1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Vista Won't Start, Normally Or Repair Mode, Black Screen

Discussion in 'Malware Removal Help' started by CarolsSis, Jun 23, 2012.

  1. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-07-03 22:03:13
    -----------------------------
    22:03:13.834 OS Version: Windows 6.0.6002 Service Pack 2
    22:03:13.835 Number of processors: 2 586 0xF0D
    22:03:13.836 ComputerName: TRAVELER UserName: Jan
    22:03:19.934 Initialize success
    22:03:20.803 AVAST engine defs: 12070301
    22:03:58.235 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
    22:03:58.238 Disk 0 Vendor: Hitachi_HTS542512K9SA00 BB2OC31P Size: 114473MB BusType: 3
    22:03:58.257 Disk 0 MBR read successfully
    22:03:58.261 Disk 0 MBR scan
    22:03:58.268 Disk 0 unknown MBR code
    22:03:58.272 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 9993 MB offset 63
    22:03:58.294 Disk 0 Partition 2 80 (A) 06 FAT16 NTFS 52371 MB offset 20467712
    22:03:58.322 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 52107 MB offset 127723520
    22:03:58.330 Disk 0 scanning sectors +234438656
    22:03:58.405 Disk 0 scanning C:\Windows\system32\drivers
    22:04:06.282 Service scanning
    22:04:40.606 Modules scanning
    22:04:56.618 Disk 0 trace - called modules:
    22:04:56.644 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
    22:04:56.654 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85005968]
    22:04:56.664 3 CLASSPNP.SYS[883ac8b3] -> nt!IofCallDriver -> [0x840c8a70]
    22:04:56.674 5 acpi.sys[8069b6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x840cfb98]
    22:04:57.511 AVAST engine scan C:\Windows
    22:04:59.992 AVAST engine scan C:\Windows\system32
    22:07:06.763 AVAST engine scan C:\Windows\system32\drivers
    22:07:15.532 AVAST engine scan C:\Users\Jan
    22:08:52.573 AVAST engine scan C:\ProgramData
    22:09:12.809 Scan finished successfully
    22:09:37.596 Disk 0 MBR has been saved successfully to "C:\Users\Jan\Documents\MBR.dat"
    22:09:37.603 The log file has been saved successfully to "C:\Users\Jan\Documents\aswMBR.txt"
     
  2. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    OTL Extras logfile created on: 7/3/2012 9:27:12 PM - Run 1
    OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Jan\Downloads
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1.99 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.55% Memory free
    4.22 Gb Paging File | 2.81 Gb Available in Paging File | 66.55% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 51.14 Gb Total Space | 21.20 Gb Free Space | 41.45% Space Free | Partition Type: NTFS
    Drive D: | 50.89 Gb Total Space | 42.91 Gb Free Space | 84.32% Space Free | Partition Type: NTFS

    Computer Name: TRAVELER | User Name: Jan | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
    .html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = ChromeHTML] -- Reg Error: Key error. File not found

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
    https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Acer\Empowering Technology\eDataSecurity\x86\eDSfsu.exe" = C:\Acer\Empowering Technology\eDataSecurity\x86\eDSfsu.exe:*:Enabled:eDSfsu -- (Egis Incorporated.)
    "C:\Acer\Empowering Technology\eDataSecurity\x86\encryption.exe" = C:\Acer\Empowering Technology\eDataSecurity\x86\encryption.exe:*:Enabled:encryption -- ( Egis Incorporated.)
    "C:\Acer\Empowering Technology\eDataSecurity\x86\decryption.exe" = C:\Acer\Empowering Technology\eDataSecurity\x86\decryption.exe:*:Enabled:decryption -- ( Egis Incorporated.)
    "C:\Acer\Empowering Technology\eDataSecurity\x86\eDSMgr.exe" = C:\Acer\Empowering Technology\eDataSecurity\x86\eDSMgr.exe:*:Enabled:eDSMgr
    "C:\Acer\Empowering Technology\eDataSecurity\x86\eDStbmngr.exe" = C:\Acer\Empowering Technology\eDataSecurity\x86\eDStbmngr.exe:*:Enabled:eDStbmngr -- (Egis Incorporated.)
    "C:\Acer\Empowering Technology\eDataSecurity\x64\eDSfsu.exe" = C:\Acer\Empowering Technology\eDataSecurity\x64\eDSfsu.exe:*:Enabled:eDSfsu -- (Egis Incorporated.)
    "C:\Acer\Empowering Technology\eDataSecurity\x64\encryption.exe" = C:\Acer\Empowering Technology\eDataSecurity\x64\encryption.exe:*:Enabled:encryption
    "C:\Acer\Empowering Technology\eDataSecurity\x64\decryption.exe" = C:\Acer\Empowering Technology\eDataSecurity\x64\decryption.exe:*:Enabled:decryption
    "C:\Acer\Empowering Technology\eDataSecurity\x64\eDSMgr.exe" = C:\Acer\Empowering Technology\eDataSecurity\x64\eDSMgr.exe:*:Enabled:eDSMgr
    "C:\Acer\Empowering Technology\eDataSecurity\x64\eDStbmngr.exe" = C:\Acer\Empowering Technology\eDataSecurity\x64\eDStbmngr.exe:*:Enabled:eDStbmngr -- (Egis Incorporated.)


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0568A9C1-7BB9-4DFD-A276-B2FCBF547B4F}" = rport=139 | protocol=6 | dir=out | app=system |
    "{10FBC126-1975-42B9-8E92-E9A0B7707119}" = rport=138 | protocol=17 | dir=out | app=system |
    "{3AE20C2C-2B55-4647-8CB7-0D79DE712652}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{4A6B34E8-C896-44EA-B5A5-D5B161243295}" = rport=137 | protocol=17 | dir=out | app=system |
    "{57968748-2A92-4F48-8DF0-60B8CF543BE4}" = lport=139 | protocol=6 | dir=in | app=system |
    "{72441022-CE2E-47E6-B35D-3D7276CD4AB7}" = lport=137 | protocol=17 | dir=in | app=system |
    "{8641CBF5-9B53-4787-8246-4AC34F65304F}" = lport=138 | protocol=17 | dir=in | app=system |
    "{8BF1E208-2C25-47AF-80EB-A11BF3992169}" = rport=445 | protocol=6 | dir=out | app=system |
    "{94875267-D61C-4989-B9CD-00CA8347C302}" = lport=445 | protocol=6 | dir=in | app=system |
    "{C3516095-837B-4B15-9ECB-BB42D8D3D129}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{01E5B4F1-2553-486D-856D-9DD239B76417}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "{12D289A9-4D2E-44AA-86A9-C8AD9610257A}" = dir=in | app=c:\program files\acer arcade deluxe\play movie\playmovie.exe |
    "{370EEFB2-323B-4156-876A-D25C3D267C2C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{4E93DFB6-C7FC-42F1-ADBB-C1A89E49A114}" = dir=in | app=c:\program files\acer arcade deluxe\play movie\pmvservice.exe |
    "{585B3550-FEE7-4183-8F73-C4F66DE696B5}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
    "{5D282683-EF96-4375-9A8F-DBD3C337389F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{5D75EE2C-E8B5-4284-9FB6-0A391BFD4870}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{99FD2269-0AA1-4BA9-BF9C-FD76015CB876}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "{C32F6579-8815-4815-A91D-33EBF8E83902}" = dir=in | app=c:\program files\acer arcade deluxe\dvdivine\dvdivine.exe |
    "{D9C84413-BEB2-4DAF-A817-A14CAA842BB7}" = dir=in | app=c:\program files\acer arcade deluxe\dv wizard\dv wizard.exe |
    "{E06EC9EA-32B8-4FEA-9D87-CA7111A5507D}" = dir=in | app=c:\program files\acer arcade deluxe\videomagician\videomagician.exe |
    "{E82E77A9-2EAB-40F9-9A5C-C543B020A4D8}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
    "{ECC26E64-C568-4BE3-8072-7DBB58D4E750}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0BF78E88-A7C9-4406-89CF-0BA473BA7821}" = Orion
    "{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
    "{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}" = Acer eLock Management
    "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
    "{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{427967BF-09F8-46D5-9275-37001CCBBA5D}" = Winbond CIR Drivers
    "{57265292-228A-41FA-9AEC-4620CBCC2739}" = Acer eAudio Management
    "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
    "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
    "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
    "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
    "{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112615863}" = Agatha Christie Death on the Nile
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
    "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
    "{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
    "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
    "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
    "{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management
    "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
    "{CE65A9A0-9686-45C6-9098-3C9543A412F0}" = Acer eSettings Management
    "{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Deluxe
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{FC57FC53-104C-415C-98D7-B05E659461A9}" = Broadcom Gigabit Integrated Controller
    "Acer Assist" = Acer Assist
    "Acer GameZone Console_is1" = Acer GameZone Console 2.0.1.1
    "Acer Registration" = Acer Registration
    "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
    "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
    "Agere Systems Soft Modem" = Agere Systems HDA Modem
    "avast" = avast! Free Antivirus
    "ERUNT_is1" = ERUNT 1.1j
    "Google Chrome" = Google Chrome
    "GridVista" = Acer GridVista
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "HOMESTUDENTR" = Microsoft Office Home and Student 2007
    "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
    "InstallShield_{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
    "LManager" = Launch Manager
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "TVWiz" = Intel(R) TV Wizard
    "Yahoo! Companion" = Yahoo! Toolbar
    "Yahoo! Toolbar" = Yahoo! Toolbar

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 6/30/2012 8:42:42 AM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 6/30/2012 9:37:16 AM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 6/30/2012 11:09:27 AM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 6/30/2012 11:10:53 AM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 6/30/2012 11:24:03 AM | Computer Name = traveler | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 7.0.6002.18005, time stamp
    0x49e01e78, faulting module aswWebRepIE.dll, version 7.0.1451.402, time stamp 0x4fec52d8,
    exception code 0x40000015, fault offset 0x0001854c, process id 0xc34, application
    start time 0x01cd56d3c0bc1363.

    Error - 6/30/2012 12:04:06 PM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 6/30/2012 1:32:15 PM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 6/30/2012 8:18:07 PM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 7/1/2012 6:56:00 AM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 7/1/2012 7:55:38 AM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    Error - 7/1/2012 8:37:51 AM | Computer Name = traveler | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 6/30/2012 2:29:37 AM | Computer Name = traveler | Source = Service Control Manager | ID = 7000
    Description =

    Error - 6/30/2012 2:45:35 AM | Computer Name = traveler | Source = DCOM | ID = 10010
    Description =

    Error - 6/30/2012 8:42:10 AM | Computer Name = traveler | Source = HTTP | ID = 15016
    Description =

    Error - 6/30/2012 8:42:42 AM | Computer Name = traveler | Source = Service Control Manager | ID = 7000
    Description =

    Error - 6/30/2012 9:34:58 AM | Computer Name = traveler | Source = DCOM | ID = 10010
    Description =

    Error - 6/30/2012 9:36:46 AM | Computer Name = traveler | Source = HTTP | ID = 15016
    Description =

    Error - 6/30/2012 9:37:16 AM | Computer Name = traveler | Source = Service Control Manager | ID = 7000
    Description =

    Error - 6/30/2012 11:09:28 AM | Computer Name = traveler | Source = Service Control Manager | ID = 7000
    Description =

    Error - 6/30/2012 12:01:52 PM | Computer Name = traveler | Source = DCOM | ID = 10010
    Description =

    Error - 6/30/2012 12:04:07 PM | Computer Name = traveler | Source = Service Control Manager | ID = 7000
    Description =


    < End of report >
     
  3. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    test
     

    Attached Files:

  4. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi CarolSis-

    I still need the information I asked for earlier to be able to understand what is going on with your system. I've provided some detail in the instructions to help.
    • Post the OTL log
    • Only the Extras.txt is currently posted. Please go to the directory you have OTL.exe in, open OTL.txt and copy/paste that log into your reply.
    • Post the updated MBAM log
      • Please launch Malwarebyte's Anti-Malware
      • Click the Update tab
      • Click Check for Updates, if it finds one it will update automatically.
      • If it updates, click OK to acknowledge it updated.
      • Click the Scanner tab
      • Select Perform quick scan
      • Click Scan and wait for the scan to complete.
      • Press OK when it says the scan is done.
      • Click Show Results
      • If anything is found, make sure to click in the checkbox on the left of each entry to select it. Then, click Removed Selected
      • If it tells you to reboot with a popup window, don't click anything yet. Make sure to post hte log first:
      • A logfile will pop up in Notepad. Click Edit --> Select All then Edit --> Copy.
      • Go to your reply to this thread, click in the box and select Paste to paste the log in your reply.
      • Once it is posted, if it asked you to reboot, close all the other programs then click Yes to reboot.
    • Attach the MBR.dat file
      • Look on your desktop for either MBR or MBR.dat
      • If the file name is MBR and not MBR.dat:
        • Click Start --> Computer
        • Press Alt-T to bring up the tools menu.
        • Click Folder Options
        • Click the View tab.
        • UNcheck the box next to Hide extensions for known file types
        • OK your way out of the menus.
        • It should now appear as MBR.dat on your desktop.
      • Right-click MBR.dat on your desktop and click Rename
      • Replace the MBR.dat with MBR.txt and press Enter to rename it.
      • It should now appear as MBR.txt on your desktop.
      • Under this post, in the "Reply to this topic" section, click More Reply Options
      • Under the text box, there is a section called "Attach Files".
        Click Choose Files
      • Navigate to your Documents folder (C:\Users\Jan\Documents) and click MBR.txt to highlight it.
      • Click Open and it will attach to the post. Type a message in the box, then click Add Reply and it will attach that file.
    • List out the issues you are experiencing
    • Please post the exact issues you are experiencing. That will help me diagnose the issue.
    Thanks!
    -etavares
     
  5. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    1. I have found and tried 4 times to post the OTL Log, message says it's too long. 2. MBR.DAT file is in documents folder, not desktop, do not know how to change file name, have not found a way. 3. Internet Explorer closes program 4 to six times and gives message it's looking for solution, doesn't find one, and closes program. 4. Start up takes 3 to 4 minutes, Acer screen shows for 3 seconds or so, always has, then black screen with row of blue boxes and multicolor shapes at top of screen, then continues boot. 5. Will try again to update and run MBR and post log, making sure it's saved to desktop. Thanks.
     
  6. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    1. You can copy and paste the first half of the OTL log in one post, then the other in a second post.
    2. That MBR.dat on the desktop is a typo on my part, another tool I use puts it on the desktop. You can still right-click on MBR.dat in the documents folder and rename it to MBR.txt. No need to run the program again, it will just overwrite the same file.

    PS> Thanks for sharing the list of issues, that is helpful.
     
  7. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org
    Database version: v2012.07.06.14
    Windows Vista Service Pack 2 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Jan :: TRAVELER [administrator]
    7/6/2012 5:30:07 PM
    mbam-log-2012-07-06 (17-30-07).txt
    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 194991
    Time elapsed: 7 minute(s), 51 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 0
    (No malicious items detected)
    (end)
     
  8. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    OTL logfile created on: 7/3/2012 9:42:46 PM - Run 1
    OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Jan\Downloads
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1.99 Gb Total Physical Memory | 0.88 Gb Available Physical Memory | 44.06% Memory free
    4.22 Gb Paging File | 2.51 Gb Available in Paging File | 59.44% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 51.14 Gb Total Space | 21.19 Gb Free Space | 41.43% Space Free | Partition Type: NTFS
    Drive D: | 50.89 Gb Total Space | 42.91 Gb Free Space | 84.32% Space Free | Partition Type: NTFS

    Computer Name: TRAVELER | User Name: Jan | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - C:\Users\Jan\Downloads\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
    PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
    PRC - C:\Users\Jan\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
    PRC - C:\Windows\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
    PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
    PRC - C:\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
    PRC - C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe (CyberLink Corp.)
    PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    PRC - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
    PRC - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
    PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
    PRC - C:\Acer\Empowering Technology\eNet\eNMTray.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\eNet\eNet Service.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ()
    PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
    PRC - C:\Acer\Mobility Center\MobilityService.exe ()
    PRC - C:\Windows\System32\Macromed\Flash\FlashUtil9e.exe (Adobe Systems, Inc.)
    PRC - C:\Acer\Empowering Technology\eAudio\eAudio.exe (CyberLink)
    PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
    PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
    PRC - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (acer)
    PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
    PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
    PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)


    ========== Modules (No Company Name) ==========

    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8bbcd31ecc8edc7d1f9cdd83ef2bb2d3\System.ServiceProcess.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll ()
    MOD - C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll ()
    MOD - C:\Acer\Empowering Technology\Acer.Empowering.Framework.DialogManager.dll ()
    MOD - C:\Acer\Empowering Technology\Acer.Empowering.Framework.PasswordSetting.dll ()
    MOD - C:\Acer\Empowering Technology\eDataSecurity\x86\ShowErrMsg.dll ()
    MOD - C:\Acer\Empowering Technology\eLock\eLockCTL.dll ()
    MOD - C:\Acer\Empowering Technology\eNet\eNetPlugin.dll ()
    MOD - C:\Acer\Empowering Technology\eSettings\eSettings.Plugin.dll ()
    MOD - C:\Acer\Empowering Technology\eSettings\eSettings.Presenter.dll ()
    MOD - C:\Acer\Empowering Technology\eSettings\eSettings.View.dll ()
    MOD - C:\Acer\Empowering Technology\eSettings.Model.ComputerInterfaces.dll ()
    MOD - C:\Acer\Empowering Technology\eAudio\eAudioUI.dll ()
    MOD - C:\Acer\Empowering Technology\ePower\SysHook.dll ()
    MOD - C:\Acer\Empowering Technology\ePresentation\ePresentationCTL.dll ()
    MOD - C:\Acer\Empowering Technology\eRecovery\ServiceInterface.dll ()


    ========== Win32 Services (SafeList) ==========

    SRV - (SBSDWSCService) -- C:\Program Files\Spybot File not found
    SRV - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
    SRV - (MatSvc) -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
    SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SRV - (eDataSecurity Service) -- C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
    SRV - (eNet Service) -- C:\Acer\Empowering Technology\eNet\eNet Service.exe (Acer Inc.)
    SRV - (eSettingsService) -- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ()
    SRV - (MobilityService) -- C:\Acer\Mobility Center\MobilityService.exe ()
    SRV - (IAANTMON) Intel(R) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
    SRV - (eLockService) -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (Acer Inc.)
    SRV - (WMIService) -- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (acer)
    SRV - (eRecoveryService) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
    SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)


    ========== Driver Services (SafeList) ==========
     
  9. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Driver Services (SafeList) ==========[/color]

    DRV - (USBSTOR) -- C:\Windows\system32\drivers\usbstor.sys File not found
    DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
    DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
    DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
    DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
    DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
    DRV - (aswSnx) -- C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
    DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
    DRV - (AswRdr) -- C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
    DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
    DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) -- C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl (Cyberlink Corp.)
    DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
    DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
    DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
    DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
    DRV - (int15) -- C:\Acer\Empowering Technology\eRecovery\int15.sys (Acer, Inc.)
    DRV - (winbondcir) -- C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)
    DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://azstarnet.com/?guid=on
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
    IE - HKCU\..\SearchScopes,DefaultScope = {FBD2310E-AC55-4A44-A3DD-576DA3F925BF}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKCU\..\SearchScopes\{FBD2310E-AC55-4A44-A3DD-576DA3F925BF}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


    ========== FireFox ==========

    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)



    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.47\pdf.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    CHR - Extension: YouTube = C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
    CHR - Extension: Google Search = C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
    CHR - Extension: avast! WebRep = C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1451_0\
    CHR - Extension: Gmail = C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

    O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: ::1 localhost
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
    O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
    O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe ()
    O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files\Acer\Acer Registration\ACE1.exe (Leader Technologies)
    O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [eAudio] C:\Acer\Empowering Technology\eAudio\eAudio.exe (CyberLink)
    O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
    O4 - HKLM..\Run: [eRecoveryService] File not found
    O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
    O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
    O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
    O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
    O4 - Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Users\Jan\Desktop\ERUNT\AUTOBACK.EXE ()
    O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O13 - gopher Prefix: missing
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{82447EF1-0445-4ED3-8CE1-220AFC8E058D}: DhcpNameServer = 192.168.1.1
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Waterfall.jpg
    O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Waterfall.jpg
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    NetSvcs: FastUserSwitchingCompatibility - File not found
    NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
    NetSvcs: Nla - File not found
    NetSvcs: Ntmssvc - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: SRService - File not found
    NetSvcs: WmdmPmSp - File not found
    NetSvcs: LogonHours - File not found
    NetSvcs: PCAudit - File not found
    NetSvcs: helpsvc - File not found
    NetSvcs: uploadmgr - File not found


    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/07/03 18:39:35 | 000,000,000 | ---D | C] -- C:\Users\Jan\Desktop\ERUNT
    [2012/07/03 18:39:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
     
  10. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/07/03 18:39:35 | 000,000,000 | ---D | C] -- C:\Users\Jan\Desktop\ERUNT
    [2012/07/03 18:39:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
    [2012/07/01 21:00:19 | 000,000,000 | ---D | C] -- C:\EGIS_Drive
    [2012/07/01 19:54:05 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\FixItCenter
    [2012/07/01 04:55:53 | 000,398,336 | ---- | C] (Intel(R) Corporation) -- C:\Windows\System32\TVWizudlg.exe
    [2012/06/30 18:32:58 | 000,000,000 | ---D | C] -- C:\Windows\MATS
    [2012/06/30 18:32:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center
    [2012/06/30 17:53:42 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
    [2012/06/30 17:53:40 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
    [2012/06/30 17:53:40 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
    [2012/06/30 17:53:40 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
    [2012/06/30 17:53:39 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
    [2012/06/30 17:53:39 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
    [2012/06/30 17:43:28 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
    [2012/06/30 17:43:27 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
    [2012/06/30 17:43:00 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
    [2012/06/30 17:42:59 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
    [2012/06/30 17:42:59 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
    [2012/06/30 17:42:37 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
    [2012/06/30 17:42:37 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
    [2012/06/30 10:28:23 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
    [2012/06/30 10:19:13 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll
    [2012/06/30 10:19:09 | 003,023,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
    [2012/06/30 10:19:09 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
    [2012/06/30 10:16:12 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BthMtpContextHandler.dll
    [2012/06/30 10:16:12 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDShextAutoplay.exe
    [2012/06/30 10:16:04 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceConnectApi.dll
    [2012/06/30 10:15:56 | 000,546,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpd_ci.dll
    [2012/06/30 10:15:55 | 000,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDSp.dll
    [2012/06/30 10:15:55 | 000,334,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
    [2012/06/30 10:15:55 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceWMDRM.dll
    [2012/06/30 10:15:55 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceTypes.dll
    [2012/06/30 10:15:55 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceClassExtension.dll
    [2012/06/30 10:00:00 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2012/06/30 10:00:00 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2012/06/30 10:00:00 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2012/06/30 10:00:00 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2012/06/30 10:00:00 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2012/06/30 10:00:00 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2012/06/30 10:00:00 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2012/06/30 10:00:00 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2012/06/30 09:59:59 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2012/06/30 09:59:59 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2012/06/30 09:59:59 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2012/06/30 09:59:59 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2012/06/30 09:59:59 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2012/06/30 09:59:59 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2012/06/30 09:59:59 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2012/06/30 09:59:59 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2012/06/30 09:59:59 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2012/06/30 09:59:59 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2012/06/30 09:59:59 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2012/06/30 09:59:59 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2012/06/30 09:59:59 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2012/06/30 09:59:59 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2012/06/30 09:59:59 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2012/06/30 09:59:59 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2012/06/30 09:59:58 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
    [2012/06/30 09:59:58 | 001,800,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2012/06/30 09:59:58 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2012/06/30 09:59:58 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2012/06/30 09:59:58 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2012/06/30 09:59:58 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2012/06/30 09:59:58 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2012/06/30 09:59:58 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2012/06/30 09:59:58 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2012/06/30 09:59:58 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2012/06/30 09:59:58 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2012/06/30 09:59:58 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2012/06/30 09:59:58 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2012/06/30 09:59:11 | 000,979,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll
    [2012/06/30 09:59:11 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll
    [2012/06/30 09:59:11 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll
    [2012/06/30 09:59:11 | 000,261,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
    [2012/06/30 09:59:10 | 002,873,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
    [2012/06/30 09:59:10 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
    [2012/06/30 09:59:10 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
    [2012/06/30 09:59:09 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
    [2012/06/30 09:59:08 | 001,554,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
    [2012/06/30 09:59:08 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
    [2012/06/30 09:59:08 | 000,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
    [2012/06/30 09:59:08 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
    [2012/06/30 09:59:08 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
    [2012/06/30 09:59:08 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
    [2012/06/30 09:59:08 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
    [2012/06/30 09:59:08 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
    [2012/06/30 09:59:08 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
    [2012/06/30 09:58:26 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
    [2012/06/30 09:58:26 | 000,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
    [2012/06/30 09:58:26 | 000,321,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
    [2012/06/30 09:58:26 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiag.exe
    [2012/06/30 09:58:26 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
    [2012/06/30 09:58:26 | 000,189,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
    [2012/06/30 09:30:20 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll
    [2012/06/30 09:30:16 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
    [2012/06/30 09:30:16 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
    [2012/06/30 09:30:15 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
    [2012/06/30 09:30:15 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
    [2012/06/30 09:30:04 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciseq.dll
    [2012/06/30 09:29:13 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
    [2012/06/30 09:28:49 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
    [2012/06/30 09:28:32 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
    [2012/06/30 09:28:29 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
    [2012/06/30 09:28:05 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
    [2012/06/30 09:28:02 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 zres.dll
    [2012/06/30 09:27:54 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
    [2012/06/30 09:27:54 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
    [2012/06/30 09:27:45 | 000,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
    [2012/06/30 09:27:45 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
    [2012/06/30 09:27:23 | 002,045,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
    [2012/06/30 09:27:20 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
    [2012/06/30 09:27:19 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
    [2012/06/30 09:13:50 | 000,613,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpencom.dll
    [2012/06/30 08:31:07 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe
    [2012/06/30 08:04:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
    [2012/06/30 08:04:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
    [2012/06/30 08:04:39 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
    [2012/06/30 08:00:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\SPReview
    [2012/06/30 07:44:38 | 000,928,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scavenge.dll
    [2012/06/30 07:44:19 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\compcln.exe
    [2012/06/30 07:43:35 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdohlp.dll
    [2012/06/30 07:43:34 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtffilt.dll
    [2012/06/30 07:43:33 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rpchttp.dll
    [2012/06/30 07:43:33 | 000,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rmcast.sys
    [2012/06/30 07:43:33 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\RNDISMP.sys
    [2012/06/30 07:43:32 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scansetting.dll
    [2012/06/30 07:43:31 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scksp.dll
    [2012/06/30 07:43:30 | 000,180,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrobj.dll
    [2012/06/30 07:43:29 | 001,248,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PerfCenterCPL.dll
    [2012/06/30 07:43:29 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\phon.ime
    [2012/06/30 07:43:28 | 001,823,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pnidui.dll
    [2012/06/30 07:43:28 | 000,464,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pcaui.dll
    [2012/06/30 07:43:28 | 000,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\P2PGraph.dll
    [2012/06/30 07:43:28 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PNPXAssoc.dll
    [2012/06/30 07:43:28 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PnPUnattend.exe
    [2012/06/30 07:43:28 | 000,043,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\pciidex.sys
    [2012/06/30 07:43:28 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PnPutil.exe
    [2012/06/30 07:43:27 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\powercpl.dll
    [2012/06/30 07:43:27 | 000,542,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pnpui.dll
    [2012/06/30 07:43:27 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pnpsetup.dll
    [2012/06/30 07:43:27 | 000,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\portcls.sys
    [2012/06/30 07:43:26 | 001,107,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pidgenx.dll
    [2012/06/30 07:43:26 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoScreensaver.scr
    [2012/06/30 07:43:25 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PkgMgr.exe
    [2012/06/30 07:43:25 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pintlgnt.ime
    [2012/06/30 07:43:25 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nslookup.exe
    [2012/06/30 07:43:23 | 012,240,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0007.dll
    [2012/06/30 07:43:23 | 002,644,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons0009.dll
    [2012/06/30 07:43:23 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\offfilt.dll
    [2012/06/30 07:43:23 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlhtml.dll
    [2012/06/30 07:43:22 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\osk.exe
    [2012/06/30 07:43:22 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
    [2012/06/30 07:43:22 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcconf.dll
    [2012/06/30 07:43:21 | 002,153,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oobefldr.dll
    [2012/06/30 07:43:21 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleprn.dll
    [2012/06/30 07:43:21 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ocsetup.exe
    [2012/06/30 07:43:20 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntprint.dll
    [2012/06/30 07:43:19 | 000,642,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasgcw.dll
    [2012/06/30 07:43:19 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasplap.dll
    [2012/06/30 07:43:19 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasmontr.dll
    [2012/06/30 07:43:19 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasdiag.dll
    [2012/06/30 07:43:19 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rasdial.exe
    [2012/06/30 07:43:18 | 000,880,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RacEngn.dll
    [2012/06/30 07:43:18 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
    [2012/06/30 07:43:18 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quick.ime
    [2012/06/30 07:43:18 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qintlgnt.ime
    [2012/06/30 07:43:17 | 000,340,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RelMon.dll
    [2012/06/30 07:43:17 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rekeywiz.exe
    [2012/06/30 07:43:16 | 000,779,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationNative_v0300.dll
    [2012/06/30 07:43:16 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationSettings.exe
    [2012/06/30 07:43:16 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
    [2012/06/30 07:43:16 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\reg.exe
    [2012/06/30 07:43:15 | 000,551,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prnntfy.dll
    [2012/06/30 07:43:15 | 000,102,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
    [2012/06/30 07:43:13 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\puiapi.dll
    [2012/06/30 07:43:12 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\propdefs.dll
    [2012/06/30 07:43:11 | 000,050,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PSHED.DLL
    [2012/06/30 07:43:06 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sethc.exe
    [2012/06/30 07:43:03 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eapphost.dll
    [2012/06/30 07:43:03 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eappgnui.dll
    [2012/06/30 07:43:02 | 000,187,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eapp3hst.dll
    [2012/06/30 07:43:02 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsprop.dll
    [2012/06/30 07:43:02 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EhStorAPI.dll
    [2012/06/30 07:43:02 | 000,027,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Dumpata.sys
    [2012/06/30 07:43:01 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\evr.dll
    [2012/06/30 07:43:01 | 000,444,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dsound.dll
    [2012/06/30 07:43:01 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxg.sys
    [2012/06/30 07:43:00 | 002,926,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
    [2012/06/30 07:43:00 | 000,205,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\eudcedit.exe
    [2012/06/30 07:43:00 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
    [2012/06/30 07:42:59 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\f3ahvoas.dll
    [2012/06/30 07:42:58 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EhStorPwdMgr.dll
    [2012/06/30 07:42:57 | 001,078,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diagperf.dll
    [2012/06/30 07:42:57 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dimsroam.dll
    [2012/06/30 07:42:56 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diskraid.exe
    [2012/06/30 07:42:56 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll
    [2012/06/30 07:42:56 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diskpart.exe
    [2012/06/30 07:42:56 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
    [2012/06/30 07:42:55 | 000,378,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\devmgr.dll
    [2012/06/30 07:42:53 | 000,407,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpapimig.exe
    [2012/06/30 07:42:53 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmmgrtn.dll
    [2012/06/30 07:42:53 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drvstore.dll
    [2012/06/30 07:42:53 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drvinst.exe
    [2012/06/30 07:42:53 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3msm.dll
    [2012/06/30 07:42:53 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dot3cfg.dll
    [2012/06/30 07:42:52 | 000,978,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drmv2clt.dll
    [2012/06/30 07:42:52 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmsynth.dll
    [2012/06/30 07:42:52 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dmusic.dll
    [2012/06/30 07:42:51 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hbaapi.dll
    [2012/06/30 07:42:50 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpresult.exe
    [2012/06/30 07:42:49 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iashlpr.dll
    [2012/06/30 07:42:49 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasacct.dll
    [2012/06/30 07:42:49 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasads.dll
    [2012/06/30 07:42:49 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasdatastore.dll
    [2012/06/30 07:42:49 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpupdate.exe
    [2012/06/30 07:42:48 | 000,463,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IasMigReader.exe
    [2012/06/30 07:42:48 | 000,454,144 | ---- | C] (Microsoft) -- C:\Windows\System32\IasMigPlugin.dll
    [2012/06/30 07:42:48 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasnap.dll
    [2012/06/30 07:42:48 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hdwwiz.exe
    [2012/06/30 07:42:48 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidclass.sys
    [2012/06/30 07:42:47 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll
    [2012/06/30 07:42:47 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\findstr.exe
    [2012/06/30 07:42:46 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdBth.dll
    [2012/06/30 07:42:46 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpapi.dll
    [2012/06/30 07:42:46 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdWCN.dll
    [2012/06/30 07:42:46 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdSSDP.dll
    [2012/06/30 07:42:46 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdWSD.dll
    [2012/06/30 07:42:46 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\feclient.dll
    [2012/06/30 07:42:46 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdeploy.dll
    [2012/06/30 07:42:46 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdProxy.dll
    [2012/06/30 07:42:46 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fc.exe
    [2012/06/30 07:42:46 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fdBthProxy.dll
    [2012/06/30 07:42:44 | 000,950,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpedit.dll
    [2012/06/30 07:42:43 | 002,134,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FunctionDiscoveryFolder.dll
    [2012/06/30 07:42:43 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fundisc.dll
    [2012/06/30 07:42:43 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ftp.exe
    [2012/06/30 07:42:42 | 001,985,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
    [2012/06/30 07:42:42 | 000,595,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FWPUCLNT.DLL
    [2012/06/30 07:42:42 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AudioSes.dll
    [2012/06/30 07:42:42 | 000,099,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
    [2012/06/30 07:42:42 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FwRemoteSvr.dll
    [2012/06/30 07:42:41 | 001,216,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayCpl.dll
    [2012/06/30 07:42:41 | 000,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autoconv.exe
    [2012/06/30 07:42:41 | 000,636,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autofmt.exe
    [2012/06/30 07:42:41 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayDriverLib.dll
    [2012/06/30 07:42:41 | 000,109,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ataport.sys
    [2012/06/30 07:42:41 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\AuxiliaryDisplayServices.dll
    [2012/06/30 07:42:41 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
    [2012/06/30 07:42:40 | 000,516,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\autoplay.dll
    [2012/06/30 07:42:39 | 001,342,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\brcpl.dll
    [2012/06/30 07:42:39 | 000,130,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\basecsp.dll
    [2012/06/30 07:42:39 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bthci.dll
    [2012/06/30 07:42:38 | 000,757,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\azroles.dll
    [2012/06/30 07:42:38 | 000,542,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\blackbox.dll
    [2012/06/30 07:42:38 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bcrypt.dll
    [2012/06/30 07:42:38 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bitsigd.dll
    [2012/06/30 07:42:37 | 002,515,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\accessibilitycpl.dll
    [2012/06/30 07:42:36 | 001,730,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apds.dll
    [2012/06/30 07:42:35 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adtschema.dll
    [2012/06/30 07:42:35 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adsmsext.dll
    [2012/06/30 07:42:34 | 001,645,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\connect.dll
    [2012/06/30 07:42:34 | 000,593,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comuid.dll
    [2012/06/30 07:42:34 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
    [2012/06/30 07:42:34 | 000,035,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\crashdmp.sys
    [2012/06/30 07:42:33 | 000,481,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmdial32.dll
    [2012/06/30 07:42:32 | 001,856,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dbgeng.dll
    [2012/06/30 07:42:32 | 001,788,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d9.dll
    [2012/06/30 07:42:32 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DevicePairing.dll
    [2012/06/30 07:42:32 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DevicePairingWizard.exe
    [2012/06/30 07:42:32 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DevicePairingProxy.dll
    [2012/06/30 07:42:32 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cmmon32.exe
    [2012/06/30 07:42:32 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dataclen.dll
    [2012/06/30 07:42:32 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DeviceEject.exe
    [2012/06/30 07:42:31 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cscript.exe
    [2012/06/30 07:42:31 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrstub.exe
    [2012/06/30 07:42:30 | 001,502,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certmgr.dll
    [2012/06/30 07:42:30 | 001,112,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
    [2012/06/30 07:42:30 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnrollUI.dll
    [2012/06/30 07:42:29 | 000,640,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bthprops.cpl
    [2012/06/30 07:42:29 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cbsra.exe
    [2012/06/30 07:42:29 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\bthudtask.exe
    [2012/06/30 07:42:28 | 006,103,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chtbrkr.dll
    [2012/06/30 07:42:28 | 001,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chsbrkr.dll
    [2012/06/30 07:42:28 | 000,614,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ci.dll
    [2012/06/30 07:42:28 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certreq.exe
    [2012/06/30 07:42:28 | 000,125,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Classpnp.sys
    [2012/06/30 07:42:28 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cintlgnt.ime
    [2012/06/30 07:42:28 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cipher.exe
    [2012/06/30 07:42:28 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CHxReadingStringIME.dll
    [2012/06/30 07:42:27 | 000,799,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe
    [2012/06/30 07:42:27 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\chajei.ime
    [2012/06/30 07:42:26 | 001,053,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtctm.dll
    [2012/06/30 07:42:26 | 000,564,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msftedit.dll
    [2012/06/30 07:42:26 | 000,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msexch40.dll
    [2012/06/30 07:42:26 | 000,339,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msexcl40.dll
    [2012/06/30 07:42:26 | 000,332,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msihnd.dll
    [2012/06/30 07:42:24 | 000,560,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtcprx.dll
    [2012/06/30 07:42:24 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msctfui.dll
    [2012/06/30 07:42:24 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsCtfMonitor.dll
    [2012/06/30 07:42:23 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msimsg.dll
    [2012/06/30 07:42:22 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\modemui.dll
    [2012/06/30 07:42:22 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MMDevAPI.dll
    [2012/06/30 07:42:21 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscms.dll
    [2012/06/30 07:42:21 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscandui.dll
    [2012/06/30 07:42:20 | 000,155,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscorier.dll
    [2012/06/30 07:42:20 | 000,080,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscories.dll
    [2012/06/30 07:42:19 | 002,225,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcenter.dll
    [2012/06/30 07:42:19 | 001,086,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NetProjW.dll
    [2012/06/30 07:42:19 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncryptui.dll
    [2012/06/30 07:42:19 | 000,223,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
    [2012/06/30 07:42:19 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
    [2012/06/30 07:42:18 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NaturalLanguage6.dll
    [2012/06/30 07:42:18 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NcdProp.dll
    [2012/06/30 07:42:17 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\newdev.exe
    [2012/06/30 07:42:16 | 003,072,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\networkmap.dll
    [2012/06/30 07:42:16 | 000,469,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\newdev.dll
    [2012/06/30 07:42:16 | 000,241,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msltus40.dll
    [2012/06/30 07:42:16 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
    [2012/06/30 07:42:16 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\networkitemfactory.dll
    [2012/06/30 07:42:15 | 000,643,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrepl40.dll
    [2012/06/30 07:42:15 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2VDEC.DLL
    [2012/06/30 07:42:15 | 000,408,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msinfo32.exe
    [2012/06/30 07:42:15 | 000,368,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspbde40.dll
    [2012/06/30 07:42:15 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrd3x40.dll
    [2012/06/30 07:42:15 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrd2x40.dll
    [2012/06/30 07:42:15 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msnetobj.dll
    [2012/06/30 07:42:15 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
    [2012/06/30 07:42:15 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscb.dll
    [2012/06/30 07:42:15 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msimtf.dll
    [2012/06/30 07:42:14 | 001,589,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msjet40.dll
    [2012/06/30 07:42:14 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msjtes40.dll
    [2012/06/30 07:42:14 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msjter40.dll
    [2012/06/30 07:42:14 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msjint40.dll
    [2012/06/30 07:42:14 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msisip.dll
    [2012/06/30 07:42:13 | 000,856,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mswdat10.dll
    [2012/06/30 07:42:13 | 000,618,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mswstr10.dll
    [2012/06/30 07:42:13 | 000,454,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxbde40.dll
    [2012/06/30 07:42:13 | 000,351,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
    [2012/06/30 07:42:13 | 000,203,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
    [2012/06/30 07:42:12 | 001,480,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
    [2012/06/30 07:42:12 | 000,670,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
    [2012/06/30 07:42:12 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscp.dll
    [2012/06/30 07:42:12 | 000,282,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstext40.dll
    [2012/06/30 07:42:12 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssitlb.dll
    [2012/06/30 07:42:12 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msstrc.dll
    [2012/06/30 07:42:12 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssprxy.dll
    [2012/06/30 07:42:12 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshooks.dll
    [2012/06/30 07:42:11 | 000,217,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\InkEd.dll
    [2012/06/30 07:42:11 | 000,035,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardcpl.cpl
    [2012/06/30 07:42:11 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetppui.dll
    [2012/06/30 07:42:10 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imkr80.ime
    [2012/06/30 07:42:10 | 000,099,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardapi.dll
    [2012/06/30 07:42:09 | 000,396,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ipsmsnap.dll
    [2012/06/30 07:42:09 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iscsilog.dll
    [2012/06/30 07:42:08 | 000,759,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ipsecsnp.dll
    [2012/06/30 07:42:08 | 000,200,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\input.dll
    [2012/06/30 07:42:08 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ipconfig.exe
    [2012/06/30 07:42:07 | 000,619,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardagt.exe
    [2012/06/30 07:42:07 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iassdo.dll
    [2012/06/30 07:42:07 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrad.dll
    [2012/06/30 07:42:07 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iassvcs.dll
    [2012/06/30 07:42:07 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iaspolcy.dll
    [2012/06/30 07:42:07 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ifmon.dll
    [2012/06/30 07:42:07 | 000,009,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardres.dll
    [2012/06/30 07:42:06 | 000,729,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IMJP10K.DLL
    [2012/06/30 07:42:06 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iassam.dll
    [2012/06/30 07:42:06 | 000,119,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrecst.dll
    [2012/06/30 07:42:05 | 000,883,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IMJP10.IME
    [2012/06/30 07:42:05 | 000,378,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi2.dll
    [2012/06/30 07:42:05 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi.dll
    [2012/06/30 07:42:04 | 000,677,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imapi2fs.dll
    [2012/06/30 07:42:00 | 002,012,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\milcore.dll
    [2012/06/30 07:42:00 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mimefilt.dll
    [2012/06/30 07:41:59 | 002,167,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmcndmgr.dll
    [2012/06/30 07:41:59 | 001,792,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmc.exe
    [2012/06/30 07:41:59 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmci.dll
    [2012/06/30 07:41:59 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mmcico.dll
    [2012/06/30 07:41:57 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ks.sys
    [2012/06/30 07:41:57 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\korwbrkr.dll
    [2012/06/30 07:41:57 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Kswdmcap.ax
    [2012/06/30 07:41:57 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\l2nacp.dll
    [2012/06/30 07:41:57 | 000,017,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kd1394.dll
    [2012/06/30 07:41:56 | 000,950,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mblctr.exe
    [2012/06/30 07:41:56 | 000,852,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcmde.dll
    [2012/06/30 07:41:56 | 000,438,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mcupdate_GenuineIntel.dll
    [2012/06/30 07:41:56 | 000,019,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kdusb.dll
    [2012/06/30 07:41:56 | 000,017,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kdcom.dll
    [2012/06/30 07:41:55 | 000,356,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MediaMetadataHandler.dll
    [2012/06/30 07:41:55 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logagent.exe
    [2012/06/30 07:41:54 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Magnify.exe
    [2012/06/30 07:41:54 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\logman.exe
    [2012/06/30 07:41:53 | 001,143,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wercon.exe
    [2012/06/30 07:41:53 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shsetup.dll
    [2012/06/30 07:41:52 | 001,020,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdc.dll
    [2012/06/30 07:41:52 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wer.dll
    [2012/06/30 07:41:52 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdscore.dll
    [2012/06/30 07:41:49 | 001,524,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsAnytimeUpgradeCPL.dll
    [2012/06/30 07:41:49 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtutil.exe
    [2012/06/30 07:41:48 | 000,860,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WerFaultSecure.exe
    [2012/06/30 07:41:48 | 000,250,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtapi.dll
    [2012/06/30 07:41:48 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WerFault.exe
    [2012/06/30 07:41:48 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\whealogr.dll
    [2012/06/30 07:41:47 | 000,547,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wiaaut.dll
    [2012/06/30 07:41:46 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdmdbg.dll
    [2012/06/30 07:41:45 | 000,507,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsdyn.dll
    [2012/06/30 07:41:45 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vdsutil.dll
    [2012/06/30 07:41:44 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
    [2012/06/30 07:41:43 | 000,638,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Utilman.exe
    [2012/06/30 07:41:42 | 001,123,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\usercpl.dll
    [2012/06/30 07:41:42 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\watchdog.sys
    [2012/06/30 07:41:41 | 001,533,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wcnwiz.dll
    [2012/06/30 07:41:41 | 000,968,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wcnwiz2.dll
    [2012/06/30 07:41:41 | 000,165,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WcnNetsh.dll
    [2012/06/30 07:41:38 | 000,291,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WscEapPr.dll
    [2012/06/30 07:41:38 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscapi.dll
    [2012/06/30 07:41:38 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsdchngr.dll
    [2012/06/30 07:41:38 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscisvif.dll
    [2012/06/30 07:41:37 | 001,689,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscui.cpl
    [2012/06/30 07:41:37 | 001,382,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVSDECD.DLL
    [2012/06/30 07:41:37 | 000,223,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscntfy.dll
    [2012/06/30 07:41:37 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSDMon.dll
    [2012/06/30 07:41:36 | 001,575,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVENCOD.DLL
    [2012/06/30 07:41:36 | 000,657,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVXENCD.DLL
    [2012/06/30 07:41:36 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wow32.dll
    [2012/06/30 07:41:35 | 001,580,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpccpl.dll
    [2012/06/30 07:41:35 | 000,532,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpcao.dll
    [2012/06/30 07:41:35 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wusa.exe
    [2012/06/30 07:41:34 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xmlfilter.dll
    [2012/06/30 07:41:33 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsepno.dll
    [2012/06/30 07:41:32 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsnmp32.dll
    [2012/06/30 07:41:31 | 001,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanpref.dll
    [2012/06/30 07:41:31 | 000,399,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlangpui.dll
    [2012/06/30 07:41:31 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanui.dll
    [2012/06/30 07:41:30 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlgpclnt.dll
    [2012/06/30 07:41:29 | 000,926,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
    [2012/06/30 07:41:28 | 003,217,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSAT.exe
    [2012/06/30 07:41:28 | 000,986,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
    [2012/06/30 07:41:27 | 000,996,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMNetMgr.dll
    [2012/06/30 07:41:26 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpeffects.dll
    [2012/06/30 07:41:24 | 000,533,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmdrmsdk.dll
    [2012/06/30 07:41:22 | 000,122,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Storport.sys
    [2012/06/30 07:41:22 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Storprop.dll
    [2012/06/30 07:41:22 | 000,052,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\stream.sys
    [2012/06/30 07:41:21 | 001,224,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sud.dll
    [2012/06/30 07:41:19 | 000,378,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
    [2012/06/30 07:41:19 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll
    [2012/06/30 07:41:15 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sysclass.dll
    [2012/06/30 07:41:14 | 002,205,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SyncCenter.dll
    [2012/06/30 07:41:14 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sysmon.ocx
    [2012/06/30 07:41:13 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SmartcardCredentialProvider.dll
    [2012/06/30 07:41:13 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slwmi.dll
    [2012/06/30 07:41:12 | 000,705,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SmiEngine.dll
    [2012/06/30 07:41:12 | 000,083,456 | ---- | C] (Microsoft) -- C:\Windows\System32\SMBHelperClass.dll
    [2012/06/30 07:41:11 | 000,777,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slcc.dll
    [2012/06/30 07:41:11 | 000,425,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\shwebsvc.dll
    [2012/06/30 07:41:10 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SLUI.exe
    [2012/06/30 07:41:10 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slcinst.dll
    [2012/06/30 07:41:10 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slwga.dll
    [2012/06/30 07:41:09 | 001,081,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SLCExt.dll
    [2012/06/30 07:41:09 | 000,582,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SLCommDlg.dll
    [2012/06/30 07:41:09 | 000,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spinstall.exe
    [2012/06/30 07:41:09 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SLLUA.exe
    [2012/06/30 07:41:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spcmsg.dll
    [2012/06/30 07:41:07 | 000,524,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sqlsrv32.dll
    [2012/06/30 07:41:07 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sperror.dll
    [2012/06/30 07:41:07 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwizui.dll
    [2012/06/30 07:41:07 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwinsat.dll
    [2012/06/30 07:41:06 | 000,684,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\spsys.sys
    [2012/06/30 07:41:06 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spreview.exe
    [2012/06/30 07:41:05 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SnippingTool.exe
    [2012/06/30 07:41:05 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SndVol.exe
    [2012/06/30 07:41:05 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\softkbd.dll
    [2012/06/30 07:41:04 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSTheme.exe
    [2012/06/30 07:41:04 | 000,035,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsWpfWrp.exe
    [2012/06/30 07:41:02 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\untfs.dll
    [2012/06/30 07:41:02 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\USBCAMD.sys
    [2012/06/30 07:41:02 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys
    [2012/06/30 07:41:00 | 000,203,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\uDWM.dll
    [2012/06/30 07:41:00 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\USBCAMD2.sys
    [2012/06/30 07:40:57 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ulib.dll
    [2012/06/30 07:40:56 | 000,842,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\systemcpl.dll
    [2012/06/30 07:40:50 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 intlgnt.ime
    [2012/06/30 07:40:48 | 001,576,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 query.dll
    [2012/06/30 07:40:47 | 000,170,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 cpipcfg.dll
    [2012/06/30 07:40:45 | 000,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 hawbrkr.dll
    [2012/06/30 07:40:44 | 001,152,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 hemecpl.dll
    [2012/06/30 07:37:14 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
    [2012/06/30 06:29:43 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
    [2012/06/30 06:29:43 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
    [2012/06/30 06:29:42 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
    [2012/06/29 23:39:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    [2012/06/29 23:38:16 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Google
    [2012/06/29 23:38:16 | 000,000,000 | ---D | C] -- C:\Program Files\Google
    [2012/06/29 23:38:14 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
    [2012/06/29 23:38:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
    [2012/06/29 23:38:13 | 000,353,688 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
    [2012/06/29 23:38:04 | 000,035,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
    [2012/06/29 23:38:03 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
    [2012/06/29 23:38:02 | 000,721,000 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
    [2012/06/29 23:37:59 | 000,057,656 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
    [2012/06/29 23:36:36 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
    [2012/06/29 23:36:35 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
    [2012/06/29 23:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
    [2012/06/29 23:36:03 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
    [2012/06/29 22:51:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
    [2012/06/29 22:51:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
    [2012/06/29 22:51:43 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
    [2012/06/29 22:28:31 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Malwarebytes
    [2012/06/29 22:28:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/06/29 22:28:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/06/29 22:28:13 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
    [2012/06/29 22:28:13 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2012/06/29 20:04:15 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nshhttp.dll
    [2012/06/29 20:02:54 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
    [2012/06/29 19:59:48 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrsmgr.dll
    [2012/06/29 19:59:36 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrs.exe
    [2012/06/29 19:59:36 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrshost.exe
    [2012/06/29 19:59:36 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsmprovhost.exe
    [2012/06/29 19:59:35 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsmplpxy.dll
    [2012/06/29 19:59:35 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrssrv.dll
    [2012/06/29 19:59:33 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtfwd.dll
    [2012/06/29 19:59:33 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecutil.exe
    [2012/06/29 19:59:33 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecapi.dll
    [2012/06/29 19:59:33 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmRes.dll
    [2012/06/29 19:59:32 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pwrshplugin.dll
    [2012/06/29 19:59:26 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmWmiPl.dll
    [2012/06/29 19:59:26 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmAuto.dll
    [2012/06/29 19:59:25 | 000,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManMigrationPlugin.dll
    [2012/06/29 19:59:25 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManHTTPConfig.exe
    [2012/06/29 19:59:25 | 000,241,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrscmd.dll
    [2012/06/29 19:56:45 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\asycfilt.dll
    [2012/06/29 19:56:43 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
    [2012/06/29 19:56:41 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
    [2012/06/29 19:56:40 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
    [2012/06/29 19:56:40 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dciman32.dll
    [2012/06/29 19:56:28 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll
    [2012/06/29 19:56:28 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
    [2012/06/29 19:56:28 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll
    [2012/06/29 19:56:27 | 008,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
    [2012/06/29 19:53:13 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netiohlp.dll
    [2012/06/29 19:53:10 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NETSTAT.EXE
    [2012/06/29 19:53:09 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ARP.EXE
    [2012/06/29 19:53:08 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\finger.exe
    [2012/06/29 19:53:08 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\HOSTNAME.EXE
    [2012/06/29 19:53:07 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ROUTE.EXE
    [2012/06/29 19:53:07 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MRINFO.EXE
    [2012/06/29 19:52:19 | 002,386,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVCORE.DLL
    [2012/06/29 19:52:16 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rrinstaller.exe
    [2012/06/29 19:52:15 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfpmp.exe
    [2012/06/29 19:52:15 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mferror.dll
    [2012/06/29 19:52:07 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlansec.dll
    [2012/06/29 19:52:07 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanmsm.dll
    [2012/06/29 19:52:07 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\L2SecHC.dll
    [2012/06/29 19:52:07 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanhlp.dll
    [2012/06/29 19:52:05 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wlanapi.dll
    [2012/06/29 19:51:38 | 000,081,920 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
    [2012/06/29 19:51:32 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
    [2012/06/29 19:51:32 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
    [2012/06/29 19:51:19 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
    [2012/06/29 19:51:02 | 000,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 2embed.dll
    [2012/06/29 19:48:21 | 001,169,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
    [2012/06/29 19:41:51 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
    [2012/06/29 19:41:51 | 000,518,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
    [2012/06/29 19:41:50 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
    [2012/06/29 19:41:49 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
    [2012/06/29 19:41:48 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
    [2012/06/29 19:41:48 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
    [2012/06/29 19:41:47 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
    [2012/06/29 19:41:47 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
    [2012/06/29 19:41:44 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
    [2012/06/29 19:39:46 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll
    [2012/06/29 19:39:45 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll
    [2012/06/29 19:39:25 | 001,696,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
    [2012/06/29 19:39:24 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
    [2012/06/29 19:39:22 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
    [2012/06/29 19:38:38 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.tlb
    [2012/06/29 19:38:38 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\amcompat.tlb
    [2012/06/29 19:38:23 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Microsoft Games
    [2012/06/29 19:38:12 | 000,714,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 imedate.cpl
    [2012/06/29 19:38:07 | 000,317,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MP4SDECD.DLL
    [2012/06/29 19:37:46 | 000,310,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unregmp2.exe
    [2012/06/29 19:35:45 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kbd106n.dll
    [2012/06/29 19:35:12 | 000,867,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll
    [2012/06/29 19:34:57 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 askschd.dll
    [2012/06/29 19:34:54 | 000,345,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmicmiplugin.dll
    [2012/06/29 19:34:53 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 askcomp.dll
    [2012/06/29 19:34:44 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
    [2012/06/29 19:34:35 | 000,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
    [2012/06/29 19:33:38 | 000,322,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
    [2012/06/29 19:33:38 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
    [2012/06/29 19:33:38 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbeio.dll
    [2012/06/29 19:33:33 | 000,220,672 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\l3codecp.acm
    [2012/06/29 19:33:33 | 000,062,464 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\l3codeca.acm
    [2012/06/29 19:33:24 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
    [2012/06/29 19:33:24 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 scupgrd.exe
    [2012/06/29 19:33:24 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32 sgqec.dll
    [2012/06/29 19:33:17 | 000,604,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOD.DLL
    [2012/06/29 19:33:14 | 000,355,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSDApi.dll
    [2012/06/29 19:32:13 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
    [2012/06/29 19:26:11 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\ElevatedDiagnostics
    [2012/06/29 19:25:25 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
    [2012/06/29 19:20:56 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell 1.0
    [2012/06/29 19:20:56 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
    [2012/06/29 08:19:32 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Adobe
    [2012/06/28 17:38:34 | 000,000,000 | ---D | C] -- C:\Program Files\Vic512WA
    [2012/06/28 17:38:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer GridVista
    [2012/06/28 17:37:58 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\PlayMovie
    [2012/06/28 17:37:58 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Leadertech
    [2012/06/28 17:37:57 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Acer
    [2012/06/26 21:56:23 | 017,730,504 | ---- | C] (Acer Incorporated) -- C:\Windows\eRy.exe
    [2012/06/26 21:55:45 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\devcon.exe
    [2012/06/26 21:22:34 | 000,368,640 | ---- | C] (Acer Inc.) -- C:\Windows\System32\CheckD2DSystem.exe
    [2012/06/26 21:22:34 | 000,327,680 | ---- | C] (Acer Inc.) -- C:\Windows\System32\Remove_eRecovery.exe
    [2012/06/26 21:22:06 | 000,000,000 | ---D | C] -- C:\Program Files\Acer
    [2012/06/26 21:21:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Launch Manager
    [2012/06/26 21:21:08 | 000,000,000 | ---D | C] -- C:\Program Files\Launch Manager
    [2012/06/26 21:20:54 | 000,040,960 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\junction.exe
    [2012/06/26 21:20:11 | 001,706,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gdiplus.dll
    [2012/06/26 21:18:43 | 000,050,752 | ---- | C] (Agere Systems) -- C:\Windows\System32\agrsmdel.exe
    [2012/06/26 21:17:57 | 000,000,000 | ---D | C] -- C:\Windows\Options
    [2012/06/26 21:17:35 | 000,000,000 | -H-D | C] -- C:\Users\Jan\AppData\Local\acer eNM
    [2012/06/26 21:16:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2012/06/26 21:16:46 | 000,000,000 | R--D | C] -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    [2012/06/26 21:16:46 | 000,000,000 | R--D | C] -- C:\Users\Jan\Searches
    [2012/06/26 21:16:46 | 000,000,000 | R--D | C] -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    [2012/06/26 21:16:35 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Identities
    [2012/06/26 21:16:33 | 000,000,000 | R--D | C] -- C:\Users\Jan\Contacts
    [2012/06/26 21:16:08 | 040,280,138 | ---- | C] (Adobe Systems, Inc.) -- C:\Windows\System32\acer.exe
    [2012/06/26 21:16:06 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Macromedia
    [2012/06/26 21:15:59 | 000,000,000 | ---D | C] -- C:\Program Files\Acer Inc
    [2012/06/26 21:15:55 | 000,000,000 | ---D | C] -- C:\Windows\ACER
    [2012/06/26 21:14:56 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\VirtualStore
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\AppData\Local\Temporary Internet Files
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Templates
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Start Menu
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\SendTo
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Recent
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\PrintHood
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\NetHood
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Documents\My Videos
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Documents\My Pictures
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Documents\My Music
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\My Documents
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Local Settings
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\AppData\Local\History
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Cookies
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\Application Data
    [2012/06/26 21:14:51 | 000,000,000 | -HSD | C] -- C:\Users\Jan\AppData\Local\Application Data
    [2012/06/26 21:14:50 | 000,000,000 | --SD | C] -- C:\Users\Jan\AppData\Roaming\Microsoft
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Videos
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Saved Games
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Pictures
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Music
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Links
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Favorites
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Downloads
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Documents
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\Desktop
    [2012/06/26 21:14:50 | 000,000,000 | R--D | C] -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    [2012/06/26 21:14:50 | 000,000,000 | -H-D | C] -- C:\Users\Jan\AppData
    [2012/06/26 21:14:50 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Temp
    [2012/06/26 21:14:50 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Local\Microsoft
    [2012/06/26 21:14:50 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Media Center Programs
    [2012/06/26 21:14:50 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerProducer
    [2012/06/26 21:14:50 | 000,000,000 | ---D | C] -- C:\Users\Jan\AppData\Roaming\Acer GameZone Console
    [2012/06/26 21:03:07 | 001,002,008 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igxpun.exe
    [2012/06/26 21:03:07 | 000,319,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\difxapi.dll
    [2012/06/26 21:03:07 | 000,000,000 | ---D | C] -- C:\Windows\System32\Lang
    [2012/06/26 21:01:55 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution

    ========== Files - Modified Within 30 Days ==========

    [2012/07/03 21:48:05 | 000,000,880 | ---- | M] () -- C:\Windows asks\GoogleUpdateTaskMachineUA.job
    [2012/07/03 20:34:13 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/07/03 20:34:13 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/07/03 18:41:06 | 000,604,502 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2012/07/03 18:41:06 | 000,104,170 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2012/07/03 18:39:48 | 000,000,676 | ---- | M] () -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/03 18:39:36 | 000,000,478 | ---- | M] () -- C:\Users\Jan\Desktop\NTREGOPT.lnk
    [2012/07/03 18:39:36 | 000,000,459 | ---- | M] () -- C:\Users\Jan\Desktop\ERUNT.lnk
    [2012/07/03 18:34:12 | 000,000,876 | ---- | M] () -- C:\Windows asks\GoogleUpdateTaskMachineCore.job
    [2012/07/03 18:33:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/07/03 18:33:33 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
    [2012/07/03 09:13:22 | 000,003,584 | ---- | M] () -- C:\Users\Jan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/07/01 04:56:24 | 000,016,068 | ---- | M] () -- C:\Windows\System32\results.xml
    [2012/06/30 18:33:01 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Fix it Center.lnk
    [2012/06/30 10:33:26 | 000,000,947 | ---- | M] () -- C:\Users\Jan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2012/06/30 10:31:29 | 000,297,240 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2012/06/30 10:00:11 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
    [2012/06/30 10:00:11 | 000,001,988 | ---- | M] () -- C:\Windows\System32 icrf.rat
    [2012/06/30 10:00:00 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2012/06/30 10:00:00 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2012/06/30 10:00:00 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2012/06/30 10:00:00 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2012/06/30 10:00:00 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2012/06/30 10:00:00 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2012/06/30 10:00:00 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2012/06/30 10:00:00 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2012/06/30 09:59:59 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2012/06/30 09:59:59 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2012/06/30 09:59:59 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2012/06/30 09:59:59 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2012/06/30 09:59:59 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2012/06/30 09:59:59 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2012/06/30 09:59:59 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2012/06/30 09:59:59 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2012/06/30 09:59:59 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2012/06/30 09:59:59 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2012/06/30 09:59:59 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2012/06/30 09:59:59 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2012/06/30 09:59:59 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2012/06/30 09:59:59 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2012/06/30 09:59:59 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
    [2012/06/30 09:59:59 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2012/06/30 09:59:59 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2012/06/30 09:59:58 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
    [2012/06/30 09:59:58 | 001,800,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2012/06/30 09:59:58 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2012/06/30 09:59:58 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2012/06/30 09:59:58 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2012/06/30 09:59:58 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2012/06/30 09:59:58 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2012/06/30 09:59:58 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2012/06/30 09:59:58 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2012/06/30 09:59:58 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2012/06/30 09:59:58 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2012/06/30 09:59:58 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2012/06/30 09:59:58 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2012/06/30 09:59:11 | 000,979,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll
    [2012/06/30 09:59:11 | 000,357,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll
    [2012/06/30 09:59:11 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll
    [2012/06/30 09:59:11 | 000,261,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
    [2012/06/30 09:59:10 | 002,873,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
    [2012/06/30 09:59:10 | 000,209,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
    [2012/06/30 09:59:10 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
    [2012/06/30 09:59:09 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
    [2012/06/30 09:59:08 | 001,554,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
    [2012/06/30 09:59:08 | 001,029,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
    [2012/06/30 09:59:08 | 000,847,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
    [2012/06/30 09:59:08 | 000,667,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
    [2012/06/30 09:59:08 | 000,486,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
    [2012/06/30 09:59:08 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
    [2012/06/30 09:59:08 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
    [2012/06/30 09:59:08 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
    [2012/06/30 09:59:08 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
    [2012/06/30 09:58:27 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\en-US\dxgkrnl.sys.mui
    [2012/06/30 09:58:26 | 000,519,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
    [2012/06/30 09:58:26 | 000,369,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
    [2012/06/30 09:58:26 | 000,321,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
    [2012/06/30 09:58:26 | 000,252,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxdiag.exe
    [2012/06/30 09:58:26 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
    [2012/06/30 09:58:26 | 000,189,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
    [2012/06/29 23:40:00 | 000,001,975 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2012/06/29 23:40:00 | 000,001,959 | ---- | M] () -- C:\Users\Jan\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    [2012/06/29 23:38:14 | 000,001,833 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
    [2012/06/29 23:37:59 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
    [2012/06/29 22:51:49 | 000,001,059 | ---- | M] () -- C:\Users\Jan\Desktop\Spybot - Search & Destroy.lnk
    [2012/06/29 22:28:17 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/06/29 19:19:37 | 001,114,112 | ---- | M] () -- C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
    [2012/06/29 19:19:37 | 000,196,608 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
    [2012/06/29 19:19:37 | 000,065,536 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
    [2012/06/28 17:38:46 | 000,000,120 | ---- | M] () -- C:\Windows\Alaunch.ini
    [2012/06/28 17:38:29 | 000,000,092 | ---- | M] () -- C:\Windows\GridV.UNI
    [2012/06/28 05:52:42 | 000,353,688 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
    [2012/06/28 05:52:42 | 000,054,232 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
    [2012/06/28 05:52:37 | 000,721,000 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
    [2012/06/28 05:52:37 | 000,057,656 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
    [2012/06/28 05:52:37 | 000,035,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
    [2012/06/28 05:52:36 | 000,021,256 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
    [2012/06/28 05:52:20 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
    [2012/06/28 05:51:49 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
    [2012/06/26 21:56:33 | 000,000,003 | ---- | M] () -- C:\Windows\AFirst.cmd
    [2012/06/26 21:21:10 | 000,000,083 | ---- | M] () -- C:\Windows\QtZgAcer.UNI
    [2012/06/26 21:15:20 | 000,004,398 | ---- | M] () -- C:\Windows\CLEANUP.CMD
    [2012/06/26 21:05:59 | 000,047,092 | ---- | M] () -- C:\Windows\System32\license.rtf

    ========== Files Created - No Company Name ==========

    [2012/07/03 18:39:48 | 000,000,676 | ---- | C] () -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
    [2012/07/03 18:39:36 | 000,000,478 | ---- | C] () -- C:\Users\Jan\Desktop\NTREGOPT.lnk
    [2012/07/03 18:39:36 | 000,000,459 | ---- | C] () -- C:\Users\Jan\Desktop\ERUNT.lnk
    [2012/07/03 09:13:19 | 000,003,584 | ---- | C] () -- C:\Users\Jan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/07/01 04:55:53 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
    [2012/07/01 04:55:53 | 000,121,232 | ---- | C] () -- C:\Windows\System32\IScrNB.bmp
    [2012/06/30 18:33:01 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Fix it Center.lnk
    [2012/06/30 18:33:01 | 000,000,846 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Fix it Center.lnk
    [2012/06/30 09:59:59 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
    [2012/06/30 07:43:22 | 000,392,170 | ---- | C] () -- C:\Windows\System32\onex.tmf
    [2012/06/30 07:43:18 | 000,009,212 | ---- | C] () -- C:\Windows\System32\RacUR.xml
    [2012/06/30 07:43:18 | 000,000,153 | ---- | C] () -- C:\Windows\System32\RacUREx.xml
    [2012/06/30 07:43:03 | 000,344,698 | ---- | C] () -- C:\Windows\System32\eaphost.tmf
    [2012/06/30 07:42:58 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
    [2012/06/30 07:42:53 | 000,442,788 | ---- | C] () -- C:\Windows\System32\dot3.tmf
    [2012/06/30 07:41:49 | 000,208,966 | ---- | C] () -- C:\Windows\System32\WFP.TMF
    [2012/06/30 07:41:21 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
    [2012/06/30 07:41:10 | 000,092,918 | ---- | C] () -- C:\Windows\System32\slmgr.vbs
    [2012/06/30 07:41:07 | 000,009,239 | ---- | C] () -- C:\Windows\System32\spcinstrumentation.man
    [2012/06/30 07:40:57 | 000,130,008 | ---- | C] () -- C:\Windows\System32\systemsf.ebd
    [2012/06/29 23:40:00 | 000,001,975 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2012/06/29 23:40:00 | 000,001,959 | ---- | C] () -- C:\Users\Jan\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    [2012/06/29 23:38:42 | 000,000,880 | ---- | C] () -- C:\Windows asks\GoogleUpdateTaskMachineUA.job
    [2012/06/29 23:38:33 | 000,000,876 | ---- | C] () -- C:\Windows asks\GoogleUpdateTaskMachineCore.job
    [2012/06/29 23:38:14 | 000,001,833 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
    [2012/06/29 22:51:49 | 000,001,059 | ---- | C] () -- C:\Users\Jan\Desktop\Spybot - Search & Destroy.lnk
    [2012/06/29 22:28:17 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/06/29 20:54:31 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
    [2012/06/29 20:54:27 | 011,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
    [2012/06/29 19:59:28 | 000,201,184 | ---- | C] () -- C:\Windows\System32\winrm.vbs
    [2012/06/29 19:59:28 | 000,004,675 | ---- | C] () -- C:\Windows\System32\wsmanconfig_schema.xml
    [2012/06/29 19:59:28 | 000,002,426 | ---- | C] () -- C:\Windows\System32\WsmTxt.xsl
    [2012/06/29 19:52:10 | 002,501,921 | ---- | C] () -- C:\Windows\System32\wlan.tmf
    [2012/06/29 19:19:25 | 001,114,112 | ---- | C] () -- C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
    [2012/06/29 19:19:25 | 000,196,608 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
    [2012/06/29 19:19:25 | 000,065,536 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
    [2012/06/28 17:38:29 | 000,000,092 | ---- | C] () -- C:\Windows\GridV.UNI
    [2012/06/26 21:56:33 | 000,000,003 | ---- | C] () -- C:\Windows\AFirst.cmd
    [2012/06/26 21:55:48 | 000,000,030 | ---- | C] () -- C:\Windows\SETPANEL.INI
    [2012/06/26 21:55:46 | 000,000,294 | ---- | C] () -- C:\Windows\offline.reg
    [2012/06/26 21:55:46 | 000,000,155 | ---- | C] () -- C:\Windows\IR.reg
    [2012/06/26 21:55:45 | 000,004,398 | ---- | C] () -- C:\Windows\CLEANUP.CMD
    [2012/06/26 21:55:45 | 000,000,092 | ---- | C] () -- C:\Windows\CLEANUP.INI
    [2012/06/26 21:55:45 | 000,000,023 | ---- | C] () -- C:\Windows\System32\$Acer$.cmd
    [2012/06/26 21:22:35 | 000,000,552 | ---- | C] () -- C:\Windows\System32\setup.iss
    [2012/06/26 21:22:34 | 000,016,384 | ---- | C] () -- C:\Windows\System32\LauncheRyAgentUser.exe
    [2012/06/26 21:22:34 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe
    [2012/06/26 21:22:07 | 000,001,856 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Assist.lnk
    [2012/06/26 21:22:06 | 000,001,876 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Registration.lnk
    [2012/06/26 21:21:10 | 000,000,083 | ---- | C] () -- C:\Windows\QtZgAcer.UNI
    [2012/06/26 21:16:48 | 000,000,953 | ---- | C] () -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    [2012/06/26 21:16:45 | 000,000,948 | ---- | C] () -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    [2012/06/26 21:16:32 | 000,000,919 | ---- | C] () -- C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
    [2012/06/26 21:16:06 | 083,554,304 | ---- | C] () -- C:\Windows\System32\acer.scr
    [2012/06/26 21:15:21 | 000,000,947 | ---- | C] () -- C:\Users\Jan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2012/06/26 21:15:18 | 000,016,068 | ---- | C] () -- C:\Windows\System32\results.xml
    [2012/06/26 21:14:50 | 000,000,258 | ---- | C] () -- C:\Users\Jan\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
    [2012/06/26 21:14:50 | 000,000,240 | ---- | C] () -- C:\Users\Jan\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
    [2012/06/26 21:04:48 | 2137,448,448 | -HS- | C] () -- C:\hiberfil.sys

    ========== LOP Check ==========

    [2012/06/28 17:37:59 | 000,000,000 | ---D | M] -- C:\Users\Jan\AppData\Roaming\Acer
    [2008/03/13 23:21:06 | 000,000,000 | ---D | M] -- C:\Users\Jan\AppData\Roaming\Acer GameZone Console
    [2012/06/28 17:37:58 | 000,000,000 | ---D | M] -- C:\Users\Jan\AppData\Roaming\Leadertech
    [2012/07/03 09:13:56 | 000,015,902 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========

    < %SYSTEMDRIVE%\*.* >
    [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
    [2008/03/13 23:05:56 | 000,699,974 | ---- | M] () -- C:\bknowsetup.log
    [2009/04/10 23:36:38 | 000,333,257 | RHS- | M] () -- C:\bootmgr
    [2008/03/13 23:06:02 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
    [2006/09/18 14:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
    [2012/07/03 18:33:33 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
    [2005/08/16 08:49:12 | 000,040,960 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\junction.exe
    [2012/07/03 18:33:31 | 2451,238,912 | -HS- | M] () -- C:\pagefile.sys

    < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
    [2006/11/02 05:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\w32x86\jnwppr.dll
    [2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Spool\prtprocs\w32x86\msonpppr.dll

    < %systemroot%\*. /mp /s >

    < %systemroot%\system32\*.dll /lockedfiles >

    < %systemroot%\Tasks\*.job /lockedfiles >

    < %systemroot%\system32\drivers\*.sys /lockedfiles >

    < %systemroot%\system32\*.exe /lockedfiles >

    < %systemroot%\System32\config\*.sav >
    [2008/01/20 20:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
    [2008/01/20 20:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
    [2008/01/20 20:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
    [2006/11/02 03:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
    [2006/11/02 03:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

    < %PROGRAMFILES%\* >
    [2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

    < %USERPROFILE%\..|smtmp;true;true;true /FP >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < hklm\software\clients\startmenuinternet|command /rs >
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --show-icons [2012/06/28 03:28:57 | 001,250,328 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --hide-icons [2012/06/28 03:28:57 | 001,250,328 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/06/28 03:28:57 | 001,250,328 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files\Google\Chrome\Application\chrome.exe" [2012/06/28 03:28:57 | 001,250,328 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\system32\ie4uinit.exe" -hide [2012/06/30 09:59:59 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\system32\ie4uinit.exe" -show [2012/06/30 09:59:59 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\system32\ie4uinit.exe" -reinstall [2012/06/30 09:59:59 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2012/06/30 10:00:00 | 000,748,664 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2012/06/30 10:00:00 | 000,748,664 | ---- | M] (Microsoft Corporation)

    < hklm\software\clients\startmenuinternet|command /64 /rs >
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --show-icons [2012/06/28 03:28:57 | 001,250,328 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --hide-icons [2012/06/28 03:28:57 | 001,250,328 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/06/28 03:28:57 | 001,250,328 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files\Google\Chrome\Application\chrome.exe" [2012/06/28 03:28:57 | 001,250,328 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\system32\ie4uinit.exe" -hide [2012/06/30 09:59:59 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\system32\ie4uinit.exe" -show [2012/06/30 09:59:59 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\system32\ie4uinit.exe" -reinstall [2012/06/30 09:59:59 | 000,074,240 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2012/06/30 10:00:00 | 000,748,664 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2012/06/30 10:00:00 | 000,748,664 | ---- | M] (Microsoft Corporation)

    < >

    < End of report >

    etavares, so sorry I'm having a tough time with this. I haven't used the computer much with this problem much, read news online. I forgot to mention, my solitaire game is not playing normally either. May not be encountering problems because I read news, this forum and solitaire, until I get it fixed. thanks for the help and patience.
     
  11. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi CarolSis-

    OK, we're making progress on getting the right information. All that's left is the MBR.dat file.

    • Post the OTL log
    • Post the updated MBAM log
    • Attach the MBR.dat file
      • Click Start --> Computer
      • Look in C:\Users\Jan\Documents for either MBR or MBR.dat
      • If the file name is MBR and not MBR.dat:
        • Press Alt-T to bring up the tools menu.
        • Click Folder Options
        • Click the View tab.
        • UNcheck the box next to Hide extensions for known file types
        • OK your way out of the menus.
        • It should now appear as MBR.dat on your desktop.
      • Right-click MBR.dat and click Rename
      • Replace the MBR.dat with MBR.txt by typing with your keyboard and press Enter to confirm the new name.
      • It will warn you about changing the file extension, click Yes to allow the change.
      • It should now appear as MBR.txt
      • Under this post, in the "Reply to this topic" section, click More Reply Options
      • Under the text box, there is a section called "Attach Files".
      • Click Choose Files
      • Navigate to your Documents folder (C:\Users\Jan\Documents) and click MBR.txt to highlight it.
      • Click Open and it will attach to the post. Type a message in the box, then click Add Reply and it will attach that file.
    • List out the issues you are experiencing

    Thanks!
    -etavares
     
  12. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    If you are having problems with finding the MBR.dat file let us know as there are a few tricks that can be done to make finding it a bit easier if you have never looked for something like this before. Once you find it though you must then follow etavares's directions precisely from the point where you are told to rename it.
     
  13. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    error message trying to run ERUNT. error saving file, security!, access is denied.

    Had MBR.dat ready to attach, you aren't permitted to upload this kind of file. I had drag and dropped it onto my desktop, am now able to right click it, and copy it to move it here. I can't seem to get to the place to change file name, have looked several times.

    finally able to rename MBR.txt, copy, change to forum, click in post field, can not paste, they are greyed out. This has happened several times.

    Above start button, Javascript-void-paste. This shows after I click in post field, and paste is greyed out.
     
  14. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Why were you running erunt? I believe that you were asked not to do anything other than what you were specifically asked to do.

    Nobody asked you to try to upload the MBR.dat file directly you were asked to create a .txt file so you can attach it directly.

    Is the file on your desktop the actual file or a shortcut. On the actual file when you right click its icon without opening the file you will get a fairly long dropdown menu. Rename should be on that menu toward the bottom.
     
  15. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Please do not edit a post to add information not included in the original post. It confuses the person who is trying to help you. If you read etavares's instructions carefully you would not have tried to paste the file. These are the relevant directions:
    • It should now appear as MBR.txt
    • Under this post, in the "Reply to this topic" section, click More Reply Options
    • Under the text box, there is a section called "Attach Files".
    • Click Choose Files
    • Navigate to your Documents folder (C:\Users\Jan\Documents) and click MBR.txt to highlight it.
    • Click Open and it will attach to the post. Type a message in the box, then click Add Reply and it will attach that file.
    This is the way to attach the file: The directions came specifically from etavares' instructions and deal with the part about attaching the file. Another option for you is to open the MBR.txt file and highlight and copy the whole thing. The you can paste the text directly here. You cannot copy and paste the file itself.
     
  16. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I dragged the file to desktop from documents. I assume it's original file as none exists in documents any longer.

    Found rename, renamed file, copy, post field, again, message that I'm not permitted to post this kind of file.

    Will not do anything else. I had gone back to post with instructions and after running malwarebytes, instructions were to run ERUNT. Will not do it again.
    just read your post, was typing this when it came up. will try again with mbr.

    1ÀŽÐ¼ |ûPPü¾|¿PW¹åó¤Ë¿ 1À²€ÍsOtëóëþ½ˆ€~ ZtTø¸–³Írù t+ø¸–³Írù tø¸–³Írù u$ø¸ÊÍ€út¾¾±8,|u Æ âô‰õéo éi ½¾f‹^`h h fSh h |h h ´B²€‰æÍaas Ot0ä²€ÍëÍè{ ½¾ÆF €ÆF ÆF ÆF ‰¨t€N$ ‰¨t€N4èr h h |˽Îf‹^`h h fSh h |h h ´B²€‰æÍaas Ot0ä²€ÍëÍè ½¾€~'tºÆF'è% 뱿 1ÀŽÀ» ~¸µ ±¶ ²€Ís Ot0äÍ
    ëÞÿ 1ÀŽÀ» ~¸µ ±¶ ²€Ís Ot0äÍ
    ëÞà Acer.3 system $¼ßb  'þÿÿ? ;L8€þÿÿþÿÿ P8 ˜d þÿÿþÿÿ èœ X\ Uª
     
  17. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    PLEASE just attach the file here or post the actual text. Do not run anything again unless etavares specifically tells you to. If you have found the MBR.dat file simply deal with that according to the instructions.
     
  18. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hello, Carolsis.


    BeeCeeBee, ERUNT was in the preparation guide. That error will occur with Windows Vista and 7 on every boot. It is OK, just acknowledge it. It will stop when we uninstall ERUNT when we clean up.

    In regards to MBR.txt, I'm guessing the real file name is MBR.txt.dat and the extension is hidden. I did look at the text from it you posted, but it looks odd. It may the text encoding, so I need the actual file. Please run this:


    Download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • A blank Windows shall open with the title "SystemLook v1.0-by Jpshortstuff".
    • Copy and Paste the content of the following codebox into the main textfield under "File":
      Code:
      :filefind
      mbr*.*
      
    • Please Confirm everything is copied and Pasted as I have provided above
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan.
    • Please post this log in your next reply.


    Note: The log can also be found on your Desktop entitled SystemLook.txt
    2nd Note: The scan may take a while from several seconds to a minute or more depending on the number of files you have and how fast your computer can perform the task


    etavares
     
  19. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I wasn't given the option to save to desktop, it's in IE downloads file. I tried to hilight the text in box. When it's hilighted, I rt. click and the box to chose copy comes up, but hilight goes off, when I try to hilight with box showing, box disappears. You were right about the file extension on MBR, I checked the details and that is how it's listed.
     
  20. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Despite the fact that the highlight may disappear the text is (or was) probably on your clip board anyhow. Try highlighting again and pasting it to a blank document and see if it comes up. If it does you can copy and paste it here.
     

Share This Page