This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] pop ups, redirects, recent blue screen of death, help?

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently had to do a complete reinstall of vista due to computer would not boot to windows desktop, lost everything, now lately getting pop ups galore, page redirects, just really goofy stuff.

here is a hijack this log I did, can you help?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:28:29 AM, on 01/01/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Windows\system32\schtasks.exe
C:\WINDOWS\System32\rundll32.exe
C:\Windows\system32\jusched.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\conime.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\House\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 200.124.131.116 casinocontroller.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Comrade.exe] C:\Program Files\GameSpy\Comrade\Comrade.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
O16 - DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} (PCPitstop AntiVirus) - http://utilities.pcpitstop.com/Exterminate…opAntiVirus.dll
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.eu/Register/Bra…018/flashax.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 10824 bytes
Hi, and Welcome to WhatTheTech :)

Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around. If you still require help, please do the following:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.

Thanks.
Thank you sooooooo much for your reply, not a problem on taking so long, just appreaciate that you guys take the time to help us out, the log is below and the other is attached. Thanks again mrsbaumer DDS (Ver_09-01-19.01) - NTFSx86 Run by [removed] at 13:35:16.10 on 30/01/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2942.1646 [GMT -5:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\rundll32.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\PSIService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Windows\system32\wbem\wmiprvse.exe C:\hp\support\hpsysdrv.exe C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe C:\WINDOWS\RtHDVCpl.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\WINDOWS\System32\rundll32.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\schtasks.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\jusched.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\hp\kbd\kbd.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Internet Explorer\IEUser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Windows\System32\mobsync.exe C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\House\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\61WY9WY3\dds[1].scr C:\Windows\system32\conime.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ig?source=gama&hl=en uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: NoExplorer - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KbdStub.EXE mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Corel File Shell Monitor] c:\program files\corel\corel paint shop pro photo x2\CorelIOMonitor.exe mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe StartupFolder: c:\users\house\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Risk/Images/armhelper.ocx ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-20 64160] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-30 111184] R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-30 20560] R4 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2008-12-30 51792] R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 942416] =============== Created Last 30 ================ 2009-01-29 16:22 –d—– c:\windows\system32\Adobe 2009-01-27 06:30 –d—– c:\users\house\.thumbnails 2009-01-27 06:27 –d—– c:\users\house\.gimp-2.6 2009-01-27 06:27 –d—– c:\users\house\.gegl-0.0 2009-01-27 06:27 –d—– c:\program files\GIMP-2.0 2009-01-23 20:16 –d—– c:\program files\Disney 2009-01-22 14:18 15,688 a——- c:\windows\system32\lsdelete.exe 2009-01-22 05:54 –d—– C:\apps 2009-01-20 04:38 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-01-20 04:36 -cd-h— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-01-20 04:36 -cd-h— c:\progra~2\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-01-20 04:36 –d—– c:\program files\Lavasoft 2009-01-19 11:05 –d—– c:\program files\SimpleD Budget 2009-01-18 11:14 –d—– c:\program files\Palace of Chance 2009-01-17 10:58 –d—– c:\program files\PKR 2009-01-17 04:11 –dsh— c:\users\house\appdata\roaming\.# 2009-01-17 04:11 –d—– c:\program files\common files\SWF Studio 2009-01-14 05:22 288,768 a——- c:\windows\system32\drivers\srv.sys 2009-01-13 06:36 –d—– c:\program files\GreenScreenWizardPro 2009-01-13 06:20 –d—– c:\program files\FXhome PhotoKey 2009-01-12 16:08 1,682 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-01-12 16:00 –d—– c:\programdata\Corel 2009-01-12 16:00 –d—– c:\progra~2\Corel 2009-01-12 15:55 –d—– c:\program files\common files\Corel 2009-01-10 11:18 56 a—h— c:\programdata\ezsidmv.dat 2009-01-10 11:18 56 a—h— c:\progra~2\ezsidmv.dat 2009-01-10 11:14 –d—– c:\programdata\Skype 2009-01-09 18:33 –d—– c:\program files\directx 2009-01-09 18:30 –d—– c:\program files\Activision Value 2009-01-09 04:48 –d—– c:\users\house\appdata\roaming\Anthropics 2009-01-09 04:45 –d—– c:\program files\Portrait Professional 8 Trial 2009-01-07 19:56 –d—– C:\ComboFix 2009-01-07 19:56 318,976 a——- c:\windows\system32\CF31372.exe 2009-01-06 07:50 –d—– c:\program files\MonkeyPhoto 2009-01-06 07:40 –d—– c:\program files\Greeting Card Studio 2009-01-06 05:00 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-01-06 05:00 891,448 a——- c:\windows\system32\drivers\tcpip.sys 2009-01-06 05:00 72,192 a——- c:\windows\system32\drivers\pacer.sys 2009-01-06 05:00 15,360 a——- c:\windows\system32\pacerprf.dll 2009-01-05 17:33 3,751,995 a——- c:\windows\system32\GPhotos.scr 2009-01-05 14:01 161,792 a——- c:\windows\SWREG.exe 2009-01-05 14:01 98,816 a——- c:\windows\sed.exe 2009-01-04 17:35 –d—– c:\programdata\NVIDIA 2009-01-04 17:19 553 a——- c:\windows\USetup.iss 2009-01-04 17:19 98,304 a——- c:\windows\RTKAUDIOSERVICE.EXE 2009-01-04 17:18 2,047,576 a——- c:\windows\system32\drivers\RTKVHDA.sys 2009-01-04 17:18 1,191,936 a——- c:\windows\RtlUpd.exe 2009-01-04 17:18 636,416 a——- c:\windows\system32\RtkPgExt.dll 2009-01-04 17:18 532,480 a——- c:\windows\system32\RTSndMgr.cpl 2009-01-04 17:18 135,168 a——- c:\windows\system32\SRSWOW.dll 2009-01-04 17:18 29,696 a——- c:\windows\system32\RtkCoInst.dll 2009-01-04 17:18 4,874,240 a——- c:\windows\RtHDVCpl.exe 2009-01-04 17:14 –d—– c:\users\house\appdata\roaming\WinBatch 2009-01-04 08:33 691 a——- c:\users\house\appdata\roaming\GetValue.vbs 2009-01-04 08:33 35 a——- c:\users\house\appdata\roaming\SetValue.bat 2009-01-04 08:32 78,336 a——- c:\windows\system32\Agent.OMZ.Fix.exe 2009-01-04 08:32 –d—– c:\windows\system32\SmitfraudFix 2009-01-04 06:54 –d—– c:\users\house\appdata\roaming\NeatImage SL 2009-01-04 06:53 –d—– c:\program files\Neat Image 2009-01-04 06:45 –d—– c:\program files\PictureCode 2009-01-03 16:11 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf 2009-01-01 09:32 –d—– c:\users\house\appdata\roaming\Malwarebytes 2009-01-01 09:32 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-01-01 09:32 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-01 09:32 –d—– c:\programdata\Malwarebytes 2009-01-01 09:32 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-01-01 09:32 –d—– c:\progra~2\Malwarebytes 2008-12-31 18:08 –d—– c:\users\house\appdata\roaming\Boomzap ==================== Find3M ==================== 2009-01-16 17:16 34 a——- c:\users\house\jagex_runescape_preferences.dat 2009-01-08 07:31 2,516 a–sh— c:\programdata\KGyGaAvL.sys 2009-01-08 07:31 2,516 a–sh— c:\progra~2\KGyGaAvL.sys 2009-01-08 07:31 88 —shr– c:\programdata\C0D09EBF43.sys 2009-01-08 07:31 88 —shr– c:\progra~2\C0D09EBF43.sys 2009-01-06 06:06 51,200 a——- c:\windows\inf\infpub.dat 2009-01-06 06:06 143,360 a——- c:\windows\inf\infstrng.dat 2009-01-04 17:30 86,016 a——- c:\windows\inf\infstor.dat 2009-01-04 17:18 319,456 a——- c:\windows\DIFxAPI.dll 2008-12-25 09:24 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2008-12-20 03:11 174 a–sh— c:\program files\desktop.ini 2008-12-20 03:02 665,600 a——- c:\windows\inf\drvindex.dat 2008-12-20 02:53 101,888 a——- c:\windows\system32\ifxcardm.dll 2008-12-20 02:53 82,432 a——- c:\windows\system32\axaltocm.dll 2008-12-10 04:36 296,960 a——- c:\windows\system32\gdi32.dll 2008-12-10 04:36 28,672 a——- c:\windows\system32\Apphlpdm.dll 2008-12-10 04:36 2,560 a——- c:\windows\apppatch\AcRes.dll 2008-12-10 04:36 2,154,496 a——- c:\windows\apppatch\AcGenral.dll 2008-12-10 04:36 460,288 a——- c:\windows\apppatch\AcSpecfc.dll 2008-12-10 04:36 541,696 a——- c:\windows\apppatch\AcLayers.dll 2008-12-10 04:36 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2008-12-10 04:36 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2008-12-10 04:36 1,695,744 a——- c:\windows\system32\gameux.dll 2008-12-10 04:36 52,736 a——- c:\windows\apppatch\iebrshim.dll 2008-12-10 04:35 2,048 a——- c:\windows\system32\tzres.dll 2008-12-10 04:34 2,927,104 a——- c:\windows\explorer.exe 2008-12-10 04:33 827,392 a——- c:\windows\system32\wininet.dll 2008-12-10 04:31 2,868,736 a——- c:\windows\system32\mf.dll 2008-12-10 04:31 98,816 a——- c:\windows\system32\mfps.dll 2008-12-10 04:30 53,248 a——- c:\windows\system32\rrinstaller.exe 2008-12-10 04:30 24,576 a——- c:\windows\system32\mfpmp.exe 2008-12-10 04:30 2,048 a——- c:\windows\system32\mferror.dll 2008-12-10 04:30 94,720 a——- c:\windows\system32\logagent.exe 2008-12-10 04:30 996,352 a——- c:\windows\system32\WMNetMgr.dll 2008-12-08 04:47 269,312 a——- c:\windows\system32\es.dll 2008-12-07 09:34 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf 2008-12-06 15:02 61,440 a——- c:\windows\system32\winipsec.dll 2008-12-06 15:02 28,672 a——- c:\windows\system32\FwRemoteSvr.dll 2008-12-06 15:02 361,984 a——- c:\windows\system32\IPSECSVC.DLL 2008-12-06 15:02 272,896 a——- c:\windows\system32\polstore.dll 2008-12-06 15:01 241,152 a——- c:\windows\system32\PortableDeviceApi.dll 2008-12-06 15:01 160,768 a——- c:\windows\system32\PortableDeviceTypes.dll 2008-12-06 15:01 94,720 a——- c:\windows\system32\PortableDeviceClassExtension.dll 2008-12-06 14:58 428,544 a——- c:\windows\system32\EncDec.dll 2008-12-06 14:58 293,376 a——- c:\windows\system32\psisdecd.dll 2008-12-06 14:56 212,480 a——- c:\windows\system32\drivers\mrxsmb10.sys 2008-12-06 14:55 303,616 a——- c:\windows\system32\wmpeffects.dll 2008-12-06 14:54 2,032,640 a——- c:\windows\system32\win32k.sys 2008-12-06 14:54 1,191,936 a——- c:\windows\system32\msxml3.dll 2008-12-06 14:54 2,048 a——- c:\windows\system32\msxml3r.dll 2008-12-06 14:45 3,104,768 a——- c:\windows\system32\NlsData004b.dll 2008-12-06 14:43 6,656 a——- c:\windows\system32\kbd106n.dll 2008-12-06 14:43 988,216 a——- c:\windows\system32\winload.exe 2008-12-06 14:43 927,288 a——- c:\windows\system32\winresume.exe 2008-12-06 14:43 615,992 a——- c:\windows\system32\ci.dll 2008-12-06 14:43 378,368 a——- c:\windows\system32\srcore.dll 2008-12-06 14:43 318,464 a——- c:\windows\system32\rstrui.exe 2008-12-06 14:43 46,592 a——- c:\windows\system32\setbcdlocale.dll 2008-12-06 14:43 40,960 a——- c:\windows\system32\srclient.dll 2008-12-06 14:43 19,000 a——- c:\windows\system32\kd1394.dll 2008-12-06 14:43 14,848 a——- c:\windows\system32\srdelayed.exe 2008-12-06 14:40 425,472 a——- c:\windows\system32\PhotoMetadataHandler.dll 2008-12-06 14:40 712,704 a——- c:\windows\system32\WindowsCodecs.dll 2008-12-06 14:40 347,136 a——- c:\windows\system32\WindowsCodecsExt.dll 2008-12-06 14:39 443,392 a——- c:\windows\system32\win32spl.dll 2008-12-06 14:39 37,888 a——- c:\windows\system32\printcom.dll 2008-12-06 14:39 113,664 a——- c:\windows\system32\drivers\rmcast.sys 2008-12-06 14:39 14,848 a——- c:\windows\system32\wshrm.dll 2008-12-06 14:37 738,304 a——- c:\windows\system32\inetcomm.dll 2008-12-06 14:37 84,480 a——- c:\windows\system32\INETRES.dll 2008-12-06 14:37 1,645,568 a——- c:\windows\system32\connect.dll 2008-12-06 14:37 1,314,816 a——- c:\windows\system32\quartz.dll 2008-12-06 14:35 3,601,464 a——- c:\windows\system32\ntkrnlpa.exe 2008-12-06 14:35 3,549,240 a——- c:\windows\system32\ntoskrnl.exe 2008-12-06 14:35 1,334,272 a——- c:\windows\system32\msxml6.dll 2008-12-06 14:35 2,048 a——- c:\windows\system32\msxml6r.dll 2008-12-06 14:14 1,841 a–shr– c:\windows\system32\drivers\103C_HP_CPC_GN561AA-ABA a6230n_YC_0Pavi_QCNH732_E74NAv3PrA1_49_INARRA2_SASUSTek Computer INC._V2.00_B5.11_T070716_WUH0_L409_M2943_J400_7AMD_8Athlon 64 X2 Dual Core_92.8_#071225_N10DE03EF_Z14F12F20_G10DE03D0.MRK 2008-12-06 14:09 1,524,736 a——- c:\windows\system32\wucltux.dll 2008-12-06 14:09 83,456 a——- c:\windows\system32\wudriver.dll 2008-12-06 14:09 162,064 a——- c:\windows\system32\wuwebv.dll 2008-12-06 14:09 31,232 a——- c:\windows\system32\wuapp.exe 2008-11-24 03:06 129,520 ——– c:\windows\system32\PxAFS.DLL 2008-11-24 03:06 120,568 ——– c:\windows\system32\pxcpyi64.exe 2008-11-24 03:06 118,256 ——– c:\windows\system32\pxinsi64.exe 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2008-01-08 17:34 22 a–sh— c:\windows\sminst\HPCD.SYS 2007-08-05 00:16 8,192 a–sh— c:\windows\users\default\NTUSER.DAT ============= FINISH: 13:36:27.33 ===============

Attachments:

Hi :)

LimeWire
You have LimeWire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


You appear to have Weatherbug installed. It is considered adware as it displays pop-ups and is used to install My Search Toolbar. A safe alternative to WeatherBug is Weatherpulse. I recommend you uninstall WeatherBug for the above reasons. You can do this by clicking Start >> Control Panel >> Add/Remove Programs and clicking remove by the WeatherBug entry.


Please open MalwareBytes' AntiMalware, update it, and run a Quick Scan. Please post the resulting log, fixing anything it finds.


Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.


Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 11.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 11, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop.
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windowsi586.exe to install the newest version.
Run Eset NOD32 Online AntiVirus
http://www.eset.eu/online-scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your current Antivirus software. You can usually do this with its Notfication Tray icon near the clock.
  • Click Start
  • Make sure that the option "Remove found threats" is Un-checked, and the option "Scan unwanted applications" is checked
  • Click Scan
  • Wait for the scan to finish
  • Re-enable your Anvirisus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.
Please also run DDS again and post the first log (DDS.txt) from that.

Thanks.
eset would not run, said it needed administrative rights to run? couldnt get that. DDS (Ver_09-01-19.01) - NTFSx86 Run by [removed] at 5:56:17.15 on 31/01/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2942.1813 [GMT -5:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\PSIService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\WUDFHost.exe C:\hp\support\hpsysdrv.exe C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe C:\WINDOWS\RtHDVCpl.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\WINDOWS\System32\rundll32.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\System32\mobsync.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\hp\kbd\kbd.exe C:\Windows\system32\conime.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\House\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R6FL84RH\dds[1].scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ig?source=gama&hl=en uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: NoExplorer - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KbdStub.EXE mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe" -delete mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Corel File Shell Monitor] c:\program files\corel\corel paint shop pro photo x2\CorelIOMonitor.exe mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe StartupFolder: c:\users\house\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/OnlineScanner.cab DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Risk/Images/armhelper.ocx ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-20 64160] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-30 111184] R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-30 20560] R4 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2008-12-30 51792] S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 942416] =============== Created Last 30 ================ 2009-01-31 05:41 410,984 a——- c:\windows\system32\deploytk.dll 2009-01-31 05:05 250 a——- c:\windows\gmer.ini 2009-01-31 05:04 –d—– c:\program files\common files\PKWARE 2009-01-31 05:04 –d—– c:\program files\PKWARE 2009-01-29 16:22 –d—– c:\windows\system32\Adobe 2009-01-27 06:30 –d—– c:\users\house\.thumbnails 2009-01-27 06:27 –d—– c:\users\house\.gimp-2.6 2009-01-27 06:27 –d—– c:\users\house\.gegl-0.0 2009-01-27 06:27 –d—– c:\program files\GIMP-2.0 2009-01-23 20:16 –d—– c:\program files\Disney 2009-01-22 14:18 15,688 a——- c:\windows\system32\lsdelete.exe 2009-01-22 05:54 –d—– C:\apps 2009-01-20 04:38 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-01-20 04:36 -cd-h— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-01-20 04:36 -cd-h— c:\progra~2\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-01-20 04:36 –d—– c:\program files\Lavasoft 2009-01-19 11:05 –d—– c:\program files\SimpleD Budget 2009-01-18 11:14 –d—– c:\program files\Palace of Chance 2009-01-17 10:58 –d—– c:\program files\PKR 2009-01-17 04:11 –dsh— c:\users\house\appdata\roaming\.# 2009-01-17 04:11 –d—– c:\program files\common files\SWF Studio 2009-01-14 05:22 288,768 a——- c:\windows\system32\drivers\srv.sys 2009-01-13 06:36 –d—– c:\program files\GreenScreenWizardPro 2009-01-13 06:20 –d—– c:\program files\FXhome PhotoKey 2009-01-12 16:08 1,682 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-01-12 16:00 –d—– c:\programdata\Corel 2009-01-12 16:00 –d—– c:\progra~2\Corel 2009-01-12 15:55 –d—– c:\program files\common files\Corel 2009-01-10 11:18 56 a—h— c:\programdata\ezsidmv.dat 2009-01-10 11:18 56 a—h— c:\progra~2\ezsidmv.dat 2009-01-10 11:14 –d—– c:\programdata\Skype 2009-01-09 18:33 –d—– c:\program files\directx 2009-01-09 18:30 –d—– c:\program files\Activision Value 2009-01-09 04:48 –d—– c:\users\house\appdata\roaming\Anthropics 2009-01-09 04:45 –d—– c:\program files\Portrait Professional 8 Trial 2009-01-07 19:56 –d—– C:\ComboFix 2009-01-07 19:56 318,976 a——- c:\windows\system32\CF31372.exe 2009-01-06 07:50 –d—– c:\program files\MonkeyPhoto 2009-01-06 07:40 –d—– c:\program files\Greeting Card Studio 2009-01-06 05:00 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-01-06 05:00 891,448 a——- c:\windows\system32\drivers\tcpip.sys 2009-01-06 05:00 72,192 a——- c:\windows\system32\drivers\pacer.sys 2009-01-06 05:00 15,360 a——- c:\windows\system32\pacerprf.dll 2009-01-05 17:33 3,751,995 a——- c:\windows\system32\GPhotos.scr 2009-01-05 14:01 161,792 a——- c:\windows\SWREG.exe 2009-01-05 14:01 98,816 a——- c:\windows\sed.exe 2009-01-04 17:35 –d—– c:\programdata\NVIDIA 2009-01-04 17:19 553 a——- c:\windows\USetup.iss 2009-01-04 17:19 98,304 a——- c:\windows\RTKAUDIOSERVICE.EXE 2009-01-04 17:18 2,047,576 a——- c:\windows\system32\drivers\RTKVHDA.sys 2009-01-04 17:18 1,191,936 a——- c:\windows\RtlUpd.exe 2009-01-04 17:18 636,416 a——- c:\windows\system32\RtkPgExt.dll 2009-01-04 17:18 532,480 a——- c:\windows\system32\RTSndMgr.cpl 2009-01-04 17:18 135,168 a——- c:\windows\system32\SRSWOW.dll 2009-01-04 17:18 29,696 a——- c:\windows\system32\RtkCoInst.dll 2009-01-04 17:18 4,874,240 a——- c:\windows\RtHDVCpl.exe 2009-01-04 17:14 –d—– c:\users\house\appdata\roaming\WinBatch 2009-01-04 08:33 691 a——- c:\users\house\appdata\roaming\GetValue.vbs 2009-01-04 08:33 35 a——- c:\users\house\appdata\roaming\SetValue.bat 2009-01-04 08:32 78,336 a——- c:\windows\system32\Agent.OMZ.Fix.exe 2009-01-04 08:32 –d—– c:\windows\system32\SmitfraudFix 2009-01-04 06:54 –d—– c:\users\house\appdata\roaming\NeatImage SL 2009-01-04 06:53 –d—– c:\program files\Neat Image 2009-01-04 06:45 –d—– c:\program files\PictureCode 2009-01-03 16:11 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf 2009-01-01 09:32 –d—– c:\users\house\appdata\roaming\Malwarebytes 2009-01-01 09:32 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-01-01 09:32 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-01 09:32 –d—– c:\programdata\Malwarebytes 2009-01-01 09:32 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-01-01 09:32 –d—– c:\progra~2\Malwarebytes ==================== Find3M ==================== 2009-01-16 17:16 34 a——- c:\users\house\jagex_runescape_preferences.dat 2009-01-08 07:31 2,516 a–sh— c:\programdata\KGyGaAvL.sys 2009-01-08 07:31 2,516 a–sh— c:\progra~2\KGyGaAvL.sys 2009-01-08 07:31 88 —shr– c:\programdata\C0D09EBF43.sys 2009-01-08 07:31 88 —shr– c:\progra~2\C0D09EBF43.sys 2009-01-06 06:06 51,200 a——- c:\windows\inf\infpub.dat 2009-01-06 06:06 143,360 a——- c:\windows\inf\infstrng.dat 2009-01-04 17:30 86,016 a——- c:\windows\inf\infstor.dat 2009-01-04 17:18 319,456 a——- c:\windows\DIFxAPI.dll 2008-12-25 09:24 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2008-12-20 03:11 174 a–sh— c:\program files\desktop.ini 2008-12-20 03:02 665,600 a——- c:\windows\inf\drvindex.dat 2008-12-20 02:53 101,888 a——- c:\windows\system32\ifxcardm.dll 2008-12-20 02:53 82,432 a——- c:\windows\system32\axaltocm.dll 2008-12-10 04:36 296,960 a——- c:\windows\system32\gdi32.dll 2008-12-10 04:36 28,672 a——- c:\windows\system32\Apphlpdm.dll 2008-12-10 04:36 2,560 a——- c:\windows\apppatch\AcRes.dll 2008-12-10 04:36 2,154,496 a——- c:\windows\apppatch\AcGenral.dll 2008-12-10 04:36 460,288 a——- c:\windows\apppatch\AcSpecfc.dll 2008-12-10 04:36 541,696 a——- c:\windows\apppatch\AcLayers.dll 2008-12-10 04:36 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2008-12-10 04:36 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2008-12-10 04:36 1,695,744 a——- c:\windows\system32\gameux.dll 2008-12-10 04:36 52,736 a——- c:\windows\apppatch\iebrshim.dll 2008-12-10 04:35 2,048 a——- c:\windows\system32\tzres.dll 2008-12-10 04:34 2,927,104 a——- c:\windows\explorer.exe 2008-12-10 04:33 827,392 a——- c:\windows\system32\wininet.dll 2008-12-10 04:31 2,868,736 a——- c:\windows\system32\mf.dll 2008-12-10 04:31 98,816 a——- c:\windows\system32\mfps.dll 2008-12-10 04:30 53,248 a——- c:\windows\system32\rrinstaller.exe 2008-12-10 04:30 24,576 a——- c:\windows\system32\mfpmp.exe 2008-12-10 04:30 2,048 a——- c:\windows\system32\mferror.dll 2008-12-10 04:30 94,720 a——- c:\windows\system32\logagent.exe 2008-12-10 04:30 996,352 a——- c:\windows\system32\WMNetMgr.dll 2008-12-08 04:47 269,312 a——- c:\windows\system32\es.dll 2008-12-07 09:34 0 a—h— c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf 2008-12-06 15:02 61,440 a——- c:\windows\system32\winipsec.dll 2008-12-06 15:02 28,672 a——- c:\windows\system32\FwRemoteSvr.dll 2008-12-06 15:02 361,984 a——- c:\windows\system32\IPSECSVC.DLL 2008-12-06 15:02 272,896 a——- c:\windows\system32\polstore.dll 2008-12-06 15:01 241,152 a——- c:\windows\system32\PortableDeviceApi.dll 2008-12-06 15:01 160,768 a——- c:\windows\system32\PortableDeviceTypes.dll 2008-12-06 15:01 94,720 a——- c:\windows\system32\PortableDeviceClassExtension.dll 2008-12-06 14:58 428,544 a——- c:\windows\system32\EncDec.dll 2008-12-06 14:58 293,376 a——- c:\windows\system32\psisdecd.dll 2008-12-06 14:56 212,480 a——- c:\windows\system32\drivers\mrxsmb10.sys 2008-12-06 14:55 303,616 a——- c:\windows\system32\wmpeffects.dll 2008-12-06 14:54 2,032,640 a——- c:\windows\system32\win32k.sys 2008-12-06 14:54 1,191,936 a——- c:\windows\system32\msxml3.dll 2008-12-06 14:54 2,048 a——- c:\windows\system32\msxml3r.dll 2008-12-06 14:45 3,104,768 a——- c:\windows\system32\NlsData004b.dll 2008-12-06 14:43 6,656 a——- c:\windows\system32\kbd106n.dll 2008-12-06 14:43 988,216 a——- c:\windows\system32\winload.exe 2008-12-06 14:43 927,288 a——- c:\windows\system32\winresume.exe 2008-12-06 14:43 615,992 a——- c:\windows\system32\ci.dll 2008-12-06 14:43 378,368 a——- c:\windows\system32\srcore.dll 2008-12-06 14:43 318,464 a——- c:\windows\system32\rstrui.exe 2008-12-06 14:43 46,592 a——- c:\windows\system32\setbcdlocale.dll 2008-12-06 14:43 40,960 a——- c:\windows\system32\srclient.dll 2008-12-06 14:43 19,000 a——- c:\windows\system32\kd1394.dll 2008-12-06 14:43 14,848 a——- c:\windows\system32\srdelayed.exe 2008-12-06 14:40 425,472 a——- c:\windows\system32\PhotoMetadataHandler.dll 2008-12-06 14:40 712,704 a——- c:\windows\system32\WindowsCodecs.dll 2008-12-06 14:40 347,136 a——- c:\windows\system32\WindowsCodecsExt.dll 2008-12-06 14:39 443,392 a——- c:\windows\system32\win32spl.dll 2008-12-06 14:39 37,888 a——- c:\windows\system32\printcom.dll 2008-12-06 14:39 113,664 a——- c:\windows\system32\drivers\rmcast.sys 2008-12-06 14:39 14,848 a——- c:\windows\system32\wshrm.dll 2008-12-06 14:37 738,304 a——- c:\windows\system32\inetcomm.dll 2008-12-06 14:37 84,480 a——- c:\windows\system32\INETRES.dll 2008-12-06 14:37 1,645,568 a——- c:\windows\system32\connect.dll 2008-12-06 14:37 1,314,816 a——- c:\windows\system32\quartz.dll 2008-12-06 14:35 3,601,464 a——- c:\windows\system32\ntkrnlpa.exe 2008-12-06 14:35 3,549,240 a——- c:\windows\system32\ntoskrnl.exe 2008-12-06 14:35 1,334,272 a——- c:\windows\system32\msxml6.dll 2008-12-06 14:35 2,048 a——- c:\windows\system32\msxml6r.dll 2008-12-06 14:14 1,841 a–shr– c:\windows\system32\drivers\103C_HP_CPC_GN561AA-ABA a6230n_YC_0Pavi_QCNH732_E74NAv3PrA1_49_INARRA2_SASUSTek Computer INC._V2.00_B5.11_T070716_WUH0_L409_M2943_J400_7AMD_8Athlon 64 X2 Dual Core_92.8_#071225_N10DE03EF_Z14F12F20_G10DE03D0.MRK 2008-12-06 14:09 1,524,736 a——- c:\windows\system32\wucltux.dll 2008-12-06 14:09 83,456 a——- c:\windows\system32\wudriver.dll 2008-12-06 14:09 162,064 a——- c:\windows\system32\wuwebv.dll 2008-12-06 14:09 31,232 a——- c:\windows\system32\wuapp.exe 2008-11-24 03:06 129,520 ——– c:\windows\system32\PxAFS.DLL 2008-11-24 03:06 120,568 ——– c:\windows\system32\pxcpyi64.exe 2008-11-24 03:06 118,256 ——– c:\windows\system32\pxinsi64.exe 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2008-01-08 17:34 22 a–sh— c:\windows\sminst\HPCD.SYS 2007-08-05 00:16 8,192 a–sh— c:\windows\users\default\NTUSER.DAT ============= FINISH: 5:57:04.92 ===============
Malwarebytes' Anti-Malware 1.33 Database version: 1712 Windows 6.0.6001 Service Pack 1 31/01/2009 4:55:36 AM mbam-log-2009-01-31 (04-55-36).txt Scan type: Quick Scan Objects scanned: 50494 Time elapsed: 2 minute(s), 12 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\extravideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Users\House\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\extravideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\extravideo\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Hi,

Apologies, I forgot you were running Vista. Please right-click Internet Explorer and then select Run As Administrator… Then perform the ESET steps. Close Internet after completing all the ESET steps.

Can you run GMER as well please?

Also run HijackThis and post a fresh log from that.

Thanks.
Ok, did that, here are the logs you requested.
thank you


# version=4
# OnlineScanner.ocx=[removed]
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3818 (20090202)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=f7f07fae8542524c8038e6f765a442b7
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2009-02-02 12:21:26
# local_time=2009-02-02 07:21:26 (-0500, Eastern Standard Time)
# country="Canada"
# osver=6.0.6001 NT Service Pack 1
# scanned=543916
# found=1
# scan_time=4756
C:\Qoobox\Quarantine\C\WINDOWS\System32\msqpdxsniomovp.dll.vir a variant of Win32/Kryptik.DJ trojan 1191374317DFC03F54123B95EAB870DE





GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-02-02 10:46:57
Windows 6.0.6001 Service Pack 1


—- User code sections - GMER 1.0.14 —-

.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2272] kernel32.dll!SetUnhandledExceptionFilter 763D6E2D 5 Bytes JMP 0056DBBD C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation)

—- User IAT/EAT - GMER 1.0.14 —-

IAT C:\Windows\system32\services.exe[668] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00C20002
IAT C:\Windows\system32\services.exe[668] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 00C20000

—- Devices - GMER 1.0.14 —-

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.14 —-

Service system32\drivers\msqpdxcxxbbsus.sys (*** hidden *** ) [SYSTEM] msqpdxserv.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys@imagepath \systemroot\system32\drivers\msqpdxcxxbbsus.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys\modules@msqpdxserv \\?\globalroot\systemroot\system32\drivers\msqpdxcxxbbsus.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys\modules@msqpdxl \\?\globalroot\systemroot\system32\msqpdxpnjtvwbv.dll
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys@imagepath \systemroot\system32\drivers\msqpdxcxxbbsus.sys
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys\modules@msqpdxserv \\?\globalroot\systemroot\system32\drivers\msqpdxcxxbbsus.sys
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys\modules@msqpdxl \\?\globalroot\systemroot\system32\msqpdxpnjtvwbv.dll

—- EOF - GMER 1.0.14 —-



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:47:36 AM, on 02/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\System32\mobsync.exe
C:\Users\House\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 200.124.131.116 casinocontroller.com
O1 - Hosts: 200.124.131.116 casinocontroller.com
O1 - Hosts: 200.124.131.116 casinocontroller.com
O1 - Hosts: 200.124.131.116 casinocontroller.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe" -delete
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O13 - Gopher Prefix:
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} (PCPitstop AntiVirus) - http://utilities.pcpitstop.com/Exterminate…opAntiVirus.dll
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8020 bytes
Hi,

Looks like you've got a nasty that was trying to hide from us.

Please delete ComboFix if you have a copy on your machine. We need the latest version.

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Right click on the avast! icon in system tray (looks like this: [external image: Posted Image]) and choose (Stop On-Access Protection)

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks.
ComboFix 09-02-02.01 - House 2009-02-02 13:32:56.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2942.2005 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\House\AppData\Roaming\.#
c:\windows\system32\Agent.OMZ.Fix.exe

.
((((((((((((((((((((((((( Files Created from 2009-01-02 to 2009-02-02 )))))))))))))))))))))))))))))))
.

2009-02-02 13:21 . 2009-02-02 13:21 d——– c:\program files\Common Files\Macrovision Shared
2009-02-02 13:18 . 2009-02-02 13:21 d——– c:\users\House\AppData\Roaming\123 Free Solitaire
2009-02-02 13:16 . 2009-02-02 13:16 209 –a—— c:\windows\ODBCINST.INI
2009-02-02 11:22 . 2009-02-02 11:22 d——– c:\program files\Fractalus
2009-02-02 11:22 . 2009-02-02 11:22 d——– c:\program files\123 Free Solitaire
2009-02-02 11:19 . 2009-02-02 11:19 d——– c:\users\All Users\BVRP Software
2009-02-02 11:19 . 2009-02-02 11:19 d——– c:\programdata\BVRP Software
2009-02-02 11:19 . 2009-02-02 11:19 d——– c:\program files\Ringtone Media Studio
2009-02-02 11:19 . 2009-02-02 11:19 d——– c:\program files\Avanquest update
2009-02-02 11:19 . 2001-08-23 17:25 1,706,800 –a—— c:\windows\System32\gdiplus.dll
2009-02-02 05:58 . 2009-02-02 07:21 d——– c:\program files\EsetOnlineScanner
2009-01-31 05:41 . 2009-01-31 05:40 410,984 –a—— c:\windows\System32\deploytk.dll
2009-01-31 05:05 . 2009-02-02 07:37 250 –a—— c:\windows\gmer.ini
2009-01-31 05:04 . 2009-01-31 05:04 d——– c:\program files\PKWARE
2009-01-31 05:04 . 2009-01-31 05:04 d——– c:\program files\Common Files\PKWARE
2009-01-29 16:22 . 2009-01-29 16:22 d——– c:\windows\System32\Adobe
2009-01-27 06:30 . 2009-01-27 06:30 d——– c:\users\House\AppData\Roaming\gtk-2.0
2009-01-27 06:30 . 2009-01-27 06:30 d——– c:\users\House\.thumbnails
2009-01-27 06:27 . 2009-01-27 06:49 d——– c:\users\House\.gimp-2.6
2009-01-27 06:27 . 2009-01-27 06:27 d——– c:\users\House\.gegl-0.0
2009-01-27 06:27 . 2009-01-27 06:27 d——– c:\program files\GIMP-2.0
2009-01-23 20:16 . 2009-01-23 20:16 d——– c:\program files\Disney
2009-01-22 14:18 . 2009-01-18 16:35 15,688 –a—— c:\windows\System32\lsdelete.exe
2009-01-22 05:54 . 2009-01-22 05:54 d——– C:\apps
2009-01-20 04:38 . 2009-01-18 16:30 64,160 –a—— c:\windows\System32\drivers\Lbd.sys
2009-01-20 04:36 . 2009-01-20 04:36 d–h-c— c:\users\All Users\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-20 04:36 . 2009-01-20 04:36 d–h-c— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-20 04:36 . 2009-01-20 04:36 d——– c:\program files\Lavasoft
2009-01-19 11:05 . 2009-01-19 11:05 d——– c:\program files\SimpleD Budget
2009-01-18 11:14 . 2009-01-18 11:24 d——– c:\program files\Palace of Chance
2009-01-17 10:58 . 2009-01-17 13:10 d——– c:\program files\PKR
2009-01-17 04:11 . 2009-01-17 04:11 d——– c:\program files\Common Files\SWF Studio
2009-01-14 05:22 . 2008-12-15 21:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-13 06:36 . 2009-01-13 06:36 d——– c:\program files\GreenScreenWizardPro
2009-01-13 06:20 . 2009-01-13 06:20 d——– c:\program files\FXhome PhotoKey
2009-01-12 16:08 . 2009-02-02 12:01 1,682 –ahs—- c:\windows\System32\KGyGaAvL.sys
2009-01-12 16:00 . 2009-01-12 17:00 d——– c:\users\House\AppData\Roaming\Corel
2009-01-12 16:00 . 2009-01-12 17:01 d——– c:\users\All Users\Corel
2009-01-12 16:00 . 2009-01-12 17:01 d——– c:\programdata\Corel
2009-01-12 15:55 . 2009-01-12 16:58 d——– c:\program files\Common Files\Corel
2009-01-10 11:18 . 2009-01-12 21:28 d——– c:\users\House\AppData\Roaming\skypePM
2009-01-10 11:18 . 2009-01-10 11:18 56 –ah—– c:\users\All Users\ezsidmv.dat
2009-01-10 11:18 . 2009-01-10 11:18 56 –ah—– c:\programdata\ezsidmv.dat
2009-01-10 11:14 . 2009-01-13 12:46 d——– c:\users\All Users\Skype
2009-01-10 11:14 . 2009-01-13 12:46 d——– c:\programdata\Skype
2009-01-09 18:33 . 2009-01-09 18:33 d——– c:\program files\directx
2009-01-09 18:30 . 2009-01-09 18:30 d——– c:\program files\Activision Value
2009-01-09 04:48 . 2009-01-09 04:48 d——– c:\users\House\AppData\Roaming\Anthropics
2009-01-09 04:45 . 2009-01-09 04:45 d——– c:\program files\Portrait Professional 8 Trial
2009-01-06 07:50 . 2009-01-06 07:50 d——– c:\program files\MonkeyPhoto
2009-01-06 07:40 . 2009-01-06 07:40 d——– c:\program files\Greeting Card Studio
2009-01-06 05:00 . 2008-04-26 03:26 891,448 –a—— c:\windows\System32\drivers\tcpip.sys
2009-01-06 05:00 . 2008-04-11 22:32 784,896 –a—— c:\windows\System32\rpcrt4.dll
2009-01-06 05:00 . 2008-04-04 20:21 72,192 –a—— c:\windows\System32\drivers\pacer.sys
2009-01-06 05:00 . 2008-04-04 22:34 15,360 –a—— c:\windows\System32\pacerprf.dll
2009-01-05 17:33 . 2009-01-05 17:33 3,751,995 –a—— c:\windows\System32\GPhotos.scr
2009-01-04 17:35 . 2009-01-04 17:35 d——– c:\users\All Users\NVIDIA
2009-01-04 17:35 . 2009-01-04 17:35 d——– c:\programdata\NVIDIA
2009-01-04 17:19 . 2008-01-08 13:10 98,304 –a—— c:\windows\RTKAUDIOSERVICE.EXE
2009-01-04 17:19 . 2007-11-14 15:18 553 –a—— c:\windows\USetup.iss
2009-01-04 17:18 . 2008-01-15 11:26 4,874,240 –a—— c:\windows\RtHDVCpl.exe
2009-01-04 17:18 . 2008-01-15 19:19 2,047,576 –a—— c:\windows\System32\drivers\RTKVHDA.sys
2009-01-04 17:18 . 2007-11-07 17:31 1,191,936 –a—— c:\windows\RtlUpd.exe
2009-01-04 17:18 . 2008-01-09 18:52 636,416 –a—— c:\windows\System32\RtkPgExt.dll
2009-01-04 17:18 . 2007-11-13 12:35 532,480 –a—— c:\windows\System32\RTSndMgr.cpl
2009-01-04 17:18 . 2007-07-25 09:33 135,168 –a—— c:\windows\System32\SRSWOW.dll
2009-01-04 17:18 . 2008-01-14 16:18 29,696 –a—— c:\windows\System32\RtkCoInst.dll
2009-01-04 17:14 . 2009-01-04 17:14 d——– c:\users\House\AppData\Roaming\WinBatch
2009-01-04 12:12 . 2009-01-04 12:12 d——– c:\windows\Sun
2009-01-04 08:33 . 2009-01-04 08:33 691 –a—— c:\users\House\AppData\Roaming\GetValue.vbs
2009-01-04 08:33 . 2009-01-04 08:33 35 –a—— c:\users\House\AppData\Roaming\SetValue.bat
2009-01-04 08:32 . 2009-01-04 08:35 d——– c:\windows\System32\SmitfraudFix
2009-01-04 06:54 . 2009-01-04 06:54 d——– c:\users\House\AppData\Roaming\NeatImage SL
2009-01-04 06:53 . 2009-01-04 06:53 d——– c:\program files\Neat Image
2009-01-04 06:45 . 2009-01-04 06:45 d——– c:\program files\PictureCode
2009-01-03 16:11 . 2009-01-03 16:11 0 –ah—– c:\windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-02 18:31 ——— d—–w c:\users\House\AppData\Roaming\LimeWire
2009-02-02 18:21 ——— d—–w c:\program files\Common Files\Adobe
2009-02-02 16:19 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-02 10:00 ——— d—a-w c:\programdata\TEMP
2009-02-02 00:22 34 —-a-w c:\users\House\jagex_runescape_preferences.dat
2009-01-31 10:40 ——— d—–w c:\program files\Java
2009-01-31 09:58 ——— d—–w c:\programdata\WinZip
2009-01-31 09:52 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-01-20 09:36 ——— d—–w c:\programdata\Lavasoft
2009-01-18 15:21 ——— d—–w c:\program files\PCPitstop
2009-01-18 15:20 ——— d—–w c:\programdata\Symantec
2009-01-18 15:20 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-14 21:11 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 21:11 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-01-14 10:34 ——— d—–w c:\program files\Windows Mail
2009-01-12 21:59 ——— d—–w c:\program files\Common Files\PX Storage Engine
2009-01-12 21:58 ——— d—–w c:\program files\Corel
2009-01-11 22:51 ——— d—–w c:\program files\HP
2009-01-08 12:31 88 –sh–r c:\users\All Users\C0D09EBF43.sys
2009-01-08 12:31 88 –sh–r c:\programdata\C0D09EBF43.sys
2009-01-08 12:31 2,516 –sha-w c:\users\All Users\KGyGaAvL.sys
2009-01-08 12:31 2,516 –sha-w c:\programdata\KGyGaAvL.sys
2009-01-04 22:22 ——— d—–w c:\program files\Risk
2009-01-04 22:18 319,456 —-a-w c:\windows\DIFxAPI.dll
2009-01-04 22:18 ——— d—–w c:\program files\Realtek
2009-01-01 14:32 ——— d—–w c:\users\House\AppData\Roaming\Malwarebytes
2009-01-01 14:32 ——— d—–w c:\programdata\Malwarebytes
2008-12-31 23:19 ——— d—–w c:\users\House\AppData\Roaming\Boomzap
2008-12-30 22:10 ——— d—–w c:\program files\HP Games
2008-12-30 10:28 ——— d—–w c:\program files\Alwil Software
2008-12-30 10:19 ——— d—–w c:\programdata\avg8
2008-12-30 08:54 ——— d—–w c:\program files\CCleaner
2008-12-29 13:25 ——— d—–w c:\programdata\PC Tools
2008-12-28 10:02 ——— d–h–w c:\programdata\yahoo!
2008-12-28 10:02 ——— d—–w c:\users\House\AppData\Roaming\Snapfish
2008-12-28 10:02 ——— d—–w c:\program files\Yahoo!
2008-12-28 09:59 ——— d—–w c:\programdata\PCPitstop
2008-12-28 09:54 ——— d—–w c:\program files\MeadCo Neptune
2008-12-27 12:23 ——— d—–w c:\programdata\MGS
2008-12-27 10:32 ——— d—–w c:\programdata\Microgaming
2008-12-27 02:28 ——— d—–w c:\programdata\PopCap Games
2008-12-27 02:27 ——— d—–w c:\programdata\WildTangent
2008-12-25 19:40 ——— d—–w c:\users\House\AppData\Roaming\Apple Computer
2008-12-25 14:54 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-25 14:54 ——— d—–w c:\program files\iTunes
2008-12-25 14:53 ——— d—–w c:\program files\iPod
2008-12-25 14:53 ——— d—–w c:\program files\Common Files\Apple
2008-12-25 14:53 ——— d—–w c:\program files\Bonjour
2008-12-25 14:52 ——— d—–w c:\programdata\Apple Computer
2008-12-25 14:52 ——— d—–w c:\program files\QuickTime
2008-12-25 14:24 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-12-25 13:58 ——— d—–w c:\programdata\Apple
2008-12-25 13:58 ——— d—–w c:\program files\Apple Software Update
2008-12-23 21:45 ——— d—–w c:\programdata\KingsIsle Entertainment
2008-12-23 12:01 ——— d—–w c:\users\House\AppData\Roaming\PCToolsSpamMonitorPlus
2008-12-23 12:01 ——— d—–w c:\users\House\AppData\Roaming\PCToolsFirewallPlus
2008-12-20 14:16 ——— d—–w c:\users\House\AppData\Roaming\WildTangent
2008-12-20 08:11 174 –sha-w c:\program files\desktop.ini
2008-12-20 08:05 ——— d—–w c:\program files\Windows Sidebar
2008-12-20 08:05 ——— d—–w c:\program files\Windows Photo Gallery
2008-12-20 08:05 ——— d—–w c:\program files\Windows Journal
2008-12-20 08:05 ——— d—–w c:\program files\Windows Defender
2008-12-20 08:05 ——— d—–w c:\program files\Windows Collaboration
2008-12-20 08:05 ——— d—–w c:\program files\Windows Calendar
2008-12-20 07:53 82,432 —-a-w c:\windows\System32\axaltocm.dll
2008-12-20 07:53 101,888 —-a-w c:\windows\System32\ifxcardm.dll
2008-12-19 10:35 ——— d—–w c:\program files\Microsoft Silverlight
2008-12-17 09:42 ——— d—–w c:\program files\Bonusprint PIX
2008-12-10 09:36 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2008-12-10 09:36 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-12-10 09:36 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2008-12-10 09:36 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-10 09:36 296,960 —-a-w c:\windows\System32\gdi32.dll
2008-12-10 09:36 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2008-12-10 09:36 2,560 —-a-w c:\windows\AppPatch\AcRes.dll
2008-12-10 09:36 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2008-12-10 09:36 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2008-12-10 09:36 1,695,744 —-a-w c:\windows\System32\gameux.dll
2008-12-10 09:35 2,048 —-a-w c:\windows\System32\tzres.dll
2008-12-10 09:34 2,927,104 —-a-w c:\windows\explorer.exe
2008-12-10 09:33 827,392 —-a-w c:\windows\System32\wininet.dll
2008-12-10 09:31 98,816 —-a-w c:\windows\System32\mfps.dll
2008-12-10 09:31 2,868,736 —-a-w c:\windows\System32\mf.dll
2008-12-10 09:30 996,352 —-a-w c:\windows\System32\WMNetMgr.dll
2008-12-10 09:30 94,720 —-a-w c:\windows\System32\logagent.exe
2008-12-10 09:30 53,248 —-a-w c:\windows\System32\rrinstaller.exe
2008-12-10 09:30 24,576 —-a-w c:\windows\System32\mfpmp.exe
2008-12-10 09:30 2,048 —-a-w c:\windows\System32\mferror.dll
2008-12-08 22:04 ——— d—–w c:\program files\LimeWire
2008-12-08 17:31 ——— d—–w c:\users\House\AppData\Roaming\Canon
2008-12-08 09:47 269,312 —-a-w c:\windows\System32\es.dll
2008-12-08 09:45 ——— d—–w c:\program files\Microsoft Works
2008-12-07 23:58 ——— d—–w c:\program files\Windows Live
2008-12-07 23:55 ——— dcsh–w c:\program files\Common Files\WindowsLiveInstaller
2008-12-07 23:49 ——— d—–w c:\programdata\WLInstaller
2008-12-07 14:34 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-12-07 14:33 ——— d—–w c:\program files\Common Files\Motorola Shared
2008-12-07 14:11 ——— d—–w c:\program files\Canon
2008-12-07 02:08 ——— d—–w c:\program files\Google
2008-12-06 21:41 ——— d—–w c:\users\House\AppData\Roaming\SpinTop
.

((((((((((((((((((((((((((((( snapshot@2009-01-05_14.11.14.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-20 12:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2009-01-31 10:05:33 884,736 —-a-w c:\windows\gmer.dll
+ 2008-04-18 02:13:02 811,008 —-a-w c:\windows\gmer.exe
- 2009-01-04 22:30:27 51,200 —-a-w c:\windows\inf\infpub.dat
+ 2009-01-06 11:06:35 51,200 —-a-w c:\windows\inf\infpub.dat
- 2009-01-04 22:30:27 143,360 —-a-w c:\windows\inf\infstrng.dat
+ 2009-01-06 11:06:34 143,360 —-a-w c:\windows\inf\infstrng.dat
+ 2007-09-13 17:00:00 77,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\am.dll
+ 2007-09-13 17:00:00 904,008 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdartistic.dll
+ 2007-09-13 17:00:00 154,440 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdartisticrc.dll
+ 2007-09-13 17:00:00 154,440 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdartisticrc.dll0
+ 2007-09-13 17:00:00 1,373,000 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbase1.dll
+ 2007-09-13 17:00:00 582,472 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbase1rc.dll
+ 2007-09-13 17:00:00 582,472 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbase1rc.dll0
+ 2007-09-13 17:00:00 1,870,664 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbase2.dll
+ 2007-09-13 17:00:00 2,717,512 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbase2rc.dll
+ 2007-09-13 17:00:00 2,717,512 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbase2rc.dll0
+ 2007-09-13 17:00:00 247,624 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbevels.dll
+ 2007-09-13 17:00:00 23,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbevelsrc.dll
+ 2007-09-13 17:00:00 23,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdbevelsrc.dll0
+ 2007-09-13 17:00:00 428,872 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdclipboard.dll
+ 2007-09-13 17:00:00 51,016 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdclipboardrc.dll
+ 2007-09-13 17:00:00 51,016 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdclipboardrc.dll0
+ 2007-09-13 17:00:00 791,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdcolor.dll
+ 2007-09-13 17:00:00 3,293,512 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdcolorrc.dll
+ 2007-09-13 17:00:00 3,293,512 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdcolorrc.dll0
+ 2007-09-13 17:00:00 165,192 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdemail.dll
+ 2007-09-13 17:00:00 118,600 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdemailrc.dll
+ 2007-09-13 17:00:00 118,600 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdemailrc.dll0
+ 2007-09-13 17:00:00 118,088 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdexternal.dll
+ 2007-09-13 17:00:00 19,784 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdexternalrc.dll
+ 2007-09-13 17:00:00 19,784 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdexternalrc.dll0
+ 2007-09-13 17:00:00 1,300,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdfile.dll
+ 2007-09-13 17:00:00 1,514,312 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdfilerc.dll
+ 2007-09-13 17:00:00 1,514,312 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdfilerc.dll0
+ 2007-09-13 17:00:00 575,816 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdgeometry.dll
+ 2007-09-13 17:00:00 93,000 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdgeometryrc.dll
+ 2007-09-13 17:00:00 93,000 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdgeometryrc.dll0
+ 2007-09-13 17:00:00 165,192 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdjgl.dll
+ 2007-09-13 17:00:00 23,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdjglrc.dll
+ 2007-09-13 17:00:00 23,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdjglrc.dll0
+ 2007-09-13 17:00:00 1,085,768 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlayers.dll
+ 2007-09-13 17:00:00 258,376 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlayersrc.dll
+ 2007-09-13 17:00:00 258,376 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlayersrc.dll0
+ 2007-09-13 17:00:00 200,520 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlighting.dll
+ 2007-09-13 17:00:00 23,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlightingrc.dll
+ 2007-09-13 17:00:00 23,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlightingrc.dll0
+ 2007-09-13 17:00:00 23,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlightingrc.dll5
+ 2007-09-13 17:00:00 23,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlightingrc.dll7
+ 2007-09-13 17:00:00 23,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdlightingrc.dll9
+ 2007-09-13 17:00:00 874,312 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdnongraphic.dll
+ 2007-09-13 17:00:00 661,832 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdnongraphicrc.dll
+ 2007-09-13 17:00:00 661,832 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdnongraphicrc.dll0
+ 2007-09-13 17:00:00 250,696 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdorganizer.dll
+ 2007-09-13 17:00:00 30,024 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdorganizerrc.dll
+ 2007-09-13 17:00:00 30,024 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdorganizerrc.dll0
+ 2007-09-13 17:00:00 1,288,520 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdphoto.dll
+ 2007-09-13 17:00:00 1,687,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdphotorc.dll
+ 2007-09-13 17:00:00 1,687,880 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdphotorc.dll0
+ 2007-09-13 17:00:00 147,784 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdphotosharing.dll
+ 2007-09-13 17:00:00 14,152 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdphotosharingrc.dll
+ 2007-09-13 17:00:00 14,152 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdphotosharingrc.dll0
+ 2007-09-13 17:00:00 239,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpluginhost.dll
+ 2007-09-13 17:00:00 11,592 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpluginhostrc.dll
+ 2007-09-13 17:00:00 11,592 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpluginhostrc.dll0
+ 2007-09-13 17:00:00 11,592 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpluginhostrc.dll5
+ 2007-09-13 17:00:00 11,592 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpluginhostrc.dll6
+ 2007-09-13 17:00:00 11,592 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpluginhostrc.dll7
+ 2007-09-13 17:00:00 11,592 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpluginhostrc.dll9
+ 2007-09-13 17:00:00 267,080 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdprint.dll
+ 2007-09-13 17:00:00 57,160 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdprintrc.dll
+ 2007-09-13 17:00:00 57,160 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdprintrc.dll0
+ 2007-09-13 17:00:00 319,816 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpyscript.dll
+ 2007-09-13 17:00:00 91,976 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpyscriptrc.dll
+ 2007-09-13 17:00:00 91,976 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdpyscriptrc.dll0
+ 2007-09-13 17:00:00 676,680 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdselections.dll
+ 2007-09-13 17:00:00 1,314,632 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdselectionsrc.dll
+ 2007-09-13 17:00:00 1,314,632 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdselectionsrc.dll0
+ 2007-09-13 17:00:00 352,072 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdslideshow.dll
+ 2007-09-13 17:00:00 87,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdslideshowrc.dll
+ 2007-09-13 17:00:00 87,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdslideshowrc.dll0
+ 2007-09-13 17:00:00 755,528 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdstandard.dll
+ 2007-09-13 17:00:00 1,353,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdstandardrc.dll
+ 2007-09-13 17:00:00 1,353,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdstandardrc.dll0
+ 2007-09-13 17:00:00 416,072 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdtexture.dll
+ 2007-09-13 17:00:00 56,136 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdtexturerc.dll
+ 2007-09-13 17:00:00 56,136 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdtexturerc.dll0
+ 2007-09-13 17:00:00 301,896 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdvector.dll
+ 2007-09-13 17:00:00 71,496 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdvectorrc.dll
+ 2007-09-13 17:00:00 71,496 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdvectorrc.dll0
+ 2007-09-13 17:00:00 414,024 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdweb.dll
+ 2007-09-13 17:00:00 49,992 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdwebrc.dll
+ 2007-09-13 17:00:00 49,992 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\cmdwebrc.dll0
+ 2007-09-13 17:00:00 111,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corebrowserutil.dll
+ 2007-09-13 17:00:00 23,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corebrowserutilrc.dll
+ 2007-09-13 17:00:00 23,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corebrowserutilrc.dll0
+ 2007-09-13 17:00:00 24,392 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecapture.dll
+ 2007-09-13 17:00:00 2,642,760 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecmd.dll
+ 2007-09-13 17:00:00 211,784 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecmdrc.dll
+ 2007-09-13 17:00:00 211,784 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecmdrc.dll0
+ 2007-09-13 17:00:00 175,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecolormgr.dll
+ 2007-09-13 17:00:00 9,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecolormgrrc.dll
+ 2007-09-13 17:00:00 9,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecolormgrrc.dll0
+ 2007-09-13 17:00:00 9,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecolormgrrc.dll5
+ 2007-09-13 17:00:00 9,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecolormgrrc.dll6
+ 2007-09-13 17:00:00 9,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecolormgrrc.dll7
+ 2007-09-13 17:00:00 9,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecolormgrrc.dll8
+ 2007-09-13 17:00:00 9,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecolormgrrc.dll9
+ 2007-09-13 17:00:00 1,060,168 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecontrols.dll
+ 2007-09-13 17:00:00 532,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecontrolsrc.dll
+ 2007-09-13 17:00:00 532,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corecontrolsrc.dll0
+ 2007-09-13 17:00:00 269,128 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreenums.dll
+ 2007-09-13 17:00:00 36,168 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreerrorcodes.dll
+ 2007-09-13 17:00:00 47,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreerrorcodesrc.dll
+ 2007-09-13 17:00:00 47,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreerrorcodesrc.dll0
+ 2007-09-13 17:00:00 316,744 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corefileformats.dll
+ 2007-09-13 17:00:00 69,960 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corefileformatsrc.dll
+ 2007-09-13 17:00:00 69,960 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corefileformatsrc.dll0
+ 2007-09-13 17:00:00 836,936 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corefileutil.dll
+ 2007-09-13 17:00:00 32,072 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corefileutilrc.dll
+ 2007-09-13 17:00:00 32,072 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corefileutilrc.dll0
+ 2007-09-13 17:00:00 1,612,104 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coregdi.dll
+ 2007-09-13 17:00:00 1,662,280 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coregui.dll
+ 2007-09-13 17:00:00 67,912 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreguirc.dll
+ 2007-09-13 17:00:00 67,912 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreguirc.dll0
+ 2007-09-13 17:00:00 109,896 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehistorypalette.dll
+ 2007-09-13 17:00:00 18,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehistorypaletterc.dll
+ 2007-09-13 17:00:00 18,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehistorypaletterc.dll0
+ 2007-09-13 17:00:00 18,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehistorypaletterc.dll5
+ 2007-09-13 17:00:00 18,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehistorypaletterc.dll6
+ 2007-09-13 17:00:00 18,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehistorypaletterc.dll7
+ 2007-09-13 17:00:00 18,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehistorypaletterc.dll8
+ 2007-09-13 17:00:00 18,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehistorypaletterc.dll9
+ 2007-09-13 17:00:00 13,640 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corehook.dll
+ 2007-09-13 17:00:00 1,918,792 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreimageformats.dll
+ 2007-09-13 17:00:00 15,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreimageformatsrc.dll
+ 2007-09-13 17:00:00 15,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreimageformatsrc.dll0
+ 2007-09-13 17:00:00 15,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreimageformatsrc.dll5
+ 2007-09-13 17:00:00 15,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreimageformatsrc.dll6
+ 2007-09-13 17:00:00 15,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreimageformatsrc.dll8
+ 2007-09-13 17:00:00 15,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreimageformatsrc.dll9
+ 2007-09-13 17:00:00 60,744 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelanguage.dll
+ 2007-09-13 17:00:00 178,504 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelayerpalette.dll
+ 2007-09-13 17:00:00 40,776 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelayerpaletterc.dll
+ 2007-09-13 17:00:00 40,776 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelayerpaletterc.dll0
+ 2007-09-13 17:00:00 105,288 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelearningcenter.dll
+ 2007-09-13 17:00:00 12,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelearningcenterrc.dll
+ 2007-09-13 17:00:00 12,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelearningcenterrc.dll0
+ 2007-09-13 17:00:00 12,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelearningcenterrc.dll5
+ 2007-09-13 17:00:00 12,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelearningcenterrc.dll6
+ 2007-09-13 17:00:00 12,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelearningcenterrc.dll7
+ 2007-09-13 17:00:00 12,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelearningcenterrc.dll8
+ 2007-09-13 17:00:00 12,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corelearningcenterrc.dll9
+ 2007-09-13 17:00:00 427,848 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corematerialpalette.dll
+ 2007-09-13 17:00:00 53,064 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corematerialpaletterc.dll
+ 2007-09-13 17:00:00 53,064 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corematerialpaletterc.dll0
+ 2007-09-13 17:00:00 53,064 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corematerialpaletterc.dll6
+ 2007-09-13 17:00:00 74,056 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corememory.dll
+ 2007-09-13 17:00:00 393,032 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coremip.dll
+ 2007-09-13 17:00:00 46,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coremiprc.dll
+ 2007-09-13 17:00:00 46,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coremiprc.dll0
+ 2007-09-13 17:00:00 248,136 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coremultimedia.dll
+ 2007-09-13 17:00:00 61,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coremultimediarc.dll
+ 2007-09-13 17:00:00 61,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coremultimediarc.dll0
+ 2007-09-13 17:00:00 61,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coremultimediarc.dll5
+ 2007-09-13 17:00:00 1,241,416 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreorganizer.dll
+ 2007-09-13 17:00:00 167,752 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreorganizerrc.dll
+ 2007-09-13 17:00:00 167,752 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreorganizerrc.dll0
+ 2007-09-13 17:00:00 128,840 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corepreferences.dll
+ 2007-09-13 17:00:00 42,312 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corepreferencesrc.dll
+ 2007-09-13 17:00:00 42,312 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corepreferencesrc.dll0
+ 2007-09-13 17:00:00 2,213,192 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\corepython25.dll
+ 2007-09-13 17:00:00 36,168 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coresingletonmgr.dll
+ 2007-09-13 17:00:00 610,120 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreslideshow.dll
+ 2007-09-13 17:00:00 20,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreslideshowrc.dll
+ 2007-09-13 17:00:00 20,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreslideshowrc.dll0
+ 2007-09-13 17:00:00 20,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreslideshowrc.dll5
+ 2007-09-13 17:00:00 20,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coreslideshowrc.dll9
+ 2007-09-13 17:00:00 140,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coresvgidentify.dll
+ 2007-09-13 17:00:00 1,910,088 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\coresvgimport.dll
+ 2007-09-13 17:00:00 31,048 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\email.exe
+ 2007-09-13 17:00:00 619,848 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\mediacataloger.exe
+ 2007-09-13 17:00:00 46,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\mediacatalogerrc.dll
+ 2007-09-13 17:00:00 46,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\mediacatalogerrc.dll0
+ 2007-09-13 17:00:00 1,060,864 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\mfc71.dll
+ 2007-09-13 17:00:00 1,101,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\mfc80.dll
+ 2007-09-13 17:00:00 499,712 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\msvcp71.dll
+ 2007-09-13 17:00:00 548,864 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\msvcp80.dll
+ 2007-09-13 17:00:00 348,160 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\msvcr71.dll
+ 2007-09-13 17:00:00 626,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\msvcr80.dll
+ 2007-09-13 17:00:00 86,344 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\photoupload.exe
+ 2007-09-13 17:00:00 38,216 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\photouploadrc.dll
+ 2007-09-13 17:00:00 38,216 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\photouploadrc.dll0
+ 2007-09-13 17:00:00 132,424 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\renderer.dll
+ 2007-09-13 17:00:00 107,848 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\riffio.dll
+ 2007-09-13 17:00:00 776,520 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolart.dll
+ 2007-09-13 17:00:00 46,920 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolartrc.dll
+ 2007-09-13 17:00:00 46,920 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolartrc.dll0
+ 2007-09-13 17:00:00 1,653,064 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolobject.dll
+ 2007-09-13 17:00:00 386,376 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolobjectrc.dll
+ 2007-09-13 17:00:00 386,376 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolobjectrc.dll0
+ 2007-09-13 17:00:00 1,443,144 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolpaint.dll
+ 2007-09-13 17:00:00 106,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolpaintrc.dll
+ 2007-09-13 17:00:00 106,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolpaintrc.dll0
+ 2007-09-13 17:00:00 399,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolselect.dll
+ 2007-09-13 17:00:00 33,096 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolselectrc.dll
+ 2007-09-13 17:00:00 33,096 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolselectrc.dll0
+ 2007-09-13 17:00:00 717,640 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolstandard.dll
+ 2007-09-13 17:00:00 451,912 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\tooltext.dll
+ 2007-09-13 17:00:00 47,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\tooltextrc.dll
+ 2007-09-13 17:00:00 47,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\tooltextrc.dll0
+ 2007-09-13 17:00:00 737,096 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolwarp.dll
+ 2007-09-13 17:00:00 54,600 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolwarprc.dll
+ 2007-09-13 17:00:00 54,600 —-a-r c:\windows\Installer\$PatchCache$\Managed\1BF27E46343277944B8A62C25DD3B03D\12.1.0\toolwarprc.dll0
+ 2007-08-21 16:50:00 77,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\am.dll
+ 2007-08-21 16:50:00 83,272 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\camwia.dll
+ 2007-08-21 16:50:00 1,227,592 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdbase1.dll
+ 2007-08-21 16:50:00 208,712 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdbase1rc.dll
+ 2007-08-21 16:50:00 1,705,800 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdbase2.dll
+ 2007-08-21 16:50:00 1,556,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdbase2rc.dll
+ 2007-08-21 16:50:00 137,032 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdemail.dll
+ 2007-08-21 16:50:00 118,088 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdemailrc.dll
+ 2007-08-21 16:50:00 130,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdjgl.dll
+ 2007-08-21 16:50:00 23,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdjglrc.dll
+ 2007-08-21 16:50:00 186,696 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdorganizer.dll
+ 2007-08-21 16:50:00 25,928 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdorganizerrc.dll
+ 2007-08-21 16:50:00 122,696 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdphotosharing.dll
+ 2007-08-21 16:50:00 14,152 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdphotosharingrc.dll
+ 2007-08-21 16:50:00 223,048 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdprojects.dll
+ 2007-08-21 16:50:00 31,560 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdprojectsrc.dll
+ 2007-08-21 16:50:00 300,360 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdslideshow.dll
+ 2007-08-21 16:50:00 87,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\cmdslideshowrc.dll
+ 2007-08-21 16:50:00 2,333,000 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corecmd.dll
+ 2007-08-21 16:50:00 213,320 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corecmdrc.dll
+ 2007-08-21 16:50:00 150,856 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corecolormgr.dll
+ 2007-08-21 16:50:00 9,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corecolormgrrc.dll
+ 2007-08-21 16:50:00 1,012,040 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corecontrols.dll
+ 2007-08-21 16:50:00 155,976 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corecontrolsrc.dll
+ 2007-08-21 16:50:00 255,816 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreenums.dll
+ 2007-08-21 16:50:00 124,232 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreenumsrc.dll
+ 2007-08-21 16:50:00 29,512 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreerrorcodes.dll
+ 2007-08-21 16:50:00 47,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreerrorcodesrc.dll
+ 2007-08-21 16:50:00 296,264 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corefileformats.dll
+ 2007-08-21 16:50:00 69,448 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corefileformatsrc.dll
+ 2007-08-21 16:50:00 759,624 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corefileutil.dll
+ 2007-08-21 16:50:00 31,048 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corefileutilrc.dll
+ 2007-08-21 16:50:00 1,530,696 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coregdi.dll
+ 2007-08-21 16:50:00 1,594,696 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coregui.dll
+ 2007-08-21 16:50:00 67,912 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreguirc.dll
+ 2007-08-21 16:50:00 1,882,952 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreimageformats.dll
+ 2007-08-21 16:50:00 15,176 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreimageformatsrc.dll
+ 2007-08-21 16:50:00 2,301,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corel_mediaone.exe
+ 2007-08-21 16:50:00 42,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corelanguage.dll
+ 2007-08-21 16:50:00 66,376 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corememory.dll
+ 2007-08-21 16:50:00 230,728 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coremultimedia.dll
+ 2007-08-21 16:50:00 61,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coremultimediarc.dll
+ 2007-08-21 16:50:00 1,086,792 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreorganizer.dll
+ 2007-08-21 16:50:00 164,168 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreorganizerrc.dll
+ 2007-08-21 16:50:00 126,280 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corepreferences.dll
+ 2007-08-21 16:50:00 41,288 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corepreferencesrc.dll
+ 2007-08-21 16:50:00 517,448 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreprojects.dll
+ 2007-08-21 16:50:00 42,312 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreprojectsrc.dll
+ 2007-08-21 16:50:00 1,873,224 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\corepython24.dll
+ 2007-08-21 16:50:00 27,464 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coresingletonmgr.dll
+ 2007-08-21 16:50:00 570,696 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreslideshow.dll
+ 2007-08-21 16:50:00 19,784 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\coreslideshowrc.dll
+ 2007-08-21 16:50:00 28,488 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\email.exe
+ 2007-08-21 16:50:00 2,180,968 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\igcore15d.dll
+ 2007-08-21 16:50:00 632,680 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\igjpeg2k15d.dll
+ 2007-08-21 16:50:00 75,624 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\iglzw15d.dll
+ 2007-08-21 16:50:00 542,568 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\kdu_v52r.dll
+ 2007-08-21 16:50:00 574,792 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\mediacataloger.exe
+ 2007-08-21 16:50:00 1,060,864 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\mfc71.dll
+ 2007-08-21 16:50:00 499,712 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\msvcp71.dll
+ 2007-08-21 16:50:00 348,160 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\msvcr71.dll
+ 2007-08-21 16:50:00 73,032 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\photoupload.exe
+ 2007-08-21 16:50:00 38,728 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\photouploadrc.dll
+ 2007-08-21 16:50:00 427,848 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\tooltext.dll
+ 2007-08-21 16:50:00 47,944 —-a-r c:\windows\Installer\$PatchCache$\Managed\336965C3ED8C2E64BBF86F158986C1F2\2.0.0\tooltextrc.dll
+ 2009-01-12 22:15:20 22,486 —-a-r c:\windows\Installer\{3C569633-C8DE-46E2-BB8F-F65198681C2F}\ARPPRODUCTICON.exe
+ 2009-01-12 22:15:20 22,486 —-a-r c:\windows\Installer\{3C569633-C8DE-46E2-BB8F-F65198681C2F}\NewShortcut1.73D5A293_D496_4B44_B535_AA8F98088895.exe
+ 2009-01-12 22:15:20 8,854 —-a-r c:\windows\Installer\{3C569633-C8DE-46E2-BB8F-F65198681C2F}\ShortcutUninstall.exe
+ 2009-01-12 22:15:20 22,486 —-a-r c:\windows\Installer\{3C569633-C8DE-46E2-BB8F-F65198681C2F}\SnapfireIcon_Corel.exe
- 2008-12-21 01:45:44 394,534 —-a-r c:\windows\Installer\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}\ARPPRODUCTICON.exe
+ 2009-01-14 10:19:10 394,534 —-a-r c:\windows\Installer\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}\ARPPRODUCTICON.exe
- 2008-12-21 01:45:44 22,486 —-a-r c:\windows\Installer\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}\NewShortcut1.73D5A293_D496_4B44_B535_AA8F98088895.exe
+ 2009-01-14 10:19:09 22,486 —-a-r c:\windows\Installer\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}\NewShortcut1.73D5A293_D496_4B44_B535_AA8F98088895.exe
+ 2009-01-31 10:04:50 69,632 —-a-r c:\windows\Installer\{856C155E-4A74-4041-B026-04F96FFD1BCD}\NewShortcut2_964897AB9B3346B68EB8A3193DFFAD09.exe
+ 2009-01-31 10:04:50 69,632 —-a-r c:\windows\Installer\{856C155E-4A74-4041-B026-04F96FFD1BCD}\NewShortcut3_964897AB9B3346B68EB8A3193DFFAD09.exe
+ 2009-01-07 11:17:45 292,878 —-a-r c:\windows\Installer\{A4EE4223-98B1-4874-BA6E-E8A574F9C0FF}\ARPPRODUCTICON.exe
+ 2009-01-07 11:17:45 292,878 —-a-r c:\windows\Installer\{A4EE4223-98B1-4874-BA6E-E8A574F9C0FF}\NewShortcut4_C2C2101F05384548B5AF39E0D3B3CB50.exe
+ 2009-01-07 11:17:45 292,878 —-a-r c:\windows\Installer\{A4EE4223-98B1-4874-BA6E-E8A574F9C0FF}\RunLightroom313212_C2C2101F05384548B5AF39E0D3B3CB50.exe
+ 2009-01-11 22:51:59 689,456 —-a-r c:\windows\Installer\{FE57DE70-95DE-4B64-9266-84DA811053DB}\HPSUShortcut_BB85ED9CAFC943BDB8DC258C3C7DF72E.exe
- 2000-08-31 13:00:00 28,672 —-a-w c:\windows\NIRCMD.exe
+ 2000-08-31 13:00:00 29,696 —-a-w c:\windows\NIRCMD.exe
- 2009-01-05 19:05:05 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-02-02 18:28:49 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-01-05 19:05:05 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-02 18:28:49 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-05 19:10:59 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-02 18:30:36 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-12-20 08:11:50 2,638,619 -c–a-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2009-01-06 11:26:21 2,638,619 -c–a-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
- 2009-01-05 19:10:54 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-02 18:30:28 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-02 18:30:28 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
+ 2009-01-16 22:19:40 202,168 —-a-w c:\windows\System32\Adobe\Director\swdir.dll
+ 2009-01-16 22:19:58 67,000 —-a-w c:\windows\System32\Adobe\Director\SwDnld.exe
- 2008-01-19 07:26:52 36,864 —-a-w c:\windows\System32\cdd.dll
+ 2008-08-02 03:26:00 36,864 —-a-w c:\windows\System32\cdd.dll
- 2008-01-19 07:34:37 1,671,168 —-a-w c:\windows\System32\chsbrkr.dll
+ 2008-05-27 05:17:13 1,671,680 —-a-w c:\windows\System32\chsbrkr.dll
- 2008-01-19 07:34:40 6,103,040 —-a-w c:\windows\System32\chtbrkr.dll
+ 2008-05-27 05:17:16 6,103,040 —-a-w c:\windows\System32\chtbrkr.dll
- 2009-01-05 19:06:00 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-02 18:30:13 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-05 19:06:00 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-02 18:30:13 49,152 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-05 19:06:00 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-02 18:30:13 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-05 19:02:11 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-02-02 18:32:50 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2008-01-19 07:33:05 139,264 —-a-w c:\windows\System32\cscript.exe
+ 2008-05-08 21:58:40 135,168 —-a-w c:\windows\System32\cscript.exe
- 2006-11-02 12:34:36 45,056 —-a-w c:\windows\System32\dataclen.dll
+ 2008-06-26 03:29:02 45,056 —-a-w c:\windows\System32\dataclen.dll
- 2008-01-19 05:36:41 625,152 —-a-w c:\windows\System32\drivers\dxgkrnl.sys
+ 2008-08-02 01:01:23 625,152 —-a-w c:\windows\System32\drivers\dxgkrnl.sys
+ 2009-01-31 10:05:33 85,969 —-a-w c:\windows\System32\drivers\gmer.sys
- 2007-10-16 22:52:24 660,992 —-a-w c:\windows\System32\drivers\HSX_CNXT.sys
+ 2008-05-08 10:04:16 661,504 —-a-w c:\windows\System32\drivers\HSX_CNXT.sys
- 2007-10-16 22:51:38 985,088 —-a-w c:\windows\System32\drivers\HSX_DP.sys
+ 2008-05-08 10:03:18 980,992 —-a-w c:\windows\System32\drivers\HSX_DP.sys
- 2007-10-16 22:53:24 267,264 —-a-w c:\windows\System32\drivers\HSXHWBS2.sys
+ 2008-05-08 10:05:18 266,752 —-a-w c:\windows\System32\drivers\HSXHWBS2.sys
- 2008-01-19 05:53:59 148,480 —-a-w c:\windows\System32\drivers\nwifi.sys
+ 2008-05-20 02:07:31 148,480 —-a-w c:\windows\System32\drivers\nwifi.sys
- 2008-04-07 23:16:45 43,872 —-a-w c:\windows\System32\drivers\pxhelp20.sys
+ 2008-07-31 22:17:04 43,872 —-a-w c:\windows\System32\drivers\pxhelp20.sys
- 2007-08-07 19:26:28 386,560 —-a-w c:\windows\System32\drivers\XAudio.exe
+ 2007-10-18 12:37:04 386,560 —-a-w c:\windows\System32\drivers\XAudio.exe
- 2007-08-07 19:26:14 8,704 —-a-w c:\windows\System32\drivers\XAudio.sys
+ 2007-10-18 12:36:54 8,704 —-a-w c:\windows\System32\drivers\XAudio.sys
+ 2009-01-18 21:30:13 64,160 -c–a-w c:\windows\System32\DRVSTORE\lbd_D996E5CC178082520D5C11260A28955C8455FD4A\Lbd.sys
- 2008-01-19 07:34:09 564,736 —-a-w c:\windows\System32\emdmgmt.dll
+ 2008-06-26 03:29:02 565,248 —-a-w c:\windows\System32\emdmgmt.dll
- 2008-01-19 07:34:21 147,456 —-a-w c:\windows\System32\Faultrep.dll
+ 2008-09-18 04:56:02 147,456 —-a-w c:\windows\System32\Faultrep.dll
- 2008-12-20 08:08:29 327,408 —-a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-02-02 18:28:47 328,752 —-a-w c:\windows\System32\FNTCACHE.DAT
- 2007-04-07 07:15:26 135,168 —-a-w c:\windows\System32\java.exe
+ 2009-01-31 10:40:51 144,792 —-a-w c:\windows\System32\java.exe
- 2007-04-07 07:15:28 135,168 —-a-w c:\windows\System32\javaw.exe
+ 2009-01-31 10:40:51 144,792 —-a-w c:\windows\System32\javaw.exe
- 2007-04-07 08:16:26 139,264 —-a-w c:\windows\System32\javaws.exe
+ 2009-01-31 10:40:51 148,888 —-a-w c:\windows\System32\javaws.exe
- 2008-01-19 07:34:35 512,000 —-a-w c:\windows\System32\jscript.dll
+ 2008-05-08 21:59:28 512,000 —-a-w c:\windows\System32\jscript.dll
- 2008-01-19 07:34:42 42,496 —-a-w c:\windows\System32\korwbrkr.dll
+ 2008-05-27 05:17:16 143,872 —-a-w c:\windows\System32\korwbrkr.dll
+ 2007-07-27 20:49:02 196,683 —-a-w c:\windows\System32\lnod32apiA.dll
+ 2007-07-27 20:49:02 225,355 —-a-w c:\windows\System32\lnod32apiW.dll
+ 2005-12-06 01:25:22 139,264 —-a-w c:\windows\System32\lnod32umc.dll
+ 2005-12-05 18:37:10 106,496 —-a-w c:\windows\System32\lnod32upd.dll
+ 2007-06-11 18:04:38 190,696 —-a-w c:\windows\System32\Macromed\Flash\FlashUtil9d.exe
+ 2007-09-13 17:00:00 1,101,824 —-a-w c:\windows\System32\mfc80.dll
- 2008-01-19 07:34:49 35,328 —-a-w c:\windows\System32\mimefilt.dll
+ 2008-05-27 05:18:32 40,448 —-a-w c:\windows\System32\mimefilt.dll
- 2008-12-09 23:24:37 17,593,280 —-a-w c:\windows\System32\mrt.exe
+ 2009-01-10 01:35:28 20,853,704 —-a-w c:\windows\System32\mrt.exe
- 2008-01-19 07:35:12 23,552 —-a-w c:\windows\System32\msscb.dll
+ 2008-05-27 05:17:42 34,816 —-a-w c:\windows\System32\msscb.dll
- 2008-01-19 07:35:12 51,200 —-a-w c:\windows\System32\msscntrs.dll
+ 2008-05-27 05:17:25 60,416 —-a-w c:\windows\System32\msscntrs.dll
+ 2008-05-27 05:17:36 11,776 —-a-w c:\windows\System32\msshooks.dll
- 2008-01-19 07:35:13 248,832 —-a-w c:\windows\System32\msshsq.dll
+ 2008-05-27 05:18:32 231,936 —-a-w c:\windows\System32\msshsq.dll
- 2008-01-19 07:35:13 98,304 —-a-w c:\windows\System32\mssitlb.dll
+ 2008-05-27 05:17:25 87,552 —-a-w c:\windows\System32\mssitlb.dll
- 2008-01-19 07:35:13 333,824 —-a-w c:\windows\System32\mssph.dll
+ 2008-05-27 05:18:25 350,208 —-a-w c:\windows\System32\mssph.dll
- 2008-01-19 07:35:13 167,936 —-a-w c:\windows\System32\mssphtb.dll
+ 2008-05-27 05:18:55 203,776 —-a-w c:\windows\System32\mssphtb.dll
- 2008-01-19 07:35:13 32,256 —-a-w c:\windows\System32\mssprxy.dll
+ 2008-05-27 05:17:26 32,768 —-a-w c:\windows\System32\mssprxy.dll
- 2008-01-19 07:36:08 1,400,832 —-a-w c:\windows\System32\mssrch.dll
+ 2008-05-27 05:21:24 1,418,240 —-a-w c:\windows\System32\mssrch.dll
- 2008-01-19 07:35:13 52,224 —-a-w c:\windows\System32\msstrc.dll
+ 2008-05-27 05:18:40 44,032 —-a-w c:\windows\System32\msstrc.dll
- 2008-01-19 07:35:13 1,696,768 —-a-w c:\windows\System32\mssvp.dll
+ 2008-05-27 05:18:56 670,208 —-a-w c:\windows\System32\mssvp.dll
+ 2007-09-13 17:00:00 548,864 —-a-w c:\windows\System32\msvcp80.dll
+ 2007-09-13 17:00:00 626,688 —-a-w c:\windows\System32\msvcr80.dll
- 2008-01-19 07:35:38 122,368 —-a-w c:\windows\System32\nlhtml.dll
+ 2008-05-27 05:18:30 136,704 —-a-w c:\windows\System32\nlhtml.dll
- 2008-01-19 07:36:00 194,560 —-a-w c:\windows\System32\offfilt.dll
+ 2008-05-27 05:17:23 194,560 —-a-w c:\windows\System32\offfilt.dll
+ 2007-08-02 23:11:28 253,952 —-a-w c:\windows\System32\OnlineScannerDLLA.dll
+ 2007-08-02 23:11:14 241,664 —-a-w c:\windows\System32\OnlineScannerDLLW.dll
+ 2007-08-06 18:17:40 19,456 —-a-w c:\windows\System32\OnlineScannerLang.dll
+ 2007-06-13 16:10:34 77,824 —-a-w c:\windows\System32\OnlineScannerUninstaller.exe
- 2009-01-05 18:08:36 109,138 —-a-w c:\windows\System32\perfc009.dat
+ 2009-02-02 18:36:19 109,138 —-a-w c:\windows\System32\perfc009.dat
- 2008-01-19 07:36:11 65,536 —-a-w c:\windows\System32\propdefs.dll
+ 2008-05-27 05:18:06 71,680 —-a-w c:\windows\System32\propdefs.dll
- 2008-01-19 07:36:11 750,080 —-a-w c:\windows\System32\propsys.dll
+ 2008-05-27 05:17:46 754,176 —-a-w c:\windows\System32\propsys.dll
+ 2007-06-05 18:20:30 1,459,752 —-a-w c:\windows\System32\PSIKey.dll
+ 2007-06-05 18:20:32 177,704 —-a-w c:\windows\System32\PSIService.exe
- 2007-02-06 23:03:44 129,784 ——w c:\windows\System32\PxAFS.DLL
+ 2008-11-24 08:06:28 129,520 ——w c:\windows\System32\PxAFS.DLL
- 2007-01-09 08:00:00 64,760 ——w c:\windows\System32\pxcpya64.exe
+ 2008-11-24 08:06:26 66,296 ——w c:\windows\System32\pxcpya64.exe
- 2007-01-09 08:00:00 116,472 ——w c:\windows\System32\pxcpyi64.exe
+ 2008-11-24 08:06:26 120,568 ——w c:\windows\System32\pxcpyi64.exe
- 2007-02-02 10:00:00 64,760 ——w c:\windows\System32\pxinsa64.exe
+ 2008-11-24 08:06:26 65,008 ——w c:\windows\System32\pxinsa64.exe
- 2007-02-02 10:00:00 118,520 ——w c:\windows\System32\pxinsi64.exe
+ 2008-11-24 08:06:26 118,256 ——w c:\windows\System32\pxinsi64.exe
- 2007-02-06 23:03:54 1,628,920 ——w c:\windows\System32\PxSFS.DLL
+ 2008-11-24 08:06:28 1,690,096 ——w c:\windows\System32\PxSFS.DLL
- 2007-02-06 23:04:04 158,456 ——w c:\windows\System32\pxwma.dll
+ 2007-04-04 22:08:56 158,456 ——w c:\windows\System32\pxwma.dll
- 2008-01-19 07:36:17 26,624 —-a-w c:\windows\System32\rtffilt.dll
+ 2008-05-27 05:18:30 38,400 —-a-w c:\windows\System32\rtffilt.dll
- 2008-01-19 07:36:19 180,224 —-a-w c:\windows\System32\scrobj.dll
+ 2008-05-08 21:59:32 180,224 —-a-w c:\windows\System32\scrobj.dll
- 2008-01-19 07:36:19 172,032 —-a-w c:\windows\System32\scrrun.dll
+ 2008-05-08 21:59:32 172,032 —-a-w c:\windows\System32\scrrun.dll
- 2008-01-19 07:33:28 76,800 —-a-w c:\windows\System32\SearchFilterHost.exe
+ 2008-05-27 05:17:55 87,552 —-a-w c:\windows\System32\SearchFilterHost.exe
- 2008-01-19 07:33:28 302,080 —-a-w c:\windows\System32\SearchIndexer.exe
+ 2008-05-27 05:18:43 439,808 —-a-w c:\windows\System32\SearchIndexer.exe
- 2008-01-19 07:33:28 179,200 —-a-w c:\windows\System32\SearchProtocolHost.exe
+ 2008-05-27 05:18:16 184,832 —-a-w c:\windows\System32\SearchProtocolHost.exe
- 2008-12-21 03:11:52 6,291,456 —-a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-01-20 09:38:24 6,291,456 —-a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2008-01-19 07:36:35 258,048 —-a-w c:\windows\System32\srchadmin.dll
+ 2008-05-27 05:17:28 301,568 —-a-w c:\windows\System32\srchadmin.dll
- 2008-01-19 03:17:42 100,043 —-a-w c:\windows\System32\StructuredQuerySchema.bin
+ 2008-05-27 04:59:39 106,605 —-a-w c:\windows\System32\StructuredQuerySchema.bin
- 2006-11-02 06:29:53 18,271 —-a-w c:\windows\System32\StructuredQuerySchemaTrivial.bin
+ 2008-05-27 04:59:40 18,904 —-a-w c:\windows\System32\StructuredQuerySchemaTrivial.bin
- 2006-11-02 09:46:13 313,344 —-a-w c:\windows\System32\thawbrkr.dll
+ 2008-05-27 05:17:16 313,344 —-a-w c:\windows\System32\thawbrkr.dll
- 2008-01-19 07:36:42 1,505,792 —-a-w c:\windows\System32\tquery.dll
+ 2008-05-27 05:21:07 1,582,592 —-a-w c:\windows\System32\tquery.dll
+ 2004-12-07 16:11:34 258,352 —-a-w c:\windows\System32\unicows.dll
- 2008-01-19 07:36:47 430,080 —-a-w c:\windows\System32\vbscript.dll
+ 2008-05-08 21:59:33 430,080 —-a-w c:\windows\System32\vbscript.dll
- 2009-01-05 19:07:40 8,036 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1811550359-2718204304-211020303-1000_UserData.bin
+ 2009-02-02 18:30:49 9,092 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1811550359-2718204304-211020303-1000_UserData.bin
- 2009-01-05 19:07:40 58,872 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-02 18:30:49 60,696 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-05 19:07:33 47,222 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-01 09:35:32 49,760 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-01-19 07:36:52 125,952 —-a-w c:\windows\System32\wersvc.dll
+ 2008-09-18 04:56:07 125,952 —-a-w c:\windows\System32\wersvc.dll
- 2008-01-19 07:33:40 155,648 —-a-w c:\windows\System32\wscript.exe
+ 2008-05-08 21:59:26 155,648 —-a-w c:\windows\System32\wscript.exe
- 2008-01-19 07:37:11 27,136 —-a-w c:\windows\System32\wsepno.dll
+ 2008-05-27 05:18:35 29,184 —-a-w c:\windows\System32\wsepno.dll
- 2008-01-19 07:37:11 90,112 —-a-w c:\windows\System32\wshext.dll
+ 2008-05-08 21:59:35 90,112 —-a-w c:\windows\System32\wshext.dll
- 2008-01-19 07:37:12 110,592 —-a-w c:\windows\System32\xmlfilter.dll
+ 2008-05-27 05:18:32 56,320 —-a-w c:\windows\System32\xmlfilter.dll
- 2008-12-30 08:48:19 142,429,406 —-a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-01-20 09:36:01 144,338,149 —-a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-05-27 05:17:28 301,568 —-a-w c:\windows\winsxs\x86_desktop_shell-search-srchadmin_31bf3856ad364e35_7.0.6001.16503_none_13fcab3737a334c2\srchadmin.dll
+ 2008-05-27 05:18:30 136,704 —-a-w c:\windows\winsxs\x86_microsoft-windows-content-filter-html_31bf3856ad364e35_7.0.6001.16503_none_13ff1de93d266b97\nlhtml.dll
+ 2008-05-27 05:18:32 56,320 —-a-w c:\windows\winsxs\x86_microsoft-windows-content-filter-html_31bf3856ad364e35_7.0.6001.16503_none_13ff1de93d266b97\xmlfilter.dll
+ 2008-05-27 05:18:32 40,448 —-a-w c:\windows\winsxs\x86_microsoft-windows-content-filter-mime_31bf3856ad364e35_7.0.6001.16503_none_10a358dd3f57c0de\mimefilt.dll
+ 2008-05-27 05:17:23 194,560 —-a-w c:\windows\winsxs\x86_microsoft-windows-content-filter-office_31bf3856ad364e35_7.0.6001.16503_none_fab3f42bbfadf408\offfilt.dll
+ 2008-05-27 05:18:30 38,400 —-a-w c:\windows\winsxs\x86_microsoft-windows-content-filter-rtf_31bf3856ad364e35_7.0.6001.16503_none_485964bf76e0570a\rtffilt.dll
+ 2008-06-26 03:29:02 45,056 —-a-w c:\windows\winsxs\x86_microsoft-windows-dataclen_31bf3856ad364e35_6.0.6001.18098_none_f64ce87593b7801f\dataclen.dll
+ 2008-06-26 03:15:06 45,056 —-a-w c:\windows\winsxs\x86_microsoft-windows-dataclen_31bf3856ad364e35_6.0.6001.22211_none_f7260480ac9a8c27\dataclen.dll
+ 2008-05-10 03:35:15 564,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18069_none_9e540f60f6e2ecf1\emdmgmt.dll
+ 2008-06-26 03:29:02 565,248 —-a-w c:\windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18098_none_9e329f52f6fc276d\emdmgmt.dll
+ 2008-05-10 03:17:36 564,736 —-a-w c:\windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.22176_none_9ecfdb62100b5ca7\emdmgmt.dll
+ 2008-06-26 03:15:30 565,248 —-a-w c:\windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.22211_none_9f0bbb5e0fdf3375\emdmgmt.dll
+ 2008-09-18 04:56:02 147,456 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\Faultrep.dll
+ 2008-01-19 07:33:35 217,088 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\WerFault.exe
+ 2008-01-19 07:33:35 860,160 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.18145_none_6fe0e04a3ce53cd7\WerFaultSecure.exe
+ 2008-09-20 04:00:23 147,456 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\Faultrep.dll
+ 2008-09-20 04:00:16 217,088 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\WerFault.exe
+ 2008-09-20 04:00:16 860,160 —-a-w c:\windows\winsxs\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_6.0.6001.22271_none_70460c29561ecb18\WerFaultSecure.exe
+ 2008-09-18 04:56:07 125,952 —-a-w c:\windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.18145_none_79a5b70991018b47\wersvc.dll
+ 2008-09-20 04:00:26 125,952 —-a-w c:\windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.22271_none_7a0ae2e8aa3b1988\wersvc.dll
+ 2008-08-02 03:26:00 36,864 —-a-w c:\windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.18114_none_abc1cbc0e39143f0\cdd.dll
+ 2008-08-02 01:01:23 625,152 —-a-w c:\windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.18114_none_abc1cbc0e39143f0\dxgkrnl.sys
+ 2008-08-02 03:20:51 36,864 —-a-w c:\windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.22235_none_ac36c8fdfcbe34f3\cdd.dll
+ 2008-08-02 00:59:11 625,152 —-a-w c:\windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.22235_none_ac36c8fdfcbe34f3\dxgkrnl.sys
+ 2008-05-20 02:07:31 148,480 —-a-w c:\windows\winsxs\x86_microsoft-windows-native-80211_31bf3856ad364e35_6.0.6001.18075_none_4ec1fb0e8f26c88a\nwifi.sys
+ 2008-05-20 02:00:06 148,480 —-a-w c:\windows\winsxs\x86_microsoft-windows-native-80211_31bf3856ad364e35_6.0.6001.22183_none_4f3ec759a84e5197\nwifi.sys
+ 2008-05-28 03:27:17 223,288 —-a-w c:\windows\winsxs\x86_microsoft-windows-netio-infrastructure_31bf3856ad364e35_6.0.6001.22188_none_56d68c90cea4d169\netio.sys
+ 2008-05-28 03:17:25 328,704 —-a-w c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22188_none_cd5f8fa443e22213\BFE.DLL
+ 2008-05-28 03:28:43 101,432 —-a-w c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22188_none_cd5f8fa443e22213\FWPKCLNT.SYS
+ 2008-05-28 03:19:07 595,456 —-a-w c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22188_none_cd5f8fa443e22213\FWPUCLNT.DLL
+ 2008-05-28 03:19:32 438,272 —-a-w c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22188_none_cd5f8fa443e22213\IKEEXT.DLL
+ 2008-12-08 23:22:10 2,410,800 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16787_none_f052600a6e8e5046\OESpamFilter.dat
+ 2008-12-08 23:23:32 2,410,800 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20972_none_f0e1cd3587a85293\OESpamFilter.dat
+ 2008-12-09 23:54:42 2,410,800 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18182_none_f2339d3e6bb96284\OESpamFilter.dat
+ 2008-12-09 23:55:37 2,410,800 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22327_none_f3031ce984a1d682\OESpamFilter.dat
+ 2008-04-26 08:25:53 3,600,952 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_6bf282f6b4510613\ntkrnlpa.exe
+ 2008-04-26 08:25:54 3,549,240 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_6bf282f6b4510613\ntoskrnl.exe
+ 2008-04-26 08:11:34 3,601,464 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_6c8020e9cd6b0b39\ntkrnlpa.exe
+ 2008-04-26 08:11:33 3,549,240 —-a-w c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_6c8020e9cd6b0b39\ntoskrnl.exe
+ 2008-05-27 05:17:46 754,176 —-a-w c:\windows\winsxs\x86_microsoft-windows-propsys_31bf3856ad364e35_7.0.6001.16503_none_f3d11aeeb9526bbb\propsys.dll
+ 2008-04-05 01:21:42 72,192 —-a-w c:\windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.18046_none_ae262a9c57bfa9b1\pacer.sys
+ 2008-04-05 03:34:31 15,360 —-a-w c:\windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.18046_none_ae262a9c57bfa9b1\pacerprf.dll
+ 2006-11-02 09:46:13 33,280 —-a-w c:\windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.18046_none_ae262a9c57bfa9b1\traffic.dll
+ 2006-11-02 09:46:14 13,824 —-a-w c:\windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.18046_none_ae262a9c57bfa9b1\wshqos.dll
+ 2008-04-05 01:20:52 72,192 —-a-w c:\windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.22151_none_ae9ff60970e9e6b9\pacer.sys
+ 2008-04-05 03:20:42 15,360 —-a-w c:\windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.22151_none_ae9ff60970e9e6b9\pacerprf.dll
+ 2008-04-05 03:21:19 33,280 —-a-w c:\windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.22151_none_ae9ff60970e9e6b9\traffic.dll
+ 2008-04-05 03:21:39 13,824 —-a-w c:\windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.22151_none_ae9ff60970e9e6b9\wshqos.dll
+ 2008-04-12 03:32:11 784,896 —-a-w c:\windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6001.18051_none_b3c58fc5453bf46b\rpcrt4.dll
+ 2008-04-12 03:16:32 784,896 —-a-w c:\windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6001.22156_none_b4542e025e5512e8\rpcrt4.dll
+ 2008-05-08 21:59:35 90,112 —-a-w c:\windows\winsxs\x86_microsoft-windows-s..ing-shell-extension_31bf3856ad364e35_6.0.6001.18068_none_0a48f9ec246cf834\wshext.dll
+ 2008-05-08 05:22:33 90,112 —-a-w c:\windows\winsxs\x86_microsoft-windows-s..ing-shell-extension_31bf3856ad364e35_6.0.6001.22175_none_0ac4c5ed3d9567ea\wshext.dll
+ 2008-05-08 21:59:28 512,000 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6001.18068_none_82a70b5ef74dc96b\jscript.dll
+ 2008-05-08 05:18:59 512,000 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6001.22175_none_8322d76010763921\jscript.dll
+ 2008-05-08 21:59:33 430,080 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting-vbscript_31bf3856ad364e35_6.0.6001.18068_none_482126172e1075a7\vbscript.dll
+ 2008-05-08 05:22:13 430,080 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting-vbscript_31bf3856ad364e35_6.0.6001.22175_none_489cf2184738e55d\vbscript.dll
+ 2008-05-08 21:58:40 135,168 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482f75de008363d9\cscript.exe
+ 2008-01-19 07:34:04 32,768 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482f75de008363d9\dispex.dll
+ 2008-05-08 21:59:32 180,224 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482f75de008363d9\scrobj.dll
+ 2008-05-08 21:59:32 172,032 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482f75de008363d9\scrrun.dll
+ 2008-05-08 21:59:26 155,648 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482f75de008363d9\wscript.exe
+ 2008-01-19 07:37:11 36,864 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482f75de008363d9\wshcon.dll
+ 2008-05-08 03:12:11 135,168 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48ab41df19abd38f\cscript.exe
+ 2008-05-08 05:17:02 32,768 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48ab41df19abd38f\dispex.dll
+ 2008-05-08 05:21:52 180,224 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48ab41df19abd38f\scrobj.dll
+ 2008-05-08 05:21:52 172,032 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48ab41df19abd38f\scrrun.dll
+ 2008-05-08 03:12:11 155,648 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48ab41df19abd38f\wscript.exe
+ 2008-05-08 05:22:33 36,864 —-a-w c:\windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48ab41df19abd38f\wshcon.dll
+ 2008-05-27 05:18:35 29,184 —-a-w c:\windows\winsxs\x86_microsoft-windows-search-profilenotify_31bf3856ad364e35_7.0.6001.16503_none_d86cd72c8d3c237e\wsepno.dll
+ 2008-05-08 19:21:56 211,968 —-a-w c:\windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.18068_none_886bae514b981fe3\mrxsmb10.sys
+ 2008-05-08 02:47:34 211,968 —-a-w c:\windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.22175_none_88e77a5264c08f99\mrxsmb10.sys
+ 2008-12-16 03:14:37 290,304 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6000.16789_none_d7c3afd4f985c7a2\srv.sys
+ 2008-12-16 03:07:02 290,816 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6000.20976_none_d8551d94129dfc9d\srv.sys
+ 2008-12-16 02:42:39 288,768 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.18185_none_d9a5ed52f6aff337\srv.sys
+ 2008-12-16 01:53:56 288,768 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.22331_none_da619a780fa89f17\srv.sys
+ 2008-04-26 08:26:49 891,448 —-a-w c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys
+ 2008-04-26 08:08:16 891,448 —-a-w c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36dd19b7fae39c7\tcpip.sys
+ 2008-05-27 05:17:16 6,103,040 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..-chinesetraditional_31bf3856ad364e35_7.0.6001.16503_none_df2000cce0d8c017\chtbrkr.dll
+ 2008-05-27 05:17:16 313,344 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..breakerstemmer-thai_31bf3856ad364e35_7.0.6001.16503_none_d40428cfc6b6fdf9\thawbrkr.dll
+ 2008-05-27 05:17:16 143,872 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..eakerstemmer-korean_31bf3856ad364e35_7.0.6001.16503_none_14072d09797cf93d\korwbrkr.dll
+ 2008-05-27 05:17:13 1,671,680 —-a-w c:\windows\winsxs\x86_microsoft-windows-w..r-chinesesimplified_31bf3856ad364e35_7.0.6001.16503_none_4cbdb704b61543d2\chsbrkr.dll
+ 2009-01-20 09:35:56 161,784 —-a-w c:\windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e\ATL90.dll
+ 2009-01-20 09:35:57 225,280 —-a-w c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll
+ 2009-01-20 09:35:57 572,928 —-a-w c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll
+ 2009-01-20 09:35:57 655,872 —-a-w c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll
+ 2009-01-20 09:35:59 312,832 —-a-w c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c3
5eb\msvcm90d.dll
+ 2009-01-20 09:35:59 875,520 —-a-w c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c3
5eb\msvcp90d.dll
+ 2009-01-20 09:35:59 1,180,672 —-a-w c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c3
5eb\msvcr90d.dll
+ 2009-01-20 09:36:00 5,937,144 —-a-w c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d606
51e\mfc90d.dll
+ 2009-01-20 09:36:00 5,982,720 —-a-w c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d606
51e\mfc90ud.dll
+ 2009-01-20 09:36:00 80,896 —-a-w c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d606
51e\mfcm90d.dll
+ 2009-01-20 09:36:00 80,896 —-a-w c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d606
51e\mfcm90ud.dll
+ 2009-01-20 09:35:58 3,768,312 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll
+ 2009-01-20 09:35:58 3,783,672 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll
+ 2009-01-20 09:35:58 59,904 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll
+ 2009-01-20 09:35:58 59,904 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll
+ 2009-01-20 09:35:58 38,912 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90CHS.DLL
+ 2009-01-20 09:35:58 39,936 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90CHT.DLL
+ 2009-01-20 09:35:58 66,560 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90DEU.DLL
+ 2009-01-20 09:35:58 56,832 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ENU.DLL
+ 2009-01-20 09:35:58 65,024 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ESN.DLL
+ 2009-01-20 09:35:58 65,024 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ESP.DLL
+ 2009-01-20 09:35:58 66,048 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90FRA.DLL
+ 2009-01-20 09:35:58 64,512 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ITA.DLL
+ 2009-01-20 09:35:58 46,592 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90JPN.DLL
+ 2009-01-20 09:35:58 46,080 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90KOR.DLL
+ 2009-01-20 09:35:58 62,976 —-a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90RUS.DLL
+ 2008-05-27 05:18:43 13,824 —-a-w c:\windows\winsxs\x86_windowssearch-wtrservicingsupport_31bf3856ad364e35_7.0.6001.16503_none_163fe74a2171e12e\WSWTRSvc.exe
+ 2008-05-27 05:18:32 231,936 —-a-w c:\windows\winsxs\x86_windowssearchengine-structuredquery_31bf3856ad364e35_7.0.6001.16503_none_98586419f9103903\msshsq.dll
+ 2008-05-27 04:59:39 106,605 —-a-w c:\windows\winsxs\x86_windowssearchengine..uredqueryschema.bin_31bf3856ad364e35_7.0.6001.1650
3_none_88f88929e3c77aa3\StructuredQuerySchema.bin
+ 2008-05-27 04:59:40 18,904 —-a-w c:\windows\winsxs\x86_windowssearchengine..uredqueryschema.bin_31bf3856ad364e35_7.0.6001.1650
3_none_88f88929e3c77aa3\StructuredQuerySchemaTrivial.bin
+ 2008-05-27 05:17:42 34,816 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\msscb.dll
+ 2008-05-27 05:17:25 60,416 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\msscntrs.dll
+ 2008-05-27 05:17:36 11,776 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\msshooks.dll
+ 2008-05-27 05:17:25 87,552 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\mssitlb.dll
+ 2008-05-27 05:18:25 350,208 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\mssph.dll
+ 2008-05-27 05:18:55 203,776 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\mssphtb.dll
+ 2008-05-27 05:17:26 32,768 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\mssprxy.dll
+ 2008-05-27 05:21:24 1,418,240 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\mssrch.dll
+ 2008-05-27 05:18:40 44,032 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\msstrc.dll
+ 2008-05-27 05:18:56 670,208 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\mssvp.dll
+ 2008-05-27 05:18:06 71,680 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\propdefs.dll
+ 2008-05-27 05:17:55 87,552 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\SearchFilterHost.exe
+ 2008-05-27 05:18:43 439,808 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\SearchIndexer.exe
+ 2008-05-27 05:18:16 184,832 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\SearchProtocolHost.exe
+ 2008-05-27 05:21:07 1,582,592 —-a-w c:\windows\winsxs\x86_windowssearchengine_31bf3856ad364e35_7.0.6001.16503_none_3b8c27e8ba3dd3
dd\tquery.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-06 39408]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Corel File Shell Monitor"="c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2007-10-30 16200]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-02 509784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-31 136600]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-10-02 67488]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 c:\windows\RtHDVCpl.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-04-03 44168]

c:\users\House\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-09-18 147456]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-07 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{90823AD4-A2F1-486D-8EA7-9E2C01DE83B2}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4AE50274-27D8-4966-87D5-6311AA99B027}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{AD0E426E-AB2A-4962-AE9B-768675D72A51}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BA8C0E53-1F52-47C1-8971-885FFD426EE4}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{E7BCF2CF-8A5A-459D-A68B-F732A469DAB3}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CBF53917-2CFE-4BF8-8EAA-BD1A70250085}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{74DF6363-4F99-4AD6-943F-E610CD8E7FB8}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2911227A-0E81-40EC-8EC0-31E675F1B071}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{740A1727-E354-4476-9417-E3E5310B160A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A41B3878-63A3-43CA-8C17-2E5427855CF7}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{34E9A5FD-543C-42E3-A889-01901E2ED476}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7EC6633B-5AB4-4868-8224-901ECA904574}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{E575F44B-09C1-43EF-9AF1-8A74082946AE}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-01-20 64160]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2008-12-30 111184]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 124832]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2008-12-30 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2008-12-30 51792]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
.
Contents of the 'Scheduled Tasks' folder

2009-02-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-02 04:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?source=gama&hl=en
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-02 13:36:17
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-02 13:37:54
ComboFix-quarantined-files.txt 2009-02-02 18:37:52
ComboFix2.txt 2009-01-05 19:12:42

Pre-Run: 296,282,046,464 bytes free
Post-Run: 296,749,334,528 bytes free

899 — E O F — 2009-01-27 00:12:14

********************************************************************************
*********************************************************************************
*******************
********************************************************************************
*********************************************************************************
****************


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:41:56 PM, on 02/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\hp\kbd\kbd.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\House\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 200.124.131.116 casinocontroller.com
O1 - Hosts: 200.124.131.116 casinocontroller.com
O1 - Hosts: 200.124.131.116 casinocontroller.com
O1 - Hosts: 200.124.131.116 casinocontroller.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe" -delete
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O13 - Gopher Prefix:
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} (PCPitstop AntiVirus) - http://utilities.pcpitstop.com/Exterminate…opAntiVirus.dll
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8607 bytes
Hi :)

Please disable Avast! as before.

Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/pop_ups_redi…elp_t98521.html

Collect::
C:\WINDOWS\system32\drivers\msqpdxcxxbbsus.sys
C:\WINDOWS\system32\msqpdxpnjtvwbv.dll

Driver::
msqpdxserv.sys

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[-HKEY_CLASSES_ROOT\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[-HKEY_CLASSES_ROOT\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\msqpdxserv.sys]


Save this as CFScript.txt


[external image: Posted Image]


Referring to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

Please also run GMER again (as before) and post the log from that.

Thanks.
ComboFix 09-02-02.04 - House 2009-02-03 5:26:30.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2942.2050 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\House\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.

2009-02-03 05:06 . 2009-02-03 05:06 d——– c:\program files\Topaz Labs
2009-02-03 04:55 . 2009-02-03 04:55 d——– c:\users\All Users\FLEXnet
2009-02-03 04:55 . 2009-02-03 04:55 d——– c:\programdata\FLEXnet
2009-02-02 13:21 . 2009-02-02 13:21 d——– c:\program files\Common Files\Macrovision Shared
2009-02-02 13:18 . 2009-02-02 13:21 d——– c:\users\House\AppData\Roaming\123 Free Solitaire
2009-02-02 13:16 . 2009-02-02 13:16 209 –a—— c:\windows\ODBCINST.INI
2009-02-02 11:22 . 2009-02-02 11:22 d——– c:\program files\Fractalus
2009-02-02 11:22 . 2009-02-02 11:22 d——– c:\program files\123 Free Solitaire
2009-02-02 11:19 . 2001-08-23 17:25 1,706,800 –a—— c:\windows\System32\gdiplus.dll
2009-02-02 05:58 . 2009-02-02 07:21 d——– c:\program files\EsetOnlineScanner
2009-01-31 05:41 . 2009-01-31 05:40 410,984 –a—— c:\windows\System32\deploytk.dll
2009-01-31 05:05 . 2009-02-02 07:37 250 –a—— c:\windows\gmer.ini
2009-01-31 05:04 . 2009-01-31 05:04 d——– c:\program files\PKWARE
2009-01-31 05:04 . 2009-01-31 05:04 d——– c:\program files\Common Files\PKWARE
2009-01-29 16:22 . 2009-01-29 16:22 d——– c:\windows\System32\Adobe
2009-01-27 06:30 . 2009-01-27 06:30 d——– c:\users\House\AppData\Roaming\gtk-2.0
2009-01-27 06:30 . 2009-01-27 06:30 d——– c:\users\House\.thumbnails
2009-01-27 06:27 . 2009-01-27 06:49 d——– c:\users\House\.gimp-2.6
2009-01-27 06:27 . 2009-01-27 06:27 d——– c:\users\House\.gegl-0.0
2009-01-27 06:27 . 2009-01-27 06:27 d——– c:\program files\GIMP-2.0
2009-01-23 20:16 . 2009-01-23 20:16 d——– c:\program files\Disney
2009-01-22 14:18 . 2009-01-18 16:35 15,688 –a—— c:\windows\System32\lsdelete.exe
2009-01-22 05:54 . 2009-01-22 05:54 d——– C:\apps
2009-01-20 04:38 . 2009-01-18 16:30 64,160 –a—— c:\windows\System32\drivers\Lbd.sys
2009-01-20 04:36 . 2009-01-20 04:36 d–h-c— c:\users\All Users\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-20 04:36 . 2009-01-20 04:36 d–h-c— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-20 04:36 . 2009-01-20 04:36 d——– c:\program files\Lavasoft
2009-01-19 11:05 . 2009-01-19 11:05 d——– c:\program files\SimpleD Budget
2009-01-18 11:14 . 2009-01-18 11:24 d——– c:\program files\Palace of Chance
2009-01-17 10:58 . 2009-01-17 13:10 d——– c:\program files\PKR
2009-01-17 04:11 . 2009-01-17 04:11 d——– c:\program files\Common Files\SWF Studio
2009-01-14 05:22 . 2008-12-15 21:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-13 06:36 . 2009-01-13 06:36 d——– c:\program files\GreenScreenWizardPro
2009-01-13 06:20 . 2009-01-13 06:20 d——– c:\program files\FXhome PhotoKey
2009-01-12 16:08 . 2009-02-02 12:01 1,682 –ahs—- c:\windows\System32\KGyGaAvL.sys
2009-01-12 16:00 . 2009-01-12 17:00 d——– c:\users\House\AppData\Roaming\Corel
2009-01-12 16:00 . 2009-01-12 17:01 d——– c:\users\All Users\Corel
2009-01-12 16:00 . 2009-01-12 17:01 d——– c:\programdata\Corel
2009-01-12 15:55 . 2009-01-12 16:58 d——– c:\program files\Common Files\Corel
2009-01-10 11:18 . 2009-01-12 21:28 d——– c:\users\House\AppData\Roaming\skypePM
2009-01-10 11:18 . 2009-01-10 11:18 56 –ah—– c:\users\All Users\ezsidmv.dat
2009-01-10 11:18 . 2009-01-10 11:18 56 –ah—– c:\programdata\ezsidmv.dat
2009-01-10 11:14 . 2009-01-13 12:46 d——– c:\users\All Users\Skype
2009-01-10 11:14 . 2009-01-13 12:46 d——– c:\programdata\Skype
2009-01-09 18:33 . 2009-01-09 18:33 d——– c:\program files\directx
2009-01-09 18:30 . 2009-01-09 18:30 d——– c:\program files\Activision Value
2009-01-09 04:48 . 2009-01-09 04:48 d——– c:\users\House\AppData\Roaming\Anthropics
2009-01-09 04:45 . 2009-01-09 04:45 d——– c:\program files\Portrait Professional 8 Trial
2009-01-06 07:50 . 2009-01-06 07:50 d——– c:\program files\MonkeyPhoto
2009-01-06 07:40 . 2009-01-06 07:40 d——– c:\program files\Greeting Card Studio
2009-01-06 05:00 . 2008-04-26 03:26 891,448 –a—— c:\windows\System32\drivers\tcpip.sys
2009-01-06 05:00 . 2008-04-11 22:32 784,896 –a—— c:\windows\System32\rpcrt4.dll
2009-01-06 05:00 . 2008-04-04 20:21 72,192 –a—— c:\windows\System32\drivers\pacer.sys
2009-01-06 05:00 . 2008-04-04 22:34 15,360 –a—— c:\windows\System32\pacerprf.dll
2009-01-05 17:33 . 2009-01-05 17:33 3,751,995 –a—— c:\windows\System32\GPhotos.scr
2009-01-04 17:35 . 2009-01-04 17:35 d——– c:\users\All Users\NVIDIA
2009-01-04 17:35 . 2009-01-04 17:35 d——– c:\programdata\NVIDIA
2009-01-04 17:19 . 2008-01-08 13:10 98,304 –a—— c:\windows\RTKAUDIOSERVICE.EXE
2009-01-04 17:19 . 2007-11-14 15:18 553 –a—— c:\windows\USetup.iss
2009-01-04 17:18 . 2008-01-15 11:26 4,874,240 –a—— c:\windows\RtHDVCpl.exe
2009-01-04 17:18 . 2008-01-15 19:19 2,047,576 –a—— c:\windows\System32\drivers\RTKVHDA.sys
2009-01-04 17:18 . 2007-11-07 17:31 1,191,936 –a—— c:\windows\RtlUpd.exe
2009-01-04 17:18 . 2008-01-09 18:52 636,416 –a—— c:\windows\System32\RtkPgExt.dll
2009-01-04 17:18 . 2007-11-13 12:35 532,480 –a—— c:\windows\System32\RTSndMgr.cpl
2009-01-04 17:18 . 2007-07-25 09:33 135,168 –a—— c:\windows\System32\SRSWOW.dll
2009-01-04 17:18 . 2008-01-14 16:18 29,696 –a—— c:\windows\System32\RtkCoInst.dll
2009-01-04 17:14 . 2009-01-04 17:14 d——– c:\users\House\AppData\Roaming\WinBatch
2009-01-04 12:12 . 2009-01-04 12:12 d——– c:\windows\Sun
2009-01-04 08:41 . 2009-01-04 08:41 6,537,728 –a—— c:\windows\System32\tliadjust26.dll
2009-01-04 08:33 . 2009-01-04 08:33 691 –a—— c:\users\House\AppData\Roaming\GetValue.vbs
2009-01-04 08:33 . 2009-01-04 08:33 35 –a—— c:\users\House\AppData\Roaming\SetValue.bat
2009-01-04 08:32 . 2009-01-04 08:35 d——– c:\windows\System32\SmitfraudFix
2009-01-04 06:54 . 2009-01-04 06:54 d——– c:\users\House\AppData\Roaming\NeatImage SL
2009-01-04 06:53 . 2009-01-04 06:53 d——– c:\program files\Neat Image
2009-01-04 06:45 . 2009-01-04 06:45 d——– c:\program files\PictureCode
2009-01-03 16:11 . 2009-01-03 16:11 0 –ah—– c:\windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 10:22 ——— d—–w c:\users\House\AppData\Roaming\LimeWire
2009-02-03 09:47 ——— d—a-w c:\programdata\TEMP
2009-02-03 00:08 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-02 18:21 ——— d—–w c:\program files\Common Files\Adobe
2009-02-02 00:22 34 —-a-w c:\users\House\jagex_runescape_preferences.dat
2009-01-31 10:40 ——— d—–w c:\program files\Java
2009-01-31 09:58 ——— d—–w c:\programdata\WinZip
2009-01-31 09:52 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-01-20 09:36 ——— d—–w c:\programdata\Lavasoft
2009-01-18 15:21 ——— d—–w c:\program files\PCPitstop
2009-01-18 15:20 ——— d—–w c:\programdata\Symantec
2009-01-18 15:20 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-14 21:11 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 21:11 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-01-14 10:34 ——— d—–w c:\program files\Windows Mail
2009-01-12 21:59 ——— d—–w c:\program files\Common Files\PX Storage Engine
2009-01-12 21:58 ——— d—–w c:\program files\Corel
2009-01-11 22:51 ——— d—–w c:\program files\HP
2009-01-08 12:31 88 –sh–r c:\users\All Users\C0D09EBF43.sys
2009-01-08 12:31 88 –sh–r c:\programdata\C0D09EBF43.sys
2009-01-08 12:31 2,516 –sha-w c:\users\All Users\KGyGaAvL.sys
2009-01-08 12:31 2,516 –sha-w c:\programdata\KGyGaAvL.sys
2009-01-04 22:22 ——— d—–w c:\program files\Risk
2009-01-04 22:18 319,456 —-a-w c:\windows\DIFxAPI.dll
2009-01-04 22:18 ——— d—–w c:\program files\Realtek
2009-01-01 14:32 ——— d—–w c:\users\House\AppData\Roaming\Malwarebytes
2009-01-01 14:32 ——— d—–w c:\programdata\Malwarebytes
2008-12-31 23:19 ——— d—–w c:\users\House\AppData\Roaming\Boomzap
2008-12-30 22:10 ——— d—–w c:\program files\HP Games
2008-12-30 10:28 ——— d—–w c:\program files\Alwil Software
2008-12-30 10:19 ——— d—–w c:\programdata\avg8
2008-12-30 08:54 ——— d—–w c:\program files\CCleaner
2008-12-29 13:25 ——— d—–w c:\programdata\PC Tools
2008-12-28 10:02 ——— d–h–w c:\programdata\yahoo!
2008-12-28 10:02 ——— d—–w c:\users\House\AppData\Roaming\Snapfish
2008-12-28 10:02 ——— d—–w c:\program files\Yahoo!
2008-12-28 09:59 ——— d—–w c:\programdata\PCPitstop
2008-12-28 09:54 ——— d—–w c:\program files\MeadCo Neptune
2008-12-27 12:23 ——— d—–w c:\programdata\MGS
2008-12-27 10:32 ——— d—–w c:\programdata\Microgaming
2008-12-27 02:28 ——— d—–w c:\programdata\PopCap Games
2008-12-27 02:27 ——— d—–w c:\programdata\WildTangent
2008-12-25 19:40 ——— d—–w c:\users\House\AppData\Roaming\Apple Computer
2008-12-25 14:54 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-25 14:54 ——— d—–w c:\program files\iTunes
2008-12-25 14:53 ——— d—–w c:\program files\iPod
2008-12-25 14:53 ——— d—–w c:\program files\Common Files\Apple
2008-12-25 14:53 ——— d—–w c:\program files\Bonjour
2008-12-25 14:52 ——— d—–w c:\programdata\Apple Computer
2008-12-25 14:52 ——— d—–w c:\program files\QuickTime
2008-12-25 14:24 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-12-25 13:58 ——— d—–w c:\programdata\Apple
2008-12-25 13:58 ——— d—–w c:\program files\Apple Software Update
2008-12-23 21:45 ——— d—–w c:\programdata\KingsIsle Entertainment
2008-12-23 12:01 ——— d—–w c:\users\House\AppData\Roaming\PCToolsSpamMonitorPlus
2008-12-23 12:01 ——— d—–w c:\users\House\AppData\Roaming\PCToolsFirewallPlus
2008-12-20 14:16 ——— d—–w c:\users\House\AppData\Roaming\WildTangent
2008-12-20 08:11 174 –sha-w c:\program files\desktop.ini
2008-12-20 08:05 ——— d—–w c:\program files\Windows Sidebar
2008-12-20 08:05 ——— d—–w c:\program files\Windows Photo Gallery
2008-12-20 08:05 ——— d—–w c:\program files\Windows Journal
2008-12-20 08:05 ——— d—–w c:\program files\Windows Defender
2008-12-20 08:05 ——— d—–w c:\program files\Windows Collaboration
2008-12-20 08:05 ——— d—–w c:\program files\Windows Calendar
2008-12-20 07:53 82,432 —-a-w c:\windows\System32\axaltocm.dll
2008-12-20 07:53 101,888 —-a-w c:\windows\System32\ifxcardm.dll
2008-12-19 10:35 ——— d—–w c:\program files\Microsoft Silverlight
2008-12-17 09:42 ——— d—–w c:\program files\Bonusprint PIX
2008-12-10 09:36 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2008-12-10 09:36 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-12-10 09:36 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2008-12-10 09:36 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-10 09:36 296,960 —-a-w c:\windows\System32\gdi32.dll
2008-12-10 09:36 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2008-12-10 09:36 2,560 —-a-w c:\windows\AppPatch\AcRes.dll
2008-12-10 09:36 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2008-12-10 09:36 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2008-12-10 09:36 1,695,744 —-a-w c:\windows\System32\gameux.dll
2008-12-10 09:35 2,048 —-a-w c:\windows\System32\tzres.dll
2008-12-10 09:34 2,927,104 —-a-w c:\windows\explorer.exe
2008-12-10 09:33 827,392 —-a-w c:\windows\System32\wininet.dll
2008-12-10 09:31 98,816 —-a-w c:\windows\System32\mfps.dll
2008-12-10 09:31 2,868,736 —-a-w c:\windows\System32\mf.dll
2008-12-10 09:30 996,352 —-a-w c:\windows\System32\WMNetMgr.dll
2008-12-10 09:30 94,720 —-a-w c:\windows\System32\logagent.exe
2008-12-10 09:30 53,248 —-a-w c:\windows\System32\rrinstaller.exe
2008-12-10 09:30 24,576 —-a-w c:\windows\System32\mfpmp.exe
2008-12-10 09:30 2,048 —-a-w c:\windows\System32\mferror.dll
2008-12-08 22:04 ——— d—–w c:\program files\LimeWire
2008-12-08 17:31 ——— d—–w c:\users\House\AppData\Roaming\Canon
2008-12-08 09:47 269,312 —-a-w c:\windows\System32\es.dll
2008-12-08 09:45 ——— d—–w c:\program files\Microsoft Works
2008-12-07 23:58 ——— d—–w c:\program files\Windows Live
2008-12-07 23:55 ——— dcsh–w c:\program files\Common Files\WindowsLiveInstaller
2008-12-07 23:49 ——— d—–w c:\programdata\WLInstaller
2008-12-07 14:34 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-12-07 14:33 ——— d—–w c:\program files\Common Files\Motorola Shared
2008-12-07 14:11 ——— d—–w c:\program files\Canon
2008-12-07 02:08 ——— d—–w c:\program files\Google
2008-12-06 21:41 ——— d—–w c:\users\House\AppData\Roaming\SpinTop
.

((((((((((((((((((((((((((((( snapshot_2009-02-02_13.36.41.25 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 12:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2009-02-03 10:06:32 6,006 —-a-r c:\windows\Installer\{59C2E0E4-0859-4EC1-BCD3-53DBCEFE7AFA}\_6FEFF9B68218417F98F549.exe
+ 2009-02-03 10:06:33 10,134 —-a-r c:\windows\Installer\{59C2E0E4-0859-4EC1-BCD3-53DBCEFE7AFA}\_C6E28EEA5FDDDB3BA597FC.exe
+ 2009-02-03 10:06:32 6,006 —-a-r c:\windows\Installer\{59C2E0E4-0859-4EC1-BCD3-53DBCEFE7AFA}\_D03C44DB4ECE913CB3C174.exe
+ 2009-02-03 10:06:33 10,134 —-a-r c:\windows\Installer\{59C2E0E4-0859-4EC1-BCD3-53DBCEFE7AFA}\_D1C5020354A0FC1D99BDC2.exe
+ 2009-02-03 10:03:41 295,606 —-a-r c:\windows\Installer\{AC76BA86-7AD7-5464-3428-800000000003}\ARPPRODUCTICON.exe
- 2009-02-02 18:28:49 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-02-03 10:21:11 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-02-02 18:28:49 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-03 10:21:11 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-02-02 18:30:36 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-03 10:22:44 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-03 10:22:44 262,144 —ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-02-02 18:30:28 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-03 10:22:39 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-03 10:22:39 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-02-02 18:30:13 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-03 10:21:29 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-02-02 18:30:13 49,152 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-03 10:21:29 49,152 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-02 18:30:13 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-03 10:21:29 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-02 18:32:50 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-02-03 10:24:50 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-02-02 18:36:19 608,270 —-a-w c:\windows\System32\perfh009.dat
+ 2008-11-26 01:48:10 1,695,744 —-a-w c:\windows\System32\tliadjust26_dll.dll
+ 2008-11-07 12:48:46 1,744,896 —-a-w c:\windows\System32\tliadjustreg.exe
- 2009-02-02 18:30:49 9,092 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1811550359-2718204304-211020303-1000_UserData.bin
+ 2009-02-03 10:23:00 9,116 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1811550359-2718204304-211020303-1000_UserData.bin
- 2009-02-02 18:30:49 60,696 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-03 10:23:00 60,892 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-06 39408]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Corel File Shell Monitor"="c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2007-10-30 16200]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-02 509784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-31 136600]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-10-02 67488]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 c:\windows\RtHDVCpl.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-04-03 44168]

c:\users\House\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-09-18 147456]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-07 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{90823AD4-A2F1-486D-8EA7-9E2C01DE83B2}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4AE50274-27D8-4966-87D5-6311AA99B027}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{AD0E426E-AB2A-4962-AE9B-768675D72A51}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BA8C0E53-1F52-47C1-8971-885FFD426EE4}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{E7BCF2CF-8A5A-459D-A68B-F732A469DAB3}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CBF53917-2CFE-4BF8-8EAA-BD1A70250085}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{74DF6363-4F99-4AD6-943F-E610CD8E7FB8}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2911227A-0E81-40EC-8EC0-31E675F1B071}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{740A1727-E354-4476-9417-E3E5310B160A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A41B3878-63A3-43CA-8C17-2E5427855CF7}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{34E9A5FD-543C-42E3-A889-01901E2ED476}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7EC6633B-5AB4-4868-8224-901ECA904574}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{E575F44B-09C1-43EF-9AF1-8A74082946AE}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-01-20 64160]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2008-12-30 111184]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 124832]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2008-12-30 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2008-12-30 51792]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
.
Contents of the 'Scheduled Tasks' folder

2009-02-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-02 04:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?source=gama&hl=en
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-03 05:28:01
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-03 5:29:43
ComboFix-quarantined-files.txt 2009-02-03 10:29:40
ComboFix2.txt 2009-02-02 18:37:55
ComboFix3.txt 2009-01-05 19:12:42

Pre-Run: 294,788,763,648 bytes free
Post-Run: 294,749,724,672 bytes free

333 — E O F — 2009-02-02 20:35:58


********************************************************************************
**************************************************
********************************************************************************
************************************************

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-02-03 06:04:19
Windows 6.0.6001 Service Pack 1


—- Kernel code sections - GMER 1.0.14 —-

? C:\Windows\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !
? C:\Users\House\AppData\Local\Temp\catchme.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.14 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[5764] USER32.dll!DialogBoxIndirectParamW 7699BD25 5 Bytes JMP 6AA45BF3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] USER32.dll!DialogBoxParamW 769B1FD5 5 Bytes JMP 6AA45B7D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] USER32.dll!DialogBoxParamA 769D80B2 5 Bytes JMP 6AA45BB8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] USER32.dll!DialogBoxIndirectParamA 769D83DD 5 Bytes JMP 6AA45C2E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] USER32.dll!MessageBoxIndirectA 769ED471 5 Bytes JMP 6AA45B39 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] USER32.dll!MessageBoxIndirectW 769ED56B 5 Bytes JMP 6AA45AF5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] USER32.dll!MessageBoxExA 769ED5D1 5 Bytes JMP 6AA45ABB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] USER32.dll!MessageBoxExW 769ED5F5 5 Bytes JMP 6AA45A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] SHELL32.dll!SHRestricted + DFD 76FC8390 4 Bytes [ 99, 0B, 43, 72 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[5764] SHELL32.dll!SHRestricted + E05 76FC8398 8 Bytes [ A7, 0A, 43, 72, A4, 32, 42, … ]

—- User IAT/EAT - GMER 1.0.14 —-

IAT C:\Windows\system32\services.exe[668] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 000B0002
IAT C:\Windows\system32\services.exe[668] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 000B0000
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [7241D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [7241D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [7241B6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [7241D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [7241BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [7241F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [7241C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [7241F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [7241D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [7241B6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [7241DE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [7241C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [7241F49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [72420D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [7241FC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [724202A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [7241D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [7241BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [7241B114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [7241D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [7241A970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [7242DB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [7242E479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [7242CB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [7242D773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [7242CEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [7242C625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [7242CD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [7241D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [7241E151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [7241B114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [7241A970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [7241A819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [7241C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [7241D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [72418D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [7241BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [724202A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [7241FC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [7241F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [72418AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [72418C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [7241BBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [7241FF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [7241FB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [72420D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [7241EFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [724189D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [7241D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [7241CF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [7241CE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [7242CD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [7242C49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [7242CD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [7242D913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [7242CA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [7242C625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [7242CB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [7242E169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [7242D437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [7242CEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [7242DB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [7242D773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [7242E479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [7242DE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [7242DFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [7242E2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [7242DD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [7242D5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [7241A460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [7241FC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [7241E151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [7241A6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [7241AE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [7241B114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [7241C023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [7241B6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [72419700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [7241D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [7241DE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [724202A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [72420D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [72419362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [724189D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [7241F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [7241A1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [7241A970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [7241EAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [7241E4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [7241C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [72418D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [72418AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [7241DE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [724194A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [7241D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [7241BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [72418FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [7241D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [72419231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [7241F49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [7241C58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [7241CF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [7241CA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [7242CB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [7242C625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW] [7242DE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW] [7242E479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW] [7242CEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [7242DB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [7242D913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW] [7242E169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW] [7242D13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW] [7242D773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW] [7242D437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW] [7242C8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW] [7242C35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA] [7242D5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [7242CA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [7242CD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [724291AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [72420D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [724202A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7241D537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [7241F233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [7241C301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [724194A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [72418FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [7241BD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [7241D221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [72418AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [7241D09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW] [7242D13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] [7242D28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW] [7242E169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW] [7242E479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA] [7242DD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA] [7242CD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [7242DB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [7242D913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW] [7242D437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW] [7242DE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [7242CD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW] [7242D773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [7242CB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW] [7242CEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [7242C625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA] [7242D5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [7242CA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueW] [72425CFD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueA] [72425C9F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathUnExpandEnvStringsA] [72424D95] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteKeyA] [724250AF] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteValueW] [7242519F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCreateFromUrlW] [724240A2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueA] [72425357] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueA] [7242619F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueW] [724253B2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueW] [724261FA] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5764] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCombineW] [72423FFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdiplusShutdown] [74E47BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCloneImage] [74E898C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDrawImageRectI] [74E4D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipSetInterpolationMode] [74E3F527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdiplusStartup] [74E47599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCreateFromHDC] [74E3E43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74E7B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipCreateBitmapFromStream] [74E4D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipGetImageHeight] [74E4012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipGetImageWidth] [74E40095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDisposeImage] [74E371F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipLoadImageFromFileICM] [74ECD802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipLoadImageFromFile] [74E675E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipDeleteGraphics] [74E3DAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipFree] [74E3668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipAlloc] [74E366BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.exe[5900] @ C:\Windows\Explorer.exe [gdiplus.dll!GdipSetCompositingMode] [74E41E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

—- Devices - GMER 1.0.14 —-

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- EOF - GMER 1.0.14 —-
Hi there, thanks so much for your help. I will pop back in tomorrow morning and let you know more. I have been away all day and not on much to little use today to tell. Will let you know asap thanks again but seems good :o) K will post the new hjt log in the morning as well

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI