Malware Infection

Hi, I ran GMER and checked the C: Drive and unchecked all except the Sections Tab, but when it finished, the log was empty.

I ran the scan, it didn't detect anything, but here is the fsbl log.

08/13/10 16:45:42 [Info]: BlackLight Engine 2.2.1092 initialized
08/13/10 16:45:42 [Info]: OS: 6.0 build 6002 (Service Pack 2)
08/13/10 16:45:43 [Note]: 7019 4
08/13/10 16:45:43 [Note]: 7005 0
08/13/10 16:50:12 [Note]: 7006 0
08/13/10 16:50:12 [Note]: 7027 0
08/13/10 16:50:12 [Note]: 7035 0
08/13/10 16:50:13 [Note]: 7026 0
08/13/10 16:50:13 [Note]: 7026 0
08/13/10 16:50:15 [Note]: FSRAW library version 1.7.1024
08/13/10 16:51:58 [Note]: 4015 80354
08/13/10 16:51:58 [Note]: 4027 80354 196608
08/13/10 16:51:58 [Note]: 4020 78928 262144
08/13/10 16:51:58 [Note]: 4018 78928 262144
08/13/10 16:53:25 [Note]: 4015 9344
08/13/10 16:53:25 [Note]: 4027 9344 65536
08/13/10 16:53:25 [Note]: 4020 36 65536
08/13/10 16:53:25 [Note]: 4018 36 65536
08/13/10 17:06:26 [Note]: 2000 1012
08/13/10 17:06:52 [Note]: 7007 0
 
Wow, this bugger is hard to track down


First drag Combofix to the trash and download a fresh copy

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


Backup Your Registry with ERUNT:
  • Download erunt.zip to your Desktop from here:
    http://aumha.org/downloads/erunt.zip
  • Right-click erunt.zip, select Extract All... and follow the prompts to extract ERUNT to a new folder on your Desktop
  • Inside the new folder, double-click ERUNT.exe to start the program
  • OK all the prompts to back up your registry to the default location.
Note: to restore your registry, go to the backup folder and start ERDNT.exe




Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Folder::


Code:
Folder::
c:\program files\SGPSA

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FBSSA"=-

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

CFScriptB-4.gif



This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
 
Last edited:
Hi. Here is the combofix log.

ComboFix 10-08-14.01 - Darlin 14/08/2010 14:32:08.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2814.2009 [GMT -4:00]
Running from: c:\users\Darlin\Desktop\ComboFix.exe
Command switches used :: c:\users\Darlin\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-07-14 to 2010-08-14 )))))))))))))))))))))))))))))))
.

2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\TEMP.Darlin-PC\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\TEMP.Darlin-PC.000\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-14 18:40 . 2010-08-14 18:40 -------- d-----w- c:\users\Bhing or J.A\AppData\Local\temp
2010-08-12 01:05 . 2010-05-27 20:08 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-08-12 01:05 . 2010-06-29 15:47 834048 ----a-w- c:\windows\system32\wininet.dll
2010-08-12 01:05 . 2010-06-28 16:13 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-08-12 01:05 . 2010-06-11 16:16 274944 ----a-w- c:\windows\system32\schannel.dll
2010-08-12 01:04 . 2010-06-21 13:37 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-08-12 01:04 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-08-12 01:04 . 2010-06-08 17:35 3600768 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-12 01:04 . 2010-06-08 17:35 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-08-12 01:04 . 2010-06-11 16:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-08-12 01:04 . 2010-06-18 15:04 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-12 01:04 . 2010-06-18 15:04 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-12 01:04 . 2010-06-16 16:04 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-03 15:53 . 2010-08-03 15:54 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-08-01 20:15 . 2010-08-01 20:15 -------- d-----w- c:\program files\iPod
2010-08-01 20:08 . 2010-08-01 20:08 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-08-01 03:09 . 2010-08-01 03:09 -------- d-----w- c:\users\Darlin\AppData\Local\Yahoo
2010-08-01 03:04 . 2010-08-03 15:55 -------- d-----w- c:\programdata\Yahoo! Companion
2010-08-01 03:03 . 2010-08-01 03:04 -------- d-----w- c:\programdata\Yahoo!
2010-08-01 03:03 . 2010-04-20 20:45 607472 ----a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2010-07-31 19:24 . 2010-07-31 19:24 -------- d-----w- C:\_OTM
2010-07-22 18:17 . 2010-07-22 18:17 -------- d-----w- c:\program files\Trend Micro
2010-07-22 17:01 . 2010-07-22 17:01 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-07-19 18:09 . 2010-07-19 18:09 -------- d-----w- C:\_OTL
2010-07-18 19:12 . 2010-07-18 19:12 -------- d-----w- c:\users\Darlin\AppData\Local\Apple
2010-07-18 18:54 . 2010-07-19 18:56 -------- d-----w- c:\users\Darlin\AppData\Local\Adobe
2010-07-18 17:28 . 2010-07-18 17:28 -------- d-----w- c:\users\Darlin\AppData\Local\Apple Computer
2010-07-18 16:48 . 2010-07-18 16:48 -------- d-----w- c:\users\Darlin\AppData\Roaming\Malwarebytes
2010-07-18 16:48 . 2010-07-18 16:48 -------- d-----w- c:\programdata\Malwarebytes
2010-07-18 16:48 . 2010-07-21 18:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-14 17:04 . 2009-08-14 18:57 -------- d-----w- c:\program files\Microsoft Works
2010-08-14 17:01 . 2009-08-14 18:59 -------- d-----w- c:\programdata\Microsoft Help
2010-08-14 16:54 . 2009-09-05 23:39 48670 ----a-w- c:\programdata\nvModes.dat
2010-08-14 05:09 . 2008-08-11 12:18 12 ----a-w- c:\windows\bthservsdp.dat
2010-08-13 17:40 . 2008-08-11 10:56 62236 ----a-w- c:\windows\system32\perfh00C.dat
2010-08-13 17:40 . 2008-08-11 10:56 19286 ----a-w- c:\windows\system32\perfc00C.dat
2010-08-13 17:37 . 2009-08-24 20:51 1356 ----a-w- c:\users\Darlin\AppData\Local\d3d9caps.dat
2010-08-12 13:44 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-07 18:16 . 2009-09-11 20:45 -------- d-----w- c:\programdata\HP Product Assistant
2010-08-07 18:16 . 2009-08-22 00:41 -------- d-----w- c:\program files\Microsoft
2010-08-01 20:15 . 2010-06-20 19:29 -------- d-----w- c:\program files\iTunes
2010-08-01 20:15 . 2009-08-21 23:38 -------- d-----w- c:\program files\Common Files\Apple
2010-08-01 03:05 . 2009-09-07 21:28 -------- d-----w- c:\users\Darlin\AppData\Roaming\Yahoo!
2010-08-01 03:04 . 2008-08-11 14:32 -------- d-----w- c:\program files\Yahoo!
2010-07-20 18:28 . 2010-07-11 21:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-18 00:48 . 2009-08-21 23:44 -------- d-----w- c:\users\Darlin\AppData\Roaming\LimeWire
2010-07-18 00:44 . 2009-08-21 23:40 -------- d-----w- c:\program files\LimeWire
2010-07-14 02:07 . 2009-08-14 18:56 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-12 16:25 . 2010-07-12 16:25 -------- d-----w- c:\program files\Safer Networking
2010-07-12 13:25 . 2010-07-12 13:25 8 ----a-w- c:\users\Darlin\AppData\Roaming\vdnxlf.dat
2010-07-12 01:18 . 2010-07-11 21:16 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-11 23:54 . 2010-07-11 23:54 -------- d-----w- c:\program files\TweetDeck
2010-07-11 18:14 . 2010-07-11 18:14 -------- d-sh--w- c:\programdata\SMACCEEAV
2010-07-11 17:54 . 2009-12-30 23:37 -------- d-----w- c:\users\Darlin\AppData\Roaming\vlc
2010-07-10 03:20 . 2010-07-10 03:20 88576 --sha-r- c:\users\Darlin\AppData\Roaming\nb-NOM.dll
2010-07-10 03:20 . 2010-07-10 03:20 88576 --sha-r- c:\users\Darlin\AppData\Roaming\nb-NOM.dll
2010-06-25 15:15 . 2009-08-24 21:08 -------- d-----w- c:\program files\Microsoft.NET
2010-06-23 17:56 . 2009-08-22 01:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-20 19:24 . 2010-06-20 19:24 -------- d-----w- c:\program files\Bonjour
2010-06-14 16:08 . 2010-06-29 20:36 103424 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-06-14 16:08 . 2010-06-29 20:36 545280 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-06-14 16:08 . 2010-06-29 20:36 4687360 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-06-14 16:08 . 2010-06-29 20:36 425984 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-06-14 16:08 . 2010-06-29 20:36 152064 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-06-14 16:08 . 2010-06-29 20:36 4687872 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-06-14 16:08 . 2010-06-29 20:36 57856 ----a-w- c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-06-08 21:01 . 2009-08-21 22:23 77944 ----a-w- c:\users\Darlin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-26 17:06 . 2010-06-10 18:58 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-10 18:58 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14 . 2009-10-03 03:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-03-10 23:05 . 2009-10-03 04:02 59232800 --sha-w- c:\windows\System32\drivers\fidbox.dat
2008-08-11 10:58 . 2008-08-11 10:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2010-07-18_01.05.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-01 03:03 . 2010-08-01 03:03 65536 c:\windows\winsxs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.4053_none_3b0e32bdc9afe437\vcomp.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 49152 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80KOR.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 49152 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80JPN.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ITA.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80FRA.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ESP.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 57344 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ENU.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 65536 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80DEU.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 45056 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80CHT.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 40960 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80CHS.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 57856 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfcm80u.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 69632 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfcm80.dll
+ 2010-08-12 01:05 . 2010-05-28 16:14 81920 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6002.22414_none_6f0c0c64eeb82f1d\iccvid.dll
+ 2010-08-12 01:05 . 2010-05-27 20:08 81920 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6002.18263_none_6e4b5dcdd5c4048a\iccvid.dll
+ 2010-08-12 01:05 . 2010-05-27 19:11 81920 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6001.22702_none_6d2e69d4f18b8b5a\iccvid.dll
+ 2010-08-12 01:05 . 2010-05-27 19:16 81920 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6001.18483_none_6c4f4a27d8adea21\iccvid.dll
+ 2010-08-12 01:04 . 2010-06-18 14:50 99328 c:\windows\winsxs\x86_microsoft-windows-smbserver-common_31bf3856ad364e35_6.0.6001.22715_none_045a07e92948400f\srvnet.sys
+ 2010-08-12 01:04 . 2010-06-18 18:00 36864 c:\windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6002.22427_none_0f77105600c85cb8\rtutils.dll
+ 2010-08-12 01:04 . 2010-06-18 17:31 36864 c:\windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6002.18274_none_0eb4612ae7d5ff77\rtutils.dll
+ 2010-08-12 01:04 . 2010-06-18 16:38 36352 c:\windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6001.22715_none_0d996dc6039bb8f5\rtutils.dll
+ 2010-08-12 01:04 . 2010-06-18 16:43 36352 c:\windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6001.18495_none_0cb94dceeabefe65\rtutils.dll
+ 2010-08-12 01:04 . 2010-06-16 15:56 98192 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22713_none_cda6490a43adceb3\FWPKCLNT.SYS
+ 2010-08-12 01:04 . 2010-06-17 18:30 23552 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.22426_none_f4c2683b236c5a9c\WMM2EXT.dll
+ 2009-09-17 20:22 . 2009-04-11 06:28 23040 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.18273_none_f3ffb9100a79fd5b\WMM2EXT.dll
+ 2010-08-12 01:04 . 2010-06-17 17:24 23552 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.22714_none_f2e4c5ab263fb6d9\WMM2EXT.dll
+ 2006-11-02 12:36 . 2006-11-02 12:36 23040 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.18494_none_f204a5b40d62fc49\WMM2EXT.dll
+ 2010-08-12 01:04 . 2010-06-16 14:01 31232 c:\windows\winsxs\x86_microsoft-windows-l..istry-support-tcpip_31bf3856ad364e35_6.0.6002.22425_none_887cb1b81bbc94f9\tcpipreg.sys
+ 2010-08-12 01:05 . 2010-06-28 14:52 26624 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_2fd60860332c475f\ieUnatt.exe
+ 2010-06-10 18:58 . 2010-05-04 16:53 26624 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_2f08baa51a403b96\ieUnatt.exe
+ 2010-08-12 01:05 . 2010-06-28 14:52 48128 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.22720_none_f3e18ed7d35462d7\mshtmler.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 78336 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.22720_none_f3e18ed7d35462d7\ieencode.dll
+ 2006-11-02 07:33 . 2006-11-02 07:33 48128 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18498_none_f314411cba68570e\mshtmler.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 78336 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18498_none_f314411cba68570e\ieencode.dll
+ 2010-08-12 01:05 . 2010-06-28 16:24 72704 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22720_none_aea62a241ff3b022\admparse.dll
+ 2008-01-21 02:23 . 2008-01-21 02:23 72704 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18498_none_add8dc690707a459\admparse.dll
+ 2010-08-12 01:05 . 2010-06-29 16:05 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22434_none_043c9ef8b82baeed\WininetPlugin.dll
+ 2010-08-12 01:05 . 2010-06-29 16:00 27648 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22434_none_043c9ef8b82baeed\jsproxy.dll
+ 2009-08-22 16:08 . 2009-04-11 06:28 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18278_none_038bc1bf9f2ae71c\WininetPlugin.dll
+ 2009-08-22 16:08 . 2009-04-11 06:28 27648 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18278_none_038bc1bf9f2ae71c\jsproxy.dll
+ 2010-08-12 01:05 . 2010-06-28 16:30 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22720_none_025cfbd4bb00d87c\WininetPlugin.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 28160 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22720_none_025cfbd4bb00d87c\jsproxy.dll
+ 2008-08-11 11:02 . 2008-08-11 11:02 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18498_none_018fae19a214ccb3\WininetPlugin.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 28160 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18498_none_018fae19a214ccb3\jsproxy.dll
+ 2008-01-21 01:58 . 2010-08-14 16:56 74548 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-08-21 22:24 . 2010-08-14 16:57 18080 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1042238982-2704989617-889929576-1000_UserData.bin
+ 2010-03-26 01:30 . 2010-03-26 01:30 42368 c:\windows\System32\drivers\MpNWMon.sys
+ 2007-09-02 11:55 . 2010-08-14 16:53 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-08-09 17:58 . 2010-08-14 16:53 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-07-12 02:45 . 2010-07-18 00:25 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-09-02 11:55 . 2010-07-18 00:25 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-09-02 11:55 . 2010-08-14 16:53 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-07-07 00:05 . 2010-08-13 17:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-07-07 00:05 . 2010-07-14 21:17 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-07-07 00:05 . 2010-08-13 17:38 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-07-07 00:05 . 2010-07-14 21:17 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-07-07 00:05 . 2010-08-13 17:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-07-07 00:05 . 2010-07-14 21:17 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-08-21 22:31 . 2010-08-13 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-08-21 22:31 . 2010-07-17 14:47 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-08-21 22:31 . 2010-07-17 14:47 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-08-21 22:31 . 2010-08-13 14:14 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-08-21 22:31 . 2010-08-13 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-08-21 22:31 . 2010-07-17 14:47 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-08-24 21:11 . 2010-06-11 17:22 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-06-11 17:21 . 2010-06-11 17:21 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2010-08-12 13:44 . 2010-08-12 13:44 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 25214 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\MSWorks.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 25214 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\MSWorks.exe
+ 2006-10-27 19:11 . 2006-10-27 19:11 21264 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\WRD12EXE.EXE
+ 2010-08-13 14:54 . 2010-08-13 14:54 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\cf552934b75cb6b61f08e3354af8ab38\UIAutomationProvider.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f393e672479ce6ba2f7dfb5e4f3116b7\System.Windows.Presentation.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\c5cd985c876a7bffc61898614694059c\System.Web.DynamicData.Design.ni.dll
+ 2010-08-13 14:55 . 2010-08-13 14:55 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\04bea9cca189a163d0c16e891ad2fdc8\System.ComponentModel.DataAnnotations.ni.dll
+ 2010-08-13 14:55 . 2010-08-13 14:55 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\a899daa177f7bf5c6958dc5969e3a3de\System.AddIn.Contract.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\e6acb23a203e892f501d0924fcc12f2c\stdole.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\156b0418acf284f30f7602a8378b52fd\PresentationFontCache.ni.exe
+ 2010-08-13 14:54 . 2010-08-13 14:54 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5d23c64bac1fd4b0b2bcb1b9d83e6cf6\PresentationCFFRasterizer.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:54 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\b8c20b6ea36a8097e743cd22a16de151\napcrypt.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\c648ec7ca268d909186339d7002c0810\Microsoft.Vsa.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\8133699911f51e80280dfeab3e5d7ab4\Microsoft.VisualC.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\a356e8fb2f59ff46079840306184cbcb\Microsoft.Build.Framework.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\3c2132d7b78b099112e669342aff5524\Microsoft.Build.Framework.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 68608 c:\windows\assembly\NativeImages_v2.0.50727_32\loadmxf\406368ba3f73633200eea9195292a828\loadmxf.ni.exe
+ 2010-08-13 14:52 . 2010-08-13 14:52 57856 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\5602e95333639ce92b0dd1ea5d7fde7a\ehiUserXp.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiReplay\a46cac19a4d8b6b690fdf79b3617f292\ehiReplay.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 23552 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtCOM\4c5668bbcf91950113bf75e5a31a4dc4\ehiExtCOM.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtCOM\a5996401de2fe555bf9f1a3356603c62\ehExtCOM.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\1885a95e9314f393e86670da9930e08f\dfsvc.ni.exe
+ 2010-08-13 14:49 . 2010-08-13 14:49 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2565dad071661e3881888abd594e9e9d\Accessibility.ni.dll
+ 2010-08-12 01:04 . 2010-06-11 16:31 2048 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.22422_none_8acabb6dad2870a4\msxml3r.dll
+ 2006-11-02 08:26 . 2006-11-02 09:41 2048 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.18269_none_8a1cdf129424f4d8\msxml3r.dll
+ 2010-08-12 01:04 . 2010-06-11 15:25 2048 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.22709_none_8900eb63afeb94ff\msxml3r.dll
+ 2006-11-02 08:26 . 2006-11-02 09:41 2048 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18490_none_880cf8e6971f1251\msxml3r.dll
+ 2010-02-15 15:36 . 2010-07-24 14:47 6700 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1042238982-2704989617-889929576-1001_UserData.bin
+ 2010-07-24 23:37 . 2010-07-24 23:37 9560 c:\windows\System32\networklist\icons\{C9BA03F1-AD2D-44A0-8C13-3DEEA1DAADD3}_48.bin
+ 2010-07-24 23:37 . 2010-07-24 23:37 4280 c:\windows\System32\networklist\icons\{C9BA03F1-AD2D-44A0-8C13-3DEEA1DAADD3}_32.bin
+ 2010-07-24 23:37 . 2010-07-24 23:37 2456 c:\windows\System32\networklist\icons\{C9BA03F1-AD2D-44A0-8C13-3DEEA1DAADD3}_24.bin
+ 2010-07-25 04:25 . 2010-07-25 04:25 9560 c:\windows\System32\networklist\icons\{B3E9DFD4-84B2-407F-9965-812B2C5003A0}_48.bin
+ 2010-07-25 04:25 . 2010-07-25 04:25 4280 c:\windows\System32\networklist\icons\{B3E9DFD4-84B2-407F-9965-812B2C5003A0}_32.bin
+ 2010-07-25 04:25 . 2010-07-25 04:25 2456 c:\windows\System32\networklist\icons\{B3E9DFD4-84B2-407F-9965-812B2C5003A0}_24.bin
+ 2010-07-25 00:17 . 2010-07-25 00:17 9560 c:\windows\System32\networklist\icons\{1601C27C-A7FB-4062-9D6C-0B415F13E4A1}_48.bin
+ 2010-07-25 00:17 . 2010-07-25 00:17 4280 c:\windows\System32\networklist\icons\{1601C27C-A7FB-4062-9D6C-0B415F13E4A1}_32.bin
+ 2010-07-25 00:17 . 2010-07-25 00:17 2456 c:\windows\System32\networklist\icons\{1601C27C-A7FB-4062-9D6C-0B415F13E4A1}_24.bin
- 2010-07-18 00:37 . 2010-07-18 00:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-08-14 16:53 . 2010-08-14 16:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-08-14 16:53 . 2010-08-14 16:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-07-18 00:37 . 2010-07-18 00:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-08-12 01:04 . 2010-05-19 11:41 388936 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.22409_none_fcfd41ec14d22069\SOS.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 388936 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.18260_none_13d1b793fb247173\SOS.dll
+ 2010-08-12 01:04 . 2010-05-19 11:39 989016 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.22409_none_142efa2b20dd4454\mscordacwks.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 989016 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.18260_none_2b036fd3072f955e\mscordacwks.dll
+ 2010-08-12 01:05 . 2010-05-28 16:14 197632 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6002.22414_none_6f0c0c64eeb82f1d\ir32_32.dll
+ 2006-11-02 12:34 . 2006-11-02 12:34 197632 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6002.18263_none_6e4b5dcdd5c4048a\ir32_32.dll
+ 2010-08-12 01:05 . 2010-05-27 19:11 197632 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6001.22702_none_6d2e69d4f18b8b5a\ir32_32.dll
+ 2006-11-02 12:34 . 2006-11-02 12:34 197632 c:\windows\winsxs\x86_microsoft-windows-vcm-core-codecs_31bf3856ad364e35_6.0.6001.18483_none_6c4f4a27d8adea21\ir32_32.dll
+ 2010-08-12 01:04 . 2010-06-16 16:39 912776 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22425_none_b57d8e037cb5db63\tcpip.sys
+ 2010-08-12 01:04 . 2010-06-16 16:04 905088 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.18272_none_b4baded863c37e22\tcpip.sys
+ 2010-08-12 01:04 . 2010-06-16 15:55 902032 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys
+ 2010-08-12 01:04 . 2010-06-16 15:59 898952 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18493_none_b2bfcb7c66ac7d10\tcpip.sys
+ 2010-08-12 01:04 . 2010-06-18 15:14 145408 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.22427_none_dc4e15b40cc980e1\srv2.sys
+ 2010-08-12 01:04 . 2010-06-18 15:04 144896 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.18274_none_db8b6688f3d723a0\srv2.sys
+ 2010-08-12 01:04 . 2010-06-18 14:51 145408 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.22715_none_da7073240f9cdd1e\srv2.sys
+ 2010-08-12 01:04 . 2010-06-18 14:43 144896 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.18495_none_d990532cf6c0228e\srv2.sys
+ 2010-08-12 01:04 . 2010-06-18 15:14 303104 c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6002.22427_none_dc58e5a00cc164f0\srv.sys
+ 2010-08-12 01:04 . 2010-06-18 15:04 302080 c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6002.18274_none_db963674f3cf07af\srv.sys
+ 2010-08-12 01:04 . 2010-06-18 14:51 303104 c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.22715_none_da7b43100f94c12d\srv.sys
+ 2010-08-12 01:04 . 2010-06-18 14:43 302080 c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.18495_none_d99b2318f6b8069d\srv.sys
+ 2010-08-12 01:05 . 2010-06-11 16:33 275456 c:\windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6002.22422_none_2472c5e16b952529\schannel.dll
+ 2010-08-12 01:05 . 2010-06-11 16:16 274944 c:\windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6002.18269_none_23c4e9865291a95d\schannel.dll
+ 2010-08-12 01:05 . 2010-06-11 15:26 274944 c:\windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6001.22709_none_22a8f5d76e584984\schannel.dll
+ 2010-08-12 01:05 . 2010-06-11 15:31 274432 c:\windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6001.18490_none_21b5035a558bc6d6\schannel.dll
+ 2010-08-12 01:04 . 2010-06-16 15:11 438272 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22713_none_cda6490a43adceb3\IKEEXT.DLL
+ 2010-08-12 01:04 . 2010-06-16 15:10 595456 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22713_none_cda6490a43adceb3\FWPUCLNT.DLL
+ 2010-08-12 01:04 . 2010-06-16 15:09 328704 c:\windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22713_none_cda6490a43adceb3\BFE.DLL
+ 2010-08-12 01:04 . 2010-06-16 15:55 220040 c:\windows\winsxs\x86_microsoft-windows-netio-infrastructure_31bf3856ad364e35_6.0.6001.22713_none_571d45f6ce707e09\netio.sys
+ 2010-08-12 01:04 . 2010-06-17 18:30 195072 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.22426_none_f4c2683b236c5a9c\WMM2AE.dll
+ 2010-08-12 01:04 . 2010-06-17 16:27 150016 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.22426_none_f4c2683b236c5a9c\MOVIEMK.exe
+ 2009-09-17 20:22 . 2009-04-11 06:28 195072 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.18273_none_f3ffb9100a79fd5b\WMM2AE.dll
+ 2010-08-12 01:04 . 2010-06-17 16:16 150016 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.18273_none_f3ffb9100a79fd5b\MOVIEMK.exe
+ 2010-08-12 01:04 . 2010-06-17 17:24 195072 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.22714_none_f2e4c5ab263fb6d9\WMM2AE.dll
+ 2010-08-12 01:04 . 2010-06-17 16:03 150016 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.22714_none_f2e4c5ab263fb6d9\MOVIEMK.exe
+ 2008-01-21 02:25 . 2008-01-21 02:25 195072 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.18494_none_f204a5b40d62fc49\WMM2AE.dll
+ 2010-08-12 01:04 . 2010-06-17 15:49 150016 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.18494_none_f204a5b40d62fc49\MOVIEMK.exe
+ 2010-08-12 01:05 . 2010-06-29 16:00 180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22434_none_66f6181ac477a650\ieui.dll
+ 2010-06-10 18:58 . 2010-05-04 19:10 180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18278_none_66453ae1ab76de7f\ieui.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22720_none_651674f6c74ccfdf\ieui.dll
+ 2008-01-21 02:24 . 2008-01-21 02:24 180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18498_none_6449273bae60c416\ieui.dll
+ 2010-08-12 01:05 . 2010-06-28 16:30 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22720_none_4817b2b0a5b1f6d9\sqmapi.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 271360 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.22720_none_4817b2b0a5b1f6d9\iertutil.dll
+ 2008-01-21 02:24 . 2008-01-21 02:24 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18498_none_474a64f58cc5eb10\sqmapi.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 270848 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18498_none_474a64f58cc5eb10\iertutil.dll
+ 2010-08-12 01:05 . 2010-06-28 16:29 146432 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.22720_none_379a70832d50dc47\occache.dll
+ 2010-08-12 01:05 . 2010-06-28 16:15 146432 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_6.0.6001.18498_none_36cd22c81464d07e\occache.dll
+ 2010-08-12 01:05 . 2010-06-28 16:33 634656 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_2fd60860332c475f\iexplore.exe
+ 2010-08-12 01:05 . 2010-06-28 16:19 634648 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_2f08baa51a403b96\iexplore.exe
+ 2010-08-12 01:05 . 2010-06-29 16:01 477184 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6002.22434_none_4a7c94e259bd61fb\mshtmled.dll
+ 2010-08-12 01:05 . 2010-06-29 15:44 477184 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6002.18278_none_49cbb7a940bc9a2a\mshtmled.dll
+ 2010-08-12 01:05 . 2010-06-28 16:28 476672 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6001.22720_none_489cf1be5c928b8a\mshtmled.dll
+ 2010-08-12 01:05 . 2010-06-28 16:14 476672 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6001.18498_none_47cfa40343a67fc1\mshtmled.dll
+ 2010-08-12 01:05 . 2010-06-28 16:28 458240 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.22720_none_605a92a353a42b34\msfeeds.dll
+ 2010-08-12 01:05 . 2010-06-28 16:14 458240 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_6.0.6001.18498_none_5f8d44e83ab81f6b\msfeeds.dll
+ 2010-08-12 01:05 . 2010-06-29 16:00 193024 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_6.0.6002.22434_none_3f17302a0866774f\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 193024 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_6.0.6002.18278_none_3e6652f0ef65af7e\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 193024 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_6.0.6001.22720_none_3d378d060b3ba0de\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 193024 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_6.0.6001.18498_none_3c6a3f4af24f9515\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-29 16:00 380928 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.22434_none_fde5c1d282172940\ieapfltr.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 380928 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.18278_none_fd34e4996916616f\ieapfltr.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 380928 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.22720_none_fc061eae84ec52cf\ieapfltr.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 380928 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.18498_none_fb38d0f36c004706\ieapfltr.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 161792 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22720_none_aea62a241ff3b022\ieakui.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 230400 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.22720_none_aea62a241ff3b022\ieaksie.dll
+ 2006-11-02 07:27 . 2006-11-02 09:39 161792 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18498_none_add8dc690707a459\ieakui.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 230400 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18498_none_add8dc690707a459\ieaksie.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 389120 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.22720_none_74c474d070aaf943\iedkcs32.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 389120 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_6.0.6001.18498_none_73f7271557beed7a\iedkcs32.dll
+ 2010-08-12 01:05 . 2010-06-29 16:05 834560 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22434_none_043c9ef8b82baeed\wininet.dll
+ 2010-08-12 01:05 . 2010-06-29 15:47 834048 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18278_none_038bc1bf9f2ae71c\wininet.dll
+ 2010-08-12 01:05 . 2010-06-28 16:30 834048 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22720_none_025cfbd4bb00d87c\wininet.dll
+ 2010-08-12 01:05 . 2010-06-28 16:17 833024 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18498_none_018fae19a214ccb3\wininet.dll
+ 2010-08-12 01:05 . 2010-06-28 16:28 671232 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22720_none_e139aefb95a07158\mstime.dll
+ 2010-08-12 01:05 . 2010-06-28 16:14 671232 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18498_none_e06c61407cb4658f\mstime.dll
+ 2009-09-17 20:22 . 2009-03-30 04:42 311296 c:\windows\winsxs\msil_mscorlib.resources_b77a5c561934e089_6.0.6002.22409_fr-fr_a8afccd9f1058ad5\mscorlib.Resources.dll
+ 2009-09-17 20:22 . 2009-03-30 04:42 311296 c:\windows\winsxs\msil_mscorlib.resources_b77a5c561934e089_6.0.6002.18260_fr-fr_bf844281d757dbdf\mscorlib.Resources.dll
+ 2009-08-22 23:27 . 2010-08-06 02:04 180088 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2009-08-22 00:25 . 2010-08-13 17:37 321868 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 13:05 . 2010-08-14 16:57 100812 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 10:33 . 2010-08-13 17:40 742954 c:\windows\System32\perfc009.dat
+ 2010-08-12 01:05 . 2010-06-29 15:44 477184 c:\windows\System32\mshtmled.dll
- 2010-06-10 18:58 . 2010-05-04 19:12 477184 c:\windows\System32\mshtmled.dll
+ 2010-08-01 03:04 . 2010-08-01 03:04 231888 c:\windows\System32\Macromed\Flash\FlashUtil10h_ActiveX.exe
+ 2010-08-01 03:04 . 2010-08-01 03:04 311760 c:\windows\System32\Macromed\Flash\FlashUtil10h_ActiveX.dll
- 2010-06-10 18:58 . 2010-05-04 19:10 193024 c:\windows\System32\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 193024 c:\windows\System32\iepeers.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 380928 c:\windows\System32\ieapfltr.dll
- 2010-06-10 18:58 . 2010-05-04 19:10 380928 c:\windows\System32\ieapfltr.dll
+ 2006-11-02 12:47 . 2010-08-12 17:15 311040 c:\windows\System32\FNTCACHE.DAT
- 2006-11-02 12:47 . 2010-07-11 23:19 311040 c:\windows\System32\FNTCACHE.DAT
+ 2010-03-26 01:30 . 2010-03-26 01:30 151216 c:\windows\System32\drivers\MpFilter.sys
+ 2010-08-06 17:21 . 2010-08-06 17:31 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2010-04-29 23:00 . 2009-09-04 06:59 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2010-08-03 15:54 . 2010-08-03 15:54 272384 c:\windows\Installer\24d074.msi
+ 2010-08-03 15:53 . 2010-08-03 15:53 254976 c:\windows\Installer\24d06e.msi
+ 2010-08-01 03:03 . 2010-08-01 03:03 424960 c:\windows\Installer\1a18a2d.msi
 
Here is the second half of the log.

c:\windows\Installer\{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}\iTunesIco.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-08-24 21:11 . 2010-08-14 17:01 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 693600 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksWP.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 693600 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksWP.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 947552 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksss.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 947552 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksss.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 709984 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksCal.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 709984 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksCal.exe
+ 2007-06-21 05:04 . 2007-06-21 05:04 173408 c:\windows\Installer\$PatchCache$\Managed\0DC8CB51B56A0D742ADD098A4295F08A\9.7.621\F378_WkProof.dll
+ 2007-06-22 05:48 . 2007-06-22 05:48 972128 c:\windows\Installer\$PatchCache$\Managed\0DC8CB51B56A0D742ADD098A4295F08A\9.7.621\F20987_wkwpqd.dll
+ 2007-06-21 05:04 . 2007-06-21 05:04 161120 c:\windows\Installer\$PatchCache$\Managed\0DC8CB51B56A0D742ADD098A4295F08A\9.7.621\F20985_wkwpqrtf.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\96e88a5f9dbbcfdb736568e69d43cff9\WsatConfig.ni.exe
+ 2010-08-13 14:59 . 2010-08-13 14:59 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\60ecc5c53d5ba77c9c40d01e5af58246\WindowsFormsIntegration.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\9df5076cb69aeb3101fd624ad4f499b0\UIAutomationTypes.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\a45d53185f7690a65a8c1bb758f14d40\UIAutomationClient.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 235520 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\282b33969e987f3c2dafaa2e5c5f728b\TaskScheduler.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\5fc514748fdde7be8871044e0102f208\System.Xml.Linq.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\07efa566dfb7e3367085d310e55f677f\System.Web.Routing.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\7735dbcd7f5280a01ec1e9ebfbfd9564\System.Web.RegularExpressions.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\cb9bb30db142c3f856202fae6efd755d\System.Web.Extensions.Design.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\309dc95f10521331d7813e54946d164d\System.Web.Entity.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\3bbf6be655c227fed53b4d7c1758b741\System.Web.Entity.Design.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\2598e27d1f0d6cf86b1f2ea605379b49\System.Web.DynamicData.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\371304d76734059d69e93c7c7c5f3f87\System.Web.Abstractions.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9f38a2b0adadce82d09209811af4043e\System.Transactions.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\33891c1f2a8120a3b7bb463cc6f97438\System.ServiceProcess.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\b5d2d15c9453a01b8761bf19afd1ccb6\System.Security.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e6beeb0283ef0a1e2c1b65fa05bf2876\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6c2e750e360af7a54a6713cf66920869\System.Runtime.Remoting.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\a151e0db5d00543aecc4eaae05d8c7b1\System.Net.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\dab204b4ba2212740f4c0f1563f37696\System.Messaging.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\7187abb11454f0dece04ed04dea43929\System.Management.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\4aead7d6a1a6ab1c9e73c6c5f0dc8c1b\System.Management.Instrumentation.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\937481e0aef42993453207c3a0f8bc55\System.IO.Log.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\96102bf56b1e4d8924eac8818ea68820\System.IdentityModel.Selectors.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\32e6bf88bb0dcdad040abc8ad97cab83\System.EnterpriseServices.Wrapper.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\32e6bf88bb0dcdad040abc8ad97cab83\System.EnterpriseServices.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\373c6551ad640a1de178a5f7becd41fd\System.Drawing.Design.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\a96524c7c097d56fcc70dd505debcc1d\System.DirectoryServices.Protocols.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\51747c9fabada4a2f0c4def76613c6cd\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\eed47170f4b867402cbb44915f45f298\System.Data.Services.Design.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3097f90ab5e29e5eb0d8c433000acf16\System.Data.Services.Client.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\6c294d7fba114025a3f4f330cf541c7e\System.Data.Entity.Design.ni.dll
+ 2010-08-13 14:55 . 2010-08-13 14:55 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\e404c37e48fe5eafa395333520045a24\System.Data.DataSetExtensions.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\ca467e23bbfcffac8809b9e21dcbd9a6\System.Configuration.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\5904e3d51b6d7628ed01c0f5345e5ff6\System.Configuration.Install.ni.dll
+ 2010-08-13 14:55 . 2010-08-13 14:55 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\b56f5ff3e814e0a4e83231153cde0d0e\System.AddIn.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\aa85f92b421a8ca0af79b376f37e51fb\sysglobl.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\3229c727887ebc9f4065e0cd12d05e2d\SMSvcHost.ni.exe
+ 2010-08-13 14:51 . 2010-08-13 14:51 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\93c834845cbbddae777d614b2d0f8f95\SMDiagnostics.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\70e0d7f2c857c3566aa82053c199e696\ServiceModelReg.ni.exe
+ 2010-08-12 17:20 . 2010-08-12 17:20 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bc66d228134a22312c0e1b66dedb6355\PresentationFramework.Royale.ni.dll
+ 2010-08-12 17:20 . 2010-08-12 17:20 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6d23ebf0175664d7a8579e2762cae3d0\PresentationFramework.Luna.ni.dll
+ 2010-08-12 17:19 . 2010-08-12 17:19 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\60e971a87bbff522188ae9c6985f40b9\PresentationFramework.Aero.ni.dll
+ 2010-08-12 17:19 . 2010-08-12 17:19 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2748627bab39e441420b5cdf329c6be1\PresentationFramework.Classic.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 724992 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\2f105c5bb0901401129bf03e8e71cc94\napsnap.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 110080 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\974e310546d192d00c5fd8b1f9650e79\napinit.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 115712 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\61baa41cfd0504ef33ec7e13df3c170d\naphlpr.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\2a571636031f617332a0abbaf5c3f084\MSBuild.ni.exe
+ 2010-08-13 14:52 . 2010-08-13 14:52 285184 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\d986a5602301ae525f12aab511e93c4e\MMCFxCommon.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\28d7f58060857b4cf2c63be26048cb65\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 227840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\9c02ac74b4f52ae5cf0f2660be7810be\Microsoft.MediaCenter.Shell.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 659968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\5a227376c67a644a05e9154d3d850b2d\Microsoft.MediaCenter.Sports.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\15ee9ad3f763e25098d89605ba99702c\Microsoft.MediaCenter.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 558592 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\6f1906228f69deb64dd61d0e5131e503\Microsoft.ManagementConsole.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\6c824af5aeae3dd7beb68403481e4067\Microsoft.Build.Utilities.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\287c1915da744bdf10ec4feb443d17cb\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\b6fc09b42edaabcc0f8f6ed5cd825736\Microsoft.Build.Engine.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\9684b6d4d7467b94b04faf8e477bab0f\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 238592 c:\windows\assembly\NativeImages_v2.0.50727_32\Mcx2Dvcs\c3c8102a4cbdea2ab1aa4d89bf86ed92\Mcx2Dvcs.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 254976 c:\windows\assembly\NativeImages_v2.0.50727_32\mcupdate\f07dac825e440c785869077bb7dcefed\mcupdate.ni.exe
+ 2010-08-13 14:52 . 2010-08-13 14:52 225280 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\45534af3333fa890ea204a596ae1e5e6\mcstoredb.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 642560 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\591041993cfe14fe8dcbea7d2081908f\mcstore.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 543744 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\dbb5ef49b7916ce0a2cf60ff3afb5e70\EventViewer.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 103936 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiWUapi\132b716b550c2dc96f34cdf14ed8317a\ehiWUapi.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 338432 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiwmp\b5f6733da0da72ead97a0f58e1b40df1\ehiwmp.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 797696 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\0804b988efb74339c7d05caec7d6a174\ehiVidCtl.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 965632 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\d51895c8f10f165aa7d9d2cdb7dc0083\ehiProxy.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 565760 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiPlay\da82144c320425d06fa6ea20372cf368\ehiPlay.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\42a72017d8679378086420169f6ab2d6\ehiExtens.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 243200 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost\f1081a83479e0a0abedc41b910a01138\ehExtHost.ni.exe
+ 2010-08-13 14:52 . 2010-08-13 14:52 305152 c:\windows\assembly\NativeImages_v2.0.50727_32\ehepgdat\a2fc62ad63f3c13b83b6006db80641bd\ehepgdat.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 220160 c:\windows\assembly\NativeImages_v2.0.50727_32\ehCIR\9fc65e7d119c6abccc56530451a61e5c\ehCIR.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\df51961ed496f46601dd0bb255a31161\CustomMarshalers.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\7212937280ee06b0ef45b41651516be8\ComSvcConfig.ni.exe
+ 2010-08-13 14:49 . 2010-08-13 14:49 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\ba32856173defc992995032a2c8fe78b\BDATunePIA.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\c36ac9c6cd9b8d58c34fa0c965770c18\AspNetMMCExt.ni.dll
+ 2010-08-12 01:04 . 2010-05-19 11:41 5819728 c:\windows\winsxs\x86_netfx-mscorwks_dll_b03f5f7f11d50a3a_6.0.6002.22409_none_1b6ad74448dc3881\mscorwks.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 5813072 c:\windows\winsxs\x86_netfx-mscorwks_dll_b03f5f7f11d50a3a_6.0.6002.18260_none_323f4cec2f2e898b\mscorwks.dll
+ 2010-08-12 01:04 . 2010-05-19 11:39 4550656 c:\windows\winsxs\x86_mscorlib_b77a5c561934e089_6.0.6002.22409_none_b0c40856db54d3fc\mscorlib.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 4550656 c:\windows\winsxs\x86_mscorlib_b77a5c561934e089_6.0.6002.18260_none_c7987dfec1a72506\mscorlib.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 1093120 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80u.dll
+ 2010-08-01 03:03 . 2010-08-01 03:03 1105920 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80.dll
+ 2010-08-12 01:04 . 2010-06-21 13:47 2045952 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6002.22428_none_bb55f649b0d3b032\win32k.sys
+ 2010-08-12 01:04 . 2010-06-21 13:37 2037760 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6002.18275_none_ba93471e97e152f1\win32k.sys
+ 2010-08-12 01:04 . 2010-06-21 13:25 2036736 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.22716_none_b97853b9b3a70c6f\win32k.sys
+ 2010-08-12 01:04 . 2010-06-21 13:18 2036736 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.18496_none_b89833c29aca51df\win32k.sys
+ 2010-08-12 01:04 . 2010-06-08 18:04 3550600 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22420_none_6e8adbdfca772e22\ntoskrnl.exe
+ 2010-08-12 01:04 . 2010-06-08 18:04 3601792 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22420_none_6e8adbdfca772e22\ntkrnlpa.exe
+ 2010-08-12 01:04 . 2010-06-08 17:35 3548040 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18267_none_6ddcff84b173b256\ntoskrnl.exe
+ 2010-08-12 01:04 . 2010-06-08 17:35 3600768 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18267_none_6ddcff84b173b256\ntkrnlpa.exe
+ 2010-08-12 01:04 . 2010-06-08 16:47 3548552 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22707_none_6cc10bd5cd3a527d\ntoskrnl.exe
+ 2010-08-12 01:04 . 2010-06-08 16:47 3600784 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22707_none_6cc10bd5cd3a527d\ntkrnlpa.exe
+ 2010-08-12 01:04 . 2010-06-08 17:00 3545992 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18488_none_6be1ec28b45cb144\ntoskrnl.exe
+ 2010-08-12 01:04 . 2010-06-08 17:00 3598216 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18488_none_6be1ec28b45cb144\ntkrnlpa.exe
+ 2010-08-12 01:04 . 2010-07-13 10:54 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22447_none_f4d3f69181d85824\OESpamFilter.dat
+ 2010-08-12 01:04 . 2010-07-13 10:53 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18281_none_f419167468e092ed\OESpamFilter.dat
+ 2010-08-12 01:04 . 2010-07-13 10:53 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22729_none_f3052515849ffdcc\OESpamFilter.dat
+ 2010-08-12 01:04 . 2010-07-13 10:52 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18500_none_f28823a26b7a44ea\OESpamFilter.dat
+ 2010-08-12 01:04 . 2010-06-11 16:31 1248768 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.22422_none_8acabb6dad2870a4\msxml3.dll
+ 2010-08-12 01:04 . 2010-06-11 16:15 1248768 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.18269_none_8a1cdf129424f4d8\msxml3.dll
+ 2010-08-12 01:04 . 2010-06-11 15:25 1257472 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.22709_none_8900eb63afeb94ff\msxml3.dll
+ 2010-08-12 01:04 . 2010-06-11 15:30 1257472 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18490_none_880cf8e6971f1251\msxml3.dll
+ 2010-08-12 01:05 . 2010-06-29 16:00 6081536 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22434_none_66f6181ac477a650\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 6080000 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18278_none_66453ae1ab76de7f\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-28 16:27 6072832 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22720_none_651674f6c74ccfdf\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-28 16:13 6069248 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18498_none_6449273bae60c416\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-29 16:01 3604480 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22434_none_1596be1738821823\mshtml.dll
+ 2010-08-12 01:05 . 2010-06-29 15:44 3603456 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18278_none_14e5e0de1f815052\mshtml.dll
+ 2010-08-12 01:05 . 2010-06-28 16:28 3588608 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22720_none_13b71af33b5741b2\mshtml.dll
+ 2010-08-12 01:05 . 2010-06-28 16:14 3586560 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18498_none_12e9cd38226b35e9\mshtml.dll
+ 2009-08-22 16:08 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.22434_none_fde5c1d282172940\ieapfltr.dat
+ 2009-08-22 16:08 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6002.18278_none_fd34e4996916616f\ieapfltr.dat
+ 2009-08-22 16:08 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.22720_none_fc061eae84ec52cf\ieapfltr.dat
+ 2009-08-22 16:08 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6001.18498_none_fb38d0f36c004706\ieapfltr.dat
+ 2010-08-12 01:05 . 2010-06-29 16:05 1176576 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.22434_none_b736c356ed22885a\urlmon.dll
+ 2010-08-12 01:05 . 2010-06-29 15:46 1176064 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.18278_none_b685e61dd421c089\urlmon.dll
+ 2010-08-12 01:05 . 2010-06-28 16:30 1175552 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22720_none_b5572032eff7b1e9\urlmon.dll
+ 2010-08-12 01:05 . 2010-06-28 16:17 1174528 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18498_none_b489d277d70ba620\urlmon.dll
+ 2010-08-12 01:05 . 2010-06-29 15:46 1176064 c:\windows\System32\urlmon.dll
- 2010-06-10 18:58 . 2010-05-04 19:15 1176064 c:\windows\System32\urlmon.dll
+ 2006-11-02 10:22 . 2010-08-13 02:57 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2010-07-16 03:36 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:33 . 2010-08-13 17:40 2435422 c:\windows\System32\perfh009.dat
+ 2010-08-12 01:05 . 2010-06-29 15:44 3603456 c:\windows\System32\mshtml.dll
- 2010-06-10 18:58 . 2010-05-04 19:10 6080000 c:\windows\System32\ieframe.dll
+ 2010-08-12 01:05 . 2010-06-29 15:43 6080000 c:\windows\System32\ieframe.dll
+ 2006-11-02 12:47 . 2010-08-12 17:17 4296641 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
- 2006-11-02 12:47 . 2010-04-27 22:04 4296641 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2010-08-12 01:04 . 2010-05-21 10:56 5813072 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2010-04-29 23:00 . 2009-09-04 06:58 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2010-07-09 21:28 . 2010-07-09 21:28 2151424 c:\windows\Installer\5ada1.msp
+ 2010-07-11 00:14 . 2010-07-11 00:14 2850816 c:\windows\Installer\5a57d.msp
+ 2010-08-01 20:16 . 2010-08-01 20:16 5731328 c:\windows\Installer\14f1dbb.msi
+ 2009-08-24 21:11 . 2010-08-14 17:01 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-08-24 21:11 . 2010-06-11 17:22 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 1099104 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksSb.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 1099104 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksSb.exe
- 2009-08-14 18:58 . 2009-08-22 17:31 1242464 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksdb.exe
+ 2009-08-14 18:58 . 2010-08-14 17:05 1242464 c:\windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksdb.exe
+ 2007-06-22 05:44 . 2007-06-22 05:44 2901344 c:\windows\Installer\$PatchCache$\Managed\0DC8CB51B56A0D742ADD098A4295F08A\9.7.621\F22194_wksssdb.dll
+ 2006-10-27 19:11 . 2006-10-27 19:11 4235560 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\WRD12CNV.DLL
+ 2010-08-12 17:18 . 2010-08-12 17:18 3325952 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c7397dc3e95ddda32dd9ad6c3ce38019\WindowsBase.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\0f599411410c58b574703eb522bc318e\UIAutomationClientsideProviders.ni.dll
+ 2010-08-12 17:18 . 2010-08-12 17:18 7949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\ed6ae2749d12c4729ee43ff339de4bb8\System.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\88593f5f0fc6de5d5f4a85aa2b1466f3\System.Xml.ni.dll
+ 2010-08-13 14:59 . 2010-08-13 14:59 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\c2f18081b5d836e6231fd79b684a6f86\System.WorkflowServices.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 1911296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\dd88f37f1c35c4c449dbbdacb8c5dccc\System.Workflow.Runtime.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\04a684bdfb5938f0052650cb253983bf\System.Workflow.ComponentModel.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\77e3806584727e882dd8f0d04beb2abe\System.Workflow.Activities.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\2479988f1fa243fe4b9c8b261620191d\System.Web.Services.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\7f1540fb7e3f32852e885e54e032d3cb\System.Web.Mobile.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\1092e6f0382fd93a027cd450466971b1\System.Web.Extensions.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\f030a2f4334cf1d2cd15f6f0c79985ae\System.Speech.ni.dll
+ 2010-08-13 14:58 . 2010-08-13 14:58 1705984 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\cf2b1dc50e5b12378dcc342ecb1f4624\System.ServiceModel.Web.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 2346496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\ea3e8cee7c10a120515149a633a7a2de\System.Runtime.Serialization.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\8a321bc80e196ea1a25ecc4c0ce12568\System.Printing.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\7000f5568c75ad5357d7d443e265456b\System.IdentityModel.ni.dll
+ 2010-08-12 17:27 . 2010-08-12 17:27 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\887fa2d6b76e7302b0c664effad4f91f\System.Drawing.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\9f571d6b546818ce10a382f55137eaa7\System.DirectoryServices.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\7fe837b36e9ba44dcee7b5465d17282e\System.Deployment.ni.dll
+ 2010-08-12 17:20 . 2010-08-12 17:20 6621696 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\cc009a955f4b35c344c2f9aaf453f329\System.Data.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\7916ad24cf12bd19b73abefe981a0e30\System.Data.SqlXml.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\0c5f04a4016dfaa3ac079f34bfaaf28b\System.Data.Services.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 1119232 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\fb8da45f3873169a502db3cb492b25a0\System.Data.OracleClient.ni.dll
+ 2010-08-12 17:20 . 2010-08-12 17:20 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\94d9826184cb0d2772324c098814d218\System.Data.Linq.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\17e7810a55cc31245af28625d1d8c666\System.Data.Entity.ni.dll
+ 2010-08-12 17:20 . 2010-08-12 17:20 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\f6e32268d4b0127287d722e41bb6b58b\System.Core.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 2146816 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\c56cdd40df48edbfeb58f11f8ef023b9\ReachFramework.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\c0ae6dcf0d17a79db705a0cf01c8d301\PresentationUI.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\85dfa2585edc672cf9d66573de4ca266\PresentationBuildTasks.ni.dll
+ 2010-08-13 14:54 . 2010-08-13 14:54 2538496 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\de94a577713ca374c08d2512d69e1643\Narrator.ni.exe
+ 2010-08-13 14:53 . 2010-08-13 14:53 1536512 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\a301ed86595ddc85b07e4aab9cf4e251\MMCEx.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 6340096 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\3b25fb301c8ebd1da13b7769f6c6678e\MIGUIControls.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 1711616 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\2a92f46eb0e385a2eafd9b92ad0bedf4\Microsoft.VisualBasic.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\20ec66c02bbe2d66bfecb98b95394e02\Microsoft.Transactions.Bridge.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 5486080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\0cf5f49c556724a4506e989775020925\Microsoft.MediaCenter.UI.ni.dll
+ 2010-08-13 14:57 . 2010-08-13 14:57 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\bca1f9fffa3059a8c36db7c1cd78ba8e\Microsoft.JScript.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\e2191bf9847c0a0af1410ff266678957\Microsoft.Ink.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\a6f49ce5533655922d675c3c957106c8\Microsoft.Build.Tasks.ni.dll
+ 2010-08-13 14:53 . 2010-08-13 14:53 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\95d9b86433cabf54e4a7de11daa91030\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-08-13 14:49 . 2010-08-13 14:49 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\00969e3f4559c1a79394b1170e158cbb\Microsoft.Build.Engine.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 1732608 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\34109895a5e9a9d3350e5662f1020279\ehRecObj.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 2130432 c:\windows\assembly\NativeImages_v2.0.50727_32\ehepg\4f4ff2af819d88ddf166a5d98417686e\ehepg.ni.dll
- 2010-04-29 23:00 . 2009-09-04 06:58 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-08-12 01:04 . 2010-05-21 10:56 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-08-03 13:28 . 2010-07-26 18:04 11587072 c:\windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6002.22454_none_6e6736812864c2a8\shell32.dll
+ 2010-08-03 13:28 . 2010-07-26 15:51 11584512 c:\windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6002.18287_none_6dc028ea0f5cc58f\shell32.dll
+ 2010-08-03 13:28 . 2010-07-26 16:56 11586560 c:\windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6001.22735_none_6c9764bb2b2d4ef9\shell32.dll
+ 2010-08-03 13:28 . 2010-07-26 16:55 11581440 c:\windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6001.18505_none_6c2e35ce11f75e35\shell32.dll
+ 2010-08-12 01:05 . 2010-06-17 18:27 10926592 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.22426_none_f4c2683b236c5a9c\MOVIEMK.dll
+ 2010-08-12 01:05 . 2010-06-17 18:08 10926592 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6002.18273_none_f3ffb9100a79fd5b\MOVIEMK.dll
+ 2010-08-12 01:05 . 2010-06-17 17:22 10926592 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.22714_none_f2e4c5ab263fb6d9\MOVIEMK.dll
+ 2010-08-12 01:05 . 2010-06-17 17:15 10926592 c:\windows\winsxs\x86_microsoft-windows-moviemaker_31bf3856ad364e35_6.0.6001.18494_none_f204a5b40d62fc49\MOVIEMK.dll
+ 2010-08-03 13:28 . 2010-07-26 15:51 11584512 c:\windows\System32\shell32.dll
+ 2006-11-02 10:24 . 2010-08-03 18:09 35962312 c:\windows\System32\mrt.exe
+ 2010-07-11 00:06 . 2010-07-11 00:06 10120192 c:\windows\Installer\5ad7e.msp
+ 2010-08-12 17:27 . 2010-08-12 17:27 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d9ab6e29eba6cb0d8459fcbb2c40c1a7\System.Windows.Forms.ni.dll
+ 2010-08-13 14:50 . 2010-08-13 14:50 11801088 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\e1ea6e4d25161658e08fc8d2fa64ec73\System.Web.ni.dll
+ 2010-08-13 14:51 . 2010-08-13 14:51 17404416 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\d1cad83b4223917ed45765ee942dc824\System.ServiceModel.ni.dll
+ 2010-08-12 17:26 . 2010-08-12 17:26 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\7964468060d9f7a9b177eb1c6827936a\System.Design.ni.dll
+ 2010-08-12 17:19 . 2010-08-12 17:19 14328832 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c87cc40b22b2b014f9c0ade54773b6ea\PresentationFramework.ni.dll
+ 2010-08-12 17:19 . 2010-08-12 17:19 12216832 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\e53b9c43b17c02a75f2358a24047dd52\PresentationCore.ni.dll
+ 2010-08-12 17:18 . 2010-08-12 17:18 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\98bbdd8c400493ad228b8283665cc9da\mscorlib.ni.dll
+ 2010-08-13 14:52 . 2010-08-13 14:52 11588096 c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\533e0c125f72bccb38eac041552250bb\ehshell.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
"Google Update"="c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-08-21 133104]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"RogersServicepointAgent.exe"="c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" [2009-02-27 3228912]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-12 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]

c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-7-31 139776]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):2f,48,75,21,55,e6,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1ca2cdcaf95cfe9;Google Update Service (gupdate1ca2cdcaf95cfe9);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 133104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-26 361808]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-26 42368]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-08-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-03 21:21]

2010-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

2010-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-03 21:22]

2010-08-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
- c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]

2010-08-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
- c:\users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-21 23:27]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
IE: {{612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe
FF - ProfilePath - c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\RadioWMPCore.dll
FF - component: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
FF - plugin: c:\users\Darlin\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-14 14:40
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-14 14:44:01
ComboFix-quarantined-files.txt 2010-08-14 18:43
ComboFix2.txt 2010-07-18 01:09

Pre-Run: 138,762,579,968 bytes free
Post-Run: 138,721,267,712 bytes free

- - End Of File - - 6056C2298D7CCC299612718DBAC27536
 
Here is the new HijackThis log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:18:18 PM, on 22/07/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Darlin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [pacqwen] rundll32 "C:\Users\Darlin\AppData\Roaming\nb-NOM.dll",UDPNTWWWQJ
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra 'Tools' menuitem: Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca2cdcaf95cfe9) (gupdate1ca2cdcaf95cfe9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11316 bytes
 
It looks like something we removed earlier is came back. Disable the TeaTimer and leave it disabled, when were done I will link you to another free program to install that will do the same thing but won't get in your face as much

Do this first...Important

Disable the TeaTimer, leave it disabled, do not turn it back on until we're done or it will prevent fixes from taking

  • Run Spybot-S&D in Advanced Mode.
  • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
  • On the left hand side, Click on Tools
  • Then click on the Resident Icon in the List
  • Uncheck "Resident TeaTimer" and OK any prompts.
  • Restart your computer.<--You need to do this for it to take effect
Please do not proceed until the TeaTimer is disabled




Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555

O4 - HKCU\..\Run: [pacqwen] rundll32 "C:\Users\Darlin\AppData\Roaming\nb-NOM.dll",UDPNTWWWQJ



C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Cookies <-- Go into this folder and delete all cookies but not the cookie folder. Before you do make sure you write down user names and passwords for sites you frequent or you wont be able to access them unless you remember the passwords and usernames


Reboot and post a new HJT log please, if your still getting redirected to SearchPro let me know. I will have to have someone else look at this, I see no entries for SearchPro in any of your logs.

You never updated to IE8 ???
 
Last edited:
Hi. I have a problem. I disabled TeaTimer and restarted the computer as instructed. But when I did a system scan only and looked for the entries you asked me to delete, they weren't there. I kept doing system scans and looked at every single entry, but no luck. I just deleted the cookies and did a new system scan with a log. Here it is. Oh...and when I did updates on my laptop, I thought it updated IE to IE8. I'll try to update it again.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:20:19 PM, on 15/08/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Darlin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra 'Tools' menuitem: Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca2cdcaf95cfe9) (gupdate1ca2cdcaf95cfe9) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10231 bytes
 
Hi. Here is the new OTL log.


OTL logfile created on: 16/08/2010 9:13:45 AM - Run 6
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Darlin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.54 Gb Total Space | 128.56 Gb Free Space | 57.51% Space Free | Partition Type: NTFS
Drive D: | 9.35 Gb Total Space | 1.70 Gb Free Space | 18.16% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DARLIN-PC
Current User Name: Darlin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Darlin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) -- C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Recovery Service for Windows) -- C:\WINDOWS\SMINST\BLService.exe ()
SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (RPSKT) Security Services Driver (x86) -- C:\Windows\System32\DRIVERS\rp_skt32.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\Users\Darlin\AppData\Local\Temp\catchme.sys File not found
DRV - (MpFilter) -- C:\WINDOWS\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) -- C:\WINDOWS\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (BCM43XX) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (BCM43XV) -- C:\WINDOWS\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTSTOR) -- C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (CnxtHdAudService) -- C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NVHDA) -- C:\WINDOWS\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) -- C:\WINDOWS\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (HSF_DPV) -- C:\WINDOWS\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\WINDOWS\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) -- C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (PID_0928) Labtec WebCam(PID_0928) -- C:\WINDOWS\System32\drivers\LV561AV.SYS (Labtec Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\System32\drivers\LVUSBSta.sys (Labtec Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/09/11 16:51:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/09 19:03:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/09 19:03:01 | 000,000,000 | ---D | M]

[2010/03/17 16:27:38 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions
[2009/08/21 19:44:39 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
[2010/08/11 21:56:53 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/04/27 17:10:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/18 20:51:56 | 000,000,000 | ---D | M] (AniWeather) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/25 20:18:05 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/28 14:09:55 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2010/07/31 23:04:28 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/03/18 21:01:38 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/06/08 11:09:24 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/07/28 12:11:30 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/06/30 22:17:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/18 21:34:21 | 000,000,000 | ---D | M] (Pixlr Grabber) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
[2010/06/02 19:11:22 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/12 10:07:01 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/05/15 21:16:08 | 000,000,000 | ---D | M] (DVDVideoSoft Toolbar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/07/28 12:11:45 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/07/28 12:11:31 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/18 21:39:06 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\googletube@googletube.com
[2010/03/18 20:51:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\illimitux@illimitux.net
[2010/04/12 10:07:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\isreaditlater@ideashower.com
[2010/04/14 10:14:52 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\personas@christopher.beard
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com
[2010/06/29 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\piclens@cooliris.com-trash
[2010/03/18 21:01:33 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\SkipScreen@SkipScreen
[2010/06/16 15:38:34 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\smarterwiki@wikiatic.com
[2010/07/28 12:11:30 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\unplug@compunach
[2010/06/16 15:38:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\videosurf_enhanced@videosurf.com
[2010/04/21 10:16:53 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\15fd17a9.default\extensions\YoutubeDownloader@PeterOlayev.com
[2010/03/05 15:29:29 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (TwitterBar) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2010/03/05 15:04:55 | 000,000,000 | ---D | M] (TV-Fox) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{99210d54-6321-41e8-bd1b-2b4c55874efb}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] (QuickWiki) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{EE223D7A-F30F-11DD-8F0A-D2AD55D89593}
[2010/03/04 17:52:58 | 000,000,000 | ---D | M] (FoxTab) -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2010/03/04 18:20:44 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\en-CA@dictionaries.addons.mozilla.org
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@myfacebook.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\FirefoxAddon@similarWeb.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com
[2010/03/04 18:20:46 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\googletube@googletube.com
[2010/03/04 18:20:43 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\illimitux@illimitux.net
[2010/03/04 17:52:54 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\isreaditlater@ideashower.com
[2010/03/04 17:52:55 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\personas@christopher.beard
[2010/03/04 17:53:00 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\piclens@cooliris.com
[2010/03/04 17:53:01 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\quickdrag@mozilla.ktechcomputing.com
[2010/03/04 18:20:45 | 000,000,000 | ---D | M] -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\extensions\firefox-extension@shareaholic.com\chrome
[2010/03/04 18:32:31 | 000,007,972 | ---- | M] () -- C:\Users\Darlin\AppData\Roaming\Mozilla\Firefox\Profiles\ky0tyjts.default\searchplugins\oneriot-social-web-search.xml
[2010/03/04 17:43:36 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/02/21 06:22:32 | 000,712,704 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll

O1 HOSTS File: ([2010/08/09 13:00:58 | 000,000,698 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\Darlin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra 'Tools' menuitem : Youku Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\Youku Downloader\YoukuDownloader(xmlbar).exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/downl...-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.71.255.198 192.168.1.1
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O24 - Desktop BackupWallPaper: C:\Users\Darlin\Pictures\wild_shutterstock_8532871.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/11 09:46:21 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/08/16 09:12:14 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/08/14 19:29:59 | 000,000,000 | ---D | C] -- C:\My Music
[2010/08/14 19:29:44 | 000,123,392 | ---- | C] (RealNetworks) -- C:\Windows\System32\rmoc3260.dll
[2010/08/14 19:29:40 | 000,024,576 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\prefscpl.cpl
[2010/08/14 19:29:40 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2010/08/14 19:29:40 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2010/08/14 19:29:28 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\System32\pncrt.dll
[2010/08/14 19:29:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Real
[2010/08/14 19:29:14 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2010/08/14 19:28:01 | 000,057,344 | ---- | C] (Micronas Intermetall) -- C:\Windows\System32\mi-sc4.acm
[2010/08/14 19:28:01 | 000,010,135 | ---- | C] (Windows (R) 2000 DDK provider) -- C:\Windows\System32\drivers\SECYPUSB.sys
[2010/08/14 14:44:04 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/08/14 14:43:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/08/14 14:28:00 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/08/14 14:27:25 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/08/11 21:05:18 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2010/08/11 21:05:08 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010/08/11 21:05:08 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2010/08/11 21:05:07 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2010/08/11 21:04:58 | 002,037,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2010/08/11 21:04:55 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2010/08/11 21:04:38 | 003,600,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010/08/11 21:04:37 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2010/08/03 11:53:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/08/01 16:15:08 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/07/31 23:09:04 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Yahoo
[2010/07/31 23:04:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2010/07/31 23:03:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2010/07/31 15:24:56 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/07/22 14:17:32 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/07/22 13:01:49 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/07/19 14:09:04 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/07/18 15:12:02 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple
[2010/07/18 14:54:21 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Adobe
[2010/07/18 13:28:51 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Local\Apple Computer
[2010/07/18 12:48:42 | 000,000,000 | ---D | C] -- C:\Users\Darlin\AppData\Roaming\Malwarebytes
[2010/07/18 12:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/07/18 12:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 20:50:15 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/07/17 20:50:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/07/17 20:50:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/07/17 20:50:08 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/07/17 20:49:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/16 09:13:36 | 008,388,608 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat
[2010/08/16 09:12:17 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Darlin\Desktop\OTL.exe
[2010/08/16 08:56:01 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/16 08:52:59 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/08/16 08:51:56 | 000,002,255 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/16 08:50:23 | 000,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/08/16 08:49:36 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/08/16 08:49:36 | 000,048,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/08/16 08:49:33 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/16 08:49:01 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/16 08:49:00 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/16 08:49:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job
[2010/08/16 08:48:54 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/08/16 08:48:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/08/16 08:48:42 | 2951,110,656 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/15 23:22:44 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/08/15 23:22:41 | 000,524,288 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TMContainer00000000000000000001.regtrans-ms
[2010/08/15 23:22:41 | 000,065,536 | -HS- | M] () -- C:\Users\Darlin\ntuser.dat{222d7bbb-2541-11df-b6a1-001d7263ad85}.TM.blf
[2010/08/15 23:22:36 | 002,675,049 | -H-- | M] () -- C:\Users\Darlin\AppData\Local\IconCache.db
[2010/08/15 19:57:05 | 002,508,566 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/08/15 19:57:05 | 000,780,938 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/08/15 19:57:05 | 000,062,236 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010/08/15 19:57:05 | 000,019,286 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010/08/15 19:57:04 | 000,059,822 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/08/15 17:49:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job
[2010/08/14 19:29:58 | 000,000,871 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer Basic.lnk
[2010/08/14 19:29:44 | 000,123,392 | ---- | M] (RealNetworks) -- C:\Windows\System32\rmoc3260.dll
[2010/08/14 19:29:40 | 000,024,576 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\prefscpl.cpl
[2010/08/14 19:29:40 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2010/08/14 19:29:40 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2010/08/14 19:29:28 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\Windows\System32\pncrt.dll
[2010/08/14 14:40:49 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/08/13 16:37:36 | 273,266,934 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/08/13 13:37:51 | 000,001,356 | ---- | M] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2010/08/12 13:15:33 | 000,311,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/08/11 21:50:25 | 000,002,047 | ---- | M] () -- C:\Users\Darlin\Desktop\Google Chrome.lnk
[2010/08/11 21:50:25 | 000,002,009 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/08/09 13:00:58 | 000,000,698 | ---- | M] () -- C:\Windows\System32\drivers\etc\HOSTS
[2010/08/08 18:06:18 | 000,000,943 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/01 16:16:01 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/07/31 23:03:45 | 000,000,966 | ---- | M] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/29 18:44:36 | 000,013,312 | ---- | M] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/28 18:38:07 | 002,512,767 | ---- | M] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/22 19:06:22 | 000,030,720 | ---- | M] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 19:06:13 | 000,014,769 | ---- | M] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 14:17:32 | 000,001,874 | ---- | M] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/20 22:25:46 | 000,019,373 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:57:21 | 000,023,377 | ---- | M] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | M] () -- C:\Users\Darlin\Documents\Charter.rtf
[4 C:\Users\Darlin\Documents\*.tmp files -> C:\Users\Darlin\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/14 19:29:58 | 000,000,871 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer Basic.lnk
[2010/08/14 19:28:01 | 000,081,408 | ---- | C] () -- C:\Windows\System32\secumax.dll
[2010/08/02 20:08:00 | 000,002,255 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/08/01 16:16:01 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/07/31 23:03:45 | 000,000,966 | ---- | C] () -- C:\Users\Darlin\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/07/27 23:08:14 | 002,512,767 | ---- | C] () -- C:\Users\Darlin\Documents\Canadian Achievements.pptx
[2010/07/22 19:06:13 | 000,014,769 | ---- | C] () -- C:\Users\Darlin\Documents\Final Unit Essay.docx
[2010/07/22 16:16:18 | 000,030,720 | ---- | C] () -- C:\Users\Darlin\Documents\Water Consumption.doc
[2010/07/22 14:17:32 | 000,001,874 | ---- | C] () -- C:\Users\Darlin\Desktop\HijackThis.lnk
[2010/07/21 17:04:41 | 000,020,148 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 6 Activity 3.docx
[2010/07/21 14:45:52 | 2951,110,656 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/20 22:25:44 | 000,019,373 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 5.docx
[2010/07/20 19:56:30 | 000,023,377 | ---- | C] () -- C:\Users\Darlin\Documents\Unit 5 Activity 3.docx
[2010/07/20 14:39:39 | 000,038,252 | ---- | C] () -- C:\Users\Darlin\Documents\Charter.rtf
[2010/07/17 20:50:15 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/07/17 20:50:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/07/17 20:50:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/07/17 20:50:15 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/07/17 20:50:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/07/12 09:25:28 | 000,000,008 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\vdnxlf.dat
[2010/07/11 17:46:31 | 000,000,088 | ---- | C] () -- C:\Windows\wininit.ini
[2010/07/09 23:20:48 | 000,088,576 | RHS- | C] () -- C:\Users\Darlin\AppData\Roaming\nb-NOM.dll
[2010/03/06 21:39:05 | 000,007,916 | -HS- | C] () -- C:\Users\Darlin\AppData\Local\8mtxM1
[2010/03/04 19:20:11 | 000,001,536 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\Sketchpad 5 Preferences.dat
[2010/01/26 18:01:45 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\Scaqutafuzaca.bin
[2010/01/26 18:01:44 | 000,000,120 | ---- | C] () -- C:\Users\Darlin\AppData\Local\Fweyuxuzede.dat
[2009/11/18 16:40:24 | 000,013,312 | ---- | C] () -- C:\Users\Darlin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/02 23:13:27 | 000,005,184 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009/09/17 16:23:53 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/11 19:18:19 | 000,000,248 | ---- | C] () -- C:\Users\Darlin\AppData\Roaming\wklnhst.dat
[2009/09/05 19:41:30 | 000,048,670 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/09/05 19:39:30 | 000,048,670 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/08/24 16:51:58 | 000,001,356 | ---- | C] () -- C:\Users\Darlin\AppData\Local\d3d9caps.dat
[2009/08/21 18:23:44 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\QSwitch.txt
[2009/08/21 18:23:44 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\DSwitch.txt
[2009/08/21 18:23:44 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\AtStart.txt
[2008/08/11 10:06:45 | 000,002,084 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2008/01/20 22:24:38 | 000,033,794 | ---- | C] () -- C:\Windows\System32\unelwin.dll
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 05:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/01/19 09:30:54 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini

========== Files - Unicode (All) ==========
[2009/10/02 23:23:37 | 000,000,036 | ---- | M] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
[2009/10/02 23:23:37 | 000,000,036 | ---- | C] ()(C:\Windows\System32\?????????????????????????????????????????????????) -- C:\Windows\System32\㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩
< End of report >
 
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Code:
    :OTL
    PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    [2010/01/26 18:01:45 | 000,000,000 | ---- | C] () -- C:\Users\Darlin\AppData\Local\Scaqutafuzaca.bin
    [2010/01/26 18:01:44 | 000,000,120 | ---- | C] () -- C:\Users\Darlin\AppData\Local\Fweyuxuzede.dat
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Post the log its created please
 
Hi. I ran the custom fix on OTL. Here is the log.

All processes killed
========== OTL ==========
No active process named Explorer.EXE was found!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
C:\Users\Darlin\AppData\Local\Scaqutafuzaca.bin moved successfully.
C:\Users\Darlin\AppData\Local\Fweyuxuzede.dat moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Bhing or J.A
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Darlin
->Temp folder emptied: 736362 bytes
->Temporary Internet Files folder emptied: 72693135 bytes
->Java cache emptied: 7140 bytes
->FireFox cache emptied: 12953784 bytes
->Google Chrome cache emptied: 26802799 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 75947 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Darlin-PC.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 478433 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 3752596 bytes

Total Files Cleaned = 112.00 mb


OTL by OldTimer - Version 3.2.10.0 log created on 08172010_124355

Files\Folders moved on Reboot...
C:\Users\Darlin\AppData\Local\Temp\ehmsas.txt moved successfully.
C:\Users\Darlin\AppData\Local\Temp\VGX450A.tmp moved successfully.

Registry entries deleted on Reboot...
 
Hi. Here is the the TDSSKiller log.


2010/08/19 12:46:17.0494 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23
2010/08/19 12:46:17.0494 ================================================================================
2010/08/19 12:46:17.0494 SystemInfo:
2010/08/19 12:46:17.0494
2010/08/19 12:46:17.0494 OS Version: 6.0.6002 ServicePack: 2.0
2010/08/19 12:46:17.0494 Product type: Workstation
2010/08/19 12:46:17.0494 ComputerName: DARLIN-PC
2010/08/19 12:46:17.0494 UserName: Darlin
2010/08/19 12:46:17.0494 Windows directory: C:\Windows
2010/08/19 12:46:17.0494 System windows directory: C:\Windows
2010/08/19 12:46:17.0494 Processor architecture: Intel x86
2010/08/19 12:46:17.0494 Number of processors: 2
2010/08/19 12:46:17.0494 Page size: 0x1000
2010/08/19 12:46:17.0494 Boot type: Normal boot
2010/08/19 12:46:17.0494 ================================================================================
2010/08/19 12:46:18.0602 Initialize success
2010/08/19 12:46:30.0161 ================================================================================
2010/08/19 12:46:30.0161 Scan started
2010/08/19 12:46:30.0161 Mode: Manual;
2010/08/19 12:46:30.0161 ================================================================================
2010/08/19 12:46:31.0019 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2010/08/19 12:46:31.0456 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2010/08/19 12:46:31.0768 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2010/08/19 12:46:32.0065 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2010/08/19 12:46:32.0439 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2010/08/19 12:46:32.0845 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2010/08/19 12:46:33.0016 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2010/08/19 12:46:33.0313 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2010/08/19 12:46:33.0671 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2010/08/19 12:46:33.0999 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2010/08/19 12:46:34.0436 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2010/08/19 12:46:34.0919 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2010/08/19 12:46:35.0543 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2010/08/19 12:46:35.0933 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2010/08/19 12:46:36.0620 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2010/08/19 12:46:36.0932 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/08/19 12:46:37.0462 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2010/08/19 12:46:37.0915 BCM43XV (a176653093b28e4deb9f3d81cb4056ec) C:\Windows\system32\DRIVERS\bcmwl6.sys
2010/08/19 12:46:38.0149 BCM43XX (a176653093b28e4deb9f3d81cb4056ec) C:\Windows\system32\DRIVERS\bcmwl6.sys
2010/08/19 12:46:38.0461 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2010/08/19 12:46:38.0991 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2010/08/19 12:46:39.0568 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2010/08/19 12:46:39.0896 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2010/08/19 12:46:40.0317 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2010/08/19 12:46:40.0520 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2010/08/19 12:46:40.0754 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2010/08/19 12:46:41.0097 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2010/08/19 12:46:41.0596 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2010/08/19 12:46:41.0861 BthEnum (cce53afc28347cc18ea139972e5b5e5a) C:\Windows\system32\DRIVERS\BthEnum.sys
2010/08/19 12:46:42.0127 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2010/08/19 12:46:42.0407 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
2010/08/19 12:46:42.0735 BTHPORT (ac8a1689d5efc4d214201155a78d8f4b) C:\Windows\system32\Drivers\BTHport.sys
2010/08/19 12:46:42.0969 BTHUSB (288c1f74e3e2eed6c7b54eb3aac70856) C:\Windows\system32\Drivers\BTHUSB.sys
2010/08/19 12:46:43.0375 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2010/08/19 12:46:43.0811 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2010/08/19 12:46:44.0201 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2010/08/19 12:46:44.0498 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2010/08/19 12:46:45.0137 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/08/19 12:46:45.0980 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2010/08/19 12:46:46.0261 CnxtHdAudService (1adf6f4852e7d7e2e8ac481bdb970586) C:\Windows\system32\drivers\CHDRT32.sys
2010/08/19 12:46:46.0775 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2010/08/19 12:46:47.0041 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2010/08/19 12:46:47.0368 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2010/08/19 12:46:48.0148 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2010/08/19 12:46:48.0788 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2010/08/19 12:46:49.0162 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
2010/08/19 12:46:49.0521 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2010/08/19 12:46:50.0020 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
2010/08/19 12:46:50.0535 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2010/08/19 12:46:51.0097 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys
2010/08/19 12:46:51.0845 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2010/08/19 12:46:52.0407 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2010/08/19 12:46:52.0953 eeCtrl (96bcd90ed9235a21629effde5e941fb1) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2010/08/19 12:46:53.0499 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2010/08/19 12:46:54.0029 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2010/08/19 12:46:54.0341 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2010/08/19 12:46:54.0809 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2010/08/19 12:46:55.0277 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2010/08/19 12:46:56.0011 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2010/08/19 12:46:56.0229 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2010/08/19 12:46:56.0276 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/08/19 12:46:56.0432 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2010/08/19 12:46:56.0775 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2010/08/19 12:46:57.0243 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2010/08/19 12:46:57.0976 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2010/08/19 12:46:58.0288 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2010/08/19 12:46:58.0475 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/08/19 12:46:58.0881 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2010/08/19 12:46:59.0146 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2010/08/19 12:46:59.0318 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2010/08/19 12:46:59.0723 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2010/08/19 12:47:00.0269 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
2010/08/19 12:47:00.0987 HpqRemHid (115c0933b3ed51dfbec4449348c8065b) C:\Windows\system32\DRIVERS\HpqRemHid.sys
2010/08/19 12:47:01.0283 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
2010/08/19 12:47:02.0141 HSF_DPV (cc267848cb3508e72762be65734e764d) C:\Windows\system32\DRIVERS\HSX_DPV.sys
2010/08/19 12:47:02.0531 HSXHWAZL (a2882945cc4b6e3e4e9e825590438888) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
2010/08/19 12:47:03.0015 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2010/08/19 12:47:03.0405 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2010/08/19 12:47:03.0873 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/08/19 12:47:04.0325 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2010/08/19 12:47:04.0731 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2010/08/19 12:47:05.0121 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2010/08/19 12:47:05.0324 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2010/08/19 12:47:05.0371 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/08/19 12:47:05.0839 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2010/08/19 12:47:06.0229 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2010/08/19 12:47:06.0385 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2010/08/19 12:47:07.0227 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2010/08/19 12:47:07.0414 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/08/19 12:47:07.0508 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2010/08/19 12:47:07.0633 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2010/08/19 12:47:07.0679 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/08/19 12:47:07.0851 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/08/19 12:47:08.0007 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2010/08/19 12:47:08.0225 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/08/19 12:47:08.0335 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2010/08/19 12:47:08.0366 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2010/08/19 12:47:08.0537 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2010/08/19 12:47:08.0600 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2010/08/19 12:47:08.0662 LVUSBSta (c7fcb579956b7fde002e6e9de36728d3) C:\Windows\system32\drivers\lvusbsta.sys
2010/08/19 12:47:08.0865 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2010/08/19 12:47:09.0005 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2010/08/19 12:47:09.0083 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2010/08/19 12:47:09.0146 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2010/08/19 12:47:09.0239 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2010/08/19 12:47:09.0286 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2010/08/19 12:47:09.0317 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2010/08/19 12:47:09.0427 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2010/08/19 12:47:09.0536 MpFilter (c98301ad8173a2235a9ab828955c32bb) C:\Windows\system32\DRIVERS\MpFilter.sys
2010/08/19 12:47:09.0645 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2010/08/19 12:47:09.0739 MpNWMon (aeb186afff5d9cfed823c15d846aac3b) C:\Windows\system32\DRIVERS\MpNWMon.sys
2010/08/19 12:47:09.0848 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2010/08/19 12:47:09.0910 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2010/08/19 12:47:09.0988 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2010/08/19 12:47:10.0113 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/08/19 12:47:10.0175 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/08/19 12:47:10.0207 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/08/19 12:47:10.0253 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2010/08/19 12:47:10.0363 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2010/08/19 12:47:10.0472 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2010/08/19 12:47:10.0597 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2010/08/19 12:47:10.0659 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2010/08/19 12:47:10.0815 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/08/19 12:47:10.0862 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2010/08/19 12:47:10.0971 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2010/08/19 12:47:11.0065 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/08/19 12:47:11.0158 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2010/08/19 12:47:11.0283 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2010/08/19 12:47:11.0408 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2010/08/19 12:47:11.0564 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2010/08/19 12:47:11.0673 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/08/19 12:47:11.0751 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/08/19 12:47:11.0907 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/08/19 12:47:12.0001 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2010/08/19 12:47:12.0110 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2010/08/19 12:47:12.0547 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2010/08/19 12:47:13.0217 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2010/08/19 12:47:13.0576 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2010/08/19 12:47:14.0278 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2010/08/19 12:47:15.0152 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2010/08/19 12:47:15.0682 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2010/08/19 12:47:16.0181 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2010/08/19 12:47:16.0556 NVENETFD (ae78a7285df03a277415fc62f8ce8f24) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2010/08/19 12:47:16.0993 NVHDA (b0dd52428bf564f5fc5ee331060be2a6) C:\Windows\system32\drivers\nvhda32v.sys
2010/08/19 12:47:18.0709 nvlddmkm (9dac05d828e56801fd6ce5fdfced64af) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/08/19 12:47:19.0535 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2010/08/19 12:47:20.0269 nvsmu (0fb6bf3ab170fc5bd403d25e134eafde) C:\Windows\system32\DRIVERS\nvsmu.sys
2010/08/19 12:47:20.0705 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2010/08/19 12:47:21.0220 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2010/08/19 12:47:22.0624 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2010/08/19 12:47:23.0373 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2010/08/19 12:47:23.0638 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2010/08/19 12:47:24.0122 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2010/08/19 12:47:24.0668 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2010/08/19 12:47:25.0495 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
2010/08/19 12:47:25.0682 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2010/08/19 12:47:25.0807 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2010/08/19 12:47:26.0259 PID_0928 (03e86718bb5aa2716c7349a854ff6203) C:\Windows\system32\DRIVERS\LV561AV.SYS
2010/08/19 12:47:26.0696 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2010/08/19 12:47:27.0117 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys
2010/08/19 12:47:27.0679 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2010/08/19 12:47:28.0661 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2010/08/19 12:47:29.0473 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2010/08/19 12:47:29.0878 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2010/08/19 12:47:30.0393 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2010/08/19 12:47:30.0814 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/08/19 12:47:31.0438 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/08/19 12:47:31.0828 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2010/08/19 12:47:32.0780 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2010/08/19 12:47:33.0544 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/08/19 12:47:33.0809 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2010/08/19 12:47:34.0277 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2010/08/19 12:47:34.0792 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2010/08/19 12:47:35.0525 RFCOMM (23f486726da7a9b2f3ec7326421a9c36) C:\Windows\system32\DRIVERS\rfcomm.sys
2010/08/19 12:47:36.0181 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2010/08/19 12:47:36.0383 RTSTOR (b0538dea03e088b80482ca939f4e8740) C:\Windows\system32\drivers\RTSTOR.SYS
2010/08/19 12:47:36.0820 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2010/08/19 12:47:37.0366 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/08/19 12:47:37.0663 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2010/08/19 12:47:37.0865 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2010/08/19 12:47:38.0271 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2010/08/19 12:47:38.0723 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2010/08/19 12:47:38.0848 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2010/08/19 12:47:38.0973 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2010/08/19 12:47:39.0160 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2010/08/19 12:47:39.0441 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2010/08/19 12:47:39.0691 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2010/08/19 12:47:39.0987 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2010/08/19 12:47:40.0611 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2010/08/19 12:47:40.0985 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2010/08/19 12:47:41.0516 srv (96a5e2c642af8f591a7366429809506b) C:\Windows\system32\DRIVERS\srv.sys
2010/08/19 12:47:41.0906 srv2 (71da2d64880c97e5ffc3c81761632751) C:\Windows\system32\DRIVERS\srv2.sys
2010/08/19 12:47:42.0608 srvnet (0c5ab1892ae0fa504218db094bf6d041) C:\Windows\system32\DRIVERS\srvnet.sys
2010/08/19 12:47:43.0060 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2010/08/19 12:47:43.0622 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2010/08/19 12:47:43.0918 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2010/08/19 12:47:44.0495 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2010/08/19 12:47:44.0823 SynTP (00b19f27858f56181edb58b71a7c67a0) C:\Windows\system32\DRIVERS\SynTP.sys
2010/08/19 12:47:45.0322 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2010/08/19 12:47:45.0899 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2010/08/19 12:47:46.0414 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2010/08/19 12:47:46.0929 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2010/08/19 12:47:47.0366 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2010/08/19 12:47:47.0959 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2010/08/19 12:47:48.0598 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2010/08/19 12:47:49.0129 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/08/19 12:47:49.0394 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2010/08/19 12:47:49.0628 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2010/08/19 12:47:49.0862 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2010/08/19 12:47:50.0065 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2010/08/19 12:47:50.0361 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2010/08/19 12:47:50.0595 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2010/08/19 12:47:50.0907 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2010/08/19 12:47:51.0094 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2010/08/19 12:47:51.0344 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2010/08/19 12:47:51.0593 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) C:\Windows\system32\Drivers\usbaapl.sys
2010/08/19 12:47:51.0890 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/08/19 12:47:52.0077 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2010/08/19 12:47:52.0373 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2010/08/19 12:47:52.0623 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2010/08/19 12:47:53.0060 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
2010/08/19 12:47:53.0621 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2010/08/19 12:47:54.0074 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/08/19 12:47:54.0667 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/08/19 12:47:55.0010 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2010/08/19 12:47:55.0244 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/08/19 12:47:55.0509 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2010/08/19 12:47:55.0883 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2010/08/19 12:47:56.0117 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2010/08/19 12:47:56.0414 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2010/08/19 12:47:56.0617 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2010/08/19 12:47:56.0804 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2010/08/19 12:47:57.0007 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2010/08/19 12:47:57.0241 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2010/08/19 12:47:57.0506 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2010/08/19 12:47:57.0709 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2010/08/19 12:47:57.0740 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2010/08/19 12:47:57.0943 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2010/08/19 12:47:58.0130 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2010/08/19 12:47:58.0567 winachsf (0acd399f5db3df1b58903cf4949ab5a8) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
2010/08/19 12:47:58.0972 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/08/19 12:47:59.0222 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2010/08/19 12:47:59.0487 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2010/08/19 12:47:59.0877 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/08/19 12:48:00.0189 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
2010/08/19 12:48:00.0329 ================================================================================
2010/08/19 12:48:00.0329 Scan finished
2010/08/19 12:48:00.0329 ================================================================================
 
Nothing found.

If your still being redirected and getting error messages, I need you to write down the error messages your getting word for word and also exactly what sites your being redirected to
 
I have gotten these messages many times when I visit sites I regularly visit like facebook, hotmail, or twitter.

Oops! Google Chrome could not find twitter.com
This webpage is not available.

I have been getting redirected to a variety of sites. Here is some of the sites that I got redirected too.

This webpage is not available.

The webpage at http://c.enhance.com/c?e1=dxqnWIGdX...CkHQVJ54vhCQktA&h=3ETD4cw2RAYZtpAng&b=2422999 might be temporarily down or it may have moved permanently to a new web address.

http://www.cafemom.com/group/416/fo..._for_your_favorite_park?utm_medium=sem2&utm_s
 
Try this

Please download Kenco.exe by jpshortstuff and save it to your desktop.
http://jpshortstuff.247fixes.com/Kenco.exe

* Double-click on Kenco.exe to run it (if you get a security warning, click run).
* You will see a black command window and shortly thereafter, a logfile (kenco.log) will open in Notepad. The log will be saved on your desktop.
* In order to complete the cleaning process, Kenco.exe may need to reboot your computer.
* Please copy and paste the contents of kenco.log in your next reply.
 
Here is the log created by Kenco. Also I have been redirected to this site multiple times. http://gathi.131.blueseek.com/jump2/?affiliate=gathi&subid=131&terms=letmewatchthis

Kenco by jpshortstuff (31.12.09.1)
Log created at 14:45 on 22/08/2010 (Darlin)

========== Task Unlocker ==========

========== KencoScan ==========

========== C:\Windows\Tasks ==========
Google Software Updater.job -> [21:21 03/09/2009] 868 bytes
GoogleUpdateTaskMachineCore.job -> [21:30 03/09/2009] 882 bytes
GoogleUpdateTaskMachineUA.job -> [21:30 03/09/2009] 886 bytes
GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000Core.job -> [23:27 21/08/2009] 860 bytes
GoogleUpdateTaskUserS-1-5-21-1042238982-2704989617-889929576-1000UA.job -> [23:27 21/08/2009] 912 bytes

-=E.O.F=-
 
That bugger is hiding as I dont see it in any of your scans

Please do a scan with Kaspersky Online Scanner or from Here.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.

KAS9.gif
 
Back
Top