010-08-05 13:24:41 0 d-----w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-05 13:23:28 0 d-----w- c:\program files\Bonjour
2010-08-05 13:15:03 0 d-----w- c:\docume~1\jakeea~1\applic~1\Camfrog
2010-08-05 12:51:17 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-08-05 12:51:15 0 d-----w- c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2010-08-05 12:50:51 0 d-----w- c:\program files\NVIDIA Corporation
2010-08-05 12:49:10 0 d-----w- c:\program files\Vtune
2010-08-05 12:43:45 0 d-----w- c:\program files\Microsoft ActiveSync
2010-08-05 12:39:19 0 d-----w- c:\program files\QuickTime Alternative
2010-08-05 12:37:30 0 d-sh--w- c:\documents and settings\all users\DRM
2010-08-05 12:37:07 0 d--h--w- c:\program files\WindowsUpdate
2010-08-05 12:37:03 0 d-----w- c:\program files\Online Services
2010-08-05 12:36:16 0 d-----w- c:\program files\common files\MSSoap
2010-08-05 12:34:46 0 d-----w- c:\program files\Unlocker
2010-08-05 12:31:37 0 d-----w- c:\program files\MSN Messenger
2010-08-05 12:31:13 0 d-----w- c:\program files\Windows NT
2010-08-05 06:57:31 0 d-----w- c:\docume~1\jakeea~1\applic~1\Avira
2010-08-05 06:07:03 0 d-----w- c:\docume~1\jakeea~1\applic~1\LimeWire
2010-08-05 05:59:59 0 d-----w- c:\program files\IDT
==================== Find3M ====================
2010-08-10 07:15:45 1033216 ----a-w- c:\windows\explorer.exe
2010-08-05 12:39:18 2293 ----a-w- c:\windows\mozver.dat
2010-08-05 12:39:18 107132 ----a-w- c:\windows\UninstallFirefox.exe
2010-08-05 12:35:16 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-08-05 06:06:24 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-18 15:35:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 15:35:16 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-05-18 15:35:16 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 15:35:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
============= FINISH: 7:58:04.07 ===============