This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help me.

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI there…

My computer which is one of those little acer aspires (windows 7) was running perfectly fine until i made a bad choice in letting one of my friends use it.

When it was returned to me all of my files have been deleted and I now have this "windows recovery" thing that keeps popping up and won't minimize.

I try to crtl + alt delete and go to the task manager to end the process, but it won't let me.

Right now i'm running in safe mode with networking and i downloaded hijack this, but it won't setup.

whatever should i do?

your help will be greatly appreciated.

ps. my desktop is completely black and all my desktop shortcuts etc are gone





OLT POST #1

OTL logfile created on: 6/8/2011 9:47:21 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1013.10 Mb Total Physical Memory | 204.23 Mb Available Physical Memory | 20.16% Memory free
1.99 Gb Paging File | 1.23 Gb Available in Paging File | 61.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 219.79 Gb Total Space | 37.39 Gb Free Space | 17.01% Space Free | Partition Type: NTFS

Computer Name: MONTA-PC | User Name: Monta | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) – C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (GameConsoleService) – C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (RS_Service) – C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV - (GREGService) – C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (EUCR) – C:\Windows\System32\drivers\EUCR6SK.sys (ENE Technology Inc.)
DRV - (L1C) – C:\Windows\System32\drivers\L1C62x86.sys (Atheros Communications, Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (mwlPSDVDisk) – C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV - (mwlPSDNServ) – C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV - (mwlPSDFilter) – C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (SWMX00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…34ww65w4712u741
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…34ww65w4712u741

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…34ww65w4712u741
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.ca/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ig
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2011/05/27 06:50:05 | 000,434,670 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 14957 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (ALOT Toolbar Helper) - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\BHO\alotBHO.dll (Vertro)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Vertro)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [iBryte playbryte Desktop] C:\Program Files\iBryte\playbryte\iBryteDesktop.exe (iBryte)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [SuiteTray] C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [WatcherHelper] C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe (Sierra Wireless Inc.)
O4 - HKCU..\Run: [aAgTqsVXLlTXJ] C:\ProgramData\aAgTqsVXLlTXJ.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group)
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10q_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab (IWinAmpActiveX Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{40dbbfef-37b8-11e0-a2fd-88ae1d6c7748}\Shell - "" = AutoRun
O33 - MountPoints2\{40dbbfef-37b8-11e0-a2fd-88ae1d6c7748}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\AppLaunch.exe AUTORUN=1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()


========== Files/Folders - Created Within 30 Days ==========

[2011/06/08 21:45:20 | 000,580,096 | —- | C] (OldTimer Tools) – C:\OTL.exe
[2011/06/07 22:57:32 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{18F19DC1-96F1-4044-AAE1-FACCE83E8D17}
[2011/06/02 22:56:31 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{647447FF-A3F8-42D9-9829-BE6B992101D7}
[2011/06/02 02:21:05 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{8EEC84A5-6F74-4403-8DE0-E8C8C2063D55}
[2011/05/31 14:22:55 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{99415816-9113-4FCA-BD7F-E42155E1A541}
[2011/05/31 11:36:02 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{FC1B948D-E405-4B92-9EAC-186814A945B0}
[2011/05/31 11:14:28 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{FBEFDB65-DA15-4360-9AB3-F75B019B786F}
[2011/05/31 10:51:25 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{1CA80C3A-2A88-426B-BB31-F2FF90AE991E}
[2011/05/30 19:39:13 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\ElevatedDiagnostics
[2011/05/30 15:47:57 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{5C73EC84-3D84-47DC-8BFD-6DEDAC46B35F}
[2011/05/29 23:22:38 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{5FE4BCB8-10E2-49C1-A69C-FD93A65C31AF}
[2011/05/28 08:16:04 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{B7CFEFCB-BBD4-4741-873E-49827977A8C9}
[2011/05/27 13:14:51 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{6ABC8976-2E0A-4431-8672-7EB18893EBF0}
[2011/05/27 06:52:28 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Recovery
[2011/05/27 06:51:48 | 000,370,176 | -H– | C] (Microsoft Corporation) – C:\ProgramData\31579896.exe
[2011/05/27 06:42:39 | 000,478,720 | -H– | C] (Microsoft Corporation) – C:\ProgramData\aAgTqsVXLlTXJ.exe
[2011/05/27 01:39:05 | 000,000,000 | -H-D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/05/27 01:39:05 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/05/27 01:15:02 | 000,404,640 | -H– | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/27 01:14:17 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{A93989CD-BB66-4814-B9F4-401FFB46053A}
[2011/05/27 00:47:00 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
[2011/05/27 00:47:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
[2011/05/27 00:46:55 | 000,000,000 | —D | C] – C:\Program Files\Eusing Free Registry Cleaner
[2011/05/27 00:26:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/05/27 00:26:04 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/05/27 00:24:43 | 000,000,000 | -H-D | C] – C:\Windows\System32\SPReview
[2011/05/27 00:20:22 | 000,000,000 | -H-D | C] – C:\Windows\System32\EventProviders
[2011/05/25 18:56:02 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\TsUsbFlt.sys
[2011/05/25 18:56:02 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2011/05/25 18:55:54 | 001,171,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/05/25 18:55:53 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2011/05/25 18:55:52 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2011/05/25 18:55:47 | 000,423,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2011/05/25 18:55:44 | 000,428,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2011/05/25 18:55:44 | 000,327,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2011/05/25 18:55:42 | 000,322,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2011/05/25 18:55:40 | 000,253,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizui.dll
[2011/05/25 18:55:38 | 003,207,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/05/25 18:55:37 | 000,520,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcupdate_GenuineIntel.dll
[2011/05/25 18:55:36 | 001,334,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2011/05/25 18:55:35 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2011/05/25 18:55:31 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2011/05/25 18:55:31 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2011/05/25 18:55:28 | 001,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2011/05/25 18:55:27 | 001,115,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RacEngn.dll
[2011/05/25 18:55:26 | 005,066,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuthFWSnapin.dll
[2011/05/25 18:55:22 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2011/05/25 18:55:18 | 001,828,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d9.dll
[2011/05/25 18:55:17 | 000,505,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2011/05/25 18:55:15 | 000,456,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spinstall.exe
[2011/05/25 18:55:15 | 000,280,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spreview.exe
[2011/05/25 18:55:14 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wer.dll
[2011/05/25 18:55:14 | 000,342,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certcli.dll
[2011/05/25 18:55:13 | 001,038,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2011/05/25 18:55:12 | 001,371,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dwmcore.dll
[2011/05/25 18:55:12 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbc32.dll
[2011/05/25 18:55:11 | 000,863,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diagperf.dll
[2011/05/25 18:55:10 | 003,367,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSAT.exe
[2011/05/25 18:55:10 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/05/25 18:55:10 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scavengeui.dll
[2011/05/25 18:55:09 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2011/05/25 18:55:09 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSWorkspace.dll
[2011/05/25 18:55:09 | 000,270,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsmf.dll
[2011/05/25 18:55:09 | 000,091,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3api.dll
[2011/05/25 18:55:08 | 000,768,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localspl.dll
[2011/05/25 18:55:08 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/05/25 18:55:08 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/05/25 18:55:06 | 002,522,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbgeng.dll
[2011/05/25 18:55:05 | 000,563,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netlogon.dll
[2011/05/25 18:55:05 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2011/05/25 18:55:05 | 000,406,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcfgx.dll
[2011/05/25 18:55:04 | 001,619,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2011/05/25 18:55:03 | 001,363,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Query.dll
[2011/05/25 18:55:03 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webio.dll
[2011/05/25 18:55:01 | 002,151,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcndmgr.dll
[2011/05/25 18:55:01 | 000,252,928 | —- | C] (Microsoft) – C:\Windows\System32\DShowRdpFilter.dll
[2011/05/25 18:55:01 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\upnp.dll
[2011/05/25 18:55:00 | 000,732,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2fs.dll
[2011/05/25 18:55:00 | 000,049,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2011/05/25 18:54:59 | 001,792,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2011/05/25 18:54:59 | 000,974,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sppobjs.dll
[2011/05/25 18:54:59 | 000,341,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2011/05/25 18:54:58 | 000,547,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2011/05/25 18:54:57 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcbuilder.exe
[2011/05/25 18:54:56 | 001,555,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certmgr.dll
[2011/05/25 18:54:56 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/05/25 18:54:55 | 001,712,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/05/25 18:54:55 | 000,508,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2011/05/25 18:54:54 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sppwinob.dll
[2011/05/25 18:54:53 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmd.exe
[2011/05/25 18:54:52 | 000,492,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32spl.dll
[2011/05/25 18:54:52 | 000,296,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfds.dll
[2011/05/25 18:54:52 | 000,206,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\framedynos.dll
[2011/05/25 18:54:50 | 002,414,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2011/05/25 18:54:50 | 000,551,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\samsrv.dll
[2011/05/25 18:54:50 | 000,442,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2011/05/25 18:54:50 | 000,240,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2011/05/25 18:54:49 | 001,063,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\werconcpl.dll
[2011/05/25 18:54:49 | 000,762,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroles.dll
[2011/05/25 18:54:49 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncsi.dll
[2011/05/25 18:54:47 | 000,168,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\credui.dll
[2011/05/25 18:54:45 | 000,854,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbghelp.dll
[2011/05/25 18:54:45 | 000,508,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/05/25 18:54:45 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/05/25 18:54:45 | 000,144,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basecsp.dll
[2011/05/25 18:54:44 | 000,801,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2011/05/25 18:54:44 | 000,488,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\evr.dll
[2011/05/25 18:54:44 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2011/05/25 18:54:43 | 000,335,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSATAPI.dll
[2011/05/25 18:54:42 | 000,776,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\calc.exe
[2011/05/25 18:54:41 | 000,778,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlsrv32.dll
[2011/05/25 18:54:41 | 000,242,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vpnike.dll
[2011/05/25 18:54:40 | 002,983,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2011/05/25 18:54:39 | 000,477,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lpksetup.exe
[2011/05/25 18:54:39 | 000,271,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fveapi.dll
[2011/05/25 18:54:38 | 000,380,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sxs.dll
[2011/05/25 18:54:37 | 000,176,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/05/25 18:54:36 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hgprint.dll
[2011/05/25 18:54:35 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prncache.dll
[2011/05/25 18:54:33 | 000,690,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2011/05/25 18:54:33 | 000,458,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2011/05/25 18:54:33 | 000,352,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2011/05/25 18:54:33 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\net1.exe
[2011/05/25 18:54:33 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpchttp.dll
[2011/05/25 18:54:32 | 000,321,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aepdu.dll
[2011/05/25 18:54:32 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aitagent.exe
[2011/05/25 18:54:30 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scansetting.dll
[2011/05/25 18:54:29 | 002,504,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2011/05/25 18:54:29 | 000,411,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlangpui.dll
[2011/05/25 18:54:29 | 000,213,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MMDevAPI.dll
[2011/05/25 18:54:29 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2011/05/25 18:54:29 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\davclnt.dll
[2011/05/25 18:54:28 | 000,167,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QSHVHOST.DLL
[2011/05/25 18:54:28 | 000,101,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2011/05/25 18:54:27 | 001,750,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnidui.dll
[2011/05/25 18:54:27 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2011/05/25 18:54:26 | 000,782,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2011/05/25 18:54:25 | 000,124,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fde.dll
[2011/05/25 18:54:24 | 002,146,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SyncCenter.dll
[2011/05/25 18:54:24 | 000,225,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netdiagfx.dll
[2011/05/25 18:54:24 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsUsbGDCoInstaller.dll
[2011/05/25 18:54:23 | 000,907,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdengin2.dll
[2011/05/25 18:54:23 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2011/05/25 18:54:22 | 000,560,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2011/05/25 18:54:20 | 000,830,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2ENC.DLL
[2011/05/25 18:54:20 | 000,826,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcore.dll
[2011/05/25 18:54:20 | 000,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSCard.dll
[2011/05/25 18:54:19 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2011/05/25 18:54:19 | 000,186,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/05/25 18:54:19 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsta.dll
[2011/05/25 18:54:18 | 000,630,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DXPTaskRingtone.dll
[2011/05/25 18:54:18 | 000,392,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2.dll
[2011/05/25 18:54:18 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aeinv.dll
[2011/05/25 18:54:18 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupcl.exe
[2011/05/25 18:54:17 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2011/05/25 18:54:15 | 001,624,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPEncEn.dll
[2011/05/25 18:54:15 | 000,199,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\onex.dll
[2011/05/25 18:54:15 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dwmredir.dll
[2011/05/25 18:54:14 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2011/05/25 18:54:13 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hbaapi.dll
[2011/05/25 18:54:12 | 002,217,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bootres.dll
[2011/05/25 18:54:12 | 001,077,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Narrator.exe
[2011/05/25 18:54:12 | 000,658,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autofmt.exe
[2011/05/25 18:54:12 | 000,196,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vaultsvc.dll
[2011/05/25 18:54:11 | 000,194,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\halmacpi.dll
[2011/05/25 18:54:11 | 000,194,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hal.dll
[2011/05/25 18:54:11 | 000,166,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2011/05/25 18:54:11 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IPHLPAPI.DLL
[2011/05/25 18:54:11 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiodg.exe
[2011/05/25 18:54:11 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\proquota.exe
[2011/05/25 18:54:10 | 000,679,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoconv.exe
[2011/05/25 18:54:10 | 000,400,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsmsnap.dll
[2011/05/25 18:54:10 | 000,303,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msinfo32.exe
[2011/05/25 18:54:10 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AudioSes.dll
[2011/05/25 18:54:10 | 000,167,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msutb.dll
[2011/05/25 18:54:10 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\regapi.dll
[2011/05/25 18:54:10 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mimefilt.dll
[2011/05/25 18:54:09 | 000,301,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srchadmin.dll
[2011/05/25 18:54:08 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercpl.dll
[2011/05/25 18:54:08 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msihnd.dll
[2011/05/25 18:54:08 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapphost.dll
[2011/05/25 18:54:08 | 000,202,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\framedyn.dll
[2011/05/25 18:54:08 | 000,181,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2011/05/25 18:54:08 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schtasks.exe
[2011/05/25 18:54:08 | 000,035,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\winusb.sys
[2011/05/25 18:54:07 | 001,466,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/05/25 18:54:07 | 000,155,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2011/05/25 18:54:06 | 000,171,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QAGENT.DLL
[2011/05/25 18:54:05 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2011/05/25 18:54:05 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netid.dll
[2011/05/25 18:54:03 | 000,399,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DXP.dll
[2011/05/25 18:54:03 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2011/05/25 18:54:02 | 001,227,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdc.dll
[2011/05/25 18:54:01 | 000,307,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scesrv.dll
[2011/05/25 18:53:59 | 000,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\untfs.dll
[2011/05/25 18:53:58 | 001,131,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2011/05/25 18:53:58 | 000,933,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Vault.dll
[2011/05/25 18:53:58 | 000,372,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2011/05/25 18:53:58 | 000,132,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ataport.sys
[2011/05/25 18:53:58 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nci.dll
[2011/05/25 18:53:57 | 001,326,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanpref.dll
[2011/05/25 18:53:56 | 001,003,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2011/05/25 18:53:56 | 000,187,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2011/05/25 18:53:56 | 000,098,816 | —- | C] (Microsoft) – C:\Windows\System32\Robocopy.exe
[2011/05/25 18:53:56 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/05/25 18:53:54 | 001,400,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DxpTaskSync.dll
[2011/05/25 18:53:54 | 001,040,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Display.dll
[2011/05/25 18:53:54 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mtxclu.dll
[2011/05/25 18:53:52 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\puiobj.dll
[2011/05/25 18:53:52 | 000,316,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sharemediacpl.dll
[2011/05/25 18:53:52 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2011/05/25 18:53:52 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/05/25 18:53:51 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\termmgr.dll
[2011/05/25 18:53:50 | 001,188,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DiagCpl.dll
[2011/05/25 18:53:50 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eudcedit.exe
[2011/05/25 18:53:50 | 000,140,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\scsiport.sys
[2011/05/25 18:53:48 | 001,066,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtctm.dll
[2011/05/25 18:53:48 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logoncli.dll
[2011/05/25 18:53:47 | 000,428,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\biocpl.dll
[2011/05/25 18:53:47 | 000,416,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiadefui.dll
[2011/05/25 18:53:47 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasppp.dll
[2011/05/25 18:53:47 | 000,111,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsetup.dll
[2011/05/25 18:53:46 | 000,856,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FirewallControlPanel.dll
[2011/05/25 18:53:46 | 000,233,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msconfig.exe
[2011/05/25 18:53:46 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sppcomapi.dll
[2011/05/25 18:53:44 | 002,157,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themecpl.dll
[2011/05/25 18:53:44 | 000,766,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpccpl.dll
[2011/05/25 18:53:44 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FWPUCLNT.DLL
[2011/05/25 18:53:44 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscmmc.dll
[2011/05/25 18:53:42 | 000,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2011/05/25 18:53:42 | 000,312,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hgcpl.dll
[2011/05/25 18:53:41 | 000,175,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scecli.dll
[2011/05/25 18:53:40 | 000,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscms.dll
[2011/05/25 18:53:40 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localsec.dll
[2011/05/25 18:53:40 | 000,268,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mprddm.dll
[2011/05/25 18:53:40 | 000,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2011/05/25 18:53:40 | 000,080,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2011/05/25 18:53:39 | 000,400,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2011/05/25 18:53:39 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SndVolSSO.dll
[2011/05/25 18:53:39 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcdsrv.dll
[2011/05/25 18:53:39 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasacct.dll
[2011/05/25 18:53:38 | 000,740,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\batmeter.dll
[2011/05/25 18:53:38 | 000,638,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\VAN.dll
[2011/05/25 18:53:38 | 000,600,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PerfCenterCPL.dll
[2011/05/25 18:53:38 | 000,600,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usercpl.dll
[2011/05/25 18:53:38 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2011/05/25 18:53:38 | 000,410,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanui.dll
[2011/05/25 18:53:37 | 001,644,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcenter.dll
[2011/05/25 18:53:37 | 000,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prntvpt.dll
[2011/05/25 18:53:36 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2011/05/25 18:53:36 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SndVol.exe
[2011/05/25 18:53:36 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\w32tm.exe
[2011/05/25 18:53:35 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizeng.dll
[2011/05/25 18:53:35 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroleui.dll
[2011/05/25 18:53:35 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wksprt.exe
[2011/05/25 18:53:34 | 003,727,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\accessibilitycpl.dll
[2011/05/25 18:53:34 | 000,190,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2011/05/25 18:53:34 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdeploy.dll
[2011/05/25 18:53:33 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSAC3ENC.DLL
[2011/05/25 18:53:32 | 002,130,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkmap.dll
[2011/05/25 18:53:32 | 000,516,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\main.cpl
[2011/05/25 18:53:32 | 000,186,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsldp.dll
[2011/05/25 18:53:32 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netjoin.dll
[2011/05/25 18:53:31 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2011/05/25 18:53:31 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wusa.exe
[2011/05/25 18:53:31 | 000,312,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MCEWMDRMNDBootstrap.dll
[2011/05/25 18:53:30 | 000,755,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sud.dll
[2011/05/25 18:53:30 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ActionCenter.dll
[2011/05/25 18:53:30 | 000,395,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prnfldr.dll
[2011/05/25 18:53:30 | 000,218,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OnLineIDCpl.dll
[2011/05/25 18:53:29 | 000,266,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2011/05/25 18:53:29 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskbarcpl.dll
[2011/05/25 18:53:28 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmon.ocx
[2011/05/25 18:53:28 | 000,325,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slui.exe
[2011/05/25 18:53:28 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iprtrmgr.dll
[2011/05/25 18:53:28 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrad.dll
[2011/05/25 18:53:28 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
[2011/05/25 18:53:27 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\defaultlocationcpl.dll
[2011/05/25 18:53:27 | 000,137,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\halacpi.dll
[2011/05/25 18:53:27 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorekmts.dll
[2011/05/25 18:53:27 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3cfg.dll
[2011/05/25 18:53:27 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidclass.sys
[2011/05/25 18:53:27 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftp.exe
[2011/05/25 18:53:26 | 000,692,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthprops.cpl
[2011/05/25 18:53:26 | 000,577,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2011/05/25 18:53:26 | 000,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shwebsvc.dll
[2011/05/25 18:53:26 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\intl.cpl
[2011/05/25 18:53:26 | 000,205,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\efscore.dll
[2011/05/25 18:53:26 | 000,148,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ifsutil.dll
[2011/05/25 18:53:26 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/05/25 18:53:26 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sisbkup.dll
[2011/05/25 18:53:25 | 000,750,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdcpl.dll
[2011/05/25 18:53:25 | 000,537,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ActionCenterCPL.dll
[2011/05/25 18:53:25 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcjt32.dll
[2011/05/25 18:53:25 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\recovery.dll
[2011/05/25 18:53:25 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/05/25 18:53:24 | 000,600,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TabletPC.cpl
[2011/05/25 18:53:24 | 000,484,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DeviceCenter.dll
[2011/05/25 18:53:24 | 000,295,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcdedit.exe
[2011/05/25 18:53:24 | 000,146,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoplay.dll
[2011/05/25 18:53:24 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2011/05/25 18:53:23 | 000,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2011/05/25 18:53:23 | 000,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sppnp.dll
[2011/05/25 18:53:23 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntlanman.dll
[2011/05/25 18:53:22 | 000,859,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OobeFldr.dll
[2011/05/25 18:53:22 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsutil.dll
[2011/05/25 18:53:22 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSTPager.ax
[2011/05/25 18:53:22 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2011/05/25 18:53:21 | 000,410,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\systemcpl.dll
[2011/05/25 18:53:21 | 000,297,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2011/05/25 18:53:21 | 000,210,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\recdisc.exe
[2011/05/25 18:53:21 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmartcardCredentialProvider.dll
[2011/05/25 18:53:20 | 000,656,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshwfp.dll
[2011/05/25 18:53:20 | 000,473,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\riched20.dll
[2011/05/25 18:53:20 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sethc.exe
[2011/05/25 18:53:20 | 000,262,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rstrui.exe
[2011/05/25 18:53:20 | 000,146,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcdboot.exe
[2011/05/25 18:53:19 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\blackbox.dll
[2011/05/25 18:53:19 | 000,202,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\activeds.dll
[2011/05/25 18:53:19 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ksproxy.ax
[2011/05/25 18:53:19 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NAPHLPR.DLL
[2011/05/25 18:53:18 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdosys.dll
[2011/05/25 18:53:18 | 000,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpsrcwp.dll
[2011/05/25 18:53:18 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\migisol.dll
[2011/05/25 18:53:18 | 000,093,696 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\System32\fms.dll
[2011/05/25 18:53:18 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2011/05/25 18:53:17 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshipsec.dll
[2011/05/25 18:53:17 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asycfilt.dll
[2011/05/25 18:53:16 | 000,592,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2011/05/25 18:53:16 | 000,428,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2011/05/25 18:53:16 | 000,254,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsqmcons.exe
[2011/05/25 18:53:16 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ReAgent.dll
[2011/05/25 18:53:16 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wavemsp.dll
[2011/05/25 18:53:16 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\isoburn.exe
[2011/05/25 18:53:15 | 000,586,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfrgui.exe
[2011/05/25 18:53:15 | 000,333,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3ui.dll
[2011/05/25 18:53:15 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2011/05/25 18:53:14 | 000,444,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wvc.dll
[2011/05/25 18:53:14 | 000,406,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wimgapi.dll
[2011/05/25 18:53:14 | 000,198,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysclass.dll
[2011/05/25 18:53:14 | 000,197,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ocsetup.exe
[2011/05/25 18:53:14 | 000,047,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzutil.exe
[2011/05/25 18:53:14 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wtsapi32.dll
[2011/05/25 18:53:12 | 000,281,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unimdm.tsp
[2011/05/25 18:53:12 | 000,190,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qcap.dll
[2011/05/25 18:53:12 | 000,113,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupugc.exe
[2011/05/25 18:53:12 | 000,051,200 | —- | C] (Twain Working Group) – C:\Windows\twain_32.dll
[2011/05/25 18:53:11 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qasf.dll
[2011/05/25 18:53:11 | 000,195,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/05/25 18:53:11 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/05/25 18:53:10 | 000,293,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ssText3d.scr
[2011/05/25 18:53:10 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srrstr.dll
[2011/05/25 18:53:10 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uxlib.dll
[2011/05/25 18:53:10 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2011/05/25 18:53:09 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanconn.dll
[2011/05/25 18:53:08 | 000,616,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmsdk.dll
[2011/05/25 18:53:08 | 000,230,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\clusapi.dll
[2011/05/25 18:53:08 | 000,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvfw32.dll
[2011/05/25 18:53:08 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nslookup.exe
[2011/05/25 18:53:08 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2011/05/25 18:53:08 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/05/25 18:53:07 | 000,211,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingFolder.dll
[2011/05/25 18:53:06 | 000,504,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2011/05/25 18:53:06 | 000,327,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wimserv.exe
[2011/05/25 18:53:06 | 000,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[2011/05/25 18:53:06 | 000,276,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskraid.exe
[2011/05/25 18:53:06 | 000,186,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2011/05/25 18:53:06 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perfmon.exe
[2011/05/25 18:53:06 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\acppage.dll
[2011/05/25 18:53:05 | 000,402,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmmgrtn.dll
[2011/05/25 18:53:05 | 000,202,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\input.dll
[2011/05/25 18:53:05 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QUTIL.DLL
[2011/05/25 18:53:05 | 000,046,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NAPCRYPT.DLL
[2011/05/25 18:53:04 | 000,327,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nltest.exe
[2011/05/25 18:53:04 | 000,292,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsAnytimeUpgradeResults.exe
[2011/05/25 18:53:04 | 000,174,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ocsetapi.dll
[2011/05/25 18:53:04 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2011/05/25 18:53:04 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UserAccountControlSettings.dll
[2011/05/25 18:53:04 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vpnikeapi.dll
[2011/05/25 18:53:03 | 001,111,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\onexui.dll
[2011/05/25 18:53:02 | 000,210,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2011/05/25 18:53:02 | 000,198,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpdwcn.dll
[2011/05/25 18:53:02 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsbas.dll
[2011/05/25 18:53:02 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/05/25 18:53:02 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\bfsvc.exe
[2011/05/25 18:53:02 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\runonce.exe
[2011/05/25 18:53:01 | 000,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2011/05/25 18:53:01 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/05/25 18:53:01 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sspisrv.dll
[2011/05/25 18:53:00 | 000,489,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/05/25 18:53:00 | 000,242,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapp3hst.dll
[2011/05/25 18:53:00 | 000,176,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFPlay.dll
[2011/05/25 18:53:00 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2011/05/25 18:52:59 | 000,507,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmdev.dll
[2011/05/25 18:52:59 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shacct.dll
[2011/05/25 18:52:59 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPUnattend.exe
[2011/05/25 18:52:58 | 000,186,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsadmin.exe
[2011/05/25 18:52:58 | 000,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2011/05/25 18:52:58 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unimdmat.dll
[2011/05/25 18:52:58 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsium.dll
[2011/05/25 18:52:58 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsmproxy.dll
[2011/05/25 18:52:57 | 000,878,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Bubbles.scr
[2011/05/25 18:52:57 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlcese30.dll
[2011/05/25 18:52:57 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mprapi.dll
[2011/05/25 18:52:57 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tabcal.exe
[2011/05/25 18:52:57 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpd3d.dll
[2011/05/25 18:52:56 | 001,160,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/05/25 18:52:56 | 000,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pdh.dll
[2011/05/25 18:52:56 | 000,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceSyncProvider.dll
[2011/05/25 18:52:56 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kstvtune.ax
[2011/05/25 18:52:56 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logman.exe
[2011/05/25 18:52:55 | 000,427,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceStatus.dll
[2011/05/25 18:52:55 | 000,350,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2011/05/25 18:52:55 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2011/05/25 18:52:55 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MdSched.exe
[2011/05/25 18:52:55 | 000,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\olethk32.dll
[2011/05/25 18:52:55 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncryptui.dll
[2011/05/25 18:52:55 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\djoin.exe
[2011/05/25 18:52:54 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mystify.scr
[2011/05/25 18:52:54 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Ribbons.scr
[2011/05/25 18:52:54 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbctrac.dll
[2011/05/25 18:52:54 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercfg.cpl
[2011/05/25 18:52:54 | 000,099,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QSVRMGMT.DLL
[2011/05/25 18:52:54 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lpremove.exe
[2011/05/25 18:52:54 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2011/05/25 18:52:54 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2011/05/25 18:52:53 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMADMOD.DLL
[2011/05/25 18:52:53 | 000,318,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2011/05/25 18:52:53 | 000,179,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ActionQueue.dll
[2011/05/25 18:52:53 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mapistub.dll
[2011/05/25 18:52:53 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mapi32.dll
[2011/05/25 18:52:53 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2011/05/25 18:52:53 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\utildll.dll
[2011/05/25 18:52:52 | 000,257,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsAnytimeUpgrade.exe
[2011/05/25 18:52:52 | 000,115,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3msm.dll
[2011/05/25 18:52:52 | 000,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiavideo.dll
[2011/05/25 18:52:52 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Kswdmcap.ax
[2011/05/25 18:52:52 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fphc.dll
[2011/05/25 18:52:52 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll
[2011/05/25 18:52:52 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\takeown.exe
[2011/05/25 18:52:52 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2011/05/25 18:52:51 | 000,541,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVSDECD.DLL
[2011/05/25 18:52:51 | 000,436,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmnet.dll
[2011/05/25 18:52:51 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqmapi.dll
[2011/05/25 18:52:51 | 000,153,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\VBICodec.ax
[2011/05/25 18:52:50 | 000,283,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdv.dll
[2011/05/25 18:52:50 | 000,265,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msnetobj.dll
[2011/05/25 18:52:50 | 000,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorAPI.dll
[2011/05/25 18:52:50 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sppinst.dll
[2011/05/25 18:52:50 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2011/05/25 18:52:50 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QCLIPROV.DLL
[2011/05/25 18:52:49 | 000,567,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2011/05/25 18:52:49 | 000,202,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unattend.dll
[2011/05/25 18:52:49 | 000,182,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RelPost.exe
[2011/05/25 18:52:49 | 000,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmstp.exe
[2011/05/25 18:52:49 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cca.dll
[2011/05/25 18:52:48 | 000,739,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOD.DLL
[2011/05/25 18:52:48 | 000,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupcln.dll
[2011/05/25 18:52:48 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MuiUnattend.exe
[2011/05/25 18:52:48 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vfwwdm32.dll
[2011/05/25 18:52:48 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsnmp32.dll
[2011/05/25 18:52:48 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\umb.dll
[2011/05/25 18:52:48 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pdhui.dll
[2011/05/25 18:52:48 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basesrv.dll
[2011/05/25 18:52:48 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AzSqlExt.dll
[2011/05/25 18:52:47 | 000,176,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msorcl32.dll
[2011/05/25 18:52:47 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2011/05/25 18:52:46 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsicli.exe
[2011/05/25 18:52:46 | 000,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\desk.cpl
[2011/05/25 18:52:46 | 000,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\relog.exe
[2011/05/25 18:52:46 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PrintIsolationProxy.dll
[2011/05/25 18:52:46 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiougc.exe
[2011/05/25 18:52:45 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spbcd.dll
[2011/05/25 18:52:45 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wkscli.dll
[2011/05/25 18:52:45 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WavDest.dll
[2011/05/25 18:52:44 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskpart.exe
[2011/05/25 18:52:44 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amstream.dll
[2011/05/25 18:52:44 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastapi.dll
[2011/05/25 18:52:44 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netbtugc.exe
[2011/05/25 18:52:43 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\itircl.dll
[2011/05/25 18:52:43 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2011/05/25 18:52:43 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2011/05/25 18:52:43 | 000,071,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\resutils.dll
[2011/05/25 18:52:43 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MultiDigiMon.exe
[2011/05/25 18:52:43 | 000,050,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setbcdlocale.dll
[2011/05/25 18:52:43 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nrpsrv.dll
[2011/05/25 18:52:42 | 001,027,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10.IME
[2011/05/25 18:52:42 | 000,430,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSTIFF.dll
[2011/05/25 18:52:42 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpps.dll
[2011/05/25 18:52:42 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertPolEng.dll
[2011/05/25 18:52:42 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ksxbar.ax
[2011/05/25 18:52:42 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\syssetup.dll
[2011/05/25 18:52:41 | 000,278,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2011/05/25 18:52:41 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2011/05/25 18:52:41 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFaultSecure.exe
[2011/05/25 18:52:40 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2011/05/25 18:52:40 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappgnui.dll
[2011/05/25 18:52:40 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tlscsp.dll
[2011/05/25 18:52:40 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\findstr.exe
[2011/05/25 18:52:40 | 000,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciqtz32.dll
[2011/05/25 18:52:40 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiarpc.dll
[2011/05/25 18:52:40 | 000,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ReAgentc.exe
[2011/05/25 18:52:39 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cabinet.dll
[2011/05/25 18:52:39 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2011/05/25 18:52:39 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\muifontsetup.dll
[2011/05/25 18:52:38 | 000,121,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sppc.dll
[2011/05/25 18:52:38 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2011/05/25 18:52:38 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tdi.sys
[2011/05/25 18:52:38 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spopk.dll
[2011/05/25 18:52:37 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\luainstall.dll
[2011/05/25 18:52:37 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbrpm.sys
[2011/05/25 18:52:36 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\manage-bde.exe
[2011/05/25 18:52:36 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\repair-bde.exe
[2011/05/25 18:52:36 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unlodctr.exe
[2011/05/25 18:52:36 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbisurf.ax
[2011/05/25 18:52:36 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdiasqmmodule.dll
[2011/05/25 18:52:36 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdmo.dll
[2011/05/25 18:52:36 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcfg.exe
[2011/05/25 18:52:36 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdprefdrvapi.dll
[2011/05/25 18:52:35 | 000,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetmib1.dll
[2011/05/25 18:52:35 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\g711codc.ax
[2011/05/25 18:52:34 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2011/05/25 18:52:34 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browcli.dll
[2011/05/25 18:52:34 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcconf.dll
[2011/05/25 18:52:34 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2011/05/25 18:52:34 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\profprov.dll
[2011/05/25 18:52:33 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2011/05/25 18:52:32 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perfts.dll
[2011/05/25 18:52:32 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icaapi.dll
[2011/05/25 18:52:31 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSMON.dll
[2011/05/25 18:52:30 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RDPENCDD.dll
[2011/05/25 18:52:30 | 000,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elsTrans.dll
[2011/05/25 18:52:30 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TRAPI.dll
[2011/05/25 18:52:30 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/05/25 18:52:29 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsperf.dll
[2011/05/25 18:52:29 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schedcli.dll
[2011/05/25 18:52:28 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\napdsnap.dll
[2011/05/25 18:52:28 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsauth.dll
[2011/05/25 18:52:26 | 000,430,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imkr80.ime
[2011/05/25 18:52:26 | 000,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2011/05/25 18:52:26 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsdchngr.dll
[2011/05/25 18:52:26 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shgina.dll
[2011/05/25 18:52:26 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sscore.dll
[2011/05/25 18:52:26 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\riched32.dll
[2011/05/25 18:52:24 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcfgex.dll
[2011/05/25 18:52:23 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/05/25 18:52:22 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshirda.dll
[2011/05/25 18:52:20 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD2.sys
[2011/05/25 18:52:20 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD.sys
[2011/05/25 18:52:19 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2011/05/25 18:52:18 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RDPREFDD.dll
[2011/05/25 18:52:18 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\C_ISCII.DLL
[2011/05/25 18:52:17 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shunimpl.dll
[2011/05/25 18:52:17 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2011/05/25 18:52:17 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2011/05/25 18:52:15 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2011/05/25 18:52:13 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDUS.DLL
[2011/05/25 18:52:13 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDUGHR1.DLL
[2011/05/25 18:52:13 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDINTEL.DLL
[2011/05/25 18:52:13 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDINKAN.DLL
[2011/05/25 18:52:12 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kbdlk41a.dll
[2011/05/25 18:52:12 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDSF.DLL
[2011/05/25 18:52:12 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDNEPR.DLL
[2011/05/25 18:52:12 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDINBEN.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDTURME.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDTAJIK.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDMON.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDMAORI.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDLT1.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDINTAM.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDINORI.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDINMAR.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDINHIN.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDBULG.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDBLR.DLL
[2011/05/25 18:52:12 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDBASH.DLL
[2011/05/25 18:52:12 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDGEO.DLL
[2011/05/25 18:52:11 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlsbres.dll
[2011/05/25 18:52:11 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDSG.DLL
[2011/05/25 18:52:11 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDCZ1.DLL
[2011/05/25 18:52:11 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDTUQ.DLL
[2011/05/25 18:52:11 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDTUF.DLL
[2011/05/25 18:52:11 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDPO.DLL
[2011/05/25 18:52:11 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDGR1.DLL
[2011/05/25 18:52:11 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDGKL.DLL
[2011/05/25 18:52:11 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnaddr.dll
[2011/05/25 18:52:11 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/05/25 18:52:10 | 000,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BlbEvents.dll
[2011/05/25 18:52:10 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pifmgr.dll
[2011/05/25 18:52:10 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizres.dll
[2011/05/25 18:51:06 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wbemcomn.dll
[2011/05/25 18:51:06 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2011/05/25 18:50:37 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmiEngine.dll
[2011/05/25 18:50:26 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PkgMgr.exe
[2011/05/25 18:50:26 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdscore.dll
[2011/05/25 18:48:49 | 000,323,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvstore.dll
[2011/05/25 18:48:49 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpx.dll
[2011/05/24 17:40:17 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2011/05/20 01:45:43 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{B061B159-9F52-4911-A1ED-3B752BA5FAF7}
[2011/05/19 11:42:24 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{A900E413-5AD6-4E35-A5DA-1F136A47037E}
[2011/05/18 20:29:58 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/05/18 16:31:31 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{EE93C549-DAE6-47EB-A4FE-6DD663490787}
[2011/05/18 03:48:26 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{A0719F36-7C31-415C-8FCC-69B7A7C22E3E}
[2011/05/16 16:15:27 | 000,000,000 | —D | C] – C:\Program Files\MyFreeCams
[2011/05/16 16:12:53 | 000,113,561 | -H– | C] (MyFreeCams.com ) – C:\Users\Monta\Desktop\SetupMFC.exe
[2011/05/16 15:44:17 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{EC925A32-BC9A-4CB9-8FBE-971BBD430DE4}
[2011/05/15 18:56:51 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{A1865609-6AF7-49C3-BC90-0D7CBAB8E543}
[2011/05/14 16:13:31 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{27A117CB-D7CA-4FDC-AFEF-D7A9C3DD3BB3}
[2011/05/12 02:45:47 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{2AD17850-0060-48B6-B618-2923FA6AD50D}
[2011/05/11 14:44:42 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{C5059BE2-6365-488E-87CE-928DA4F30030}
[2011/05/10 22:02:37 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\{21D4DC54-A54B-4CF7-B2E8-58D4A8BF440D}
[2011/05/10 13:31:47 | 000,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2011/05/10 13:31:46 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2011/05/10 13:26:38 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/05/10 13:26:37 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/05/10 02:59:55 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Local\Cranium_Consulting_and_Cu
[2011/05/10 02:58:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iPhoneBrowser
[2011/05/10 02:58:53 | 000,000,000 | —D | C] – C:\Program Files\iPhoneBrowser
[2011/05/10 01:11:46 | 000,000,000 | -H-D | C] – C:\Users\Monta\Desktop\Punjabi, Bhangra
[2011/04/02 16:41:49 | 000,114,688 | -HS- | C] (Microsoft Corporation) – C:\Users\Monta\AppData\Local\hcl.exe
[2011/04/02 16:41:45 | 000,114,688 | -HS- | C] (Microsoft Corporation) – C:\Users\Monta\AppData\Local\ukw.exe

========== Files - Modified Within 30 Days ==========

[2011/06/08 21:49:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\HiJackThis.exe
[2011/06/08 21:45:22 | 000,580,096 | —- | M] (OldTimer Tools) – C:\OTL.exe
[2011/06/08 18:04:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/08 18:04:24 | 796,733,440 | -HS- | M] () – C:\hiberfil.sys
[2011/06/03 06:25:56 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/03 06:25:56 | 000,009,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/31 14:51:07 | 001,402,880 | —- | M] () – C:\Program Files\HijackThis.msi
[2011/05/31 11:21:06 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/31 11:21:06 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/27 06:52:42 | 000,000,168 | -H– | M] () – C:\ProgramData\~31579896r
[2011/05/27 06:52:42 | 000,000,144 | -H– | M] () – C:\ProgramData\~31579896
[2011/05/27 06:52:30 | 000,000,639 | -H– | M] () – C:\Users\Monta\Desktop\Windows 7 Recovery.lnk
[2011/05/27 06:51:58 | 000,000,344 | -H– | M] () – C:\ProgramData\31579896
[2011/05/27 06:51:48 | 000,370,176 | -H– | M] (Microsoft Corporation) – C:\ProgramData\31579896.exe
[2011/05/27 06:50:05 | 000,434,670 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/05/27 06:42:34 | 000,478,720 | -H– | M] (Microsoft Corporation) – C:\ProgramData\aAgTqsVXLlTXJ.exe
[2011/05/27 01:39:16 | 000,001,244 | -H– | M] () – C:\Users\Monta\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/05/27 01:39:16 | 000,001,220 | -H– | M] () – C:\Users\Monta\Desktop\Spybot - Search & Destroy.lnk
[2011/05/27 01:15:02 | 000,404,640 | -H– | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/27 01:06:46 | 000,257,736 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/05/27 00:50:26 | 000,152,576 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\msclmd.dll
[2011/05/27 00:47:01 | 000,001,027 | -H– | M] () – C:\Users\Monta\Desktop\Eusing Free Registry Cleaner.lnk
[2011/05/26 10:37:55 | 143,848,174 | -H– | M] () – C:\Users\Monta\Desktop\Mercurialux_-_Synthetic_Stardust_Sound_Spa_Therapy_Tape_Intensive_(4S-2Ti).mp3
[2011/05/18 05:28:30 | 000,001,608 | -H– | M] () – C:\Users\Monta\Documents\time flies by.rtf
[2011/05/16 20:51:25 | 000,000,195 | -H– | M] () – C:\Users\Monta\Documents\police property.rtf
[2011/05/16 16:54:26 | 000,000,697 | -H– | M] () – C:\Users\Monta\Documents\letta.rtf
[2011/05/16 16:12:54 | 000,113,561 | -H– | M] (MyFreeCams.com ) – C:\Users\Monta\Desktop\SetupMFC.exe
[2011/05/13 18:33:02 | 000,000,195 | -H– | M] () – C:\Users\Monta\Documents\busters.rtf
[2011/05/10 21:20:58 | 000,003,584 | -H– | M] () – C:\Users\Monta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/10 02:56:34 | 000,554,273 | -H– | M] () – C:\Users\Monta\Desktop\SetupiPhoneBrowser.1.81.rar

========== Files Created - No Company Name ==========

[2011/05/31 14:51:06 | 001,402,880 | —- | C] () – C:\Program Files\HijackThis.msi
[2011/05/27 06:52:42 | 000,000,168 | -H– | C] () – C:\ProgramData\~31579896r
[2011/05/27 06:52:41 | 000,000,144 | -H– | C] () – C:\ProgramData\~31579896
[2011/05/27 06:52:30 | 000,000,639 | -H– | C] () – C:\Users\Monta\Desktop\Windows 7 Recovery.lnk
[2011/05/27 06:51:58 | 000,000,344 | -H– | C] () – C:\ProgramData\31579896
[2011/05/27 01:39:16 | 000,001,244 | -H– | C] () – C:\Users\Monta\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/05/27 01:39:16 | 000,001,220 | -H– | C] () – C:\Users\Monta\Desktop\Spybot - Search & Destroy.lnk
[2011/05/27 00:47:01 | 000,001,027 | -H– | C] () – C:\Users\Monta\Desktop\Eusing Free Registry Cleaner.lnk
[2011/05/26 10:37:19 | 143,848,174 | -H– | C] () – C:\Users\Monta\Desktop\Mercurialux_-_Synthetic_Stardust_Sound_Spa_Therapy_Tape_Intensive_(4S-2Ti).mp3
[2011/05/25 18:55:23 | 000,146,852 | —- | C] () – C:\Windows\System32\systemsf.ebd
[2011/05/25 18:52:31 | 000,010,429 | —- | C] () – C:\Windows\System32\ScavengeSpace.xml
[2011/05/25 18:52:07 | 000,105,559 | —- | C] () – C:\Windows\System32\RacRules.xml
[2011/05/18 05:00:40 | 000,001,608 | -H– | C] () – C:\Users\Monta\Documents\time flies by.rtf
[2011/05/16 20:51:24 | 000,000,195 | -H– | C] () – C:\Users\Monta\Documents\police property.rtf
[2011/05/13 19:07:07 | 000,000,697 | -H– | C] () – C:\Users\Monta\Documents\letta.rtf
[2011/05/13 18:33:01 | 000,000,195 | -H– | C] () – C:\Users\Monta\Documents\busters.rtf
[2011/05/10 21:20:58 | 000,003,584 | -H– | C] () – C:\Users\Monta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/10 02:56:29 | 000,554,273 | -H– | C] () – C:\Users\Monta\Desktop\SetupiPhoneBrowser.1.81.rar
[2011/05/09 17:56:11 | 000,000,193 | -H– | C] () – C:\Windows\WORDPAD.INI
[2011/04/23 17:09:57 | 000,819,200 | -H– | C] () – C:\Windows\System32\xvidcore.dll
[2011/04/23 17:09:56 | 000,180,224 | -H– | C] () – C:\Windows\System32\xvidvfw.dll
[2011/04/02 16:41:45 | 000,000,996 | -HS- | C] () – C:\Users\Monta\AppData\Local\61am7kh612rw85n14158n8334sb5378m1c5h32
[2011/04/02 16:41:45 | 000,000,996 | -HS- | C] () – C:\ProgramData\61am7kh612rw85n14158n8334sb5378m1c5h32
[2010/12/26 04:20:02 | 000,085,504 | -H– | C] () – C:\Windows\System32\ff_vfw.dll
[2010/08/15 16:15:43 | 000,206,208 | -H– | C] () – C:\Windows\PLFSetI.exe
[2010/08/15 16:15:42 | 000,113,264 | -H– | C] () – C:\Windows\FixUVC.exe
[2010/08/15 16:15:42 | 000,000,302 | -H– | C] () – C:\Windows\PidList_C.ini
[2010/07/06 08:09:56 | 000,361,808 | —- | C] () – C:\Windows\EMCRI_E.dll
[2010/07/06 08:01:36 | 000,247,560 | —- | C] () – C:\Windows\System32\drivers\RTConvEQ.dat
[2010/07/06 08:01:36 | 000,037,468 | —- | C] () – C:\Windows\System32\drivers\RtPCEE3.DAT
[2010/07/06 08:01:36 | 000,001,448 | —- | C] () – C:\Windows\System32\drivers\RtHdatEx.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX3.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX2.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX1.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX0.dat
[2010/07/06 08:01:36 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ1.dat
[2010/07/06 08:01:36 | 000,000,024 | —- | C] () – C:\Windows\System32\drivers\rtkhdaud.dat
[2010/01/13 19:41:00 | 000,309,248 | -H– | C] () – C:\Windows\System32\sqlite36_engine.dll
[2010/01/13 19:38:00 | 000,023,552 | -H– | C] () – C:\Windows\System32\DirectCOM.dll
[2009/07/13 21:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:33:53 | 000,257,736 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 19:05:48 | 000,628,460 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 19:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 19:05:48 | 000,110,612 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 19:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 19:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 19:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 16:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/02/29 18:08:08 | 000,024,840 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys

========== LOP Check ==========

[2011/06/07 23:04:01 | 000,000,000 | -H-D | M] – C:\Users\Monta\AppData\Roaming\BitTorrent
[2011/02/20 14:10:19 | 000,000,000 | -H-D | M] – C:\Users\Monta\AppData\Roaming\Hardcore
[2011/02/19 21:30:29 | 000,000,000 | -H-D | M] – C:\Users\Monta\AppData\Roaming\Ludia
[2011/02/19 20:50:16 | 000,000,000 | -H-D | M] – C:\Users\Monta\AppData\Roaming\PlayFirst
[2011/02/14 13:31:58 | 000,000,000 | -H-D | M] – C:\Users\Monta\AppData\Roaming\Sierra Wireless
[2011/02/19 20:48:49 | 000,000,000 | -H-D | M] – C:\Users\Monta\AppData\Roaming\WildTangent
[2011/04/03 00:11:37 | 000,000,000 | -H-D | M] – C:\Users\Monta\AppData\Roaming\Windows Live Writer
[2009/07/13 21:53:46 | 000,017,966 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 14:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/07/06 08:13:57 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 14:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/06/08 18:04:24 | 796,733,440 | -HS- | M] () – C:\hiberfil.sys
[2011/06/08 21:49:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\HiJackThis.exe
[2011/06/08 21:45:22 | 000,580,096 | —- | M] (OldTimer Tools) – C:\OTL.exe
[2011/06/08 18:04:25 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2010/07/06 08:02:24 | 000,002,167 | —- | M] () – C:\RHDSetup.log
[2011/05/02 21:58:28 | 000,000,356 | —- | M] () – C:\rkill.log

< %systemroot%\Fonts\*.com >
[2009/07/13 21:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/11/20 05:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | -H– | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2011/05/31 14:51:07 | 001,402,880 | —- | M] () – C:\Program Files\HijackThis.msi

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/12/26 05:22:06 | 000,000,221 | -HS- | M] () – C:\Users\Monta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/05/16 16:12:54 | 000,113,561 | -H– | M] (MyFreeCams.com ) – C:\Users\Monta\Desktop\SetupMFC.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-27 07:57:17

< >

< End of report >
OLT Extra report


OTL Extras logfile created on: 6/8/2011 9:47:21 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1013.10 Mb Total Physical Memory | 204.23 Mb Available Physical Memory | 20.16% Memory free
1.99 Gb Paging File | 1.23 Gb Available in Paging File | 61.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 219.79 Gb Total Space | 37.39 Gb Free Space | 17.01% Space Free | Partition Type: NTFS

Computer Name: MONTA-PC | User Name: Monta | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"" =
"C:\Program Files\Sierra Wireless Inc\Watcher\SwiApiMux.exe" = C:\Program Files\Sierra Wireless Inc\Watcher\SwiApiMux.exe:*:Enabled:SwiApiMux – (Sierra Wireless, Inc.)
"C:\Program Files\iBryte\playbryte\ibrytedesktop.exe" = C:\Program Files\iBryte\playbryte\ibrytedesktop.exe:*:Enabled:iBryteDesktop – (iBryte)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{353FE16B-30FE-469A-BF55-B978F4218003}" = iTunes
"{3B93C778-C710-4B38-A3DC-0DFBB8E2C894}" = FreePhoneLine
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E0E6383-9754-4471-939E-E4ABE02E3440}" = InstallIQ Updater
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A94D0A32-5BDB-4400-8E78-07B148B929C5}_is1" = MyFreeCams 2.2010.05.13
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BF0B77ED-11D9-4AF4-A408-CA75D8676C09}" = Sierra Wireless Watcher
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.184.610
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E33EAB77-A36A-4FBF-BB15-2BBF74C7A796}" = iPhoneBrowser
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"AC3Filter_is1" = AC3Filter 1.63b
"Acer Game Console" = Acer Game Console
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AiroWizard 1.0 Beta" = AiroWizard 1.0 Beta
"Ares" = Ares 2.1.7
"ASIO4ALL" = ASIO4ALL
"BitTorrent" = BitTorrent
"CCleaner" = CCleaner
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"ffdshow_is1" = ffdshow
"FL Studio 9" = FL Studio 9
"Hardcore" = Hardcore
"HDMI" = Intel® Graphics Media Accelerator Driver
"iBryte_playbryte" = PlayBryte
"Identity Card" = Identity Card
"IL Download Manager" = IL Download Manager
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"Itibiti_is1" = Launch Pad
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"PoiZone" = PoiZone
"Sawer" = Sawer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Toxic Biohazard" = Toxic Biohazard
"VLC media player" = VLC media player 1.1.9
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"WT088300" = Bejeweled 2 Deluxe
"WT088312" = Chuzzle Deluxe
"WT088318" = Diner Dash 2 Restaurant Rescue
"WT088332" = Farm Frenzy
"WT088336" = Insaniquarium Deluxe
"WT088350" = Jewel Quest Solitaire 2
"WT088364" = Plants vs. Zombies
"WT088371" = Zuma Deluxe
"WT088373" = Blackhawk Striker 2
"WT088393" = Dora's Carnival Adventure
"WT088413" = FATE
"WT088417" = Final Drive Nitro
"WT088441" = Jewel Quest
"WT088449" = Penguins!
"WT088453" = Polar Bowler
"WT088485" = The Price is Right 2010 Edition
"WT088517" = Zuma's Revenge
"WT088553" = Virtual Villagers 4 - The Tree of Life
"WT088653" = Jewel Quest - Heritage
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/28/2011 9:28:33 AM | Computer Name = Monta-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
of attribute "version" in element "assemblyIdentity" is invalid.

Error - 5/28/2011 9:28:48 AM | Computer Name = Monta-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\itibiti
soft phone\Itibiti.exe". Dependent Assembly Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 5/28/2011 9:30:06 AM | Computer Name = Monta-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.

Error - 5/28/2011 11:14:09 AM | Computer Name = Monta-PC | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: Received from 192.168.0.132:5353 4 monta-pc.local.
Addr 192.168.0.132

Error - 5/28/2011 11:14:09 AM | Computer Name = Monta-PC | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: ProbeCount 2; will rename 4 Monta-PC.local.
Addr 192.168.0.130

Error - 5/28/2011 11:14:09 AM | Computer Name = Monta-PC | Source = Bonjour Service | ID = 100
Description = Local Hostname Monta-PC.local already in use; will try Monta-PC-2.local
instead

Error - 5/28/2011 11:46:02 AM | Computer Name = Monta-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce79912 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x0001ffff Faulting process id:
0x1108 Faulting application start time: 0x01cc1d4a3aa021b1 Faulting application path:
C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: unknown Report
Id: 96de8d89-8941-11e0-b2ea-88ae1d6c7748

Error - 5/28/2011 12:42:18 PM | Computer Name = Monta-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce79912 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000096 Fault offset: 0x046a000d Faulting process id:
0x1108 Faulting application start time: 0x01cc1d4a3aa021b1 Faulting application path:
C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: unknown Report
Id: 72fc3067-8949-11e0-b2ea-88ae1d6c7748

Error - 5/28/2011 12:42:18 PM | Computer Name = Monta-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program Internet Explorer because of this error. Program: Internet Explorer
File:
The error value is listed in the Additional Data section. User Action 1. Open the
file again. This situation might be a temporary problem that corrects itself when
the program runs again. 2. If the file still cannot be accessed and - It is on the
network, your network administrator should verify that there is not a problem with
the network and that the server can be contacted. - It is on a removable disk, for
example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the
computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK,
click Start, click Run, type CMD, and then click OK. At the command prompt, type
CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from
a backup copy. 5. Determine whether other files on the same disk can be opened.
If not, the disk might be damaged. If it is a hard disk, contact your administrator
or computer hardware vendor for further assistance. Additional Data Error value: 00000000
Disk
type: 0

Error - 5/30/2011 7:34:15 AM | Computer Name = Monta-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce79912 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x006e0049 Faulting process id:
0xa40 Faulting application start time: 0x01cc1ebaca8f63f3 Faulting application path:
C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: unknown Report
Id: bf38e0a6-8ab0-11e0-b3ac-88ae1d6c7748

[ System Events ]
Error - 6/8/2011 9:05:03 PM | Computer Name = Monta-PC | Source = DCOM | ID = 10005
Description =

Error - 6/8/2011 9:05:11 PM | Computer Name = Monta-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1068

Error - 6/8/2011 9:05:12 PM | Computer Name = Monta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/8/2011 9:05:12 PM | Computer Name = Monta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/8/2011 9:06:28 PM | Computer Name = Monta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/8/2011 9:06:28 PM | Computer Name = Monta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/8/2011 9:06:56 PM | Computer Name = Monta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/8/2011 9:06:56 PM | Computer Name = Monta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/8/2011 9:06:56 PM | Computer Name = Monta-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1068

Error - 6/8/2011 9:12:00 PM | Computer Name = Monta-PC | Source = DCOM | ID = 10005
Description =


< End of report >
Hi

Please do the following:


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKCU..\Run: [aAgTqsVXLlTXJ] C:\ProgramData\aAgTqsVXLlTXJ.exe (Microsoft Corporation)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O33 - MountPoints2\{40dbbfef-37b8-11e0-a2fd-88ae1d6c7748}\Shell - "" = AutoRun
    O33 - MountPoints2\{40dbbfef-37b8-11e0-a2fd-88ae1d6c7748}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\AppLaunch.exe AUTORUN=1
    [2011/05/27 06:52:28 | 000,000,000 | -H-D | C] – C:\Users\Monta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Recovery
    [2011/05/27 06:51:48 | 000,370,176 | -H– | C] (Microsoft Corporation) – C:\ProgramData\31579896.exe
    [2011/05/27 06:42:39 | 000,478,720 | -H– | C] (Microsoft Corporation) – C:\ProgramData\aAgTqsVXLlTXJ.exe
    [2011/04/02 16:41:49 | 000,114,688 | -HS- | C] (Microsoft Corporation) – C:\Users\Monta\AppData\Local\hcl.exe
    [2011/04/02 16:41:45 | 000,114,688 | -HS- | C] (Microsoft Corporation) – C:\Users\Monta\AppData\Local\ukw.exe
    [2011/05/27 06:52:42 | 000,000,168 | -H– | M] () – C:\ProgramData\~31579896r
    [2011/05/27 06:52:42 | 000,000,144 | -H– | M] () – C:\ProgramData\~31579896
    [2011/05/27 06:52:30 | 000,000,639 | -H– | M] () – C:\Users\Monta\Desktop\Windows 7 Recovery.lnk
    [2011/05/27 06:51:58 | 000,000,344 | -H– | M] () – C:\ProgramData\31579896
    [2011/04/02 16:41:45 | 000,000,996 | -HS- | C] () – C:\Users\Monta\AppData\Local\61am7kh612rw85n14158n8334sb5378m1c5h32
    [2011/04/02 16:41:45 | 000,000,996 | -HS- | C] () – C:\ProgramData\61am7kh612rw85n14158n8334sb5378m1c5h32
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
hey, thanks for yourhelp. I havent been aable to save anything to my desktop, but i'msaving it in the c drive instead . (i hopethat doesnt make too much of a difference)

here's the first OTL log :

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\aAgTqsVXLlTXJ deleted successfully.
C:\ProgramData\aAgTqsVXLlTXJ.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{40dbbfef-37b8-11e0-a2fd-88ae1d6c7748}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40dbbfef-37b8-11e0-a2fd-88ae1d6c7748}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{40dbbfef-37b8-11e0-a2fd-88ae1d6c7748}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40dbbfef-37b8-11e0-a2fd-88ae1d6c7748}\ not found.
File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\AppLaunch.exe AUTORUN=1 not found.
C:\Users\Monta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Recovery folder moved successfully.
C:\ProgramData\31579896.exe moved successfully.
File C:\ProgramData\aAgTqsVXLlTXJ.exe not found.
C:\Users\Monta\AppData\Local\hcl.exe moved successfully.
C:\Users\Monta\AppData\Local\ukw.exe moved successfully.
C:\ProgramData\~31579896r moved successfully.
C:\ProgramData\~31579896 moved successfully.
C:\Users\Monta\Desktop\Windows 7 Recovery.lnk moved successfully.
C:\ProgramData\31579896 moved successfully.
C:\Users\Monta\AppData\Local\61am7kh612rw85n14158n8334sb5378m1c5h32 moved successfully.
C:\ProgramData\61am7kh612rw85n14158n8334sb5378m1c5h32 moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\cmd.bat deleted successfully.
C:\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Monta
->Flash cache emptied: 9532 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Monta
->Temp folder emptied: 11003230 bytes
->Temporary Internet Files folder emptied: 213306401 bytes
->Java cache emptied: 754342 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 69100 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 215.00 mb


OTL by OldTimer - Version 3.2.23.0 log created on 06102011_170623

Files\Folders moved on Reboot…
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZHRVDQ2T\iframe[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZHRVDQ2T\like[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O1XINW4O\google_ca[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O1XINW4O\index[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O1XINW4O\like[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J831CBVV\ifr[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J831CBVV\ifr[2].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J831CBVV\proxy[1].html moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H4DJ2GWJ\button[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPVTBAOH\xd_proxy[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES9MCIY1\google_ca[3].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES9MCIY1\google_ca[4].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES9MCIY1\iepngfix[2].htc moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES9MCIY1\ig[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4PFNSA29\localpages_com[2].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QVPDJ3C\lpc[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QVPDJ3C\mailhome[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QVPDJ3C\mailhome[2].htm moved successfully.
File move failed. C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot…

Files\Folders moved on Reboot…
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZHRVDQ2T\iframe[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZHRVDQ2T\like[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O1XINW4O\google_ca[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O1XINW4O\index[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O1XINW4O\like[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J831CBVV\ifr[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J831CBVV\ifr[2].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J831CBVV\proxy[1].html not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H4DJ2GWJ\button[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPVTBAOH\xd_proxy[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES9MCIY1\google_ca[3].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES9MCIY1\google_ca[4].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES9MCIY1\iepngfix[2].htc not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ES9MCIY1\ig[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4PFNSA29\localpages_com[2].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QVPDJ3C\lpc[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QVPDJ3C\mailhome[1].htm not found!
File\Folder C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QVPDJ3C\mailhome[2].htm not found!
File move failed. C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot…




now here's the aswMBR log :

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-10 17:21:22
—————————–
17:21:22.697 OS Version: Windows 6.1.7601 Service Pack 1
17:21:22.697 Number of processors: 2 586 0x1C0A
17:21:22.697 ComputerName: MONTA-PC UserName: Monta
17:21:24.460 Initialize success
17:21:30.279 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
17:21:30.294 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3
17:21:30.310 Disk 0 MBR read successfully
17:21:30.326 Disk 0 MBR scan
17:21:30.326 Disk 0 Windows 7 default MBR code
17:21:30.341 Disk 0 scanning sectors +488394752
17:21:30.388 Disk 0 scanning C:\Windows\system32\drivers
17:21:39.093 Service scanning
17:21:40.684 Disk 0 trace - called modules:
17:21:40.746 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x850671ed]<<
17:21:40.762 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85037030]
17:21:40.778 3 CLASSPNP.SYS[86d8259e] -> nt!IofCallDriver -> [0x84639958]
17:21:40.809 5 ACPI.sys[866973d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84645028]
17:21:40.809 \Driver\iaStor[0x8462d838] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x850671ed
17:21:40.840 Scan finished successfully
17:22:01.214 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
17:22:01.229 The log file has been saved successfully to "C:\aswMBR.txt"
Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
ComboFix 11-06-10.09 - Monta 10/06/2011 17:41:52.1.2 - x86 NETWORK Microsoft Windows 7 Starter 6.1.7601.1.1252.2.1033.18.1013.662 [GMT -7:00] Running from: C:\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\airowizard\AiroWizard.exe . . ((((((((((((((((((((((((( Files Created from 2011-05-11 to 2011-06-11 ))))))))))))))))))))))))))))))) . . 2011-06-11 00:51 . 2011-06-11 00:52 ——– d—–w- c:\users\Monta\AppData\Local\temp 2011-06-11 00:51 . 2011-06-11 00:51 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-11 00:38 . 2011-06-11 00:38 ——– d—–w- C:\32788R22FWJFW 2011-06-11 00:19 . 2011-06-11 00:19 589632 —-a-w- C:\aswMBR.exe 2011-06-11 00:06 . 2011-06-11 00:06 ——– d—–w- C:\_OTL 2011-06-09 05:13 . 2011-06-09 05:13 625664 —-a-w- C:\dds.scr 2011-06-09 04:49 . 2011-06-09 04:49 388608 —-a-w- C:\HiJackThis.exe 2011-06-09 04:45 . 2011-06-09 04:45 580096 —-a-w- C:\OTL.exe 2011-06-08 05:57 . 2011-06-08 05:57 ——– d–h–w- c:\users\Monta\AppData\Local\{18F19DC1-96F1-4044-AAE1-FACCE83E8D17} 2011-06-03 05:56 . 2011-06-03 05:56 ——– d–h–w- c:\users\Monta\AppData\Local\{647447FF-A3F8-42D9-9829-BE6B992101D7} 2011-06-02 09:21 . 2011-06-02 09:21 ——– d–h–w- c:\users\Monta\AppData\Local\{8EEC84A5-6F74-4403-8DE0-E8C8C2063D55} 2011-05-31 21:51 . 2011-05-31 21:51 1402880 —-a-w- c:\program files\HijackThis.msi 2011-05-31 21:22 . 2011-05-31 21:22 ——– d–h–w- c:\users\Monta\AppData\Local\{99415816-9113-4FCA-BD7F-E42155E1A541} 2011-05-31 18:36 . 2011-05-31 18:36 ——– d–h–w- c:\users\Monta\AppData\Local\{FC1B948D-E405-4B92-9EAC-186814A945B0} 2011-05-31 18:14 . 2011-05-31 18:14 ——– d–h–w- c:\users\Monta\AppData\Local\{FBEFDB65-DA15-4360-9AB3-F75B019B786F} 2011-05-31 17:51 . 2011-05-31 17:51 ——– d–h–w- c:\users\Monta\AppData\Local\{1CA80C3A-2A88-426B-BB31-F2FF90AE991E} 2011-05-31 02:39 . 2011-05-31 02:39 ——– d—–w- c:\users\Monta\AppData\Local\ElevatedDiagnostics 2011-05-30 22:47 . 2011-05-30 22:48 ——– d–h–w- c:\users\Monta\AppData\Local\{5C73EC84-3D84-47DC-8BFD-6DEDAC46B35F} 2011-05-30 06:22 . 2011-05-30 06:22 ——– d–h–w- c:\users\Monta\AppData\Local\{5FE4BCB8-10E2-49C1-A69C-FD93A65C31AF} 2011-05-28 15:16 . 2011-05-29 03:17 ——– d–h–w- c:\users\Monta\AppData\Local\{B7CFEFCB-BBD4-4741-873E-49827977A8C9} 2011-05-27 20:14 . 2011-05-27 20:14 ——– d–h–w- c:\users\Monta\AppData\Local\{6ABC8976-2E0A-4431-8672-7EB18893EBF0} 2011-05-27 08:39 . 2011-05-31 18:47 ——– d–h–w- c:\programdata\Spybot - Search & Destroy 2011-05-27 08:39 . 2011-05-27 08:41 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-05-27 08:15 . 2011-05-27 08:15 404640 —ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-27 08:14 . 2011-05-27 08:14 ——– d–h–w- c:\users\Monta\AppData\Local\{A93989CD-BB66-4814-B9F4-401FFB46053A} 2011-05-27 07:46 . 2011-05-27 07:56 ——– d—–w- c:\program files\Eusing Free Registry Cleaner 2011-05-27 07:26 . 2011-05-27 07:26 ——– d—–w- c:\program files\CCleaner 2011-05-27 07:24 . 2011-05-31 18:48 ——– d–h–w- c:\windows\system32\SPReview 2011-05-27 07:20 . 2011-05-31 18:48 ——– d–h–w- c:\windows\system32\EventProviders 2011-05-26 01:56 . 2010-11-05 01:58 1130824 —-a-w- c:\windows\system32\dfshim.dll 2011-05-26 01:56 . 2010-11-20 12:21 11776 —-a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2011-05-26 01:56 . 2010-11-20 10:24 52224 —-a-w- c:\windows\system32\drivers\TsUsbFlt.sys 2011-05-26 01:56 . 2010-11-20 12:19 3215872 —-a-w- c:\windows\system32\mstscax.dll 2011-05-26 01:54 . 2010-11-20 12:21 974336 —-a-w- c:\windows\system32\sppobjs.dll 2011-05-26 01:53 . 2010-11-20 12:21 346624 —-a-w- c:\windows\system32\untfs.dll 2011-05-26 01:52 . 2010-11-20 12:21 507392 —-a-w- c:\windows\system32\wmdrmdev.dll 2011-05-26 01:51 . 2010-11-20 12:21 351232 —-a-w- c:\windows\system32\wmicmiplugin.dll 2011-05-26 01:51 . 2010-11-20 12:21 780288 —-a-w- c:\windows\system32\wbem\wbemcore.dll 2011-05-26 01:51 . 2010-11-20 12:21 363008 —-a-w- c:\windows\system32\wbemcomn.dll 2011-05-26 01:51 . 2010-11-20 12:19 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll 2011-05-26 01:50 . 2010-11-20 12:21 697344 —-a-w- c:\windows\system32\SmiEngine.dll 2011-05-26 01:50 . 2010-11-20 12:21 189952 —-a-w- c:\windows\system32\wdscore.dll 2011-05-26 01:50 . 2010-11-20 12:17 209920 —-a-w- c:\windows\system32\PkgMgr.exe 2011-05-26 01:48 . 2010-11-20 12:18 323072 —-a-w- c:\windows\system32\drvstore.dll 2011-05-26 01:48 . 2010-11-20 12:18 257024 —-a-w- c:\windows\system32\dpx.dll 2011-05-25 00:40 . 2011-04-22 19:14 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-20 08:45 . 2011-05-20 08:45 ——– d–h–w- c:\users\Monta\AppData\Local\{B061B159-9F52-4911-A1ED-3B752BA5FAF7} 2011-05-19 18:42 . 2011-05-19 18:42 ——– d–h–w- c:\users\Monta\AppData\Local\{A900E413-5AD6-4E35-A5DA-1F136A47037E} 2011-05-19 03:29 . 2011-04-09 05:56 123904 —-a-w- c:\windows\system32\poqexec.exe 2011-05-18 23:31 . 2011-05-18 23:31 ——– d–h–w- c:\users\Monta\AppData\Local\{EE93C549-DAE6-47EB-A4FE-6DD663490787} 2011-05-18 10:48 . 2011-05-18 10:48 ——– d–h–w- c:\users\Monta\AppData\Local\{A0719F36-7C31-415C-8FCC-69B7A7C22E3E} 2011-05-16 23:15 . 2011-05-31 18:47 ——– d—–w- c:\program files\MyFreeCams 2011-05-16 22:44 . 2011-05-16 22:44 ——– d–h–w- c:\users\Monta\AppData\Local\{EC925A32-BC9A-4CB9-8FBE-971BBD430DE4} 2011-05-16 01:56 . 2011-05-16 01:57 ——– d–h–w- c:\users\Monta\AppData\Local\{A1865609-6AF7-49C3-BC90-0D7CBAB8E543} 2011-05-14 23:13 . 2011-05-14 23:13 ——– d–h–w- c:\users\Monta\AppData\Local\{27A117CB-D7CA-4FDC-AFEF-D7A9C3DD3BB3} 2011-05-12 09:45 . 2011-05-12 09:45 ——– d–h–w- c:\users\Monta\AppData\Local\{2AD17850-0060-48B6-B618-2923FA6AD50D} . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-27 07:50 . 2009-07-14 02:05 152576 —ha-w- c:\windows\system32\msclmd.dll 2011-04-09 06:02 . 2011-05-10 20:26 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-04-09 06:02 . 2011-05-10 20:26 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-04-06 23:20 . 2011-04-06 23:20 91424 —ha-w- c:\windows\system32\dnssd.dll 2011-04-06 23:20 . 2011-04-06 23:20 75040 —ha-w- c:\windows\system32\jdns_sd.dll 2011-04-06 23:20 . 2011-04-06 23:20 197920 —ha-w- c:\windows\system32\dnssdX.dll 2011-04-06 23:20 . 2011-04-06 23:20 107808 —ha-w- c:\windows\system32\dns-sd.exe 2011-03-25 02:58 . 2011-05-10 20:31 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-03-25 02:58 . 2011-05-10 20:31 284672 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-03-25 02:58 . 2011-05-10 20:31 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-03-25 02:57 . 2011-05-10 20:31 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-03-25 02:57 . 2011-05-10 20:31 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-03-25 02:57 . 2011-05-10 20:31 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-03-25 02:57 . 2011-05-10 20:31 5888 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-03-15 06:47 . 2010-06-24 19:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-03-15 04:05 . 2011-03-29 20:55 6792528 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E9673A71-ABE1-4CD9-BF07-2300FD33219F}\mpengine.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}] 2010-11-05 01:58 297808 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{b278d9f8-0fa9-465e-9938-0c392605d8e3}"= "mscoree.dll" [2010-11-05 297808] . [HKEY_CLASSES_ROOT\clsid\{b278d9f8-0fa9-465e-9938-0c392605d8e3}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-05-27 02:40 120176 —ha-w- c:\program files\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ares"="c:\program files\Ares\Ares.exe" [2010-10-27 1015808] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-04-04 1165824] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-22 9292392] "SuiteTray"="c:\program files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264] "EgisUpdate"="c:\program files\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584] "EgisTecPMMUpdate"="c:\program files\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920] "mwlDaemon"="c:\program files\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-06-16 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-06-16 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-06-16 150552] "LManager"="c:\program files\Launch Manager\LManager.exe" [2010-06-22 968272] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-05 1692968] "PLFSetI"="c:\windows\PLFSetI.exe" [2010-08-15 206208] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 715296] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888] "WatcherHelper"="c:\program files\Sierra Wireless Inc\Watcher\WaHelper.exe" [2008-05-28 114688] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] "iBryte playbryte Desktop"="c:\program files\iBryte\playbryte\ibrytedesktop.exe" [2011-04-24 167936] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-21 963976] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 18992] R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 16432] R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60976] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2010-06-22 321104] R2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 735776] R2 GREGService;GREGService;c:\program files\Acer\Registration\GREGsvc.exe [2010-01-08 23584] R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232] R3 EUCR;EUCR;c:\windows\system32\DRIVERS\EUCR6SK.SYS [2010-06-17 82768] R3 MWLService;MyWinLocker Service;c:\program files\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-05-20 68208] . . — Other Services/Drivers In Memory — . *NewlyCreated* - ASWMBR *Deregistered* - aswMBR . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.ca/ig mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&m=aod255&r=27b51210w555l0434ww65w4712u741 uInternet Settings,ProxyOverride = *.local IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.1.254 192.168.1.254 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-06-10 17:58:24 ComboFix-quarantined-files.txt 2011-06-11 00:58 . Pre-Run: 40,317,919,232 bytes free Post-Run: 40,211,648,512 bytes free . - - End Of File - - CB9715A89AA057B2998A5923ACBAD288
Hi

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
hey, so i dont have malware bytes and everytime i go to the page to try and download it i get redireced to some fake anti virus carp**.
there was nothing found in the malware one…. The online scanner took forever and said there was six threats, however there was no list of threats found button that i could see, or maybe i accidently went passed it , either way i'm rescanning it and will try again. my first scan took two hours, so it might be a bit… Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6496 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 02/05/2011 11:02:33 PM mbam-log-2011-05-02 (23-02-33).txt Scan type: Full scan (C:\|) Objects scanned: 253018 Time elapsed: 31 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 6 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\mF31004PjCfH31004 (Trojan.FakeAlert) -> Value: mF31004PjCfH31004 -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\programdata\mf31004pjcfh31004\mf31004pjcfh31004.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Monta\AppData\Local\fhf.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully. c:\Users\Monta\AppData\Local\yof.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully. c:\Users\Monta\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\0R481U27\xvidsetup[1].exe (Adware.Hotbar) -> Quarantined and deleted successfully. c:\Users\Monta\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\NHX7TEKH\xvidsetup[1].exe (Adware.Hotbar) -> Quarantined and deleted successfully. c:\Users\Monta\AppData\Local\Temp\0.2898192124595429.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
nope, The malware one said there was nothing detected .. here's the online one ESET: C:\Users\Monta\Desktop\Fruity Loops FL Studio Producer Edition [2010] + Cracks - www.GuruFuel.com\flstudio_9.0.exe Win32/OpenCandy application C:\Users\Monta\Downloads\Fruity Loops FL Studio Producer Edition [2010] + Cracks - www.GuruFuel.com.rar Win32/OpenCandy application C:\Users\Monta\Music\Chris_Brown-F.A.M.E. & (Deluxe Version) 2011\Chris_Brown-F.A.M.E._(Deluxe_Version)_(2011).7z multiple threats C:\Windows\System32\sysprep\CRYPTBASE.DLL a variant of Win32/Injector.FQG trojan C:\_OTL\MovedFiles\06102011_170623\C_ProgramData\31579896.exe a variant of Win32/Kryptik.OGD trojan C:\_OTL\MovedFiles\06102011_170623\C_ProgramData\aAgTqsVXLlTXJ.exe a variant of Win32/Kryptik.OGD trojan
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::
File::
C:\Users\Monta\Desktop\Fruity Loops FL Studio Producer Edition [2010] + Cracks - www.GuruFuel.com\flstudio_9.0.exe
C:\Users\Monta\Downloads\Fruity Loops FL Studio Producer Edition [2010] + Cracks - www.GuruFuel.com.rar 
C:\Users\Monta\Music\Chris_Brown-F.A.M.E. & (Deluxe Version) 2011\Chris_Brown-F.A.M.E._(Deluxe_Version)_(2011).7z

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT



submit a file to virustotal for analysis
  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file
    C:\Windows\System32\sysprep\CRYPTBASE.DLL
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results
  • If you get a message saying File has already been analyzed: click Reanalyze file now
  • Once scanned, copy and paste the link to the results page in your next reply.


NEXT



Visit ADOBEand download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 20 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Java cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Please advise how the computer is running now and if there are any outstanding issues
my computers running allot better, though i wasnt able to find the CRYPTBASE.DLL file to scan. it doesnt seem to exist. also, i found that my sound while trying to play audio online doesn't work, though every other sound on y computer does, such as listening to music with windows media player or system sounds and beeps etc… i checked the settings in internet options under multedmiedia but it appears all the right boxes are checked… here's my combo fix log : ComboFix 11-06-13.03 - Monta 13/06/2011 23:22:45.3.2 - x86 NETWORK Microsoft Windows 7 Starter 6.1.7601.1.1252.2.1033.18.1013.701 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Monta\Desktop\CFScript.txt SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\users\Monta\Desktop\Fruity Loops FL Studio Producer Edition [2010] + Cracks - www.GuruFuel.com\flstudio_9.0.exe" "c:\users\Monta\Downloads\Fruity Loops FL Studio Producer Edition [2010] + Cracks - www.GuruFuel.com.rar" "c:\users\Monta\Music\Chris_Brown-F.A.M.E. & (Deluxe Version) 2011\Chris_Brown-F.A.M.E._(Deluxe_Version)_(2011).7z" . . ((((((((((((((((((((((((( Files Created from 2011-05-14 to 2011-06-14 ))))))))))))))))))))))))))))))) . . 2011-06-14 06:34 . 2011-06-14 06:34 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-14 06:01 . 2011-06-14 06:02 ——– d—–w- c:\users\Monta\AppData\Local\{1B6EA47D-20F1-4637-9EFC-B9DDB11322C1} 2011-06-14 05:57 . 2011-06-14 06:36 ——– d—–w- c:\users\Monta\AppData\Local\temp 2011-06-11 02:27 . 2011-06-11 02:27 ——– d—–w- c:\program files\ESET 2011-06-11 00:19 . 2011-06-11 00:19 589632 —-a-w- C:\aswMBR.exe 2011-06-11 00:06 . 2011-06-11 00:06 ——– d—–w- C:\_OTL 2011-06-09 05:13 . 2011-06-09 05:13 625664 —-a-w- C:\dds.scr 2011-06-09 04:49 . 2011-06-09 04:49 388608 —-a-w- C:\HiJackThis.exe 2011-06-09 04:45 . 2011-06-09 04:45 580096 —-a-w- C:\OTL.exe 2011-06-08 05:57 . 2011-06-08 05:57 ——– d—–w- c:\users\Monta\AppData\Local\{18F19DC1-96F1-4044-AAE1-FACCE83E8D17} 2011-06-03 05:56 . 2011-06-03 05:56 ——– d—–w- c:\users\Monta\AppData\Local\{647447FF-A3F8-42D9-9829-BE6B992101D7} 2011-06-02 09:21 . 2011-06-02 09:21 ——– d—–w- c:\users\Monta\AppData\Local\{8EEC84A5-6F74-4403-8DE0-E8C8C2063D55} 2011-05-31 21:51 . 2011-05-31 21:51 1402880 —-a-w- c:\program files\HijackThis.msi 2011-05-31 21:22 . 2011-05-31 21:22 ——– d—–w- c:\users\Monta\AppData\Local\{99415816-9113-4FCA-BD7F-E42155E1A541} 2011-05-31 18:36 . 2011-05-31 18:36 ——– d—–w- c:\users\Monta\AppData\Local\{FC1B948D-E405-4B92-9EAC-186814A945B0} 2011-05-31 18:14 . 2011-05-31 18:14 ——– d—–w- c:\users\Monta\AppData\Local\{FBEFDB65-DA15-4360-9AB3-F75B019B786F} 2011-05-31 17:51 . 2011-05-31 17:51 ——– d—–w- c:\users\Monta\AppData\Local\{1CA80C3A-2A88-426B-BB31-F2FF90AE991E} 2011-05-31 02:39 . 2011-05-31 02:39 ——– d—–w- c:\users\Monta\AppData\Local\ElevatedDiagnostics 2011-05-30 22:47 . 2011-05-30 22:48 ——– d—–w- c:\users\Monta\AppData\Local\{5C73EC84-3D84-47DC-8BFD-6DEDAC46B35F} 2011-05-30 06:22 . 2011-05-30 06:22 ——– d—–w- c:\users\Monta\AppData\Local\{5FE4BCB8-10E2-49C1-A69C-FD93A65C31AF} 2011-05-28 15:16 . 2011-05-29 03:17 ——– d—–w- c:\users\Monta\AppData\Local\{B7CFEFCB-BBD4-4741-873E-49827977A8C9} 2011-05-27 20:14 . 2011-05-27 20:14 ——– d—–w- c:\users\Monta\AppData\Local\{6ABC8976-2E0A-4431-8672-7EB18893EBF0} 2011-05-27 08:39 . 2011-05-31 18:47 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2011-05-27 08:39 . 2011-05-27 08:41 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-05-27 08:15 . 2011-05-27 08:15 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-27 08:14 . 2011-05-27 08:14 ——– d—–w- c:\users\Monta\AppData\Local\{A93989CD-BB66-4814-B9F4-401FFB46053A} 2011-05-27 07:46 . 2011-06-11 01:43 ——– d—–w- c:\program files\Eusing Free Registry Cleaner 2011-05-27 07:26 . 2011-05-27 07:26 ——– d—–w- c:\program files\CCleaner 2011-05-27 07:24 . 2011-05-31 18:48 ——– d—–w- c:\windows\system32\SPReview 2011-05-27 07:20 . 2011-05-31 18:48 ——– d—–w- c:\windows\system32\EventProviders 2011-05-26 01:56 . 2010-11-05 01:58 1130824 —-a-w- c:\windows\system32\dfshim.dll 2011-05-26 01:56 . 2010-11-20 12:21 11776 —-a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2011-05-26 01:56 . 2010-11-20 10:24 52224 —-a-w- c:\windows\system32\drivers\TsUsbFlt.sys 2011-05-26 01:56 . 2010-11-20 12:19 3215872 —-a-w- c:\windows\system32\mstscax.dll 2011-05-26 01:54 . 2010-11-20 12:21 974336 —-a-w- c:\windows\system32\sppobjs.dll 2011-05-26 01:53 . 2010-11-20 12:21 346624 —-a-w- c:\windows\system32\untfs.dll 2011-05-26 01:52 . 2010-11-20 12:21 507392 —-a-w- c:\windows\system32\wmdrmdev.dll 2011-05-26 01:51 . 2010-11-20 12:21 351232 —-a-w- c:\windows\system32\wmicmiplugin.dll 2011-05-26 01:51 . 2010-11-20 12:21 780288 —-a-w- c:\windows\system32\wbem\wbemcore.dll 2011-05-26 01:51 . 2010-11-20 12:21 363008 —-a-w- c:\windows\system32\wbemcomn.dll 2011-05-26 01:51 . 2010-11-20 12:19 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll 2011-05-26 01:50 . 2010-11-20 12:21 697344 —-a-w- c:\windows\system32\SmiEngine.dll 2011-05-26 01:50 . 2010-11-20 12:21 189952 —-a-w- c:\windows\system32\wdscore.dll 2011-05-26 01:50 . 2010-11-20 12:17 209920 —-a-w- c:\windows\system32\PkgMgr.exe 2011-05-26 01:48 . 2010-11-20 12:18 323072 —-a-w- c:\windows\system32\drvstore.dll 2011-05-26 01:48 . 2010-11-20 12:18 257024 —-a-w- c:\windows\system32\dpx.dll 2011-05-25 00:40 . 2011-04-22 19:14 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-20 08:45 . 2011-05-20 08:45 ——– d—–w- c:\users\Monta\AppData\Local\{B061B159-9F52-4911-A1ED-3B752BA5FAF7} 2011-05-19 18:42 . 2011-05-19 18:42 ——– d—–w- c:\users\Monta\AppData\Local\{A900E413-5AD6-4E35-A5DA-1F136A47037E} 2011-05-19 03:29 . 2011-04-09 05:56 123904 —-a-w- c:\windows\system32\poqexec.exe 2011-05-18 23:31 . 2011-05-18 23:31 ——– d—–w- c:\users\Monta\AppData\Local\{EE93C549-DAE6-47EB-A4FE-6DD663490787} 2011-05-18 10:48 . 2011-05-18 10:48 ——– d—–w- c:\users\Monta\AppData\Local\{A0719F36-7C31-415C-8FCC-69B7A7C22E3E} 2011-05-16 23:15 . 2011-05-31 18:47 ——– d—–w- c:\program files\MyFreeCams 2011-05-16 22:44 . 2011-05-16 22:44 ——– d—–w- c:\users\Monta\AppData\Local\{EC925A32-BC9A-4CB9-8FBE-971BBD430DE4} 2011-05-16 01:56 . 2011-05-16 01:57 ——– d—–w- c:\users\Monta\AppData\Local\{A1865609-6AF7-49C3-BC90-0D7CBAB8E543} . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-29 16:11 . 2011-05-03 05:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-27 07:50 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll 2011-04-09 06:02 . 2011-05-10 20:26 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-04-09 06:02 . 2011-05-10 20:26 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-04-06 23:20 . 2011-04-06 23:20 91424 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 23:20 . 2011-04-06 23:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 23:20 . 2011-04-06 23:20 197920 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 23:20 . 2011-04-06 23:20 107808 —-a-w- c:\windows\system32\dns-sd.exe 2011-03-25 02:58 . 2011-05-10 20:31 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-03-25 02:58 . 2011-05-10 20:31 284672 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-03-25 02:58 . 2011-05-10 20:31 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-03-25 02:57 . 2011-05-10 20:31 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-03-25 02:57 . 2011-05-10 20:31 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-03-25 02:57 . 2011-05-10 20:31 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-03-25 02:57 . 2011-05-10 20:31 5888 —-a-w- c:\windows\system32\drivers\usbd.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}] 2010-11-05 01:58 297808 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{b278d9f8-0fa9-465e-9938-0c392605d8e3}"= "mscoree.dll" [2010-11-05 297808] . [HKEY_CLASSES_ROOT\clsid\{b278d9f8-0fa9-465e-9938-0c392605d8e3}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-05-27 02:40 120176 —-a-w- c:\program files\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ares"="c:\program files\Ares\Ares.exe" [2010-10-27 1015808] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-04-04 1165824] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-22 9292392] "SuiteTray"="c:\program files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264] "EgisUpdate"="c:\program files\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584] "EgisTecPMMUpdate"="c:\program files\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920] "mwlDaemon"="c:\program files\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-06-16 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-06-16 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-06-16 150552] "LManager"="c:\program files\Launch Manager\LManager.exe" [2010-06-22 968272] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-05 1692968] "PLFSetI"="c:\windows\PLFSetI.exe" [2010-08-15 206208] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 715296] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888] "WatcherHelper"="c:\program files\Sierra Wireless Inc\Watcher\WaHelper.exe" [2008-05-28 114688] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] "iBryte playbryte Desktop"="c:\program files\iBryte\playbryte\ibrytedesktop.exe" [2011-04-24 167936] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640] R3 EUCR;EUCR;c:\windows\system32\DRIVERS\EUCR6SK.SYS [2010-06-17 82768] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] R3 MWLService;MyWinLocker Service;c:\program files\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 18992] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 16432] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60976] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2010-06-22 321104] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 735776] S2 GREGService;GREGService;c:\program files\Acer\Registration\GREGsvc.exe [2010-01-08 23584] S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-05-20 68208] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.ca/ig mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&m=aod255&r=27b51210w555l0434ww65w4712u741 uInternet Settings,ProxyOverride = *.local IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.1.254 192.168.1.254 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(5876) c:\program files\EgisTec MyWinLocker\x86\psdprotect.dll c:\program files\EgisTec MyWinLocker\x86\sysenv.dll . ———————— Other Running Processes ———————— . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\taskhost.exe c:\program files\Internet Explorer\iexplore.exe c:\program files\Internet Explorer\iexplore.exe c:\windows\system32\conhost.exe c:\windows\system32\igfxsrvc.exe c:\program files\Launch Manager\LMworker.exe c:\windows\system32\wbem\unsecapp.exe c:\windows\system32\igfxext.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2011-06-13 23:58:50 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-14 06:58 ComboFix2.txt 2011-06-14 06:10 ComboFix3.txt 2011-06-11 00:58 . Pre-Run: 40,209,051,648 bytes free Post-Run: 40,162,484,224 bytes free . - - End Of File - - 869EB6AF0FEA90DA5B6565F520CC785C

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI