This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] APPL/ACLSET and nonsense

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've never had a problem like this before.
About 3 days ago my computer started acting slow and weird. I used Avira,Spybot AVG and reset my OS to factory settings 3 times already.
i found a few problems and I thought I licked "it" ,apparently not.
My computer becomes unresponsive after 5 minutes or so.
When I click on an icon or the start menu in the task bar i get nothing..
I can navigate my browser a bit longer then everything else but that becomes unresponsive after a short while too.
But if I Ctrl alt del and click the task manager which takes a few seconds to respond I can operate "normaly" for a short while again.
Computer resources are between 7 and 17 % memory is 40% at times.


My hijackthis file


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:23:56 PM, on 8/1/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Opera\opera.exe
C:\hp\kbd\kbd.exe
C:\Users\Daddy\Desktop\ATF-Cleaner.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\GUARDGUI.EXE
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~2\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

–
End of file - 9515 bytes







mbam-log-2009-08-01 (19-18-51)

Malwarebytes' Anti-Malware 1.39
Database version: 2547
Windows 6.0.6001 Service Pack 1

8/1/2009 7:18:51 PM
mbam-log-2009-08-01 (19-18-51).txt

Scan type: Quick Scan
Objects scanned: 75127
Time elapsed: 2 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Also after running ATF Avira picked this up ..
C:\Program Files (x86)Hewlett-Packard\HP TCS\SetACL.exe
Contains recongnition pattern of the APPL/ACLSET application


thanks

Mike
Hi,

Please do the following

As a Vista user I will require that all the programs I ask you to run, be run by right clicking the icon and selecting Run as Administrator. Otherwise some programs may fail to operate correctly


  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Had to bring up the task manager to get a response again to copy these .




OTL logfile created on: 8/6/2009 12:49:04 AM - Run 1
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Users\Daddy\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.19 Gb Available Physical Memory | 79.68% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 687.65 Gb Total Space | 628.39 Gb Free Space | 91.38% Space Free | Partition Type: NTFS
Drive D: | 10.98 Gb Total Space | 1.04 Gb Free Space | 9.43% Space Free | Partition Type: NTFS
Drive E: | 674.78 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DADDY-PC
Current User Name: Daddy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\hp\kbd\kbd.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Users\Daddy\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV:64bit: - (XAudioService [Auto | Running]) – C:\Windows\SysNative\DRIVERS\xaudio64.exe ()
SRV - (AntiVirSchedulerService [Auto | Running]) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService [Auto | Running]) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (Automatic LiveUpdate Scheduler [Auto | Running]) – c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (ccEvtMgr [Auto | Running]) – c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLTNetCnService [Auto | Running]) – c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (comHost [On_Demand | Stopped]) – c:\Program Files (x86)\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Running]) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GameConsoleService [On_Demand | Stopped]) – C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (HP Health Check Service [Auto | Running]) – c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (KeyIso [On_Demand | Stopped]) – C:\Windows\SysWow64\keyiso.dll (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LiveUpdate [On_Demand | Stopped]) – c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (LiveUpdate Notice [Auto | Running]) – c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (MSDTC [Unknown | Stopped]) – C:\Windows\SysWow64\Msdtc [2006/11/02 06:34:14 | 00,000,000 | —D | M]
SRV - (Netlogon [On_Demand | Stopped]) – C:\Windows\SysWow64\netlogon.dll (Microsoft Corporation)
SRV - (SBSDWSCService [Auto | Running]) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Symantec Core LC [On_Demand | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (vds [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vds.mof ()
SRV - (VSS [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vss.mof ()

========== Driver Services (SafeList) ==========

DRV:64bit: - (avgntflt [Auto | Running]) – C:\Windows\SysNative\DRIVERS\avgntflt.sys ()
DRV:64bit: - (CAXHWBS2 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\CAXHWBS2.sys ()
DRV:64bit: - (COH_Mon [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\COH_Mon.sys ()
DRV:64bit: - (HSF_DP [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\CAX_DP.sys ()
DRV:64bit: - (iaStor [Boot | Running]) – C:\Windows\SysNative\drivers\iastor.sys ()
DRV:64bit: - (igfx [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys ()
DRV:64bit: - (mdmxsdk [Auto | Running]) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys ()
DRV:64bit: - (RTL8169 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:64bit: - (SRTSP [On_Demand | Running]) – C:\Windows\SysNative\Drivers\SRTSP64.SYS ()
DRV:64bit: - (SRTSPL [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\SRTSPL64.SYS ()
DRV:64bit: - (SRTSPX [System | Running]) – C:\Windows\SysNative\Drivers\SRTSPX64.SYS ()
DRV:64bit: - (SYMDNS [On_Demand | Running]) – C:\Windows\SysNative\Drivers\SYMDNS.SYS ()
DRV:64bit: - (SymEvent [On_Demand | Running]) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS ()
DRV:64bit: - (SYMFW [On_Demand | Running]) – C:\Windows\SysNative\Drivers\SYMFW.SYS ()
DRV:64bit: - (SymIM [System | Running]) – C:\Windows\SysNative\DRIVERS\SymIMv.sys ()
DRV:64bit: - (SYMNDISV [On_Demand | Running]) – C:\Windows\SysNative\Drivers\SYMNDISV.SYS ()
DRV:64bit: - (SYMREDRV [On_Demand | Running]) – C:\Windows\SysNative\Drivers\SYMREDRV.SYS ()
DRV:64bit: - (SYMTDI [System | Running]) – C:\Windows\SysNative\Drivers\SYMTDI.SYS ()
DRV:64bit: - (winachsf [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys ()
DRV:64bit: - (XAudio [Auto | Running]) – C:\Windows\SysNative\DRIVERS\xaudio64.sys ()
DRV - (COH_Mon [On_Demand | Stopped]) – C:\Windows\SysWow64\drivers\COH_Mon.inf ()
DRV - (eeCtrl [System | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSvia64 [System | Running]) – C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20090730.002\IDSviA64.sys (Symantec Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\SysWow64\mdmxsdk.dll (Conexant)
DRV - (mpsdrv [On_Demand | Running]) – C:\Windows\SysWow64\Wbem\mpsdrv.mof ()
DRV - (NAVENG [On_Demand | Running]) – C:\ProgramData\Symantec\Definitions\VirusDefs\20090806.023\ENG64.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\ProgramData\Symantec\Definitions\VirusDefs\20090806.023\EX64.SYS (Symantec Corporation)
DRV - (Tcpip [Boot | Running]) – C:\Windows\SysWow64\Wbem\tcpip.mof ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "hotmail.com"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.1

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/01 01:20:25 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/08/03 22:12:48 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/08/03 22:12:41 | 00,000,000 | —D | M]

[2009/08/01 01:47:54 | 00,000,000 | —D | M] – C:\Users\Daddy\AppData\Roaming\mozilla\Extensions
[2009/08/01 01:47:54 | 00,000,000 | —D | M] – C:\Users\Daddy\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/01 01:47:54 | 00,000,000 | —D | M] – C:\Users\Daddy\AppData\Roaming\mozilla\Firefox\Profiles\dafqg1lj.default\extensions
[2009/08/01 01:47:30 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/08/01 01:47:30 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/15 13:30:53 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/07/15 13:30:54 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2008/06/30 13:44:08 | 00,324,976 | —- | M] (Symantec Corporation) – C:\Program Files (x86)\mozilla firefox\components\coFFPlgn.dll
[2009/07/15 13:30:55 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2008/10/14 21:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2009/08/03 22:12:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2009/08/03 22:12:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2009/08/03 22:12:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2009/08/03 22:12:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2009/08/03 22:12:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2009/08/03 22:12:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2009/08/03 22:12:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2009/07/15 11:10:00 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/15 11:10:00 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2009/07/15 11:10:00 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/15 11:10:00 | 00,002,344 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2009/07/15 11:10:00 | 00,002,371 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2009/07/15 11:10:00 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2009/07/15 11:10:00 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe ()
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] File not found
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ccApp] c:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KbdStub.EXE ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.DLL (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2000/09/20 18:55:56 | 00,827,392 | R— | M] () - E:\AUTORUN.EXE – [ CDFS ]
O32 - AutoRun File - [2003/03/13 07:11:46 | 00,000,049 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\{4c22dddb-7e48-11de-8606-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{4c22dddb-7e48-11de-8606-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.now.exe – [2004/04/19 04:22:38 | 00,066,048 | R— | M] (Sold Out Sales & Marketing Ltd.)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/08/06 00:43:57 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Users\Daddy\Desktop\OTL.exe
[2009/08/05 00:38:43 | 00,474,551 | —- | C] () – C:\Users\Daddy\Desktop\SF3675_Authorization_to_Wire_Funds.pdf
[2009/08/05 00:02:46 | 00,227,205 | —- | C] () – C:\Users\Daddy\Desktop\20092010Calendarletter_new_finalCombined.pdf
[2009/08/03 22:12:24 | 00,001,758 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2009/08/03 22:12:13 | 00,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2009/08/03 22:06:03 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Apple Computer
[2009/08/03 22:06:03 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\Apple Computer
[2009/08/03 22:05:49 | 00,001,866 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2009/08/03 22:05:38 | 00,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2009/08/03 22:05:38 | 00,000,000 | —D | C] – C:\Program Files (x86)\Safari
[2009/08/03 22:05:14 | 00,000,000 | —D | C] – C:\Program Files\Bonjour
[2009/08/03 22:05:14 | 00,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2009/08/03 22:05:11 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\Apple
[2009/08/03 22:05:09 | 00,000,000 | —D | C] – C:\ProgramData\Apple
[2009/08/03 22:05:09 | 00,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2009/08/03 19:39:24 | 00,001,919 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/08/03 19:39:18 | 00,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2009/08/03 19:39:04 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/08/02 21:59:39 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\Adobe
[2009/08/02 01:31:11 | 03,766,552 | —- | C] (Hewlett-Packard Development Company, L.P. ) – C:\Users\Daddy\Desktop\sp40966.exe
[2009/08/02 01:29:24 | 00,406,040 | —- | C] () – C:\Windows\SysNative\drivers\iaStor.sys
[2009/08/02 01:27:41 | 00,139,808 | —- | C] (Realtek Semiconductor) – C:\Windows\RTKAUDIOSERVICE.EXE
[2009/08/02 01:26:48 | 06,430,208 | —- | C] (Realtek Semiconductor) – C:\Windows\RAVCpl64.exe
[2009/08/02 01:26:48 | 01,477,272 | —- | C] () – C:\Windows\SysNative\drivers\RTKVHD64.sys
[2009/08/02 01:26:48 | 01,364,480 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlUpd64.exe
[2009/08/02 01:26:48 | 00,797,184 | —- | C] () – C:\Windows\SysNative\RtPgEx64.dll
[2009/08/02 01:26:48 | 00,666,112 | —- | C] () – C:\Windows\SysNative\RTCOM64.dll
[2009/08/02 01:26:48 | 00,598,528 | —- | C] () – C:\Windows\SysNative\RTSnMg64.cpl
[2009/08/02 01:26:48 | 00,368,672 | —- | C] () – C:\Windows\SysNative\RtkApi64.dll
[2009/08/02 01:24:09 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\WinBatch
[2009/08/01 19:12:06 | 00,050,688 | —- | C] (Atribune.org) – C:\Users\Daddy\Desktop\ATF-Cleaner.exe
[2009/08/01 18:21:44 | 00,001,930 | —- | C] () – C:\Users\Daddy\Desktop\HijackThis.lnk
[2009/08/01 18:21:44 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/08/01 18:17:19 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Users\Daddy\Desktop\HJTInstall.exe
[2009/08/01 15:14:55 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Malwarebytes
[2009/08/01 15:14:54 | 00,000,850 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/01 15:14:51 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/08/01 15:14:49 | 00,022,040 | —- | C] () – C:\Windows\SysNative\drivers\mbam.sys
[2009/08/01 15:14:49 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/08/01 15:14:49 | 00,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009/08/01 15:13:34 | 03,775,176 | —- | C] (Malwarebytes Corporation ) – C:\Users\Daddy\Desktop\mbam-setup.exe
[2009/08/01 15:01:59 | 00,265,216 | —- | C] (OldTimer Tools) – C:\Users\Daddy\Desktop\TFC.exe
[2009/08/01 14:49:27 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Opera
[2009/08/01 14:49:27 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\Opera
[2009/08/01 14:49:18 | 00,000,746 | —- | C] () – C:\Users\Public\Desktop\Opera.lnk
[2009/08/01 14:49:16 | 00,000,000 | —D | C] – C:\Program Files (x86)\Opera
[2009/08/01 02:05:34 | 00,001,903 | —- | C] () – C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2009/08/01 02:05:32 | 00,073,048 | —- | C] () – C:\Windows\SysNative\drivers\avgntflt.sys
[2009/08/01 02:05:32 | 00,028,520 | —- | C] (Avira GmbH) – C:\Windows\SysWow64\drivers\ssmdrv.sys
[2009/08/01 02:05:31 | 00,000,000 | —D | C] – C:\ProgramData\Avira
[2009/08/01 02:05:31 | 00,000,000 | —D | C] – C:\Program Files (x86)\Avira
[2009/08/01 02:03:42 | 00,001,099 | —- | C] () – C:\Users\Daddy\Desktop\Spybot - Search & Destroy.lnk
[2009/08/01 02:03:37 | 00,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2009/08/01 02:03:37 | 00,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2009/08/01 01:47:37 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Mozilla
[2009/08/01 01:47:37 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\Mozilla
[2009/08/01 01:47:31 | 00,001,780 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/08/01 01:47:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2009/08/01 01:34:13 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\Hewlett-Packard
[2009/08/01 01:19:02 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Macromedia
[2009/08/01 01:19:01 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Adobe
[2009/08/01 01:18:01 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.tlb
[2009/08/01 01:18:01 | 01,638,912 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2009/08/01 01:18:01 | 00,243,712 | —- | C] () – C:\Windows\SysNative\occache.dll
[2009/08/01 01:18:01 | 00,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2009/08/01 01:18:01 | 00,071,680 | —- | C] () – C:\Windows\SysNative\msfeedsbs.dll
[2009/08/01 01:18:01 | 00,031,744 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2009/08/01 01:18:01 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2009/08/01 01:18:00 | 00,700,928 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2009/08/01 01:18:00 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2009/08/01 01:18:00 | 00,252,416 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2009/08/01 01:18:00 | 00,219,136 | —- | C] () – C:\Windows\SysNative\ieui.dll
[2009/08/01 01:18:00 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2009/08/01 01:18:00 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2009/08/01 01:18:00 | 00,072,192 | —- | C] () – C:\Windows\SysNative\iernonce.dll
[2009/08/01 01:18:00 | 00,070,656 | —- | C] () – C:\Windows\SysNative\ie4uinit.exe
[2009/08/01 01:18:00 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2009/08/01 01:18:00 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2009/08/01 01:18:00 | 00,012,288 | —- | C] () – C:\Windows\SysNative\msfeedssync.exe
[2009/08/01 01:17:59 | 01,484,288 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2009/08/01 01:17:59 | 01,208,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\urlmon.dll
[2009/08/01 01:17:59 | 01,146,880 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2009/08/01 01:17:59 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2009/08/01 01:17:59 | 00,458,240 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2009/08/01 01:17:59 | 00,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2009/08/01 01:17:59 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2009/08/01 01:17:59 | 00,077,312 | —- | C] () – C:\Windows\SysNative\iesetup.dll
[2009/08/01 01:17:59 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2009/08/01 01:17:59 | 00,057,667 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2009/08/01 01:17:59 | 00,057,667 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2009/08/01 01:17:59 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2009/08/01 01:17:58 | 11,067,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieframe.dll
[2009/08/01 01:17:58 | 02,334,208 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2009/08/01 01:17:58 | 01,985,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iertutil.dll
[2009/08/01 01:17:58 | 01,538,560 | —- | C] () – C:\Windows\SysNative\inetcpl.cpl
[2009/08/01 01:17:58 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2009/08/01 01:17:57 | 12,458,496 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2009/08/01 01:17:56 | 09,233,408 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2009/08/01 01:17:56 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.dll
[2009/08/01 01:17:56 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2009/08/01 01:17:55 | 00,162,816 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2009/08/01 01:17:55 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2009/08/01 01:17:55 | 00,132,096 | —- | C] () – C:\Windows\SysNative\iesysprep.dll
[2009/08/01 01:16:04 | 00,223,232 | —- | C] () – C:\Windows\SysNative\msls31.dll
[2009/08/01 01:16:04 | 00,161,792 | —- | C] () – C:\Windows\SysNative\advpack.dll
[2009/08/01 01:16:04 | 00,157,696 | —- | C] () – C:\Windows\SysNative\ieakeng.dll
[2009/08/01 01:16:04 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\advpack.dll
[2009/08/01 01:16:04 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2009/08/01 01:16:04 | 00,088,064 | —- | C] () – C:\Windows\SysNative\admparse.dll
[2009/08/01 01:16:04 | 00,085,504 | —- | C] () – C:\Windows\SysNative\icardie.dll
[2009/08/01 01:16:04 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2009/08/01 01:16:04 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2009/08/01 01:16:04 | 00,022,528 | —- | C] () – C:\Windows\SysNative\corpol.dll
[2009/08/01 01:16:04 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\corpol.dll
[2009/08/01 01:16:03 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msls31.dll
[2009/08/01 01:16:03 | 00,125,952 | —- | C] () – C:\Windows\SysNative\inseng.dll
[2009/08/01 01:16:03 | 00,077,824 | —- | C] () – C:\Windows\SysNative\tdc.ocx
[2009/08/01 01:16:03 | 00,076,288 | —- | C] () – C:\Windows\SysNative\wextract.exe
[2009/08/01 01:16:03 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2009/08/01 01:16:03 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2009/08/01 01:16:03 | 00,055,808 | —- | C] () – C:\Windows\SysNative\licmgr10.dll
[2009/08/01 01:16:03 | 00,052,736 | —- | C] () – C:\Windows\SysNative\imgutil.dll
[2009/08/01 01:16:02 | 00,481,280 | —- | C] () – C:\Windows\SysNative\ieapfltr.dll
[2009/08/01 01:16:02 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2009/08/01 01:16:02 | 00,063,488 | —- | C] () – C:\Windows\SysNative\pngfilt.dll
[2009/08/01 01:16:02 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2009/08/01 01:16:02 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\imgutil.dll
[2009/08/01 01:16:01 | 01,062,912 | —- | C] () – C:\Windows\SysNative\mstime.dll
[2009/08/01 01:16:01 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstime.dll
[2009/08/01 01:16:01 | 00,508,416 | —- | C] () – C:\Windows\SysNative\dxtmsft.dll
[2009/08/01 01:16:01 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtmsft.dll
[2009/08/01 01:16:01 | 00,318,464 | —- | C] () – C:\Windows\SysNative\dxtrans.dll
[2009/08/01 01:16:01 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webcheck.dll
[2009/08/01 01:16:01 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtrans.dll
[2009/08/01 01:16:01 | 00,096,768 | —- | C] () – C:\Windows\SysNative\mshtmled.dll
[2009/08/01 01:16:01 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2009/08/01 01:16:01 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2009/08/01 01:16:01 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2009/08/01 01:16:00 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2009/08/01 01:16:00 | 00,612,864 | —- | C] () – C:\Windows\SysNative\vbscript.dll
[2009/08/01 01:16:00 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\vbscript.dll
[2009/08/01 01:16:00 | 00,304,640 | —- | C] () – C:\Windows\SysNative\webcheck.dll
[2009/08/01 01:16:00 | 00,278,528 | —- | C] () – C:\Windows\SysNative\WinFXDocObj.exe
[2009/08/01 01:16:00 | 00,271,872 | —- | C] () – C:\Windows\SysNative\ieaksie.dll
[2009/08/01 01:16:00 | 00,241,664 | —- | C] () – C:\Windows\SysNative\msrating.dll
[2009/08/01 01:16:00 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2009/08/01 01:16:00 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WinFXDocObj.exe
[2009/08/01 01:16:00 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2009/08/01 01:16:00 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2009/08/01 01:16:00 | 00,163,840 | —- | C] () – C:\Windows\SysNative\ieakui.dll
[2009/08/01 01:16:00 | 00,131,584 | —- | C] () – C:\Windows\SysNative\PDMSetup.exe
[2009/08/01 01:16:00 | 00,129,024 | —- | C] () – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2009/08/01 01:16:00 | 00,128,512 | —- | C] () – C:\Windows\SysNative\SetIEInstalledDate.exe
[2009/08/01 01:16:00 | 00,125,440 | —- | C] () – C:\Windows\SysNative\SetDepNx.exe
[2009/08/01 01:16:00 | 00,041,984 | —- | C] () – C:\Windows\SysNative\mshta.exe
[2009/08/01 01:15:59 | 00,817,664 | —- | C] () – C:\Windows\SysNative\jscript.dll
[2009/08/01 01:15:59 | 00,479,744 | —- | C] () – C:\Windows\SysNative\html.iec
[2009/08/01 01:15:59 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2009/08/01 01:15:59 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2009/08/01 01:15:59 | 00,108,032 | —- | C] () – C:\Windows\SysNative\url.dll
[2009/08/01 01:15:59 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2009/08/01 01:15:59 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2009/08/01 01:15:59 | 00,048,128 | —- | C] () – C:\Windows\SysNative\mshtmler.dll
[2009/08/01 01:15:59 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshta.exe
[2009/08/01 01:15:58 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2009/08/01 01:15:58 | 03,698,584 | —- | C] () – C:\Windows\SysNative\ieapfltr.dat
[2009/08/01 01:15:58 | 00,193,536 | —- | C] () – C:\Windows\SysNative\iexpress.exe
[2009/08/01 01:15:58 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PDMSetup.exe
[2009/08/01 01:15:58 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2009/08/01 01:15:58 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2009/08/01 01:15:58 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetDepNx.exe
[2009/08/01 00:39:19 | 01,666,193 | -H– | C] () – C:\Users\Daddy\AppData\Local\IconCache.db
[2009/08/01 00:20:40 | 00,024,064 | —- | C] () – C:\Windows\SysNative\wsepno.dll
[2009/08/01 00:20:38 | 00,044,544 | —- | C] () – C:\Windows\SysNative\msscb.dll
[2009/08/01 00:20:38 | 00,012,288 | —- | C] () – C:\Windows\SysNative\msshooks.dll
[2009/08/01 00:20:37 | 00,106,605 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/08/01 00:20:37 | 00,106,605 | —- | C] () – C:\Windows\SysNative\StructuredQuerySchema.bin
[2009/08/01 00:20:37 | 00,080,896 | —- | C] () – C:\Windows\SysNative\propdefs.dll
[2009/08/01 00:20:37 | 00,067,072 | —- | C] () – C:\Windows\SysNative\xmlfilter.dll
[2009/08/01 00:20:37 | 00,043,008 | —- | C] () – C:\Windows\SysNative\rtffilt.dll
[2009/08/01 00:20:37 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mimefilt.dll
[2009/08/01 00:20:37 | 00,037,376 | —- | C] () – C:\Windows\SysNative\mimefilt.dll
[2009/08/01 00:20:37 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscb.dll
[2009/08/01 00:20:37 | 00,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009/08/01 00:20:37 | 00,018,904 | —- | C] () – C:\Windows\SysNative\StructuredQuerySchemaTrivial.bin
[2009/08/01 00:20:37 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msshooks.dll
[2009/08/01 00:20:35 | 11,967,524 | —- | C] () – C:\Windows\SysWow64\korwbrkr.lex
[2009/08/01 00:20:35 | 11,967,524 | —- | C] () – C:\Windows\SysNative\korwbrkr.lex
[2009/08/01 00:20:35 | 01,676,800 | —- | C] () – C:\Windows\SysNative\chsbrkr.dll
[2009/08/01 00:20:35 | 01,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\chsbrkr.dll
[2009/08/01 00:20:35 | 00,921,088 | —- | C] () – C:\Windows\SysNative\propsys.dll
[2009/08/01 00:20:35 | 00,754,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\propsys.dll
[2009/08/01 00:20:35 | 00,347,648 | —- | C] () – C:\Windows\SysNative\srchadmin.dll
[2009/08/01 00:20:35 | 00,317,440 | —- | C] () – C:\Windows\SysNative\thawbrkr.dll
[2009/08/01 00:20:35 | 00,316,928 | —- | C] () – C:\Windows\SysNative\msshsq.dll
[2009/08/01 00:20:35 | 00,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\thawbrkr.dll
[2009/08/01 00:20:35 | 00,280,064 | —- | C] () – C:\Windows\SysNative\offfilt.dll
[2009/08/01 00:20:35 | 00,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msshsq.dll
[2009/08/01 00:20:35 | 00,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\offfilt.dll
[2009/08/01 00:20:35 | 00,181,248 | —- | C] () – C:\Windows\SysNative\nlhtml.dll
[2009/08/01 00:20:35 | 00,180,736 | —- | C] () – C:\Windows\SysNative\korwbrkr.dll
[2009/08/01 00:20:35 | 00,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\korwbrkr.dll
[2009/08/01 00:20:35 | 00,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SearchFilterHost.exe
[2009/08/01 00:20:35 | 00,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssitlb.dll
[2009/08/01 00:20:35 | 00,087,552 | —- | C] () – C:\Windows\SysNative\mssitlb.dll
[2009/08/01 00:20:35 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\propdefs.dll
[2009/08/01 00:20:35 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msstrc.dll
[2009/08/01 00:20:35 | 00,040,448 | —- | C] () – C:\Windows\SysNative\mssprxy.dll
[2009/08/01 00:20:35 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtffilt.dll
[2009/08/01 00:20:35 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssprxy.dll
[2009/08/01 00:20:34 | 06,103,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\chtbrkr.dll
[2009/08/01 00:20:34 | 06,100,480 | —- | C] () – C:\Windows\SysNative\chtbrkr.dll
[2009/08/01 00:20:34 | 02,209,792 | —- | C] () – C:\Windows\SysNative\tquery.dll
[2009/08/01 00:20:34 | 02,176,512 | —- | C] () – C:\Windows\SysNative\mssrch.dll
[2009/08/01 00:20:34 | 01,582,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2009/08/01 00:20:34 | 01,418,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2009/08/01 00:20:34 | 00,796,672 | —- | C] () – C:\Windows\SysNative\mssvp.dll
[2009/08/01 00:20:34 | 00,670,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2009/08/01 00:20:34 | 00,598,016 | —- | C] () – C:\Windows\SysNative\SearchIndexer.exe
[2009/08/01 00:20:34 | 00,498,176 | —- | C] () – C:\Windows\SysNative\mssph.dll
[2009/08/01 00:20:34 | 00,439,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SearchIndexer.exe
[2009/08/01 00:20:34 | 00,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2009/08/01 00:20:34 | 00,312,832 | —- | C] () – C:\Windows\SysNative\mssphtb.dll
[2009/08/01 00:20:34 | 00,258,560 | —- | C] () – C:\Windows\SysNative\SearchProtocolHost.exe
[2009/08/01 00:20:34 | 00,203,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssphtb.dll
[2009/08/01 00:20:34 | 00,184,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SearchProtocolHost.exe
[2009/08/01 00:20:34 | 00,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\nlhtml.dll
[2009/08/01 00:20:34 | 00,112,128 | —- | C] () – C:\Windows\SysNative\SearchFilterHost.exe
[2009/08/01 00:20:34 | 00,078,848 | —- | C] () – C:\Windows\SysNative\msstrc.dll
[2009/08/01 00:20:34 | 00,073,728 | —- | C] () – C:\Windows\SysNative\msscntrs.dll
[2009/08/01 00:20:34 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2009/08/01 00:20:34 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xmlfilter.dll
[2009/07/31 23:59:22 | 00,000,000 | —D | C] – C:\Users\Public\Documents\Symantec
[2009/07/31 23:58:48 | 00,025,424 | —- | C] () – C:\Windows\SysNative\drivers\COH_Mon.sys
[2009/07/31 23:58:48 | 00,010,557 | —- | C] () – C:\Windows\SysNative\drivers\COH_Mon.cat
[2009/07/31 23:57:23 | 00,049,160 | —- | C] () – C:\Windows\SysNative\infocardcpl.cpl
[2009/07/31 23:57:23 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\infocardcpl.cpl
[2009/07/31 23:57:20 | 00,052,760 | —- | C] () – C:\Windows\SysNative\PresentationHostProxy.dll
[2009/07/31 23:57:20 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2009/07/31 23:57:20 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardres.dll
[2009/07/31 23:57:20 | 00,011,264 | —- | C] () – C:\Windows\SysNative\icardres.dll
[2009/07/31 23:57:19 | 01,383,936 | —- | C] () – C:\Windows\SysNative\icardagt.exe
[2009/07/31 23:57:19 | 01,168,928 | —- | C] () – C:\Windows\SysNative\PresentationNative_v0300.dll
[2009/07/31 23:57:19 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationNative_v0300.dll
[2009/07/31 23:57:19 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardagt.exe
[2009/07/31 23:57:19 | 00,167,432 | —- | C] () – C:\Windows\SysNative\infocardapi.dll
[2009/07/31 23:57:19 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\infocardapi.dll
[2009/07/31 23:57:14 | 00,126,520 | —- | C] () – C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2009/07/31 23:57:14 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2009/07/31 23:57:12 | 00,357,904 | —- | C] () – C:\Windows\SysNative\PresentationHost.exe
[2009/07/31 23:57:12 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2009/07/31 23:51:50 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2009/07/31 23:51:50 | 00,013,824 | —- | C] () – C:\Windows\SysNative\netfxperf.dll
[2009/07/31 23:51:42 | 00,112,120 | —- | C] () – C:\Windows\SysNative\dfshim.dll
[2009/07/31 23:51:42 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2009/07/31 23:51:35 | 00,406,528 | —- | C] () – C:\Windows\SysNative\mscoree.dll
[2009/07/31 23:51:35 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mscoree.dll
[2009/07/31 23:51:30 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mscorier.dll
[2009/07/31 23:51:30 | 00,158,208 | —- | C] () – C:\Windows\SysNative\mscorier.dll
[2009/07/31 23:51:28 | 00,076,288 | —- | C] () – C:\Windows\SysNative\mscories.dll
[2009/07/31 23:51:27 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mscories.dll
[2009/07/31 23:48:35 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tzres.dll
[2009/07/31 23:48:35 | 00,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2009/07/31 23:43:01 | 00,382,008 | —- | C] () – C:\Windows\SysNative\ci.dll
[2009/07/31 23:43:00 | 00,474,624 | —- | C] () – C:\Windows\SysNative\srcore.dll
[2009/07/31 23:43:00 | 00,339,968 | —- | C] () – C:\Windows\SysNative\rstrui.exe
[2009/07/31 23:43:00 | 00,058,368 | —- | C] () – C:\Windows\SysNative\setbcdlocale.dll
[2009/07/31 23:43:00 | 00,046,592 | —- | C] () – C:\Windows\SysNative\srclient.dll
[2009/07/31 23:43:00 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\srclient.dll
[2009/07/31 23:43:00 | 00,018,944 | —- | C] () – C:\Windows\SysNative\srdelayed.exe
[2009/07/31 23:43:00 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\kbd106n.dll
[2009/07/31 23:43:00 | 00,007,680 | —- | C] () – C:\Windows\SysNative\kbd106n.dll
[2009/07/31 23:42:56 | 01,078,840 | —- | C] () – C:\Windows\SysNative\winload.efi
[2009/07/31 23:42:56 | 01,066,040 | —- | C] () – C:\Windows\SysNative\winload.exe
[2009/07/31 23:42:56 | 00,993,336 | —- | C] () – C:\Windows\SysNative\winresume.efi
[2009/07/31 23:42:56 | 00,982,584 | —- | C] () – C:\Windows\SysNative\winresume.exe
[2009/07/31 23:42:56 | 00,022,072 | —- | C] () – C:\Windows\SysNative\kd1394.dll
[2009/07/31 23:42:33 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Hewlett-Packard
[2009/07/31 23:41:57 | 00,000,558 | —- | C] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Daddy.job
[2009/07/31 23:41:35 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Symantec
[2009/07/31 23:41:23 | 00,558,592 | —- | C] () – C:\Windows\SysNative\EncDec.dll
[2009/07/31 23:41:22 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2009/07/31 23:41:22 | 00,289,792 | —- | C] () – C:\Windows\SysNative\psisrndr.ax
[2009/07/31 23:41:21 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2009/07/31 23:41:20 | 00,375,808 | —- | C] () – C:\Windows\SysNative\psisdecd.dll
[2009/07/31 23:41:20 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2009/07/31 23:41:20 | 00,101,376 | —- | C] () – C:\Windows\SysNative\MSNP.ax
[2009/07/31 23:41:20 | 00,073,216 | —- | C] () – C:\Windows\SysNative\MSDvbNP.ax
[2009/07/31 23:41:17 | 00,227,328 | —- | C] () – C:\Windows\SysNative\mpg2splt.ax
[2009/07/31 23:41:17 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2009/07/31 23:41:17 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2009/07/31 23:41:17 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2009/07/31 23:41:04 | 12,240,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\NlsLexicons0007.dll
[2009/07/31 23:41:04 | 12,240,896 | —- | C] () – C:\Windows\SysNative\NlsLexicons0007.dll
[2009/07/31 23:41:02 | 02,644,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\NlsLexicons0009.dll
[2009/07/31 23:41:02 | 02,644,480 | —- | C] () – C:\Windows\SysNative\NlsLexicons0009.dll
[2009/07/31 23:40:51 | 01,361,920 | —- | C] () – C:\Windows\SysNative\NaturalLanguage6.dll
[2009/07/31 23:40:51 | 00,801,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\NaturalLanguage6.dll
[2009/07/31 23:40:17 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Identities
[2009/07/31 23:39:50 | 04,692,448 | —- | C] () – C:\Windows\SysNative\ntoskrnl.exe
[2009/07/31 23:39:49 | 01,030,656 | —- | C] () – C:\Windows\SysNative\printfilterpipelinesvc.exe
[2009/07/31 23:39:49 | 00,718,336 | —- | C] () – C:\Windows\SysNative\rpcss.dll
[2009/07/31 23:39:48 | 00,231,424 | —- | C] () – C:\Windows\SysNative\sdohlp.dll
[2009/07/31 23:39:48 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sdohlp.dll
[2009/07/31 23:39:48 | 00,163,840 | —- | C] () – C:\Windows\SysNative\iasrecst.dll
[2009/07/31 23:39:48 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iasrecst.dll
[2009/07/31 23:39:48 | 00,075,776 | —- | C] () – C:\Windows\SysNative\iasads.dll
[2009/07/31 23:39:48 | 00,061,440 | —- | C] () – C:\Windows\SysNative\iasdatastore.dll
[2009/07/31 23:39:48 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iasdatastore.dll
[2009/07/31 23:39:48 | 00,036,352 | —- | C] () – C:\Windows\SysNative\printfilterpipelineprxy.dll
[2009/07/31 23:39:47 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iasads.dll
[2009/07/31 23:39:47 | 00,024,576 | —- | C] () – C:\Windows\SysNative\iashost.exe
[2009/07/31 23:39:47 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iashost.exe
[2009/07/31 23:39:41 | 01,926,656 | —- | C] () – C:\Windows\SysNative\gameux.dll
[2009/07/31 23:39:41 | 00,032,256 | —- | C] () – C:\Windows\SysNative\Apphlpdm.dll
[2009/07/31 23:39:41 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Apphlpdm.dll
[2009/07/31 23:39:40 | 04,240,384 | —- | C] (Microsoft) – C:\Windows\SysWow64\GameUXLegacyGDFs.dll
[2009/07/31 23:39:40 | 04,240,384 | —- | C] () – C:\Windows\SysNative\GameUXLegacyGDFs.dll
[2009/07/31 23:39:40 | 01,695,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2009/07/31 23:39:39 | 02,868,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2009/07/31 23:39:38 | 03,547,648 | —- | C] () – C:\Windows\SysNative\mf.dll
[2009/07/31 23:39:38 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\VirtualStore
[2009/07/31 23:39:37 | 02,900,480 | —- | C] () – C:\Windows\SysNative\WMVCORE.DLL
[2009/07/31 23:39:37 | 02,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVCORE.DLL
[2009/07/31 23:39:37 | 01,245,184 | —- | C] () – C:\Windows\SysNative\WMNetMgr.dll
[2009/07/31 23:39:37 | 00,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMNetMgr.dll
[2009/07/31 23:39:36 | 00,112,640 | —- | C] () – C:\Windows\SysNative\logagent.exe
[2009/07/31 23:39:36 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\logagent.exe
[2009/07/31 23:39:30 | 01,691,648 | —- | C] () – C:\Windows\SysNative\lsasrv.dll
[2009/07/31 23:39:30 | 01,208,832 | —- | C] () – C:\Windows\SysNative\kernel32.dll
[2009/07/31 23:39:29 | 00,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\kernel32.dll
[2009/07/31 23:39:29 | 00,094,720 | —- | C] () – C:\Windows\SysNative\secur32.dll
[2009/07/31 23:39:28 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secur32.dll
[2009/07/31 23:39:28 | 00,025,600 | —- | C] () – C:\Windows\SysNative\amxread.dll
[2009/07/31 23:39:28 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\amxread.dll
[2009/07/31 23:39:28 | 00,015,872 | —- | C] () – C:\Windows\SysNative\apilogen.dll
[2009/07/31 23:39:28 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apilogen.dll
[2009/07/31 23:39:23 | 12,897,792 | —- | C] () – C:\Windows\SysNative\shell32.dll
[2009/07/31 23:39:22 | 11,580,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\shell32.dll
[2009/07/31 23:39:19 | 01,729,024 | —- | C] () – C:\Windows\SysNative\msxml6.dll
[2009/07/31 23:39:19 | 01,334,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml6.dll
[2009/07/31 23:39:15 | 01,809,408 | —- | C] () – C:\Windows\SysNative\msxml3.dll
[2009/07/31 23:39:15 | 01,191,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3.dll
[2009/07/31 23:39:11 | 01,421,368 | —- | C] () – C:\Windows\SysNative\drivers\tcpip.sys
[2009/07/31 23:39:11 | 00,094,208 | —- | C] () – C:\Windows\SysNative\drivers\pacer.sys
[2009/07/31 23:39:10 | 00,039,424 | —- | C] () – C:\Windows\SysNative\traffic.dll
[2009/07/31 23:39:10 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\traffic.dll
[2009/07/31 23:39:10 | 00,017,920 | —- | C] () – C:\Windows\SysNative\pacerprf.dll
[2009/07/31 23:39:10 | 00,016,896 | —- | C] () – C:\Windows\SysNative\wshqos.dll
[2009/07/31 23:39:10 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pacerprf.dll
[2009/07/31 23:39:10 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wshqos.dll
[2009/07/31 23:39:09 | 01,280,512 | —- | C] () – C:\Windows\SysNative\rpcrt4.dll
[2009/07/31 23:39:08 | 00,677,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rpcrt4.dll
[2009/07/31 23:39:07 | 00,791,552 | —- | C] () – C:\Windows\SysNative\localspl.dll
[2009/07/31 23:39:07 | 00,636,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\localspl.dll
[2009/07/31 23:39:05 | 00,366,080 | —- | C] () – C:\Windows\SysNative\atmfd.dll
[2009/07/31 23:39:05 | 00,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2009/07/31 23:39:05 | 00,189,440 | —- | C] () – C:\Windows\SysNative\t2embed.dll
[2009/07/31 23:39:05 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2009/07/31 23:39:05 | 00,096,256 | —- | C] () – C:\Windows\SysNative\fontsub.dll
[2009/07/31 23:39:05 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2009/07/31 23:39:05 | 00,048,128 | —- | C] () – C:\Windows\SysNative\atmlib.dll
[2009/07/31 23:39:05 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dciman32.dll
[2009/07/31 23:39:04 | 00,531,456 | —- | C] () – C:\Windows\SysNative\IPSECSVC.DLL
[2009/07/31 23:39:04 | 00,272,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\polstore.dll
[2009/07/31 23:39:04 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\winipsec.dll
[2009/07/31 23:39:04 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\FwRemoteSvr.dll
[2009/07/31 23:39:03 | 01,571,328 | —- | C] () – C:\Windows\SysNative\quartz.dll
[2009/07/31 23:39:03 | 01,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2009/07/31 23:39:02 | 00,361,984 | —- | C] () – C:\Windows\SysNative\es.dll
[2009/07/31 23:39:02 | 00,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\es.dll
[2009/07/31 23:39:00 | 02,742,272 | —- | C] () – C:\Windows\SysNative\win32k.sys
[2009/07/31 23:38:59 | 00,730,112 | —- | C] () – C:\Windows\SysNative\msdtcprx.dll
[2009/07/31 23:38:59 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msdtcprx.dll
[2009/07/31 23:38:59 | 00,048,640 | —- | C] () – C:\Windows\SysNative\xolehlp.dll
[2009/07/31 23:38:59 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xolehlp.dll
[2009/07/31 23:38:55 | 00,660,480 | —- | C] () – C:\Windows\SysNative\win32spl.dll
[2009/07/31 23:38:55 | 00,000,044 | —- | C] () – C:\Windows\System\hpsysdrv.dat
[2009/07/31 23:38:54 | 00,443,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2009/07/31 23:38:53 | 00,334,336 | —- | C] () – C:\Windows\SysNative\schannel.dll
[2009/07/31 23:38:53 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schannel.dll
[2009/07/31 23:38:49 | 00,388,608 | —- | C] () – C:\Windows\SysNative\gdi32.dll
[2009/07/31 23:38:48 | 00,303,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gdi32.dll
[2009/07/31 23:38:45 | 00,451,584 | —- | C] () – C:\Windows\SysNative\drivers\srv.sys
[2009/07/31 23:38:44 | 03,080,704 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/07/31 23:38:44 | 02,927,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2009/07/31 23:38:43 | 00,439,808 | —- | C] () – C:\Windows\SysNative\winhttp.dll
[2009/07/31 23:38:43 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\winhttp.dll
[2009/07/31 23:38:42 | 00,324,608 | —- | C] () – C:\Windows\SysNative\PortableDeviceApi.dll
[2009/07/31 23:38:42 | 00,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceApi.dll
[2009/07/31 23:38:41 | 00,974,848 | —- | C] () – C:\Windows\SysNative\inetcomm.dll
[2009/07/31 23:38:41 | 00,738,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcomm.dll
[2009/07/31 23:38:41 | 00,227,328 | —- | C] () – C:\Windows\SysNative\scrobj.dll
[2009/07/31 23:38:40 | 00,197,632 | —- | C] () – C:\Windows\SysNative\scrrun.dll
[2009/07/31 23:38:40 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\scrobj.dll
[2009/07/31 23:38:40 | 00,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\scrrun.dll
[2009/07/31 23:38:40 | 00,166,912 | —- | C] () – C:\Windows\SysNative\wscript.exe
[2009/07/31 23:38:40 | 00,155,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscript.exe
[2009/07/31 23:38:40 | 00,147,968 | —- | C] () – C:\Windows\SysNative\cscript.exe
[2009/07/31 23:38:40 | 00,144,384 | —- | C] () – C:\Windows\SysNative\wshom.ocx
[2009/07/31 23:38:40 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wshom.ocx
[2009/07/31 23:38:40 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cscript.exe
[2009/07/31 23:38:40 | 00,101,888 | —- | C] () – C:\Windows\SysNative\wshext.dll
[2009/07/31 23:38:40 | 00,090,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wshext.dll
[2009/07/31 23:38:39 | 00,557,056 | —- | C] () – C:\Windows\SysNative\wmpeffects.dll
[2009/07/31 23:38:39 | 00,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmpeffects.dll
[2009/07/31 23:38:39 | 00,140,288 | —- | C] () – C:\Windows\SysNative\drivers\rmcast.sys
[2009/07/31 23:38:39 | 00,017,408 | —- | C] () – C:\Windows\SysNative\wshrm.dll
[2009/07/31 23:38:39 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wshrm.dll
[2009/07/31 23:38:38 | 00,883,200 | —- | C] () – C:\Windows\SysNative\drivers\dxgkrnl.sys
[2009/07/31 23:38:38 | 00,399,872 | —- | C] () – C:\Windows\SysNative\emdmgmt.dll
[2009/07/31 23:38:38 | 00,187,392 | —- | C] () – C:\Windows\SysNative\drivers\nwifi.sys
[2009/07/31 23:38:38 | 00,048,640 | —- | C] () – C:\Windows\SysNative\dataclen.dll
[2009/07/31 23:38:38 | 00,047,104 | —- | C] () – C:\Windows\SysNative\cdd.dll
[2009/07/31 23:38:38 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dataclen.dll
[2009/07/31 23:38:37 | 01,691,648 | —- | C] () – C:\Windows\SysNative\connect.dll
[2009/07/31 23:38:37 | 01,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\connect.dll
[2009/07/31 23:38:37 | 00,272,896 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb10.sys
[2009/07/31 23:38:33 | 00,176,640 | —- | C] () – C:\Windows\SysNative\Faultrep.dll
[2009/07/31 23:38:33 | 00,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Faultrep.dll
[2009/07/31 23:38:33 | 00,120,832 | —- | C] () – C:\Windows\SysNative\wersvc.dll
[2009/07/31 23:34:52 | 00,074,368 | —- | C] () – C:\Users\Daddy\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/07/31 23:32:15 | 00,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2009/07/31 23:31:17 | 00,470,016 | —- | C] () – C:\Windows\SysNative\PhotoMetadataHandler.dll
[2009/07/31 23:31:16 | 00,841,216 | —- | C] () – C:\Windows\SysNative\WindowsCodecs.dll
[2009/07/31 23:31:16 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WindowsCodecs.dll
[2009/07/31 23:31:16 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PhotoMetadataHandler.dll
[2009/07/31 23:31:16 | 00,386,560 | —- | C] () – C:\Windows\SysNative\WindowsCodecsExt.dll
[2009/07/31 23:31:16 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WindowsCodecsExt.dll
[2009/07/31 23:30:57 | 00,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2009/07/31 23:30:22 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\HP TCS
[2009/07/31 23:29:37 | 00,000,000 | —D | C] – C:\ProgramData\Adobe
[2009/07/31 23:29:34 | 00,648,704 | —- | C] () – C:\Windows\SysNative\netapi32.dll
[2009/07/31 23:29:34 | 00,466,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netapi32.dll
[2009/07/31 23:29:27 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2009/07/31 23:29:12 | 00,000,172 | —- | C] () – C:\Users\Public\Desktop\Help and Support.lnk
[2009/07/31 23:28:59 | 00,126,976 | —- | C] () – C:\Windows\SysNative\Imsmudlg.exe
[2009/07/31 23:28:59 | 00,000,000 | —D | C] – C:\Windows\SysNative\ENU
[2009/07/31 23:28:49 | 00,000,000 | —D | C] – C:\Program Files (x86)\Intel
[2009/07/31 23:28:48 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\InstallShield
[2009/07/31 23:28:06 | 00,001,702 | RHS- | C] () – C:\Windows\SysWow64\drivers\103C_HP_CPC_FJ464AAR-ABA a6554f_YC_0Pavi_Q3CW824_E83NAv6PrA4_49_IBenicia_SPEGATRON CORPORATION_V1.01_B5.30_T080905_WUH1_L409_M5110_J750_7Intel_8Core2 Quad Q6600_92.4_#081021_N10EC8168_Z14F12F20_G808629C2.MRK
[2009/07/31 23:28:06 | 00,001,702 | RHS- | C] () – C:\Windows\SysNative\drivers\103C_HP_CPC_FJ464AAR-ABA a6554f_YC_0Pavi_Q3CW824_E83NAv6PrA4_49_IBenicia_SPEGATRON CORPORATION_V1.01_B5.30_T080905_WUH1_L409_M5110_J750_7Intel_8Core2 Quad Q6600_92.4_#081021_N10EC8168_Z14F12F20_G808629C2.MRK
[2009/07/31 23:27:53 | 00,001,368 | —- | C] () – C:\Users\Public\Desktop\Snapfish Photos - First 25 Prints Free.lnk
[2009/07/31 23:26:56 | 00,001,903 | —- | C] () – C:\Users\Public\Desktop\HP Total Care Advisor.lnk
[2009/07/31 23:26:49 | 00,002,153 | —- | C] () – C:\Users\Public\Desktop\eBay.lnk
[2009/07/31 23:26:49 | 00,001,562 | —- | C] () – C:\Users\Public\Desktop\Try Microsoft Office for 60 days.lnk
[2009/07/31 23:26:12 | 00,000,000 | -HSD | C] – C:\Users\Daddy\Documents\My Videos
[2009/07/31 23:26:12 | 00,000,000 | -HSD | C] – C:\Users\Daddy\Documents\My Pictures
[2009/07/31 23:26:12 | 00,000,000 | -HSD | C] – C:\Users\Daddy\Documents\My Music
[2009/07/31 23:26:12 | 00,000,000 | -HSD | C] – C:\Users\Daddy\AppData\Local\Temporary Internet Files
[2009/07/31 23:26:12 | 00,000,000 | -HSD | C] – C:\Users\Daddy\AppData\Local\History
[2009/07/31 23:26:12 | 00,000,000 | -HSD | C] – C:\Users\Daddy\AppData\Local\Application Data
[2009/07/31 23:26:11 | 00,000,000 | –SD | C] – C:\Users\Daddy\AppData\Roaming\Microsoft
[2009/07/31 23:26:11 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Roaming\Media Center Programs
[2009/07/31 23:26:11 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\Temp
[2009/07/31 23:26:11 | 00,000,000 | —D | C] – C:\Users\Daddy\AppData\Local\Microsoft
[2009/07/31 23:23:21 | 02,289,688 | —- | C] () – C:\Windows\SysNative\wuaueng.dll
[2009/07/31 23:23:21 | 01,717,248 | —- | C] () – C:\Windows\SysNative\wucltux.dll
[2009/07/31 23:23:21 | 00,054,296 | —- | C] () – C:\Windows\SysNative\wuauclt.exe
[2009/07/31 23:23:21 | 00,043,032 | —- | C] () – C:\Windows\SysNative\wups2.dll
[2009/07/31 23:23:07 | 00,685,592 | —- | C] () – C:\Windows\SysNative\wuapi.dll
[2009/07/31 23:23:07 | 00,561,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2009/07/31 23:23:07 | 00,093,184 | —- | C] () – C:\Windows\SysNative\wudriver.dll
[2009/07/31 23:23:07 | 00,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2009/07/31 23:23:07 | 00,035,352 | —- | C] () – C:\Windows\SysNative\wups.dll
[2009/07/31 23:23:07 | 00,034,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wups.dll
[2009/07/31 23:22:57 | 00,175,376 | —- | C] () – C:\Windows\SysNative\wuwebv.dll
[2009/07/31 23:22:57 | 00,162,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2009/07/31 23:22:57 | 00,033,792 | —- | C] () – C:\Windows\SysNative\wuapp.exe
[2009/07/31 23:22:57 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\Users\Public\Documents\My Videos
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\Users\Public\Documents\My Pictures
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\Users\Public\Documents\My Music
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\ProgramData\Templates
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\ProgramData\Start Menu
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\ProgramData\Favorites
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\ProgramData\Documents
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\ProgramData\Desktop
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\ProgramData\Application Data
[2009/07/31 23:22:13 | 00,000,000 | -HSD | C] – C:\Documents and Settings
[2009/07/31 20:11:12 | 00,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2009/07/31 20:09:09 | 00,000,000 | -HSD | C] – C:\System Volume Information
[2008/09/02 10:36:55 | 00,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/09/02 10:36:55 | 00,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/01/20 19:50:05 | 00,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 19:49:49 | 00,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2006/11/02 05:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 05:34:27 | 00,000,144 | —- | C] () – C:\Windows\win.ini

========== Files - Modified Within 30 Days ==========

[2009/08/06 00:43:58 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Users\Daddy\Desktop\OTL.exe
[2009/08/06 00:38:58 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/08/05 23:58:06 | 00,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/05 23:58:06 | 00,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/05 00:38:43 | 00,474,551 | —- | M] () – C:\Users\Daddy\Desktop\SF3675_Authorization_to_Wire_Funds.pdf
[2009/08/05 00:02:46 | 00,227,205 | —- | M] () – C:\Users\Daddy\Desktop\20092010Calendarletter_new_finalCombined.pdf
[2009/08/04 21:29:14 | 00,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2009/08/04 21:29:14 | 00,595,446 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2009/08/04 21:29:14 | 00,101,144 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2009/08/04 21:23:49 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/08/04 21:23:00 | 01,666,193 | -H– | M] () – C:\Users\Daddy\AppData\Local\IconCache.db
[2009/08/04 16:57:41 | 00,172,080 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2009/08/04 16:57:41 | 00,010,655 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2009/08/04 16:57:41 | 00,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2009/08/03 22:12:24 | 00,001,758 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2009/08/03 22:05:49 | 00,001,866 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2009/08/03 21:25:37 | 00,000,558 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Daddy.job
[2009/08/03 19:39:24 | 00,001,919 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/08/02 01:26:51 | 00,525,792 | —- | M] (Microsoft Corporation) – C:\Windows\DIFxAPI.dll
[2009/08/01 19:12:06 | 00,050,688 | —- | M] (Atribune.org) – C:\Users\Daddy\Desktop\ATF-Cleaner.exe
[2009/08/01 18:21:44 | 00,001,930 | —- | M] () – C:\Users\Daddy\Desktop\HijackThis.lnk
[2009/08/01 18:21:15 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Users\Daddy\Desktop\HJTInstall.exe
[2009/08/01 15:14:54 | 00,000,850 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/01 15:13:40 | 03,775,176 | —- | M] (Malwarebytes Corporation ) – C:\Users\Daddy\Desktop\mbam-setup.exe
[2009/08/01 15:01:59 | 00,265,216 | —- | M] (OldTimer Tools) – C:\Users\Daddy\Desktop\TFC.exe
[2009/08/01 14:49:18 | 00,000,746 | —- | M] () – C:\Users\Public\Desktop\Opera.lnk
[2009/08/01 02:05:34 | 00,001,903 | —- | M] () – C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2009/08/01 02:03:42 | 00,001,099 | —- | M] () – C:\Users\Daddy\Desktop\Spybot - Search & Destroy.lnk
[2009/08/01 01:47:31 | 00,001,780 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/08/01 00:43:50 | 00,301,288 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2009/07/31 23:38:55 | 00,000,044 | —- | M] () – C:\Windows\System\hpsysdrv.dat
[2009/07/31 23:34:52 | 00,074,368 | —- | M] () – C:\Users\Daddy\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/07/31 23:28:14 | 00,001,702 | RHS- | M] () – C:\Windows\SysWow64\drivers\103C_HP_CPC_FJ464AAR-ABA a6554f_YC_0Pavi_Q3CW824_E83NAv6PrA4_49_IBenicia_SPEGATRON CORPORATION_V1.01_B5.30_T080905_WUH1_L409_M5110_J750_7Intel_8Core2 Quad Q6600_92.4_#081021_N10EC8168_Z14F12F20_G808629C2.MRK
[2009/07/31 23:28:14 | 00,001,702 | RHS- | M] () – C:\Windows\SysNative\drivers\103C_HP_CPC_FJ464AAR-ABA a6554f_YC_0Pavi_Q3CW824_E83NAv6PrA4_49_IBenicia_SPEGATRON CORPORATION_V1.01_B5.30_T080905_WUH1_L409_M5110_J750_7Intel_8Core2 Quad Q6600_92.4_#081021_N10EC8168_Z14F12F20_G808629C2.MRK
[2009/07/31 23:27:53 | 00,001,368 | —- | M] () – C:\Users\Public\Desktop\Snapfish Photos - First 25 Prints Free.lnk
[2009/07/31 23:20:31 | 00,047,092 | —- | M] () – C:\Windows\SysNative\license.rtf
[2009/07/21 15:11:15 | 01,146,880 | —- | M] () – C:\Windows\SysNative\wininet.dll
[2009/07/21 15:11:04 | 01,484,288 | —- | M] () – C:\Windows\SysNative\urlmon.dll
[2009/07/21 15:09:54 | 00,243,712 | —- | M] () – C:\Windows\SysNative\occache.dll
[2009/07/21 15:07:37 | 09,233,408 | —- | M] () – C:\Windows\SysNative\mshtml.dll
[2009/07/21 15:07:34 | 00,700,928 | —- | M] () – C:\Windows\SysNative\msfeeds.dll
[2009/07/21 15:07:34 | 00,071,680 | —- | M] () – C:\Windows\SysNative\msfeedsbs.dll
[2009/07/21 15:06:56 | 00,031,744 | —- | M] () – C:\Windows\SysNative\jsproxy.dll
[2009/07/21 15:06:48 | 01,538,560 | —- | M] () – C:\Windows\SysNative\inetcpl.cpl
[2009/07/21 15:06:31 | 02,334,208 | —- | M] () – C:\Windows\SysNative\iertutil.dll
[2009/07/21 15:06:31 | 00,219,136 | —- | M] () – C:\Windows\SysNative\ieui.dll
[2009/07/21 15:06:31 | 00,132,096 | —- | M] () – C:\Windows\SysNative\iesysprep.dll
[2009/07/21 15:06:31 | 00,077,312 | —- | M] () – C:\Windows\SysNative\iesetup.dll
[2009/07/21 15:06:30 | 12,458,496 | —- | M] () – C:\Windows\SysNative\ieframe.dll
[2009/07/21 15:06:30 | 00,252,416 | —- | M] () – C:\Windows\SysNative\iepeers.dll
[2009/07/21 15:06:30 | 00,072,192 | —- | M] () – C:\Windows\SysNative\iernonce.dll
[2009/07/21 15:06:27 | 00,458,240 | —- | M] () – C:\Windows\SysNative\iedkcs32.dll
[2009/07/21 14:52:28 | 00,915,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2009/07/21 14:52:13 | 01,208,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\urlmon.dll
[2009/07/21 14:50:46 | 00,206,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2009/07/21 14:48:31 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.dll
[2009/07/21 14:48:27 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2009/07/21 14:48:27 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2009/07/21 14:47:47 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2009/07/21 14:47:41 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2009/07/21 14:47:28 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2009/07/21 14:47:28 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2009/07/21 14:47:27 | 01,985,536 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iertutil.dll
[2009/07/21 14:47:27 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2009/07/21 14:47:26 | 11,067,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieframe.dll
[2009/07/21 14:47:26 | 00,184,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2009/07/21 14:47:26 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2009/07/21 14:47:21 | 00,386,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2009/07/21 13:34:53 | 00,162,816 | —- | M] () – C:\Windows\SysNative\ieUnatt.exe
[2009/07/21 13:34:41 | 00,070,656 | —- | M] () – C:\Windows\SysNative\ie4uinit.exe
[2009/07/21 13:34:12 | 00,012,288 | —- | M] () – C:\Windows\SysNative\msfeedssync.exe
[2009/07/21 13:34:00 | 01,638,912 | —- | M] () – C:\Windows\SysNative\mshtml.tlb
[2009/07/21 13:13:58 | 00,133,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2009/07/21 13:13:51 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2009/07/21 13:13:15 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2009/07/21 13:12:49 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.tlb
[2009/07/21 12:09:32 | 00,057,667 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2009/07/21 11:31:43 | 00,057,667 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2009/07/13 13:36:34 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/07/13 13:36:14 | 00,022,040 | —- | M] () – C:\Windows\SysNative\drivers\mbam.sys
[2009/07/07 08:43:32 | 26,410,432 | —- | M] () – C:\Windows\SysNative\mrt.exe

========== LOP Check ==========

[2009/08/03 22:06:03 | 00,000,000 | —D | M] – C:\Users\Daddy\AppData\Roaming
[2006/11/02 08:07:25 | 00,000,000 | —D | M] – C:\Users\Daddy\AppData\Roaming\Media Center Programs
[2009/08/01 14:49:27 | 00,000,000 | —D | M] – C:\Users\Daddy\AppData\Roaming\Opera
[2009/08/02 01:24:09 | 00,000,000 | —D | M] – C:\Users\Daddy\AppData\Roaming\WinBatch
[2009/08/03 21:25:37 | 00,000,558 | —- | M] () – C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Daddy.job
[2009/08/04 21:23:49 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/08/04 21:23:03 | 00,008,580 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
OTL Extras logfile created on: 8/6/2009 12:49:08 AM - Run 1
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Users\Daddy\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.19 Gb Available Physical Memory | 79.68% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 687.65 Gb Total Space | 628.39 Gb Free Space | 91.38% Space Free | Partition Type: NTFS
Drive D: | 10.98 Gb Total Space | 1.04 Gb Free Space | 9.43% Space Free | Partition Type: NTFS
Drive E: | 674.78 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DADDY-PC
Current User Name: Daddy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl[@ = cplfile] – C:\Windows\SysNative\control.exe ()
.hlp[@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html[@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.ini[@ = inifile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js[@ = JSFile] – C:\Windows\SysNative\WScript.exe ()
.jse[@ = JSEFile] – C:\Windows\SysNative\WScript.exe ()
.txt[@ = txtfile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.vbe[@ = VBEFile] – C:\Windows\SysNative\WScript.exe ()
.vbs[@ = VBSFile] – C:\Windows\SysNative\WScript.exe ()
.wsf[@ = WSFFile] – C:\Windows\SysNative\WScript.exe ()
.wsh[@ = WSHFile] – C:\Windows\SysNative\WScript.exe ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5423DACD-5233-4251-9A63-DBC4BC420B70}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9F3CD89F-5A4C-44F5-B49D-D41FADD1F9D7}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{F1C6D7D7-44CB-4611-97E7-6C3A697041A8}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{2B8AD1EE-28D4-42FF-AE4B-856E5862D583}" = ccCommon64
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D75B1A1F-BBEC-4DF2-ACE4-9B166438A621}" = Symantec Real Time Storage Protection Component (x64)
"{D9030EBC-78B1-493F-9172-A8D33598A428}" = SymNet x64
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"{F303C668-7674-484A-8C04-579881C382F8}" = Norton Protection Center
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"OfficeTrial" = Microsoft Office Home and Student 60 day trial

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{2D6ED011-055B-4041-B198-BB903827EBFB}" = Safari
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}" = Component Framework
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{62120008-8E1E-4807-860D-A8B48F8552DB}" = Norton Protection Center
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A2A60894-E3ED-46FE-9A6A-7CF7A87572A0}" = Opera 9.64
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{E0810CC2-4B5B-4439-B1D0-452306AF2D64}" = HP Active Support Library
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton AntiVirus Help
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FDDB69BB-2F9A-4830-A579-ABBB7C5AF9A8}" = muvee autoProducer 6.1
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"HijackThis" = HijackThis 2.0.2
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.1)" = Mozilla Firefox (3.5.1)
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"sp41121" = sp41121
"SymSetup.{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security (Symantec Corporation)
"WildTangent hp Master Uninstall" = My HP Games
"Yahoo! Companion" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/1/2009 3:03:21 AM | Computer Name = Daddy-PC | Source = MsiInstaller | ID = 11935
Description =

Error - 8/1/2009 3:44:57 AM | Computer Name = Daddy-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/1/2009 4:14:55 AM | Computer Name = Daddy-PC | Source = Application Error | ID = 1000
Description = Faulting application SymCUW.exe, version 8.1.0.28, time stamp 0x47c0ba4f,
faulting module MSVCR80.dll, version 8.0.50727.3053, time stamp 0x4889d619, exception
code 0xc0000005, fault offset 0x000149d1, process id 0x1158, application start time
0x01ca127fe1c475b1.

Error - 8/1/2009 4:32:03 AM | Computer Name = Daddy-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/1/2009 5:08:19 AM | Computer Name = Daddy-PC | Source = Application Hang | ID = 1002
Description = The program SpybotSD.exe version 1.6.2.46 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 134c Start Time: 01ca12875f9d27d6 Termination Time: 12

Error - 8/1/2009 6:09:04 PM | Computer Name = Daddy-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/1/2009 6:23:36 PM | Computer Name = Daddy-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/1/2009 9:02:19 PM | Computer Name = Daddy-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 8/1/2009 11:56:08 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/1/2009 11:56:17 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/1/2009 11:56:23 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/1/2009 11:56:31 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/1/2009 11:56:38 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/1/2009 11:56:46 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/1/2009 11:56:53 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/1/2009 11:57:01 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/1/2009 11:57:08 PM | Computer Name = Daddy-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/2/2009 2:06:13 AM | Computer Name = Daddy-PC | Source = W32Time | ID = 39452706
Description = The time service has detected that the system time needs to be changed
by +75590 seconds. The time service will not change the system time by more than
+54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->207.46.197.32:123) is working
properly.


< End of report >
Hi,

I do not see any malware in those logs that could account for your issues.

re: APPL/ACLSET
Setup uses a tool called SetACL for setting write permissions to the mods screenshots / cfg / SAVE directories.
Some antivirus software could warn about possible malware. This is a false positive.

This would appear to be a hardware issue.

64 bit systems still have some stability issues.

Post in our HARDWARE forum and see if they can assist.

Link back to this topic so they can see it is not malware related
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI