InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 301. |
Solve : Help: Several problems I believed caused by an infection long ago? |
|
Answer» 1. Right-click the My Computer icon on the Desktop and click Properties.
rstrui.exe
SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 09:43 on 11/06/2010 by Rachell (Administrator - Elevation successful) ========== filefind ========== Searching for "rstrui.exe" C:\WINDOWS\$NtServicePackUninstall$\rstrui.exe--a--c 380416 bytes[08:02 16/10/2008][19:00 04/08/2004] 4375CD59161C0A033DF68D9510D1F8CF C:\WINDOWS\ServicePackFiles\i386\rstrui.exe--a--c 380416 bytes[17:31 29/08/2008][00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD C:\WINDOWS\system32\dllcache\rstrui.exe--a--c 380416 bytes[19:01 07/08/2004][00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD C:\WINDOWS\system32\Restore\rstrui.exe--a--- 380416 bytes[19:01 07/08/2004][00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD -=End Of File=-Please open Notepad and enter in the following: Quote Windows Registry Editor Version 5.00Then, click File > Save as... Save as enableSR.reg to your Desktop. Choose Save as type... All Files. Click Save. Then, exit Notepad. Double-click on enableSR.reg. Then, restart your computer. Then, look in the System Properties window again for the System Restore tab.Sorry for just now writing back, long weekend... I did what you said and it asked if I wanted to add it to my registry I said yes and it said it had. I restarted and still no system restore tab. Also I get the same message still if I try to open System restore.
Diagnostic Report (1.9.0027.0): ----------------------------------------- Windows Validation Data--> Validation Status: Genuine Validation Code: 0 Cached Validation Code: N/A Windows Product Key: *****-*****-XXXXX-XXXXX-XXXXX Windows Product Key HASH: 2V2VyxlfhiaCt/JkDzYQfiNOHMA= Windows Product ID: 76477-OEM-2111907-00106 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010300.3.0.hom ID: {16CCC64D-E3B3-4DA7-B4CA-7D6BBD0ECCAE}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: Registered, 1.7.69.2 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1 Resolution Status: N/A Vista WgaER Data--> ThreatID(s): N/A Version: N/A Windows XP Notifications Data--> Cached Result: 0 File Exists: Yes Version: 1.7.17.0 WgaTray.exe Signed By: Microsoft WgaLogon.dll Signed By: Microsoft OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 102 Microsoft Office Standard Edition 2003 - 100 Genuine OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005 Browser Data--> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not MARKED as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> Other data--> Office Details: {16CCC64D-E3B3-4DA7-B4CA-7D6BBD0ECCAE}1.9.0027.05.1.2600.2.00010300.3.0.homx32*****-*****-*****-*****-3PMFT76477-OEM-2111907-001062S-1-5-21-1273659944-3790613762-3211983470HP Pavilion 061PL382AA-ABA A706NPhoenix Technologies, LTD 3.1120040902000000.000000+000HP PAVILION21DD39AF0184205F04090409Eastern Standard Time(GMT-05:00)02Hewlett-PackardPavilion102100Microsoft Office Standard Edition 200311606A581CC1FD930FEOgdhbkAmkHjihJ9UWrNxearM4=70141-152-3817414-5631810 Licensing Data--> N/A Windows Activation Technologies--> N/A HWID Data--> N/A OEM Activation 1.0 Data--> BIOS string MATCHES: yes Marker string from BIOS: 106DD:Compaq Computer Corporation|106DD:Compaq Computer Corporation|106DD:Hewlett-Packard Company|10859:Hewlett-Packard Company Marker string from OEMBIOS.DAT: HP PAVILION OEM Activation 2.0 Data--> N/A -Click Start, and then click My Computer. -On the Tools menu, click Folder Options. -On the View tab, click Show hidden files and folders. -Clear the Hide protected operating system files (Recommended) check box. Click Yes when you are prompted to confirm the change. -Clear the Use simple file sharing (Recommended) check box. -Click OK. -Right-click the System Volume Information folder in the root folder, and then click Properties. -Click the Security tab. -Click Add, and then type the name of the user to whom you want to give access to the folder. Typically, this is the account with which you are logged on. Click OK, and then click OK again. -Then, navigate to C:\SystemVolumeInformation right click on it, and click on Rename. -Rename it to SystemVolumeBAK -Restart your computer. Tell me if you can see the Restore tab.Ok, Can you explain ''-Right-click the System Volume Information folder in the root folder'' I don't know where/what those are exactly? Sorry when I got to that step I was unsure of what to do. I did the first stuff already though. Clicked Show hidden files and folders already, Hide protected operating system files (Recommended) was already unchecked and there is no Use simple file sharing (Recommended) check box. c:\SystemVolumeInformationIt's not there and if I try to RUN it says Windows can not find 'c:\SystemVolumeInformation'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click search. Do you have a Windows XP CD?? We need to do a system in-place upgrade, which is a data-safe process to fully repair Windows. However, if you do not feel comfortable with this, there are alternative routes to be able to take to backup your system configuration, like ERUNT program. |
|
| 302. |
Solve : psw.generic8.QQ malware?? |
|
Answer» I've been working on a neighbors system for a few days trying to remove this pswgeneric8.QQ anyone have any experience with this one? I'll be running Hihack this this tomorrow night. Looks well written and have been OUTWITTED at most turns.
Please DOWNLOAD MySystem-Search from here: Download mirror
|
|
| 303. |
Solve : Application cannot be executed. The file *** is infected.? |
|
Answer» I got a serious issue with my system. Somehow some trogan/rogue has affected my system. It keeps flashing me virus alert and whenever i try to run any program it says "Application cannot be executed. The file **** is infected......." (not even a command prompt or notepad can be opened but with multiple try sometime i get the command prompt but it is ridiculous). I saw a post about this but super dave said i would need my own help b/c it is complicated i need help asap[ SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 03/01/2010 at 04:45 AM Application Version : 4.34.1000 Core Rules Database Version : 4596 Trace Rules Database Version: 1978 Scan type : Complete Scan Total Scan Time : 00:56:48 Memory ITEMS scanned : 475 Memory threats detected : 0 Registry items scanned : 5328 Registry threats detected : 4 File items scanned : 56527 File threats detected : 91 Rogue.AntivirusSoft [eyvcgfqu] C:\DOCUMENTS AND SETTINGS\MARCUS\LOCAL SETTINGS\APPLICATION DATA\YXRHFW\NMHWSFTAV.EXE C:\DOCUMENTS AND SETTINGS\MARCUS\LOCAL SETTINGS\APPLICATION DATA\YXRHFW\NMHWSFTAV.EXE HKU\S-1-5-21-13070270-1486359743-909414271-1008\Software\avsoft Adware.Tracking Cookie C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][3].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][3].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\jud[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][3].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt Rogue.Agent/Gen HKLM\SOFTWARE\07720420 HKLM\SOFTWARE\07720420#FirstRun Malware.Installer-Pkg/Gen C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{26D2C2C3-CF14-4ED7-B1FC-0BE64AFBA3B3}.EXE C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{3C48F877-A164-45E9-B9DA-26A049FFC207}.EXE C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6293BC00-4EB8-4C65-8548-53E2FC3BF937}.EXE C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{651956B7-1969-42AA-9453-E0B813019D54}.EXE C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA}.EXE C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{989E4C3B-B2C9-4486-9A09-D5A8F953837C}.EXE C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C2D8F0E2-6978-4409-8351-BA8785DA11EE}.EXE C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{D1A6F3FD-7B40-443F-8767-BADB25A0D222}.EXE C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{E0814F95-5380-4892-B8C8-7FA4B349EF46}.EXE Adware.Vundo/Variant-Senorita C:\WINDOWS\SYSTEM32\BIGUKOVE.DLL C:\WINDOWS\SYSTEM32\BOBUHEZE.DLL C:\WINDOWS\SYSTEM32\FUNEREVU.DLL C:\WINDOWS\SYSTEM32\GAWOJUSO.DLL C:\WINDOWS\SYSTEM32\HIGUBOWO.DLL C:\WINDOWS\SYSTEM32\KABAHIGO.DLL C:\WINDOWS\SYSTEM32\KUFULEMU.DLL C:\WINDOWS\SYSTEM32\MEMUREZO.DLL C:\WINDOWS\SYSTEM32\MUFOHITO.DLL C:\WINDOWS\SYSTEM32\NAHATONA.DLL C:\WINDOWS\SYSTEM32\PAJOSURI.DLL C:\WINDOWS\SYSTEM32\WURAJOBI.DLL C:\WINDOWS\SYSTEM32\YAWEVODU.DLL C:\WINDOWS\SYSTEM32\ZAWEDIVO.DLL C:\WINDOWS\SYSTEM32\ZUHUYABA.DLL C:\WINDOWS\SYSTEM32\ZUWUPIMA.DLL Adware.Vundo/Variant-EC C:\WINDOWS\SYSTEM32\DIFORUSA.DLL C:\WINDOWS\SYSTEM32\FAGESEFA.DLL C:\WINDOWS\SYSTEM32\YOBIJOWU.DLL Adware.Vundo/Variant-[Fixed] C:\WINDOWS\SYSTEM32\LODORAJA.DLL C:\WINDOWS\SYSTEM32\MIZUYOHA.DLL C:\WINDOWS\SYSTEM32\TAROKUWE.DLL Adware.Vundo/Variant-BigJunk C:\WINDOWS\SYSTEM32\VIDUVUVE.DLL Adware.Vundo/Variant-Diddle C:\WINDOWS\SYSTEM32\YUYIFANE.DLL May I know the operating system? Internet connection type? Any specific pop up that you're being prompted to INSTALL? Hello, I am getting the same message.. Application cannot be executed. The file *** is infected. and it keeps popping up every 2 minutes....also a windows security alert keeps popping up...i need help desperatley!!!! please...Hi Telly 24... May I know the version of the operating system that you have. Internet connection type:..?yes, its windows xp and i use internet exploer and moziilla firefox...and i have at&t dsl..i recently got it about 5 days ago...and those yellow shields with the exclamation points are all acroos my toolbar at the bottom of my screen!!! i need help!!Hi, this seems to be what's happening to me as well. In addition, after awhile random PORN sites will pop up. There's also a file on my desktop that I didn't put there: hs_err_pid1176.txt I'm running Windows XP, using a wireless connection on my laptop. As for my browser, I use Internet Explorer. I hope that's enough! YES THE RANDOM PORN WEBSITES ARE HAPPENING TO ME AS WELL!!!Please DO NOT give advice in this forum UNLESS you are a malware specialist.thank u so much..i will give it a try and u know!!!! -tellyhey... it wont let me open the iexplore (misconfig)...the same error message is popping up..its saying its infected and do i want to run antivrus scan now....the "System Configuration Utility" screen pops up now but it dissaperas after a second..i cant do anything with it...You have been warned to not post any advice in this forum. |
|
| 304. |
Solve : persistent TR/Crypt.Xpack.gen? |
|
Answer» I'll look you up the NEXT time I'm in HAWAII OK - how do I MARK this ONE [solved] ? I can do that for you |
|
| 305. |
Solve : Virus will not get out of my computer...requesting assistance pls.? |
|
Answer» That's good. I would say your computer is as clean as our scans can make it. Let's do some clean-up. |
|
| 306. |
Solve : Stuck with fake antivirus, can't install anything.? |
|
Answer» Alright, here is the OTM log first, scanning with ESET now. That file looked suspicious to me also when I looked at the GSI report, 58FE1887.exe. Hey man, I really appreciate the time and effort you guys spend on these forums.
Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Results of screen317's Security Check version 0.99.4 Windows XP Service Pack 3 Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! ESET Online Scanner v3 ESET Online Scanner WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Java(TM) 6 Update 18 Out of date Java installed! Adobe Flash Player 9 (Out of date Flash Player installed!) Adobe Flash Player 10.0.45.2 Adobe Reader 9.1.2 Out of date Adobe Reader installed! Mozilla Firefox (3.6.6) ```````````````````````````````` Process Check: objlist.exe by Laurent ```````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) ``````````End of Log```````````` Those are in quarantine and are harmless. Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is IMPORTANT to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7). Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. == Please download the newest version of Java from Java.com. Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7). Search in the list for all previous installed versions of Java. (J2SE Runtime ENVIRONMENT). Please uninstall/remove each of them. Once old versions are gone, please install the newest version. ================================= Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Antivirus/Antispyware
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
Okay, I updated my Java and my Adobe Flash, and I tried using hphost but I feel like it is to much for me so I took it off. Thanks for all these great programs!You're welcome.lol. I don't really know how to express my relieve and my gratefulness for you because I'm not very good at it. lol I just want to say that I am just very happy for this forum to exist and for people like you who spend countless hours providing easy to read step by step instructions on fighting malware. I don't know if you guys have a database where you keep a bunch of pre-written instructions but I think it is very helpful and it definitely makes things go a lot quicker. You probably receive hundreds of thank you's or whatnot but I don't know any other way to express how I feel right not without using profanity so thank you. This will be my last post for a while because I am inspired deeply of the things a Malware removal specialist do. Next time I post, it will be approximately a year or so later and I will come back telling you about my accomplishments as a Malware removal specialist. I know it isn't like riding a bike on a downhill and its not just saying I have to do it, but I have a lot of time on me and hopefully I will have a good start. Hopefully you will remain in this forum, no pressure =P. You might be busy with other important things. p.s-waiting for bleepingcomputer to have an open slot |
|
| 307. |
Solve : infected laptop?? |
|
Answer» i'm running Windows XP home service pack 1. S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/4/2009 2:50 PM 7408] . Contents of the 'Scheduled Tasks' folder 2010-07-07 c:\windows\Tasks\Symantec NetDetect.job - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-10-23 17:24] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/ IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm . - - - - ORPHANS REMOVED - - - - BHO-{BD31D51D-B8AD-4E64-B8CE-91AAF4DB1E54} - c:\windows\System32\byvsq.dll HKCU-Run-dmfcvtdn - c:\documents and settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe HKCU-Run-{029289AA-FCD3-A95A-5DCF-8D3D723B1BBA} - c:\documents and settings\Big Dog\Application Data\Ryxun\kulei.exe HKCU-Run-Acarucu - c:\windows\moncodi.dll HKLM-Run-dmfcvtdn - c:\documents and settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe HKLM-Run-Evuco - c:\windows\amuhegucob.dll MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe MSConfigStartUp-SSC_UserPrompt - c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-07-07 00:32 Windows 5.1.2600 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\8ond*Ä***Àˆ/*_*a*u*t*o*_*f*i*l*e*\shell\open\command] @="\"c:\\Program Files\\Winamp\\winamp.exe\" \"%1\"" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(968) c:\windows\system32\ODBC32.dll c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'lsass.exe'(1028) c:\windows\System32\dssenh.dll . Completion time: 2010-07-07 00:35:37 ComboFix-quarantined-files.txt 2010-07-07 04:35 Pre-Run: 11,391,451,136 bytes free Post-Run: 11,687,886,848 bytes free winxpsp1_en_hom_bf.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect - - End Of File - - 79FC033ACDA507704DE217164703EEA6 GMER Note about this tool:
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised! If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Rootkit scan 2010-07-09 23:37:37 Windows 5.1.2600 Service Pack 1 Running: gmer.exe; Driver: C:\DOCUME~1\BIGDOG~1\LOCALS~1\Temp\uwtdqpob.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwConnectPort [0xB2A82C90] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateFile [0xB2A7FB70] SSDT F8C3B496 ZwCreateKey SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateProcess [0xB2A97760] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateProcessEx [0xB2A97980] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateSection [0xB2A9A610] SSDT F8C3B48C ZwCreateThread SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteFile [0xB2A80180] SSDT F8C3B49B ZwDeleteKey SSDT F8C3B4A5 ZwDeleteValueKey SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDuplicateObject [0xB2A97080] SSDT F8C3B4AA ZwLoadKey SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenFile [0xB2A7FFD0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenProcess [0xB2A96E80] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenThread [0xB2A96C40] SSDT F8C3B4B4 ZwReplaceKey SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRequestWaitReplyPort [0xB2A82960] SSDT F8C3B4AF ZwRestoreKey SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSecureConnectPort [0xB2A82E40] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetInformationFile [0xB2A802F0] SSDT F8C3B4A0 ZwSetValueKey SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwTerminateProcess [0xB2A97BB0] ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!_abnormal_termination + 38F 804DE941 3 Bytes [2E, A8, B2] ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCoSendPackets] 8162C5C0 IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [B2AA5980] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\irda.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\irda.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\irda.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\irda.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [B2A80630] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [B2A80580] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [B2A806F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtCreateFile] [B2A804A0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [63601740] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.) ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs avgntmgr.sys (Avira AntiVir File Filter Driver Manager/Avira GmbH) AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.) Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft CORPORATION) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.) Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.) Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.) Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.) AttachedDevice \FileSystem\Fastfat \Fat avgntmgr.sys (Avira AntiVir File Filter Driver Manager/Avira GmbH) AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.) ---- EOF - GMER 1.0.15 ---- Please run a free online scan with the ESET Online Scanner
[emailprotected] as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # IEXPLORE.EXE=6.00.2800.1106 (xpsp1.020828-1920) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=e54cef16f0e80844b00e0a12fbd7fbd1 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-07-12 04:45:50 # local_time=2010-07-12 12:45:50 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 1 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775165 100 94 0 50622782 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=9217 16777214 75 70 128644083 135471291 0 0 # scanned=39824 # found=4 # cleaned=4 # scan_time=2089 C:\Qoobox\Quarantine\C\Documents and Settings\Big Dog\Application Data\Ryxun\kulei.exe.virWin32/Spy.Zbot.YW trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\Documents and Settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe.vira variant of Win32/Injector.BXP trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\WINDOWS\amuhegucob.dll.vira variant of Win32/Cimag.CK trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\WINDOWS\moncodi.dll.vira variant of Win32/Cimag.CL trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
i couldnt get past the disk cleanup part. the program hangs up. should i skip that step?sureagain, sorry for the late reply but i have a SERIOUS problem now. i'm using a friend's computer right now because mine will not boot up. it seems as if my hard drive crashed. it started almost a week ago. i downloaded TFC and followed the steps. after all was finished i had to reboot manually as directed. i did and went to bed. i awoke the next morning to find a black screen with the words "Non-System disk or disk error. replace and strike any key when ready" nothing happens no matter which key i hit. i shut the computer off and tried to restart it. this time i hear clicking noises, then i get the same message. and the same results. what gives?Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster Jay@bklyn Do you have an XP disc?Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JaySorry, I mistakenly posted the last post from my friend's account. i thought he had logged off. Remember, I'm using his computer since i cannot use mine? Ok, all i have is a disc labeled "Operating System CD". Microsoft Windoes XP Home SP1a. |
|
| 308. |
Solve : Alureon.H rootkit virus TermDD? |
|
Answer» ESET Scan result: |
|
| 309. |
Solve : Spyware Problem. :/? |
|
Answer» Re-running ComboFix to remove infections:
Snapshot:: SysRst:: TDL:: c:\windows\system32\drivers\mouclass.sys c:\windows\system32\drivers\atapi.sys Reboot:: |
|
| 310. |
Solve : File wuauclt.exe is infected? |
|
Answer» Thank you very much for your assistance in CLEANING my COMPUTER. It WORKS great! Thanks again!You're WELCOME. |
|
| 311. |
Solve : multiple virus attacks? |
|
Answer» I have been attacked by multiple viruses. My AV, Bit Defender has blocked them but has not gotten rid of them, after waiting 4 days for their help I DECIDED to follow the steps here to remove them. I used SuperAV and found four infections, and removed them, but today the viruses came back. So I ran antiMalware and found 5( some of which MIGHT have be in quarantine. I next did a hijack log but I got a message saying "denied write access to Host file" hijack gave me instructions on how to resolve this but that didn't work. I suspect these viruses are still there. I could not cut and paste the hijack log but I did take a pic of it. I would appreciate any help . |
|
| 312. |
Solve : Malware removal - can't perform any suggested steps with .exe file? |
|
Answer» I ran superantispyware this morning and rebooted per your instructions. Once I did that, I could not open any progeam, I get the error message about .exe file being infected. So I ran rkill again since that is what enabled me to do ANYTHING yesterday. OK, now I am very proud of myself - hahaGood job well done! Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system. First Verify your Java Version If there are any other version(s) installed then update now. Get the new version (if needed) If your version is out of date install the newest version of the Sun Java Runtime Environment. Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close ALL open web browsers before starting the installation. Remove any old versions 1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA. 4. Run CCleaner. Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. ************************************* Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. *************************************** Open HijackThis and select Do a system scan only Place a check mark next to the following entries: (if there) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) O4 - HKCU\..\Run: [rjyqbvyn] Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. **************************************** Download ComboFix by sUBs from one of the below links. Important! You MUST save ComboFix to your desktop link # 1 Link # 2 Temporarily disable your Anti-virus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click on ComboFix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) Do not mouse-click ComboFix's window while it is running. That may cause it to stall. When the scan completes it will open a text window. Post the contents of that log in your next reply. Remember to re-enable your Anti-virus and Antispyware protection when ComboFix is complete.I did everything, except ComboFix will not install is pops u[ an Error - Win32 only. I have 64 bit, Vista.Quote I have 64 bit, Vista.Oops. 64 bit machines severely limits the number of tools I can use to clean your computer. Sorry. Download OTL to your Desktop
msconfig safebootminimal safebootnetwork activex drivers32 %SYSTEMDRIVE%\*.exe %systemroot%\*. /mp /s c:\$recycle.bin\*.* /s HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs /md5start eventlog.dll scecli.dll netlogon.dll cngaudit.dll sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys nvstor32.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll explorer.exe svchost.exe userinit.exe qmgr.dll ws2_32.dll proquota.exe imm32.dll kernel32.dll ndis.sys autochk.exe spoolsv.exe xmlprov.dll ntmssvc.dll mswsock.dll Beep.SYS ntfs.sys termsrv.dll sfcfiles.dll st3shark.sys ahcix86.sys srsvc.dll nvrd32.sys /md5stop %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles
Here is the OTL log: OTL logfile created on: 8/22/2010 1:14:00 PM - Run 1 OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Lisa\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18943) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 52.00% Memory free 8.00 Grb Paging File | 6.00 Gb Available in Paging File | 73.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 219.91 Gb Total Space | 68.89 Gb Free Space | 31.32% Space Free | Partition Type: NTFS Drive D: | 12.97 Gb Total Space | 2.43 Gb Free Space | 18.77% Space Free | Partition Type: NTFS Drive E: | 7.24 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: LISA-LAPTOP Current User Name: Lisa Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: On Skip Microsoft Files: On File Age = 90 Days Output = Standard Quick Scan ========== Processes (SafeList) ========== PRC - [2010/08/22 13:10:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Lisa\Desktop\OTL.exe PRC - [2010/06/19 12:36:46 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe PRC - [2010/06/11 09:37:26 | 000,185,640 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe PRC - [2010/06/11 09:37:24 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe PRC - [2010/06/11 09:37:10 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe PRC - [2010/05/14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe PRC - [2010/04/22 10:25:38 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PRC - [2010/03/17 16:53:24 | 000,207,872 | ---- | M] (Alcatel-Lucent) -- C:\Program Files (x86)\Common Files\Motive\McciContextHookShim.exe PRC - [2010/02/12 11:02:08 | 000,240,992 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe PRC - [2010/02/09 17:07:22 | 001,275,408 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\Internet Content Filter\mfp.exe PRC - [2010/01/26 20:58:38 | 000,256,280 | R--- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10e.exe PRC - [2009/11/18 10:50:40 | 000,668,912 | ---- | M] (Radialpoint Inc.) -- C:\Program Files (x86)\Verizon\VSP\ServicepointService.exe PRC - [2009/11/18 10:50:32 | 000,468,208 | ---- | M] (Radialpoint Inc.) -- C:\Program Files (x86)\Verizon\VSP\VerizonServicepointComHandler.exe PRC - [2009/11/18 10:50:30 | 004,269,296 | ---- | M] (Verizon) -- C:\Program Files (x86)\Verizon\VSP\VerizonServicepoint.exe PRC - [2009/08/05 22:11:05 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2009/05/13 16:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2009/04/11 02:28:15 | 000,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe PRC - [2009/03/02 13:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2008/08/01 20:10:54 | 000,675,840 | ---- | M] (Sonix) -- C:\Windows\vsnp2uvc.exe PRC - [2008/04/15 18:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe PRC - [2008/04/15 18:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe ========== Modules (SafeList) ========== MOD - [2010/08/22 13:10:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Lisa\Desktop\OTL.exe MOD - [2008/01/20 22:50:01 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx ========== Win32 Services (SafeList) ========== SRV:64bit: - [2010/06/29 13:49:27 | 000,128,752 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE) SRV:64bit: - [2009/10/28 10:05:15 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:64bit: - [2009/08/18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2010/06/11 09:37:26 | 000,185,640 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe -- (tgsrvc_verizondm) SupportSoft Repair Service (verizondm) SRV - [2010/06/11 09:37:24 | 000,206,120 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe -- (sprtsvc_verizondm) SupportSoft Sprocket Service (verizondm) SRV - [2010/05/14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort) SRV - [2010/03/18 14:27:14 | 001,020,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400) SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64) SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/02/10 19:11:00 | 000,020,480 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Verizon\Online Backup & Sharing\Scheduler\OnlineBackup.SchedulerService.exe -- (OnlineBackupSchedulerService) SRV - [2010/02/09 17:13:32 | 000,275,456 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\Internet Content Filter\UpdateService.exe -- (fpUpdateSvc) SRV - [2010/02/02 20:02:52 | 000,024,576 | ---- | M] (DigiData Corp.) [Auto | Running] -- C:\Program Files (x86)\Verizon\Online Backup & Sharing\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe -- (FilesystemWatcher) SRV - [2009/11/18 10:50:40 | 000,668,912 | ---- | M] (Radialpoint Inc.) [Auto | Running] -- C:\Program Files (x86)\Verizon\VSP\ServicepointService.exe -- (ServicepointService) SRV - [2009/10/28 10:02:52 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2009/08/05 22:11:05 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2009/05/13 16:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2008/08/15 05:46:20 | 000,284,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4) SRV - [2008/04/15 18:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R) SRV - [2007/03/05 13:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb) ========== Driver Services (SafeList) ========== DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\SymIM.sys -- (SymIMMP) DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\SymIM.sys -- (SymIM) DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ipinip.sys -- (IpInIp) DRV:64bit: - [2009/12/07 10:30:10 | 000,074,880 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\DRIVERS\avgntflt.sys -- (avgntflt) DRV:64bit: - [2009/09/30 20:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb) DRV:64bit: - [2009/08/28 20:42:52 | 000,049,152 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64) DRV:64bit: - [2009/06/09 17:16:06 | 003,557,376 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC) DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2009/04/11 01:03:32 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\sdbus.sys -- (sdbus) DRV:64bit: - [2008/07/07 13:23:56 | 000,025,600 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\NwUsbCdFil64.sys -- (NWUSBCDFIL64) DRV:64bit: - [2008/06/02 17:28:52 | 000,247,808 | ---- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\NWADIenum.sys -- (NWADI) DRV:64bit: - [2008/05/09 12:08:40 | 000,213,120 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwusbser2.sys -- (NWUSBPort2) DRV:64bit: - [2008/05/09 12:08:40 | 000,213,120 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwusbser.sys -- (NWUSBPort) DRV:64bit: - [2008/05/09 12:08:40 | 000,213,120 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwusbmdm.sys -- (NWUSBModem) DRV:64bit: - [2008/04/15 18:54:16 | 000,388,120 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\iaStor.sys -- (iaStor) DRV:64bit: - [2008/01/20 22:49:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RootMdm.sys -- (ROOTMODEM) DRV:64bit: - [2008/01/20 22:46:57 | 001,523,712 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS -- (HSF_DPV) DRV:64bit: - [2008/01/20 22:46:57 | 000,724,480 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS -- (winachsf) DRV:64bit: - [2008/01/20 22:46:57 | 000,286,720 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS -- (HSFHWAZL) DRV:64bit: - [2008/01/18 07:31:30 | 000,320,560 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\SynTP.sys -- (SynTP) DRV:64bit: - [2007/09/17 19:17:46 | 000,135,680 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169) DRV:64bit: - [2007/07/11 13:30:34 | 000,009,088 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\HpqRemHid.sys -- (HpqRemHid) DRV:64bit: - [2007/06/28 11:09:56 | 003,148,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\NETw4v64.sys -- (NETw4v64) Intel(R) DRV:64bit: - [2007/06/18 20:13:12 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys -- (HpqKbFiltr) DRV:64bit: - [2007/05/31 14:39:32 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RimUsb_AMD64.sys -- (RimUsb) DRV:64bit: - [2007/05/01 04:00:00 | 000,052,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2007/03/26 22:48:24 | 000,055,808 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rixdpx64.sys -- (rismxdp) DRV:64bit: - [2007/03/19 15:09:36 | 000,055,808 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rimmpx64.sys -- (rimmptsk) DRV:64bit: - [2007/02/27 19:10:38 | 000,053,760 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rimspx64.sys -- (rimsptsk) DRV:64bit: - [2007/01/18 16:10:22 | 000,030,336 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys -- (RimVSerPort) DRV:64bit: - [2007/01/17 09:48:30 | 001,455,616 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\smserial.sys -- (smserial) DRV:64bit: - [2006/10/09 22:09:03 | 000,742,696 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nvm60x64.sys -- (NVENETFD) DRV:64bit: - [2006/10/06 22:13:22 | 000,550,912 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys -- (BCM43XV) DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\Wbem\ntfs.mof -- (Ntfs) DRV - [2010/03/17 16:53:38 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Motive\MREMP50.sys -- (MREMP50) DRV - [2010/03/17 16:53:22 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Motive\MRESP50.sys -- (MRESP50) DRV - [2009/03/20 20:03:36 | 000,043,032 | ---- | M] (Smith Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Verizon Wireless\VZAccess Manager\SMSIVZAM5X64.sys -- (SMSIVZAM5X64) DRV - [2008/08/14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0unattached&bm=ho_central IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0unattached&bm=ho_central" FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546 FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/08/20 03:03:48 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/16 22:44:40 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/19 22:19:51 | 000,000,000 | ---D | M] [2008/08/29 16:19:26 | 000,000,000 | ---D | M] -- C:\Users\Lisa\AppData\Roaming\Mozilla\Extensions [2010/08/16 21:10:08 | 000,000,000 | ---D | M] -- C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\extensions [2009/09/03 12:31:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009/09/24 21:08:55 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2010/08/18 22:12:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions [2010/08/18 22:12:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.) O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found. O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.) O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll (Microsoft Corporation) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\Program Files (x86)\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll (Microsoft Corporation) O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] File not found O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) O4:64bit: - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix) O4:64bit: - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent) O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard) O4 - HKLM..\Run: [ICF] C:\Program Files (x86)\Internet Content Filter\mfp.exe (McAfee, Inc.) O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation) O4 - HKLM..\Run: [MSN Toolbar] c:\Program Files (x86)\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe (Microsoft Corp.) O4 - HKLM..\Run: [Online Backup Auto Update] C:\Program Files (x86)\Verizon\Online Backup & Sharing\Auto Update\OnlineBackup.UpdateSystemTray.exe () O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions) O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [Vault Explorer Cache Watcher] C:\Program Files (x86)\Verizon\Online Backup & Sharing\vewatch.exe (DigiData Corp.) O4 - HKLM..\Run: [VERIZONDM] C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKLM..\Run: [VerizonServicepoint.exe] C:\Program Files (x86)\Verizon\VSP\VerizonServicepoint.exe (Verizon) O4 - HKCU..\Run: [AdobeBridge] File not found O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com) O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/62.12/uploader2.cab (UploadListView Class) O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab (DLM Control) O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab (Verizon Wireless Media Upload) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 71.250.0.12 O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\HPSplash.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\HPSplash.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ] O33 - MountPoints2\{0d1e4c97-6bbf-11de-818e-001e68767086}\Shell - "" = AutoRun O33 - MountPoints2\{60aed025-a83a-11de-9cc3-001e68767086}\Shell - "" = AutoRun O33 - MountPoints2\{b9b5e17e-5c46-11de-8b9b-001e68767086}\Shell - "" = AutoRun O33 - MountPoints2\{dc3f7eeb-ef0c-11de-8248-001e68767086}\Shell - "" = AutoRun O33 - MountPoints2\{dc3f7f27-ef0c-11de-8248-001e68767086}\Shell - "" = AutoRun O33 - MountPoints2\{dc3f7f27-ef0c-11de-8248-001e68767086}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe -- File not found O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\G\Shell - "" = AutoRun O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) SafeBootMin:64bit: AppMgmt - Service SafeBootMin:64bit: Base - Driver Group SafeBootMin:64bit: Boot Bus Extender - Driver Group SafeBootMin:64bit: Boot file system - Driver Group SafeBootMin:64bit: File system - Driver Group SafeBootMin:64bit: Filter - Driver Group SafeBootMin:64bit: HelpSvc - Service SafeBootMin:64bit: mcmscsvc - Service SafeBootMin:64bit: MCODS - Service SafeBootMin:64bit: PCI Configuration - Driver Group SafeBootMin:64bit: PEVSystemStart - Service SafeBootMin:64bit: PNP Filter - Driver Group SafeBootMin:64bit: Primary disk - Driver Group SafeBootMin:64bit: procexp90.Sys - Driver SafeBootMin:64bit: sacsvr - Service SafeBootMin:64bit: SCSI Class - Driver Group SafeBootMin:64bit: System Bus Extender - Driver Group SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: mcmscsvc - Service SafeBootMin: MCODS - Service SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PEVSystemStart - Service SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: procexp90.Sys - Driver SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) SafeBootNet:64bit: AppMgmt - Service SafeBootNet:64bit: Base - Driver Group SafeBootNet:64bit: Boot Bus Extender - Driver Group SafeBootNet:64bit: Boot file system - Driver Group SafeBootNet:64bit: File system - Driver Group SafeBootNet:64bit: Filter - Driver Group SafeBootNet:64bit: HelpSvc - Service SafeBootNet:64bit: mcmscsvc - Service SafeBootNet:64bit: MCODS - Service SafeBootNet:64bit: Messenger - Service SafeBootNet:64bit: MpfService - Service SafeBootNet:64bit: NDIS Wrapper - Driver Group SafeBootNet:64bit: NetBIOSGroup - Driver Group SafeBootNet:64bit: NetDDEGroup - Driver Group SafeBootNet:64bit: Network - Driver Group SafeBootNet:64bit: NetworkProvider - Driver Group SafeBootNet:64bit: PCI Configuration - Driver Group SafeBootNet:64bit: PEVSystemStart - Service SafeBootNet:64bit: PNP Filter - Driver Group SafeBootNet:64bit: PNP_TDI - Driver Group SafeBootNet:64bit: Primary disk - Driver Group SafeBootNet:64bit: procexp90.Sys - Driver SafeBootNet:64bit: rdsessmgr - Service SafeBootNet:64bit: sacsvr - Service SafeBootNet:64bit: SCSI Class - Driver Group SafeBootNet:64bit: Streams Drivers - Driver Group SafeBootNet:64bit: System Bus Extender - Driver Group SafeBootNet:64bit: TDI - Driver Group SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet:64bit: WudfPf - Driver SafeBootNet:64bit: WudfUsbccidDriver - Driver SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart CARD readers SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: mcmscsvc - Service SafeBootNet: MCODS - Service SafeBootNet: Messenger - Service SafeBootNet: MpfService - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PEVSystemStart - Service SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: procexp90.Sys - Driver SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: WudfPf - Driver SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {96BFD4F7-F575-5C17-05D3-688924F854EB} - Browser Customizations ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player ActiveX: {25E8E74C-C20D-210C-870C-510830400FBC} - Microsoft Windows Media Player ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {B466C5AD-B9F4-24CE-66A7-2AF39C67E7A7} - Microsoft VM ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.3IV2 - C:\Windows\SysWow64\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.) Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) ========== Files/Folders - Created Within 90 Days ========== [2010/08/22 13:10:48 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Lisa\Desktop\OTL.exe [2010/08/20 03:24:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Portable Devices [2010/08/20 03:24:28 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices [2010/08/20 03:03:46 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\vi-VN [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\eu-ES [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\eu-ES [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ca-ES [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ca-ES [2010/08/19 11:00:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\vi-VN [2010/08/19 10:31:01 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\virus stuff [2010/08/18 22:37:52 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\TURTLE template 8610-446 *censored* [2010/08/18 22:32:10 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW [2010/08/18 22:23:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft [2010/08/18 22:23:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSN Toolbar [2010/08/18 22:17:02 | 000,000,000 | ---D | C] -- C:\Windows\Sun [2010/08/18 22:14:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSN Toolbar Installer [2010/08/18 22:14:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2010/08/17 10:49:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro [2010/08/17 08:11:37 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\SUPERAntiSpyware.com [2010/08/17 08:11:27 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware [2010/08/14 15:18:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner [2010/08/13 22:14:55 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\Malwarebytes [2010/08/13 22:14:43 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010/08/13 22:14:41 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010/08/13 22:14:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010/08/13 22:14:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010/08/13 13:47:10 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com [2010/08/13 13:47:05 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE [2010/08/13 09:58:32 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\INNOVATION [2010/08/12 23:03:56 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\tconxtygj [2010/08/12 09:38:16 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\Converted [2010/08/10 16:15:47 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\Joe Z Banner file (3) [2010/08/04 20:23:07 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\personal and confidential [2010/07/30 15:33:44 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\File Folders USB Files [2010/07/30 15:15:18 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\Resumes [2010/07/30 15:14:42 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\Personal [2010/07/27 11:57:24 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\SOE documents [2010/07/26 09:24:45 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\Motive [2010/07/26 09:24:42 | 000,000,000 | ---D | C] -- C:\Program Files\Verizon [2010/07/22 10:33:07 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\Verizon [2010/07/21 18:53:39 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\Verizon [2010/07/21 18:53:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Radialpoint [2010/07/21 18:53:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Verizon [2010/07/21 18:53:28 | 000,000,000 | ---D | C] -- C:\Windows\bin [2010/07/21 18:52:45 | 000,409,928 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\seinst.dll [2010/07/21 18:52:45 | 000,378,696 | ---- | C] (McAfee, Inc.) -- C:\Windows\sediag.exe [2010/07/21 18:52:45 | 000,318,280 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysWow64\seinst.dll [2010/07/21 18:52:45 | 000,299,024 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysWow64\ICF.dll [2010/07/21 18:52:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Content Filter [2010/07/21 18:52:42 | 000,335,376 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\ICF.dll [2010/07/21 18:51:45 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\Citrix [2010/07/21 18:50:44 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\Apps [2010/07/21 18:50:41 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\Deployment [2010/07/21 18:47:14 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee [2010/07/21 18:46:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\verizon_broad [2010/07/21 18:46:54 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\DigiData [2010/07/21 18:46:26 | 000,000,000 | ---D | C] -- C:\ProgramData\DigiData [2010/07/21 18:46:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Verizon Online Backup [2010/07/21 18:44:21 | 000,000,000 | ---D | C] -- C:\Windows\FIOS [2010/07/21 18:13:48 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\SupportSoft [2010/07/21 18:13:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VERIZONDM [2010/07/21 18:13:30 | 000,000,000 | ---D | C] -- C:\ProgramData\SupportSoft [2010/07/21 18:13:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SupportSoft [2010/07/21 17:19:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Motive [2010/07/21 17:19:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Motive [2010/07/21 17:19:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Motive [2010/07/21 17:15:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Verizon [2010/07/14 12:49:07 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\Aurobindo Generics Support Catalogue and Monograph (2) [2010/06/15 09:51:36 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\RE new ecard_files [2010/05/26 09:55:20 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\Repository [1 C:\Users\Lisa\Desktop\*.tmp files -> C:\Users\Lisa\Desktop\*.tmp -> ] ========== Files - Modified Within 90 Days ========== [2010/08/22 13:14:08 | 004,718,592 | -HS- | M] () -- C:\Users\Lisa\NTUSER.DAT [2010/08/22 13:10:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Lisa\Desktop\OTL.exe [2010/08/22 12:38:35 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010/08/22 12:38:34 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010/08/22 12:22:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010/08/22 10:38:50 | 000,060,096 | ---- | M] () -- C:\ProgramData\nvModes.dat [2010/08/22 10:38:48 | 000,060,096 | ---- | M] () -- C:\ProgramData\nvModes.001 [2010/08/22 10:38:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010/08/21 17:04:43 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010/08/20 09:54:01 | 000,000,703 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2010/08/20 03:35:23 | 000,703,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010/08/20 03:35:23 | 000,604,502 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010/08/20 03:35:23 | 000,104,170 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010/08/20 03:27:37 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010/08/20 03:26:56 | 4293,320,704 | -HS- | M] () -- C:\hiberfil.sys [2010/08/20 03:24:03 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf [2010/08/20 03:23:46 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf [2010/08/20 03:23:39 | 000,524,288 | -HS- | M] () -- C:\Users\Lisa\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms [2010/08/20 03:23:39 | 000,065,536 | -HS- | M] () -- C:\Users\Lisa\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf [2010/08/20 03:23:34 | 001,526,296 | -H-- | M] () -- C:\Users\Lisa\AppData\Local\IconCache.db [2010/08/19 22:38:11 | 000,115,850 | ---- | M] () -- C:\Users\Lisa\Desktop\Innovation logo.jpg [2010/08/19 22:22:25 | 000,113,221 | ---- | M] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v4.jpg [2010/08/19 15:42:33 | 000,417,024 | ---- | M] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v3.jpg [2010/08/19 15:36:42 | 000,398,052 | ---- | M] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v2.jpg [2010/08/19 15:30:16 | 000,421,005 | ---- | M] () -- C:\Users\Lisa\Desktop\Static Innovation eCard.jpg [2010/08/19 11:10:19 | 003,824,136 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010/08/18 22:43:35 | 000,013,618 | ---- | M] () -- C:\Users\Lisa\Desktop\IndiaVisaApplication_Carco_Matthew_15YL.pdf [2010/08/13 22:05:57 | 000,000,680 | ---- | M] () -- C:\Users\Lisa\AppData\Local\d3d9caps.dat [2010/08/12 23:50:14 | 000,032,256 | ---- | M] () -- C:\Users\Lisa\Desktop\WE Innovate Posters - Print Grid 8-11-10 v2.xls [2010/08/12 19:26:52 | 065,744,817 | ---- | M] () -- C:\Users\Lisa\Desktop\I-innovate - flower resized.psd [2010/08/12 13:32:40 | 090,099,109 | ---- | M] () -- C:\Users\Lisa\Desktop\I-innovate - SEEK2 resized.psd [2010/08/11 23:43:30 | 065,278,521 | ---- | M] () -- C:\Users\Lisa\Desktop\I-innovate mohawk mirror resized.psd [2010/08/11 23:05:46 | 001,706,233 | ---- | M] () -- C:\Users\Lisa\Desktop\Ryan family background.ai [2010/08/10 13:11:52 | 000,045,568 | ---- | M] () -- C:\Users\Lisa\Documents\calendar INNOVATION dates.doc [2010/08/07 13:53:42 | 000,205,312 | ---- | M] () -- C:\Users\Lisa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/08/06 20:30:58 | 000,012,455 | ---- | M] () -- C:\Users\Lisa\Documents\HBO job.docx [2010/08/04 20:27:56 | 000,066,982 | ---- | M] () -- C:\Users\Lisa\Desktop\Volunteer-Abroad-US[1].pdf [2010/08/03 18:02:19 | 000,101,858 | ---- | M] () -- C:\Users\Lisa\Desktop\Horizon billing form.pdf [2010/08/01 21:21:12 | 000,794,320 | ---- | M] () -- C:\Users\Lisa\Desktop\our_path_forward_2009.pdf [2010/07/28 18:38:26 | 000,041,404 | ---- | M] () -- C:\Users\Lisa\Documents\Engagement via SkipLevelLunchesWithTheCEO.pdf [2010/07/27 10:16:03 | 000,184,333 | ---- | M] () -- C:\Users\Lisa\Documents\Matt EOB 7_24_2010.pdf [2010/07/21 18:51:45 | 000,103,720 | ---- | M] () -- C:\Users\Lisa\GoToAssistDownloadHelper.exe [2010/07/21 18:51:44 | 000,000,251 | ---- | M] () -- C:\Windows\win.ini [2010/07/19 23:13:40 | 000,000,162 | -H-- | M] () -- C:\Users\Lisa\Desktop\~$oxicillin_WIP_7-14-2010_v2.docx [2010/07/14 12:49:53 | 000,000,162 | -H-- | M] () -- C:\Users\Lisa\Desktop\~$robindo Generics Support Catalogue and Monograph_Amoxicillin_WIP_7-14-2010.doc [2010/07/12 19:38:01 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat [2010/07/09 18:47:42 | 001,535,488 | ---- | M] () -- C:\Users\Lisa\Desktop\Prescriber-Based Multi-Channel Non-Personal PROMOTION.ppt [2010/07/09 18:46:00 | 001,751,552 | ---- | M] () -- C:\Users\Lisa\Desktop\PAH Promotion Resource Optimization Proposal by ZS v3.0.ppt [2010/06/14 22:11:00 | 000,274,144 | ---- | M] () -- C:\Users\Lisa\AppData\Local\GDIPFONTCACHEV1.DAT [2010/06/11 22:16:54 | 009,830,400 | ---- | M] () -- C:\Windows\VerizonDM.msi [2010/06/09 10:53:29 | 000,726,349 | ---- | M] () -- C:\Users\Lisa\Documents\Kidnapped 3rd edition.pdf [2010/05/27 12:25:25 | 000,000,732 | ---- | M] () -- C:\Users\Lisa\AppData\Local\d3d9caps64.dat [1 C:\Users\Lisa\Desktop\*.tmp files -> C:\Users\Lisa\Desktop\*.tmp -> ] ========== Files Created - No Company Name ========== [2010/08/20 03:24:03 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf [2010/08/20 03:23:46 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf [2010/08/19 22:38:09 | 000,115,850 | ---- | C] () -- C:\Users\Lisa\Desktop\Innovation logo.jpg [2010/08/19 15:43:44 | 000,113,221 | ---- | C] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v4.jpg [2010/08/19 15:42:31 | 000,417,024 | ---- | C] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v3.jpg [2010/08/19 15:36:40 | 000,398,052 | ---- | C] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v2.jpg [2010/08/19 15:30:12 | 000,421,005 | ---- | C] () -- C:\Users\Lisa\Desktop\Static Innovation eCard.jpg [2010/08/18 22:43:26 | 000,01And here is the other. OTL Extras logfile created on: 8/22/2010 1:14:00 PM - Run 1 OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Lisa\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18943) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 52.00% Memory free 8.00 Gb Paging File | 6.00 Gb Available in Paging File | 73.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 219.91 Gb Total Space | 68.89 Gb Free Space | 31.32% Space Free | Partition Type: NTFS Drive D: | 12.97 Gb Total Space | 2.43 Gb Free Space | 18.77% Space Free | Partition Type: NTFS Drive E: | 7.24 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: LISA-LAPTOP Current User Name: Lisa Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: On Skip Microsoft Files: On File Age = 90 Days Output = Standard Quick Scan ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data] "VistaSp2" = 17 66 AF 91 B1 3F CB 01 [binary data] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "oobe_av" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.) "C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5625AE28-4574-41FB-A4DE-1CC871FAF451}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server | "{5E892D33-CFF7-40D7-A4E4-824AD5251D47}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{8DA6F7F6-CA3D-4CEE-A3BB-DEA851E17C9F}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server | "{8E995BE9-4939-4533-B171-9A54CDC0979A}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server | "{A65378CF-363F-40F9-914E-6D89560ABDB9}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 | "{BE1FEBAB-975B-4588-80C8-932CF374934D}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{23A3F5AC-386D-4A57-81F0-8A37F0A47244}" = protocol=17 | dir=in | app=c:\program files (x86)\verizon\vsp\servicepointservice.exe | "{2DD8283C-15DF-4A15-BED3-964E69FFDC73}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe | "{30ABFFFF-488F-43AD-996C-B6F5EA10E71B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{34276E30-E762-4410-A4FA-28E892D9CA3A}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe | "{3915D1B0-AF9B-4E63-A0D3-9C9D163407FF}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{433A6A18-2AD5-45B9-A8A0-298C95484410}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe | "{4E37717E-3A3F-4A82-874A-4FFB80A97219}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe | "{5EB2E882-0441-4BA0-9F5A-EEC7FC24553C}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe | "{68258586-E440-4BA9-B667-B490D866971E}" = protocol=6 | dir=in | app=c:\program files (x86)\verizon\vsp\servicepointservice.exe | "{731E5AD2-37AB-4D8F-A03F-2F1EFB658B87}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe | "{827F11E7-010A-4F53-919F-B6D5690315D6}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe | "{9CFD211B-FCB0-42A7-8F90-EC8202E47207}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{A6DA8734-DE4B-4E23-9DA1-B4E0D54F7009}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe | "{AFF0FA27-3D85-4CC4-818C-D60013EC36A8}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{BF5CA861-59EE-442F-8135-907F35F3C52C}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe | "{C963D5FD-CC67-4899-A390-155F9368A8AA}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe | "{D240A1BF-E625-4A99-B27A-DDAAA7B6DB62}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe | "{E6EDE86C-A88D-4A2A-96B9-D03F6E5BB1A0}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe | "{EB743B3C-82ED-4D04-8BB0-18DCE5633780}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe | "{EDED57E6-1299-44B0-9492-0843BF83102F}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe | "TCP Query User{034AB4B4-31EB-47E6-9060-EFF85738A9C9}C:\program files (x86)\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe | "TCP Query User{95ED204A-58C2-47F7-A973-FF64EF774398}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{CF882BE5-FAC7-4DA9-9718-2665997523CF}C:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe | "UDP Query User{14BC8FCA-DF02-46E0-A18F-685ADA7A066C}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{4D1D29DC-A63E-40C8-9D5A-D359936F874B}C:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe | "UDP Query User{9268EB9E-E61C-4A3D-9742-111F7462D417}C:\program files (x86)\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{11192F89-510C-4E23-A62A-D3BEA9139596}" = HP QuickTouch 1.00 C3 "{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget "{22ABA92B-6C1B-46D8-AC2B-C48EEAE172A9}" = VD64Inst "{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64 "{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64 "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll "{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64 "{68451E5C-0A9C-4D5C-8D06-6E296242E908}" = 64 Bit HP CIO Components Installer "{84BC87D4-0480-4E10-B15D-1E7886D55180}" = iTunes "{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64 "{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4 "{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4 "{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64 "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit "{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4 "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support "{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64 "{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64 "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit) "{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour "{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4 "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "HP Photosmart Essential" = HP Photosmart Essential 2.5 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "NVIDIA Drivers" = NVIDIA Drivers "SMSERIAL" = Motorola SM56 Data Fax Modem "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4 "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}" = Adobe Flash Player 10 Plugin "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4 "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4 "{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack "{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1 "{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = MSN Toolbar "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{082F8ABA-84D5-4837-9DFC-F365D91A07D4}" = HP Smart Web Printing "{08DE682A-3858-4591-9EBB-E5290E4DC3DD}" = Family Protection "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4 "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4 "{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1 "{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime "{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4 "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4 "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4 "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB "{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1 "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR "{1A21FC72-611F-4ADC-B6A6-795E06D72324}" = Verizon Download Manager "{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server "{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4 "{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1 "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check "{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 21 "{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman) "{303379C9-8610-4CCF-AF37-C4BF8998C591}" = Roxio Media Manager "{303F7619-4E67-450F-985A-A2DF51B30AC8}" = Adobe Setup "{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2 "{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1 "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4 "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4 "{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4 "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin "{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6 "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4 "{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout "{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087 "{535A4F3D-06C3-446C-A2AA-DBB71EC192B8}" = LightScribe Applications "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features "{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4 "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 "{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library "{5F89E4AF-07EF-48C7-9F3D-46E96E338D1D}" = Verizon Online Backup and Sharing "{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager "{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4 "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{66468F4D-BC4E-470C-9093-B3B6A1BB378C}" = MSN Toolbar Platform "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4 "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7641FD7D-E94E-424E-A95C-0593C84DC0C0}" = VZAccess Manager "{76A38425-741A-415C-96CF-AAD907FAB421}" = Vz In Home Agent "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7B2ADCB5-3F3D-478A-90A9-A8C04EF82BF6}" = Mobile Broadband Generic Drivers "{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files "{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4 "{82CA0A0C-A3EC-4167-B694-909205B2EDEC}" = muvee Plugin 1.0 "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4 "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4 "{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4 "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista "{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90120000-002A-0000-1000-0000000FF1CE}_STANDARDR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-002A-0409-1000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00B0-0409-0000-0000000FF1CE}" = Microsoft Save as PDF Add-in for 2007 Microsoft Office programs "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0116-0409-1000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007 "{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4 "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4 "{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC388C78-2619-452C-BFBE-FABCC3194387}" = Microsoft Office Live Meeting 2007 "{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch "{AC76BA86-1033-F400-7760-000000000004}_934" = Adobe Acrobat 9.3.4 - CPSID_83708 "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0 "{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1 "{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect "{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc "{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4 "{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0 "{B7F98125-4955-41E3-8A71-4CE11CE9C198}" = KODAK Gallery Upload Software "{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4 "{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5 "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module "{BC7E2C06-D255-4300-AA12-33AB54D009AC}" = Adobe Creative Suite 4 Design Standard "{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4 "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant "{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1 "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1 "{D793A12F-E362-48BB-B332-1DA5E936B52D}" = BlackBerry Desktop Software 4.3 "{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1 "{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01 "{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1" = Uniblue RegistryBooster 2010 "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4 "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4 "{FCBE0690-CBE1-4C60-87B0-4A70A6F5434E}" = LightScribe Template Labeler "{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All "3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only) "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe SVG Viewer" = Adobe SVG Viewer 3.0 "Adobe_1e3ba55b33b1e8227645fb9c82acca3" = Adobe Creative Suite 4 Design Standard "Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9 "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "BlackBerry_{D793A12F-E362-48BB-B332-1DA5E936B52D}" = BlackBerry Desktop Software 4.3 "CCleaner" = CCleaner "com.adobe.amp.4875E02D9FB21EE389F73B8D1 702B320485DF8CE.1" = Adobe Media Player "com.adobe.mauby.4875E02D9FB21EE389F73B8 D1702B320485DF8CE.1" = Acrobat.com "Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149) "HijackThis" = HijackThis 2.0.2 "HP Smart Web Printing" = HP Smart Web Printing "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers "Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6) "RadialpointClientGateway_is1" = Verizon Servicepoint 3.5.10 "SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6 "SpiceFX for Movie Maker" = SpiceFX for Movie Maker "STANDARDR" = Microsoft Office Standard 2007 "Verizon FiOS Activation_is1" = Verizon FiOS Activation "Verizon Help and Support" = Verizon Help and Support Tool "Xilisoft Video Converter Platinum" = Xilisoft Video Converter Platinum ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "ActiveTouchMeetingClient" = WebEx "GoToMeeting" = GoToMeeting 4.1.0.366 "Move Media Player" = Move Media Player ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 8/17/2010 3:36:25 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 | ID = 2000 Description = Accepted Safe Mode action : Microsoft Office Outlook. Error - 8/18/2010 10:57:41 PM | Computer Name = Lisa-laptop | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 8.0.6001.18943, time stamp 0x4c25813d, faulting module Flash10e.ocx, version 10.0.45.2, time stamp 0x4b5f8faa, exception code 0xc0000005, fault offset 0x001582b2, process id 0x1a98, application start time 0x01cb3f49cd978970. Error - 8/19/2010 11:10:58 AM | Computer Name = Lisa-laptop | Source = WinMgmt | ID = 10 Description = Error - 8/19/2010 11:14:47 AM | Computer Name = Lisa-laptop | Source = WinMgmt | ID = 10 Description = Error - 8/19/2010 11:22:05 AM | Computer Name = Lisa-laptop | Source = Google Update | ID = 20 Description = Error - 8/19/2010 11:29:01 AM | Computer Name = Lisa-laptop | Source = ESENT | ID = 215 Description = WinMail (4116) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed. Error - 8/19/2010 11:29:44 AM | Computer Name = Lisa-laptop | Source = SideBySide | ID = 16842830 Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat 9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest. Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest. Error - 8/19/2010 12:29:30 PM | Computer Name = Lisa-laptop | Source = Google Update | ID = 20 Description = Error - 8/19/2010 9:10:16 PM | Computer Name = Lisa-laptop | Source = Google Update | ID = 20 Description = Error - 8/19/2010 9:22:11 PM | Computer Name = Lisa-laptop | Source = Google Update | ID = 20 Description = [ OSession Events ] Error - 9/5/2009 3:17:17 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3354 seconds with 1740 seconds of active time. This session ended with a crash. Error - 10/2/2009 8:30:18 AM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 533 seconds with 420 seconds of active time. This session ended with a crash. Error - 11/8/2009 7:52:21 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/8/2009 7:52:48 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/13/2009 12:59:38 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7918 seconds with 5040 seconds of active time. This session ended with a crash. Error - 12/3/2009 10:20:04 AM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2189 seconds with 780 seconds of active time. This session ended with a crash. Error - 1/12/2010 4:20:35 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 118044 seconds with 13860 seconds of active time. This session ended with a crash. Error - 3/1/2010 10:54:26 AM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2409 seconds with 600 seconds of active time. This session ended with a crash. Error - 4/19/2010 8:20:15 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6524.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 188234 seconds with 3840 seconds of active time. This session ended with a crash. Error - 4/23/2010 12:58:18 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 97760 seconds with 13260 seconds of active time. This session ended with a crash. [ System Events ] Error - 6/4/2009 8:59:23 PM | Computer Name = Lisa-laptop | Source = HTTP | ID = 15016 Description = Error - 6/4/2009 9:00:58 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7022 Description = Error - 6/4/2009 9:00:59 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7001 Description = Error - 6/6/2009 5:02:04 PM | Computer Name = Lisa-laptop | Source = EventLog | ID = 6008 Description = The previous system shutdown at 5:00:04 PM on 6/6/2009 was unexpected. Error - 6/6/2009 5:02:05 PM | Computer Name = Lisa-laptop | Source = HTTP | ID = 15016 Description = Error - 6/6/2009 5:03:52 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7022 Description = Error - 6/6/2009 5:03:53 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7001 Description = Error - 6/6/2009 5:29:49 PM | Computer Name = Lisa-laptop | Source = HTTP | ID = 15016 Description = Error - 6/6/2009 5:31:23 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7022 Description = Error - 6/6/2009 5:31:24 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7001 Description = < End of report > You have Viewpoint installed. Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". More INFORMATION: * ViewMgr.exe - Useless * Viewpoint to Plunge Into Adware It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present. * Viewpoint * Viewpoint Manager * Viewpoint Media Player * Viewpoint Toolbar * Viewpoint Experience Technology ************************************* You can also remove these from your programs: Java(TM) 6 Update 2 Java(TM) 6 Update 4 Java(TM) 6 Update 7 ***************************************** * Open OTL * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window. Code: [Select]:OTL IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. :COMMANDS [resethosts] [purity] [clearrestorepoints] [emptytemp] [start explorer] * Click Run Fix * OTLI2 may ask to reboot the machine. Please do so if asked. * Click OK * A report will open. Copy and Paste that report in your next reply. ********************************************** I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Viewpoint is not in the list of currently installed programs (fromthe control panel). Is there some way it can be hidden? Should I continue with the next steps without uninstalling it? Please let me know. Thanks.... LisaHere is the OTL log: All processes killed ========== OTL ========== HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. ========== COMMANDS ========== File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully Error: Unable to interpret <[clearrestorepoints]> in the current context! [EMPTYTEMP] User: Administrator User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Lisa ->Temp folder emptied: 12351101 bytes ->Temporary Internet Files folder emptied: 1547608380 bytes ->Java cache emptied: 80336527 bytes ->FireFox cache emptied: 36530560 bytes ->Flash cache emptied: 202717 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 52115250 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 17307307 bytes %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 7620233 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 816013 bytes Total Files Cleaned = 1,674.00 mb OTL by OldTimer - Version 3.2.10.0 log created on 08222010_233947 Files\Folders moved on Reboot... File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\hover[6].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\ifr[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\ifr[2].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\ifr[3].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\index[5].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\msnbc_msn_com[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\wrap-widget[2].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\5731[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\7454-43775-2060-322[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\huffingtonpost_com[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ifr[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ifr[2].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ifr[3].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ifr[4].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ig[1].txt not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\mailhome[2].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\pid=NBCFC1_A[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\xd_proxy[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\1234569222[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\all[1].html not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\bind[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\google_ads_iframe_loader[1].html not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\hips=1;sex=1;sex-advice=1;sexuality=1;women=1;global=1;cap_12=n;qcs=D;;load_mode=inline;page_type=bpage;pos=leaderboard_top;sz=728x90;tile=1;ord=7841259748[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\ifr[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\ifr[2].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\ifr[3].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\mole[6].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\rpc_relay[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\01[2].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\AdDisplayTrackerServlet[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\flash[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\flash[2].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\freq[1].html not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\ifr[1].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\notifierclient[2].htm not found! File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\SetGridCookie[1].htm not found! C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. Registry entries deleted on Reboot... ESET LOG: C:\SWSetup\AOLIMS\setup.exeprobably a variant of Win32/Agent.HZHBURL trojancleaned by deleting - quarantined C:\Users\Lisa\AppData\Local\Temp\jar_cache8398643626540035938.tmpa variant of Java/TrojanDownloader.Agent.NAC trojandeleted - quarantined Quote Viewpoint is not in the list of currently installed programs (fromthe control panel).Please try this to see if you can find it there. Delete An Uninstall Entry •Start HijackThis •Click on the Open the Misc Tools section •Click on the Open Uninstall Manager button. •Highlight the entry you want to remove. •Click Delete this entry |
|
| 313. |
Solve : programs close for no reason. :S :( Need help!? |
|
Answer» ESET Online Scan Please run a free online scan with the ESET Online Scanner
OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=4cc7483854806345a03a64acb250f7bd # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-08-07 02:38:48 # local_time=2010-08-07 08:08:48 (+0530, India Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 795555 795555 0 0 # compatibility_mode=1280 16777175 100 0 20360950 20360950 0 0 # compatibility_mode=8192 67108863 100 0 94219 94219 0 0 # scanned=75585 # found=0 # cleaned=0 # scan_time=16627Any more SIGNS of infection?signs? if you MEAN the programs not closing thing? its gone. but a folder named recycler sometimes appears in drive F. :S its not there today, maybe its gone as well. i delete the folder whenever i see it.That folder is the Recycle Bin on that drive. It should be hidden, correct? Clean up System RESTORE Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
Purge old temporary files Please download TFC by OldTimer to your desktop
Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
|
|
| 314. |
Solve : need help with spyware? |
|
Answer» HI. Could you please re-run ComboFix in Safe Mode with Networking by rebooting, tapping F8 until is asks you which mode to boot into please choose Safe mode with Networking and re-run ComboFix.hi i run windows in safe mode with networking.. re-run commy and nothing different happens... it LOADS and no windows open... any solutions?... thanksHi. I will SEND you a PM of instructions.hi Sneakyone .. i will be on holiday for 5-7 DAYS so please post ur instructions and i will try to do it as fast as possible.. thanksHi. I thought I sent you a PM with instructions, but I will do it again. hi i sent u a personal message... please reply:D |
|
| 315. |
Solve : File cannot be executed...? |
|
Answer» Hi guys, I'm new here and not fantastic with computers. I've recently been having some issues, some lame spyware DEAL that I got fixed and now this "File cannot be executed" issue. I don't know where to start and could really use some help. Anything would be APPRECIATED! Thanks. Sorry for the delay, we are busy here on the boards. If you are still having issues, please do the following:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. |
|
| 316. |
Solve : Possible infection?? |
|
Answer» Hi there,
|
|
| 317. |
Solve : Application cannot be executed. The file "****.exe" is infected? |
|
Answer» almost every application i have except firefox (WOW) that i try to open, i GET a windows security alert saying "Application cannot be executed. The file "winamp.exe" is infected" and wats weird is my IE wont let me go to any sites but 5 mins later itll show up with a popup from www.*adult URL* or sum other retarded site. please helpSorry for the delay. We are busy here on the boards. If you are still having issues, please do the following, if possible:
|
|
| 318. |
Solve : avira / advanced registry optimizer? |
|
Answer» hi all i am having probs with the computer when i am on the web (sky) every now and then the computer freezes and / or crashes totally and throws up a blue screen with white writing?!?! i am CONVINCED i have picked up some viruses... only when i run Avira it says no viruses found when i run my advanced registry optimizer which i paid for last yr it straight away found 44! viruses! then a day later another 14... i am a little confused why one is finding and the other isnt? my understanding was the antivirus (avira) would stop any viruses coming in.... where as the advanced thing got RID once you actually had them?! please correct me if i am wrong or using the wrong programmes could someone anyone please advise what is best and even after keep getting rid of these viruses its finding am i still having problems !! arghhhhhh! many thanks in advance, MEL 1) Avira is an anti virus utility 2) Advanced registry optimizer is NOT an anti virus utility 3) Advanced registry optimizer is a waste of your money. You should never use ANY registry optimizers or cleaners. They are not only worthless, but they often cause major problems. 4) What is the blue screen error message you get? And what OS are you using so I can move this to the correct forum? thanks for your quick reply its a shame ive wasted my money on the A R O, so is it NOT actually finding errors and viruses then? its telling me it is, and then telling me im cleaning them up! bit confused... am i best to delete it entirely, if you think its causing problems in itself?? to be honest i havent written down the blue screen errors, i will deffo do so as soon as it happens again. not good on my part i know, but this HAPPENED yesterday and this morning and i only thought to JOIN this forum and send a message tonite. i am operating on vista i believe although not 100% abt that as someone else set it all up for me. thank you again melYour software is not telling you that it's finding viruses. What makes you think it is? It's telling you that it's finding "registry errors" (which is nonsense, by the way). I don't know what is causing your problems, but I would not be surprised if it is the registry utility. Just let us know what the blue screen error says. oh ok maybe it has a devious way of making you think that its viruses that its found! i will stop using it, thanks for this adivce wont waste your time any more tonite, i will deffo write the error down as soon as it happens again thanks mel |
|
| 319. |
Solve : Infected laptop - corrupted search engines? |
|
Answer» Thanks in advance for the information and HELP. I'm hoping to avoid a reformat. Here is what I experience: |
|
| 320. |
Solve : unable to get rid of adware and spyware? |
|
Answer» MBRCheck, version 1.1.1
(c) 2009 eSage Lab www.esagelab.com \\.\C: -> \\.\PhysicalDrive0 MD5: 6def5ffcbcdbdb4082f1015625e597bd \\.\E: -> \\.\PhysicalDrive0 Size Device Name MBR Status -------------------------------------------- 232 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found) Press any key to quit... Good. Now, are you still having the same issue?wow!! everything seems to be running normally now and i can boot up without any problems i really cannot thank you enough for all the time you've spent helping me i really appreciate it!Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some STAGE you will be clean. There are several ways to reset your restore points, but this is my method:
Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Windows XP Service Pack 2 Out of date service pack!! Internet Explorer 6 Out of date! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! avast! Antivirus ESET Online Scanner v3 Antivirus up to date! ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Java(TM) 6 Update 11 Java(TM) SE Runtime Environment 6 Update 1 Out of date Java installed! Adobe Flash Player 9 (Out of date Flash Player installed!) Adobe Flash Player 10.0.45.2 ```````````````````````````````` Process Check: objlist.exe by Laurent Alwil Software Avast4 aswUpdSv.exe Alwil Software Avast4 ashServ.exe Alwil Software Avast4 ashDisp.exe Alwil Software Avast4 ashMaiSv.exe Alwil Software Avast4 ashWebSv.exe ```````````````````````````````` DNS Vulnerability Check: ``````````End of Log```````````` Please upgrade to Windows XP SP3, because it includes all previously released updates. It also includes a small number of new functionalities. Some of the updates that Service Pack 3 provides, you may not have. It is now available via Windows Update. More info about SP3: http://www.geekpolice.net/operating-systems-f20/windows-xp-service-pack-3-information-t16956.htm =========================================================== Please download and install the newest version of Adobe Flash Player from Adobe.com == Please download the newest version of Java from Java.com. Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still LEAVE you vulnerable. Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7). Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them. Once old versions are gone, please install the newest version. ============================================= Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
again thank you so much for all your help!!! You're welcome. |
|
| 321. |
Solve : Recently had a av suite virus (?) now things aren't right???? |
|
Answer» I got the file you described on my desktop, but I don't know how to manually upload it?? All it opened was a page Getsysteminfo parser 2.96 and there is no place to upload anything? All it says is what's your problem, with a DROPDOWN menu. I'm also now getting tons of pop ups, even though my blocker is set at high, and every page or email, everything I go to has certain words underlined twice in green, and if I put my cursor on them, a gamevance ad pops up? What is that and how do I get rid of it?Seems LIKE adware.
If so, click it, then click the next icon right below and select Move incurable. (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
gtdownde_110.ocx;C:\WINDOWS\system32;Probably DLOADER.Trojan;Incurable.Deleted.; SkillJamLoader.dll;C:\Documents and Settings\All Users\Application Data\SkillJam\SecurePlayer;Program.PopcapLoader.4;; SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Christopher Apostle\Desktop\Unused Desktop Shortcuts\SDFix.exe;Tool.Killproc.3;; SDFix.exe;C:\Documents and Settings\Christopher Apostle\Desktop\Unused Desktop Shortcuts;Archive contains infected objects;Moved.; jar_cache1456766111123690851.tmp\AppleT.class;C:\Documents and Settings\Christopher Apostle\Local Settings\temp\jar_cache1456766111123690851.tmp;Exploit.Java.90;; jar_cache1456766111123690851.tmp;C:\Documents and Settings\Christopher Apostle\Local Settings\temp;Archive contains infected objects;Moved.; WmaInfo.dll;C:\Program Files\AMT;BackDoor.Click.679;Deleted.; Let's move to a different tool. Save these instructions so you can have access to them while in Safe Mode. Please click here to download AVP Tool by Kaspersky.
|
|
| 322. |
Solve : Infected wuauclt.exe - please help? |
|
Answer» Sorry put this in the main forum so repeating it here in the hope that I might get some HELP. |
|
| 323. |
Solve : Another "cannot be executed. **** is infected" problem? |
|
Answer» I FOLLOWED a similar thread and ran RKILL, OTL and ComboFix (downloaded from another computer.) RKILL log provided below. I'll save the others until told to include them. |
|
| 324. |
Solve : Pretty sure I got hold of some malware? |
|
Answer» I keep getting error messages that say that Windows Explorer is shutting down. This happens when I am moving or opening FILES and programs. Sometimes it seems to be random; other times a specific file or program will cause the error repeatedly. When I am on the internet, Internet Explorer will randomly shut down. Sometimes it restarts itself, other times it gives me a message telling me that it shut down to protect my computer. I can download, but am completely unable to install new programs--I get an error message telling me to clear my internet cache and download again (which I have already done--twice). I have Avira antivirus, and have run several scans, which came back clean. It hasn't been updated in about three weeks because the updates won't work. I have tried everything I can think of. System restore fails, even in safe mode. I could not find anything suspicious in add/remove programs and I have cleaned my hard drive using CCleaner. I am unable to follow the steps that are suggested because I can't install new programs. Just for information's sake, I am running Windows Vista, and this has been happening for about a day or two now. Any help you can provide would be greatly appreciated, as I really do not want to have to wipe my hard drive! Hi,
%systemroot%\system32\*.dll /lockedfiles %systemroot%\system32\*.exe /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.sys %systemroot%\system32\drivers\*.dll %systemroot%\system32\drivers\*.ini %systemroot%\system32\drivers\*.exe %SYSTEMDRIVE%\*.* %PROGRAMFILES%\*. %appdata%\*.* netsvcs msconfig safebootminimal safebootnetwork activex drivers32 /md5start eventlog.dll scecli.dll netlogon.dll cngaudit.dll sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys disk.sys nvstor32.sys ahcix86s.sys nvrd32.sys symmpi.sys adp3132.sys mv61xx.sys usbstor.sys /md5stop CREATERESTOREPOINT HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
http://oldtimer.geekstogo.com/OTL.com http://oldtimer.geekstogo.com/OTL.scrok, here are the logs OTL logfile created on: 7/20/2010 6:00:10 PM - Run 1 OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\owner\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18928) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free 8.00 Gb Paging File | 6.00 Gb Available in Paging File | 77.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 286.54 Gb Total Space | 79.67 Gb Free Space | 27.80% Space Free | Partition Type: NTFS Drive D: | 289.63 Gb Total Space | 278.85 Gb Free Space | 96.28% Space Free | Partition Type: NTFS Drive E: | 612.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF Drive F: | 139.82 Gb Total Space | 19.48 Gb Free Space | 13.93% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded Drive I: | 139.77 Gb Total Space | 16.41 Gb Free Space | 11.74% Space Free | Partition Type: NTFS Computer Name: POOKLET Current User Name: owner Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2010/07/20 17:58:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe PRC - [2010/07/07 15:50:42 | 000,176,408 | ---- | M] (iWin Inc.) -- C:\Program Files (x86)\iWin Games\iWinTrusted.exe PRC - [2010/04/19 09:21:37 | 000,267,432 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2010/03/02 09:28:31 | 000,282,792 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2010/02/24 08:28:09 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2009/11/13 16:37:30 | 002,022,072 | ---- | M] (NesterSoft Inc.) -- C:\Program Files (x86)\TimeLeft3\TimeLeft.exe PRC - [2009/04/10 11:58:53 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PRC - [2008/12/09 06:08:38 | 000,495,616 | ---- | M] (Gadwin Systems, Inc) -- C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe PRC - [2008/07/29 19:53:00 | 000,500,784 | ---- | M] (Egis Incorporated) -- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe PRC - [2008/05/20 19:50:50 | 000,269,448 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe PRC - [2008/04/25 23:36:20 | 000,045,056 | ---- | M] (NewTech InfoSystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe PRC - [2008/04/25 23:36:02 | 000,131,072 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe PRC - [2008/03/03 15:11:14 | 000,016,384 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe ========== Modules (SafeList) ========== MOD - [2010/07/20 17:58:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe MOD - [2008/01/20 21:50:01 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx ========== Win32 Services (SafeList) ========== SRV:64bit: - [2008/08/19 16:27:22 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -- (ETService) SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2007/12/10 22:11:30 | 000,015,872 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\SysNative\agr64svc.exe -- (AgereModemAudio) SRV - [2010/07/07 15:50:42 | 000,176,408 | ---- | M] (iWin Inc.) [Auto | Running] -- C:\Program Files (x86)\iWin Games\iWinTrusted.exe -- (iWinTrusted) SRV - [2010/04/19 09:21:37 | 000,267,432 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2010/03/18 14:27:14 | 001,020,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400) SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64) SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010/02/24 08:28:09 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2008/07/29 19:53:00 | 000,500,784 | ---- | M] (Egis Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -- (eDataSecurity Service) SRV - [2008/05/20 19:50:50 | 000,269,448 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -- (Acer HomeMedia Connect Service) SRV - [2008/04/25 23:36:20 | 000,045,056 | ---- | M] (NewTech InfoSystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe -- (NTIBackupSvc) SRV - [2008/04/25 23:36:02 | 000,131,072 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -- (NTISchedulerSvc) SRV - [2008/03/03 15:11:14 | 000,016,384 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe -- (BUNAgentSvc) ========== Driver Services (SafeList) ========== DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ipinip.sys -- (IpInIp) DRV:64bit: - [2010/03/30 20:58:04 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2010/03/02 11:35:01 | 000,116,568 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avipbb.sys -- (avipbb) DRV:64bit: - [2010/02/16 12:24:00 | 000,081,072 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\DRIVERS\avgntflt.sys -- (avgntflt) DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb) DRV:64bit: - [2009/07/25 11:38:29 | 000,311,968 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\atksgt.sys -- (atksgt) DRV:64bit: - [2009/07/25 11:38:29 | 000,043,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\lirsgt.sys -- (lirsgt) DRV:64bit: - [2008/08/04 23:29:26 | 000,056,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:64bit: - [2008/07/29 19:53:50 | 000,060,976 | ---- | M] (Egis Incorporated) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\PSDVdisk.sys -- (psdvdisk) DRV:64bit: - [2008/07/29 19:53:50 | 000,021,040 | ---- | M] (Egis Incorporated) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\PSDNServ.sys -- (PSDNServ) DRV:64bit: - [2008/07/29 19:53:48 | 000,022,064 | ---- | M] (Egis Incorporated) [File_System | Boot | Running] -- C:\Windows\SysNative\DRIVERS\psdfilter.sys -- (PSDFilter) DRV:64bit: - [2008/07/29 06:47:00 | 001,075,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\athrxusb.sys -- (athrusb) DRV:64bit: - [2008/03/05 01:22:34 | 001,253,376 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\agrsm64.sys -- (AgereSoftModem) DRV:64bit: - [2008/01/30 19:48:32 | 000,016,384 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\NTIDrvr.sys -- (NTIDrvr) DRV:64bit: - [2008/01/20 21:49:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\RootMdm.sys -- (ROOTMODEM) DRV:64bit: - [2007/05/31 11:39:32 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RimUsb_AMD64.sys -- (RimUsb) DRV:64bit: - [2007/01/18 14:10:22 | 000,030,336 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys -- (RimVSerPort) DRV:64bit: - [2006/09/18 16:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\Wbem\ntfs.mof -- (Ntfs) DRV - [2008/08/19 16:23:00 | 000,017,952 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\int15_64.sys -- (int15) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0849}: C:\ProgramData\iWin Games\firefox [2010/06/15 09:24:58 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/01/21 15:20:50 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/01/22 22:10:14 | 000,000,000 | ---D | M] [2010/06/07 04:27:44 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Extensions [2010/07/19 23:20:28 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\0dy5c5j8.default\extensions [2010/06/07 06:16:32 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\cm83o6ap.default\extensions [2010/06/07 06:16:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\cm83o6ap.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010/01/21 15:20:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2:64bit: - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis) O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (ShoppingReport) - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files (x86)\ShoppingReport\Bin\2.6.71\ShoppingReport.dll File not found O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files (x86)\iWin Games\iWinGamesHookIE.dll (iWin Inc.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.) O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files (x86)\PicLensIE\cooliris.dll File not found O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.) O3:64bit: - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.) O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.) O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [1157840481] C:\Program Files (x86)\eGames\Twistingo\Register\eGamesRegistration.exe (DataLode, Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions) O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files (x86)\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated) O4 - HKCU..\Run: [Gadwin PrintScreen] C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc) O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TimeLeft.lnk = C:\Program Files (x86)\TimeLeft3\TimeLeft.exe (NesterSoft Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1 O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files (x86)\PicLensIE\cooliris.dll File not found O9 - Extra Button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files (x86)\ShoppingReport\Bin\2.6.71\ShoppingReport.dll File not found O9 - Extra Button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files (x86)\ShoppingReport\Bin\2.6.71\ShoppingReport.dll File not found O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll (Installation Support) O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos1.walmart.com/WalmartActivia.cab (Snapfish Activia) O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab (BDSCANONLINE Control) O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: ActiveGS.cab http://activegs.freetoolsassociation.com/ActiveGS.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg O24 - Desktop BackupWallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008/10/11 18:47:17 | 000,662,592 | R--- | M] (Electronic Arts Inc.) - E:\AutoRunGUI.dll -- [ UDF ] O32 - AutoRun File - [2008/10/22 09:19:21 | 000,000,000 | R--D | M] - E:\AutoRun -- [ UDF ] O32 - AutoRun File - [2008/10/11 18:47:17 | 000,703,552 | R--- | M] (Electronic Arts Inc.) - E:\AutoRun.exe -- [ UDF ] O32 - AutoRun File - [2008/10/11 18:47:12 | 000,000,166 | R--- | M] () - E:\autorun.inf -- [ UDF ] O33 - MountPoints2\{7b189048-25f5-11de-9b10-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{7b189048-25f5-11de-9b10-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/10/11 18:47:17 | 000,703,552 | R--- | M] (Electronic Arts Inc.) O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* MsConfig:64bit - StartUpReg: Acer Empowering Technology Monitor - hkey= - key= - C:\Program Files\Acer\Empowering Technology\SysMonitor.exe () MsConfig:64bit - StartUpReg: eDataSecurity Loader - hkey= - key= - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe (Egis Incorporated) MsConfig:64bit - StartUpReg: EmpoweringTechnology - hkey= - key= - C:\Program Files\Acer\Empowering Technology\Framework.Lau File not found MsConfig:64bit - StartUpReg: NvCplDaemon - hkey= - key= - C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation) MsConfig:64bit - StartUpReg: RtHDVCpl - hkey= - key= - C:\Windows\RAVCpl64.exe (Realtek Semiconductor) MsConfig:64bit - StartUpReg: Skytel - hkey= - key= - C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.) SafeBootMin:64bit: AppMgmt - Service SafeBootMin:64bit: Base - Driver Group SafeBootMin:64bit: Boot Bus Extender - Driver Group SafeBootMin:64bit: Boot file system - Driver Group SafeBootMin:64bit: File system - Driver Group SafeBootMin:64bit: Filter - Driver Group SafeBootMin:64bit: HelpSvc - Service SafeBootMin:64bit: PCI Configuration - Driver Group SafeBootMin:64bit: PNP Filter - Driver Group SafeBootMin:64bit: Primary disk - Driver Group SafeBootMin:64bit: sacsvr - Service SafeBootMin:64bit: SCSI Class - Driver Group SafeBootMin:64bit: System Bus Extender - Driver Group SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:64bit: AppMgmt - Service SafeBootNet:64bit: Base - Driver Group SafeBootNet:64bit: Boot Bus Extender - Driver Group SafeBootNet:64bit: Boot file system - Driver Group SafeBootNet:64bit: File system - Driver Group SafeBootNet:64bit: Filter - Driver Group SafeBootNet:64bit: HelpSvc - Service SafeBootNet:64bit: Messenger - Service SafeBootNet:64bit: NDIS Wrapper - Driver Group SafeBootNet:64bit: NetBIOSGroup - Driver Group SafeBootNet:64bit: NetDDEGroup - Driver Group SafeBootNet:64bit: Network - Driver Group SafeBootNet:64bit: NetworkProvider - Driver Group SafeBootNet:64bit: PCI Configuration - Driver Group SafeBootNet:64bit: PNP Filter - Driver Group SafeBootNet:64bit: PNP_TDI - Driver Group SafeBootNet:64bit: Primary disk - Driver Group SafeBootNet:64bit: rdsessmgr - Service SafeBootNet:64bit: sacsvr - Service SafeBootNet:64bit: SCSI Class - Driver Group SafeBootNet:64bit: Streams Drivers - Driver Group SafeBootNet:64bit: System Bus Extender - Driver Group SafeBootNet:64bit: TDI - Driver Group SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet:64bit: WudfPf - Driver SafeBootNet:64bit: WudfUsbccidDriver - Driver SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: WudfPf - Driver SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error. ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error. ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error. ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L) Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.mkdmp3enc - C:\PROGRA~2\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM File not found Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L) Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com) Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2010/07/20 17:58:23 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe [2010/07/19 23:08:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner [2010/07/19 22:28:52 | 000,043,520 | ---- | C] (NirSoft) -- C:\Users\owner\Desktop\shexview.exe [2010/07/19 18:32:47 | 000,000,000 | ---D | C] -- C:\Users\owner\Desktop\Sims 3 [2010/07/19 16:44:36 | 000,000,000 | ---D | C] -- C:\Users\owner\Desktop\Simmy [2010/07/15 04:26:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2010/07/15 04:26:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2010/07/15 04:26:46 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Local\Cooliris [2010/07/10 02:57:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iWin Games [2010/07/09 02:03:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Astar Games [2010/07/08 20:55:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Gogii [2010/07/08 20:50:56 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\Floodgate [2010/07/04 04:19:22 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\KitchenBrigade [2010/07/03 23:06:23 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\com.picaboo.Picaboo.A382D4714709B456C4E0088DFC1F7243AF9EBF75.1 [2010/07/03 23:06:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Picaboo X [2010/07/03 23:06:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR [2010/06/29 14:33:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared(158) [2010/06/29 14:33:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Roxio(356) [2010/06/25 04:01:35 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\cerasus.media [2010/06/24 23:00:18 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\Pet Vet 3D Down Under [2010/06/24 22:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Islands [2010/06/24 22:28:55 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Islands [2010/06/24 09:00:52 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll [2010/06/24 09:00:52 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll [2010/06/24 09:00:52 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe [2010/06/24 09:00:52 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe [2010/06/24 09:00:52 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll [2010/06/24 09:00:52 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll [2010/06/24 09:00:52 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll [2010/06/24 09:00:52 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netfxperf.dll [2010/06/24 03:39:12 | 000,000,000 | ---D | C] -- C:\ProgramData\GameHouse [2010/06/23 20:54:22 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\GameUXLegacyGDFs.dll [2010/06/23 20:54:22 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\SysNative\GameUXLegacyGDFs.dll [2010/06/23 20:54:22 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Apphlpdm.dll [2010/06/23 20:54:22 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Apphlpdm.dll [2010/06/23 05:55:06 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Go-Go Gourmet Chef of the Year [2010/06/23 05:41:42 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\YoudaGames [2010/06/22 23:07:59 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\iwin [2009/03/13 20:28:09 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll ========== Files - Modified Within 30 Days ========== [2010/07/20 18:00:12 | 003,407,872 | -HS- | M] () -- C:\Users\owner\ntuser.dat [2010/07/20 17:59:04 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010/07/20 17:58:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe [2010/07/20 17:15:10 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010/07/20 17:15:10 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010/07/20 12:59:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010/07/20 12:29:10 | 003,645,694 | -H-- | M] () -- C:\Users\owner\AppData\Local\IconCache.db [2010/07/19 23:22:01 | 000,703,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010/07/19 23:22:01 | 000,604,264 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010/07/19 23:22:01 | 000,103,964 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010/07/19 23:15:19 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\LogConfigTemp.xml [2010/07/19 23:15:08 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010/07/19 23:15:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010/07/19 23:15:02 | 4294,172,672 | -HS- | M] () -- C:\hiberfil.sys [2010/07/19 23:08:38 | 000,000,865 | ---- | M] () -- C:\Users\owner\Desktop\CCleaner.lnk [2010/07/19 22:34:11 | 000,000,667 | ---- | M] () -- C:\Users\owner\Desktop\shexview.cfg [2010/07/19 22:28:39 | 000,055,898 | ---- | M] () -- C:\Users\owner\Desktop\shexview.zip [2010/07/19 21:03:03 | 000,524,288 | -HS- | M] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TMContainer00000000000000000001.regtrans-ms [2010/07/19 21:03:03 | 000,065,536 | -HS- | M] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TM.blf [2010/07/19 20:26:00 | 054,835,272 | ---- | M] () -- C:\Users\owner\Desktop\setup_av_free.exe [2010/07/19 17:55:27 | 000,003,108 | ---- | M] () -- C:\Users\owner\AppData\Roaming\wklnhst.dat [2010/07/19 17:52:22 | 000,017,408 | ---- | M] () -- C:\Users\owner\Documents\scrapstuff.wps [2010/07/19 17:51:35 | 000,018,432 | ---- | M] () -- C:\Users\owner\Documents\scrap master.wps [2010/07/19 17:50:27 | 000,017,920 | ---- | M] () -- C:\Users\owner\Documents\Scrap List.wps [2010/07/19 02:49:53 | 000,041,472 | ---- | M] () -- C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/07/18 05:29:06 | 000,001,910 | ---- | M] () -- C:\Users\Public\Desktop\Coconut Queen.lnk [2010/07/15 04:26:47 | 000,000,868 | ---- | M] () -- C:\Users\owner\Desktop\Launch Cooliris.lnk [2010/07/05 00:21:43 | 000,018,432 | ---- | M] () -- C:\Users\owner\Documents\home decor stuff.wps [2010/06/30 15:38:06 | 000,119,768 | ---- | M] () -- C:\Users\owner\AppData\Local\GDIPFONTCACHEV1.DAT [2010/06/30 15:35:08 | 000,524,288 | -HS- | M] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TMContainer00000000000000000002.regtrans-ms [2010/06/30 15:33:51 | 003,407,872 | -HS- | M] () -- C:\Users\owner\ntuser.dat_previous [2010/06/30 15:33:50 | 000,524,288 | -HS- | M] () -- C:\Users\owner\ntuser.dat{a1e78f04-72da-11df-8bf6-9fce7987da27}.TMContainer00000000000000000001.regtrans-ms [2010/06/30 15:33:50 | 000,065,536 | -HS- | M] () -- C:\Users\owner\ntuser.dat{a1e78f04-72da-11df-8bf6-9fce7987da27}.TM.blf [2010/06/28 14:31:56 | 000,017,408 | ---- | M] () -- C:\Users\owner\Documents\calendar stuff.wps [2010/06/22 19:39:53 | 000,017,408 | ---- | M] () -- C:\Users\owner\Documents\stuff.wps ========== Files Created - No Company Name ========== [2010/07/19 23:08:38 | 000,000,865 | ---- | C] () -- C:\Users\owner\Desktop\CCleaner.lnk [2010/07/19 22:34:11 | 000,000,667 | ---- | C] () -- C:\Users\owner\Desktop\shexview.cfg [2010/07/19 22:28:52 | 000,018,238 | ---- | C] () -- C:\Users\owner\Desktop\shexview.chm [2010/07/19 22:28:38 | 000,055,898 | ---- | C] () -- C:\Users\owner\Desktop\shexview.zip [2010/07/19 16:47:19 | 054,835,272 | ---- | C] () -- C:\Users\owner\Desktop\setup_av_free.exe [2010/07/18 05:29:06 | 000,001,910 | ---- | C] () -- C:\Users\Public\Desktop\Coconut Queen.lnk [2010/07/15 04:26:47 | 000,000,868 | ---- | C] () -- C:\Users\owner\Desktop\Launch Cooliris.lnk [2010/07/05 00:21:43 | 000,018,432 | ---- | C] () -- C:\Users\owner\Documents\home decor stuff.wps [2010/07/04 03:10:04 | 000,018,432 | ---- | C] () -- C:\Users\owner\Documents\scrap master.wps [2010/07/04 03:05:12 | 000,017,920 | ---- | C] () -- C:\Users\owner\Documents\Scrap List.wps [2010/07/03 06:05:30 | 000,017,408 | ---- | C] () -- C:\Users\owner\Documents\scrapstuff.wps [2010/06/30 15:35:08 | 000,524,288 | -HS- | C] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TMContainer00000000000000000002.regtrans-ms [2010/06/30 15:35:08 | 000,524,288 | -HS- | C] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TMContainer00000000000000000001.regtrans-ms [2010/06/30 15:35:08 | 000,065,536 | -HS- | C] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TM.blf [2010/06/22 19:39:53 | 000,017,408 | ---- | C] () -- C:\Users\owner\Documents\stuff.wps [2010/01/05 23:33:17 | 000,151,552 | ---- | C] () -- C:\Windows\SysWow64\nvRegDev.dll [2009/07/15 21:23:50 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009/07/15 21:23:34 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll [2009/04/10 12:08:23 | 000,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini [2009/04/10 12:08:22 | 000,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini [2009/03/13 21:05:40 | 000,001,024 | RH-- | C] () -- C:\Windows\SysWow64\NTIOFM4.dll [2009/03/13 21:05:40 | 000,001,024 | RH-- | C] () -- C:\Windows\SysWow64\NTIBUN5.dll [2009/01/05 15:44:10 | 000,000,453 | ---- | C] () -- C:\Windows\bdoscandellang.ini [2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini [2008/01/15 05:31:00 | 000,000,530 | ---- | C] () -- C:\Windows\SysWow64\tx14_ic.ini [2001/12/26 18:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\multiplex_vcd.dll [2001/09/04 01:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\SysWow64\Hmpg12.dll [2001/07/30 18:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\SysWow64\HMPV2_ENC.dll [2001/07/24 00:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\SysWow64\HMPV2_ENC_MMX.dll ========== Custom Scans ========== < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\system32\*.exe /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\system32\*.sys > < %systemroot%\system32\drivers\*.dll > < %systemroot%\system32\drivers\*.ini > < %systemroot%\system32\drivers\*.exe > < %SYSTEMDRIVE%\*.* > [2009/04/11 01:36:38 | 000,333,257 | RHS- | M] () -- C:\bootmgr [2009/03/13 20:28:46 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK [2010/03/03 15:41:02 | 000,096,264 | ---- | M] (Microsoft Corporation) -- C:\GameuxInstallHelper.dll [2010/07/19 23:15:02 | 4294,172,672 | -HS- | M] () -- C:\hiberfil.sys [2010/07/19 23:13:45 | 000,000,090 | ---- | M] () -- C:\MDisc.log [2010/07/19 23:13:47 | 000,000,090 | ---- | M] () -- C:\MDR.log [2010/07/19 23:15:01 | 312,811,519 | -HS- | M] () -- C:\pagefile.sys [2009/03/13 20:33:11 | 000,000,787 | ---- | M] () -- C:\RHDSetup.log [2010/04/25 23:53:49 | 000,005,729 | ---- | M] () -- C:\scramble.log < %PROGRAMFILES%\*. > [2009/04/10 11:59:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer [2010/07/19 23:13:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer Arcade Live [2010/07/19 23:17:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer GameZone [2009/04/10 12:08:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer Incorporated [2010/07/03 23:06:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe [2010/01/30 19:36:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Amazon [2009/12/05 03:30:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update [2009/08/28 12:18:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Atari [2010/04/25 23:54:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Atrinsic [2010/01/20 01:26:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Avira [2009/07/25 22:09:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\BFG [2009/07/25 22:38:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Brainiversity [2010/07/19 23:08:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CCleaner [2010/01/26 04:11:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Chocolatier Decadence by Design [2010/07/19 23:23:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files [2009/03/13 20:58:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink [2010/07/19 23:23:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DivX [2010/04/26 15:09:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\e-Sword [2010/05/19 00:32:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EA GAMES [2010/01/29 01:54:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\eGames [2010/01/06 17:33:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Electronic Arts [2009/03/13 21:22:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\eSobi [2010/05/29 22:51:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Free Ride Games [2009/11/23 02:23:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Gadwin Systems [2010/01/26 03:29:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GameHouse [2010/03/06 22:02:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Games [2009/07/25 22:46:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Games A Go-Go [2010/02/03 15:39:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google [2009/07/25 22:24:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hidden Expedition - Amazon [2009/07/25 22:28:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hidden Expedition - Everest [2009/07/25 22:21:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hidden Expedition Titanic [2009/11/28 11:17:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HP [2010/07/19 23:13:38 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information [2010/06/12 09:17:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer [2010/07/10 02:57:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iWin Games [2010/07/18 05:29:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iWin.com [2010/07/15 04:26:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java [2009/12/30 02:56:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\LDA Games [2010/01/29 18:32:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\LimeWire [2009/07/25 22:26:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Lost Treasures of Alexandria [2009/08/06 21:53:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mad Scientist PRODUCTIONS [2010/01/03 03:05:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Maxis [2009/09/05 21:28:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Games [2009/03/13 20:47:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office [2009/03/13 20:47:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office Suite Activation Assistant [2010/02/17 17:10:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight [2009/03/13 20:47:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Works [2009/08/06 21:52:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft WSE [2010/06/26 09:01:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET [2010/06/15 13:29:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MostFun [2010/01/21 15:20:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox [2006/11/02 10:07:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild [2009/12/18 20:07:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSECache [2009/07/15 20:49:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0 [2009/07/25 22:45:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MumboJumbo [2009/07/25 22:09:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery in London [2009/03/13 21:05:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NewTech Infosystems [2010/01/05 23:38:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA Corporation [2009/10/13 19:03:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OverDrive Media Console [2010/07/03 23:06:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Picaboo X [2009/07/25 22:34:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PlayFirst [2009/07/25 22:40:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PopCap Games [2009/10/28 14:06:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ProPoster [2009/12/05 03:31:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime [2009/12/30 02:59:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\RealArcade [2009/03/13 20:32:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek [2006/11/02 10:07:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies [2009/10/30 14:40:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Research In Motion [2010/06/30 15:33:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Roxio [2010/06/29 14:34:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Roxio(356) [2009/07/25 22:19:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Scholastic [2010/06/08 03:55:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Shockwave.com [2009/07/26 01:52:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Sims2Pack Clean Installer [2009/12/27 04:10:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TimeLeft3 [2009/12/25 15:56:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Ubisoft [2006/11/02 10:36:07 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information [2009/09/02 16:28:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VideoLAN [2010/03/12 17:12:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Wardrobe Wrangler [2009/07/25 22:39:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent [2009/07/15 21:56:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Calendar [2008/01/20 22:09:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Collaboration [2008/01/20 22:09:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender [2010/07/14 09:00:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail [2009/10/28 08:06:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player [2006/11/02 10:07:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT [2009/07/15 21:56:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Gallery [2009/11/17 09:17:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices [2009/07/15 21:56:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar [2009/07/26 01:14:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WinRAR [2010/04/15 18:18:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Yahoo! < %appdata%\*.* > [2009/10/30 14:46:42 | 000,000,006 | -HS- | M] () -- C:\Users\owner\AppData\Roaming\desktop.ini [2010/07/19 17:55:27 | 000,003,108 | ---- | M] () -- C:\Users\owner\AppData\Roaming\wklnhst.dat < MD5 for: AGP440.SYS > [2008/01/20 21:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys [2008/01/20 21:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys < MD5 for: AHCIX86S.SYS > [2007/08/07 23:55:08 | 000,122,880 | ---- | M] (Promise Technology, Inc.) MD5=4283A0F3A9557EB133D2BA8979747A77 -- C:\ACER\Preload\Autorun\DRV\ATI VGA PCI-E\Packages\Drivers\SBDrv\SB6xx\RAID\LH\ahcix86s.sys < MD5 for: ATAPI.SYS > [2008/01/20 21:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys [2009/04/11 02:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys < MD5 for: CNGAUDIT.DLL > [2006/11/02 06:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll [2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll [2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll [2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll OTL Extras logfile created on: 7/20/2010 6:00:10 PM - Run 1 OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\owner\Desktop 64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18928) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free 8.00 Gb Paging File | 6.00 Gb Available in Paging File | 77.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 286.54 Gb Total Space | 79.67 Gb Free Space | 27.80% Space Free | Partition Type: NTFS Drive D: | 289.63 Gb Total Space | 278.85 Gb Free Space | 96.28% Space Free | Partition Type: NTFS Drive E: | 612.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF Drive F: | 139.82 Gb Total Space | 19.48 Gb Free Space | 13.93% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded Drive I: | 139.77 Gb Total Space | 16.41 Gb Free Space | 11.74% Space Free | Partition Type: NTFS Computer Name: POOKLET Current User Name: owner Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Extra Registry (SafeList) ========== ========== File Associations ========== Hi, Please download Malwarebytes Anti-Malware from Here. Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.When I tried to install, it said "The setup files are corrupted. Please obtain a new copy of the program." Some version of this appears whenever I try to install anything.Hi, Download Dr.Web CureIt to the desktop: ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
o Now, go to Settings >> Change Settings o Go to Actions tab >> under Objects section, change the settings to below Infected objects - Cure Incurable objects - Report Suspicious objects - Report o Don't change any other settings
In the launch files of everything in the Acer Games folder: Trojan.Downloader 1.5449 Plus, three files listed as probably DLOADER.TROJAN These are all in my F drive. In order to get it to finish a scan, I had to delte thr files it found on my C drive, which were all of the same Acer Game files and a couple of Java ones. I didn't need the programs, so I just deleted the whole folders, and tried the scan again. Also, before deleting those files I suddenly couldn't access the internet, but now it's allowing me back on again.Hi, Please run a free online scan with the ESET Online Scanner Note: You will need to use Internet Explorer for this scan[/i]
"Can not get update. Is proxy configured?"Hi. Remove the Proxy setting in Internet explorer and/or in FireFox. In IE: Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously. In Firefox in Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection > Choose "No Proxy" Click the apply button and restart that computer in normal mode.The box you indicated was already not checked.Hi. Could you please re-run ComboFix?Comment removed. Do not post in the malware forum unless you need help. ~Sneakyone I am unable to download ComboFix. It says connection with the server was reset. |
|
| 325. |
Solve : need some help thanks? |
|
Answer» about the same i think but i'm thinking it might be the internet connectionAll looks GOOD on my end.
ok thanks for your help! |
|
| 326. |
Solve : Nasty trojan(s) redirecting, came from facebook, followed evilfantasy's steps? |
|
Answer» You're WELCOME. |
|
| 327. |
Solve : malware/virus help? |
|
Answer» How are things running now? So far, so good Ok. Let's do one more scan
|
|
| 328. |
Solve : Malware infection? |
|
Answer» Hi,
2010, AD \\.\C: --> \\.\PhysicalDrive0 \\.\D: --> \\.\PhysicalDrive1 \\.\E: --> \\.\PhysicalDrive1 Size Device Name MBR Status ---------------------------------------------------------------------- 232 GB \\.\PhysicalDrive0 MBR Code Faked! 232 GB \\.\PhysicalDrive1 Windows XP MBR code detected Found non-standard for infected MBR Enter 'Y' and hit entere for more options, or 'N' to exit: y Options: [1] Dump the MBR of a physical disk to file. [2] Restore the MBR of a phyical disk with a standard boot code [3] Exit Enter your choice: Hi, Run MBRCheck.exe
Hi, Could you please run MBRCheck again and post the log here, to be sure it is gone. MBRCheck, version 1.1.1 2010, AD \\.\C: --> \\.\PhysicalDrive0 \\.\D: --> \\.\PhysicalDrive1 \\.\E: --> \\.\PhysicalDrive1 Size Device Name MBR Status ---------------------------------------------------------------------- 232 GB \\.\PhysicalDrive0 Windows XP MBR code detected 232 GB \\.\PhysicalDrive1 Windows XP MBR code detected Done! Press ENTER to exit....Hi, Please download ComboFix from BleepingComputer.com Alternate link: GeeksToGo.com Alternate link: Forospyware.com Rename ComboFix.exe to commy.exe before you save it to your Desktop
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Then automatically rebooted. Combofix log: ComboFix 10-07-21.02 - Toni 07/22/2010 2:11.4.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1181 [GMT -4:00] Running from: c:\documents and settings\Toni\desktop\commy.exe Command switches used :: /stepdel AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Toni\Application Data\Sky-Banners c:\documents and settings\Toni\Application Data\Street-Ads c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B} c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor c:\windows\$NtUninstallMTF1011$ c:\windows\TEMP\logishrd\LVPrcInj01.dll c:\documents and settings\Toni\Application Data\09f7619a.exe c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome.manifest c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\_cfg.js c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\overlay.xul c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\install.rdf c:\documents and settings\Toni\Start Menu\Antimalware Doctor.lnk c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk c:\windows\$NtUninstallMTF1011$\apUninstall.exe c:\windows\$NtUninstallMTF1011$\zrpt.xml c:\windows\system32\ernel32.dll . ((((((((((((((((((((((((( Files Created from 2010-06-22 to 2010-07-22 ))))))))))))))))))))))))))))))) . 2010-07-21 13:54 . 2010-07-21 14:49--------d-----w-C:\commy21098c 2010-07-21 11:25 . 2010-07-21 12:14--------d-----w-C:\commy 2010-07-21 11:18 . 2010-07-21 11:18--------d-----w-C:\_OTL 2010-07-20 10:57 . 2010-07-20 10:57--------d-----w-c:\program files\CCleaner 2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\program files\Uniblue 2010-07-18 16:03 . 2010-07-18 16:034057620----a-w-c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\registrybooster1-Wrapped.exe 2010-07-18 16:03 . 2010-07-18 16:06--------d-----w-c:\documents and settings\Toni\Local Settings\Application Data\OpenCandy 2010-07-18 16:03 . 2010-07-18 16:03331304----a-w-c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\DLMgr_3_1.6.44.exe 2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\documents and settings\Toni\Application Data\OpenCandy 2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\program files\Winamp Detect 2010-07-18 16:01 . 2010-07-18 16:51--------d-----w-c:\documents and settings\Toni\Application Data\Winamp 2010-07-18 16:01 . 2010-07-18 16:03--------d-----w-c:\program files\Winamp 2010-07-17 15:37 . 2010-07-21 16:00--------d-----w-c:\documents and settings\Toni\Local Settings\Application Data\AskToolbar 2010-07-15 16:36 . 2010-07-15 16:362944904----a-w-c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\extensions\[emailprotected]\chrome\temp\askToolbar.exe 2010-07-14 13:39 . 2010-07-14 13:39--------d-----w-c:\documents and settings\Toni\Application Data\Avery 2010-07-14 13:24 . 2010-07-14 13:24--------d-----w-c:\program files\Avery Dennison 2010-07-14 13:24 . 2010-07-14 13:24--------d-----w-c:\documents and settings\All Users\Application Data\Avery 2010-07-14 13:10 . 2010-07-17 14:02--------d-----w-c:\program files\Ask.com 2010-07-14 13:05 . 2010-07-14 13:0789582136----a-w-c:\program files\DesignPro5_5_Limited.exe 2010-07-14 09:10 . 2010-06-14 14:31744448-c----w-c:\windows\system32\dllcache\helpsvc.exe 2010-07-12 15:35 . 2010-07-12 15:352272----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2010-07-10 14:39 . 2010-07-10 14:39--------d-----w-c:\documents and settings\Administrator\Application Data\Malwarebytes . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-22 06:17 . 2009-02-17 19:400----a-w-c:\windows\system32\drivers\lvuvc.hs 2010-07-22 06:17 . 2009-02-17 19:380----a-w-c:\windows\system32\drivers\logiflt.iad 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k7 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k6 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k5 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k4 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k3 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k2 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k1 2010-07-22 06:16 . 2009-01-28 19:20227220----a-w-c:\windows\system32\drivers\kmxcfg.u2k0 2010-07-22 05:55 . 2010-04-09 13:471324----a-w-c:\windows\system32\d3d9caps.dat 2010-07-20 19:53 . 2010-03-10 14:04--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-07-18 00:58 . 2009-08-13 23:13--------d-----w-c:\documents and settings\Toni\Application Data\Vso 2010-07-16 20:20 . 2010-03-22 17:58--------d-----w-c:\program files\uTorrent 2010-07-15 15:39 . 2009-01-30 16:19395984----a-w-c:\documents and settings\Toni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-07-14 13:33 . 2009-01-28 14:38--------d--h--w-c:\program files\InstallShield Installation Information 2010-07-10 23:55 . 2010-02-11 12:30--------d-----w-c:\documents and settings\All Users\Application Data\Roxio 2010-06-25 18:51 . 2009-02-04 05:06--------d-----w-c:\documents and settings\Toni\Application Data\ZoomBrowser EX 2010-06-25 18:50 . 2009-01-31 18:06--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser 2010-06-19 16:23 . 2009-02-03 02:26--------d-----w-c:\documents and settings\Toni\Application Data\AdobeUM 2010-06-17 15:46 . 2010-06-16 20:29--------d-----w-c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe 2010-06-16 20:25 . 2009-01-30 07:02--------d-----w-c:\program files\Common Files\Adobe 2010-06-16 19:40 . 2010-06-16 19:40--------d-----w-c:\program files\Adobe Media Player 2010-06-16 19:39 . 2010-06-16 19:3910134----a-r-c:\documents and settings\Toni\Application Data\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe 2010-06-16 19:39 . 2010-06-16 19:39--------d-----w-c:\program files\My Company Name 2010-06-16 19:34 . 2010-06-16 19:34--------d-----w-c:\program files\Common Files\Adobe AIR 2010-06-16 16:18 . 2009-02-26 02:14--------d-----w-c:\documents and settings\Toni\Application Data\Move Networks 2010-06-14 19:58 . 2010-06-14 19:58--------d-----w-c:\documents and settings\All Users\Application Data\vsosdk 2010-06-14 14:31 . 2009-01-28 13:06744448----a-w-c:\windows\pchealth\helpctr\binaries\helpsvc.exe 2010-06-13 18:14 . 2010-06-13 18:06--------d-----w-c:\program files\PeerGuardian2 2010-06-07 00:19 . 2010-05-04 17:20--------d-----w-c:\program files\Microsoft Silverlight 2010-06-03 16:35 . 2009-07-09 01:421561896----a-w-c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll 2010-06-03 16:35 . 2009-01-28 18:24746216----a-w-c:\windows\system32\drivers\vetefile.sys 2010-06-03 16:35 . 2009-01-28 18:24130280----a-w-c:\windows\system32\drivers\veteboot.sys 2010-05-28 18:57 . 2009-01-28 18:2491472----a-w-c:\windows\system32\isafprod.dll 2010-05-04 17:20 . 2004-08-04 12:00832512----a-w-c:\windows\system32\wininet.dll 2010-05-04 17:20 . 2004-08-04 12:0078336----a-w-c:\windows\system32\ieencode.dll 2010-05-04 17:20 . 2004-08-04 12:0017408----a-w-c:\windows\system32\corpol.dll 2010-05-02 05:22 . 2004-08-04 12:001851264----a-w-c:\windows\system32\win32k.sys 2010-04-29 19:39 . 2010-03-10 14:0438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-29 19:39 . 2010-03-10 14:0420952----a-w-c:\windows\system32\drivers\mbam.sys 2010-02-02 17:02 . 2010-02-02 17:021438976----a-w-c:\program files\MoveMediaPlayerWin_071505000011.exe 2010-02-01 01:43 . 2010-02-01 01:432107456----a-w-c:\program files\Install_Facebook_Plug-In_1.0.1.exe 2010-01-31 12:26 . 2010-01-31 12:261533702----a-w-c:\program files\gburner27.exe 2009-08-13 23:06 . 2009-08-13 23:057741336----a-w-c:\program files\DivX521XP2K_1.exe 2009-08-13 22:54 . 2009-08-13 22:534526458----a-w-c:\program files\WinAVI_Video_Converter.exe 2009-06-16 21:38 . 2009-06-16 21:382144584----a-w-c:\program files\InstallFirefoxPluginV3.exe 2009-06-12 22:34 . 2009-06-12 22:3024527365----a-w-c:\program files\FreeVideoConverter.exe 2009-03-05 21:24 . 2009-03-05 21:244909440----a-w-c:\program files\Silverlight.2.0.exe . ((((((((((((((((((((((((((((( [emailprotected]_11.57.58 ))))))))))))))))))))))))))))))))))))))))) . + 2009-06-26 23:10 . 2009-06-26 23:1059904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90u.dll + 2009-06-26 23:10 . 2009-06-26 23:1059904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90.dll + 2009-07-12 00:32 . 2009-07-12 00:3249152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll + 2009-07-12 00:32 . 2009-07-12 00:3249152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll + 2009-07-12 00:32 . 2009-07-12 00:3257344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll + 2009-07-12 00:32 . 2009-07-12 00:3265536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll + 2009-07-12 00:32 . 2009-07-12 00:3245056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll + 2009-07-12 00:32 . 2009-07-12 00:3240960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll + 2009-07-12 05:07 . 2009-07-12 05:0757856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll + 2009-07-12 05:19 . 2009-07-12 05:1969632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll + 2009-07-11 23:41 . 2009-07-11 23:4197280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll + 2010-07-22 06:17 . 2010-07-22 06:1716384 c:\windows\temp\Perflib_Perfdata_4e8.dat - 2008-04-14 00:12 . 2010-01-23 08:1146080 c:\windows\system32\tzchange.exe + 2008-04-14 00:12 . 2010-04-21 13:2846080 c:\windows\system32\tzchange.exe + 2006-03-25 00:00 . 2006-03-25 00:0045056 c:\windows\system32\spool\prtprocs\w32x86\iQ17cEI7q.dll + 2005-05-24 00:00 . 2005-05-24 00:0045056 c:\windows\system32\spool\prtprocs\w32x86\aAA17eI.dll + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\pxinsa64.exe - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\pxinsa64.exe + 2010-07-18 16:02 . 2009-04-28 20:2072176 c:\windows\system32\pxhpinst.exe + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\pxcpya64.exe - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\pxcpya64.exe + 2010-03-31 04:16 . 2010-03-31 04:1699176 c:\windows\system32\PresentationHostProxy.dll + 2004-08-04 12:00 . 2010-05-04 17:2044544 c:\windows\system32\pngfilt.dll - 2004-08-04 12:00 . 2010-03-11 12:3844544 c:\windows\system32\pngfilt.dll - 2004-08-04 12:00 . 2010-03-14 12:5378958 c:\windows\system32\perfc009.dat + 2004-08-04 12:00 . 2010-07-08 14:5278958 c:\windows\system32\perfc009.dat + 2009-11-07 05:07 . 2009-11-07 05:0749488 c:\windows\system32\netfxperf.dll + 2009-11-06 02:17 . 2009-11-06 02:1711600 c:\windows\system32\mui\0409\mscorees.dll - 2007-08-14 02:54 . 2010-03-11 12:3852224 c:\windows\system32\msfeedsbs.dll + 2007-08-14 02:54 . 2010-05-04 17:2052224 c:\windows\system32\msfeedsbs.dll + 2004-08-04 12:00 . 2010-05-04 17:2027648 c:\windows\system32\jsproxy.dll - 2004-08-04 12:00 . 2010-03-11 12:3827648 c:\windows\system32\jsproxy.dll + 2007-08-14 02:39 . 2010-05-04 12:3913824 c:\windows\system32\ieudinit.exe - 2007-08-14 02:39 . 2010-03-10 13:1813824 c:\windows\system32\ieudinit.exe - 2004-08-04 12:00 . 2010-03-11 12:3844544 c:\windows\system32\iernonce.dll + 2004-08-04 12:00 . 2010-05-04 17:2044544 c:\windows\system32\iernonce.dll - 2004-08-04 12:00 . 2010-03-10 13:1870656 c:\windows\system32\ie4uinit.exe + 2004-08-04 12:00 . 2010-05-04 12:3970656 c:\windows\system32\ie4uinit.exe - 2007-08-14 02:36 . 2010-03-11 12:3863488 c:\windows\system32\icardie.dll + 2007-08-14 02:36 . 2010-05-04 17:2063488 c:\windows\system32\icardie.dll - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\drvins64.exe + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\drvins64.exe + 2009-07-09 07:00 . 2009-07-09 07:0045200 c:\windows\system32\drivers\pxhelp20.sys - 2009-07-09 08:00 . 2009-07-09 08:0045200 c:\windows\system32\drivers\pxhelp20.sys + 2007-08-14 02:36 . 2010-05-04 17:2044544 c:\windows\system32\dllcache\pngfilt.dll - 2007-08-14 02:36 . 2010-03-11 12:3844544 c:\windows\system32\dllcache\pngfilt.dll + 2009-01-28 15:29 . 2010-05-04 17:2052224 c:\windows\system32\dllcache\msfeedsbs.dll - 2009-01-28 15:29 . 2010-03-11 12:3852224 c:\windows\system32\dllcache\msfeedsbs.dll + 2007-08-14 02:54 . 2010-05-04 17:2027648 c:\windows\system32\dllcache\jsproxy.dll - 2007-08-14 02:54 . 2010-03-11 12:3827648 c:\windows\system32\dllcache\jsproxy.dll - 2009-01-28 15:29 . 2010-03-10 13:1813824 c:\windows\system32\dllcache\ieudinit.exe + 2009-01-28 15:29 . 2010-05-04 12:3913824 c:\windows\system32\dllcache\ieudinit.exe - 2007-08-14 02:39 . 2010-03-11 12:3844544 c:\windows\system32\dllcache\iernonce.dll + 2007-08-14 02:39 . 2010-05-04 17:2044544 c:\windows\system32\dllcache\iernonce.dll + 2007-08-14 02:45 . 2010-05-04 17:2078336 c:\windows\system32\dllcache\ieencode.dll - 2007-08-14 02:45 . 2010-03-11 12:3878336 c:\windows\system32\dllcache\ieencode.dll + 2007-08-14 02:39 . 2010-05-04 12:3970656 c:\windows\system32\dllcache\ie4uinit.exe - 2007-08-14 02:39 . 2010-03-10 13:1870656 c:\windows\system32\dllcache\ie4uinit.exe + 2009-01-28 15:29 . 2010-05-04 17:2063488 c:\windows\system32\dllcache\icardie.dll - 2009-01-28 15:29 . 2010-03-11 12:3863488 c:\windows\system32\dllcache\icardie.dll + 2007-08-14 02:42 . 2010-05-04 17:2017408 c:\windows\system32\dllcache\corpol.dll - 2007-08-14 02:42 . 2010-03-11 12:3817408 c:\windows\system32\dllcache\corpol.dll + 2010-03-05 14:37 . 2010-03-05 14:3765536 c:\windows\system32\dllcache\asycfilt.dll - 2009-01-28 13:12 . 2009-03-24 23:1632768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2009-01-28 13:12 . 2010-07-10 19:4832768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2009-01-28 13:12 . 2009-03-24 23:1616384 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2010-05-07 15:17 . 2010-07-10 19:4816384 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2004-08-04 12:00 . 2010-03-05 14:3765536 c:\windows\system32\asycfilt.dll - 2008-07-30 03:16 . 2008-07-30 03:1632768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll + 2010-04-08 03:48 . 2010-04-08 03:4832768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll + 2010-03-23 09:31 . 2010-03-23 09:3130544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe + 2010-04-01 15:42 . 2010-04-01 15:4281920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll - 2008-05-28 04:49 . 2008-05-28 04:4977824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll + 2010-03-31 18:51 . 2010-03-31 18:5177824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll - 2008-05-28 04:49 . 2008-05-28 04:4986016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll + 2010-03-31 18:51 . 2010-03-31 18:5186016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll + 2010-03-31 18:51 . 2010-03-31 18:5181920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll - 2008-05-28 04:49 . 2008-05-28 04:4981920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll + 2010-03-31 19:32 . 2010-03-31 19:3232768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe - 2008-05-28 05:30 . 2008-05-28 05:3032768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe - 2003-02-21 03:19 . 2003-02-21 03:1924576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll + 2010-03-31 19:32 . 2010-03-31 19:3224576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll + 2009-11-07 05:07 . 2009-11-07 05:0713688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll + 2009-11-07 05:07 . 2009-11-07 05:0713696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll + 2009-11-07 05:07 . 2009-11-07 05:0713672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll + 2009-11-07 05:07 . 2009-11-07 05:0786864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe + 2010-06-16 19:40 . 2010-06-16 19:4022016 c:\windows\Installer\a68879.msi + 2010-06-16 19:34 . 2010-06-16 19:3422528 c:\windows\Installer\a6885b.msi + 2010-06-16 19:34 . 2010-06-16 19:3427648 c:\windows\Installer\a68853.msi + 2010-05-04 17:20 . 2010-05-04 17:2049664 c:\windows\Installer\35251f9.msi + 2010-06-15 00:32 . 2010-06-15 00:3221504 c:\windows\Installer\1712a6bf.msi + 2010-07-14 13:26 . 2010-07-14 13:2640960 c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\ARPPRODUCTICON.exe + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}\ARPPRODUCTICON.exe + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{D1A19B02-817E-4296-A45B-07853FD74D57}\ARPPRODUCTICON.exe + 2010-06-16 20:25 . 2010-06-16 20:2581920 c:\windows\Installer\{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}\ARPPRODUCTICON.exe + 2010-05-08 16:34 . 2010-05-08 16:3425214 c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe + 2010-05-08 16:34 . 2010-05-08 16:3425214 c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\ARPPRODUCTICON.exe + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\ARPPRODUCTICON.exe - 2009-01-28 18:22 . 2010-04-14 03:4723040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe + 2009-01-28 18:22 . 2010-07-15 11:0423040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2009-01-28 18:22 . 2010-04-14 03:4761440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe + 2009-01-28 18:22 . 2010-07-15 11:0461440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe - 2009-01-28 18:22 . 2010-04-14 03:4727136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2009-01-28 18:22 . 2010-07-15 11:0427136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe - 2009-01-28 18:22 . 2010-04-14 03:4711264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2009-01-28 18:22 . 2010-07-15 11:0411264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe - 2009-01-28 18:22 . 2010-04-14 03:4712288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2009-01-28 18:22 . 2010-07-15 11:0412288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2010-06-10 12:21 . 2010-06-10 12:2138240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe - 2010-04-14 03:51 . 2010-04-14 03:5138240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe + 2010-05-04 17:26 . 2010-06-04 07:0149152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll + 2010-06-16 19:43 . 2010-06-16 19:4381920 c:\windows\Installer\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}\ARPPRODUCTICON.exe + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}\ARPPRODUCTICON.exe + 2010-06-16 19:33 . 2010-06-16 19:3310134 c:\windows\Installer\{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}\ARPPRODUCTICON.exe + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{08D2E121-7F6A-43EB-97FD-629B44903403}\ARPPRODUCTICON.exe + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}\ARPPRODUCTICON.exe + 2010-06-10 11:51 . 2010-03-11 12:3844544 c:\windows\ie7updates\KB982381-IE7\pngfilt.dll + 2010-06-10 11:51 . 2010-03-11 12:3852224 c:\windows\ie7updates\KB982381-IE7\msfeedsbs.dll + 2010-06-10 11:52 . 2010-03-11 12:3827648 c:\windows\ie7updates\KB982381-IE7\jsproxy.dll + 2010-06-10 11:52 . 2010-03-10 13:1813824 c:\windows\ie7updates\KB982381-IE7\ieudinit.exe + 2010-06-10 11:52 . 2010-03-11 12:3844544 c:\windows\ie7updates\KB982381-IE7\iernonce.dll + 2010-06-10 11:52 . 2010-03-11 12:3878336 c:\windows\ie7updates\KB982381-IE7\ieencode.dll + 2010-06-10 11:52 . 2010-03-10 13:1870656 c:\windows\ie7updates\KB982381-IE7\ie4uinit.exe + 2010-06-10 11:52 . 2010-03-11 12:3863488 c:\windows\ie7updates\KB982381-IE7\icardie.dll + 2010-06-10 11:52 . 2010-03-11 12:3817408 c:\windows\ie7updates\KB982381-IE7\corpol.dll + 2010-06-10 12:23 . 2010-06-10 12:2390112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ee3c85bd\System.Drawing.Design.dll + 2010-06-10 12:23 . 2010-06-10 12:2361440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b31c6c1f\CustomMarshalers.dll + 2010-06-10 12:27 . 2010-06-10 12:2747616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\11b5c5344eb40eeb36a818d2824fe3a1\WindowsLiveWriter.ni.exe + 2010-06-10 12:29 . 2010-06-10 12:2999840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c69cc7d4e4fca9aa892ddfacc64cddb2\WindowsLive.Writer.Api.ni.dll + 2010-06-24 07:11 . 2010-06-24 07:1160928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ea1b4fbde0e772748c6ac42d627cf684\UIAutomationProvider.ni.dll + 2010-06-24 07:13 . 2010-06-24 07:1337888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f46915dfc57bc7e49c5402e9b8f7ec18\System.Windows.Presentation.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:3137888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\1c1629f536fa9874ef08d09fb19ab0f0\System.Windows.Presentation.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:3136864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\1464c662c302ea6372a885161b983732\System.Web.DynamicData.Design.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:3094208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\5d535ecadf77ac2d9278a1661beb2855\System.ComponentModel.DataAnnotations.ni.dll + 2010-06-10 12:12 . 2010-06-10 12:1247104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e67992626a30603458b0df22841c2423\PresentationFontCache.ni.exe + 2010-06-24 07:09 . 2010-06-24 07:0947104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\18729514178d458aa1225dd068718d4e\PresentationFontCache.ni.exe + 2010-06-10 12:10 . 2010-06-10 12:1039424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\6be27d744e6e2bfc4b0e25bd2998ef7c\PresentationCFFRasterizer.ni.dll + 2010-06-24 07:08 . 2010-06-24 07:0839424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0375dfa28e2f6ef7e89df9edede4b83d\PresentationCFFRasterizer.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:3155296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\4a52287444c36c89310856b38ff52fe0\Microsoft.Vsa.ni.dll + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll - 2009-10-17 07:13 . 2009-10-17 07:1377824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll + 2010-06-10 12:10 . 2010-06-10 12:1032768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll - 2009-01-28 15:35 . 2009-01-28 15:3532768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll - 2009-10-17 07:13 . 2009-10-17 07:1381920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2010-06-24 07:04 . 2010-06-24 07:0481920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2010-06-24 07:04 . 2010-06-24 07:0481920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll - 2009-10-17 07:14 . 2009-10-17 07:1481920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll - 2009-10-17 07:13 . 2009-10-17 07:1332768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll + 2010-06-24 07:04 . 2010-06-24 07:0432768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2009-10-17 07:13 . 2009-10-17 07:1312800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2010-06-24 07:04 . 2010-06-24 07:0412800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2010-06-24 07:04 . 2010-06-24 07:0428672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll - 2009-10-17 07:13 . 2009-10-17 07:1328672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll - 2009-10-17 07:14 . 2009-10-17 07:1477824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll + 2010-06-24 07:04 . 2010-06-24 07:0436864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll - 2009-10-17 07:13 . 2009-10-17 07:1336864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll - 2009-10-17 07:13 . 2009-10-17 07:1377824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2009-10-17 07:13 . 2009-10-17 07:1313312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll + 2010-06-24 07:04 . 2010-06-24 07:0413312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll - 2009-10-17 07:13 . 2009-10-17 07:1310752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2010-06-24 07:04 . 2010-06-24 07:0410752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2010-06-24 07:04 . 2010-06-24 07:0472192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2009-10-17 07:13 . 2009-10-17 07:1372192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2009-10-17 07:13 . 2009-10-17 07:1369120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2010-06-24 07:04 . 2010-06-24 07:0469120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2010-06-10 12:23 . 2010-06-10 12:2381920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll + 2010-05-26 07:00 . 2010-01-23 08:1146080 c:\windows\$NtUninstallKB981793$\tzchange.exe + 2010-05-26 07:00 . 2010-04-22 22:2116896 c:\windows\$NtUninstallKB981793$\spuninst\tzchange.dll + 2010-06-10 12:12 . 2008-04-14 00:1165024 c:\windows\$NtUninstallKB979482$\asycfilt.dll + 2010-06-10 11:52 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB982381-IE7\update\spcustom.dll + 2010-06-10 11:52 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB982381-IE7\spmsg.dll + 2010-05-04 17:20 . 2010-05-04 17:2044544 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\pngfilt.dll + 2010-05-04 17:20 . 2010-05-04 17:2052224 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeedsbs.dll + 2010-05-04 17:20 . 2010-05-04 17:2027648 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\jsproxy.dll + 2010-05-04 13:19 . 2010-05-04 13:1913824 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieudinit.exe + 2010-05-04 17:20 . 2010-05-04 17:2044544 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iernonce.dll + 2010-05-04 17:20 . 2010-05-04 17:2078336 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieencode.dll + 2010-05-04 13:19 . 2010-05-04 13:1970656 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ie4uinit.exe + 2010-05-04 17:20 . 2010-05-04 17:2063488 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\icardie.dll + 2010-05-04 17:19 . 2010-05-04 17:1917408 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\corpol.dll + 2010-06-10 12:28 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB980218\update\spcustom.dll + 2010-06-10 12:28 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB980218\spmsg.dll + 2010-06-10 12:23 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB980195\update\spcustom.dll + 2010-06-10 12:23 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB980195\spmsg.dll + 2010-06-10 12:19 . 2009-05-26 09:0126488 c:\windows\$hf_mig$\KB979559\update\spcustom.dll + 2010-06-10 12:19 . 2009-05-26 09:0117272 c:\windows\$hf_mig$\KB979559\spmsg.dll + 2010-06-10 12:12 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB979482\update\spcustom.dll + 2010-06-10 12:12 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB979482\spmsg.dll + 2010-03-05 14:52 . 2010-03-05 14:5265536 c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll + 2010-05-13 07:01 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB978542\update\spcustom.dll + 2010-05-13 07:01 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB978542\spmsg.dll + 2010-06-10 12:12 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB975562\update\spcustom.dll + 2010-06-10 12:12 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB975562\spmsg.dll - 2009-10-17 07:13 . 2009-10-17 07:138192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll + 2010-06-24 07:04 . 2010-06-24 07:048192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll - 2009-06-23 08:00 . 2009-06-23 08:009200 c:\windows\system32\drivers\cdralw2k.sys + 2009-06-23 07:00 . 2009-06-23 07:009200 c:\windows\system32\drivers\cdralw2k.sys - 2009-06-23 08:00 . 2009-06-23 08:009072 c:\windows\system32\drivers\cdr4_xp.sys + 2009-06-23 07:00 . 2009-06-23 07:009072 c:\windows\system32\drivers\cdr4_xp.sys + 2010-07-14 13:26 . 2010-07-14 13:262238 c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\Shortcut1_71F6DF7DB6394FADBA93E6DF267AA44D.exe + 2009-01-28 18:22 . 2010-07-15 11:044096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe - 2009-01-28 18:22 . 2010-04-14 03:474096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2010-06-24 07:04 . 2010-06-24 07:047168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll - 2009-10-17 07:13 . 2009-10-17 07:137168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2010-06-24 07:04 . 2010-06-24 07:045632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2009-10-17 07:14 . 2009-10-17 07:145632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll + 2010-06-24 07:04 . 2010-06-24 07:046656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll - 2009-10-17 07:13 . 2009-10-17 07:136656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2010-06-24 07:04 . 2010-06-24 07:048192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2009-10-17 07:13 . 2009-10-17 07:138192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2009-10-17 07:13 . 2009-10-17 07:13113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll + 2010-06-24 07:04 . 2010-06-24 07:04113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2009-06-26 23:07 . 2009-06-26 23:07653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcr90.dll + 2009-06-26 23:07 . 2009-06-26 23:07569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcp90.dll + 2009-06-26 23:10 . 2009-06-26 23:10225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcm90.dll + 2009-06-26 23:07 . 2009-06-26 23:07159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_35349982\atl90.dll + 2009-07-12 05:12 . 2009-07-12 05:12632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll + 2009-07-12 05:09 . 2009-07-12 05:09554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll + 2009-07-12 05:08 . 2009-07-12 05:08479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll + 2004-08-04 12:00 . 2010-05-04 17:20233472 c:\windows\system32\webcheck.dll - 2004-08-04 12:00 . 2010-03-11 12:38233472 c:\windows\system32\webcheck.dll + 2004-08-04 12:00 . 2010-05-04 17:20105984 c:\windows\system32\url.dll - 2004-08-04 12:00 . 2010-03-11 12:38105984 c:\windows\system32\url.dll + 2009-07-10 02:03 . 2009-07-10 02:03125424 c:\windows\system32\pxinsi64.exe - 2009-07-10 03:03 . 2009-07-10 03:03125424 c:\windows\system32\pxinsi64.exe - 2009-07-10 03:03 . 2009-07-10 03:03123888 c:\windows\system32\pxcpyi64.exe + 2009-07-10 02:03 . 2009-07-10 02:03123888 c:\windows\system32\pxcpyi64.exe + 2010-03-31 04:10 . 2010-03-31 04:10295264 c:\windows\system32\PresentationHost.exe - 2004-08-04 12:00 . 2010-03-14 12:53465072 c:\windows\system32\perfh009.dat + 2004-08-04 12:00 . 2010-07-08 14:52465072 c:\windows\system32\perfh009.dat + 2004-08-04 12:00 . 2010-05-04 17:20102912 c:\windows\system32\occache.dll - 2004-08-04 12:00 . 2010-03-11 12:38102912 c:\windows\system32\occache.dll + 2004-08-04 12:00 . 2010-05-04 17:20671232 c:\windows\system32\mstime.dll - 2004-08-04 12:00 . 2010-03-11 12:38671232 c:\windows\system32\mstime.dll - 2004-08-04 12:00 . 2010-03-11 12:38193024 c:\windows\system32\msrating.dll + 2004-08-04 12:00 . 2010-05-04 17:20193024 c:\windows\system32\msrating.dll - 2004-08-04 12:00 . 2010-03-11 12:38477696 c:\windows\system32\mshtmled.dll + 2004-08-04 12:00 . 2010-05-04 17:20477696 c:\windows\system32\mshtmled.dll - 2007-08-14 02:54 . 2010-03-11 12:38459264 c:\windows\system32\msfeeds.dll + 2007-08-14 02:54 . 2010-05-04 17:20459264 c:\windows\system32\msfeeds.dll + 2009-11-07 05:07 . 2009-11-07 05:07297808 c:\windows\system32\mscoree.dll + 2010-06-16 20:25 . 2010-06-16 20:25223184 c:\windows\system32\Macromed\Flash\FlashUtil10g_Plugin.exe + 2010-06-16 19:43 . 2010-06-16 19:43223184 c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.exe + 2010-06-16 19:43 . 2010-06-16 19:43268240 c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.dll + 2009-01-28 13:06 . 2010-01-29 15:01691712 c:\windows\system32\inetcomm.dll - 2009-01-28 13:06 . 2008-04-11 19:04691712 c:\windows\system32\inetcomm.dll - 2007-08-14 02:34 . 2010-03-11 12:38268288 c:\windows\system32\iertutil.dll + 2007-08-14 02:34 . 2010-05-04 17:20268288 c:\windows\system32\iertutil.dll + 2004-08-04 12:00 . 2010-05-04 17:20192512 c:\windows\system32\iepeers.dll - 2004-08-04 12:00 . 2010-03-11 12:38192512 c:\windows\system32\iepeers.dll - 2004-08-04 12:00 . 2010-03-11 12:38385024 c:\windows\system32\iedkcs32.dll + 2004-08-04 12:00 . 2010-05-04 17:20385024 c:\windows\system32\iedkcs32.dll - 2007-07-11 20:27 . 2010-03-11 12:38380928 c:\windows\system32\ieapfltr.dll + 2007-07-11 20:27 . 2010-05-04 17:20380928 c:\windows\system32\ieapfltr.dll + 2004-08-04 12:00 . 2010-04-16 11:43161792 c:\windows\system32\ieakui.dll - 2004-08-04 12:00 . 2010-02-23 05:18161792 c:\windows\system32\ieakui.dll + 2004-08-04 12:00 . 2010-05-04 17:20230400 c:\windows\system32\ieaksie.dll - 2004-08-04 12:00 . 2010-03-11 12:38230400 c:\windows\system32\ieaksie.dll + 2004-08-04 12:00 . 2010-05-04 17:20153088 c:\windows\system32\ieakeng.dll - 2004-08-04 12:00 . 2010-03-11 12:38153088 c:\windows\system32\ieakeng.dll - 2004-08-04 12:00 . 2010-03-11 12:38133120 c:\windows\system32\extmgr.dll + 2004-08-04 12:00 . 2010-05-04 17:20133120 c:\windows\system32\extmgr.dll - 2004-08-04 12:00 . 2010-03-11 12:38214528 c:\windows\system32\dxtrans.dll + 2004-08-04 12:00 . 2010-05-04 17:20214528 c:\windows\system32\dxtrans.dll - 2004-08-04 12:00 . 2010-03-11 12:38347136 c:\windows\system32\dxtmsft.dll + 2004-08-04 12:00 . 2010-05-04 17:20347136 c:\windows\system32\dxtmsft.dll + 2007-08-14 02:54 . 2010-05-04 17:20832512 c:\windows\system32\dllcache\wininet.dll - 2007-08-14 02:54 . 2010-03-11 12:38832512 c:\windows\system32\dllcache\wininet.dll + 2007-08-14 02:54 . 2010-05-04 17:20233472 c:\windows\system32\dllcache\webcheck.dll - 2007-08-14 02:54 . 2010-03-11 12:38233472 c:\windows\system32\dllcache\webcheck.dll - 2007-08-14 02:44 . 2010-03-11 12:38105984 c:\windows\system32\dllcache\url.dll + 2007-08-14 02:44 . 2010-05-04 17:20105984 c:\windows\system32\dllcache\url.dll + 2007-08-14 02:44 . 2010-05-04 17:20102912 c:\windows\system32\dllcache\occache.dll - 2007-08-14 02:44 . 2010-03-11 12:38102912 c:\windows\system32\dllcache\occache.dll - 2007-08-14 02:54 . 2010-03-11 12:38671232 c:\windows\system32\dllcache\mstime.dll + 2007-08-14 02:54 . 2010-05-04 17:20671232 c:\windows\system32\dllcache\mstime.dll - 2007-08-14 02:44 . 2010-03-11 12:38193024 c:\windows\system32\dllcache\msrating.dll + 2007-08-14 02:44 . 2010-05-04 17:20193024 c:\windows\system32\dllcache\msrating.dll + 2007-08-14 02:54 . 2010-05-04 17:20477696 c:\windows\system32\dllcache\mshtmled.dll - 2007-08-14 02:54 . 2010-03-11 12:38477696 c:\windows\system32\dllcache\mshtmled.dll + 2009-01-28 15:29 . 2010-05-04 17:20459264 c:\windows\system32\dllcache\msfeeds.dll - 2009-01-28 15:29 . 2010-03-11 12:38459264 c:\windows\system32\dllcache\msfeeds.dll + 2009-01-28 14:49 . 2010-01-29 15:01691712 c:\windows\system32\dllcache\inetcomm.dll - 2009-01-28 14:49 . 2008-04-11 19:04691712 c:\windows\system32\dllcache\inetcomm.dll + 2007-08-14 02:43 . 2010-04-16 11:43634656 c:\windows\system32\dllcache\iexplore.exe + 2009-01-28 15:29 . 2010-05-04 17:20268288 c:\windows\system32\dllcache\iertutil.dll - 2009-01-28 15:29 . 2010-03-11 12:38268288 c:\windows\system32\dllcache\iertutil.dll - 2007-08-14 02:54 . 2010-03-11 12:38192512 c:\windows\system32\dllcache\iepeers.dll + 2007-08-14 02:54 . 2010-05-04 17:20192512 c:\windows\system32\dllcache\iepeers.dll - 2007-08-14 02:39 . 2010-03-11 12:38385024 c:\windows\system32\dllcache\iedkcs32.dll + 2007-08-14 02:39 . 2010-05-04 17:20385024 c:\windows\system32\dllcache\iedkcs32.dll - 2009-01-28 15:29 . 2010-03-11 12:38380928 c:\windows\system32\dllcache\ieapfltr.dll + 2009-01-28 15:29 . 2010-05-04 17:20380928 c:\windows\system32\dllcache\ieapfltr.dll + 2004-08-04 12:00 . 2010-04-16 11:43161792 c:\windows\system32\dllcache\ieakui.dll - 2004-08-04 12:00 . 2010-02-23 05:18161792 c:\windows\system32\dllcache\ieakui.dll + 2007-08-14 02:39 . 2010-05-04 17:20230400 c:\windows\system32\dllcache\ieaksie.dll - 2007-08-14 02:39 . 2010-03-11 12:38230400 c:\windows\system32\dllcache\ieaksie.dll - 2007-08-14 02:39 . 2010-03-11 12:38153088 c:\windows\system32\dllcache\ieakeng.dll + 2007-08-14 02:39 . 2010-05-04 17:20153088 c:\windows\system32\dllcache\ieakeng.dll + 2007-08-14 02:54 . 2010-05-04 17:20133120 c:\windows\system32\dllcache\extmgr.dll - 2007-08-14 02:54 . 2010-03-11 12:38133120 c:\windows\system32\dllcache\extmgr.dll + 2007-08-14 02:35 . 2010-05-04 17:20214528 c:\windows\system32\dllcache\dxtrans.dll - 2007-08-14 02:35 . 2010-03-11 12:38214528 c:\windows\system32\dllcache\dxtrans.dll + 2007-08-14 02:35 . 2010-05-04 17:20347136 c:\windows\system32\dllcache\dxtmsft.dll - 2007-08-14 02:35 . 2010-03-11 12:38347136 c:\windows\system32\dllcache\dxtmsft.dll + 2010-04-20 05:30 . 2010-04-20 05:30285696 c:\windows\system32\dllcache\atmfd.dll + 2009-01-28 14:40 . 2008-04-13 16:39142592 c:\windows\system32\dllcache\aec.sys - 2007-08-14 02:39 . 2010-03-11 12:38124928 c:\windows\system32\dllcache\advpack.dll + 2007-08-14 02:39 . 2010-05-04 17:20124928 c:\windows\system32\dllcache\advpack.dll - 2004-08-04 12:00 . 2008-04-14 00:09285696 c:\windows\system32\atmfd.dll + 2004-08-04 12:00 . 2010-04-20 05:30285696 c:\windows\system32\atmfd.dll + 2004-08-04 12:00 . 2010-05-04 17:20124928 c:\windows\system32\advpack.dll - 2004-08-04 12:00 . 2010-03-11 12:38124928 c:\windows\system32\advpack.dll + 2010-03-31 04:16 . 2010-03-31 04:16130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll + 2010-04-08 03:48 . 2010-04-08 03:48970752 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll - 2008-07-30 03:16 . 2008-07-30 03:16110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll + 2010-04-08 03:48 . 2010-04-08 03:48110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll + 2010-03-23 09:31 . 2010-03-23 09:31435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll + 2010-02-09 16:22 . 2010-02-09 16:22258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll - 2008-07-25 19:17 . 2008-07-25 19:17258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll - 2008-05-28 04:49 . 2008-05-28 04:49102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll + 2010-03-31 18:51 . 2010-03-31 18:51102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll - 2008-05-28 04:48 . 2008-05-28 04:48315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll + 2010-03-31 18:49 . 2010-03-31 18:49315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll + 2010-03-31 19:32 . 2010-03-31 19:32258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll - 2008-05-28 05:30 . 2008-05-28 05:30258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll + 2010-06-10 12:22 . 2010-06-10 12:22200192 c:\windows\Installer\be07f0b.msi + 2010-02-25 04:14 . 2010-02-25 04:14543232 c:\windows\Installer\be07e85.msp + 2010-06-16 19:39 . 2010-06-16 19:39454144 c:\windows\Installer\a68871.msi + 2010-06-16 19:33 . 2010-06-16 19:33356352 c:\windows\Installer\a6884b.msi + 2010-06-16 19:32 . 2010-06-16 19:32315392 c:\windows\Installer\a68843.msi + 2010-06-16 19:32 . 2010-06-16 19:32316928 c:\windows\Installer\a6883b.msi + 2010-06-16 19:32 . 2010-06-16 19:32356864 c:\windows\Installer\a68833.msi + 2010-06-16 19:31 . 2010-06-16 19:31359424 c:\windows\Installer\a6882b.msi + 2010-06-16 19:31 . 2010-06-16 19:31356352Hi, Your log is cut off, could you please post the full log. Oh goodness...sorry! Here you go. ComboFix 10-07-21.02 - Toni 07/22/2010 2:11.4.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1181 [GMT -4:00] Running from: c:\documents and settings\Toni\desktop\commy.exe Command switches used :: /stepdel AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Toni\Application Data\Sky-Banners c:\documents and settings\Toni\Application Data\Street-Ads c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B} c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor c:\windows\$NtUninstallMTF1011$ c:\windows\TEMP\logishrd\LVPrcInj01.dll c:\documents and settings\Toni\Application Data\09f7619a.exe c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome.manifest c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\_cfg.js c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\overlay.xul c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\install.rdf c:\documents and settings\Toni\Start Menu\Antimalware Doctor.lnk c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk c:\windows\$NtUninstallMTF1011$\apUninstall.exe c:\windows\$NtUninstallMTF1011$\zrpt.xml c:\windows\system32\ernel32.dll . ((((((((((((((((((((((((( Files Created from 2010-06-22 to 2010-07-22 ))))))))))))))))))))))))))))))) . 2010-07-21 13:54 . 2010-07-21 14:49--------d-----w-C:\commy21098c 2010-07-21 11:25 . 2010-07-21 12:14--------d-----w-C:\commy 2010-07-21 11:18 . 2010-07-21 11:18--------d-----w-C:\_OTL 2010-07-20 10:57 . 2010-07-20 10:57--------d-----w-c:\program files\CCleaner 2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\program files\Uniblue 2010-07-18 16:03 . 2010-07-18 16:034057620----a-w-c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\registrybooster1-Wrapped.exe 2010-07-18 16:03 . 2010-07-18 16:06--------d-----w-c:\documents and settings\Toni\Local Settings\Application Data\OpenCandy 2010-07-18 16:03 . 2010-07-18 16:03331304----a-w-c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\DLMgr_3_1.6.44.exe 2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\documents and settings\Toni\Application Data\OpenCandy 2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\program files\Winamp Detect 2010-07-18 16:01 . 2010-07-18 16:51--------d-----w-c:\documents and settings\Toni\Application Data\Winamp 2010-07-18 16:01 . 2010-07-18 16:03--------d-----w-c:\program files\Winamp 2010-07-17 15:37 . 2010-07-21 16:00--------d-----w-c:\documents and settings\Toni\Local Settings\Application Data\AskToolbar 2010-07-15 16:36 . 2010-07-15 16:362944904----a-w-c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\extensions\[emailprotected]\chrome\temp\askToolbar.exe 2010-07-14 13:39 . 2010-07-14 13:39--------d-----w-c:\documents and settings\Toni\Application Data\Avery 2010-07-14 13:24 . 2010-07-14 13:24--------d-----w-c:\program files\Avery Dennison 2010-07-14 13:24 . 2010-07-14 13:24--------d-----w-c:\documents and settings\All Users\Application Data\Avery 2010-07-14 13:10 . 2010-07-17 14:02--------d-----w-c:\program files\Ask.com 2010-07-14 13:05 . 2010-07-14 13:0789582136----a-w-c:\program files\DesignPro5_5_Limited.exe 2010-07-14 09:10 . 2010-06-14 14:31744448-c----w-c:\windows\system32\dllcache\helpsvc.exe 2010-07-12 15:35 . 2010-07-12 15:352272----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2010-07-10 14:39 . 2010-07-10 14:39--------d-----w-c:\documents and settings\Administrator\Application Data\Malwarebytes . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-22 06:17 . 2009-02-17 19:400----a-w-c:\windows\system32\drivers\lvuvc.hs 2010-07-22 06:17 . 2009-02-17 19:380----a-w-c:\windows\system32\drivers\logiflt.iad 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k7 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k6 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k5 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k4 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k3 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k2 2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k1 2010-07-22 06:16 . 2009-01-28 19:20227220----a-w-c:\windows\system32\drivers\kmxcfg.u2k0 2010-07-22 05:55 . 2010-04-09 13:471324----a-w-c:\windows\system32\d3d9caps.dat 2010-07-20 19:53 . 2010-03-10 14:04--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-07-18 00:58 . 2009-08-13 23:13--------d-----w-c:\documents and settings\Toni\Application Data\Vso 2010-07-16 20:20 . 2010-03-22 17:58--------d-----w-c:\program files\uTorrent 2010-07-15 15:39 . 2009-01-30 16:19395984----a-w-c:\documents and settings\Toni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-07-14 13:33 . 2009-01-28 14:38--------d--h--w-c:\program files\InstallShield Installation Information 2010-07-10 23:55 . 2010-02-11 12:30--------d-----w-c:\documents and settings\All Users\Application Data\Roxio 2010-06-25 18:51 . 2009-02-04 05:06--------d-----w-c:\documents and settings\Toni\Application Data\ZoomBrowser EX 2010-06-25 18:50 . 2009-01-31 18:06--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser 2010-06-19 16:23 . 2009-02-03 02:26--------d-----w-c:\documents and settings\Toni\Application Data\AdobeUM 2010-06-17 15:46 . 2010-06-16 20:29--------d-----w-c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe 2010-06-16 20:25 . 2009-01-30 07:02--------d-----w-c:\program files\Common Files\Adobe 2010-06-16 19:40 . 2010-06-16 19:40--------d-----w-c:\program files\Adobe Media Player 2010-06-16 19:39 . 2010-06-16 19:3910134----a-r-c:\documents and settings\Toni\Application Data\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe 2010-06-16 19:39 . 2010-06-16 19:39--------d-----w-c:\program files\My Company Name 2010-06-16 19:34 . 2010-06-16 19:34--------d-----w-c:\program files\Common Files\Adobe AIR 2010-06-16 16:18 . 2009-02-26 02:14--------d-----w-c:\documents and settings\Toni\Application Data\Move Networks 2010-06-14 19:58 . 2010-06-14 19:58--------d-----w-c:\documents and settings\All Users\Application Data\vsosdk 2010-06-14 14:31 . 2009-01-28 13:06744448----a-w-c:\windows\pchealth\helpctr\binaries\helpsvc.exe 2010-06-13 18:14 . 2010-06-13 18:06--------d-----w-c:\program files\PeerGuardian2 2010-06-07 00:19 . 2010-05-04 17:20--------d-----w-c:\program files\Microsoft Silverlight 2010-06-03 16:35 . 2009-07-09 01:421561896----a-w-c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll 2010-06-03 16:35 . 2009-01-28 18:24746216----a-w-c:\windows\system32\drivers\vetefile.sys 2010-06-03 16:35 . 2009-01-28 18:24130280----a-w-c:\windows\system32\drivers\veteboot.sys 2010-05-28 18:57 . 2009-01-28 18:2491472----a-w-c:\windows\system32\isafprod.dll 2010-05-04 17:20 . 2004-08-04 12:00832512----a-w-c:\windows\system32\wininet.dll 2010-05-04 17:20 . 2004-08-04 12:0078336----a-w-c:\windows\system32\ieencode.dll 2010-05-04 17:20 . 2004-08-04 12:0017408----a-w-c:\windows\system32\corpol.dll 2010-05-02 05:22 . 2004-08-04 12:001851264----a-w-c:\windows\system32\win32k.sys 2010-04-29 19:39 . 2010-03-10 14:0438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-29 19:39 . 2010-03-10 14:0420952----a-w-c:\windows\system32\drivers\mbam.sys 2010-02-02 17:02 . 2010-02-02 17:021438976----a-w-c:\program files\MoveMediaPlayerWin_071505000011.exe 2010-02-01 01:43 . 2010-02-01 01:432107456----a-w-c:\program files\Install_Facebook_Plug-In_1.0.1.exe 2010-01-31 12:26 . 2010-01-31 12:261533702----a-w-c:\program files\gburner27.exe 2009-08-13 23:06 . 2009-08-13 23:057741336----a-w-c:\program files\DivX521XP2K_1.exe 2009-08-13 22:54 . 2009-08-13 22:534526458----a-w-c:\program files\WinAVI_Video_Converter.exe 2009-06-16 21:38 . 2009-06-16 21:382144584----a-w-c:\program files\InstallFirefoxPluginV3.exe 2009-06-12 22:34 . 2009-06-12 22:3024527365----a-w-c:\program files\FreeVideoConverter.exe 2009-03-05 21:24 . 2009-03-05 21:244909440----a-w-c:\program files\Silverlight.2.0.exe . ((((((((((((((((((((((((((((( [emailprotected]_11.57.58 ))))))))))))))))))))))))))))))))))))))))) . + 2009-06-26 23:10 . 2009-06-26 23:1059904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90u.dll + 2009-06-26 23:10 . 2009-06-26 23:1059904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90.dll + 2009-07-12 00:32 . 2009-07-12 00:3249152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll + 2009-07-12 00:32 . 2009-07-12 00:3249152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll + 2009-07-12 00:32 . 2009-07-12 00:3257344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll + 2009-07-12 00:32 . 2009-07-12 00:3265536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll + 2009-07-12 00:32 . 2009-07-12 00:3245056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll + 2009-07-12 00:32 . 2009-07-12 00:3240960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll + 2009-07-12 05:07 . 2009-07-12 05:0757856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll + 2009-07-12 05:19 . 2009-07-12 05:1969632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll + 2009-07-11 23:41 . 2009-07-11 23:4197280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll + 2010-07-22 06:17 . 2010-07-22 06:1716384 c:\windows\temp\Perflib_Perfdata_4e8.dat - 2008-04-14 00:12 . 2010-01-23 08:1146080 c:\windows\system32\tzchange.exe + 2008-04-14 00:12 . 2010-04-21 13:2846080 c:\windows\system32\tzchange.exe + 2006-03-25 00:00 . 2006-03-25 00:0045056 c:\windows\system32\spool\prtprocs\w32x86\iQ17cEI7q.dll + 2005-05-24 00:00 . 2005-05-24 00:0045056 c:\windows\system32\spool\prtprocs\w32x86\aAA17eI.dll + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\pxinsa64.exe - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\pxinsa64.exe + 2010-07-18 16:02 . 2009-04-28 20:2072176 c:\windows\system32\pxhpinst.exe + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\pxcpya64.exe - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\pxcpya64.exe + 2010-03-31 04:16 . 2010-03-31 04:1699176 c:\windows\system32\PresentationHostProxy.dll + 2004-08-04 12:00 . 2010-05-04 17:2044544 c:\windows\system32\pngfilt.dll - 2004-08-04 12:00 . 2010-03-11 12:3844544 c:\windows\system32\pngfilt.dll - 2004-08-04 12:00 . 2010-03-14 12:5378958 c:\windows\system32\perfc009.dat + 2004-08-04 12:00 . 2010-07-08 14:5278958 c:\windows\system32\perfc009.dat + 2009-11-07 05:07 . 2009-11-07 05:0749488 c:\windows\system32\netfxperf.dll + 2009-11-06 02:17 . 2009-11-06 02:1711600 c:\windows\system32\mui\0409\mscorees.dll - 2007-08-14 02:54 . 2010-03-11 12:3852224 c:\windows\system32\msfeedsbs.dll + 2007-08-14 02:54 . 2010-05-04 17:2052224 c:\windows\system32\msfeedsbs.dll + 2004-08-04 12:00 . 2010-05-04 17:2027648 c:\windows\system32\jsproxy.dll - 2004-08-04 12:00 . 2010-03-11 12:3827648 c:\windows\system32\jsproxy.dll + 2007-08-14 02:39 . 2010-05-04 12:3913824 c:\windows\system32\ieudinit.exe - 2007-08-14 02:39 . 2010-03-10 13:1813824 c:\windows\system32\ieudinit.exe - 2004-08-04 12:00 . 2010-03-11 12:3844544 c:\windows\system32\iernonce.dll + 2004-08-04 12:00 . 2010-05-04 17:2044544 c:\windows\system32\iernonce.dll - 2004-08-04 12:00 . 2010-03-10 13:1870656 c:\windows\system32\ie4uinit.exe + 2004-08-04 12:00 . 2010-05-04 12:3970656 c:\windows\system32\ie4uinit.exe - 2007-08-14 02:36 . 2010-03-11 12:3863488 c:\windows\system32\icardie.dll + 2007-08-14 02:36 . 2010-05-04 17:2063488 c:\windows\system32\icardie.dll - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\drvins64.exe + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\drvins64.exe + 2009-07-09 07:00 . 2009-07-09 07:0045200 c:\windows\system32\drivers\pxhelp20.sys - 2009-07-09 08:00 . 2009-07-09 08:0045200 c:\windows\system32\drivers\pxhelp20.sys + 2007-08-14 02:36 . 2010-05-04 17:2044544 c:\windows\system32\dllcache\pngfilt.dll - 2007-08-14 02:36 . 2010-03-11 12:3844544 c:\windows\system32\dllcache\pngfilt.dll + 2009-01-28 15:29 . 2010-05-04 17:2052224 c:\windows\system32\dllcache\msfeedsbs.dll - 2009-01-28 15:29 . 2010-03-11 12:3852224 c:\windows\system32\dllcache\msfeedsbs.dll + 2007-08-14 02:54 . 2010-05-04 17:2027648 c:\windows\system32\dllcache\jsproxy.dll - 2007-08-14 02:54 . 2010-03-11 12:3827648 c:\windows\system32\dllcache\jsproxy.dll - 2009-01-28 15:29 . 2010-03-10 13:1813824 c:\windows\system32\dllcache\ieudinit.exe + 2009-01-28 15:29 . 2010-05-04 12:3913824 c:\windows\system32\dllcache\ieudinit.exe - 2007-08-14 02:39 . 2010-03-11 12:3844544 c:\windows\system32\dllcache\iernonce.dll + 2007-08-14 02:39 . 2010-05-04 17:2044544 c:\windows\system32\dllcache\iernonce.dll + 2007-08-14 02:45 . 2010-05-04 17:2078336 c:\windows\system32\dllcache\ieencode.dll - 2007-08-14 02:45 . 2010-03-11 12:3878336 c:\windows\system32\dllcache\ieencode.dll + 2007-08-14 02:39 . 2010-05-04 12:3970656 c:\windows\system32\dllcache\ie4uinit.exe - 2007-08-14 02:39 . 2010-03-10 13:1870656 c:\windows\system32\dllcache\ie4uinit.exe + 2009-01-28 15:29 . 2010-05-04 17:2063488 c:\windows\system32\dllcache\icardie.dll - 2009-01-28 15:29 . 2010-03-11 12:3863488 c:\windows\system32\dllcache\icardie.dll + 2007-08-14 02:42 . 2010-05-04 17:2017408 c:\windows\system32\dllcache\corpol.dll - 2007-08-14 02:42 . 2010-03-11 12:3817408 c:\windows\system32\dllcache\corpol.dll + 2010-03-05 14:37 . 2010-03-05 14:3765536 c:\windows\system32\dllcache\asycfilt.dll - 2009-01-28 13:12 . 2009-03-24 23:1632768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2009-01-28 13:12 . 2010-07-10 19:4832768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2009-01-28 13:12 . 2009-03-24 23:1616384 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2010-05-07 15:17 . 2010-07-10 19:4816384 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2004-08-04 12:00 . 2010-03-05 14:3765536 c:\windows\system32\asycfilt.dll - 2008-07-30 03:16 . 2008-07-30 03:1632768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll + 2010-04-08 03:48 . 2010-04-08 03:4832768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll + 2010-03-23 09:31 . 2010-03-23 09:3130544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe + 2010-04-01 15:42 . 2010-04-01 15:4281920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll - 2008-05-28 04:49 . 2008-05-28 04:4977824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll + 2010-03-31 18:51 . 2010-03-31 18:5177824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll - 2008-05-28 04:49 . 2008-05-28 04:4986016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll + 2010-03-31 18:51 . 2010-03-31 18:5186016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll + 2010-03-31 18:51 . 2010-03-31 18:5181920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll - 2008-05-28 04:49 . 2008-05-28 04:4981920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll + 2010-03-31 19:32 . 2010-03-31 19:3232768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe - 2008-05-28 05:30 . 2008-05-28 05:3032768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe - 2003-02-21 03:19 . 2003-02-21 03:1924576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll + 2010-03-31 19:32 . 2010-03-31 19:3224576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll + 2009-11-07 05:07 . 2009-11-07 05:0713688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll + 2009-11-07 05:07 . 2009-11-07 05:0713696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll + 2009-11-07 05:07 . 2009-11-07 05:0713672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll + 2009-11-07 05:07 . 2009-11-07 05:0786864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe + 2010-06-16 19:40 . 2010-06-16 19:4022016 c:\windows\Installer\a68879.msi + 2010-06-16 19:34 . 2010-06-16 19:3422528 c:\windows\Installer\a6885b.msi + 2010-06-16 19:34 . 2010-06-16 19:3427648 c:\windows\Installer\a68853.msi + 2010-05-04 17:20 . 2010-05-04 17:2049664 c:\windows\Installer\35251f9.msi + 2010-06-15 00:32 . 2010-06-15 00:3221504 c:\windows\Installer\1712a6bf.msi + 2010-07-14 13:26 . 2010-07-14 13:2640960 c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\ARPPRODUCTICON.exe + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}\ARPPRODUCTICON.exe + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{D1A19B02-817E-4296-A45B-07853FD74D57}\ARPPRODUCTICON.exe + 2010-06-16 20:25 . 2010-06-16 20:2581920 c:\windows\Installer\{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}\ARPPRODUCTICON.exe + 2010-05-08 16:34 . 2010-05-08 16:3425214 c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe + 2010-05-08 16:34 . 2010-05-08 16:3425214 c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\ARPPRODUCTICON.exe + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\ARPPRODUCTICON.exe - 2009-01-28 18:22 . 2010-04-14 03:4723040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe + 2009-01-28 18:22 . 2010-07-15 11:0423040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2009-01-28 18:22 . 2010-04-14 03:4761440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe + 2009-01-28 18:22 . 2010-07-15 11:0461440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe - 2009-01-28 18:22 . 2010-04-14 03:4727136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2009-01-28 18:22 . 2010-07-15 11:0427136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe - 2009-01-28 18:22 . 2010-04-14 03:4711264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2009-01-28 18:22 . 2010-07-15 11:0411264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe - 2009-01-28 18:22 . 2010-04-14 03:4712288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2009-01-28 18:22 . 2010-07-15 11:0412288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2010-06-10 12:21 . 2010-06-10 12:2138240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe - 2010-04-14 03:51 . 2010-04-14 03:5138240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe + 2010-05-04 17:26 . 2010-06-04 07:0149152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll + 2010-06-16 19:43 . 2010-06-16 19:4381920 c:\windows\Installer\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}\ARPPRODUCTICON.exe + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}\ARPPRODUCTICON.exe + 2010-06-16 19:33 . 2010-06-16 19:3310134 c:\windows\Installer\{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}\ARPPRODUCTICON.exe + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{08D2E121-7F6A-43EB-97FD-629B44903403}\ARPPRODUCTICON.exe + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}\ARPPRODUCTICON.exe + 2010-06-10 11:51 . 2010-03-11 12:3844544 c:\windows\ie7updates\KB982381-IE7\pngfilt.dll + 2010-06-10 11:51 . 2010-03-11 12:3852224 c:\windows\ie7updates\KB982381-IE7\msfeedsbs.dll + 2010-06-10 11:52 . 2010-03-11 12:3827648 c:\windows\ie7updates\KB982381-IE7\jsproxy.dll + 2010-06-10 11:52 . 2010-03-10 13:1813824 c:\windows\ie7updates\KB982381-IE7\ieudinit.exe + 2010-06-10 11:52 . 2010-03-11 12:3844544 c:\windows\ie7updates\KB982381-IE7\iernonce.dll + 2010-06-10 11:52 . 2010-03-11 12:3878336 c:\windows\ie7updates\KB982381-IE7\ieencode.dll + 2010-06-10 11:52 . 2010-03-10 13:1870656 c:\windows\ie7updates\KB982381-IE7\ie4uinit.exe + 2010-06-10 11:52 . 2010-03-11 12:3863488 c:\windows\ie7updates\KB982381-IE7\icardie.dll + 2010-06-10 11:52 . 2010-03-11 12:3817408 c:\windows\ie7updates\KB982381-IE7\corpol.dll + 2010-06-10 12:23 . 2010-06-10 12:2390112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ee3c85bd\System.Drawing.Design.dll + 2010-06-10 12:23 . 2010-06-10 12:2361440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b31c6c1f\CustomMarshalers.dll + 2010-06-10 12:27 . 2010-06-10 12:2747616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\11b5c5344eb40eeb36a818d2824fe3a1\WindowsLiveWriter.ni.exe + 2010-06-10 12:29 . 2010-06-10 12:2999840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c69cc7d4e4fca9aa892ddfacc64cddb2\WindowsLive.Writer.Api.ni.dll + 2010-06-24 07:11 . 2010-06-24 07:1160928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ea1b4fbde0e772748c6ac42d627cf684\UIAutomationProvider.ni.dll + 2010-06-24 07:13 . 2010-06-24 07:1337888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f46915dfc57bc7e49c5402e9b8f7ec18\System.Windows.Presentation.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:3137888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\1c1629f536fa9874ef08d09fb19ab0f0\System.Windows.Presentation.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:3136864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\1464c662c302ea6372a885161b983732\System.Web.DynamicData.Design.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:3094208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\5d535ecadf77ac2d9278a1661beb2855\System.ComponentModel.DataAnnotations.ni.dll + 2010-06-10 12:12 . 2010-06-10 12:1247104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e67992626a30603458b0df22841c2423\PresentationFontCache.ni.exe + 2010-06-24 07:09 . 2010-06-24 07:0947104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\18729514178d458aa1225dd068718d4e\PresentationFontCache.ni.exe + 2010-06-10 12:10 . 2010-06-10 12:1039424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\6be27d744e6e2bfc4b0e25bd2998ef7c\PresentationCFFRasterizer.ni.dll + 2010-06-24 07:08 . 2010-06-24 07:0839424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0375dfa28e2f6ef7e89df9edede4b83d\PresentationCFFRasterizer.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:3155296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\4a52287444c36c89310856b38ff52fe0\Microsoft.Vsa.ni.dll + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll - 2009-10-17 07:13 . 2009-10-17 07:1377824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll + 2010-06-10 12:10 . 2010-06-10 12:1032768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll - 2009-01-28 15:35 . 2009-01-28 15:3532768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll - 2009-10-17 07:13 . 2009-10-17 07:1381920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2010-06-24 07:04 . 2010-06-24 07:0481920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2010-06-24 07:04 . 2010-06-24 07:0481920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll - 2009-10-17 07:14 . 2009-10-17 07:1481920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll - 2009-10-17 07:13 . 2009-10-17 07:1332768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll + 2010-06-24 07:04 . 2010-06-24 07:0432768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2009-10-17 07:13 . 2009-10-17 07:1312800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2010-06-24 07:04 . 2010-06-24 07:0412800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2010-06-24 07:04 . 2010-06-24 07:0428672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll - 2009-10-17 07:13 . 2009-10-17 07:1328672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll - 2009-10-17 07:14 . 2009-10-17 07:1477824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll + 2010-06-24 07:04 . 2010-06-24 07:0436864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll - 2009-10-17 07:13 . 2009-10-17 07:1336864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll - 2009-10-17 07:13 . 2009-10-17 07:1377824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2009-10-17 07:13 . 2009-10-17 07:1313312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll + 2010-06-24 07:04 . 2010-06-24 07:0413312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll - 2009-10-17 07:13 . 2009-10-17 07:1310752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2010-06-24 07:04 . 2010-06-24 07:0410752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2010-06-24 07:04 . 2010-06-24 07:0472192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2009-10-17 07:13 . 2009-10-17 07:1372192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2009-10-17 07:13 . 2009-10-17 07:1369120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2010-06-24 07:04 . 2010-06-24 07:0469120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2010-06-10 12:23 . 2010-06-10 12:2381920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll + 2010-05-26 07:00 . 2010-01-23 08:1146080 c:\windows\$NtUninstallKB981793$\tzchange.exe + 2010-05-26 07:00 . 2010-04-22 22:2116896 c:\windows\$NtUninstallKB981793$\spuninst\tzchange.dll + 2010-06-10 12:12 . 2008-04-14 00:1165024 c:\windows\$NtUninstallKB979482$\asycfilt.dll + 2010-06-10 11:52 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB982381-IE7\update\spcustom.dll + 2010-06-10 11:52 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB982381-IE7\spmsg.dll + 2010-05-04 17:20 . 2010-05-04 17:2044544 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\pngfilt.dll + 2010-05-04 17:20 . 2010-05-04 17:2052224 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeedsbs.dll + 2010-05-04 17:20 . 2010-05-04 17:2027648 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\jsproxy.dll + 2010-05-04 13:19 . 2010-05-04 13:1913824 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieudinit.exe + 2010-05-04 17:20 . 2010-05-04 17:2044544 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iernonce.dll + 2010-05-04 17:20 . 2010-05-04 17:2078336 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieencode.dll + 2010-05-04 13:19 . 2010-05-04 13:1970656 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ie4uinit.exe + 2010-05-04 17:20 . 2010-05-04 17:2063488 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\icardie.dll + 2010-05-04 17:19 . 2010-05-04 17:1917408 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\corpol.dll + 2010-06-10 12:28 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB980218\update\spcustom.dll + 2010-06-10 12:28 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB980218\spmsg.dll + 2010-06-10 12:23 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB980195\update\spcustom.dll + 2010-06-10 12:23 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB980195\spmsg.dll + 2010-06-10 12:19 . 2009-05-26 09:0126488 c:\windows\$hf_mig$\KB979559\update\spcustom.dll + 2010-06-10 12:19 . 2009-05-26 09:0117272 c:\windows\$hf_mig$\KB979559\spmsg.dll + 2010-06-10 12:12 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB979482\update\spcustom.dll + 2010-06-10 12:12 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB979482\spmsg.dll + 2010-03-05 14:52 . 2010-03-05 14:5265536 c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll + 2010-05-13 07:01 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB978542\update\spcustom.dll + 2010-05-13 07:01 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB978542\spmsg.dll + 2010-06-10 12:12 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB975562\update\spcustom.dll + 2010-06-10 12:12 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB975562\spmsg.dll - 2009-10-17 07:13 . 2009-10-17 07:138192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll + 2010-06-24 07:04 . 2010-06-24 07:048192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll - 2009-06-23 08:00 . 2009-06-23 08:009200 c:\windows\system32\drivers\cdralw2k.sys + 2009-06-23 07:00 . 2009-06-23 07:009200 c:\windows\system32\drivers\cdralw2k.sys - 2009-06-23 08:00 . 2009-06-23 08:009072 c:\windows\system32\drivers\cdr4_xp.sys + 2009-06-23 07:00 . 2009-06-23 07:009072 c:\windows\system32\drivers\cdr4_xp.sys + 2010-07-14 13:26 . 2010-07-14 13:262238 c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\Shortcut1_71F6DF7DB6394FADBA93E6DF267AA44D.exe + 2009-01-28 18:22 . 2010-07-15 11:044096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe - 2009-01-28 18:22 . 2010-04-14 03:474096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2010-06-24 07:04 . 2010-06-24 07:047168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll - 2009-10-17 07:13 . 2009-10-17 07:137168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2010-06-24 07:04 . 2010-06-24 07:045632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2009-10-17 07:14 . 2009-10-17 07:145632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll + 2010-06-24 07:04 . 2010-06-24 07:046656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll - 2009-10-17 07:13 . 2009-10-17 07:136656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2010-06-24 07:04 . 2010-06-24 07:048192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2009-10-17 07:13 . 2009-10-17 07:138192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2009-10-17 07:13 . 2009-10-17 07:13113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll + 2010-06-24 07:04 . 2010-06-24 07:04113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2009-06-26 23:07 . 2009-06-26 23:07653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcr90.dll + 2009-06-26 23:07 . 2009-06-26 23:07569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcp90.dll + 2009-06-26 23:10 . 2009-06-26 23:10225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcm90.dll + 2009-06-26 23:07 . 2009-06-26 23:07159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_35349982\atl90.dll + 2009-07-12 05:12 . 2009-07-12 05:12632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll + 2009-07-12 05:09 . 2009-07-12 05:09554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll + 2009-07-12 05:08 . 2009-07-12 05:08479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll + 2004-08-04 12:00 . 2010-05-04 17:20233472 c:\windows\system32\webcheck.dll - 2004-08-04 12:00 . 2010-03-11 12:38233472 c:\windows\system32\webcheck.dll + 2004-08-04 12:00 . 2010-05-04 17:20105984 c:\windows\system32\url.dll - 2004-08-04 12:00 . 2010-03-11 12:38105984 c:\windows\system32\url.dll + 2009-07-10 02:03 . 2009-07-10 02:03125424 c:\windows\system32\pxinsi64.exe - 2009-07-10 03:03 . 2009-07-10 03:03125424 c:\windows\system32\pxinsi64.exe - 2009-07-10 03:03 . 2009-07-10 03:03123888 c:\windows\system32\pxcpyi64.exe + 2009-07-10 02:03 . 2009-07-10 02:03123888 c:\windows\system32\pxcpyi64.exe + 2010-03-31 04:10 . 2010-03-31 04:10295264 c:\windows\system32\PresentationHost.exe - 2004-08-04 12:00 . 2010-03-14 12:53465072 c:\windows\system32\perfh009.dat + 2004-08-04 12:00 . 2010-07-08 14:52465072 c:\windows\system32\perfh009.dat + 2004-08-04 12:00 . 2010-05-04 17:20102912 c:\windows\system32\occache.dll - 2004-08-04 12:00 . 2010-03-11 12:38102912 c:\windows\system32\occache.dll + 2004-08-04 12:00 . 2010-05-04 17:20671232 c:\windows\system32\mstime.dll - 2004-08-04 12:00 . 2010-03-11 12:38671232 c:\windows\system32\mstime.dll - 2004-08-04 12:00 . 2010-03-11 12:38193024 c:\windows\system32\msrating.dll + 2004-08-04 12:00 . 2010-05-04 17:20193024 c:\windows\system32\msrating.dll - 2004-08-04 12:00 . 2010-03-11 12:38477696 c:\windows\system32\mshtmled.dll + 2004-08-04 12:00 . 2010-05-04 17:20477696 c:\windows\system32\mshtmled.dll - 2007-08-14 02:54 . 2010-03-11 12:38459264 c:\windows\system32\msfeeds.dll + 2007-08-14 02:54 . 2010-05-04 17:20459264 c:\windows\system32\msfeeds.dll + 2009-11-07 05:07 . 2009-11-07 05:07297808 c:\windows\system32\mscoree.dll + 2010-06-16 20:25 . 2010-06-16 20:25223184 c:\windows\system32\Macromed\Flash\FlashUtil10g_Plugin.exe + 2010-06-16 19:43 . 2010-06-16 19:43223184 c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.exe + 2010-06-16 19:43 . 2010-06-16 19:43268240 c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.dll + 2009-01-28 13:06 . 2010-01-29 15:01691712 c:\windows\system32\inetcomm.dll - 2009-01-28 13:06 . 2008-04-11 19:04691712 c:\windows\system32\inetcomm.dll - 2007-08-14 02:34 . 2010-03-11 12:38268288 c:\windows\system32\iertutil.dll + 2007-08-14 02:34 . 2010-05-04 17:20268288 c:\windows\system32\iertutil.dll + 2004-08-04 12:00 . 2010-05-04 17:20192512 c:\windows\system32\iepeers.dll - 2004-08-04 12:00 . 2010-03-11 12:38192512 c:\windows\system32\iepeers.dll - 2004-08-04 12:00 . 2010-03-11 12:38385024 c:\windows\system32\iedkcs32.dll + 2004-08-04 12:00 . 2010-05-04 17:20385024 c:\windows\system32\iedkcs32.dll - 2007-07-11 20:27 . 2010-03-11 12:38380928 c:\windows\system32\ieapfltr.dll + 2007-07-11 20:27 . 2010-05-04 17:20380928 c:\windows\system32\ieapfltr.dll + 2004-08-04 12:00 . 2010-04-16 11:43161792 c:\windows\system32\ieakui.dll - 2004-08-04 12:00 . 2010-02-23 05:18161792 c:\windows\system32\ieakui.dll + 2004-08-04 12:00 . 2010-05-04 17:20230400 c:\windows\system32\ieaksie.dll - 2004-08-04 12:00 . 2010-03-11 12:38230400 c:\windows\system32\ieaksie.dll + 2004-08-04 12:00 . 2010-05-04 17:20153088 c:\windows\system32\ieakeng.dll - 2004-08-04 12:00 . 2010-03-11 12:38153088 c:\windows\system32\ieakeng.dll - 2004-08-04 12:00 . 2010-03-11 12:38133120 c:\windows\system32\extmgr.dll + 2004-08-04 12:00 . 2010-05-04 17:20133120 c:\windows\system32\extmgr.dll - 2004-08-04 12:00 . 2010-03-11 12:38214528 c:\windows\system32\dxtrans.dll + 2004-08-04 12:00 . 2010-05-04 17:20214528 c:\windows\system32\dxtrans.dll - 2004-08-04 12:00 . 2010-03-11 12:38347136 c:\windows\system32\dxtmsft.dll + 2004-08-04 12:00 . 2010-05-04 17:20347136 c:\windows\system32\dxtmsft.dll + 2007-08-14 02:54 . 2010-05-04 17:20832512 c:\windows\system32\dllcache\wininet.dll - 2007-08-14 02:54 . 2010-03-11 12:38832512 c:\windows\system32\dllcache\wininet.dll + 2007-08-14 02:54 . 2010-05-04 17:20233472 c:\windows\system32\dllcache\webcheck.dll - 2007-08-14 02:54 . 2010-03-11 12:38233472 c:\windows\system32\dllcache\webcheck.dll - 2007-08-14 02:44 . 2010-03-11 12:38105984 c:\windows\system32\dllcache\url.dll + 2007-08-14 02:44 . 2010-05-04 17:20105984 c:\windows\system32\dllcache\url.dll + 2007-08-14 02:44 . 2010-05-04 17:20102912 c:\windows\system32\dllcache\occache.dll - 2007-08-14 02:44 . 2010-03-11 12:38102912 c:\windows\system32\dllcache\occache.dll - 2007-08-14 02:54 . 2010-03-11 12:38671232 c:\windows\system32\dllcache\mstime.dll + 2007-08-14 02:54 . 2010-05-04 17:20671232 c:\windows\system32\dllcache\mstime.dll - 2007-08-14 02:44 . 2010-03-11 12:38193024 c:\windows\system32\dllcache\msrating.dll + 2007-08-14 02:44 . 2010-05-04 17:20193024 c:\windows\system32\dllcache\msrating.dll + 2007-08-14 02:54 . 2010-05-04 17:20477696 c:\windows\system32\dllcache\mshtmled.dll - 2007-08-14 02:54 . 2010-03-11 12:38477696 c:\windows\system32\dllcache\mshtmled.dll + 2009-01-28 15:29 . 2010-05-04 17:20459264 c:\windows\system32\dllcache\msfeeds.dll - 2009-01-28 15:29 . 2010-03-11 12:38459264 c:\windows\system32\dllcache\msfeeds.dll + 2009-01-28 14:49 . 2010-01-29 15:01691712 c:\windows\system32\dllcache\inetcomm.dll - 2009-01-28 14:49 . 2008-04-11 19:04691712 c:\windows\system32\dllcache\inetcomm.dll + 2007-08-14 02:43 . 2010-04-16 11:43634656 c:\windows\system32\dllcache\iexplore.exe + 2009-01-28 15:29 . 2010-05-04 17:20268288 c:\windows\system32\dllcache\iertutil.dll - 2009-01-28 15:29 . 2010-03-11 12:38268288 c:\windows\system32\dllcache\iertutil.dll - 2007-08-14 02:54 . 2010-03-11 12:38192512 c:\windows\system32\dllcache\iepeers.dll + 2007-08-14 02:54 . 2010-05-04 17:20192512 c:\windows\system32\dllcache\iepeers.dll - 2007-08-14 02:39 . 2010-03-11 12:38385024 c:\windows\system32\dllcache\iedkcs32.dll + 2007-08-14 02:39 . 2010-05-04 17:20385024 c:\windows\system32\dllcache\iedkcs32.dll - 2009-01-28 15:29 . 2010-03-11 12:38380928 c:\windows\system32\dllcache\ieapfltr.dll + 2009-01-28 15:29 . 2010-05-04 17:20380928 c:\windows\system32\dllcache\ieapfltr.dll + 2004-08-04 12:00 . 2010-04-16 11:43161792 c:\windows\system32\dllcache\ieakui.dll - 2004-08-04 12:00 . 2010-02-23 05:18161792 c:\windows\system32\dllcache\ieakui.dll + 2007-08-14 02:39 . 2010-05-04 17:20230400 c:\windows\system32\dllcache\ieaksie.dll - 2007-08-14 02:39 . 2010-03-11 12:38230400 c:\windows\system32\dllcache\ieaksie.dll - 2007-08-14 02:39 . 2010-03-11 12:38153088 c:\windows\system32\dllcache\ieakeng.dll + 2007-08-14 02:39 . 2010-05-04 17:20153088 c:\windows\system32\dllcache\ieakeng.dll + 2007-08-14 02:54 . 2010-05-04 17:20133120 c:\windows\system32\dllcache\extmgr.dll - 2007-08-14 02:54 . 2010-03-11 12:38133120 c:\windows\system32\dllcache\extmgr.dll + 2007-08-14 02:35 . 2010-05-04 17:20214528 c:\windows\system32\dllcache\dxtrans.dll - 2007-08-14 02:35 . 2010-03-11 12:38214528 c:\windows\system32\dllcache\dxtrans.dll + 2007-08-14 02:35 . 2010-05-04 17:20347136 c:\windows\system32\dllcache\dxtmsft.dll - 2007-08-14 02:35 . 2010-03-11 12:38347136 c:\windows\system32\dllcache\dxtmsft.dll + 2010-04-20 05:30 . 2010-04-20 05:30285696 c:\windows\system32\dllcache\atmfd.dll + 2009-01-28 14:40 . 2008-04-13 16:39142592 c:\windows\system32\dllcache\aec.sys - 2007-08-14 02:39 . 2010-03-11 12:38124928 c:\windows\system32\dllcache\advpack.dll + 2007-08-14 02:39 . 2010-05-04 17:20124928 c:\windows\system32\dllcache\advpack.dll - 2004-08-04 12:00 . 2008-04-14 00:09285696 c:\windows\system32\atmfd.dll + 2004-08-04 12:00 . 2010-04-20 05:30285696 c:\windows\system32\atmfd.dll + 2004-08-04 12:00 . 2010-05-04 17:20124928 c:\windows\system32\advpack.dll - 2004-08-04 12:00 . 2010-03-11 12:38124928 c:\windows\system32\advpack.dll + 2010-03-31 04:16 . 2010-03-31 04:16130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll + 2010-04-08 03:48 . 2010-04-08 03:48970752 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll - 2008-07-30 03:16 . 2008-07-30 03:16110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll + 2010-04-08 03:48 . 2010-04-08 03:48110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll + 2010-03-23 09:31 . 2010-03-23 09:31435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll + 2010-02-09 16:22 . 2010-02-09 16:22258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll - 2008-07-25 19:17 . 2008-07-25 19:17258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll - 2008-05-28 04:49 . 2008-05-28 04:49102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll + 2010-03-31 18:51 . 2010-03-31 18:51102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll - 2008-05-28 04:48 . 2008-05-28 04:48315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll + 2010-03-31 18:49 . 2010-03-31 18:49315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll + 2010-03-31 19:32 . 2010-03-31 19:32258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll - 2008-05-28 05:30 . 2008-05-28 05:30258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll + 2010-06-10 12:22 . 2010-06-10 12:22200192 c:\windows\Installer\be07f0b.msi + 2010-02-25 04:14 . 2010-02-25 04:14543232 c:\windows\Installer\be07e85.msp + 2010-06-16 19:39 . 2010-06-16 19:39454144 c:\windows\Installer\a68871.msi + 2010-06-16 19:33 . 2010-06-16 19:33356352 c:\windows\Installer\a6884b.msi + 2010-06-16 19:32 . 2010-06-16 19:32315392 c:\windows\Installer\a68843.msi + 2010-06-16 19:32 . 2010-06-16 19:32316928 c:\windows\Installer\a6883b.msi + 2010-06-16 19:32 . 2010-06-16 19:32356864 c:\windows\Installer\a68833.msi + 2010-06-16 19:31 . 2010-06-16 19:31359424 c:\windows\Installer\a6882b.msi + 2010-06-16 19:31 . 2010-06-16 19:31356352 &nbsI guess it is too long. I will copy in multiple posts. + 2010-06-16 19:31 . 2010-06-16 19:31356352 c:\windows\Installer\a68823.msi + 2010-06-16 19:31 . 2010-06-16 19:31316416 c:\windows\Installer\a6881b.msi + 2010-06-11 23:07 . 2010-06-11 23:07168960 c:\windows\Installer\843fc78.msp + 2010-05-08 16:34 . 2010-05-08 16:34881664 c:\windows\Installer\28fe89.msi + 2009-01-28 18:22 . 2010-07-15 11:04409600 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe - 2009-01-28 18:22 . 2010-04-14 03:47409600 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe - 2009-01-28 18:22 . 2010-04-14 03:47286720 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe + 2009-01-28 18:22 . 2010-07-15 11:04286720 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe + 2009-01-28 18:22 . 2010-07-15 11:04249856 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe - 2009-01-28 18:22 . 2010-04-14 03:47249856 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe - 2009-01-28 18:22 . 2010-04-14 03:47794624 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe + 2009-01-28 18:22 . 2010-07-15 11:04794624 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe + 2009-01-28 18:22 . 2010-07-15 11:04135168 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe - 2009-01-28 18:22 . 2010-04-14 03:47135168 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe + 2010-07-14 13:10 . 2010-07-17 14:01102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe + 2010-06-10 11:51 . 2010-03-11 12:38832512 c:\windows\ie7updates\KB982381-IE7\wininet.dll + 2010-06-10 11:51 . 2010-03-11 12:38233472 c:\windows\ie7updates\KB982381-IE7\webcheck.dll + 2010-06-10 11:51 . 2010-03-11 12:38105984 c:\windows\ie7updates\KB982381-IE7\url.dll + 2010-06-10 11:52 . 2009-05-26 11:40382840 c:\windows\ie7updates\KB982381-IE7\spuninst\updspapi.dll + 2010-06-10 11:52 . 2008-07-08 13:02231288 c:\windows\ie7updates\KB982381-IE7\spuninst\spuninst.exe + 2010-06-10 11:51 . 2010-03-11 12:38102912 c:\windows\ie7updates\KB982381-IE7\occache.dll + 2010-06-10 11:51 . 2010-03-11 12:38671232 c:\windows\ie7updates\KB982381-IE7\mstime.dll + 2010-06-10 11:51 . 2010-03-11 12:38193024 c:\windows\ie7updates\KB982381-IE7\msrating.dll + 2010-06-10 11:51 . 2010-03-11 12:38477696 c:\windows\ie7updates\KB982381-IE7\mshtmled.dll + 2010-06-10 11:51 . 2010-03-11 12:38459264 c:\windows\ie7updates\KB982381-IE7\msfeeds.dll + 2010-06-10 11:52 . 2010-02-23 05:20634648 c:\windows\ie7updates\KB982381-IE7\iexplore.exe + 2010-06-10 11:52 . 2010-03-11 12:38268288 c:\windows\ie7updates\KB982381-IE7\iertutil.dll + 2010-06-10 11:52 . 2010-03-11 12:38192512 c:\windows\ie7updates\KB982381-IE7\iepeers.dll + 2010-06-10 11:52 . 2010-03-11 12:38385024 c:\windows\ie7updates\KB982381-IE7\iedkcs32.dll + 2010-06-10 11:52 . 2010-03-11 12:38380928 c:\windows\ie7updates\KB982381-IE7\ieapfltr.dll + 2010-06-10 11:52 . 2010-02-23 05:18161792 c:\windows\ie7updates\KB982381-IE7\ieakui.dll + 2010-06-10 11:52 . 2010-03-11 12:38230400 c:\windows\ie7updates\KB982381-IE7\ieaksie.dll + 2010-06-10 11:52 . 2010-03-11 12:38153088 c:\windows\ie7updates\KB982381-IE7\ieakeng.dll + 2010-06-10 11:52 . 2010-03-11 12:38133120 c:\windows\ie7updates\KB982381-IE7\extmgr.dll + 2010-06-10 11:52 . 2010-03-11 12:38214528 c:\windows\ie7updates\KB982381-IE7\dxtrans.dll + 2010-06-10 11:52 . 2010-03-11 12:38347136 c:\windows\ie7updates\KB982381-IE7\dxtmsft.dll + 2010-06-10 11:52 . 2010-03-11 12:38124928 c:\windows\ie7updates\KB982381-IE7\advpack.dll + 2010-06-10 12:24 . 2010-06-10 12:24835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_00504892\System.Drawing.dll + 2010-06-10 12:24 . 2010-06-10 12:24192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_01398cc1\System.Drawing.Design.dll + 2010-06-10 12:24 . 2010-06-10 12:24118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_7930f4fc\CustomMarshalers.dll + 2010-06-10 12:26 . 2010-06-10 12:26321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\4d07b1ccecca66f320c1a0971dd614d1\WsatConfig.ni.exe + 2010-06-10 12:29 . 2010-06-10 12:29633856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\31a06c9eb6c083d9b8710ac6ce1be937\WindowsLiveLocal.WriterPlugin.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:28319488 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f0530ae077336e0eca143d4b32e8d34e\WindowsLive.Writer.Interop.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29258048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e50904b2c1e6e1ac5a4c7df032c2123c\WindowsLive.Writer.Mshtml.ni.dll + 2010-06-10 12:27 . 2010-06-10 12:27843776 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c6f20d937db1a69d005f791db60ee326\WindowsLive.Writer.Controls.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29118784 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c35124ff18874635fa84856596f154cc\WindowsLive.Writer.Extensibility.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:28152064 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c1992981a0cafba5e0d3753b8ec39b21\WindowsLive.Writer.HtmlParser.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29594944 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bea5a870bbb250130356c5dd8c2f3ca9\WindowsLive.Writer.HtmlEditor.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29428032 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b07e085adf681435595a729c5f8ca528\WindowsLive.Writer.Localization.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a148f5e5315f10bd4dfb626fdcf001c2\WindowsLive.Writer.FileDestinations.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29851968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\53a0614cafe16513d774a5d7b0473a73\WindowsLive.Writer.BlogClient.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29117760 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4190016a1225c8f33b8ebd96addb2a8e\WindowsLive.Writer.Instrumentation.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29322048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\27e34aec3681f62ec3791cdfe9ac0230\WindowsLive.Writer.SpellChecker.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29108544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\18dce358e91aedbd9656a6a0d0da582a\WindowsLive.Writer.Passport.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:28174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\06657a351a8cafd8101bbd06c31c6194\WindowsLive.Writer.BrowserControl.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29145920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\3aca1d7df14c17850246ef5ebca827c5\WindowsLive.Client.ni.dll + 2010-06-24 07:11 . 2010-06-24 07:11240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\b3a9fac9aea3ad913781fafbdcbb0cae\WindowsFormsIntegration.ni.dll + 2010-06-10 12:20 . 2010-06-10 12:20240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a7c702f75d47bf841b9587e582c2d0b2\WindowsFormsIntegration.ni.dll + 2010-06-24 07:11 . 2010-06-24 07:11447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\4131a3627fec69291dbaed236f30dc65\UIAutomationClient.ni.dll + 2010-06-10 12:20 . 2010-06-10 12:20447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\3a78043c85333d5af49a0d958912ae4a\UIAutomationClient.ni.dll + 2010-06-10 12:32 . 2010-06-10 12:32400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\747e84d81d1de2041661f0f71b04734a\System.Xml.Linq.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\d51dfbd8d5431eb89181baaa24863e15\System.Web.Routing.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\436dde9611932489da3dc8a1be170843\System.Web.RegularExpressions.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\e8ef769b3e899e62b26daadee50b97ed\System.Web.Extensions.Design.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\ce3b446b7bee5c47949c994ec89b1649\System.Web.Entity.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\ad04fe1182e55e7c01066b62a4bee6b5\System.Web.Entity.Design.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\20ba0d4d182a1a9c1f54c00d3bc29a68\System.Web.DynamicData.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\c97ecf9250c2f0794262534f27f98b72\System.Web.Abstractions.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:28627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9c56656c88979cf18de6cbcb6587ba8f\System.Transactions.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:28679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\42b2ffb594dbd5652a576a0dce28722c\System.Security.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:28311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\3231473e2ec4451c8f218930fda80d19\System.Runtime.Serialization.Formatters.Soap.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\2077ce69bd24a095dd54683ae26454d4\System.Runtime.Remoting.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\f90965b9d9a6a6604c9a66f57c37c026\System.Net.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\e6bd59fec415e273c173170c6508180a\System.Management.Instrumentation.ni.dll + 2010-06-10 12:25 . 2010-06-10 12:25381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\e3eb86170cba4c80e6e22ca33c63c218\System.IO.Log.ni.dll + 2010-06-10 12:27 . 2010-06-10 12:27212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\cfa48936affc9a5fb89f0bf66cc52a47\System.IdentityModel.Selectors.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:28280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\e9edc5cd12ebb513b4a3c53cb4640771\System.EnterpriseServices.Wrapper.dll + 2010-06-10 12:28 . 2010-06-10 12:28627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\e9edc5cd12ebb513b4a3c53cb4640771\System.EnterpriseServices.ni.dll + 2010-06-10 12:19 . 2010-06-10 12:19208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\aeba6820f20655dec7fe0fe05aaeb818\System.Drawing.Design.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\9ef70079beca3a9982a3aa76ebc0ddd8\System.DirectoryServices.Protocols.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\277619716d9136216065bea970365c65\System.DirectoryServices.AccountManagement.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\90b67e13866b176ae6cbdb23144f724d\System.Data.Services.Client.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\131a477d41a8669b15696128b94c2636\System.Data.Services.Design.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:31756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\d4990681ce373d81a52b231ee4c4afea\System.Data.Entity.Design.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:30135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\9e9d66a3a0e16fceead505c25af569eb\System.Data.DataSetExtensions.ni.dll + 2010-06-10 12:27 . 2010-06-10 12:27971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\39e4f9a276fb12125d8a1444d8b65a84\System.Configuration.Install.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:30633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\849916c5cb3ff7763d15a3976766c2f6\System.AddIn.ni.dll + 2010-06-10 12:26 . 2010-06-10 12:26366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\f38a426b90e6c526dcb2c435c7380450\SMSvcHost.ni.exe + 2010-06-10 12:26 . 2010-06-10 12:26256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\6cabc7d1700c224e8b41ff2f96a3087c\SMDiagnostics.ni.dll + 2010-06-10 12:26 . 2010-06-10 12:26320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\5c8f5ca36498f43980d64820d8186c8a\ServiceModelReg.ni.exe + 2010-06-10 12:15 . 2010-06-10 12:15258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ae733e4062edba3a33bb0a632bef66bf\PresentationFramework.Royale.ni.dll + 2010-06-24 07:10 . 2010-06-24 07:10368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a10c2c7e38291c3ada631ad13e762818\PresentationFramework.Aero.ni.dll + 2010-06-24 07:10 . 2010-06-24 07:10539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7579c76fa81eb309d3170b62467be58d\PresentationFramework.Luna.ni.dll + 2010-06-10 12:14 . 2010-06-10 12:14368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3ffad524016f0aba7b11a8aa33301a65\PresentationFramework.Aero.ni.dll + 2010-06-24 07:10 . 2010-06-24 07:10224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3bef0992fb684e71dbfab5c0a99316af\PresentationFramework.Classic.ni.dll + 2010-06-24 07:10 . 2010-06-24 07:10258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2f6687d394813d760496f60acf046384\PresentationFramework.Royale.ni.dll + 2010-06-10 12:14 . 2010-06-10 12:14224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\201968d038a23a4688310fed1eeaddaa\PresentationFramework.Classic.ni.dll + 2010-06-10 12:14 . 2010-06-10 12:14539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1ead87ca8eb84c595c77c70e3b2df88d\PresentationFramework.Luna.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\7700963610c1af364aa934c3c824b7b4\MSBuild.ni.exe + 2010-06-10 12:26 . 2010-06-10 12:26386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\c74d4c69c49992dfb23ba512081dc3de\Microsoft.Transactions.Bridge.Dtc.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:30144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\a6a9f24b1a8984eaafbabb1ee968e359\Microsoft.Build.Utilities.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:30175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\2fa81d363cb1496be2427d848a867409\Microsoft.Build.Utilities.v3.5.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\c4c360df9c1024ebc3f0de77f5cf8b1c\Microsoft.Build.Engine.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:29222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\c9386dcd89c2518a74115f3bfd861830\Microsoft.Build.Conversion.v3.5.ni.dll + 2010-06-10 12:26 . 2010-06-10 12:26410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\abb62e3ed74c974f0282bc7ea5d3f1c1\ComSvcConfig.ni.exe + 2010-06-10 12:27 . 2010-06-10 12:27842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\6d34f00b6a782d15bec70d6cdb00b5e8\AspNetMMCExt.ni.dll - 2009-10-17 07:13 . 2009-10-17 07:13839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2010-06-24 07:04 . 2010-06-24 07:04839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2010-06-24 07:04 . 2010-06-24 07:04835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll - 2009-10-17 07:13 . 2009-10-17 07:13835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll - 2009-10-17 07:13 . 2009-10-17 07:13114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll + 2010-06-24 07:04 . 2010-06-24 07:04114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2010-06-10 12:10 . 2010-06-10 12:10970752 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll + 2010-06-24 07:04 . 2010-06-24 07:04131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll - 2009-10-17 07:13 . 2009-10-17 07:13131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll + 2010-06-24 07:04 . 2010-06-24 07:04303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll - 2009-10-17 07:13 . 2009-10-17 07:13303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll - 2009-10-17 07:14 . 2009-10-17 07:14372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2010-06-24 07:04 . 2010-06-24 07:04372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2010-06-10 12:10 . 2010-06-10 12:10438272 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll + 2010-06-24 07:04 . 2010-06-24 07:04626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll - 2009-10-17 07:13 . 2009-10-17 07:13626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll + 2010-06-24 07:04 . 2010-06-24 07:04401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll - 2009-10-17 07:13 . 2009-10-17 07:13401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll + 2010-06-24 07:04 . 2010-06-24 07:04188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll - 2009-10-17 07:13 . 2009-10-17 07:13188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll - 2009-10-17 07:14 . 2009-10-17 07:14970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2010-06-24 07:04 . 2010-06-24 07:04970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll - 2009-10-17 07:14 . 2009-10-17 07:14745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll + 2010-06-24 07:04 . 2010-06-24 07:04745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll - 2009-10-17 07:14 . 2009-10-17 07:14425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll + 2010-06-24 07:04 . 2010-06-24 07:04425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll + 2010-06-24 07:04 . 2010-06-24 07:04110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll - 2009-10-17 07:14 . 2009-10-17 07:14110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll - 2009-01-28 15:35 . 2009-01-28 15:35110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll + 2010-06-10 12:10 . 2010-06-10 12:10110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll - 2009-10-17 07:13 . 2009-10-17 07:13659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll + 2010-06-24 07:04 . 2010-06-24 07:04659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll - 2009-10-17 07:13 . 2009-10-17 07:13372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll + 2010-06-24 07:04 . 2010-06-24 07:04372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll - 2009-10-17 07:13 . 2009-10-17 07:13110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2010-06-24 07:04 . 2010-06-24 07:04110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll - 2009-10-17 07:13 . 2009-10-17 07:13749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll + 2010-06-24 07:04 . 2010-06-24 07:04749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll + 2010-06-24 07:04 . 2010-06-24 07:04655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll - 2009-10-17 07:14 . 2009-10-17 07:14655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll - 2009-10-17 07:13 . 2009-10-17 07:13348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll + 2010-06-24 07:04 . 2010-06-24 07:04348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll - 2009-10-17 07:13 . 2009-10-17 07:13507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2010-06-24 07:04 . 2010-06-24 07:04507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll - 2009-10-17 07:13 . 2009-10-17 07:13261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2010-06-24 07:04 . 2010-06-24 07:04261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2010-06-24 07:04 . 2010-06-24 07:04113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll - 2009-10-17 07:13 . 2009-10-17 07:13113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll - 2009-10-17 07:14 . 2009-10-17 07:14486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2010-06-24 07:04 . 2010-06-24 07:04486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2010-05-26 07:00 . 2009-05-26 09:01382840 c:\windows\$NtUninstallKB981793$\spuninst\updspapi.dll + 2010-05-26 07:00 . 2009-05-26 09:01231288 c:\windows\$NtUninstallKB981793$\spuninst\spuninst.exe + 2010-06-10 12:28 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB980218$\spuninst\updspapi.dll + 2010-06-10 12:28 . 2009-05-26 11:40231288 c:\windows\$NtUninstallKB980218$\spuninst\spuninst.exe + 2010-06-10 12:28 . 2008-04-14 00:09285696 c:\windows\$NtUninstallKB980218$\atmfd.dll + 2010-06-10 12:23 . 2008-07-08 13:02382840 c:\windows\$NtUninstallKB980195$\spuninst\updspapi.dll + 2010-06-10 12:23 . 2008-07-08 13:02231288 c:\windows\$NtUninstallKB980195$\spuninst\spuninst.exe + 2010-06-10 12:19 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB979559$\spuninst\updspapi.dll + 2010-06-10 12:19 . 2009-05-26 09:01231288 c:\windows\$NtUninstallKB979559$\spuninst\spuninst.exe + 2010-06-10 12:12 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB979482$\spuninst\updspapi.dll + 2010-06-10 12:12 . 2009-05-26 11:40231288 c:\windows\$NtUninstallKB979482$\spuninst\spuninst.exe + 2010-06-10 12:13 . 2007-07-28 03:11382840 c:\windows\$NtUninstallKB978695_WM9$\spuninst\updspapi.dll + 2010-06-10 12:13 . 2007-07-28 03:11231288 c:\windows\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe + 2010-05-13 07:01 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB978542$\spuninst\updspapi.dll + 2010-05-13 07:01 . 2009-05-26 11:40231288 c:\windows\$NtUninstallKB978542$\spuninst\spuninst.exe + 2010-05-13 07:00 . 2008-04-11 19:04691712 c:\windows\$NtUninstallKB978542$\inetcomm.dll + 2010-06-10 12:12 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB975562$\spuninst\updspapi.dll + 2010-06-10 12:12 . 2008-07-08 13:02231288 c:\windows\$NtUninstallKB975562$\spuninst\spuninst.exe + 2010-06-10 11:52 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB982381-IE7\update\updspapi.dll + 2010-06-10 11:52 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB982381-IE7\update\update.exe + 2010-06-10 11:52 . 2008-07-08 13:02231288 c:\windows\$hf_mig$\KB982381-IE7\spuninst.exe + 2010-05-04 17:20 . 2010-05-04 17:20841216 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\wininet.dll + 2010-05-04 17:20 . 2010-05-04 17:20233472 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\webcheck.dll + 2010-05-04 17:20 . 2010-05-04 17:20105984 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\url.dll + 2010-05-04 17:20 . 2010-05-04 17:20102912 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\occache.dll + 2010-05-04 17:20 . 2010-05-04 17:20671232 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mstime.dll + 2010-05-04 17:20 . 2010-05-04 17:20193024 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msrating.dll + 2010-05-04 17:20 . 2010-05-04 17:20477696 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mshtmled.dll + 2010-05-04 17:20 . 2010-05-04 17:20459264 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeeds.dll + 2010-04-16 11:08 . 2010-04-16 11:08634648 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe + 2010-05-04 17:20 . 2010-05-04 17:20268288 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iertutil.dll + 2010-05-04 17:20 . 2010-05-04 17:20193024 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iepeers.dll + 2010-05-04 17:20 . 2010-05-04 17:20388608 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iedkcs32.dll + 2010-05-04 17:20 . 2010-05-04 17:20380928 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieapfltr.dll + 2010-04-16 11:06 . 2010-04-16 11:06161792 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieakui.dll + 2010-05-04 17:20 . 2010-05-04 17:20230400 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieaksie.dll + 2010-05-04 17:20 . 2010-05-04 17:20153088 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieakeng.dll + 2010-05-04 17:20 . 2010-05-04 17:20132608 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\extmgr.dll + 2010-05-04 17:20 . 2010-05-04 17:20214528 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\dxtrans.dll + 2010-05-04 17:20 . 2010-05-04 17:20347136 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\dxtmsft.dll + 2010-05-04 17:19 . 2010-05-04 17:19124928 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\advpack.dll + 2010-06-10 12:28 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB980218\update\updspapi.dll + 2010-06-10 12:28 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB980218\update\update.exe + 2010-06-10 12:28 . 2009-05-26 11:40231288 c:\windows\$hf_mig$\KB980218\spuninst.exe + 2010-04-20 05:37 . 2010-04-20 05:37285824 c:\windows\$hf_mig$\KB980218\SP3QFE\atmfd.dll + 2010-06-10 12:23 . 2008-07-08 13:02382840 c:\windows\$hf_mig$\KB980195\update\updspapi.dll + 2010-06-10 12:23 . 2008-07-08 13:02755576 c:\windows\$hf_mig$\KB980195\update\update.exe + 2010-06-10 12:23 . 2008-07-08 13:02231288 c:\windows\$hf_mig$\KB980195\spuninst.exe + 2010-06-10 12:19 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB979559\update\updspapi.dll + 2010-06-10 12:19 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB979559\update\update.exe + 2010-06-10 12:19 . 2009-05-26 09:01231288 c:\windows\$hf_mig$\KB979559\spuninst.exe + 2010-06-10 12:12 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB979482\update\updspapi.dll + 2010-06-10 12:12 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB979482\update\update.exe + 2010-06-10 12:12 . 2009-05-26 11:40231288 c:\windows\$hf_mig$\KB979482\spuninst.exe + 2010-05-13 07:01 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB978542\update\updspapi.dll + 2010-05-13 07:01 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB978542\update\update.exe + 2010-05-13 07:01 . 2009-05-26 11:40231288 c:\windows\$hf_mig$\KB978542\spuninst.exe + 2010-01-29 14:53 . 2010-01-29 14:53691712 c:\windows\$hf_mig$\KB978542\SP3QFE\inetcomm.dll + 2010-06-10 12:12 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB975562\update\updspapi.dll + 2010-06-10 12:12 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB975562\update\update.exe + 2010-06-10 12:12 . 2008-07-08 13:02231288 c:\windows\$hf_mig$\KB975562\spuninst.exe + 2009-06-26 23:07 . 2009-06-26 23:073780416 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfc90u.dll + 2009-06-26 23:07 . 2009-06-26 23:073765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfc90.dll + 2009-07-12 00:46 . 2009-07-12 00:461093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll + 2009-07-12 00:46 . 2009-07-12 00:461105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll + 2004-08-04 12:00 . 2010-04-06 08:522462720 c:\windows\system32\WMVCore.dll - 2004-08-04 12:00 . 2010-03-11 12:381168384 c:\windows\system32\urlmon.dll + 2004-08-04 12:00 . 2010-05-04 17:201168384 c:\windows\system32\urlmon.dll + 2004-08-04 12:00 . 2010-02-05 18:271291776 c:\windows\system32\quartz.dll - 2004-08-04 12:00 . 2009-11-27 17:111291776 c:\windows\system32\quartz.dll + 2004-08-04 12:00 . 2010-05-04 17:203600384 c:\windows\system32\mshtml.dll + 2009-07-18 03:21 . 2010-06-16 20:255537232 c:\windows\system32\Macromed\Flash\NPSWF32.dll - 2007-08-14 02:54 . 2010-03-11 12:386067200 c:\windows\system32\ieframe.dll + 2007-08-14 02:54 . 2010-05-04 17:206067200 c:\windows\system32\ieframe.dll + 2009-01-28 04:53 . 2010-07-14 16:274429288 c:\windows\system32\FNTCACHE.DAT + 2004-08-04 12:00 . 2010-04-06 08:522462720 c:\windows\system32\dllcache\WMVCore.dll + 2009-01-28 14:48 . 2010-05-02 05:221851264 c:\windows\system32\dllcache\win32k.sys - 2007-08-14 02:54 . 2010-03-11 12:381168384 c:\windows\system32\dllcache\urlmon.dll + 2007-08-14 02:54 . 2010-05-04 17:201168384 c:\windows\system32\dllcache\urlmon.dll + 2008-05-07 05:12 . 2010-02-05 18:271291776 c:\windows\system32\dllcache\quartz.dll - 2008-05-07 05:12 . 2009-11-27 17:111291776 c:\windows\system32\dllcache\quartz.dll - 2009-08-12 21:03 . 2009-07-10 13:271315328 c:\windows\system32\dllcache\msoe.dll + 2009-08-12 21:03 . 2010-01-29 15:011315328 c:\windows\system32\dllcache\msoe.dll + 2007-08-14 02:54 . 2010-05-04 17:203600384 c:\windows\system32\dllcache\mshtml.dll - 2009-01-28 15:29 . 2010-03-11 12:386067200 c:\windows\system32\dllcache\ieframe.dll + 2009-01-28 15:29 . 2010-05-04 17:206067200 c:\windows\system32\dllcache\ieframe.dll + 2009-11-07 05:06 . 2009-11-07 05:061130824 c:\windows\system32\dfshim.dll + 2010-04-08 03:48 . 2010-04-08 03:485967872 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll - 2008-11-25 12:59 . 2008-11-25 12:595242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll + 2010-03-23 09:32 . 2010-03-23 09:325242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll + 2010-03-23 09:32 . 2010-03-23 09:323182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll - 2008-05-28 05:35 . 2008-05-28 05:351265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll + 2010-04-01 15:42 . 2010-04-01 15:421265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll - 2008-05-28 05:35 . 2008-05-28 05:351232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll + 2010-04-01 15:42 . 2010-04-01 15:421232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll - 2008-05-28 04:48 . 2008-05-28 04:482514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll + 2010-03-31 18:50 . 2010-03-31 18:502514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll + 2010-03-31 18:50 . 2010-03-31 18:502527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll - 2008-05-28 04:43 . 2008-05-28 04:432142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll + 2010-04-01 15:42 . 2010-04-01 15:422142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll + 2010-06-16 20:25 . 2010-06-16 20:251093120 c:\windows\Installer\d825a5.msi + 2010-05-03 20:27 . 2010-05-03 20:276825472 c:\windows\Installer\be07f42.msp + 2010-05-03 20:11 . 2010-05-03 20:114149760 c:\windows\Installer\be07ee7.msp + 2010-05-05 02:25 . 2010-05-05 02:257681024 c:\windows\Installer\be07ed1.msp + 2010-05-10 21:17 . 2010-05-10 21:175520896 c:\windows\Installer\be07ebb.msp + 2010-04-12 02:17 . 2010-04-12 02:172607104 c:\windows\Installer\be07e94.msp + 2010-04-12 02:17 . 2010-04-12 02:174210688 c:\windows\Installer\be07e93.msp + 2010-04-24 21:10 . 2010-04-24 21:108486400 c:\windows\Installer\be07e74.msp + 2010-05-03 20:06 . 2010-05-03 20:065053952 c:\windows\Installer\be07e69.msp + 2010-06-16 19:43 . 2010-06-16 19:431093120 c:\windows\Installer\a68889.msi + 2009-10-16 22:07 . 2009-10-16 22:076115328 c:\windows\Installer\4b9138a.msp + 2010-04-21 21:46 . 2010-04-21 21:465522432 c:\windows\Installer\4b91374.msp + 2010-07-14 13:26 . 2010-07-14 13:266483968 c:\windows\Installer\47ec359.msi + 2009-11-09 04:25 . 2009-11-09 04:251935360 c:\windows\Installer\43767ad.msp + 2010-05-25 15:45 . 2010-05-25 15:458445440 c:\windows\Installer\3fb686e.msp + 2010-07-01 02:52 . 2010-07-01 02:525522944 c:\windows\Installer\3fb6857.msp + 2010-07-17 14:01 . 2010-07-17 14:011904640 c:\windows\Installer\24ef50.msi + 2009-01-30 07:03 . 2010-07-13 16:533777536 c:\windows\Installer\12178a.msi - 2009-01-30 07:03 . 2010-04-14 23:133777536 c:\windows\Installer\12178a.msi + 2010-06-10 11:51 . 2010-03-11 12:381168384 c:\windows\ie7updates\KB982381-IE7\urlmon.dll + 2010-06-10 11:51 . 2010-03-11 12:383599872 c:\windows\ie7updates\KB982381-IE7\mshtml.dll + 2010-06-10 11:52 . 2010-03-11 12:386067200 c:\windows\ie7updates\KB982381-IE7\ieframe.dll + 2009-01-28 15:38 . 2009-01-28 15:385283840 c:\windows\assembly\temp\PCP2T7DR5Y\PresentationFramework.dll + 2009-01-28 15:35 . 2009-01-28 15:354210688 c:\windows\assembly\temp\4CMKJJJJJJ\PresentationCore.dll + 2009-01-28 15:35 . 2009-01-28 15:351245184 c:\windows\assembly\temp\0ILZDDDDDD\WindowsBase.dll + 2010-06-10 12:23 . 2010-06-10 12:231966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_f636947c\System.dll + 2010-06-10 12:24 . 2010-06-10 12:244792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_79ae7e92\System.dll + 2010-06-10 12:24 . 2010-06-10 12:245513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_c444e089\System.Xml.dll + 2010-06-10 12:23 . 2010-06-10 12:232088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_66bef7e9\System.Xml.dll + 2010-06-10 12:23 . 2010-06-10 12:233018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_b54f8c9d\System.Windows.Forms.dll + 2010-06-10 12:24 . 2010-06-10 12:247884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_6b5a1c44\System.Windows.Forms.dll + 2010-06-10 12:24 . 2010-06-10 12:242244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_09d267e4\System.Drawing.dll + 2010-06-10 12:24 . 2010-06-10 12:243395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_b8fadec9\System.Design.dll + 2010-06-10 12:24 . 2010-06-10 12:241470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_297bc57f\System.Design.dll + 2010-06-10 12:24 . 2010-06-10 12:248908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_d460f315\mscorlib.dll + 2010-06-10 12:24 . 2010-06-10 12:243391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_7590502d\mscorlib.dll + 2010-06-10 12:27 . 2010-06-10 12:276392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\af8ff11dbab485d5d13323bbf6a5be79\WindowsLive.Writer.PostEditor.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:282002432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\590ced109c1eb276203e1561a695ab99\WindowsLive.Writer.CoreServices.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:291105920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0654d7056eddd323f13f38ff67325ca7\WindowsLive.Writer.ApplicationFramework.ni.dll + 2010-06-10 12:10 . 2010-06-10 12:103313664 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\f231461883859922a040002dddfb7b12\WindowsBase.ni.dll + 2010-06-24 07:08 . 2010-06-24 07:083325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d63164ac4ed5adabc6a1b0fdf07eee05\WindowsBase.ni.dll + 2010-06-24 07:11 . 2010-06-24 07:111049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\d8549ce90b26cdc3071224ab6f020189\UIAutomationClientsideProviders.ni.dll + 2010-06-10 12:20 . 2010-06-10 12:201049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\48b66876f72f472db62de48ae4369406\UIAutomationClientsideProviders.ni.dll + 2010-06-10 12:09 . 2010-06-10 12:097949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll + 2010-06-10 12:20 . 2010-06-10 12:205450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll + 2010-06-10 12:32 . 2010-06-10 12:321356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\016b75f60a18535c8d6b3e5d861ab559\System.WorkflowServices.ni.dll + 2010-06-10 12:32 . 2010-06-10 12:321908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6dacae37d337004345518976fb57099e\System.Workflow.Runtime.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:314514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\c7b832bbc5bb11c6c7f128c801ce90d7\System.Workflow.ComponentModel.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:312992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\b9ea6ea910293cd6f13f765775867ebd\System.Workflow.Activities.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:291840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:312209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\5dfda43f1991ee6ba345d62b2be4801c\System.Web.Mobile.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:312403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f08b3b8cdf548e3dfe61f342536175eb\System.Web.Extensions.ni.dll + 2010-06-10 12:19 . 2010-06-10 12:191917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2d6a5dbee4506bf643b853e41668afa3\System.Speech.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:311706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\169fe0ad9d59982a2a6b89779c09885b\System.ServiceModel.Web.ni.dll + 2010-06-10 12:25 . 2010-06-10 12:252345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8b2710a63ecd363315ef16b257588b95\System.Runtime.Serialization.ni.dll + 2010-06-24 07:11 . 2010-06-24 07:111035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\af217ef58e5558991f331d482c2bdba6\System.Printing.ni.dll + 2010-06-10 12:19 . 2010-06-10 12:191035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\161b423dc4e86e569af019e838d39de5\System.Printing.ni.dll + 2010-06-10 12:25 . 2010-06-10 12:251070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\ad4fb86064d7a1ebcb9ee997e7208ac1\System.IdentityModel.ni.dll + 2010-06-10 12:18 . 2010-06-10 12:181587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:291116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\7deab2494d53763cd83c567e71e0d8e0\System.DirectoryServices.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:281801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\b81efadfee7702624b713c6d86f7e369\System.Deployment.ni.dll + 2010-06-10 12:16 . 2010-06-10 12:166616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\50130ef751b98a4a11bd4ab73af7cab5\System.Data.ni.dll + 2010-06-10 12:27 . 2010-06-10 12:272510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\f71abf392c5ca05a4e46a5d1c4c72856\System.Data.SqlXml.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:311328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\5e6311aff5ada83d0f854922fa62faf6\System.Data.Services.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:291115136 c:\windows\assembly\NativeImages_v2.0.5072 + 2010-06-10 12:29 . 2010-06-10 12:291115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\f249a2dbc8dcb91860d0997c163c73ff\System.Data.OracleClient.ni.dll + 2010-06-10 12:16 . 2010-06-10 12:162516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c3ba3367d03779ad6e76c5d4cdfe572a\System.Data.Linq.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:309924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6abf820d8ec57a0561c3367727d274df\System.Data.Entity.ni.dll + 2010-06-10 12:16 . 2010-06-10 12:162295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\e98726349766935ec0e9b980f19a046a\System.Core.ni.dll + 2010-06-10 12:16 . 2010-06-10 12:162128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\fc373f0a8dbd173c63b6b95551b1c673\ReachFramework.ni.dll + 2010-06-24 07:10 . 2010-06-24 07:102128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\57abb757c1f38586390dcc63bf056322\ReachFramework.ni.dll + 2010-06-10 12:16 . 2010-06-10 12:161657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\ead93b6a4f0101cb99d09f3e3fc6491c\PresentationUI.ni.dll + 2010-06-24 07:10 . 2010-06-24 07:101657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\0095ba60255d4addaf5b8ebee697a027\PresentationUI.ni.dll + 2010-06-10 12:09 . 2010-06-10 12:091451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\20ef773b20f6ce721ae60e5c2c2e8f80\PresentationBuildTasks.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:301712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\935b855860088a86bb65d37a19f059cc\Microsoft.VisualBasic.ni.dll + 2010-06-10 12:26 . 2010-06-10 12:261093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\7a266de493d30eed21cb60ebe300be53\Microsoft.Transactions.Bridge.ni.dll + 2010-06-10 12:31 . 2010-06-10 12:312332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\9db8f9f7fe63ca4451bb5316a3ebb009\Microsoft.JScript.ni.dll + 2010-06-10 12:30 . 2010-06-10 12:301966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\c96be82d6cb00367db4e3553272165ef\Microsoft.Build.Tasks.v3.5.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:291620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\3815de5b052187b5d9375681a6784255\Microsoft.Build.Tasks.ni.dll + 2010-06-10 12:29 . 2010-06-10 12:291888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\43fc6723d08e9ce88701c29653efd224\Microsoft.Build.Engine.ni.dll + 2010-06-24 07:07 . 2010-06-24 07:071249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll + 2010-06-24 07:04 . 2010-06-24 07:043182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll - 2009-10-17 07:14 . 2009-10-17 07:142048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll + 2010-06-24 07:04 . 2010-06-24 07:042048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll - 2009-10-17 07:13 . 2009-10-17 07:135025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll + 2010-06-24 07:04 . 2010-06-24 07:045025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll + 2010-06-10 12:10 . 2010-06-10 12:105967872 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll - 2009-10-17 07:13 . 2009-10-17 07:135062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll + 2010-06-24 07:04 . 2010-06-24 07:045062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll + 2010-06-24 07:07 . 2010-06-24 07:075279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll + 2010-06-24 07:03 . 2010-06-24 07:035242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll - 2009-10-17 07:13 . 2009-10-17 07:135242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll - 2009-10-17 07:14 . 2009-10-17 07:142933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2010-06-24 07:04 . 2010-06-24 07:042933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2010-06-24 07:07 . 2010-06-24 07:074210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll - 2009-01-28 15:35 . 2009-01-28 15:354210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll + 2010-06-24 07:04 . 2010-06-24 07:044546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll - 2009-10-17 07:14 . 2009-10-17 07:144546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll + 2010-06-10 12:23 . 2010-06-10 12:231232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll - 2009-10-17 07:02 . 2009-10-17 07:021232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll + 2010-06-10 12:23 . 2010-06-10 12:231265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll - 2009-10-17 07:02 . 2009-10-17 07:021265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll + 2010-06-10 12:19 . 2009-08-14 13:211850624 c:\windows\$NtUninstallKB979559$\win32k.sys + 2010-06-10 12:13 . 2009-05-20 08:562458112 c:\windows\$NtUninstallKB978695_WM9$\wmvcore.dll + 2010-05-13 07:00 . 2009-07-10 13:271315328 c:\windows\$NtUninstallKB978542$\msoe.dll + 2010-06-10 12:12 . 2009-11-27 17:111291776 c:\windows\$NtUninstallKB975562$\quartz.dll + 2010-05-04 17:20 . 2010-05-04 17:201171968 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\urlmon.dll + 2010-05-04 17:20 . 2010-05-04 17:203603456 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mshtml.dll + 2010-05-04 17:20 . 2010-05-04 17:206071296 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieframe.dll + 2010-06-09 23:07 . 2009-06-29 08:332452872 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieapfltr.dat + 2010-05-02 06:34 . 2010-05-02 06:341860352 c:\windows\$hf_mig$\KB979559\SP3QFE\win32k.sys + 2010-01-29 14:53 . 2010-01-29 14:531315328 c:\windows\$hf_mig$\KB978542\SP3QFE\msoe.dll + 2010-02-05 18:29 . 2010-02-05 18:291291776 c:\windows\$hf_mig$\KB975562\SP3QFE\quartz.dll + 2009-01-28 15:27 . 2010-07-02 19:3934045896 c:\windows\system32\MRT.exe + 2010-04-02 23:29 . 2010-04-02 23:2911413504 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp + 2010-05-11 15:30 . 2010-05-11 15:3011194880 c:\windows\Installer\be07f58.msp + 2010-04-02 16:30 . 2010-04-02 16:3017456640 c:\windows\Installer\be07f2d.msp + 2010-04-24 21:09 . 2010-04-24 21:0911750912 c:\windows\Installer\be07ef2.msp + 2010-04-12 02:17 . 2010-04-12 02:1714599680 c:\windows\Installer\be07ea5.msp + 2010-03-31 05:23 . 2010-03-31 05:2315638528 c:\windows\Installer\43767bc.msp + 2010-05-04 17:25 . 2010-05-04 17:2520240896 c:\windows\Installer\352520c.msp + 2010-05-04 17:20 . 2010-05-04 17:2015710720 c:\windows\Installer\3525202.msp + 2010-06-04 07:00 . 2010-06-04 07:0020242432 c:\windows\Installer\2b89935.msp + 2010-06-10 12:19 . 2010-06-10 12:1912430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll + 2010-06-10 12:28 . 2010-06-10 12:2811797504 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll + 2010-06-10 12:26 . 2010-06-10 12:2617403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\8b74f2fe3f3632f95ff4ddb8c4839a1e\System.ServiceModel.ni.dll + 2010-06-10 12:18 . 2010-06-10 12:1810683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\f352c5cb50bee105e4c873ca050f9f46\System.Design.ni.dll + 2010-06-10 12:13 . 2010-06-10 12:1314327808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ca898d942e4d85af4c3d5f14a77c359a\PresentationFramework.ni.dll + 2010-06-24 07:09 . 2010-06-24 07:0914328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\560662ada034afb6ec78a152bd9a47b5\PresentationFramework.ni.dll + 2010-06-10 12:12 . 2010-06-10 12:1212216320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\ba8f917fd89d7afa8885c2a326379f03\PresentationCore.ni.dll + 2010-06-24 07:09 . 2010-06-24 07:0912215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\9f5dff344ac6ac923b5ade8ba1ab9382\PresentationCore.ni.dll . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2010-05-26 19:231385864----a-w-c:\program files\Ask.com\GenericAskToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\INTERNET Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13574144] "nwiz"="nwiz.exe" [2008-09-18 1657376] "RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416] "SkyTel"="SkyTel.EXE" [2007-06-15 1826816] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 86016] "cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-05-22 181488] "CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2010-05-28 230736] "cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2009-01-28 771312] "capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2009-01-28 173296] "capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2009-01-28 259312] "QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [2009-01-28 14088] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-01-27 788880] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112] "CPMonitor"="c:\program files\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464] "Desktop Disc Tool"="c:\program files\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752] c:\documents and settings\Toni\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW] 2007-05-18 21:3079368----a-w-c:\windows\system32\UmxWNP.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\Roxio 2010\\Venue\\Venue.exe"= "c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 11:08 PM 93712] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/13/2009 7:20 PM 64288] R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [2/11/2010 8:42 AM 21488] R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [2/11/2010 8:42 AM 15856] R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 11:08 PM 63504] R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 11:08 PM 45584] R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [2/11/2010 8:42 AM 25584] R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 8:05 PM 457200] R2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [6/23/2009 6:40 PM 127352] R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 11:08 PM 134648] R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 11:08 PM 66576] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 7:17 AM 1181328] R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/18/2007 2:24 PM 1010192] R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 2:24 PM 801296] R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [6/24/2008 11:10 PM 281104] R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 11:08 PM 88816] R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [1/28/2009 2:24 PM 185680] S1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 11:08 PM 115216] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/4/2010 1:27 PM 136176] S2 RoxWatch12;Roxio Hard Drive WATCHER 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [7/24/2009 9:33 AM 219632] S3 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [7/24/2009 9:33 AM 1116656] . Contents of the 'Scheduled Tasks' folder 2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 1).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18] 2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 2).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18] 2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 3).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18] 2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 4).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18] 2010-07-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18] 2010-07-16 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34] 2010-06-23 c:\windows\Tasks\CAAntiSpywareScan_Daily as Toni at 10 24 AM.job - c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2009-01-28 10:53] 2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 17:26] 2010-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 17:26] 2010-07-22 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job - c:\program files\Ask.com\UpdateTask.exe [2010-05-26 19:23] . . ------- SUPPLEMENTARY Scan ------- . uLocal Page = \blank.htm uStart Page = hxxp://www.google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 LSP: c:\windows\system32\VetRedir.dll FF - ProfilePath - c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\ FF - prefs.js: browser.search.selectedEngine - Ask FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q= FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\documents and settings\Toni\Application Data\Facebook\npfbplugin_1_0_1.dll FF - plugin: c:\documents and settings\Toni\Application Data\Facebook\npfbplugin_1_0_3.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . - - - - ORPHANS REMOVED - - - - BHO-{675B23E3-279D-4AEF-B6F7-5783DA94959C} - c:\windows\system32\hbfqp.dll BHO-{6892BD80-AD3F-4F86-BF67-05DDFC491C6E} - c:\windows\system32\lbfqp.dll HKCU-Run-Usorijaxesab - c:\windows\dimspstl.dll AddRemove-$NtUninstallMTF1011$ - c:\windows\$NtUninstallMTF1011$\apUninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-07-22 02:19 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(712) c:\windows\system32\UmxWnp.Dll c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll - - - - - - - > 'explorer.exe'(4608) c:\windows\system32\WININET.dll c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\nvsvc32.exe c:\windows\system32\HPZipm12.exe c:\windows\RTHDCPL.EXE c:\windows\system32\RUNDLL32.EXE c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe c:\windows\system32\SearchIndexer.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe c:\program files\Canon\CAL\CALMAIN.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\CA\CA Internet Security Suite\ccprovsp.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2010-07-22 02:23:33 - machine was rebooted ComboFix-quarantined-files.txt 2010-07-22 06:23 ComboFix2.txt 2010-04-16 12:27 ComboFix3.txt 2010-04-16 12:16 ComboFix4.txt 2010-04-15 11:59 Pre-Run: 108,868,366,336 bytes free Post-Run: 108,861,652,992 bytes free - - End Of File - - 5D4E06B3AA9DEF8BD66DE6468C4CB7D0 Hi, Please download Malwarebytes Anti-Malware from Here. Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.Malwarebytes' log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4339 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 7/22/2010 7:58:40 PM mbam-log-2010-07-22 (19-58-40).txt Scan type: Quick scan Objects scanned: 143606 Time elapsed: 6 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
| 329. |
Solve : THINKPOINT boot virus? |
|
Answer» SuperDave! Re-running ComboFix to remove infections: It worked; now the boot virus messages from the motherboard are gone Here are the OTL logs: ---------------------------------------------------------------------- OTL logfile created on: 11/16/2010 12:42:16 AM - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Rob\Desktop\war on spyware Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1,024.00 Mb Total Physical Memory | 596.00 Mb Available Physical Memory | 58.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 76.33 Gb Total Space | 15.50 Gb Free Space | 20.31% Space Free | Partition Type: NTFS Unable to calculate disk information. Computer Name: CROMWELL | User Name: Rob | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2010/11/16 00:39:43 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rob\Desktop\war on spyware\OTL.exe PRC - [2010/09/10 23:41:42 | 001,901,056 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe PRC - [2010/09/07 17:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe PRC - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe PRC - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe PRC - [2010/07/20 08:09:40 | 000,080,384 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe PRC - [2009/12/16 17:38:20 | 000,375,296 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe PRC - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe PRC - [2006/03/03 20:03:10 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe PRC - [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2003/12/10 02:53:46 | 000,056,320 | R--- | M] (Doug Fetter Software Wizardry) -- C:\WINDOWS\system32\delttray.exe ========== Modules (SafeList) ========== MOD - [2010/11/16 00:39:43 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rob\Desktop\war on spyware\OTL.exe MOD - [2010/09/10 23:41:40 | 000,285,480 | ---- | M] (COMODO) -- C:\WINDOWS\system32\guard32.dll MOD - [2004/08/03 23:57:02 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll ========== Win32 Services (SafeList) ========== SRV - [2010/09/10 23:41:42 | 001,901,056 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent) SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner) SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner) SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon) SRV - [2010/02/05 20:44:23 | 001,181,328 | ---- | M] (Lavasoft) [Auto | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service) SRV - [2009/12/16 17:38:20 | 000,375,296 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater) SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend) SRV - [2006/03/03 20:03:10 | 000,069,632 | ---- | M] (HP) [Unknown | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Internet Explorer\SABProcEnum.sys -- (SABProcEnum) DRV - File not found [Kernel | On_Demand | Running] -- C:\commy\catchme.sys -- (catchme) DRV - [2010/09/10 23:40:54 | 000,091,560 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect) DRV - [2010/09/10 23:40:52 | 000,239,240 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard) DRV - [2010/09/10 23:40:52 | 000,025,240 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp) DRV - [2010/09/07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2010/09/07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2010/09/07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2010/09/07 16:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2010/09/07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2010/09/07 16:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2010/05/10 19:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL) DRV - [2010/02/17 19:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV) DRV - [2010/01/21 01:59:58 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag) DRV - [2010/01/21 01:59:56 | 000,024,960 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem) DRV - [2010/01/21 01:59:56 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus) DRV - [2009/09/23 13:55:23 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd) DRV - [2007/11/06 12:22:00 | 000,036,224 | ---- | M] (ArcSoft Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ArcCD.sys -- (ArcCD) DRV - [2007/04/25 07:55:02 | 000,134,912 | ---- | M] (ArcSoft Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\ArcUdfs.sys -- (ArcUdfs) DRV - [2006/11/10 14:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc) DRV - [2005/12/23 10:03:02 | 000,020,224 | R--- | M] (Initio Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\inic1620.sys -- (inic1620) DRV - [2005/11/18 17:29:38 | 010,192,896 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snp2sxp.sys -- (SNP2STD) USB2.0 PC Camera (SNP2STD) DRV - [2004/08/04 00:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum) DRV - [2004/08/03 23:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2004/08/03 22:10:12 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\61883.sys -- (61883) DRV - [2004/08/03 22:10:12 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc) DRV - [2004/08/03 22:10:00 | 000,051,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV) DRV - [2004/08/03 22:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM) DRV - [2004/06/10 21:42:38 | 000,015,429 | R--- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Sacm2K.sys -- (USBCM) DRV - [2003/12/10 02:53:45 | 000,386,464 | R--- | M] (Midiman/M-Audio) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\delta.sys -- (DELTA) Service for Delta Driver (WDM) DRV - [2002/10/16 03:57:04 | 000,084,529 | R--- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\si3112r.sys -- (Si3112r) DRV - [2002/03/21 20:21:32 | 000,134,784 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [2001/08/17 14:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginen ame: "Web Search" FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034" FF - prefs.js..browser.search.selectedEngine: "Web Search" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/403" FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.783 FF - prefs.js..extensions.enabledItems: [emailprotected]:2.14 FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0 FF - prefs.js..extensions.enabledItems: [emailprotected]:1.2.3 FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1 FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=403&q=" FF - prefs.js..browser.search.order.1: "Web Search" FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/30 19:29:13 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/30 19:29:13 | 000,000,000 | ---D | M] [2009/12/11 13:40:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Mozilla\Extensions [2009/12/11 13:40:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rob\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010/11/02 22:32:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\extensions [2010/02/27 14:08:29 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2009/10/06 00:08:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\extensions\[emailprotected] [2009/10/06 20:37:34 | 000,001,649 | ---- | M] () -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\searchplugins\Ask.xml [2010/08/16 15:07:36 | 000,005,529 | ---- | M] () -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\searchplugins\SearchquWebSearch.xml [2010/03/20 13:07:37 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\searchplugins\winamp-search.xml [2010/03/20 13:07:34 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2007/03/27 10:50:58 | 001,093,632 | ---- | M] (UNISYS France) -- C:\Program Files\Mozilla Firefox\plugins\npornap.dll [2010/01/13 23:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll [2010/08/16 15:07:36 | 000,005,529 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml O1 HOSTS File: ([2010/11/16 00:32:05 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found. O4 - HKLM..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO) O4 - HKLM..\Run: [DeltTray] C:\WINDOWS\System32\delttray.exe (Doug Fetter Software Wizardry) O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251900866625 (WUWebControl Class) O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class) O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com) O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/09/02 14:50:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe () O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 0 MsConfig - State: "startup" - 0 SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft) SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vga.sys - Driver SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft) SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics RENDERING (VML) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web FOLDERS ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install ActiveX: {8AD33C5C-9B70-434C-A412-9AD6EFB50373} - Microsoft Silverlight 2.0 ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{0CD71F12-53B7-4AAB-9324-AB16F6484AC2} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler) Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm () Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !) Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.) Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll () Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com) Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com) Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com) Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll () Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org) ========== Files/Folders - Created Within 30 Days ========== [2010/11/16 00:36:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2010/11/14 03:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Defender [2010/11/14 01:57:32 | 000,000,000 | RHSD | C] -- C:\cmdcons [2010/11/14 01:53:51 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2010/11/14 01:53:51 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2010/11/14 01:53:51 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2010/11/14 01:53:51 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2010/11/14 01:51:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2010/11/13 20:32:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Desktop\TWA charts [2010/11/13 15:35:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Desktop\1989 - Oh Mercy [2010/11/13 15:18:09 | 000,165,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2010/11/13 15:18:09 | 000,017,744 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2010/11/13 15:18:07 | 000,023,376 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2010/11/13 15:18:05 | 000,046,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2010/11/13 15:18:03 | 000,100,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2010/11/13 15:18:03 | 000,094,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2010/11/13 15:18:03 | 000,028,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2010/11/13 15:17:26 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2010/11/13 15:17:25 | 000,167,592 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2010/11/13 15:17:18 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software [2010/11/13 15:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software [2010/11/13 14:17:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData [2010/11/11 14:44:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Desktop\back up Nov 11 2010 [2010/11/10 23:43:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\Celemony Software GmbH [2010/11/10 23:42:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\VST3 [2010/11/10 23:42:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Celemony [2010/11/10 23:41:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Celemony Software GmbH [2010/11/10 23:41:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Celemony [2010/11/08 05:09:39 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro [2010/11/06 13:19:07 | 000,000,000 | ---D | C] -- C:\Qoobox [2010/11/04 03:55:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss [2010/11/03 20:23:06 | 000,000,000 | ---D | C] -- C:\VritualRoot [2010/11/03 12:39:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\Malwarebytes [2010/11/03 12:39:40 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010/11/03 12:39:39 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2010/11/03 12:39:39 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2010/11/03 12:39:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2010/11/03 03:22:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\SUPERAntiSpyware.com [2010/11/03 03:22:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com [2010/11/03 03:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware [2010/11/03 03:09:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Rob\Recent [2010/11/03 02:59:18 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2010/11/03 02:45:31 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO [2010/11/03 02:42:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Comodo [2010/11/02 20:30:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia [2010/11/02 20:27:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe [2010/11/02 19:00:08 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Documents\Server [2010/11/02 09:52:11 | 000,368,640 | ---- | C] (Propellerhead Software AB) -- C:\WINDOWS\System32\ReWire.dll [2010/10/31 00:44:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\DriverCure [2010/10/29 00:34:47 | 000,000,000 | ---D | C] -- C:\Program Files\u-he [2010/10/29 00:34:41 | 000,000,000 | ---D | C] -- C:\Program Files\Celemony [2010/10/27 22:40:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\Antares [2010/10/27 22:33:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\My Documents\Images [2010/10/27 22:33:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\My Documents\Audio [2010/10/27 22:18:39 | 000,000,000 | ---D | C] -- C:\Program Files\Antares Audio Technologies [2010/10/27 13:15:47 | 000,000,000 | ---D | C] -- C:\found.001 [2010/10/26 18:15:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Desktop\UTORRENT DOWNLOADS [2010/10/26 18:12:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\uTorrent [2010/10/26 13:49:52 | 000,000,000 | ---D | C] -- C:\Program Files\Syncrosoft [2010/10/26 13:49:49 | 000,045,056 | ---- | C] (Syncrosoft Hard- und Software GmbH) -- C:\WINDOWS\System32\Synsopos.exe [2010/10/25 23:37:43 | 000,249,856 | ---- | C] (Brooks Younce Software) -- C:\Documents and Settings\Rob\Desktop\DupFinder.exe [2010/10/25 23:24:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\Easy Duplicate Finder [2010/10/23 23:32:56 | 000,134,912 | ---- | C] (ArcSoft Inc.) -- C:\WINDOWS\System32\drivers\ArcUdfs.sys [2010/10/23 23:32:56 | 000,036,224 | ---- | C] (ArcSoft Inc.) -- C:\WINDOWS\System32\drivers\ArcCD.sys [2010/10/23 23:32:56 | 000,007,680 | ---- | C] (ArcSoft Inc.) -- C:\WINDOWS\System32\drivers\ArcRec.sys [2010/10/21 14:47:20 | 000,000,000 | ---D | C] -- C:\Program Files\Kodak [2010/10/20 21:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\My Documents\Any Video CONVERTER [2010/10/20 21:16:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\AnvSoft [2010/10/20 21:16:33 | 000,000,000 | ---D | C] -- C:\Program Files\Any Video Converter [2010/10/20 21:15:17 | 016,847,824 | ---- | C] (Any-Video-Converter.com ) -- C:\Documents and Settings\Rob\Desktop\avc-free.exe [2010/10/20 20:29:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\My Documents\Video Converter [2010/10/20 20:29:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Local Settings\Application Data\Video Converter [2010/10/20 20:28:38 | 000,000,000 | ---D | C] -- C:\Program Files\Free Video Converter [2010/10/20 20:27:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\VideoConverter [2010/10/20 20:26:42 | 024,527,365 | ---- | C] (Extensoft) -- C:\Documents and Settings\Rob\Desktop\FreeVideoConverter.exe [2010/10/19 16:46:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Local Settings\Application Data\ArcSoft [2010/10/19 16:42:09 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\ArcSoft [2010/10/19 16:40:12 | 000,018,688 | ---- | C] (Arcsoft, Inc.) -- C:\WINDOWS\System32\drivers\afc.sys [2010/10/19 16:40:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ArcSoft [2010/10/19 16:39:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\ArcSoft [2010/06/01 20:46:55 | 000,225,350 | ---- | C] ( ) -- C:\WINDOWS\rsnp2std.dll [2010/06/01 20:46:55 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2std.dll [2009/09/02 15:00:24 | 000,015,429 | R--- | C] ( ) -- C:\WINDOWS\System32\drivers\Sacm2K.sys [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [13 C:\*.tmp files -> C:\*.tmp -> ] [1 C:\Documents and Settings\Rob\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\Rob\Local Settings\Application Data\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010/11/16 00:36:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2010/11/16 00:36:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job [2010/11/16 00:36:02 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job [2010/11/16 00:36:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job [2010/11/16 00:36:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job [2010/11/16 00:34:52 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job [2010/11/16 00:32:05 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2010/11/16 00:31:47 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010/11/16 00:31:46 | 1073,319,936 | -HS- | M] () -- C:\hiberfil.sys [2010/11/15 23:44:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010/11/14 01:57:40 | 000,000,327 | RHS- | M] () -- C:\boot.ini [2010/11/13 20:47:58 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Rob\Local Settings\Application Data\prvlcl.dat [2010/11/13 15:18:10 | 000,001,710 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2010/11/13 15:18:03 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2010/11/11 21:10:01 | 000,012,477 | ---- | M] () -- C:\WINDOWS\System32\234.js [2010/11/11 16:23:45 | 000,000,515 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\Shortcut to Incoming.lnk [2010/11/10 04:10:17 | 000,001,673 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FileZilla Client.lnk [2010/11/08 18:36:54 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2010/11/08 05:09:39 | 000,001,980 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\HiJackThis.lnk [2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe [2010/11/05 00:08:05 | 000,000,211 | ---- | M] () -- C:\Boot.bak [2010/11/03 00:06:41 | 000,290,088 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010/11/02 08:54:47 | 000,000,834 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Cubase SX 3.lnk [2010/10/31 12:38:49 | 000,397,560 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010/10/31 12:38:49 | 000,059,780 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010/10/26 21:17:20 | 000,000,801 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\Cubase SX.lnk [2010/10/25 18:29:47 | 000,000,029 | ---- | M] () -- C:\WINDOWS\AudACM.ini [2010/10/24 11:55:42 | 000,001,245 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\everything is broken.rtf [2010/10/23 19:42:24 | 000,000,419 | ---- | M] () -- C:\WINDOWS\cdplayer.ini [2010/10/20 21:17:00 | 000,000,725 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\Any Video Converter.lnk [2010/10/20 21:15:17 | 016,847,824 | ---- | M] (Any-Video-Converter.com ) -- C:\Documents and Settings\Rob\Desktop\avc-free.exe [2010/10/20 20:26:54 | 024,527,365 | ---- | M] (Extensoft) -- C:\Documents and Settings\Rob\Desktop\FreeVideoConverter.exe [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [13 C:\*.tmp files -> C:\*.tmp -> ] [1 C:\Documents and Settings\Rob\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\Rob\Local Settings\Application Data\*.tmp -> ] ========== Files Created - No Company Name ========== [2010/11/16 00:12:58 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe [2010/11/14 03:37:51 | 000,000,330 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job [2010/11/14 01:57:40 | 000,000,211 | ---- | C] () -- C:\Boot.bak [2010/11/14 01:57:35 | 000,260,272 | RHS- | C] () -- C:\cmldr [2010/11/14 01:53:51 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe [2010/11/14 01:53:51 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2010/11/14 01:53:51 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2010/11/14 01:53:51 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2010/11/13 15:18:10 | 000,001,710 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2010/11/13 14:03:38 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2010/11/10 04:10:17 | 000,001,673 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FileZilla Client.lnk [2010/11/10 04:10:03 | 000,012,477 | ---- | C] () -- C:\WINDOWS\System32\234.js [2010/11/08 05:09:39 | 000,001,980 | ---- | C] () -- C:\Documents and Settings\Rob\Desktop\HiJackThis.lnk [2010/11/03 12:33:11 | 1073,319,936 | -HS- | C] () -- C:\hiberfil.sys [2010/11/02 21:25:57 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010/11/02 09:07:41 | 002,402,025 | ---- | C] () -- C:\WINDOWS\System32\dongle.dll [2010/11/02 08:54:47 | 000,000,834 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Cubase SX 3.lnk [2010/10/26 21:17:20 | 000,000,801 | ---- | C] () -- C:\Documents and Settings\Rob\Desktop\Cubase SX.lnk [2010/10/24 11:55:42 | 000,001,245 | ---- | C] () -- C:\Documents and Settings\Rob\Desktop\everything is broken.rtf [2010/10/20 21:17:00 | 000,000,725 | ---- | C] () -- C:\Documents and Settings\Rob\Desktop\Any Video Converter.lnk [2010/06/01 20:46:57 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2std.ini [2010/06/01 20:46:55 | 010,192,896 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2sxp.sys [2010/03/20 14:15:14 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Rob\Local Settings\Application Data\prvlcl.dat [2010/03/04 13:42:39 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\CommonDL.dll [2010/03/04 13:42:39 | 000,002,412 | ---- | C] () -- C:\WINDOWS\System32\lgAxconfig.ini [2010/01/29 17:27:28 | 000,000,419 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2010/01/12 21:26:23 | 000,005,103 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\amjmwaey.gaf [2010/01/12 02:00:49 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2009/11/03 17:48:21 | 000,000,051 | ---- | C] () -- C:\WINDOWS\npornap.INI [2009/10/30 14:51:15 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009/10/21 17:06:03 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2009/10/15 02:56:31 | 000,000,155 | ---- | C] () -- C:\WINDOWS\winamp.ini [2009/10/09 20:16:31 | 000,189,952 | ---- | C] () -- C:\Documents and Settings\Rob\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/10/06 13:27:58 | 000,400,384 | ---- | C] () -- C:\WINDOWS\System32\SYNSOACC.dll [2009/09/24 12:27:36 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009/09/24 12:27:36 | 000,585,728 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009/09/11 15:05:30 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log [2009/09/11 15:05:15 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll [2009/09/08 15:14:46 | 000,000,030 | R--- | C] () -- C:\WINDOWS\System32\drivers\RevHDD.ini [2009/09/07 21:28:16 | 000,000,029 | ---- | C] () -- C:\WINDOWS\AudACM.ini [2009/09/07 12:09:23 | 000,000,312 | ---- | C] () -- C:\WINDOWS\MusicStudio.INI [2009/09/07 12:09:23 | 000,000,047 | ---- | C] () -- C:\WINDOWS\SamControlpanel95.INI [2009/09/07 11:37:43 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\mgxasio2.dll [2009/09/07 11:36:49 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll [2009/09/07 11:35:46 | 000,005,937 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini [2009/09/04 17:06:34 | 000,003,637 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2009/09/04 17:06:32 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2009/09/02 16:37:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2009/09/02 15:00:24 | 000,053,693 | R--- | C] () -- C:\WINDOWS\UNDPX2K.sys [2009/08/27 20:04:44 | 000,557,003 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll [2009/08/27 20:04:32 | 000,811,835 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll [2009/08/27 20:03:52 | 004,456,201 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll [2009/08/25 19:07:36 | 000,328,334 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll [2009/08/25 18:38:04 | 000,425,040 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll [2009/08/25 17:37:02 | 000,146,098 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll [2009/06/02 18:15:44 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll [2009/06/02 18:15:18 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll [2009/06/02 18:15:04 | 000,183,296 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll [2009/06/02 18:14:56 | 000,178,688 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll [2009/06/02 18:14:30 | 000,486,400 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll [2009/06/02 18:13:58 | 000,257,024 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll [2009/06/02 18:13:50 | 000,142,848 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll [2009/06/02 18:11:26 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll [2009/06/02 18:11:16 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009/01/10 23:17:32 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\ts.dll [2009/01/10 23:16:56 | 000,148,480 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll [2009/01/10 23:16:50 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\avi.dll [2009/01/10 23:16:14 | 000,141,312 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll [2009/01/10 23:15:54 | 000,120,832 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll [2009/01/10 23:15:44 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll [2009/01/10 23:15:32 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\avss.dll [2009/01/10 23:15:28 | 000,246,784 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll [2009/01/10 23:15:12 | 000,097,280 | ---- | C] () -- C:\WINDOWS\System32\avs.dll [2009/01/10 23:14:08 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll [2009/01/10 23:14:06 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll [2008/11/06 17:37:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2007/10/13 10:30:20 | 000,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini [2004/07/17 10:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys [2003/02/19 01:26:28 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll [2002/06/06 01:01:58 | 000,029,696 | ---- | C] () -- C:\WINDOWS\System32\asutl8.dll [2001/07/07 02:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini ========== LOP Check ========== [2010/11/13 15:17:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software [2010/11/14 01:35:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9 [2010/11/10 23:43:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Celemony Software GmbH [2010/03/24 17:14:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Whiz [2010/10/03 17:06:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Empress Effects Inc [2010/10/04 14:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure [2010/02/27 18:17:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\flag ace stupid data [2009/10/06 13:07:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE [2010/04/07 18:47:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LGMOBILEAX [2010/03/12 17:11:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX [2010/11/13 14:27:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData [2009/10/06 13:28:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle [2009/12/02 21:01:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spell Check Anywhere [2010/10/20 20:27:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VideoConverter [2010/09/30 19:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2009/10/24 13:35:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} [2010/10/27 22:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Antares [2010/07/29 01:09:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Anvil Studio [2010/10/20 21:16:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\AnvSoft [2010/11/11 00:50:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Celemony Software GmbH [2010/10/31 00:44:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\DriverCure [2010/10/25 23:36:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Easy Duplicate Finder [2010/11/13 15:11:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\FileZilla [2010/01/21 20:06:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\FreeVideoConverter [2010/03/24 17:19:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\GetRightToGo [2009/10/06 20:41:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\GlobalSCAPE [2010/07/02 09:40:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Image Zone Express [2010/04/07 19:57:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\LG Electronics [2009/10/31 18:10:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Likno [2010/01/21 20:18:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Search Settings [2009/10/14 00:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Softplicity [2010/10/28 00:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Steinberg [2009/12/11 13:39:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Thunderbird [2010/11/13 14:10:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\uTorrent [2010/10/07 23:33:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\WhiteSmokeSetup [2010/10/04 14:19:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\WhiteSmokeTranslator [2010/11/16 00:36:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job [2010/11/16 00:36:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job [2010/11/16 00:36:02 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job [2010/11/16 00:36:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job [2010/11/16 00:36:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job [2010/11/16 00:34:52 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %systemroot%\*. /mp /s > < c:\$recycle.bin\*.* /s > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-09-02 14:34:02 < MD5 for: AGP440.SYS > [2004/08/04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys [2004/08/04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ERDNT\cache\AGP440.SYS [2004/08/04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\AGP440.SYS < MD5 for: ATAPI.SYS > [2004/08/04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys [2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys < MD5 for: AUTOCHK.EXE > [2004/08/03 23:56:48 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\cmdcons\autochk.exe [2004/08/03 23:56:48 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\WINDOWS\system32\autochk.exe [2004/08/03 23:56:48 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\WINDOWS\system32\dllcache\autochk.exe < MD5 for: BEEP.SYS > [2002/08/29 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\ERDNT\cache\beep.sys [2002/08/29 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\dllcache\beep.sys [2002/08/29 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys < MD5 for: EVENTLOG.DLL > [2004/08/03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ERDNT\cache\eventlog.dll [2004/08/03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll [2004/08/03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: EXPLORER.EXE > [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\ERDNT\cache\explorer.exe [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\explorer.exe [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\system32\dllcache\explorer.exe < MD5 for: IMM32.DLL > [2004/08/03 23:56:44 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=87CA7CE6469577F059297B9D6556D66D -- C:\WINDOWS\ERDNT\cache\imm32.dll [2004/08/03 23:56:44 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=87CA7CE6469577F059297B9D6556D66D -- C:\WINDOWS\system32\dllcache\imm32.dll [2004/08/03 23:56:44 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=87CA7CE6469577F059297B9D6556D66D -- C:\WINDOWS\system32\imm32.dll < MD5 for: KERNEL32.DLL > [2004/08/03 23:56:44 | 000,983,552 | ---- | M] (Microsoft Corporation) MD5=888190E31455FAD793312F8D087146EB -- C:\WINDOWS\ERDNT\cache\kernel32.dll [2004/08/03 23:56:44 | 000,983,552 | ---- | M] (Microsoft Corporation) MD5=888190E31455FAD793312F8D087146EB -- C:\WINDOWS\system32\dllcache\kernel32.dll [2004/08/03 23:56:44 | 000,983,552 | ---- | M] (Microsoft Corporation) MD5=888190E31455FAD793312F8D087146EB -- C:\WINDOWS\system32\kernel32.dll < MD5 for: MSWSOCK.DLL > [2004/08/03 23:56:46 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=4E74AF063C3271FBEA20DD940CFD1184 -- C:\WINDOWS\ERDNT\cache\mswsock.dll [2004/08/03 23:56:46 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=4E74AF063C3271FBEA20DD940CFD1184 -- C:\WINDOWS\system32\dllcache\mswsock.dll [2004/08/03 23:56:46 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=4E74AF063C3271FBEA20DD940CFD1184 -- C:\WINDOWS\system32\mswsock.dll < MD5 for: NDIS.SYS > [2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ERDNT\cache\ndis.sys [2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys [2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys < MD5 for: NETLOGON.DLL > [2004/08/03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll [2004/08/03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll [2004/08/03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll < MD5 for: NTFS.SYS > [2004/08/03 23:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS [2004/08/03 22:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\ERDNT\cache\ntfs.sys [2004/08/03 22:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\system32\dllcache\ntfs.sys [2004/08/03 22:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\system32\drivers\ntfs.sys < MD5 for: NTMSSVC.DLL > [2004/08/03 23:56:46 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=B62F29C00AC55A761B2E45877D85EA0F -- C:\WINDOWS\ERDNT\cache\ntmssvc.dll [2004/08/03 23:56:46 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=B62F29C00AC55A761B2E45877D85EA0F -- C:\WINDOWS\system32\dllcache\ntmssvc.dll [2004/08/03 23:56:46 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=B62F29C00AC55A761B2E45877D85EA0F -- C:\WINDOWS\system32\ntmssvc.dll < MD5 for: PROQUOTA.EXE > [2004/08/03 23:56:56 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=4D9D45A4370E0C2AD00C362B7118E2A4 -- C:\WINDOWS\system32\dllcache\proquota.exe [2004/08/03 23:56:56 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=4D9D45A4370E0C2AD00C362B7118E2A4 -- C:\WINDOWS\system32\proquota.exe < MD5 for: QMGR.DLL > [2004/08/03 23:56:46 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\ERDNT\cache\qmgr.dll [2004/08/03 23:56:46 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\system32\dllcache\qmgr.dll [2004/08/03 23:56:46 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\system32\qmgr.dll < MD5 for: SCECLI.DLL > [2004/08/03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ERDNT\cache\scecli.dll [2004/08/03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll [2004/08/03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll < MD5 for: SFCFILES.DLL > [2004/08/03 23:56:46 | 001,580,544 | ---- | M] (Microsoft Corporation) MD5=30A609E00BD1D4FFC49D6B5A432BE7F2 -- C:\WINDOWS\ERDNT\cache\sfcfiles.dll [2004/08/03 23:56:46 | 001,580,544 | ---- | M] (Microsoft Corporation) MD5=30A609E00BD1D4FFC49D6B5A432BE7F2 -- C:\WINDOWS\system32\dllcache\sfcfiles.dll [2004/08/03 23:56:46 | 001,580,544 | ---- | M] (Microsoft Corporation) MD5=30A609E00BD1D4FFC49D6B5A432BE7F2 -- C:\WINDOWS\system32\sfcfiles.dll < MD5 for: SPOOLSV.EXE > [2004/08/03 23:56:58 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=7435B108B935E42EA92CA94F59C8E717 -- C:\WINDOWS\ERDNT\cache\spoolsv.exe [2004/08/03 23:56:58 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=7435B108B935E42EA92CA94F59C8E717 -- C:\WINDOWS\system32\dllcache\spoolsv.exe [2004/08/03 23:56:58 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=7435B108B935E42EA92CA94F59C8E717 -- C:\WINDOWS\system32\spoolsv.exe < MD5 for: SRSVC.DLL > [2004/08/03 23:56:46 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\ERDNT\cache\srsvc.dll [2004/08/03 23:56:46 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\system32\dllcache\srsvc.dll [2004/08/03 23:56:46 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\system32\srsvc.dll < MD5 for: SVCHOST.EXE > [2004/08/03 23:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4EHow's your computer running now? I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt SuperDave! Quote How's your computer running now? Better malware symtoms seem to be gone. here is the ESET log: C:\Documents and Settings\All Users\Documents\Server\hlp.datWin32/Bamital.EK trojancleaned by deleting - quarantined C:\Documents and Settings\Rob\Desktop\back up Nov 11 2010\Incoming\adobe premier pro 7 serial.zipprobably a variant of Win32/Spy.Agent.MJJETOK trojandeleted - quarantined C:\Documents and Settings\Rob\Desktop\back up Nov 11 2010\VST Native Instruments B4 II + KeyGen\b4 II\(Vst Plug-In) Native Instruments Hammond b4 v1.11.zipa variant of Win32/Keygen.AA applicationdeleted - quarantined C:\Documents and Settings\Rob\Desktop\back up Nov 11 2010\VST Native Instruments B4 II + KeyGen\keygen b4 II\h-nib42a.zipa variant of Win32/Keygen.AA applicationdeleted - quarantined C:\Program Files\Trend Micro\HiJackThis\backups\backup-20101109-135051-994.dllWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined C:\Qoobox\Quarantine\MBR_HardDisk0.mbrWin32/Olmarik.ADA trojancleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettings.exe.virWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettingsRes409.dll.virWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettings_AVG_RESTORED.exe.virWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP11\A0029830.exemultiple threatsdeleted - quarantined C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP15\A0035135.exeWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP15\A0035136.exeWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP15\A0035137.dllWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP2\A0004339.exeNSIS/TrojanDownloader.FakeAlert.DK.Gen trojandeleted - quarantined C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP20\A0040902.dllWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP6\A0021602.dllWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined That's good news. If there are no other issues, let's do some cleanup. * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box. * Now type commy /uninstall in the runbox * Make sure there's a space between commy and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ****************************** To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
****************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. **************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! ;DSuperDave! Sorry it took so long to reply, i was called out of town for work. Thank you the computer is running much better now and seems to be malware free I can't uninstal SuperAntiSpyware though I would suggest that you keep SAS and MBAM. Update them and run them about once a week to keep your computer clean. |
|
| 330. |
Solve : Google redirect & random ads? |
|
Answer» Ok. How's your computer running now?it goes back to normal now. no more redirect or ads. thank you very much daveThat good. It's time for some cleanup.
****************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have SAVED all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *************************************** To set a new Restore Point. Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box NEXT to the disk, and then click OK. Reboot to Normal Mode. Click the Start button , click Control Panel, click System and Maintenance, and then click System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK. ******************************************** Some information about third-party firewalls. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from ONE of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not BLOCK outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ********************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's EASY and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! So should I keep both the Superantimalware and MBAM or just one of them and download the Spybot-search and destroy? And which of the firewall would you most recommend? Comodo personal firewall?Quote So should I keep both the Superantimalware and MBAM or just one of them and download the Spybot-search and destroy?Yes. It wouldn't hurt to run their scans every so often to keep the bugs out. Quote And which of the firewall would you most recommend? Comodo personal firewall?I'm running Comodo now. It takes a bit of getting used but after a while you don't know it's even there. It's the price you pay for being secure.thanks for answering my questions. I have one more question if you don't mind answering. Is the spywareblaster and spybot have similar function? Do I need to have both of them?They target different malware.ok got it. thanks a lot for your help again |
|
| 331. |
Solve : Zlob-LO Virus? |
|
Answer» Please do a search for that file. Go to Start, Search, All files or folders and copy and paste the file in the code box below to see if it's still there. Everything seems to be running smoothGood. Let's do some cleanup. * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box. * Now type commy /uninstall in the runbox * Make sure there's a space between commy and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ********************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************* Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a FREE firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone HOME" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ************************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything LISTED. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. ALSO stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe SURFING! Great, steps taken and onward to a safer journey. Much Thanks! |
|
| 332. |
Solve : My 1st bad, (?) virus: I don't even know where to start on this. I'm stuck...? |
|
Answer» Dave: Question: How do I find out if I'm using the MS firewall? Apparently, my wireless router is not a firewall as I've been told. (I thought I was good already for firewalls)Look for it in the Control Panel under Windows Firewall or the Security Center. Java is your choice.Dave: After a few sessions here's where I stand: MS Firewall is in this laptop, however, it was and is disabled. I ran Secunia and updated that list. I am now updating MS Windows update. I will nex add Web of Trust. I've never used SpyWare Blaster, but will add that too. I'll update, again, SpyBot. ? DennisDave: Thank you so much for all your help. Things look like they are running fine now. Plus, I've learned a lot. You are a great benefit to the forum. Cheers, Dennis |
|
| 333. |
Solve : Mouse/screen pointer freezes near end of laptop startup? |
|
Answer» WELL, Dave, if you're energetic enough to check this post of mine too, this is a very similar, but different laptop. When I told my wife you fixed the floater laptop, she rushed in with her's that she's not used for about 3 months. HP 4800, XP WINDOWS. I fired it up and all looked fine until just after the start screen populated with icons. Then pointer/MOUSE pad freezes. Hard power down and a few restarts produced no better results. It has AVG, but certainly needs updating. This machine has been used at times with external mouse. I tried that as well. Nothing. I can hit numeric key and it toggles light back-and-forth which I read is a GOOD sign. There is some minimal access to arrow keys being useful, but not entirely. So I guess I need to figure out how to work-around the freeze to get something going. I once used safe mode, but it's been a LONG time. ?? DennisAfter a few attempted restarts, when powered down, I tried the external mouse in a different USB port and it worked when I fired it back up. ?? Beats me. Thank you; this request can be closed now. Dennis |
|
| 334. |
Solve : Tidserv? |
|
Answer» Quote Also can I run a live update with "Symantec Endpoint" or will it interfere with all the programs that were installed to help resolve my issues?Yes. Go ahead and run it . We will be removing those programs now. You may keep SAS and MBAM, if you wish. Update them and run them every so often to keep the bugs out. Quote Also I am currently using Mozilla and it is asking me to upgrade, should I.Mozilla is a safer browser than Internet Explorer. Not sure about Chrome. You can just download the updates and it will install over itself and it will save all your settings. * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box. * Now type Combofix /uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ******************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ****************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Thanks for all your help !! Just wondering do I keep Symantec Endpoint with all the programs that I downloaded like Malwarebytes, SUPERantispyware, spybot, spywarebuster and HijackThis. Can you run all these programs at the same time? Thanks again !!!Quote Just wondering do I keep Symantec Endpoint with all the programs that I downloaded like Malwarebytes, SUPERantispyware, spybot, spywarebuster and HijackThis. Can you run all these programs at the same time?You can uninstall HiJackThis. We won't need it anymore. You may keep SAS, MBAM and Spybot. Keep them updated and run the scans every so often to keep your computer clean and for peace of mind. SpywareBlaster can be uninstalled but it won't hurt to keep it running. Hey SuperDave, What about TDSSKiller should it still be on my system? Also will there be any problems when I run Symantec Endpoint at the same time as all these other programs in my system? Sorry just want to make sure because from what I heard, running more than one system will CAUSE your system to crash? Is this true ??The systems conflict with each other??? Remember I'm a rookie Ha Ha Thanks again. Quote What about TDSSKiller should it still be on my system?Ok. Please delete it. Quote Also will there be any problems when I run Symantec Endpoint at the same time as all these other programs in my system? No. The only things you should only have one of, is your Anti-Virus and your Firewall. I run at least 4 malware programs on my computer with no problem. You can try running this tool to check to see what's running at start-up. Also, read the link I mentioned earlier in my closing speech about Slow computer for maintenance you can do to improve performance. StartupLite Download StartupLite by MalwareBytes to your Desktop. Doubleclick StartupLite.exe to launch the program. Ensure the Disable box is checked. Click Continue. A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer. Re-start your computer. Do you think with this "Tidserv" virus that any of my passwords have been comprised ?? Or was it strictly hijacking web searches and web pages ? Thanks again for all your help in ridding my computer of this problem!!! Tidserv is known as a backdoor trojan but all the scans didn't reveal this infection. However, we did find and fixed a rootkit infection. We cannot guarantee that your computer is 100% clean. While looking over this thread I realized that I had FORGOT one important scan. I will also give you some information about rootkits and then the decision will be up to you on your course of action. If you don't use your computer for financial transactions it shouldn't bother you too much. I'd like to scan your machine with ESET OnlineScan •Hold down CONTROL and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt ***************************************** It appears your system was infected with a rootkit. A rootkit is a powerful piece of malware, that allows hackers full control over your computer for means of sending attacks over the Internet, or using your computer to generate revenue. Malware experts have recommended that we make it clear that with the system under control of a hacker, your computer might become impossible to clean 100%. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. They can disable your antivirus and security tools to prevent detection and removal. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is sent back to the hacker. To learn more about these types of infections, you can refer to: What danger is presented by rootkits? Rootkits and how to combat them r00tkit Analysis: What Is A Rootkit If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? What Should I Do If I've Become A Victim Of Identity Theft? Identity Theft Victims Guide - What to do It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired so you can never be sure that you have completely removed a rootkit. The malware may leave so many remnants behind that security tools cannot find them. Tools that claim to be able to remove rootkits cannot guarantee that all traces of it will be removed. Many experts in the security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety. Making this decision is based on what the computer is used for, and what information can be accessed from it. For more information, please read these references very carefully: When should I re-format? How should I reinstall? Help: I Got Hacked. Now What Do I Do? Help: I Got Hacked. Now What Do I Do? Part II Where to draw the line? When to recommend a format and reinstall? Guides for format and reinstall: how-to-reformat-and-reinstall-your-operating-system-the-easy-way However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat. If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful. Please let me know what you have DECIDED to do in your next post. Should you have any questions, please feel free to ask. The scan ran for about 25 minutes and found no THREATS (0 threats) the following is the log from eset: [emailprotected] as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=9dd46370711cd64da8d35ff45b4f10f7 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-11-23 03:22:10 # local_time=2010-11-23 10:22:10 (-0500, Eastern Standard Time) # country="Canada" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 1314078 1314078 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=48118 # found=0 # cleaned=0 # scan_time=2934 Upon completeion Eset asked if I wanted to remove program when finished and I opted yes remove it. Just to keep you up to speed, computer is running very good with no problems since you fixed rootkit issue. I have used computer in the past (very sparingly) to do banking, but have not done anything in the past 3 months or so. The problems with tidserv started about a month and a half or so ago, so nothing was done on computer (financial) while "Tidserv" was detected. As I mentioned before, the decision is yours to make. If you don't feel comfortable doing financial transactions or other personal business then you should back-up whatever important documents, files and pictures and reformat. My laptop was hit with a rootkit a few days after I puchased it and I still won't conduct financial business on it. Plus, I'm not too happy with Vista. I appreciate all your guidance and advice !! I have read alot of the links you have attached in a previous thread about rootkits and malware. I did a search in virus and malware database but didn't find "Tidserv Backdoor", do you have any info on it? is it high risk, low risk? Also in my reading it says that alot of these rootkit issues are undetectable, does that mean that a computer can have these issues and never even get a warning that something is wrong? In my case the Symantec Endpoint was constantly giving me a popup warning that "Tidserv" was detected. You also directed me to Panda Security website for reading about rootkits and they have a tool called "Panda Anti-Rootkit" Is this worth running? Again thanks for your direction !!!Quote do you have any info on it? is it high risk, low risk?You can find some info here. Quote does that mean that a computer can have these issues and never even get a warning that something is wrong?The most difficult thing about rootkits is their ability to hide themselves. That's why we have to run so many tools/scans to find them. Quote Is this worth running?Yes, by all means. Download it and run it. Most major AV companies have their own rootkit scanner.Thanks again for all your help! I have read the article from symantec about tidserv very informative. In one of the articles from symantec it states the following: Response A removal tool is available to clean infections of Backdoor.Tidserv. The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines. 1. Disable System Restore (Windows Me/XP). 2. Update the virus definitions. 3. Run a full system scan. 4. Delete any values added to the registry. When I went into My Computer and system restore I noticed my system restore was already disabled?? Should this be changed back to enable restore? When it says delete any values added to the registry, where would i find that info? Will Symantec tell me if there is any values added? Quote Disable System Restore (Windows Me/XP).I would never ask a user to disable their System Restore. An infected Restore Point is better than no Restore Point. Quote Should this be changed back to enable restore?Yes. Quote When it says delete any values added to the registry, where would i find that info?Only an expert should mess around in the registry. You could turn your computer into a doorstop. Thanks I will set my computer to have restore enabled. I don't ever remember disabling it??? Could it of been the "Tidserv" malware doing this??Also I was thinking could it have been EvilFantasy that turned system restore off while doing one of his processes?? Also he installed something whereas when I first turn on my computer i get a black screen for only about 3-5 seconds that has different options on it to help me in case there are issues (I believe this is for if computer has issues i can debug, start in safe mode, reboot etc.) Thanks again to yourself and EvilFantasy for all your help!! |
|
| 335. |
Solve : Changes to my computer that I did not make? |
|
Answer» Hello! Is there anything else I should do at this point?No. Just STAY safe.Alright then. Have a great day and THANK YOU again. (I SHALL pursue my other questions in another AREA on this site ) nhchap |
|
| 336. |
Solve : Pc Problems? |
|
Answer» Still FINISHING off the cleanup and preventative maintenance items you suggested, but WANTED to give you a huge thanks for all your HELP. It has been a long PROCESS but got there with your help. Everything has been running great now. |
|
| 337. |
Solve : Neep help removing remnants of "AntiMalware Doctor" infection? |
|
Answer» The only thing I can suggest now is to relocate your computer to a location where you can hardwire it to a modem and then try to connect to the internet. If it works, that would indicate the problem is with the Wi-fi connection.Before you attempt to move your computer, let's try this. Since we can't flush the DNS, we'll disable it and then try to connect to the net. If it doesn't work, go back and start it again and then attempt what I've suggested in the previous post.
"Service status" says "Stopped" "Startup type" is set as "disabled", with the option of setting it to "automatic" or "manual". should i change this setting? would it help?Try setting it to Automatic.ok, i turned it to automatic, and unfortunately, it did not change anything. so i figured maybe if i restarted my computer it might start working. so i restarted, and now it won't let me open anything. the cursor moves, but if i double or single click any icon, nothing happens. also, i tried doing ctrl/alt/del to find out if something was eating up cpu power, and the task manager window never popped up. do i need to restart in safe mode or something?That shouldn't HAPPEN. Try starting in Safe Mode and see what happens. Do you have your OS disk?ok, so i started in safe mode. everything worked normally. unfortunately, in safe mode, no internet is allowed, so i can't really CHECK it. at the F8 menu at startup, there was an option for safe mode with networking. should i do that instead? YES, i do have the OS disk.Ok. Let's try this:Try a System Restore to see if you can get your computer working again. You can do this in Safe Mode. If you can get it to work, please try below: Make sure, your computer is set to obtain IP address automatically. 1. Go Start>Settings>Control Panel (Vista/7 users: Start>Control Panel) 2. Double click Network Connections (Vista/7 users: Network and Sharing Center) 3. Vista/7 users - From the list of tasks on the left, click Manage network connections. 4. For a WIRED network connection, right-click Local AREA Connection, and then select Properties. For a wireless network connection, right-click Wireless Network Connection, and then select Properties. 5. From the General tab (Vista/7 users: Networking tab), click Internet Protocol (TCP/IP), make sure it is checked, and then click Properties 6. Click Obtain an IP Address Automatically, and then click OK.okay, suddenly my computer is working again, no explanation. so i followed your directions, and my tcp/ip is already set to obtain the IP address automatically.And still no connection?nope, still no connection. like i said, i do have the OS disk. should i just go ahead and reformat my hard drive? i've done it before, so i'm no stranger to it. it might be the most simple fix to this problem.Quote from: piratesteve83 on November 16, 2010, 06:34:05 PM nope, still no connection. like i said, i do have the OS disk. should i just go ahead and reformat my hard drive? i've done it before, so i'm no stranger to it. it might be the most simple fix to this problem.If you don't mind doing it, it would be the best solution. You'll be starting off with a clean slate. Please let me know your course-of-action.yeah, i'll go ahead and reformat. thanks so much for all of your effort, anyway! |
|
| 338. |
Solve : Personal Internet Security 2011 Virus Removal? |
|
Answer» I ran the ciscoeapfast.xsd file through Jotti and it came up with nothing. Are we dealing with some residual effect of a virus or a hardware problem? Also, if you think it would be best, I think I could back up everything of value off the computer and reformat the drive. There is one program that I don't have disks for that I would have to investigate how to get it back, but everything else, I believe, would be pretty easy to backup prior to a re-format.It's looking more and more like a hardware or software problem. Of course, a full re-format is a good route to take but not everyone can or want to take that route. If you don't have the disks for that particular program I don't see anyway to get it back. Of course, the choice is yours. Please try this: Do you have your OS CD/DVD? If so, 1/ Click the Start button. 2/ From the Start Menu, Click All programs followed by Accessories. 3/ In the Accessories menu, Right Click on the Command Prompt option. 4/ From the drop down menu that appears, Click on the Run as administrator option. 5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc. 6/ In the Command Prompt window, type: sfc /scannow and then press Enter. 7/ A message will appear stating that the system scan will begin. 8/ Be patient because the scan may take some time. 9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue. 10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations. 11/ After the scan has completed, Close the command prompt window. Here's the final story on this computer. I believe there is a hard drive issue or something else that is gumming things up and not any virus. I ran the SFC and, surprise, it found errors but was unable to repair them. I came up with a work around for MBAM where I told it to ignore any of the igfx*.* files (which was a PITA) and ran a scan. The scan completed without issue and no malware was found. I then set up SAS to ignore the Cisco file folder that it normally was hanging up on. I could not find a WAY to get SAS to ignore individual files, but this tool rarely hung up on the igfx files. I ran the scan and it caused the blue screen of death. When the computer restarted I got a windows message about a disk I/O issue and in the Help context it mentioned that heavy disk access programs such as malware scanners could be early detectors of POSSIBLE disk issues. Also, PERIODICALLY, when the computer boots it goes into the check disk screen and reports unindexed files or other issues that seem to suggest the life of the drive may be drawing to a close. I am going to back up the computer data and continue to run it. When the issue becomes enough of a pain I will replace the drive and start over with the operating system. The scanner issues seem to suggest more of a hang up trying to access data on a physical location of the disk than some remnant of malware. There are no more re-directs in I-Explorer and the rest of the system seems to be operating well. I thank you for your time on this and your help walking through all of this. I will keep MBAM on the MACHINE and get rid of the other tools we have downloaded. If you could give me some direction on that cleanup, please let me know. Once done we can close the thread. If something comes up I will PM you to reopen the thread. Thank You, ScottThis is all I have. You can keep SAS and MBAM, if you wish. Be sure to update them before running any scans. To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
|
|
| 339. |
Solve : Security Defendender Virus! Please help - Windows 7 x64? |
|
Answer» Hi there, Post the ComboFix log and a new HijackThis log in your next reply. Did you want a HiJackThis log as well? If so, do you have a download link? ThanksQuote Did you want a HiJackThis log as well?Yes, I would like to see both logs. Please don't post download links, especially the ones I can't see. Copy and paste the logs in your replies.Where do I download HijackThis?Please download: HiJackThis to your Desktop.
|
|
| 340. |
Solve : Help with System Tools virus? |
|
Answer» Quote from: SuperDave on February 09, 2011, 12:04:44 PM That's it. You can keep SAS and MBAM on your computer, if you wish. Update them and run them on a regular basis. Good Luck! Really?? Seriously???...You're not messing with me right? lol Well let me just SAY again...THANK YOU SuperDave from the bottom of my heart!!! I don't know what I would have done WITHOUT this great website and all the wonderful people here donating their time! Your the best! ginaQuote You're not messing with me right? lolGina, I wouldn't mess with you with something as IMPORTANT as your computer. Quote THANK YOU SuperDave from the bottom of my heart!!!You're welcome. I will lock this thread. If you need it re-opened, PLEASE SEND me a pm. |
|
| 341. |
Solve : Yahoo IM "IQ Test Hack"? |
|
Answer» Yay! This one worked!
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download UPDATES for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET ONLINE Scanner\log.txt Here's the report from ESET: C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\65891f0d-3955331bmultiple threatsdeleted - quarantined C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\286463dc-2a9a9656multiple threatsdeleted - quarantined C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\330b03dd-3763c60cmultiple threatsdeleted - quarantined C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\4cad16f7-383f81fbmultiple threatsdeleted - quarantined C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\73d2f5b8-4ecc26demultiple threatsdeleted - quarantined C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\7127249-4a57221bmultiple threatsdeleted - quarantinedThat looks good. If there are no other issues, let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************* Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! No other issues I can think of. Thank you so much for all the help! You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 342. |
Solve : application can not be executed - xy is infected - trojan horse? |
|
Answer» with web cure it same thing as last time: i could not open the page - server not found... and what about the two threats that were found by eset this time? since i pressed merely the 'scan archives' button and not the 'remove found threats'-one?Run the ESET scan again and, this time remove them please.this time i removed the threats (which amounted to 5 now...) and these are the results: C:\Windows\temp\37716533.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined C:\Windows\temp\5f9d0076.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined C:\Windows\temp\8d556260.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined C:\Windows\temp\a879b485.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined C:\Windows\temp\d7db9f3.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined web Cureit still does not work however... i don't know if it would work if i just didn't use the link you posted but would download it from here http://www.freedrweb.com/cureit/?lng=en -> is this the right thing? many thanks!Quote from: ekluever on July 13, 2010, 04:41:29 PM i don't know if it would work if i just didn't use the link you posted but would download it from here http://www.freedrweb.com/cureit/?lng=en -> is this the right thing?Yes, that's correct. We don't normally send users to websites; by clicking on the link you should get a download message.hello dave, i ran the dr.web cure it quick scan (while i was gone to work) and when i returned it said it didn't find any threats. in the meantime my friend said however, that i should have cut my internet connection, while doing the scan. i did not do the complete scan - cause i wasn't sure since it hadn't found anything in the first place. what do you recommend next? thanks, elisa ps: yes, i know, usually clicking your links always directly opened the download window, just this one tried to open a new tab and then said it couldn't find the server...Elisa, could you please give it a few days and then come back and tell how everything is working. If it's ok by then, we'll do some cleanup.hello dave malicious software removal tool today alerted me and said it found a Trojan:WinNT/Bubnix.gen!A which it partially removed. what keeps happening unfortunately, is that it won't properly start, it'll say a problem has been detected and windows has been shut down to prevent damage to your computer acpi.sys then it'll restart, come to the site i described before, where you can choose one of five start-options. the normal starting is the highlighted choice which will be chosen automatically after 30 sec. this cycle will be gone through a COUPLE of times, until eventually, with the automatic choice it'll start normally... i just wanted to describe this problem again. other than that, it seems to be working fine. i'll shut it down now and then run a complete antivir scan, as this is whast was suggested after finding the above mentioned file... else, i'll follow your advice and call back in a couple of days. many thanks! elisaoh, and something was found when i started another antivr-scan just now, i'll paste the log: Avira AntiVir Personal Report file date: Thursday, July 15, 2010 09:27 Scanning for 2346510 virus strains and unwanted programs. The program is running as an UNRESTRICTED full version. Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows Vista Windows version : (Service Pack 2) [6.0.6002] Boot mode : Normally booted Username : SYSTEM Computer name : ELISA-PC Version information: BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00 AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 12:37:38 AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 12:57:04 LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 18:33:04 LUKERES.DLL : 10.0.0.1 12648 Bytes 2/10/2010 23:40:49 VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 09:05:36 VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 19:27:49 VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 17:37:42 VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 16:37:42 VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 11:29:03 VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 11:09:48 VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 11:09:54 VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 11:09:54 VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 11:09:54 VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 11:09:54 VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 11:09:54 VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 11:09:54 VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 11:09:54 VBASE013.VDF : 7.10.8.37 270336 Bytes 6/10/2010 11:09:55 VBASE014.VDF : 7.10.8.69 138752 Bytes 6/14/2010 11:09:55 VBASE015.VDF : 7.10.8.102 130560 Bytes 6/16/2010 11:09:56 VBASE016.VDF : 7.10.8.135 152064 Bytes 6/21/2010 11:09:56 VBASE017.VDF : 7.10.8.163 432128 Bytes 6/23/2010 11:09:57 VBASE018.VDF : 7.10.8.194 133632 Bytes 6/27/2010 11:09:57 VBASE019.VDF : 7.10.8.220 134656 Bytes 6/29/2010 11:09:58 VBASE020.VDF : 7.10.8.252 171520 Bytes 7/4/2010 11:09:58 VBASE021.VDF : 7.10.9.19 131072 Bytes 7/6/2010 11:09:59 VBASE022.VDF : 7.10.9.36 297472 Bytes 7/7/2010 11:09:59 VBASE023.VDF : 7.10.9.60 150016 Bytes 7/11/2010 08:02:27 VBASE024.VDF : 7.10.9.79 113152 Bytes 7/13/2010 08:02:27 VBASE025.VDF : 7.10.9.80 2048 Bytes 7/13/2010 08:02:27 VBASE026.VDF : 7.10.9.81 2048 Bytes 7/13/2010 08:02:27 VBASE027.VDF : 7.10.9.82 2048 Bytes 7/13/2010 08:02:27 VBASE028.VDF : 7.10.9.83 2048 Bytes 7/13/2010 08:02:28 VBASE029.VDF : 7.10.9.84 2048 Bytes 7/13/2010 08:02:28 VBASE030.VDF : 7.10.9.85 2048 Bytes 7/13/2010 08:02:28 VBASE031.VDF : 7.10.9.90 95744 Bytes 7/14/2010 08:02:30 Engineversion : 8.2.4.10 AEVDF.DLL : 8.1.2.0 106868 Bytes 7/8/2010 11:10:09 AESCRIPT.DLL : 8.1.3.39 1335674 Bytes 7/8/2010 11:10:09 AESCN.DLL : 8.1.6.1 127347 Bytes 7/8/2010 11:10:08 AESBX.DLL : 8.1.3.1 254324 Bytes 7/8/2010 11:10:10 AERDL.DLL : 8.1.4.6 541043 Bytes 7/8/2010 11:10:08 AEPACK.DLL : 8.2.2.5 430453 Bytes 7/8/2010 11:10:08 AEOFFICE.DLL : 8.1.1.6 201081 Bytes 7/8/2010 11:10:07 AEHEUR.DLL : 8.1.1.38 2724214 Bytes 7/8/2010 11:10:07 AEHELP.DLL : 8.1.11.6 242038 Bytes 7/8/2010 11:10:04 AEGEN.DLL : 8.1.3.13 381300 Bytes 7/8/2010 11:10:04 AEEMU.DLL : 8.1.2.0 393588 Bytes 7/8/2010 11:10:03 AECORE.DLL : 8.1.15.3 192886 Bytes 7/8/2010 11:10:02 AEBB.DLL : 8.1.1.0 53618 Bytes 7/8/2010 11:10:00 AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 12:03:38 AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 12:03:35 AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 16:47:40 AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 12:35:46 AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 12:39:51 AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 12:22:13 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 09:53:30 SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 12:57:58 AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 15:38:56 NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 14:41:00 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 13:10:20 RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 14:14:29 Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: C:\program files\avira\antivir desktop\sysscan.avp Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, D:, Process scan........................: on Extended process scan...............: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Start of the scan: Thursday, July 15, 2010 09:27 Starting search for hidden objects. The scan of running processes will be started Scan process 'winamp.exe' - '190' Module(s) have been scanned Scan process 'svchost.exe' - '30' Module(s) have been scanned Scan process 'vssvc.exe' - '49' Module(s) have been scanned Scan process 'avscan.exe' - '79' Module(s) have been scanned Scan process 'SkypeNames.exe' - '25' Module(s) have been scanned Scan process 'skypePM.exe' - '67' Module(s) have been scanned Scan process 'Skype.exe' - '123' Module(s) have been scanned Scan process 'firefox.exe' - '118' Module(s) have been scanned Scan process 'mobsync.exe' - '38' Module(s) have been scanned Scan process 'igfxsrvc.exe' - '30' Module(s) have been scanned Scan process 'FirewallGUI.exe' - '48' Module(s) have been scanned Scan process 'avgnt.exe' - '54' Module(s) have been scanned Scan process 'pctsTray.exe' - '59' Module(s) have been scanned Scan process 'winampa.exe' - '21' Module(s) have been scanned Scan process 'jusched.exe' - '24' Module(s) have been scanned Scan process 'OEM02Mon.exe' - '34' Module(s) have been scanned Scan process 'igfxpers.exe' - '26' Module(s) have been scanned Scan process 'hkcmd.exe' - '26' Module(s) have been scanned Scan process 'GrooveMonitor.exe' - '43' Module(s) have been scanned Scan process 'MSASCui.exe' - '40' Module(s) have been scanned Scan process 'taskeng.exe' - '47' Module(s) have been scanned Scan process 'RapportService.exe' - '72' Module(s) have been scanned Scan process 'Explorer.EXE' - '160' Module(s) have been scanned Scan process 'taskeng.exe' - '82' Module(s) have been scanned Scan process 'Dwm.exe' - '29' Module(s) have been scanned Scan process 'WUDFHost.exe' - '33' Module(s) have been scanned Scan process 'SearchIndexer.exe' - '60' Module(s) have been scanned Scan process 'svchost.exe' - '9' Module(s) have been scanned Scan process 'svchost.exe' - '44' Module(s) have been scanned Scan process 'avshadow.exe' - '33' Module(s) have been scanned Scan process 'pctsAuxs.exe' - '26' Module(s) have been scanned Scan process 'svchost.exe' - '40' Module(s) have been scanned Scan process 'IoctlSvc.exe' - '21' Module(s) have been scanned Scan process 'FWService.exe' - '61' Module(s) have been scanned Scan process 'avguard.exe' - '64' Module(s) have been scanned Scan process 'svchost.exe' - '62' Module(s) have been scanned Scan process 'sched.exe' - '56' Module(s) have been scanned Scan process 'spoolsv.exe' - '85' Module(s) have been scanned Scan process 'svchost.exe' - '91' Module(s) have been scanned Scan process 'svchost.exe' - '86' Module(s) have been scanned Scan process 'SLsvc.exe' - '23' Module(s) have been scanned Scan process 'svchost.exe' - '153' Module(s) have been scanned Scan process 'svchost.exe' - '115' Module(s) have been scanned Scan process 'svchost.exe' - '66' Module(s) have been scanned Scan process 'RapportMgmtService.exe' - '68' Module(s) have been scanned Scan process 'svchost.exe' - '54' Module(s) have been scanned Scan process 'svchost.exe' - '35' Module(s) have been scanned Scan process 'svchost.exe' - '40' Module(s) have been scanned Scan process 'lsm.exe' - '22' Module(s) have been scanned Scan process 'winlogon.exe' - '30' Module(s) have been scanned Scan process 'lsass.exe' - '60' Module(s) have been scanned Scan process 'services.exe' - '33' Module(s) have been scanned Scan process 'csrss.exe' - '14' Module(s) have been scanned Scan process 'wininit.exe' - '26' Module(s) have been scanned Scan process 'csrss.exe' - '14' Module(s) have been scanned Scan process 'smss.exe' - '2' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Master boot sector HD1 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Boot sector 'D:\' [INFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '350' files ). Starting the file scan: BEGIN scan in 'C:\' C:\Program Files\7-Zip\Uninstall.exe [WARNING] Insufficient memory. The file was not scanned. C:\Users\Elisa\Downloads\7z465.exe [WARNING] Insufficient memory. The file was not scanned. C:\Windows\System32\drivers\igcmc.sys [DETECTION] Is the TR/Rootkit.Gen Trojan Begin scan in 'D:\' Beginning disinfection: C:\Windows\System32\drivers\igcmc.sys [DETECTION] Is the TR/Rootkit.Gen Trojan [NOTE] The file was moved to the quarantine directory under the name '48757dfe.qua'. End of the scan: Thursday, July 15, 2010 10:46 Used time: 1:14:10 Hour(s) The scan has been done completely. 17360 Scanned directories 274560 Files were scanned 1 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 1 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 274559 Files not concerned 1061 Archives were scanned 2 Warnings 1 Notes 462110 Objects were scanned with rootkit scan 0 Hidden objects were found cheersDownload the GMER Rootkit Scanner. Unzip it to your Desktop. Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised! If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
everything went a bit different from the description, i wasn't asked whether i wanted to perform any scan, so i just checked whether the boxes were all checked/unchecked and then started the scan, which seemed to have finished but again i didn't receive any notice. here is the log: GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-07-16 15:01:42 Windows 6.0.6002 Service Pack 2 Running: gmer.exe; Driver: C:\Users\Elisa\AppData\Local\Temp\uglcapoc.sys ---- System - GMER 1.0.15 ---- SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAllocateVirtualMemory [0xA82F5752] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAlpcConnectPort [0xA82F5388] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAssignProcessToJobObject [0xA82F5440] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwConnectPort [0xA82F5482] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateFile [0xA82F5530] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateProcess [0xA82F5DD8] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateProcessEx [0xA82F5E64] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateThread [0xA82F5EF4] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwDebugActiveProcess [0xA82F5580] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwDuplicateObject [0xA82F55C2] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwLoadDriver [0xA82F5606] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenKey [0xA82F5648] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenSection [0xA82F568A] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenThread [0xA82F56CC] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwProtectVirtualMemory [0xA82F579A] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwRequestWaitReplyPort [0xA82F570E] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwRestoreKey [0xA82F57DC] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwResumeThread [0xA82F5824] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSecureConnectPort [0xA82F58B4] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSetValueKey [0xA82F5866] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSuspendProcess [0xA82F5958] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSystemDebugControl [0xA82F599A] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwTerminateProcess [0xA82F59DC] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwWriteVirtualMemory [0xA82F5A2A] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateThreadEx [0xA82F5F96] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateUserProcess [0xA82F5D68] INT 0x62 ? 854F6BF8 INT 0x72 ? 854F6BF8 INT 0x72 ? 854F6BF8 INT 0x72 ? 854F6BF8 INT 0x82 ? 854F6BF8 INT 0x82 ? 854F6BF8 INT 0x82 ? 854F6BF8 INT 0x82 ? 854F6BF8 INT 0xA2 ? 84606BF8 INT 0xB2 ? 84606BF8 INT 0xB2 ? 84606BF8 INT 0xB2 ? 84606BF8 ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!KeSetEvent + 131 81AEE894 4 Bytes [52, 57, 2F, A8] .text ntkrnlpa.exe!KeSetEvent + 13D 81AEE8A0 4 Bytes [88, 53, 2F, A8] .text ntkrnlpa.exe!KeSetEvent + 191 81AEE8F4 4 Bytes [40, 54, 2F, A8] .text ntkrnlpa.exe!KeSetEvent + 1C1 81AEE924 4 Bytes [82, 54, 2F, A8] .text ntkrnlpa.exe!KeSetEvent + 1D9 81AEE93C 4 Bytes [30, 55, 2F, A8] .text ... ? System32\Drivers\spxo.sys The system cannot find the path specified. ! .text USBPORT.SYS!DllUnload 8C5A341B 5 Bytes JMP 854F61D8 .text au8ydgj3.SYS 8BA35000 22 Bytes [82, 63, A1, 81, 6C, 62, A1, ...] .text au8ydgj3.SYS 8BA35017 181 Bytes [00, 32, B7, 79, 80, 3D, B5, ...] .text au8ydgj3.SYS 8BA350CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, ...] .text au8ydgj3.SYS 8BA350DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...] .text au8ydgj3.SYS 8BA350E7 714 Bytes [00, F0, 0E, 00, 00, 00, 00, ...] .text ... ? \ArcName\multi(0)disk(0)rdisk(0)partition(1)\Windows\system32\drivers\PctWfpFilter.sys The system cannot find the path specified. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 00414A50 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.) .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] USER32.dll!InSendMessageEx + 3B1 76FAE6B0 6 Bytes JMP 0044C7F0 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.) .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] WS2_32.dll!getaddrinfo 77A2418A 5 Bytes JMP 71640022 .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] WS2_32.dll!gethostbyname 77A362D4 5 Bytes JMP 71670022 .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] ntdll.dll!LdrLoadDll 77819390 5 Bytes JMP 00B013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 02187B40 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.) .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] kernel32.dll!SetUnhandledExceptionFilter 76E4A84F 6 Bytes PUSH 71510022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!DdeInitializeW 76FA7921 6 Bytes PUSH 714E0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!RegisterClassExW 76FADA30 6 Bytes PUSH 716E0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!GetMessageW 76FBFEF7 6 Bytes PUSH 71480022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!TranslateMessage 76FC01AD 6 Bytes PUSH 71410022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!GetClipboardData 76FE715A 6 Bytes PUSH 714B0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] GDI32.dll!BitBlt 76F070A6 6 Bytes PUSH 71540022; RET .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 00438CE0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.) .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] WS2_32.dll!getaddrinfo 77A2418A 5 Bytes JMP 71670022 .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] WS2_32.dll!gethostbyname 77A362D4 5 Bytes JMP 716E0022 .text C:\Program Files\Spyware Doctor\pctsTray.exe[3848] kernel32.dll!CreateThread + 1A 76E6C928 4 Bytes CALL 0044B8D9 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806916D6] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80691042] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [80691800] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806910C0] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069113E] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A0E9C] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortNotification] CC358B04 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortUchar] 838BA5AF IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortUlong] 458B38C6 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetPhysicalAddress] A5A5A514 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 100D8BA5 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5F8BA580 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortUchar] 30810889 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortStallExecution] 54771129 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetParentBusType] 10C25D5E IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortRequestCallback] 8B55CC00 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 084D8BEC IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0CF0918B IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortCompleteRequest] 458B0000 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortMoveMemory] 8B108910 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 000CF491 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 04508900 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 053C7980 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortUshort] 560C558B IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortBufferUshort] C6127557 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortInitialize] B18D0502 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetDeviceBase] 00000CF8 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortDeviceStateChange] A508788D ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 71670000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\GDI32.dll [USER32.dll!GetWindowRect] 71450000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ole32.dll [USER32.dll!GetWindowRect] 71450000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowRect] 71450000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WININET.dll [USER32.dll!GetWindowRect] 71450000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3848] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools) IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3848] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8460C1F8 Device \Driver\volmgr \Device\VolMgrControl 846081F8 Device \Driver\usbuhci \Device\USBPDO-0 854F31F8 Device \Driver\sptd \Device\1136032336 spxo.sys Device \Driver\usbuhci \Device\USBPDO-1 854F31F8 Device \Driver\usbehci \Device\USBPDO-2 854E41F8 Device \Driver\usbuhci \Device\USBPDO-3 854F31F8 Device \Driver\usbuhci \Device\USBPDO-4 854F31F8 AttachedDevice \Driver\tdx \Device\Tcp pctgntdi.sys Device \Driver\usbuhci \Device\USBPDO-5 854F31F8 Device \Driver\usbehci \Device\USBPDO-6 854E41F8 Device \Driver\volmgr \Device\HarddiskVolume1 846081F8 Device \Driver\PCI_PNP0319 \Device\00000058 spxo.sys Device \Driver\volmgr \Device\HarddiskVolume2 846081F8 Device \Driver\cdrom \Device\CdRom0 8551E1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8460A1F8 Device \Driver\atapi \Device\Ide\IdePort0 8460A1F8 Device \Driver\atapi \Device\Ide\IdePort1 8460A1F8 Device \Driver\atapi \Device\Ide\IdePort2 8460A1F8 Device \Driver\msahci \Device\Ide\PciIde1Channel0 8460B1F8 Device \Driver\msahci \Device\Ide\PciIde1Channel2 8460B1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 8460A1F8 Device \Driver\cdrom \Device\CdRom1 8551E1F8 Device \Driver\netbt \Device\NetBT_Tcpip_{D1957ABD-6FAC-430A-98F1-B0F3C259C5C7} 85B68500 Device \Driver\netbt \Device\NetBt_Wins_Export 85B68500 Device \Driver\Smb \Device\NetbiosSmb 85C3F1F8 Device \Driver\iScsiPrt \Device\RaidPort0 855771F8 Device \Driver\usbuhci \Device\USBFDO-0 854F31F8 Device \Driver\usbuhci \Device\USBFDO-1 854F31F8 Device \Driver\netbt \Device\NetBT_Tcpip_{0C10FA32-146C-4B41-A940-8A06AA1733CB} 85B68500 Device \Driver\usbehci \Device\USBFDO-2 854E41F8 Device \Driver\usbuhci \Device\USBFDO-3 854F31F8 Device \Driver\usbuhci \Device\USBFDO-4 854F31F8 Device \Driver\usbuhci \Device\USBFDO-5 854F31F8 Device \Driver\usbehci \Device\USBFDO-6 854E41F8 Device \Driver\au8ydgj3 \Device\Scsi\au8ydgj31Port4Path0Target0Lun0 855621F8 Device \Driver\au8ydgj3 \Device\Scsi\au8ydgj31 855621F8 Device \FileSystem\cdfs \Cdfs 855111F8 ---- EOF - GMER 1.0.15 ---- many thanks!Quote malicious software removal tool today alerted me and said it found a Trojan:WinNT/Bubnix.gen!A which it partially removed.What do you mean by "partially removed"? Do you have your OS CD/DVD? If so, 1/ Click the Start button. 2/ From the Start Menu, Click All programs followed by Accessories. 3/ In the Accessories menu, Right Click on the Command Prompt option. 4/ From the drop down menu that appears, Click on the Run as administrator option. 5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc. 6/ In the Command Prompt window, type: sfc /scannow and then press Enter. 7/ A message will appear stating that the system scan will begin. 8/ Be patient because the scan may take some time. 9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue. 10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations. 11/ After the scan has completed, Close the command prompt window. Dear Dave I just wanted to thank you for all your help!!! You definitely got it working again and then I was really busy for a few days and always planning to eventually do all the last things you suggested and never got round to it. In the meantime my laptop entirely broke, but I just wanna thank you for all your efforts. I felt really lucky that there was a forum like this and someone out there who understood all these logs... Thank you!!! You're welcome. I will lock this thread. If you need it opened for any reason, please pm me. |
|
| 343. |
Solve : Blue screen + AVG not working + webcam not working + unknown USB software? |
|
Answer» You're welcome. I will lock this THREAD. If you NEED it re-opened, PLEASE pm me. |
|
| 344. |
Solve : Opening/Saving files kicks me off the internet? |
|
Answer» Yes we have done that many times, waiting for several minutes. Also, every time that we get disconnected after opening or SAVING a file, and use the troubleshooter to get reconnected, it prompts us at the end to unplug the POWER cord, wait 10 seconds and plug it back in. After that is done, we click "CHECK to see if the problem is resolved". That's when it checks the connection and gives me that message about the DEFAULT gateway not being available and the local area connection not having a valid IP address. It always says that the local area connection issue is fixed and that the default gateway issue is still detected. When we unplug that cord, we remove it from the back of the router, but the other end of the cord stays plugged into the power strip under the desk. That's what the technicians from the cable company said to do. Also they have been out several times to check our connection and they say there is no problem. I'm pretty sure they've also tested the router and the modem and said that they were ok too. They've told us that we probably either have a virus or it's a problem in the settings somewhere in the computer. Another thing I forgot to TELL you is that we have a laptop that connects through the same router. The only time it gets disconnected is when this computer gets disconnected first. When we first got this computer (last January) I tried to set it up to be able to share files with the laptop and every time I attempted I was disconnected from this one and then the laptop. I eventually gave up on that.Quote The only time it gets disconnected is when this computer gets disconnected first.This really sounds like a problem with the router. Think about it. The laptop is running well on the router and then you start up your pc and it gets disconnected and, at the same time, your laptop gets disconnected. The router is dropping out but I'm not sure what's causing it. S suspect it's something that was caused when you attempted to swap files. Please try this. Reset Explorer Settings IE I've done that before and I just did it again. It did not fix the problem.Quote I've done that before and I just did it again. It did not fix the problem.Just as I thought. The problem appears to be with the router. You can post a thread in the this forum. Someone there could possibly help you with this problem. Thank you for your help so far.You're welcome. I will lock this thread. If you need it opened, please pm me. |
|
| 345. |
Solve : System Tool 2011? |
|
Answer» C:\Users\McGilvray\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00004ePDF/Exploit.Pidief.PFK.Gen trojanHeather, please run the ESET scan again and fix the problem. How's your computer running now?Sorry for the late reply was UNAVAILABLE for a few days. 1. Is there a way to prevent this from happening in the future?Yes. Make sure your Anti-Virus is kept up-to-date and follow the instructions below. Quote 2. We have an older PC that has Windows XP. Following the instrctions on this site I added an extra firewall but now it seems to be running funny. Should I post as a seperate problem.You should only have one firewall running on your computer. You should disable the Windows firewall. It that doesn't help, please start a new thread in the proper forum, not this one. We should do some cleanup. You can keep SAS and MBAM, if you wish. Update them and run them regularly. To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************************ Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************ Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to USE only one firewall at the same time. ******************************************************* Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Hi, Looks like I have some more work to do. But it will be worth it if this stops things from happening again. Hopefully I can get through it all without too many questions. I do have one question at first glance: Should I download a firewall if the computers that is using the OPERATING system Windows 7 or only for the computer that is using the operating system Windows XP? Thanks, Heather Quote Should I download a firewall if the computers that is using the operating system Windows 7 or only for the computer that is using the operating system Windows XP?You should consider using a Firewall on XP especially if your using your computer for banking and other financial transactions. You will have to research the Firewall on Windows 7 to see if it blocks traffic in both directions. |
|
| 346. |
Solve : Application cannot be executed. The file (insert file).exe is infected.? |
|
Answer» So I just had this happen to me tonight, and I am getting quite annoyed with 50 porn websites come up, a popup asking me to run the antivirus software, and not being able to connect to the internet, or run anything. I looked up on my parents' computer for a fix to this problem, and realized firefox works. So i decided to fix the proxy settings so i can browse the internet on my laptop rather than walk back and forth between rooms. |
|
| 347. |
Solve : Icons and taskbar is missing (winXP)? |
|
Answer» ComboFix 10-12-30.01 - xxx 12/31/2010 9:12.1.2 - x86
Please download TDSSKiller from here and save it to your Desktop.
|
|
| 348. |
Solve : drweb.exe amongst other names? |
Answer»
Still won't let me update Avast. Still getting web page redirects. Most recent redirect was to: hxxp://www.happili.com/vht/innerxy.php?q=Cnn&xy=riva-631 Quote Is this because it is Windows 7? Could be. I don't have Win7 Quote Does not allow me to "check" running processes - it is grayed out. Running SCAN now will post update shortly.This is the first time I've used this canned speech. It's possibly because of Win7 Open HijackThis and select Do a system scan only Place a check mark next to the following entries: (if there) O1 - Hosts: ÿþ127.0.0.1 localhost O1 - Hosts: ::1 localhost Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ****************************************** Ok. Let's try this one. Please download Rooter and Save it to your desktop.
O1 - Hosts: ÿþ127.0.0.1 localhost DoneQuote from: SuperDave on December 28, 2010, 01:44:28 PM Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully ... . Windows 7 Home Edition (6.1.7600) [32_bits] - Intel64 Family 6 Model 23 Stepping 10, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [MpsSvc] RUNNING (state:4) Windows Firewall -> Enabled Windows Defender -> Enabled User Account Control (UAC) -> Enabled . Internet Explorer 8.0.7600.16385 . C:\ [Fixed-NTFS] .. ( Total:451 Go - Free:403 Go ) D:\ [CD_Rom] . Scan : 15:52.48 Path : C:\Users\Gerrit deBorst\Desktop\Rooter.exe User : Gerrit deBorst ( Administrator -> YES ) . ----------------------\\ Processes . Locked [System Process] (0) Locked System (4) ______ ???z??? (264) ______ ???z??? (400) ______ ???z??? (464) ______ ???z??? (480) ______ ???z??? (512) ______ ???z??? (536) ______ ???z??? (544) ______ ???z??? (628) ______ ???z??? (700) ______ ???z??? (788) ______ ???z??? (852) ______ ???z??? (916) ______ ???z??? (964) ______ ???z??? (1000) ______ ???z??? (312) ______ C:\Program Files\Dell\DellDock\DockLogin.exe (1052) ______ ???z??? (1128) ______ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (1212) ______ ???z??? (1312) ______ ???z??? (1336) ______ ???z??? (1588) ______ ???z??? (1620) ______ ???z??? (1632) ______ C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1764) ______ ???z??? (1864) ______ C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (1908) ______ C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (1964) ______ ???z??? (2000) ______ C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (2032) ______ ???z??? (2852) ______ ???z??? (2652) ______ C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (2904) ______ ???z??? (3044) ______ C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe (2960) ______ C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (2676) ______ C:\Program Files\Alwil Software\Avast5\AvastUI.exe (2604) ______ ???z??? (2252) ______ ???z??? (1300) ______ C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (3560) ______ ???z??? (3732) ______ C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_ActiveX.exe (3764) Locked audiodg.exe (3840) ______ ???z??? (4080) ______ ???z??? (1652) ______ ???z??? (3196) ______ C:\Users\Gerrit deBorst\Desktop\Rooter.exe (2320) . ----------------------\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:41094144) \Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:41126400 | Length:15728640000) \Device\Harddisk0\Partition3 (Start_Offset:15769766400 | Length:484337047040) . ----------------------\\ Scheduled Tasks . C:\Windows\Tasks\SA.DAT C:\Windows\Tasks\SCHEDLGU.TXT . ----------------------\\ Registry . . ----------------------\\ Files & Folders . ----------------------\\ Scan completed at 15:52.55 . C:\Rooter$\Rooter_1.txt - (28/12/2010 | 15:52.55) First off I appreciate you taking the time to help me with this - and I can see from the forum you are working on multiple issues at one. I realize that you don't want me to attempt anything to solve the problem, but time is of the essence as my father is returning to Florida and I need to get this done before he leaves. That being the case I have researched the issue and narrowed it down to a bootkit infection specifically rootkit.win32.tdss. I have dowloaded and run Kaspersky TDSSKILLER. This program found the the bootkit infection and removed it. A review of internet explorer appears that the redirect is GONE. I loaded about 20 pages without getting redirected. Additionaly I have researched the AVAST problem with AVAST and found that by changing the connection in the AVAST settings page for Proxy Server to direct connect this resolves my problem. If there is any cleanup you think I should do please let me know. If my actions have caused further problem for you - please accept my apologies and close this thread.I'm glad that you were able to get it cleaned. I would like you to run one last scan, if you please. I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Quote from: SuperDave on December 28, 2010, 04:40:53 PM save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. C:\Users\Gerrit deBorst\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\30d181d3-6c62447emultiple threatsdeleted - quarantined C:\Users\Gerrit deBorst\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\5def9a73-63f50e0cmultiple threatsdeleted - quarantined Ok. That's looks GOOD. Let's cleanup. To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************ Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *************************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Quote from: SuperDave on December 29, 2010, 12:59:25 PM Ok. That's looks good. Let's cleanup. Thanks for all your help!! |
|
| 349. |
Solve : Explore.exe and services.exe virus - Windows XP...!!!? |
|
Answer» SuperDave - |
|
| 350. |
Solve : Deep rooted fake anti-virus software (I think)? |
|
Answer» Let's see what happens once we clean it all up.
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
Purge old temporary files Please download TFC by OldTimer to your desktop
Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
|
|