InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1451. |
Solve : advanced care system? |
|
Answer» do any of the experts USE ADVANCED care system , i would like to know more about the utilities sectionWhilst you are waiting for an expert reply, my experience with it was good until it updated a couple of months AGO and caused problems. AWC forum was not helpful to either me or OTHERS who POSTED the same problem, so I have ditched it. |
|
| 1452. |
Solve : Panda update? |
|
Answer» Recently updated Panda and ran a scan, then logged off. Now can't log back in. When I shut off the POWER and restart windows looks like it's going to load but then goes into this saving your settings, logging off, saving your settings, logging off type loop. |
|
| 1453. |
Solve : I'm pretty sure I have a root kit, but I can't get rid of it.? |
|
Answer» About a week and a half ago, I CLICKED on a link on another forum that gave me a bunch of viruses and spyware(it was a tinyurl link, which I know I shouldn't have clicked on...). I've managed to get almost all of it out, but there's one thing I can't get rid of. It's a file called "88e25094" and it's located in F:\WINDOWS\system32\drivers. |
|
| 1454. |
Solve : Norton subscription expires soon? |
|
Answer» hello I run Windows Vista on my laptop, which is almost a year old. When i first got it, i INSTALLED Norton Internet Security as my antivirus and it has worked fairly well (although i had a huge problem with Brontok virus last year, but that's been cleared up now). My Norton SUBSCRIPTION expires in a couple weeks and i'm considering switching to a free antivirus program that can be found online, LIKE AVG or Avast. is this a bad idea? will i be compromising my laptop's security? any feedback would be greatly appreciated. Thanks a bunch Dee Avira or Avast are the best bets....... Here's the removal tool for Norton...Make sure you remove it completely..... http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039/Some experts here like this one: http://www.free-av.com/ AVG or Avast ave both very good. As for Norton, I will bite my tongue. Thanks for the input! Even after my subscription expires, should i still uninstall the Norton? can't i just disable evrything and not risk causing any trouble? Thanks again PS i forgot to mention that i was also considering BitDefender Another good choice, but it may be a bit tougher on resources.......Completely remove Norton. Quote from: Karnac on September 13, 2009, 08:04:17 AM Avira or Avast are the best bets....... Quote from: Karnac on September 13, 2009, 08:29:38 AM Another good choice, but it may be a bit tougher on resources.......Completely remove Norton. adeeba222 , the above advice is goodHere's my two cents. I have no problem with free software. But when it COMES to certain utilities (with ANTI VIRUS sw at the very top of the list) there's no way I'm looking to go cheap - I want the BEST available. In my opinion that's Kaspersky. But hey, that's me. Regardless of your choice, make sure it's updated regularly and kept resident at all times. Quote there's no way I'm looking to go cheap - I want the BEST availableBut most of the best software is free. Look at Linux for example. I'm not arguing here, but giving my opinion...) Quote from: kpac on September 13, 2009, 12:11:20 PM But most of the best software is free.And my opinion is --- I disagree.Heh okay. No persuasion at all? Quote from: kpac on September 13, 2009, 12:16:50 PM Heh okay. No persuasion at all?No persuasion? I don't understand your question.As in, I can't persuade you to change your mind about free software...No persuasion needed. I try not to speak unless I know what I'm TALKING about. My input is based on empirical data.Okay - no harm done. |
|
| 1455. |
Solve : An Infected E-mail attachment.? |
|
Answer» Hi, |
|
| 1456. |
Solve : Malware in flash drive? |
|
Answer» I have the reader_s VIRUS in my Flash drive but I have something I need in there too. Is there anyway I can get what I need out of the flash drive, without getting infected? I'm using windows xp PROFESSIONAL sp3. If u need to know what KIND of file I want to get from the flash drive, its some cpp files and some PICS (I think they're jpg). before opening your flashdrive you must scan it with any spyware you got, but I highly prefer AVG or avast, after scanning you can easily see files that are infected and remove them, after that you can easily copy anything you want without worries.AVG or Avast will not catch spyware/malware. |
|
| 1457. |
Solve : Eraser? |
|
Answer» I have installed 'Eraser' on my PC as I wish to CREATE a Nuke Boot Disk on a CD-R. We have an older model PC that we wish to dispose of, and want to wipe out the hard drive. We originally had this unit custom made without the internet options as we were not in an area where the internet was available ( on a REMOTE island !! ) The Eraser instructions specify - Start>All programs>Eraser>Create Nuke Boot Disk, but this last step doesn't appear anywhere - - Any suggestions?? - Well, if your gonna throw it away then I would suggest just SMASHING the hard drive with a HAMMER. Nope, not throwing it away - we want to DONATE it.Your windows disk can format the drive. |
|
| 1458. |
Solve : Problems with pop ups--Hijack this posted last entry of thread? |
|
Answer» To answer all questions, everything is fine. We will take care of the IMGRogue-WiniFighter_Small[1].gif. before we are done. S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-05-26 9968] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-08-11 74480] S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824] S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-08-17 20560] S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-08-17 53328] S2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe [2006-10-11 532480] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-08-29 c:\windows\Tasks\User_Feed_Synchronization-{34BB2544-E314-4CD1-A261-BD1AA15CAABB}.job - c:\windows\system32\msfeedssync.exe [2009-07-30 20:13] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.comcast.net/a/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 Trusted Zone: comcast.net\www FF - ProfilePath - c:\users\Susan M\AppData\Roaming\Mozilla\Firefox\Profiles\wlpwrnl4.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/a/ FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-08-28 23:52 Windows 6.0.6002 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCXCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,[email protected]?? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\nvvsvc.exe c:\windows\System32\audiodg.exe c:\windows\System32\rundll32.exe c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\windows\System32\drivers\XAudio.exe c:\windows\System32\WUDFHost.exe c:\program files\Alwil Software\Avast4\ashWebSv.exe c:\windows\System32\rundll32.exe c:\program files\Alwil Software\Avast4\ashDisp.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\ehome\ehmsas.exe c:\windows\System32\wbem\WMIADAP.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Completion time: 2009-08-29 23:58 - machine was rebooted ComboFix-quarantined-files.txt 2009-08-29 03:58 ComboFix2.txt 2009-08-29 00:03 Pre-Run: 236,156,841,984 bytes free Post-Run: 235,897,585,664 bytes free 247 --- E O F --- 2009-08-28 12:30 npersn31Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- Use the Kaspersky Lab Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. If needed, this animation will guide you through the process.I am concerned about what should be on and when as I am afraid stuff will interfer with other stuff, including stuff that appears in the tray, stuff that appears to the right of the Windows 'pearl'(Belarc icon, computer icon, internet explorer icon,Office Note 2007icon,Display Desktop icon,Firefox icon, Windows Media icon,Switch between windows icon,Spybot Search and Destroy icon [Tea timer icon not currently in system tray.]). In system tray upon start up/restart are Dell Support Center,Google Desktop[Desktop currently has both Google gadget icon and Google side bar],the button with options to add google gadgets(hides/shows sidebar),Dell Data Online,Avast, Avast Virus Recovery Database Generator icon,network icon,Realtek HD Audio Manager icon, and Safely remove hardware icon. What do I need to do about these? And now for the major questions: Questions to be answered before I run this: 1) I know where to find Tools on Internet Explorer favorites bar and from there Internet options and on General tab under Browsing History find Delete. I find :preserve favorites website data; temporary internet files;cookies;history;form data;passwords;InPrivate filtering data. Under this there is a delete button and a cancel button. I think that the Disk Cleanup used to have a regularly scheduled time, but when I had McAfee I got rid of that and McAfee's default cleaning as it was messing with D: where shadow copies are causing unauthorized access message in Event Viewer. How do I delete temporary internet files and temporary files? 2)What must be off when I run this Combo /u? I have turned on everything back on/or options to have in tray when run (SuperAntiSpyware Free) in order to go onto the internet. Does the firewall need to be off? And when I go back on to run TFC by OldTimer what do I do? Do I turn stuff off for the online download, and then, while modem is on standby, turn everything off? Then run TFC.exe? 3)What about that start up magnifier, the Dell Support Center in the tray, and the google gadget button with the google sidebar(on right side of screen)? Also,Dell Data online is in the tray upon start up? Will these interfer with anything? 4)After TfC.exe run: turn Windows firewall on with everything else off to do Kaspersky run? 5)Will Kaspersky let me choose settings before it starts scan? I looked at your automation for Kaspersky and noticed that you need to run Internet Explorer as administrator and I have no such option. What do I do about this? 6)What about dds.scr which is still on my desktop? 7)What about the C:\Program Files\Trend Micro\sniper.exe? The sniper shortcut on desk top and the downloaded sniper2.exe? I had problems with the renaming.... 8)Any special instructions for Spyware Blaster and SpyBot Search and Destroy? Tea time is still off --- I assume so since I have not gone back to Advanced Mode to turn it on. 9)I don't know if you need to know about PEB Corruption error that showed up in Problem reports in Windows vista(date of entry August 28). Do you? Sorry for the list of concerns and questions but I don't want to mess up. I think the last thing we tried had to do with siv, a program that I uninstalled long ago and tried to get it out of the registry without success. Also a long time ago a computer repair person put a marker in the registry--I think--so someone who knew what they were doing would find it.Did you read my list of questionable programs in an earlier post in this thread? Trying to make sure all the bases get covered! Thanks so much for the help thus far. npersn31 Quote How do I delete temporary internet files and temporary files? You will be doing that by running TFC from my prior instructions. Quote What must be off when I run this Combo /u? Nothing needs to be turned off. Just run Combo /u and then TFC. Quote Will Kaspersky let me choose settings before it starts scan? All of the options should already be set. Quote I looked at your automation for Kaspersky and noticed that you need to run Internet Explorer as administrator and I have no such option. What do I do about this? Right click the Internet Explorer icon in the system tray (bottom left) and choose Runs as Administrator. Quote What about dds.scr which is still on my desktop? Delete it. Quote What about the C:\Program Files\Trend Micro\sniper.exe Leave it for now. When we are done you can uninstall it in Add or Remove Programs. Quote Any special instructions for Spyware Blaster and SpyBot Search and Destroy? Tea time is still off Leave Tea Timer off. Don't worry about Spywareblaster. Quote I don't know if you need to know about PEB Corruption error that showed up in Problem reports in Windows vista(date of entry August 28). Do you? I have no clue what that is. Just run Kaspersky so we can see if any malware is left. Then we will deal with any remaining issues. Instructions followed; many files deleted, clicked IE 8 icon near pearl to run as administrator. Still got message that with Windows Vista you must run Kaspersky as administrator. Report follows. Did remove dds.scr to Recycle Bin and from there deleted it [after Combofix removal.] TFC.exe still on desktop. Npersn31 calling it a night. Reply when convenient and thanks! -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, August 30, 2009 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, August 30, 2009 03:34:54 Records in database: 2718240 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 110011 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 01:52:19 No threats found. Scanned area is clean. Selected area has been scanned. Quote PEB Corruption error Are you sure this is spelled right?Evilfantasy: Here is the text taken from the Event viewer-----and you tell me! Product PEB_CORRUPTION Problem Driver host process disconnect Date 8/28/2009 11:45 PM Status Report Sent Description The Windows User-Mode Driver Framework detected that a driver host-process disconnected unexpectedly. This report contains information about the process and the drivers running within and will be used to improve the quality of these drivers. Problem signature Problem Event Name: WUDFHostProblem EventClass: HostProblem Problem: HostDisconnect DetectedBy: 2 UMDFVersion: 6.0.6001.18000. (longhorn_rtm.080118-1840) ExitCode: ffffffffffffffff Operation: 0 Message: 0 Status: ffffffff OS Version: 6.0.6002.2.2.0.768.3 Locale ID: 1033 Extra information about the problem Bucket ID: 169643709 I have more details about what has been going on ,but don't have the time yet. npersn31 signing off.That error is most likely not malware related so we can finish up here. Post the information about the error in the Microsoft Windows forum and someone there will help. I deal with malware... Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Evilfantasy, lots of files were deleted but quarantine in SuperAntiSpyware was not affected.Trace.Known Threat Sources C:\Users\Susan M\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZE8Y5QVT\IMGRogue-WiniFighter_Small[1].gif was still in quarantine and whether it was adviseable to remove, it has been done. I also checked to see if anything from McAfee had been forgotten and it had: some logs from McAfee(exported text),some logs from McAfee Virtual TECHNICIAN (html form),McAfee manuals(Adobe Acrobat pdf). I am going to remove these. Last hjt that I ran just to see what it looked like after all this(including reverted to last known good configuration with Combofix problem and not having ever removing/stopping any restore points before running a/v) showed: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O1 - Hosts: ::1 localhost Which doesn't take me where I want to go--- most of them. Im not sure what I am going to do next. The Avast questions, I guess I'll have to ask in Avast forum and ask about Windows firewall elsewhere too. Internet Explorer not having administrative rights is puzzling since when I had attempted to use BitDefender scanner I used administrative rights selection from a shortcut on my desktop instead of the one to the right of the 'pearl'. npersn31All of the entries in the HJT log are legitimate. You don't have to worry about them or you can fix them with HJT. What is wrong with Avast and Windows Firewall?Before I forget,I hope you don't take this as a request for instant help---I appreciate the help when it comes. Also I still have the Oldtimer executable on my desktop: what does it take to get this removed? In reference to your question about Avast and my firewall, I would refer you to the hjt that I just used the tool to evaluate but I cannot figure how to get back to the evaluation. This evaluation did not recognize my firewall. As for what is wrong with Avast, I cannot get it to scan my email in my Windows Mail inbox. I do not understand their settings and what they mean by redirected email. I don't think that I used your method to run IE 8 as administrator when installing Avast and am wondering if I need to reinstall it. What do you think? Also there seems to be a reference to McAfee here:O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab. What about it? Here is the HJT that I used: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:03:18 PM, on 9/1/2009 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18813) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe C:\Windows\System32\rundll32.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe C:\Program Files\Dell Photo AIO Printer 926\memcard.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Trend Micro\HijackThis\sniper.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar NOTIFIER BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,[email protected] O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 7140 bytes npersn31 Quote Also I still have the Oldtimer executable on my desktop: what does it take to get this removed? Just delete it. Quote In reference to your question about Avast and my firewall, I would refer you to the hjt that I just used the tool to evaluate but I cannot figure how to get back to the evaluation. This evaluation did not recognize my firewall. As for what is wrong with Avast, I cannot get it to scan my email in my Windows Mail inbox. I do not understand their settings and what they mean by redirected email. I don't think that I used your method to run IE 8 as administrator when installing Avast and am wondering if I need to reinstall it. What do you think? Your files are scanned automatically. You don't need to do anything. Quote O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab Fix it with HJT.evil fantasy, I ran the Secunia Software Inspector and it ran over an hour, hanging up on D:---or so it seemed to me. I ran it after updating Java 6 update 15 to Java 6 update 16. Backtracking a second, recall that the Internet explorer 8 shortcut as well as the Internet explorer "e" icon on the desktop had no "run as administrator" option available in previous steps of this malware chase, I have used the one in the tray to create a new "launch Internet Explorer" shortcut with the option desired. Using this shortcut and the available "run as administrator" option, I ran the Secunia Inspector in Internet Explorer 8[I do have Foxfire, but not as default browser.] I am logged in as administrator, so I don't know if this was necessary or not---right clicking the option, that is. Just making sure circumstances surrounding the "hanging up" on D: are clearly understood. D: has the "shadow copies" and is not a separate drive from C:. The insecure programs were listed as the process went on and 8 programs were listed as found, 3 were insecure,5 were patched. I choose to go directly to sites to get the updates. Adobe Flash, Adobe Acrobat Reader,and Mozilla Foxfire were the insecure ones. I have had second thoughts about those legitimate sites you said I could take out using HJT. I have asked someone about the PEB corruption, and am wondering if my administrative rights questions are too much to ask. I have not posted any internet explorer questions yet. If you think this is ok, we can end this thread. I wait your reply and thank you so much for your patience and help. npersn31Yes we can wrap this up now. |
|
| 1460. |
Solve : Got problems, virus or malware? |
|
Answer» Hey folks,
%systemroot%\system32\*.dll /lockedfiles %systemroot%\system32\*.exe /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %SYSTEMDRIVE%\*.* %PROGRAMFILES%\*. netsvcs msconfig safebootminimal safebootnetwork activex drivers32 /md5start eventlog.dll scecli.dll netlogon.dll cngaudit.dll sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys nvrd32.sys symmpi.sys adp3132.sys mv61xx.sys /md5stop CREATERESTOREPOINT HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
|
|
| 1461. |
Solve : Need Help Opening My Programs!!!? |
|
Answer» I recently had a COMPUTER problem, where it was telling me i had no firewall, and wouldn't let me GO on mozilla. I installed Super antispyware thinking it would work, it showed alot of viruses and trojans amongst other things . When i deleted all the intrusions, it asked to restart and when i did, i can't click on any of my icons or my system restore, everytime i click on them it brings up a open with, and when i go to the program and click on it it won't work. When i try to go to my control panel and try to click on any icons there it says application not found. Now i am completely lost in what this is or how to fix it. I am up for any HELP here.......Go to this link to create a Rescue CD or to this site to create a Rescue USB. Carefully follow all the instructions for whichever method you choose.i don't get it, i did everything they instructed me to do. With the avira rescue cd i waited 1 1/2 HRS because it SAID it was loading modules and never loaded, and i can't start a scan until it finishes loading modules. With the weblive cd i got to the point to start the scan but when i get to it my mouse doesn't work and i can't go to start scan as if it froze up. Any suggestions....I couldn't get it to work, i scanned the computer and it found 177 warnings, and 7 records. It didn't delete any of them or repair any of them. I don't where i was suppose to delete them. but i still have th problem. |
|
| 1462. |
Solve : MSE wants to UPGRADE but wont?? |
|
Answer» Quote I tried to download and install the updates but have been continually failed as the Microsoft installer seems to be inoperative/corrupted, inaccessible.Are you getting any errors when you try this?Yes SuperDave, the Windows Installer seems to be the main problem. Quote from: ImnoGuru on March 22, 2011, 07:58:57 PM I went there and did Dial-a-Fix and it came back with, After that there are a string of other error codes from Dial-a-Fix. There were that many that copying them became excessive, so I photographed them as they came up. Other updates that I have tried also fail with the primary fail message "Windows Installer cannot be accessed." There are no other error messages from the Windows Installer other than "Access denied". It seems a general, across the board problem that all other fails COME up with as well, such as Abobe Reader update "Error 1604", MSE and others. I guess maybe I should start looking for my Windows CD.What I meant was were there any error messages when you try to get the Windows updates? Let's try this to make sure there are no corrupt files. Do you have an XP CD? If so, place it in your CD ROM drive and follow the instructions below: •Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow) *Let this run undisturbed until the window with the blue progress bar goes away SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.SuperDave, over the years I have got/bought/inherited/found several copies of XP (and you must admit by todays STANDARDS XP is a bit outdated), and I am not sure which one is on this computer. I suppose that I should just keep this computer as XP Pro and that is that. Is there a way to find out which CD is the right one for this computer (usually I write it on the CD)? I have in the past tried the wrong CD in different machines and it tries to install a new copy all the time. Can I find out the Registration Key Code from the machine somewhere? I have 2 here in front of me with different key codes. A slipstream bootable CD of W2K and another that says it is service pack 3 (probably this one), and then there are my laptops which should have new CD's for each x 3 for Vista? ( I mean obviously not the Vista ones, what I was thinking is, is it worth upgrading to Vista maybe? Or would that cause more problems for me? Oh my head hurts... Lets just stick to the CD's and reg keys OK. Thank you ImnoGuru. Quote Is there a way to find out which CD is the right one for this computer (usually I write it on the CD)?If you right-click on My Computer and select Properties the info. should be there under the General tab.Or, you could just run SFC. If it asks for a disk, just insert the ones you have. Quote I have in the past tried the wrong CD in different machines and it tries to install a new copy all the time.SFC will not install a new copy.I tried all the CD's I had found SuperDave, but none of them were the right disk. "Start run SFD" went through the check, but none of the files were accepted and I had to click the "skip file" box all the way through. Right now, I dont seem to have this Windows install CD. Actually just thinking deeply about it ... I think I inherited this machine from someone. Which means of course that I dont have access to the original install disk. I remember at one time recently that Patio recommended I use Macrium Reflect to take a copy of the drive, which I did, to an external hard drive. Would that be able to help with this problem SuperDave? Thank you ImnoGuru.From what you're telling me, there is a problem with some of the Windows files. If you made a copy of your harddrive, you could use it to restore your computer back to when the copy was made and you should be back in business. I will check with my buddy to see if there's anything else we can.
************************************************** Download OTL to your Desktop
msconfig safebootminimal safebootnetwork activex drivers32 %SYSTEMDRIVE%\*.exe %systemroot%\*. /mp /s c:\$recycle.bin\*.* /s HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs /md5start eventlog.dll scecli.dll netlogon.dll cngaudit.dll sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys nvstor32.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll explorer.exe svchost.exe userinit.exe qmgr.dll ws2_32.dll proquota.exe imm32.dll kernel32.dll ndis.sys autochk.exe spoolsv.exe xmlprov.dll ntmssvc.dll mswsock.dll Beep.SYS ntfs.sys termsrv.dll sfcfiles.dll st3shark.sys ahcix86.sys srsvc.dll nvrd32.sys /md5stop %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles
2011/03/30 15:14:05.0218 4232 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28 2011/03/30 15:14:07.0218 4232 ================================================================================ 2011/03/30 15:14:07.0218 4232 SystemInfo: 2011/03/30 15:14:07.0218 4232 2011/03/30 15:14:07.0218 4232 OS Version: 5.1.2600 ServicePack: 3.0 2011/03/30 15:14:07.0218 4232 Product type: Workstation 2011/03/30 15:14:07.0218 4232 ComputerName: DELLCOMPUTER1 2011/03/30 15:14:07.0218 4232 UserName: Administrator 2011/03/30 15:14:07.0218 4232 Windows directory: C:\WINDOWS 2011/03/30 15:14:07.0218 4232 System windows directory: C:\WINDOWS 2011/03/30 15:14:07.0218 4232 Processor architecture: Intel x86 2011/03/30 15:14:07.0218 4232 Number of processors: 1 2011/03/30 15:14:07.0218 4232 Page size: 0x1000 2011/03/30 15:14:07.0218 4232 Boot type: Normal boot 2011/03/30 15:14:07.0218 4232 ================================================================================ 2011/03/30 15:14:08.0656 4232 Initialize success 2011/03/30 15:14:53.0421 5668 ================================================================================ 2011/03/30 15:14:53.0421 5668 Scan started 2011/03/30 15:14:53.0421 5668 Mode: Manual; 2011/03/30 15:14:53.0421 5668 ================================================================================ 2011/03/30 15:14:53.0796 5668 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/03/30 15:14:53.0859 5668 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/03/30 15:14:53.0968 5668 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/03/30 15:14:54.0093 5668 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2011/03/30 15:14:54.0625 5668 Aspi32 (20d04091eba710f6988f710507d85868) C:\WINDOWS\system32\drivers\Aspi32.sys 2011/03/30 15:14:54.0671 5668 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/03/30 15:14:54.0703 5668 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/03/30 15:14:54.0781 5668 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/03/30 15:14:54.0843 5668 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/03/30 15:14:54.0937 5668 AVGIDSDriver (0c61f066f4d94bd67063dc6691935143) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 2011/03/30 15:14:55.0000 5668 AVGIDSEH (84853f800cd69252c3c764fe50d0346f) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 2011/03/30 15:14:55.0046 5668 AVGIDSFilter (28d6adcd03e10f3838488b9b5d407dd4) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 2011/03/30 15:14:55.0109 5668 AVGIDSShim (0eb16f4dbbb946360af30d2b13a52d1d) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 2011/03/30 15:14:55.0140 5668 Avgldx86 (5fe5a2c2330c376a1d8dcff8d2680a2d) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 2011/03/30 15:14:55.0187 5668 Avgmfx86 (54f1a9b4c9b540c2d8ac4baa171696b1) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 2011/03/30 15:14:55.0218 5668 Avgrkx86 (8da3b77993c5f354cc2977b7ea06d03a) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 2011/03/30 15:14:55.0281 5668 Avgtdix (660788ec46f10ece80274d564fa8b4aa) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 2011/03/30 15:14:55.0359 5668 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/03/30 15:14:55.0453 5668 Ca533av (a8eae8e358de3a21e6eb54f4fc7f65ec) C:\WINDOWS\system32\Drivers\Ca533av.sys 2011/03/30 15:14:55.0531 5668 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/03/30 15:14:55.0578 5668 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/03/30 15:14:55.0656 5668 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/03/30 15:14:55.0687 5668 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/03/30 15:14:55.0718 5668 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/03/30 15:14:55.0953 5668 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/03/30 15:14:56.0015 5668 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/03/30 15:14:56.0062 5668 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/03/30 15:14:56.0078 5668 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/03/30 15:14:56.0140 5668 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/03/30 15:14:56.0265 5668 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/03/30 15:14:56.0375 5668 E100B (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2011/03/30 15:14:56.0546 5668 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/03/30 15:14:56.0578 5668 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/03/30 15:14:56.0609 5668 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/03/30 15:14:56.0640 5668 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/03/30 15:14:56.0703 5668 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2011/03/30 15:14:56.0765 5668 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/03/30 15:14:56.0796 5668 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/03/30 15:14:56.0859 5668 giveio (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys 2011/03/30 15:14:56.0921 5668 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/03/30 15:14:57.0046 5668 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/03/30 15:14:57.0125 5668 HPZid412 (30ca91e657cede2f95359d6ef186f650) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 2011/03/30 15:14:57.0156 5668 HPZipr12 (efd31afa752aa7c7bbb57bcbe2b01c78) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 2011/03/30 15:14:57.0218 5668 HPZius12 (7ac43c38ca8fd7ed0b0a4466f753e06e) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 2011/03/30 15:14:57.0296 5668 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/03/30 15:14:57.0406 5668 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/03/30 15:14:57.0500 5668 ialm (da58a8be6a445835f603720c4bc8837e) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 2011/03/30 15:14:57.0593 5668 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/03/30 15:14:57.0656 5668 InCDfs (868883fb2c9ab158df2a5015837e2f3a) C:\WINDOWS\system32\drivers\InCDfs.sys 2011/03/30 15:14:57.0671 5668 InCDPass (15d32c0e4b24276e76f180b508f5deba) C:\WINDOWS\system32\DRIVERS\InCDPass.sys 2011/03/30 15:14:57.0734 5668 InCDrec (dbfb05d659500a268797bbc32f3742f0) C:\WINDOWS\system32\drivers\InCDrec.sys 2011/03/30 15:14:57.0812 5668 incdrm (9d1adfe6ce5c2e2a42f3b8aa57821d87) C:\WINDOWS\system32\drivers\incdrm.sys 2011/03/30 15:14:58.0062 5668 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/03/30 15:14:58.0125 5668 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/03/30 15:14:58.0171 5668 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2011/03/30 15:14:58.0218 5668 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/03/30 15:14:58.0250 5668 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/03/30 15:14:58.0312 5668 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/03/30 15:14:58.0390 5668 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/03/30 15:14:58.0484 5668 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/03/30 15:14:58.0625 5668 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/03/30 15:14:58.0687 5668 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/03/30 15:14:58.0765 5668 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/03/30 15:14:58.0843 5668 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/03/30 15:14:58.0890 5668 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/03/30 15:14:59.0000 5668 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/03/30 15:14:59.0078 5668 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/03/30 15:14:59.0125 5668 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/03/30 15:14:59.0203 5668 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/03/30 15:14:59.0234 5668 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/03/30 15:14:59.0296 5668 MpFilter (c98301ad8173a2235a9ab828955c32bb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 2011/03/30 15:14:59.0343 5668 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/03/30 15:14:59.0437 5668 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/03/30 15:14:59.0484 5668 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/03/30 15:14:59.0562 5668 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/03/30 15:14:59.0609 5668 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/03/30 15:14:59.0640 5668 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/03/30 15:14:59.0687 5668 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/03/30 15:14:59.0765 5668 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/03/30 15:14:59.0796 5668 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/03/30 15:14:59.0859 5668 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/03/30 15:14:59.0921 5668 NCHSSVAD (e78ce4b8e70ccc1a6e63008c3660867c) C:\WINDOWS\system32\drivers\nchssvad.sys 2011/03/30 15:15:00.0109 5668 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/03/30 15:15:00.0156 5668 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/03/30 15:15:00.0203 5668 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/03/30 15:15:00.0265 5668 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/03/30 15:15:00.0312 5668 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/03/30 15:15:00.0390 5668 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/03/30 15:15:00.0546 5668 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/03/30 15:15:00.0593 5668 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/03/30 15:15:00.0750 5668 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/03/30 15:15:00.0812 5668 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/03/30 15:15:00.0890 5668 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/03/30 15:15:00.0921 5668 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/03/30 15:15:00.0953 5668 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/03/30 15:15:01.0031 5668 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/03/30 15:15:01.0062 5668 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/03/30 15:15:01.0093 5668 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/03/30 15:15:01.0156 5668 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/03/30 15:15:01.0218 5668 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\drivers\PCIIde.sys 2011/03/30 15:15:01.0265 5668 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/03/30 15:15:01.0343 5668 PCTAppEvent (cc174f32cc9c18ea3109c4b0fc2ca8df) C:\WINDOWS\system32\drivers\PCTAppEvent.sys 2011/03/30 15:15:01.0421 5668 PCTFW-PacketFilter (4a7ef973fcd9c6cad6040ebb61262a5c) C:\WINDOWS\system32\drivers\pctNdis-PacketFilter.sys 2011/03/30 15:15:01.0484 5668 pctgntdi (d15669bd3e1cf18f00b46a7949ea541f) C:\WINDOWS\system32\drivers\pctgntdi.sys 2011/03/30 15:15:01.0562 5668 pctNDIS (8bbe917bc4da64b0ba8db33d4c0e0b7d) C:\WINDOWS\system32\DRIVERS\pctNdis.sys 2011/03/30 15:15:01.0671 5668 pctplfw (6d74df36716a458619a62dd764fc4f8b) C:\WINDOWS\system32\drivers\pctplfw.sys 2011/03/30 15:15:02.0218 5668 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/03/30 15:15:02.0390 5668 pssnap (32c45180bbc19abeb5742b5b9dc4b8d7) C:\WINDOWS\system32\DRIVERS\pssnap.sys 2011/03/30 15:15:02.0453 5668 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/03/30 15:15:02.0515 5668 QCDonner (fddd1aeb9f81ef1e6e48ae1edc2a97d6) C:\WINDOWS\system32\DRIVERS\OVCD.sys 2011/03/30 15:15:02.0703 5668 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/03/30 15:15:02.0765 5668 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/03/30 15:15:02.0828 5668 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/03/30 15:15:02.0859 5668 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/03/30 15:15:02.0906 5668 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/03/30 15:15:02.0937 5668 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/03/30 15:15:03.0000 5668 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/03/30 15:15:03.0078 5668 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/03/30 15:15:03.0156 5668 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/03/30 15:15:03.0359 5668 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/03/30 15:15:03.0421 5668 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/03/30 15:15:03.0515 5668 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys 2011/03/30 15:15:03.0578 5668 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/03/30 15:15:03.0718 5668 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/03/30 15:15:03.0875 5668 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/03/30 15:15:03.0984 5668 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/03/30 15:15:04.0031 5668 smwdm (c6d9959e493682f872a639b6ec1b4a08) C:\WINDOWS\system32\drivers\smwdm.sys 2011/03/30 15:15:04.0109 5668 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) C:\WINDOWS\system32\speedfan.sys 2011/03/30 15:15:04.0218 5668 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/03/30 15:15:04.0312 5668 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/03/30 15:15:04.0375 5668 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/03/30 15:15:04.0453 5668 sscdbus (2d4027c46b4c6e45875e3c4ba3f67492) C:\WINDOWS\system32\DRIVERS\sscdbus.sys 2011/03/30 15:15:04.0500 5668 sscdmdfl (f548f1eba107bc19e91189e6a460bd0e) C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys 2011/03/30 15:15:04.0531 5668 sscdmdm (71d348d53597379dfe1de255d70af13c) C:\WINDOWS\system32\DRIVERS\sscdmdm.sys 2011/03/30 15:15:04.0593 5668 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys 2011/03/30 15:15:04.0640 5668 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/03/30 15:15:04.0687 5668 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/03/30 15:15:04.0750 5668 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/03/30 15:15:04.0890 5668 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/03/30 15:15:05.0000 5668 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/03/30 15:15:05.0078 5668 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/03/30 15:15:05.0125 5668 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/03/30 15:15:05.0187 5668 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/03/30 15:15:05.0296 5668 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/03/30 15:15:05.0375 5668 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/03/30 15:15:05.0468 5668 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/03/30 15:15:05.0609 5668 USBCamera (0c28dd9ec68ccb6e95d49bfd24fd2c11) C:\WINDOWS\system32\Drivers\Bulk533.sys 2011/03/30 15:15:05.0734 5668 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/03/30 15:15:05.0781 5668 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/03/30 15:15:05.0812 5668 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/03/30 15:15:05.0875 5668 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/03/30 15:15:05.0890 5668 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/03/30 15:15:05.0953 5668 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/03/30 15:15:06.0000 5668 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/03/30 15:15:06.0031 5668 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/03/30 15:15:06.0109 5668 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/03/30 15:15:06.0171 5668 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/03/30 15:15:06.0250 5668 wceusbsh (4c0b8ef721783f52f8e531fbdc4b1f74) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys 2011/03/30 15:15:06.0343 5668 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/03/30 15:15:06.0484 5668 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2011/03/30 15:15:06.0546 5668 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 2011/03/30 15:15:06.0625 5668 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/03/30 15:15:06.0671 5668 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/03/30 15:15:06.0703 5668 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/03/30 15:15:06.0906 5668 ================================================================================ 2011/03/30 15:15:06.0906 5668 Scan finished 2011/03/30 15:15:06.0906 5668 ================================================================================ It was very fast, ran all the way through and reported that there were no infections found. Now I am downloading OTL to run.and here is my OTL report. OTL logfile created on: 30/03/2011 3:23:16 PM - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Administrator\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy 1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 465.75 Gb Total Space | 211.41 Gb Free Space | 45.39% Space Free | Partition Type: NTFS Computer Name: DELLCOMPUTER1 | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011/03/30 15:21:28 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe PRC - [2011/03/24 18:11:25 | 000,167,936 | ---- | M] (Applian Technologies, Inc.) -- C:\Program Files\Freecorder\FLVSrvc.exe PRC - [2011/01/07 01:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe PRC - [2011/01/07 01:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe PRC - [2011/01/06 15:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe PRC - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe PRC - [2010/12/05 16:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe PRC - [2010/12/05 16:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe PRC - [2010/10/22 04:56:58 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe PRC - [2010/09/28 23:02:58 | 000,220,128 | ---- | M] () -- C:\Program Files\Macrium\Reflect\ReflectService.exe PRC - [2010/01/12 12:41:00 | 003,168,216 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe PRC - [2009/11/09 12:20:14 | 000,818,432 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FWService.exe PRC - [2008/12/04 13:24:30 | 000,665,424 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/12/18 09:00:00 | 000,143,872 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE PRC - [2007/08/09 18:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe PRC - [2007/01/12 09:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE PRC - [2004/02/27 17:02:32 | 001,269,870 | ---- | M] (Ahead Software AG) -- C:\Program Files\Ahead\InCD\InCD.exe PRC - [2004/02/27 17:02:02 | 000,847,984 | ---- | M] (Ahead Software AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe ========== Modules (SafeList) ========== MOD - [2011/03/30 15:21:28 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe MOD - [2011/03/28 10:40:18 | 000,018,432 | ---- | M] (Applian Technologies, Inc.) -- C:\Documents and Settings\Administrator\Local Settings\Application Data\FLVService\lib\FLVSrvLib.dll MOD - [2010/08/24 03:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll MOD - [2009/07/12 00:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll MOD - [2006/05/03 22:53:54 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\framedyn.dll ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (UPS) SRV - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent) SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd) SRV - [2010/09/28 23:02:58 | 000,220,128 | ---- | M] () [Auto | Running] -- C:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService) SRV - [2010/08/02 00:13:09 | 000,028,766 | ---- | M] (IWON) [Auto | Stopped] -- C:\Program Files\IWONG\bar\1.bin\9ubarsvc.exe -- (IWONGService) SRV - [2010/02/19 19:31:44 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R) SRV - [2009/11/09 12:20:14 | 000,818,432 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\PC Tools Firewall Plus\FWService.exe -- (PCToolsFirewallPlus) SRV - [2007/12/18 09:00:00 | 000,143,872 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE -- (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) SRV - [2007/08/09 18:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (PML Driver HPZ12) SRV - [2007/01/12 09:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) SRV - [2004/02/27 17:02:02 | 000,847,984 | ---- | M] (Ahead Software AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv) ========== Driver Services (SafeList) ========== DRV - [2010/12/08 04:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2010/11/12 13:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2010/09/28 23:03:21 | 000,015,328 | ---- | M] (Macrium Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\pssnap.sys -- (pssnap) DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH) DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86) DRV - [2010/08/03 15:23:36 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim) DRV - [2010/08/03 15:23:34 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver) DRV - [2010/08/03 15:23:32 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter) DRV - [2010/05/11 05:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL) DRV - [2010/03/01 00:35:13 | 000,033,848 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD) SoundTap Recorder (32 Bit) DRV - [2010/02/05 10:17:56 | 000,233,136 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pctgntdi.sys -- (pctgntdi) DRV - [2010/01/13 09:59:28 | 000,115,216 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctplfw.sys -- (pctplfw) DRV - [2010/01/12 10:34:14 | 000,070,664 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctNdis-PacketFilter.sys -- (PCTFW-PacketFilter) DRV - [2010/01/07 12:35:06 | 000,058,816 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pctNdis.sys -- (pctNDIS) DRV - [2009/11/23 14:54:20 | 000,088,040 | ---- | M] (PC Tools) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PCTAppEvent.sys -- (PCTAppEvent) DRV - [2009/02/03 19:30:13 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2006/09/25 00:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan) DRV - [2006/03/23 18:15:56 | 000,033,536 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm) DRV - [2005/12/22 12:24:52 | 000,137,884 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm) DRV - [2005/12/22 12:24:52 | 000,010,864 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl) DRV - [2005/12/22 12:24:50 | 000,080,272 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM) DRV - [2004/09/17 10:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt) DRV - [2004/02/27 17:03:56 | 000,027,440 | ---- | M] (Ahead Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass) DRV - [2004/02/27 17:03:46 | 000,094,320 | ---- | M] (Ahead Software AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs) DRV - [2002/10/21 12:37:16 | 000,515,803 | ---- | M] (Digital Camera) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\Ca533av.sys -- (Ca533av) Icatch(IV) DRV - [2002/07/25 12:19:48 | 000,010,986 | ---- | M] (USB BULK) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Bulk533.sys -- (USBCamera) Icatch(IV) DRV - [1997/12/23 13:02:46 | 000,023,936 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32) DRV - [1996/04/04 06:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\IWONG\bar\1.bin [2011/03/17 15:37:03 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/03/16 18:09:57 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/16 15:07:51 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/18 01:45:30 | 000,000,000 | ---D | M] [2009/12/29 15:33:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions [2011/03/30 11:10:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions [2011/03/28 10:49:11 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612} [2011/03/28 09:55:47 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37} [2010/04/28 23:14:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011/03/28 09:55:51 | 000,000,000 | ---D | M] ("ToolbarBrowser") -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{2e710e6b-5e9d-44ba-8f4e-09a040978b49} [2009/11/23 12:42:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} [2009/11/23 12:42:53 | 000,000,000 | ---D | M] (FEBE) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}(2) [2010/01/20 23:55:18 | 000,000,000 | ---D | M] (CashKeywords Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{9eb64fa9-57c4-4a41-9940-e12e0418b693}(2) [2011/03/28 09:55:46 | 000,000,000 | ---D | M] ("Shorten URL") -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{a1109c2a-1187-4027-901d-13097b755625} [2010/01/20 23:56:54 | 000,000,000 | ---D | M] (FireFTP) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}(2) [2010/12/15 20:31:07 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} [2011/01/07 21:49:20 | 000,000,000 | ---D | M] (Web Developer) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12} [2011/03/28 09:55:47 | 000,000,000 | ---D | M] (Fast Video Download (with SearchMenu)) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8} [2010/03/14 18:23:04 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2010/10/02 17:43:54 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected] [2011/03/28 10:49:09 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected] [2009/11/23 12:43:55 | 000,000,000 | ---D | M] (Firebug) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).com [2010/01/20 23:54:44 | 000,000,000 | ---D | M] (FirePHP) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).org [2009/11/23 12:44:25 | 000,000,000 | ---D | M] (FastestFox) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).com [2011/03/28 09:55:50 | 000,000,000 | ---D | M] (Echofon) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected] [2010/01/19 19:31:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).org\__MACOSX(2) [2010/01/20 23:54:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).org\chrome(2) [2010/01/20 23:54:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\n9lrtipw.default\extensions\[email protected](2).org\defaults(2) [2011/03/29 10:56:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2010/05/09 18:32:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010/08/10 11:55:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010/12/16 08:09:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010/12/16 15:10:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2010/11/12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll O1 HOSTS File: ([2011/03/20 23:15:57 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.) O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.) O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (&Save Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll (TODO: ) O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKCU\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (&Save Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll (TODO: ) O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [00PCTFW] C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools) O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.) O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKCU..\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro] File not found O4 - HKCU..\Run: [Wisdom-soft ScreenHunter 5.1 Pro] File not found O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10n_Plugin.exe (Adobe Systems, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab (EPUImageControl Class) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com) O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O24 - Desktop WALLPAPER: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008/09/14 16:05:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [ = ComFile] -- "%1" %* O37 - HKLM\...exe [ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - HUMAN Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906) ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447) ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8 ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Security Update for Windows XP (KB923789) ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders ActiveX: {75D04B76-E0D3-9685-9369-AF82CB13E868} - Microsoft Windows Media Player ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install ActiveX: {8DB52A01-AEF7-9ACF-7808-55F420F23178} - Browser Customizations ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) Drivers32: VIDC.SP54 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus) Drivers32: VIDC.SP55 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus) Drivers32: VIDC.SP56 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus) Drivers32: VIDC.SP57 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus) Drivers32: VIDC.SP58 - C:\WINDOWS\System32\SP5X_32.DLL (Sunplus) Drivers32: VIDC.XFR1 - C:\WINDOWS\System32\xfcodec.dll () ========== Files/Folders - Created Within 30 Days ========== [2011/03/30 15:21:26 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe [2011/03/30 15:13:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\tdsskiller [2011/03/28 11:23:17 | 000,116,224 | ---- | C] (Xerox) -- C:\WINDOWS\System32\dllcache\xrxwiadr.dll [2011/03/28 11:23:17 | 000,023,040 | ---- | C] (Xerox Corporation) -- C:\WINDOWS\System32\dllcache\xrxwbtmp.dll [2011/03/28 11:23:16 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xrxflnch.exe [2011/03/28 11:22:06 | 000,019,455 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wvchntxx.sys [2011/03/28 11:22:06 | 000,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys [2011/03/28 11:22:03 | 000,012,063 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wsiintxx.sys [2011/03/28 11:22:02 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshirda.dll [2011/03/28 11:21:50 | 000,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiacpi.sys [2011/03/28 11:21:49 | 000,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys [2011/03/28 11:21:49 | 000,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys [2011/03/28 11:21:43 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiafbdrv.dll [2011/03/28 11:21:43 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiamsmud.dll [2011/03/28 11:21:35 | 000,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys [2011/03/28 11:21:35 | 000,023,615 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wch7xxnt.sys [2011/03/28 11:21:33 | 000,033,599 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv04nt.sys [2011/03/28 11:21:33 | 000,025,471 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv10nt.sys [2011/03/28 11:21:33 | 000,022,271 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv06nt.sys [2011/03/28 11:21:33 | 000,019,551 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv02nt.sys [2011/03/28 11:21:32 | 000,029,311 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv01nt.sys [2011/03/28 11:21:27 | 000,011,935 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv11nt.sys [2011/03/28 11:21:26 | 000,011,871 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv09nt.sys [2011/03/28 11:21:26 | 000,011,807 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv07nt.sys [2011/03/28 11:21:26 | 000,011,775 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv05nt.sys [2011/03/28 11:21:26 | 000,011,295 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv08nt.sys [2011/03/28 11:21:25 | 000,012,415 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv01nt.sys [2011/03/28 11:21:25 | 000,012,127 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv02nt.sys [2011/03/28 11:21:22 | 000,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys [2011/03/28 11:21:22 | 000,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys [2011/03/28 11:21:22 | 000,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys [2011/03/28 11:21:08 | 000,042,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\viaagp.sys [2011/03/28 11:21:08 | 000,024,576 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\viairda.sys [2011/03/28 11:21:08 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\viaide.sys [2011/03/28 11:21:05 | 000,011,325 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\vchnt5.dll [2011/03/28 11:20:23 | 000,121,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbvideo.sys [2011/03/28 11:20:22 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbser.sys [2011/03/28 11:20:22 | 000,017,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbohci.sys [2011/03/28 11:20:21 | 000,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys [2011/03/28 11:20:21 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usb8023x.sys [2011/03/28 11:20:19 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxud32.dll [2011/03/28 11:20:18 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu12.dll [2011/03/28 11:20:18 | 000,050,688 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\umaxscan.dll [2011/03/28 11:20:18 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu40.dll [2011/03/28 11:20:18 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu22.dll [2011/03/28 11:20:18 | 000,022,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxpcls.sys [2011/03/28 11:20:17 | 000,211,968 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um54scan.dll [2011/03/28 11:20:17 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxp60.dll [2011/03/28 11:20:17 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxcam.dll [2011/03/28 11:20:16 | 000,216,064 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um34scan.dll [2011/03/28 11:20:16 | 000,036,736 | ---- | C] (Promise Technology, Inc.) -- C:\WINDOWS\System32\dllcache\ultra.sys [2011/03/28 11:20:14 | 000,044,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uagp35.sys [2011/03/28 11:20:08 | 000,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll [2011/03/28 11:20:08 | 000,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys [2011/03/28 11:20:08 | 000,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys [2011/03/28 11:20:07 | 000,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll [2011/03/28 11:20:07 | 000,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys [2011/03/28 11:20:06 | 000,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll [2011/03/28 11:20:06 | 000,034,375 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\tpro4.sys [2011/03/28 11:19:58 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\toside.sys [2011/03/28 11:19:53 | 000,028,232 | ---- | C] (TOSHIBA Corporation) -- C:\WINDOWS\System32\dllcache\tos4mo.sys [2011/03/28 11:19:48 | 000,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys [2011/03/28 11:19:48 | 000,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll [2011/03/28 11:19:47 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys [2011/03/28 11:19:44 | 000,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys [2011/03/28 11:19:44 | 000,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys [2011/03/28 11:19:23 | 000,032,640 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\symc8xx.sys [2011/03/28 11:19:23 | 000,016,256 | ---- | C] (Symbios Logic Inc.) -- C:\WINDOWS\System32\dllcache\symc810.sys [2011/03/28 11:19:22 | 000,030,688 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\sym_u3.sys [2011/03/28 11:19:22 | 000,028,384 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\sym_hi.sys [2011/03/28 11:19:18 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_wheel.dll [2011/03/28 11:19:18 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpidflt.dll [2011/03/28 11:19:18 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpdflt2.dll [2011/03/28 11:19:18 | 000,003,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swusbflt.sys [2011/03/28 11:19:17 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_effct.dll [2011/03/28 11:19:09 | 000,016,896 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys [2011/03/28 11:19:04 | 000,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys [2011/03/28 11:19:03 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusd.dll [2011/03/28 11:18:52 | 000,019,072 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\dllcache\sparrow.sys [2011/03/28 11:18:51 | 000,007,552 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypvu1.sys [2011/03/28 11:18:47 | 000,009,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sonymc.sys [2011/03/28 11:18:44 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snyaitmc.sys [2011/03/28 11:18:25 | 000,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys [2011/03/28 11:18:22 | 000,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll [2011/03/28 11:18:20 | 000,035,913 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys [2011/03/28 11:18:20 | 000,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys [2011/03/28 11:18:19 | 000,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys [2011/03/28 11:18:19 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbclass.sys [2011/03/28 11:18:19 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbhc.sys [2011/03/28 11:18:18 | 000,016,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbbatt.sys [2011/03/28 11:18:18 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbali.sys [2011/03/28 11:18:16 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb3w.dll [2011/03/28 11:18:15 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb0w.dll [2011/03/28 11:18:13 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma0w.dll [2011/03/28 11:18:07 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm91w.dll [2011/03/28 11:17:37 | 000,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys [2011/03/28 11:17:37 | 000,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys [2011/03/28 11:17:36 | 000,157,696 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv256.dll [2011/03/28 11:17:36 | 000,094,698 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys [2011/03/28 11:17:36 | 000,050,432 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv.sys [2011/03/28 11:17:35 | 000,238,592 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrv.dll [2011/03/28 11:17:35 | 000,104,064 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrp.sys [2011/03/28 11:17:35 | 000,040,960 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisagp.sys [2011/03/28 11:17:35 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys [2011/03/28 11:17:34 | 000,252,032 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300iv.dll [2011/03/28 11:17:34 | 000,150,144 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306v.dll [2011/03/28 11:17:34 | 000,101,760 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300ip.sys [2011/03/28 11:17:34 | 000,068,608 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306p.sys [2011/03/28 11:17:33 | 000,003,901 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\siint5.dll [2011/03/28 11:17:18 | 000,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys [2011/03/28 11:17:17 | 000,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll [2011/03/28 11:17:17 | 000,036,480 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sfmanm.sys [2011/03/28 11:17:13 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sermouse.sys [2011/03/28 11:17:13 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\serscan.sys [2011/03/28 11:17:07 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seaddsmc.sys [2011/03/28 11:17:06 | 000,011,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiprnt.sys [2011/03/28 11:17:06 | 000,011,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiscan.sys [2011/03/28 11:17:03 | 000,017,280 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys [2011/03/28 11:17:03 | 000,016,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scmstcs.sys [2011/03/28 11:17:02 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys [2011/03/28 11:17:02 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys [2011/03/28 11:17:01 | 000,495,616 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sblfx.dll [2011/03/28 11:17:01 | 000,043,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sbp2port.sys [2011/03/28 11:17:00 | 000,245,632 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmx.dll [2011/03/28 11:17:00 | 000,075,392 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmxm.sys [2011/03/28 11:16:59 | 000,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll [2011/03/28 11:16:59 | 000,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys [2011/03/28 11:16:59 | 000,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys [2011/03/28 11:16:58 | 000,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll [2011/03/28 11:16:54 | 000,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll [2011/03/28 11:16:54 | 000,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys [2011/03/28 11:16:49 | 000,397,056 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3gnb.dll [2011/03/28 11:16:49 | 000,166,912 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3gnbm.sys [2011/03/28 11:16:47 | 000,082,432 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia450.dll [2011/03/28 11:16:47 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia430.dll [2011/03/28 11:16:43 | 000,029,696 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw450ext.dll [2011/03/28 11:16:42 | 000,027,648 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw430ext.dll [2011/03/28 11:16:34 | 000,020,992 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8139.sys [2011/03/28 11:16:33 | 000,030,720 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\rthwcls.sys [2011/03/28 11:16:33 | 000,019,017 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8029.sys [2011/03/28 11:16:32 | 000,009,216 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\rsmgrstr.dll [2011/03/28 11:16:31 | 000,003,840 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\rpfun.sys [2011/03/28 11:16:28 | 000,030,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rndismpx.sys [2011/03/28 11:16:27 | 000,059,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rfcomm.sys [2011/03/28 11:16:27 | 000,037,563 | ---- | C] (RadioLAN) -- C:\WINDOWS\System32\dllcache\rlnet5.sys [2011/03/28 11:16:13 | 000,019,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasirda.sys [2011/03/28 11:16:07 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qvusd.dll [2011/03/28 11:16:07 | 000,003,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qv2kux.sys [2011/03/28 11:15:53 | 000,049,024 | ---- | C] (QLogic Corporation) -- C:\WINDOWS\System32\dllcache\ql1280.sys [2011/03/28 11:15:53 | 000,045,312 | ---- | C] (QLogic Corporation) -- C:\WINDOWS\System32\dllcache\ql12160.sys [2011/03/28 11:15:53 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ql1240.sys [2011/03/28 11:15:52 | 000,040,320 | ---- | C] (QLogic Corporation) -- C:\WINDOWS\System32\dllcache\ql1080.sys [2011/03/28 11:15:52 | 000,033,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ql10wnt.sys [2011/03/28 11:15:43 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ptpusd.dll [2011/03/28 11:15:43 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ptpusb.dll [2011/03/28 11:15:42 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\psisload.dll [2011/03/28 11:15:42 | 000,016,128 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\pscr.sys [2011/03/28 11:15:40 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ppa3.sys [2011/03/28 11:15:39 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ppa.sys [2011/03/28 11:15:39 | 000,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\powerfil.sys [2011/03/28 11:15:38 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pnrmc.sys [2011/03/28 11:15:30 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phvfwext.dll [2011/03/28 11:15:30 | 000,092,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phildec.sys [2011/03/28 11:15:30 | 000,019,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philtune.sys [2011/03/28 11:15:29 | 000,173,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam2.sys [2011/03/28 11:15:29 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phdsext.ax [2011/03/28 11:15:29 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam1.sys [2011/03/28 11:15:29 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam1.dll [2011/03/28 11:15:28 | 000,259,328 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm3dd.dll [2011/03/28 11:15:28 | 000,028,032 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm3.sys [2011/03/28 11:15:27 | 000,211,584 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm2dll.dll [2011/03/28 11:15:27 | 000,027,904 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm2.sys [2011/03/28 11:15:26 | 000,027,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\perc2.sys [2011/03/28 11:15:26 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\perc2hib.sys [2011/03/28 11:15:25 | 000,169,984 | ---- | C] (Cisco Systems) -- C:\WINDOWS\System32\dllcache\pcx500.sys [2011/03/28 11:15:23 | 000,035,328 | ---- | C] (AMD Inc.) -- C:\WINDOWS\System32\dllcache\pcntpci5.sys [2011/03/28 11:15:23 | 000,030,282 | ---- | C] (AMD Inc.) -- C:\WINDOWS\System32\dllcache\pcntn5hl.sys [2011/03/28 11:15:23 | 000,029,769 | ---- | C] (AMD Inc.) -- C:\WINDOWS\System32\dllcache\pcntn5m.sys [2011/03/28 11:15:18 | 000,030,495 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pc100nds.sys [2011/03/28 11:15:16 | 000,031,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovce.sys [2011/03/28 11:15:16 | 000,025,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovsound2.sys [2011/03/28 11:15:15 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovca.sys [2011/03/28 11:15:06 | 000,043,689 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otceth5.sys [2011/03/28 11:15:06 | 000,027,209 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otc06x5.sys [2011/03/28 11:15:05 | 000,054,528 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\opl3sax.sys [2011/03/28 11:15:04 | 000,061,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ohci1394.sys [2011/03/28 11:15:01 | 004,274,816 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv4_disp.dll [2011/03/28 11:15:01 | 001,897,408 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv4_mini.sys [2011/03/28 11:15:00 | 000,198,144 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv3.sys [2011/03/28 11:15:00 | 000,123,776 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv3.dll [2011/03/28 11:14:50 | 000,009,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntapm.sys [2011/03/28 11:14:50 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nsmmc.sys [2011/03/28 11:14:49 | 000,028,672 | ---- | C] (National Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\nscirda.sys [2011/03/28 11:14:48 | 000,126,080 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm5a2wdm.sys [2011/03/28 11:14:48 | 000,087,040 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm6wdm.sys [2011/03/28 11:14:47 | 000,032,840 | ---- | C] (NETGEAR Corporation.) -- C:\WINDOWS\System32\dllcache\ngrpci.sys [2011/03/28 11:14:46 | 000,132,695 | ---- | C] (802.11b) -- C:\WINDOWS\System32\dllcache\netwlan5.sys [2011/03/28 11:14:44 | 000,065,278 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\netflx3.sys [2011/03/28 11:14:43 | 000,060,480 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.dll [2011/03/28 11:14:43 | 000,039,264 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.sys [2011/03/28 11:14:43 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ne2000.sys [2011/03/28 11:14:28 | 000,128,000 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\n100325.sys [2011/03/28 11:14:28 | 000,052,255 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\n1000nt5.sys [2011/03/28 11:14:23 | 000,019,968 | ---- | C] (Macronix International Co., Ltd. ) -- C:\WINDOWS\System32\dllcache\mxnic.sys [2011/03/28 11:14:10 | 001,737,856 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mtxparhd.dll [2011/03/28 11:14:10 | 000,452,736 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mtxparhm.sys [2011/03/28 11:14:10 | 000,103,296 | ---- | C] (Matrox Graphics Inc) -- C:\WINDOWS\System32\dllcache\mtxvideo.sys [2011/03/28 11:13:56 | 000,012,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msriffwv.sys [2011/03/28 11:13:53 | 000,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msmpu401.sys [2011/03/28 11:13:51 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msircomm.sys [2011/03/28 11:13:41 | 000,035,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msgame.sys [2011/03/28 11:13:41 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfsio.sys [2011/03/28 11:13:40 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdv.sys [2011/03/28 11:13:36 | 000,017,280 | ---- | C] (American Megatrends Inc.) -- C:\WINDOWS\System32\dllcache\mraid35x.sys [2011/03/28 11:13:34 | 000,015,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mpe.sys [2011/03/28 11:13:32 | 000,016,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\modemcsa.sys [2011/03/28 11:13:20 | 000,320,384 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mgaum.sys [2011/03/28 11:13:20 | 000,235,648 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mgaud.dll [2011/03/28 11:13:12 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\memgrp.dll [2011/03/28 11:13:12 | 000,026,112 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\memstpci.sys [2011/03/28 11:13:11 | 000,008,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\memcard.sys [2011/03/28 11:13:10 | 000,164,586 | ---- | C] (Madge Networks Ltd) -- C:\WINDOWS\System32\dllcache\mdgndis5.sys [2011/03/28 11:13:03 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\m3092dc.dll [2011/03/28 11:13:03 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\m3091dc.dll [2011/03/28 11:13:03 | 000,048,768 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\maestro.sys [2011/03/28 11:13:02 | 000,022,848 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\dllcache\lwusbhid.sys [2011/03/28 11:13:02 | 000,020,864 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\dllcache\lwadihid.sys [2011/03/28 11:12:45 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\loop.sys [2011/03/28 11:12:43 | 000,070,730 | ---- | C] (Linksys Group, Inc.) -- C:\WINDOWS\System32\dllcache\lne100tx.sys [2011/03/28 11:12:43 | 000,020,573 | ---- | C] (The Linksts Group ) -- C:\WINDOWS\System32\dllcache\lne100.sys [2011/03/28 11:12:42 | 000,025,065 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\lmndis3.sys [2011/03/28 11:12:42 | 000,015,744 | ---- | C] (Litronic Industries) -- C:\WINDOWS\System32\dllcache\lit220p.sys [2011/03/28 11:12:40 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\dllcache\lbrtfdc.sys [2011/03/28 11:12:40 | 000,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys [2011/03/28 11:12:39 | 000,019,016 | ---- | C] (Kingston Technology Company ) -- C:\WINDOWS\System32\dllcache\ktc111.sys [2011/03/28 11:12:38 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kousd.dll [2011/03/28 11:12:33 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsusd.dll [2011/03/28 11:12:32 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsui.dll [2011/03/28 11:10:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irmon.dll [2011/03/28 11:10:28 | 000,026,624 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\dllcache\irstusb.sys [2011/03/28 11:10:The OTL Extra.txt log is missing. Quote from: ImnoGuru on March 29, 2011, 10:42:27 PM and here is my OTL report. Yes I found that part that was missing SuperDave. I highlighted a bit of the overlap for you to continue from. (Hope I was accurate with that) Maybe it was to big to process the whole thing? OR it could have been an operators mistake? 2011/03/28 11:12:40 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\dllcache\lbrtfdc.sys [2011/03/28 11:12:40 | 000,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys [2011/03/28 11:12:39 | 000,019,016 | ---- | C] (Kingston Technology Company ) -- C:\WINDOWS\System32\dllcache\ktc111.sys [2011/03/28 11:12:38 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kousd.dll [2011/03/28 11:12:33 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsusd.dll [2011/03/28 11:12:32 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsui.dll [2011/03/28 11:10:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irmon.dll [2011/03/28 11:10:28 | 000,026,624 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\dllcache\irstusb.sys [2011/03/28 11:10:28 | 000,018,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irsir.sys [2011/03/28 11:10:27 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irftp.exe [2011/03/28 11:10:27 | 000,088,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irda.sys [2011/03/28 11:10:27 | 000,023,552 | ---- | C] (MKNet Corporation) -- C:\WINDOWS\System32\dllcache\irmk7.sys [2011/03/28 11:10:26 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irbus.sys [2011/03/28 11:10:17 | 000,013,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inport.sys [2011/03/28 11:10:16 | 000,016,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ini910u.sys [2011/03/28 11:09:40 | 000,100,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5usb.sys [2011/03/28 11:09:39 | 000,154,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4usb.sys [2011/03/28 11:09:39 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5com.dll [2011/03/28 11:09:39 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5ext.dll [2011/03/28 11:09:38 | 000,141,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam3.sys [2011/03/28 11:09:38 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4com.dll [2011/03/28 11:09:38 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4ext.dll [2011/03/28 11:09:38 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam3ext.dll [2011/03/28 11:09:37 | 000,109,085 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmtrp.sys [2011/03/28 11:09:37 | 000,100,936 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmtok.sys [2011/03/28 11:09:37 | 000,038,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ibmvcap.sys [2011/03/28 11:09:36 | 000,161,020 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\i81xnt5.sys [2011/03/28 11:09:36 | 000,028,700 | ---- | C] (IBM Corp.) -- C:\WINDOWS\System32\dllcache\ibmexmp.sys [2011/03/28 11:09:36 | 000,009,216 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmsgnet.dll [2011/03/28 11:09:35 | 000,702,845 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\i81xdnt5.dll [2011/03/28 11:09:35 | 000,353,184 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\i740dnt5.dll [2011/03/28 11:09:35 | 000,058,592 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\i740nt5.sys [2011/03/28 11:09:34 | 000,018,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\i2omp.sys [2011/03/28 11:09:34 | 000,008,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\i2omgmt.sys [2011/03/28 11:08:55 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hr1w.dll [2011/03/28 11:08:52 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpojwia.dll [2011/03/28 11:08:52 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgtmcro.dll [2011/03/28 11:08:52 | 000,025,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpn.sys [2011/03/28 11:08:52 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpsjmcro.dll [2011/03/28 11:08:51 | 000,068,608 | ---- | C] (Avisioin) -- C:\WINDOWS\System32\dllcache\hpgt53tk.dll [2011/03/28 11:08:51 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt42tk.dll [2011/03/28 11:08:50 | 000,126,976 | ---- | C] (Hewlett Packard) -- C:\WINDOWS\System32\dllcache\hpgt34tk.dll [2011/03/28 11:08:50 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt33tk.dll [2011/03/28 11:08:49 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt21tk.dll [2011/03/28 11:08:49 | 000,119,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpdigwia.dll [2011/03/28 11:08:47 | 000,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidir.sys [2011/03/28 11:08:47 | 000,008,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidgame.sys [2011/03/28 11:08:47 | 000,002,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidswvd.sys [2011/03/28 11:08:46 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidbth.sys [2011/03/28 11:08:46 | 000,020,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidbatt.sys [2011/03/28 11:08:42 | 000,028,288 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grserial.sys [2011/03/28 11:08:41 | 000,082,304 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grclass.sys [2011/03/28 11:08:40 | 000,017,408 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\gpr400.sys [2011/03/28 11:08:39 | 000,059,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gckernel.sys [2011/03/28 11:08:39 | 000,010,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gameenum.sys [2011/03/28 11:08:38 | 001,733,120 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g400d.dll [2011/03/28 11:08:38 | 000,322,432 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g400m.sys [2011/03/28 11:08:38 | 000,046,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gagp30kx.sys [2011/03/28 11:08:37 | 000,470,144 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g200d.dll [2011/03/28 11:08:37 | 000,320,384 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g200m.sys [2011/03/28 11:07:58 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fuusd.dll [2011/03/28 11:07:41 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fnfilter.dll [2011/03/28 11:07:38 | 000,027,165 | ---- | C] (VIA Technologies, Inc. ) -- C:\WINDOWS\System32\dllcache\fetnd5.sys [2011/03/28 11:07:37 | 000,022,090 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\fem556n5.sys [2011/03/28 11:07:34 | 000,024,618 | ---- | C] (NETGEAR) -- C:\WINDOWS\System32\dllcache\fa410nd5.sys [2011/03/28 11:07:34 | 000,016,074 | ---- | C] (NETGEAR Corp.) -- C:\WINDOWS\System32\dllcache\fa312nd5.sys [2011/03/28 11:07:33 | 000,012,362 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xi.sys [2011/03/28 11:07:33 | 000,011,850 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xj.sys [2011/03/28 11:07:30 | 000,016,998 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\ex10.sys [2011/03/28 11:07:24 | 000,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunib.dll [2011/03/28 11:07:24 | 000,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuni.dll [2011/03/28 11:07:22 | 000,034,816 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimg.dll [2011/03/28 11:07:20 | 000,137,088 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\essm2e.sys [2011/03/28 11:07:20 | 000,043,008 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucm.dll [2011/03/28 11:07:19 | 000,063,360 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\ess.sys [2011/03/28 11:07:10 | 000,174,464 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\es198x.sys [2011/03/28 11:07:10 | 000,072,192 | ---- | C] (ESS Technology Inc.) -- C:\WINDOWS\System32\dllcache\es1969.sys [2011/03/28 11:07:10 | 000,040,704 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\es1371mp.sys [2011/03/28 11:07:10 | 000,037,120 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\es1370mp.sys [2011/03/28 11:06:59 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\epcfw2k.sys [2011/03/28 11:06:59 | 000,114,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\epstw2k.sys [2011/03/28 11:06:59 | 000,018,503 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\epro4.sys [2011/03/28 11:06:59 | 000,006,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\enum1394.sys [2011/03/28 11:06:58 | 000,283,904 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\emu10k1m.sys [2011/03/28 11:06:57 | 000,171,520 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el99xn51.sys [2011/03/28 11:06:57 | 000,025,159 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\elnk3.sys [2011/03/28 11:06:57 | 000,019,996 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\em556n4.sys [2011/03/28 11:06:57 | 000,007,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\elmsmc.sys [2011/03/28 11:06:56 | 000,455,199 | ---- | C] (3Com Corporation.) -- C:\WINDOWS\System32\dllcache\el985n51.sys [2011/03/28 11:06:56 | 000,153,631 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el90xnd5.sys [2011/03/28 11:06:56 | 000,070,174 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el98xn5.sys [2011/03/28 11:06:56 | 000,066,591 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el90xbc5.sys [2011/03/28 11:06:53 | 000,077,386 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el656nd5.sys [2011/03/28 11:06:42 | 000,069,194 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el656cd5.sys [2011/03/28 11:06:42 | 000,026,141 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el589nd5.sys [2011/03/28 11:06:41 | 000,069,692 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el575nd5.sys [2011/03/28 11:06:41 | 000,055,999 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el556nd5.sys [2011/03/28 11:06:41 | 000,024,653 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el574nd4.sys [2011/03/28 11:06:40 | 000,044,103 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el515.sys [2011/03/28 11:06:38 | 000,050,719 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\e1000nt5.sys [2011/03/28 11:06:38 | 000,019,594 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\e100isa4.sys [2011/03/28 11:06:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dshowext.ax [2011/03/28 11:06:34 | 000,334,208 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\ds1wdm.sys [2011/03/28 11:06:33 | 000,020,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpti2o.sys [2011/03/28 11:06:30 | 000,206,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4.sys [2011/03/28 11:06:30 | 000,028,062 | ---- | C] (National Semiconductor Coproration) -- C:\WINDOWS\System32\dllcache\dp83820.sys [2011/03/28 11:06:30 | 000,023,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4usb.sys [2011/03/28 11:06:30 | 000,012,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4prt.sys [2011/03/28 11:06:30 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4scan.sys [2011/03/28 11:06:27 | 000,029,696 | ---- | C] (CNet Technology, Inc. ) -- C:\WINDOWS\System32\dllcache\dm9pci5.sys [2011/03/28 11:06:24 | 000,026,698 | ---- | C] (D-Link Corporation) -- C:\WINDOWS\System32\dllcache\dlh5xnd5.sys [2011/03/28 11:05:24 | 000,024,649 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650d.sys [2011/03/28 11:05:24 | 000,024,648 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650.sys [2011/03/28 11:05:23 | 000,256,512 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\devcon32.dll [2011/03/28 11:05:23 | 000,024,064 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\devldr32.exe [2011/03/28 11:05:23 | 000,020,928 | ---- | C] (Digital Networks, LLC) -- C:\WINDOWS\System32\dllcache\defpa.sys [2011/03/28 11:05:22 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc260usd.dll [2011/03/28 11:05:22 | 000,007,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ddsmc.sys [2011/03/28 11:05:21 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc240usd.dll [2011/03/28 11:05:21 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc210usd.dll [2011/03/28 11:05:21 | 000,063,208 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\dllcache\dc21x4.sys [2011/03/28 11:05:21 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc210_32.dll [2011/03/28 11:05:17 | 000,179,584 | ---- | C] (Mylex Corporation) -- C:\WINDOWS\System32\dllcache\dac2w2k.sys [2011/03/28 11:05:17 | 000,014,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dac960nt.sys [2011/03/28 11:05:16 | 000,117,760 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\d100ib5.sys [2011/03/28 11:05:02 | 000,093,952 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcwdm.sys [2011/03/28 11:05:02 | 000,048,640 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwrwdm.sys [2011/03/28 11:05:01 | 000,111,872 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcspud.sys [2011/03/28 11:05:01 | 000,072,832 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbwdm.sys [2011/03/28 11:05:01 | 000,003,584 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcosnt5.sys [2011/03/28 11:05:01 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbmidi.sys [2011/03/28 11:05:00 | 000,004,096 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\ctwdm32.dll [2011/03/28 11:05:00 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbase.sys [2011/03/28 11:04:58 | 000,096,256 | ---- | C] (Copyright (C) Creative Technology Ltd. 1994-2001) -- C:\WINDOWS\System32\dllcache\ctlsb16.sys [2011/03/28 11:04:58 | 000,003,712 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\ctljystk.sys [2011/03/28 11:04:57 | 000,006,912 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\ctlfacem.sys [2011/03/28 11:04:56 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\csamsp.dll [2011/03/28 11:04:56 | 000,042,112 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\crtaud.sys [2011/03/28 11:04:55 | 000,216,064 | ---- | C] (COMPAQ Inc.) -- C:\WINDOWS\System32\dllcache\cpscan.dll [2011/03/28 11:04:51 | 000,021,533 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\cpqndis5.sys [2011/03/28 11:04:51 | 000,014,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cpqarray.sys [2011/03/28 11:04:47 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\compbatt.sys [2011/03/28 11:04:46 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cnusd.dll [2011/03/28 11:04:46 | 000,039,936 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\dllcache\cnxt1803.sys [2011/03/28 11:04:45 | 000,006,656 | ---- | C] (CMD Technology, Inc.) -- C:\WINDOWS\System32\dllcache\cmdide.sys [2011/03/28 11:04:44 | 000,020,736 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\cmbp0wdm.sys [2011/03/28 11:04:44 | 000,013,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cmbatt.sys [2011/03/28 11:04:10 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\changer.sys [2011/03/28 11:04:06 | 000,015,423 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\ch7xxnt5.dll [2011/03/28 11:04:05 | 000,049,182 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem56n5.sys [2011/03/28 11:04:05 | 000,027,164 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce3n5.sys [2011/03/28 11:04:05 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem33n5.sys [2011/03/28 11:04:05 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem28n5.sys [2011/03/28 11:04:04 | 000,021,530 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce2n5.sys [2011/03/28 11:04:03 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cd20xrnt.sys [2011/03/28 11:04:00 | 000,046,108 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cben5.sys [2011/03/28 11:04:00 | 000,039,680 | ---- | C] (Silicom Ltd.) -- C:\WINDOWS\System32\dllcache\cb325.sys [2011/03/28 11:04:00 | 000,037,916 | ---- | C] (Fast Ethernet Controller Provider) -- C:\WINDOWS\System32\dllcache\cb102.sys [2011/03/28 11:03:50 | 000,244,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camext20.ax [2011/03/28 11:03:50 | 000,236,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camext20.dll [2011/03/28 11:03:50 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camext30.dll [2011/03/28 11:03:50 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camext30.ax [2011/03/28 11:03:49 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camdrv21.sys [2011/03/28 11:03:49 | 000,171,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camdrv30.sys [2011/03/28 11:03:49 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camexo20.dll [2011/03/28 11:03:49 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camexo20.ax [2011/03/28 11:03:48 | 000,314,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\camdro21.sys [2011/03/28 11:03:31 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bulltlp3.sys [2011/03/28 11:03:30 | 000,036,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthprint.sys [2011/03/28 11:03:30 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthusb.sys [2011/03/28 11:03:29 | 000,101,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthpan.sys [2011/03/28 11:03:29 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthmodem.sys [2011/03/28 11:03:29 | 000,031,529 | ---- | C] (BreezeCOM) -- C:\WINDOWS\System32\dllcache\brzwlan.sys [2011/03/28 11:03:29 | 000,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthenum.sys [2011/03/28 11:03:28 | 000,060,416 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brserwdm.sys [2011/03/28 11:03:28 | 000,011,008 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbmdm.sys [2011/03/28 11:03:28 | 000,010,368 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbscn.sys [2011/03/28 11:03:28 | 000,009,728 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brserif.dll [2011/03/28 11:03:27 | 000,039,552 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparwdm.sys [2011/03/28 11:03:27 | 000,005,120 | ---- | C] (Brother Industries,Ltd.) -- C:\WINDOWS\System32\dllcache\brscnrsm.dll [2011/03/28 11:03:26 | 000,003,168 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparimg.sys [2011/03/28 11:03:25 | 000,041,472 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfusb.dll [2011/03/28 11:03:25 | 000,032,256 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfrsmg.exe [2011/03/28 11:03:25 | 000,029,696 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmflpt.dll [2011/03/28 11:03:24 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\brmfcwia.dll [2011/03/28 11:03:24 | 000,015,360 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfbidi.dll [2011/03/28 11:03:24 | 000,003,968 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltup.sys [2011/03/28 11:03:23 | 000,012,800 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brevif.dll [2011/03/28 11:03:23 | 000,012,160 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltlo.sys [2011/03/28 11:03:23 | 000,002,944 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brfilt.sys [2011/03/28 11:03:22 | 000,019,456 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brbidiif.dll [2011/03/28 11:03:22 | 000,009,728 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brcoinst.dll [2011/03/28 11:03:18 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\binlsvc.dll [2011/03/28 11:03:18 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bdasup.sys [2011/03/28 11:03:17 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bdaplgin.ax [2011/03/28 11:03:15 | 000,054,271 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\dllcache\bcm42xx5.sys [2011/03/28 11:03:15 | 000,026,568 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\dllcache\bcm4e5.sys [2011/03/28 11:03:14 | 000,066,557 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\dllcache\bcm42u.sys [2011/03/28 11:03:14 | 000,036,128 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.sys [2011/03/28 11:03:14 | 000,014,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\battc.sys [2011/03/28 11:03:13 | 000,342,336 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.dll [2011/03/28 11:03:13 | 000,096,640 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\dllcache\b57xp32.sys [2011/03/28 11:03:10 | 000,036,992 | ---- | C] (Aztech Systems Ltd) -- C:\WINDOWS\System32\dllcache\aztw2320.sys [2011/03/28 11:02:55 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avc.sys [2011/03/28 11:02:55 | 000,036,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avcaudio.sys [2011/03/28 11:02:53 | 000,025,471 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv04nt5.dll [2011/03/28 11:02:53 | 000,017,279 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv10nt5.dll [2011/03/28 11:02:53 | 000,014,143 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv06nt5.dll [2011/03/28 11:02:53 | 000,011,359 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv02nt5.dll [2011/03/28 11:02:52 | 000,021,183 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\atv01nt5.dll [2011/03/28 11:02:51 | 000,516,768 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\dllcache\ativvaxx.dll [2011/03/28 11:02:50 | 000,032,768 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ativtmxx.dll [2011/03/28 11:02:50 | 000,023,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ativmvxx.ax [2011/03/28 11:02:50 | 000,009,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ativdaxx.ax [2011/03/28 11:02:43 | 000,063,488 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinxsxx.sys [2011/03/28 11:02:42 | 000,073,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atintuxx.sys [2011/03/28 11:02:42 | 000,031,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinxbxx.sys [2011/03/28 11:02:42 | 000,028,672 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinsnxx.sys [2011/03/28 11:02:42 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinttxx.sys [2011/03/28 11:02:41 | 000,104,960 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinrvxx.sys [2011/03/28 11:02:41 | 000,057,856 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinbtxx.sys [2011/03/28 11:02:41 | 000,052,224 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinraxx.sys [2011/03/28 11:02:41 | 000,014,336 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinpdxx.sys [2011/03/28 11:02:41 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atinmdxx.sys [2011/03/28 11:02:40 | 000,289,664 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atimpab.sys [2011/03/28 11:02:40 | 000,281,600 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atimtai.sys [2011/03/28 11:02:40 | 000,075,136 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atimpae.sys [2011/03/28 11:02:40 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\atievxx.exe [2011/03/28 11:02:39 | 000,382,592 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atidrab.dll [2011/03/28 11:02:39 | 000,268,160 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atidvai.dll [2011/03/28 11:02:39 | 000,137,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\atidrae.dll [2011/03/28 11:02:38 | 001,888,992 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\dllcache\ati3duag.dll [2011/03/28 11:02:38 | 000,870,784 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\dllcache\ati3d1ag.dll [2011/03/28 11:02:38 | 000,701,440 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2mtag.sys [2011/03/28 11:02:37 | 000,377,984 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2dvaa.dll [2011/03/28 11:02:37 | 000,327,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2mtaa.sys [2011/03/28 11:02:37 | 000,201,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2dvag.dll [2011/03/28 11:02:36 | 000,229,376 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati2cqag.dll [2011/03/28 11:02:36 | 000,036,463 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1tuxx.sys [2011/03/28 11:02:36 | 000,034,735 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1xsxx.sys [2011/03/28 11:02:36 | 000,029,455 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1xbxx.sys [2011/03/28 11:02:36 | 000,021,343 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1ttxx.sys [2011/03/28 11:02:35 | 000,063,663 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1rvxx.sys [2011/03/28 11:02:35 | 000,030,671 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1raxx.sys [2011/03/28 11:02:35 | 000,026,367 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1snxx.sys [2011/03/28 11:02:34 | 000,056,623 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1btxx.sys [2011/03/28 11:02:34 | 000,012,047 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1pdxx.sys [2011/03/28 11:02:34 | 000,011,615 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\dllcache\ati1mdxx.sys [2011/03/28 11:02:27 | 000,097,354 | ---- | C] (Bay Networks, Inc.) -- C:\WINDOWS\System32\dllcache\aspndis3.sys [2011/03/28 11:02:21 | 000,014,848 | ---- | C] (Advanced System Products, Inc.) -- C:\WINDOWS\System32\dllcache\asc3550.sys [2011/03/28 11:02:20 | 000,026,496 | ---- | C] (Advanced System Products, Inc.) -- C:\WINDOWS\System32\dllcache\asc.sys [2011/03/28 11:02:20 | 000,022,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asc3350p.sys [2011/03/28 11:02:05 | 000,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\apmbatt.sys [2011/03/28 11:02:04 | 000,043,008 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\dllcache\amdagp.sys [2011/03/28 11:02:04 | 000,036,224 | ---- | C] (ADMtek Incorporated.) -- C:\WINDOWS\System32\dllcache\an983.sys [2011/03/28 11:02:04 | 000,012,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\amsint.sys [2011/03/28 11:02:03 | 000,042,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\alim1541.sys [2011/03/28 11:02:03 | 000,016,969 | ---- | C] (AmbiCom, Inc.) -- C:\WINDOWS\System32\dllcache\amb8002.sys [2011/03/28 11:02:03 | 000,005,248 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\aliide.sys [2011/03/28 11:02:02 | 000,027,678 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\ali5261.sys [2011/03/28 11:02:02 | 000,026,624 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\alifir.sys [2011/03/28 11:02:01 | 000,056,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aic78xx.sys [2011/03/28 11:02:01 | 000,055,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aic78u2.sys [2011/03/28 11:02:01 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aha154x.sys [2011/03/28 11:01:55 | 000,044,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agpcpq.sys [2011/03/28 11:01:55 | 000,042,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agp440.sys [2011/03/28 11:01:54 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agcgauge.ax [2011/03/28 11:01:53 | 000,003,775 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv11nt5.dll [2011/03/28 11:01:53 | 000,003,711 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv09nt5.dll [2011/03/28 11:01:53 | 000,003,647 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv07nt5.dll [2011/03/28 11:01:53 | 000,003,135 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv08nt5.dll [2011/03/28 11:01:52 | 000,004,255 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv01nt5.dll [2011/03/28 11:01:52 | 000,003,967 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv02nt5.dll [2011/03/28 11:01:52 | 000,003,615 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\adv05nt5.dll [2011/03/28 11:01:47 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adpu160m.sys [2011/03/28 11:01:47 | 000,046,112 | ---- | C] (Adaptec, Inc ) -- C:\WINDOWS\System32\dllcache\adptsf50.sys [2011/03/28 11:01:46 | 000,010,880 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\admjoy.sys [2011/03/28 11:01:45 | 000,747,392 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8830.sys [2011/03/28 11:01:45 | 000,553,984 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8820.sys [2011/03/28 11:01:44 | 000,584,448 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8810.sys [2011/03/28 11:01:44 | 000,020,160 | ---- | C] (ADMtek Incorporated) -- C:\WINDOWS\System32\dllcache\adm8511.sys [2011/03/28 11:01:44 | 000,007,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adicvls.sys [2011/03/28 11:01:43 | 000,061,440 | ---- | C] (Color Flatbed Scanner) -- C:\WINDOWS\System32\dllcache\acerscad.dll [2011/03/28 11:01:42 | 000,297,728 | ---- | C] (Silicon Integrated Systems Corp.) -- C:\WINDOWS\System32\dllcache\ac97sis.sys [2011/03/28 11:01:42 | 000,084,480 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\ac97via.sys [2011/03/28 11:01:41 | 000,231,552 | ---- | C] (Acer Laboratories Inc.) -- C:\WINDOWS\System32\dllcache\ac97ali.sys [2011/03/28 11:01:41 | 000,096,256 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\ac97intc.sys [2011/03/28 11:01:41 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\abp480n5.sys [2011/03/28 11:01:40 | 000,462,848 | ---- | C] (Aureal Inc.) -- C:\WINDOWS\System32\dllcache\a3dapi.dll [2011/03/28 11:01:40 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\dllcache\a3d.dll [2011/03/28 11:01:34 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\61883.sys [2011/03/28 11:01:32 | 000,148,352 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvsm.sys [2011/03/28 11:01:31 | 000,689,216 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvs.dll [2011/03/28 11:01:28 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\1394vdbg.sys [2011/03/28 11:01:27 | 000,053,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\1394bus.sys [2011/03/28 11:00:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood [2011/03/28 11:00:21 | 000,109,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98swin.exe [2011/03/28 11:00:21 | 000,014,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98sadm.exe [2011/03/28 10:42:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\PriceGong [2011/03/28 10:41:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Freecorder [2011/03/28 10:41:48 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit [2011/03/28 10:41:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ConduitEngine [2011/03/28 10:41:38 | 000,000,000 | ---D | C] -- C:\Program Files\ConduitEngine [2011/03/28 10:40:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Freecorder [2011/03/28 10:40:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\FLVService [2011/03/28 10:40:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Freecorder [2011/03/28 10:39:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\Freecorder [2011/03/28 10:39:58 | 000,000,000 | ---D | C] -- C:\Program Files\Freecorder [2011/03/23 12:31:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2 [2011/03/23 11:22:11 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8 [2011/03/16 19:10:46 | 000,000,000 | -H-D | C] -- C:\$AVG [2011/03/16 18:14:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\AVG10 [2011/03/16 18:10:53 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files [2011/03/16 18:10:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011 [2011/03/16 18:09:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10 [2011/03/16 18:09:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG [2011/03/16 18:09:15 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2011/03/16 17:47:15 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2011/03/16 13:29:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2011/03/10 11:34:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData [2011/03/09 10:56:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\VS Revo Group [2011/03/09 10:56:03 | 000,027,064 | ---- | C] (VS Revo Group) -- C:\WINDOWS\System32\drivers\revoflt.sys [2011/03/09 10:56:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller Pro [2011/03/09 10:55:56 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group [6 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] [46 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011/03/30 15:24:21 | 000,000,410 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8BFB428B-A956-4BAC-B2D4-FDCAD16CEE5B}.job [2011/03/30 15:21:28 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe [2011/03/30 15:13:03 | 001,263,721 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip [2011/03/30 14:48:00 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2011/03/30 13:45:20 | 007,858,208 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\2 Winning Tattslotto Tickets.jpg [2011/03/30 13:09:46 | 013,496,453 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\3 Winning Tattslotto Tickets.jpg [2011/03/30 12:38:36 | 013,702,958 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\5 Winning Tattslotto Tickets 2.jpg [2011/03/30 12:07:08 | 011,507,368 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\5 Winning Tattslotto Tickets.jpg [2011/03/30 09:41:28 | 110,353,329 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm [2011/03/30 05:48:00 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2011/03/29 18:35:11 | 000,106,698 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm [2011/03/29 09:41:18 | 110,164,074 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm.old [2011/03/28 09:53:07 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011/03/28 09:53:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011/03/23 12:32:43 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb [2011/03/23 12:32:43 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb [2011/03/23 11:41:50 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/03/23 11:25:59 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2011/03/23 11:24:28 | 000,000,873 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf [2011/03/22 23:54:16 | 006,854,650 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Barcode Petrol Voucher.jpg [2011/03/22 11:26:19 | 002,157,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011/03/20 23:15:57 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts [2011/03/10 11:40:51 | 000,010,158 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\AVGInstLog.cab [2011/03/09 11:49:55 | 000,002,115 | ---- | M] () -- C:\WINDOWS\epplauncher.mif [6 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] [46 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2011/03/30 15:12:54 | 001,263,721 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip [2011/03/30 13:44:56 | 007,858,208 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\2 Winning Tattslotto Tickets.jpg [2011/03/30 13:09:18 | 013,496,453 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\3 Winning Tattslotto Tickets.jpg [2011/03/30 12:37:46 | 013,702,958 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\5 Winning Tattslotto Tickets 2.jpg [2011/03/30 12:06:35 | 011,507,368 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\5 Winning Tattslotto Tickets.jpg [2011/03/30 09:41:28 | 110,353,329 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm [2011/03/29 18:35:10 | 000,106,698 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm [2011/03/29 09:41:18 | 110,164,074 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm.old [2011/03/28 11:23:17 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxftplt.exe [2011/03/28 11:23:17 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxscnui.dll [2011/03/28 11:15:42 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisdecd.dll [2011/03/28 11:15:42 | 000,033,280 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisrndr.ax [2011/03/28 11:13:40 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdvbnp.ax [2011/03/28 11:08:51 | 000,165,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt53.dll [2011/03/28 11:08:51 | 000,093,696 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt42.dll [2011/03/28 11:08:50 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt34.dll [2011/03/28 11:08:50 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt33.dll [2011/03/28 11:08:49 | 000,083,968 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt21.dll [2011/03/28 11:07:48 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll [2011/03/28 11:02:51 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys [2011/03/28 11:02:51 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys [2011/03/28 11:02:50 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys [2011/03/28 11:02:50 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys [2011/03/28 11:02:49 | 000,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys [2011/03/28 11:02:49 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys [2011/03/28 11:02:49 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys [2011/03/28 11:02:48 | 000,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys [2011/03/28 11:02:43 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys [2011/03/28 11:02:39 | 000,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys [2011/03/28 10:44:23 | 000,000,410 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8BFB428B-A956-4BAC-B2D4-FDCAD16CEE5B}.job [2011/03/23 11:24:28 | 000,000,873 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf [2011/03/22 23:53:37 | 006,854,650 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Barcode Petrol Voucher.jpg [2011/03/10 11:40:51 | 000,010,158 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\AVGInstLog.cab [2010/09/05 04:10:46 | 000,000,013 | ---- | C] () -- C:\WINDOWS\popcinfo.dat [2010/07/10 06:04:40 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll [2010/06/18 14:17:34 | 000,000,155 | ---- | C] () -- C:\WINDOWS\viewer.ini [2010/06/18 14:17:27 | 000,000,083 | ---- | C] () -- C:\WINDOWS\artgalry.ini [2010/06/18 14:16:59 | 000,004,028 | ---- | C] () -- C:\WINDOWS\MSWORKS3.INI [2010/02/27 21:42:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI [2010/02/27 21:05:16 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2010/02/27 21:05:15 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat [2010/02/27 21:05:15 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat [2010/02/27 21:05:15 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat [2010/02/27 21:05:15 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat [2010/02/27 21:05:15 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat [2010/02/27 21:05:15 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat [2010/02/27 21:05:15 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat [2010/02/27 21:05:15 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat [2010/02/27 21:05:15 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat [2010/02/27 21:05:15 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat [2010/02/27 21:05:15 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat [2010/02/27 21:05:15 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat [2010/02/27 21:05:15 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat [2010/02/27 21:05:15 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat [2010/02/27 21:05:15 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat [2010/02/27 21:05:15 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat [2010/02/27 21:05:15 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat [2010/02/27 21:05:15 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat [2009/10/18 18:58:39 | 000,000,016 | ---- | C] () -- C:\WINDOWS\aebconfig.ini [2009/09/18 17:19:08 | 000,000,023 | ---- | C] () -- C:\WINDOWS\ovas.ini [2009/09/17 09:10:07 | 000,000,053 | ---- | C] () -- C:\WINDOWS\ArticleAssistant.ini [2009/09/05 19:25:10 | 000,000,381 | ---- | C] () -- C:\WINDOWS\EMSOFT.INI [2009/09/01 02:12:10 | 000,000,059 | ---- | C] () -- C:\WINDOWS\FAX.INI [2009/08/09 17:29:06 | 000,000,637 | ---- | C] () -- C:\WINDOWS\aasinst.ini [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll [2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe [2009/08/01 13:54:53 | 000,000,221 | ---- | C] () -- C:\WINDOWS\NCLogConfig.ini [2009/04/21 13:13:53 | 000,000,730 | ---- | C] () -- C:\WINDOWS\videoimp.ini [2009/04/21 13:13:45 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll [2009/04/21 13:13:33 | 000,000,021 | ---- | C] () -- C:\WINDOWS\VI_setup.ini [2009/04/21 13:11:22 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PI4_setup.ini [2009/04/21 13:10:08 | 000,118,784 | ---- | C] () -- C:\WINDOWS\ShowBmp.exe [2009/04/21 13:10:08 | 000,001,888 | ---- | C] () -- C:\WINDOWS\CA533A.INI [2009/04/21 13:10:08 | 000,001,325 | ---- | C] () -- C:\WINDOWS\Remove.ini [2009/04/13 20:37:45 | 000,001,450 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\filterclsid.dat [2009/03/22 09:43:41 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI [2009/03/04 13:36:00 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat [2009/03/04 12:30:54 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll [2009/02/15 21:18:11 | 000,029,184 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/02/03 19:30:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt [2009/02/03 19:03:00 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys [2008/09/18 17:01:08 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2008/09/15 23:57:18 | 000,000,281 | ---- | C] () -- C:\WINDOWS\EReg072.dat [2008/09/15 23:50:27 | 000,000,168 | ---- | C] () -- C:\WINDOWS\atoms.ini [2008/09/15 01:56:18 | 000,004,346 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2008/09/15 01:55:18 | 002,157,440 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2008/09/15 00:10:21 | 000,000,737 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2008/09/14 23:51:17 | 000,000,095 | ---- | C] () -- C:\WINDOWS\winamp.ini [2008/09/14 22:33:02 | 000,000,139 | ---- | C] () -- C:\WINDOWS\SYMGAMES.INI [2008/09/14 22:26:02 | 000,000,445 | ---- | C] () -- C:\WINDOWS\EntPack.dat [2008/09/14 22:26:02 | 000,000,045 | ---- | C] () -- C:\WINDOWS\EntPack.ini [2008/09/14 21:30:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2008/09/14 16:51:05 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll [2008/09/14 16:05:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2008/09/14 16:02:11 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2008/04/14 05:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin [2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2001/08/23 22:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2001/08/23 22:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2001/08/23 22:00:00 | 000,440,646 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2001/08/23 22:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2001/08/23 22:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2001/08/23 22:00:00 | 000,070,516 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2001/08/23 22:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2001/08/23 22:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2001/08/23 22:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2001/08/23 22:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini [1997/07/11 01:00:00 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\WRKGADM.EXE [1997/07/11 01:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL [1997/07/11 01:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL [1997/07/11 01:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL [1996/04/04 06:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %systemroot%\*. /mp /s > < c:\$recycle.bin\*.* /s > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-18 13:28:15 < MD5 for: AGP440.SYS > [2008/05/17 03:03:46 | 016,511,184 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys [2008/04/13 14:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys < MD5 for: ATAPI.SYS > [2008/05/17 03:03:46 | 016,511,184 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys [2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys [2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys < MD5 for: AUTOCHK.EXE > [2008/04/14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\cmdcons\autochk.exe [2008/04/14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\autochk.exe [2008/04/14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\dllcache\autochk.exe < MD5 for: BEEP.SYS > [2001/08/23 22:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\ERDNT\cache\beep.sys [2001/08/23 22:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\dllcache\beep.sys [2001/08/23 22:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys < MD5 for: EVENTLOG.DLL > [2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll [2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll [2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: EXPLORER.EXE > [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ERDNT\cache\explorer.exe [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe < MD5 for: IMM32.DLL > [2008/04/14 05:41:56 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=0DA85218E92526972A821587E6A8BF8F -- C:\WINDOWS\ERDNT\cache\imm32.dll [2008/04/14 05:41:56 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=0DA85218E92526972A821587E6A8BF8F -- C:\WINDOWS\system32\dllcache\imm32.dll [2008/04/14 05:41:56 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=0DA85218E92526972A821587E6A8BF8F -- C:\WINDOWS\system32\imm32.dll < MD5 for: KERNEL32.DLL > [2009/03/22 01:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\ERDNT\cache\kernel32.dll [2009/03/22 01:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\system32\dllcache\kernel32.dll [2009/03/22 01:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\system32\kernel32.dll [2008/04/14 05:41:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=C24B983D211C34DA8FCC1AC38477971D -- C:\WINDOWS\$NtUninstallKB959426$\kernel32.dll [2009/03/22 00:59:23 | 000,991,744 | ---- | M] (Microsoft Corporation) MD5=DA11D9D6ECBDF0F93436A4B7C13F7BEC -- C:\WINDOWS\$hf_mig$\KB959426\SP3QFE\kernel32.dll < MD5 for: MSWSOCK.DLL > [2008/06/21 04:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\ERDNT\cache\mswsock.dll [2008/06/21 04:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\system32\dllcache\mswsock.dll [2008/06/21 04:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\system32\mswsock.dll [2008/04/14 05:42:02 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=B4138E99236F0F57D4CF49BAE98A0746 -- C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll [2008/06/21 04:43:05 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=FCEE5FCB99F7C724593365C706D28388 -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\mswsock.dll < MD5 for: NDIS.SYS > [2008/04/14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys [2008/04/14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys [2008/04/14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys < MD5 for: NETLOGON.DLL > [2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll [2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll [2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll < MD5 for: NTFS.SYS > [2008/04/14 00:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ERDNT\cache\ntfs.sys [2008/04/14 00:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\dllcache\ntfs.sys [2008/04/14 00:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys [2004/08/04 00:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS < MD5 for: NTMSSVC.DLL > [2008/04/14 05:42:04 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\ERDNT\cache\ntmssvc.dll [2008/04/14 05:42:04 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\system32\dllcache\ntmssvc.dll [2008/04/14 05:42:04 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\system32\ntmssvc.dll < MD5 for: PROQUOTA.EXE > [2008/04/14 05:42:34 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\system32\dllcache\proquota.exe [2008/04/14 05:42:34 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\system32\proquota.exe < MD5 for: QMGR.DLL > [2008/04/14 05:42:04 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\ERDNT\cache\qmgr.dll [2008/04/14 05:42:04 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\dllcache\qmgr.dll [2008/04/14 05:42:04 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\qmgr.dll < MD5 for: SCECLI.DLL > [2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll [2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll [2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll < MD5 for: SFCFILES.DLL > [2008/04/14 05:42:06 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\ERDNT\cache\sfcfiles.dll [2008/04/14 05:42:06 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\system32\dllcache\sfcfiles.dll [2008/04/14 05:42:06 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\system32\sfcfiles.dll < MD5 for: SPOOLSV.EXE > [2010/08/18 00:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe [2010/08/18 00:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\ERDNT\cache\spoolsv.exe [2010/08/18 00:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe [2010/08/18 00:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe [2008/04/14 05:42:38 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=D8E14A61ACIt's been almost a month since we started on this. Is there any change in your computer?Yes SuperDave I think there has been a significant improvement. The drive has had a complete cleaning of unwanted programs and is running quite smoothly now. Viruses and potential threats have been removed and I feel that the drive/computer is once again reliable and safe to use for my banking. (This above all else is my greatest concern SuperDave.) We have discovered during this journey that the system restore did not resolve the problem. MSE is removed but still wont reinstall, Security center will not change the automatic updates configuration and Adobe update installs, still fail. AVG is running and updating regularly. Also that there is a problem with the Windows files and I dont have the CD for this build. (which just goes to show, me/others how important it is to back up your data.(Thank you Allan. See here for discussion/thread)). I have learned different operations, that before hand I would not have had the confidence to even try. I think that is what, you and CH ultimately are all about... teaching others and not just relying on the specialists and to build confidence to try things yourself always knowing that there is help at hand if I get stuck. I have the external drive now. Quote from: SuperDave on March 28, 2011, 12:50:56 PM From what you're telling me, there is a problem with some of the Windows files. If you made a copy of your harddrive, you could use it to restore your computer back to when the copy was made and you should be back in business. I will check with my buddy to see if there's anything else we can do. and with a little more help maybe I can restore my corrupted Windows file/s. I think my computer is as good and clean as we can make it. I am quite happy to start a new thread to restore the files, in a different forum if that is what you wish, because obviously your time to help one individual can be consuming when you can direct your expertise to others in need of your help. I can only say at this time "Thank you" for your continued assistance and support SuperDave. Thank you ImnoGuru. Ok. You may be able to remove MSE with this tool. Revo Uninstaller Malware is often stored in System Restore so that every time you use System Restore you re-infect the computer. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 1463. |
Solve : memory stick, external HD errors from infection?? |
|
Answer» I regularly use memory sticks and and external harddrive. Yesterday when I plugged in the external hard drive, I tried to open the drive in My COMPUTER. I get the following error message. Error loading setup 50045.fon The SPECIFIED module could not be FOUND. I RAN Malwarebytes and it did find a couple of items. I rebooted the computer and same thing. I plugged in a memory stick and it has the same error too. I re-ran MBAM, and it found a few things while scanning the external hard drive and the memory stick. Is this from one of the infections or something ELSE? |
|
| 1464. |
Solve : Malware Help Needed!? |
|
Answer» I've fixed the problem, what next?Please tell me how your computer is running. Any other issues?Running much better than it was but still seems slow when i go to access programs. Once i pull up the internet, no issues there. Just if i step away for awhile and then try to click on something, the response time is slow. Ok. Let's clean up. I have some instructions at the bottom for a slow computer.
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how OFTEN you clean temp files, execution time should be ANYWHERE from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************* Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet SECURITY addon for your browser. It will KEEP you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Thank you Dave for all your help. Seems to be doing much better. You're welcome, Katman. I will lock this thread. If you need it opened, please pm me. |
|
| 1465. |
Solve : After running superantispyware my pc won't boot OS and blue screens!? |
|
Answer» Ok, that will take me a few days. Will you still be here? I should probably have it done by Sunday at the latest. I work during the day, that's why it will take so long. Quote Will you still be here?Unless the Grim Reaper gets me.All right, well I ran the Dr. Web Live CD and the BitDefender bootable USB. Both of them found viruses/spyware and I deleted/cleaned all of them. Unfortunately, my system still does not boot in regular or safe mode! I think I am MISSING a system file or something that tells my computer that an OS is installed. That's my best guess at least. PS: thanks for waiting! Some google searching showed me this website, which seems to confirm what I am suspecting. I think that Superantispyware did what this website says AVG does. I am missing a vital file for my computer to run which needs to be located and replaced. I haven't followed any other help sites or anything, I am just looking at information. Let me know what you think and thanks! http://mikemstech.blogspot.com/2012/01/troubleshooting-0xc0000135.htmlPlease tell me what happens when you boot with the OS disk. When I boot the OS disk it goes to the install screen and I click the "repair" option in the bottom left. The next screen says "choose your OS" and has a little white box, but there is nothing in the box! There is no OS or anything. The other option in this screen is to "search for drivers." This allows me to search through my hard drive for a file, but I don't know which file I am supposed to find that will show that I have an OS installed. When I was backing up my files I could navigate to the windows folder and look at all the system files I had there, so I know that my OS is still installed. A google search for this problem showed that a COMMON cause of this problem is missing a DLL or some other system file so my computer/OS disk no longer RECOGNIZES the OS. I really do not want to format and reinstall! When I try to boot into regular or safe mode I still get the same blue screen mentioned in my first post and the article I linked in my last post.Here's a rescue disk that will let you boot your computer,run a scan and post the log. You can boot your computer again using this disk and save your important documents. We are going to be using a Windows Recovery Environment to help disinfect the system so it may boot again. Download the OTLPE Standard REATOGO Windows Recovery Environment.
OTL logfile created on: 1/30/2012 9:20:38 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE 64bit-Windows 7 Ultimate Service Pack 1 (Version = 6.1.7601) - Type = System Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free Paging file location(s): c:\pagefile.sys 9216 18432 [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86) Drive C: | 100.00 Mb Total Space | 73.82 Mb Free Space | 73.82% Space Free | Partition Type: NTFS Drive D: | 931.50 Gb Total Space | 312.03 Gb Free Space | 33.50% Space Free | Partition Type: NTFS Drive E: | 931.41 Gb Total Space | 104.63 Gb Free Space | 11.23% Space Free | Partition Type: NTFS Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011/11/09 18:40:36 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto] -- E:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE) SRV:64bit: - [2009/11/26 01:47:36 | 000,665,320 | ---- | M] () [Auto] -- E:\Windows\System32\atwtusb.exe -- (WTService) SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\appmgmts.dll -- (AppMgmt) SRV - [2011/12/15 04:39:18 | 000,008,192 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\srvany.exe -- (KMService) SRV - [2011/09/02 08:29:30 | 002,152,152 | ---- | M] (Lavasoft Limited) [On_Demand] -- E:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service) SRV - [2011/08/03 06:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) SRV - [2011/08/03 05:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2011/07/12 19:27:09 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011/06/06 14:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2010/03/18 16:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2007/09/21 13:02:02 | 000,393,216 | ---- | M] (NetGear) [Auto] -- E:\Windows\SysWOW64\WN311BFCS.exe -- (WN311BFCS) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011/08/01 17:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\point64.sys -- (Point64) DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- E:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV) DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- E:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL) DRV:64bit: - [2011/05/10 04:41:27 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2011/01/19 20:47:18 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto] -- E:\Windows\System32\drivers\cpuz135_x64.sys -- (cpuz135) DRV:64bit: - [2010/11/20 06:07:06 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/20 06:03:44 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:64bit: - [2010/04/27 18:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid) DRV:64bit: - [2010/04/27 18:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum) DRV:64bit: - [2010/04/27 16:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore) DRV:64bit: - [2010/04/27 16:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmFilter.sys -- (WmFilter) DRV:64bit: - [2010/04/03 05:31:50 | 003,058,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WN311B64.SYS -- (NTG43XX) DRV:64bit: - [2009/08/26 00:15:10 | 000,007,552 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand] -- E:\Windows\System32\drivers\walvhid.sys -- (vhidmini) DRV:64bit: - [2009/07/08 03:45:50 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BCMWL664.SYS -- (BCM43XX) DRV:64bit: - [2009/07/01 14:20:56 | 000,339,744 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\nvmf6264.sys -- (NVNET) DRV:64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009/06/10 15:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\nvm62x64.sys -- (NVENETFD) DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/05/14 11:26:24 | 000,015,416 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) DRV:64bit: - [2009/03/08 06:16:14 | 000,007,680 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand] -- E:\Windows\System32\drivers\moufiltr.sys -- (moufiltr) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Administrator_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Curtis_&_Andrea_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = IE - HKU\Curtis_&_Andrea_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us IE - HKU\Curtis_&_Andrea_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 E4 5B BA 76 D0 CB 01 [binary data] IE - HKU\Curtis_&_Andrea_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.com/" FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.260.0 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6 FF - prefs.js..extensions.enabledItems: {1f91cde0-c040-11da-a94d-0800200c9a66}:4.1 FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3 FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2 FF - prefs.js..extensions.enabledItems: {2e61e246-e640-4c56-b1ed-f146dbed48cd}:1.2.1 FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/FlashPlayer: E:\Windows\System32\Macromed\Flash\NPSWF64_11_1_102.dll () FF:64bit: - HKLM\Software\MozillaPlugins\microsoft.com/GENUINE: File not found FF:64bit: - HKLM\Software\MozillaPlugins\microsoft.com/OfficeAuthz,version=14.0: E:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\Wow6432Node\MozillaPlugins\adobe.com/ShockwavePlayer: E:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\checkpoint.com/FFApi: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\divx.com/DivX Browser Plugin,version=1.0.0: E:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF - HKLM\Software\Wow6432Node\MozillaPlugins\divx.com/DivX VOD Helper,version=1.0.0: E:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\google.com/npPicasa3,version=3.0.0: E:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/GENUINE: File not found FF - HKLM\Software\Wow6432Node\MozillaPlugins\Microsoft.com/NpCtrl,version=1.0: E:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/OfficeAuthz,version=14.0: E:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/SharePoint,version=14.0: E:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/WLPG,version=15.4.3502.0922: E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\microsoft.com/WLPG,version=15.4.3508.1109: E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\nvidia.com/3DVision: E:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\nvidia.com/3DVisionStreaming: E:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: E:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.) FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/04/26 14:45:10 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/04/26 14:45:10 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/02 12:39:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/15 16:17:27 | 000,000,000 | ---D | M] [2011/02/19 15:52:41 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Extensions [2011/12/25 00:40:16 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Firefox\Profiles\h1x3w93d.default\extensions [2011/12/25 00:40:16 | 000,000,000 | ---D | M] (DownloadHelper) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Firefox\Profiles\h1x3w93d.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2011/05/05 18:19:22 | 000,000,000 | ---D | M] (No name found) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Firefox\Profiles\h1x3w93d.default\extensions\nostmp [2011/03/12 15:16:28 | 000,000,000 | ---D | M] (Personas) -- E:\Users\Curtis & Andrea\AppData\Roaming\Mozilla\Firefox\Profiles\h1x3w93d.default\extensions\[email protected] [2011/11/09 20:58:15 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions File not found (No name found) -- () (No name found) -- E:\USERS\CURTIS & ANDREA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\H1X3W93D.DEFAULT\EXTENSIONS\{1F91CDE0-C040-11DA-A94D-0800200C9A66}.XPI [2012/01/02 12:39:40 | 000,121,816 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011/09/10 11:57:33 | 000,466,944 | ---- | M] (Catalina Marketing Corporation) -- E:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll [2011/05/04 06:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2011/10/04 01:01:42 | 000,002,252 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2011/11/09 20:58:14 | 000,002,040 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml O1 HOSTS File: ([2012/01/15 18:41:54 | 000,000,098 | ---- | M]) - E:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - E:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - E:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O4:64bit: - HKLM..\Run: [IntelliPoint] E:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation) O4:64bit: - HKLM..\Run: [MacroKeyManager] E:\Windows\System32\WTMKM.exe () O4:64bit: - HKLM..\Run: [RtHDVCpl] E:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [Start WingMan Profiler] E:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.) O4 - HKLM..\Run: [amd_dc_opt] E:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD) O4 - HKLM..\Run: [AS00_WN311B] E:\Program Files\NETGEAR\WN311B\Utility\WN311B.exe (NetGear) O4 - HKLM..\Run: [DivXUpdate] E:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKU\UpdatusUser_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\UpdatusUser_ON_E..\RunOnce: [mctadmin] File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKU\Administrator_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Administrator_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKU\Administrator_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Administrator_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 0 O7 - HKU\Curtis_&_Andrea_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\Curtis_&_Andrea_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKU\Curtis_&_Andrea_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\Curtis_&_Andrea_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\Curtis_&_Andrea_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1 O7 - HKU\LocalService_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\LocalService_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKU\NetworkService_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\NetworkService_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKU\systemprofile_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\systemprofile_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present O7 - HKU\UpdatusUser_ON_E\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\UpdatusUser_ON_E\Software\Policies\Microsoft\Internet Explorer\restrictions present O8 - Extra context menu item: Add to Google Photos Screensa&ver - E:\Windows\SysWow64\GPhotos.scr (Google Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (lsdelete) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found O37:64bit: - HKLM\...com [ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [ = exefile] -- "%1" %* O37 - HKLM\...com [ = ComFile] -- "%1" %* O37 - HKLM\...exe [ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/01/15 18:41:52 | 000,000,000 | ---D | C] -- E:\_OTL [2012/01/14 18:47:53 | 000,000,000 | ---D | C] -- E:\.Trash-999 [3 E:\Windows\*.tmp files -> E:\Windows\*.tmp -> ] [1 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] [1 E:\Windows\System32\drivers\*.tmp files -> E:\Windows\System32\drivers\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/01/24 00:43:42 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat [2012/01/24 00:43:35 | 535,683,071 | -HS- | M] () -- E:\hiberfil.sys [2012/01/02 17:41:09 | 000,000,064 | ---- | M] () -- E:\Windows\SysWow64\rp_stats.dat [2012/01/02 17:41:09 | 000,000,044 | ---- | M] () -- E:\Windows\SysWow64\rp_rules.dat [2012/01/02 16:09:31 | 000,014,224 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/01/02 16:09:31 | 000,014,224 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/01/02 16:06:50 | 000,675,566 | ---- | M] () -- E:\Windows\System32\perfh009.dat [2012/01/02 16:06:50 | 000,442,594 | ---- | M] () -- E:\Windows\System32\perfh012.dat [2012/01/02 16:06:50 | 000,431,000 | ---- | M] () -- E:\Windows\System32\perfh011.dat [2012/01/02 16:06:50 | 000,415,426 | ---- | M] () -- E:\Windows\System32\prfh0404.dat [2012/01/02 16:06:50 | 000,398,324 | ---- | M] () -- E:\Windows\System32\prfh0804.dat [2012/01/02 16:06:50 | 000,126,238 | ---- | M] () -- E:\Windows\System32\perfc011.dat [2012/01/02 16:06:50 | 000,126,238 | ---- | M] () -- E:\Windows\System32\perfc009.dat [2012/01/02 16:06:50 | 000,124,526 | ---- | M] () -- E:\Windows\System32\perfc012.dat [2012/01/02 16:06:50 | 000,124,098 | ---- | M] () -- E:\Windows\System32\prfc0804.dat [2012/01/02 16:06:50 | 000,119,184 | ---- | M] () -- E:\Windows\System32\prfc0404.dat [2012/01/02 14:19:55 | 001,008,141 | ---- | M] () -- E:\Users\Curtis & Andrea\Desktop\rkill.com [2012/01/02 14:17:40 | 001,578,288 | ---- | M] (Kaspersky Lab ZAO) -- E:\Users\Curtis & Andrea\Desktop\TDSSKiller.exe [2012/01/02 14:11:46 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/01/02 13:52:30 | 000,002,056 | ---- | M] () -- E:\Users\Curtis & Andrea\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2012/01/02 13:51:22 | 000,004,976 | -HS- | M] () -- E:\Users\Curtis & Andrea\AppData\Local\381wif72x512qf62m5wdo2u735427n12o0160 [2012/01/02 13:51:22 | 000,004,976 | -HS- | M] () -- E:\ProgramData\381wif72x512qf62m5wdo2u735427n12o0160 [3 E:\Windows\*.tmp files -> E:\Windows\*.tmp -> ] [1 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ] [1 E:\Windows\System32\drivers\*.tmp files -> E:\Windows\System32\drivers\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/01/02 14:19:57 | 001,008,141 | ---- | C] () -- E:\Users\Curtis & Andrea\Desktop\rkill.com [2012/01/02 12:53:15 | 000,004,976 | -HS- | C] () -- E:\Users\Curtis & Andrea\AppData\Local\381wif72x512qf62m5wdo2u735427n12o0160 [2012/01/02 12:53:15 | 000,004,976 | -HS- | C] () -- E:\ProgramData\381wif72x512qf62m5wdo2u735427n12o0160 [2011/12/31 00:19:01 | 000,001,674 | -HS- | C] () -- E:\Users\Curtis & Andrea\AppData\Local\s88mw2s78q [2011/12/31 00:19:01 | 000,001,674 | -HS- | C] () -- E:\ProgramData\s88mw2s78q [2011/12/28 04:11:47 | 000,002,052 | -HS- | C] () -- E:\Users\Curtis & Andrea\AppData\Local\le2sw25wpe16000eq3d62u3e361d6d868423f5o4g3goj [2011/12/28 04:11:47 | 000,002,052 | -HS- | C] () -- E:\ProgramData\le2sw25wpe16000eq3d62u3e361d6d868423f5o4g3goj [2011/12/26 22:36:14 | 000,009,530 | -HS- | C] () -- E:\ProgramData\dd36rm417bn1dh83kl0kjq27l5kl3207o3jv40n0318j3 [2011/12/12 20:35:01 | 000,008,988 | -HS- | C] () -- E:\ProgramData\nyvwwc4t3eyg0eco4bml8d514w2m [2011/12/11 11:50:50 | 000,010,930 | -HS- | C] () -- E:\ProgramData\kkkyie8v2dkr8ipq7ofa1g307g6b [2011/09/28 19:44:14 | 000,179,271 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat [2011/08/03 05:31:54 | 000,311,912 | ---- | C] () -- E:\Windows\SysWow64\nvStreaming.exe [2011/06/27 14:44:15 | 000,256,512 | ---- | C] () -- E:\Windows\PEV.exe [2011/06/27 14:44:15 | 000,208,896 | ---- | C] () -- E:\Windows\MBR.exe [2011/06/27 14:44:15 | 000,098,816 | ---- | C] () -- E:\Windows\sed.exe [2011/06/27 14:44:15 | 000,080,412 | ---- | C] () -- E:\Windows\grep.exe [2011/06/27 14:44:15 | 000,068,096 | ---- | C] () -- E:\Windows\zip.exe [2011/06/03 19:41:12 | 000,155,745 | ---- | C] () -- E:\Windows\SysWow64\installservice.exe [2011/05/24 01:49:53 | 000,085,504 | ---- | C] () -- E:\Windows\SysWow64\ff_vfw.dll [2011/05/02 16:40:30 | 000,000,064 | ---- | C] () -- E:\Windows\SysWow64\rp_stats.dat [2011/05/02 16:40:30 | 000,000,044 | ---- | C] () -- E:\Windows\SysWow64\rp_rules.dat [2011/04/29 03:19:00 | 000,004,096 | ---- | C] () -- E:\Windows\d3dx.dat [2011/04/19 15:23:11 | 000,008,229 | ---- | C] () -- E:\Windows\aiptbl.ini [2011/02/23 21:06:35 | 000,061,440 | ---- | C] () -- E:\Windows\SysWow64\FDI.exe [2011/02/23 20:28:56 | 000,252,928 | ---- | C] () -- E:\Windows\SysWow64\DShowRdpFilter.dll [2011/02/19 22:42:19 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat [2011/02/19 21:44:01 | 000,008,192 | ---- | C] () -- E:\Windows\SysWow64\srvany.exe [2011/02/19 17:54:26 | 000,640,957 | ---- | C] () -- E:\Windows\unins000.exe [2011/02/19 17:54:26 | 000,000,805 | ---- | C] () -- E:\Windows\unins000.dat [2011/02/19 17:06:06 | 000,073,220 | ---- | C] () -- E:\Windows\SysWow64\EPPICPrinterDB.dat [2011/02/19 17:06:06 | 000,031,053 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern131.dat [2011/02/19 17:06:06 | 000,029,114 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern1.dat [2011/02/19 17:06:06 | 000,027,417 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern121.dat [2011/02/19 17:06:06 | 000,021,021 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern3.dat [2011/02/19 17:06:06 | 000,015,670 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern5.dat [2011/02/19 17:06:06 | 000,013,280 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern2.dat [2011/02/19 17:06:06 | 000,010,673 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern4.dat [2011/02/19 17:06:06 | 000,004,943 | ---- | C] () -- E:\Windows\SysWow64\EPPICPattern6.dat [2011/02/19 17:06:06 | 000,001,140 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_PT.dat [2011/02/19 17:06:06 | 000,001,140 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_BP.dat [2011/02/19 17:06:06 | 000,001,137 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_ES.dat [2011/02/19 17:06:06 | 000,001,130 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_FR.dat [2011/02/19 17:06:06 | 000,001,130 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_CF.dat [2011/02/19 17:06:06 | 000,001,104 | ---- | C] () -- E:\Windows\SysWow64\EPPICPresetData_EN.dat [2011/02/19 17:06:06 | 000,000,097 | ---- | C] () -- E:\Windows\SysWow64\PICSDK.ini [2011/02/19 15:43:12 | 002,870,032 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI [2011/02/19 15:39:01 | 000,921,665 | ---- | C] () -- E:\Windows\SysWow64\msvcrt-ruby18.dll [2011/02/19 15:39:01 | 000,271,264 | ---- | C] () -- E:\Windows\SysWow64\vbrun100.dll [2011/02/19 15:39:01 | 000,210,944 | ---- | C] () -- E:\Windows\SysWow64\msvcrt10.dll [2011/02/19 15:39:01 | 000,027,136 | ---- | C] () -- E:\Windows\SysWow64\pythonw.exe [2011/02/19 15:39:01 | 000,026,624 | ---- | C] () -- E:\Windows\SysWow64\python.exe [2011/02/19 15:39:01 | 000,020,537 | ---- | C] () -- E:\Windows\SysWow64\rubyw.exe [2011/02/19 15:39:01 | 000,020,536 | ---- | C] () -- E:\Windows\SysWow64\ruby.exe [2009/11/10 22:28:02 | 000,129,768 | ---- | C] () -- E:\Windows\RmTablet.exe [2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat [2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT [2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat [2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin [2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\SysWow64\BWContextHandler.dll [2009/07/13 17:25:04 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll [2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll [2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat ========== LOP Check ========== [2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data [2011/05/29 01:27:26 | 000,000,000 | ---D | M] -- E:\ProgramData\AVAST Software [2011/02/19 16:42:50 | 000,000,000 | ---D | M] -- E:\ProgramData\CheckPoint [2011/09/09 15:15:36 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite [2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop [2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents [2011/07/05 21:15:40 | 000,000,000 | ---D | M] -- E:\ProgramData\eMule [2011/02/19 17:05:59 | 000,000,000 | ---D | M] -- E:\ProgramData\EPSON [2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites [2011/05/25 19:18:20 | 000,000,000 | ---D | M] -- E:\ProgramData\IObit [2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu [2011/04/19 15:23:48 | 000,000,000 | ---D | M] -- E:\ProgramData\Tablet [2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates [2011/12/17 03:56:28 | 000,000,000 | ---D | M] -- E:\ProgramData\Zoom Player [2011/07/27 14:07:16 | 000,032,544 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > Computer still blue screens with same error upon boot and also with safe mode!It appears that your OS is located on the E drive and there is only 11% free space on that drive. Windows requires at least 15% free space to operate which could be one of your problems. This is also why it cannot find the OS when you boot with the OS disk. * Open OTL * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window. CODE: [Select]:OTL :Files E:\ProgramData\nyvwwc4t3eyg0eco4bml8d514w2m E:\ProgramData\kkkyie8v2dkr8ipq7ofa1g307g6b :COMMANDS [resethosts] [purity] [start explorer] * Click Run Fix * OTLI2 may ask to reboot the machine. Please do so if asked. * Click OK * A report will open. Copy and Paste that report in your next reply. ************************************************************* Please try re-booting in Normal Mode after doing the above. Sorry for the delay, I am still really busy. I have two jobs, and one of them is high school teacher, so I have grading and WHATNOT to do when I get home. I really appreciate your help, and I'm sorry to make you wait like this. Here is the log from the fix you gave me. I also deleted some games and movies on my hard drive that I didn't need in the hopes of clearing some more space for the OS. ========== OTL ========== ========== FILES ========== E:\ProgramData\nyvwwc4t3eyg0eco4bml8d514w2m moved successfully. E:\ProgramData\kkkyie8v2dkr8ipq7ofa1g307g6b moved successfully. ========== COMMANDS ========== E:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTLPE by OldTimer - Version 3.1.48.0 log created on 02042012_175645 Booting normally and in safe mode still give the same bluescreen, and the windows CD still doesn't detect the OS. Quote am still really busy. I have two jobs, and one of them is high school teacher, so I have grading and whatnot to do when I get home. I really appreciate your help, and I'm sorry to make you wait like this.No need to apologize. Your job comes first especially in these trying times. I'm here every day. Quote and the windows CD still doesn't detect the OS.Download BlueScreenView to your desktop. BlueScreenView unzip downloaded file and double click on BlueScreenView.exe to run the program. when scanning is done, go to EDIT - Select All Go to FILE - SAVE Selected Items, and save the report as BSOD.txt Open BSOD.txt in Notepad, copy all of the content, and paste it into your next reply. How am I supposed to run it? I tried running through the OTPLE startup disc, but it didn't do anything.Unfortunately, we've come to the point where you should boot your computer using the OTLPE rescue disk and save all your important data to memory sticks or DVD's and prepare to reinstall your OS.SIGH, okay, well thank you for all your help. Quote from: CuNaMo on February 05, 2012, 03:03:37 PM SIGH, okay, well thank you for all your help.You're welcome. Sometimes you win some and sometimes you lose. |
|
| 1466. |
Solve : Website has been hacked again? |
|
Answer» I have a website hosted on Startlogic and it keeps getting hacked. I have changed my password and deleted all files and replaced with new ones that I have on my external hd. When trying to open my website Advast blocked it from opening so I ran a scan through http://sitecheck.sucuri.net. (Log also attached). But even after deleting all files it still SCANS with the same results. Is there anyway for me to find these and remove them without paying to have it done. Also I ran a scan on my computer Windows 8.1 with MALWAREBYTES Anti-Malware and the log is also attached. I wasn't able to download the other two as requested. One wouldn't allow me to download and the other was a dead link. Any help would be greatly appreciated. Startlogic is only suggesting hiring sitelock. |
|
| 1467. |
Solve : Game.EXE Bad Image Error? |
|
Answer» Hi |
|
| 1468. |
Solve : Recently had a RUNDLL malware.? |
|
Answer» Hi I had a RUNDLL problem that said it was missing. Then i tried the forums guide on how to remove malware. It hasn't been showing but I am not sure if it is good.
---------- Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.Hi thanks for the help, much appreciation. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:40:19 PM, on 25/08/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe C:\WINDOWS\system32\dllhost.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Xfire\xfire.exe C:\WINDOWS\explorer.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=1607 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file) O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user') O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Download with ImTOO YouTube Video Converter - C:\Program Files\ImTOO\YouTube Video Converter\upod_link.HTM O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim .exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.trymedia.com (HKLM) O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cab O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- End of file - 10568 bytes [recovering disk space -- attachment deleted by admin] Download the Norton Removal Tool (SymNRT) to your Desktop. Once downloaded please close ALL open browsers, also save any work because this may require a restart.
Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad.
Code: [Select]KillAll:: Folder:: C:\Program Files\AskSBar RENV:: ----a-w 67,112 2008-02-22 20:00:08 C:\Program Files\AIM\aim .exe ----a-w 180,269 2008-02-22 19:59:59 C:\Program Files\Common Files\Real\Update_OB\realsched .exe ----a-w 692,224 2008-02-22 20:00:09 C:\Program Files\Creative\Sync Manager Unicode\CTSyncU .exe ----a-w 1,077,248 2008-02-22 19:59:52 C:\Program Files\DISC\DISCover .exe ----a-w 61,440 2008-02-22 19:59:52 C:\Program Files\DISC\DiscUpdMgr .exe ----a-w 249,856 2008-02-22 19:59:53 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe ----a-w 49,152 2008-02-22 19:59:52 C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08 .exe ----a-w 90,112 2008-02-22 19:59:52 C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe ----a-w 139,264 2008-02-22 19:59:50 C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe ----a-w 83,608 2008-02-22 19:59:55 C:\Program Files\Java\jre1.6.0_01\bin\jusched .exe ----a-w 1,694,208 2008-02-22 20:00:03 C:\Program Files\Messenger\msmsgs .exe ----a-w 282,624 2008-02-22 19:59:59 C:\Program Files\QuickTime\qttask .exe ----a-w 1,266,936 2008-02-22 20:00:11 C:\Program Files\Steam\Steam .exe ----a-w 3,477,504 2008-02-22 20:00:13 C:\Program Files\Veoh Networks\Veoh\VeohClient .exe ----a-w 438,359 2008-02-22 19:59:54 C:\Program Files\verizon\SmartBridge\MotiveSB .exe ----a-w 663,552 2008-02-22 19:59:55 C:\WINDOWS\CREATOR\Remind_XP .exe ----a-w 208,952 2008-02-22 19:59:56 C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE ----a-w 44,032 2008-02-22 19:59:57 C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE ----a-w 237,568 2008-02-22 19:59:53 C:\WINDOWS\SMINST\RECGUARD .EXE ----a-w 15,360 2008-02-22 20:00:05 C:\WINDOWS\system32\ctfmon .exe ----a-w 77,824 2008-02-22 19:59:50 C:\WINDOWS\system32\hkcmd .exe ----a-w 118,784 2008-02-22 19:59:50 C:\WINDOWS\system32\igfxpers .exe ----a-w 59,392 2008-02-22 19:59:57 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst .exe ----a-w 455,168 2008-02-22 19:59:58 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP .EXE Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"=- [-HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\[u]0[/u]49b147a] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM07a827e6] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dot1XCfg] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule12] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick combofix's window while it is running. That may cause your system to freezeHey I've attached the log because it was too large and exceeded the maximum allowed length. [recovering disk space -- attachment deleted by admin]Looking better. You may want to look here and get your antivirus updated to the latest supported version. AVG 7.5 Free ends 31st August 2008 ---------- Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. Download JavaRa to your Desktop and unzip it to its own folder.
----------
---------- How is everything now? |
|
| 1469. |
Solve : Internet connection issue (Network cable unplugged/enabled)...Virus the cause?? |
|
Answer» So here is the deal |
|
| 1470. |
Solve : trojan-zlob? |
|
Answer» I seem to have BECOME infected with a trojan! After running the prerequisites, Webroot says I'm clean but would like some confirmation... |
|
| 1471. |
Solve : take a look please? |
|
Answer» Did a stupid thing yesterday , tried downloading atorrent software from mininova which badly infected my computer to the extent that i had to reinstall windows.
---------- Use the In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator. Click on SCAN NOW Click on the Accept button and install any components it needs.
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.scan report oddjob [recovering disk space -- attachment deleted by admin]You will end up destroying your Hard Drive using cracked software. Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Now download The Avenger by Swandog46 and save it to your Desktop.
Files to delete: C:\Documents and Settings\Mike\Desktop\Anti Virus\VundoFix.exe C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Outlook\outlook.pst C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\CRACK\RegCure.exe C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\RegCure 1.5.0.0 Trial.exe C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Mcafee 2008\McAfee Total Protection 2008 (Retail) - HeartBug\CDSetup.exe C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Mcafee 2008\McAfee Total Protection 2008 (Retail) - HeartBug\CDSetup.exe C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe
[recovering disk space -- attachment deleted by admin]Please do the following: 1. Download this diagnostics tool MGADiag.exe and save this to your Desktop. 2. Double-click on MGADiag.exe and click Continue 3. When the program has finished, click on Copy 4. Post the results in your next reply. Quote You will end up destroying your Hard Drive using cracked software.Thanks for your advice i think i have learnt that lesson btw the key board issue i have resolved in languages and region cant do a copy of the report sshot oddjob [recovering disk space -- attachment deleted by admin]
C:\Documents and Settings\Mike\Desktop\Anti Virus\VundoFix.exe C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Outlook\outlook.pst C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\CRACK\RegCure.exe C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\RegCure 1.5.0.0 Trial.exe C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Mcafee 2008\McAfee Total Protection 2008 (Retail) - HeartBug\CDSetup.exe C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Mcafee 2008\McAfee Total Protection 2008 (Retail) - HeartBug\CDSetup.exe C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe EmptyTemp [start explorer]
---------- Now run a new HijackThis scan and post the log.where are we going with this, am i infected? Explorer killed successfully File/Folder C:\Documents and Settings\Mike\Desktop\Anti Virus\VundoFix.exe not found. File/Folder C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Outlook\outlook.pst not found. File/Folder C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\CRACK\RegCure.exe not found. File/Folder C:\Documents and Settings\Mike Carney\My Documents\Downloads\RegCure 1.5.0.0 + Crack + Latest Version + Keygens\RegCure 1.5.0.0 Trial.exe not found. File/Folder C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Mcafee 2008\McAfee Total Protection 2008 (Retail) - HeartBug\CDSetup.exe not found. < C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe > File/Folder C:\Documents and Settings\Mike Carney\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe not found. File/Folder C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Mcafee 2008\McAfee Total Protection 2008 (Retail) - HeartBug\CDSetup.exe not found. < C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe > File/Folder C:\Documents and Settings\Mike.ATLAS-FEA1386A2\My Documents\Downloads From Mininova\Nero 8 Ultra Edition 8.3.2.1 New KeyGen + Activation + Serials[Full Activated]\Nero-8.3.2.1_eng_f.u.l.l\Nero-8.3.2.1_eng_trial_2.exe not found. < EmptyTemp > File delete failed. C:\DOCUME~1\MIKE~1.ATL\LOCALS~1\Temp\~DF2475.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\MIKE~1.ATL\LOCALS~1\Temp\~DF2489.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\MIKE~1.ATL\LOCALS~1\Temp\~DFC204.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\PCPalSrvHost.log scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_2Fe45bzcI1jfxQI scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_31g49IvlLdhrJcc scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_J2mg6aSWeVftDZf scheduled to be deleted on reboot. Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08172008_190850hjt log [recovering disk space -- attachment deleted by admin] Quote where are we going with this Cleaning the computer... Would you rather stop? Run this online scan. Requires Internet Explorer Use the ESET Nod32 Online Scanner 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply Quote Cleaning the computer... Would you rather stop?not at all, just thought that if i did a complete reinstall of windows that it would take care of any viruses and problems i was having ,so thou i did a complete install that viruses are still lurking ? btw that scan was 5 hours skyblue [recovering disk space -- attachment deleted by admin]Reinstalling is always the safest way as it will remove anything that we may never find this way. The log is clean though. 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates. If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update. ---------- Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a GOOD idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them. Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 1472. |
Solve : Installing Spybot ( other programs without internet access? )? |
| Answer» YEP, were DONE here. | |
| 1473. |
Solve : Virus and spyware removal? |
| Answer» NONE | |
| 1474. |
Solve : Windows Data Execution Prevention closes IE8? |
|
Answer» Everytime I close a page or tab in IE8, I get a message saying "Internet Explorer has stopped working...Windows is checking for a SOLUTION to this problem" Then I have to hit Close Program. After that a box pops up in my toolbar saying"Data Execution Prevention has closed internet explorer to protect your computer" (copied from a Jul 6 message) |
|
| 1475. |
Solve : AVG detections? |
|
Answer» Well, I had AVG turned off (Resident Shield that is) that whole time before and after ComboFix did it's job. I just now turned it back on and the constant trojan notifications have stopped.. so problem solved there. All AVG seems to be running fine now. Is it safe to empty the vault of all those "infections"? The ComboFix uninstall didn't get rid of the icon on the desktop. Should I delete that since all the other things related to it were (probably) uninstalled? You can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt Quote And in general... what programs (that you've had me install throughout the process) would you suggest I keep to help keep the computer in shape on a regular basis? Are there any that I can/should get rid of when I'm done? Keep Malwarebytes and SUPERAntispyware. Update ans run them now and then to be sure nothing else has gotten into the computer. Also keep CCleaner. You can use it as a daily drive cleaner. Quote got rid of jre1.6.0_07 but when I look in my program files, there's still an 80mb folder there. There should only be one folder inside of the Java folder from the newest version of Java. Quote And finally, it seems several things around my computer have returned to default settings. Is that a "side effect" of ComboFix? Things like the wallpaper changing and icons returning (without performing a system restore) make me a little wary. Yes some of the tools we use reset Windows to it's default settings. Quote As for Malwarebytes', I uninstalled that yesterday after we tried the redownload and installation. I'm pretty sure I've restarted several times since then. Should I restart yet again and then try your link? Try malwarebytes again. If it won't work let me know the exact error you get.Thank you for the advice. I used the MBAM cleaner and then reinstalled and I still get the same problem. Right after the installation bar is complete a Microsoft Windows notification pops-up that says "Malwarebytes' Anti-Malware has stopped working" then it searches for a solution, then says "A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available". Then I press the close button. Then the same notification pops up again. It always happens twice. After that, it says it installed successfully and then whenever it/I try to launch it, the same notification pops up twice again. The way I got that scan that I provided you before is because I rebooted in safe mode and it worked there.I'm not sure I've ever seen that error with MBAM before. You might want to mention it in their forums. http://www.malwarebytes.org/forums/index.php?showforum=41 Final steps and suggestions. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Alright, I might mention the Malwarebytes' issue there when I get the chance. I updated everything detected in SSI. I'll be checking out the rest in the near future. I also wanted to know if there is a safe registry cleaner that you'd recommend or if you think it's best to leave it alone. I just want to make sure everything is cleaned out when I uninstall programs. I was also curious about the Kapersky Scan. Is there anything I need to clear out that it downloaded? Lastly, I use the No Script add-on for Firefox sometime. I got that malware when I had it disabled. I dislike how it restricts so many things on websites, but I've never had virus issues while using it. What's you opinion on that add-on? And about the Java updates. I now have 3 folders in C:\Program Files\Java (jre6, jre1.6.0_07, jre1.6.0_13). Since you said I should only have 1, should I delete any of them? Thank you so much for your time and help Kevin. I'm very grateful. Quote I also wanted to know if there is a safe registry cleaner that you'd recommend or if you think it's best to leave it alone. Unless you really know what you are doing then leave them alone. Use Revo Uninstaller to completely and safely remove software. * Open Revo and let the list populate (can take several seconds to finish). * Right click what you want to uninstall and choose Uninstall * Next choose Advanced then click Next * This will (try to) launch the programs built in uninstaller and go through the normal uninstall process. * If the uninstaller fails just continue on with the Revo instructions. * Once complete: In Revo Uninstaller click Next and Revo will scan the registry for LEFTOVERS. * This scan can take several seconds. * Once the results are shown look at each one to ensure they are all related to the program that was uninstalled. * Choose Select All then click Delete * Click Next and Revo will scan for any files or folders that were not removed. * If any files/folders are found choose Select all > Delete Quote I was also curious about the Kapersky Scan. Is there anything I need to clear out that it downloaded? I think there is a Kaspersky entry in Add/Remove Programs you can uninstall. Quote Lastly, I use the No Script add-on for Firefox I'm the same as you. NoScript is a great add on but it blocks too much so I don't use it. I rely on Spywareblaster and Spybots Immunize. Those and Avast antivirus have kept me safe. Quote (jre6, jre1.6.0_07, jre1.6.0_13) The newest version is Sun Java Runtime Environment 6 Update 14 so you are still out of date. First install the new Sun Java Runtime Environment Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close all browser windows before beginning the install. Remove the old version(s) Download JavaRa * Unzip the file and open the JavaRa.exe * Click Remove Older Versions * JavaRa will search for and remove any outdated version of Java and remove any that are found. * Click ADDITIONAL Tasks * Place a check next to Remove Useless JRE Files and click Go * Exit JavaRa * Delete the JavaRa files from the Desktop Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer. Quote Thank you so much for your time and help Kevin. I'm very grateful. Your welcome. Let us know if anything else comes up. |
|
| 1476. |
Solve : DLLHOST.EXE/SVCHOST.EXE malicious actions?? |
|
Answer» Hi, can anyone tell me how to fix this problem? Every few minutes the following message pops up on my computer from spyware dr:
-------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type NOTEPAD.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: Viewpoint Manager Service DDS:: BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File Firefox:: FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll Folder:: c:\program files\viewpoint c:\users\phils\appdata\roaming\ParetoLogic c:\users\phils\appdata\roaming\DriverCure c:\programdata\ParetoLogic c:\programdata\DriverCure c:\progra~2\ParetoLogic c:\progra~2\DriverCure c:\programdata\RegCure c:\progra~2\RegCure 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ---------- Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. First install the new Sun Java Runtime Environment Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close all browser windows before beginning the install. Remove the old version(s) Download JavaRa * Unzip the file and open the JavaRa.exe * Click Remove Older Versions * JavaRa will search for and remove any outdated version of Java and remove any that are found. * Click Additional Tasks * Place a check next to Remove Useless JRE Files and click Go * Exit JavaRa * Delete the JavaRa files from the Desktop Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.ok, i keep gettting this popup - "You don't have sufficient access to uninstall ____. Please contact your system administrator." when trying to uninstall anything.. javara worked. i could not install the new java...i got an error message saying "Unzipping core files failed." and the installation exited. ComboFix 09-07-14.08 - PhilS 07/18/2009 18:45.1.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2814.1659 [GMT -7:00] Running from: c:\users\PhilS\Desktop\ComboFix.exe Command switches used :: c:\users\PhilS\Desktop\CFScript.txt SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\progra~2\DriverCure c:\progra~2\DriverCure\9B13A86D3456.plf c:\progra~2\ParetoLogic c:\progra~2\ParetoLogic\Privacy Controls\AppPreferences.dat c:\progra~2\ParetoLogic\UUS2\DriverCure\Master.xml c:\progra~2\ParetoLogic\UUS2\DriverCure\Patch.xml c:\progra~2\ParetoLogic\UUS2\DriverCure\Update.xml c:\progra~2\RegCure c:\progra~2\RegCure\whitelist.dat c:\program files\viewpoint c:\program files\viewpoint\Common\ViewpointService.exe c:\program files\viewpoint\Common\VistaBoot.sdll c:\program files\viewpoint\Viewpoint Media Player\AxMetaStream.dll c:\program files\viewpoint\Viewpoint Media Player\ClassIDs.ini c:\program files\viewpoint\Viewpoint Media Player\ComponentMgr.dll c:\program files\viewpoint\Viewpoint Media Player\ComponentRegistry.ini c:\program files\viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll c:\program files\viewpoint\Viewpoint Media Player\Components\Cursors.dll c:\program files\viewpoint\Viewpoint Media Player\Components\JpegReader.dll c:\program files\viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll c:\program files\viewpoint\Viewpoint Media Player\Components\SceneComponent.dll c:\program files\viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll c:\program files\viewpoint\Viewpoint Media Player\Components\SWFView.dll c:\program files\viewpoint\Viewpoint Media Player\Components\VETScriptInterpreter.dll c:\program files\viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll c:\program files\viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll c:\program files\viewpoint\Viewpoint Media Player\HostRegistry.ini c:\program files\viewpoint\Viewpoint Media Player\MetaStreamConfig.ini c:\program files\viewpoint\Viewpoint Media Player\MetaStreamID.ini c:\program files\viewpoint\Viewpoint Media Player\MtsAxInstaller.exe c:\program files\viewpoint\Viewpoint Media Player\MTSDownloadSites.txt c:\program files\viewpoint\Viewpoint Media Player\npViewpoint.dll c:\program files\viewpoint\Viewpoint Media Player\npViewpoint.xpt c:\programdata\DriverCure\9B13A86D3456.plf c:\programdata\ParetoLogic\Privacy Controls\AppPreferences.dat c:\programdata\ParetoLogic\UUS2\DriverCure\Master.xml c:\programdata\ParetoLogic\UUS2\DriverCure\Patch.xml c:\programdata\ParetoLogic\UUS2\DriverCure\Update.xml c:\programdata\RegCure\whitelist.dat c:\users\phils\appdata\roaming\DriverCure c:\users\phils\appdata\roaming\DriverCure\Client.txt c:\users\phils\appdata\roaming\DriverCure\LogFile.txt c:\users\phils\appdata\roaming\DriverCure\Server.txt c:\users\phils\appdata\roaming\ParetoLogic c:\users\phils\appdata\roaming\ParetoLogic\Privacy Controls\CleanPreferences.db . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_Viewpoint Manager Service ((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 ))))))))))))))))))))))))))))))) . 2009-07-19 01:56 . 2009-07-19 02:01 -------- d-----w- c:\users\PhilS\AppData\Local\temp 2009-07-15 21:01 . 2009-07-15 21:01 -------- d-----w- c:\program files\Trend Micro 2009-07-15 08:51 . 2009-07-15 08:51 -------- d-----w- c:\users\PhilS\AppData\Roaming\Malwarebytes 2009-07-15 08:51 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-15 08:51 . 2009-07-15 08:51 -------- d-----w- c:\programdata\Malwarebytes 2009-07-15 08:51 . 2009-07-15 08:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-15 08:51 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-14 20:11 . 2009-06-15 14:53 156672 ----a-w- c:\windows\system32\t2embed.dll 2009-07-14 20:11 . 2009-06-15 14:52 72704 ----a-w- c:\windows\system32\fontsub.dll 2009-07-14 20:11 . 2009-06-15 12:42 289792 ----a-w- c:\windows\system32\atmfd.dll 2009-07-14 20:11 . 2009-06-15 14:52 23552 ----a-w- c:\windows\system32\lpk.dll 2009-07-14 20:11 . 2009-06-15 14:51 10240 ----a-w- c:\windows\system32\dciman32.dll 2009-07-14 17:06 . 2009-07-14 17:06 -------- d-----w- c:\programdata\Cached Installations 2009-07-14 17:00 . 2009-07-14 17:00 -------- d-----w- c:\programdata\Downloaded Installations 2009-07-14 08:25 . 2009-07-14 08:39 -------- d-----w- c:\program files\RegCure 2009-07-13 17:41 . 2009-07-16 00:48 117760 ----a-w- c:\users\PhilS\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-07-13 17:41 . 2009-07-13 17:41 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2009-07-13 17:40 . 2009-07-13 17:40 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-07-13 17:40 . 2009-07-13 17:40 -------- d-----w- c:\users\PhilS\AppData\Roaming\SUPERAntiSpyware.com 2009-07-13 17:39 . 2009-07-13 17:39 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-07-10 23:43 . 2009-07-10 23:43 -------- d-----w- c:\users\PhilS\AppData\Roaming\funkitron 2009-07-09 09:08 . 2009-07-09 09:08 -------- d-----w- c:\users\PhilS\AppData\Roaming\iWin 2009-07-04 21:05 . 2009-07-04 21:06 -------- d-----w- c:\windows\system32\ca-ES 2009-07-04 21:05 . 2009-07-04 21:06 -------- d-----w- c:\windows\system32\eu-ES 2009-07-04 21:05 . 2009-07-04 21:06 -------- d-----w- c:\windows\system32\vi-VN 2009-07-04 19:40 . 2009-07-04 19:40 -------- d-----w- c:\windows\system32\EventProviders 2009-07-04 19:36 . 2009-04-11 06:28 289792 ----a-w- c:\windows\system32\spinstall.exe 2009-07-04 19:35 . 2009-04-11 06:28 71680 ----a-w- c:\windows\system32\propdefs.dll 2009-07-04 19:34 . 2009-04-11 06:28 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2009-07-04 19:33 . 2009-04-11 06:28 140288 ----a-w- c:\windows\system32\wpcsvc.dll 2009-07-04 19:32 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll 2009-07-04 19:32 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll 2009-07-04 19:32 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll 2009-07-04 19:32 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll 2009-07-04 19:32 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll 2009-07-04 19:32 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll 2009-07-04 19:32 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll 2009-07-04 19:32 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll 2009-07-04 19:32 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll 2009-07-04 19:32 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe 2009-07-04 19:32 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll 2009-06-25 08:20 . 2009-06-25 08:24 -------- d-----w- c:\program files\SystemRequirementsLab 2009-06-25 08:20 . 2009-06-25 08:21 -------- d-----w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab 2009-06-25 08:20 . 2009-06-25 08:20 290816 ----a-w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_4.dll 2009-06-25 08:20 . 2009-06-25 08:20 290816 ----a-w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_3.dll 2009-06-25 08:20 . 2009-06-25 08:20 290816 ----a-w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_2.dll 2009-06-25 08:20 . 2009-06-25 08:20 290816 ----a-w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_1.dll 2009-06-22 10:42 . 2009-06-24 11:14 -------- d-----w- c:\users\PhilS\AppData\Roaming\dvdcss 2009-06-21 21:50 . 2009-06-05 11:33 68640 ----a-w- c:\windows\unTMV.exe 2009-06-21 21:50 . 2009-06-21 21:50 -------- d-----w- c:\program files\SoftMaker Viewer 2009-06-19 19:58 . 2009-06-19 19:58 -------- d-----w- c:\users\PhilS\AppData\Roaming\Recordpad 2009-06-19 11:32 . 2009-06-19 11:33 -------- d-----w- c:\programdata\NCH Swift Sound 2009-06-19 11:32 . 2009-06-19 11:33 -------- d-----w- c:\users\PhilS\AppData\Roaming\NCH Swift Sound 2009-06-19 11:32 . 2009-06-19 11:32 -------- d-----w- c:\program files\NCH Software 2009-06-19 11:31 . 2009-06-27 03:50 -------- d-----w- c:\program files\NCH Swift Sound 2009-06-19 11:28 . 2009-06-19 11:28 -------- d-----w- c:\programdata\FreeRIP 2009-06-19 11:28 . 2009-06-19 11:28 -------- d-----w- c:\program files\FreeRIP3 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-19 01:59 . 2008-12-26 00:31 -------- d-----w- c:\program files\Spyware Doctor 2009-07-19 00:35 . 2008-12-26 00:22 27839 ----a-w- c:\programdata\nvModes.dat 2009-07-15 06:38 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-07-15 00:12 . 2008-12-26 00:25 1092 ----a-w- c:\users\PhilS\AppData\Roaming\wklnhst.dat 2009-07-14 17:11 . 2008-12-26 00:31 -------- d-----w- c:\program files\Common Files\PC Tools 2009-07-14 17:07 . 2008-12-30 00:43 -------- d-----w- c:\users\PhilS\AppData\Roaming\uTorrent 2009-07-14 08:56 . 2008-12-26 07:54 74432 ----a-w- c:\users\PhilS\AppData\Local\GDIPFONTCACHEV1.DAT 2009-07-11 11:16 . 2008-08-04 17:19 -------- d-----w- c:\programdata\WildTangent 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender 2009-07-04 21:05 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat 2009-07-04 19:58 . 2008-11-06 03:37 -------- d-----w- c:\programdata\NVIDIA 2009-07-04 19:47 . 2006-11-02 12:37 37665 ----a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont 2009-06-30 22:36 . 2009-07-12 05:36 18696 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryReplaceNew.exe 2009-06-30 22:10 . 2009-07-12 05:36 18696 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryNoTravel.exe 2009-06-30 22:03 . 2009-07-12 05:36 18696 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryAccessories.exe 2009-06-30 19:44 . 2009-07-12 05:36 18184 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryWeakNew.exe 2009-06-27 01:36 . 2009-07-12 05:36 18184 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryUpgrade.exe 2009-06-21 08:52 . 2009-06-18 10:22 -------- d-----w- c:\users\PhilS\AppData\Roaming\vlc 2009-06-18 10:21 . 2009-06-18 10:21 -------- d-----w- c:\program files\VideoLAN 2009-06-18 10:15 . 2009-06-18 10:13 -------- d-----w- c:\program files\GPL MPEG Decoder 2009-06-13 10:03 . 2008-08-04 17:50 -------- d-----w- c:\program files\Microsoft Works 2009-06-07 06:27 . 2009-01-09 00:06 -------- d-----w- c:\program files\DivX 2009-06-07 06:23 . 2009-06-07 06:23 -------- d-----w- c:\program files\Common Files\DivX Shared 2009-06-07 05:54 . 2009-04-08 05:13 -------- d-----w- c:\users\PhilS\AppData\Roaming\DivX 2009-05-09 05:50 . 2009-06-12 14:11 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-09 05:34 . 2009-06-12 14:11 71680 ----a-w- c:\windows\system32\iesetup.dll 2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll 2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll 2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll 2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll 2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll 2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll 2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll 2009-04-23 12:15 . 2009-06-12 14:11 784896 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-23 12:14 . 2009-06-12 14:12 623616 ----a-w- c:\windows\system32\localspl.dll 2009-04-21 11:39 . 2009-06-12 14:12 2034688 ----a-w- c:\windows\system32\win32k.sys 2009-04-20 06:26 . 2009-03-30 00:32 39200 ----a-w- c:\windows\system32\drivers\TfSysMon.sys 2009-04-20 06:26 . 2009-03-30 00:32 33056 ----a-w- c:\windows\system32\drivers\TfNetMon.sys 2009-04-20 06:26 . 2009-03-30 00:32 51488 ----a-w- c:\windows\system32\drivers\TfFsMon.sys 2009-04-20 06:26 . 2009-03-30 00:32 12576 ----a-w- c:\windows\system32\drivers\TfKbMon.sys 2009-04-20 06:26 . 2009-03-30 00:30 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2009-06-12 10:19 . 2009-01-06 23:26 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll 2008-08-04 15:03 . 2008-08-04 15:03 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752] "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-11 13543968] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-11 92704] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] ="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] ="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] ="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):d7,86,ac,d9,ec,fc,c9,01 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{053E5549-ECD5-4FE4-8DB9-641DFB10CF77}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play "{C1BAABB6-21B7-49B7-91E1-E455B4B6BC44}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program "{C55EE582-4D18-4465-B67C-01CCBFDC83AC}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{B2DD7404-A6FC-40B9-8308-6C878692A3C9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{61163C9B-D9DA-4470-B24F-3F12B829515A}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "TCP Query User{5FFDBBF0-35FB-4F2D-9936-1E5CA81749AD}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM "UDP Query User{557017AC-78EB-4FEF-B5BA-785EC157B329}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM "TCP Query User{C02004D7-C5DA-4F5A-9748-7C6D34C4B495}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent "UDP Query User{F9002FAE-E853-4411-9606-D546AA53E040}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent "{C584877B-5ED8-4DE5-AF02-3B55F5AEF3FD}"= Disabled:UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{1AFE8673-5972-4C8A-BC15-0B44CC879F75}"= Disabled:TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{7D94000C-BBBC-44EB-BCCA-577F962A31C6}"= Disabled:UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{17ECCB8F-DF6F-416B-884A-F0B83C4C6A41}"= Disabled:TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "DoNotAllowExceptions"= 1 (0x1) R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [3/29/2009 5:30 PM 130936] R0 TfFsMon;TfFsMon;c:\windows\System32\drivers\TfFsMon.sys [3/29/2009 5:32 PM 51488] R0 TfSysMon;TfSysMon;c:\windows\System32\drivers\TfSysMon.sys [3/29/2009 5:32 PM 39200] R1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [3/29/2009 5:30 PM 159600] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944] R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [8/4/2008 11:43 AM 361808] R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/25/2008 5:31 PM 348752] R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/4/2008 10:15 AM 193840] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [5/9/2008 12:17 PM 43040] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [3/29/2009 5:30 PM 64392] R3 TfNetMon;TfNetMon;c:\windows\System32\drivers\TfNetMon.sys [3/29/2009 5:32 PM 33056] R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408] --- Other Services/Drivers In Memory --- *Deregistered* - mchInjDrv [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-18 c:\windows\Tasks\HPCeeScheduleForPhilS.job - c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-08-04 03:03] 2009-07-19 c:\windows\Tasks\RegCure Program Check.job - c:\program files\RegCure\RegCure.exe [2009-06-10 22:28] 2009-07-19 c:\windows\Tasks\RegCure Startup.job - c:\program files\RegCure\RegCure.exe [2009-06-10 22:28] 2009-07-14 c:\windows\Tasks\RegCure.job - c:\program files\RegCure\RegCure.exe [2009-06-10 22:28] 2009-07-18 c:\windows\Tasks\User_Feed_Synchronization-{9051D44C-782E-4E8D-B571-01D8B4400FEE}.job - c:\windows\system32\msfeedssync.exe [2009-04-06 11:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.aol.com/ mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb uInternet Settings,ProxyOverride = *.local LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll FF - ProfilePath - c:\users\PhilS\AppData\Roaming\Mozilla\Firefox\Profiles\r2or64x5.default\ FF - prefs.js: browser.startup.homepage - hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-18 19:00 Windows 6.0.6002 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] Denied: (A) (Users) Denied: (A) (Everyone) Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1196) c:\program files\Spyware Doctor\TFEngine\TFWAH.dll - - - - - - - > 'lsass.exe'(660) c:\program files\Spyware Doctor\TFEngine\TFWAH.dll - - - - - - - > 'Explorer.exe'(3008) c:\program files\Spyware Doctor\TFEngine\TFWAH.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\nvvsvc.exe c:\windows\System32\audiodg.exe c:\windows\System32\rundll32.exe c:\windows\System32\wlanext.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\program files\Spyware Doctor\pctsSvc.exe c:\windows\System32\drivers\XAudio.exe c:\program files\Spyware Doctor\TFEngine\TFService.exe c:\windows\System32\rundll32.exe c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe c:\program files\Windows Media Player\wmpnscfg.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe . ************************************************************************** . Completion time: 2009-07-19 19:10 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-19 02:10 ComboFix2.txt 2009-07-17 10:37 Pre-Run: 75,693,498,368 bytes free Post-Run: 75,118,772,224 bytes free 318 --- E O F --- 2009-07-15 06:38 Is this a limited account? Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: File:: c:\windows\Tasks\RegCure Program Check.job c:\windows\Tasks\RegCure Startup.job c:\windows\Tasks\RegCure.job Folder:: c:\program files\RegCure Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] RegLock:: [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeIt never was...these limitations saying "PhilS" is not the admin began with the spyware doctor dllhost/svchost messages , I dont know what's going on. doing combofix now..ComboFix 09-07-14.08 - PhilS 07/19/2009 0:43.3.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2814.1746 [GMT -7:00] Running from: c:\users\PhilS\Desktop\ComboFix.exe Command switches used :: c:\users\PhilS\Desktop\CFScript.txt SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} FILE :: "c:\windows\Tasks\RegCure Program Check.job" "c:\windows\Tasks\RegCure Startup.job" "c:\windows\Tasks\RegCure.job" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . c:\program files\RegCure c:\program files\RegCure\0_days.htm c:\program files\RegCure\1_days.htm c:\program files\RegCure\15_days.htm c:\program files\RegCure\2_days.htm c:\program files\RegCure\30_days.htm c:\program files\RegCure\5_days.htm c:\program files\RegCure\Animated-Bar.gif c:\program files\RegCure\AutoUpdate.dll c:\program files\RegCure\Backup\RegCureBak_July_14_09_01_39_51.bak c:\program files\RegCure\Backup\RegCureBak_July_14_09_01_39_51.reg c:\program files\RegCure\Backup\RegCureBak_July_14_09_01_39_51\Sample Music.lnk c:\program files\RegCure\Backup\RegCureBak_July_14_09_01_39_51\Sample Videos.lnk c:\program files\RegCure\Backup\RegCureBak_July_14_09_09_45_18.reg c:\program files\RegCure\Backup\RegCureBak_July_16_09_02_29_39.bak c:\program files\RegCure\Backup\RegCureBak_July_16_09_02_29_39.reg c:\program files\RegCure\Backup\RegCureBak_July_16_09_02_29_39\Recently Changed.lnk c:\program files\RegCure\blue_duo.jpg c:\program files\RegCure\buttonfill.jpg c:\program files\RegCure\buttonfill_expire.jpg c:\program files\RegCure\buttonfill_mo.jpg c:\program files\RegCure\buttonfill_mo_expire.jpg c:\program files\RegCure\BuyNags.htm c:\program files\RegCure\center_gradient.jpg c:\program files\RegCure\container_content_bkimg.gif c:\program files\RegCure\container_content_leftimg.gif c:\program files\RegCure\container_content_rightimg.gif c:\program files\RegCure\contentwrapper.gif c:\program files\RegCure\email.htm c:\program files\RegCure\expire.css c:\program files\RegCure\footerbar.gif c:\program files\RegCure\green_duo.jpg c:\program files\RegCure\help.chm c:\program files\RegCure\info_bubble.jpg c:\program files\RegCure\left_gradient.jpg c:\program files\RegCure\logo.jpg c:\program files\RegCure\Logs\Regcure-14-07-09-01-39-53.zip c:\program files\RegCure\Logs\Regcure-14-07-09-09-45-19.zip c:\program files\RegCure\Logs\Regcure-16-07-09-02-29-39.zip c:\program files\RegCure\Logs\SystemInfo.zip c:\program files\RegCure\LogSettings.xml c:\program files\RegCure\main.css c:\program files\RegCure\main_nag.css c:\program files\RegCure\main_showstats.css c:\program files\RegCure\package_titlebar_bkimg.jpg c:\program files\RegCure\process-animation.gif c:\program files\RegCure\RegCure.exe c:\program files\RegCure\regcure.gif c:\program files\RegCure\right_gradient.jpg c:\program files\RegCure\settings.xml c:\program files\RegCure\showstats.htm c:\program files\RegCure\small_vbxregcure.jpg c:\program files\RegCure\special_offer.jpg c:\program files\RegCure\special_offer_nag.jpg c:\program files\RegCure\subtitlebar.gif c:\program files\RegCure\tile_titlebar.jpg c:\program files\RegCure\Tip1.html c:\program files\RegCure\Tip10.html c:\program files\RegCure\Tip11.html c:\program files\RegCure\Tip12.html c:\program files\RegCure\Tip13.html c:\program files\RegCure\Tip14.html c:\program files\RegCure\Tip15.html c:\program files\RegCure\Tip2.html c:\program files\RegCure\Tip3.html c:\program files\RegCure\Tip4.html c:\program files\RegCure\Tip5.html c:\program files\RegCure\Tip6.html c:\program files\RegCure\Tip7.html c:\program files\RegCure\Tip8.html c:\program files\RegCure\Tip9.html c:\program files\RegCure\titlebar_left.jpg c:\program files\RegCure\titlebar_right.jpg c:\program files\RegCure\tp.css c:\program files\RegCure\TrialPay.htm c:\program files\RegCure\underline.gif c:\program files\RegCure\uninst.exe c:\program files\RegCure\zlibwapi.dll c:\windows\Tasks\RegCure Program Check.job c:\windows\Tasks\RegCure Startup.job c:\windows\Tasks\RegCure.job . ((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 ))))))))))))))))))))))))))))))) . 2009-07-19 07:52 . 2009-07-19 07:55 -------- d-----w- c:\users\PhilS\AppData\Local\temp 2009-07-19 07:38 . 2009-07-19 07:38 -------- d-----w- c:\programdata\McAfee 2009-07-15 21:01 . 2009-07-15 21:01 -------- d-----w- c:\program files\Trend Micro 2009-07-15 08:51 . 2009-07-15 08:51 -------- d-----w- c:\users\PhilS\AppData\Roaming\Malwarebytes 2009-07-15 08:51 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-15 08:51 . 2009-07-15 08:51 -------- d-----w- c:\programdata\Malwarebytes 2009-07-15 08:51 . 2009-07-15 08:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-15 08:51 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-14 20:11 . 2009-06-15 14:53 156672 ----a-w- c:\windows\system32\t2embed.dll 2009-07-14 20:11 . 2009-06-15 14:52 72704 ----a-w- c:\windows\system32\fontsub.dll 2009-07-14 20:11 . 2009-06-15 12:42 289792 ----a-w- c:\windows\system32\atmfd.dll 2009-07-14 20:11 . 2009-06-15 14:52 23552 ----a-w- c:\windows\system32\lpk.dll 2009-07-14 20:11 . 2009-06-15 14:51 10240 ----a-w- c:\windows\system32\dciman32.dll 2009-07-14 17:06 . 2009-07-14 17:06 -------- d-----w- c:\programdata\Cached Installations 2009-07-14 17:00 . 2009-07-14 17:00 -------- d-----w- c:\programdata\Downloaded Installations 2009-07-13 17:41 . 2009-07-16 00:48 117760 ----a-w- c:\users\PhilS\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-07-13 17:41 . 2009-07-13 17:41 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2009-07-13 17:40 . 2009-07-13 17:40 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-07-13 17:40 . 2009-07-13 17:40 -------- d-----w- c:\users\PhilS\AppData\Roaming\SUPERAntiSpyware.com 2009-07-13 17:39 . 2009-07-13 17:39 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-07-10 23:43 . 2009-07-10 23:43 -------- d-----w- c:\users\PhilS\AppData\Roaming\funkitron 2009-07-09 09:08 . 2009-07-09 09:08 -------- d-----w- c:\users\PhilS\AppData\Roaming\iWin 2009-07-04 21:05 . 2009-07-04 21:06 -------- d-----w- c:\windows\system32\ca-ES 2009-07-04 21:05 . 2009-07-04 21:06 -------- d-----w- c:\windows\system32\eu-ES 2009-07-04 21:05 . 2009-07-04 21:06 -------- d-----w- c:\windows\system32\vi-VN 2009-07-04 19:40 . 2009-07-04 19:40 -------- d-----w- c:\windows\system32\EventProviders 2009-07-04 19:36 . 2009-04-11 06:28 289792 ----a-w- c:\windows\system32\spinstall.exe 2009-07-04 19:35 . 2009-04-11 06:28 71680 ----a-w- c:\windows\system32\propdefs.dll 2009-07-04 19:34 . 2009-04-11 06:28 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2009-07-04 19:33 . 2009-04-11 06:28 140288 ----a-w- c:\windows\system32\wpcsvc.dll 2009-07-04 19:32 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll 2009-07-04 19:32 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll 2009-07-04 19:32 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll 2009-07-04 19:32 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll 2009-07-04 19:32 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll 2009-07-04 19:32 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll 2009-07-04 19:32 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll 2009-07-04 19:32 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll 2009-07-04 19:32 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll 2009-07-04 19:32 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe 2009-07-04 19:32 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll 2009-06-25 08:20 . 2009-06-25 08:24 -------- d-----w- c:\program files\SystemRequirementsLab 2009-06-25 08:20 . 2009-06-25 08:21 -------- d-----w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab 2009-06-25 08:20 . 2009-06-25 08:20 290816 ----a-w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_4.dll 2009-06-25 08:20 . 2009-06-25 08:20 290816 ----a-w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_3.dll 2009-06-25 08:20 . 2009-06-25 08:20 290816 ----a-w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_2.dll 2009-06-25 08:20 . 2009-06-25 08:20 290816 ----a-w- c:\users\PhilS\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_1.dll 2009-06-22 10:42 . 2009-06-24 11:14 -------- d-----w- c:\users\PhilS\AppData\Roaming\dvdcss 2009-06-21 21:50 . 2009-06-05 11:33 68640 ----a-w- c:\windows\unTMV.exe 2009-06-21 21:50 . 2009-06-21 21:50 -------- d-----w- c:\program files\SoftMaker Viewer 2009-06-19 19:58 . 2009-06-19 19:58 -------- d-----w- c:\users\PhilS\AppData\Roaming\Recordpad 2009-06-19 11:32 . 2009-06-19 11:33 -------- d-----w- c:\programdata\NCH Swift Sound 2009-06-19 11:32 . 2009-06-19 11:33 -------- d-----w- c:\users\PhilS\AppData\Roaming\NCH Swift Sound 2009-06-19 11:32 . 2009-06-19 11:32 -------- d-----w- c:\program files\NCH Software 2009-06-19 11:31 . 2009-06-27 03:50 -------- d-----w- c:\program files\NCH Swift Sound 2009-06-19 11:28 . 2009-06-19 11:28 -------- d-----w- c:\programdata\FreeRIP 2009-06-19 11:28 . 2009-06-19 11:28 -------- d-----w- c:\program files\FreeRIP3 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-19 07:54 . 2008-12-26 00:31 -------- d-----w- c:\program files\Spyware Doctor 2009-07-19 00:35 . 2008-12-26 00:22 27839 ----a-w- c:\programdata\nvModes.dat 2009-07-15 06:38 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-07-15 00:12 . 2008-12-26 00:25 1092 ----a-w- c:\users\PhilS\AppData\Roaming\wklnhst.dat 2009-07-14 17:11 . 2008-12-26 00:31 -------- d-----w- c:\program files\Common Files\PC Tools 2009-07-14 17:07 . 2008-12-30 00:43 -------- d-----w- c:\users\PhilS\AppData\Roaming\uTorrent 2009-07-14 08:56 . 2008-12-26 07:54 74432 ----a-w- c:\users\PhilS\AppData\Local\GDIPFONTCACHEV1.DAT 2009-07-11 11:16 . 2008-08-04 17:19 -------- d-----w- c:\programdata\WildTangent 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar 2009-07-04 21:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender 2009-07-04 21:05 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat 2009-07-04 19:58 . 2008-11-06 03:37 -------- d-----w- c:\programdata\NVIDIA 2009-07-04 19:47 . 2006-11-02 12:37 37665 ----a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont 2009-06-30 22:36 . 2009-07-12 05:36 18696 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryReplaceNew.exe 2009-06-30 22:10 . 2009-07-12 05:36 18696 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryNoTravel.exe 2009-06-30 22:03 . 2009-07-12 05:36 18696 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryAccessories.exe 2009-06-30 19:44 . 2009-07-12 05:36 18184 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryWeakNew.exe 2009-06-27 01:36 . 2009-07-12 05:36 18184 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryUpgrade.exe 2009-06-21 08:52 . 2009-06-18 10:22 -------- d-----w- c:\users\PhilS\AppData\Roaming\vlc 2009-06-18 10:21 . 2009-06-18 10:21 -------- d-----w- c:\program files\VideoLAN 2009-06-18 10:15 . 2009-06-18 10:13 -------- d-----w- c:\program files\GPL MPEG Decoder 2009-06-13 10:03 . 2008-08-04 17:50 -------- d-----w- c:\program files\Microsoft Works 2009-06-07 06:27 . 2009-01-09 00:06 -------- d-----w- c:\program files\DivX 2009-06-07 06:23 . 2009-06-07 06:23 -------- d-----w- c:\program files\Common Files\DivX Shared 2009-06-07 05:54 . 2009-04-08 05:13 -------- d-----w- c:\users\PhilS\AppData\Roaming\DivX 2009-05-09 05:50 . 2009-06-12 14:11 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-09 05:34 . 2009-06-12 14:11 71680 ----a-w- c:\windows\system32\iesetup.dll 2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll 2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll 2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll 2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll 2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll 2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll 2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll 2009-04-23 12:15 . 2009-06-12 14:11 784896 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-23 12:14 . 2009-06-12 14:12 623616 ----a-w- c:\windows\system32\localspl.dll 2009-04-21 11:39 . 2009-06-12 14:12 2034688 ----a-w- c:\windows\system32\win32k.sys 2009-06-12 10:19 . 2009-01-06 23:26 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll 2008-08-04 15:03 . 2008-08-04 15:03 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( [email protected]_02.00.53 ))))))))))))))))))))))))))))))))))))))))) . + 2006-11-02 13:05 . 2009-07-19 07:34 79512 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin - 2008-12-26 07:42 . 2009-07-19 01:58 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-12-26 07:42 . 2009-07-19 07:54 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2008-12-26 07:42 . 2009-07-19 01:58 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-12-26 07:42 . 2009-07-19 07:54 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-12-26 07:42 . 2009-07-19 07:54 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2008-12-26 07:42 . 2009-07-19 01:58 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-19 07:53 . 2009-07-19 07:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2009-07-19 01:58 . 2009-07-19 01:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2009-07-19 01:58 . 2009-07-19 01:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-19 07:53 . 2009-07-19 07:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2008-12-26 04:27 . 2009-07-19 07:05 254518 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2006-11-02 10:33 . 2009-07-19 07:38 595684 c:\windows\System32\perfh009.dat - 2006-11-02 10:33 . 2009-07-18 20:03 595684 c:\windows\System32\perfh009.dat + 2006-11-02 10:33 . 2009-07-19 07:38 101350 c:\windows\System32\perfc009.dat - 2006-11-02 10:33 . 2009-07-18 20:03 101350 c:\windows\System32\perfc009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752] "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-11 13543968] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-11 92704] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] ="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] ="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] ="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] ="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):d7,86,ac,d9,ec,fc,c9,01 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{053E5549-ECD5-4FE4-8DB9-641DFB10CF77}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play "{C1BAABB6-21B7-49B7-91E1-E455B4B6BC44}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program "{C55EE582-4D18-4465-B67C-01CCBFDC83AC}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{B2DD7404-A6FC-40B9-8308-6C878692A3C9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{61163C9B-D9DA-4470-B24F-3F12B829515A}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "TCP Query User{5FFDBBF0-35FB-4F2D-9936-1E5CA81749AD}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM "UDP Query User{557017AC-78EB-4FEF-B5BA-785EC157B329}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM "TCP Query User{C02004D7-C5DA-4F5A-9748-7C6D34C4B495}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent "UDP Query User{F9002FAE-E853-4411-9606-D546AA53E040}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent "{C584877B-5ED8-4DE5-AF02-3B55F5AEF3FD}"= Disabled:UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{1AFE8673-5972-4C8A-BC15-0B44CC879F75}"= Disabled:TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{7D94000C-BBBC-44EB-BCCA-577F962A31C6}"= Disabled:UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{17ECCB8F-DF6F-416B-884A-F0B83C4C6A41}"= Disabled:TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "DoNotAllowExceptions"= 1 (0x1) R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [3/29/2009 5:30 PM 130936] R0 TfFsMon;TfFsMon;c:\windows\System32\drivers\TfFsMon.sys [3/29/2009 5:32 PM 51488] R0 TfSysMon;TfSysMon;c:\windows\System32\drivers\TfSysMon.sys [3/29/2009 5:32 PM 39200] R1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [3/29/2009 5:30 PM 159600] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944] R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [8/4/2008 11:43 AM 361808] R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/25/2008 5:31 PM 348752] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [5/9/2008 12:17 PM 43040] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [3/29/2009 5:30 PM 64392] R3 TfNetMon;TfNetMon;c:\windows\System32\drivers\TfNetMon.sys [3/29/2009 5:32 PM 33056] R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?] S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/4/2008 10:15 AM 193840] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408] --- Other Services/Drivers In Memory --- *Deregistered* - mchInjDrv [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-18 c:\windows\Tasks\HPCeeScheduleForPhilS.job - c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-08-04 03:03] 2009-07-19 c:\windows\Tasks\User_Feed_Synchronization-{9051D44C-782E-4E8D-B571-01D8B4400FEE}.job - c:\windows\system32\msfeedssync.exe [2009-04-06 11:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.aol.com/ mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb uInternet Settings,ProxyOverride = *.local LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll FF - ProfilePath - c:\users\PhilS\AppData\Roaming\Mozilla\Firefox\Profiles\r2or64x5.default\ FF - prefs.js: browser.startup.homepage - hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-19 00:54 Windows 6.0.6002 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\users\PhilS\AppData\Local\Temp\catchme.dll 53248 bytes executable scan completed successfully hidden files: 1 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1140) c:\program files\Spyware Doctor\TFEngine\TFWAH.dll - - - - - - - > 'lsass.exe'(660) c:\program files\Spyware Doctor\TFEngine\TFWAH.dll - - - - - - - > 'Explorer.exe'(2912) c:\program files\Spyware Doctor\TFEngine\TFWAH.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\nvvsvc.exe c:\windows\System32\audiodg.exe c:\windows\System32\rundll32.exe c:\windows\System32\wlanext.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\program files\Spyware Doctor\pctsSvc.exe c:\windows\System32\drivers\XAudio.exe c:\program files\Spyware Doctor\TFEngine\TFService.exe c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe c:\windows\servicing\TrustedInstaller.exe c:\program files\Windows Media Player\wmpnscfg.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2009-07-19 1:03 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-19 08:03 ComboFix2.txt 2009-07-19 02:10 ComboFix3.txt 2009-07-17 10:37 Pre-Run: 73,999,659,008 bytes free Post-Run: 74,679,185,408 bytes free 356 --- E O F --- 2009-07-15 06:38 * Click START then RUN * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- Use the Kaspersky Lab Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. If needed, this animation will guide you through the process. |
|
| 1477. |
Solve : Internet Explorer has virus, I think. Keeps reappearing even after I delete it? |
|
Answer» Thanks to combo-fix, I think everything is OK now! Thanks!Uninstall ComboFix
---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make SURE you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * PLEASE let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free TOOLS to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 1478. |
Solve : Pwdump? |
|
Answer» Hi guy's any idea why this keeps cropping up? Behavior HTTP://www.symantec.com/security_response/writeup.jsp?docid=2005-032616-0025-99&tabid=1Thanks EVIL I did search symantec but I may of done a typo ERROR. Thanks again. |
|
| 1479. |
Solve : Having a bit of trouble...? |
|
Answer» Hi, |
|
| 1480. |
Solve : One Tough Virus Infection will not allow any application to launch? |
|
Answer» Computer is slow at certain task, like going to any sites that have microsoft URL. Still have major problems with microsoft update. I did a services pack update, which did give a clue that something is running under stealth. I've reloaded hundreds of XP systems, and have updated services packs many times. But this one exhibits one strange behavior, on reboot (after service pack 3 applied) it had three command windows open after windows was completely loaded. They stayed open about 10 second then closed.Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.
Is the problem fixed? ---------- If not... Do you have an XP CD? If so, place it in your CD ROM drive and follow the instructions below:
Thanks for your EXCELLENT professional Troubleshooting and Malware extraction techniques! With High Regards Atech Hmmm, just when you though it was safe to go back-into-thMalwarebytes' Anti-Malware 1.38 Database version: 2411 Windows 5.1.2600 Service Pack 3 7/13/2009 12:51:40 AM mbam-log-2009-07-13 (00-51-33).txt Scan type: Full Scan (C:\|F:\|) Objects scanned: 198453 Time elapsed: 2 hour(s), 7 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegedit (Hijack.Regedit) -> No ACTION taken. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) e water! And there's more Here's what spynot has to say Win32.Iroffer.af: [SBI $E19E27B1] Data (File, nothing done) C:\WINNT\Client Properties.size=0 Properties.md5=D41D8CD98F00B204E9800998ECF8427E Properties.filedate=1065381757 Properties.filedatetext=2003-10-05 12:22:36 Win32.Agent.pz: [SBI $7EC6899E] Settings (Registry value, nothing done) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Network\UID Win32.Agent.pz: [SBI $8980C6CD] Settings (Registry value, nothing done) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Network\UID MyWay.MyWebSearch: [SBI $D6FC06E2] Class ID (Registry key, nothing done) HKEY_CLASSES_ROOT\CLSID\{DC250EB2-2928-41c5-89C9-5FF86FEE1691} WildTangent: [SBI $CC7760FE] Settings (Registry value, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\ClassPath=...;C:\Program Files\WildTangent\Apps\DRM0301Java.jar... Microsoft.WindowsSecurityCenter.AntiVir usOverride: [SBI $3604910C] Settings (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride BonziBuddy: [SBI $0ABCD7B1] Program directory (Directory, nothing done) C:\Program Files\BonziBuddy\ BonziBuddy: [SBI $EBA31E67] Settings (Registry key, nothing done) HKEY_USERS\S-1-5-21-3563514748-1417066420-3376078148-1006\Software\VB and VBA Program Settings\BONZIBUDDY NewtonKnows: [SBI $9F6FF28E] Class ID (Registry key, nothing done) HKEY_CLASSES_ROOT\CLSID\{6600D22F-083F-11D6-99DE-D172E92EBC2A} NewtonKnows: [SBI $FA85E989] Interface (Registry key, nothing done) HKEY_CLASSES_ROOT\Interface\{6600D22C-083F-11D6-99DE-D172E92EBC2A} NewtonKnows: [SBI $0D7AE83A] Type library (Registry key, nothing done) HKEY_CLASSES_ROOT\TypeLib\{6600D220-083F-11D6-99DE-D172E92EBC2A} StarWare: [SBI $A82637BF] Settings (Registry key, nothing done) HKEY_USERS\.DEFAULT\Software\Starware322 StarWare: [SBI $A82637BF] Settings (Registry key, nothing done) HKEY_USERS\S-1-5-18\Software\Starware322 StarWare: [SBI $8008440B] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\BrowserSearch\ StarWare: [SBI $157F2D4F] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Configurator\ StarWare: [SBI $9780440A] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ErrorSearch\ StarWare: [SBI $76047FA3] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Layouts\ StarWare: [SBI $E5A2946D] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Manager\ StarWare: [SBI $3F6D43DB] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Reference\ StarWare: [SBI $461B2748] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\RelatedSearch\ StarWare: [SBI $D5728ACA] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Toolbar\ StarWare: [SBI $007CB757] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ToolbarLogo\ StarWare: [SBI $F5040D20] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ToolbarSearch\ StarWare: [SBI $6F569955] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\TravelSearch\ StarWare: [SBI $FDA327EC] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Weather\ StarWare: [SBI $F26334AD] Web page (File, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Weather\AlertArchive.xml Properties.size=112 Properties.md5=895945C70D7AB748FFDA17CA2338D3D2 Properties.filedate=1187326290 Properties.filedatetext=2007-08-16 21:51:30 StarWare: [SBI $A6C3D1ED] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ StarWare: [SBI $4AFA1DB7] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\ StarWare: [SBI $BF882AFD] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\images\ StarWare: [SBI $37E48ACD] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\images\active\ StarWare: [SBI $4A2FB6EE] Picture (File, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\images\active\Games0.bmp Properties.size=1208 Properties.md5=984A8652D52AE5D4F27503FF3F851D76 Properties.filedate=1187326300 Properties.filedatetext=2007-08-16 21:51:39 StarWare: [SBI $465B4952] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Games\images\default\ StarWare: [SBI $2ABAE699] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Movies\ StarWare: [SBI $3C8A2EAC] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Movies\images\ StarWare: [SBI $ACFB606D] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Movies\images\active\ StarWare: [SBI $9016F550] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Movies\images\default\ StarWare: [SBI $D7FD12CF] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\Screensavers\ StarWare: [SBI $0C066ECE] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ScreensaversMarketingSitePager\ StarWare: [SBI $78757AD7] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ScreensaversMarketingSitePager\images\ StarWare: [SBI $0B99A6BB] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ScreensaversMarketingSitePager\images\active\ StarWare: [SBI $FF01E077] Program directory (Directory, nothing done) C:\WINNT\system32\config\systemprofile\Application Data\Starware322\ScreensaversMarketingSitePager\images\default\ Right Media: Tracking cookie (Internet Explorer: Bill) (Cookie, nothing done) --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --- 2009-01-26 blindman.exe (1.0.0. 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-03-05 TeaTimer.exe (1.6.6.32) 2009-07-07 unins000.exe (51.41.0.0) 2009-07-07 unins001.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll (1.6.2.15) 2007-04-02 aports.dll (2.1.0.0) 2005-05-31 borlndmm.dll (7.0.4.453) 2005-05-31 delphimm.dll (7.0.4.453) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2005-05-31 UnzDll.dll (1.73.1.1) 2005-05-31 ZipDll.dll (1.73.2.0) 2009-05-19 Includes\Adware.sbi (*) 2009-06-02 Includes\AdwareC.sbi (*) 2009-01-22 Includes\Cookies.sbi (*) 2009-05-19 Includes\Dialer.sbi (*) 2009-06-02 Includes\DialerC.sbi (*) 2009-01-22 Includes\HeavyDuty.sbi (*) 2009-05-26 Includes\Hijackers.sbi (*) 2009-07-07 Includes\HijackersC.sbi (*) 2009-06-23 Includes\Keyloggers.sbi (*) 2009-07-07 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2009-06-30 Includes\Malware.sbi (*) 2009-07-07 Includes\MalwareC.sbi (*) 2009-03-25 Includes\PUPS.sbi (*) 2009-07-07 Includes\PUPSC.sbi (*) 2009-01-22 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2009-06-02 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2009-04-07 Includes\Spyware.sbi (*) 2009-07-07 Includes\SpywareC.sbi (*) 2009-06-08 Includes\Tracks.uti 2009-07-07 Includes\Trojans.sbi (*) 2009-07-08 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll Just let SpyBot fix those. They are not a real threat but should be fixed still.
. The above procedure will:
---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware INFECTION in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hmm, I've cleaned all of the cache's done all of the suggested items. The system will appear totally clean... for about 3 reboots... then strange things begin to happen. Now mind this, I've totally isolated this system from the internet. So it's not going on-line and down loading these new infections. There has to be a generator somewhere on the system that start the process all over again, locking out the registry, infecting exe files, changing system polices. The system has degraded so badly I am no longer able to launch any spyware or virus applications loaded. I know how to remedy all of this, but it seems like a futile effort... Are you (or do you know of anyone who is) proficient with Icesword? Thanks for your thoughts in-advance AtechYou don't need IceSword, we already RAN GMER. Besides it hasn't updated in a very long time. Download Lop S&D by Eric_71 and save it to your Desktop. Lop S&D will only run on Windows XP and Windows Vista Disable your antivirus and antimalware programs so they do not interfere with the running of Lop S&D. If needed see: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs Double click LopSD.exe - If you are using Windows Vista, right-click on the LopSD icon and select Run as administrator to perform this scan.
A copy of the report can be found at this location: %systemdrive%\lopR.txt, in most cases C:\lopR.txtHello EF, I hate it when forum users don't log the final outcome of a problem. That being said, I am here to share the outcome of all our efforts. The system degraded to a state worse then the first case. All of the steps I used to access the registry failed, no exe or com files where able to launch, unable to browse the internet freely. Meaning I could go to any search engine, but was not allowed to open any sites that had to do with virus, spyware, malware, if I did the browser closed. I know we gave it our best shot, but this system could not be saved. I imaged the drive and then D-bombed it this evening (a type of low level reformat) and will do a fresh system install. No data extracted from the old system will be moved forward to the new one, until we better understand what we are dealing with. Thanks till you are better paid AtechThanks for letting me know. |
|
| 1481. |
Solve : Problem with CLayoutEngine-Tooltip? |
|
Answer» During computer shut down, I get a message that CLayoutEngine-Tooltip is having a PROBLEM shutting down. I eventually have to click "END" to close it. I know that this type of occurrence SOMETIMES indicates a problem which may be associated with viruses or spy-ware. |
|
| 1482. |
Solve : HijackThis / Superantispyware / Malwarebytes - Logs posted? |
|
Answer» Have had Internet connection loss at regular intervals requiring a reboot, which has coincided with a rather active DVD ROM drive drawer opening and closing repeatedly at given periods. |
|
| 1483. |
Solve : Question about Virus damage!? |
|
Answer» I have just a simple question: |
|
| 1484. |
Solve : GMER shows rootkit in registry but cannot delete???? |
|
Answer» Okay have run the combofix and the cleaner. Now the Kapersky Lab ask that you turn off antivirus programs to run but I don't feel comfortable doing that is that safe?Yes it's safe.Okay, here is the Kscan report and GMER:
. The above procedure will:
---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - WEB of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. ---------- Let me know if anything else comes up. Safe surfing.., |
|
| 1485. |
Solve : Virus that changes my administrator pass.....and changes my folder to applicatio? |
|
Answer» Here's my Combo Fix Log..... the Kaspersky Online Scanner is not done yet.... Currently, im using G Data Antivirus but its only a trial, it is not updated. You need to get a good updated antivirus installed ASAP. Download one of these to the desktop but before installing it uninstall G Data, restart the computer and then install the new one before going online. Remember to only install one antivirus! 1) Avast! Home Free Edition 2) AVG Free Edition 3) Avira AntiVir Personal Then run a full scan with the new antivirus. You can place your backup CD in the drive and let it be scanned also. Let me know how that goes. |
|
| 1486. |
Solve : An unhandled win32 exception has occurred in xxx.exe? |
|
Answer» THANK you once again EVILFANTASY! REGARDS, FRIDAY |
|
| 1487. |
Solve : This is not a bump but I'm not sure what else to do...? |
|
Answer» I posted my logs on July 18 under the "Need HELP with malware" thread. I also read evilfantasy's post stating that we should not bump and that help would be given starting from the oldest posts to the newest, so I have not posted again. But I am seeing others receiving direction that have posted more recently. I'm wondering if maybe my thread has been forgotten since it has lapsed to page 2. |
|
| 1488. |
Solve : Blue screen appeared need help, slow computer? |
|
Answer» Hi All, |
|
| 1489. |
Solve : Data Execution Prevention Issue? |
|
Answer» Gateway 7330Gz LAPTOP |
|
| 1490. |
Solve : Spotty Face of Avira Mascot!?? |
|
Answer» Hi Geeks! |
|
| 1491. |
Solve : needing help with uacd.sys trojan? |
|
Answer» Hi there , looks like i just got a nasty virus......... downloaded combofix and got a report. |
|
| 1492. |
Solve : trojans in itunes? |
|
Answer» Hi can you HELP SEEN this POST in forums but somewhere is says sent a new post to get personal help HOPE this is okay THANKS Sorry, what? |
|
| 1493. |
Solve : Is my friends computer infected?? |
|
Answer» Logfile of Trend Micro HijackThis v2.0.2 |
|
| 1494. |
Solve : Ok, I have followed your request & here is the SAS results? |
|
Answer» THANK you, I will TRY that. I'll LET you know. roc |
|
| 1495. |
Solve : The post you requested dmoody? |
|
Answer» Malwarebytes' Anti-Malware 1.39 |
|
| 1496. |
Solve : Cross Partition Virus/Malware infectability?? |
|
Answer» It's not really an "updated version" but, rather a FORK from the original source as Virtual PC. http://en.wikipedia.org/wiki/Microsoft_Java_Virtual_MachineYes, but it was never owned by MS, and Virtual PC allows you to run alternate OS's. I'm not sure that I understand what you are trying to say, can you please rephrase it?Technology is owned by someone... right? What am I unclear on? Quote from: BC_Programmer on July 20, 2009, 03:45:48 PM He wants multiple Installations of his OS. One of which he will use on-line, and another mostly off-line; that is, his important data on the "off-line" partition. Yes, you've got it exactly That's what I meant. So, if I'm getting this right, you COULD hide the "dirty" partition using a boot mgr and it'd be cool. One Q on that though, I seem to remember reading something about a Hide flag VS an "actual" hide. The flag was supposedly not totally secure on this or that, but I forget exactly what the issue was. Would say, BootIt or Partition Magic do the full hide? Oh, and a little off subj, which proggy is better in your opinion? I've heard polar opposites on opinions. In my personal exp, Norton when down the toilet after the last DOS ver of Norton Utilities. AFAIK PM was bought by them. It's possible PM had some "break" in the quality, like before X ver good and after crap. Now, as far as the file infectability on a 3rd partition, would data files be safe from the "dirty" partition? Used to be nice and simple, executable was executable and everything else was not. Now it seems to blur a little. I know there was the scarey JPG virus a ways back, but IIRC it only got you if you used an M$ prog to view the pic. All others were immune (shocker huh). Anyway, my data partition(s) would have huge newsgroup data files, tons of jpgs, AVI, M4V, email datafiles (but they're Pegasus Mail Obviously, I need to share some stuff between the dirty and clean or I'd have to do something insane like save to USB drive dirty, scan with AV running clean, then access. UG! How much should I worry! I have a friend who DOES worry that much, heheh. But then, he believes there not only isn't GLOBAL warming, it's cooling! AFAIK, he's not on crack either! Quote from: evilfantasy on July 20, 2009, 04:31:15 PM Hold on. I think I'm talking about two different things here. Sorry. err MS never owned Java, they licensed it from Sun, who started a project they called "oak" that was supposed to be a generic and easy way to program appliances, such as coffee makers and refridgerators and so forth (I think it was more aimed at the manufacturers, rather then the end user, which is to say, they intended to sell the VM to the manufacturers, who could use it instead of a set of hard-coded IC's that they usually used for features such as the temperature control and so forth. I can't remember exactly what happened, but it ended up being a viable language for more then just programming simple appliances. ahh, here it is: http://www.java.com/en/javahistory/timeline.jsp the confusion with MS and Java is that their license was revoked by Sun after Microsoft Visual J++, and the WFC and the various other bastardizations that MS made to their VM, which ended up making it possible that a Java Program would run on the MS VM but not on any others. (namely, the integrated support for COM). Since MS was no longer able to create anything using Java technology, I believe they transformed J++ into Visual Basic .NET, speaking of which one might surmise that the whole Java License thing could have sparked MS to create .NET in the first place- they are both virtual machines, after all, the Java VM and the CLR... not to mention the whole thing get's even more confused when you have companies like netscape producing completely different technologies (LiveScript) and then renaming them based on the latest craze (which is how we got JavaScript.... JavaScript and Java are so unrelated the mere fact that the name of one is used in another is utterly ridiculous. Java runs in a VM on a client and is a strongly-typed, purely object oriented language that is compiled to bytecode. JavaScript is a Client-side scripting language that barely supports the basics of object access, let alone the creation of objects (real objects- not this IDispatchEx crap- I mean, Objects have VTABLE's, *censored*!) woops. sorry. went off on a tangent there. for hiding the partition- there aren't any flags to set- you merely don't give the clean partition a drive letter in the Infectable OS. basically- think of the infectable OS as completely untrusted from the viewpoint of the Clean OS. if the infecteable OS cannot access the clean partition it simply cannot infect it... (although, as you said, you'd still be susceptible to a MBR virus) if you use a third partition to store data; any data/executables on that partition can be infected if that partition is accessible from the "infectable" OS. for example, if it got infected with Virut/Sality, then chances are any installers, programs, WMV files, HTML files, etc you had on the data drive would be infected. running any of these from teh "Clean" OS could easily infect it, especially if virus protection was only kept on the "infectable" machine and you don't access the net via the clean parittion at all. This would leave you with two infected OS's and a need to reinstall and then check all your data files. Quote I have a friend who DOES worry that much, heheh. Well... maps recovered from sea-faring civilizations in the 1300-1400's showed rivers and lakes on the surface of Antarctica. Interesting stuff to ponder... how did they map it? supposedly nobody went to Antarctica until much later; but it kind of goes to show that we cannot assume when their was a first time for anything, I guess. Thanks BC. Although personally in examples like this, since MS could pretty much do with it as they pleased, I think the difference between license and ownership is a thin line.I think, "license" as it pertains to say licensing a technology from another company is different then the more consumer-based use of the term for licensing software- but they are definitely similar- with a copy of windows or most software, for example, your really paying for the license to use the software, rather then the software itself. Since, in actuality you can do whatever you wished with the contents of the CD, I think that in a very basic way you "own" the CD and it's contents. I think, the license, more or less pertains to the source code and related libraries and so forth; and in the case of the Java VM, Sun had specific licensing requirements that basically said that the licensee could do whatever they pleased with their VM, as long as it adhered to a specific set of standards, most of which were in place to make sure that the Virtual Machines were consistent across platforms. For example, All VM's implement garbage collection, because it's part of the specification; However, within that limit the creators of the VM could do what they pleased to implement that garbage collection; for example, many VMs use something called "mark and sweep" which goes through the list of objects in memory, and marks those that are unused; then goes through again and disposes of those objects that were marked. Others, for example, the Microsoft VM did this, if I recall, was called "Stop and copy" and was pretty similar, however, instead of going through twice, the objects are looped through just once, and all active objects are copied to a new memory location, the old one is deallocated, and the new one copied back into it's place. this method is faster but more memory intensive (heh, MS always goes for the faster but more memory consuming options...) In a way, it's similar to the Patent on the GIF/LZW file format that is held my Compuserve/Unisys; a license. which allows you to implement the algorithm legally, is prohibitively expensive, but it really isn't that hard to implement the code; it uses LZW compression, which is a very common and well documented format; basically the patent covers how the file is organized rather then how it is compressed, which is a kind of lame thing to patent. it would be like patenting a living room layout and then charging people who used that layout a "licensing fee". The way I like to think of it, is that, Owning it, is when you have, and legally obtained, the source code to the product. licensing the product usually means that the company gives you precompiled OBJ files that you can link into your program. Of course this line is blurred when the licensee is actually given a license for the actual source code. I believe Russia has the source code for windows to meet some sort of esoteric government rule regulating software; but does this mean that Russia owns windows? Well, not really. They just wanted it probably to make sure there wasn't any anti-communist stuff embedded in it, not to modify it. I added that "obtained legally" bit for obvious reasons; take the Half-Life 2 Source code leak; it was obtained illegally; but without that clause it would fit under the definition of ownership. Another definition is who wrote it, which, IMO is the fairest of all, but is too cumbersome to implement. Big companies that have thousands of employees usually have their employees sign a contract which basically signs over anything they write programming-wise to be owned by the company; this includes stuff they write at home. (In my opinion this is dangerously close to breaching some form of human right, (freedom to... express themselves? I don't know... just seems odd). This means that all the source is owned by the company rather then the original writer of the source, which also, seems fair since the company in general paid them to write the program/module. The real issue with such a setup is when the same programmer writes a utility or small program for public consumption. Before they are able to release it, they literally need to get their own source code given to them, since, because of the aforementioned agreement the company owns it. In general this is to avoid, for example, a company releasing a program, and then one of the employees releasing a competing program that uses portions of the companies code (which may include the work of their co-workers); however because of the wide coverage of the contract a company could practically silence all the work of a programmer except for that done for the company. (the programmer can of course release them anonymously)Hey BC. Doesn't it seem like every time we start a conversation about Java + Microsoft we end up learning more than we want to. Quote from: BC_Programmer on July 21, 2009, 03:48:26 AM woops. sorry. went off on a tangent there. I wouldn't totally doubt they got to Antarctica since we know some Norse dude found America way before Columbus. If it WAS warm there, they coulda done it I guess. My DEAL with the warming is all about the ice cores taken. Shows the atmospheric content up to 600K yrs ago. If it was high, coulda been warm. It goes in big 1000yr+ cycles. FYI, did yall know there was 60% more oxygen content in the air in dino times? Apparently that explains why everything was so huge. Always wondered about that myself. There's my tangent back at ya, heheh. By data partition and non-executables, I consider html, all web scripting, doc, wmv, and a couple other M$-made tragedies. If those are out, would TRUELY data only files be safe or are there viruses that alter them.. I guess just to trash them, as they couldn't run any code thru them? Looks like the answer to the Q is not exactly a cross partition virus could get you with this setup, but a MBR could infect that which affects all? No way to protect that other than run AV on all OS partitions? I plan to do that, but there is the lag time issue as with all malware. I haven't heard of any MBR virs in a long time, but didn't somebody say they were resurging? Hows the dmg they do these days rate as far as virs go? I think my move should be to reinstall everything from clean M$ CD, then pull M$ updates, then the AV update, burn boot CD, scan everything on the backed up drive(s), then scan the whole F-ing dirty partition with the latest update every time I switch to the clean one. Guess I better keep it small! Man, I need to comps like my friend does. Grrr. It was sooooo nice back in BBS days when you could just scan every file you dl'd and every floppy you put in, and you were good to go Cursed web! BTW, how about we separate out the Java posts, the specific virus prob posts, and whatever else into separate threads? I'm exempting me and you about Antarctica though ;> That makes a lot more sense now. Thanks for the information guys, you just schooled me. |
|
| 1497. |
Solve : Fatal System Error (associated w/ csrss.exe) PLEASE HELP!!? |
|
Answer» **THANK YOU IN ADVANCE FOR ALL THE HELP & ASSISTANCE** Go here and follow the directions. Thanks for the reply. However, I don't think posting there will do me any good (right now), because I can't even boot up the computer. I can't run HiJack This and/or anything else. Basically,.....right now, I am dead in water. Believe me though. If I can get this first step resolved, I WILL be posting there! Thanks.Do you know anybody that has a windows XP disc that you can borrow? Quote from: iamtonsoffun247 on July 25, 2009, 10:34:13 PM Do you know anybody that has a windows XP disc that you can borrow? Thank you for the reply. Not readily available. I do, however, have a Dell "operating system" CD from a different Dell I have. (My problem is on my Dell Inspiron laptop. I have the system recovery CD for a Dell Dimension desktop.) Both the laptop and desktop run XP. However, I just attempted to boot the CD ROM first, as opposed to the hard drive, because I was attempting to see if I could get MalwareBytes & HiJackThis to run/load. No such luck. Still got the Fatal System Error. |
|
| 1498. |
Solve : Sit & Meditate while your SuperAntispyware Updates!? |
|
Answer» Hi Geeks!
Windows itself will repair the connection, you can access that utility in networks, and Windows also has the ability to take a screen capture. Extra utilities aren't necessary for those two. |
|
| 1499. |
Solve : Hyjack log after Firefox mystery? |
|
Answer» i posted about a problem that i'm having with firefox 3.5 in the browser forum and karnac suggested that i post my hyjack scan here. |
|
| 1500. |
Solve : downloading free avg to a mamory stick to be transfered to another p.c.?? |
|
Answer» I ahve an old 2001 compaq with a lot of VIRUSES on it it won't let me connect to the INTERNET so need to down load avg to a memory stick on my LAPTOP and transfer it to my old desktop. How can I do that please help!!!Just hold tight man. A virus specialist will be with you. |
|