eyedr90
2010-08-21, 04:48
Hi,
Don't know where else to turn and thought you guys could help. My e-mail contacts keep getting spam from "me" and after running several virus and other scans and getting a brand new computer it is still happening. If you can't help, please direct me to some other help. Thanks a lot.
DDS (Ver_10-03-17.01) - NTFSX64
Run by Bigler at 19:37:15.99 on Fri 08/20/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6136.4360 [GMT -6:00]
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0369.0\mswinext.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\DllHost.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\SysWOW64\WinMsgBalloonServer.exe
C:\Windows\SysWOW64\WinMsgBalloonClient.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Bigler\Desktop\dds.scr
C:\Windows\system32\conhost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://my.msn.com
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\17.7.0.12\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\micros~1\office14\URLREDIR.DLL
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files (x86)\msn toolbar\platform\4.0.0369.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files (x86)\msn toolbar\platform\4.0.0369.0\npwinext.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
uRun: [Google Update] "c:\users\bigler\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Steam] "c:\program files (x86)\steam\Steam.exe" -silent
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [NortonOnlineBackupReminder] "c:\program files (x86)\symantec\norton online backup\activation\NOBuActivation.exe" UNATTENDED
mRun: [MSN Toolbar] "c:\program files (x86)\msn toolbar\platform\4.0.0369.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files (x86)\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files (x86)\picturemover\bin\PictureMover.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files (x86)\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files (x86)\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\common files\microsoft shared\office14\MSOXMLMF.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
mRun-x64: [SmartMenu] c:\program files\hewlett-packard\hp mediasmart\SmartMenu.exe /background
============= SERVICES / DRIVERS ===============
R0 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys [2010-8-13 230456]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nisx64\1107000.00c\symds64.sys [2010-8-19 433200]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1107000.00c\symefa64.sys [2010-8-19 221232]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\bashdefs\20100810.004\BHDrvx64.sys [2010-8-10 945200]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1107000.00c\cchpx64.sys [2010-8-19 615040]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\ipsdefs\20100818.002\IDSviA64.sys [2010-8-20 463408]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\saskutil64.sys [2010-2-17 12360]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nisx64\1107000.00c\ironx64.sys [2010-8-19 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nisx64\1107000.00c\symtdiv.sys [2010-8-19 451120]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore64.exe [2010-6-29 128752]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-8-13 202752]
R2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files (x86)\amd\raidxpert\bin\RAIDXpertService.exe [2009-12-15 122880]
R2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\cinemanow\cinemanow media manager\CinemaNowSvc.exe [2010-2-26 127984]
R2 NIS;Norton Internet Security;c:\program files (x86)\norton internet security\engine\17.7.0.12\ccsvchst.exe [2010-8-19 126392]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2010-8-13 6327296]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-8-13 185344]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-8-19 132656]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2010-8-13 346144]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2010-8-13 39480]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2010-1-19 23536]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-8-20 1255736]
=============== Created Last 30 ================
2010-08-21 00:53:28 0 d-----w- c:\program files\Microsoft Office
2010-08-21 00:53:18 0 d-----w- c:\program files (x86)\Microsoft Analysis Services
2010-08-21 00:52:28 0 d-----w- c:\programdata\Microsoft Help
2010-08-20 22:08:28 0 d--h--w- c:\programdata\{0E8E33D8-193A-414A-A909-0F101A142D26}
2010-08-20 21:59:27 0 d-----w- c:\program files (x86)\Stardock Games
2010-08-20 21:37:21 0 d-----w- c:\users\bigler\appdata\roaming\WildTangent
2010-08-20 20:41:49 0 d-----w- c:\windows\syswow64\Wat
2010-08-20 20:41:49 0 d-----w- c:\windows\system32\Wat
2010-08-20 20:35:54 0 d-----w- c:\program files (x86)\MSXML 4.0
2010-08-20 20:35:20 99176 ----a-w- c:\windows\syswow64\PresentationHostProxy.dll
2010-08-20 20:35:20 49472 ----a-w- c:\windows\syswow64\netfxperf.dll
2010-08-20 20:35:20 48960 ----a-w- c:\windows\system32\netfxperf.dll
2010-08-20 20:35:20 444752 ----a-w- c:\windows\system32\mscoree.dll
2010-08-20 20:35:20 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2010-08-20 20:35:20 297808 ----a-w- c:\windows\syswow64\mscoree.dll
2010-08-20 20:35:20 295264 ----a-w- c:\windows\syswow64\PresentationHost.exe
2010-08-20 20:35:20 1942856 ----a-w- c:\windows\system32\dfshim.dll
2010-08-20 20:35:20 1130824 ----a-w- c:\windows\syswow64\dfshim.dll
2010-08-20 20:35:20 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-08-20 19:59:30 0 d-----w- c:\program files (x86)\LucasArts
2010-08-20 19:58:46 0 d-s---w- c:\program files (x86)\Xfire
2010-08-20 19:58:46 0 d-----w- c:\users\bigler\appdata\roaming\Xfire
2010-08-20 16:49:41 74576 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2010-08-20 16:49:41 70992 ----a-w- c:\windows\syswow64\XAPOFX1_2.dll
2010-08-20 16:49:41 518480 ----a-w- c:\windows\system32\XAudio2_3.dll
2010-08-20 16:49:41 514384 ----a-w- c:\windows\syswow64\XAudio2_3.dll
2010-08-20 16:49:41 235856 ----a-w- c:\windows\syswow64\xactengine3_3.dll
2010-08-20 16:49:41 175440 ----a-w- c:\windows\system32\xactengine3_3.dll
2010-08-20 16:49:40 25936 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2010-08-20 16:49:40 23376 ----a-w- c:\windows\syswow64\X3DAudio1_5.dll
2010-08-20 15:17:06 0 d-----w- c:\windows\syswow64\AGEIA
2010-08-20 15:17:00 0 d-----w- c:\program files (x86)\common files\Wise Installation Wizard
2010-08-20 15:15:59 2337488 ----a-w- c:\windows\syswow64\d3dx9_25.dll
2010-08-20 15:15:59 2222800 ----a-w- c:\windows\syswow64\d3dx9_24.dll
2010-08-20 09:11:03 84992 ----a-w- c:\windows\system32\asycfilt.dll
2010-08-20 09:11:03 67584 ----a-w- c:\windows\syswow64\asycfilt.dll
2010-08-20 09:11:00 463360 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-20 09:11:00 404992 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-20 09:11:00 162304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-08-20 09:09:59 389632 ----a-w- c:\windows\system32\winlogon.exe
2010-08-20 09:08:57 46080 ----a-w- c:\windows\system32\atmlib.dll
2010-08-20 09:08:57 366080 ----a-w- c:\windows\system32\atmfd.dll
2010-08-20 09:08:57 34304 ----a-w- c:\windows\syswow64\atmlib.dll
2010-08-20 09:08:57 293888 ----a-w- c:\windows\syswow64\atmfd.dll
2010-08-20 09:08:56 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-08-20 09:08:56 2048 ----a-w- c:\windows\system32\tzres.dll
2010-08-20 04:30:46 0 d-----w- c:\users\bigler\appdata\roaming\SUPERAntiSpyware.com
2010-08-20 04:30:46 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-20 04:30:43 0 d-----w- c:\programdata\!SASCORE
2010-08-20 04:30:42 0 d-----w- c:\program files\SUPERAntiSpyware
2010-08-20 04:09:32 0 d-----w- c:\programdata\Adobe
2010-08-20 03:58:14 0 d-----w- c:\program files (x86)\common files\Symantec Shared
2010-08-20 02:58:50 0 d-----w- c:\program files (x86)\SystemRequirementsLab
2010-08-20 02:53:14 0 d-----w- c:\programdata\Sun
2010-08-20 02:52:29 423656 ----a-w- c:\windows\syswow64\deployJava1.dll
2010-08-20 02:52:29 153376 ----a-w- c:\windows\syswow64\javaws.exe
2010-08-20 02:52:29 145184 ----a-w- c:\windows\syswow64\javaw.exe
2010-08-20 02:52:29 145184 ----a-w- c:\windows\syswow64\java.exe
2010-08-20 02:47:47 0 d-----w- c:\program files (x86)\common files\Steam
2010-08-20 02:47:46 0 d-----w- c:\program files (x86)\Steam
2010-08-20 02:30:27 854 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.INF
2010-08-20 02:30:27 7440 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.CAT
2010-08-20 02:30:27 173104 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2010-08-20 02:30:27 0 d-----w- c:\program files\Symantec
2010-08-20 02:30:27 0 d-----w- c:\program files\common files\Symantec Shared
2010-08-20 02:29:11 0 d-----w- c:\users\bigler\appdata\roaming\PictureMover
2010-08-20 02:28:54 220672 ----a-w- c:\windows\system32\wintrust.dll
2010-08-20 02:28:54 172032 ----a-w- c:\windows\syswow64\wintrust.dll
2010-08-20 02:28:53 139264 ----a-w- c:\windows\system32\cabview.dll
2010-08-20 02:28:53 132608 ----a-w- c:\windows\syswow64\cabview.dll
2010-08-14 05:41:07 0 --sha-r- C:\OS
2010-08-14 04:59:23 51712 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-08-14 04:59:23 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2010-08-14 04:58:31 311808 ----a-w- c:\windows\system32\msv1_0.dll
2010-08-14 04:58:31 257024 ----a-w- c:\windows\syswow64\msv1_0.dll
2010-08-14 04:58:14 960512 ----a-w- c:\windows\system32\CPFilters.dll
2010-08-14 04:58:14 641536 ----a-w- c:\windows\syswow64\CPFilters.dll
2010-08-14 04:58:05 46592 ----a-w- c:\windows\system32\msasn1.dll
2010-08-14 04:58:05 34816 ----a-w- c:\windows\syswow64\msasn1.dll
2010-08-14 04:57:40 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2010-08-14 04:57:40 12625408 ----a-w- c:\windows\syswow64\wmploc.DLL
2010-08-14 04:57:40 11406336 ----a-w- c:\windows\syswow64\wmp.dll
2010-08-14 04:57:39 982600 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-08-14 04:57:39 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2010-08-14 04:57:39 1320960 ----a-w- c:\windows\syswow64\CertEnroll.dll
2010-08-14 04:56:50 70656 ----a-w- c:\windows\syswow64\fontsub.dll
2010-08-14 04:56:50 148480 ----a-w- c:\windows\system32\t2embed.dll
2010-08-14 04:56:50 108544 ----a-w- c:\windows\syswow64\t2embed.dll
2010-08-14 04:56:50 100864 ----a-w- c:\windows\system32\fontsub.dll
2010-08-14 04:48:56 16440 ----a-w- c:\windows\system32\drivers\AtiPcie64.sys
2010-08-14 04:48:55 230456 ----a-w- c:\windows\system32\drivers\ahcix64s.sys
2010-08-14 04:48:54 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2010-08-14 04:48:54 346144 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2010-08-14 04:48:54 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2010-08-14 04:39:26 0 d-sh--w- C:\$RECYCLE.BIN
2010-08-14 04:33:48 0 d-----w- c:\windows\system32\drivers\NISx64
2010-08-14 04:33:46 0 d-----w- c:\programdata\Norton
2010-08-14 04:33:46 0 d-----w- c:\program files (x86)\Norton Internet Security
2010-08-14 04:33:33 0 d-----w- c:\programdata\NortonInstaller
2010-08-14 04:33:33 0 d-----w- c:\program files (x86)\NortonInstaller
2010-08-14 04:33:07 4398360 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-08-14 04:33:07 3426072 ----a-w- c:\windows\syswow64\d3dx9_32.dll
2010-08-14 04:33:05 20 ----a-w- c:\windows\àóÒ
2010-08-14 04:33:05 0 d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2010-08-14 04:32:22 0 d-----w- c:\program files (x86)\Windows Live SkyDrive
2010-08-14 04:31:59 0 d-----w- c:\windows\PCHEALTH
2010-08-14 04:31:35 0 d-----w- c:\program files (x86)\common files\Windows Live
2010-08-14 04:31:20 0 d-----w- c:\program files (x86)\Microsoft
2010-08-14 04:31:19 0 d-----w- c:\program files (x86)\MSN Toolbar
2010-08-14 04:31:12 0 d-----w- c:\program files (x86)\MSN Toolbar Installer
2010-08-14 04:30:43 0 d-----w- c:\program files\PlayReady
2010-08-14 04:25:24 0 d---a-w- c:\program files (x86)\common files\LS Getting Started
2010-08-14 04:22:02 0 d-----w- c:\programdata\WildTangent
2010-08-14 04:22:02 0 d-----w- c:\program files (x86)\HP Games
2010-08-14 04:21:55 0 d-----w- c:\programdata\PictureMover
2010-08-14 04:21:55 0 d-----w- c:\program files (x86)\PictureMover
2010-08-14 04:21:51 0 d-----w- c:\programdata\Symantec
2010-08-14 04:21:51 0 d-----w- c:\program files (x86)\Symantec
2010-08-14 04:21:48 0 d-----r- c:\program files (x86)\Online Services
2010-08-14 04:17:37 0 d-----w- c:\programdata\Uninstall
2010-08-14 04:17:33 0 d-----w- c:\programdata\CinemaNow
2010-08-14 04:17:32 0 d-----w- c:\program files (x86)\CinemaNow
2010-08-14 04:17:30 0 d-----w- c:\program files (x86)\Microsoft WSE
2010-08-14 04:17:28 0 d-----w- c:\programdata\Sonic
2010-08-14 04:17:18 0 d-----w- c:\programdata\Macrovision
2010-08-14 04:16:45 0 d-----w- c:\programdata\CyberLink
2010-08-14 04:11:37 253952 ----a-w- c:\windows\syswow64\cPC_DMIRD.dll
2010-08-14 04:11:32 0 d-----w- c:\program files (x86)\Hp
2010-08-14 04:11:00 0 d-----w- c:\programdata\Temp
2010-08-14 04:10:56 0 d-----w- c:\programdata\PC-Doctor for Windows
2010-08-14 04:10:33 0 d-----w- c:\program files\PC-Doctor for Windows
2010-08-14 04:09:53 0 d-----w- c:\windows\Downloaded Installations
2010-08-14 04:07:47 64000 ------w- c:\windows\syswow64\agrsmdel.exe
2010-08-14 04:07:47 27648 ------w- c:\windows\syswow64\agrsco64.dll
2010-08-14 04:07:46 0 d-----w- c:\windows\Options
2010-08-14 04:07:40 0 d-----w- c:\programdata\ATI
2010-08-14 04:07:12 0 d-----w- c:\program files\ATI
2010-08-14 04:07:12 0 d-----w- c:\program files (x86)\ATI Technologies
2010-08-14 04:06:54 0 d-----w- c:\program files\DIFX
2010-08-14 04:06:53 39480 ----a-w- c:\windows\system32\drivers\usbfilter.sys
2010-08-14 04:06:53 0 d-----w- c:\program files (x86)\AMD
2010-08-14 04:06:16 0 d-----w- c:\program files (x86)\Realtek
2010-08-14 04:06:15 1247776 ----a-w- c:\windows\RtlExUpd.dll
2010-08-14 04:06:15 0 d--h--w- c:\program files (x86)\Temp
2010-08-14 04:05:47 0 d-----w- c:\programdata\Hewlett-Packard
2010-08-14 04:05:20 0 d-----w- c:\programdata\{657095DF-DBDB-4B17-8245-B38845C97069}
2010-08-14 04:05:01 0 d-----w- c:\program files\hp
2010-08-14 04:04:59 0 d-----w- c:\windows\syswow64\Macromed
2010-08-14 04:04:53 0 d-----w- c:\program files\Hewlett-Packard
2010-08-14 04:04:32 0 d-sh--w- c:\windows\Installer
2010-08-14 04:01:57 0 d-----w- c:\windows\syswow64\RTCOM
2010-08-14 04:01:57 0 d-----w- c:\program files\Realtek
2010-08-14 04:01:52 0 ----a-w- c:\windows\ativpsrm.bin
2010-08-14 04:01:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-08-06 16:35:28 0 d-sha-r- C:\hp
==================== Find3M ====================
2010-08-20 02:27:53 0 --sha-r- c:\windows\system32\drivers\103C_HP_53316J G D_HPE-300z_Y53316J G D_0U_Q2MD032_E2MD0320H6P DPS_4A_I2A92_SFOXCONN_V1.01_6.05_T100702_WU3-0_L409_M6136_J750_7AMD_8F43_92.80_#100819_N10EC8168_(WS387AV#ABA)_X_CD3_Z_2_G100268D9.MRK
2010-07-29 06:30:34 82944 ----a-w- c:\windows\syswow64\iccvid.dll
2010-07-27 14:03:24 12867584 ----a-w- c:\windows\syswow64\shell32.dll
2010-06-30 07:13:46 1192960 ----a-w- c:\windows\system32\wininet.dll
2010-06-30 06:25:31 978432 ----a-w- c:\windows\syswow64\wininet.dll
2010-06-30 06:25:18 1226240 ----a-w- c:\windows\syswow64\urlmon.dll
2010-06-30 06:22:45 606208 ----a-w- c:\windows\syswow64\mstime.dll
2010-06-30 06:22:34 5971456 ----a-w- c:\windows\syswow64\mshtml.dll
2010-06-30 06:22:33 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2010-06-30 06:21:57 48128 ----a-w- c:\windows\syswow64\jsproxy.dll
2010-06-30 06:21:47 185856 ----a-w- c:\windows\syswow64\iepeers.dll
2010-06-30 06:21:47 176640 ----a-w- c:\windows\syswow64\ieui.dll
2010-06-30 06:21:46 10985472 ----a-w- c:\windows\syswow64\ieframe.dll
2010-06-30 06:21:44 381440 ----a-w- c:\windows\syswow64\iedkcs32.dll
2010-06-30 06:19:16 12800 ----a-w- c:\windows\syswow64\msfeedssync.exe
2010-06-19 07:05:01 5507968 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:53:18 52224 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 06:33:29 3955080 ----a-w- c:\windows\syswow64\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- c:\windows\syswow64\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- c:\windows\syswow64\rtutils.dll
2010-06-19 04:32:34 3122688 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 06:11:10 340992 ----a-w- c:\windows\system32\schannel.dll
2010-06-16 05:48:35 224256 ----a-w- c:\windows\syswow64\schannel.dll
2010-06-08 06:02:06 1233920 ----a-w- c:\windows\syswow64\msxml3.dll
2010-06-08 05:36:31 1877504 ----a-w- c:\windows\system32\msxml3.dll
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 04:55:03 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-07-14 04:55:03 32768 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-07-14 04:55:03 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\cookies\index.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 19:37:26.90 ===============
Don't know where else to turn and thought you guys could help. My e-mail contacts keep getting spam from "me" and after running several virus and other scans and getting a brand new computer it is still happening. If you can't help, please direct me to some other help. Thanks a lot.
DDS (Ver_10-03-17.01) - NTFSX64
Run by Bigler at 19:37:15.99 on Fri 08/20/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6136.4360 [GMT -6:00]
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0369.0\mswinext.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\DllHost.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\SysWOW64\WinMsgBalloonServer.exe
C:\Windows\SysWOW64\WinMsgBalloonClient.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Bigler\Desktop\dds.scr
C:\Windows\system32\conhost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://my.msn.com
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\17.7.0.12\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\micros~1\office14\URLREDIR.DLL
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files (x86)\msn toolbar\platform\4.0.0369.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files (x86)\msn toolbar\platform\4.0.0369.0\npwinext.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
uRun: [Google Update] "c:\users\bigler\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Steam] "c:\program files (x86)\steam\Steam.exe" -silent
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [NortonOnlineBackupReminder] "c:\program files (x86)\symantec\norton online backup\activation\NOBuActivation.exe" UNATTENDED
mRun: [MSN Toolbar] "c:\program files (x86)\msn toolbar\platform\4.0.0369.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files (x86)\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files (x86)\picturemover\bin\PictureMover.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files (x86)\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files (x86)\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\common files\microsoft shared\office14\MSOXMLMF.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
mRun-x64: [SmartMenu] c:\program files\hewlett-packard\hp mediasmart\SmartMenu.exe /background
============= SERVICES / DRIVERS ===============
R0 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys [2010-8-13 230456]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nisx64\1107000.00c\symds64.sys [2010-8-19 433200]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1107000.00c\symefa64.sys [2010-8-19 221232]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\bashdefs\20100810.004\BHDrvx64.sys [2010-8-10 945200]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1107000.00c\cchpx64.sys [2010-8-19 615040]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\ipsdefs\20100818.002\IDSviA64.sys [2010-8-20 463408]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\saskutil64.sys [2010-2-17 12360]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nisx64\1107000.00c\ironx64.sys [2010-8-19 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nisx64\1107000.00c\symtdiv.sys [2010-8-19 451120]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore64.exe [2010-6-29 128752]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-8-13 202752]
R2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files (x86)\amd\raidxpert\bin\RAIDXpertService.exe [2009-12-15 122880]
R2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\cinemanow\cinemanow media manager\CinemaNowSvc.exe [2010-2-26 127984]
R2 NIS;Norton Internet Security;c:\program files (x86)\norton internet security\engine\17.7.0.12\ccsvchst.exe [2010-8-19 126392]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2010-8-13 6327296]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-8-13 185344]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-8-19 132656]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2010-8-13 346144]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2010-8-13 39480]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2010-1-19 23536]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-8-20 1255736]
=============== Created Last 30 ================
2010-08-21 00:53:28 0 d-----w- c:\program files\Microsoft Office
2010-08-21 00:53:18 0 d-----w- c:\program files (x86)\Microsoft Analysis Services
2010-08-21 00:52:28 0 d-----w- c:\programdata\Microsoft Help
2010-08-20 22:08:28 0 d--h--w- c:\programdata\{0E8E33D8-193A-414A-A909-0F101A142D26}
2010-08-20 21:59:27 0 d-----w- c:\program files (x86)\Stardock Games
2010-08-20 21:37:21 0 d-----w- c:\users\bigler\appdata\roaming\WildTangent
2010-08-20 20:41:49 0 d-----w- c:\windows\syswow64\Wat
2010-08-20 20:41:49 0 d-----w- c:\windows\system32\Wat
2010-08-20 20:35:54 0 d-----w- c:\program files (x86)\MSXML 4.0
2010-08-20 20:35:20 99176 ----a-w- c:\windows\syswow64\PresentationHostProxy.dll
2010-08-20 20:35:20 49472 ----a-w- c:\windows\syswow64\netfxperf.dll
2010-08-20 20:35:20 48960 ----a-w- c:\windows\system32\netfxperf.dll
2010-08-20 20:35:20 444752 ----a-w- c:\windows\system32\mscoree.dll
2010-08-20 20:35:20 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2010-08-20 20:35:20 297808 ----a-w- c:\windows\syswow64\mscoree.dll
2010-08-20 20:35:20 295264 ----a-w- c:\windows\syswow64\PresentationHost.exe
2010-08-20 20:35:20 1942856 ----a-w- c:\windows\system32\dfshim.dll
2010-08-20 20:35:20 1130824 ----a-w- c:\windows\syswow64\dfshim.dll
2010-08-20 20:35:20 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-08-20 19:59:30 0 d-----w- c:\program files (x86)\LucasArts
2010-08-20 19:58:46 0 d-s---w- c:\program files (x86)\Xfire
2010-08-20 19:58:46 0 d-----w- c:\users\bigler\appdata\roaming\Xfire
2010-08-20 16:49:41 74576 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2010-08-20 16:49:41 70992 ----a-w- c:\windows\syswow64\XAPOFX1_2.dll
2010-08-20 16:49:41 518480 ----a-w- c:\windows\system32\XAudio2_3.dll
2010-08-20 16:49:41 514384 ----a-w- c:\windows\syswow64\XAudio2_3.dll
2010-08-20 16:49:41 235856 ----a-w- c:\windows\syswow64\xactengine3_3.dll
2010-08-20 16:49:41 175440 ----a-w- c:\windows\system32\xactengine3_3.dll
2010-08-20 16:49:40 25936 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2010-08-20 16:49:40 23376 ----a-w- c:\windows\syswow64\X3DAudio1_5.dll
2010-08-20 15:17:06 0 d-----w- c:\windows\syswow64\AGEIA
2010-08-20 15:17:00 0 d-----w- c:\program files (x86)\common files\Wise Installation Wizard
2010-08-20 15:15:59 2337488 ----a-w- c:\windows\syswow64\d3dx9_25.dll
2010-08-20 15:15:59 2222800 ----a-w- c:\windows\syswow64\d3dx9_24.dll
2010-08-20 09:11:03 84992 ----a-w- c:\windows\system32\asycfilt.dll
2010-08-20 09:11:03 67584 ----a-w- c:\windows\syswow64\asycfilt.dll
2010-08-20 09:11:00 463360 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-20 09:11:00 404992 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-20 09:11:00 162304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-08-20 09:09:59 389632 ----a-w- c:\windows\system32\winlogon.exe
2010-08-20 09:08:57 46080 ----a-w- c:\windows\system32\atmlib.dll
2010-08-20 09:08:57 366080 ----a-w- c:\windows\system32\atmfd.dll
2010-08-20 09:08:57 34304 ----a-w- c:\windows\syswow64\atmlib.dll
2010-08-20 09:08:57 293888 ----a-w- c:\windows\syswow64\atmfd.dll
2010-08-20 09:08:56 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-08-20 09:08:56 2048 ----a-w- c:\windows\system32\tzres.dll
2010-08-20 04:30:46 0 d-----w- c:\users\bigler\appdata\roaming\SUPERAntiSpyware.com
2010-08-20 04:30:46 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-20 04:30:43 0 d-----w- c:\programdata\!SASCORE
2010-08-20 04:30:42 0 d-----w- c:\program files\SUPERAntiSpyware
2010-08-20 04:09:32 0 d-----w- c:\programdata\Adobe
2010-08-20 03:58:14 0 d-----w- c:\program files (x86)\common files\Symantec Shared
2010-08-20 02:58:50 0 d-----w- c:\program files (x86)\SystemRequirementsLab
2010-08-20 02:53:14 0 d-----w- c:\programdata\Sun
2010-08-20 02:52:29 423656 ----a-w- c:\windows\syswow64\deployJava1.dll
2010-08-20 02:52:29 153376 ----a-w- c:\windows\syswow64\javaws.exe
2010-08-20 02:52:29 145184 ----a-w- c:\windows\syswow64\javaw.exe
2010-08-20 02:52:29 145184 ----a-w- c:\windows\syswow64\java.exe
2010-08-20 02:47:47 0 d-----w- c:\program files (x86)\common files\Steam
2010-08-20 02:47:46 0 d-----w- c:\program files (x86)\Steam
2010-08-20 02:30:27 854 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.INF
2010-08-20 02:30:27 7440 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.CAT
2010-08-20 02:30:27 173104 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2010-08-20 02:30:27 0 d-----w- c:\program files\Symantec
2010-08-20 02:30:27 0 d-----w- c:\program files\common files\Symantec Shared
2010-08-20 02:29:11 0 d-----w- c:\users\bigler\appdata\roaming\PictureMover
2010-08-20 02:28:54 220672 ----a-w- c:\windows\system32\wintrust.dll
2010-08-20 02:28:54 172032 ----a-w- c:\windows\syswow64\wintrust.dll
2010-08-20 02:28:53 139264 ----a-w- c:\windows\system32\cabview.dll
2010-08-20 02:28:53 132608 ----a-w- c:\windows\syswow64\cabview.dll
2010-08-14 05:41:07 0 --sha-r- C:\OS
2010-08-14 04:59:23 51712 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-08-14 04:59:23 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2010-08-14 04:58:31 311808 ----a-w- c:\windows\system32\msv1_0.dll
2010-08-14 04:58:31 257024 ----a-w- c:\windows\syswow64\msv1_0.dll
2010-08-14 04:58:14 960512 ----a-w- c:\windows\system32\CPFilters.dll
2010-08-14 04:58:14 641536 ----a-w- c:\windows\syswow64\CPFilters.dll
2010-08-14 04:58:05 46592 ----a-w- c:\windows\system32\msasn1.dll
2010-08-14 04:58:05 34816 ----a-w- c:\windows\syswow64\msasn1.dll
2010-08-14 04:57:40 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2010-08-14 04:57:40 12625408 ----a-w- c:\windows\syswow64\wmploc.DLL
2010-08-14 04:57:40 11406336 ----a-w- c:\windows\syswow64\wmp.dll
2010-08-14 04:57:39 982600 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-08-14 04:57:39 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2010-08-14 04:57:39 1320960 ----a-w- c:\windows\syswow64\CertEnroll.dll
2010-08-14 04:56:50 70656 ----a-w- c:\windows\syswow64\fontsub.dll
2010-08-14 04:56:50 148480 ----a-w- c:\windows\system32\t2embed.dll
2010-08-14 04:56:50 108544 ----a-w- c:\windows\syswow64\t2embed.dll
2010-08-14 04:56:50 100864 ----a-w- c:\windows\system32\fontsub.dll
2010-08-14 04:48:56 16440 ----a-w- c:\windows\system32\drivers\AtiPcie64.sys
2010-08-14 04:48:55 230456 ----a-w- c:\windows\system32\drivers\ahcix64s.sys
2010-08-14 04:48:54 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2010-08-14 04:48:54 346144 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2010-08-14 04:48:54 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2010-08-14 04:39:26 0 d-sh--w- C:\$RECYCLE.BIN
2010-08-14 04:33:48 0 d-----w- c:\windows\system32\drivers\NISx64
2010-08-14 04:33:46 0 d-----w- c:\programdata\Norton
2010-08-14 04:33:46 0 d-----w- c:\program files (x86)\Norton Internet Security
2010-08-14 04:33:33 0 d-----w- c:\programdata\NortonInstaller
2010-08-14 04:33:33 0 d-----w- c:\program files (x86)\NortonInstaller
2010-08-14 04:33:07 4398360 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-08-14 04:33:07 3426072 ----a-w- c:\windows\syswow64\d3dx9_32.dll
2010-08-14 04:33:05 20 ----a-w- c:\windows\àóÒ
2010-08-14 04:33:05 0 d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2010-08-14 04:32:22 0 d-----w- c:\program files (x86)\Windows Live SkyDrive
2010-08-14 04:31:59 0 d-----w- c:\windows\PCHEALTH
2010-08-14 04:31:35 0 d-----w- c:\program files (x86)\common files\Windows Live
2010-08-14 04:31:20 0 d-----w- c:\program files (x86)\Microsoft
2010-08-14 04:31:19 0 d-----w- c:\program files (x86)\MSN Toolbar
2010-08-14 04:31:12 0 d-----w- c:\program files (x86)\MSN Toolbar Installer
2010-08-14 04:30:43 0 d-----w- c:\program files\PlayReady
2010-08-14 04:25:24 0 d---a-w- c:\program files (x86)\common files\LS Getting Started
2010-08-14 04:22:02 0 d-----w- c:\programdata\WildTangent
2010-08-14 04:22:02 0 d-----w- c:\program files (x86)\HP Games
2010-08-14 04:21:55 0 d-----w- c:\programdata\PictureMover
2010-08-14 04:21:55 0 d-----w- c:\program files (x86)\PictureMover
2010-08-14 04:21:51 0 d-----w- c:\programdata\Symantec
2010-08-14 04:21:51 0 d-----w- c:\program files (x86)\Symantec
2010-08-14 04:21:48 0 d-----r- c:\program files (x86)\Online Services
2010-08-14 04:17:37 0 d-----w- c:\programdata\Uninstall
2010-08-14 04:17:33 0 d-----w- c:\programdata\CinemaNow
2010-08-14 04:17:32 0 d-----w- c:\program files (x86)\CinemaNow
2010-08-14 04:17:30 0 d-----w- c:\program files (x86)\Microsoft WSE
2010-08-14 04:17:28 0 d-----w- c:\programdata\Sonic
2010-08-14 04:17:18 0 d-----w- c:\programdata\Macrovision
2010-08-14 04:16:45 0 d-----w- c:\programdata\CyberLink
2010-08-14 04:11:37 253952 ----a-w- c:\windows\syswow64\cPC_DMIRD.dll
2010-08-14 04:11:32 0 d-----w- c:\program files (x86)\Hp
2010-08-14 04:11:00 0 d-----w- c:\programdata\Temp
2010-08-14 04:10:56 0 d-----w- c:\programdata\PC-Doctor for Windows
2010-08-14 04:10:33 0 d-----w- c:\program files\PC-Doctor for Windows
2010-08-14 04:09:53 0 d-----w- c:\windows\Downloaded Installations
2010-08-14 04:07:47 64000 ------w- c:\windows\syswow64\agrsmdel.exe
2010-08-14 04:07:47 27648 ------w- c:\windows\syswow64\agrsco64.dll
2010-08-14 04:07:46 0 d-----w- c:\windows\Options
2010-08-14 04:07:40 0 d-----w- c:\programdata\ATI
2010-08-14 04:07:12 0 d-----w- c:\program files\ATI
2010-08-14 04:07:12 0 d-----w- c:\program files (x86)\ATI Technologies
2010-08-14 04:06:54 0 d-----w- c:\program files\DIFX
2010-08-14 04:06:53 39480 ----a-w- c:\windows\system32\drivers\usbfilter.sys
2010-08-14 04:06:53 0 d-----w- c:\program files (x86)\AMD
2010-08-14 04:06:16 0 d-----w- c:\program files (x86)\Realtek
2010-08-14 04:06:15 1247776 ----a-w- c:\windows\RtlExUpd.dll
2010-08-14 04:06:15 0 d--h--w- c:\program files (x86)\Temp
2010-08-14 04:05:47 0 d-----w- c:\programdata\Hewlett-Packard
2010-08-14 04:05:20 0 d-----w- c:\programdata\{657095DF-DBDB-4B17-8245-B38845C97069}
2010-08-14 04:05:01 0 d-----w- c:\program files\hp
2010-08-14 04:04:59 0 d-----w- c:\windows\syswow64\Macromed
2010-08-14 04:04:53 0 d-----w- c:\program files\Hewlett-Packard
2010-08-14 04:04:32 0 d-sh--w- c:\windows\Installer
2010-08-14 04:01:57 0 d-----w- c:\windows\syswow64\RTCOM
2010-08-14 04:01:57 0 d-----w- c:\program files\Realtek
2010-08-14 04:01:52 0 ----a-w- c:\windows\ativpsrm.bin
2010-08-14 04:01:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-08-06 16:35:28 0 d-sha-r- C:\hp
==================== Find3M ====================
2010-08-20 02:27:53 0 --sha-r- c:\windows\system32\drivers\103C_HP_53316J G D_HPE-300z_Y53316J G D_0U_Q2MD032_E2MD0320H6P DPS_4A_I2A92_SFOXCONN_V1.01_6.05_T100702_WU3-0_L409_M6136_J750_7AMD_8F43_92.80_#100819_N10EC8168_(WS387AV#ABA)_X_CD3_Z_2_G100268D9.MRK
2010-07-29 06:30:34 82944 ----a-w- c:\windows\syswow64\iccvid.dll
2010-07-27 14:03:24 12867584 ----a-w- c:\windows\syswow64\shell32.dll
2010-06-30 07:13:46 1192960 ----a-w- c:\windows\system32\wininet.dll
2010-06-30 06:25:31 978432 ----a-w- c:\windows\syswow64\wininet.dll
2010-06-30 06:25:18 1226240 ----a-w- c:\windows\syswow64\urlmon.dll
2010-06-30 06:22:45 606208 ----a-w- c:\windows\syswow64\mstime.dll
2010-06-30 06:22:34 5971456 ----a-w- c:\windows\syswow64\mshtml.dll
2010-06-30 06:22:33 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2010-06-30 06:21:57 48128 ----a-w- c:\windows\syswow64\jsproxy.dll
2010-06-30 06:21:47 185856 ----a-w- c:\windows\syswow64\iepeers.dll
2010-06-30 06:21:47 176640 ----a-w- c:\windows\syswow64\ieui.dll
2010-06-30 06:21:46 10985472 ----a-w- c:\windows\syswow64\ieframe.dll
2010-06-30 06:21:44 381440 ----a-w- c:\windows\syswow64\iedkcs32.dll
2010-06-30 06:19:16 12800 ----a-w- c:\windows\syswow64\msfeedssync.exe
2010-06-19 07:05:01 5507968 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:53:18 52224 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 06:33:29 3955080 ----a-w- c:\windows\syswow64\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- c:\windows\syswow64\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- c:\windows\syswow64\rtutils.dll
2010-06-19 04:32:34 3122688 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 06:11:10 340992 ----a-w- c:\windows\system32\schannel.dll
2010-06-16 05:48:35 224256 ----a-w- c:\windows\syswow64\schannel.dll
2010-06-08 06:02:06 1233920 ----a-w- c:\windows\syswow64\msxml3.dll
2010-06-08 05:36:31 1877504 ----a-w- c:\windows\system32\msxml3.dll
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 04:55:03 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-07-14 04:55:03 32768 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-07-14 04:55:03 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\cookies\index.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 19:37:26.90 ===============