studX3
Topic Starter
So far I've tried doing system restore and all types of things like that, my computer has been like this for over a month and I've just been using safe mode w/networking which I know is probably really stupid. Anyway whenever i start my computer not in safe mode, a bunch of .dlls are missing and when I exit out of those, six windows problems pop up. module to process wifi messages, virusScan tray icon, common user interface, hp quicktouch on screen display, quick launch buttons, and synaptics touchpad enhancements have all stopped working.
Thanks a lot!
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/23 21:51
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8EA00000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8EBEF000 Size: 45056 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9CF28000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spep.sys
Image Path: C:\Windows\System32\Drivers\spep.sys
Address: 0x8060F000 Size: 995328 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1160 Status: Locked to the Windows API!
Path: C:\Windows\System32\mfpmp.exe
PID: 4064 Status: Locked to the Windows API!
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:52:47.23 on Mon 11/23/2009
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.1891 [GMT -5:00]
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: VirusScan Enterprise + AntiSpyware Enterprise *disabled* (Updated) {24E45799-D058-4314-AC5D-1B2EE5C3151F}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\taskeng.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Will\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: 1 (0x1): {02478d38-c3f9-4efb-9b51-7695eca05670} - &Yahoo! Toolbar Helper
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_02\bin\jusched.exe"
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\will\appdata\roaming\mozilla\firefox\profiles\grcmeoez.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\will\appdata\roaming\mozilla\firefox\profiles\grcmeoez.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071302000002.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-3-29 24652]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
============== File Associations ===============
regfile="regedit.exe" "%1"
=============== Created Last 30 ================
2009-11-23 09:07 –d—– c:\program files\Windows Portable Devices
2009-11-23 09:06 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-23 02:27 92,672 a——- c:\windows\system32\UIAnimation.dll
2009-11-23 02:27 3,023,360 a——- c:\windows\system32\UIRibbon.dll
2009-11-23 02:27 1,164,800 a——- c:\windows\system32\UIRibbonRes.dll
2009-11-23 02:24 30,208 a——- c:\windows\system32\WPDShextAutoplay.exe
2009-11-22 14:50 4,096 a——- c:\windows\system32\oleaccrc.dll
2009-11-22 14:50 555,520 a——- c:\windows\system32\UIAutomationCore.dll
2009-11-22 14:50 234,496 a——- c:\windows\system32\oleacc.dll
2009-11-13 03:00 0 a—h— c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-11-11 14:59 2,036,736 a——- c:\windows\system32\win32k.sys
2009-11-11 14:58 355,328 a——- c:\windows\system32\WSDApi.dll
2009-11-06 14:13 691,696 a——- c:\windows\system32\drivers\sptd.sys
2009-11-05 12:24 –d—– c:\windows\CheckSur
2009-11-05 01:03 834,048 a——- c:\windows\system32\wininet.dll
2009-11-05 01:03 78,336 a——- c:\windows\system32\ieencode.dll
2009-10-29 18:18 310,784 a——- c:\windows\system32\unregmp2.exe
2009-10-29 18:18 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-10-26 20:01 –dsh— C:\found.001
==================== Find3M ====================
2009-11-23 09:35 27,744 a——- c:\programdata\nvModes.dat
2009-11-23 09:35 27,744 a——- c:\progra~2\nvModes.dat
2009-11-23 09:07 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-23 09:07 51,200 a——- c:\windows\inf\infpub.dat
2009-11-23 09:07 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-23 09:07 86,016 a——- c:\windows\inf\infstor.dat
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-10-05 00:13 56 a—h— c:\programdata\ezsidmv.dat
2009-10-05 00:13 56 a—h— c:\progra~2\ezsidmv.dat
2009-09-30 20:02 2,537,472 a——- c:\windows\system32\wpdshext.dll
2009-09-30 20:02 334,848 a——- c:\windows\system32\PortableDeviceApi.dll
2009-09-30 20:02 87,552 a——- c:\windows\system32\WPDShServiceObj.dll
2009-09-30 20:02 31,232 a——- c:\windows\system32\BthMtpContextHandler.dll
2009-09-30 20:01 546,816 a——- c:\windows\system32\wpd_ci.dll
2009-09-30 20:01 160,256 a——- c:\windows\system32\PortableDeviceTypes.dll
2009-09-30 20:01 350,208 a——- c:\windows\system32\WPDSp.dll
2009-09-30 20:01 196,608 a——- c:\windows\system32\PortableDeviceWMDRM.dll
2009-09-30 20:01 100,864 a——- c:\windows\system32\PortableDeviceClassExtension.dll
2009-09-30 20:01 60,928 a——- c:\windows\system32\PortableDeviceConnectApi.dll
2009-09-30 20:01 81,920 a——- c:\windows\system32\wpdbusenum.dll
2009-09-24 21:10 974,848 a——- c:\windows\system32\WindowsCodecs.dll
2009-09-24 21:07 189,440 a——- c:\windows\system32\WindowsCodecsExt.dll
2009-09-24 21:04 321,024 a——- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-24 20:49 1,554,432 a——- c:\windows\system32\xpsservices.dll
2009-09-24 20:48 351,232 a——- c:\windows\system32\XpsPrint.dll
2009-09-24 20:38 847,360 a——- c:\windows\system32\OpcServices.dll
2009-09-24 20:36 280,064 a——- c:\windows\system32\XpsGdiConverter.dll
2009-09-24 20:35 135,680 a——- c:\windows\system32\XpsRasterService.dll
2009-09-24 20:33 195,584 a——- c:\windows\system32\dxdiagn.dll
2009-09-24 20:33 829,440 a——- c:\windows\system32\d3d10warp.dll
2009-09-24 20:33 369,664 a——- c:\windows\system32\WMPhoto.dll
2009-09-24 20:32 252,928 a——- c:\windows\system32\dxdiag.exe
2009-09-24 20:31 519,680 a——- c:\windows\system32\d3d11.dll
2009-09-24 20:31 486,912 a——- c:\windows\system32\d3d10level9.dll
2009-09-24 20:31 161,280 a——- c:\windows\system32\d3d10_1.dll
2009-09-24 20:31 218,112 a——- c:\windows\system32\d3d10_1core.dll
2009-09-24 20:31 1,030,144 a——- c:\windows\system32\d3d10.dll
2009-09-24 20:31 828,928 a——- c:\windows\system32\d2d1.dll
2009-09-24 20:30 481,792 a——- c:\windows\system32\dxgi.dll
2009-09-24 20:30 190,464 a——- c:\windows\system32\d3d10core.dll
2009-09-24 20:27 1,064,448 a——- c:\windows\system32\DWrite.dll
2009-09-24 20:27 793,088 a——- c:\windows\system32\FntCache.dll
2009-09-24 20:27 37,888 a——- c:\windows\system32\cdd.dll
2009-09-24 17:54 258,048 a——- c:\windows\system32\winspool.drv
2009-09-24 17:54 667,648 a——- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 17:54 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-10 11:48 218,624 a——- c:\windows\system32\msv1_0.dll
2009-09-04 06:41 60,928 a——- c:\windows\system32\msasn1.dll
2009-08-28 21:30 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 21:30 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 21:30 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 21:30 542,720 a——- c:\windows\apppatch\AcLayers.dll
2009-08-28 19:27 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-28 19:14 28,672 a——- c:\windows\system32\Apphlpdm.dll
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 21:53:08.20 ===============
Thanks a lot!
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/23 21:51
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8EA00000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8EBEF000 Size: 45056 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9CF28000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spep.sys
Image Path: C:\Windows\System32\Drivers\spep.sys
Address: 0x8060F000 Size: 995328 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1160 Status: Locked to the Windows API!
Path: C:\Windows\System32\mfpmp.exe
PID: 4064 Status: Locked to the Windows API!
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:52:47.23 on Mon 11/23/2009
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.1891 [GMT -5:00]
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: VirusScan Enterprise + AntiSpyware Enterprise *disabled* (Updated) {24E45799-D058-4314-AC5D-1B2EE5C3151F}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\taskeng.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Will\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: 1 (0x1): {02478d38-c3f9-4efb-9b51-7695eca05670} - &Yahoo! Toolbar Helper
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_02\bin\jusched.exe"
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\will\appdata\roaming\mozilla\firefox\profiles\grcmeoez.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\will\appdata\roaming\mozilla\firefox\profiles\grcmeoez.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071302000002.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-3-29 24652]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
============== File Associations ===============
regfile="regedit.exe" "%1"
=============== Created Last 30 ================
2009-11-23 09:07 –d—– c:\program files\Windows Portable Devices
2009-11-23 09:06 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-23 02:27 92,672 a——- c:\windows\system32\UIAnimation.dll
2009-11-23 02:27 3,023,360 a——- c:\windows\system32\UIRibbon.dll
2009-11-23 02:27 1,164,800 a——- c:\windows\system32\UIRibbonRes.dll
2009-11-23 02:24 30,208 a——- c:\windows\system32\WPDShextAutoplay.exe
2009-11-22 14:50 4,096 a——- c:\windows\system32\oleaccrc.dll
2009-11-22 14:50 555,520 a——- c:\windows\system32\UIAutomationCore.dll
2009-11-22 14:50 234,496 a——- c:\windows\system32\oleacc.dll
2009-11-13 03:00 0 a—h— c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-11-11 14:59 2,036,736 a——- c:\windows\system32\win32k.sys
2009-11-11 14:58 355,328 a——- c:\windows\system32\WSDApi.dll
2009-11-06 14:13 691,696 a——- c:\windows\system32\drivers\sptd.sys
2009-11-05 12:24 –d—– c:\windows\CheckSur
2009-11-05 01:03 834,048 a——- c:\windows\system32\wininet.dll
2009-11-05 01:03 78,336 a——- c:\windows\system32\ieencode.dll
2009-10-29 18:18 310,784 a——- c:\windows\system32\unregmp2.exe
2009-10-29 18:18 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-10-26 20:01 –dsh— C:\found.001
==================== Find3M ====================
2009-11-23 09:35 27,744 a——- c:\programdata\nvModes.dat
2009-11-23 09:35 27,744 a——- c:\progra~2\nvModes.dat
2009-11-23 09:07 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-23 09:07 51,200 a——- c:\windows\inf\infpub.dat
2009-11-23 09:07 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-23 09:07 86,016 a——- c:\windows\inf\infstor.dat
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-10-05 00:13 56 a—h— c:\programdata\ezsidmv.dat
2009-10-05 00:13 56 a—h— c:\progra~2\ezsidmv.dat
2009-09-30 20:02 2,537,472 a——- c:\windows\system32\wpdshext.dll
2009-09-30 20:02 334,848 a——- c:\windows\system32\PortableDeviceApi.dll
2009-09-30 20:02 87,552 a——- c:\windows\system32\WPDShServiceObj.dll
2009-09-30 20:02 31,232 a——- c:\windows\system32\BthMtpContextHandler.dll
2009-09-30 20:01 546,816 a——- c:\windows\system32\wpd_ci.dll
2009-09-30 20:01 160,256 a——- c:\windows\system32\PortableDeviceTypes.dll
2009-09-30 20:01 350,208 a——- c:\windows\system32\WPDSp.dll
2009-09-30 20:01 196,608 a——- c:\windows\system32\PortableDeviceWMDRM.dll
2009-09-30 20:01 100,864 a——- c:\windows\system32\PortableDeviceClassExtension.dll
2009-09-30 20:01 60,928 a——- c:\windows\system32\PortableDeviceConnectApi.dll
2009-09-30 20:01 81,920 a——- c:\windows\system32\wpdbusenum.dll
2009-09-24 21:10 974,848 a——- c:\windows\system32\WindowsCodecs.dll
2009-09-24 21:07 189,440 a——- c:\windows\system32\WindowsCodecsExt.dll
2009-09-24 21:04 321,024 a——- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-24 20:49 1,554,432 a——- c:\windows\system32\xpsservices.dll
2009-09-24 20:48 351,232 a——- c:\windows\system32\XpsPrint.dll
2009-09-24 20:38 847,360 a——- c:\windows\system32\OpcServices.dll
2009-09-24 20:36 280,064 a——- c:\windows\system32\XpsGdiConverter.dll
2009-09-24 20:35 135,680 a——- c:\windows\system32\XpsRasterService.dll
2009-09-24 20:33 195,584 a——- c:\windows\system32\dxdiagn.dll
2009-09-24 20:33 829,440 a——- c:\windows\system32\d3d10warp.dll
2009-09-24 20:33 369,664 a——- c:\windows\system32\WMPhoto.dll
2009-09-24 20:32 252,928 a——- c:\windows\system32\dxdiag.exe
2009-09-24 20:31 519,680 a——- c:\windows\system32\d3d11.dll
2009-09-24 20:31 486,912 a——- c:\windows\system32\d3d10level9.dll
2009-09-24 20:31 161,280 a——- c:\windows\system32\d3d10_1.dll
2009-09-24 20:31 218,112 a——- c:\windows\system32\d3d10_1core.dll
2009-09-24 20:31 1,030,144 a——- c:\windows\system32\d3d10.dll
2009-09-24 20:31 828,928 a——- c:\windows\system32\d2d1.dll
2009-09-24 20:30 481,792 a——- c:\windows\system32\dxgi.dll
2009-09-24 20:30 190,464 a——- c:\windows\system32\d3d10core.dll
2009-09-24 20:27 1,064,448 a——- c:\windows\system32\DWrite.dll
2009-09-24 20:27 793,088 a——- c:\windows\system32\FntCache.dll
2009-09-24 20:27 37,888 a——- c:\windows\system32\cdd.dll
2009-09-24 17:54 258,048 a——- c:\windows\system32\winspool.drv
2009-09-24 17:54 667,648 a——- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 17:54 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-10 11:48 218,624 a——- c:\windows\system32\msv1_0.dll
2009-09-04 06:41 60,928 a——- c:\windows\system32\msasn1.dll
2009-08-28 21:30 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 21:30 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 21:30 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 21:30 542,720 a——- c:\windows\apppatch\AcLayers.dll
2009-08-28 19:27 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-28 19:14 28,672 a——- c:\windows\system32\Apphlpdm.dll
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 21:53:08.20 ===============