New
#11
No... that is chkdsk performing a scan of your hard drive....
You may need to use another computer (XP) to use flash disinfector. These instructions are clearer. Flash Disinfector – free autorun.inf trojans removal tool | My Anti Spyware
I did everything you said, and still when I click it nothing happens. Is there some sort of program, that can find this file you are speaking of and remove it?
Do you have this folder showing? If you do, look in Programs and features and uninstall the application. Then boot into safe mode and delete the folder.
C:\Program Files\Common Files\SecurePCCleaner\stm.exe
Ok, found nothing in "Malwarebytes" or "Norton Antivirus", but I found 23 "Adware.Tracking Cookies" which are obviously nothing to do with the problem. Going to do a restart now, I will update this post, when it is complete.
*UPDATE*
I restarted my pc and I got the "Blue screen of death" again, it only appeared for 2 seconds but it asked me to do "System Restore" again.
I recorded the "Diagnostic and repair details" log and uploaded it to Photobucket.
http://s839.photobucket.com/albums/z...8072010065.mp4
Apparently, the "Root cause" was:
Unknown Bugcheck: Bugcheck 6b. Parameters = 0x0, 0x0, 0x0, 0x0.
Last edited by 05dgarner; 18 Jul 2010 at 14:18.
"Video not found"
Download DDS from one of these links:
Mirror 1 Mirror 2 Mirror 3
- Disable any script blocking protection
- Double click the dds icon to run the tool.
- When done, DDS will open two (2) logs:
- DDS.txt
- Attach.txt <----This will be minimized in the task tray
- Save both reports to your desktop.
Include the contents of both logs
DDS (Ver_10-03-17.01) - NTFSX64
Run by Dan at 20:41:06.92 on 18/07/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.8191.3942 [GMT 1:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PSIService.exe
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Norton AntiVirus\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLClient.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\Corel Paint Shop Pro Photo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\AUDIODG.EXE
C:\Users\Dan\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files (x86)\sweetim\toolbars\internet explorer\mgHelper.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton antivirus\engine\17.7.0.12\IPSBHO.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
BHO: SweetIM Toolbar Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files (x86)\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: SweetIM Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files (x86)\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files (x86)\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [System] c:\users\dan\documents\system32\XBox 360 Points Generator.exe
mRun: [Standby] "c:\program files (x86)\common files\corel\standby\Standby.exe" -START
mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Google Sidewiki... - c:\program files (x86)\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\mif5ba~1\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_64.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg64.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\google\google toolbar\GoogleToolbar_64.dll
TB-X64: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
================= FIREFOX ===================
FF - ProfilePath - c:\users\dan\appdata\roaming\mozilla\firefox\profiles\31uqqvlh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files (x86)\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\np_IEGetPlugin.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npicaN.dll
FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\dan\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\navx64\1107000.00c\symds64.sys [2010-6-29 433200]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\navx64\1107000.00c\symefa64.sys [2010-6-29 221232]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\bashdefs\20100709.001\BHDrvx64.sys [2010-7-13 942640]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\navx64\1107000.00c\cchpx64.sys [2010-6-29 615040]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\ipsdefs\20100712.001\IDSviA64.sys [2010-7-13 463408]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\navx64\1107000.00c\ironx64.sys [2010-6-29 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\navx64\1107000.00c\symtdiv.sys [2010-6-29 451120]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-5-5 202752]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-14 27136]
R2 NAV;Norton AntiVirus;c:\program files (x86)\norton antivirus\engine\17.7.0.12\ccsvchst.exe [2010-6-29 126392]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-5-5 6789632]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-5-5 221184]
R3 CAXHWBS2;CAXHWBS2;c:\windows\system32\drivers\CAXHWBS2.sys [2009-6-30 411136]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-11-5 325152]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-2-18 1235968]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2010-2-17 135664]
S3 nosGetPlusHelper;getPlus(R) Installer;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2009-7-14 27136]
S3 SrvHsfPCI;SrvHsfPCI;c:\windows\system32\drivers\VSTBS26.SYS [2009-7-13 411136]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-4 1255736]
============== File Associations ===============
regfile="regedit.exe" "%1"
=============== Created Last 30 ================
2010-07-18 18:59:06 524288 --sha-w- c:\users\dan\ntuser.dat{783addd3-929e-11df-ac09-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-18 18:59:06 524288 --sha-w- c:\users\dan\ntuser.dat{783addd3-929e-11df-ac09-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-18 18:59:05 65536 --sha-w- c:\users\dan\ntuser.dat{783addd3-929e-11df-ac09-002618e82c0d}.TM.blf
2010-07-18 08:13:52 3304 ------w- C:\bootsqm.dat
2010-07-18 07:40:21 65536 --sha-w- c:\users\dan\ntuser.dat{aaff57f0-923f-11df-a09e-002618e82c0d}.TM.blf
2010-07-18 07:40:21 524288 --sha-w- c:\users\dan\ntuser.dat{aaff57f0-923f-11df-a09e-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-18 07:40:21 524288 --sha-w- c:\users\dan\ntuser.dat{aaff57f0-923f-11df-a09e-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-18 07:30:52 65536 --sha-w- c:\users\dan\ntuser.dat{590c63d2-923e-11df-a102-002618e82c0d}.TM.blf
2010-07-18 07:30:52 524288 --sha-w- c:\users\dan\ntuser.dat{590c63d2-923e-11df-a102-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-18 07:30:52 524288 --sha-w- c:\users\dan\ntuser.dat{590c63d2-923e-11df-a102-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-17 21:31:56 24664 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-17 18:58:31 0 d-----w- c:\users\dan\appdata\roaming\Malwarebytes
2010-07-17 18:58:20 0 d-----w- c:\programdata\Malwarebytes
2010-07-17 18:58:18 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2010-07-17 18:54:42 0 d-----w- c:\users\dan\appdata\roaming\SUPERAntiSpyware.com
2010-07-17 18:54:42 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-07-17 18:54:35 0 d-----w- c:\program files\SUPERAntiSpyware
2010-07-17 18:44:35 65536 --sha-w- c:\users\dan\ntuser.dat{35672816-91d3-11df-82b5-002618e82c0d}.TM.blf
2010-07-17 18:44:35 524288 --sha-w- c:\users\dan\ntuser.dat{35672816-91d3-11df-82b5-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-17 18:44:35 524288 --sha-w- c:\users\dan\ntuser.dat{35672816-91d3-11df-82b5-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-16 21:52:06 65536 --sha-w- c:\users\dan\ntuser.dat{51706a15-9124-11df-8512-002618e82c0d}.TM.blf
2010-07-16 21:52:06 524288 --sha-w- c:\users\dan\ntuser.dat{51706a15-9124-11df-8512-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-16 21:52:06 524288 --sha-w- c:\users\dan\ntuser.dat{51706a15-9124-11df-8512-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-16 11:57:04 65536 --sha-w- c:\users\dan\ntuser.dat{0e6d39db-90d1-11df-bcc0-002618e82c0d}.TM.blf
2010-07-16 11:57:04 524288 --sha-w- c:\users\dan\ntuser.dat{0e6d39db-90d1-11df-bcc0-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-16 11:57:04 524288 --sha-w- c:\users\dan\ntuser.dat{0e6d39db-90d1-11df-bcc0-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-16 10:09:42 0 d-----w- c:\program files (x86)\common files\PC Tools
2010-07-16 10:09:24 0 d---a-w- c:\programdata\TEMP
2010-07-16 09:44:46 0 d-----w- c:\programdata\IObit
2010-07-16 09:41:59 0 d-----w- c:\users\dan\appdata\roaming\IObit
2010-07-16 09:41:59 0 d-----w- c:\program files (x86)\IObit
2010-07-16 09:26:57 65536 --sha-w- c:\users\dan\ntuser.dat{27a4b078-90bc-11df-a406-002618e82c0d}.TM.blf
2010-07-16 09:26:57 524288 --sha-w- c:\users\dan\ntuser.dat{27a4b078-90bc-11df-a406-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-16 09:26:57 524288 --sha-w- c:\users\dan\ntuser.dat{27a4b078-90bc-11df-a406-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-16 09:12:47 0 d-----w- c:\users\dan\appdata\roaming\Uniblue
2010-07-16 08:59:57 0 d-----w- c:\users\dan\appdata\roaming\BitDefender
2010-07-16 08:59:57 0 d-----w- c:\programdata\BitDefender
2010-07-16 08:59:57 0 d-----w- c:\program files\common files\BitDefender
2010-07-16 08:59:57 0 d-----w- c:\program files\BitDefender
2010-07-16 08:58:13 0 d-----w- c:\program files (x86)\common files\BitDefender
2010-07-16 08:41:38 65536 --sha-w- c:\users\dan\ntuser.dat{d4a90891-90b5-11df-8ff0-002618e82c0d}.TM.blf
2010-07-16 08:41:38 524288 --sha-w- c:\users\dan\ntuser.dat{d4a90891-90b5-11df-8ff0-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-16 08:41:38 524288 --sha-w- c:\users\dan\ntuser.dat{d4a90891-90b5-11df-8ff0-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-15 09:36:57 65536 --sha-w- c:\users\dan\ntuser.dat{65ae2593-8ff4-11df-b0e3-002618e82c0d}.TM.blf
2010-07-15 09:36:57 524288 --sha-w- c:\users\dan\ntuser.dat{65ae2593-8ff4-11df-b0e3-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-15 09:36:57 524288 --sha-w- c:\users\dan\ntuser.dat{65ae2593-8ff4-11df-b0e3-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-13 07:31:50 0 d-----w- c:\users\dan\appdata\roaming\Tific
2010-07-13 07:30:06 65536 --sha-w- c:\users\dan\ntuser.dat{67c473f1-8e50-11df-9634-002618e82c0d}.TM.blf
2010-07-13 07:30:06 524288 --sha-w- c:\users\dan\ntuser.dat{67c473f1-8e50-11df-9634-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-07-13 07:30:06 524288 --sha-w- c:\users\dan\ntuser.dat{67c473f1-8e50-11df-9634-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-07-11 20:28:26 0 d-----w- c:\programdata\Codemasters
2010-07-11 20:27:45 17686528 ----a-w- c:\windows\syswow64\mkl_blueripple.dll
2010-07-11 20:27:45 1347584 ----a-w- c:\windows\syswow64\rapture3d_oal.dll
2010-07-11 20:27:45 0 d-----w- c:\program files (x86)\BRS
2010-07-11 20:22:22 0 d-----w- c:\program files (x86)\Codemasters
2010-07-11 18:57:18 0 d-----w- c:\users\dan\appdata\roaming\Activision
2010-07-11 18:57:18 0 d-----w- c:\programdata\Activision
2010-07-11 18:34:55 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-07-11 18:34:55 467984 ----a-w- c:\windows\syswow64\d3dx10_39.dll
2010-07-11 18:34:55 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-07-11 18:34:55 1493528 ----a-w- c:\windows\syswow64\D3DCompiler_39.dll
2010-07-11 18:34:54 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-07-11 18:34:54 3851784 ----a-w- c:\windows\syswow64\D3DX9_39.dll
2010-07-11 17:52:08 0 d-----w- c:\program files (x86)\Capcom
2010-07-11 16:10:40 0 d-----w- c:\windows\syswow64\Adobe
2010-06-28 19:19:10 854 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.INF
2010-06-28 19:19:10 7440 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.CAT
2010-06-28 19:19:10 173104 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2010-06-28 19:19:08 0 d-----w- c:\program files\Symantec
2010-06-28 19:19:08 0 d-----w- c:\program files\common files\Symantec Shared
2010-06-28 19:18:41 0 d-----w- c:\windows\system32\drivers\NAVx64
2010-06-28 19:18:40 0 d-----w- c:\program files (x86)\Norton AntiVirus
2010-06-28 19:12:59 0 d-----w- c:\program files (x86)\NortonInstaller
2010-06-28 17:22:39 65536 --sha-w- c:\users\dan\ntuser.dat{b582c339-82d9-11df-a3ec-002618e82c0d}.TM.blf
2010-06-28 17:22:39 524288 --sha-w- c:\users\dan\ntuser.dat{b582c339-82d9-11df-a3ec-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-06-28 17:22:39 524288 --sha-w- c:\users\dan\ntuser.dat{b582c339-82d9-11df-a3ec-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-06-28 12:18:29 65536 --sha-w- c:\users\dan\ntuser.dat{37d6fc5e-82af-11df-8672-002618e82c0d}.TM.blf
2010-06-28 12:18:29 524288 --sha-w- c:\users\dan\ntuser.dat{37d6fc5e-82af-11df-8672-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-06-28 12:18:29 524288 --sha-w- c:\users\dan\ntuser.dat{37d6fc5e-82af-11df-8672-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-06-27 20:37:22 0 d-----w- c:\users\dan\appdata\roaming\Sunbelt
2010-06-27 20:36:52 0 d-----w- c:\programdata\Sunbelt
2010-06-27 20:34:24 0 d-----w- c:\program files\Microsoft SQL Server
2010-06-27 20:33:56 0 d-----w- c:\program files (x86)\Microsoft SQL Server
2010-06-27 20:08:45 65536 --sha-w- c:\users\dan\ntuser.dat{c018e2fe-8227-11df-9f53-002618e82c0d}.TM.blf
2010-06-27 20:08:45 524288 --sha-w- c:\users\dan\ntuser.dat{c018e2fe-8227-11df-9f53-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-06-27 20:08:45 524288 --sha-w- c:\users\dan\ntuser.dat{c018e2fe-8227-11df-9f53-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-06-26 07:52:29 65536 --sha-w- c:\users\dan\ntuser.dat{bb504ebe-80f7-11df-ba21-002618e82c0d}.TM.blf
2010-06-26 07:52:29 524288 --sha-w- c:\users\dan\ntuser.dat{bb504ebe-80f7-11df-ba21-002618e82c0d}.TMContainer00000000000000000002.regtrans-ms
2010-06-26 07:52:29 524288 --sha-w- c:\users\dan\ntuser.dat{bb504ebe-80f7-11df-ba21-002618e82c0d}.TMContainer00000000000000000001.regtrans-ms
2010-06-24 19:32:55 0 d-----w- c:\programdata\Windows Genuine Advantage
2010-06-24 19:29:46 0 d-----w- c:\program files (x86)\XBox 360 Controller for Windows Software
2010-06-24 00:02:58 0 d-----w- c:\users\dan\appdata\roaming\Facebook
2010-06-23 13:34:38 99176 ----a-w- c:\windows\syswow64\PresentationHostProxy.dll
2010-06-23 13:34:38 49472 ----a-w- c:\windows\syswow64\netfxperf.dll
2010-06-23 13:34:38 48960 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 13:34:38 444752 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 13:34:38 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 13:34:38 297808 ----a-w- c:\windows\syswow64\mscoree.dll
2010-06-23 13:34:38 295264 ----a-w- c:\windows\syswow64\PresentationHost.exe
2010-06-23 13:34:38 1942856 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 13:34:38 1130824 ----a-w- c:\windows\syswow64\dfshim.dll
2010-06-23 13:34:38 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 13:33:38 1736608 ----a-w- c:\windows\system32\ntdll.dll
2010-06-23 13:33:38 1289528 ----a-w- c:\windows\syswow64\ntdll.dll
2010-06-23 13:33:34 961024 ----a-w- c:\windows\system32\CPFilters.dll
2010-06-23 13:33:34 641536 ----a-w- c:\windows\syswow64\CPFilters.dll
2010-06-23 13:33:33 552960 ----a-w- c:\windows\system32\msdri.dll
2010-06-23 13:33:33 288256 ----a-w- c:\windows\system32\MSNP.ax
2010-06-23 13:33:33 258560 ----a-w- c:\windows\system32\mpg2splt.ax
2010-06-23 13:33:33 204288 ----a-w- c:\windows\syswow64\MSNP.ax
2010-06-23 13:33:33 199680 ----a-w- c:\windows\syswow64\mpg2splt.ax
2010-06-20 19:03:23 0 d-----w- c:\program files\iTunes
2010-06-20 19:03:23 0 d-----w- c:\program files\iPod
2010-06-20 19:03:23 0 d-----w- c:\program files (x86)\iTunes
2010-06-20 19:01:55 0 d-----w- c:\program files\Bonjour
2010-06-20 19:01:55 0 d-----w- c:\program files (x86)\Bonjour
==================== Find3M ====================
2010-07-18 19:02:39 756624 ----a-w- c:\windows\system32\perfh00C.dat
2010-07-18 19:02:39 695108 ----a-w- c:\windows\system32\perfh00E.dat
2010-07-18 19:02:39 489046 ----a-w- c:\windows\system32\perfh001.dat
2010-07-18 19:02:39 389754 ----a-w- c:\windows\system32\prfh0804.dat
2010-07-18 19:02:39 179248 ----a-w- c:\windows\system32\perfc00E.dat
2010-07-18 19:02:39 156360 ----a-w- c:\windows\system32\perfc00C.dat
2010-07-18 19:02:39 126286 ----a-w- c:\windows\system32\prfc0804.dat
2010-07-18 19:02:39 101022 ----a-w- c:\windows\system32\perfc001.dat
2010-07-12 14:22:48 10022 --sha-w- c:\programdata\KGyGaAvL.sys
2010-07-11 20:27:36 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2010-07-11 20:27:36 445016 ----a-w- c:\windows\syswow64\wrap_oal.dll
2010-07-11 20:27:36 122968 ----a-w- c:\windows\system32\OpenAL32.dll
2010-07-11 20:27:36 109144 ----a-w- c:\windows\syswow64\OpenAL32.dll
2010-07-02 13:53:11 168 --sha-r- c:\programdata\CF0AFE3845.sys
2010-06-09 13:13:29 178800 ----a-w- c:\windows\syswow64\CmdLineExt_x64.dll
2010-06-05 10:51:51 108144 ----a-w- c:\windows\syswow64\CmdLineExt.dll
2010-06-04 19:19:13 31548 ----a-w- c:\windows\system32\prfd0804.dat
2010-06-04 19:19:13 31548 ----a-w- c:\windows\inf\perflib\0804\perfd.dat
2010-06-04 19:19:13 31548 ----a-w- c:\windows\inf\perflib\0804\perfc.dat
2010-06-04 19:19:13 111310 ----a-w- c:\windows\system32\prfi0804.dat
2010-06-04 19:19:13 111310 ----a-w- c:\windows\inf\perflib\0804\perfi.dat
2010-06-04 19:19:13 111310 ----a-w- c:\windows\inf\perflib\0804\perfh.dat
2010-05-30 14:02:32 99384 ----a-w- c:\users\dan\appdata\roaming\inst.exe
2010-05-30 14:02:32 82816 ----a-w- c:\users\dan\appdata\roaming\pcouffin.sys
2010-05-27 07:24:13 34304 ----a-w- c:\windows\syswow64\atmlib.dll
2010-05-27 06:34:09 46080 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 04:11:32 366080 ----a-w- c:\windows\system32\atmfd.dll
2010-05-27 03:49:37 293888 ----a-w- c:\windows\syswow64\atmfd.dll
2010-05-21 13:14:28 270208 ----a-w- c:\windows\system32\MpSigStub.exe
2010-05-21 05:52:30 1192960 ----a-w- c:\windows\system32\wininet.dll
2010-05-21 05:18:06 977920 ----a-w- c:\windows\syswow64\wininet.dll
2010-05-21 05:14:50 48128 ----a-w- c:\windows\syswow64\jsproxy.dll
2010-05-18 15:55:18 95520 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 15:55:18 119584 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-18 15:35:16 91424 ----a-w- c:\windows\syswow64\dnssd.dll
2010-05-18 15:35:16 107808 ----a-w- c:\windows\syswow64\dns-sd.exe
2010-05-06 12:42:05 1225216 ----a-w- c:\windows\syswow64\urlmon.dll
2010-05-06 12:41:55 606208 ----a-w- c:\windows\syswow64\mstime.dll
2010-05-06 12:41:53 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2010-05-06 12:41:53 5970944 ----a-w- c:\windows\syswow64\mshtml.dll
2010-05-06 12:41:49 381440 ----a-w- c:\windows\syswow64\iedkcs32.dll
2010-05-06 12:41:49 10984448 ----a-w- c:\windows\syswow64\ieframe.dll
2010-05-05 02:43:40 19735040 ----a-w- c:\windows\system32\atio6axx.dll
2010-05-05 02:19:48 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-05-05 02:19:38 506880 ----a-w- c:\windows\syswow64\aticfx32.dll
2010-05-05 02:18:36 584704 ----a-w- c:\windows\system32\aticfx64.dll
2010-05-05 02:16:04 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-05-05 02:15:56 455168 ----a-w- c:\windows\system32\atieclxx.exe
2010-05-05 02:15:10 202752 ----a-w- c:\windows\system32\atiesrxx.exe
2010-05-05 02:14:44 15024128 ----a-w- c:\windows\syswow64\atioglxx.dll
2010-05-05 02:13:38 120320 ----a-w- c:\windows\system32\atitmm64.dll
2010-05-05 02:13:20 421376 ----a-w- c:\windows\system32\atipdl64.dll
2010-05-05 02:13:10 356352 ----a-w- c:\windows\syswow64\atipdlxx.dll
2010-05-05 02:12:56 278528 ----a-w- c:\windows\syswow64\Oemdspif.dll
2010-05-05 02:12:50 12288 ----a-w- c:\windows\system32\atimuixx.dll
2010-05-05 02:12:44 59392 ----a-w- c:\windows\system32\atiedu64.dll
2010-05-05 02:12:36 43520 ----a-w- c:\windows\syswow64\ati2edxx.dll
2010-05-05 02:08:46 3611648 ----a-w- c:\windows\syswow64\atidxx32.dll
2010-05-05 01:56:30 4225536 ----a-w- c:\windows\system32\atidxx64.dll
2010-05-05 01:41:48 3788288 ----a-w- c:\windows\syswow64\atiumdag.dll
2010-05-05 01:41:12 43008 ----a-w- c:\windows\system32\aticalrt64.dll
2010-05-05 01:41:10 53248 ----a-w- c:\windows\syswow64\aticalrt.dll
2010-05-05 01:41:02 39936 ----a-w- c:\windows\system32\aticalcl64.dll
2010-05-05 01:41:00 53248 ----a-w- c:\windows\syswow64\aticalcl.dll
2010-05-05 01:40:50 5194752 ----a-w- c:\windows\system32\aticaldd64.dll
2010-05-05 01:38:58 4022272 ----a-w- c:\windows\syswow64\aticaldd.dll
2010-05-05 01:35:00 55296 ----a-w- c:\windows\system32\coinst.dll
2010-05-05 01:33:24 4902400 ----a-w- c:\windows\system32\atiumd64.dll
2010-05-05 01:24:38 2738176 ----a-w- c:\windows\system32\atiumd6a.dll
2010-05-05 01:24:02 334336 ----a-w- c:\windows\system32\atiadlxx.dll
2010-05-05 01:23:52 237568 ----a-w- c:\windows\syswow64\atiadlxy.dll
2010-05-05 01:23:40 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2010-05-05 01:23:36 12800 ----a-w- c:\windows\syswow64\atiglpxx.dll
2010-05-05 01:23:36 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-05-05 01:23:32 16384 ----a-w- c:\windows\system32\atig6txx.dll
2010-05-05 01:23:28 15360 ----a-w- c:\windows\syswow64\atigktxx.dll
2010-05-05 01:22:36 36864 ----a-w- c:\windows\system32\atiuxp64.dll
2010-05-05 01:22:26 28160 ----a-w- c:\windows\syswow64\atiuxpag.dll
2010-05-05 01:22:20 28160 ----a-w- c:\windows\system32\atiu9p64.dll
2010-05-05 01:22:12 20480 ----a-w- c:\windows\syswow64\atiu9pag.dll
2010-05-05 01:19:16 3015680 ----a-w- c:\windows\syswow64\atiumdva.dll
2010-05-05 01:08:42 53248 ----a-w- c:\windows\system32\atimpc64.dll
2010-05-05 01:08:42 53248 ----a-w- c:\windows\system32\amdpcom64.dll
2010-05-05 01:08:38 52224 ----a-w- c:\windows\syswow64\atimpc32.dll
2010-05-05 01:08:38 52224 ----a-w- c:\windows\syswow64\amdpcom32.dll
2010-05-01 15:07:05 3122176 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 14:23:43 138432 ---ha-w- c:\windows\syswow64\mlfcache.dat
2010-04-28 21:17:50 2110 ----a-w- c:\windows\syswow64\atipblag.dat
2010-04-28 21:17:50 2110 ----a-w- c:\windows\system32\atipblag.dat
2010-04-28 04:23:07 103736 ----a-w- c:\windows\syswow64\PnkBstrB.exe
2010-04-28 04:21:06 669184 ----a-w- c:\windows\syswow64\pbsvc.exe
2010-04-28 04:21:06 66872 ----a-w- c:\windows\syswow64\PnkBstrA.exe
2010-04-27 13:45:56 72856 ----a-w- c:\windows\syswow64\xliveinstallhost.exe
2010-04-27 13:45:56 187544 ----a-w- c:\windows\syswow64\xliveinstall.dll
2010-04-23 07:13:36 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-04-23 07:11:58 2048 ----a-w- c:\windows\system32\tzres.dll
2010-03-31 14:13:38 42056 ----a-w- c:\windows\inf\perflib\0401\perfd.dat
2010-03-31 14:13:38 42056 ----a-w- c:\windows\inf\perflib\0401\perfc.dat
2010-03-31 14:13:38 38160 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
2010-03-31 14:13:38 38160 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2010-03-02 19:44:19 245760 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-02-17 17:27:49 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 20:41:33.94 ===============