This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New Laptop [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Most of the time, it it seems to run slow. Occasionally locks up. sometimes it seems to run very slow. Just got it from a friend just a few days. At first installed an outrageous number of updates. Now that everything seems up to date, I don't think it's much better.

OS: Vista

Also I tried to run windows defrag, I never started.

OTL logfile created on: 2/8/2013 5:56:51 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\cockrell\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.75 Gb Total Physical Memory | 0.37 Gb Available Physical Memory | 20.97% Memory free
3.74 Gb Paging File | 2.23 Gb Available in Paging File | 59.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.01 Gb Total Space | 174.94 Gb Free Space | 78.80% Space Free | Partition Type: NTFS
Drive D: | 10.88 Gb Total Space | 1.78 Gb Free Space | 16.33% Space Free | Partition Type: NTFS
Drive E: | 76.08 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: COCKRELL-PC | User Name: cockrell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\cockrell\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Wajam\Updater\WajamUpdater.exe (Wajam)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Users\cockrell\AppData\Local\Strongvault\StrongVaultApp.exe ()
PRC - C:\Program Files\Strongvault Online Backup\ClientMessenger.exe (Stronghold LLC)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f042f66c2ad8fd5b8c34fa22cd22079e\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\9b2eef59d0cfc5aff182d0951de5f040\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\004bc6615f9c06df5c98859d35149fe6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\12915bd8afbaac3b0308f7ab6a3e57e1\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0c3da9004b277959e24a9fd606d3dd05\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\0f5a23bb73681b6388daccd8e250ba66\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\2cbdbc8bb7fcf0d7eb7a8d616e141d79\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\libglesv2.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\libegl.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\ffmpegsumo.dll ()
MOD - C:\Users\cockrell\AppData\Local\Strongvault\StrongVaultApp.exe ()
MOD - C:\Program Files\Strongvault Online Backup\BusinessLogic.StrongholdManagement.dll ()
MOD - C:\Program Files\Strongvault Online Backup\Infrastructure.Metadata.dll ()
MOD - C:\Program Files\Strongvault Online Backup\Infrastructure.Helpers.dll ()
MOD - C:\Program Files\Strongvault Online Backup\Environment.Identification.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WajamUpdater) – C:\Program Files\Wajam\Updater\WajamUpdater.exe (Wajam)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe (Symantec Corporation)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SYMREDRV) – C:\Windows\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS File not found
DRV - (SYMDNS) – C:\Windows\system32\drivers\NIS\1000000.07D\SYMDNS.SYS File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (ccHP) – C:\Windows\System32\drivers\NIS\1008030.006\cchpx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20130207.002\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130208.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130208.003\NAVENG.SYS (Symantec Corporation)
DRV - (Motousbnet) – C:\Windows\System32\drivers\Motousbnet.sys (Motorola Mobility Inc)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola Mobility Inc)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola Mobility Inc)
DRV - (motusbdevice) – C:\Windows\System32\drivers\motusbdevice.sys (Motorola Inc)
DRV - (SYMTDI) – C:\Windows\System32\drivers\NIS\1008030.006\symtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\drivers\NIS\1008030.006\symfw.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\drivers\NIS\1008030.006\symndisv.sys (Symantec Corporation)
DRV - (NVNET) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1008030.006\SymEFA.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1008030.006\srtsp.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Windows\System32\drivers\NIS\1008030.006\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1008030.006\srtspx.sys (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (motandroidusb) – C:\Windows\System32\drivers\motoandroid.sys (Motorola)
DRV - (BTCFilterService) – C:\Windows\System32\drivers\motfilt.sys (Motorola Inc)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (NETw3v32) – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (MotoSwitchService) – C:\Windows\System32\drivers\motswch.sys (Motorola)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\..\URLSearchHook: {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - C:\Program Files\MixiDJ\prxtbMixi.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE - HKLM\..\SearchScopes\{60A4E56C-445B-47E9-8637-F329433B1DB3}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPNTDF
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…148415424629118

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=1732&gct=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - C:\Program Files\MixiDJ\prxtbMixi.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKCU\..\SearchScopes\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…31-9D8B5C8BDE57
IE - HKCU\..\SearchScopes\{60A4E56C-445B-47E9-8637-F329433B1DB3}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…148415424629118
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2013/01/13 04:29:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Mozilla FireFox\extensions\[removed] [2013/02/04 21:26:17 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi [2013/02/07 19:05:24 | 000,037,909 | —- | M] ()

[2013/02/04 21:26:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla FireFox\extensions
[2013/02/04 21:26:17 | 000,000,000 | —D | M] (InfoAtoms) – C:\Program Files\Mozilla FireFox\extensions\[removed]

========== Chrome ==========

CHR - homepage: http://search.conduit.com/?CUI=UN132945277…SearchSource=48
CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…;ctid=CT3272718
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.conduit.com/?CUI=UN132945277…SearchSource=48
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Wajam (Enabled) = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Docs = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: InfoAtoms = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhbgpoakplhahbklhkcfbpicgjcaoglk\1.5.0.0_0\
CHR - Extension: Coupon Companion Plugin = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\jneaojaoiajhnemidnjhoempalnidbhj\1.21.11_0\crossrider
CHR - Extension: Coupon Companion Plugin = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\jneaojaoiajhnemidnjhoempalnidbhj\1.21.11_0\
CHR - Extension: Wajam = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: MixiDJ = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbofibgamhkgoonaocfgemncghhadmgb\10.14.40.128_0\
CHR - Extension: Gmail = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (InfoAtoms) - {103089DA-0F31-4A8B-843F-7D24A7FE8345} - C:\Program Files\InfoAtoms\IE32\InfoAtomsClientIE.dll (InfoAtoms Inc.)
O2 - BHO: (Coupon Companion Plugin) - {11111111-1111-1111-1111-110211181104} - C:\Program Files\Coupon Companion Plugin\Coupon Companion Plugin.dll (215 Apps)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (MixiDJ Toolbar) - {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - C:\Program Files\MixiDJ\prxtbMixi.dll (Conduit Ltd.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (MixiDJ Toolbar) - {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - C:\Program Files\MixiDJ\prxtbMixi.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (MixiDJ Toolbar) - {C0C2693D-2EE8-47B4-9DF7-B67A0EE31988} - C:\Program Files\MixiDJ\prxtbMixi.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SMessaging] C:\Users\cockrell\AppData\Local\Strongvault Online Backup\SMessaging.exe (Stronghold Online Backup)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN File not found
O4 - HKCU..\Run: [Messenger] C:\Program Files\Strongvault Online Backup\ClientMessenger.exe (Stronghold LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{89015AC8-32D1-421A-96CE-7C4B155793AF}: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/04/03 09:05:10 | 000,000,052 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7f8662fd-5c29-11e2-96e8-001f166ee388}\Shell - "" = AutoRun
O33 - MountPoints2\{7f8662fd-5c29-11e2-96e8-001f166ee388}\Shell\AutoRun\command - "" = F:\setup.exe -a
O33 - MountPoints2\{82d180e4-5994-11e2-96df-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{82d180e4-5994-11e2-96df-806e6f6e6963}\Shell\AutoRun\command - "" = E:\install.exe – [2007/04/24 11:59:07 | 001,074,768 | R— | M] (SupportSoft, Inc.)
O33 - MountPoints2\{ba158ed1-6993-11e2-ab6d-001f166ee388}\Shell - "" = AutoRun
O33 - MountPoints2\{ba158ed1-6993-11e2-ab6d-001f166ee388}\Shell\AutoRun\command - "" = F:\setup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/02/08 17:45:01 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\cockrell\Desktop\HiJackThis.exe
[2013/02/08 17:44:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\MSSoap
[2013/02/08 17:44:12 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Strongvault Online Backup
[2013/02/08 17:43:43 | 000,000,000 | -HSD | C] – C:\Windows\System32\AI_RecycleBin
[2013/02/08 17:43:33 | 000,000,000 | —D | C] – C:\ProgramData\Strongvault Online Backup
[2013/02/08 17:43:32 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Strongvault
[2013/02/08 17:43:27 | 000,000,000 | —D | C] – C:\Program Files\Strongvault Online Backup
[2013/02/08 17:43:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strongvault Online Backup
[2013/02/08 17:43:00 | 000,000,000 | -HSD | C] – C:\AI_RecycleBin
[2013/02/08 17:41:25 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2013/02/08 17:41:10 | 000,000,000 | —D | C] – C:\Program Files\Wajam
[2013/02/08 17:32:02 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\cockrell\Desktop\OTL.exe
[2013/02/08 17:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/02/08 17:25:59 | 000,477,616 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 17:25:59 | 000,473,520 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 17:25:59 | 000,158,128 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2013/02/08 17:25:58 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2013/02/08 17:25:57 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2013/02/08 16:59:18 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\cockrell\Desktop\ATF-Cleaner.exe
[2013/02/08 16:50:48 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/02/07 19:22:20 | 000,758,784 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\cohelper.dll
[2013/02/07 19:22:18 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2013/02/07 18:47:14 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/02/07 18:47:11 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/02/07 18:47:11 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/02/07 18:47:10 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/02/07 18:47:10 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/02/07 18:47:10 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/02/07 18:16:29 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2013/02/06 20:46:08 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/02/06 20:46:06 | 003,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2013/02/06 20:46:06 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2013/02/06 20:43:31 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BthMtpContextHandler.dll
[2013/02/06 20:43:31 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShextAutoplay.exe
[2013/02/06 20:43:26 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceConnectApi.dll
[2013/02/06 20:43:22 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdMtpUS.dll
[2013/02/06 20:43:22 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdConns.dll
[2013/02/06 20:43:21 | 000,546,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2013/02/06 20:43:21 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdMtp.dll
[2013/02/06 20:43:20 | 000,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2013/02/06 20:43:20 | 000,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2013/02/06 20:43:20 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWMDRM.dll
[2013/02/06 20:43:20 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2013/02/06 20:43:20 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2013/02/06 20:18:45 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/02/06 20:18:44 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/02/06 20:18:44 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/02/06 20:18:44 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/02/06 20:18:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/02/06 20:18:43 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/02/06 20:18:43 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/02/06 20:18:43 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/02/06 20:18:42 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/02/06 20:18:42 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/02/06 20:18:42 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/02/06 20:18:41 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/02/06 20:18:41 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/02/06 20:18:41 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/02/06 20:18:41 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/02/06 20:18:41 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/02/06 20:18:41 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/02/06 20:18:41 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/02/06 20:18:41 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/02/06 20:18:41 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/02/06 20:18:41 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/02/06 20:18:41 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/02/06 20:18:41 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/02/06 20:18:41 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/02/06 20:18:40 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/02/06 20:18:40 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2013/02/06 20:18:40 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2013/02/06 20:18:40 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/02/06 20:18:40 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2013/02/06 20:18:40 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/02/06 20:18:39 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/02/06 20:18:39 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2013/02/06 20:18:39 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/02/06 20:18:39 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/02/06 20:18:39 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/02/06 20:18:39 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/02/06 20:18:39 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/02/06 20:16:17 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2013/02/06 20:16:17 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2013/02/06 20:16:16 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2013/02/06 20:16:13 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2013/02/06 20:16:13 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2013/02/06 20:16:13 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2013/02/06 20:16:13 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2013/02/06 20:16:11 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2013/02/06 20:16:10 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/02/06 20:16:10 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/02/06 20:16:10 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/02/06 20:16:10 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/02/06 20:16:09 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2013/02/06 20:16:09 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2013/02/06 20:16:09 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2013/02/06 20:16:09 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2013/02/06 20:16:09 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2013/02/06 20:14:51 | 000,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/02/06 20:14:51 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/02/06 20:14:51 | 000,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2013/02/06 20:14:51 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2013/02/06 20:14:51 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2013/02/06 20:14:51 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/02/06 19:50:02 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2013/02/06 19:49:54 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2013/02/06 19:49:54 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winusb.dll
[2013/02/06 19:49:51 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2013/02/06 19:49:47 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2013/02/06 19:49:46 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2013/02/06 19:37:57 | 000,293,376 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2013/02/06 19:37:57 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2013/02/06 18:20:14 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2013/02/06 18:20:13 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2013/02/06 18:20:13 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2013/02/06 18:20:13 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2013/02/06 18:20:00 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciseq.dll
[2013/02/06 18:17:38 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\synceng.dll
[2013/02/06 18:17:30 | 002,048,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/02/06 18:17:27 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2013/02/06 18:16:44 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2013/02/06 18:16:44 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnsvr.exe
[2013/02/06 18:15:55 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/02/06 18:15:41 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2013/02/06 18:13:08 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2013/02/06 18:12:46 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/02/06 18:11:07 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/02/06 18:10:43 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/02/06 18:10:40 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2013/02/06 18:10:39 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2013/02/06 18:10:06 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2013/02/06 18:10:06 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2013/02/06 18:06:28 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2013/02/06 18:06:20 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/02/06 18:06:20 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/02/06 17:31:30 | 000,613,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2013/02/05 20:51:43 | 002,422,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2013/02/05 20:51:43 | 000,045,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2013/02/05 20:50:56 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2013/02/05 20:50:56 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2013/02/05 20:50:56 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2013/02/05 20:50:26 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2013/02/05 20:50:26 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2013/02/04 21:28:32 | 000,735,232 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\drivers\athr.sys
[2013/02/04 21:28:32 | 000,735,232 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\athr.sys
[2013/02/04 21:28:32 | 000,000,000 | —D | C] – C:\Windows\Options
[2013/02/04 21:27:51 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2013/02/04 21:27:39 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Conduit
[2013/02/04 21:27:34 | 000,000,000 | —D | C] – C:\Program Files\MixiDJ
[2013/02/04 21:27:26 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\CRE
[2013/02/04 21:27:03 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Coupon Companion Plugin
[2013/02/04 21:26:19 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Updater21804
[2013/02/04 21:26:17 | 000,000,000 | —D | C] – C:\Program Files\Mozilla FireFox
[2013/02/04 21:25:49 | 000,000,000 | —D | C] – C:\Program Files\Coupon Companion Plugin
[2013/02/04 21:25:35 | 000,000,000 | —D | C] – C:\Program Files\InfoAtoms
[2013/02/04 20:55:01 | 000,000,000 | —D | C] – C:\ProgramData\PCPitstop
[2013/02/04 20:55:00 | 000,000,000 | —D | C] – C:\Program Files\PCPitstop
[2013/02/04 18:31:05 | 000,000,000 | —D | C] – C:\Windows\System32\eu-ES
[2013/02/04 18:31:05 | 000,000,000 | —D | C] – C:\Windows\System32\ca-ES
[2013/02/04 18:31:04 | 000,000,000 | —D | C] – C:\Windows\System32\vi-VN
[2013/02/03 18:24:56 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Malwarebytes
[2013/02/03 18:24:38 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/02/03 18:24:35 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/02/03 18:24:34 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/28 17:05:55 | 000,000,000 | —D | C] – C:\Temp
[2013/01/28 17:05:55 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Motorola
[2013/01/28 16:52:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Motorola Shared
[2013/01/28 16:51:59 | 000,000,000 | —D | C] – C:\Program Files\Motorola
[2013/01/27 22:58:29 | 000,000,000 | —D | C] – C:\Program Files\support.com
[2013/01/27 22:58:25 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\SupportSoft
[2013/01/27 22:57:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SupportSoft
[2013/01/23 20:45:42 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\spotmau
[2013/01/23 20:44:07 | 000,000,000 | —D | C] – C:\ProgramData\TuneUp360
[2013/01/23 20:18:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/01/23 20:15:47 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/01/23 20:15:37 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Google
[2013/01/23 20:14:36 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Deployment
[2013/01/23 20:14:36 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Apps
[2013/01/23 16:26:57 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2013/01/23 16:25:16 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Wajam
[2013/01/23 16:24:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2013/01/23 16:24:17 | 001,242,112 | —- | C] (Microsoft Corporation) – C:\Users\cockrell\Desktop\wlsetup-web.exe
[2013/01/23 16:03:53 | 000,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2013/01/13 05:08:19 | 012,240,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0007.dll
[2013/01/13 05:08:15 | 001,081,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCExt.dll
[2013/01/13 05:08:12 | 000,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingWizard.exe
[2013/01/13 05:08:11 | 002,134,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FunctionDiscoveryFolder.dll
[2013/01/13 05:08:08 | 002,644,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0009.dll
[2013/01/13 05:08:05 | 001,480,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2013/01/13 05:08:02 | 000,684,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\spsys.sys
[2013/01/13 05:08:01 | 001,576,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2013/01/13 05:08:00 | 000,779,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2013/01/13 05:07:59 | 000,928,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scavenge.dll
[2013/01/13 05:07:57 | 000,677,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2fs.dll
[2013/01/13 05:07:56 | 000,291,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WscEapPr.dll
[2013/01/13 05:07:55 | 000,968,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz2.dll
[2013/01/13 05:07:53 | 000,619,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2013/01/13 05:07:52 | 001,216,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2013/01/13 05:07:50 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spinstall.exe
[2013/01/13 05:07:50 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spreview.exe
[2013/01/13 05:07:49 | 000,978,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmv2clt.dll
[2013/01/13 05:07:48 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizui.dll
[2013/01/13 05:07:47 | 000,438,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcupdate_GenuineIntel.dll
[2013/01/13 05:07:45 | 000,670,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2013/01/13 05:07:43 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2VDEC.DLL
[2013/01/13 05:07:43 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2.dll
[2013/01/13 05:07:43 | 000,351,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2013/01/13 05:07:43 | 000,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2013/01/13 05:07:42 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2013/01/13 05:07:41 | 000,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10K.DLL
[2013/01/13 05:07:40 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairing.dll
[2013/01/13 05:07:39 | 000,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sperror.dll
[2013/01/13 05:07:39 | 000,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\korwbrkr.dll
[2013/01/13 05:07:38 | 000,463,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IasMigReader.exe
[2013/01/13 05:07:36 | 001,589,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjet40.dll
[2013/01/13 05:07:33 | 000,883,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10.IME
[2013/01/13 05:07:33 | 000,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexch40.dll
[2013/01/13 05:07:32 | 001,078,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diagperf.dll
[2013/01/13 05:07:32 | 000,327,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\P2PGraph.dll
[2013/01/13 05:07:31 | 000,986,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2013/01/13 05:07:31 | 000,950,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mblctr.exe
[2013/01/13 05:07:31 | 000,301,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srchadmin.dll
[2013/01/13 05:07:30 | 001,792,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmc.exe
[2013/01/13 05:07:30 | 000,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uDWM.dll
[2013/01/13 05:07:29 | 000,454,144 | —- | C] (Microsoft) – C:\Windows\System32\IasMigPlugin.dll
[2013/01/13 05:07:29 | 000,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBth.dll
[2013/01/13 05:07:28 | 000,880,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RacEngn.dll
[2013/01/13 05:07:26 | 002,012,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\milcore.dll
[2013/01/13 05:07:26 | 001,112,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2013/01/13 05:07:26 | 000,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorAPI.dll
[2013/01/13 05:07:25 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2013/01/13 05:07:24 | 000,950,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpedit.dll
[2013/01/13 05:07:24 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjtes40.dll
[2013/01/13 05:07:24 | 000,115,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayDriverLib.dll
[2013/01/13 05:07:24 | 000,099,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2013/01/13 05:07:23 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSAT.exe
[2013/01/13 05:07:22 | 000,710,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Magnify.exe
[2013/01/13 05:07:22 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationSettings.exe
[2013/01/13 05:07:22 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayServices.dll
[2013/01/13 05:07:21 | 000,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstext40.dll
[2013/01/13 05:07:18 | 000,454,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxbde40.dll
[2013/01/13 05:07:18 | 000,339,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexcl40.dll
[2013/01/13 05:07:18 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwmi.dll
[2013/01/13 05:07:17 | 001,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsAnytimeUpgradeCPL.dll
[2013/01/13 05:07:16 | 001,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2013/01/13 05:07:16 | 001,086,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NetProjW.dll
[2013/01/13 05:07:15 | 000,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrepl40.dll
[2013/01/13 05:07:15 | 000,640,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthprops.cpl
[2013/01/13 05:07:14 | 000,469,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.dll
[2013/01/13 05:07:14 | 000,205,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eudcedit.exe
[2013/01/13 05:07:14 | 000,119,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2013/01/13 05:07:14 | 000,102,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2013/01/13 05:07:13 | 002,926,592 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/01/13 05:07:12 | 001,788,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d9.dll
[2013/01/13 05:07:12 | 000,368,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mspbde40.dll
[2013/01/13 05:07:11 | 000,241,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msltus40.dll
[2013/01/13 05:07:11 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorPwdMgr.dll
[2013/01/13 05:07:10 | 001,053,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtctm.dll
[2013/01/13 05:07:10 | 000,344,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd3x40.dll
[2013/01/13 05:07:09 | 000,250,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtapi.dll
[2013/01/13 05:07:09 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlhtml.dll
[2013/01/13 05:07:07 | 000,614,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2013/01/13 05:07:06 | 000,582,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCommDlg.dll
[2013/01/13 05:07:06 | 000,165,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WcnNetsh.dll
[2013/01/13 05:07:05 | 001,730,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apds.dll
[2013/01/13 05:07:05 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\compcln.exe
[2013/01/13 05:07:04 | 000,618,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswstr10.dll
[2013/01/13 05:07:03 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xmlfilter.dll
[2013/01/13 05:07:01 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUI.exe
[2013/01/13 05:07:01 | 000,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapphost.dll
[2013/01/13 05:07:00 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlsrv32.dll
[2013/01/13 05:07:00 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd2x40.dll
[2013/01/13 05:06:59 | 000,926,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2013/01/13 05:06:59 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propdefs.dll
[2013/01/13 05:06:58 | 001,856,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbgeng.dll
[2013/01/13 05:06:58 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtutil.exe
[2013/01/13 05:06:57 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssitlb.dll
[2013/01/13 05:06:56 | 002,167,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcndmgr.dll
[2013/01/13 05:06:54 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\devmgr.dll
[2013/01/13 05:06:54 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvinst.exe
[2013/01/13 05:06:54 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscb.dll
[2013/01/13 05:06:54 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBthProxy.dll
[2013/01/13 05:06:53 | 000,485,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\evr.dll
[2013/01/13 05:06:53 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingProxy.dll
[2013/01/13 05:06:52 | 001,533,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz.dll
[2013/01/13 05:06:52 | 001,382,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVSDECD.DLL
[2013/01/13 05:06:51 | 001,143,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wercon.exe
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quick.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qintlgnt.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\phon.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cintlgnt.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chajei.ime
[2013/01/13 05:06:50 | 000,617,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adtschema.dll
[2013/01/13 05:06:50 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mimefilt.dll
[2013/01/13 05:06:49 | 000,856,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswdat10.dll
[2013/01/13 05:06:49 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2013/01/13 05:06:49 | 000,396,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsmsnap.dll
[2013/01/13 05:06:49 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjter40.dll
[2013/01/13 05:06:48 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\reg.exe
[2013/01/13 05:06:48 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtffilt.dll
[2013/01/13 05:06:46 | 000,799,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/01/13 05:06:46 | 000,035,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2013/01/13 05:06:45 | 000,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2013/01/13 05:06:44 | 000,704,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2013/01/13 05:06:44 | 000,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcrypt.dll
[2013/01/13 05:06:44 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2013/01/13 05:06:43 | 000,060,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2013/01/13 05:06:43 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshooks.dll
[2013/01/13 05:06:42 | 000,332,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msihnd.dll
[2013/01/13 05:06:42 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MMDevAPI.dll
[2013/01/13 05:06:42 | 000,035,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsWpfWrp.exe
[2013/01/13 05:06:41 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msstrc.dll
[2013/01/13 05:06:40 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fundisc.dll
[2013/01/13 05:06:39 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2013/01/13 05:06:39 | 000,080,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2013/01/13 05:06:37 | 001,020,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdc.dll
[2013/01/13 05:06:37 | 000,125,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Classpnp.sys
[2013/01/13 05:06:37 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi.dll
[2013/01/13 05:06:36 | 001,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chsbrkr.dll
[2013/01/13 05:06:36 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassdo.dll
[2013/01/13 05:06:36 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Kswdmcap.ax
[2013/01/13 05:06:35 | 001,823,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnidui.dll
[2013/01/13 05:06:35 | 000,636,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autofmt.exe
[2013/01/13 05:06:35 | 000,009,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2013/01/13 05:06:34 | 000,122,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Storport.sys
[2013/01/13 05:06:34 | 000,109,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ataport.sys
[2013/01/13 05:06:34 | 000,050,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PSHED.DLL
[2013/01/13 05:06:34 | 000,035,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\crashdmp.sys
[2013/01/13 05:06:33 | 000,757,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroles.dll
[2013/01/13 05:06:33 | 000,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnrollUI.dll
[2013/01/13 05:06:32 | 001,107,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pidgenx.dll
[2013/01/13 05:06:32 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmon.ocx
[2013/01/13 05:06:31 | 002,205,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SyncCenter.dll
[2013/01/13 05:06:30 | 001,502,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certmgr.dll
[2013/01/13 05:06:30 | 000,627,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sethc.exe
[2013/01/13 05:06:30 | 000,593,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comuid.dll
[2013/01/13 05:06:30 | 000,017,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kd1394.dll
[2013/01/13 05:06:29 | 000,324,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\untfs.dll
[2013/01/13 05:06:29 | 000,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassam.dll
[2013/01/13 05:06:29 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrobj.dll
[2013/01/13 05:06:28 | 000,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imkr80.ime
[2013/01/13 05:06:28 | 000,099,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/01/13 05:06:28 | 000,043,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pciidex.sys
[2013/01/13 05:06:27 | 000,656,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoconv.exe
[2013/01/13 05:06:27 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasnap.dll
[2013/01/13 05:06:26 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscript.exe
[2013/01/13 05:06:26 | 000,027,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Dumpata.sys
[2013/01/13 05:06:25 | 000,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wow32.dll
[2013/01/13 05:06:25 | 000,130,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basecsp.dll
[2013/01/13 05:06:25 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiodg.exe
[2013/01/13 05:06:25 | 000,017,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdcom.dll
[2013/01/13 05:06:24 | 000,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\osk.exe
[2013/01/13 05:06:23 | 000,019,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdusb.dll
[2013/01/13 05:06:22 | 000,340,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RelMon.dll
[2013/01/13 05:06:22 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spcmsg.dll
[2013/01/13 05:06:20 | 000,860,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFaultSecure.exe
[2013/01/13 05:06:20 | 000,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2013/01/13 05:06:20 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\offfilt.dll
[2013/01/13 05:06:19 | 000,638,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Utilman.exe
[2013/01/13 05:06:18 | 000,230,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskraid.exe
[2013/01/13 05:06:18 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
[2013/01/13 05:06:18 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsepno.dll
[2013/01/13 05:06:17 | 000,852,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2013/01/13 05:06:17 | 000,391,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscms.dll
[2013/01/13 05:06:17 | 000,197,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SndVol.exe
[2013/01/13 05:06:17 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msnetobj.dll
[2013/01/13 05:06:16 | 000,551,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prnntfy.dll
[2013/01/13 05:06:16 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2013/01/13 05:06:16 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysclass.dll
[2013/01/13 05:06:16 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ulib.dll
[2013/01/13 05:06:16 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsmsext.dll
[2013/01/13 05:06:16 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2013/01/13 05:06:15 | 000,444,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsound.dll
[2013/01/13 05:06:14 | 000,223,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscntfy.dll
[2013/01/13 05:06:14 | 000,181,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpsetup.dll
[2013/01/13 05:06:14 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdProxy.dll
[2013/01/13 05:06:13 | 001,342,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\brcpl.dll
[2013/01/13 05:06:13 | 000,759,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsecsnp.dll
[2013/01/13 05:06:13 | 000,399,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlangpui.dll
[2013/01/13 05:06:13 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskpart.exe
[2013/01/13 05:06:12 | 001,575,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVENCOD.DLL
[2013/01/13 05:06:12 | 000,507,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsdyn.dll
[2013/01/13 05:06:12 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpapi.dll
[2013/01/13 05:06:12 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashlpr.dll
[2013/01/13 05:06:12 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logman.exe
[2013/01/13 05:06:11 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2013/01/13 05:06:11 | 000,158,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrad.dll
[2013/01/13 05:06:11 | 000,155,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2013/01/13 05:06:11 | 000,140,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wusa.exe
[2013/01/13 05:06:11 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\findstr.exe
[2013/01/13 05:06:10 | 002,225,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcenter.dll
[2013/01/13 05:06:10 | 001,580,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpccpl.dll
[2013/01/13 05:06:09 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wer.dll
[2013/01/13 05:06:09 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassvcs.dll
[2013/01/13 05:06:08 | 001,152,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themecpl.dll
[2013/01/13 05:06:08 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsnmp32.dll
[2013/01/13 05:06:06 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scansetting.dll
[2013/01/13 05:06:06 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2013/01/13 05:06:06 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssprxy.dll
[2013/01/13 05:06:05 | 000,777,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcc.dll
[2013/01/13 05:06:05 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2013/01/13 05:06:05 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasacct.dll
[2013/01/13 05:06:04 | 003,072,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkmap.dll
[2013/01/13 05:06:04 | 001,248,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PerfCenterCPL.dll
[2013/01/13 05:06:04 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercpl.dll
[2013/01/13 05:06:03 | 001,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2013/01/13 05:06:03 | 001,224,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sud.dll
[2013/01/13 05:06:03 | 000,842,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\systemcpl.dll
[2013/01/13 05:06:03 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.exe
[2013/01/13 05:06:02 | 002,515,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\accessibilitycpl.dll
[2013/01/13 05:06:02 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pcaui.dll
[2013/01/13 05:06:02 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmci.dll
[2013/01/13 05:06:01 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usercpl.dll
[2013/01/13 05:06:01 | 000,516,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoplay.dll
[2013/01/13 05:06:00 | 001,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanpref.dll
[2013/01/13 05:06:00 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpchttp.dll
[2013/01/13 05:06:00 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pintlgnt.ime
[2013/01/13 05:05:59 | 000,532,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcao.dll
[2013/01/13 05:05:59 | 000,408,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msinfo32.exe
[2013/01/13 05:05:59 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scksp.dll
[2013/01/13 05:05:59 | 000,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsutil.dll
[2013/01/13 05:05:58 | 000,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AudioSes.dll
[2013/01/13 05:05:58 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleprn.dll
[2013/01/13 05:05:58 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3msm.dll
[2013/01/13 05:05:58 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\feclient.dll
[2013/01/13 05:05:57 | 000,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2013/01/13 05:05:57 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rekeywiz.exe
[2013/01/13 05:05:57 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iaspolcy.dll
[2013/01/13 05:05:57 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DeviceEject.exe
[2013/01/13 05:05:57 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscisvif.dll
[2013/01/13 05:05:56 | 001,689,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscui.cpl
[2013/01/13 05:05:56 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpui.dll
[2013/01/13 05:05:56 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/01/13 05:05:56 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncryptui.dll
[2013/01/13 05:05:56 | 000,407,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpapimig.exe
[2013/01/13 05:05:55 | 000,642,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasgcw.dll
[2013/01/13 05:05:55 | 000,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FWPUCLNT.DLL
[2013/01/13 05:05:55 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasplap.dll
[2013/01/13 05:05:55 | 000,215,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certreq.exe
[2013/01/13 05:05:55 | 000,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmartcardCredentialProvider.dll
[2013/01/13 05:05:55 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hdwwiz.exe
[2013/01/13 05:05:55 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSTheme.exe
[2013/01/13 05:05:54 | 000,170,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2013/01/13 05:05:54 | 000,167,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\portcls.sys
[2013/01/13 05:05:54 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWSD.dll
[2013/01/13 05:05:54 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPUnattend.exe
[2013/01/13 05:05:54 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmmon32.exe
[2013/01/13 05:05:54 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwinsat.dll
[2013/01/13 05:05:53 | 000,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmdial32.dll
[2013/01/13 05:05:53 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2013/01/13 05:05:53 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\whealogr.dll
[2013/01/13 05:05:53 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD2.sys
[2013/01/13 05:05:53 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD.sys
[2013/01/13 05:05:52 | 000,275,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SnippingTool.exe
[2013/01/13 05:05:52 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conime.exe
[2013/01/13 05:05:51 | 000,657,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVXENCD.DLL
[2013/01/13 05:05:51 | 000,547,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaaut.dll
[2013/01/13 05:05:51 | 000,202,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanui.dll
[2013/01/13 05:05:51 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPutil.exe
[2013/01/13 05:05:50 | 002,153,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oobefldr.dll
[2013/01/13 05:05:50 | 000,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shwebsvc.dll
[2013/01/13 05:05:50 | 000,137,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsprop.dll
[2013/01/13 05:05:50 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dimsroam.dll
[2013/01/13 05:05:49 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\modemui.dll
[2013/01/13 05:05:49 | 000,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsetup.dll
[2013/01/13 05:05:48 | 006,103,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chtbrkr.dll
[2013/01/13 05:05:48 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscandui.dll
[2013/01/13 05:05:48 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmontr.dll
[2013/01/13 05:05:47 | 000,542,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\blackbox.dll
[2013/01/13 05:05:47 | 000,533,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmsdk.dll
[2013/01/13 05:05:47 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2013/01/13 05:05:47 | 000,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlgpclnt.dll
[2013/01/13 05:05:47 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dataclen.dll
[2013/01/13 05:05:46 | 000,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2013/01/13 05:05:46 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDMon.dll
[2013/01/13 05:05:45 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2013/01/13 05:05:45 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cipher.exe
[2013/01/13 05:05:45 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ifmon.dll
[2013/01/13 05:05:44 | 000,414,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2013/01/13 05:05:44 | 000,217,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\InkEd.dll
[2013/01/13 05:05:44 | 000,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpresult.exe
[2013/01/13 05:05:44 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2013/01/13 05:05:44 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2013/01/13 05:05:44 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimtf.dll
[2013/01/13 05:05:43 | 000,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\thawbrkr.dll
[2013/01/13 05:05:43 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\watchdog.sys
[2013/01/13 05:05:42 | 000,356,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2013/01/13 05:05:42 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\softkbd.dll
[2013/01/13 05:05:41 | 000,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmmgrtn.dll
[2013/01/13 05:05:41 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmsynth.dll
[2013/01/13 05:05:41 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfui.dll
[2013/01/13 05:05:40 | 000,200,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\input.dll
[2013/01/13 05:05:40 | 000,166,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\puiapi.dll
[2013/01/13 05:05:40 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2013/01/13 05:05:39 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLLUA.exe
[2013/01/13 05:05:39 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fc.exe
[2013/01/13 05:05:39 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msisip.dll
[2013/01/13 05:05:38 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmusic.dll
[2013/01/13 05:05:38 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2013/01/13 05:05:38 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdSSDP.dll
[2013/01/13 05:05:37 | 000,187,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapp3hst.dll
[2013/01/13 05:05:37 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tintlgnt.ime
[2013/01/13 05:05:37 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\l2nacp.dll
[2013/01/13 05:05:37 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjint40.dll
[2013/01/13 05:05:37 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsCtfMonitor.dll
[2013/01/13 05:05:36 | 000,083,456 | —- | C] (Microsoft) – C:\Windows\System32\SMBHelperClass.dll
[2013/01/13 05:05:36 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftp.exe
[2013/01/13 05:05:36 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsdchngr.dll
[2013/01/13 05:05:35 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWCN.dll
[2013/01/13 05:05:35 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Storprop.dll
[2013/01/13 05:05:35 | 000,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdiag.dll
[2013/01/13 05:05:35 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3cfg.dll
[2013/01/13 05:05:35 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthci.dll
[2013/01/13 05:05:35 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthudtask.exe
[2013/01/13 05:05:35 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdial.exe
[2013/01/13 05:05:34 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcinst.dll
[2013/01/13 05:05:34 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipconfig.exe
[2013/01/13 05:05:34 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CHxReadingStringIME.dll
[2013/01/13 05:05:33 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappgnui.dll
[2013/01/13 05:05:33 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nslookup.exe
[2013/01/13 05:05:33 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hbaapi.dll
[2013/01/13 05:05:33 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkitemfactory.dll
[2013/01/13 05:05:33 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ocsetup.exe
[2013/01/13 05:05:33 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FwRemoteSvr.dll
[2013/01/13 05:05:32 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdeploy.dll
[2013/01/13 05:05:32 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcico.dll
[2013/01/13 05:05:31 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PNPXAssoc.dll
[2013/01/13 05:05:30 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpupdate.exe
[2013/01/13 05:05:29 | 000,046,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrstub.exe
[2013/01/13 05:05:29 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cbsra.exe
[2013/01/13 05:05:29 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsigd.dll
[2013/01/13 05:05:29 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NcdProp.dll
[2013/01/13 05:05:29 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsilog.dll
[2013/01/13 05:05:28 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxg.sys
[2013/01/13 05:05:28 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcconf.dll
[2013/01/13 05:05:28 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdmdbg.dll
[2013/01/13 05:05:27 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2013/01/13 05:05:27 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetppui.dll
[2013/01/13 05:05:27 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2013/01/13 05:05:24 | 000,052,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\stream.sys
[2013/01/13 05:05:24 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2013/01/13 05:05:22 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/01/13 05:05:21 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\f3ahvoas.dll
[2013/01/13 05:05:21 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimsg.dll
[2013/01/13 05:04:56 | 000,705,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmiEngine.dll
[2013/01/13 05:04:48 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdscore.dll
[2013/01/13 05:04:48 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PkgMgr.exe
[2013/01/13 05:04:28 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvstore.dll
[2013/01/13 04:44:28 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/01/13 04:28:53 | 000,025,648 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\SymIMV.sys
[2013/01/13 03:26:39 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2013/01/13 03:26:38 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2013/01/13 03:26:38 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2013/01/12 07:43:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/01/11 15:51:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Wizard
[2013/01/11 15:51:10 | 000,000,000 | —D | C] – C:\Program Files\Driver Wizard
[2013/01/11 15:50:34 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Driver Wizard
[2013/01/11 15:24:52 | 000,232,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/01/11 14:51:46 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2013/01/10 19:00:43 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2013/01/10 18:48:09 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2013/01/10 18:40:27 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/10 18:37:45 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2013/01/10 18:37:28 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2013/01/10 18:37:28 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2013/01/10 18:37:28 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2013/01/10 18:37:25 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2013/01/10 18:37:25 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2013/01/10 18:37:21 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2013/01/10 18:37:21 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2013/01/10 18:37:21 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2013/01/10 18:37:21 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2013/01/10 18:37:20 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2013/01/10 18:37:11 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2013/01/10 18:37:10 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2013/01/10 18:37:10 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2013/01/10 18:37:09 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2013/01/10 18:37:08 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2013/01/10 18:29:02 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2013/01/10 18:29:00 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NETSTAT.EXE
[2013/01/10 18:28:59 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ARP.EXE
[2013/01/10 18:28:59 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\finger.exe
[2013/01/10 18:28:59 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\HOSTNAME.EXE
[2013/01/10 18:28:58 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ROUTE.EXE
[2013/01/10 18:28:58 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MRINFO.EXE
[2013/01/10 18:27:16 | 002,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2013/01/10 18:27:14 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rrinstaller.exe
[2013/01/10 18:27:14 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfpmp.exe
[2013/01/10 18:27:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mferror.dll
[2013/01/10 18:26:51 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2013/01/10 18:26:51 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\L2SecHC.dll
[2013/01/10 18:26:51 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanhlp.dll
[2013/01/10 18:26:50 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansec.dll
[2013/01/10 18:26:50 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanapi.dll
[2013/01/10 18:26:26 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2013/01/10 18:26:26 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2013/01/10 18:26:26 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2013/01/10 18:26:26 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2013/01/10 18:25:37 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2013/01/10 18:25:36 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2013/01/10 18:25:33 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2013/01/10 18:25:30 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2013/01/10 18:25:30 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2013/01/10 18:25:27 | 000,714,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2013/01/10 18:25:08 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2013/01/10 18:24:31 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2013/01/10 18:24:17 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asycfilt.dll
[2013/01/10 18:24:07 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2013/01/10 18:23:41 | 000,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2013/01/10 18:23:39 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2013/01/10 18:23:39 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2013/01/10 18:23:39 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2013/01/10 18:23:11 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2013/01/10 18:23:11 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2013/01/10 18:22:57 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2013/01/10 18:22:56 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2013/01/10 18:22:55 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2013/01/10 18:22:38 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2013/01/10 18:22:17 | 000,062,464 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2013/01/10 18:22:16 | 000,220,672 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codecp.acm
[2013/01/10 18:21:52 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2013/01/10 18:21:51 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2013/01/10 18:21:50 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2013/01/10 18:11:12 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2013/01/10 18:10:20 | 000,697,712 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/01/10 18:10:20 | 000,074,096 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/01/10 18:09:09 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.tlb
[2013/01/10 18:09:09 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amcompat.tlb
[2013/01/10 18:09:01 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2013/01/10 18:09:01 | 000,518,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2013/01/10 18:08:57 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2013/01/10 18:08:57 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2013/01/10 18:08:56 | 000,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2013/01/10 18:08:55 | 000,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2013/01/10 18:08:54 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2013/01/10 18:08:54 | 000,152,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2013/01/10 18:08:54 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2013/01/10 18:07:19 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/01/10 18:07:19 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tscupgrd.exe
[2013/01/10 18:07:19 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/01/10 18:06:42 | 000,355,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2013/01/10 18:06:04 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2013/01/10 18:05:21 | 000,310,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unregmp2.exe
[2013/01/10 18:04:00 | 000,604,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOD.DLL
[2013/01/10 16:51:30 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Macromedia
[2013/01/10 16:51:09 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Adobe
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/08 18:02:07 | 002,194,612 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\Cat.DB
[2013/02/08 17:47:15 | 000,625,664 | —- | M] () – C:\Users\cockrell\Desktop\dds.scr
[2013/02/08 17:45:53 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\cockrell\Desktop\HiJackThis.exe
[2013/02/08 17:43:38 | 000,001,146 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\StrongVaultApp.exe.lnk
[2013/02/08 17:43:36 | 000,000,955 | —- | M] () – C:\Users\Public\Desktop\Shortcut to Strongvault.lnk
[2013/02/08 17:32:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\cockrell\Desktop\OTL.exe
[2013/02/08 17:24:34 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/08 17:24:32 | 000,158,128 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2013/02/08 17:24:32 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2013/02/08 17:24:31 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2013/02/08 17:24:25 | 000,477,616 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 17:24:24 | 000,473,520 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 17:20:34 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/08 17:07:29 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/08 17:07:08 | 000,032,156 | —- | M] () – C:\ProgramData\nvModes.dat
[2013/02/08 17:07:08 | 000,032,156 | —- | M] () – C:\ProgramData\nvModes.001
[2013/02/08 17:07:00 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/08 17:07:00 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/08 17:06:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/08 17:06:45 | 1877,327,872 | -HS- | M] () – C:\hiberfil.sys
[2013/02/08 16:59:18 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\cockrell\Desktop\ATF-Cleaner.exe
[2013/02/07 19:23:15 | 000,697,712 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/02/07 19:23:15 | 000,074,096 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/02/07 19:01:26 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/02/07 19:01:26 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/02/07 18:26:17 | 000,000,943 | —- | M] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/02/07 18:21:14 | 000,314,048 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/02/07 18:15:46 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2013/02/07 18:15:34 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013/02/06 20:19:00 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2013/02/06 20:19:00 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2013/02/06 20:18:45 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/02/06 20:18:44 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/02/06 20:18:44 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/02/06 20:18:44 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/02/06 20:18:43 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/02/06 20:18:43 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/02/06 20:18:43 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/02/06 20:18:43 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/02/06 20:18:42 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/02/06 20:18:42 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/02/06 20:18:42 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/02/06 20:18:41 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/02/06 20:18:41 | 001,427,968 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/02/06 20:18:41 | 000,607,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/02/06 20:18:41 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/02/06 20:18:41 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/02/06 20:18:41 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/02/06 20:18:41 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/02/06 20:18:41 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/02/06 20:18:41 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/02/06 20:18:41 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/02/06 20:18:41 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/02/06 20:18:41 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/02/06 20:18:41 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/02/06 20:18:41 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/02/06 20:18:40 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/02/06 20:18:40 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2013/02/06 20:18:40 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2013/02/06 20:18:40 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/02/06 20:18:40 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2013/02/06 20:18:40 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/02/06 20:18:39 | 001,800,704 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/02/06 20:18:39 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2013/02/06 20:18:39 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/02/06 20:18:39 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/02/06 20:18:39 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/02/06 20:18:39 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/02/06 20:18:39 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/02/06 20:16:17 | 000,979,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2013/02/06 20:16:17 | 000,357,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2013/02/06 20:16:16 | 000,302,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2013/02/06 20:16:13 | 002,873,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2013/02/06 20:16:13 | 000,261,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2013/02/06 20:16:13 | 000,209,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2013/02/06 20:16:13 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2013/02/06 20:16:11 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2013/02/06 20:16:10 | 001,029,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/02/06 20:16:10 | 000,486,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/02/06 20:16:10 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/02/06 20:16:10 | 000,189,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/02/06 20:16:09 | 001,554,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2013/02/06 20:16:09 | 000,847,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2013/02/06 20:16:09 | 000,667,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2013/02/06 20:16:09 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2013/02/06 20:16:09 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2013/02/06 20:14:52 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\dxgkrnl.sys.mui
[2013/02/06 20:14:51 | 000,519,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/02/06 20:14:51 | 000,369,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/02/06 20:14:51 | 000,321,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2013/02/06 20:14:51 | 000,252,928 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2013/02/06 20:14:51 | 000,195,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2013/02/06 20:14:51 | 000,189,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/02/04 21:28:04 | 000,000,009 | —- | M] () – C:\END
[2013/02/04 18:49:28 | 000,000,246 | —- | M] () – C:\ProgramData\hpqp.ini
[2013/02/03 18:24:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/31 21:47:33 | 000,034,253 | —- | M] () – C:\Users\cockrell\Desktop\ken and rhonda phone pics 013113 076.jpg
[2013/01/31 21:27:12 | 000,001,971 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/01/30 20:44:49 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motoandroid_01007.Wdf
[2013/01/28 17:07:09 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motfilt_01007.Wdf
[2013/01/28 17:07:07 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motccgp_01007.Wdf
[2013/01/28 17:05:42 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf
[2013/01/27 22:59:03 | 000,000,865 | —- | M] () – C:\net_save.dna
[2013/01/25 12:51:34 | 000,001,995 | —- | M] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/23 20:45:36 | 000,075,356 | —- | M] () – C:\Users\cockrell\AppData\Roaming\userenv.xml.urlencode
[2013/01/23 20:45:36 | 000,056,742 | —- | M] () – C:\Users\cockrell\AppData\Roaming\userenv.xml
[2013/01/23 20:24:17 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/01/23 16:24:20 | 001,242,112 | —- | M] (Microsoft Corporation) – C:\Users\cockrell\Desktop\wlsetup-web.exe
[2013/01/17 01:28:58 | 000,232,336 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/01/13 04:28:26 | 000,002,204 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2013/01/12 09:10:53 | 000,467,592 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\NIS\1008030.006\cchpx86.sys
[2013/01/12 09:10:43 | 000,000,172 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\isolate.ini
[2013/01/11 17:41:33 | 000,006,144 | —- | M] () – C:\Users\cockrell\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/11 16:16:53 | 000,124,976 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2013/01/11 16:16:53 | 000,007,456 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2013/01/11 16:16:53 | 000,000,806 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2013/01/11 16:14:34 | 000,009,412 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\symnetv.cat
[2013/01/11 16:14:34 | 000,001,562 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\SymNetV.inf
[2013/01/11 15:51:19 | 000,000,859 | —- | M] () – C:\Users\cockrell\Desktop\Driver Wizard.lnk
[2013/01/11 15:35:22 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/08 17:46:58 | 000,625,664 | —- | C] () – C:\Users\cockrell\Desktop\dds.scr
[2013/02/08 17:43:38 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\StrongVaultApp.exe.lnk
[2013/02/08 17:43:36 | 000,000,955 | —- | C] () – C:\Users\Public\Desktop\Shortcut to Strongvault.lnk
[2013/02/07 22:06:05 | 1877,327,872 | -HS- | C] () – C:\hiberfil.sys
[2013/02/07 18:15:46 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2013/02/07 18:15:34 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013/02/06 20:18:41 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/02/06 19:50:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/02/06 19:50:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/02/04 21:28:33 | 000,010,844 | —- | C] () – C:\Windows\System32\athrext.cat
[2013/02/04 21:28:33 | 000,006,483 | —- | C] () – C:\Windows\System32\netathr.inf
[2013/02/04 21:26:12 | 000,000,009 | —- | C] () – C:\END
[2013/02/03 18:24:40 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/31 21:48:54 | 000,034,253 | —- | C] () – C:\Users\cockrell\Desktop\ken and rhonda phone pics 013113 076.jpg
[2013/01/30 20:44:49 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motoandroid_01007.Wdf
[2013/01/28 17:07:09 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motfilt_01007.Wdf
[2013/01/28 17:07:07 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motccgp_01007.Wdf
[2013/01/28 17:05:42 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf
[2013/01/27 22:59:03 | 000,000,865 | —- | C] () – C:\net_save.dna
[2013/01/23 20:45:36 | 000,075,356 | —- | C] () – C:\Users\cockrell\AppData\Roaming\userenv.xml.urlencode
[2013/01/23 20:45:36 | 000,056,742 | —- | C] () – C:\Users\cockrell\AppData\Roaming\userenv.xml
[2013/01/23 20:18:08 | 000,001,995 | —- | C] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/23 20:18:08 | 000,001,971 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/01/23 20:15:56 | 000,000,890 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/23 20:15:55 | 000,000,886 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/13 05:07:29 | 000,130,008 | —- | C] () – C:\Windows\System32\systemsf.ebd
[2013/01/13 05:07:26 | 000,009,239 | —- | C] () – C:\Windows\System32\spcinstrumentation.man
[2013/01/13 05:07:13 | 000,442,788 | —- | C] () – C:\Windows\System32\dot3.tmf
[2013/01/13 05:07:11 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2013/01/13 05:07:11 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2013/01/13 05:07:07 | 000,392,170 | —- | C] () – C:\Windows\System32\onex.tmf
[2013/01/13 05:07:01 | 000,344,698 | —- | C] () – C:\Windows\System32\eaphost.tmf
[2013/01/13 05:06:37 | 000,208,966 | —- | C] () – C:\Windows\System32\WFP.TMF
[2013/01/13 05:06:34 | 000,092,918 | —- | C] () – C:\Windows\System32\slmgr.vbs
[2013/01/13 05:05:27 | 000,009,212 | —- | C] () – C:\Windows\System32\RacUR.xml
[2013/01/11 17:36:57 | 000,006,144 | —- | C] () – C:\Users\cockrell\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/11 15:51:19 | 000,000,859 | —- | C] () – C:\Users\cockrell\Desktop\Driver Wizard.lnk
[2013/01/11 15:35:22 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2013/01/11 14:47:35 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2013/01/10 20:46:50 | 000,032,156 | —- | C] () – C:\ProgramData\nvModes.001
[2013/01/10 20:46:29 | 000,032,156 | —- | C] () – C:\ProgramData\nvModes.dat
[2013/01/10 18:37:13 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2013/01/10 18:37:13 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2013/01/10 18:37:13 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2013/01/10 18:26:52 | 002,501,921 | —- | C] () – C:\Windows\System32\wlan.tmf
[2013/01/10 18:10:29 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/10 16:46:35 | 000,000,943 | —- | C] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/08 07:58:44 | 000,000,246 | —- | C] () – C:\ProgramData\hpqp.ini
[2013/01/08 07:49:27 | 000,011,164 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin

========== ZeroAccess Check ==========

[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 01:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/11 15:51:30 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\Driver Wizard
[2013/01/28 17:05:55 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\Motorola
[2013/01/23 20:45:42 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\spotmau

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 21:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 07:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 07:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2008/10/25 18:07:03 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=07ED775D6DB4BFA96D7CFB09EB228418 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\iexplore.exe
[2008/10/25 18:14:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=157F8DE991396C536820D7FA5C8DCF7D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\iexplore.exe
[2008/10/25 18:03:23 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=182CAF7403705ACCB51211A761080B8F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_2dc0b0c03628049a\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/04/11 01:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2008/10/25 18:14:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4DBD95312B1C96C5285D38F1D748CD4D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\iexplore.exe
[2008/01/20 21:23:50 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2011/04/21 09:34:57 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=6C93AC7C0A8718E2A1543DB1B1B3B19F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22905_none_2ff0ad763317887e\iexplore.exe
[2011/04/21 10:02:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=77B9A891222FB46B13E414B99E1AF842 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18639_none_2f4a9e431a0ea795\iexplore.exe
[2008/10/25 18:03:23 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9437CA21CD48C9B6BFD6F5AC0143D251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_2d5382911cf5aba1\iexplore.exe
[2008/10/25 18:07:03 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9F1427F203CA078005C9943800929640 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\iexplore.exe
[2013/02/06 20:18:44 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=B201AF83DF2E85323E29EB83E4046810 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/02/06 20:18:44 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=B201AF83DF2E85323E29EB83E4046810 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_588f2941ebbcf9c3\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 07:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2013/02/06 20:18:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/02/06 20:18:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.1.8112.16421_en-us_52562cc123574ecd\iexplore.exe.mui

< MD5 for: SERVICES >
[2006/09/18 16:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/18 16:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.EXE >
[2008/01/20 21:24:48 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 01:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 01:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 07:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 07:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.LNK >
[2008/01/20 21:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/01/20 21:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 07:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/18 16:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 07:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 16:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 21:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2008/01/20 21:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 21:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 07:40:50 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui

< MD5 for: WINLOGON.MOF >
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2013/02/04 21:28:04 | 000,000,009 | —- | M] () – C:\END
[2013/02/08 17:06:45 | 1877,327,872 | -HS- | M] () – C:\hiberfil.sys
[2013/01/27 22:59:03 | 000,000,865 | —- | M] () – C:\net_save.dna
[2013/02/08 17:06:44 | 2191,200,256 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2013/02/04 18:11:26 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 21:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/02/07 18:26:17 | 000,000,221 | -HS- | M] () – C:\Users\cockrell\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/02/08 16:59:18 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\cockrell\Desktop\ATF-Cleaner.exe
[2013/02/08 17:45:53 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\cockrell\Desktop\HiJackThis.exe
[2013/02/08 17:32:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\cockrell\Desktop\OTL.exe
[2013/01/23 16:24:20 | 001,242,112 | —- | M] (Microsoft Corporation) – C:\Users\cockrell\Desktop\wlsetup-web.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-02-08 22:20:59

< End of report >


OTL Extras logfile created on: 2/8/2013 5:56:51 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\cockrell\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.75 Gb Total Physical Memory | 0.37 Gb Available Physical Memory | 20.97% Memory free
3.74 Gb Paging File | 2.23 Gb Available in Paging File | 59.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.01 Gb Total Space | 174.94 Gb Free Space | 78.80% Space Free | Partition Type: NTFS
Drive D: | 10.88 Gb Total Space | 1.78 Gb Free Space | 16.33% Space Free | Partition Type: NTFS
Drive E: | 76.08 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: COCKRELL-PC | User Name: cockrell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{116E4D05-1782-4CEC-B486-8C0E36EF5903}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1FF9B5FA-F576-4093-AFC7-0A218C7D27C9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{4902CBA3-3773-4B14-B6C8-7E215919B83C}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{5137CFA9-CFA2-4439-9BD2-C10951AFDFE7}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{87EE5144-E4A9-4EE0-B936-54E6CB921BE3}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216039FF}" = Java™ 6 Update 39
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}" = Juno Preloader
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{692EF506-1E15-4473-A829-ED951D6C49DB}" = Strongvault Online Backup
"{6A370610-3778-44AF-9AAC-69B2FD1A3356}" = Microsoft Live Search Toolbar
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{846DDADA-0239-4B67-A6B1-33658863793B}" = HPTCSSetup
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{97F2E8BE-3018-47D2-BC2D-F0B5E92D1BF3}" = Motorola Mobile Drivers Installation 5.5.0
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3}" = HP User Guides 0118
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ComcastHSI" = Comcast High-Speed Internet Install Wizard
"Coupon Companion Plugin" = Coupon Companion Plugin
"Driver Wizard_is1" = Driver Wizard v3.0
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InfoAtoms" = InfoAtoms [Uninstall]
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MixiDJ Toolbar" = MixiDJ Toolbar
"MotoHelper" = MotoHelper 2.1.41 Driver 5.5.0
"NIS" = Norton Internet Security
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wajam" = Wajam
"WildTangent hp Master Uninstall" = My HP Games

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2/4/2013 7:46:53 PM | Computer Name = cockrell-PC | Source = ESENT | ID = 215
Description = WinMail (3516) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 2/4/2013 10:00:05 PM | Computer Name = cockrell-PC | Source = Perflib | ID = 1010
Description =

Error - 2/4/2013 10:00:07 PM | Computer Name = cockrell-PC | Source = Perflib | ID = 1008
Description =

Error - 2/4/2013 10:00:07 PM | Computer Name = cockrell-PC | Source = Perflib | ID = 1005
Description =

Error - 2/4/2013 10:00:07 PM | Computer Name = cockrell-PC | Source = Perflib | ID = 1017
Description =

Error - 2/4/2013 10:27:19 PM | Computer Name = cockrell-PC | Source = VSS | ID = 8194
Description =

Error - 2/4/2013 10:54:21 PM | Computer Name = cockrell-PC | Source = WinMgmt | ID = 10
Description =

Error - 2/5/2013 9:23:52 PM | Computer Name = cockrell-PC | Source = VSS | ID = 8194
Description =

Error - 2/7/2013 7:21:51 PM | Computer Name = cockrell-PC | Source = WinMgmt | ID = 10
Description =

Error - 2/7/2013 7:54:43 PM | Computer Name = cockrell-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 1/21/2013 1:05:04 PM | Computer Name = cockrell-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/23/2013 10:23:51 AM | Computer Name = cockrell-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 1/23/2013 10:24:21 AM | Computer Name = cockrell-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 1/23/2013 3:42:33 PM | Computer Name = cockrell-PC | Source = DCOM | ID = 10005
Description =

Error - 1/23/2013 3:42:38 PM | Computer Name = cockrell-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 1/23/2013 3:42:38 PM | Computer Name = cockrell-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/23/2013 3:42:41 PM | Computer Name = cockrell-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 1/23/2013 4:08:20 PM | Computer Name = cockrell-PC | Source = Service Control Manager | ID = 7043
Description =

Error - 1/23/2013 4:12:07 PM | Computer Name = cockrell-PC | Source = HTTP | ID = 15016
Description =

Error - 1/23/2013 4:13:39 PM | Computer Name = cockrell-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:32:07 PM, on 2/8/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Users\cockrell\AppData\Local\Strongvault\StrongVaultApp.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\cockrell\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=1732&gct=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: MixiDJ Toolbar - {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - C:\Program Files\MixiDJ\prxtbMixi.dll
O1 - Hosts: ::1 localhost
O2 - BHO: InfoAtoms - {103089DA-0F31-4A8B-843F-7D24A7FE8345} - C:\Program Files\InfoAtoms\IE32\InfoAtomsClientIE.dll
O2 - BHO: CrossriderApp0021804 - {11111111-1111-1111-1111-110211181104} - C:\Program Files\Coupon Companion Plugin\Coupon Companion Plugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Wajam IE BHO - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll
O2 - BHO: MixiDJ - {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - C:\Program Files\MixiDJ\prxtbMixi.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: MixiDJ Toolbar - {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - C:\Program Files\MixiDJ\prxtbMixi.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SMessaging] C:\Users\cockrell\AppData\Local\Strongvault Online Backup\SMessaging.exe
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [Messenger] "C:\Program Files\Strongvault Online Backup\ClientMessenger.exe"
O4 - Global Startup: StrongVaultApp.exe.lnk = C:\Users\cockrell\AppData\Local\Strongvault\StrongVaultApp.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: WajamUpdater - Wajam - C:\Program Files\Wajam\Updater\WajamUpdater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8836 bytes


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 18:32:56.66 on Fri 02/08/2013
Internet Explorer: 9.0.8112.16421
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1790.586 [GMT -5:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Wajam\Updater\WajamUpdater.exe
C:\Program Files\Strongvault Online Backup\ClientMessenger.exe
C:\Users\cockrell\AppData\Local\Strongvault\StrongVaultApp.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\cockrell\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com/?l=dis&o=1732&gct=hp
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: MixiDJ Toolbar: {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - c:\program files\mixidj\prxtbMixi.dll
mURLSearchHooks: MixiDJ Toolbar: {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - c:\program files\mixidj\prxtbMixi.dll
BHO: InfoAtoms: {103089da-0f31-4a8b-843f-7d24a7fe8345} - c:\program files\infoatoms\ie32\InfoAtomsClientIE.dll
BHO: Coupon Companion Plugin: {11111111-1111-1111-1111-110211181104} - c:\program files\coupon companion plugin\Coupon Companion Plugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.8.3.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.8.3.6\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Wajam: {a7a6995d-6ee1-4fd1-a258-49395d5bf99c} - c:\program files\wajam\ie\priam_bho.dll
BHO: MixiDJ Toolbar: {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - c:\program files\mixidj\prxtbMixi.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.8.3.6\coIEPlg.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: MixiDJ Toolbar: {c0c2693d-2ee8-47b4-9df7-b67a0ee31988} - c:\program files\mixidj\prxtbMixi.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [Messenger] "c:\program files\strongvault online backup\ClientMessenger.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: []
mRun: [SMessaging] c:\users\cockrell\appdata\local\strongvault online backup\SMessaging.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\strong~1.lnk - c:\users\cockrell\appdata\local\strongvault\StrongVaultApp.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.8.3.6\CoIEPlg.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\24.0.1312.57\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
.
============= SERVICES / DRIVERS ===============
.
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1008030.006\SymEFA.sys [2013-1-12 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1008030.006\BHDrvx86.sys [2013-1-12 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1008030.006\cchpx86.sys [2013-1-12 467592]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20130207.002\IDSvix86.sys [2013-2-7 386720]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 MotoHelper;MotoHelper Service;c:\program files\motorola\motohelper\MotoHelperService.exe [2012-2-6 214896]
R2 Norton Internet Security;Norton Internet Security;c:\program files\norton internet security\engine\16.8.3.6\ccSvcHst.exe [2013-1-12 117648]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2008-10-25 365952]
R2 WajamUpdater;WajamUpdater;c:\program files\wajam\updater\WajamUpdater.exe [2013-2-7 109064]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2013-1-11 106656]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nis\1008030.006\symndisv.sys [2013-1-12 48760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2013-1-23 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2013-1-10 251248]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2009-1-29 6016]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-10-25 193840]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2013-1-23 116648]
S3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\drivers\motoandroid.sys [2009-7-10 25856]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2012-1-25 20864]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2012-1-25 8448]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2012-1-25 23808]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2011-11-8 11008]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2013-02-08 22:44:16 ——– d—–w- c:\program files\common files\MSSoap
2013-02-08 22:44:12 ——– d—–w- c:\users\cockrell\appdata\local\Strongvault Online Backup
2013-02-08 22:43:43 ——– d-sh–w- c:\windows\system32\AI_RecycleBin
2013-02-08 22:43:33 ——– d—–w- c:\progra~2\Strongvault Online Backup
2013-02-08 22:43:32 ——– d—–w- c:\users\cockrell\appdata\local\Strongvault
2013-02-08 22:43:27 ——– d—–w- c:\program files\Strongvault Online Backup
2013-02-08 22:43:00 ——– d-sh–w- C:\AI_RecycleBin
2013-02-08 22:41:10 ——– d—–w- c:\program files\Wajam
2013-02-08 22:25:59 477616 —-a-w- c:\windows\system32\npdeployJava1.dll
2013-02-08 22:25:59 473520 —-a-w- c:\windows\system32\deployJava1.dll
2013-02-08 22:20:35 6991832 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{8c0cc9c1-a503-416a-bf84-ac2e97e1f7ed}\mpengine.dll
2013-02-08 21:49:39 4126720 —-a-w- c:\program files\GUT9D8C.tmp
2013-02-08 21:49:39 ——– d—–w- c:\program files\GUM9D8B.tmp
2013-02-08 00:22:20 758784 —-a-w- c:\windows\system32\cohelper.dll
2013-02-08 00:22:18 ——– d—–w- c:\program files\NVIDIA Corporation
2013-02-07 23:47:14 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2013-02-07 23:47:11 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2013-02-07 23:47:11 1069056 —-a-w- c:\windows\system32\DWrite.dll
2013-02-07 23:47:10 683008 —-a-w- c:\windows\system32\d2d1.dll
2013-02-07 23:47:10 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2013-02-07 23:47:10 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2013-02-07 23:16:29 ——– d—–w- c:\program files\Windows Portable Devices
2013-02-07 01:46:08 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2013-02-07 01:46:06 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2013-02-07 01:46:06 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2013-02-07 01:31:33 5120 —-a-w- c:\windows\system32\wmi.dll
2013-02-07 01:31:33 157696 —-a-w- c:\windows\system32\imagehlp.dll
2013-02-07 01:31:33 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2013-02-07 01:16:17 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2013-02-07 01:14:51 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2013-02-07 01:14:51 519680 —-a-w- c:\windows\system32\d3d11.dll
2013-02-07 01:14:51 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2013-02-07 01:14:51 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2013-02-07 01:14:51 252928 —-a-w- c:\windows\system32\dxdiag.exe
2013-02-07 01:14:51 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2013-02-07 01:14:51 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-02-07 00:50:02 9728 —-a-w- c:\windows\system32\Wdfres.dll
2013-02-07 00:49:55 66560 —-a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-02-07 00:49:55 155136 —-a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-02-07 00:49:54 73216 —-a-w- c:\windows\system32\WUDFSvc.dll
2013-02-07 00:49:54 172032 —-a-w- c:\windows\system32\WUDFPlatform.dll
2013-02-07 00:49:54 16896 —-a-w- c:\windows\system32\winusb.dll
2013-02-07 00:49:51 526952 —-a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-02-07 00:49:51 47720 —-a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-02-07 00:49:47 38912 —-a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-02-07 00:49:46 613888 —-a-w- c:\windows\system32\WUDFx.dll
2013-02-07 00:49:46 196608 —-a-w- c:\windows\system32\WUDFHost.exe
2013-02-07 00:37:57 34304 —-a-w- c:\windows\system32\atmlib.dll
2013-02-07 00:37:57 293376 —-a-w- c:\windows\system32\atmfd.dll
2013-02-06 23:20:14 293376 —-a-w- c:\windows\system32\psisdecd.dll
2013-02-06 23:20:13 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2013-02-06 23:20:13 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2013-02-06 23:20:13 217088 —-a-w- c:\windows\system32\psisrndr.ax
2013-02-06 23:20:02 189952 —-a-w- c:\windows\system32\winmm.dll
2013-02-06 23:20:00 23552 —-a-w- c:\windows\system32\mciseq.dll
2013-02-06 23:19:41 623616 —-a-w- c:\windows\system32\localspl.dll
2013-02-06 23:18:44 1205064 —-a-w- c:\windows\system32\ntdll.dll
2013-02-06 23:17:38 75776 —-a-w- c:\windows\system32\synceng.dll
2013-02-06 23:17:30 2048000 —-a-w- c:\windows\system32\win32k.sys
2013-02-06 23:17:27 429056 —-a-w- c:\windows\system32\EncDec.dll
2013-02-06 23:15:56 797696 —-a-w- c:\windows\system32\FntCache.dll
2013-02-06 23:15:55 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2013-02-06 23:15:41 66560 —-a-w- c:\windows\system32\packager.dll
2013-02-06 23:13:08 204288 —-a-w- c:\windows\system32\ncrypt.dll
2013-02-06 23:12:46 376320 —-a-w- c:\windows\system32\winsrv.dll
2013-02-06 23:12:44 680448 —-a-w- c:\windows\system32\msvcrt.dll
2013-02-06 23:12:10 985088 —-a-w- c:\windows\system32\crypt32.dll
2013-02-06 23:12:10 98304 —-a-w- c:\windows\system32\cryptnet.dll
2013-02-06 23:12:10 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2013-02-06 23:11:31 172544 —-a-w- c:\windows\system32\wintrust.dll
2013-02-06 23:11:23 708608 —-a-w- c:\program files\common files\system\ado\msado15.dll
2013-02-06 23:11:07 2048 —-a-w- c:\windows\system32\tzres.dll
2013-02-06 23:10:46 1400832 —-a-w- c:\windows\system32\msxml6.dll
2013-02-06 23:10:43 49152 —-a-w- c:\windows\system32\csrsrv.dll
2013-02-06 23:10:40 1314816 —-a-w- c:\windows\system32\quartz.dll
2013-02-06 23:10:39 497152 —-a-w- c:\windows\system32\qdvd.dll
2013-02-06 23:10:35 377344 —-a-w- c:\windows\system32\winhttp.dll
2013-02-06 23:10:30 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2013-02-06 23:10:06 563712 —-a-w- c:\windows\system32\oleaut32.dll
2013-02-06 23:10:06 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2013-02-06 23:10:06 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2013-02-06 23:10:06 238080 —-a-w- c:\windows\system32\oleacc.dll
2013-02-06 23:09:39 1248768 —-a-w- c:\windows\system32\msxml3.dll
2013-02-06 23:08:43 707584 —-a-w- c:\program files\common files\system\wab32.dll
2013-02-06 23:08:30 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2013-02-06 23:06:35 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2013-02-06 23:06:35 278528 —-a-w- c:\windows\system32\schannel.dll
2013-02-06 23:06:34 72704 —-a-w- c:\windows\system32\secur32.dll
2013-02-06 23:06:34 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2013-02-06 23:06:33 9728 —-a-w- c:\windows\system32\lsass.exe
2013-02-06 23:06:28 231424 —-a-w- c:\windows\system32\msshsq.dll
2013-02-06 23:06:20 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-06 23:06:20 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-02-06 22:31:30 613376 —-a-w- c:\windows\system32\rdpencom.dll
2013-02-06 01:51:43 2422272 —-a-w- c:\windows\system32\wucltux.dll
2013-02-06 01:50:56 88576 —-a-w- c:\windows\system32\wudriver.dll
2013-02-06 01:50:26 33792 —-a-w- c:\windows\system32\wuapp.exe
2013-02-06 01:50:26 171904 —-a-w- c:\windows\system32\wuwebv.dll
2013-02-05 02:28:32 735232 —-a-w- c:\windows\system32\drivers\athr.sys
2013-02-05 02:28:32 735232 —-a-w- c:\windows\system32\athr.sys
2013-02-05 02:28:32 ——– d—–w- c:\windows\Options
2013-02-05 02:27:51 ——– d—–w- c:\program files\Conduit
2013-02-05 02:27:39 ——– d—–w- c:\users\cockrell\appdata\local\Conduit
2013-02-05 02:27:34 ——– d—–w- c:\program files\MixiDJ
2013-02-05 02:27:26 ——– d—–w- c:\users\cockrell\appdata\local\CRE
2013-02-05 02:27:03 ——– d—–w- c:\users\cockrell\appdata\local\Coupon Companion Plugin
2013-02-05 02:26:52 274432 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2013-02-05 02:26:52 204800 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2013-02-05 02:26:51 757760 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2013-02-05 02:26:51 69715 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2013-02-05 02:26:51 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2013-02-05 02:26:49 200836 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2013-02-05 02:26:48 331908 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2013-02-05 02:26:19 ——– d—–w- c:\users\cockrell\appdata\local\Updater21804
2013-02-05 02:25:49 ——– d—–w- c:\program files\Coupon Companion Plugin
2013-02-05 02:25:35 ——– d—–w- c:\program files\InfoAtoms
2013-02-05 01:55:01 ——– d—–w- c:\progra~2\PCPitstop
2013-02-05 01:55:00 ——– d—–w- c:\program files\PCPitstop
2013-02-04 23:31:05 ——– d—–w- c:\windows\system32\eu-ES
2013-02-04 23:31:05 ——– d—–w- c:\windows\system32\ca-ES
2013-02-04 23:31:04 ——– d—–w- c:\windows\system32\vi-VN
2013-02-03 23:24:56 ——– d—–w- c:\users\cockrell\appdata\roaming\Malwarebytes
2013-02-03 23:24:38 ——– d—–w- c:\progra~2\Malwarebytes
2013-02-03 23:24:35 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-02-03 23:24:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-01-28 22:05:55 ——– d—–w- c:\users\cockrell\appdata\roaming\Motorola
2013-01-28 22:05:55 ——– d—–w- C:\Temp
2013-01-28 21:52:03 ——– d—–w- c:\program files\common files\Motorola Shared
2013-01-28 21:51:59 ——– d—–w- c:\program files\Motorola
2013-01-28 03:58:29 ——– d—–w- c:\program files\support.com
2013-01-28 03:58:25 ——– d—–w- c:\users\cockrell\appdata\local\SupportSoft
2013-01-28 03:57:51 ——– d—–w- c:\program files\common files\SupportSoft
2013-01-24 11:56:44 6991832 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-01-24 01:45:42 ——– d—–w- c:\users\cockrell\appdata\roaming\spotmau
2013-01-24 01:44:07 ——– d—–w- c:\progra~2\TuneUp360
2013-01-24 01:15:37 ——– d—–w- c:\users\cockrell\appdata\local\Google
2013-01-24 01:14:36 ——– d—–w- c:\users\cockrell\appdata\local\Deployment
2013-01-24 01:14:36 ——– d—–w- c:\users\cockrell\appdata\local\Apps
2013-01-23 21:26:57 ——– d—–w- c:\program files\Ask.com
2013-01-23 21:25:16 ——– d—–w- c:\users\cockrell\appdata\local\Wajam
2013-01-23 21:24:35 ——– d—–w- c:\program files\common files\Windows Live
2013-01-23 21:03:53 ——– d—–w- c:\windows\system32\EventProviders
2013-01-13 10:08:19 12240896 —-a-w- c:\windows\system32\NlsLexicons0007.dll
2013-01-13 10:08:15 3408896 —-a-w- c:\windows\system32\SLsvc.exe
2013-01-13 10:08:15 1081344 —-a-w- c:\windows\system32\SLCExt.dll
2013-01-13 10:08:12 65536 —-a-w- c:\windows\system32\DevicePairingWizard.exe
2013-01-13 10:08:11 2134528 —-a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2013-01-13 10:08:08 2644480 —-a-w- c:\windows\system32\NlsLexicons0009.dll
2013-01-13 10:08:05 1480704 —-a-w- c:\windows\system32\mssrch.dll
2013-01-13 10:08:02 684032 —-a-w- c:\windows\system32\drivers\spsys.sys
2013-01-13 10:08:01 1576960 —-a-w- c:\windows\system32\tquery.dll
2013-01-13 10:08:01 1305600 —-a-w- c:\program files\common files\microsoft shared\ink\tipskins.dll
2013-01-13 10:08:00 779136 —-a-w- c:\windows\system32\PresentationNative_v0300.dll
2013-01-13 10:08:00 561152 —-a-w- c:\windows\system32\drivers\hdaudbus.sys
2013-01-13 10:06:59 926184 —-a-w- c:\windows\system32\winresume.exe
2013-01-13 10:05:59 532992 —-a-w- c:\windows\system32\wpcao.dll
2013-01-13 10:04:59 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2013-01-13 10:04:59 265728 —-a-w- c:\windows\system32\wbem\repdrvfs.dll
2013-01-13 10:04:56 705536 —-a-w- c:\windows\system32\SmiEngine.dll
2013-01-13 10:04:48 218624 —-a-w- c:\windows\system32\wdscore.dll
2013-01-13 10:04:48 130560 —-a-w- c:\windows\system32\PkgMgr.exe
2013-01-13 10:04:28 247808 —-a-w- c:\windows\system32\drvstore.dll
2013-01-13 09:44:29 125952 —-a-w- c:\windows\system32\srvsvc.dll
2013-01-13 09:44:28 17920 —-a-w- c:\windows\system32\netevent.dll
2013-01-13 09:28:53 25648 —-a-r- c:\windows\system32\drivers\SymIMV.sys
2013-01-13 09:20:08 739328 —-a-w- c:\windows\system32\inetcomm.dll
2013-01-13 08:26:39 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2013-01-13 08:26:38 49472 —-a-w- c:\windows\system32\netfxperf.dll
2013-01-13 08:26:38 297808 —-a-w- c:\windows\system32\mscoree.dll
2013-01-13 08:26:38 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2013-01-13 08:26:38 1130824 —-a-w- c:\windows\system32\dfshim.dll
2013-01-12 14:11:48 217464 —-a-w- c:\windows\system32\drivers\nis\1008030.006\symtdi.sys
2013-01-12 14:11:47 89976 —-a-w- c:\windows\system32\drivers\nis\1008030.006\symfw.sys
2013-01-12 14:11:47 48760 —-a-w- c:\windows\system32\drivers\nis\1008030.006\symndisv.sys
2013-01-12 14:11:47 36472 —-a-w- c:\windows\system32\drivers\nis\1008030.006\symndis.sys
2013-01-12 14:11:47 33144 —-a-w- c:\windows\system32\drivers\nis\1008030.006\symids.sys
2013-01-12 14:11:47 310320 —-a-w- c:\windows\system32\drivers\nis\1008030.006\SymEFA.sys
2013-01-12 14:11:46 43696 —-a-w- c:\windows\system32\drivers\nis\1008030.006\srtspx.sys
2013-01-12 14:11:46 308272 —-a-w- c:\windows\system32\drivers\nis\1008030.006\srtsp.sys
2013-01-12 14:11:46 259632 —-a-w- c:\windows\system32\drivers\nis\1008030.006\BHDrvx86.sys
2013-01-12 14:10:52 467592 —-a-w- c:\windows\system32\drivers\nis\1008030.006\cchpx86.sys
2013-01-12 14:10:43 ——– d—–w- c:\windows\system32\drivers\nis\1008030.006
2013-01-11 20:51:10 ——– d—–w- c:\program files\Driver Wizard
2013-01-11 20:50:34 ——– d—–w- c:\users\cockrell\appdata\roaming\Driver Wizard
2013-01-11 20:24:52 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-11 19:51:46 221568 —-a-w- c:\windows\system32\drivers\netio.sys
2013-01-10 23:48:09 24064 —-a-w- c:\windows\system32\nshhttp.dll
2013-01-10 23:48:03 411648 —-a-w- c:\windows\system32\drivers\http.sys
2013-01-10 23:48:03 30720 —-a-w- c:\windows\system32\httpapi.dll
2013-01-10 23:40:27 ——– d—–w- c:\program files\MSXML 4.0
2013-01-10 23:29:02 105984 —-a-w- c:\windows\system32\netiohlp.dll
2013-01-10 23:29:00 27136 —-a-w- c:\windows\system32\NETSTAT.EXE
2013-01-10 23:28:59 9728 —-a-w- c:\windows\system32\TCPSVCS.EXE
2013-01-10 23:28:59 8704 —-a-w- c:\windows\system32\HOSTNAME.EXE
2013-01-10 23:28:59 19968 —-a-w- c:\windows\system32\ARP.EXE
2013-01-10 23:28:59 10240 —-a-w- c:\windows\system32\finger.exe
2013-01-10 23:28:58 17920 —-a-w- c:\windows\system32\ROUTE.EXE
2013-01-10 23:28:58 11264 —-a-w- c:\windows\system32\MRINFO.EXE
2013-01-10 23:27:14 53248 —-a-w- c:\windows\system32\rrinstaller.exe
2013-01-10 23:27:14 24576 —-a-w- c:\windows\system32\mfpmp.exe
2013-01-10 23:27:13 2048 —-a-w- c:\windows\system32\mferror.dll
2013-01-10 23:27:01 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2013-01-10 23:27:01 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2013-01-10 23:27:01 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2013-01-10 23:25:57 413696 —-a-w- c:\windows\system32\odbc32.dll
2013-01-10 23:24:41 339968 —-a-w- c:\program files\windows nt\accessories\wordpad.exe
2013-01-10 23:24:41 1316864 —-a-w- c:\windows\system32\ole32.dll
2013-01-10 23:24:36 1616384 —-a-w- c:\program files\windows mail\msoe.dll
2013-01-10 23:24:33 75264 —-a-w- c:\windows\system32\drivers\dfsc.sys
2013-01-10 23:24:31 1169408 —-a-w- c:\windows\system32\sdclt.exe
2013-01-10 23:24:25 128000 —-a-w- c:\windows\system32\spoolsv.exe
2013-01-10 23:24:17 67072 —-a-w- c:\windows\system32\asycfilt.dll
2013-01-10 23:24:15 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2013-01-10 23:24:10 71680 —-a-w- c:\windows\system32\atl.dll
2013-01-10 23:24:07 157184 —-a-w- c:\windows\system32\t2embed.dll
2013-01-10 23:24:05 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2013-01-10 23:24:05 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2013-01-10 23:23:41 317952 —-a-w- c:\windows\system32\MP4SDECD.DLL
2013-01-10 23:23:39 322560 —-a-w- c:\windows\system32\sbe.dll
2013-01-10 23:23:39 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2013-01-10 23:23:39 153088 —-a-w- c:\windows\system32\sbeio.dll
2013-01-10 23:23:11 954752 —-a-w- c:\windows\system32\mfc40.dll
2013-01-10 23:23:11 954288 —-a-w- c:\windows\system32\mfc40u.dll
2013-01-10 23:23:08 36864 —-a-w- c:\windows\system32\rtutils.dll
2013-01-10 23:22:57 1696256 —-a-w- c:\windows\system32\gameux.dll
2013-01-10 23:22:56 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2013-01-10 23:22:55 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2013-01-10 23:22:47 499712 —-a-w- c:\windows\system32\kerberos.dll
2013-01-10 23:22:47 175104 —-a-w- c:\windows\system32\wdigest.dll
2013-01-10 23:22:38 867328 —-a-w- c:\windows\system32\wmpmde.dll
2013-01-10 23:22:17 62464 —-a-w- c:\windows\system32\l3codeca.acm
2013-01-10 23:22:16 220672 —-a-w- c:\windows\system32\l3codecp.acm
2013-01-10 23:22:11 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2013-01-10 23:22:10 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2013-01-10 23:21:52 601600 —-a-w- c:\windows\system32\schedsvc.dll
2013-01-10 23:21:52 352768 —-a-w- c:\windows\system32\taskschd.dll
2013-01-10 23:21:51 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll
2013-01-10 23:21:51 171520 —-a-w- c:\windows\system32\taskeng.exe
2013-01-10 23:21:50 270336 —-a-w- c:\windows\system32\taskcomp.dll
2013-01-10 23:11:12 81920 —-a-w- c:\windows\system32\consent.exe
2013-01-10 23:10:20 74096 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-10 23:10:20 697712 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-10 23:09:20 313344 —-a-w- c:\windows\system32\wmpdxm.dll
2013-01-10 23:09:09 43520 —-a-w- c:\windows\system32\msdxm.tlb
2013-01-10 23:09:09 18432 —-a-w- c:\windows\system32\amcompat.tlb
2013-01-10 23:09:01 526336 —-a-w- c:\windows\system32\RMActivate_isv.exe
2013-01-10 23:09:01 518144 —-a-w- c:\windows\system32\RMActivate.exe
2013-01-10 23:08:57 471552 —-a-w- c:\windows\system32\secproc_isv.dll
2013-01-10 23:08:57 471552 —-a-w- c:\windows\system32\secproc.dll
2013-01-10 23:08:56 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2013-01-10 23:08:55 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2013-01-10 23:08:54 332288 —-a-w- c:\windows\system32\msdrm.dll
2013-01-10 23:08:54 152576 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2013-01-10 23:08:54 152064 —-a-w- c:\windows\system32\secproc_ssp.dll
2013-01-10 23:08:25 60928 —-a-w- c:\windows\system32\msasn1.dll
2013-01-10 23:07:21 2067968 —-a-w- c:\windows\system32\mstscax.dll
2013-01-10 23:07:20 677888 —-a-w- c:\windows\system32\mstsc.exe
2013-01-10 23:07:19 63488 —-a-w- c:\windows\system32\tscupgrd.exe
2013-01-10 23:07:19 53248 —-a-w- c:\windows\system32\tsgqec.dll
2013-01-10 23:07:19 136192 —-a-w- c:\windows\system32\aaclient.dll
2013-01-10 23:06:47 243712 —-a-w- c:\windows\system32\rastls.dll
2013-01-10 23:06:42 355328 —-a-w- c:\windows\system32\WSDApi.dll
2013-01-10 23:06:30 531968 —-a-w- c:\windows\system32\comctl32.dll
2013-01-10 23:06:06 31744 —-a-w- c:\windows\system32\msvidc32.dll
2013-01-10 23:06:06 22528 —-a-w- c:\windows\system32\msyuv.dll
2013-01-10 23:06:06 13312 —-a-w- c:\windows\system32\msrle32.dll
2013-01-10 23:06:06 12288 —-a-w- c:\windows\system32\tsbyuv.dll
2013-01-10 23:06:05 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2013-01-10 23:06:04 91136 —-a-w- c:\windows\system32\avifil32.dll
2013-01-10 23:06:04 82944 —-a-w- c:\windows\system32\mciavi32.dll
2013-01-10 23:06:03 123904 —-a-w- c:\windows\system32\msvfw32.dll
2013-01-10 23:05:22 1418752 —-a-w- c:\program files\windows media player\setup_wm.exe
2013-01-10 23:05:21 310784 —-a-w- c:\windows\system32\unregmp2.exe
2013-01-10 23:04:00 604672 —-a-w- c:\windows\system32\WMSPDMOD.DLL
2013-01-10 22:12:57 98304 —-a-w- c:\windows\system32\cabview.dll
.
==================== Find3M ====================
.
2013-02-07 01:16:17 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2013-01-08 12:59:11 505392 —-a-w- c:\windows\system32\msvcp71.dll
2013-01-08 12:59:11 353840 —-a-w- c:\windows\system32\msvcr71.dll
2013-01-08 12:59:11 1053232 —-a-w- c:\windows\system32\MFC71u.dll
2013-01-08 12:59:10 1066544 —-a-w- c:\windows\system32\MFC71.dll
.
============= FINISH: 18:34:29.63 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 1/8/2013 7:43:37 AM
System Uptime: 2/8/2013 5:06:26 PM (1 hours ago)
.
Motherboard: Wistron | | 303C
Processor: AMD Athlon Dual-Core QL-62 | Socket A | 1000/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 222 GiB total, 173.357 GiB free.
D: is FIXED (NTFS) - 11 GiB total, 1.776 GiB free.
E: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Acrobat.com
Activation Assistant for the 2007 Microsoft Office suites
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader 9
Adobe Shockwave Player
Ask Toolbar
Ask Toolbar Updater
Atheros Driver Installation Program
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Comcast High-Speed Internet Install Wizard
Compatibility Pack for the 2007 Office system
Conexant HD Audio
Coupon Companion Plugin
CyberLink DVD Suite
Driver Wizard v3.0
ESU for Microsoft Vista
Google Chrome
Google Update Helper
HDAUDIO Soft Data Fax Modem with SmartCP
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP DVD Play 3.7
HP Help and Support
HP Quick Launch Buttons 6.40 H2
HP Update
HP User Guides 0118
HP Wireless Assistant
HPAsset component for HP Active Support Library
HPNetworkAssistant
HPTCSSetup
InfoAtoms [Uninstall]
Java Auto Updater
Java™ 6 Update 39
Java™ 6 Update 7
Juno Preloader
LabelPrint
Malwarebytes Anti-Malware version 1.70.0.1100
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Live Search Toolbar
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MixiDJ Toolbar
MotoHelper 2.1.41 Driver 5.5.0
MotoHelper MergeModules
Motorola Mobile Drivers Installation 5.5.0
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee Reveal
My HP Games
NetWaiting
NetZero Preloader
Norton Internet Security
NVIDIA Drivers
Power2Go
PowerDirector
PVSonyDll
Realtek USB 2.0 Card Reader
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
SPORE Creature Creator Trial Edition
Strongvault Online Backup
Synaptics Pointing Device Driver
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Wajam
.
==== End Of File ===========================
Hello Amebeo and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your logs now and will reply with instructions shortly.

Satchfan
Hi again

You have a fair amount of junk on there but nothing that we shouldn’t be able to deal with.

I will need more scans to be sure that there’s nothing more serious so let’s make a start.

================================================

Uninstall programs

  • click Start, Control Panel, Programs, and then Programs and Features.
  • click on each of the following and then on Uninstall.


Ask Toolbar
Ask Toolbar Updater
Coupon Companion Plugin
InfoAtoms [Uninstall]
Java™ 6 Update 39
Java™ 6 Update 7
MixiDJ Toolbar
Wajam


================================================

Download and run Junkware Removal Tool

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.
================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
When all this is done, please run OTL again and send the new log.

Logs to include in your next post :

JRT.txt
aswMBR log
New OTL log


Thanks

Satchfan
Thank you for the response Satchfan

I completed everything you requested. One issue perhaps is when I opend Chrome up again MixiDJ Toolbar reinstalled.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.6.2 (02.02.2013:2)
OS: Windows Vista ™ Home Premium x86
Ran by [removed] on Sat 02/09/2013 at 10:59:30.43
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1758737864-3516472490-3206523650-1000\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1758737864-3516472490-3206523650-1000\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\toolbar\webbrowser\\{d4027c7f-154a-4066-a1ad-4243d8127440}



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
Successfully deleted: [Registry Key] hkey_current_user\software\cr_installer
Successfully deleted: [Registry Key] hkey_current_user\software\softonic
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduitsearchscopes
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\crossrider
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\pricegong
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\smartbar
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT3272718
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{171debeb-c3d4-40b7-ac73-056a5eba4a7e}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] "hkey_current_user\software\appdatalow\software\asktoolbar"



~~~ Files

Successfully deleted: [File] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ebay.lnk"



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\strongvault online backup"
Successfully deleted: [Folder] "C:\Users\cockrell\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\cockrell\appdata\local\coupon companion plugin"
Successfully deleted: [Folder] "C:\Users\cockrell\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\cockrell\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 02/09/2013 at 11:04:05.05
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-02-09 11:12:27
—————————–
11:12:27.059 OS Version: Windows 6.0.6002 Service Pack 2
11:12:27.059 Number of processors: 2 586 0x301
11:12:27.059 ComputerName: COCKRELL-PC UserName: cockrell
11:12:33.657 Initialize success
11:14:55.683 AVAST engine defs: 13020900
11:18:18.413 The log file has been saved successfully to "C:\Users\cockrell\Desktop\aswMBR.txt"




OTL logfile created on: 2/9/2013 11:19:00 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\cockrell\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.75 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 43.42% Memory free
3.74 Gb Paging File | 2.41 Gb Available in Paging File | 64.49% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.01 Gb Total Space | 166.67 Gb Free Space | 75.07% Space Free | Partition Type: NTFS
Drive D: | 10.88 Gb Total Space | 1.78 Gb Free Space | 16.33% Space Free | Partition Type: NTFS
Drive E: | 76.08 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: COCKRELL-PC | User Name: cockrell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\cockrell\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Windows\System32\Defrag.exe (Microsoft Corp.)
PRC - C:\Windows\System32\DfrgNtfs.exe (Microsoft Corp.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\libglesv2.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\libegl.dll ()
MOD - C:\Program Files\Google\Chrome\Application\24.0.1312.57\ffmpegsumo.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe (Symantec Corporation)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SYMREDRV) – C:\Windows\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS File not found
DRV - (SYMDNS) – C:\Windows\system32\drivers\NIS\1000000.07D\SYMDNS.SYS File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (mbr) – C:\Users\cockrell\AppData\Local\Temp\mbr.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (aswMBR) – C:\Users\cockrell\AppData\Local\Temp\aswMBR.sys File not found
DRV - (ccHP) – C:\Windows\System32\drivers\NIS\1008030.006\cchpx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20130208.004\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130208.032\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130208.032\NAVENG.SYS (Symantec Corporation)
DRV - (Motousbnet) – C:\Windows\System32\drivers\Motousbnet.sys (Motorola Mobility Inc)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola Mobility Inc)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola Mobility Inc)
DRV - (motusbdevice) – C:\Windows\System32\drivers\motusbdevice.sys (Motorola Inc)
DRV - (SYMTDI) – C:\Windows\System32\drivers\NIS\1008030.006\symtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\drivers\NIS\1008030.006\symfw.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\drivers\NIS\1008030.006\symndisv.sys (Symantec Corporation)
DRV - (NVNET) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1008030.006\SymEFA.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1008030.006\srtsp.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Windows\System32\drivers\NIS\1008030.006\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1008030.006\srtspx.sys (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (motandroidusb) – C:\Windows\System32\drivers\motoandroid.sys (Motorola)
DRV - (BTCFilterService) – C:\Windows\System32\drivers\motfilt.sys (Motorola Inc)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (NETw3v32) – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (MotoSwitchService) – C:\Windows\System32\drivers\motswch.sys (Motorola)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE - HKLM\..\SearchScopes\{60A4E56C-445B-47E9-8637-F329433B1DB3}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPNTDF

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKCU\..\SearchScopes\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
IE - HKCU\..\SearchScopes\{60A4E56C-445B-47E9-8637-F329433B1DB3}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2013/01/13 04:29:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi

[2013/02/09 10:07:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla FireFox\extensions

========== Chrome ==========

CHR - homepage: http://search.conduit.com/?CUI=UN132945277…SearchSource=48
CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…;ctid=CT3272718
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.conduit.com/?CUI=UN132945277…SearchSource=48
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Wajam (Enabled) = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Docs = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: MixiDJ = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbofibgamhkgoonaocfgemncghhadmgb\10.14.251.3_0\
CHR - Extension: Gmail = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{89015AC8-32D1-421A-96CE-7C4B155793AF}: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/04/03 09:05:10 | 000,000,052 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7f8662fd-5c29-11e2-96e8-001f166ee388}\Shell - "" = AutoRun
O33 - MountPoints2\{7f8662fd-5c29-11e2-96e8-001f166ee388}\Shell\AutoRun\command - "" = F:\setup.exe -a
O33 - MountPoints2\{82d180e4-5994-11e2-96df-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{82d180e4-5994-11e2-96df-806e6f6e6963}\Shell\AutoRun\command - "" = E:\install.exe – [2007/04/24 11:59:07 | 001,074,768 | R— | M] (SupportSoft, Inc.)
O33 - MountPoints2\{ba158ed1-6993-11e2-ab6d-001f166ee388}\Shell - "" = AutoRun
O33 - MountPoints2\{ba158ed1-6993-11e2-ab6d-001f166ee388}\Shell\AutoRun\command - "" = F:\setup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/09 10:59:19 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/09 10:59:04 | 000,000,000 | —D | C] – C:\JRT
[2013/02/09 10:44:05 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\cockrell\Desktop\aswMBR.exe
[2013/02/09 10:42:30 | 000,547,275 | —- | C] (Oleg N. Scherbakov) – C:\Users\cockrell\Desktop\JRT.exe
[2013/02/08 20:03:33 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/02/08 17:45:01 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\cockrell\Desktop\HiJackThis.exe
[2013/02/08 17:43:00 | 000,000,000 | -HSD | C] – C:\AI_RecycleBin
[2013/02/08 17:32:02 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\cockrell\Desktop\OTL.exe
[2013/02/08 17:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/02/08 17:25:59 | 000,477,616 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 17:25:59 | 000,473,520 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 16:59:18 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\cockrell\Desktop\ATF-Cleaner.exe
[2013/02/08 16:50:48 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/02/07 19:22:20 | 000,758,784 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\cohelper.dll
[2013/02/07 19:22:18 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2013/02/07 18:47:14 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/02/07 18:47:11 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/02/07 18:47:11 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/02/07 18:47:10 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/02/07 18:47:10 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/02/07 18:47:10 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/02/07 18:16:29 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2013/02/06 20:46:08 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/02/06 20:46:06 | 003,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2013/02/06 20:46:06 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2013/02/06 20:43:31 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BthMtpContextHandler.dll
[2013/02/06 20:43:31 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShextAutoplay.exe
[2013/02/06 20:43:26 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceConnectApi.dll
[2013/02/06 20:43:22 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdMtpUS.dll
[2013/02/06 20:43:22 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdConns.dll
[2013/02/06 20:43:21 | 000,546,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2013/02/06 20:43:21 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdMtp.dll
[2013/02/06 20:43:20 | 000,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2013/02/06 20:43:20 | 000,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2013/02/06 20:43:20 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWMDRM.dll
[2013/02/06 20:43:20 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2013/02/06 20:43:20 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2013/02/06 20:18:45 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/02/06 20:18:44 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/02/06 20:18:44 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/02/06 20:18:44 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/02/06 20:18:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/02/06 20:18:43 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/02/06 20:18:43 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/02/06 20:18:43 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/02/06 20:18:42 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/02/06 20:18:42 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/02/06 20:18:42 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/02/06 20:18:41 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/02/06 20:18:41 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/02/06 20:18:41 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/02/06 20:18:41 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/02/06 20:18:41 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/02/06 20:18:41 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/02/06 20:18:41 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/02/06 20:18:41 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/02/06 20:18:41 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/02/06 20:18:41 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/02/06 20:18:41 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/02/06 20:18:41 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/02/06 20:18:41 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/02/06 20:18:40 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/02/06 20:18:40 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2013/02/06 20:18:40 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2013/02/06 20:18:40 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/02/06 20:18:40 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2013/02/06 20:18:40 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/02/06 20:18:39 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/02/06 20:18:39 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2013/02/06 20:18:39 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/02/06 20:18:39 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/02/06 20:18:39 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/02/06 20:18:39 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/02/06 20:18:39 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/02/06 20:16:17 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2013/02/06 20:16:17 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2013/02/06 20:16:16 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2013/02/06 20:16:13 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2013/02/06 20:16:13 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2013/02/06 20:16:13 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2013/02/06 20:16:13 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2013/02/06 20:16:11 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2013/02/06 20:16:10 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/02/06 20:16:10 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/02/06 20:16:10 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/02/06 20:16:10 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/02/06 20:16:09 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2013/02/06 20:16:09 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2013/02/06 20:16:09 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2013/02/06 20:16:09 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2013/02/06 20:16:09 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2013/02/06 20:14:51 | 000,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/02/06 20:14:51 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/02/06 20:14:51 | 000,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2013/02/06 20:14:51 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2013/02/06 20:14:51 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2013/02/06 20:14:51 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/02/06 19:50:02 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2013/02/06 19:49:54 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2013/02/06 19:49:54 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winusb.dll
[2013/02/06 19:49:51 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2013/02/06 19:49:47 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2013/02/06 19:49:46 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2013/02/06 19:37:57 | 000,293,376 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2013/02/06 19:37:57 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2013/02/06 18:20:14 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2013/02/06 18:20:13 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2013/02/06 18:20:13 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2013/02/06 18:20:13 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2013/02/06 18:20:00 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciseq.dll
[2013/02/06 18:17:38 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\synceng.dll
[2013/02/06 18:17:30 | 002,048,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/02/06 18:17:27 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2013/02/06 18:16:44 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2013/02/06 18:16:44 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnsvr.exe
[2013/02/06 18:15:55 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/02/06 18:15:41 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2013/02/06 18:13:08 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2013/02/06 18:12:46 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/02/06 18:11:07 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/02/06 18:10:43 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/02/06 18:10:40 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2013/02/06 18:10:39 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2013/02/06 18:10:06 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2013/02/06 18:10:06 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2013/02/06 18:06:28 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2013/02/06 18:06:20 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/02/06 18:06:20 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/02/06 17:31:30 | 000,613,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2013/02/05 20:51:43 | 002,422,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2013/02/05 20:51:43 | 000,045,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2013/02/05 20:50:56 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2013/02/05 20:50:56 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2013/02/05 20:50:56 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2013/02/05 20:50:26 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2013/02/05 20:50:26 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2013/02/04 21:28:32 | 000,735,232 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\drivers\athr.sys
[2013/02/04 21:28:32 | 000,735,232 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\athr.sys
[2013/02/04 21:28:32 | 000,000,000 | —D | C] – C:\Windows\Options
[2013/02/04 21:27:26 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\CRE
[2013/02/04 21:26:17 | 000,000,000 | —D | C] – C:\Program Files\Mozilla FireFox
[2013/02/04 20:55:01 | 000,000,000 | —D | C] – C:\ProgramData\PCPitstop
[2013/02/04 20:55:00 | 000,000,000 | —D | C] – C:\Program Files\PCPitstop
[2013/02/04 18:31:05 | 000,000,000 | —D | C] – C:\Windows\System32\eu-ES
[2013/02/04 18:31:05 | 000,000,000 | —D | C] – C:\Windows\System32\ca-ES
[2013/02/04 18:31:04 | 000,000,000 | —D | C] – C:\Windows\System32\vi-VN
[2013/02/03 18:24:56 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Malwarebytes
[2013/02/03 18:24:38 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/02/03 18:24:35 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/02/03 18:24:34 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/28 17:05:55 | 000,000,000 | —D | C] – C:\Temp
[2013/01/28 17:05:55 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Motorola
[2013/01/28 16:52:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Motorola Shared
[2013/01/28 16:51:59 | 000,000,000 | —D | C] – C:\Program Files\Motorola
[2013/01/27 22:58:29 | 000,000,000 | —D | C] – C:\Program Files\support.com
[2013/01/27 22:58:25 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\SupportSoft
[2013/01/27 22:57:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SupportSoft
[2013/01/23 20:45:42 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\spotmau
[2013/01/23 20:44:07 | 000,000,000 | —D | C] – C:\ProgramData\TuneUp360
[2013/01/23 20:18:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/01/23 20:15:47 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/01/23 20:15:37 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Google
[2013/01/23 20:14:36 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Deployment
[2013/01/23 20:14:36 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Apps
[2013/01/23 16:24:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2013/01/23 16:24:17 | 001,242,112 | —- | C] (Microsoft Corporation) – C:\Users\cockrell\Desktop\wlsetup-web.exe
[2013/01/23 16:03:53 | 000,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2013/01/13 05:08:19 | 012,240,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0007.dll
[2013/01/13 05:08:15 | 001,081,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCExt.dll
[2013/01/13 05:08:12 | 000,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingWizard.exe
[2013/01/13 05:08:11 | 002,134,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FunctionDiscoveryFolder.dll
[2013/01/13 05:08:08 | 002,644,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0009.dll
[2013/01/13 05:08:05 | 001,480,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2013/01/13 05:08:02 | 000,684,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\spsys.sys
[2013/01/13 05:08:01 | 001,576,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2013/01/13 05:08:00 | 000,779,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2013/01/13 05:07:59 | 000,928,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scavenge.dll
[2013/01/13 05:07:57 | 000,677,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2fs.dll
[2013/01/13 05:07:56 | 000,291,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WscEapPr.dll
[2013/01/13 05:07:55 | 000,968,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz2.dll
[2013/01/13 05:07:53 | 000,619,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2013/01/13 05:07:52 | 001,216,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2013/01/13 05:07:50 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spinstall.exe
[2013/01/13 05:07:50 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spreview.exe
[2013/01/13 05:07:49 | 000,978,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmv2clt.dll
[2013/01/13 05:07:48 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizui.dll
[2013/01/13 05:07:47 | 000,438,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcupdate_GenuineIntel.dll
[2013/01/13 05:07:45 | 000,670,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2013/01/13 05:07:43 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2VDEC.DLL
[2013/01/13 05:07:43 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2.dll
[2013/01/13 05:07:43 | 000,351,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2013/01/13 05:07:43 | 000,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2013/01/13 05:07:42 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2013/01/13 05:07:41 | 000,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10K.DLL
[2013/01/13 05:07:40 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairing.dll
[2013/01/13 05:07:39 | 000,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sperror.dll
[2013/01/13 05:07:39 | 000,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\korwbrkr.dll
[2013/01/13 05:07:38 | 000,463,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IasMigReader.exe
[2013/01/13 05:07:36 | 001,589,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjet40.dll
[2013/01/13 05:07:33 | 000,883,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10.IME
[2013/01/13 05:07:33 | 000,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexch40.dll
[2013/01/13 05:07:32 | 001,078,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diagperf.dll
[2013/01/13 05:07:32 | 000,327,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\P2PGraph.dll
[2013/01/13 05:07:31 | 000,986,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2013/01/13 05:07:31 | 000,950,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mblctr.exe
[2013/01/13 05:07:31 | 000,301,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srchadmin.dll
[2013/01/13 05:07:30 | 001,792,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmc.exe
[2013/01/13 05:07:30 | 000,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uDWM.dll
[2013/01/13 05:07:29 | 000,454,144 | —- | C] (Microsoft) – C:\Windows\System32\IasMigPlugin.dll
[2013/01/13 05:07:29 | 000,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBth.dll
[2013/01/13 05:07:28 | 000,880,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RacEngn.dll
[2013/01/13 05:07:26 | 002,012,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\milcore.dll
[2013/01/13 05:07:26 | 001,112,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2013/01/13 05:07:26 | 000,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorAPI.dll
[2013/01/13 05:07:25 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2013/01/13 05:07:24 | 000,950,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpedit.dll
[2013/01/13 05:07:24 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjtes40.dll
[2013/01/13 05:07:24 | 000,115,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayDriverLib.dll
[2013/01/13 05:07:24 | 000,099,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2013/01/13 05:07:23 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSAT.exe
[2013/01/13 05:07:22 | 000,710,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Magnify.exe
[2013/01/13 05:07:22 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationSettings.exe
[2013/01/13 05:07:22 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayServices.dll
[2013/01/13 05:07:21 | 000,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstext40.dll
[2013/01/13 05:07:18 | 000,454,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxbde40.dll
[2013/01/13 05:07:18 | 000,339,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexcl40.dll
[2013/01/13 05:07:18 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwmi.dll
[2013/01/13 05:07:17 | 001,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsAnytimeUpgradeCPL.dll
[2013/01/13 05:07:16 | 001,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2013/01/13 05:07:16 | 001,086,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NetProjW.dll
[2013/01/13 05:07:15 | 000,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrepl40.dll
[2013/01/13 05:07:15 | 000,640,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthprops.cpl
[2013/01/13 05:07:14 | 000,469,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.dll
[2013/01/13 05:07:14 | 000,205,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eudcedit.exe
[2013/01/13 05:07:14 | 000,119,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2013/01/13 05:07:14 | 000,102,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2013/01/13 05:07:13 | 002,926,592 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/01/13 05:07:12 | 001,788,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d9.dll
[2013/01/13 05:07:12 | 000,368,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mspbde40.dll
[2013/01/13 05:07:11 | 000,241,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msltus40.dll
[2013/01/13 05:07:11 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorPwdMgr.dll
[2013/01/13 05:07:10 | 001,053,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtctm.dll
[2013/01/13 05:07:10 | 000,344,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd3x40.dll
[2013/01/13 05:07:09 | 000,250,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtapi.dll
[2013/01/13 05:07:09 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlhtml.dll
[2013/01/13 05:07:07 | 000,614,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2013/01/13 05:07:06 | 000,582,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCommDlg.dll
[2013/01/13 05:07:06 | 000,165,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WcnNetsh.dll
[2013/01/13 05:07:05 | 001,730,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apds.dll
[2013/01/13 05:07:05 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\compcln.exe
[2013/01/13 05:07:04 | 000,618,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswstr10.dll
[2013/01/13 05:07:03 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xmlfilter.dll
[2013/01/13 05:07:01 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUI.exe
[2013/01/13 05:07:01 | 000,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapphost.dll
[2013/01/13 05:07:00 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlsrv32.dll
[2013/01/13 05:07:00 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd2x40.dll
[2013/01/13 05:06:59 | 000,926,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2013/01/13 05:06:59 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propdefs.dll
[2013/01/13 05:06:58 | 001,856,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbgeng.dll
[2013/01/13 05:06:58 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtutil.exe
[2013/01/13 05:06:57 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssitlb.dll
[2013/01/13 05:06:56 | 002,167,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcndmgr.dll
[2013/01/13 05:06:54 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\devmgr.dll
[2013/01/13 05:06:54 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvinst.exe
[2013/01/13 05:06:54 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscb.dll
[2013/01/13 05:06:54 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBthProxy.dll
[2013/01/13 05:06:53 | 000,485,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\evr.dll
[2013/01/13 05:06:53 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingProxy.dll
[2013/01/13 05:06:52 | 001,533,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz.dll
[2013/01/13 05:06:52 | 001,382,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVSDECD.DLL
[2013/01/13 05:06:51 | 001,143,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wercon.exe
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quick.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qintlgnt.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\phon.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cintlgnt.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chajei.ime
[2013/01/13 05:06:50 | 000,617,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adtschema.dll
[2013/01/13 05:06:50 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mimefilt.dll
[2013/01/13 05:06:49 | 000,856,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswdat10.dll
[2013/01/13 05:06:49 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2013/01/13 05:06:49 | 000,396,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsmsnap.dll
[2013/01/13 05:06:49 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjter40.dll
[2013/01/13 05:06:48 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\reg.exe
[2013/01/13 05:06:48 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtffilt.dll
[2013/01/13 05:06:46 | 000,799,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/01/13 05:06:46 | 000,035,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2013/01/13 05:06:45 | 000,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2013/01/13 05:06:44 | 000,704,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2013/01/13 05:06:44 | 000,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcrypt.dll
[2013/01/13 05:06:44 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2013/01/13 05:06:43 | 000,060,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2013/01/13 05:06:43 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshooks.dll
[2013/01/13 05:06:42 | 000,332,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msihnd.dll
[2013/01/13 05:06:42 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MMDevAPI.dll
[2013/01/13 05:06:42 | 000,035,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsWpfWrp.exe
[2013/01/13 05:06:41 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msstrc.dll
[2013/01/13 05:06:40 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fundisc.dll
[2013/01/13 05:06:39 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2013/01/13 05:06:39 | 000,080,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2013/01/13 05:06:37 | 001,020,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdc.dll
[2013/01/13 05:06:37 | 000,125,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Classpnp.sys
[2013/01/13 05:06:37 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi.dll
[2013/01/13 05:06:36 | 001,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chsbrkr.dll
[2013/01/13 05:06:36 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassdo.dll
[2013/01/13 05:06:36 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Kswdmcap.ax
[2013/01/13 05:06:35 | 001,823,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnidui.dll
[2013/01/13 05:06:35 | 000,636,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autofmt.exe
[2013/01/13 05:06:35 | 000,009,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2013/01/13 05:06:34 | 000,122,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Storport.sys
[2013/01/13 05:06:34 | 000,109,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ataport.sys
[2013/01/13 05:06:34 | 000,050,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PSHED.DLL
[2013/01/13 05:06:34 | 000,035,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\crashdmp.sys
[2013/01/13 05:06:33 | 000,757,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroles.dll
[2013/01/13 05:06:33 | 000,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnrollUI.dll
[2013/01/13 05:06:32 | 001,107,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pidgenx.dll
[2013/01/13 05:06:32 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmon.ocx
[2013/01/13 05:06:31 | 002,205,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SyncCenter.dll
[2013/01/13 05:06:30 | 001,502,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certmgr.dll
[2013/01/13 05:06:30 | 000,627,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sethc.exe
[2013/01/13 05:06:30 | 000,593,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comuid.dll
[2013/01/13 05:06:30 | 000,017,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kd1394.dll
[2013/01/13 05:06:29 | 000,324,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\untfs.dll
[2013/01/13 05:06:29 | 000,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassam.dll
[2013/01/13 05:06:29 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrobj.dll
[2013/01/13 05:06:28 | 000,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imkr80.ime
[2013/01/13 05:06:28 | 000,099,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/01/13 05:06:28 | 000,043,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pciidex.sys
[2013/01/13 05:06:27 | 000,656,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoconv.exe
[2013/01/13 05:06:27 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasnap.dll
[2013/01/13 05:06:26 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscript.exe
[2013/01/13 05:06:26 | 000,027,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Dumpata.sys
[2013/01/13 05:06:25 | 000,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wow32.dll
[2013/01/13 05:06:25 | 000,130,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basecsp.dll
[2013/01/13 05:06:25 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiodg.exe
[2013/01/13 05:06:25 | 000,017,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdcom.dll
[2013/01/13 05:06:24 | 000,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\osk.exe
[2013/01/13 05:06:23 | 000,019,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdusb.dll
[2013/01/13 05:06:22 | 000,340,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RelMon.dll
[2013/01/13 05:06:22 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spcmsg.dll
[2013/01/13 05:06:20 | 000,860,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFaultSecure.exe
[2013/01/13 05:06:20 | 000,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2013/01/13 05:06:20 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\offfilt.dll
[2013/01/13 05:06:19 | 000,638,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Utilman.exe
[2013/01/13 05:06:18 | 000,230,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskraid.exe
[2013/01/13 05:06:18 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
[2013/01/13 05:06:18 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsepno.dll
[2013/01/13 05:06:17 | 000,852,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2013/01/13 05:06:17 | 000,391,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscms.dll
[2013/01/13 05:06:17 | 000,197,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SndVol.exe
[2013/01/13 05:06:17 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msnetobj.dll
[2013/01/13 05:06:16 | 000,551,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prnntfy.dll
[2013/01/13 05:06:16 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2013/01/13 05:06:16 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysclass.dll
[2013/01/13 05:06:16 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ulib.dll
[2013/01/13 05:06:16 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsmsext.dll
[2013/01/13 05:06:16 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2013/01/13 05:06:15 | 000,444,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsound.dll
[2013/01/13 05:06:14 | 000,223,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscntfy.dll
[2013/01/13 05:06:14 | 000,181,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpsetup.dll
[2013/01/13 05:06:14 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdProxy.dll
[2013/01/13 05:06:13 | 001,342,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\brcpl.dll
[2013/01/13 05:06:13 | 000,759,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsecsnp.dll
[2013/01/13 05:06:13 | 000,399,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlangpui.dll
[2013/01/13 05:06:13 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskpart.exe
[2013/01/13 05:06:12 | 001,575,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVENCOD.DLL
[2013/01/13 05:06:12 | 000,507,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsdyn.dll
[2013/01/13 05:06:12 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpapi.dll
[2013/01/13 05:06:12 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashlpr.dll
[2013/01/13 05:06:12 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logman.exe
[2013/01/13 05:06:11 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2013/01/13 05:06:11 | 000,158,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrad.dll
[2013/01/13 05:06:11 | 000,155,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2013/01/13 05:06:11 | 000,140,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wusa.exe
[2013/01/13 05:06:11 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\findstr.exe
[2013/01/13 05:06:10 | 002,225,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcenter.dll
[2013/01/13 05:06:10 | 001,580,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpccpl.dll
[2013/01/13 05:06:09 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wer.dll
[2013/01/13 05:06:09 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassvcs.dll
[2013/01/13 05:06:08 | 001,152,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themecpl.dll
[2013/01/13 05:06:08 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsnmp32.dll
[2013/01/13 05:06:06 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scansetting.dll
[2013/01/13 05:06:06 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2013/01/13 05:06:06 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssprxy.dll
[2013/01/13 05:06:05 | 000,777,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcc.dll
[2013/01/13 05:06:05 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2013/01/13 05:06:05 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasacct.dll
[2013/01/13 05:06:04 | 003,072,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkmap.dll
[2013/01/13 05:06:04 | 001,248,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PerfCenterCPL.dll
[2013/01/13 05:06:04 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercpl.dll
[2013/01/13 05:06:03 | 001,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2013/01/13 05:06:03 | 001,224,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sud.dll
[2013/01/13 05:06:03 | 000,842,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\systemcpl.dll
[2013/01/13 05:06:03 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.exe
[2013/01/13 05:06:02 | 002,515,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\accessibilitycpl.dll
[2013/01/13 05:06:02 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pcaui.dll
[2013/01/13 05:06:02 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmci.dll
[2013/01/13 05:06:01 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usercpl.dll
[2013/01/13 05:06:01 | 000,516,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoplay.dll
[2013/01/13 05:06:00 | 001,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanpref.dll
[2013/01/13 05:06:00 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpchttp.dll
[2013/01/13 05:06:00 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pintlgnt.ime
[2013/01/13 05:05:59 | 000,532,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcao.dll
[2013/01/13 05:05:59 | 000,408,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msinfo32.exe
[2013/01/13 05:05:59 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scksp.dll
[2013/01/13 05:05:59 | 000,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsutil.dll
[2013/01/13 05:05:58 | 000,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AudioSes.dll
[2013/01/13 05:05:58 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleprn.dll
[2013/01/13 05:05:58 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3msm.dll
[2013/01/13 05:05:58 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\feclient.dll
[2013/01/13 05:05:57 | 000,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2013/01/13 05:05:57 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rekeywiz.exe
[2013/01/13 05:05:57 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iaspolcy.dll
[2013/01/13 05:05:57 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DeviceEject.exe
[2013/01/13 05:05:57 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscisvif.dll
[2013/01/13 05:05:56 | 001,689,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscui.cpl
[2013/01/13 05:05:56 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpui.dll
[2013/01/13 05:05:56 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/01/13 05:05:56 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncryptui.dll
[2013/01/13 05:05:56 | 000,407,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpapimig.exe
[2013/01/13 05:05:55 | 000,642,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasgcw.dll
[2013/01/13 05:05:55 | 000,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FWPUCLNT.DLL
[2013/01/13 05:05:55 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasplap.dll
[2013/01/13 05:05:55 | 000,215,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certreq.exe
[2013/01/13 05:05:55 | 000,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmartcardCredentialProvider.dll
[2013/01/13 05:05:55 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hdwwiz.exe
[2013/01/13 05:05:55 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSTheme.exe
[2013/01/13 05:05:54 | 000,170,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2013/01/13 05:05:54 | 000,167,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\portcls.sys
[2013/01/13 05:05:54 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWSD.dll
[2013/01/13 05:05:54 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPUnattend.exe
[2013/01/13 05:05:54 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmmon32.exe
[2013/01/13 05:05:54 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwinsat.dll
[2013/01/13 05:05:53 | 000,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmdial32.dll
[2013/01/13 05:05:53 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2013/01/13 05:05:53 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\whealogr.dll
[2013/01/13 05:05:53 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD2.sys
[2013/01/13 05:05:53 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD.sys
[2013/01/13 05:05:52 | 000,275,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SnippingTool.exe
[2013/01/13 05:05:52 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conime.exe
[2013/01/13 05:05:51 | 000,657,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVXENCD.DLL
[2013/01/13 05:05:51 | 000,547,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaaut.dll
[2013/01/13 05:05:51 | 000,202,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanui.dll
[2013/01/13 05:05:51 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPutil.exe
[2013/01/13 05:05:50 | 002,153,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oobefldr.dll
[2013/01/13 05:05:50 | 000,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shwebsvc.dll
[2013/01/13 05:05:50 | 000,137,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsprop.dll
[2013/01/13 05:05:50 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dimsroam.dll
[2013/01/13 05:05:49 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\modemui.dll
[2013/01/13 05:05:49 | 000,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsetup.dll
[2013/01/13 05:05:48 | 006,103,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chtbrkr.dll
[2013/01/13 05:05:48 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscandui.dll
[2013/01/13 05:05:48 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmontr.dll
[2013/01/13 05:05:47 | 000,542,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\blackbox.dll
[2013/01/13 05:05:47 | 000,533,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmsdk.dll
[2013/01/13 05:05:47 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2013/01/13 05:05:47 | 000,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlgpclnt.dll
[2013/01/13 05:05:47 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dataclen.dll
[2013/01/13 05:05:46 | 000,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2013/01/13 05:05:46 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDMon.dll
[2013/01/13 05:05:45 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2013/01/13 05:05:45 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cipher.exe
[2013/01/13 05:05:45 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ifmon.dll
[2013/01/13 05:05:44 | 000,414,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2013/01/13 05:05:44 | 000,217,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\InkEd.dll
[2013/01/13 05:05:44 | 000,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpresult.exe
[2013/01/13 05:05:44 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2013/01/13 05:05:44 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2013/01/13 05:05:44 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimtf.dll
[2013/01/13 05:05:43 | 000,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\thawbrkr.dll
[2013/01/13 05:05:43 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\watchdog.sys
[2013/01/13 05:05:42 | 000,356,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2013/01/13 05:05:42 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\softkbd.dll
[2013/01/13 05:05:41 | 000,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmmgrtn.dll
[2013/01/13 05:05:41 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmsynth.dll
[2013/01/13 05:05:41 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfui.dll
[2013/01/13 05:05:40 | 000,200,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\input.dll
[2013/01/13 05:05:40 | 000,166,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\puiapi.dll
[2013/01/13 05:05:40 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2013/01/13 05:05:39 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLLUA.exe
[2013/01/13 05:05:39 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fc.exe
[2013/01/13 05:05:39 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msisip.dll
[2013/01/13 05:05:38 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmusic.dll
[2013/01/13 05:05:38 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2013/01/13 05:05:38 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdSSDP.dll
[2013/01/13 05:05:37 | 000,187,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapp3hst.dll
[2013/01/13 05:05:37 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tintlgnt.ime
[2013/01/13 05:05:37 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\l2nacp.dll
[2013/01/13 05:05:37 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjint40.dll
[2013/01/13 05:05:37 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsCtfMonitor.dll
[2013/01/13 05:05:36 | 000,083,456 | —- | C] (Microsoft) – C:\Windows\System32\SMBHelperClass.dll
[2013/01/13 05:05:36 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftp.exe
[2013/01/13 05:05:36 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsdchngr.dll
[2013/01/13 05:05:35 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWCN.dll
[2013/01/13 05:05:35 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Storprop.dll
[2013/01/13 05:05:35 | 000,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdiag.dll
[2013/01/13 05:05:35 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3cfg.dll
[2013/01/13 05:05:35 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthci.dll
[2013/01/13 05:05:35 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthudtask.exe
[2013/01/13 05:05:35 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdial.exe
[2013/01/13 05:05:34 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcinst.dll
[2013/01/13 05:05:34 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipconfig.exe
[2013/01/13 05:05:34 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CHxReadingStringIME.dll
[2013/01/13 05:05:33 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappgnui.dll
[2013/01/13 05:05:33 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nslookup.exe
[2013/01/13 05:05:33 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hbaapi.dll
[2013/01/13 05:05:33 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkitemfactory.dll
[2013/01/13 05:05:33 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ocsetup.exe
[2013/01/13 05:05:33 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FwRemoteSvr.dll
[2013/01/13 05:05:32 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdeploy.dll
[2013/01/13 05:05:32 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcico.dll
[2013/01/13 05:05:31 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PNPXAssoc.dll
[2013/01/13 05:05:30 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpupdate.exe
[2013/01/13 05:05:29 | 000,046,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrstub.exe
[2013/01/13 05:05:29 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cbsra.exe
[2013/01/13 05:05:29 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsigd.dll
[2013/01/13 05:05:29 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NcdProp.dll
[2013/01/13 05:05:29 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsilog.dll
[2013/01/13 05:05:28 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxg.sys
[2013/01/13 05:05:28 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcconf.dll
[2013/01/13 05:05:28 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdmdbg.dll
[2013/01/13 05:05:27 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2013/01/13 05:05:27 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetppui.dll
[2013/01/13 05:05:27 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2013/01/13 05:05:24 | 000,052,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\stream.sys
[2013/01/13 05:05:24 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2013/01/13 05:05:22 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/01/13 05:05:21 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\f3ahvoas.dll
[2013/01/13 05:05:21 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimsg.dll
[2013/01/13 05:04:56 | 000,705,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmiEngine.dll
[2013/01/13 05:04:48 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdscore.dll
[2013/01/13 05:04:48 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PkgMgr.exe
[2013/01/13 05:04:28 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvstore.dll
[2013/01/13 04:44:28 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/01/13 04:28:53 | 000,025,648 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\SymIMV.sys
[2013/01/13 03:26:39 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2013/01/13 03:26:38 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2013/01/13 03:26:38 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2013/01/12 07:43:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/01/11 15:51:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Wizard
[2013/01/11 15:51:10 | 000,000,000 | —D | C] – C:\Program Files\Driver Wizard
[2013/01/11 15:50:34 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Driver Wizard
[2013/01/11 15:24:52 | 000,232,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/01/11 14:51:46 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2013/01/10 19:00:43 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2013/01/10 18:48:09 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2013/01/10 18:40:27 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/10 18:37:45 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2013/01/10 18:37:28 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2013/01/10 18:37:28 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2013/01/10 18:37:28 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2013/01/10 18:37:25 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2013/01/10 18:37:25 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2013/01/10 18:37:21 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2013/01/10 18:37:21 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2013/01/10 18:37:21 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2013/01/10 18:37:21 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2013/01/10 18:37:20 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2013/01/10 18:37:11 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2013/01/10 18:37:10 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2013/01/10 18:37:10 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2013/01/10 18:37:09 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2013/01/10 18:37:08 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2013/01/10 18:29:02 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2013/01/10 18:29:00 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NETSTAT.EXE
[2013/01/10 18:28:59 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ARP.EXE
[2013/01/10 18:28:59 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\finger.exe
[2013/01/10 18:28:59 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\HOSTNAME.EXE
[2013/01/10 18:28:58 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ROUTE.EXE
[2013/01/10 18:28:58 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MRINFO.EXE
[2013/01/10 18:27:16 | 002,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2013/01/10 18:27:14 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rrinstaller.exe
[2013/01/10 18:27:14 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfpmp.exe
[2013/01/10 18:27:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mferror.dll
[2013/01/10 18:26:51 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2013/01/10 18:26:51 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\L2SecHC.dll
[2013/01/10 18:26:51 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanhlp.dll
[2013/01/10 18:26:50 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansec.dll
[2013/01/10 18:26:50 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanapi.dll
[2013/01/10 18:26:26 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2013/01/10 18:26:26 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2013/01/10 18:26:26 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2013/01/10 18:26:26 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2013/01/10 18:25:37 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2013/01/10 18:25:36 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2013/01/10 18:25:33 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2013/01/10 18:25:30 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2013/01/10 18:25:30 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2013/01/10 18:25:27 | 000,714,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2013/01/10 18:25:08 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2013/01/10 18:24:31 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2013/01/10 18:24:17 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asycfilt.dll
[2013/01/10 18:24:07 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2013/01/10 18:23:41 | 000,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2013/01/10 18:23:39 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2013/01/10 18:23:39 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2013/01/10 18:23:39 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2013/01/10 18:23:11 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2013/01/10 18:23:11 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2013/01/10 18:22:57 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2013/01/10 18:22:56 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2013/01/10 18:22:55 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2013/01/10 18:22:38 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2013/01/10 18:22:17 | 000,062,464 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2013/01/10 18:22:16 | 000,220,672 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codecp.acm
[2013/01/10 18:21:52 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2013/01/10 18:21:51 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2013/01/10 18:21:50 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2013/01/10 18:11:12 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2013/01/10 18:10:20 | 000,697,712 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/01/10 18:10:20 | 000,074,096 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/01/10 18:09:09 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.tlb
[2013/01/10 18:09:09 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amcompat.tlb
[2013/01/10 18:09:01 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2013/01/10 18:09:01 | 000,518,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2013/01/10 18:08:57 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2013/01/10 18:08:57 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2013/01/10 18:08:56 | 000,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2013/01/10 18:08:55 | 000,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2013/01/10 18:08:54 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2013/01/10 18:08:54 | 000,152,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2013/01/10 18:08:54 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2013/01/10 18:07:19 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/01/10 18:07:19 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tscupgrd.exe
[2013/01/10 18:07:19 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/01/10 18:06:42 | 000,355,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2013/01/10 18:06:04 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2013/01/10 18:05:21 | 000,310,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unregmp2.exe
[2013/01/10 18:04:00 | 000,604,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOD.DLL
[2013/01/10 16:51:30 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Macromedia
[2013/01/10 16:51:09 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Adobe
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/09 11:22:02 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/09 11:20:01 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/09 10:45:29 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\cockrell\Desktop\aswMBR.exe
[2013/02/09 10:43:36 | 000,547,275 | —- | M] (Oleg N. Scherbakov) – C:\Users\cockrell\Desktop\JRT.exe
[2013/02/09 10:20:07 | 002,194,612 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\Cat.DB
[2013/02/09 09:45:11 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/09 09:45:11 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/09 09:44:58 | 000,032,156 | —- | M] () – C:\ProgramData\nvModes.dat
[2013/02/09 09:44:58 | 000,032,156 | —- | M] () – C:\ProgramData\nvModes.001
[2013/02/09 09:44:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/08 20:20:03 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/08 17:47:15 | 000,625,664 | —- | M] () – C:\Users\cockrell\Desktop\dds.scr
[2013/02/08 17:45:53 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\cockrell\Desktop\HiJackThis.exe
[2013/02/08 17:32:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\cockrell\Desktop\OTL.exe
[2013/02/08 17:24:25 | 000,477,616 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 17:24:24 | 000,473,520 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 17:06:45 | 1877,327,872 | -HS- | M] () – C:\hiberfil.sys
[2013/02/08 16:59:18 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\cockrell\Desktop\ATF-Cleaner.exe
[2013/02/07 19:23:15 | 000,697,712 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/02/07 19:23:15 | 000,074,096 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/02/07 19:01:26 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/02/07 19:01:26 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/02/07 18:26:17 | 000,000,943 | —- | M] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/02/07 18:21:14 | 000,314,048 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/02/07 18:15:46 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2013/02/07 18:15:34 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013/02/06 20:19:00 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2013/02/06 20:19:00 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2013/02/06 20:18:45 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/02/06 20:18:44 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/02/06 20:18:44 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/02/06 20:18:44 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/02/06 20:18:43 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/02/06 20:18:43 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/02/06 20:18:43 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/02/06 20:18:43 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/02/06 20:18:42 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/02/06 20:18:42 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/02/06 20:18:42 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/02/06 20:18:41 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/02/06 20:18:41 | 001,427,968 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/02/06 20:18:41 | 000,607,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/02/06 20:18:41 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/02/06 20:18:41 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/02/06 20:18:41 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/02/06 20:18:41 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/02/06 20:18:41 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/02/06 20:18:41 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/02/06 20:18:41 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/02/06 20:18:41 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/02/06 20:18:41 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/02/06 20:18:41 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/02/06 20:18:41 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/02/06 20:18:40 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/02/06 20:18:40 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2013/02/06 20:18:40 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2013/02/06 20:18:40 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/02/06 20:18:40 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2013/02/06 20:18:40 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/02/06 20:18:39 | 001,800,704 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/02/06 20:18:39 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2013/02/06 20:18:39 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/02/06 20:18:39 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/02/06 20:18:39 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/02/06 20:18:39 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/02/06 20:18:39 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/02/06 20:16:17 | 000,979,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2013/02/06 20:16:17 | 000,357,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2013/02/06 20:16:16 | 000,302,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2013/02/06 20:16:13 | 002,873,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2013/02/06 20:16:13 | 000,261,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2013/02/06 20:16:13 | 000,209,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2013/02/06 20:16:13 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2013/02/06 20:16:11 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2013/02/06 20:16:10 | 001,029,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/02/06 20:16:10 | 000,486,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/02/06 20:16:10 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/02/06 20:16:10 | 000,189,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/02/06 20:16:09 | 001,554,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2013/02/06 20:16:09 | 000,847,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2013/02/06 20:16:09 | 000,667,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2013/02/06 20:16:09 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2013/02/06 20:16:09 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2013/02/06 20:14:52 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\dxgkrnl.sys.mui
[2013/02/06 20:14:51 | 000,519,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/02/06 20:14:51 | 000,369,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/02/06 20:14:51 | 000,321,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2013/02/06 20:14:51 | 000,252,928 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2013/02/06 20:14:51 | 000,195,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2013/02/06 20:14:51 | 000,189,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/02/04 21:28:04 | 000,000,009 | —- | M] () – C:\END
[2013/02/04 18:49:28 | 000,000,246 | —- | M] () – C:\ProgramData\hpqp.ini
[2013/02/03 18:24:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/31 21:47:33 | 000,034,253 | —- | M] () – C:\Users\cockrell\Desktop\ken and rhonda phone pics 013113 076.jpg
[2013/01/31 21:27:12 | 000,001,971 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/01/30 20:44:49 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motoandroid_01007.Wdf
[2013/01/28 17:07:09 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motfilt_01007.Wdf
[2013/01/28 17:07:07 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motccgp_01007.Wdf
[2013/01/28 17:05:42 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf
[2013/01/27 22:59:03 | 000,000,865 | —- | M] () – C:\net_save.dna
[2013/01/25 12:51:34 | 000,001,995 | —- | M] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/23 20:45:36 | 000,075,356 | —- | M] () – C:\Users\cockrell\AppData\Roaming\userenv.xml.urlencode
[2013/01/23 20:45:36 | 000,056,742 | —- | M] () – C:\Users\cockrell\AppData\Roaming\userenv.xml
[2013/01/23 20:24:17 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/01/23 16:24:20 | 001,242,112 | —- | M] (Microsoft Corporation) – C:\Users\cockrell\Desktop\wlsetup-web.exe
[2013/01/17 01:28:58 | 000,232,336 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/01/13 04:28:26 | 000,002,204 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2013/01/12 09:10:53 | 000,467,592 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\NIS\1008030.006\cchpx86.sys
[2013/01/12 09:10:43 | 000,000,172 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\isolate.ini
[2013/01/11 17:41:33 | 000,006,144 | —- | M] () – C:\Users\cockrell\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/11 16:16:53 | 000,124,976 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2013/01/11 16:16:53 | 000,007,456 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2013/01/11 16:16:53 | 000,000,806 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2013/01/11 16:14:34 | 000,009,412 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\symnetv.cat
[2013/01/11 16:14:34 | 000,001,562 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\SymNetV.inf
[2013/01/11 15:51:19 | 000,000,859 | —- | M] () – C:\Users\cockrell\Desktop\Driver Wizard.lnk
[2013/01/11 15:35:22 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/08 17:46:58 | 000,625,664 | —- | C] () – C:\Users\cockrell\Desktop\dds.scr
[2013/02/07 22:06:05 | 1877,327,872 | -HS- | C] () – C:\hiberfil.sys
[2013/02/07 18:15:46 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2013/02/07 18:15:34 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013/02/06 20:18:41 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/02/06 19:50:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/02/06 19:50:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/02/04 21:28:33 | 000,010,844 | —- | C] () – C:\Windows\System32\athrext.cat
[2013/02/04 21:28:33 | 000,006,483 | —- | C] () – C:\Windows\System32\netathr.inf
[2013/02/04 21:26:12 | 000,000,009 | —- | C] () – C:\END
[2013/02/03 18:24:40 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/31 21:48:54 | 000,034,253 | —- | C] () – C:\Users\cockrell\Desktop\ken and rhonda phone pics 013113 076.jpg
[2013/01/30 20:44:49 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motoandroid_01007.Wdf
[2013/01/28 17:07:09 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motfilt_01007.Wdf
[2013/01/28 17:07:07 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motccgp_01007.Wdf
[2013/01/28 17:05:42 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf
[2013/01/27 22:59:03 | 000,000,865 | —- | C] () – C:\net_save.dna
[2013/01/23 20:45:36 | 000,075,356 | —- | C] () – C:\Users\cockrell\AppData\Roaming\userenv.xml.urlencode
[2013/01/23 20:45:36 | 000,056,742 | —- | C] () – C:\Users\cockrell\AppData\Roaming\userenv.xml
[2013/01/23 20:18:08 | 000,001,995 | —- | C] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/23 20:18:08 | 000,001,971 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/01/23 20:15:56 | 000,000,890 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/23 20:15:55 | 000,000,886 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/13 05:07:29 | 000,130,008 | —- | C] () – C:\Windows\System32\systemsf.ebd
[2013/01/13 05:07:26 | 000,009,239 | —- | C] () – C:\Windows\System32\spcinstrumentation.man
[2013/01/13 05:07:13 | 000,442,788 | —- | C] () – C:\Windows\System32\dot3.tmf
[2013/01/13 05:07:11 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2013/01/13 05:07:11 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2013/01/13 05:07:07 | 000,392,170 | —- | C] () – C:\Windows\System32\onex.tmf
[2013/01/13 05:07:01 | 000,344,698 | —- | C] () – C:\Windows\System32\eaphost.tmf
[2013/01/13 05:06:37 | 000,208,966 | —- | C] () – C:\Windows\System32\WFP.TMF
[2013/01/13 05:06:34 | 000,092,918 | —- | C] () – C:\Windows\System32\slmgr.vbs
[2013/01/13 05:05:27 | 000,009,212 | —- | C] () – C:\Windows\System32\RacUR.xml
[2013/01/11 17:36:57 | 000,006,144 | —- | C] () – C:\Users\cockrell\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/11 15:51:19 | 000,000,859 | —- | C] () – C:\Users\cockrell\Desktop\Driver Wizard.lnk
[2013/01/11 15:35:22 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2013/01/11 14:47:35 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2013/01/10 20:46:50 | 000,032,156 | —- | C] () – C:\ProgramData\nvModes.001
[2013/01/10 20:46:29 | 000,032,156 | —- | C] () – C:\ProgramData\nvModes.dat
[2013/01/10 18:37:13 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2013/01/10 18:37:13 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2013/01/10 18:37:13 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2013/01/10 18:26:52 | 002,501,921 | —- | C] () – C:\Windows\System32\wlan.tmf
[2013/01/10 18:10:29 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/10 16:46:35 | 000,000,943 | —- | C] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/08 07:58:44 | 000,000,246 | —- | C] () – C:\ProgramData\hpqp.ini
[2013/01/08 07:49:27 | 000,011,164 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin

========== ZeroAccess Check ==========

[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 01:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/11 15:51:30 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\Driver Wizard
[2013/01/28 17:05:55 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\Motorola
[2013/01/23 20:45:42 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\spotmau

========== Purity Check ==========



< End of report >
Thank you for the logs.

The aswMBR log is incomplete. You'll find the log here:

C:\Users\cockrell\Desktop\aswMBR.txt

Please copy and paste it in you reply.

===================================

when I opend Chrome up again MixiDJ Toolbar reinstalled

Unfortunately, the easiest way to do get rid of bad entries and plugins with Google Chrome is to uninstall and re-install it.
.
Uninstall Chrome and, if asked about user data or settings, remove those also.

Restart the computer and re-install Chrome.

Please send the aswMBR log.

I will look at your OTL log later and reply as soon as I can.

Satchfan
Sorry for the mixup. Here is attempt 2. aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-02-09 11:12:27 —————————– 11:12:27.059 OS Version: Windows 6.0.6002 Service Pack 2 11:12:27.059 Number of processors: 2 586 0x301 11:12:27.059 ComputerName: COCKRELL-PC UserName: cockrell 11:12:33.657 Initialize success 11:14:55.683 AVAST engine defs: 13020900 11:18:18.413 The log file has been saved successfully to "C:\Users\cockrell\Desktop\aswMBR.txt" aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-02-09 14:32:32 —————————– 14:32:32.448 OS Version: Windows 6.0.6002 Service Pack 2 14:32:32.448 Number of processors: 2 586 0x301 14:32:32.448 ComputerName: COCKRELL-PC UserName: cockrell 14:32:34.461 Initialize success 14:32:46.052 The log file has been saved successfully to "C:\Users\cockrell\Desktop\aswMBR.txt" aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-02-09 14:32:32 —————————– 14:32:32.448 OS Version: Windows 6.0.6002 Service Pack 2 14:32:32.448 Number of processors: 2 586 0x301 14:32:32.448 ComputerName: COCKRELL-PC UserName: cockrell 14:32:34.461 Initialize success 14:32:46.052 The log file has been saved successfully to "C:\Users\cockrell\Desktop\aswMBR.txt" 14:33:04.044 AVAST engine defs: 13020900 14:33:07.288 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-5 14:33:07.288 Disk 0 Vendor: ST9250320AS HP07 Size: 238475MB BusType: 3 14:33:07.304 Disk 0 MBR read successfully 14:33:07.304 Disk 0 MBR scan 14:33:07.320 Disk 0 unknown MBR code 14:33:07.335 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 227333 MB offset 63 14:33:07.382 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 11138 MB offset 465580032 14:33:07.429 Disk 0 scanning sectors +488390656 14:33:07.694 Disk 0 scanning C:\Windows\system32\drivers 14:33:45.493 Service scanning 14:34:45.199 Modules scanning 14:35:05.757 Disk 0 trace - called modules: 14:35:06.196 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys ndis.sys nvmfdx32.sys dxgkrnl.sys nvlddmkm.sys athr.sys tcpip.sys NETIO.SYS SynTP.sys 14:35:06.204 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85630838] 14:35:06.211 3 CLASSPNP.SYS[8079d8b3] -> nt!IofCallDriver -> [0x844d25e8] 14:35:06.218 5 acpi.sys[8060a6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-5[0x8407a8a0] 14:35:07.845 AVAST engine scan C:\Windows 14:35:12.899 AVAST engine scan C:\Windows\system32 14:42:05.417 AVAST engine scan C:\Windows\system32\drivers 14:42:36.056 AVAST engine scan C:\Users\cockrell 14:45:19.653 AVAST engine scan C:\ProgramData 14:47:29.086 Scan finished successfully 14:49:55.523 Disk 0 MBR has been saved successfully to "C:\Users\cockrell\Desktop\MBR.dat" 14:49:55.523 The log file has been saved successfully to "C:\Users\cockrell\Desktop\aswMBR.txt"
Please uninstall Chrome as I previously suggested.


Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\..\SearchScopes\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE - HKLM\..\SearchScopes\{60A4E56C-445B-47E9-8637-F329433B1DB3}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPNTDF
    IE - HKCU\..\SearchScopes\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE - HKCU\..\SearchScopes\{60A4E56C-445B-47E9-8637-F329433B1DB3}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
    CHR - homepage: http://search.conduit.com/?CUI=UN132945277…SearchSource=48
    CHR - default_search_provider: Conduit (Enabled)
    CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…;ctid=CT3272718
    CHR - homepage: http://search.conduit.com/?CUI=UN132945277…SearchSource=48
    CHR - Extension: MixiDJ = C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbofibgamhkgoonaocfgemncghhadmgb\10.14.251.3_0\
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post the OTL fix log and a new OTL log AFTER you have uninstalled Chrome
Can you tell me how your computer is now.

Thanks

Satchfan
I previously removed and reinstalled Chrome as per your instruction. It has been removed again.

For the moment, things seem to be running better.


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{60A4E56C-445B-47E9-8637-F329433B1DB3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60A4E56C-445B-47E9-8637-F329433B1DB3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FA204D4-5326-43C7-A4D2-EDFB78E6EA59}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{60A4E56C-445B-47E9-8637-F329433B1DB3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60A4E56C-445B-47E9-8637-F329433B1DB3}\ not found.
Use Chrome's Settings page to change the HomePage.
Use Chrome's Settings page to remove the default_search_provider items.
Use Chrome's Settings page to remove the default_search_provider items.
Use Chrome's Settings page to change the HomePage.
File C:\Users\cockrell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbofibgamhkgoonaocfgemncghhadmgb\10.14.251.3_0 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: cockrell
->Temp folder emptied: 84531297 bytes
->Temporary Internet Files folder emptied: 128231682 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 27525 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2582 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 544224 bytes

Total Files Cleaned = 203.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 02102013_100742

Files\Folders moved on Reboot…
File\Folder C:\Windows\temp\JET2818.tmp not found!

PendingFileRenameOperations files…

Registry entries deleted on Reboot…


OTL logfile created on: 2/10/2013 10:26:16 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\cockrell\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.75 Gb Total Physical Memory | 0.91 Gb Available Physical Memory | 51.86% Memory free
3.74 Gb Paging File | 2.90 Gb Available in Paging File | 77.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.01 Gb Total Space | 165.91 Gb Free Space | 74.73% Space Free | Partition Type: NTFS
Drive D: | 10.88 Gb Total Space | 1.78 Gb Free Space | 16.33% Space Free | Partition Type: NTFS
Drive E: | 76.08 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: COCKRELL-PC | User Name: cockrell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\cockrell\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil32_11_5_502_149_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\AdobeXMP.dll ()
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll ()
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe (Symantec Corporation)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SYMREDRV) – C:\Windows\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS File not found
DRV - (SYMDNS) – C:\Windows\system32\drivers\NIS\1000000.07D\SYMDNS.SYS File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (ccHP) – C:\Windows\System32\drivers\NIS\1008030.006\cchpx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20130208.004\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130209.009\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130209.009\NAVENG.SYS (Symantec Corporation)
DRV - (Motousbnet) – C:\Windows\System32\drivers\Motousbnet.sys (Motorola Mobility Inc)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola Mobility Inc)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola Mobility Inc)
DRV - (motusbdevice) – C:\Windows\System32\drivers\motusbdevice.sys (Motorola Inc)
DRV - (SYMTDI) – C:\Windows\System32\drivers\NIS\1008030.006\symtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\drivers\NIS\1008030.006\symfw.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\drivers\NIS\1008030.006\symndisv.sys (Symantec Corporation)
DRV - (NVNET) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1008030.006\SymEFA.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1008030.006\srtsp.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Windows\System32\drivers\NIS\1008030.006\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1008030.006\srtspx.sys (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (motandroidusb) – C:\Windows\System32\drivers\motoandroid.sys (Motorola)
DRV - (BTCFilterService) – C:\Windows\System32\drivers\motfilt.sys (Motorola Inc)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (NETw3v32) – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (MotoSwitchService) – C:\Windows\System32\drivers\motswch.sys (Motorola)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2013/01/13 04:29:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi

[2013/02/09 10:07:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla FireFox\extensions

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{89015AC8-32D1-421A-96CE-7C4B155793AF}: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/04/03 09:05:10 | 000,000,052 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7f8662fd-5c29-11e2-96e8-001f166ee388}\Shell - "" = AutoRun
O33 - MountPoints2\{7f8662fd-5c29-11e2-96e8-001f166ee388}\Shell\AutoRun\command - "" = F:\setup.exe -a
O33 - MountPoints2\{82d180e4-5994-11e2-96df-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{82d180e4-5994-11e2-96df-806e6f6e6963}\Shell\AutoRun\command - "" = E:\install.exe – [2007/04/24 11:59:07 | 001,074,768 | R— | M] (SupportSoft, Inc.)
O33 - MountPoints2\{ba158ed1-6993-11e2-ab6d-001f166ee388}\Shell - "" = AutoRun
O33 - MountPoints2\{ba158ed1-6993-11e2-ab6d-001f166ee388}\Shell\AutoRun\command - "" = F:\setup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/10 10:07:42 | 000,000,000 | —D | C] – C:\_OTL
[2013/02/09 10:59:19 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/09 10:59:04 | 000,000,000 | —D | C] – C:\JRT
[2013/02/09 10:44:05 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\cockrell\Desktop\aswMBR.exe
[2013/02/09 10:42:30 | 000,547,275 | —- | C] (Oleg N. Scherbakov) – C:\Users\cockrell\Desktop\JRT.exe
[2013/02/08 17:45:01 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\cockrell\Desktop\HiJackThis.exe
[2013/02/08 17:43:00 | 000,000,000 | -HSD | C] – C:\AI_RecycleBin
[2013/02/08 17:32:02 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\cockrell\Desktop\OTL.exe
[2013/02/08 17:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/02/08 17:25:59 | 000,477,616 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 17:25:59 | 000,473,520 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 16:59:18 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\cockrell\Desktop\ATF-Cleaner.exe
[2013/02/08 16:50:48 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2013/02/07 19:22:20 | 000,758,784 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\cohelper.dll
[2013/02/07 19:22:18 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2013/02/07 18:47:14 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/02/07 18:47:11 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/02/07 18:47:11 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/02/07 18:47:10 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/02/07 18:47:10 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/02/07 18:47:10 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/02/07 18:16:29 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2013/02/06 20:46:08 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/02/06 20:46:06 | 003,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2013/02/06 20:46:06 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2013/02/06 20:43:31 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BthMtpContextHandler.dll
[2013/02/06 20:43:31 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShextAutoplay.exe
[2013/02/06 20:43:26 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceConnectApi.dll
[2013/02/06 20:43:22 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdMtpUS.dll
[2013/02/06 20:43:22 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdConns.dll
[2013/02/06 20:43:21 | 000,546,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2013/02/06 20:43:21 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WpdMtp.dll
[2013/02/06 20:43:20 | 000,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2013/02/06 20:43:20 | 000,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2013/02/06 20:43:20 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWMDRM.dll
[2013/02/06 20:43:20 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2013/02/06 20:43:20 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2013/02/06 20:18:45 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/02/06 20:18:44 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/02/06 20:18:44 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/02/06 20:18:44 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/02/06 20:18:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/02/06 20:18:43 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/02/06 20:18:43 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/02/06 20:18:43 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/02/06 20:18:42 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/02/06 20:18:42 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/02/06 20:18:42 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/02/06 20:18:41 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/02/06 20:18:41 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/02/06 20:18:41 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/02/06 20:18:41 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/02/06 20:18:41 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/02/06 20:18:41 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/02/06 20:18:41 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/02/06 20:18:41 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/02/06 20:18:41 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/02/06 20:18:41 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/02/06 20:18:41 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/02/06 20:18:41 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/02/06 20:18:41 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/02/06 20:18:40 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/02/06 20:18:40 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2013/02/06 20:18:40 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2013/02/06 20:18:40 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/02/06 20:18:40 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2013/02/06 20:18:40 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/02/06 20:18:39 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/02/06 20:18:39 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2013/02/06 20:18:39 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/02/06 20:18:39 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/02/06 20:18:39 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/02/06 20:18:39 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/02/06 20:18:39 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/02/06 20:16:17 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2013/02/06 20:16:17 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2013/02/06 20:16:16 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2013/02/06 20:16:13 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2013/02/06 20:16:13 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2013/02/06 20:16:13 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2013/02/06 20:16:13 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2013/02/06 20:16:11 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2013/02/06 20:16:10 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/02/06 20:16:10 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/02/06 20:16:10 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/02/06 20:16:10 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/02/06 20:16:09 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2013/02/06 20:16:09 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2013/02/06 20:16:09 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2013/02/06 20:16:09 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2013/02/06 20:16:09 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2013/02/06 20:14:51 | 000,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/02/06 20:14:51 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/02/06 20:14:51 | 000,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2013/02/06 20:14:51 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2013/02/06 20:14:51 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2013/02/06 20:14:51 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/02/06 19:50:02 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2013/02/06 19:49:54 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2013/02/06 19:49:54 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winusb.dll
[2013/02/06 19:49:51 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2013/02/06 19:49:47 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2013/02/06 19:49:46 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2013/02/06 19:37:57 | 000,293,376 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2013/02/06 19:37:57 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2013/02/06 18:20:14 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2013/02/06 18:20:13 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2013/02/06 18:20:13 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2013/02/06 18:20:13 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2013/02/06 18:20:00 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciseq.dll
[2013/02/06 18:17:38 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\synceng.dll
[2013/02/06 18:17:30 | 002,048,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/02/06 18:17:27 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2013/02/06 18:16:44 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2013/02/06 18:16:44 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnsvr.exe
[2013/02/06 18:15:55 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/02/06 18:15:41 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2013/02/06 18:13:08 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2013/02/06 18:12:46 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/02/06 18:11:07 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/02/06 18:10:43 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/02/06 18:10:40 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2013/02/06 18:10:39 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2013/02/06 18:10:06 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2013/02/06 18:10:06 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaccrc.dll
[2013/02/06 18:06:28 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2013/02/06 18:06:20 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/02/06 18:06:20 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/02/06 17:31:30 | 000,613,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2013/02/05 20:51:43 | 002,422,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2013/02/05 20:51:43 | 000,045,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2013/02/05 20:50:56 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2013/02/05 20:50:56 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2013/02/05 20:50:56 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2013/02/05 20:50:26 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2013/02/05 20:50:26 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2013/02/04 21:28:32 | 000,735,232 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\drivers\athr.sys
[2013/02/04 21:28:32 | 000,735,232 | —- | C] (Atheros Communications, Inc.) – C:\Windows\System32\athr.sys
[2013/02/04 21:28:32 | 000,000,000 | —D | C] – C:\Windows\Options
[2013/02/04 21:27:26 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\CRE
[2013/02/04 21:26:17 | 000,000,000 | —D | C] – C:\Program Files\Mozilla FireFox
[2013/02/04 20:55:01 | 000,000,000 | —D | C] – C:\ProgramData\PCPitstop
[2013/02/04 20:55:00 | 000,000,000 | —D | C] – C:\Program Files\PCPitstop
[2013/02/04 18:31:05 | 000,000,000 | —D | C] – C:\Windows\System32\eu-ES
[2013/02/04 18:31:05 | 000,000,000 | —D | C] – C:\Windows\System32\ca-ES
[2013/02/04 18:31:04 | 000,000,000 | —D | C] – C:\Windows\System32\vi-VN
[2013/02/03 18:24:56 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Malwarebytes
[2013/02/03 18:24:38 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/02/03 18:24:35 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/02/03 18:24:34 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/28 17:05:55 | 000,000,000 | —D | C] – C:\Temp
[2013/01/28 17:05:55 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Motorola
[2013/01/28 16:52:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Motorola Shared
[2013/01/28 16:51:59 | 000,000,000 | —D | C] – C:\Program Files\Motorola
[2013/01/27 22:58:29 | 000,000,000 | —D | C] – C:\Program Files\support.com
[2013/01/27 22:58:25 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\SupportSoft
[2013/01/27 22:57:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SupportSoft
[2013/01/23 20:45:42 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\spotmau
[2013/01/23 20:44:07 | 000,000,000 | —D | C] – C:\ProgramData\TuneUp360
[2013/01/23 20:15:47 | 000,000,000 | —D | C] – C:\Program Files\Google
[2013/01/23 20:15:37 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Google
[2013/01/23 20:14:36 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Deployment
[2013/01/23 20:14:36 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Local\Apps
[2013/01/23 16:24:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2013/01/23 16:24:17 | 001,242,112 | —- | C] (Microsoft Corporation) – C:\Users\cockrell\Desktop\wlsetup-web.exe
[2013/01/23 16:03:53 | 000,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2013/01/13 05:08:19 | 012,240,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0007.dll
[2013/01/13 05:08:15 | 001,081,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCExt.dll
[2013/01/13 05:08:12 | 000,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingWizard.exe
[2013/01/13 05:08:11 | 002,134,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FunctionDiscoveryFolder.dll
[2013/01/13 05:08:08 | 002,644,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0009.dll
[2013/01/13 05:08:05 | 001,480,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2013/01/13 05:08:02 | 000,684,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\spsys.sys
[2013/01/13 05:08:01 | 001,576,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2013/01/13 05:08:00 | 000,779,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2013/01/13 05:07:59 | 000,928,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scavenge.dll
[2013/01/13 05:07:57 | 000,677,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2fs.dll
[2013/01/13 05:07:56 | 000,291,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WscEapPr.dll
[2013/01/13 05:07:55 | 000,968,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz2.dll
[2013/01/13 05:07:53 | 000,619,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2013/01/13 05:07:52 | 001,216,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2013/01/13 05:07:50 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spinstall.exe
[2013/01/13 05:07:50 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spreview.exe
[2013/01/13 05:07:49 | 000,978,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmv2clt.dll
[2013/01/13 05:07:48 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizui.dll
[2013/01/13 05:07:47 | 000,438,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcupdate_GenuineIntel.dll
[2013/01/13 05:07:45 | 000,670,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2013/01/13 05:07:43 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2VDEC.DLL
[2013/01/13 05:07:43 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2.dll
[2013/01/13 05:07:43 | 000,351,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2013/01/13 05:07:43 | 000,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2013/01/13 05:07:42 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2013/01/13 05:07:41 | 000,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10K.DLL
[2013/01/13 05:07:40 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairing.dll
[2013/01/13 05:07:39 | 000,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sperror.dll
[2013/01/13 05:07:39 | 000,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\korwbrkr.dll
[2013/01/13 05:07:38 | 000,463,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IasMigReader.exe
[2013/01/13 05:07:36 | 001,589,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjet40.dll
[2013/01/13 05:07:33 | 000,883,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10.IME
[2013/01/13 05:07:33 | 000,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexch40.dll
[2013/01/13 05:07:32 | 001,078,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diagperf.dll
[2013/01/13 05:07:32 | 000,327,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\P2PGraph.dll
[2013/01/13 05:07:31 | 000,986,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2013/01/13 05:07:31 | 000,950,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mblctr.exe
[2013/01/13 05:07:31 | 000,301,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srchadmin.dll
[2013/01/13 05:07:30 | 001,792,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmc.exe
[2013/01/13 05:07:30 | 000,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uDWM.dll
[2013/01/13 05:07:29 | 000,454,144 | —- | C] (Microsoft) – C:\Windows\System32\IasMigPlugin.dll
[2013/01/13 05:07:29 | 000,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBth.dll
[2013/01/13 05:07:28 | 000,880,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RacEngn.dll
[2013/01/13 05:07:26 | 002,012,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\milcore.dll
[2013/01/13 05:07:26 | 001,112,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2013/01/13 05:07:26 | 000,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorAPI.dll
[2013/01/13 05:07:25 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2013/01/13 05:07:24 | 000,950,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpedit.dll
[2013/01/13 05:07:24 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjtes40.dll
[2013/01/13 05:07:24 | 000,115,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayDriverLib.dll
[2013/01/13 05:07:24 | 000,099,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2013/01/13 05:07:23 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSAT.exe
[2013/01/13 05:07:22 | 000,710,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Magnify.exe
[2013/01/13 05:07:22 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationSettings.exe
[2013/01/13 05:07:22 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayServices.dll
[2013/01/13 05:07:21 | 000,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstext40.dll
[2013/01/13 05:07:18 | 000,454,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxbde40.dll
[2013/01/13 05:07:18 | 000,339,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexcl40.dll
[2013/01/13 05:07:18 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwmi.dll
[2013/01/13 05:07:17 | 001,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsAnytimeUpgradeCPL.dll
[2013/01/13 05:07:16 | 001,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2013/01/13 05:07:16 | 001,086,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NetProjW.dll
[2013/01/13 05:07:15 | 000,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrepl40.dll
[2013/01/13 05:07:15 | 000,640,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthprops.cpl
[2013/01/13 05:07:14 | 000,469,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.dll
[2013/01/13 05:07:14 | 000,205,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eudcedit.exe
[2013/01/13 05:07:14 | 000,119,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2013/01/13 05:07:14 | 000,102,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2013/01/13 05:07:13 | 002,926,592 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/01/13 05:07:12 | 001,788,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d9.dll
[2013/01/13 05:07:12 | 000,368,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mspbde40.dll
[2013/01/13 05:07:11 | 000,241,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msltus40.dll
[2013/01/13 05:07:11 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorPwdMgr.dll
[2013/01/13 05:07:10 | 001,053,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtctm.dll
[2013/01/13 05:07:10 | 000,344,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd3x40.dll
[2013/01/13 05:07:09 | 000,250,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtapi.dll
[2013/01/13 05:07:09 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlhtml.dll
[2013/01/13 05:07:07 | 000,614,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2013/01/13 05:07:06 | 000,582,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCommDlg.dll
[2013/01/13 05:07:06 | 000,165,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WcnNetsh.dll
[2013/01/13 05:07:05 | 001,730,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apds.dll
[2013/01/13 05:07:05 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\compcln.exe
[2013/01/13 05:07:04 | 000,618,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswstr10.dll
[2013/01/13 05:07:03 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xmlfilter.dll
[2013/01/13 05:07:01 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUI.exe
[2013/01/13 05:07:01 | 000,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapphost.dll
[2013/01/13 05:07:00 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlsrv32.dll
[2013/01/13 05:07:00 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd2x40.dll
[2013/01/13 05:06:59 | 000,926,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2013/01/13 05:06:59 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propdefs.dll
[2013/01/13 05:06:58 | 001,856,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbgeng.dll
[2013/01/13 05:06:58 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtutil.exe
[2013/01/13 05:06:57 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssitlb.dll
[2013/01/13 05:06:56 | 002,167,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcndmgr.dll
[2013/01/13 05:06:54 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\devmgr.dll
[2013/01/13 05:06:54 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvinst.exe
[2013/01/13 05:06:54 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscb.dll
[2013/01/13 05:06:54 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBthProxy.dll
[2013/01/13 05:06:53 | 000,485,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\evr.dll
[2013/01/13 05:06:53 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingProxy.dll
[2013/01/13 05:06:52 | 001,533,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz.dll
[2013/01/13 05:06:52 | 001,382,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVSDECD.DLL
[2013/01/13 05:06:51 | 001,143,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wercon.exe
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quick.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qintlgnt.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\phon.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cintlgnt.ime
[2013/01/13 05:06:51 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chajei.ime
[2013/01/13 05:06:50 | 000,617,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adtschema.dll
[2013/01/13 05:06:50 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mimefilt.dll
[2013/01/13 05:06:49 | 000,856,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswdat10.dll
[2013/01/13 05:06:49 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2013/01/13 05:06:49 | 000,396,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsmsnap.dll
[2013/01/13 05:06:49 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjter40.dll
[2013/01/13 05:06:48 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\reg.exe
[2013/01/13 05:06:48 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtffilt.dll
[2013/01/13 05:06:46 | 000,799,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/01/13 05:06:46 | 000,035,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2013/01/13 05:06:45 | 000,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2013/01/13 05:06:44 | 000,704,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2013/01/13 05:06:44 | 000,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcrypt.dll
[2013/01/13 05:06:44 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2013/01/13 05:06:43 | 000,060,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2013/01/13 05:06:43 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshooks.dll
[2013/01/13 05:06:42 | 000,332,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msihnd.dll
[2013/01/13 05:06:42 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MMDevAPI.dll
[2013/01/13 05:06:42 | 000,035,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsWpfWrp.exe
[2013/01/13 05:06:41 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msstrc.dll
[2013/01/13 05:06:40 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fundisc.dll
[2013/01/13 05:06:39 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2013/01/13 05:06:39 | 000,080,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2013/01/13 05:06:37 | 001,020,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdc.dll
[2013/01/13 05:06:37 | 000,125,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Classpnp.sys
[2013/01/13 05:06:37 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi.dll
[2013/01/13 05:06:36 | 001,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chsbrkr.dll
[2013/01/13 05:06:36 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassdo.dll
[2013/01/13 05:06:36 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Kswdmcap.ax
[2013/01/13 05:06:35 | 001,823,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnidui.dll
[2013/01/13 05:06:35 | 000,636,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autofmt.exe
[2013/01/13 05:06:35 | 000,009,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2013/01/13 05:06:34 | 000,122,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Storport.sys
[2013/01/13 05:06:34 | 000,109,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ataport.sys
[2013/01/13 05:06:34 | 000,050,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PSHED.DLL
[2013/01/13 05:06:34 | 000,035,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\crashdmp.sys
[2013/01/13 05:06:33 | 000,757,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroles.dll
[2013/01/13 05:06:33 | 000,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnrollUI.dll
[2013/01/13 05:06:32 | 001,107,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pidgenx.dll
[2013/01/13 05:06:32 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmon.ocx
[2013/01/13 05:06:31 | 002,205,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SyncCenter.dll
[2013/01/13 05:06:30 | 001,502,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certmgr.dll
[2013/01/13 05:06:30 | 000,627,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sethc.exe
[2013/01/13 05:06:30 | 000,593,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comuid.dll
[2013/01/13 05:06:30 | 000,017,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kd1394.dll
[2013/01/13 05:06:29 | 000,324,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\untfs.dll
[2013/01/13 05:06:29 | 000,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassam.dll
[2013/01/13 05:06:29 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrobj.dll
[2013/01/13 05:06:28 | 000,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imkr80.ime
[2013/01/13 05:06:28 | 000,099,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/01/13 05:06:28 | 000,043,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pciidex.sys
[2013/01/13 05:06:27 | 000,656,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoconv.exe
[2013/01/13 05:06:27 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasnap.dll
[2013/01/13 05:06:26 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscript.exe
[2013/01/13 05:06:26 | 000,027,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Dumpata.sys
[2013/01/13 05:06:25 | 000,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wow32.dll
[2013/01/13 05:06:25 | 000,130,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basecsp.dll
[2013/01/13 05:06:25 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiodg.exe
[2013/01/13 05:06:25 | 000,017,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdcom.dll
[2013/01/13 05:06:24 | 000,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\osk.exe
[2013/01/13 05:06:23 | 000,019,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdusb.dll
[2013/01/13 05:06:22 | 000,340,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RelMon.dll
[2013/01/13 05:06:22 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spcmsg.dll
[2013/01/13 05:06:20 | 000,860,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFaultSecure.exe
[2013/01/13 05:06:20 | 000,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2013/01/13 05:06:20 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\offfilt.dll
[2013/01/13 05:06:19 | 000,638,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Utilman.exe
[2013/01/13 05:06:18 | 000,230,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskraid.exe
[2013/01/13 05:06:18 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
[2013/01/13 05:06:18 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsepno.dll
[2013/01/13 05:06:17 | 000,852,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2013/01/13 05:06:17 | 000,391,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscms.dll
[2013/01/13 05:06:17 | 000,197,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SndVol.exe
[2013/01/13 05:06:17 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msnetobj.dll
[2013/01/13 05:06:16 | 000,551,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prnntfy.dll
[2013/01/13 05:06:16 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2013/01/13 05:06:16 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysclass.dll
[2013/01/13 05:06:16 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ulib.dll
[2013/01/13 05:06:16 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsmsext.dll
[2013/01/13 05:06:16 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2013/01/13 05:06:15 | 000,444,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsound.dll
[2013/01/13 05:06:14 | 000,223,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscntfy.dll
[2013/01/13 05:06:14 | 000,181,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpsetup.dll
[2013/01/13 05:06:14 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdProxy.dll
[2013/01/13 05:06:13 | 001,342,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\brcpl.dll
[2013/01/13 05:06:13 | 000,759,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsecsnp.dll
[2013/01/13 05:06:13 | 000,399,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlangpui.dll
[2013/01/13 05:06:13 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskpart.exe
[2013/01/13 05:06:12 | 001,575,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVENCOD.DLL
[2013/01/13 05:06:12 | 000,507,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsdyn.dll
[2013/01/13 05:06:12 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpapi.dll
[2013/01/13 05:06:12 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashlpr.dll
[2013/01/13 05:06:12 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logman.exe
[2013/01/13 05:06:11 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2013/01/13 05:06:11 | 000,158,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrad.dll
[2013/01/13 05:06:11 | 000,155,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2013/01/13 05:06:11 | 000,140,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wusa.exe
[2013/01/13 05:06:11 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\findstr.exe
[2013/01/13 05:06:10 | 002,225,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcenter.dll
[2013/01/13 05:06:10 | 001,580,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpccpl.dll
[2013/01/13 05:06:09 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wer.dll
[2013/01/13 05:06:09 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassvcs.dll
[2013/01/13 05:06:08 | 001,152,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themecpl.dll
[2013/01/13 05:06:08 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsnmp32.dll
[2013/01/13 05:06:06 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scansetting.dll
[2013/01/13 05:06:06 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2013/01/13 05:06:06 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssprxy.dll
[2013/01/13 05:06:05 | 000,777,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcc.dll
[2013/01/13 05:06:05 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2013/01/13 05:06:05 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasacct.dll
[2013/01/13 05:06:04 | 003,072,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkmap.dll
[2013/01/13 05:06:04 | 001,248,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PerfCenterCPL.dll
[2013/01/13 05:06:04 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercpl.dll
[2013/01/13 05:06:03 | 001,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2013/01/13 05:06:03 | 001,224,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sud.dll
[2013/01/13 05:06:03 | 000,842,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\systemcpl.dll
[2013/01/13 05:06:03 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.exe
[2013/01/13 05:06:02 | 002,515,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\accessibilitycpl.dll
[2013/01/13 05:06:02 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pcaui.dll
[2013/01/13 05:06:02 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmci.dll
[2013/01/13 05:06:01 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usercpl.dll
[2013/01/13 05:06:01 | 000,516,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoplay.dll
[2013/01/13 05:06:00 | 001,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanpref.dll
[2013/01/13 05:06:00 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpchttp.dll
[2013/01/13 05:06:00 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pintlgnt.ime
[2013/01/13 05:05:59 | 000,532,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcao.dll
[2013/01/13 05:05:59 | 000,408,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msinfo32.exe
[2013/01/13 05:05:59 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scksp.dll
[2013/01/13 05:05:59 | 000,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsutil.dll
[2013/01/13 05:05:58 | 000,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AudioSes.dll
[2013/01/13 05:05:58 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleprn.dll
[2013/01/13 05:05:58 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3msm.dll
[2013/01/13 05:05:58 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\feclient.dll
[2013/01/13 05:05:57 | 000,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2013/01/13 05:05:57 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rekeywiz.exe
[2013/01/13 05:05:57 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iaspolcy.dll
[2013/01/13 05:05:57 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DeviceEject.exe
[2013/01/13 05:05:57 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscisvif.dll
[2013/01/13 05:05:56 | 001,689,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscui.cpl
[2013/01/13 05:05:56 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpui.dll
[2013/01/13 05:05:56 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/01/13 05:05:56 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncryptui.dll
[2013/01/13 05:05:56 | 000,407,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpapimig.exe
[2013/01/13 05:05:55 | 000,642,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasgcw.dll
[2013/01/13 05:05:55 | 000,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FWPUCLNT.DLL
[2013/01/13 05:05:55 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasplap.dll
[2013/01/13 05:05:55 | 000,215,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certreq.exe
[2013/01/13 05:05:55 | 000,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmartcardCredentialProvider.dll
[2013/01/13 05:05:55 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hdwwiz.exe
[2013/01/13 05:05:55 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSTheme.exe
[2013/01/13 05:05:54 | 000,170,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2013/01/13 05:05:54 | 000,167,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\portcls.sys
[2013/01/13 05:05:54 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWSD.dll
[2013/01/13 05:05:54 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPUnattend.exe
[2013/01/13 05:05:54 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmmon32.exe
[2013/01/13 05:05:54 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwinsat.dll
[2013/01/13 05:05:53 | 000,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmdial32.dll
[2013/01/13 05:05:53 | 000,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2013/01/13 05:05:53 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\whealogr.dll
[2013/01/13 05:05:53 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD2.sys
[2013/01/13 05:05:53 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD.sys
[2013/01/13 05:05:52 | 000,275,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SnippingTool.exe
[2013/01/13 05:05:52 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conime.exe
[2013/01/13 05:05:51 | 000,657,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVXENCD.DLL
[2013/01/13 05:05:51 | 000,547,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaaut.dll
[2013/01/13 05:05:51 | 000,202,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanui.dll
[2013/01/13 05:05:51 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPutil.exe
[2013/01/13 05:05:50 | 002,153,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oobefldr.dll
[2013/01/13 05:05:50 | 000,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shwebsvc.dll
[2013/01/13 05:05:50 | 000,137,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsprop.dll
[2013/01/13 05:05:50 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dimsroam.dll
[2013/01/13 05:05:49 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\modemui.dll
[2013/01/13 05:05:49 | 000,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsetup.dll
[2013/01/13 05:05:48 | 006,103,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chtbrkr.dll
[2013/01/13 05:05:48 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscandui.dll
[2013/01/13 05:05:48 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmontr.dll
[2013/01/13 05:05:47 | 000,542,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\blackbox.dll
[2013/01/13 05:05:47 | 000,533,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmsdk.dll
[2013/01/13 05:05:47 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2013/01/13 05:05:47 | 000,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlgpclnt.dll
[2013/01/13 05:05:47 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dataclen.dll
[2013/01/13 05:05:46 | 000,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2013/01/13 05:05:46 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDMon.dll
[2013/01/13 05:05:45 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2013/01/13 05:05:45 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cipher.exe
[2013/01/13 05:05:45 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ifmon.dll
[2013/01/13 05:05:44 | 000,414,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2013/01/13 05:05:44 | 000,217,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\InkEd.dll
[2013/01/13 05:05:44 | 000,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpresult.exe
[2013/01/13 05:05:44 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2013/01/13 05:05:44 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2013/01/13 05:05:44 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimtf.dll
[2013/01/13 05:05:43 | 000,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\thawbrkr.dll
[2013/01/13 05:05:43 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\watchdog.sys
[2013/01/13 05:05:42 | 000,356,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2013/01/13 05:05:42 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\softkbd.dll
[2013/01/13 05:05:41 | 000,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmmgrtn.dll
[2013/01/13 05:05:41 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmsynth.dll
[2013/01/13 05:05:41 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfui.dll
[2013/01/13 05:05:40 | 000,200,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\input.dll
[2013/01/13 05:05:40 | 000,166,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\puiapi.dll
[2013/01/13 05:05:40 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2013/01/13 05:05:39 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLLUA.exe
[2013/01/13 05:05:39 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fc.exe
[2013/01/13 05:05:39 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msisip.dll
[2013/01/13 05:05:38 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmusic.dll
[2013/01/13 05:05:38 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2013/01/13 05:05:38 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdSSDP.dll
[2013/01/13 05:05:37 | 000,187,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapp3hst.dll
[2013/01/13 05:05:37 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tintlgnt.ime
[2013/01/13 05:05:37 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\l2nacp.dll
[2013/01/13 05:05:37 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjint40.dll
[2013/01/13 05:05:37 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsCtfMonitor.dll
[2013/01/13 05:05:36 | 000,083,456 | —- | C] (Microsoft) – C:\Windows\System32\SMBHelperClass.dll
[2013/01/13 05:05:36 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftp.exe
[2013/01/13 05:05:36 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsdchngr.dll
[2013/01/13 05:05:35 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWCN.dll
[2013/01/13 05:05:35 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Storprop.dll
[2013/01/13 05:05:35 | 000,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdiag.dll
[2013/01/13 05:05:35 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3cfg.dll
[2013/01/13 05:05:35 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthci.dll
[2013/01/13 05:05:35 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthudtask.exe
[2013/01/13 05:05:35 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdial.exe
[2013/01/13 05:05:34 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcinst.dll
[2013/01/13 05:05:34 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipconfig.exe
[2013/01/13 05:05:34 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CHxReadingStringIME.dll
[2013/01/13 05:05:33 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappgnui.dll
[2013/01/13 05:05:33 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nslookup.exe
[2013/01/13 05:05:33 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hbaapi.dll
[2013/01/13 05:05:33 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkitemfactory.dll
[2013/01/13 05:05:33 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ocsetup.exe
[2013/01/13 05:05:33 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FwRemoteSvr.dll
[2013/01/13 05:05:32 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdeploy.dll
[2013/01/13 05:05:32 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcico.dll
[2013/01/13 05:05:31 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PNPXAssoc.dll
[2013/01/13 05:05:30 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpupdate.exe
[2013/01/13 05:05:29 | 000,046,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrstub.exe
[2013/01/13 05:05:29 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cbsra.exe
[2013/01/13 05:05:29 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsigd.dll
[2013/01/13 05:05:29 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NcdProp.dll
[2013/01/13 05:05:29 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsilog.dll
[2013/01/13 05:05:28 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxg.sys
[2013/01/13 05:05:28 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcconf.dll
[2013/01/13 05:05:28 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdmdbg.dll
[2013/01/13 05:05:27 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2013/01/13 05:05:27 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetppui.dll
[2013/01/13 05:05:27 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2013/01/13 05:05:24 | 000,052,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\stream.sys
[2013/01/13 05:05:24 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2013/01/13 05:05:22 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/01/13 05:05:21 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\f3ahvoas.dll
[2013/01/13 05:05:21 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimsg.dll
[2013/01/13 05:04:56 | 000,705,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmiEngine.dll
[2013/01/13 05:04:48 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdscore.dll
[2013/01/13 05:04:48 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PkgMgr.exe
[2013/01/13 05:04:28 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvstore.dll
[2013/01/13 04:44:28 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/01/13 04:28:53 | 000,025,648 | R— | C] (Symantec Corporation) – C:\Windows\System32\drivers\SymIMV.sys
[2013/01/13 03:26:39 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2013/01/13 03:26:38 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2013/01/13 03:26:38 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2013/01/12 07:43:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/01/11 15:51:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Wizard
[2013/01/11 15:51:10 | 000,000,000 | —D | C] – C:\Program Files\Driver Wizard
[2013/01/11 15:50:34 | 000,000,000 | —D | C] – C:\Users\cockrell\AppData\Roaming\Driver Wizard
[2013/01/11 15:24:52 | 000,232,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/01/11 14:51:46 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/10 10:22:18 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/10 10:14:44 | 000,032,156 | —- | M] () – C:\ProgramData\nvModes.dat
[2013/02/10 10:14:44 | 000,032,156 | —- | M] () – C:\ProgramData\nvModes.001
[2013/02/10 10:13:51 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/10 10:13:51 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/10 10:13:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/10 10:13:41 | 1877,389,312 | -HS- | M] () – C:\hiberfil.sys
[2013/02/09 14:49:55 | 000,000,512 | —- | M] () – C:\Users\cockrell\Desktop\MBR.dat
[2013/02/09 11:50:09 | 002,194,612 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\Cat.DB
[2013/02/09 10:45:29 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\cockrell\Desktop\aswMBR.exe
[2013/02/09 10:43:36 | 000,547,275 | —- | M] (Oleg N. Scherbakov) – C:\Users\cockrell\Desktop\JRT.exe
[2013/02/08 17:47:15 | 000,625,664 | —- | M] () – C:\Users\cockrell\Desktop\dds.scr
[2013/02/08 17:45:53 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\cockrell\Desktop\HiJackThis.exe
[2013/02/08 17:32:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\cockrell\Desktop\OTL.exe
[2013/02/08 17:24:25 | 000,477,616 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 17:24:24 | 000,473,520 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 16:59:18 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\cockrell\Desktop\ATF-Cleaner.exe
[2013/02/07 19:23:15 | 000,697,712 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/02/07 19:23:15 | 000,074,096 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/02/07 19:01:26 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/02/07 19:01:26 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/02/07 18:26:17 | 000,000,943 | —- | M] () – C:\Users\cockrell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/02/07 18:21:14 | 000,314,048 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/02/07 18:15:46 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2013/02/07 18:15:34 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013/02/06 20:19:00 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2013/02/06 20:19:00 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2013/02/06 20:18:45 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/02/06 20:18:44 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/02/06 20:18:44 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/02/06 20:18:44 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/02/06 20:18:43 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/02/06 20:18:43 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/02/06 20:18:43 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/02/06 20:18:43 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/02/06 20:18:42 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/02/06 20:18:42 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/02/06 20:18:42 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/02/06 20:18:41 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/02/06 20:18:41 | 001,427,968 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/02/06 20:18:41 | 000,607,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/02/06 20:18:41 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/02/06 20:18:41 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/02/06 20:18:41 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/02/06 20:18:41 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/02/06 20:18:41 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/02/06 20:18:41 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/02/06 20:18:41 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/02/06 20:18:41 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/02/06 20:18:41 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/02/06 20:18:41 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/02/06 20:18:41 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/02/06 20:18:40 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/02/06 20:18:40 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2013/02/06 20:18:40 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2013/02/06 20:18:40 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/02/06 20:18:40 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2013/02/06 20:18:40 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/02/06 20:18:39 | 001,800,704 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/02/06 20:18:39 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2013/02/06 20:18:39 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/02/06 20:18:39 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/02/06 20:18:39 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/02/06 20:18:39 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/02/06 20:18:39 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/02/06 20:16:17 | 000,979,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2013/02/06 20:16:17 | 000,357,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2013/02/06 20:16:16 | 000,302,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2013/02/06 20:16:13 | 002,873,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2013/02/06 20:16:13 | 000,261,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2013/02/06 20:16:13 | 000,209,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2013/02/06 20:16:13 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2013/02/06 20:16:11 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2013/02/06 20:16:10 | 001,029,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/02/06 20:16:10 | 000,486,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/02/06 20:16:10 | 000,478,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/02/06 20:16:10 | 000,189,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/02/06 20:16:09 | 001,554,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2013/02/06 20:16:09 | 000,847,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2013/02/06 20:16:09 | 000,667,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2013/02/06 20:16:09 | 000,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2013/02/06 20:16:09 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2013/02/06 20:14:52 | 000,004,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\en-US\dxgkrnl.sys.mui
[2013/02/06 20:14:51 | 000,519,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/02/06 20:14:51 | 000,369,664 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/02/06 20:14:51 | 000,321,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2013/02/06 20:14:51 | 000,252,928 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2013/02/06 20:14:51 | 000,195,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2013/02/06 20:14:51 | 000,189,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/02/04 21:28:04 | 000,000,009 | —- | M] () – C:\END
[2013/02/04 18:49:28 | 000,000,246 | —- | M] () – C:\ProgramData\hpqp.ini
[2013/02/03 18:24:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/31 21:47:33 | 000,034,253 | —- | M] () – C:\Users\cockrell\Desktop\ken and rhonda phone pics 013113 076.jpg
[2013/01/30 20:44:49 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motoandroid_01007.Wdf
[2013/01/28 17:07:09 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motfilt_01007.Wdf
[2013/01/28 17:07:07 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motccgp_01007.Wdf
[2013/01/28 17:05:42 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf
[2013/01/27 22:59:03 | 000,000,865 | —- | M] () – C:\net_save.dna
[2013/01/23 20:45:36 | 000,075,356 | —- | M] () – C:\Users\cockrell\AppData\Roaming\userenv.xml.urlencode
[2013/01/23 20:45:36 | 000,056,742 | —- | M] () – C:\Users\cockrell\AppData\Roaming\userenv.xml
[2013/01/23 20:24:17 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/01/23 16:24:20 | 001,242,112 | —- | M] (Microsoft Corporation) – C:\Users\cockrell\Desktop\wlsetup-web.exe
[2013/01/17 01:28:58 | 000,232,336 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/01/13 04:28:26 | 000,002,204 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2013/01/12 09:10:53 | 000,467,592 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\NIS\1008030.006\cchpx86.sys
[2013/01/12 09:10:43 | 000,000,172 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\isolate.ini
[2013/01/11 17:41:33 | 000,006,144 | —- | M] () – C:\Users\cockrell\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/11 16:16:53 | 000,124,976 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2013/01/11 16:16:53 | 000,007,456 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2013/01/11 16:16:53 | 000,000,806 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2013/01/11 16:14:34 | 000,009,412 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\symnetv.cat
[2013/01/11 16:14:34 | 000,001,562 | —- | M] () – C:\Windows\System32\drivers\NIS\1008030.006\SymNetV.inf
[2013/01/11 15:51:19 | 000,000,859 | —- | M] () – C:\Users\cockrell\Desktop\Driver Wizard.lnk
[2013/01/11 15:35:22 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/09 14:49:55 | 000,000,512 | —- | C] () – C:\Users\cockrell\Desktop\MBR.dat
[2013/02/08 17:46:58 | 000,625,664 | —- | C] () – C:\Users\cockrell\Desktop\dds.scr
[2013/02/07 22:06:05 | 1877,389,312 | -HS- | C] () – C:\hiberfil.sys
[2013/02/07 18:15:46 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2013/02/07 18:15:34 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013/02/06 20:18:41 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/02/06 19:50:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/02/06 19:50:16 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/02/04 21:28:33 | 000,010,844 | —- | C] () – C:\Windows\System32\athrext.cat
[2013/02/04 21:28:33 | 000,006,483 | —- | C] () – C:\Windows\System32\netathr.inf
[2013/02/04 21:26:12 | 000,000,009 | —- | C] () – C:\END
[2013/02/03 18:24:40 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/31 21:48:54 | 000,034,253 | —- | C] () – C:\Users\cockrell\Desktop\ken and rhonda phone pics 013113 076.jpg
[2013/01/30 20:44:49 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motoandroid_01007.Wdf
[2013/01/28 17:07:09 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motfilt_01007.Wdf
[2013/01/28 17:07:07 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
[2013/01/28 17:06:02 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motccgp_01007.Wdf
[2013/01/28 17:05:42 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf
[2013/01/27 22:59:03 | 000,000,865 | —- | C] () – C:\net_save.dna
[2013/01/23 20:45:36 | 000,075,356 | —- | C] () – C:\Users\cockrell\AppData\Roaming\userenv.xml.urlencode
[2013/01/23 20:45:36 | 000,056,742 | —- | C] () – C:\Users\cockrell\AppData\Roaming\userenv.xml
[2013/01/13 05:07:29 | 000,130,008 | —- | C] () – C:\Windows\System32\systemsf.ebd
[2013/01/13 05:07:26 | 000,009,239 | —- | C] () – C:\Windows\System32\spcinstrumentation.man
[2013/01/13 05:07:13 | 000,442,788 | —- | C] () – C:\Windows\System32\dot3.tmf
[2013/01/13 05:07:11 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2013/01/13 05:07:11 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2013/01/13 05:07:07 | 000,392,170 | —- | C] () – C:\Windows\System32\onex.tmf
[2013/01/13 05:07:01 | 000,344,698 | —- | C] () – C:\Windows\System32\eaphost.tmf
[2013/01/13 05:06:37 | 000,208,966 | —- | C] () – C:\Windows\System32\WFP.TMF
[2013/01/13 05:06:34 | 000,092,918 | —- | C] () – C:\Windows\System32\slmgr.vbs
[2013/01/13 05:05:27 | 000,009,212 | —- | C] () – C:\Windows\System32\RacUR.xml
[2013/01/11 17:36:57 | 000,006,144 | —- | C] () – C:\Users\cockrell\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/11 15:51:19 | 000,000,859 | —- | C] () – C:\Users\cockrell\Desktop\Driver Wizard.lnk
[2013/01/11 15:35:22 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2013/01/11 14:47:35 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2013/01/10 20:46:50 | 000,032,156 | —- | C] () – C:\ProgramData\nvModes.001
[2013/01/10 20:46:29 | 000,032,156 | —- | C] () – C:\ProgramData\nvModes.dat
[2013/01/08 07:58:44 | 000,000,246 | —- | C] () – C:\ProgramData\hpqp.ini
[2013/01/08 07:49:27 | 000,011,164 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin

========== ZeroAccess Check ==========

[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 01:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/11 15:51:30 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\Driver Wizard
[2013/01/28 17:05:55 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\Motorola
[2013/01/23 20:45:42 | 000,000,000 | —D | M] – C:\Users\cockrell\AppData\Roaming\spotmau

========== Purity Check ==========



< End of report >
I should leave Chrome uninstall for now. The last time it obviously restored your user data and settings.

For the moment, things seem to be running better.

You sound unconvinced :)

A few more stragglers to tidy up.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
    O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post the OTL fix log

=======================================

Run Malwarebytes’ Anti-Malware

Please enable/re-install Malwarebytes: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Logs to include with the next post:

OTL fix log
Mbam.txt


Thanks

Satchfan
Not completely convinced, no… All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}\ not found. File C:\Program Files\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: cockrell ->Temp folder emptied: 31832 bytes ->Temporary Internet Files folder emptied: 92143284 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 926 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 950648 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 89.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 02102013_122709 Files\Folders moved on Reboot… File\Folder C:\Windows\temp\JETE445.tmp not found! PendingFileRenameOperations files… Registry entries deleted on Reboot… Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.10.06 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 cockrell :: COCKRELL-PC [administrator] 2/10/2013 12:39:25 PM mbam-log-2013-02-10 (12-39-25).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 201938 Time elapsed: 6 minute(s), 26 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)

Not completely convinced, no…

Have faith. ;)

I'm happy with how we're doing even if you're not. The majority of your problems were not malicious, just very annoying.

A couple more scans should show that all is OK.

Run ESET Online Scan

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - if ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Satchfan
ESET Found no Threats and did not save a log.



Results of screen317's Security Check version 0.99.57
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Norton Internet Security
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.70.0.1100
Adobe Reader 9 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Windows Defender MSASCui.exe
Windows Defender MSASCui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 1 %
````````````````````End of Log``````````````````````
Well done, your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Uninstall OTL
  • double-click OTL.exe
  • click the CleanUp! button.
  • select Yes when the Begin cleanup Process? prompt appears.
  • if you are prompted to reboot during the cleanup, select Yes.
  • the tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

You can delete any other logs and programs from your desktop.

===================================================

Create a Restore Point
  • click on Start > Control Panel (All Control Panel Items)
  • click on System > System Protection
  • check that you have System Protection turned on for the drive that you want to create a restore point for, (usually C:
  • click Create
  • type in a description for the restore point to help recognize it when doing a System Restore, and click on the Create button.
Remove old restore points
  • open Disk Cleanup by clicking Start. In the search box, type Disk Cleanup, and then, in the list of results, click Disk Cleanup.
  • if prompted, select the drive that you want to clean up, and then click OK.
  • in the Disk Cleanup for (drive letter) dialog box, click Clean up system files. If you're prompted for an administrator password or confirmation, type the password or provide confirmation
  • if prompted, select the drive that you want to clean up, and then click OK
  • click the More Options tab, then under System Restore and Shadow Copies, click Clean up
  • in the Disk Cleanup dialog box, click Delete
  • click Delete Files, and then click OK.

===================================================

Update installed programs

You have an old version of Adobe Reader on your computer which is vulnerable to infections.
  • from the Start menu, select Control Panel.
  • in Large or Small icon view, click Programs and Features. If you're using Category view, under "Programs", click Uninstall a program.
  • select any version of Adobe Reader then click Uninstall.
Install the latest version:

Adobe Reader

===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

===================================================

Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Safe computing

Satchfan
Done! Thanks for the help Satchfan! Note I cannot resist. I reinstalled Chrome. I also removed Norton. It was about to Expire and I never really liked it anyway. I went with Avira. Thanks again for the help. Any further suggestions or comments? I'm all ears.
You're welcome for the help. I have to agree about Norton - it beats me why anyone still uses it. Avira is good, as are Avast free and Microsoft Security Essentials, (also free) but make sure only one AV is installed at one time. Regards Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI