This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Trouble

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I've recently reinstalled windows and had to use windows update and manually reinstall some drivers.
It's Windows Vis Home Prem SP2
Yesterday I had a suspicion I donwloaded a trojan and upon rebooting immediately in safe mode MBAM found and deleted 5 threats.
The only reason I'm posting today is because i learned the hard way how trojans can be extremely difficult to detect and delete, so I would really appreciate the extra help just to ensure I managed to get the little tyke before it had a chance to wreak any havoc. I have only been running in safemode w/networking since the attack.
Thanks :)

PS. Avast (free version) didn't pick it up, would MSE be a more reliable antivirus? I've been recommended it…

OTL.txt:
OTL logfile created on: 02/04/2012 16:56:01 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\James\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.93 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 82.68% Memory free
6.06 Gb Paging File | 5.72 Gb Available in Paging File | 94.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.33 Gb Total Space | 153.56 Gb Free Space | 69.07% Space Free | Partition Type: NTFS
Drive D: | 10.55 Gb Total Space | 1.80 Gb Free Space | 17.04% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\James\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PeerBlock\peerblock.exe (PeerBlock, LLC)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsi Software GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsi Software GmbH)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\Windows\System32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.ru/cnt/9134
IE - HKCU\..\SearchScopes,DefaultScope = {E88E0043-C9D4-4e33-8555-FEE4F5B63060}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={79F9CB1…mp;d=2012-03-30 10:51:23&v;=10.2.0.3&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060}: "URL" = http://go.mail.ru/search?q={searchTerms}&a;…n=1&fr;=ietb
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "http://www.mail.ru/"
FF - prefs.js..browser.search.defaulturl: "http://go.mail.ru/search?fr=fftb&utf8in;&q;="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {ab91efd4-6975-4081-8552-1b3922ed79e2}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:7.0.1426
FF - prefs.js..keyword.URL: "http://go.mail.ru/search?utf8in=1&fr;=fftbUFix&q;="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/03/27 14:29:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/29 17:56:35 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/30 11:22:08 | 000,000,000 | —D | M]

[2012/03/27 16:28:44 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Extensions
[2012/04/01 16:49:20 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0l74cvg8.default\extensions
[2012/03/29 11:05:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0l74cvg8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/03/27 17:14:02 | 000,000,000 | —D | M] (HP Detect) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0l74cvg8.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
[2012/03/27 16:26:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/03/27 14:29:37 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/03/29 17:56:25 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/03/30 10:51:12 | 000,003,749 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/03/29 17:56:26 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/03/29 17:56:26 | 000,000,769 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/03/29 17:56:26 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41FA04C7-70F4-474F-94D3-0F4EE206AC4E}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A41946F0-88E7-42A5-A6DE-766C80AA4C59}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsi Software GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{845987be-778c-11e1-843b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{845987be-778c-11e1-843b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\MSWorks\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2012/04/02 16:53:58 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Users\James\Desktop\OTL.exe
[2012/04/01 16:57:47 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
[2012/04/01 16:57:47 | 000,000,000 | —D | C] – C:\Program Files\ASIO4ALL v2
[2012/04/01 16:57:30 | 000,225,280 | —- | C] (Propellerhead Software AB) – C:\Windows\System32\rewire.dll
[2012/04/01 16:57:26 | 000,000,000 | —D | C] – C:\Users\James\Documents\Image-Line
[2012/04/01 16:57:09 | 001,554,944 | —- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) – C:\Windows\System32\vorbis.acm
[2012/04/01 16:57:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
[2012/04/01 16:56:11 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
[2012/04/01 16:56:10 | 000,000,000 | —D | C] – C:\Program Files\VstPlugins
[2012/04/01 16:55:59 | 000,000,000 | —D | C] – C:\Program Files\Outsim
[2012/04/01 16:50:48 | 000,000,000 | —D | C] – C:\Program Files\Image-Line
[2012/03/30 17:02:50 | 000,000,000 | —D | C] – C:\Users\James\Documents\AdobeReaderPatch10.1.2_cpsid_92870-2
[2012/03/30 11:26:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/03/30 11:25:35 | 000,032,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msonpmon.dll
[2012/03/30 11:20:44 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2012/03/30 11:20:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2012/03/30 11:19:17 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2012/03/30 11:18:23 | 000,000,000 | R–D | C] – C:\Users\James\Desktop\Art
[2012/03/30 11:16:01 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2012/03/30 11:14:32 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Microsoft Help
[2012/03/30 11:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2012/03/30 11:10:15 | 000,000,000 | —D | C] – C:\IUware Online
[2012/03/30 10:59:54 | 000,000,000 | —D | C] – C:\Users\James\Documents\Vuze Downloads
[2012/03/30 10:57:35 | 000,000,000 | —D | C] – C:\Users\James\.swt
[2012/03/30 10:57:29 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Azureus
[2012/03/30 10:56:11 | 000,000,000 | —D | C] – C:\Program Files\Vuze
[2012/03/30 10:50:27 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/03/30 10:19:06 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\WinRAR
[2012/03/30 10:07:58 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2012/03/30 09:57:44 | 000,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2012/03/30 09:57:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2012/03/30 09:53:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2012/03/30 09:39:46 | 000,000,000 | —D | C] – C:\Users\James\Documents\Adobe CS5
[2012/03/29 16:36:26 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Adobe
[2012/03/29 16:33:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2012/03/29 16:33:57 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2012/03/29 16:33:11 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2012/03/29 15:46:23 | 001,184,768 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\drivers\athr.sys
[2012/03/29 15:46:23 | 000,000,000 | —D | C] – C:\Windows\System32\nn-NO
[2012/03/29 15:46:22 | 000,397,312 | —- | C] (Atheros) – C:\Windows\System32\athihvs.dll
[2012/03/29 15:46:22 | 000,061,440 | —- | C] (Atheros) – C:\Windows\System32\athihvui.dll
[2012/03/29 15:46:02 | 000,000,000 | —D | C] – C:\Program Files\Cisco
[2012/03/29 15:46:01 | 000,000,000 | —D | C] – C:\Program Files\Atheros
[2012/03/29 15:45:19 | 000,000,000 | —D | C] – C:\ProgramData\Atheros
[2012/03/29 15:36:44 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2012/03/29 15:24:15 | 000,000,000 | —D | C] – C:\Program Files\Mail.Ru
[2012/03/29 11:48:00 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2012/03/29 11:47:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
[2012/03/29 11:47:52 | 001,071,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSCOMCTL.OCX
[2012/03/29 11:47:52 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSSTDFMT.DLL
[2012/03/29 11:47:50 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2012/03/29 11:44:09 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Macromedia
[2012/03/29 11:44:09 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Adobe
[2012/03/29 11:42:13 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/03/29 11:19:24 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Template
[2012/03/29 11:17:06 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2012/03/29 11:14:41 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2012/03/29 11:14:05 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2012/03/29 10:43:23 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\System32\CSVer.dll
[2012/03/29 10:40:17 | 000,000,000 | —D | C] – C:\Program Files\Device Doctor
[2012/03/27 19:42:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2012/03/27 19:14:11 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2012/03/27 19:13:59 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/03/27 19:13:59 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/03/27 19:13:58 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/03/27 19:13:58 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/03/27 19:13:58 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/03/27 18:54:33 | 000,038,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2012/03/27 18:48:11 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2012/03/27 18:34:22 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2012/03/27 18:34:21 | 003,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2012/03/27 18:34:21 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2012/03/27 18:32:42 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BthMtpContextHandler.dll
[2012/03/27 18:32:42 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShextAutoplay.exe
[2012/03/27 18:32:38 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceConnectApi.dll
[2012/03/27 18:32:34 | 000,546,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2012/03/27 18:32:34 | 000,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2012/03/27 18:32:34 | 000,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2012/03/27 18:32:34 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWMDRM.dll
[2012/03/27 18:32:34 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2012/03/27 18:32:34 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2012/03/27 18:30:22 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2012/03/27 18:29:13 | 000,000,000 | —D | C] – C:\Program Files\IDT
[2012/03/27 18:29:09 | 000,368,640 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestecap.dll
[2012/03/27 18:29:09 | 000,142,848 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestacap.dll
[2012/03/27 18:29:09 | 000,061,440 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestaren.dll
[2012/03/27 18:29:07 | 000,536,576 | —- | C] (IDT, Inc.) – C:\Windows\System32\idtmini1.exe
[2012/03/27 18:29:07 | 000,086,016 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\AESTCom.dll
[2012/03/27 18:29:06 | 012,021,852 | —- | C] (IDT, Inc.) – C:\Windows\System32\idtcpl.cpl
[2012/03/27 18:29:06 | 003,567,616 | —- | C] (IDT, Inc.) – C:\Windows\System32\stlang.dll
[2012/03/27 18:29:06 | 000,450,652 | —- | C] (IDT, Inc.) – C:\Windows\sttray.exe
[2012/03/27 18:29:01 | 000,000,000 | —D | C] – C:\Windows\System32\SRSLabs
[2012/03/27 18:20:46 | 000,237,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2012/03/27 18:12:47 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012/03/27 18:12:47 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012/03/27 18:12:47 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/03/27 18:12:47 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012/03/27 18:12:47 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/03/27 18:12:47 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/03/27 18:12:47 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012/03/27 18:12:47 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/03/27 18:12:47 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012/03/27 18:12:47 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012/03/27 18:12:47 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012/03/27 18:12:47 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012/03/27 18:12:47 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012/03/27 18:12:47 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012/03/27 18:12:47 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012/03/27 18:12:47 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/03/27 18:12:47 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012/03/27 18:12:47 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012/03/27 18:12:46 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/03/27 18:12:46 | 001,798,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/03/27 18:12:46 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/03/27 18:12:46 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/03/27 18:12:46 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012/03/27 18:12:46 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012/03/27 18:12:46 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012/03/27 18:12:46 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012/03/27 18:12:46 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/03/27 18:12:46 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/03/27 18:12:46 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012/03/27 18:12:46 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012/03/27 18:12:46 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012/03/27 18:12:46 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/03/27 18:12:46 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012/03/27 18:12:46 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/03/27 18:12:46 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/03/27 18:12:45 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012/03/27 18:12:45 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012/03/27 18:11:52 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2012/03/27 18:11:52 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2012/03/27 18:11:52 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2012/03/27 18:11:52 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2012/03/27 18:11:52 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2012/03/27 18:11:52 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2012/03/27 18:11:52 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2012/03/27 18:11:49 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2012/03/27 18:11:49 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2012/03/27 18:11:49 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2012/03/27 18:11:49 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2012/03/27 18:11:49 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2012/03/27 18:11:49 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2012/03/27 18:11:49 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2012/03/27 18:11:49 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2012/03/27 18:11:48 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2012/03/27 18:11:48 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2012/03/27 18:11:11 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2012/03/27 18:11:11 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2012/03/27 18:11:11 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2012/03/27 18:11:10 | 000,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2012/03/27 18:11:10 | 000,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2012/03/27 18:11:10 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2012/03/27 18:08:06 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2012/03/27 18:08:06 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2012/03/27 18:08:06 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2012/03/27 18:06:55 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browserchoice.exe
[2012/03/27 18:05:15 | 000,000,000 | —D | C] – C:\Program Files\Intel
[2012/03/27 18:05:14 | 000,000,000 | —D | C] – C:\Intel
[2012/03/27 18:00:01 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2012/03/27 17:58:55 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2012/03/27 17:58:39 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2012/03/27 17:58:39 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2012/03/27 17:58:39 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2012/03/27 17:58:39 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2012/03/27 17:58:39 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2012/03/27 17:58:37 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2012/03/27 17:58:37 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2012/03/27 17:58:37 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2012/03/27 17:58:37 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2012/03/27 17:58:36 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2012/03/27 17:58:29 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2012/03/27 17:58:29 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2012/03/27 17:58:29 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2012/03/27 17:58:29 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2012/03/27 17:58:29 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2012/03/27 17:56:34 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/03/27 17:56:33 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/03/27 17:56:26 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2012/03/27 17:55:55 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2012/03/27 17:55:53 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2012/03/27 17:55:53 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2012/03/27 17:55:48 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2012/03/27 17:55:47 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2012/03/27 17:55:45 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2012/03/27 17:55:44 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2012/03/27 17:55:44 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2012/03/27 17:54:38 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2012/03/27 17:54:37 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2012/03/27 17:54:35 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2012/03/27 17:54:27 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2012/03/27 17:52:59 | 000,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2012/03/27 17:52:41 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2012/03/27 17:52:14 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2012/03/27 17:52:13 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2012/03/27 17:51:21 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/03/27 17:51:06 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2012/03/27 17:50:55 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2012/03/27 17:50:37 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2012/03/27 17:50:36 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2012/03/27 17:50:33 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2012/03/27 17:50:31 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2012/03/27 17:50:30 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2012/03/27 17:50:28 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2012/03/27 17:50:23 | 002,044,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/03/27 17:50:20 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciseq.dll
[2012/03/27 17:50:01 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2012/03/27 17:50:01 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2012/03/27 17:50:01 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2012/03/27 17:49:51 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2012/03/27 17:49:44 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2012/03/27 17:49:43 | 000,613,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2012/03/27 17:49:38 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2012/03/27 17:49:38 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2012/03/27 17:49:38 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2012/03/27 17:49:37 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2012/03/27 17:49:35 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2012/03/27 17:49:29 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2012/03/27 17:49:25 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2012/03/27 17:30:21 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2012/03/27 17:23:37 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/03/27 17:23:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/03/27 17:23:32 | 000,000,000 | —D | C] – C:\Windows\WinRAR
[2012/03/27 17:23:32 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2012/03/27 16:34:41 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2012/03/27 16:34:40 | 002,421,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2012/03/27 16:34:21 | 000,575,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2012/03/27 16:34:21 | 000,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2012/03/27 16:34:21 | 000,035,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2012/03/27 16:34:13 | 000,171,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2012/03/27 16:34:13 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2012/03/27 16:33:06 | 000,000,000 | —D | C] – C:\Users\James\Desktop\KB971033
[2012/03/27 16:28:35 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Mozilla
[2012/03/27 16:28:35 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Mozilla
[2012/03/27 16:26:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2012/03/27 16:26:25 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/03/27 16:24:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock
[2012/03/27 16:24:39 | 000,000,000 | —D | C] – C:\Program Files\PeerBlock
[2012/03/27 16:22:01 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Malwarebytes
[2012/03/27 16:21:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/27 16:21:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/03/27 16:21:36 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/03/27 16:21:36 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/27 16:06:08 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Compaq Drivers Update Utility
[2012/03/27 15:52:12 | 000,000,000 | —D | C] – C:\Program Files\Realtek
[2012/03/27 15:52:11 | 000,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2012/03/27 15:51:56 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\InstallShield
[2012/03/27 15:32:38 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\DRPSu
[2012/03/27 15:31:58 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2012/03/27 15:00:39 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\hpqLog
[2012/03/27 14:35:18 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\OnlineArmor
[2012/03/27 14:35:18 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2012/03/27 14:34:06 | 000,029,312 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAnet.sys
[2012/03/27 14:34:06 | 000,025,192 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAmon.sys
[2012/03/27 14:34:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2012/03/27 14:33:17 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2012/03/27 14:30:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012/03/27 14:30:31 | 000,337,880 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2012/03/27 14:30:31 | 000,020,696 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2012/03/27 14:30:28 | 000,053,848 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2012/03/27 14:30:28 | 000,035,672 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2012/03/27 14:30:27 | 000,612,184 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2012/03/27 14:30:26 | 000,057,688 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2012/03/27 14:29:43 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2012/03/27 14:29:21 | 000,041,184 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/03/27 14:29:20 | 000,201,352 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2012/03/27 14:28:55 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2012/03/27 14:28:55 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/03/27 07:41:22 | 000,000,000 | —D | C] – C:\Windows\Panther
[2012/03/27 07:23:53 | 000,000,000 | —D | C] – C:\Windows.old.001
[2012/03/26 23:05:46 | 000,000,000 | R–D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/03/26 23:05:46 | 000,000,000 | R–D | C] – C:\Users\James\Searches
[2012/03/26 23:05:46 | 000,000,000 | R–D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/03/26 23:05:34 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Identities
[2012/03/26 23:05:33 | 000,000,000 | R–D | C] – C:\Users\James\Contacts
[2012/03/26 23:05:32 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\VirtualStore
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\AppData\Local\Temporary Internet Files
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Templates
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Start Menu
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\SendTo
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Recent
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\PrintHood
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\NetHood
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Documents\My Videos
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Documents\My Pictures
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Documents\My Music
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\My Documents
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Local Settings
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\AppData\Local\History
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Cookies
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\Application Data
[2012/03/26 23:05:28 | 000,000,000 | -HSD | C] – C:\Users\James\AppData\Local\Application Data
[2012/03/26 23:05:27 | 000,000,000 | –SD | C] – C:\Users\James\AppData\Roaming\Microsoft
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Videos
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Saved Games
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Pictures
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Music
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Links
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Favorites
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Downloads
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Documents
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\Desktop
[2012/03/26 23:05:27 | 000,000,000 | R–D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/03/26 23:05:27 | 000,000,000 | -H-D | C] – C:\Users\James\AppData
[2012/03/26 23:05:27 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Temp
[2012/03/26 23:05:27 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Microsoft
[2012/03/26 23:05:27 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Media Center Programs
[2012/03/26 23:02:29 | 000,000,000 | —D | C] – C:\Windows\Debug
[2012/03/26 22:55:55 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2012/03/26 18:03:36 | 000,000,000 | —D | C] – C:\Windows.old.000
[2012/03/26 13:41:12 | 002,068,016 | —- | C] (Kaspersky Lab ZAO) – C:\Users\James\Desktop\TDSSKiller.exe
[2012/03/26 05:28:44 | 000,000,000 | —D | C] – C:\Windows.old
[2012/03/12 10:51:26 | 000,000,000 | -H-D | C] – C:\VritualRoot

========== Files - Modified Within 30 Days ==========

[2012/04/02 16:53:59 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL.exe
[2012/04/02 16:52:12 | 000,607,600 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/02 16:52:12 | 000,107,478 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/02 16:47:46 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/01 17:01:12 | 000,003,760 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/01 17:01:12 | 000,003,760 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/01 16:57:30 | 000,000,932 | —- | M] () – C:\Users\James\Desktop\FL Studio 9.lnk
[2012/03/30 17:07:17 | 003,736,048 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/03/30 16:51:39 | 000,316,676 | —- | M] () – C:\Users\James\Documents\DELF_B1_exemple2.pdf
[2012/03/30 11:21:20 | 000,003,584 | —- | M] () – C:\Users\James\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/30 11:15:58 | 000,000,361 | —- | M] () – C:\Users\James\Desktop\Music - Shortcut.lnk
[2012/03/30 11:15:54 | 000,000,370 | —- | M] () – C:\Users\James\Desktop\Pictures - Shortcut.lnk
[2012/03/30 11:15:51 | 000,000,373 | —- | M] () – C:\Users\James\Desktop\Documents - Shortcut.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | M] () – C:\Users\Public\Desktop\Vuze.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | M] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2012/03/30 10:21:56 | 000,001,000 | —- | M] () – C:\Users\James\Desktop\Adobe Photoshop CS5.lnk
[2012/03/29 16:34:25 | 000,001,892 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/03/29 11:47:53 | 000,000,876 | —- | M] () – C:\Users\James\Desktop\SpywareBlaster.lnk
[2012/03/29 11:44:05 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/03/29 11:19:22 | 000,000,000 | —- | M] () – C:\Users\James\AppData\Roaming\wklnhst.dat
[2012/03/27 19:03:05 | 000,000,680 | —- | M] () – C:\Users\James\AppData\Local\d3d9caps.dat
[2012/03/27 18:55:46 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/03/27 18:55:24 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/03/27 18:54:06 | 000,000,943 | —- | M] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/03/27 18:47:43 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2012/03/27 18:12:59 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2012/03/27 18:12:59 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2012/03/27 18:12:47 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012/03/27 18:12:47 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012/03/27 18:12:47 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/03/27 18:12:47 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012/03/27 18:12:47 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/03/27 18:12:47 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/03/27 18:12:47 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012/03/27 18:12:47 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/03/27 18:12:47 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012/03/27 18:12:47 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012/03/27 18:12:47 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012/03/27 18:12:47 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012/03/27 18:12:47 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012/03/27 18:12:47 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012/03/27 18:12:47 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012/03/27 18:12:47 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2012/03/27 18:12:47 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/03/27 18:12:47 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012/03/27 18:12:47 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012/03/27 18:12:46 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/03/27 18:12:46 | 001,798,656 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/03/27 18:12:46 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/03/27 18:12:46 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/03/27 18:12:46 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012/03/27 18:12:46 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012/03/27 18:12:46 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012/03/27 18:12:46 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012/03/27 18:12:46 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/03/27 18:12:46 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/03/27 18:12:46 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012/03/27 18:12:46 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012/03/27 18:12:46 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012/03/27 18:12:46 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/03/27 18:12:46 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012/03/27 18:12:46 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/03/27 18:12:46 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/03/27 18:12:45 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012/03/27 18:12:45 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012/03/27 18:11:52 | 002,873,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2012/03/27 18:11:52 | 000,979,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2012/03/27 18:11:52 | 000,357,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2012/03/27 18:11:52 | 000,302,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2012/03/27 18:11:52 | 000,261,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2012/03/27 18:11:52 | 000,209,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2012/03/27 18:11:52 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2012/03/27 18:11:49 | 001,029,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2012/03/27 18:11:49 | 000,667,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2012/03/27 18:11:49 | 000,486,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2012/03/27 18:11:49 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2012/03/27 18:11:49 | 000,189,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2012/03/27 18:11:49 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2012/03/27 18:11:49 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2012/03/27 18:11:49 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2012/03/27 18:11:48 | 001,554,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2012/03/27 18:11:48 | 000,847,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2012/03/27 18:11:11 | 000,369,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2012/03/27 18:11:11 | 000,252,928 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2012/03/27 18:11:11 | 000,195,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2012/03/27 18:11:11 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\dxgkrnl.sys.mui
[2012/03/27 18:11:10 | 000,519,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2012/03/27 18:11:10 | 000,321,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2012/03/27 18:11:10 | 000,189,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2012/03/27 17:02:21 | 000,077,072 | —- | M] () – C:\Users\James\Documents\Student certificate 2011-2012.JPG
[2012/03/27 16:26:30 | 000,001,748 | —- | M] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/27 16:26:30 | 000,001,724 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/03/27 16:24:40 | 000,001,728 | —- | M] () – C:\Users\James\Desktop\PeerBlock.lnk
[2012/03/27 16:21:41 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/27 14:30:32 | 000,001,829 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/03/27 14:30:26 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/03/27 14:28:13 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2012/03/27 07:41:08 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2012/03/26 22:57:30 | 000,048,744 | —- | M] () – C:\Windows\System32\license.rtf
[2012/03/26 13:41:12 | 002,068,016 | —- | M] (Kaspersky Lab ZAO) – C:\Users\James\Desktop\TDSSKiller.exe
[2012/03/07 00:15:19 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/03/07 00:15:14 | 000,201,352 | —- | M] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2012/03/07 00:03:51 | 000,612,184 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2012/03/07 00:03:38 | 000,337,880 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2012/03/07 00:02:00 | 000,035,672 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2012/03/07 00:01:53 | 000,053,848 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2012/03/07 00:01:48 | 000,057,688 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2012/03/07 00:01:30 | 000,020,696 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys

========== Files Created - No Company Name ==========

[2012/04/01 16:57:30 | 000,000,932 | —- | C] () – C:\Users\James\Desktop\FL Studio 9.lnk
[2012/03/30 16:51:39 | 000,316,676 | —- | C] () – C:\Users\James\Documents\DELF_B1_exemple2.pdf
[2012/03/30 11:21:12 | 000,003,584 | —- | C] () – C:\Users\James\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/30 11:15:58 | 000,000,361 | —- | C] () – C:\Users\James\Desktop\Music - Shortcut.lnk
[2012/03/30 11:15:54 | 000,000,370 | —- | C] () – C:\Users\James\Desktop\Pictures - Shortcut.lnk
[2012/03/30 11:15:51 | 000,000,373 | —- | C] () – C:\Users\James\Desktop\Documents - Shortcut.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | C] () – C:\Users\Public\Desktop\Vuze.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2012/03/30 10:57:06 | 000,001,633 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk
[2012/03/30 10:21:56 | 000,001,000 | —- | C] () – C:\Users\James\Desktop\Adobe Photoshop CS5.lnk
[2012/03/30 10:03:39 | 000,001,000 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.lnk
[2012/03/30 10:01:21 | 000,000,962 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
[2012/03/30 10:00:17 | 000,001,055 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
[2012/03/30 09:56:43 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2012/03/30 09:56:13 | 000,001,308 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2012/03/30 09:53:20 | 000,000,874 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012/03/29 16:34:25 | 000,001,892 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/03/29 16:34:25 | 000,001,804 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/03/29 11:47:53 | 000,000,876 | —- | C] () – C:\Users\James\Desktop\SpywareBlaster.lnk
[2012/03/29 11:19:22 | 000,000,000 | —- | C] () – C:\Users\James\AppData\Roaming\wklnhst.dat
[2012/03/27 18:55:46 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/03/27 18:55:24 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/03/27 18:54:47 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2012/03/27 18:47:43 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2012/03/27 18:12:47 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2012/03/27 17:58:32 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2012/03/27 17:58:32 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2012/03/27 17:58:32 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2012/03/27 17:02:17 | 000,077,072 | —- | C] () – C:\Users\James\Documents\Student certificate 2011-2012.JPG
[2012/03/27 16:26:30 | 000,001,748 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/27 16:26:30 | 000,001,724 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/03/27 16:24:40 | 000,001,728 | —- | C] () – C:\Users\James\Desktop\PeerBlock.lnk
[2012/03/27 16:21:41 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/27 15:32:36 | 000,000,943 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/03/27 14:34:06 | 000,042,152 | —- | C] () – C:\Windows\System32\drivers\oahlp32.sys
[2012/03/27 14:34:05 | 000,205,864 | —- | C] () – C:\Windows\System32\drivers\OADriver.sys
[2012/03/27 14:30:32 | 000,001,829 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/03/27 14:28:13 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2012/03/26 23:05:48 | 000,000,949 | —- | C] () – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/03/26 23:05:45 | 000,000,944 | —- | C] () – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012/03/26 23:05:33 | 000,000,915 | —- | C] () – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2012/03/26 23:05:29 | 000,000,680 | —- | C] () – C:\Users\James\AppData\Local\d3d9caps.dat
[2012/03/26 23:05:27 | 000,000,258 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/03/26 23:05:27 | 000,000,240 | —- | C] () – C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/03/26 06:04:33 | 000,008,192 | R-S- | C] () – C:\BOOTSECT.BAK
[2011/09/15 02:11:16 | 001,048,576 | —- | C] () – C:\Windows\System32\syndata.bin
[2011/02/11 19:10:52 | 000,439,308 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2011/02/11 19:10:50 | 000,982,240 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2011/02/11 19:10:50 | 000,092,356 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2011/02/11 18:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2011/02/11 18:38:44 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config

========== LOP Check ==========

[2012/04/01 17:00:50 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\Azureus
[2012/03/27 16:06:08 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\Compaq Drivers Update Utility
[2012/03/29 15:28:19 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\DRPSu
[2012/03/27 14:35:25 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\OnlineArmor
[2012/03/29 11:19:24 | 000,000,000 | —D | M] – C:\Users\James\AppData\Roaming\Template
[2012/04/01 17:01:13 | 000,012,780 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 14:18:38 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2012/03/27 07:41:08 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/29 19:03:18 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/29 19:03:18 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/04/02 16:47:24 | 3462,578,176 | -HS- | M] () – C:\pagefile.sys
[2012/03/29 15:47:21 | 000,000,184 | —- | M] () – C:\setup.log
[2012/04/01 19:57:24 | 000,107,984 | —- | M] () – C:\TDSSKiller.2.7.23.0_01.04.2012_19.53.35_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/04/11 14:19:50 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 10:46:04 | 000,032,768 | —- | M] (SEIKO EPSON CORPORATION) – C:\Windows\system32\spool\prtprocs\w32x86\EP0NPP01.DLL
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/07 00:15:19 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/04/11 15:08:12 | 023,552,000 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2009/04/11 15:07:55 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2009/04/11 15:08:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/27 18:54:06 | 000,000,221 | -HS- | M] () – C:\Users\James\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/04/02 16:53:59 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL.exe
[2012/03/26 13:41:12 | 002,068,016 | —- | M] (Kaspersky Lab ZAO) – C:\Users\James\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-30 10:03:39

========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

—————————————————————————————————————————————————————————-
—————————————————————————————————————————————————————————

Extras.txt:
OTL Extras logfile created on: 02/04/2012 16:56:01 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\James\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.93 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 82.68% Memory free
6.06 Gb Paging File | 5.72 Gb Available in Paging File | 94.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.33 Gb Total Space | 153.56 Gb Free Space | 69.07% Space Free | Partition Type: NTFS
Drive D: | 10.55 Gb Total Space | 1.80 Gb Free Space | 17.04% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17FE3022-4F64-4032-BF2F-4CDBEA46F2E1}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0553FB9E-CD70-4E56-93D3-FDC3CD29B8A9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{312D53E3-A52A-4504-8C57-AF1908D8916D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{6B6C43E8-8B86-4232-BF26-3BDD47A85488}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{9FD83753-CDFF-4BB5-A2D7-C2302C292A0F}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{CF942C9B-4FED-4BAF-8DB7-47745C0DA1A7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D131B648-F11F-482C-89DB-23303B1A3545}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{65482307-FE7D-4E7F-9DEF-3F0E841BC77A}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{99A4344A-C723-4661-A507-D9D939480358}" = Cisco LEAP Module
"{9BFD5911-93E3-42BB-BFCD-50E4BA5B8D67}" = Cisco EAP-FAST Module
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{CD344FA5-6657-47CD-940F-8727EED35595}" = Cisco PEAP Module
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"1AFD0AA05210019264F445722471C9A12AA0D269" = Windows Driver Package - Atheros (AR5416) Net (02/05/2010 7.7.0.481)
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ASIO4ALL" = ASIO4ALL
"avast" = avast! Free Antivirus
"C8C34B8E5505C6C11483B29BE7F2D8EF8D2DC9D1" = Windows Driver Package - Atheros (AR5416) Net (02/05/2010 7.7.0.481)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Drumaxx" = Drumaxx
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FL Studio 9" = FL Studio 9
"Hardcore" = Hardcore
"IL Download Manager" = IL Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.28)" = Mozilla Firefox (3.6.28)
"OnlineArmor_is1" = Online Armor 5.5
"PoiZone" = PoiZone
"Sakura" = Sakura
"Sawer" = Sawer
"SpywareBlaster_is1" = SpywareBlaster 4.6
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Toxic Biohazard" = Toxic Biohazard
"WinRAR" = WinRAR

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 30/03/2012 11:52:25 | Computer Name = James-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382,
faulting module AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382, exception
code 0xc0000005, fault offset 0x0005e985, process id 0x17c4, application start time
0x01cd0e8d07f82930.

Error - 30/03/2012 11:54:06 | Computer Name = James-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382,
faulting module AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382, exception
code 0xc0000005, fault offset 0x0005e985, process id 0xaa4, application start time
0x01cd0e8d208b8320.

Error - 30/03/2012 11:55:30 | Computer Name = James-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382,
faulting module AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382, exception
code 0xc0000005, fault offset 0x0005e985, process id 0x1358, application start time
0x01cd0e8d5d1df390.

Error - 30/03/2012 12:01:56 | Computer Name = James-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382,
faulting module AcroRd32.exe, version 10.1.2.45, time stamp 0x4f02e382, exception
code 0xc0000005, fault offset 0x0005e985, process id 0xa5c, application start time
0x01cd0e8e6bd34060.

Error - 31/03/2012 14:33:21 | Computer Name = James-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 31/03/2012 15:28:44 | Computer Name = James-PC | Source = Application Hang | ID = 1002
Description = The program rundll32.exe version 6.0.6000.16386 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 14dc Start Time: 01cd0f72747d3740 Termination Time: 15

Error - 01/04/2012 12:03:53 | Computer Name = James-PC | Source = EventSystem | ID = 4609
Description =

Error - 01/04/2012 12:51:01 | Computer Name = James-PC | Source = EventSystem | ID = 4609
Description =

Error - 01/04/2012 14:50:10 | Computer Name = James-PC | Source = EventSystem | ID = 4609
Description =

Error - 02/04/2012 11:48:20 | Computer Name = James-PC | Source = EventSystem | ID = 4609
Description =

[ System Events ]
Error - 01/04/2012 14:50:13 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 01/04/2012 14:50:21 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 01/04/2012 14:50:21 | Computer Name = James-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 01/04/2012 15:03:47 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 02/04/2012 11:48:11 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 02/04/2012 11:48:13 | Computer Name = James-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description =

Error - 02/04/2012 11:48:20 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 02/04/2012 11:48:24 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 02/04/2012 11:48:32 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 02/04/2012 11:48:32 | Computer Name = James-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Your post has been Moved, Closed or Edited for one of the following reasons: 1.) You posted multiple topics and only one is required 2.) You are spamming links to other places without approval 3.) Abusive language or other problems in your text 4.) Your topic is too old (20 days or more) and no replies from you after a volunteer tried to help you This is a family oriented forum to help those that need help. ==============================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI