This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Virus - - many .exe files are missing (hijackthis log)

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am currently running Windows 7 Ultimate. About once or twice per day I was getting the Blue Screen of Death. I ran Registry Mechanic (it fixed some things), Spybot (it also fixed a few things), Malware Bytes (fixed a few things), and a couple of other things. I ran Hijackthis and found quite a few files missing. I tried to fix them and HJT cannot fix them. Below are my OTL, Extras, and HJT logs…. thanks in advance for any help.

OTL Report

OTL logfile created on: 12/7/2010 11:01:48 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\sumtingwong1381\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 63.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 58.08 Gb Free Space | 24.94% Space Free | Partition Type: NTFS
Drive D: | 279.47 Gb Total Space | 82.03 Gb Free Space | 29.35% Space Free | Partition Type: NTFS
Drive G: | 3.68 Gb Total Space | 3.33 Gb Free Space | 90.62% Space Free | Partition Type: FAT32

Computer Name: BRANDONS | User Name: sumtingwong1381 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\sumtingwong1381\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\sumtingwong1381\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (WebrootSpySweeperService) – C:\Program Files (x86)\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (P17) – C:\Windows\SysNative\drivers\P17.sys (Creative Technology Ltd.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (FETNDIS) – C:\Windows\SysNative\drivers\fet6x64.sys (VIA Technologies, Inc. )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (ssidrv) – C:\Windows\SysNative\drivers\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssfs0bbc) – C:\Windows\SysNative\drivers\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (UltraMonUtility) – C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys (Realtime Soft Ltd)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F6 D1 97 28 20 94 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2010/04/30 13:56:09 | 000,001,798 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/12/04 11:08:24 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.ACDV - File not found
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: VIDC.ACDV - ACDV.dll File not found
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/12/07 22:57:02 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\sumtingwong1381\Desktop\OTL.exe
[2010/12/07 22:24:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\EXErrorsFix
[2010/12/07 22:21:00 | 000,000,000 | —D | C] – C:\ProgramData\WebRoot
[2010/12/07 22:16:44 | 000,000,000 | —D | C] – C:\!KillBox
[2010/12/07 22:16:05 | 000,034,816 | —- | C] (Soeperman Enterprises Ltd.) – C:\Users\sumtingwong1381\Desktop\IBProcMan.exe
[2010/12/07 21:42:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/12/07 21:32:52 | 000,017,264 | —- | C] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\SysNative\SsiEfr.exe
[2010/12/07 21:32:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Webroot
[2010/12/07 21:31:36 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Registry Mechanic
[2010/12/07 21:27:31 | 000,658,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSCOMCT2.OCX
[2010/12/07 21:16:49 | 001,101,824 | —- | C] (Woodbury Associates Limited) – C:\Windows\SysWow64\UniBox210.ocx
[2010/12/07 21:16:49 | 000,880,640 | —- | C] (Woodbury Associates Limited) – C:\Windows\SysWow64\UniBox10.ocx
[2010/12/07 21:16:49 | 000,506,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml.dll
[2010/12/07 21:16:49 | 000,212,992 | —- | C] (Woodbury Associates Limited) – C:\Windows\SysWow64\UniBoxVB12.ocx
[2010/12/07 21:16:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2010/12/07 21:16:47 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/12/07 21:16:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Registry Mechanic
[2010/12/06 22:46:25 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/12/06 22:44:04 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/12/06 22:38:02 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/12/06 22:38:02 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/12/06 22:38:02 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/12/06 22:37:57 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/12/06 22:37:47 | 000,000,000 | —D | C] – C:\Qoobox
[2010/12/06 22:37:32 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/12/06 22:37:30 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/12/06 22:11:31 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Malwarebytes
[2010/12/06 22:11:23 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/12/06 22:11:21 | 000,024,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/12/06 22:11:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/12/06 22:11:21 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/12/06 21:41:44 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Adobe Mini Bridge CS5
[2010/12/06 21:41:43 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/12/06 21:15:24 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/12/05 21:42:38 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Realtime Soft
[2010/12/05 14:32:36 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\Desktop\Untitled Export
[2010/12/04 23:41:30 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\ACD Systems
[2010/12/04 23:41:30 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\ACD Systems
[2010/12/04 23:40:10 | 000,000,000 | —D | C] – C:\ProgramData\ACD Systems
[2010/12/04 23:39:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ACD Systems
[2010/12/04 23:39:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\ACD Systems
[2010/12/04 23:38:25 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Downloaded Installations
[2010/12/04 23:11:33 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Apple Computer
[2010/12/04 23:11:33 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Apple Computer
[2010/12/04 23:11:17 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2010/12/04 23:11:17 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2010/12/04 23:11:17 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2010/12/04 23:11:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/12/04 23:11:06 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/12/04 23:11:05 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/12/04 23:11:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2010/12/04 23:11:05 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2010/12/04 23:10:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2010/12/04 23:10:06 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/12/04 23:09:58 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Apple
[2010/12/04 23:09:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2010/12/04 23:09:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/12/04 23:09:40 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/12/04 23:09:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2010/12/04 23:09:36 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/12/04 23:09:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2010/12/04 23:01:31 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Anthropics
[2010/12/04 22:58:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Portrait Professional Studio 9
[2010/12/04 22:47:39 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Diagnostics
[2010/12/04 22:37:30 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010/12/04 22:36:05 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/12/04 22:35:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/12/04 22:34:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe Media Player
[2010/12/04 22:32:16 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2010/12/04 22:32:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe AIR
[2010/12/04 22:32:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2010/12/04 22:31:05 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2010/12/04 22:29:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2010/12/04 22:27:55 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Macromedia
[2010/12/04 22:27:51 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Adobe
[2010/12/04 22:27:31 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Adobe
[2010/12/04 22:18:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Creative
[2010/12/04 22:18:41 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Creative Installation Information
[2010/12/04 22:18:39 | 000,419,840 | —- | C] (Creative Labs) – C:\Windows\SysNative\wrap_oal.dll
[2010/12/04 22:18:39 | 000,133,632 | —- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysNative\OpenAL32.dll
[2010/12/04 22:18:38 | 002,873,820 | —- | C] (Creative) – C:\Windows\SysWow64\Sens_oal.dll
[2010/12/04 22:18:38 | 000,413,696 | —- | C] (Creative Labs) – C:\Windows\SysWow64\wrap_oal.dll
[2010/12/04 22:18:38 | 000,110,592 | —- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysWow64\OpenAL32.dll
[2010/12/04 22:18:37 | 001,908,736 | —- | C] (Creative) – C:\Windows\SysNative\Sens_oal.dll
[2010/12/04 22:18:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Creative Labs Shared
[2010/12/04 22:17:57 | 000,000,000 | —D | C] – C:\Program Files\Creative
[2010/12/04 22:17:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Creative
[2010/12/04 22:17:22 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2010/12/04 22:17:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2010/12/04 22:16:24 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2010/12/04 22:03:10 | 000,000,000 | —D | C] – C:\Program Files\Adobe Photoshop CS5 Extended Edition
[2010/12/04 21:59:09 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010/12/04 21:59:09 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010/12/04 21:59:09 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010/12/04 21:59:09 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010/12/04 21:59:09 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010/12/04 21:59:09 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010/12/04 21:59:09 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010/12/04 21:59:09 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2010/12/04 21:58:15 | 000,000,000 | —D | C] – C:\ProgramData\Creative
[2010/12/04 21:55:53 | 000,000,000 | —D | C] – C:\Program Files\Microsoft IntelliPoint
[2010/12/04 21:51:45 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2010/12/04 21:51:42 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2010/12/04 21:49:42 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\ElevatedDiagnostics
[2010/12/04 21:49:15 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010/12/04 21:48:19 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2010/12/04 21:48:18 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2010/12/04 21:48:18 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2010/12/04 21:48:18 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2010/12/04 21:48:18 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2010/12/04 21:48:18 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2010/12/04 21:48:18 | 000,258,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2010/12/04 21:48:18 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/12/04 21:48:18 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010/12/04 21:48:12 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2010/12/04 21:48:07 | 001,975,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CertEnroll.dll
[2010/12/04 21:48:07 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CertEnroll.dll
[2010/12/04 21:48:02 | 000,483,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\StructuredQuery.dll
[2010/12/04 21:48:02 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2010/12/04 21:48:01 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2010/12/04 21:48:00 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc.dll
[2010/12/04 21:48:00 | 000,422,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_isv.dll
[2010/12/04 21:48:00 | 000,369,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc.dll
[2010/12/04 21:48:00 | 000,365,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_isv.dll
[2010/12/04 21:48:00 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_isv.exe
[2010/12/04 21:48:00 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate.exe
[2010/12/04 21:48:00 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_isv.exe
[2010/12/04 21:48:00 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate.exe
[2010/12/04 21:48:00 | 000,306,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp.exe
[2010/12/04 21:48:00 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010/12/04 21:48:00 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp.exe
[2010/12/04 21:48:00 | 000,277,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010/12/04 21:48:00 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp_isv.dll
[2010/12/04 21:48:00 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp.dll
[2010/12/04 21:48:00 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp_isv.dll
[2010/12/04 21:48:00 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp.dll
[2010/12/04 21:47:58 | 002,085,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ole32.dll
[2010/12/04 21:47:56 | 001,736,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2010/12/04 21:47:55 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2010/12/04 21:47:55 | 000,148,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2010/12/04 21:47:55 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2010/12/04 21:47:55 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2010/12/04 21:47:55 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2010/12/04 21:47:55 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2010/12/04 21:47:55 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2010/12/04 21:47:55 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2010/12/04 21:47:04 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2010/12/04 21:46:03 | 000,702,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2010/12/04 21:46:02 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2010/12/04 21:46:02 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/12/04 21:46:02 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/12/04 21:46:02 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2010/12/04 21:46:02 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2010/12/04 21:46:02 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2010/12/04 21:46:01 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2010/12/04 21:46:01 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2010/12/04 21:46:01 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/12/04 21:46:01 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/12/04 21:46:01 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2010/12/04 21:46:01 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/12/04 21:46:01 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/12/04 21:45:58 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40.dll
[2010/12/04 21:45:58 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40u.dll
[2010/12/04 21:45:57 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010/12/04 21:45:57 | 003,955,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2010/12/04 21:45:57 | 003,899,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2010/12/04 21:45:56 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2010/12/04 21:45:56 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2010/12/04 21:45:55 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2010/12/04 21:45:54 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010/12/04 21:45:53 | 001,572,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2010/12/04 21:45:53 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2010/12/04 21:45:53 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2010/12/04 21:45:53 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2010/12/04 21:45:52 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2010/12/04 21:45:52 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2010/12/04 21:45:52 | 000,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\comctl32.dll
[2010/12/04 21:45:51 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010/12/04 21:45:51 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010/12/04 21:45:51 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010/12/04 21:45:45 | 001,024,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmpmde.dll
[2010/12/04 21:45:45 | 000,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmpmde.dll
[2010/12/04 21:45:40 | 001,446,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2010/12/04 21:45:39 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msasn1.dll
[2010/12/04 21:45:26 | 014,627,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2010/12/04 21:45:25 | 011,406,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2010/12/04 21:45:24 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2010/12/04 21:45:23 | 012,625,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2010/12/04 21:45:21 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sscore.dll
[2010/12/04 21:45:18 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010/12/04 21:45:16 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2010/12/04 21:45:16 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010/12/04 21:45:16 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2010/12/04 21:45:16 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2010/12/04 21:45:16 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2010/12/04 21:45:16 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010/12/04 21:45:04 | 000,000,000 | —D | C] – C:\Boot
[2010/12/04 21:42:14 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2010/12/04 21:42:14 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wintrust.dll
[2010/12/04 21:42:13 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2010/12/04 21:42:13 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2010/12/04 21:35:58 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/12/04 21:35:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/12/04 21:33:05 | 000,000,000 | —D | C] – C:\Windows.old
[2010/12/04 21:19:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Works
[2010/12/04 21:19:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2010/12/04 21:19:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2010/12/04 21:19:10 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/12/04 21:19:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2010/12/04 21:17:59 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2010/12/04 21:17:32 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Microsoft Help
[2010/12/04 21:17:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2010/12/04 21:17:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2010/12/04 21:17:15 | 000,000,000 | R–D | C] – C:\MSOCache
[2010/12/04 20:52:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2010/12/04 20:46:52 | 000,000,000 | —D | C] – C:\Program Files\UltraMon
[2010/12/04 20:46:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Realtime Soft
[2010/12/04 20:45:16 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\jZip
[2010/12/04 20:44:44 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Yahoo!
[2010/12/04 20:44:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2010/12/04 20:44:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\jZip
[2010/12/04 20:15:33 | 000,000,000 | R–D | C] – C:\Users\Public\Documents\Shared Wallpapers
[2010/12/04 20:15:33 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Documents\My Wallpapers
[2010/12/04 20:15:33 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Realtime Soft
[2010/12/04 20:15:33 | 000,000,000 | —D | C] – C:\ProgramData\Realtime Soft
[2010/12/04 20:14:59 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010/12/04 20:06:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Belarc
[2010/12/04 19:59:22 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Searches
[2010/12/04 19:59:21 | 000,000,000 | -H-D | C] – C:\Users\sumtingwong1381\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2010/12/04 19:59:11 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Identities
[2010/12/04 19:59:08 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Contacts
[2010/12/04 19:59:07 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\VirtualStore
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\AppData\Local\Temporary Internet Files
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Templates
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Start Menu
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\SendTo
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Recent
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\PrintHood
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\NetHood
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Documents\My Videos
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Documents\My Pictures
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Documents\My Music
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\My Documents
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Local Settings
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\AppData\Local\History
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Cookies
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\Application Data
[2010/12/04 19:58:54 | 000,000,000 | -HSD | C] – C:\Users\sumtingwong1381\AppData\Local\Application Data
[2010/12/04 19:58:53 | 000,000,000 | –SD | C] – C:\Users\sumtingwong1381\AppData\Roaming\Microsoft
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Videos
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Saved Games
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Pictures
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Music
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Links
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Favorites
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Downloads
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\My Documents
[2010/12/04 19:58:53 | 000,000,000 | R–D | C] – C:\Users\sumtingwong1381\Desktop
[2010/12/04 19:58:53 | 000,000,000 | -H-D | C] – C:\Users\sumtingwong1381\AppData
[2010/12/04 19:58:53 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Temp
[2010/12/04 19:58:53 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Local\Microsoft
[2010/12/04 19:58:53 | 000,000,000 | —D | C] – C:\Users\sumtingwong1381\AppData\Roaming\Media Center Programs
[2010/12/04 19:56:04 | 000,000,000 | —D | C] – C:\Recovery
[2010/12/04 04:58:27 | 000,000,000 | -HSD | C] – C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2010/12/07 22:57:04 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\sumtingwong1381\Desktop\OTL.exe
[2010/12/07 22:25:11 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/12/07 22:25:11 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/12/07 22:25:11 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/12/07 22:25:01 | 000,000,418 | —- | M] () – C:\Windows\tasks\EXErrorsFix Schedule.job
[2010/12/07 22:24:56 | 000,001,043 | —- | M] () – C:\Users\sumtingwong1381\Desktop\EXErrorsFix.lnk
[2010/12/07 22:20:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/07 22:20:21 | 2414,780,416 | -HS- | M] () – C:\hiberfil.sys
[2010/12/07 22:05:39 | 000,002,985 | —- | M] () – C:\Users\sumtingwong1381\Desktop\HiJackThis (2).lnk
[2010/12/07 21:32:24 | 000,017,264 | —- | M] (Webroot Software, Inc. (www.webroot.com)) – C:\Windows\SysNative\SsiEfr.exe
[2010/12/07 21:27:32 | 000,001,063 | —- | M] () – C:\Users\Public\Desktop\Registry Mechanic.lnk
[2010/12/07 21:14:42 | 253,888,280 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/12/07 11:17:01 | 038,505,136 | —- | M] () – C:\Users\sumtingwong1381\Desktop\IMG_6700-Edit.tif
[2010/12/07 11:07:10 | 047,543,344 | —- | M] () – C:\Users\sumtingwong1381\Desktop\IMG_6700.psd
[2010/12/07 11:06:04 | 003,091,095 | —- | M] () – C:\Users\sumtingwong1381\Desktop\IMG_6700 partial color.jpg
[2010/12/07 11:05:42 | 003,467,652 | —- | M] () – C:\Users\sumtingwong1381\Desktop\IMG_6700.jpg
[2010/12/06 22:13:14 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\iexplorer.lnk
[2010/12/06 15:16:12 | 009,575,264 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/12/05 13:15:58 | 000,001,152 | —- | M] () – C:\Users\sumtingwong1381\Desktop\Pictures.lnk
[2010/12/05 12:26:45 | 000,002,019 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2010/12/04 23:59:05 | 000,000,017 | —- | M] () – C:\Users\sumtingwong1381\AppData\Local\resmon.resmoncfg
[2010/12/04 23:44:55 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/12/04 23:43:27 | 000,003,584 | —- | M] () – C:\Users\sumtingwong1381\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/04 23:40:12 | 000,002,871 | —- | M] () – C:\Users\Public\Desktop\ACDSee Pro 3.lnk
[2010/12/04 23:11:29 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/04 23:10:11 | 000,001,845 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/04 22:58:44 | 000,001,183 | —- | M] () – C:\Users\sumtingwong1381\Desktop\Portrait Professional Studio 9.lnk
[2010/12/04 22:42:05 | 000,002,055 | —- | M] () – C:\Users\Public\Desktop\Lightroom 3 64-bit.lnk
[2010/12/04 22:37:27 | 000,001,075 | —- | M] () – C:\Users\sumtingwong1381\Desktop\Adobe Photoshop CS5 (64 Bit).lnk
[2010/12/04 22:21:18 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/04 22:21:18 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/04 22:18:39 | 000,419,840 | —- | M] (Creative Labs) – C:\Windows\SysNative\wrap_oal.dll
[2010/12/04 22:18:39 | 000,133,632 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysNative\OpenAL32.dll
[2010/12/04 22:18:38 | 000,413,696 | —- | M] (Creative Labs) – C:\Windows\SysWow64\wrap_oal.dll
[2010/12/04 22:18:38 | 000,110,592 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysWow64\OpenAL32.dll
[2010/12/04 22:16:05 | 000,000,159 | RH– | M] () – C:\Windows\ctfile.rfc
[2010/12/04 21:56:01 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_point64_01009.Wdf
[2010/12/04 21:45:06 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/12/04 21:45:05 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2010/12/04 21:36:07 | 000,419,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\systemcpl.dll
[2010/12/04 21:36:07 | 000,014,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2010/12/04 21:36:07 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2010/12/04 21:36:06 | 001,008,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\user32.dll
[2010/12/04 21:19:53 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/12/04 20:46:52 | 000,002,585 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk
[2010/12/04 20:06:51 | 000,002,027 | —- | M] () – C:\Users\sumtingwong1381\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2010/12/04 20:06:51 | 000,002,003 | —- | M] () – C:\Users\Public\Desktop\Belarc Advisor.lnk
[2010/12/04 20:00:09 | 000,001,437 | —- | M] () – C:\Users\sumtingwong1381\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/12/04 19:56:51 | 000,171,136 | RHS- | M] () – C:\w7ldr
[2010/12/04 19:50:34 | 000,042,045 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2010/12/04 19:50:34 | 000,042,045 | —- | M] () – C:\Windows\SysNative\license.rtf
[2010/12/04 11:45:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/04 11:08:24 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/12/04 11:08:24 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/12/04 11:08:24 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/12/04 11:08:24 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/12/04 11:03:03 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,024,152 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/11/08 01:20:24 | 000,089,088 | —- | M] () – C:\Windows\MBR.exe

========== Files Created - No Company Name ==========




EXTRAS FILE

OTL Extras logfile created on: 12/7/2010 11:01:48 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\sumtingwong1381\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 63.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 58.08 Gb Free Space | 24.94% Space Free | Partition Type: NTFS
Drive D: | 279.47 Gb Total Space | 82.03 Gb Free Space | 29.35% Space Free | Partition Type: NTFS
Drive G: | 3.68 Gb Total Space | 3.33 Gb Free Space | 90.62% Space Free | Partition Type: FAT32

Computer Name: BRANDONS | User Name: sumtingwong1381 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [ACDSee Pro 3.Manage] – "C:\Program Files (x86)\ACD Systems\ACDSee Pro\3.0\ACDSeeQVPro3.exe" "%1" (ACD Systems International Inc.)
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Pro 3.Manage] – "C:\Program Files (x86)\ACD Systems\ACDSee Pro\3.0\ACDSeeQVPro3.exe" "%1" (ACD Systems International Inc.)
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1387BA33-3FAC-49E9-B545-0E8D3BBC550B}" = Adobe Photoshop Lightroom 3 64-bit
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{563F041C-DFDB-437B-A1E8-E141E0906076}" = Microsoft IntelliPoint 8.0
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B49673F8-7AB6-4A14-8213-C8A7BE370010}" = UltraMon
"{B6EFD9A5-2ECE-4C22-BAEC-D16E73EA2013}" = iTunes
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1B280FAF-AE10-4E31-A41A-DB3917D651DC}" = ACDSee Pro 3
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AudioCS" = Creative Audio Control Panel
"Belarc Advisor" = Belarc Advisor 8.1
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"EXErrorsFix_is1" = EXErrorsFix 2.8
"HijackThis" = HijackThis 2.0.2
"jZip" = jZip
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Portrait Professional Studio 9_is1" = Portrait Professional Studio 9.0
"PROR" = Microsoft Office Professional 2007
"Registry Mechanic_is1" = Registry Mechanic 10.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/5/2010 2:37:30 AM | Computer Name = brandons | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 12/5/2010 2:56:42 AM | Computer Name = brandons | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 12/6/2010 2:30:36 AM | Computer Name = brandons | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 12/6/2010 2:31:04 AM | Computer Name = brandons | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files (x86)\common
files\Adobe\OOBE\PDApp\DWA\resources\libraries\ARKCmdCaps.dll". Dependent Assembly
Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 12/6/2010 2:31:04 AM | Computer Name = brandons | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files (x86)\common
files\Adobe\OOBE\PDApp\DWA\resources\libraries\ARKCmdDefrag.dll". Dependent Assembly
Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 12/6/2010 2:31:04 AM | Computer Name = brandons | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files (x86)\common
files\Adobe\OOBE\PDApp\DWA\resources\libraries\ARKCmdFS.dll". Dependent Assembly
Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 12/6/2010 2:31:04 AM | Computer Name = brandons | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files (x86)\common
files\Adobe\OOBE\PDApp\DWA\resources\libraries\ARKEngine.dll". Dependent Assembly
Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 12/7/2010 2:30:50 AM | Computer Name = brandons | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 12/7/2010 11:18:19 PM | Computer Name = brandons | Source = Microsoft-Windows-CAPI2 | ID = 512
Description = The Cryptographic Services service failed to initialize the VSS backup
"System Writer" object. Details: Could not query the status of the EventSystem service.

System
Error: A system shutdown is in progress. .

Error - 12/8/2010 12:48:36 AM | Computer Name = brandons | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7600.16671,
time stamp: 0x4c86f9be Faulting module name: RTSUltraMonHookX32.dll_unloaded, version:
0.0.0.0, time stamp: 0x4b7757b2 Exception code: 0xc0000005 Fault offset: 0x742e52d3
Faulting
process id: 0x518 Faulting application start time: 0x01cb9692c5f171ca Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
RTSUltraMonHookX32.dll Report Id: 6a6d9d20-0286-11e0-9f5e-0019db2d377b

[ System Events ]
Error - 12/8/2010 12:10:09 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:10:09 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:10:09 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:10:09 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:10:09 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:10:09 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:10:09 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:13:08 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:17:20 AM | Computer Name = brandons | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 12/8/2010 12:20:09 AM | Computer Name = brandons | Source = Application Popup | ID = 876
Description = Driver ssidrv.sys has been blocked from loading.


< End of report >


HJT log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:05:58 PM, on 12/7/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Global Startup: UltraMon.lnk = ?
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files (x86)\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 5708 bytes

I just learned that HJT is not compatible with Windows 7 64bit. That is probably why it is showing those files as missing. Other than that, please advise if my OTL logs look ok. Thanks
Can you tell me what these are? O1 - Hosts: 127.0.0.1 125.252.224.90 O1 - Hosts: 127.0.0.1 125.252.224.91 Are you running a "Cracked" version of Adobe? I take it you didn't post this part for a reason? ========== Files Created - No Company Name ==========

Can you tell me what these are?
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91

Are you running a "Cracked" version of Adobe?


I take it you didn't post this part for a reason?

========== Files Created - No Company Name ==========

I am not sure what those two Hosts files are, and yes, I am running a "cracked" version.
After you uninstall Adobe

OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [RESETHOSTS] 
    [purity]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI