.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.3.0
Run by Paolo at 14:28:20 on 2012-04-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.8104.6640 [GMT 2:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\windows\system32\nvvsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\Explorer.EXE
C:\windows\System32\rundll32.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\rundll32.exe
C:\windows\system32\taskeng.exe
C:\windows\system32\taskeng.exe
C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\windows\system32\SearchIndexer.exe
C:\Users\Public\Documents\AppData\PoApp\PService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\windows\system32\DllHost.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\windows\system32\igfxext.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
C:\windows\system32\hkcmd.exe
C:\windows\system32\igfxpers.exe
C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
C:\windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\windows\SysWOW64\cmd.exe
C:\windows\system32\conhost.exe
C:\windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page =
hxxp://www.google.frmStart Page =
hxxp://search.findeer.comuInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Samsung BHO Class: {aa609d72-8482-4076-8991-8cdae5b93bcb} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe
mPolicies-system: EnableUIADesktopToggle = 1 (0x1)
IE: E&sporta in Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.7.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.7.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.7.0/jinsta ... s-i586.cabTCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{15069DBC-44D7-4FA8-9252-A089DA70883D} : NameServer = 176.31.229.24,176.31.229.25
TCP: Interfaces\{2C70DF46-61CC-4655-8F21-1A840527105F} : NameServer = 176.31.229.24,176.31.229.25
TCP: Interfaces\{E02088E9-47F0-4D18-918A-941C271634D4} : NameServer = 176.31.229.24,176.31.229.25
TCP: Interfaces\{F61441A1-F2F0-4D57-B367-5F890E43991A} : NameServer = 198.153.192.40,198.153.194.40
TCP: Interfaces\{F61441A1-F2F0-4D57-B367-5F890E43991A} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{F61441A1-F2F0-4D57-B367-5F890E43991A}\9556C6C6F67702E456374702 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{F61441A1-F2F0-4D57-B367-5F890E43991A}\E4544574541425 : DhcpNameServer = 192.168.0.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{AA609D72-8482-4076-8991-8CDAE5B93BCB}
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
{d2ce3e00-f94a-4740-988e-03dc2f38c34f}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{8dcb7100-df86-4384-8842-8fa844297b3f}
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
SEH-X64: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}: Groove GFS Stub Execution Hook
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Paolo\AppData\Roaming\Mozilla\Firefox\Profiles\ctg1tijk.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.it/FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\windows\system32\npdeployJava1.dll
FF - plugin: C:\windows\system32\npmproxy.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;C:\windows\system32\DRIVERS\nvpciflt.sys

C:\windows\system32\DRIVERS\nvpciflt.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\windows\system32\DRIVERS\dtsoftbus01.sys

C:\windows\system32\DRIVERS\dtsoftbus01.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R1 SABI;SAMSUNG Kernel Driver For Windows 7;\??\C:\windows\system32\Drivers\SABI.sys

C:\windows\system32\Drivers\SABI.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys

C:\windows\system32\DRIVERS\vwififlt.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R2 AMPPALR3;Intel® Centrino® Bluetooth 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-4-21 1136640]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-3-30 923984]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-3-30 1001808]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-4-21 134928]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-9-6 2009704]
R2 TurboB;Turbo Boost UI Monitor driver;C:\windows\system32\DRIVERS\TurboB.sys

C:\windows\system32\DRIVERS\TurboB.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-9-6 2656536]
R3 AMPPAL;Scheda virtuale Intel(R) Centrino(R) Bluetooth 3.0 + High Speed;C:\windows\system32\DRIVERS\AMPPAL.sys

C:\windows\system32\DRIVERS\AMPPAL.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-3-30 1321296]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\windows\system32\DRIVERS\clwvd.sys

C:\windows\system32\DRIVERS\clwvd.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R3 ETD;ELAN PS/2 Port Input Device;C:\windows\system32\DRIVERS\ETD.sys

C:\windows\system32\DRIVERS\ETD.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R3 IntcDAud;Intel(R) Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys

C:\windows\system32\DRIVERS\IntcDAud.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R3 MEIx64;Intel(R) Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys

C:\windows\system32\DRIVERS\HECIx64.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\windows\system32\DRIVERS\MijXfilt.sys

C:\windows\system32\DRIVERS\MijXfilt.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\windows\system32\DRIVERS\NETwNs64.sys

C:\windows\system32\DRIVERS\NETwNs64.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys

C:\windows\system32\DRIVERS\vwifimp.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Servizio Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-3-7 136176]
S2 PowerOffer Service;Pos Service;"C:\Users\Paolo\AppData\Local\PosService\Pos.exe"

C:\Users\Paolo\AppData\Local\PosService\Pos.exe
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S2 ServUpdater;Serv Updater;"C:\Users\Paolo\AppData\Local\ServUpdater\ServiceUpd.exe"

C:\Users\Paolo\AppData\Local\ServUpdater\ServiceUpd.exe
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 AMPPALP;Protocollo Intel(R) Centrino(R) Bluetooth 3.0 + High Speed;C:\windows\system32\DRIVERS\amppal.sys

C:\windows\system32\DRIVERS\amppal.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 btmaux;Intel Bluetooth Auxiliary Service;C:\windows\system32\DRIVERS\btmaux.sys

C:\windows\system32\DRIVERS\btmaux.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 btmhsf;btmhsf;C:\windows\system32\DRIVERS\btmhsf.sys

C:\windows\system32\DRIVERS\btmhsf.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 gupdatem;Servizio Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-3-7 136176]
S3 iBtFltCoex;iBtFltCoex;C:\windows\system32\DRIVERS\iBtFltCoex.sys

C:\windows\system32\DRIVERS\iBtFltCoex.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys

C:\windows\system32\DRIVERS\Rt64win7.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 Samsung UPD Service;Samsung UPD Service;"C:\windows\System32\SUPDSvc.exe"

C:\windows\System32\SUPDSvc.exe
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys

C:\windows\system32\drivers\tsusbflt.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys

C:\windows\system32\drivers\TsUsbGD.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-10-8 150016]
S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\system32\Drivers\usbaapl64.sys

C:\windows\system32\Drivers\usbaapl64.sys
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S3 WatAdminSvc;Servizio Windows Activation Technologies;C:\windows\system32\Wat\WatAdminSvc.exe

C:\windows\system32\Wat\WatAdminSvc.exe
![Confuso [?]](http://www.megalab.it/forum/images/smilies/confused.gif)
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-04-26 10:22:16 -------- d-----w- C:\$RECYCLE.BIN
2012-04-25 01:02:45 8917360 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{088EEB69-97CC-4EAD-A9E6-B0573B69680E}\mpengine.dll
2012-04-19 23:44:18 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2012-04-17 09:04:10 174640 ----a-w- C:\windows\System32\drivers\SYMEVENT64x86.SYS
2012-04-16 23:37:41 98816 ----a-w- C:\windows\sed.exe
2012-04-16 23:37:41 518144 ----a-w- C:\windows\SWREG.exe
2012-04-16 23:37:41 256000 ----a-w- C:\windows\PEV.exe
2012-04-16 23:37:41 208896 ----a-w- C:\windows\MBR.exe
2012-04-11 09:07:53 81408 ----a-w- C:\windows\System32\imagehlp.dll
2012-04-11 09:07:53 23408 ----a-w- C:\windows\System32\drivers\fs_rec.sys
2012-04-11 09:07:53 159232 ----a-w- C:\windows\SysWow64\imagehlp.dll
2012-04-11 09:07:52 5120 ----a-w- C:\windows\SysWow64\wmi.dll
2012-04-11 09:07:52 5120 ----a-w- C:\windows\System32\wmi.dll
2012-04-11 09:07:52 220672 ----a-w- C:\windows\System32\wintrust.dll
2012-04-11 09:07:52 172544 ----a-w- C:\windows\SysWow64\wintrust.dll
2012-04-05 11:49:18 -------- d-----w- C:\Program Files\iTunes
2012-04-05 11:49:18 -------- d-----w- C:\Program Files\iPod
2012-04-05 11:49:18 -------- d-----w- C:\Program Files (x86)\iTunes
2012-04-05 11:46:37 -------- d-----w- C:\Program Files\Bonjour
2012-04-05 11:46:37 -------- d-----w- C:\Program Files (x86)\Bonjour
.
==================== Find3M ====================
.
2012-03-19 03:06:49 637848 ----a-w- C:\windows\SysWow64\npdeployJava1.dll
2012-03-19 03:06:49 567696 ----a-w- C:\windows\SysWow64\deployJava1.dll
2012-03-06 06:53:37 5559152 ----a-w- C:\windows\System32\ntoskrnl.exe
2012-03-06 05:59:47 3968368 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe
2012-03-06 05:59:41 3913072 ----a-w- C:\windows\SysWow64\ntoskrnl.exe
2012-03-05 15:19:38 283200 ----a-w- C:\windows\System32\drivers\dtsoftbus01.sys
2012-02-28 06:56:48 2311168 ----a-w- C:\windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 ----a-w- C:\windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 ----a-w- C:\windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 ----a-w- C:\windows\System32\mshtml.tlb
2012-02-28 01:18:55 1799168 ----a-w- C:\windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 ----a-w- C:\windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 ----a-w- C:\windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb
2012-02-23 08:18:36 279656 ------w- C:\windows\System32\MpSigStub.exe
2012-02-17 06:38:26 1031680 ----a-w- C:\windows\System32\rdpcore.dll
2012-02-17 05:34:22 826880 ----a-w- C:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58:24 210944 ----a-w- C:\windows\System32\drivers\rdpwd.sys
2012-02-17 04:57:32 23552 ----a-w- C:\windows\System32\drivers\tdtcp.sys
2012-02-15 09:01:50 52736 ----a-w- C:\windows\System32\drivers\usbaapl64.sys
2012-02-15 09:01:50 4547944 ----a-w- C:\windows\System32\usbaaplrc.dll
2012-02-10 06:36:07 1544192 ----a-w- C:\windows\System32\DWrite.dll
2012-02-10 05:38:43 1077248 ----a-w- C:\windows\SysWow64\DWrite.dll
2012-02-08 08:57:01 407040 ----a-w- C:\windows\HotfixChecker.exe
2012-02-08 08:56:00 345600 ----a-w- C:\windows\SetLCDStretchMode.exe
2012-02-07 09:02:40 1070352 ----a-w- C:\windows\SysWow64\MSCOMCTL.OCX
2012-02-03 04:34:34 3145728 ----a-w- C:\windows\System32\win32k.sys
.
============= FINISH: 14:28:32,98 ===============