jeff matthews
Topic Starter
Hi i been working on this computer for a very long time, trying to resolve a critical issue with my pc being rather slow. I think i finally found the root of the problem. Before i talk about my virus issue, i want to share with you a bit what i think it is.
First of all i have ran Memtest for memory for all my ram cards over night and none of them received any sector errors at all. That being said, i can certainly say its not my ram thats causing the slow downs.
I found out that windows 7 32bit OS only allows like 2.75 gb of ram. Well there lies my problem indefinitely. I actually have 4 gb of ram in my computer right now and its only able to read 2.42 it says. I know there is no other known hard ware issues because i basically did a complete over haul of my pc just recently. It is impossible for me to have any other hardware related issues at this time. I just recently bought a new graphics card. A GTX 450. I had a 8800 GTS in my computer prior. The moment i installed that graphics card, my computer just turned into the "titanic" It is so ridiculously slow i can't hardly do anything. I believe this cause is because i don't have enough physical memory. The card that i had prior, only required bout 300 mb of memory. This new card requires 1gb of memory. I do have 4 gb of RAM in my computer but since my 32 bit OS is limiting my memory usage, im only able to use so much. When i installed that card, it just made matters even worse.
Anyways i know your know qualified to technically help me with these problems as you only deal with work in maleware but i wanted to give you kind of an analysis of what my computer is doing. Anyways what i want to do, is get rid of windows OS 32 bit and install windows OS 64 bit. I think that will reduce alot of my issues with my computer being slow. Because i can install my full 8 gb of ram into my computer.
Now bout the viruses. My internet is redirecting URLS. I tried to make a payment online for a bank account and it wont take my user id or password information, because its trying to redirect the URL to a different website. After bout 3 failed attempts at entering my user id and pass for my bank. They locked me out. so now i have to call them in order to make a payment. I was able to do it just fine on another pc, so i know for a fact this computer has the problems. Also i can't stream literally anything. Youtube is slow, megavideo is slow. Web pages are really slow and some times my browser will just freeze. This is kind of strange for me to have infections this early because i just recently reformatted my drive and started copying information over. Evidently something that i copied over from one of my external hard drives. Infected my machine again.
Anyways there is quite alot of data on my C drive, do i have to reformat again before installing windows OS 64 bit. Because if possible i would like to just do a direct re installed of the OS 64 bit and then start cleaning up my machine. I want to make absolutely sure that i do not infect my self again. I seem to have this problem ALL the time and its really agitating me. I am almost thinking bout just deleting all my old software and re downloading all new software. Starting completely fresh with new programs.
So yeah two things i want to do, fix my memory problem, by installing windows OS 64 bit and also cleaning up my machine so i dont get any more future infections.
Anyways here is my DDS log
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_25
Run by [removed] at 12:21:01 on 2011-05-27
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2551.800 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Users\Jeff\Desktop\dds(1).scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Mal Updater 2] c:\program files\mal updater 2\MalUpdater.exe
uRun: [PlayNC Launcher]
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10p_Plugin.exe -update plugin
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: []
StartupFolder: c:\users\jeff\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\ch5zmo76.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl5254a14a;MpKsl5254a14a;c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\MpKsl5254a14a.sys [2011-5-26 28752]
R2 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2011-3-29 598312]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-4-29 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2011-05-26 10:26:55 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\MpKsl5254a14a.sys
2011-05-26 10:26:18 6962000 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\mpengine.dll
2011-05-26 00:12:10 ——– d—–w- c:\users\jeff\appdata\local\assembly
2011-05-25 22:50:50 ——– d—–w- c:\program files\NCsoft
2011-05-25 22:49:10 ——– d-sh–w- c:\users\jeff\appdata\roaming\.#
2011-05-25 09:13:12 ——– d—–w- c:\users\jeff\appdata\roaming\AnvSoft
2011-05-25 09:13:02 ——– d—–w- c:\program files\AnvSoft
2011-05-25 06:14:47 26496 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-25 03:54:07 ——– d—–w- c:\users\jeff\appdata\local\{254ABDCA-A421-4182-9720-2EDF10C5C4EF}
2011-05-25 03:46:18 ——– d—–w- c:\windows\en
2011-05-25 03:38:39 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2011-05-25 03:37:24 ——– d—–w- c:\windows\PCHEALTH
2011-05-24 05:33:20 ——– d—–w- c:\users\jeff\appdata\local\{126A424F-D7FC-4BFB-8E84-AF71782DB5B0}
2011-05-24 04:13:13 ——– d—–w- c:\program files\SquareEnix
2011-05-23 10:25:51 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2011-05-23 10:25:46 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{243c3b92-6a5b-43ac-9c62-95ab1e06e6b0}\gapaengine.dll
2011-05-18 23:17:46 123904 —-a-w- c:\windows\system32\poqexec.exe
2011-05-17 15:07:48 ——– d—–w- c:\users\jeff\appdata\roaming\avidemux
2011-05-17 15:07:38 ——– d—–w- c:\program files\Avidemux 2.5
2011-05-12 14:29:18 ——– d—–w- c:\users\jeff\appdata\local\{967727EA-AEA5-4758-8E97-695EE7B66DFC}
2011-05-12 06:29:39 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-12 06:29:39 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-05-12 06:29:34 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-12 06:29:34 284160 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-05-12 06:29:33 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-12 06:29:33 5888 —-a-w- c:\windows\system32\drivers\usbd.sys
2011-05-12 06:29:33 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-12 06:29:33 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-12 06:29:33 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-07 22:28:19 ——– d—–w- c:\users\jeff\appdata\local\{EA48DFFF-28F9-4913-A6B9-751546ECB93C}
2011-05-07 14:42:53 ——– d—–w- c:\windows\system32\appmgmt
2011-05-06 22:27:43 ——– d—–w- c:\users\jeff\appdata\local\{643CF913-DC6A-440E-A66C-18D9F33A533F}
2011-05-06 20:56:00 175616 —-a-w- c:\windows\system32\unrar.dll
2011-05-06 20:55:56 ——– d—–w- c:\program files\K-Lite Codec Pack
2011-05-03 01:14:34 ——– d—–w- c:\users\jeff\appdata\local\{F67A9513-F66C-43F5-92CE-9E1DB0259ADB}
2011-05-02 08:24:36 ——– d—–w- C:\Anime
2011-05-02 08:21:49 ——– d—–w- c:\users\jeff\appdata\roaming\Mal Updater
2011-05-02 08:21:35 ——– d—–w- c:\program files\Mal Updater 2
2011-05-02 08:15:02 ——– d—–w- c:\users\jeff\appdata\local\{55B87F8F-35F1-4075-A63F-ABFCE4404A44}
2011-05-02 08:11:19 ——– d—–w- c:\program files\DVDFab 8
2011-05-02 08:01:21 ——– d—–w- c:\users\jeff\appdata\roaming\OpenOffice.org
2011-05-02 07:59:40 ——– d—–w- c:\program files\JRE
2011-05-02 07:59:13 ——– d—–w- c:\program files\OpenOffice.org 3
2011-04-30 23:22:47 ——– d—–w- c:\programdata\WEBREG
2011-04-30 23:16:01 ——– d—–w- c:\users\jeff\appdata\local\HP
2011-04-30 23:15:19 321536 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\hpzpp696.dll
2011-04-30 22:56:17 ——– d—–w- c:\users\jeff\appdata\roaming\HpUpdate
2011-04-30 22:56:14 ——– d—–w- c:\program files\Coupons
2011-04-30 22:52:55 ——– d—–w- c:\program files\common files\HP
2011-04-30 22:52:35 ——– d—–w- c:\program files\common files\Hewlett-Packard
2011-04-30 22:51:35 118272 —-a-w- c:\windows\system32\hpz3l696.dll
2011-04-30 22:51:14 ——– d—–w- c:\program files\HP
2011-04-30 22:50:26 261432 —-a-w- c:\windows\system32\hpzids01.dll
2011-04-30 22:50:24 966656 —-a-w- c:\windows\system32\hpost_p02a.dll
2011-04-30 22:50:24 737280 —-a-w- c:\windows\system32\hposwia_p02a.dll
2011-04-30 22:50:23 307200 —-a-w- c:\windows\system32\hposc_p02a.dll
2011-04-30 22:15:36 ——– d—–w- c:\users\jeff\appdata\roaming\Windows Live Writer
2011-04-30 22:15:36 ——– d—–w- c:\users\jeff\appdata\local\Windows Live Writer
2011-04-30 16:39:43 ——– d—–w- c:\users\jeff\appdata\local\{B4E96D64-0788-4367-BE75-5E04249DE109}
2011-04-29 18:31:21 ——– d—–w- c:\windows\system32\Wat
2011-04-29 15:56:52 6962000 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-04-29 10:13:11 257024 —-a-w- c:\windows\system32\msv1_0.dll
2011-04-29 10:11:03 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2011-04-29 10:11:03 49472 —-a-w- c:\windows\system32\netfxperf.dll
2011-04-29 10:11:03 297808 —-a-w- c:\windows\system32\mscoree.dll
2011-04-29 10:11:03 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2011-04-29 10:11:03 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-04-29 10:02:06 190976 —-a-w- c:\windows\system32\drivers\ks.sys
2011-04-29 10:01:22 ——– d—–w- c:\program files\MSXML 4.0
2011-04-29 10:00:52 276992 —-a-w- c:\windows\system32\wcncsvc.dll
2011-04-28 17:16:24 ——– d—–w- c:\users\jeff\appdata\local\{96992E14-4E64-41A9-AA7F-019279337BF7}
2011-04-28 17:16:07 ——– d—–w- c:\users\jeff\Tracing
2011-04-28 16:56:07 ——– d—–w- c:\users\jeff\appdata\local\MPlayer
2011-04-28 15:22:56 ——– d—–w- c:\program files\Microsoft
2011-04-28 15:19:11 ——– d—–w- c:\program files\uTorrent
2011-04-28 15:18:24 ——– d—–w- c:\users\jeff\appdata\roaming\uTorrent
2011-04-28 15:17:25 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2011-04-28 15:17:25 515416 —-a-w- c:\windows\system32\XAudio2_5.dll
2011-04-28 15:17:25 453456 —-a-w- c:\windows\system32\d3dx10_42.dll
2011-04-28 15:17:17 15712 —-a-w- c:\program files\common files\windows live\.cache\5c8db1871cc05b706\MeshBetaRemover.exe
2011-04-28 15:17:13 94040 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\DSETUP.dll
2011-04-28 15:17:13 525656 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\DXSETUP.exe
2011-04-28 15:17:13 1691480 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\dsetup32.dll
2011-04-28 15:16:40 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2011-04-28 15:16:29 94040 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\DSETUP.dll
2011-04-28 15:16:29 525656 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\DXSETUP.exe
2011-04-28 15:16:29 1691480 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\dsetup32.dll
2011-04-28 15:08:45 2983424 —-a-w- c:\windows\system32\UIRibbon.dll
2011-04-28 15:08:45 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2011-04-28 15:07:32 3181568 —-a-w- c:\windows\system32\mf.dll
2011-04-28 15:07:32 196608 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-04-28 15:07:31 1619456 —-a-w- c:\windows\system32\WMVDECOD.DLL
2011-04-28 15:07:09 ——– d—–w- c:\users\jeff\appdata\roaming\PMS
2011-04-28 15:06:50 ——– d—–w- c:\program files\PS3 Media Server
2011-04-28 15:06:15 ——– d—–w- c:\users\jeff\appdata\local\Windows Live
2011-04-28 15:06:13 ——– d—–w- c:\program files\common files\Windows Live
2011-04-28 14:54:46 ——– d—–w- c:\program files\DVD Shrink
2011-04-28 14:49:51 ——– d—–w- c:\program files\common files\xing shared
2011-04-28 14:47:58 ——– dcsh–w- c:\program files\common files\WindowsLiveInstaller
2011-04-28 14:46:16 ——– d—–w- c:\users\jeff\appdata\roaming\CometPlayer
2011-04-28 14:44:34 ——– d—–w- c:\program files\DVD Decrypter
2011-04-28 14:43:59 ——– d—–w- c:\program files\VideoLAN
2011-04-28 14:43:10 ——– d—–w- c:\programdata\boost_interprocess
2011-04-28 14:43:05 ——– d—–w- c:\users\jeff\appdata\roaming\TigerPlayer
2011-04-28 14:42:32 ——– d—–w- c:\program files\MpcStar
2011-04-28 14:33:14 ——– d—–w- c:\users\jeff\appdata\roaming\Malwarebytes
2011-04-28 14:33:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-28 14:33:08 ——– d—–w- c:\programdata\Malwarebytes
2011-04-28 14:33:05 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-04-28 14:33:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-04-28 14:32:23 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-28 14:11:16 ——– d—–w- c:\programdata\Nero
2011-04-28 14:10:16 ——– d—–w- c:\program files\Nero
2011-04-28 14:05:54 1974616 —-a-w- c:\windows\system32\D3DCompiler_42.dll
2011-04-28 14:05:26 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll
2011-04-28 14:04:54 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2011-04-28 14:04:27 3727720 —-a-w- c:\windows\system32\d3dx9_35.dll
2011-04-28 14:04:04 3497832 —-a-w- c:\windows\system32\d3dx9_34.dll
2011-04-28 13:56:52 ——– d—–w- c:\users\jeff\appdata\local\Adobe
2011-04-28 13:50:08 417792 —-a-w- c:\windows\system32\msdri.dll
2011-04-28 13:50:08 204288 —-a-w- c:\windows\system32\MSNP.ax
2011-04-28 13:50:07 465408 —-a-w- c:\windows\system32\psisdecd.dll
2011-04-28 13:48:47 28672 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-04-28 13:48:47 132608 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-04-28 13:48:39 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-04-28 13:48:39 294912 —-a-w- c:\windows\system32\atmfd.dll
2011-04-28 13:48:19 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{42b072bb-4a7f-4d7b-9027-357faf4a87d4}\gapaengine.dll
2011-04-28 13:46:00 516096 —-a-w- c:\program files\windows mail\wab.exe
2011-04-28 13:44:50 37376 —-a-w- c:\windows\system32\rtutils.dll
2011-04-28 13:44:49 1619968 —-a-w- c:\program files\windows mail\msoe.dll
2011-04-28 13:44:45 541184 —-a-w- c:\windows\system32\kerberos.dll
2011-04-28 13:44:38 507568 —-a-w- c:\windows\system32\winload.exe
2011-04-28 13:44:38 442920 —-a-w- c:\windows\system32\winresume.exe
2011-04-28 13:44:38 1320960 —-a-w- c:\windows\system32\CertEnroll.dll
2011-04-28 13:43:47 67584 —-a-w- c:\windows\system32\asycfilt.dll
2011-04-28 13:43:46 530432 —-a-w- c:\windows\system32\comctl32.dll
2011-04-28 13:43:00 954752 —-a-w- c:\windows\system32\mfc40.dll
2011-04-28 13:42:59 954288 —-a-w- c:\windows\system32\mfc40u.dll
2011-04-28 13:42:02 164864 —-a-w- c:\program files\windows media player\wmplayer.exe
2011-04-28 13:42:01 12625408 —-a-w- c:\windows\system32\wmploc.DLL
2011-04-28 13:41:55 2331136 —-a-w- c:\windows\system32\win32k.sys
2011-04-28 13:41:51 191488 —-a-w- c:\windows\system32\FXSCOVER.exe
2011-04-28 13:41:50 70656 —-a-w- c:\windows\system32\fontsub.dll
2011-04-28 13:41:48 442880 —-a-w- c:\windows\system32\XpsPrint.dll
2011-04-28 13:41:41 292864 —-a-w- c:\windows\system32\apphelp.dll
2011-04-28 13:41:37 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-28 13:38:55 1164288 —-a-w- c:\windows\system32\mfc42u.dll
2011-04-28 13:38:55 1137664 —-a-w- c:\windows\system32\mfc42.dll
2011-04-28 13:38:54 91648 —-a-w- c:\windows\system32\avifil32.dll
2011-04-28 13:38:54 84480 —-a-w- c:\windows\system32\mciavi32.dll
2011-04-28 13:38:54 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2011-04-28 13:38:54 31744 —-a-w- c:\windows\system32\msvidc32.dll
2011-04-28 13:38:54 22016 —-a-w- c:\windows\system32\msyuv.dll
2011-04-28 13:38:54 13312 —-a-w- c:\windows\system32\msrle32.dll
2011-04-28 13:38:54 1328640 —-a-w- c:\windows\system32\quartz.dll
2011-04-28 13:38:54 12288 —-a-w- c:\windows\system32\tsbyuv.dll
2011-04-28 13:32:29 642048 —-a-w- c:\windows\system32\CPFilters.dll
2011-04-28 13:32:28 850432 —-a-w- c:\windows\system32\sbe.dll
2011-04-28 13:32:28 534528 —-a-w- c:\windows\system32\EncDec.dll
2011-04-28 13:32:28 199680 —-a-w- c:\windows\system32\mpg2splt.ax
2011-04-28 13:32:20 2614784 —-a-w- c:\windows\explorer.exe
2011-04-28 13:32:17 314368 —-a-w- c:\windows\system32\webio.dll
2011-04-28 13:32:12 2690560 —-a-w- c:\windows\system32\mstscax.dll
2011-04-28 13:32:11 1034240 —-a-w- c:\windows\system32\mstsc.exe
2011-04-28 13:31:49 740864 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-28 13:30:57 168448 —-a-w- c:\windows\system32\srvsvc.dll
2011-04-28 13:30:47 1289536 —-a-w- c:\windows\system32\ntdll.dll
2011-04-28 13:29:44 204288 —-a-w- c:\windows\system32\upnp.dll
2011-04-28 13:29:43 80384 —-a-w- c:\windows\system32\davclnt.dll
2011-04-28 13:29:43 73728 —-a-w- c:\windows\system32\wscsvc.dll
2011-04-28 13:29:43 51200 —-a-w- c:\windows\system32\wscapi.dll
2011-04-28 13:29:43 350720 —-a-w- c:\windows\system32\winhttp.dll
2011-04-28 13:29:43 204800 —-a-w- c:\windows\system32\WebClnt.dll
2011-04-28 13:29:43 14336 —-a-w- c:\windows\system32\slwga.dll
2011-04-28 13:29:43 1389568 —-a-w- c:\windows\system32\msxml6.dll
2011-04-28 13:29:43 1236992 —-a-w- c:\windows\system32\msxml3.dll
2011-04-28 13:29:06 738816 —-a-w- c:\windows\system32\wmpmde.dll
2011-04-28 13:29:06 101760 —-a-w- c:\windows\system32\consent.exe
2011-04-28 13:29:01 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-04-28 13:25:37 ——– d-sh–w- c:\windows\Installer
2011-04-28 13:25:36 ——– d—–w- c:\program files\Microsoft Security Client
2011-04-28 13:25:17 240008 —-a-w- c:\windows\system32\drivers\netio.sys
.
==================== Find3M ====================
.
2011-03-11 05:44:09 146304 —-a-w- c:\windows\system32\drivers\storport.sys
2011-03-11 05:44:01 143744 —-a-w- c:\windows\system32\drivers\nvstor.sys
2011-03-11 05:44:01 1210240 —-a-w- c:\windows\system32\drivers\ntfs.sys
2011-03-11 05:44:01 117120 —-a-w- c:\windows\system32\drivers\nvraid.sys
2011-03-11 05:43:55 332160 —-a-w- c:\windows\system32\drivers\iaStorV.sys
2011-03-11 05:43:46 80256 —-a-w- c:\windows\system32\drivers\amdsata.sys
2011-03-11 05:43:46 22400 —-a-w- c:\windows\system32\drivers\amdxata.sys
2011-03-11 05:39:35 1686016 —-a-w- c:\windows\system32\esent.dll
2011-03-11 05:37:34 74240 —-a-w- c:\windows\system32\fsutil.exe
.
============= FINISH: 12:21:36.62 ===============
First of all i have ran Memtest for memory for all my ram cards over night and none of them received any sector errors at all. That being said, i can certainly say its not my ram thats causing the slow downs.
I found out that windows 7 32bit OS only allows like 2.75 gb of ram. Well there lies my problem indefinitely. I actually have 4 gb of ram in my computer right now and its only able to read 2.42 it says. I know there is no other known hard ware issues because i basically did a complete over haul of my pc just recently. It is impossible for me to have any other hardware related issues at this time. I just recently bought a new graphics card. A GTX 450. I had a 8800 GTS in my computer prior. The moment i installed that graphics card, my computer just turned into the "titanic" It is so ridiculously slow i can't hardly do anything. I believe this cause is because i don't have enough physical memory. The card that i had prior, only required bout 300 mb of memory. This new card requires 1gb of memory. I do have 4 gb of RAM in my computer but since my 32 bit OS is limiting my memory usage, im only able to use so much. When i installed that card, it just made matters even worse.
Anyways i know your know qualified to technically help me with these problems as you only deal with work in maleware but i wanted to give you kind of an analysis of what my computer is doing. Anyways what i want to do, is get rid of windows OS 32 bit and install windows OS 64 bit. I think that will reduce alot of my issues with my computer being slow. Because i can install my full 8 gb of ram into my computer.
Now bout the viruses. My internet is redirecting URLS. I tried to make a payment online for a bank account and it wont take my user id or password information, because its trying to redirect the URL to a different website. After bout 3 failed attempts at entering my user id and pass for my bank. They locked me out. so now i have to call them in order to make a payment. I was able to do it just fine on another pc, so i know for a fact this computer has the problems. Also i can't stream literally anything. Youtube is slow, megavideo is slow. Web pages are really slow and some times my browser will just freeze. This is kind of strange for me to have infections this early because i just recently reformatted my drive and started copying information over. Evidently something that i copied over from one of my external hard drives. Infected my machine again.
Anyways there is quite alot of data on my C drive, do i have to reformat again before installing windows OS 64 bit. Because if possible i would like to just do a direct re installed of the OS 64 bit and then start cleaning up my machine. I want to make absolutely sure that i do not infect my self again. I seem to have this problem ALL the time and its really agitating me. I am almost thinking bout just deleting all my old software and re downloading all new software. Starting completely fresh with new programs.
So yeah two things i want to do, fix my memory problem, by installing windows OS 64 bit and also cleaning up my machine so i dont get any more future infections.
Anyways here is my DDS log
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_25
Run by [removed] at 12:21:01 on 2011-05-27
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2551.800 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Users\Jeff\Desktop\dds(1).scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Mal Updater 2] c:\program files\mal updater 2\MalUpdater.exe
uRun: [PlayNC Launcher]
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10p_Plugin.exe -update plugin
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: []
StartupFolder: c:\users\jeff\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\ch5zmo76.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl5254a14a;MpKsl5254a14a;c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\MpKsl5254a14a.sys [2011-5-26 28752]
R2 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2011-3-29 598312]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-4-29 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2011-05-26 10:26:55 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\MpKsl5254a14a.sys
2011-05-26 10:26:18 6962000 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9895eee-8585-477d-97d4-67f43bb01c71}\mpengine.dll
2011-05-26 00:12:10 ——– d—–w- c:\users\jeff\appdata\local\assembly
2011-05-25 22:50:50 ——– d—–w- c:\program files\NCsoft
2011-05-25 22:49:10 ——– d-sh–w- c:\users\jeff\appdata\roaming\.#
2011-05-25 09:13:12 ——– d—–w- c:\users\jeff\appdata\roaming\AnvSoft
2011-05-25 09:13:02 ——– d—–w- c:\program files\AnvSoft
2011-05-25 06:14:47 26496 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-25 03:54:07 ——– d—–w- c:\users\jeff\appdata\local\{254ABDCA-A421-4182-9720-2EDF10C5C4EF}
2011-05-25 03:46:18 ——– d—–w- c:\windows\en
2011-05-25 03:38:39 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2011-05-25 03:37:24 ——– d—–w- c:\windows\PCHEALTH
2011-05-24 05:33:20 ——– d—–w- c:\users\jeff\appdata\local\{126A424F-D7FC-4BFB-8E84-AF71782DB5B0}
2011-05-24 04:13:13 ——– d—–w- c:\program files\SquareEnix
2011-05-23 10:25:51 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2011-05-23 10:25:46 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{243c3b92-6a5b-43ac-9c62-95ab1e06e6b0}\gapaengine.dll
2011-05-18 23:17:46 123904 —-a-w- c:\windows\system32\poqexec.exe
2011-05-17 15:07:48 ——– d—–w- c:\users\jeff\appdata\roaming\avidemux
2011-05-17 15:07:38 ——– d—–w- c:\program files\Avidemux 2.5
2011-05-12 14:29:18 ——– d—–w- c:\users\jeff\appdata\local\{967727EA-AEA5-4758-8E97-695EE7B66DFC}
2011-05-12 06:29:39 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-12 06:29:39 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-05-12 06:29:34 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-12 06:29:34 284160 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-05-12 06:29:33 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-12 06:29:33 5888 —-a-w- c:\windows\system32\drivers\usbd.sys
2011-05-12 06:29:33 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-12 06:29:33 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-12 06:29:33 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-07 22:28:19 ——– d—–w- c:\users\jeff\appdata\local\{EA48DFFF-28F9-4913-A6B9-751546ECB93C}
2011-05-07 14:42:53 ——– d—–w- c:\windows\system32\appmgmt
2011-05-06 22:27:43 ——– d—–w- c:\users\jeff\appdata\local\{643CF913-DC6A-440E-A66C-18D9F33A533F}
2011-05-06 20:56:00 175616 —-a-w- c:\windows\system32\unrar.dll
2011-05-06 20:55:56 ——– d—–w- c:\program files\K-Lite Codec Pack
2011-05-03 01:14:34 ——– d—–w- c:\users\jeff\appdata\local\{F67A9513-F66C-43F5-92CE-9E1DB0259ADB}
2011-05-02 08:24:36 ——– d—–w- C:\Anime
2011-05-02 08:21:49 ——– d—–w- c:\users\jeff\appdata\roaming\Mal Updater
2011-05-02 08:21:35 ——– d—–w- c:\program files\Mal Updater 2
2011-05-02 08:15:02 ——– d—–w- c:\users\jeff\appdata\local\{55B87F8F-35F1-4075-A63F-ABFCE4404A44}
2011-05-02 08:11:19 ——– d—–w- c:\program files\DVDFab 8
2011-05-02 08:01:21 ——– d—–w- c:\users\jeff\appdata\roaming\OpenOffice.org
2011-05-02 07:59:40 ——– d—–w- c:\program files\JRE
2011-05-02 07:59:13 ——– d—–w- c:\program files\OpenOffice.org 3
2011-04-30 23:22:47 ——– d—–w- c:\programdata\WEBREG
2011-04-30 23:16:01 ——– d—–w- c:\users\jeff\appdata\local\HP
2011-04-30 23:15:19 321536 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\hpzpp696.dll
2011-04-30 22:56:17 ——– d—–w- c:\users\jeff\appdata\roaming\HpUpdate
2011-04-30 22:56:14 ——– d—–w- c:\program files\Coupons
2011-04-30 22:52:55 ——– d—–w- c:\program files\common files\HP
2011-04-30 22:52:35 ——– d—–w- c:\program files\common files\Hewlett-Packard
2011-04-30 22:51:35 118272 —-a-w- c:\windows\system32\hpz3l696.dll
2011-04-30 22:51:14 ——– d—–w- c:\program files\HP
2011-04-30 22:50:26 261432 —-a-w- c:\windows\system32\hpzids01.dll
2011-04-30 22:50:24 966656 —-a-w- c:\windows\system32\hpost_p02a.dll
2011-04-30 22:50:24 737280 —-a-w- c:\windows\system32\hposwia_p02a.dll
2011-04-30 22:50:23 307200 —-a-w- c:\windows\system32\hposc_p02a.dll
2011-04-30 22:15:36 ——– d—–w- c:\users\jeff\appdata\roaming\Windows Live Writer
2011-04-30 22:15:36 ——– d—–w- c:\users\jeff\appdata\local\Windows Live Writer
2011-04-30 16:39:43 ——– d—–w- c:\users\jeff\appdata\local\{B4E96D64-0788-4367-BE75-5E04249DE109}
2011-04-29 18:31:21 ——– d—–w- c:\windows\system32\Wat
2011-04-29 15:56:52 6962000 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-04-29 10:13:11 257024 —-a-w- c:\windows\system32\msv1_0.dll
2011-04-29 10:11:03 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2011-04-29 10:11:03 49472 —-a-w- c:\windows\system32\netfxperf.dll
2011-04-29 10:11:03 297808 —-a-w- c:\windows\system32\mscoree.dll
2011-04-29 10:11:03 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2011-04-29 10:11:03 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-04-29 10:02:06 190976 —-a-w- c:\windows\system32\drivers\ks.sys
2011-04-29 10:01:22 ——– d—–w- c:\program files\MSXML 4.0
2011-04-29 10:00:52 276992 —-a-w- c:\windows\system32\wcncsvc.dll
2011-04-28 17:16:24 ——– d—–w- c:\users\jeff\appdata\local\{96992E14-4E64-41A9-AA7F-019279337BF7}
2011-04-28 17:16:07 ——– d—–w- c:\users\jeff\Tracing
2011-04-28 16:56:07 ——– d—–w- c:\users\jeff\appdata\local\MPlayer
2011-04-28 15:22:56 ——– d—–w- c:\program files\Microsoft
2011-04-28 15:19:11 ——– d—–w- c:\program files\uTorrent
2011-04-28 15:18:24 ——– d—–w- c:\users\jeff\appdata\roaming\uTorrent
2011-04-28 15:17:25 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2011-04-28 15:17:25 515416 —-a-w- c:\windows\system32\XAudio2_5.dll
2011-04-28 15:17:25 453456 —-a-w- c:\windows\system32\d3dx10_42.dll
2011-04-28 15:17:17 15712 —-a-w- c:\program files\common files\windows live\.cache\5c8db1871cc05b706\MeshBetaRemover.exe
2011-04-28 15:17:13 94040 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\DSETUP.dll
2011-04-28 15:17:13 525656 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\DXSETUP.exe
2011-04-28 15:17:13 1691480 —-a-w- c:\program files\common files\windows live\.cache\59beb6621cc05b705\dsetup32.dll
2011-04-28 15:16:40 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2011-04-28 15:16:29 94040 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\DSETUP.dll
2011-04-28 15:16:29 525656 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\DXSETUP.exe
2011-04-28 15:16:29 1691480 —-a-w- c:\program files\common files\windows live\.cache\3f1b322e1cc05b704\dsetup32.dll
2011-04-28 15:08:45 2983424 —-a-w- c:\windows\system32\UIRibbon.dll
2011-04-28 15:08:45 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2011-04-28 15:07:32 3181568 —-a-w- c:\windows\system32\mf.dll
2011-04-28 15:07:32 196608 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-04-28 15:07:31 1619456 —-a-w- c:\windows\system32\WMVDECOD.DLL
2011-04-28 15:07:09 ——– d—–w- c:\users\jeff\appdata\roaming\PMS
2011-04-28 15:06:50 ——– d—–w- c:\program files\PS3 Media Server
2011-04-28 15:06:15 ——– d—–w- c:\users\jeff\appdata\local\Windows Live
2011-04-28 15:06:13 ——– d—–w- c:\program files\common files\Windows Live
2011-04-28 14:54:46 ——– d—–w- c:\program files\DVD Shrink
2011-04-28 14:49:51 ——– d—–w- c:\program files\common files\xing shared
2011-04-28 14:47:58 ——– dcsh–w- c:\program files\common files\WindowsLiveInstaller
2011-04-28 14:46:16 ——– d—–w- c:\users\jeff\appdata\roaming\CometPlayer
2011-04-28 14:44:34 ——– d—–w- c:\program files\DVD Decrypter
2011-04-28 14:43:59 ——– d—–w- c:\program files\VideoLAN
2011-04-28 14:43:10 ——– d—–w- c:\programdata\boost_interprocess
2011-04-28 14:43:05 ——– d—–w- c:\users\jeff\appdata\roaming\TigerPlayer
2011-04-28 14:42:32 ——– d—–w- c:\program files\MpcStar
2011-04-28 14:33:14 ——– d—–w- c:\users\jeff\appdata\roaming\Malwarebytes
2011-04-28 14:33:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-28 14:33:08 ——– d—–w- c:\programdata\Malwarebytes
2011-04-28 14:33:05 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-04-28 14:33:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-04-28 14:32:23 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-28 14:11:16 ——– d—–w- c:\programdata\Nero
2011-04-28 14:10:16 ——– d—–w- c:\program files\Nero
2011-04-28 14:05:54 1974616 —-a-w- c:\windows\system32\D3DCompiler_42.dll
2011-04-28 14:05:26 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll
2011-04-28 14:04:54 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2011-04-28 14:04:27 3727720 —-a-w- c:\windows\system32\d3dx9_35.dll
2011-04-28 14:04:04 3497832 —-a-w- c:\windows\system32\d3dx9_34.dll
2011-04-28 13:56:52 ——– d—–w- c:\users\jeff\appdata\local\Adobe
2011-04-28 13:50:08 417792 —-a-w- c:\windows\system32\msdri.dll
2011-04-28 13:50:08 204288 —-a-w- c:\windows\system32\MSNP.ax
2011-04-28 13:50:07 465408 —-a-w- c:\windows\system32\psisdecd.dll
2011-04-28 13:48:47 28672 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-04-28 13:48:47 132608 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-04-28 13:48:39 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-04-28 13:48:39 294912 —-a-w- c:\windows\system32\atmfd.dll
2011-04-28 13:48:19 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{42b072bb-4a7f-4d7b-9027-357faf4a87d4}\gapaengine.dll
2011-04-28 13:46:00 516096 —-a-w- c:\program files\windows mail\wab.exe
2011-04-28 13:44:50 37376 —-a-w- c:\windows\system32\rtutils.dll
2011-04-28 13:44:49 1619968 —-a-w- c:\program files\windows mail\msoe.dll
2011-04-28 13:44:45 541184 —-a-w- c:\windows\system32\kerberos.dll
2011-04-28 13:44:38 507568 —-a-w- c:\windows\system32\winload.exe
2011-04-28 13:44:38 442920 —-a-w- c:\windows\system32\winresume.exe
2011-04-28 13:44:38 1320960 —-a-w- c:\windows\system32\CertEnroll.dll
2011-04-28 13:43:47 67584 —-a-w- c:\windows\system32\asycfilt.dll
2011-04-28 13:43:46 530432 —-a-w- c:\windows\system32\comctl32.dll
2011-04-28 13:43:00 954752 —-a-w- c:\windows\system32\mfc40.dll
2011-04-28 13:42:59 954288 —-a-w- c:\windows\system32\mfc40u.dll
2011-04-28 13:42:02 164864 —-a-w- c:\program files\windows media player\wmplayer.exe
2011-04-28 13:42:01 12625408 —-a-w- c:\windows\system32\wmploc.DLL
2011-04-28 13:41:55 2331136 —-a-w- c:\windows\system32\win32k.sys
2011-04-28 13:41:51 191488 —-a-w- c:\windows\system32\FXSCOVER.exe
2011-04-28 13:41:50 70656 —-a-w- c:\windows\system32\fontsub.dll
2011-04-28 13:41:48 442880 —-a-w- c:\windows\system32\XpsPrint.dll
2011-04-28 13:41:41 292864 —-a-w- c:\windows\system32\apphelp.dll
2011-04-28 13:41:37 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-28 13:38:55 1164288 —-a-w- c:\windows\system32\mfc42u.dll
2011-04-28 13:38:55 1137664 —-a-w- c:\windows\system32\mfc42.dll
2011-04-28 13:38:54 91648 —-a-w- c:\windows\system32\avifil32.dll
2011-04-28 13:38:54 84480 —-a-w- c:\windows\system32\mciavi32.dll
2011-04-28 13:38:54 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2011-04-28 13:38:54 31744 —-a-w- c:\windows\system32\msvidc32.dll
2011-04-28 13:38:54 22016 —-a-w- c:\windows\system32\msyuv.dll
2011-04-28 13:38:54 13312 —-a-w- c:\windows\system32\msrle32.dll
2011-04-28 13:38:54 1328640 —-a-w- c:\windows\system32\quartz.dll
2011-04-28 13:38:54 12288 —-a-w- c:\windows\system32\tsbyuv.dll
2011-04-28 13:32:29 642048 —-a-w- c:\windows\system32\CPFilters.dll
2011-04-28 13:32:28 850432 —-a-w- c:\windows\system32\sbe.dll
2011-04-28 13:32:28 534528 —-a-w- c:\windows\system32\EncDec.dll
2011-04-28 13:32:28 199680 —-a-w- c:\windows\system32\mpg2splt.ax
2011-04-28 13:32:20 2614784 —-a-w- c:\windows\explorer.exe
2011-04-28 13:32:17 314368 —-a-w- c:\windows\system32\webio.dll
2011-04-28 13:32:12 2690560 —-a-w- c:\windows\system32\mstscax.dll
2011-04-28 13:32:11 1034240 —-a-w- c:\windows\system32\mstsc.exe
2011-04-28 13:31:49 740864 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-28 13:30:57 168448 —-a-w- c:\windows\system32\srvsvc.dll
2011-04-28 13:30:47 1289536 —-a-w- c:\windows\system32\ntdll.dll
2011-04-28 13:29:44 204288 —-a-w- c:\windows\system32\upnp.dll
2011-04-28 13:29:43 80384 —-a-w- c:\windows\system32\davclnt.dll
2011-04-28 13:29:43 73728 —-a-w- c:\windows\system32\wscsvc.dll
2011-04-28 13:29:43 51200 —-a-w- c:\windows\system32\wscapi.dll
2011-04-28 13:29:43 350720 —-a-w- c:\windows\system32\winhttp.dll
2011-04-28 13:29:43 204800 —-a-w- c:\windows\system32\WebClnt.dll
2011-04-28 13:29:43 14336 —-a-w- c:\windows\system32\slwga.dll
2011-04-28 13:29:43 1389568 —-a-w- c:\windows\system32\msxml6.dll
2011-04-28 13:29:43 1236992 —-a-w- c:\windows\system32\msxml3.dll
2011-04-28 13:29:06 738816 —-a-w- c:\windows\system32\wmpmde.dll
2011-04-28 13:29:06 101760 —-a-w- c:\windows\system32\consent.exe
2011-04-28 13:29:01 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-04-28 13:25:37 ——– d-sh–w- c:\windows\Installer
2011-04-28 13:25:36 ——– d—–w- c:\program files\Microsoft Security Client
2011-04-28 13:25:17 240008 —-a-w- c:\windows\system32\drivers\netio.sys
.
==================== Find3M ====================
.
2011-03-11 05:44:09 146304 —-a-w- c:\windows\system32\drivers\storport.sys
2011-03-11 05:44:01 143744 —-a-w- c:\windows\system32\drivers\nvstor.sys
2011-03-11 05:44:01 1210240 —-a-w- c:\windows\system32\drivers\ntfs.sys
2011-03-11 05:44:01 117120 —-a-w- c:\windows\system32\drivers\nvraid.sys
2011-03-11 05:43:55 332160 —-a-w- c:\windows\system32\drivers\iaStorV.sys
2011-03-11 05:43:46 80256 —-a-w- c:\windows\system32\drivers\amdsata.sys
2011-03-11 05:43:46 22400 —-a-w- c:\windows\system32\drivers\amdxata.sys
2011-03-11 05:39:35 1686016 —-a-w- c:\windows\system32\esent.dll
2011-03-11 05:37:34 74240 —-a-w- c:\windows\system32\fsutil.exe
.
============= FINISH: 12:21:36.62 ===============