This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Lags. Freezes suddenly.

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just changed the hard drive two weeks ago and computer is starting to lag. It's fine but will freeze suddenly.

Here is the results of OTL.Txt

OTL logfile created on: 8/6/2010 3:10:24 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Byron\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.00% Memory free
6.00 Gb Paging File | 3.00 Gb Available in Paging File | 46.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 204.06 Gb Free Space | 71.06% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.82 Gb Free Space | 16.70% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BYRON-PC
Current User Name: Byron
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Byron\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\VideoLAN\VLC\vlc.exe ()
PRC - C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\System32\svcprs32.exe ()
PRC - C:\WINDOWS\System32\mdmcls32.exe ()
PRC - C:\Program Files\BitTorrent\bittorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\WINDOWS\System32\regsvr32.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Byron\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\System32\UmxSbxExw.dll (CA)
MOD - C:\WINDOWS\System32\UmxSbxw.dll (CA)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe File not found
SRV - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV - (WinSvchostManager) – C:\WINDOWS\System32\svcprs32.exe ()
SRV - (WinExtManager) – C:\WINDOWS\System32\mdmcls32.exe ()
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (UmxFwHlp) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1000000.07D\SRTSPX.SYS File not found
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1000000.07D\SRTSP.SYS File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (KmxAMRT) – C:\Windows\system32\DRIVERS\KmxAMRT.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\System32\drivers\KmxAgent.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\System32\drivers\KmxCfg.sys (CA)
DRV - (KmxSbx) – C:\WINDOWS\System32\drivers\KmxSbx.sys (CA)
DRV - (KmxFile) – C:\WINDOWS\System32\drivers\KmxFile.sys (CA)
DRV - (KmxCF) – C:\WINDOWS\System32\drivers\KmxCF.sys (CA)
DRV - (KmxFw) – C:\Windows\System32\DRIVERS\kmxfw.sys (CA)
DRV - (KmxFilter) – C:\WINDOWS\System32\drivers\KmxFilter.sys (CA)
DRV - (NuidFltr) – C:\WINDOWS\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (KmxAMVet) – C:\WINDOWS\System32\drivers\KmxAMVet.sys (Computer Associates International, Inc.)
DRV - (athr) – C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTSTOR) – C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (igfx) – C:\WINDOWS\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (IntcHdmiAddService) Intel® – C:\WINDOWS\System32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (RTL8169) – C:\WINDOWS\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (CnxtHdAudService) – C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (SynTP) – C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (NETw3v32) Intel® – C:\WINDOWS\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (yukonwlh) – C:\WINDOWS\System32\drivers\yk60x86.sys (Marvell)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:3.1.5.5
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{e9259cba-e7ad-4f74-863f-ef9fe935394d}: C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00317165\Toolbar\Firefox [2010/07/17 17:36:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{8b02914c-4e6b-4410-90e1-1a2b1b69b12d}: C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00317165\LinkAdvisor\Firefox [2010/07/17 17:36:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/31 01:38:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/31 01:38:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{8b02914c-4e6b-4410-90e1-1a2b1b69b12d}: C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00317165\LinkAdvisor\Firefox [2010/07/17 17:36:54 | 000,000,000 | —D | M]

[2010/07/17 14:27:13 | 000,000,000 | —D | M] – C:\Users\Byron\AppData\Roaming\Mozilla\Extensions
[2010/08/06 12:22:44 | 000,000,000 | —D | M] – C:\Users\Byron\AppData\Roaming\Mozilla\Firefox\Profiles\0g2chadi.default\extensions
[2010/07/22 03:04:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Byron\AppData\Roaming\Mozilla\Firefox\Profiles\0g2chadi.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/04 16:26:45 | 000,000,000 | —D | M] – C:\Users\Byron\AppData\Roaming\Mozilla\Firefox\Profiles\0g2chadi.default\extensions\[removed]
[2010/07/18 16:22:22 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/18 16:22:22 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/18 16:22:02 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/07/21 19:02:41 | 000,002,153 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.complaintsboard.com
O1 - Hosts: 127.0.0.1 complaintsboard.com
O1 - Hosts: 127.0.0.1 www.bobbear.co.uk
O1 - Hosts: 127.0.0.1 bobbear.co.uk
O1 - Hosts: 127.0.0.1 www.bobbear.com
O1 - Hosts: 127.0.0.1 bobbear.com
O1 - Hosts: 127.0.0.1 www.419legal.org
O1 - Hosts: 127.0.0.1 419legal.org
O1 - Hosts: 127.0.0.1 www.scam.com
O1 - Hosts: 127.0.0.1 scam.com
O1 - Hosts: 127.0.0.1 www.anti-scam.org
O1 - Hosts: 127.0.0.1 anti-scam.org
O1 - Hosts: 127.0.0.1 www.consumerfraudreporting.org
O1 - Hosts: 127.0.0.1 consumerfraudreporting.org
O1 - Hosts: 127.0.0.1 www.ripoffreport.com
O1 - Hosts: 127.0.0.1 ripoffreport.com
O1 - Hosts: 127.0.0.1 www.tjshome.com
O1 - Hosts: 127.0.0.1 tjshome.com
O1 - Hosts: 127.0.0.1 www.scamfraudalert.wordpress.com
O1 - Hosts: 127.0.0.1 scamfraudalert.wordpress.com
O1 - Hosts: 127.0.0.1 www.fraudwatchers.org
O1 - Hosts: 127.0.0.1 fraudwatchers.org
O1 - Hosts: 127.0.0.1 www.scamfraudalert.com
O1 - Hosts: 24 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (CA Toolbar Helper) - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00317165\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (CA Toolbar) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00317165\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (CA Toolbar) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00317165\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4 - HKLM..\Run: [CLSA] C:\Program Files\Good Deal Software\Craigs Search Agent\search_agent.exe ()
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MSVirtual] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\VetRedir.dll (Computer Associates International, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\callingid {086D03BA-57AC-4C8E-A33D-0BAABF742411} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00317165\Toolbar\CallingIDToolbar.dll (CallingID Ltd.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\System32\UmxSbxExw.dll) - C:\WINDOWS\System32\UmxSbxExw.dll (CA)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\Windows\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Silhouette.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Silhouette.jpg
O28 - HKLM ShellExecuteHooks: {1869181A-9F50-4FCF-8BFF-1B8588ECB85C} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\1.2.1.24.00317165\LinkAdvisor\CIDLinkAdvisor.dll (CallingID Ltd.)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/08/06 12:10:41 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/08/06 12:10:40 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/08/06 12:10:39 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/08/06 12:08:41 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/08/06 12:08:34 | 000,000,000 | –SD | C] – C:\ComboFix
[2010/08/06 12:08:06 | 000,000,000 | —D | C] – C:\Qoobox
[2010/08/06 12:06:35 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/08/02 15:04:24 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010/08/02 14:59:19 | 000,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2010/08/02 14:57:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/08/02 10:43:12 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Good Deal Software
[2010/08/02 10:43:05 | 000,000,000 | —D | C] – C:\Program Files\Good Deal Software
[2010/08/02 09:35:33 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\MS
[2010/07/31 17:16:13 | 000,000,000 | —D | C] – C:\Windows\pss
[2010/07/29 07:49:46 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Apple Computer
[2010/07/29 07:40:27 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Apple Computer
[2010/07/29 03:15:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/07/29 03:14:59 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Apple
[2010/07/29 03:14:53 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/07/29 03:14:52 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/07/26 21:54:44 | 000,000,000 | —D | C] – C:\Users\Byron\Desktop\prospective_accounts.php_files
[2010/07/22 03:05:48 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\WinRAR
[2010/07/22 03:05:22 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/07/21 19:23:44 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\BitTorrent
[2010/07/21 19:23:28 | 000,000,000 | —D | C] – C:\Program Files\BitTorrent
[2010/07/20 04:42:18 | 000,000,000 | —D | C] – C:\Users\Byron\Documents\Youcam
[2010/07/20 04:22:30 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Microsoft Games
[2010/07/20 03:04:54 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2010/07/20 03:04:54 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2010/07/20 03:04:54 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2010/07/19 23:46:49 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Qurb4
[2010/07/19 04:00:09 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2010/07/19 04:00:09 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2010/07/19 04:00:05 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2010/07/19 04:00:04 | 000,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2010/07/19 04:00:04 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2010/07/19 03:34:31 | 000,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2010/07/19 03:34:30 | 000,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2010/07/19 03:34:29 | 000,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2010/07/19 03:34:29 | 000,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2010/07/19 03:34:29 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2010/07/19 03:34:28 | 000,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2010/07/19 03:26:15 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2010/07/19 03:26:10 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2010/07/19 03:04:45 | 000,000,000 | —D | C] – C:\Windows\CheckSur
[2010/07/19 03:03:37 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2010/07/19 03:03:33 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2010/07/19 03:01:54 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2010/07/19 00:53:57 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\vlc
[2010/07/19 00:52:34 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/07/18 21:28:33 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2010/07/18 19:29:45 | 000,000,000 | —D | C] – C:\ProgramData\WEBREG
[2010/07/18 19:26:59 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\HP
[2010/07/18 19:26:56 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\HP
[2010/07/18 18:56:24 | 000,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2010/07/18 18:52:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\HP
[2010/07/18 18:52:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2010/07/18 18:50:43 | 001,373,528 | R— | C] (Hewlett-Packard) – C:\Windows\hpzshl01.exe
[2010/07/18 18:50:43 | 001,140,056 | R— | C] (Hewlett-Packard) – C:\Windows\hpzmsi01.exe
[2010/07/18 18:50:42 | 000,000,000 | —D | C] – C:\Windows\yellowtail+1
[2010/07/18 18:46:07 | 000,271,704 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpzids01.dll
[2010/07/18 18:46:05 | 000,118,272 | —- | C] (Hewlett-Packard Company) – C:\Windows\System32\hpz3l5mu.dll
[2010/07/18 18:43:51 | 000,729,088 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpwwiax4.dll
[2010/07/18 18:43:51 | 000,593,920 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpwtscl3.dll
[2010/07/18 18:43:51 | 000,364,544 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hppldcoi.dll
[2010/07/18 18:43:51 | 000,294,912 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpovst11.dll
[2010/07/18 18:41:31 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2010/07/18 17:39:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2010/07/18 17:39:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2010/07/18 17:38:13 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/07/18 17:38:13 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2010/07/18 17:34:36 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Microsoft Help
[2010/07/18 17:30:05 | 000,000,000 | RH-D | C] – C:\MSOCache
[2010/07/18 16:51:33 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\KeePass
[2010/07/18 16:36:59 | 000,000,000 | —D | C] – C:\Program Files\KeePass Password Safe 2
[2010/07/18 16:23:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/07/18 16:22:33 | 000,000,000 | —D | C] – C:\Program Files\Sun
[2010/07/18 16:22:20 | 000,153,376 | —- | C] (Oracle) – C:\Windows\System32\javaws.exe
[2010/07/18 16:22:20 | 000,145,184 | —- | C] (Oracle) – C:\Windows\System32\javaw.exe
[2010/07/18 16:22:20 | 000,145,184 | —- | C] (Oracle) – C:\Windows\System32\java.exe
[2010/07/18 16:19:27 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/07/18 03:25:37 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2010/07/18 03:25:35 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/07/18 03:25:21 | 000,104,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2010/07/18 03:25:21 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NETSTAT.EXE
[2010/07/18 03:25:21 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ARP.EXE
[2010/07/18 03:25:21 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\finger.exe
[2010/07/18 03:25:21 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TCPSVCS.EXE
[2010/07/18 03:25:21 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\HOSTNAME.EXE
[2010/07/18 03:25:20 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ROUTE.EXE
[2010/07/18 03:25:20 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/07/18 03:25:20 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MRINFO.EXE
[2010/07/18 03:24:41 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansec.dll
[2010/07/18 03:24:41 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2010/07/18 03:24:41 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\L2SecHC.dll
[2010/07/18 03:24:26 | 001,256,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2010/07/18 03:24:09 | 002,868,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2010/07/18 03:24:09 | 002,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2010/07/18 03:24:04 | 003,598,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010/07/18 03:24:04 | 003,545,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010/07/18 03:23:34 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asycfilt.dll
[2010/07/18 03:23:32 | 000,430,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2010/07/18 03:23:25 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/07/18 03:23:25 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/07/18 03:23:15 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/07/18 03:22:52 | 000,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2010/07/18 03:22:52 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2010/07/18 03:22:45 | 000,714,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2010/07/18 03:22:43 | 000,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/07/18 03:22:43 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/07/18 03:22:43 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/07/18 03:22:43 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2010/07/18 03:22:33 | 000,636,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localspl.dll
[2010/07/18 03:22:28 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2010/07/18 03:22:28 | 000,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2010/07/18 03:22:28 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2010/07/18 03:22:28 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2010/07/18 03:22:28 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2010/07/18 03:22:27 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2010/07/18 03:22:27 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2010/07/18 03:22:20 | 000,062,464 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2010/07/18 03:22:18 | 000,512,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2010/07/18 03:22:09 | 002,452,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2010/07/18 03:22:06 | 000,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/07/18 03:22:06 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/07/18 03:22:06 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/07/18 03:22:05 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/07/18 03:22:04 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/07/18 03:22:04 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/07/18 03:22:04 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010/07/18 03:22:04 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/07/18 03:22:03 | 001,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/07/18 03:22:03 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/07/18 03:22:03 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/07/18 03:21:55 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2010/07/18 03:21:51 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2010/07/18 03:21:51 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2010/07/18 03:21:50 | 000,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2010/07/18 03:21:38 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.tlb
[2010/07/18 03:21:38 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amcompat.tlb
[2010/07/18 03:21:34 | 000,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2010/07/18 03:21:34 | 000,511,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2010/07/18 03:21:34 | 000,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2010/07/18 03:21:33 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2010/07/18 03:21:33 | 000,472,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2010/07/18 03:21:33 | 000,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/07/18 03:21:33 | 000,329,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2010/07/18 03:21:33 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2010/07/18 03:21:33 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2010/07/18 03:20:59 | 002,036,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/07/18 03:20:57 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[2010/07/18 03:20:57 | 000,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2010/07/18 03:20:54 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2010/07/18 03:20:50 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvfw32.dll
[2010/07/18 03:20:50 | 000,091,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll
[2010/07/18 03:20:50 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2010/07/18 03:20:50 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avicap32.dll
[2010/07/18 03:20:47 | 000,604,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOD.DLL
[2010/07/18 03:20:34 | 000,310,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unregmp2.exe
[2010/07/18 03:20:32 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2010/07/18 03:20:32 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2010/07/18 03:20:32 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2010/07/18 03:20:30 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/07/17 22:34:26 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Yahoo
[2010/07/17 22:33:48 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo! Companion
[2010/07/17 22:33:47 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Yahoo!
[2010/07/17 22:33:20 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo!
[2010/07/17 22:31:14 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2010/07/17 19:58:09 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/07/17 19:57:55 | 000,423,656 | —- | C] (Oracle) – C:\Windows\System32\deployJava1.dll
[2010/07/17 19:34:39 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Malwarebytes
[2010/07/17 19:33:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/07/17 19:33:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/07/17 19:33:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/07/17 19:33:44 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 19:20:03 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\U3
[2010/07/17 19:00:33 | 000,000,000 | —D | C] – C:\Users\Byron\Desktop\My Pictures
[2010/07/17 17:39:07 | 000,000,000 | —D | C] – C:\ProgramData\Logs
[2010/07/17 17:38:20 | 000,201,968 | —- | C] (CA, Inc.) – C:\Windows\System32\Isafprod.dll
[2010/07/17 17:38:20 | 000,128,240 | —- | C] (Computer Associates International, Inc.) – C:\Windows\System32\Isafeif.dll
[2010/07/17 17:38:20 | 000,095,472 | —- | C] (Computer Associates International, Inc.) – C:\Windows\System32\Vetredir.dll
[2010/07/17 17:37:26 | 000,000,000 | -H-D | C] – C:\Config.msi
[2010/07/17 17:36:50 | 000,000,000 | —D | C] – C:\Program Files\ISSThirdParty
[2010/07/17 17:36:08 | 001,028,096 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\Windows\System32\libeay32.dll
[2010/07/17 17:36:08 | 000,200,704 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\Windows\System32\ssleay32.dll
[2010/07/17 17:36:07 | 002,654,208 | —- | C] (PureSight Technologies Ltd) – C:\Windows\System32\winsflte.dll
[2010/07/17 17:36:07 | 000,000,000 | —D | C] – C:\Windows\rnapxs
[2010/07/17 17:36:06 | 000,007,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sporder.dll
[2010/07/17 17:35:07 | 000,000,000 | —D | C] – C:\Program Files\CA
[2010/07/17 17:34:11 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Adobe
[2010/07/17 17:26:52 | 000,000,000 | —D | C] – C:\ProgramData\CA
[2010/07/17 17:13:42 | 000,000,000 | —D | C] – C:\ProgramData\CA-SupportBridge
[2010/07/17 14:27:02 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Mozilla
[2010/07/17 14:27:02 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Mozilla
[2010/07/17 14:26:55 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/07/17 14:09:31 | 000,000,000 | —D | C] – C:\Windows\SMINST
[2010/07/17 14:09:17 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/07/17 14:06:25 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Hewlett-Packard
[2010/07/17 14:06:23 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Hewlett-Packard
[2010/07/17 14:05:38 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Macromedia
[2010/07/17 14:05:36 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Adobe
[2010/07/17 14:01:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Searches
[2010/07/17 14:01:18 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Identities
[2010/07/17 14:01:16 | 000,000,000 | R–D | C] – C:\Users\Byron\Contacts
[2010/07/17 14:01:14 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\VirtualStore
[2010/07/17 13:58:24 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\HP TCS
[2010/07/17 13:55:34 | 002,421,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2010/07/17 13:55:34 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\AppData\Local\Temporary Internet Files
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Templates
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Start Menu
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\SendTo
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Recent
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\PrintHood
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\NetHood
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Documents\My Videos
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Documents\My Pictures
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Documents\My Music
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\My Documents
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Local Settings
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\AppData\Local\History
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Cookies
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\Application Data
[2010/07/17 13:55:27 | 000,000,000 | -HSD | C] – C:\Users\Byron\AppData\Local\Application Data
[2010/07/17 13:55:25 | 000,000,000 | –SD | C] – C:\Users\Byron\AppData\Roaming\Microsoft
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Videos
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Saved Games
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Pictures
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Music
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Links
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Favorites
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Downloads
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Documents
[2010/07/17 13:55:25 | 000,000,000 | R–D | C] – C:\Users\Byron\Desktop
[2010/07/17 13:55:25 | 000,000,000 | -H-D | C] – C:\Users\Byron\AppData
[2010/07/17 13:55:25 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Temp
[2010/07/17 13:55:25 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Local\Microsoft
[2010/07/17 13:55:25 | 000,000,000 | —D | C] – C:\Users\Byron\AppData\Roaming\Media Center Programs
[2010/07/17 13:55:23 | 000,575,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2010/07/17 13:55:23 | 000,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2010/07/17 13:55:23 | 000,035,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2010/07/17 13:55:17 | 000,171,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2010/07/17 13:55:17 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2010/07/17 13:51:14 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/07/17 13:48:08 | 000,000,000 | —D | C] – C:\Program Files\muvee Technologies
[2010/07/17 13:48:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\muvee Technologies
[2010/07/17 13:43:25 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml4r.dll
[2010/07/17 13:43:25 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml4a.dll
[2010/07/17 13:43:04 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\atl71.dll
[2010/07/17 13:42:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\LightScribe
[2010/07/17 13:23:05 | 000,061,952 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\drivers\RTSTOR.sys
[2010/07/17 13:21:01 | 000,920,088 | —- | C] (Intel® Corporation) – C:\Windows\System32\igxpun.exe
[2010/07/17 13:21:01 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\difxapi.dll
[2010/07/17 13:21:01 | 000,000,000 | —D | C] – C:\Windows\System32\Lang
[2010/07/17 13:21:01 | 000,000,000 | —D | C] – C:\Intel
[2010/07/17 13:20:47 | 000,000,000 | —D | C] – C:\Program Files\NetWaiting
[2010/07/17 13:20:33 | 000,000,000 | —D | C] – C:\Program Files\CONEXANT
[2010/07/17 13:19:51 | 000,123,904 | —- | C] (Realtek Corporation ) – C:\Windows\System32\drivers\Rtlh86.sys
[2010/07/17 13:19:50 | 000,000,000 | —D | C] – C:\Program Files\Realtek
[2010/07/17 13:19:24 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2010/07/17 13:18:20 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\System32\CSVer.dll
[2010/07/17 13:18:20 | 000,000,000 | —D | C] – C:\Program Files\Intel
[2010/07/17 13:17:28 | 001,093,120 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\drivers\athr.sys
[2010/07/17 13:17:28 | 000,000,000 | —D | C] – C:\Program Files\Atheros
[2010/07/17 13:17:25 | 000,000,000 | —D | C] – C:\ProgramData\Atheros
[2010/07/17 13:14:05 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010/07/17 13:11:52 | 000,000,000 | —D | C] – C:\Windows\Prefetch

========== Files - Modified Within 30 Days ==========

[2010/08/06 15:09:50 | 001,572,864 | -HS- | M] () – C:\Users\Byron\NTUSER.DAT
[2010/08/06 13:19:07 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/06 13:19:07 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/06 12:03:04 | 000,017,920 | —- | M] () – C:\Users\Byron\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/05 13:23:39 | 000,001,356 | —- | M] () – C:\Users\Byron\AppData\Local\d3d9caps.dat
[2010/08/04 07:25:44 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/08/04 07:25:44 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/08/04 07:25:44 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/08/04 07:22:19 | 000,000,284 | —- | M] () – C:\ProgramData\hpqp.ini
[2010/08/04 07:19:42 | 003,746,928 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/08/04 07:19:08 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/04 07:19:01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/04 07:18:00 | 000,537,395 | —- | M] () – C:\Windows\System32\drivers\kmxcfg.u2k0
[2010/08/04 07:18:00 | 000,142,156 | —- | M] () – C:\Windows\System32\drivers\KmxAgent.asc
[2010/08/04 07:18:00 | 000,010,417 | —- | M] () – C:\Windows\System32\drivers\kmxcfg.u2k1
[2010/08/04 07:18:00 | 000,000,357 | —- | M] () – C:\Windows\System32\drivers\kmxzone.u2k2
[2010/08/04 07:18:00 | 000,000,357 | —- | M] () – C:\Windows\System32\drivers\kmxzone.u2k1
[2010/08/04 07:18:00 | 000,000,357 | —- | M] () – C:\Windows\System32\drivers\kmxzone.u2k0
[2010/08/04 07:18:00 | 000,000,289 | —- | M] () – C:\Windows\System32\drivers\kmxcfg.u2k2
[2010/08/04 07:18:00 | 000,000,081 | —- | M] () – C:\Windows\System32\drivers\kmxcfg.u2k7
[2010/08/04 07:18:00 | 000,000,081 | —- | M] () – C:\Windows\System32\drivers\kmxcfg.u2k6
[2010/08/04 07:18:00 | 000,000,081 | —- | M] () – C:\Windows\System32\drivers\kmxcfg.u2k5
[2010/08/04 07:18:00 | 000,000,081 | —- | M] () – C:\Windows\System32\drivers\kmxcfg.u2k4
[2010/08/04 07:18:00 | 000,000,081 | —- | M] () – C:\Windows\System32\drivers\kmxcfg.u2k3
[2010/08/04 07:18:00 | 000,000,045 | —- | M] () – C:\Windows\System32\drivers\kmxzone.u2k7
[2010/08/04 07:18:00 | 000,000,045 | —- | M] () – C:\Windows\System32\drivers\kmxzone.u2k6
[2010/08/04 07:18:00 | 000,000,045 | —- | M] () – C:\Windows\System32\drivers\kmxzone.u2k5
[2010/08/04 07:18:00 | 000,000,045 | —- | M] () – C:\Windows\System32\drivers\kmxzone.u2k4
[2010/08/04 07:18:00 | 000,000,045 | —- | M] () – C:\Windows\System32\drivers\kmxzone.u2k3
[2010/08/04 07:17:37 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/08/04 07:17:17 | 000,524,288 | -HS- | M] () – C:\Users\Byron\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/08/04 07:17:17 | 000,065,536 | -HS- | M] () – C:\Users\Byron\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/08/04 07:17:15 | 006,291,456 | -H– | M] () – C:\Users\Byron\AppData\Local\IconCache.db
[2010/08/04 05:15:42 | 000,868,728 | —- | M] () – C:\Users\Byron\Documents\Craigslit.psd
[2010/08/04 05:08:16 | 000,241,510 | —- | M] () – C:\Users\Byron\Desktop\CraigslitAd.jpg
[2010/08/04 04:59:45 | 000,243,646 | —- | M] () – C:\Users\Byron\Documents\CraigslitAd.jpg
[2010/08/04 04:52:59 | 000,242,302 | —- | M] () – C:\Users\Byron\Documents\Craigslit.jpg
[2010/08/03 16:30:16 | 000,146,892 | —- | M] () – C:\Users\Byron\Desktop\LJ.docx
[2010/08/02 15:04:25 | 000,107,512 | —- | M] () – C:\Users\Byron\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/02 12:25:36 | 000,010,363 | —- | M] () – C:\Users\Byron\Documents\Craigslist Accounts.docx
[2010/08/02 12:22:08 | 000,090,624 | —- | M] () – C:\Users\Byron\Documents\Craigslit.jpg.pub
[2010/08/02 11:58:51 | 000,090,624 | —- | M] () – C:\Users\Byron\Desktop\Craigslit.jpg.pub
[2010/08/02 11:58:46 | 000,180,760 | —- | M] () – C:\Users\Byron\Desktop\Craigslit.jpg
[2010/08/02 10:43:14 | 000,000,016 | RHS- | M] () – C:\Windows\clsa_2_0.des
[2010/08/02 08:41:35 | 000,000,162 | -H– | M] () – C:\Users\Byron\Documents\~$aigslist Accounts.docx
[2010/08/02 05:45:09 | 000,036,090 | —- | M] () – C:\Users\Byron\Desktop\front.jpg
[2010/08/02 05:45:01 | 000,035,375 | —- | M] () – C:\Users\Byron\Desktop\inside1.jpg
[2010/08/02 05:41:05 | 000,033,285 | —- | M] () – C:\Users\Byron\Desktop\Side.jpg
[2010/08/02 05:40:57 | 000,020,108 | —- | M] () – C:\Users\Byron\Desktop\Ext.jpg
[2010/07/29 18:49:09 | 000,001,887 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/07/29 00:27:38 | 000,195,904 | —- | M] () – C:\Users\Byron\Desktop\Facebook page.docx
[2010/07/28 19:37:04 | 003,298,838 | —- | M] () – C:\Users\Byron\Documents\Quotes.docx
[2010/07/27 01:00:22 | 000,146,873 | —- | M] () – C:\Users\Byron\Documents\LJ.docx
[2010/07/26 21:54:44 | 000,005,112 | —- | M] () – C:\Users\Byron\Desktop\prospective_accounts.php.htm
[2010/07/26 21:53:10 | 000,126,777 | —- | M] () – C:\Users\Byron\Desktop\Sasha 3.jpg
[2010/07/26 21:52:09 | 000,130,076 | —- | M] () – C:\Users\Byron\Desktop\Sasha 2.jpg
[2010/07/26 21:51:37 | 000,150,935 | —- | M] () – C:\Users\Byron\Desktop\Sash 1.jpg
[2010/07/22 03:13:07 | 000,245,417 | —- | M] () – C:\Users\Byron\Desktop\img027.jpg
[2010/07/22 03:11:50 | 000,752,644 | —- | M] () – C:\Users\Byron\Desktop\img025.jpg
[2010/07/21 19:23:31 | 000,000,850 | —- | M] () – C:\Users\Public\Desktop\BitTorrent.lnk
[2010/07/21 18:57:52 | 000,000,929 | —- | M] () – C:\Users\Byron\Desktop\test2.exe.lnk
[2010/07/20 23:16:39 | 000,011,666 | —- | M] () – C:\Users\Byron\Documents\Things to do.xlsx
[2010/07/19 23:46:48 | 000,000,938 | —- | M] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2010/07/19 03:46:35 | 000,000,254 | —- | M] () – C:\Windows\win.ini
[2010/07/18 19:30:00 | 000,178,440 | —- | M] () – C:\Windows\hpwins20.dat
[2010/07/18 19:02:43 | 000,002,016 | —- | M] () – C:\Users\Public\Desktop\HP Photosmart Essential 2.5.lnk
[2010/07/18 19:01:21 | 000,001,968 | —- | M] () – C:\Users\Public\Desktop\HP Document Manager.lnk
[2010/07/18 18:59:16 | 000,002,060 | —- | M] () – C:\Users\Public\Desktop\Shop for HP Supplies.lnk
[2010/07/18 18:57:39 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/07/18 16:36:59 | 000,000,844 | —- | M] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\KeePass Password Safe.lnk
[2010/07/18 16:22:01 | 000,423,656 | —- | M] (Oracle) – C:\Windows\System32\deployJava1.dll
[2010/07/18 16:22:01 | 000,153,376 | —- | M] (Oracle) – C:\Windows\System32\javaws.exe
[2010/07/18 16:22:01 | 000,145,184 | —- | M] (Oracle) – C:\Windows\System32\javaw.exe
[2010/07/18 16:22:01 | 000,145,184 | —- | M] (Oracle) – C:\Windows\System32\java.exe
[2010/07/17 22:33:23 | 000,000,966 | —- | M] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/17 22:33:23 | 000,000,942 | —- | M] () – C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2010/07/17 19:33:51 | 000,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/17 17:37:36 | 000,000,007 | —- | M] () – C:\Windows\System32\mkghj.dll
[2010/07/17 17:36:11 | 005,845,744 | —- | M] () – C:\Windows\System32\win32cpr.dll
[2010/07/17 17:36:11 | 001,872,624 | —- | M] () – C:\Windows\System32\winsflt.dll
[2010/07/17 15:28:15 | 000,000,938 | —- | M] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/07/17 14:26:58 | 000,001,748 | —- | M] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/17 14:26:58 | 000,001,724 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/07/17 14:05:24 | 000,000,943 | —- | M] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/17 14:02:26 | 000,524,288 | -HS- | M] () – C:\Users\Byron\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2010/07/17 14:02:04 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2010/07/17 13:56:17 | 000,000,000 | RHS- | M] () – C:\Windows\System32\drivers\103C_HP_cNB_G60 Notebook PC_Y5335KV_0U_Q2CE9211DW5_E508165-002_4A_I3612_SWistron_V09.54_F.38_T090416_WV3-1_L409_M3003_J320_7Intel_867A_92.00_#100717_N10EC8136;168C002A_(NW142UA#ABA)_XMO
BILE_CN10_Z_2F.38.MRK
[2010/07/17 13:55:27 | 000,000,020 | -HS- | M] () – C:\Users\Byron\ntuser.ini
[2010/07/17 13:54:02 | 000,047,092 | —- | M] () – C:\Windows\System32\license.rtf
[2010/07/17 13:44:09 | 001,053,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFC71u.dll
[2010/07/17 13:44:09 | 000,505,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msvcp71.dll
[2010/07/17 13:44:09 | 000,353,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msvcr71.dll
[2010/07/17 13:44:08 | 001,066,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFC71.dll
[2010/07/17 13:41:57 | 000,016,072 | —- | M] () – C:\Windows\System32\results.xml
[2010/07/17 13:19:42 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2010/07/15 16:52:56 | 000,020,087 | —- | M] () – C:\Users\Byron\Documents\Resume-1[1].docx

========== Files Created - No Company Name ==========

[2010/08/06 12:10:41 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/08/06 12:10:41 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/08/06 12:10:40 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/08/06 12:10:40 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/08/06 12:10:40 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/08/04 05:08:12 | 000,241,510 | —- | C] () – C:\Users\Byron\Desktop\CraigslitAd.jpg
[2010/08/04 04:59:40 | 000,243,646 | —- | C] () – C:\Users\Byron\Documents\CraigslitAd.jpg
[2010/08/04 04:53:47 | 000,868,728 | —- | C] () – C:\Users\Byron\Documents\Craigslit.psd
[2010/08/03 16:30:14 | 000,146,892 | —- | C] () – C:\Users\Byron\Desktop\LJ.docx
[2010/08/02 11:58:45 | 000,180,760 | —- | C] () – C:\Users\Byron\Desktop\Craigslit.jpg
[2010/08/02 10:43:13 | 000,000,016 | RHS- | C] () – C:\Windows\clsa_2_0.des
[2010/08/02 08:41:35 | 000,000,162 | -H– | C] () – C:\Users\Byron\Documents\~$aigslist Accounts.docx
[2010/08/02 08:41:34 | 000,010,363 | —- | C] () – C:\Users\Byron\Documents\Craigslist Accounts.docx
[2010/08/02 06:03:53 | 000,090,624 | —- | C] () – C:\Users\Byron\Desktop\Craigslit.jpg.pub
[2010/08/02 06:00:14 | 000,090,624 | —- | C] () – C:\Users\Byron\Documents\Craigslit.jpg.pub
[2010/08/02 05:47:14 | 000,242,302 | —- | C] () – C:\Users\Byron\Documents\Craigslit.jpg
[2010/08/02 05:45:08 | 000,036,090 | —- | C] () – C:\Users\Byron\Desktop\front.jpg
[2010/08/02 05:43:02 | 000,035,375 | —- | C] () – C:\Users\Byron\Desktop\inside1.jpg
[2010/08/02 05:41:05 | 000,033,285 | —- | C] () – C:\Users\Byron\Desktop\Side.jpg
[2010/08/02 05:40:56 | 000,020,108 | —- | C] () – C:\Users\Byron\Desktop\Ext.jpg
[2010/07/31 18:12:52 | 000,001,356 | —- | C] () – C:\Users\Byron\AppData\Local\d3d9caps.dat
[2010/07/29 18:49:09 | 000,001,887 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/07/29 00:27:37 | 000,195,904 | —- | C] () – C:\Users\Byron\Desktop\Facebook page.docx
[2010/07/28 19:37:03 | 003,298,838 | —- | C] () – C:\Users\Byron\Documents\Quotes.docx
[2010/07/27 01:00:21 | 000,146,873 | —- | C] () – C:\Users\Byron\Documents\LJ.docx
[2010/07/26 21:54:43 | 000,005,112 | —- | C] () – C:\Users\Byron\Desktop\prospective_accounts.php.htm
[2010/07/26 21:53:09 | 000,126,777 | —- | C] () – C:\Users\Byron\Desktop\Sasha 3.jpg
[2010/07/26 21:52:09 | 000,130,076 | —- | C] () – C:\Users\Byron\Desktop\Sasha 2.jpg
[2010/07/26 21:51:37 | 000,150,935 | —- | C] () – C:\Users\Byron\Desktop\Sash 1.jpg
[2010/07/22 03:13:06 | 000,245,417 | —- | C] () – C:\Users\Byron\Desktop\img027.jpg
[2010/07/22 03:11:49 | 000,752,644 | —- | C] () – C:\Users\Byron\Desktop\img025.jpg
[2010/07/21 19:23:31 | 000,000,850 | —- | C] () – C:\Users\Public\Desktop\BitTorrent.lnk
[2010/07/21 18:57:52 | 000,000,929 | —- | C] () – C:\Users\Byron\Desktop\test2.exe.lnk
[2010/07/19 23:46:48 | 000,000,938 | —- | C] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2010/07/19 00:18:34 | 000,017,920 | —- | C] () – C:\Users\Byron\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/18 21:19:29 | 000,011,666 | —- | C] () – C:\Users\Byron\Documents\Things to do.xlsx
[2010/07/18 19:02:43 | 000,002,016 | —- | C] () – C:\Users\Public\Desktop\HP Photosmart Essential 2.5.lnk
[2010/07/18 19:01:21 | 000,001,968 | —- | C] () – C:\Users\Public\Desktop\HP Document Manager.lnk
[2010/07/18 18:59:16 | 000,002,060 | —- | C] () – C:\Users\Public\Desktop\Shop for HP Supplies.lnk
[2010/07/18 18:57:39 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/07/18 18:50:43 | 000,012,054 | R— | C] () – C:\Windows\hpwscr20.dat
[2010/07/18 18:43:16 | 000,001,324 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/07/18 18:43:15 | 000,178,440 | —- | C] () – C:\Windows\hpwins20.dat
[2010/07/18 16:36:59 | 000,000,844 | —- | C] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\KeePass Password Safe.lnk
[2010/07/18 03:24:42 | 002,501,921 | —- | C] () – C:\Windows\System32\wlan.tmf
[2010/07/17 22:33:23 | 000,000,966 | —- | C] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/17 22:33:23 | 000,000,942 | —- | C] () – C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2010/07/17 19:33:51 | 000,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/17 19:16:51 | 000,142,156 | —- | C] () – C:\Windows\System32\drivers\KmxAgent.asc
[2010/07/17 18:56:08 | 000,025,300 | —- | C] () – C:\Users\Byron\Documents\Bank letter.docx
[2010/07/17 18:56:04 | 000,013,275 | —- | C] () – C:\Users\Byron\Documents\Bills (Autosaved).xlsx
[2010/07/17 18:55:56 | 000,013,968 | —- | C] () – C:\Users\Byron\Documents\Hardship Letter.docx
[2010/07/17 18:55:50 | 000,035,840 | —- | C] () – C:\Users\Byron\Documents\Innovative_Ability_Form_System_Levin.doc
[2010/07/17 18:55:47 | 000,015,437 | —- | C] () – C:\Users\Byron\Documents\IAF_RSC_WallSystems-211 SHORT.docx
[2010/07/17 18:55:43 | 000,011,695 | —- | C] () – C:\Users\Byron\Documents\I intend to repay these people for sowing into my life.docx
[2010/07/17 18:55:30 | 000,248,515 | —- | C] () – C:\Users\Byron\Documents\Unit 5 IP - Art Appreciation.docx
[2010/07/17 18:55:28 | 000,018,780 | —- | C] () – C:\Users\Byron\Documents\Unit 4 Individual Project- Pure Per Se and Natural Monopolies.docx
[2010/07/17 18:55:26 | 000,246,211 | —- | C] () – C:\Users\Byron\Documents\Unit 3 IP - Art Appreciation.docx
[2010/07/17 18:55:25 | 000,016,815 | —- | C] () – C:\Users\Byron\Documents\Unit 3 Individual Project- Revised.docx
[2010/07/17 18:55:24 | 000,032,256 | —- | C] () – C:\Users\Byron\Documents\This week's schedule.xls
[2010/07/17 18:55:22 | 000,009,427 | —- | C] () – C:\Users\Byron\Documents\Schedule.xlsx
[2010/07/17 18:55:20 | 000,020,087 | —- | C] () – C:\Users\Byron\Documents\Resume-1[1].docx
[2010/07/17 18:55:18 | 000,013,385 | —- | C] () – C:\Users\Byron\Documents\Proposal for Errol Service.docx
[2010/07/17 18:55:16 | 000,010,695 | —- | C] () – C:\Users\Byron\Documents\PerkNation.com.docx
[2010/07/17 18:44:07 | 000,537,395 | —- | C] () – C:\Windows\System32\drivers\kmxcfg.u2k0
[2010/07/17 18:44:07 | 000,010,417 | —- | C] () – C:\Windows\System32\drivers\kmxcfg.u2k1
[2010/07/17 18:44:07 | 000,000,357 | —- | C] () – C:\Windows\System32\drivers\kmxzone.u2k2
[2010/07/17 18:44:07 | 000,000,357 | —- | C] () – C:\Windows\System32\drivers\kmxzone.u2k1
[2010/07/17 18:44:07 | 000,000,357 | —- | C] () – C:\Windows\System32\drivers\kmxzone.u2k0
[2010/07/17 18:44:07 | 000,000,289 | —- | C] () – C:\Windows\System32\drivers\kmxcfg.u2k2
[2010/07/17 18:44:07 | 000,000,081 | —- | C] () – C:\Windows\System32\drivers\kmxcfg.u2k7
[2010/07/17 18:44:07 | 000,000,081 | —- | C] () – C:\Windows\System32\drivers\kmxcfg.u2k6
[2010/07/17 18:44:07 | 000,000,081 | —- | C] () – C:\Windows\System32\drivers\kmxcfg.u2k5
[2010/07/17 18:44:07 | 000,000,081 | —- | C] () – C:\Windows\System32\drivers\kmxcfg.u2k4
[2010/07/17 18:44:07 | 000,000,081 | —- | C] () – C:\Windows\System32\drivers\kmxcfg.u2k3
[2010/07/17 18:44:07 | 000,000,045 | —- | C] () – C:\Windows\System32\drivers\kmxzone.u2k7
[2010/07/17 18:44:07 | 000,000,045 | —- | C] () – C:\Windows\System32\drivers\kmxzone.u2k6
[2010/07/17 18:44:07 | 000,000,045 | —- | C] () – C:\Windows\System32\drivers\kmxzone.u2k5
[2010/07/17 18:44:07 | 000,000,045 | —- | C] () – C:\Windows\System32\drivers\kmxzone.u2k4
[2010/07/17 18:44:07 | 000,000,045 | —- | C] () – C:\Windows\System32\drivers\kmxzone.u2k3
[2010/07/17 17:37:36 | 000,000,007 | —- | C] () – C:\Windows\System32\mkghj.dll
[2010/07/17 17:36:50 | 001,054,032 | —- | C] () – C:\Windows\System32\cfgmig32.dll
[2010/07/17 17:36:08 | 005,845,744 | —- | C] () – C:\Windows\System32\win32cpr.dll
[2010/07/17 17:36:08 | 002,385,136 | —- | C] () – C:\Windows\System32\winsflt_x64.dll
[2010/07/17 17:36:08 | 001,377,008 | —- | C] () – C:\Windows\System32\svcprs32.exe
[2010/07/17 17:36:07 | 002,347,760 | —- | C] () – C:\Windows\System32\mdmcls32.exe
[2010/07/17 17:36:07 | 001,872,624 | —- | C] () – C:\Windows\System32\winsflt.dll
[2010/07/17 17:36:07 | 000,286,208 | —- | C] () – C:\Windows\System32\winsfinst.exe
[2010/07/17 15:28:15 | 000,000,938 | —- | C] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/07/17 14:26:58 | 000,001,748 | —- | C] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/17 14:26:58 | 000,001,724 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/07/17 14:05:24 | 000,000,943 | —- | C] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/17 14:02:04 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2010/07/17 14:02:02 | 000,000,000 | —- | C] () – C:\Users\Byron\AppData\Local\QSwitch.txt
[2010/07/17 14:02:02 | 000,000,000 | —- | C] () – C:\Users\Byron\AppData\Local\DSwitch.txt
[2010/07/17 14:02:02 | 000,000,000 | —- | C] () – C:\Users\Byron\AppData\Local\AtStart.txt
[2010/07/17 13:58:20 | 000,002,063 | —- | C] () – C:\Users\Public\Desktop\eBay.lnk
[2010/07/17 13:57:47 | 000,001,859 | —- | C] () – C:\Users\Public\Desktop\HP Total Care Advisor.lnk
[2010/07/17 13:56:17 | 000,000,000 | RHS- | C] () – C:\Windows\System32\drivers\103C_HP_cNB_G60 Notebook PC_Y5335KV_0U_Q2CE9211DW5_E508165-002_4A_I3612_SWistron_V09.54_F.38_T090416_WV3-1_L409_M3003_J320_7Intel_867A_92.00_#100717_N10EC8136;168C002A_(NW142UA#ABA)_XMO
BILE_CN10_Z_2F.38.MRK
[2010/07/17 13:55:27 | 000,000,020 | -HS- | C] () – C:\Users\Byron\ntuser.ini
[2010/07/17 13:55:26 | 000,524,288 | -HS- | C] () – C:\Users\Byron\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2010/07/17 13:55:26 | 000,524,288 | -HS- | C] () – C:\Users\Byron\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/07/17 13:55:26 | 000,262,144 | -H– | C] () – C:\Users\Byron\ntuser.dat.LOG1
[2010/07/17 13:55:26 | 000,065,536 | -HS- | C] () – C:\Users\Byron\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/07/17 13:55:26 | 000,000,258 | —- | C] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/07/17 13:55:26 | 000,000,240 | —- | C] () – C:\Users\Byron\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/07/17 13:55:26 | 000,000,000 | -H– | C] () – C:\Users\Byron\ntuser.dat.LOG2
[2010/07/17 13:55:25 | 001,572,864 | -HS- | C] () – C:\Users\Byron\NTUSER.DAT
[2010/07/17 13:46:38 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2010/07/17 13:46:30 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/07/17 13:46:12 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/07/17 13:45:44 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/07/17 13:44:38 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/07/17 13:43:41 | 000,000,284 | —- | C] () – C:\ProgramData\hpqp.ini
[2010/07/17 13:41:57 | 000,016,072 | —- | C] () – C:\Windows\System32\results.xml
[2010/07/17 13:23:05 | 006,416,928 | —- | C] () – C:\Windows\System\DriveIcon.dll
[2010/07/17 13:23:05 | 000,005,430 | —- | C] () – C:\Windows\System\MyMulti.ico
[2010/07/17 13:19:42 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2008/07/06 13:29:46 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1518.dll
[2008/06/29 07:52:14 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 02:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll

========== LOP Check ==========

[2010/08/06 15:16:45 | 000,000,000 | —D | M] – C:\Users\Byron\AppData\Roaming\BitTorrent
[2010/08/02 10:43:12 | 000,000,000 | —D | M] – C:\Users\Byron\AppData\Roaming\Good Deal Software
[2010/07/18 16:51:33 | 000,000,000 | —D | M] – C:\Users\Byron\AppData\Roaming\KeePass
[2010/08/04 07:17:42 | 000,014,972 | —- | M] () – C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/20 19:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\System32\drivers\AGP440.sys
[2008/01/20 19:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/20 19:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/20 19:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 02:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/10 23:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\WINDOWS\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/20 19:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/20 19:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 02:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2009/04/09 03:32:45 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=9C0E70031905ADBF94EDB9EA14AF943B – C:\WINDOWS\System32\drivers\atapi.sys
[2009/04/09 03:32:45 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=9C0E70031905ADBF94EDB9EA14AF943B – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_7f3e4ed9\atapi.sys
[2009/04/09 03:32:45 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=9C0E70031905ADBF94EDB9EA14AF943B – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_dd6376773aedb5e4\atapi.sys
[2009/04/09 03:32:45 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E26DDFE464B464DAF1C739122978D1D6 – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_b7393fc6\atapi.sys
[2009/04/09 03:32:45 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E26DDFE464B464DAF1C739122978D1D6 – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_dbb74a7b3d9afbc1\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\WINDOWS\System32\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/05/17 21:34:04 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008/01/20 19:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\WINDOWS\System32\drivers\iaStorV.sys
[2008/01/20 19:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/20 19:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\WINDOWS\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 02:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\WINDOWS\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/20 19:24:05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\WINDOWS\System32\netlogon.dll
[2008/01/20 19:24:05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 02:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/20 19:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\WINDOWS\System32\drivers\nvstor.sys
[2008/01/20 19:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/20 19:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\WINDOWS\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 19:24:50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\WINDOWS\System32\scecli.dll
[2008/01/20 19:24:50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\WINDOWS\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/01/20 19:24:26 | 000,347,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\dxtmsft.dll
[2008/01/20 19:24:26 | 000,214,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\dxtrans.dll
[2008/01/20 19:24:42 | 000,242,744 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\rsaenh.dll
[2008/01/20 19:24:38 | 000,225,792 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\WINDOWS\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\WINDOWS\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV
< End of report >

Results of Extras.Txt

OTL Extras logfile created on: 8/6/2010 3:10:24 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Byron\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.00% Memory free
6.00 Gb Paging File | 3.00 Gb Available in Paging File | 46.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 204.06 Gb Free Space | 71.06% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.82 Gb Free Space | 16.70% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BYRON-PC
Current User Name: Byron
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{EB1C9529-741E-4339-A7A9-54990C91A763}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{298FE1CB-5412-487C-B818-FB46BE1D3B34}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{320B4419-1380-43D1-9A3F-CFB3C089987D}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{8809A535-8907-4BFD-87B2-83BFD937265C}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{9650484A-3BB3-4184-AFCD-4B3B6C4355AD}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{C54EA3BB-A701-49B6-AEEF-CD7F7543AE4A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{D2C45D5E-10E2-4478-9705-48C8B81E66D1}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{F3330545-4170-4F18-8257-68120669276B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}" = Java DB 10.5.3.0
"{01A3E75B-54C0-407F-8B95-B77705C7DCC4}" = AMRT
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0E549A13-2B3D-4633-BA41-DC88C2D6F9A3}" = ProductContext
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{1147FF9A-D576-4cb5-B5E7-FCA21D1E7D26}" = J4680
"{1367D815-EC9F-4e2f-9FB9-E40A075AD19B}" = DNAMigrator
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{188C0E25-3D65-4DAC-9C00-7483FBA4C7EB}" = Status
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{2681A52E-FCFA-4982-A030-7B652BDD346C}" = CA Personal Firewall
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{32A3A4F4-B792-11D6-A78A-00B0D0160210}" = Java™ SE Development Kit 6 Update 21
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{38058455-8C21-4C2F-B2F6-14ED166039CB}" = HP Total Care Setup
"{38151262-FAF8-4778-9AAB-33E90B60D8E9}" = CA Anti-Virus Plus
"{3825B383-7880-48C8-AADD-49B0D764B151}" = 4660_4680_Help
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50802F8E-03B4-479D-A643-16DE5A3586CB}" = BPDSoftware_Ini
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{5A05B328-35EB-4CED-B16F-62FA5A2642E6}" =
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5BB4D7C1-52F2-4BFD-9E40-0D419E2E3021}" = bpd_scan
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}" = Juno Preloader
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{665CBCA4-5AB0-414B-A288-3F8F99FEFC45}" = HP User Guides 0118
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67335AB1-6341-4f87-A5B4-7FA92CEB77A4}" = HP Officejet All-In-One Series
"{679EC478-3FF9-4987-B2FF-C2C2B27532A2}" = DocProc
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A370610-3778-44AF-9AAC-69B2FD1A3356}" = Microsoft Live Search Toolbar
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABA00898-9467-4689-9F40-DE7F58C8429C}" = Fax
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{ACDE260A-602B-4cfb-A650-D0DBA6FFAD85}" = NetDeviceManager
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CDB98E2F-7B2A-42C2-B718-F1F6B31586DF}" = CA Website Inspector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D142FE39-3386-4d82-9AD3-36D4A92AC3C2}" = DocMgr
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D3737952-FF6E-4E72-BDEE-B0DC1C69F80B}" = BPD_HPSU
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F4EAEBEA-3E46-43b8-A63C-AD180AE86918}" = BPDSoftware
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BitTorrent" = BitTorrent
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Craigs Search Agent" = Craigs Search Agent Trial Version 2.1
"ENTERPRISER" = Microsoft Office Enterprise 2007
"eTrust Suite Personal" = CA Internet Security Suite
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Document Manager" = HP Document Manager 1.0
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"HPOCR" = OCR Software by I.R.I.S. 10.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.12
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.0
"WildTangent hp Master Uninstall" = My HP Games
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/31/2010 9:02:33 PM | Computer Name = Byron-PC | Source = EventSystem | ID = 4609
Description =

Error - 7/31/2010 9:04:01 PM | Computer Name = Byron-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/31/2010 9:23:32 PM | Computer Name = Byron-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/31/2010 9:44:06 PM | Computer Name = Byron-PC | Source = EventSystem | ID = 4609
Description =

Error - 7/31/2010 9:45:34 PM | Computer Name = Byron-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/31/2010 9:49:56 PM | Computer Name = Byron-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/31/2010 9:55:34 PM | Computer Name = Byron-PC | Source = EventSystem | ID = 4609
Description =

Error - 7/31/2010 9:57:01 PM | Computer Name = Byron-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/31/2010 10:03:24 PM | Computer Name = Byron-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/1/2010 3:47:32 AM | Computer Name = Byron-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 7/31/2010 10:03:24 PM | Computer Name = Byron-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/31/2010 10:03:33 PM | Computer Name = Byron-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 7/31/2010 10:03:33 PM | Computer Name = Byron-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 7/31/2010 10:03:39 PM | Computer Name = Byron-PC | Source = DCOM | ID = 10016
Description =

Error - 7/31/2010 10:03:39 PM | Computer Name = Byron-PC | Source = DCOM | ID = 10016
Description =

Error - 7/31/2010 10:03:41 PM | Computer Name = Byron-PC | Source = DCOM | ID = 10016
Description =

Error - 7/31/2010 10:03:41 PM | Computer Name = Byron-PC | Source = DCOM | ID = 10016
Description =

Error - 7/31/2010 10:03:44 PM | Computer Name = Byron-PC | Source = DCOM | ID = 10016
Description =

Error - 7/31/2010 10:03:44 PM | Computer Name = Byron-PC | Source = DCOM | ID = 10016
Description =

Error - 8/1/2010 3:45:53 AM | Computer Name = Byron-PC | Source = HTTP | ID = 15016
Description =


< End of report >
Hi,

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT


Please post the ComboFix Log(s) which can be located at c:\combofix.txt and C:\qoobox\combofix2.txt, c:\qoobox\combofix3.txt etc.


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
yes, sorry about the delay, we have been experiencing the odd glitch in the forum lately and i didn't receive notification of your reply, if that happens again, please feel free to send me a PM
OTL keeps stalling my computer for a long time so I end up rebooting it. MalwareBytes doesn't want to launch either. As a last resort, I've moved to the next step of running online Kapersky. It's running now. I don't know what else to do, as it's taking so long.
Online Kapersky won't scan. It keeps stopping short of the update. MalewareBytes won't run. I had previously disabled my antivirus software, and now it too won't update. It says it's out of date. My computer still runs, albeit slowly. Another strange thing is happening as well. Whenever I type something in Google and click, the page goes to the desired site but quickly lands on another advertising website. I'm not sure what that's about other than to think my browser has been hijacked.
Hi

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
there is no threat in ComboFix please right click the combofix Icon > delete no disable CA internet antivirus and download a fresh copy of combofix and run it with CA disabled.
ComboFix will save to my desktop but after I give permission to run it, nothing happens. I've attempted to run it several times now. I've even tried to run MalwareBytes and it does nothing as well.
please delete the copy you have (right click > delete) down load a fresh copy, rename it to Combo.com before saving it to your desktop

now boot into safe mode and run it


(reboot > tap F8 upon bootup until an advanced menu appears > arrow up to safe mode)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI