MML_1980
Topic Starter
A few weeks ago, my computer was running normally - and then it shut itself off out of nowhere. Since then it's been behaving bizarrely; I've had issues with all of my firewall history disappearing and a warning when I log into Yahoo that 'my browser doesn't support redirects'. Also had trouble installing a support update for the Synaptecs TouchPad. This morning I closed my browser and it warned me that some files related to windows related to the operation of Chrome no longer exist. The browser opperated correctly, so I simply said it was working well when prompted. When I logged back on my HP Support assistant launched and asked me if I wanted to make changed to the computer. I said yes, figuring this was part of an update. It launched my HP health check and numerous features in it…including a cscript.exe file.
Since then, I've found an exclusion data.xml file in my HP Healthcheck, updated today, with the following saved in it:
-
-
SDBOTGood.xml
-1
02/16/2006
-
NAVVerGood.xml
-1
02/16/2006
-
DelProtSys.xml
-1
02/16/2006
-
HaxDoor.xml
-1
02/16/2006
-
SpywareAdvertizing.xml
-1
02/16/2006
-
SpywareError.xml
-1
02/16/2006
-
SpywarePrivacy.xml
-1
02/16/2006
-
SpywareSecurity.xml
-1
02/16/2006
Also, I ran a variety of Rootkit detectors, and the only one that pulled up anything was CatchMe:
disk not found C:\
please note that you need administrator rights to perform deep scan
detected NTDLL code modification:
ZwEnumerateKey 0 != 47, ZwQueryKey 0 != 19, ZwOpenKey 0 != 15, ZwClose 0 != 12, ZwEnumerateValueKey 0 != 16, ZwQueryValueKey 0 != 20, ZwOpenFile 0 != 48, ZwQueryDirectoryFile 0 != 50, ZwQuerySystemInformation 0 != 51Initialization error
My Norton comes up with some medium-level activity, though no threat warnings: all of them seem to involve HPTouchCheck.exe has been submitted for a Sample Submission. Lots of instances of WerFault.exe. WMIPRVSE.EXE was blocked repeatedly from accessing the ccSvcHst file. A 6BF2.TMP\PEV.RKEXE tried repeatedly to access ccSvcHst.exe and was blocked (probably to do with the Root Repeal runs?) and also statistical submissions for krsqxp.exe, nircmd c.rkexe. There was also an error condition detected of high severity, errror class 0xFDB6E1EA. It blocked access thread data from Services, which triggered SymErr.exe. Statistical submissions for tlbjsw.exe and tmgrnwq.exe, vgslsf.exe. There are two IPS Detection Statistical submissions that mistake my downloading various programs as a remote attack, but the URL is seen as the attacker, not my PC.
Here's what was in my windows event logs:
The Application Virtualization Client Core initalized correctly
My Windows live has opened a lot of process keys
An error was detected on device\CDRom0 during a paging operation
Failed Application Name: RootkitRevealer.exe
Exception Code 0x00004cd
MEMSWEEP2 service failed to start due to the following error:
the driver has been blocked from loading
(That's from Sophos)
\??\C:\\Windows\system32\95ED.tmp has been blocked from loading due to incomaptibility with this system.
Same for \??\C:\\Windows\system32\D33A.tmp
Norton opened 8 Registry keys too
The one that really caught my eye was:
Volume Shadow Copy Service warning: VSS was denied access to the root volume of \\?\Volume(3106c431-cdac-11df-9a37-c80aa996553e]\ It says that administrator rights have been denied it and that it could prevent VSS from functioning properly.
There was also a warning about a patch task for the CVHSVC that failed - Probably 'cause I dissabled my connection.
Root Repeal also crashed because of werinternalmetadata.xml errors
Also errors for the ITSS and HHCTRL, with EVENT IDs 1 and 1904 unable to be found. I found that I couldn't access the help functions on
There's also a warning for the Application Virtualization client intitalizign correctly o_0
The winlogon notification subscriber was unavailible to handle a critical notification event.
I found the error that caused my initial Chrome problem:
Event Name PCA2
Fault Bucket 501991210
There was also a RADAR_PRE_LEAK_WOW64 for Acrobat just before this (I'd used it for the first time).
The unauthorized modifications, according to my seccurity viewer, seem to be to D33A.TMP and 95ED.TMP.
The effected computer is completely disconnected from the internet, so I'm typing from my unefected one. They did share the same Netgear wireless router, however. My symptoms are generalized slowness, and an occasional jumpy/spotty cursor.
I've posted all of this to the Symantec official forum, and was redirected here for assitance. Here's my DDS log; Norton, MWB and SuperAntiSpyware scans have all come up clean:
DDS (Ver_10-10-21.02) - NTFS_AMD64
Run by [removed] at 9:48:02.14 on Thu 10/28/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.1787.139 [GMT -4:00]
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\melissa\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Users\melissa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Windows\system32\conhost.exe
C:\Users\melissa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\melissa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\melissa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\melissa\Downloads\dds.scr
C:\Windows\system32\conhost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll
TB: @c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
uRun: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\melissa\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" UNATTENDED
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: []
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun-x64: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
mRun-x64: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
mRun-x64: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
mRun-x64: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1201000.025\SymDS64.sys [2010-10-25 450096]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1201000.025\SymEFA64.sys [2010-10-25 821808]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101001.001\BHDrvx64.sys [2010-8-31 954928]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101027.001\IDSviA64.sys [2010-10-19 476720]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1201000.025\Ironx64.sys [2010-10-25 168496]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NISx64\1201000.025\symnets.sys [2010-10-25 381488]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-9-20 7767552]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-9-20 279040]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-7-17 132656]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-23 344680]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-4-24 721768]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-4-24 269672]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-4-24 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-4-24 22376]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2010-5-15 38456]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-5-15 239136]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
=============== Created Last 30 ================
2010-10-28 11:13:14 ——– d—–w- C:\Program Files (x86)\ESET
2010-10-27 19:45:25 ——– d—–w- C:\PROGRA~3\Recovery
2010-10-26 17:15:19 ——– d—–w- C:\Program Files (x86)\MSN Toolbar
2010-10-26 17:14:12 ——– d—–w- C:\Program Files (x86)\Bing Bar Installer
2010-10-26 17:11:33 961024 —-a-w- C:\Windows\System32\CPFilters.dll
2010-10-26 17:11:33 641536 —-a-w- C:\Windows\SysWow64\CPFilters.dll
2010-10-26 17:11:33 552960 —-a-w- C:\Windows\System32\msdri.dll
2010-10-26 17:11:32 288256 —-a-w- C:\Windows\System32\MSNP.ax
2010-10-26 17:11:32 258560 —-a-w- C:\Windows\System32\mpg2splt.ax
2010-10-26 17:11:32 204288 —-a-w- C:\Windows\SysWow64\MSNP.ax
2010-10-26 17:11:32 199680 —-a-w- C:\Windows\SysWow64\mpg2splt.ax
2010-10-26 17:11:24 27008 —-a-w- C:\Windows\System32\drivers\Diskdump.sys
2010-10-25 19:55:12 381488 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\symnets.sys
2010-10-25 19:55:11 821808 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\SymEFA64.sys
2010-10-25 19:55:11 715824 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\srtsp64.sys
2010-10-25 19:55:11 450096 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\SymDS64.sys
2010-10-25 19:55:11 40496 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\srtspx64.sys
2010-10-25 19:55:11 168496 —-a-r- C:\Windows\System32\drivers\NISx64\1201000.025\Ironx64.sys
2010-10-25 19:55:00 ——– d—–w- C:\Windows\System32\drivers\NISx64\1201000.025
2010-10-20 04:52:23 ——– d—–w- C:\Windows\en
2010-10-20 04:41:40 69464 —-a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2010-10-20 04:41:40 515416 —-a-w- C:\Windows\SysWow64\XAudio2_5.dll
2010-10-20 04:41:39 523088 —-a-w- C:\Windows\System32\d3dx10_42.dll
2010-10-20 04:41:39 453456 —-a-w- C:\Windows\SysWow64\d3dx10_42.dll
2010-10-20 04:41:07 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\266adaf1cb701105\DSETUP.dll
2010-10-20 04:41:07 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\266adaf1cb701105\DXSETUP.exe
2010-10-20 04:41:07 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\266adaf1cb701105\dsetup32.dll
2010-10-20 04:41:05 94040 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\92d1731cb701104\DSETUP.dll
2010-10-20 04:41:05 525656 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\92d1731cb701104\DXSETUP.exe
2010-10-20 04:41:05 1691480 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\92d1731cb701104\dsetup32.dll
2010-10-20 04:39:00 ——– d—–w- C:\Users\melissa\AppData\Local\Windows Live
2010-10-20 04:37:39 257024 —-a-w- C:\Windows\System32\mfreadwrite.dll
2010-10-20 04:37:39 206848 —-a-w- C:\Windows\System32\mfps.dll
2010-10-20 04:37:38 196608 —-a-w- C:\Windows\SysWow64\mfreadwrite.dll
2010-10-20 04:37:38 1888256 —-a-w- C:\Windows\System32\WMVDECOD.DLL
2010-10-20 04:37:38 1619456 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2010-10-20 04:37:36 4068864 —-a-w- C:\Windows\System32\mf.dll
2010-10-20 04:37:35 3181568 —-a-w- C:\Windows\SysWow64\mf.dll
2010-10-13 23:10:31 167424 —-a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2010-10-13 23:10:31 164864 —-a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2010-10-13 23:10:30 12625920 —-a-w- C:\Windows\System32\wmploc.DLL
2010-10-13 23:10:30 12625408 —-a-w- C:\Windows\SysWow64\wmploc.DLL
2010-10-13 23:10:29 463360 —-a-w- C:\Windows\System32\drivers\srv.sys
2010-10-13 23:10:28 9728 —-a-w- C:\Windows\SysWow64\sscore.dll
2010-10-13 23:10:28 402944 —-a-w- C:\Windows\System32\drivers\srv2.sys
2010-10-13 23:10:28 236032 —-a-w- C:\Windows\System32\srvsvc.dll
2010-10-13 23:10:28 161792 —-a-w- C:\Windows\System32\drivers\srvnet.sys
2010-10-13 23:10:27 3123712 —-a-w- C:\Windows\System32\win32k.sys
2010-10-02 05:34:35 ——– d—–w- C:\PROGRA~3\VirtualizedApplications
2010-10-02 03:22:37 ——– d—–w- C:\Users\melissa\AppData\Local\SoftGrid Client
2010-10-02 03:22:34 ——– d—–w- C:\Users\melissa\AppData\Roaming\SoftGrid Client
2010-10-02 03:20:15 ——– d—–w- C:\Program Files (x86)\Microsoft Application Virtualization Client
2010-10-02 03:19:16 ——– d—–w- C:\Users\melissa\AppData\Roaming\TP
2010-10-01 23:04:36 214824 —-a-w- C:\Windows\System32\SynTPAPI.dll
2010-10-01 23:04:36 147752 —-a-w- C:\Windows\System32\SynTPCo4.dll
2010-10-01 23:04:32 396584 —-a-w- C:\Windows\System32\SynCOM.dll
2010-10-01 22:58:35 1964576 —-a-w- C:\Windows\System32\RtPgEx64.dll
2010-10-01 22:58:35 1146912 —-a-w- C:\Windows\System32\RTSnMg64.cpl
2010-10-01 22:58:34 332320 —-a-w- C:\Windows\System32\RtlCPAPI64.dll
2010-10-01 22:58:34 2374560 —-a-w- C:\Windows\System32\drivers\RTKVHD64.sys
2010-10-01 22:58:33 2603040 —-a-w- C:\Windows\System32\RtkAPO64.dll
2010-10-01 22:58:33 149536 —-a-w- C:\Windows\System32\RtkCfg64.dll
2010-10-01 22:58:32 476192 —-a-w- C:\Windows\System32\RtkApi64.dll
2010-10-01 22:58:32 1216032 —-a-w- C:\Windows\System32\RTCOM64.dll
2010-10-01 22:58:31 70176 —-a-w- C:\Windows\System32\RCoInst64.dll
2010-09-28 21:19:19 243712 —-a-w- C:\Windows\System32\drivers\ks.sys
2010-09-28 21:19:19 184832 —-a-w- C:\Windows\System32\drivers\usbvideo.sys
2010-09-28 21:05:33 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2010-09-28 21:05:33 2048 —-a-w- C:\Windows\System32\tzres.dll
2010-09-28 21:05:22 13312 —-a-w- C:\Program Files\Internet Explorer\iecompat.dll
2010-09-28 21:05:22 13312 —-a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
==================== Find3M ====================
2010-10-25 19:55:29 174640 —-a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2010-10-01 22:55:18 1251872 —-a-w- C:\Windows\RtlExUpd.dll
2010-09-23 04:47:28 49016 —-a-w- C:\Windows\SysWow64\sirenacm.dll
2010-09-23 04:32:56 301936 —-a-w- C:\Windows\WLXPGSS.SCR
2010-09-21 18:49:02 252800 —-a-w- C:\Windows\System32\LIVESSP.DLL
2010-09-21 18:03:14 208768 —-a-w- C:\Windows\SysWow64\LIVESSP.DLL
2010-09-20 06:14:16 7767552 —-a-w- C:\Windows\System32\drivers\atikmdag.sys
2010-09-20 06:12:00 20734464 —-a-w- C:\Windows\System32\atio6axx.dll
2010-09-20 05:59:42 143360 —-a-w- C:\Windows\System32\atiapfxx.exe
2010-09-20 05:56:38 450560 —-a-w- C:\Windows\System32\ATIDEMGX.dll
2010-09-20 05:56:32 461824 —-a-w- C:\Windows\System32\atieclxx.exe
2010-09-20 05:56:00 203264 —-a-w- C:\Windows\System32\atiesrxx.exe
2010-09-20 05:54:54 120320 —-a-w- C:\Windows\System32\atitmm64.dll
2010-09-20 05:54:52 15828480 —-a-w- C:\Windows\SysWow64\atioglxx.dll
2010-09-20 05:54:38 421376 —-a-w- C:\Windows\System32\atipdl64.dll
2010-09-20 05:54:32 356352 —-a-w- C:\Windows\SysWow64\atipdlxx.dll
2010-09-20 05:54:22 278528 —-a-w- C:\Windows\SysWow64\Oemdspif.dll
2010-09-20 05:54:18 12288 —-a-w- C:\Windows\System32\atimuixx.dll
2010-09-20 05:54:14 59392 —-a-w- C:\Windows\System32\atiedu64.dll
2010-09-20 05:54:08 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll
2010-09-20 05:52:54 3147264 —-a-w- C:\Windows\System32\atiumd6a.dll
2010-09-20 05:51:20 3913216 —-a-w- C:\Windows\SysWow64\atidxx32.dll
2010-09-20 05:46:00 3390976 —-a-w- C:\Windows\SysWow64\atiumdva.dll
2010-09-20 05:42:58 4602880 —-a-w- C:\Windows\System32\atidxx64.dll
2010-09-20 05:33:38 53760 —-a-w- C:\Windows\System32\atimpc64.dll
2010-09-20 05:33:38 53760 —-a-w- C:\Windows\System32\amdpcom64.dll
2010-09-20 05:33:32 52736 —-a-w- C:\Windows\SysWow64\atimpc32.dll
2010-09-20 05:33:32 52736 —-a-w- C:\Windows\SysWow64\amdpcom32.dll
2010-09-20 05:33:30 4032512 —-a-w- C:\Windows\SysWow64\atiumdag.dll
2010-09-20 05:33:04 51200 —-a-w- C:\Windows\System32\aticalrt64.dll
2010-09-20 05:33:02 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll
2010-09-20 05:32:54 44544 —-a-w- C:\Windows\System32\aticalcl64.dll
2010-09-20 05:32:52 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll
2010-09-20 05:32:42 5425664 —-a-w- C:\Windows\System32\aticaldd64.dll
2010-09-20 05:31:36 4375552 —-a-w- C:\Windows\SysWow64\aticaldd.dll
2010-09-20 05:30:28 57344 —-a-w- C:\Windows\System32\coinst.dll
2010-09-20 05:27:42 5202944 —-a-w- C:\Windows\System32\atiumd64.dll
2010-09-20 05:21:30 338432 —-a-w- C:\Windows\System32\atiadlxx.dll
2010-09-20 05:21:24 241664 —-a-w- C:\Windows\SysWow64\atiadlxy.dll
2010-09-20 05:21:16 14848 —-a-w- C:\Windows\System32\atig6pxx.dll
2010-09-20 05:21:12 12800 —-a-w- C:\Windows\SysWow64\atiglpxx.dll
2010-09-20 05:21:12 12800 —-a-w- C:\Windows\System32\atiglpxx.dll
2010-09-20 05:21:10 21504 —-a-w- C:\Windows\System32\atig6txx.dll
2010-09-20 05:21:06 19968 —-a-w- C:\Windows\SysWow64\atigktxx.dll
2010-09-20 05:21:04 279040 —-a-w- C:\Windows\System32\drivers\atikmpag.sys
2010-09-20 05:20:24 39424 —-a-w- C:\Windows\System32\atiuxp64.dll
2010-09-20 05:20:18 30208 —-a-w- C:\Windows\SysWow64\atiuxpag.dll
2010-09-20 05:20:12 37376 —-a-w- C:\Windows\System32\atiu9p64.dll
2010-09-20 05:20:06 27648 —-a-w- C:\Windows\SysWow64\atiu9pag.dll
2010-09-20 05:19:34 53248 —-a-w- C:\Windows\System32\drivers\ati2erec.dll
2010-09-15 08:50:37 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2010-09-10 05:35:44 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-09-10 05:35:43 347648 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-09-08 05:36:17 1192960 —-a-w- C:\Windows\System32\wininet.dll
2010-09-08 05:34:34 57856 —-a-w- C:\Windows\System32\licmgr10.dll
2010-09-08 04:30:04 978432 —-a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 04:28:15 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38 482816 —-a-w- C:\Windows\System32\html.iec
2010-09-08 03:35:30 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2010-09-08 03:22:31 386048 —-a-w- C:\Windows\SysWow64\html.iec
2010-09-08 02:48:16 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2010-08-31 04:32:30 954752 —-a-w- C:\Windows\SysWow64\mfc40.dll
2010-08-31 04:32:30 954288 —-a-w- C:\Windows\SysWow64\mfc40u.dll
2010-08-26 05:27:28 148992 —-a-w- C:\Windows\System32\t2embed.dll
2010-08-26 04:39:58 109056 —-a-w- C:\Windows\SysWow64\t2embed.dll
2010-08-21 06:38:47 1024512 —-a-w- C:\Windows\System32\wmpmde.dll
2010-08-21 06:36:49 340992 —-a-w- C:\Windows\System32\schannel.dll
2010-08-21 06:31:06 633856 —-a-w- C:\Windows\System32\comctl32.dll
2010-08-21 06:29:47 558592 —-a-w- C:\Windows\System32\spoolsv.exe
2010-08-21 05:36:33 738816 —-a-w- C:\Windows\SysWow64\wmpmde.dll
2010-08-21 05:36:24 224256 —-a-w- C:\Windows\SysWow64\schannel.dll
2010-08-21 05:33:24 530432 —-a-w- C:\Windows\SysWow64\comctl32.dll
============= FINISH: 9:52:48.86 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-10-21.02)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 7/17/2010 9:32:23 PM
System Uptime: 10/28/2010 6:31:32 AM (3 hours ago)
Motherboard: Hewlett-Packard | | 1444
Processor: AMD V120 Processor | Socket S1G4 | 2200/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 219 GiB total, 174.979 GiB free.
D: is FIXED (NTFS) - 14 GiB total, 1.943 GiB free.
E: is FIXED (FAT32) - 0 GiB total, 0.09 GiB free.
F: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP64: 10/13/2010 8:50:35 PM - Windows Update
RP65: 10/16/2010 1:34:33 AM - HPSF Restore Point
RP66: 10/16/2010 1:52:20 AM - HPSF Applying updates
RP67: 10/17/2010 7:00:12 PM - Windows Backup
RP68: 10/20/2010 12:36:45 AM - Windows Update
RP69: 10/22/2010 6:30:52 PM - HPSF Applying updates
RP70: 10/23/2010 7:48:11 PM - Windows Update
RP71: 10/25/2010 12:23:54 AM - Windows Backup
RP72: 10/25/2010 1:55:19 PM - Installed Java™ 6 Update 22
RP73: 10/25/2010 5:28:16 PM - HPSF Applying updates
RP74: 10/25/2010 5:34:32 PM - Windows Update
RP75: 10/26/2010 1:11:47 PM - Windows Update
RP76: 10/26/2010 1:27:08 PM - Windows Update
==== Installed Programs ======================
1st Page 2000 2.00 Free
Acrobat.com
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.4.0 MUI
Adobe Shockwave Player
AIM 7
Alien Outbreak 2
AMD USB Filter Driver
Atheros Driver Installation Program
Bejeweled Twist
Bing Bar
Bing Bar Platform
Bing Rewards Client Installer
Boulder Dash - Pirates Quest
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CinemaNow Media Manager
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Compatibility Pack for the 2007 Office system
CyberLink DVD Suite
CyberLink MediaShow
CyberLink PowerDVD 9
CyberLink YouCam
D3DX10
Download Updater (AOL LLC)
ESU for Microsoft Windows 7
Google Chrome
HP Advisor
HP Customer Experience Enhancements
HP Games
HP MediaSmart CinemaNow 2.0
HP Photo Creations
HP Power Plan Utility
HP Setup
HP Software Framework
HP Support Assistant
HP Update
HP User Guides 0178
HPAsset component for HP Active Support Library
Internet TV for Windows Media Center
Ipswitch WS_FTP Home 2007
Jasc Animation Shop 3
Jasc Paint Shop Pro 9
Java Auto Updater
Java™ 6 Update 22
Junk Mail filter update
LabelPrint
LightScribe System Software
Malwarebytes' Anti-Malware
Microsoft Default Manager
Microsoft Office Click-to-Run 2010
Microsoft Office Home and Student 2010 - English
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Suite Activation Assistant
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Microsoft WSE 3.0 Runtime
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Norton Internet Security
Norton Online Backup
PhotoNow!
Power2Go
PowerDirector
Realtek Ethernet Controller Driver For Windows 7
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Recovery Manager
Roxio CinemaNow 2.0
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Center Add-in for Flash
==== End Of File ===========================