This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] False positive virus warning?

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
my daughter had an apparent 'Windows virus warning' whereby a pop-up indicated there was a virus on her laptop and asking whether she wanted to download a virus scanner. I don't have further details since she showed my wife and they seemed to close the window down. My daughter reported this the next day also but again I was not around. I have used her pc and not seen any problems.

In any event I backed up the registry with Erunt, and run Malwarebyte's anti Malware. I have posted the results and wondered if you would please check the logs and let me know if there is anything further I should do.

Many thanks,
Mike

Malwarebytes' Anti-Malware 1.37
Database version: 2224
Windows 6.0.6001 Service Pack 1

03/06/2009 20:42:41
mbam-log-2009-06-03 (20-42-41).txt

Scan type: Quick Scan
Objects scanned: 85020
Time elapsed: 4 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:45:58, on 03/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\HiYo\Bin\HiYo.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-GB\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8454 bytes

Hello Mike at home,
Welcome to What the Tech.
My name is OCD, I will be helping you with your log today.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HijackThis log now, I will post back shortly with instructions.

Hello Mike at home,

  • You may want to print out these instructions for reference prior to proceeding.
  • This solution is specifically tailored for this particular problem, please do not attempt to use this solution on another computer.
  • If you have any questions, or are uncertain about any steps please ask 'before' proceeding.
- - - - - Next - - - - -

Please download ATF Cleaner by Atribune.
Download - http://www.nutnworks.com/downloads/ATF_Cleaner.exe
  • Right-click ATF-Cleaner.exe and select "Run As Administrator" to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

- - - - - Next - - - - -

Please right-click HijackThis and select "Run As Administrator"… to run the program and select Do a System Scan Only

Before proceeding, make sure all programs and browser windows are closed, EXCEPT HijackThis
Place check marks next to the following items:
  • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
  • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
  • R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
  • O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
  • O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
  • O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
Now with all browsers closed, click on Fix Checked, then EXIT the program

- - - - - Next - - - - -
  • Download OTL to your desktop.
  • Please right-click OTL and select "Run As Administrator".. to run the program. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • OTL logs
  • Tell me how your computer is running at the moment.

Thank you for your help. I have carried out your instructions.

1. For ATF Cleaner I was not able to select the Firefox tab - it was greyed out. In any event my daughter tends to use IE.
2. I ran HJT, checked the appropriate boxes but 2 of the items were not removed:

# R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
# R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

No other programmes were running.

Here are the logs from OTL:

OTL logfile created on: 06/06/2009 13:58:20 - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Sarah\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.07% Memory free
4.00 Gb Paging File | 3.28 Gb Available in Paging File | 81.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.37 Gb Total Space | 102.71 Gb Free Space | 74.76% Space Free | Partition Type: NTFS
Drive D: | 11.67 Gb Total Space | 2.05 Gb Free Space | 17.58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 7.47 Gb Total Space | 6.87 Gb Free Space | 91.96% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SARAH-PC
Current User Name: Sarah
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
PRC - C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Hp\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint2K\Apntex.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HiYo\Bin\HiYo.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe ()
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\system32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\mobsync.exe (Microsoft Corporation)
PRC - C:\Users\Sarah\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4Qlb [On_Demand | Stopped]) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GameConsoleService [On_Demand | Stopped]) – C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (getPlus® Helper [On_Demand | Stopped]) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (HP Health Check Service [Auto | Running]) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqwmiex [Auto | Running]) – C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (QPCapSvc [Auto | Running]) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
SRV - (QPSched [Auto | Running]) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\Windows\system32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BCM43XV [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\bcmwl6.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (CnxtHdAudService [On_Demand | Running]) – C:\Windows\system32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (E100B [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HdAudAddService [On_Demand | Stopped]) – C:\Windows\system32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (HpqKbFiltr [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqRemHid [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HSFHWAZL [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iaStor [Boot | Running]) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (iaStorV [Disabled | Stopped]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (NETw3v32 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\NETw3v32.sys (Intel® Corporation)
DRV - (NETw4v32 [On_Demand | Running]) – C:\Windows\system32\DRIVERS\NETw4v32.sys (Intel Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvlddmkm [On_Demand | Running]) – C:\Windows\system32\DRIVERS\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (rimmptsk [Auto | Running]) – C:\Windows\system32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [Auto | Running]) – C:\Windows\system32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [Auto | Running]) – C:\Windows\system32\DRIVERS\rixdptsk.sys (REDC)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (winachsf [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.sys (Conexant Systems, Inc.)
DRV - (yukonwlh [On_Demand | Running]) – C:\Windows\system32\DRIVERS\yk60x86.sys (Marvell)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/06/03 19:34:02 | 00,000,000 | —D | M]


O1 HOSTS File: (611053 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtb19.acecounter.com
O1 - Hosts: 127.0.0.1 gtcc1.acecounter.com
O1 - Hosts: 127.0.0.1 gtp1.acecounter.com #[eTrust.Tracking.Cookie]
O1 - Hosts: 16309 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup (IncrediMail, Ltd.)
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart (NVIDIA Corporation)
O4 - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0" (CyberLink Corp.)
O4 - HKLM..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (Hewlett-Packard Company)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-GB\local\search.html ()
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/06 23:52:59 | 00,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 16:18:54 | 00,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/06 13:52:08 | 00,000,000 | R–D | M]

========== Files/Folders - Created Within 30 Days ==========

[2009/06/06 13:50:52 | 00,501,760 | —- | C] (OldTimer Tools) – C:\Users\Sarah\Desktop\OTL.exe
[2009/06/03 23:32:33 | 00,000,000 | —D | C] – C:\Windows\System32\eu-ES
[2009/06/03 23:32:33 | 00,000,000 | —D | C] – C:\Windows\System32\ca-ES
[2009/06/03 23:32:31 | 00,000,000 | —D | C] – C:\Windows\System32\vi-VN
[2009/06/03 22:34:04 | 00,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2009/06/03 22:33:21 | 12,240,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0007.dll
[2009/06/03 22:33:18 | 03,408,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLsvc.exe
[2009/06/03 22:33:18 | 01,081,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCExt.dll
[2009/06/03 22:33:16 | 02,134,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FunctionDiscoveryFolder.dll
[2009/06/03 22:33:16 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingWizard.exe
[2009/06/03 22:33:14 | 02,644,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0009.dll
[2009/06/03 22:33:12 | 01,480,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2009/06/03 22:33:10 | 01,576,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2009/06/03 22:33:10 | 00,684,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\spsys.sys
[2009/06/03 22:33:09 | 00,779,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/06/03 22:33:08 | 01,257,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/06/03 22:33:08 | 00,928,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scavenge.dll
[2009/06/03 22:33:08 | 00,561,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hdaudbus.sys
[2009/06/03 22:33:08 | 00,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2009/06/03 22:33:08 | 00,518,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2009/06/03 22:33:07 | 02,241,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msi.dll
[2009/06/03 22:33:07 | 00,677,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2fs.dll
[2009/06/03 22:33:06 | 02,499,629 | —- | C] () – C:\Windows\System32\wlan.tmf
[2009/06/03 22:33:06 | 00,968,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz2.dll
[2009/06/03 22:33:06 | 00,558,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmain.dll
[2009/06/03 22:33:06 | 00,476,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2009/06/03 22:33:06 | 00,291,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WscEapPr.dll
[2009/06/03 22:33:05 | 00,619,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/06/03 22:33:04 | 02,868,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2009/06/03 22:33:04 | 01,216,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2009/06/03 22:33:04 | 00,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorShell.dll
[2009/06/03 22:33:03 | 00,978,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmv2clt.dll
[2009/06/03 22:33:03 | 00,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spinstall.exe
[2009/06/03 22:33:03 | 00,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spreview.exe
[2009/06/03 22:33:02 | 00,472,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2009/06/03 22:33:02 | 00,438,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcupdate_GenuineIntel.dll
[2009/06/03 22:33:02 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizui.dll
[2009/06/03 22:32:59 | 11,584,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shell32.dll
[2009/06/03 22:32:57 | 00,670,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2009/06/03 22:32:57 | 00,644,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\p2psvc.dll
[2009/06/03 22:32:57 | 00,621,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localspl.dll
[2009/06/03 22:32:57 | 00,441,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchIndexer.exe
[2009/06/03 22:32:56 | 00,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2VDEC.DLL
[2009/06/03 22:32:56 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2.dll
[2009/06/03 22:32:56 | 00,351,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2009/06/03 22:32:56 | 00,278,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/06/03 22:32:56 | 00,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2009/06/03 22:32:55 | 03,601,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2009/06/03 22:32:55 | 01,459,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esent.dll
[2009/06/03 22:32:55 | 00,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10K.DLL
[2009/06/03 22:32:55 | 00,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairing.dll
[2009/06/03 22:32:55 | 00,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/06/03 22:32:53 | 01,017,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtsvc.dll
[2009/06/03 22:32:53 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2009/06/03 22:32:53 | 00,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sperror.dll
[2009/06/03 22:32:53 | 00,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\korwbrkr.dll
[2009/06/03 22:32:53 | 00,041,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/06/03 22:32:52 | 10,624,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmp.dll
[2009/06/03 22:32:52 | 00,463,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IasMigReader.exe
[2009/06/03 22:32:52 | 00,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2009/06/03 22:32:52 | 00,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2009/06/03 22:32:52 | 00,228,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLC.dll
[2009/06/03 22:32:51 | 02,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2009/06/03 22:32:50 | 01,589,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjet40.dll
[2009/06/03 22:32:50 | 00,407,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MPSSVC.dll
[2009/06/03 22:32:49 | 03,549,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2009/06/03 22:32:49 | 01,381,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Query.dll
[2009/06/03 22:32:49 | 01,336,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml6.dll
[2009/06/03 22:32:48 | 01,078,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diagperf.dll
[2009/06/03 22:32:48 | 00,883,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10.IME
[2009/06/03 22:32:48 | 00,784,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcrt4.dll
[2009/06/03 22:32:48 | 00,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qmgr.dll
[2009/06/03 22:32:48 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexch40.dll
[2009/06/03 22:32:48 | 00,327,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\P2PGraph.dll
[2009/06/03 22:32:47 | 01,316,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ole32.dll
[2009/06/03 22:32:47 | 01,202,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntdll.dll
[2009/06/03 22:32:47 | 01,183,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3.dll
[2009/06/03 22:32:47 | 00,986,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2009/06/03 22:32:47 | 00,301,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srchadmin.dll
[2009/06/03 22:32:46 | 02,092,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfsr.exe
[2009/06/03 22:32:46 | 01,792,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmc.exe
[2009/06/03 22:32:46 | 00,950,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mblctr.exe
[2009/06/03 22:32:46 | 00,466,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\riched20.dll
[2009/06/03 22:32:46 | 00,454,144 | —- | C] (Microsoft) – C:\Windows\System32\IasMigPlugin.dll
[2009/06/03 22:32:46 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/06/03 22:32:46 | 00,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uDWM.dll
[2009/06/03 22:32:45 | 02,034,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/06/03 22:32:45 | 00,897,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2009/06/03 22:32:45 | 00,880,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RacEngn.dll
[2009/06/03 22:32:45 | 00,130,008 | —- | C] () – C:\Windows\System32\systemsf.ebd
[2009/06/03 22:32:45 | 00,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBth.dll
[2009/06/03 22:32:44 | 02,012,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\milcore.dll
[2009/06/03 22:32:44 | 01,112,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2009/06/03 22:32:44 | 00,891,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/06/03 22:32:44 | 00,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchProtocolHost.exe
[2009/06/03 22:32:44 | 00,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spoolss.dll
[2009/06/03 22:32:44 | 00,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorAPI.dll
[2009/06/03 22:32:44 | 00,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchFilterHost.exe
[2009/06/03 22:32:43 | 00,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2009/06/03 22:32:43 | 00,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schedsvc.dll
[2009/06/03 22:32:43 | 00,009,239 | —- | C] () – C:\Windows\System32\spcinstrumentation.man
[2009/06/03 22:32:42 | 00,950,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpedit.dll
[2009/06/03 22:32:42 | 00,406,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvcp60.dll
[2009/06/03 22:32:42 | 00,290,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjtes40.dll
[2009/06/03 22:32:42 | 00,115,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayDriverLib.dll
[2009/06/03 22:32:42 | 00,099,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/06/03 22:32:41 | 03,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSAT.exe
[2009/06/03 22:32:41 | 00,268,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\es.dll
[2009/06/03 22:32:41 | 00,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationSettings.exe
[2009/06/03 22:32:40 | 01,083,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ntfs.sys
[2009/06/03 22:32:40 | 00,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advapi32.dll
[2009/06/03 22:32:40 | 00,710,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Magnify.exe
[2009/06/03 22:32:40 | 00,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstext40.dll
[2009/06/03 22:32:40 | 00,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayServices.dll
[2009/06/03 22:32:39 | 01,209,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comsvcs.dll
[2009/06/03 22:32:39 | 00,454,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxbde40.dll
[2009/06/03 22:32:39 | 00,339,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexcl40.dll
[2009/06/03 22:32:39 | 00,321,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2009/06/03 22:32:39 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/06/03 22:32:39 | 00,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WebClnt.dll
[2009/06/03 22:32:39 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwmi.dll
[2009/06/03 22:32:38 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2009/06/03 22:32:38 | 01,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsAnytimeUpgradeCPL.dll
[2009/06/03 22:32:38 | 01,077,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vssapi.dll
[2009/06/03 22:32:37 | 02,066,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstscax.dll
[2009/06/03 22:32:37 | 01,086,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NetProjW.dll
[2009/06/03 22:32:36 | 00,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propsys.dll
[2009/06/03 22:32:36 | 00,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrepl40.dll
[2009/06/03 22:32:36 | 00,640,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthprops.cpl
[2009/06/03 22:32:36 | 00,576,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpsvc.dll
[2009/06/03 22:32:36 | 00,469,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.dll
[2009/06/03 22:32:36 | 00,323,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/06/03 22:32:36 | 00,205,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eudcedit.exe
[2009/06/03 22:32:36 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/06/03 22:32:36 | 00,102,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/06/03 22:32:35 | 02,926,592 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/06/03 22:32:35 | 01,591,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupapi.dll
[2009/06/03 22:32:35 | 00,978,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\crypt32.dll
[2009/06/03 22:32:35 | 00,550,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcss.dll
[2009/06/03 22:32:35 | 00,442,788 | —- | C] () – C:\Windows\System32\dot3.tmf
[2009/06/03 22:32:35 | 00,368,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mspbde40.dll
[2009/06/03 22:32:34 | 01,788,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d9.dll
[2009/06/03 22:32:34 | 01,135,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2009/06/03 22:32:34 | 00,353,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shlwapi.dll
[2009/06/03 22:32:34 | 00,241,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msltus40.dll
[2009/06/03 22:32:34 | 00,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/06/03 22:32:34 | 00,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/06/03 22:32:34 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\davclnt.dll
[2009/06/03 22:32:34 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorPwdMgr.dll
[2009/06/03 22:32:33 | 01,324,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browseui.dll
[2009/06/03 22:32:33 | 01,053,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtctm.dll
[2009/06/03 22:32:33 | 00,626,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgkrnl.sys
[2009/06/03 22:32:33 | 00,344,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd3x40.dll
[2009/06/03 22:32:33 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\photowiz.dll
[2009/06/03 22:32:33 | 00,250,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtapi.dll
[2009/06/03 22:32:33 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlhtml.dll
[2009/06/03 22:32:32 | 03,662,128 | —- | C] () – C:\Windows\System32\locale.nls
[2009/06/03 22:32:32 | 00,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\user32.dll
[2009/06/03 22:32:31 | 01,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2009/06/03 22:32:31 | 00,614,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2009/06/03 22:32:31 | 00,483,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\samsrv.dll
[2009/06/03 22:32:30 | 00,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/06/03 22:32:30 | 00,582,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCommDlg.dll
[2009/06/03 22:32:30 | 00,563,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaut32.dll
[2009/06/03 22:32:30 | 00,497,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kerberos.dll
[2009/06/03 22:32:30 | 00,443,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32spl.dll
[2009/06/03 22:32:30 | 00,392,170 | —- | C] () – C:\Windows\System32\onex.tmf
[2009/06/03 22:32:30 | 00,165,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WcnNetsh.dll
[2009/06/03 22:32:29 | 03,174,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netshell.dll
[2009/06/03 22:32:29 | 01,730,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apds.dll
[2009/06/03 22:32:29 | 00,438,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IKEEXT.DLL
[2009/06/03 22:32:29 | 00,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/06/03 22:32:29 | 00,225,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rdbss.sys
[2009/06/03 22:32:29 | 00,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msv1_0.dll
[2009/06/03 22:32:29 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\compcln.exe
[2009/06/03 22:32:28 | 00,807,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctf.dll
[2009/06/03 22:32:28 | 00,618,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswstr10.dll
[2009/06/03 22:32:28 | 00,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\emdmgmt.dll
[2009/06/03 22:32:28 | 00,315,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiosrv.dll
[2009/06/03 22:32:28 | 00,223,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2009/06/03 22:32:28 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxdav.sys
[2009/06/03 22:32:28 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xmlfilter.dll
[2009/06/03 22:32:27 | 01,160,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2009/06/03 22:32:27 | 01,055,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\VSSVC.exe
[2009/06/03 22:32:27 | 00,679,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvcrt.dll
[2009/06/03 22:32:27 | 00,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUI.exe
[2009/06/03 22:32:27 | 00,344,698 | —- | C] () – C:\Windows\System32\eaphost.tmf
[2009/06/03 22:32:27 | 00,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QAGENTRT.DLL
[2009/06/03 22:32:27 | 00,297,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gdi32.dll
[2009/06/03 22:32:27 | 00,199,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iphlpsvc.dll
[2009/06/03 22:32:27 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapphost.dll
[2009/06/03 22:32:26 | 00,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlsrv32.dll
[2009/06/03 22:32:26 | 00,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd2x40.dll
[2009/06/03 22:32:26 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBSTOR.SYS
[2009/06/03 22:32:25 | 01,068,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shdocvw.dll
[2009/06/03 22:32:25 | 00,926,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2009/06/03 22:32:25 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbc32.dll
[2009/06/03 22:32:25 | 00,196,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbhub.sys
[2009/06/03 22:32:25 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propdefs.dll
[2009/06/03 22:32:24 | 01,856,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbgeng.dll
[2009/06/03 22:32:24 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtutil.exe
[2009/06/03 22:32:24 | 00,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssitlb.dll
[2009/06/03 22:32:23 | 02,167,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcndmgr.dll
[2009/06/03 22:32:23 | 00,747,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmSvc.dll
[2009/06/03 22:32:23 | 00,311,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\swprv.dll
[2009/06/03 22:32:22 | 00,502,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usp10.dll
[2009/06/03 22:32:22 | 00,385,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vds.exe
[2009/06/03 22:32:22 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\devmgr.dll
[2009/06/03 22:32:22 | 00,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvinst.exe
[2009/06/03 22:32:21 | 00,592,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netlogon.dll
[2009/06/03 22:32:21 | 00,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BFE.DLL
[2009/06/03 22:32:21 | 00,268,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schannel.dll
[2009/06/03 22:32:21 | 00,199,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsldpc.dll
[2009/06/03 22:32:21 | 00,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfp.dll
[2009/06/03 22:32:21 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingProxy.dll
[2009/06/03 22:32:21 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscb.dll
[2009/06/03 22:32:21 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBthProxy.dll
[2009/06/03 22:32:20 | 01,533,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz.dll
[2009/06/03 22:32:20 | 01,382,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVSDECD.DLL
[2009/06/03 22:32:20 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2009/06/03 22:32:20 | 00,485,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\evr.dll
[2009/06/03 22:32:20 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2009/06/03 22:32:20 | 00,355,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2009/06/03 22:32:20 | 00,287,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wldap32.dll
[2009/06/03 22:32:19 | 01,143,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wercon.exe
[2009/06/03 22:32:19 | 00,617,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adtschema.dll
[2009/06/03 22:32:19 | 00,450,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comdlg32.dll
[2009/06/03 22:32:19 | 00,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcncsvc.dll
[2009/06/03 22:32:19 | 00,323,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certcli.dll
[2009/06/03 22:32:19 | 00,279,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\services.exe
[2009/06/03 22:32:19 | 00,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2009/06/03 22:32:19 | 00,180,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msiscsi.sys
[2009/06/03 22:32:19 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quick.ime
[2009/06/03 22:32:19 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qintlgnt.ime
[2009/06/03 22:32:19 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\phon.ime
[2009/06/03 22:32:19 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cintlgnt.ime
[2009/06/03 22:32:19 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chajei.ime
[2009/06/03 22:32:19 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mimefilt.dll
[2009/06/03 22:32:18 | 00,856,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswdat10.dll
[2009/06/03 22:32:18 | 00,799,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2009/06/03 22:32:18 | 00,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/06/03 22:32:18 | 00,396,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsmsnap.dll
[2009/06/03 22:32:18 | 00,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2009/06/03 22:32:18 | 00,222,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\umpnpmgr.dll
[2009/06/03 22:32:18 | 00,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskeng.exe
[2009/06/03 22:32:18 | 00,168,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnsapi.dll
[2009/06/03 22:32:18 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\reg.exe
[2009/06/03 22:32:18 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjter40.dll
[2009/06/03 22:32:18 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtffilt.dll
[2009/06/03 22:32:18 | 00,035,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/06/03 22:32:17 | 00,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2009/06/03 22:32:17 | 00,704,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2009/06/03 22:32:17 | 00,364,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IPSECSVC.DLL
[2009/06/03 22:32:17 | 00,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/06/03 22:32:17 | 00,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\w32time.dll
[2009/06/03 22:32:17 | 00,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2009/06/03 22:32:16 | 00,527,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndis.sys
[2009/06/03 22:32:16 | 00,332,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msihnd.dll
[2009/06/03 22:32:16 | 00,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcrypt.dll
[2009/06/03 22:32:16 | 00,241,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rsaenh.dll
[2009/06/03 22:32:16 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MMDevAPI.dll
[2009/06/03 22:32:16 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2009/06/03 22:32:16 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msstrc.dll
[2009/06/03 22:32:16 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthserv.dll
[2009/06/03 22:32:16 | 00,035,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsWpfWrp.exe
[2009/06/03 22:32:16 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshooks.dll
[2009/06/03 22:32:15 | 00,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcomm.dll
[2009/06/03 22:32:15 | 00,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netapi32.dll
[2009/06/03 22:32:15 | 00,310,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mtxclu.dll
[2009/06/03 22:32:15 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fundisc.dll
[2009/06/03 22:32:15 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptsvc.dll
[2009/06/03 22:32:15 | 00,122,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetpp.dll
[2009/06/03 22:32:15 | 00,093,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/06/03 22:32:15 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hidserv.dll
[2009/06/03 22:32:14 | 00,449,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\termsrv.dll
[2009/06/03 22:32:14 | 00,343,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2009/06/03 22:32:14 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\profsvc.dll
[2009/06/03 22:32:14 | 00,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2009/06/03 22:32:14 | 00,080,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/06/03 22:32:13 | 01,696,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2009/06/03 22:32:13 | 01,020,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdc.dll
[2009/06/03 22:32:13 | 00,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsvcs.dll
[2009/06/03 22:32:13 | 00,208,966 | —- | C] () – C:\Windows\System32\WFP.TMF
[2009/06/03 22:32:13 | 00,149,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pci.sys
[2009/06/03 22:32:13 | 00,125,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Classpnp.sys
[2009/06/03 22:32:13 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi.dll
[2009/06/03 22:32:13 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msiexec.exe
[2009/06/03 22:32:12 | 01,823,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnidui.dll
[2009/06/03 22:32:12 | 01,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chsbrkr.dll
[2009/06/03 22:32:12 | 00,262,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmans.dll
[2009/06/03 22:32:12 | 00,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassdo.dll
[2009/06/03 22:32:12 | 00,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2009/06/03 22:32:12 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Kswdmcap.ax
[2009/06/03 22:32:11 | 00,636,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autofmt.exe
[2009/06/03 22:32:11 | 00,439,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ksecdd.sys
[2009/06/03 22:32:11 | 00,265,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\acpi.sys
[2009/06/03 22:32:11 | 00,245,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\clfs.sys
[2009/06/03 22:32:11 | 00,242,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pdh.dll
[2009/06/03 22:32:11 | 00,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc.dll
[2009/06/03 22:32:11 | 00,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrrun.dll
[2009/06/03 22:32:11 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srv2.sys
[2009/06/03 22:32:11 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spoolsv.exe
[2009/06/03 22:32:11 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wersvc.dll
[2009/06/03 22:32:11 | 00,122,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Storport.sys
[2009/06/03 22:32:11 | 00,109,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ataport.sys
[2009/06/03 22:32:11 | 00,092,918 | —- | C] () – C:\Windows\System32\slmgr.vbs
[2009/06/03 22:32:11 | 00,053,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\termdd.sys
[2009/06/03 22:32:11 | 00,050,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PSHED.DLL
[2009/06/03 22:32:11 | 00,035,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\crashdmp.sys
[2009/06/03 22:32:11 | 00,009,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/06/03 22:32:10 | 01,122,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\appwiz.cpl
[2009/06/03 22:32:10 | 01,107,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pidgenx.dll
[2009/06/03 22:32:10 | 00,757,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroles.dll
[2009/06/03 22:32:10 | 00,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnrollUI.dll
[2009/06/03 22:32:10 | 00,258,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winspool.drv
[2009/06/03 22:32:10 | 00,054,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\partmgr.sys
[2009/06/03 22:32:09 | 02,205,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SyncCenter.dll
[2009/06/03 22:32:09 | 00,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2009/06/03 22:32:09 | 00,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmon.ocx
[2009/06/03 22:32:09 | 00,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winlogon.exe
[2009/06/03 22:32:08 | 00,593,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comuid.dll
[2009/06/03 22:32:08 | 00,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUINotify.dll
[2009/06/03 22:32:08 | 00,048,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mup.sys
[2009/06/03 22:32:07 | 01,502,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certmgr.dll
[2009/06/03 22:32:07 | 00,627,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sethc.exe
[2009/06/03 22:32:07 | 00,347,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2009/06/03 22:32:07 | 00,324,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\untfs.dll
[2009/06/03 22:32:07 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wisptis.exe
[2009/06/03 22:32:07 | 00,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2009/06/03 22:32:07 | 00,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassam.dll
[2009/06/03 22:32:07 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrobj.dll
[2009/06/03 22:32:07 | 00,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spp.dll
[2009/06/03 22:32:07 | 00,053,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\disk.sys
[2009/06/03 22:32:07 | 00,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2009/06/03 22:32:07 | 00,017,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kd1394.dll
[2009/06/03 22:32:06 | 00,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autochk.exe
[2009/06/03 22:32:06 | 00,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imkr80.ime
[2009/06/03 22:32:06 | 00,292,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\volmgrx.sys
[2009/06/03 22:32:06 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2009/06/03 22:32:06 | 00,099,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2009/06/03 22:32:06 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dwm.exe
[2009/06/03 22:32:06 | 00,043,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pciidex.sys
[2009/06/03 22:32:05 | 00,869,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printui.dll
[2009/06/03 22:32:05 | 00,656,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoconv.exe
[2009/06/03 22:32:05 | 00,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2009/06/03 22:32:05 | 00,226,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\volsnap.sys
[2009/06/03 22:32:05 | 00,190,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fltMgr.sys
[2009/06/03 22:32:05 | 00,161,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msrpc.sys
[2009/06/03 22:32:05 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasnap.dll
[2009/06/03 22:32:05 | 00,141,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ecache.sys
[2009/06/03 22:32:04 | 01,541,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\onex.dll
[2009/06/03 22:32:04 | 00,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wow32.dll
[2009/06/03 22:32:04 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscript.exe
[2009/06/03 22:32:04 | 00,130,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basecsp.dll
[2009/06/03 22:32:04 | 00,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\userenv.dll
[2009/06/03 22:32:04 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiodg.exe
[2009/06/03 22:32:04 | 00,027,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Dumpata.sys
[2009/06/03 22:32:04 | 00,017,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdcom.dll
[2009/06/03 22:32:03 | 00,340,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RelMon.dll
[2009/06/03 22:32:03 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswsock.dll
[2009/06/03 22:32:03 | 00,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winmm.dll
[2009/06/03 22:32:03 | 00,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\osk.exe
[2009/06/03 22:32:03 | 00,019,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdusb.dll
[2009/06/03 22:32:03 | 00,019,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\atapi.sys
[2009/06/03 22:32:03 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spcmsg.dll
[2009/06/03 22:32:02 | 00,860,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFaultSecure.exe
[2009/06/03 22:32:02 | 00,612,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2009/06/03 22:32:02 | 00,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2009/06/03 22:32:02 | 00,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\offfilt.dll
[2009/06/03 22:32:02 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netbt.sys
[2009/06/03 22:32:02 | 00,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSCard.dll
[2009/06/03 22:32:02 | 00,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnsrslvr.dll
[2009/06/03 22:32:01 | 00,638,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Utilman.exe
[2009/06/03 22:32:01 | 00,586,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\stobject.dll
[2009/06/03 22:32:01 | 00,230,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskraid.exe
[2009/06/03 22:32:01 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
[2009/06/03 22:32:01 | 00,208,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2009/06/03 22:32:01 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apphelp.dll
[2009/06/03 22:32:01 | 00,152,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2009/06/03 22:32:01 | 00,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2009/06/03 22:32:01 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2009/06/03 22:32:01 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsepno.dll
[2009/06/03 22:32:00 | 00,852,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2009/06/03 22:32:00 | 00,551,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prnntfy.dll
[2009/06/03 22:32:00 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaservc.dll
[2009/06/03 22:32:00 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\http.sys
[2009/06/03 22:32:00 | 00,391,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscms.dll
[2009/06/03 22:32:00 | 00,197,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SndVol.exe
[2009/06/03 22:32:00 | 00,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msnetobj.dll
[2009/06/03 22:32:00 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2009/06/03 22:32:00 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysclass.dll
[2009/06/03 22:32:00 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsmsext.dll
[2009/06/03 22:32:00 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/06/03 22:31:59 | 00,444,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsound.dll
[2009/06/03 22:31:59 | 00,155,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscript.exe
[2009/06/03 22:31:59 | 00,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ulib.dll
[2009/06/03 22:31:59 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2009/06/03 22:31:59 | 00,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/06/03 22:31:58 | 00,971,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptui.dll
[2009/06/03 22:31:58 | 00,759,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsecsnp.dll
[2009/06/03 22:31:58 | 00,514,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansvc.dll
[2009/06/03 22:31:58 | 00,223,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscntfy.dll
[2009/06/03 22:31:58 | 00,181,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpsetup.dll
[2009/06/03 22:31:58 | 00,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IPHLPAPI.DLL
[2009/06/03 22:31:58 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastapi.dll
[2009/06/03 22:31:58 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdProxy.dll
[2009/06/03 22:31:57 | 01,342,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\brcpl.dll
[2009/06/03 22:31:57 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsdyn.dll
[2009/06/03 22:31:57 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlangpui.dll
[2009/06/03 22:31:57 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2009/06/03 22:31:57 | 00,119,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskpart.exe
[2009/06/03 22:31:57 | 00,104,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2009/06/03 22:31:57 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/06/03 22:31:57 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpapi.dll
[2009/06/03 22:31:57 | 00,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashlpr.dll
[2009/06/03 22:31:57 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscsvc.dll
[2009/06/03 22:31:57 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logman.exe
[2009/06/03 22:31:56 | 01,575,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVENCOD.DLL
[2009/06/03 22:31:56 | 00,342,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\zipfldr.dll
[2009/06/03 22:31:56 | 00,286,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasapi32.dll
[2009/06/03 22:31:56 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2009/06/03 22:31:56 | 00,158,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrad.dll
[2009/06/03 22:31:56 | 00,155,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/06/03 22:31:56 | 00,140,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wusa.exe
[2009/06/03 22:31:56 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\regsvc.dll
[2009/06/03 22:31:56 | 00,090,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshext.dll
[2009/06/03 22:31:56 | 00,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\findstr.exe
[2009/06/03 22:31:55 | 02,225,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcenter.dll
[2009/06/03 22:31:55 | 01,580,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpccpl.dll
[2009/06/03 22:31:55 | 00,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wer.dll
[2009/06/03 22:31:55 | 00,825,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdlg.dll
[2009/06/03 22:31:55 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassvcs.dll
[2009/06/03 22:31:54 | 01,152,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themecpl.dll
[2009/06/03 22:31:54 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsnmp32.dll
[2009/06/03 22:31:54 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbehci.sys
[2009/06/03 22:31:53 | 00,777,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcc.dll
[2009/06/03 22:31:53 | 00,714,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2009/06/03 22:31:53 | 00,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scansetting.dll
[2009/06/03 22:31:53 | 00,163,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msutb.dll
[2009/06/03 22:31:53 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshom.ocx
[2009/06/03 22:31:53 | 00,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srvsvc.dll
[2009/06/03 22:31:53 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntmarta.dll
[2009/06/03 22:31:53 | 00,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstlsapi.dll
[2009/06/03 22:31:53 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/06/03 22:31:53 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssprxy.dll
[2009/06/03 22:31:53 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uxsms.dll
[2009/06/03 22:31:53 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsbyuv.dll
[2009/06/03 22:31:52 | 03,072,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkmap.dll
[2009/06/03 22:31:52 | 01,248,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PerfCenterCPL.dll
[2009/06/03 22:31:52 | 00,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercpl.dll
[2009/06/03 22:31:52 | 00,678,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstsc.exe
[2009/06/03 22:31:52 | 00,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2009/06/03 22:31:52 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powrprof.dll
[2009/06/03 22:31:52 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasacct.dll
[2009/06/03 22:31:51 | 01,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2009/06/03 22:31:51 | 01,224,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sud.dll
[2009/06/03 22:31:51 | 00,175,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3svc.dll
[2009/06/03 22:31:51 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authz.dll
[2009/06/03 22:31:51 | 00,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.exe
[2009/06/03 22:31:51 | 00,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanhlp.dll
[2009/06/03 22:31:50 | 02,515,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\accessibilitycpl.dll
[2009/06/03 22:31:50 | 00,842,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\systemcpl.dll
[2009/06/03 22:31:50 | 00,615,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themeui.dll
[2009/06/03 22:31:50 | 00,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pcaui.dll
[2009/06/03 22:31:50 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\sdbus.sys
[2009/06/03 22:31:50 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\samlib.dll
[2009/06/03 22:31:50 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmci.dll
[2009/06/03 22:31:50 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\kbdhid.sys
[2009/06/03 22:31:49 | 01,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanpref.dll
[2009/06/03 22:31:49 | 01,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usercpl.dll
[2009/06/03 22:31:49 | 00,516,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoplay.dll
[2009/06/03 22:31:49 | 00,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2009/06/03 22:31:49 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpchttp.dll
[2009/06/03 22:31:49 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pintlgnt.ime
[2009/06/03 22:31:48 | 00,532,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcao.dll
[2009/06/03 22:31:48 | 00,408,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msinfo32.exe
[2009/06/03 22:31:48 | 00,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsutil.dll
[2009/06/03 22:31:48 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\regapi.dll
[2009/06/03 22:31:47 | 01,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2009/06/03 22:31:47 | 01,102,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmsys.cpl
[2009/06/03 22:31:47 | 00,306,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scesrv.dll
[2009/06/03 22:31:47 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/06/03 22:31:47 | 00,242,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tapisrv.dll
[2009/06/03 22:31:47 | 00,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2009/06/03 22:31:47 | 00,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scksp.dll
[2009/06/03 22:31:47 | 00,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\exfat.sys
[2009/06/03 22:31:47 | 00,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AudioSes.dll
[2009/06/03 22:31:47 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imm32.dll
[2009/06/03 22:31:47 | 00,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleprn.dll
[2009/06/03 22:31:47 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3msm.dll
[2009/06/03 22:31:47 | 00,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpr.dll
[2009/06/03 22:31:47 | 00,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\feclient.dll
[2009/06/03 22:31:47 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rekeywiz.exe
[2009/06/03 22:31:47 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iaspolcy.dll
[2009/06/03 22:31:47 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DeviceEject.exe
[2009/06/03 22:31:47 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscisvif.dll
[2009/06/03 22:31:46 | 01,689,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscui.cpl
[2009/06/03 22:31:46 | 00,642,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasgcw.dll
[2009/06/03 22:31:46 | 00,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FWPUCLNT.DLL
[2009/06/03 22:31:46 | 00,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpui.dll
[2009/06/03 22:31:46 | 00,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2009/06/03 22:31:46 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncryptui.dll
[2009/06/03 22:31:46 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpapimig.exe
[2009/06/03 22:31:46 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasplap.dll
[2009/06/03 22:31:46 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certreq.exe
[2009/06/03 22:31:46 | 00,177,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scecli.dll
[2009/06/03 22:31:46 | 00,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmartcardCredentialProvider.dll
[2009/06/03 22:31:46 | 00,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hdwwiz.exe
[2009/06/03 22:31:46 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSTheme.exe
[2009/06/03 22:31:46 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perfdisk.dll
[2009/06/03 22:31:45 | 00,170,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2009/06/03 22:31:45 | 00,167,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\portcls.sys
[2009/06/03 22:31:45 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpmon.dll
[2009/06/03 22:31:45 | 00,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWSD.dll
[2009/06/03 22:31:45 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPUnattend.exe
[2009/06/03 22:31:45 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmmon32.exe
[2009/06/03 22:31:45 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\whealogr.dll
[2009/06/03 22:31:45 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwinsat.dll
[2009/06/03 22:31:44 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2009/06/03 22:31:44 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD2.sys
[2009/06/03 22:31:44 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD.sys
[2009/06/03 22:31:43 | 01,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSVidCtl.dll
[2009/06/03 22:31:43 | 00,547,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaaut.dll
[2009/06/03 22:31:43 | 00,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmdial32.dll
[2009/06/03 22:31:43 | 00,281,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[2009/06/03 22:31:43 | 00,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unimdm.tsp
[2009/06/03 22:31:43 | 00,275,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SnippingTool.exe
[2009/06/03 22:31:43 | 00,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\afd.sys
[2009/06/03 22:31:43 | 00,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdmaud.drv
[2009/06/03 22:31:43 | 00,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontext.dll
[2009/06/03 22:31:43 | 00,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SCardSvr.dll
[2009/06/03 22:31:43 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conime.exe
[2009/06/03 22:31:43 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys
[2009/06/03 22:31:42 | 02,153,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oobefldr.dll
[2009/06/03 22:31:42 | 00,657,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVXENCD.DLL
[2009/06/03 22:31:42 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shwebsvc.dll
[2009/06/03 22:31:42 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2009/06/03 22:31:42 | 00,259,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasppp.dll
[2009/06/03 22:31:42 | 00,202,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanui.dll
[2009/06/03 22:31:42 | 00,137,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsprop.dll
[2009/06/03 22:31:42 | 00,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tdx.sys
[2009/06/03 22:31:42 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dimsroam.dll
[2009/06/03 22:31:42 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\npfs.sys
[2009/06/03 22:31:42 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPutil.exe
[2009/06/03 22:31:41 | 00,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\modemui.dll
[2009/06/03 22:31:41 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscandui.dll
[2009/06/03 22:31:41 | 00,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmontr.dll
[2009/06/03 22:31:41 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsetup.dll
[2009/06/03 22:31:41 | 00,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pacer.sys
[2009/06/03 22:31:40 | 06,103,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chtbrkr.dll
[2009/06/03 22:31:40 | 00,542,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\blackbox.dll
[2009/06/03 22:31:40 | 00,533,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmsdk.dll
[2009/06/03 22:31:40 | 00,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fastfat.sys
[2009/06/03 22:31:40 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2009/06/03 22:31:40 | 00,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlgpclnt.dll
[2009/06/03 22:31:40 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dataclen.dll
[2009/06/03 22:31:39 | 02,226,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkexplorer.dll
[2009/06/03 22:31:39 | 00,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2009/06/03 22:31:39 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netplwiz.dll
[2009/06/03 22:31:39 | 00,178,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\credui.dll
[2009/06/03 22:31:39 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDMon.dll
[2009/06/03 22:31:39 | 00,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2009/06/03 22:31:39 | 00,064,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\smss.exe
[2009/06/03 22:31:39 | 00,062,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ohci1394.sys
[2009/06/03 22:31:39 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certprop.dll
[2009/06/03 22:31:38 | 00,414,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2009/06/03 22:31:38 | 00,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\thawbrkr.dll
[2009/06/03 22:31:38 | 00,217,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\InkEd.dll
[2009/06/03 22:31:38 | 00,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcsvc.dll
[2009/06/03 22:31:38 | 00,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpresult.exe
[2009/06/03 22:31:38 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2009/06/03 22:31:38 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cipher.exe
[2009/06/03 22:31:38 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2009/06/03 22:31:38 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\watchdog.sys
[2009/06/03 22:31:38 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimtf.dll
[2009/06/03 22:31:38 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ifmon.dll
[2009/06/03 22:31:37 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sendmail.dll
[2009/06/03 22:31:36 | 00,356,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2009/06/03 22:31:36 | 00,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmmgrtn.dll
[2009/06/03 22:31:36 | 00,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\udfs.sys
[2009/06/03 22:31:36 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/06/03 22:31:36 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\softkbd.dll
[2009/06/03 22:31:36 | 00,105,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmsynth.dll
[2009/06/03 22:31:36 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\olepro32.dll
[2009/06/03 22:31:36 | 00,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfui.dll
[2009/06/03 22:31:36 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\smb.sys
[2009/06/03 22:31:36 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2009/06/03 22:31:36 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidusb.sys
[2009/06/03 22:31:35 | 00,200,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\input.dll
[2009/06/03 22:31:35 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLLUA.exe
[2009/06/03 22:31:35 | 00,166,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\puiapi.dll
[2009/06/03 22:31:35 | 00,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mprapi.dll
[2009/06/03 22:31:35 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/06/03 22:31:35 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2009/06/03 22:31:35 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshbth.dll
[2009/06/03 22:31:35 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2009/06/03 22:31:35 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\version.dll
[2009/06/03 22:31:35 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fc.exe
[2009/06/03 22:31:35 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msisip.dll
[2009/06/03 22:31:34 | 00,187,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapp3hst.dll
[2009/06/03 22:31:34 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rdpwd.sys
[2009/06/03 22:31:34 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tintlgnt.ime
[2009/06/03 22:31:34 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndiswan.sys
[2009/06/03 22:31:34 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmusic.dll
[2009/06/03 22:31:34 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2009/06/03 22:31:34 | 00,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdSSDP.dll
[2009/06/03 22:31:34 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rrinstaller.exe
[2009/06/03 22:31:34 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\l2nacp.dll
[2009/06/03 22:31:34 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftp.exe
[2009/06/03 22:31:34 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscapi.dll
[2009/06/03 22:31:34 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/06/03 22:31:34 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjint40.dll
[2009/06/03 22:31:34 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscdll.dll
[2009/06/03 22:31:34 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsCtfMonitor.dll
[2009/06/03 22:31:33 | 00,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2009/06/03 22:31:33 | 00,083,456 | —- | C] (Microsoft) – C:\Windows\System32\SMBHelperClass.dll
[2009/06/03 22:31:33 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWCN.dll
[2009/06/03 22:31:33 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Storprop.dll
[2009/06/03 22:31:33 | 00,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdiag.dll
[2009/06/03 22:31:33 | 00,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3cfg.dll
[2009/06/03 22:31:33 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthci.dll
[2009/06/03 22:31:33 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthudtask.exe
[2009/06/03 22:31:33 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsdchngr.dll
[2009/06/03 22:31:33 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdial.exe
[2009/06/03 22:31:32 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2009/06/03 22:31:32 | 00,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappcfg.dll
[2009/06/03 22:31:32 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rassstp.sys
[2009/06/03 22:31:32 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tscupgrd.exe
[2009/06/03 22:31:32 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipconfig.exe
[2009/06/03 22:31:32 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CHxReadingStringIME.dll
[2009/06/03 22:31:31 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2009/06/03 22:31:31 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappgnui.dll
[2009/06/03 22:31:31 | 00,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nslookup.exe
[2009/06/03 22:31:31 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdeploy.dll
[2009/06/03 22:31:31 | 00,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcinst.dll
[2009/06/03 22:31:31 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hbaapi.dll
[2009/06/03 22:31:31 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkitemfactory.dll
[2009/06/03 22:31:31 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidclass.sys
[2009/06/03 22:31:31 | 00,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ocsetup.exe
[2009/06/03 22:31:31 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FwRemoteSvr.dll
[2009/06/03 22:31:31 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfpmp.exe
[2009/06/03 22:31:31 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcico.dll
[2009/06/03 22:31:30 | 00,148,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\nwifi.sys
[2009/06/03 22:31:30 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dfsc.sys
[2009/06/03 22:31:30 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PNPXAssoc.dll
[2009/06/03 22:31:30 | 00,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\cdrom.sys
[2009/06/03 22:31:30 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2009/06/03 22:31:30 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cbsra.exe
[2009/06/03 22:31:30 | 00,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2009/06/03 22:31:30 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msacm32.drv
[2009/06/03 22:31:30 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpupdate.exe
[2009/06/03 22:31:29 | 00,046,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrstub.exe
[2009/06/03 22:31:29 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsigd.dll
[2009/06/03 22:31:29 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NcdProp.dll
[2009/06/03 22:31:29 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdmdbg.dll
[2009/06/03 22:31:29 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsilog.dll
[2009/06/03 22:31:28 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxg.sys
[2009/06/03 22:31:28 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcconf.dll
[2009/06/03 22:31:28 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrnr.dll
[2009/06/03 22:31:28 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2009/06/03 22:31:28 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\midimap.dll
[2009/06/03 22:31:28 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetppui.dll
[2009/06/03 22:31:28 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2009/06/03 22:31:28 | 00,009,212 | —- | C] () – C:\Windows\System32\RacUR.xml
[2009/06/03 22:31:27 | 08,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2009/06/03 22:31:27 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\bridge.sys
[2009/06/03 22:31:27 | 00,052,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\stream.sys
[2009/06/03 22:31:27 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\raspppoe.sys
[2009/06/03 22:31:27 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2009/06/03 22:31:27 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2009/06/03 22:31:27 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2009/06/03 22:31:27 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2009/06/03 22:31:27 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2009/06/03 22:31:22 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\f3ahvoas.dll
[2009/06/03 22:31:22 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimsg.dll
[2009/06/03 22:31:22 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mferror.dll
[2009/06/03 22:31:19 | 00,000,153 | —- | C] () – C:\Windows\System32\RacUREx.xml
[2009/06/03 22:31:08 | 00,705,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmiEngine.dll
[2009/06/03 22:31:05 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdscore.dll
[2009/06/03 22:31:05 | 00,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PkgMgr.exe
[2009/06/03 22:30:59 | 00,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvstore.dll
[2009/06/03 21:52:34 | 00,000,000 | —D | C] – C:\Users\Sarah\Documents\hosts[1]
[2009/06/03 21:04:28 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/06/03 21:04:27 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/06/03 21:04:26 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/06/03 21:04:26 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/06/03 21:04:26 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/06/03 21:04:26 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/06/03 21:04:26 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/06/03 21:04:26 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/06/03 21:04:26 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/06/03 21:04:26 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/06/03 21:04:26 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/06/03 21:04:26 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/06/03 21:04:25 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/06/03 21:04:25 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/06/03 21:04:25 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/06/03 21:04:25 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/06/03 21:04:25 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/06/03 21:04:25 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/06/03 21:04:25 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/06/03 21:04:25 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/06/03 21:04:25 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/06/03 21:04:25 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/06/03 21:04:25 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/06/03 21:04:24 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/06/03 21:04:24 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/06/03 21:04:24 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/06/03 21:04:24 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/06/03 21:04:24 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/06/03 21:04:24 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/06/03 21:04:24 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/06/03 21:04:24 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/06/03 21:04:24 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/06/03 21:04:23 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/06/03 21:04:23 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/06/03 21:04:23 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/06/03 21:04:23 | 00,391,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/06/03 21:04:23 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/06/03 21:04:23 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/06/03 21:04:22 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/06/03 21:04:22 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/06/03 21:04:22 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/06/03 21:04:22 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/06/03 21:04:22 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/06/03 21:04:22 | 00,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/06/03 21:04:22 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/06/03 21:04:22 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/06/03 21:04:22 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/06/03 21:04:22 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/06/03 21:04:22 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/06/03 21:04:22 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/06/03 21:04:21 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/06/03 21:04:21 | 01,206,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/06/03 21:04:21 | 00,914,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/06/03 21:04:20 | 11,063,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/06/03 21:04:20 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/06/03 20:45:46 | 00,001,874 | —- | C] () – C:\Users\Sarah\Desktop\HijackThis.lnk
[2009/06/03 20:45:45 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/06/03 20:37:01 | 00,000,000 | —D | C] – C:\Users\Sarah\AppData\Roaming\Malwarebytes
[2009/06/03 20:37:00 | 00,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/03 20:36:57 | 00,040,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/06/03 20:36:56 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/06/03 20:36:56 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/06/03 20:36:56 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/03 19:24:41 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/06/03 19:03:49 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/06/03 19:03:11 | 00,000,733 | —- | C] () – C:\Users\Sarah\Desktop\NTREGOPT.lnk
[2009/06/03 19:03:10 | 00,000,714 | —- | C] () – C:\Users\Sarah\Desktop\ERUNT.lnk
[2009/06/03 19:03:06 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/06/01 16:26:28 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/05/25 08:44:33 | 00,011,374 | —- | C] () – C:\Users\Sarah\Documents\Lookin for a hero.docx
[2009/05/13 16:45:57 | 00,090,624 | —- | C] () – C:\Users\Sarah\Documents\daddy b day card.pub
[2009/05/08 19:25:23 | 00,084,480 | —- | C] () – C:\Users\Sarah\Documents\katie noel birthday card.pub
[2009/05/08 18:17:59 | 00,126,464 | —- | C] () – C:\Users\Sarah\Documents\Katie noels b day card.pub
[2009/05/07 18:15:20 | 00,213,305 | —- | C] () – C:\Users\Sarah\Documents\London Zoo English homework.docx
[2009/05/07 18:14:44 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonBJ
[2006/11/02 13:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:25:21 | 00,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 11:23:31 | 00,000,219 | —- | C] () – C:\Windows\win.ini
[2006/11/02 11:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 08:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== Files - Modified Within 30 Days ==========

[2009/06/06 13:53:17 | 00,694,964 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/06/06 13:53:17 | 00,603,282 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/06/06 13:53:17 | 00,106,696 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/06/06 13:50:54 | 00,501,760 | —- | M] (OldTimer Tools) – C:\Users\Sarah\Desktop\OTL.exe
[2009/06/06 13:50:40 | 00,027,335 | —- | M] () – C:\Users\Sarah\AppData\Roaming\nvModes.001
[2009/06/06 13:49:57 | 00,000,163 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2009/06/06 13:48:39 | 36,849,169 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2009/06/06 13:48:39 | 00,065,017 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2009/06/06 13:46:49 | 00,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/06/06 13:46:49 | 00,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/06/06 13:46:47 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/06/06 13:46:41 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/06/06 13:46:04 | 21,457,71520 | -HS- | M] () – C:\hiberfil.sys
[2009/06/03 23:38:04 | 00,407,424 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/06/03 22:03:35 | 00,000,521 | —- | M] () – C:\Users\Sarah\Documents\My Sharing Folders.lnk
[2009/06/03 21:08:17 | 00,000,219 | —- | M] () – C:\Windows\win.ini
[2009/06/03 20:45:46 | 00,001,874 | —- | M] () – C:\Users\Sarah\Desktop\HijackThis.lnk
[2009/06/03 20:37:00 | 00,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/03 19:03:11 | 00,000,733 | —- | M] () – C:\Users\Sarah\Desktop\NTREGOPT.lnk
[2009/06/03 19:03:10 | 00,000,714 | —- | M] () – C:\Users\Sarah\Desktop\ERUNT.lnk
[2009/06/03 18:59:40 | 00,001,670 | —- | M] () – C:\Users\Sarah\Desktop\CCleaner.lnk
[2009/06/03 18:54:00 | 00,027,335 | —- | M] () – C:\Users\Sarah\AppData\Roaming\nvModes.dat
[2009/05/26 13:20:08 | 00,040,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/05/25 08:44:34 | 00,011,374 | —- | M] () – C:\Users\Sarah\Documents\Lookin for a hero.docx
[2009/05/22 19:42:03 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2009/05/22 19:42:03 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2009/05/22 19:42:03 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2009/05/22 19:42:00 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2009/05/13 16:45:59 | 00,090,624 | —- | M] () – C:\Users\Sarah\Documents\daddy b day card.pub
[2009/05/08 20:00:05 | 00,084,480 | —- | M] () – C:\Users\Sarah\Documents\katie noel birthday card.pub
[2009/05/08 18:18:01 | 00,126,464 | —- | M] () – C:\Users\Sarah\Documents\Katie noels b day card.pub
[2009/05/07 18:15:24 | 00,213,305 | —- | M] () – C:\Users\Sarah\Documents\London Zoo English homework.docx
[2009/05/07 18:13:38 | 00,024,416 | —- | M] () – C:\Users\Sarah\Documents\London Zoo Englinsh homework.docx

========== LOP Check ==========

[2009/06/03 20:37:01 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming
[2009/05/06 17:43:12 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\Adobe
[2008/12/25 17:09:54 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\CyberLink
[2008/11/19 12:49:11 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\Hewlett-Packard
[2009/02/14 19:14:27 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\HiYo
[2008/12/25 17:09:54 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\HP
[2008/11/19 12:47:59 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\Identities
[2008/11/19 11:37:51 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\Macromedia
[2008/12/26 18:30:43 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\Magic Academy
[2009/06/03 20:37:01 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\Malwarebytes
[2006/11/02 13:37:34 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\Media Center Programs
[2009/05/04 11:45:36 | 00,000,000 | –SD | M] – C:\Users\Sarah\AppData\Roaming\Microsoft
[2008/11/24 17:27:19 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\OpenOffice.org
[2008/11/19 12:48:34 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\Symantec
[2008/12/25 20:52:28 | 00,000,000 | —D | M] – C:\Users\Sarah\AppData\Roaming\WildTangent
[2009/06/06 13:46:47 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/06/04 00:58:18 | 00,032,648 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========

< End of report >



OTL Extras logfile created on: 06/06/2009 13:58:20 - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Sarah\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.07% Memory free
4.00 Gb Paging File | 3.28 Gb Available in Paging File | 81.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.37 Gb Total Space | 102.71 Gb Free Space | 74.76% Space Free | Partition Type: NTFS
Drive D: | 11.67 Gb Total Space | 2.05 Gb Free Space | 17.58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 7.47 Gb Total Space | 6.87 Gb Free Space | 91.96% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SARAH-PC
Current User Name: Sarah
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
Reg Error: Unknown registry data type File not found
Reg Error: Unknown registry data type File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-3455024616-2670954171-3149420496-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 5
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"DisableNotifications" = 0
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile
"DisableNotifications" = 0
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========

{D8CE2A58-3257-4A06-BE11-CCBB68711814} = LPORT=6004 | PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\OUTLOOK.EXE |
{EE99367B-C761-4AEE-BA22-AE2FD579482E} = LPORT=1900 | PROTOCOL=17 | DIR=IN | APP=SVCHOST.EXE | SVC=SSDPSRV |
{FD346095-42FD-409D-8E52-CDE208539043} = LPORT=2869 | PROTOCOL=6 | DIR=IN | APP=SYSTEM |

========== Vista Active Application Exception List ==========

{1ABE8237-A447-4E25-BAA5-EB9407ECF4F7} = DIR=IN | APP=C:\PROGRAM FILES\HP\QUICKPLAY\QPSERVICE.EXE |
{1E69BF33-F361-4A61-8349-B3BDD4021730} = DIR=IN | APP=C:\PROGRAM FILES\HP\QUICKPLAY\QP.EXE |
{264FBC35-6544-435B-B12E-BC6A98EFFC9B} = DIR=IN | APP=C:\PROGRAM FILES\AVG\AVG8\AVGUPD.EXE |
{88772F07-C588-414B-B533-E414BA384747} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\COMMON FILES\AOL\LOADER\AOLLOAD.EXE |
{B5CACFB7-CE06-4B11-80F6-5172000CE3E8} = DIR=IN | APP=C:\PROGRAM FILES\CYBERLINK\POWERDIRECTOR\PDR.EXE |
{C1D52C03-36A5-4350-9DBA-9BAFA75B4503} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\COMMON FILES\AOL\LOADER\AOLLOAD.EXE |
{CF830900-D87C-4AEC-B278-ADDBECF87913} = DIR=IN | APP=C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE |
{E78997A3-3443-4BA7-B026-CCFE65B1EC20} = DIR=IN | APP=C:\PROGRAM FILES\AVG\AVG8\AVGEMC.EXE |
{FE7C3D37-C96D-400D-AAC2-B2B670E7A85A} = DIR=IN | APP=C:\PROGRAM FILES\MSN MESSENGER\LIVECALL.EXE |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{546A0B92-34FF-4796-A39A-4842FAF0B70E}" = ESU for Microsoft Vista
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{8F3A13FC-DFDA-4001-A6C3-030495A1E66E}" = HiYo
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUSR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUSR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUSR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUSR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUSR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B53620C0-3A83-4F50-A7AB-175DB64C1CE3}" = HP User Guides 0090
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{F7F3B252-E772-48AA-93EB-7964BC326067}" = MSCU for Microsoft Vista
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"AOL Toolbar" = AOL Toolbar 5.0
"AVG8Uninstall" = AVG Free 8.5
"CCleaner" = CCleaner (remove only)
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ERUNT_is1" = ERUNT 1.1j
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HijackThis" = HijackThis 2.0.2
"HiYo" = HiYo
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers
"PROPLUSR" = Microsoft Office Professional Plus 2007
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = HP Games

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 05/05/2009 04:44:12 | Computer Name = Sarah-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6001.18226, time stamp
0x49ac95d6, faulting module Flash9d.ocx, version 9.0.47.0, time stamp 0x466daac0,
exception code 0xc0000005, fault offset 0x000fee6f, process id 0x13d4, application
start time 0x01c9cd5b9101de9e.

Error - 05/05/2009 04:55:03 | Computer Name = Sarah-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6001.18226, time stamp
0x49ac95d6, faulting module Flash9d.ocx, version 9.0.47.0, time stamp 0x466daac0,
exception code 0xc0000005, fault offset 0x000fee6f, process id 0xaa4, application
start time 0x01c9cd5dada95eee.

Error - 08/05/2009 12:38:49 | Computer Name = Sarah-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6001.18226, time stamp
0x49ac95d6, faulting module Flash9d.ocx, version 9.0.47.0, time stamp 0x466daac0,
exception code 0xc0000005, fault offset 0x000e173c, process id 0xa80, application
start time 0x01c9cffa3fb2e7ea.

Error - 17/05/2009 06:19:48 | Computer Name = Sarah-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6001.18226, time stamp
0x49ac95d6, faulting module Flash9d.ocx, version 9.0.47.0, time stamp 0x466daac0,
exception code 0xc0000005, fault offset 0x000e173c, process id 0x1ec, application
start time 0x01c9d6d813c40a9c.

Error - 17/05/2009 06:20:18 | Computer Name = Sarah-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6001.18226, time stamp
0x49ac95d6, faulting module Flash9d.ocx, version 9.0.47.0, time stamp 0x466daac0,
exception code 0xc0000005, fault offset 0x000e173c, process id 0x348, application
start time 0x01c9d6d9051d2acc.

Error - 17/05/2009 06:22:31 | Computer Name = Sarah-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6001.18226, time stamp
0x49ac95d6, faulting module Flash9d.ocx, version 9.0.47.0, time stamp 0x466daac0,
exception code 0xc0000005, fault offset 0x000fee6f, process id 0x159c, application
start time 0x01c9d6d9167a347c.

Error - 22/05/2009 14:39:32 | Computer Name = Sarah-PC | Source = VSS | ID = 8194
Description =

Error - 22/05/2009 14:42:27 | Computer Name = Sarah-PC | Source = VSS | ID = 8194
Description =

Error - 22/05/2009 15:00:55 | Computer Name = Sarah-PC | Source = Application Hang | ID = 1002
Description = The program msnmsgr.exe version 8.1.178.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: de8 Start Time: 01c9db0cfb70b056 Termination Time: 85

Error - 27/05/2009 10:47:22 | Computer Name = Sarah-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6001.18226, time stamp
0x49ac95d6, faulting module Flash9d.ocx, version 9.0.47.0, time stamp 0x466daac0,
exception code 0xc0000005, fault offset 0x000fee6f, process id 0x1274, application
start time 0x01c9ded88dd7907e.


========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


Thank you for your help.

Regards,
Mike

Mike at home,

Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:

  • Java™ 6 Update 2
  • Java™ 6 Update 7
  • Viewpoint / Viewpoint Media Player
Select each one of the programs, then select remove.
(if the program is not listed don't be alarmed, just continue with the list)

Exit the Control Panel when finished.

- - - - - Next - - - - -

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
    O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{3248F0A8-6813-11D6-A77B-00B0D0160020}"=-
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}"=-
    "ViewpointMediaPlayer"=-
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time )
  • Tell me how your computer is running at the moment.

Hi OCD, The log file is as follows: ========== OTL ========== Process explorer.exe killed successfully! HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully! HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Security Risk Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully! Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\{3248F0A8-6813-11D6-A77B-00B0D0160020} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3248F0A8-6813-11D6-A77B-00B0D0160020}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\{3248F0A8-6813-11D6-A77B-00B0D0160070} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3248F0A8-6813-11D6-A77B-00B0D0160070}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\ViewpointMediaPlayer not found. ========== COMMANDS ========== User's Temp folder emptied. User's Internet Explorer cache folder emptied. User's Temporary Internet Files folder emptied. Windows Temp folder emptied. Temp folders emptied. Explorer started successfully OTL by OldTimer - Version 2.1.1.0 log created on 06072009_190237 As far as I can tell, the computer seems to be working ok. Regards, Mike

Mike at home,

Please run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ESET log.txt
  • New HijackThis log
  • Tell me how your computer is running at the moment.

OCD,

logs are below:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=6
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.5863
# api_version=3.0.2
# EOSSerial=e31eb6fc42811648ba80975fe18d1d79
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-06-08 06:25:42
# local_time=2009-06-08 07:25:42 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1026 61 83 100 14678191221972
# compatibility_mode=5889 61 66 100 437572234974158
# scanned=173930
# found=0
# cleaned=0
# scan_time=4883




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:38:13, on 08/06/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\HiYo\Bin\HiYo.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-GB\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8230 bytes



Again, many thanks for your assistance.

Regards,
Mike

Mike at home,

Let's try and remove these two (2) entries once more. Please disable your Windows Defender first as this may be stopping us from completing our task.

  • Click Start >> Programs >> Right Click Windows Defender and select "Run As Administrator",or launch from the system tray icon.
  • Click on Tools & Settings >> Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start >> Control Panel >> Security >> Windows Defender, at the bottom of the Window Defenders page uncheck
    under Administrator Options "use Windows Defender" and then Save.
(When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)

- - - - - Next - - - - -

Run HijackThis and select Do a System Scan Only

Before proceeding, make sure all programs and browser windows are closed, EXCEPT HijackThis
Place check marks next to the following items:
  • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
  • R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
Now with all browsers closed, click on Fix Checked, then EXIT the program

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • New HijackThis log
  • Tell me how your computer is running at the moment.

Hi,
followed instructions, here is the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:40:26, on 09/06/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\HiYo\Bin\HiYo.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-GB\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8147 bytes


Many thanks,
Mike

Mike at home,

Congratulations, your log is clean! We have a few items to address before we get to the "All Clean Speech"

Let's re-enable your Windows Defender.

Please re-enable your Windows Defender first as this may be stopping us from completing our task.

  • Click Start >> Programs >> Right Click Windows Defender and select "Run As Administrator",or launch from the system tray icon.
  • Click on Tools & Settings >> Options.
  • Under Real-time protection options, check the "Real-time protection" check box.
  • Click Save.
  • Go to Start >> Control Panel >> Security >> Windows Defender, at the bottom of the Window Defenders page check
    under Administrator Options "use Windows Defender" and then Save.
- - - - - Next - - - - -

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
- - - - - Next - - - - -

I strongly reccomend changing your Firewall to one that provides better protection than the Windows Firewall you are currently using.
Here are a few FREE ones:
  • Please download one (1) of the firewalls below, but do not install it just yet.
  • After you have downloaded the new firewall, disable the Windows firewall.
  • Then install the newly selected firewall.
Firewall:
- - - - - Next - - - - -

Here comes the "All Clean Speech"

Now that your log is clean, you need to set a new clean System Restore Point

Create a new Restore Point
  • Click on the Start button to open your Start Menu.
  • Click on the Control Panel menu option.
  • Click on the System and Maintenance menu option.
  • Click on the System menu option.
  • Click on System Protection in the left-hand task list.
  • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
  • Type in a title for the manual restore point and press the Create button.
  • Close the System window after you have been advised that the procedure has been successfully completed.
- - - - - Next - - - - -

Clear your existing system restore points except for the new clean restore point you just created:
  • Go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Next to System Restore click Clean up
  • This will remove all restore points except the new one you just created.
- - - - - Next - - - - -

Delete the Contents of the Temporary Internet Files Folder:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
  • Click OK
- - - - - Next - - - - -

Automatic Updates:

The easiest way to ensure you don't miss any of the critical Windows Updates is to set your computer up to receive Automatic Updates.
To set your computer up for Automatic Updates please do the following:
  • Click Start, and then click Control Panel.
  • Depending on which Control Panel view you use, Classic or Category, do one of the following:
  • Click System, and then click the Automatic Updates tab.
  • Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
  • Select Automatic and choose a frequency and time that's convenient for you to get the updates.
  • Click Apply, then OK
  • Close the Control Panel.
- - - - - Next - - - - -

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Simple and easy ways to keep your computer safe and secure on the Internet

Alternate Browsers - If you are currently using Internet Explorer you might want to consider changing over to Firefox.
Firefox is one of the most popular alternate browsers. - Mozilla Firefox

Update your AntiVirus Software - You are using AVG8 as your anti virus software. It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - You are using Windows Firewall. I cannot stress how important it is that you keep the Firewall on your computer active at all times. Without a firewall your computer is susceptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that
aren't actually innocent at all. Using IE-SPYAD to help block unwanted sites and activities

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer always has the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Update all security programs regularly - Make sure you update all the programs regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.

Remember to have only one (1) Firewall and one (1) Anti-Virus program running at any one time.

I would also suggest you read "So how did I get infected in the first place"?: by Tony Klein

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI