HeyItsRey
Topic Starter
Hello whatthetech forums. I'm here because I've tried everything I could think of, my problem is still persistant, and because a friend directed me here. I'll try to explain my problem the best that I can…
Well when I start up my internet explorer I get a blank window (attached), and when I close that window my internet explorer works like it normally would. That is, untill I brouse a few webpages. Then my internet explorer pull up a window that says "windows explorer has stopped working…" and then "windows explorer is restarting…" and it restarts and brings up that blank window again.
At first I thought the problem was just internet explorer, but on firefox it does the same thing: brouse a few pages, quits and restarts. I honestly don't know what the problem is. I did at least two full scans with my avast (no viruses each time) and I've tried defragmentizing my computer, and neither of those helped me. And so, I have come here for ask for help, it would be greatly appreciated
Here are my logs to help. Also if it helps any I'm using windows vista home premium.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/21 16:41
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================
Drivers
——————-
Name:
Image Path:
Address: 0x8E9C6000 Size: 65536 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name:
Image Path:
Address: 0x8E9D6000 Size: 172032 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: bowser
Image Path: \FileSystem\bowser
Address: 0x9A889000 Size: 102400 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: downloads[1].sys
Image Path: C:\Windows\system32\drivers\downloads[1].sys
Address: 0xBB3A9000 Size: 49152 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8ED0B000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8ED00000 Size: 45056 File Visible: No Signed: -
Status: -
Name: HTTP
Image Path: \Driver\HTTP
Address: 0x9A801000 Size: 438272 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: mpsdrv
Image Path: \Driver\mpsdrv
Address: 0x9A8A2000 Size: 86016 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: MRxDAV
Image Path: \FileSystem\MRxDAV
Address: 0x9A8B7000 Size: 131072 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: mrxsmb
Image Path: \FileSystem\mrxsmb
Address: 0x9A8D7000 Size: 126976 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: mrxsmb20
Image Path: \FileSystem\mrxsmb20
Address: 0x9A92F000 Size: 98304 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: PEAUTH
Image Path: \Driver\PEAUTH
Address: 0x9AC02000 Size: 909312 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: srv2
Image Path: \FileSystem\srv2
Address: 0x9A947000 Size: 159744 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: srvnet
Image Path: \FileSystem\srvnet
Address: 0x9A86C000 Size: 118784 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: •楬散獮䥥㵤笢扢㈸昴愵攭㜰ⴵㄴ㘱愭戴ⴱ㈵挹㡥挶㌹㘱≽砠汭獮猺㵸產湲洺数㩧灭来ㄲ
Image Path: •楬散獮䥥㵤笢扢㈸昴愵攭㜰ⴵㄴ㘱愭戴ⴱ㈵挹㡥挶㌹㘱≽砠汭獮猺㵸產湲洺数㩧灭来ㄲ
Address: 0x9ACE0000 Size: 40960 File Visible: No Signed: -
Status: Hidden from the Windows API!
Name: 䱍⼲䱓瘯∲砠汭獮琺㵭栢瑴㩰⼯睷業牣獯景潣⽭剄⽍牘䱍⼲䵔瘯∲㰾㩲楴汴㹥楗摮睯⡳䵔
Image Path: 䱍⼲䱓瘯∲砠汭獮琺㵭栢瑴㩰⼯睷業牣獯景潣⽭剄⽍牘䱍⼲䵔瘯∲㰾㩲楴汴㹥楗摮睯⡳䵔
Address: 0x9ACEA000 Size: 49152 File Visible: No Signed: -
Status: Hidden from the Windows API!
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1268 Status: Locked to the Windows API!
SSDT
——————-
#: 013 Function Name: NtAlertResumeThread
Status: Hooked by "" at address 0x87017310
#: 014 Function Name: NtAlertThread
Status: Hooked by "" at address 0x870173f0
#: 018 Function Name: NtAllocateVirtualMemory
Status: Hooked by "" at address 0x870134a0
#: 054 Function Name: NtConnectPort
Status: Hooked by "" at address 0x86ec23a0
#: 067 Function Name: NtCreateMutant
Status: Hooked by "" at address 0x87017070
#: 078 Function Name: NtCreateThread
Status: Hooked by "" at address 0x870146a0
#: 147 Function Name: NtFreeVirtualMemory
Status: Hooked by "" at address 0x870132f0
#: 156 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "" at address 0x87017150
#: 158 Function Name: NtImpersonateThread
Status: Hooked by "" at address 0x87017230
#: 177 Function Name: NtMapViewOfSection
Status: Hooked by "" at address 0x87f52810
#: 184 Function Name: NtOpenEvent
Status: Hooked by "" at address 0x87016f48
#: 195 Function Name: NtOpenProcessToken
Status: Hooked by "" at address 0x870145e0
#: 202 Function Name: NtOpenThreadToken
Status: Hooked by "" at address 0x87014fd0
#: 282 Function Name: NtResumeThread
Status: Hooked by "" at address 0x87f38440
#: 289 Function Name: NtSetContextThread
Status: Hooked by "" at address 0x87014f10
#: 305 Function Name: NtSetInformationProcess
Status: Hooked by "" at address 0x87f52670
#: 306 Function Name: NtSetInformationThread
Status: Hooked by "" at address 0x87014e30
#: 330 Function Name: NtSuspendProcess
Status: Hooked by "" at address 0x87016e68
#: 331 Function Name: NtSuspendThread
Status: Hooked by "" at address 0x87014c70
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "" at address 0x87017ac0
#: 335 Function Name: NtTerminateThread
Status: Hooked by "" at address 0x87014d50
#: 348 Function Name: NtUnmapViewOfSection
Status: Hooked by "" at address 0x87f52750
#: 358 Function Name: NtWriteVirtualMemory
Status: Hooked by "" at address 0x870133d0
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:46:01.29 on Mon 09/21/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2941.1213 [GMT -7:00]
AV: Norton 360 *On-access scanning enabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton 360 *enabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\taskeng.exe
C:\TOSHIBA\IVP\ISM\ivpsvmgr.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Reynard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8V6NXOAQ\downloads[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll
BHO: NP Helper Class: {35b8d58c-b0cb-46b0-ba64-05b3804e4e86} - c:\program files\internet saving optimizer\3.6.2.4500\NPIEAddOn.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: System Search Dispatcher: {cdbfb47b-58a8-4111-bf95-06178dce326d} - c:\program files\system search dispatcher\1.3.5.960\ssd.dll
TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - No File
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\TOSCDSPD.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Camera Assistant Software] "c:\program files\camera assistant software for toshiba\traybar.exe" /start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [jswtrayutil] "c:\program files\jumpstart\jswtrayutil.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NDSTray.exe] NDSTray.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [TP CfgWiz] "c:\program files\common files\symantec shared\opc\{31011d49-d90c-4da0-878b-78d28ad507af}\SymCuw.exe" -G:{2D617065-1C52-4240-B5BC-C0AE12157777} -T:Config
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [00TCrdMain] c:\program files\toshiba\flashcards\TCrdMain.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\users\reynard\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
StartupFolder: c:\users\reynard\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
================= FIREFOX ===================
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-2-16 114768]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2008-8-27 20352]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-2-16 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-2-16 51792]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2007-12-25 40960]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-2-12 7168]
S3 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20070108.003\IDSvix86.sys [2008-2-12 212280]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2008-8-27 937984]
=============== Created Last 30 ================
2009-09-21 16:41 0 a——- c:\users\reynard\settings.dat
2009-09-08 12:10 897,608 a——- c:\windows\system32\drivers\tcpip.sys
2009-09-08 12:10 104,960 a——- c:\windows\system32\netiohlp.dll
2009-09-08 12:10 27,136 a——- c:\windows\system32\NETSTAT.EXE
2009-09-08 12:10 19,968 a——- c:\windows\system32\ARP.EXE
2009-09-08 12:10 17,920 a——- c:\windows\system32\ROUTE.EXE
2009-09-08 12:10 17,920 a——- c:\windows\system32\netevent.dll
2009-09-08 12:10 11,264 a——- c:\windows\system32\MRINFO.EXE
2009-09-08 12:10 10,240 a——- c:\windows\system32\finger.exe
2009-09-08 12:10 9,728 a——- c:\windows\system32\TCPSVCS.EXE
2009-09-08 12:10 8,704 a——- c:\windows\system32\HOSTNAME.EXE
2009-09-08 12:09 2,501,921 a——- c:\windows\system32\wlan.tmf
2009-09-08 12:09 513,024 a——- c:\windows\system32\wlansvc.dll
2009-09-08 12:09 302,592 a——- c:\windows\system32\wlansec.dll
2009-09-08 12:09 293,376 a——- c:\windows\system32\wlanmsm.dll
2009-09-08 12:09 127,488 a——- c:\windows\system32\L2SecHC.dll
2009-09-08 12:09 2,868,224 a——- c:\windows\system32\mf.dll
2009-09-02 22:55 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-09-02 22:55 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-26 03:01 2,048 a——- c:\windows\system32\tzres.dll
==================== Find3M ====================
2009-08-28 05:39 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 05:38 2,153,984 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 05:38 541,696 a——- c:\windows\apppatch\AcLayers.dll
2009-08-28 05:38 459,776 a——- c:\windows\apppatch\AcSpecfc.dll
2009-07-18 09:06 827,904 a——- c:\windows\system32\wininet.dll
2009-07-18 09:01 78,336 a——- c:\windows\system32\ieencode.dll
2009-07-18 02:46 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-07-17 07:35 71,680 a——- c:\windows\system32\atl.dll
2009-07-14 06:00 313,344 a——- c:\windows\system32\wmpdxm.dll
2009-07-14 05:59 4,096 a——- c:\windows\system32\dxmasf.dll
2009-07-14 05:58 7,680 a——- c:\windows\system32\spwmp.dll
2009-07-14 03:59 8,147,456 a——- c:\windows\system32\wmploc.DLL
2008-11-11 17:01 86,016 a——- c:\windows\inf\infstor.dat
2008-11-11 17:01 51,200 a——- c:\windows\inf\infpub.dat
2008-11-11 17:01 665,600 a——- c:\windows\inf\drvindex.dat
2008-11-11 17:01 86,016 a——- c:\windows\inf\infstrng.dat
2008-01-20 19:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat