Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: computer keep logging off  (Read 44118 times)

0 Members and 1 Guest are viewing this topic.

shoyou

    Topic Starter


    Beginner

    computer keep logging off
    « on: May 05, 2010, 09:51:50 PM »
    i do not know if this is the cause of a virus, but i did read somewhere that this problem can also be cause by viruses.

    My computer keep logging off when i log on. As soon as i type my password, it will log off.
    so far i went to F8 and try to stop it from turning off atomically so i can get a blue screen of death, but i couldn't get one. i don't have the CD to reinstall.
    it's been like this for a week already, if pass this week, it's 2 week. i have been looking for help, but the help all deal with the CD which i do not have or can not borrow.

    The day before this happen, everything was normal. so i don't know what may be the cause of this.

    Dr Jay

    • Malware Removal Specialist


    • Specialist
    • Moderator emeritus
    • Thanked: 119
    • Experience: Guru
    • OS: Windows 10
    Re: computer keep logging off
    « Reply #1 on: May 06, 2010, 07:56:13 AM »
    Please visit this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.
    ~Dr Jay

    shoyou

      Topic Starter


      Beginner

      Re: computer keep logging off
      « Reply #2 on: May 06, 2010, 08:33:39 PM »
      Please visit this webpage for a tutorial on downloading and running ComboFix:

      http://www.bleepingcomputer.com/combofix/how-to-use-combofix

      See the area: Using ComboFix, and when done, post the log back here.
      can't, computer wont open. as i said, it keep logging off when i log in.

      Dr Jay

      • Malware Removal Specialist


      • Specialist
      • Moderator emeritus
      • Thanked: 119
      • Experience: Guru
      • OS: Windows 10
      Re: computer keep logging off
      « Reply #3 on: May 06, 2010, 11:36:02 PM »
      Oh ok.

      Do this please:

      First
      ISOBurner this will allow you to burn OTLPE ISO to a cd and make it bootable. Just install the program, from there on in it is fairly automatic.  Instructions

      Second
      • Download OTLPE.iso and burn to a CD using ISO Burner. NOTE: This file is 292Mb in size so it may take some time to download.
      • When downloaded double click and this will then open ISOBurner to burn the file to CD
      • Reboot your system using the boot CD you just created.
      Note : If you do not know how to set your computer to boot from CD follow the steps here
      • Your system should now display a REATOGO-X-PE desktop.
      • Double-click on the OTLPE icon.
      • When asked "Do you wish to load the remote registry", select Yes
      • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
      • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
      • OTL should now start. Change the following settings
      • Change Drivers to Non-Microsoft
      • Press Run Scan to start the scan.
      • When finished, the file will be saved  in drive C:\_OTL\MovedFiles
      • Copy this file to your USB drive if you do not have internet connection on this system
      • Please post the contents of the OTL.txt file in your reply.
      [/list]
      ~Dr Jay

      shoyou

        Topic Starter


        Beginner

        Re: computer keep logging off
        « Reply #4 on: May 07, 2010, 06:44:55 PM »
        Oh ok.

        Do this please:

        First
        ISOBurner this will allow you to burn OTLPE ISO to a cd and make it bootable. Just install the program, from there on in it is fairly automatic.  Instructions

        Second
        • Download OTLPE.iso and burn to a CD using ISO Burner. NOTE: This file is 292Mb in size so it may take some time to download.
        • When downloaded double click and this will then open ISOBurner to burn the file to CD
        • Reboot your system using the boot CD you just created.
        Note : If you do not know how to set your computer to boot from CD follow the steps here
        • Your system should now display a REATOGO-X-PE desktop.
        • Double-click on the OTLPE icon.
        • When asked "Do you wish to load the remote registry", select Yes
        • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
        • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
        • OTL should now start. Change the following settings
        • Change Drivers to Non-Microsoft
        • Press Run Scan to start the scan.
        • When finished, the file will be saved  in drive C:\_OTL\MovedFiles
        • Copy this file to your USB drive if you do not have internet connection on this system
        • Please post the contents of the OTL.txt file in your reply.
        [/list]

        i see driver, but i don't see Non-Microsof.
        the choice are none, all, and use safelist.

        Dr Jay

        • Malware Removal Specialist


        • Specialist
        • Moderator emeritus
        • Thanked: 119
        • Experience: Guru
        • OS: Windows 10
        Re: computer keep logging off
        « Reply #5 on: May 08, 2010, 08:05:50 AM »
        OK. Any options you can use, go ahead.
        ~Dr Jay

        shoyou

          Topic Starter


          Beginner

          Re: computer keep logging off
          « Reply #6 on: May 09, 2010, 08:51:41 AM »
          attachment. split it into two file cause the file was too big.

          [recovering disk space - old attachment deleted by admin]

          Dr Jay

          • Malware Removal Specialist


          • Specialist
          • Moderator emeritus
          • Thanked: 119
          • Experience: Guru
          • OS: Windows 10
          Re: computer keep logging off
          « Reply #7 on: May 09, 2010, 11:43:07 AM »
          Sorry, but please copy and paste it in to the board in bits, and use multiple posts to get all the info in.
          ~Dr Jay

          shoyou

            Topic Starter


            Beginner

            Re: computer keep logging off
            « Reply #8 on: May 09, 2010, 12:50:29 PM »
            OTL logfile created on: 5/8/2010 11:21:19 PM - Run
            OTLPE by OldTimer - Version 3.1.23.0     Folder = X:\Programs\OTLPE
            Windows XP Professional Edition  (Version = 5.1.2600) - Type = NTWorkstation
            Internet Explorer (Version = 8.0.6001.18702)
            Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
             
            1,022.00 Mb Total Physical Memory | 786.00 Mb Available Physical Memory | 77.00% Memory free
            925.00 Mb Paging File | 847.00 Mb Available in Paging File | 92.00% Paging File free
            Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
             
            %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
            Drive C: | 108.59 Gb Total Space | 78.99 Gb Free Space | 72.75% Space Free | Partition Type: NTFS
            Drive D: | 36.31 Gb Total Space | 1.12 Gb Free Space | 3.07% Space Free | Partition Type: NTFS
            E: Drive not present or media not loaded
            F: Drive not present or media not loaded
            G: Drive not present or media not loaded
            H: Drive not present or media not loaded
            I: Drive not present or media not loaded
            Drive X: | 272.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

            shoyou

              Topic Starter


              Beginner

              Re: computer keep logging off
              « Reply #9 on: May 09, 2010, 12:50:55 PM »
              Computer Name: REATOGO
              Current User Name: SYSTEM
              Logged in as Administrator.
               
              Current Boot Mode: Normal
              Scan Mode: All users
              Company Name Whitelist: Off
              Skip Microsoft Files: Off
              File Age = 30 Days
              Output = Standard
               
              ========== Win32 Services (SafeList) ==========
               
              SRV - [2010/01/31 20:44:19 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
              SRV - [2009/12/08 18:25:28 | 00,093,320 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
              SRV - [2009/11/04 20:53:34 | 00,144,704 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
              SRV - [2009/11/04 19:59:50 | 00,606,736 | ---- | M] (McAfee, Inc.) [On_Demand] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
              SRV - [2009/10/29 10:54:44 | 00,865,832 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
              SRV - [2009/10/28 15:50:32 | 00,365,072 | ---- | M] (McAfee, Inc.) [On_Demand] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
              SRV - [2009/10/27 15:19:46 | 00,895,696 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
              SRV - [2009/10/02 17:02:56 | 00,026,640 | ---- | M] (McAfee, Inc.) [Auto] -- C:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service)
              SRV - [2009/07/08 15:54:34 | 00,359,952 | ---- | M] (McAfee, Inc.) [Auto] -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
              SRV - [2009/07/07 23:10:02 | 02,482,848 | ---- | M] (McAfee, Inc.) [Auto] -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
              SRV - [2009/07/07 18:48:44 | 00,647,216 | ---- | M] (Cisco Systems, Inc.) [Auto] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
              SRV - [2009/02/10 12:01:49 | 00,116,104 | ---- | M] () [Auto] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
              SRV - [2008/12/18 14:47:08 | 09,158,656 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe -- (MSSQL$MICROSOFTSMLBIZ)
              SRV - [2008/07/10 12:23:26 | 00,053,032 | ---- | M] (Nero AG) [Auto] -- C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe -- (NeroRegInCDSrv)
              SRV - [2008/07/10 12:23:16 | 01,442,088 | ---- | M] (Nero AG) [Auto] -- C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe -- (InCDsrv)
              SRV - [2008/06/24 19:05:56 | 00,537,896 | ---- | M] (Nero AG) [On_Demand] -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
              SRV - [2007/11/07 01:16:54 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) [On_Demand] -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08)
              SRV - [2007/11/07 01:16:54 | 00,139,264 | ---- | M] (Hewlett-Packard Co.) [Auto] -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc)
              SRV - [2006/05/30 09:57:48 | 00,822,424 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)
              SRV - [2005/12/07 17:05:34 | 02,066,072 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Norton Ghost\Agent\VProSvc.exe -- (Norton Ghost)
              SRV - [2005/12/07 17:05:12 | 00,053,248 | ---- | M] (GEAR Software) [Auto] -- C:\WINDOWS\system32\gearsec.exe -- (GEARSecurity)
              SRV - [2005/05/03 22:42:56 | 00,323,584 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE -- (SQLAgent$MICROSOFTSMLBIZ)
              SRV - [2004/12/13 16:30:10 | 00,165,488 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
              SRV - [2004/12/13 16:30:08 | 00,079,472 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc)
              SRV - [2004/12/13 16:30:04 | 00,198,256 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
              SRV - [2004/04/07 13:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) [Disabled] -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS)
              SRV - [2003/12/17 14:59:48 | 00,143,360 | ---- | M] (Intel(R) Corporation) [On_Demand] -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc)
              SRV - [2003/07/28 13:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
               

              shoyou

                Topic Starter


                Beginner

                Re: computer keep logging off
                « Reply #10 on: May 09, 2010, 12:51:19 PM »
                ========== Driver Services (SafeList) ==========
                 
                DRV - File not found [Kernel | On_Demand] --  -- (XDva332)
                DRV - File not found [Kernel | On_Demand] --  -- (WDICA)
                DRV - File not found [Kernel | On_Demand] --  -- (PDRFRAME)
                DRV - File not found [Kernel | On_Demand] --  -- (PDRELI)
                DRV - File not found [Kernel | On_Demand] --  -- (PDFRAME)
                DRV - File not found [Kernel | On_Demand] --  -- (PDCOMP)
                DRV - File not found [Kernel | System] --  -- (PCIDump)
                DRV - File not found [Kernel | System] --  -- (lbrtfdc)
                DRV - File not found [Kernel | System] --  -- (Changer)
                DRV - File not found [Kernel | On_Demand] --  -- (catchme)
                DRV - File not found [Kernel | On_Demand] --  -- (aec)
                DRV - [2010/05/02 22:01:59 | 00,096,512 | ---- | M] () [Kernel | Boot] -- C:\WINDOWS\system32\drivers\atapi.sys -- (atapi)
                DRV - [2010/04/30 18:55:33 | 00,004,736 | ---- | M] () [Kernel | Auto] -- C:\WINDOWS\system32\o.sys -- (k)
                DRV - [2010/02/28 13:51:26 | 00,047,360 | ---- | M] (VSO Software) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\pcouffin.sys -- (pcouffin)
                DRV - [2010/02/28 13:50:50 | 00,018,816 | ---- | M] (RIF) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\dvd43llh.sys -- (dvd43llh)
                DRV - [2010/02/20 14:20:41 | 00,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
                DRV - [2010/02/20 14:20:40 | 00,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
                DRV - [2010/02/20 14:20:40 | 00,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
                DRV - [2009/11/04 20:54:12 | 00,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
                DRV - [2009/11/04 20:54:12 | 00,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
                DRV - [2009/11/04 20:54:12 | 00,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfesmfk.sys -- (mfesmfk)
                DRV - [2009/11/04 20:54:12 | 00,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
                DRV - [2009/11/04 20:53:40 | 00,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\mferkdk.sys -- (mferkdk)
                DRV - [2009/10/29 23:49:30 | 00,024,576 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto] -- C:\Program Files\GameTap Web Player\bin\release\X4HSX32.sys -- (X4HSX32)
                DRV - [2009/07/16 16:32:26 | 00,120,136 | ---- | M] (McAfee, Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\Mpfp.sys -- (MPFP)
                DRV - [2009/07/07 18:48:44 | 00,026,672 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\purendis.sys -- (purendis)
                DRV - [2009/07/07 18:48:44 | 00,025,392 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\pnarp.sys -- (pnarp)
                DRV - [2008/07/10 12:23:14 | 00,040,488 | ---- | M] (Nero AG) [Kernel | System] -- C:\WINDOWS\system32\drivers\InCDRm.sys -- (incdrm)
                DRV - [2008/07/10 12:23:14 | 00,038,952 | ---- | M] (Nero AG) [Kernel | System] -- C:\WINDOWS\system32\drivers\InCDPass.sys -- (InCDPass)
                DRV - [2008/07/10 12:23:14 | 00,018,088 | ---- | M] (Nero AG) [Recognizer | System] -- C:\WINDOWS\system32\drivers\InCDrec.sys -- (InCDRec)
                DRV - [2008/07/10 12:23:04 | 00,128,424 | ---- | M] (Nero AG) [File_System | Disabled] -- C:\WINDOWS\system32\drivers\InCDfs.sys -- (InCDfs)
                DRV - [2008/04/13 14:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
                DRV - [2008/04/13 14:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
                DRV - [2008/04/13 12:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
                DRV - [2006/05/30 09:57:48 | 00,004,608 | ---- | M] (Symantec Corporation) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd)
                DRV - [2005/12/07 17:05:26 | 00,144,880 | ---- | M] (StorageCraft) [File_System | Boot] -- C:\WINDOWS\system32\drivers\SymSnap.sys -- (SymSnap)
                DRV - [2005/12/07 17:05:24 | 00,056,240 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\WINDOWS\system32\drivers\V2iMount.sys -- (V2IMount)
                DRV - [2005/12/07 17:05:12 | 00,014,408 | ---- | M] (GEAR Software Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GearAspiWDM)
                DRV - [2005/09/12 04:30:00 | 00,089,264 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\DRVMCDB.SYS -- (DRVMCDB)
                DRV - [2005/09/08 06:20:00 | 00,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
                DRV - [2005/09/08 06:20:00 | 00,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
                DRV - [2005/09/08 06:20:00 | 00,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
                DRV - [2005/09/08 06:20:00 | 00,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
                DRV - [2005/09/08 06:20:00 | 00,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
                DRV - [2005/09/08 06:20:00 | 00,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
                DRV - [2005/09/08 06:20:00 | 00,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
                DRV - [2005/08/25 13:16:52 | 00,005,628 | ---- | M] (Sonic Solutions) [File_System | System] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
                DRV - [2005/08/25 13:16:16 | 00,022,684 | ---- | M] (Sonic Solutions) [File_System | System] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
                DRV - [2005/08/16 17:18:40 | 00,080,640 | ---- | M] (McAfee) [Kernel | System] -- C:\WINDOWS\system32\drivers\MpFirewall.sys -- (MPFIREWL)
                DRV - [2005/08/12 06:20:00 | 00,040,544 | ---- | M] (Sonic Solutions) [File_System | Auto] -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
                DRV - [2005/04/25 03:03:00 | 00,020,640 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20)
                DRV - [2005/04/05 20:46:28 | 00,830,684 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm)
                DRV - [2005/03/22 18:08:40 | 00,260,224 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm)
                DRV - [2004/09/17 15:02:54 | 00,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
                DRV - [2004/08/04 06:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
                DRV - [2004/08/04 06:00:00 | 00,008,832 | ---- | M] () [Kernel | System] -- C:\WINDOWS\system32\drivers\rasacd.sys -- (RasAcd)
                DRV - [2004/08/04 06:00:00 | 00,007,936 | ---- | M] (Microsoft Corporation) [Recognizer | System] -- C:\WINDOWS\system32\drivers\fs_rec.sys -- (Fs_Rec)
                DRV - [2004/08/04 06:00:00 | 00,002,864 | ---- | M] (Microsoft Corporation) [Adapter | On_Demand] -- C:\WINDOWS\system32\winsock.dll -- (Winsock)
                DRV - [2004/08/03 23:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
                DRV - [2004/02/10 21:49:14 | 00,154,112 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\e100b325.sys -- (E100B) Intel(R)
                DRV - [2003/01/10 17:13:04 | 00,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
                DRV - [2001/08/17 15:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
                DRV - [2001/08/17 15:07:42 | 00,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
                DRV - [2001/08/17 15:07:40 | 00,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
                DRV - [2001/08/17 15:07:36 | 00,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
                DRV - [2001/08/17 15:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
                DRV - [2001/08/17 14:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
                DRV - [2001/08/17 14:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
                DRV - [2001/08/17 14:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
                DRV - [2001/08/17 14:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
                DRV - [2001/08/17 14:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
                DRV - [2001/08/17 14:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
                DRV - [2001/08/17 14:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
                DRV - [2001/08/17 14:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
                DRV - [2001/08/17 14:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
                DRV - [2001/08/17 14:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
                 
                 
                ========== Standard Registry (SafeList) ==========
                 
                 
                ========== Internet Explorer ==========
                 
                IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
                IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
                 
                 
                IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
                IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
                IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-inc/en/side.html?channel=us
                IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
                IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
                 
                IE - HKU\DEFAULT_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
                IE - HKU\DEFAULT_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
                IE - HKU\DEFAULT_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE8ENUS/701
                IE - HKU\DEFAULT_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
                IE - HKU\DEFAULT_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = www.bing.com [binary data]
                IE - HKU\DEFAULT_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
                IE - HKU\DEFAULT_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
                 
                IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
                 
                IE - HKU\shon_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
                IE - HKU\shon_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
                IE - HKU\shon_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
                IE - HKU\shon_ON_C\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
                IE - HKU\shon_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
                 
                FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/04/21 20:52:01 | 00,000,000 | ---D | M]
                FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\MyWebSearch\bar\1.bin File not found
                FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/02 18:51:34 | 00,000,000 | ---D | M]
                FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/02 18:51:34 | 00,000,000 | ---D | M]
                 
                [2010/04/29 02:54:30 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
                [2010/03/19 16:28:09 | 00,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
                [2010/02/27 17:32:43 | 00,002,191 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml

                shoyou

                  Topic Starter


                  Beginner

                  Re: computer keep logging off
                  « Reply #11 on: May 09, 2010, 12:51:38 PM »
                   
                  O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
                  O1 - Hosts: 127.0.0.1       localhost
                  O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
                  O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
                  O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
                  O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\real\realplayer\rpbrowserrecordplugin.dll (RealPlayer)
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
                  O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
                  O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
                  O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
                  O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll (Dell Inc.)
                  O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
                  O2 - BHO: (no name) - {d3df614d-7ecc-4b00-a669-fba8f1f033b3} -  File not found
                  O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
                  O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
                  O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
                  O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
                  O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
                  O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O3 - HKU\DEFAULT_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O3 - HKU\shon_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
                  O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
                  O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe ()
                  O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe File not found
                  O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
                  O4 - HKLM..\Run: [MPFExe] C:\Program Files\McAfee.com\Personal Firewall\MpfTray.exe ()
                  O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe ()
                  O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe ()
                  O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
                  O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask .exe ()
                  O4 - HKLM..\Run: [smss32.exe] C:\WINDOWS\System32\smss32.exe File not found
                  O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe ()
                  O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe ()
                  O4 - HKU\Administrator_ON_C..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe ()
                  O4 - HKU\DEFAULT_ON_C..\Run: [smss32.exe] C:\WINDOWS\System32\smss32.exe File not found
                  O4 - HKU\shon_ON_C..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe ()
                  O4 - HKU\shon_ON_C..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe ()
                  O4 - HKU\shon_ON_C..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe ()
                  O4 - HKU\shon_ON_C..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ()
                  O4 - HKU\Administrator_ON_C..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Nero\Lib\NMFirstStart.exe (Nero AG)
                  O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
                  O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
                  O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
                  O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
                  O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
                  O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
                  O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
                  O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
                  O7 - HKU\DEFAULT_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
                  O7 - HKU\DEFAULT_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
                  O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
                  O7 - HKU\shon_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
                  O7 - HKU\shon_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
                  O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
                  O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\shon\Start Menu\Programs\IMVU\Run IMVU.lnk ()
                  O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
                  O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ()
                  O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ()
                  O15 - HKLM\..Trusted Domains: buy-security-essentials.com ([]http in Trusted sites)
                  O15 - HKLM\..Trusted Domains: get-key-se10.com ([]http in Trusted sites)
                  O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
                  O15 - HKU\DEFAULT_ON_C\..Trusted Domains: buy-security-essentials.com ([]http in Trusted sites)
                  O15 - HKU\DEFAULT_ON_C\..Trusted Domains: download-soft-package.com ([]http in Trusted sites)
                  O15 - HKU\DEFAULT_ON_C\..Trusted Domains: download-software-package.com ([]http in Trusted sites)
                  O15 - HKU\DEFAULT_ON_C\..Trusted Domains: get-key-se10.com ([]http in Trusted sites)
                  O15 - HKU\DEFAULT_ON_C\..Trusted Domains: is-software-download.com ([]http in Trusted sites)
                  O15 - HKU\shon_ON_C\..Trusted Domains: moove.com ([]* in Trusted sites)
                  O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab (Reg Error: Key error.)
                  O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
                  O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} http://archives.gametap.com/static/cab_headless/GameTapWebUpdater.cab (GameTap Web Updater)
                  O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_03-windows-i586.cab (Java Plug-in 1.4.2_03)
                  O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
                  O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
                  O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}  (Reg Error: Value error.)
                  O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
                  O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
                  O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
                  O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
                  O18 - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
                  O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
                  O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
                  O20 - AppInit_DLLs: (vukotuja.dll) -  File not found
                  O20 - AppInit_DLLs: (lusanuwo.dll) -  File not found
                  O20 - AppInit_DLLs: (c:\windows\system32\bufufodu.dll) - C:\WINDOWS\System32\bufufodu.dll File not found
                  O20 - AppInit_DLLs: (pirotima.dll) -  File not found
                  O20 - AppInit_DLLs: (c:\windows\system32\kitejiru.dll) - C:\WINDOWS\System32\kitejiru.dll File not found
                  O20 - AppInit_DLLs: (c:\windows\system32\jeyiniyo.dll) - C:\WINDOWS\System32\jeyiniyo.dll File not found
                  O20 - AppInit_DLLs: (c:\windows\system32\lazimiki.dll) - C:\WINDOWS\System32\lazimiki.dll File not found
                  O20 - AppInit_DLLs: (gogiyajo.dll) -  File not found
                  O20 - AppInit_DLLs: (c:\windows\system32\fuvatozi.dll) - C:\WINDOWS\System32\fuvatozi.dll File not found
                  O20 - AppInit_DLLs: (yoyudoka.dll) -  File not found
                  O20 - AppInit_DLLs: (c:\windows\system32\fetunigu.dll) - C:\WINDOWS\System32\fetunigu.dll File not found
                  O20 - AppInit_DLLs: (c:\windows\) - c:\windows\ [2010/05/03 18:53:16 | 00,000,000 | ---D | M]
                  O20 - AppInit_DLLs: (c:\windows\system32\fiyobubi.dll) - C:\WINDOWS\System32\fiyobubi.dll File not found
                  O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
                  O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\winlogon32.exe) - C:\WINDOWS\System32\winlogon32.exe File not found
                  O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
                  O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
                  O27 - HKLM IFEO\MpCmdRun.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
                  O27 - HKLM IFEO\MsMpEng.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
                  O27 - HKLM IFEO\msseces.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
                  O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
                  O32 - HKLM CDRom: AutoRun - 1
                  O32 - AutoRun File - [2004/08/11 18:15:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
                  O32 - AutoRun File - [2006/03/24 07:06:41 | 00,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
                  O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
                  O35 - comfile [open] -- "%1" %*
                  O35 - exefile [open] -- "%1" %*

                  shoyou

                    Topic Starter


                    Beginner

                    Re: computer keep logging off
                    « Reply #12 on: May 09, 2010, 12:52:01 PM »
                    ========== Files/Folders - Created Within (All) ==========
                     
                    [2010/05/08 22:54:15 | 00,000,000 | R--D | C] -- B:\Documents and Settings\Default User\My Documents\My Pictures
                    [2010/05/08 22:54:15 | 00,000,000 | R--D | C] -- B:\Documents and Settings\Default User\My Documents\My Music
                    [2010/05/08 22:54:15 | 00,000,000 | ---D | C] -- B:\Documents and Settings\Default User\My Documents\My Videos
                    [2010/04/30 18:57:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\McAfee.com Personal Firewall
                    [2010/04/30 18:56:12 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\NetworkService\SendTo
                    [2010/04/30 18:55:39 | 00,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\My Documents\My Pictures
                    [2010/04/30 18:55:39 | 00,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\My Documents\My Music
                    [2010/04/30 18:55:37 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\NetworkService\Recent
                    [2010/04/30 18:55:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Start Menu
                    [2010/04/30 18:55:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Desktop
                    [2010/04/30 18:55:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Real
                    [2010/04/27 20:32:27 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\LocalService\IETldCache
                    [2010/04/23 22:38:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\avG
                    [2010/04/22 21:24:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Identities
                    [2010/04/22 21:24:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Identities
                    [2010/04/18 03:59:47 | 31,971,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
                    [2010/04/17 01:04:29 | 00,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\Favorites
                    [2010/04/15 20:54:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
                    [2010/04/15 19:41:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
                    [2010/04/15 19:41:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
                    [2010/04/15 19:41:45 | 00,000,000 | R--D | C] -- C:\Documents and Settings\NetworkService\My Documents
                    [2010/04/15 19:41:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\My Documents\My eBooks
                    [2010/04/15 04:09:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
                    [2010/04/15 04:09:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
                    [2010/04/11 19:59:37 | 00,000,000 | -H-D | C] -- C:\WINDOWS\PIF
                    [2010/03/26 21:19:26 | 00,000,000 | -HSD | C] -- C:\found.000
                    [2010/03/23 19:24:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
                    [2010/03/23 19:22:27 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
                    [2010/03/23 19:22:27 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
                    [2010/03/23 19:22:27 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
                    [2010/03/23 19:22:27 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
                    [2010/03/23 19:22:26 | 00,000,000 | ---D | C] -- C:\d6ef64f95ba9b0ce2e64658ea75f85
                    [2010/03/22 22:58:33 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\CanonIJ Uninstaller Information
                    [2010/03/20 03:33:10 | 00,237,568 | ---- | C] (moove (www.moove.com)) -- C:\WINDOWS\System32\demoover.exe
                    [2010/03/20 03:32:51 | 00,000,000 | ---D | C] -- C:\moove
                    [2010/03/19 19:35:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
                    [2010/03/19 18:23:39 | 00,000,000 | ---D | C] -- C:\gPotato
                    [2010/03/13 14:25:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\Graboid
                    [2010/03/09 19:54:30 | 03,558,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
                    [2010/03/06 02:03:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\.jagex_cache_32
                    [2010/03/05 21:43:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\SmitfraudFix
                    [2010/02/28 13:51:26 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\shon\Application Data\pcouffin.sys
                    [2010/02/28 13:51:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\PcSetup
                    [2010/02/15 13:54:31 | 00,000,000 | ---D | C] -- C:\GameHouse Games
                    [2010/02/14 23:25:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
                    [2010/02/12 00:33:11 | 00,100,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\6to4svc.dll
                    [2010/02/03 21:20:52 | 00,000,000 | -HSD | C] -- C:\RECYCLER
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-TW
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\zh-HK
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\tr-TR
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\sv-SE
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\pt-BR
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\nl-NL
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\nb-NO
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ko-KR
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\it-IT
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\he-IL
                    [2010/02/03 03:11:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\fr-FR
                    [2010/02/03 03:11:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\fi-FI
                    [2010/02/03 03:11:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\es-ES
                    [2010/02/03 03:11:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\el-GR
                    [2010/02/03 03:11:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\de-DE
                    [2010/02/03 03:11:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\da-DK
                    [2010/02/03 03:11:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ar-SA
                    [2010/02/02 22:39:15 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\NetworkService\Cookies
                    [2010/01/31 20:45:29 | 00,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
                    [2010/01/31 20:45:26 | 00,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
                    [2010/01/31 20:45:26 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
                    [2010/01/31 20:45:26 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
                    [2010/01/31 18:49:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
                    [2010/01/30 20:03:05 | 00,046,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\setdebug.exe
                    [2010/01/30 20:02:47 | 00,171,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wjview.exe
                    [2010/01/30 20:02:45 | 00,172,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\jview.exe
                    [2010/01/30 20:02:45 | 00,015,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\jdbgmgr.exe
                    [2010/01/30 20:02:42 | 00,049,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clspack.exe
                    [2010/01/30 20:00:05 | 00,253,952 | ---- | C] (TODO: <Company name>) -- C:\WINDOWS\SBCDSL.exe
                    [2010/01/30 19:43:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\CSC
                    [2010/01/27 22:16:47 | 00,000,000 | ---D | C] -- C:\776aa654f4478a71b30e2f03895ed075
                    [2010/01/27 22:15:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\Desktop\ProcessExplorer
                    [2010/01/26 00:36:58 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbscan.sys
                    [2010/01/24 15:35:30 | 00,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\thawbrkr.dll
                    [2010/01/24 15:35:26 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_iscii.dll
                    [2010/01/24 15:35:22 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdusa.dll
                    [2010/01/24 15:35:13 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftlx041e.dll
                    [2010/01/16 23:10:25 | 00,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
                    [2010/01/16 22:50:25 | 00,000,000 | RHSD | C] -- C:\cmdcons
                    [2010/01/16 22:48:44 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
                    [2010/01/16 22:48:44 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
                    [2010/01/16 22:48:44 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
                    [2010/01/16 22:48:44 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
                    [2010/01/16 22:48:31 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
                    [2010/01/16 22:48:01 | 00,000,000 | ---D | C] -- C:\Qoobox
                    [2010/01/15 16:59:13 | 00,538,624 | R--- | C] (OldTimer Tools) -- C:\OTLPE.exe
                    [2010/01/15 16:59:10 | 00,000,000 | ---D | C] -- C:\_OTL
                    [2010/01/13 10:01:25 | 00,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cabview.dll
                    [2010/01/08 20:24:16 | 00,000,000 | ---D | C] -- C:\spoolerlogs
                    [2010/01/03 03:27:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
                    [2009/12/25 22:54:56 | 00,000,000 | ---D | C] -- C:\Perfect World Entertainment
                    [2009/12/25 03:34:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun
                    [2009/12/24 02:59:40 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wintrust.dll
                    [2009/12/23 16:55:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\hwswchecker
                    [2009/12/22 00:02:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
                    [2009/12/22 00:02:04 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys
                    [2009/12/22 00:01:59 | 00,032,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
                    [2009/12/22 00:01:20 | 00,000,000 | ---D | C] -- C:\Config.Msi
                    [2009/12/16 14:43:27 | 00,343,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspaint.exe
                    [2009/12/15 03:02:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
                    [2009/12/15 02:45:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en
                    [2009/12/15 02:45:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
                    [2009/12/15 02:18:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
                    [2009/12/15 01:04:15 | 00,000,000 | R--D | C] -- C:\Documents and Settings\shon\My Documents\My Videos
                    [2009/12/14 20:38:52 | 00,195,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
                    [2009/12/14 03:34:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\My eBooks
                    [2009/12/14 03:08:23 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\csrsrv.dll
                    [2009/12/09 21:41:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
                    [2009/12/09 21:41:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\l2schemas

                    shoyou

                      Topic Starter


                      Beginner

                      Re: computer keep logging off
                      « Reply #13 on: May 09, 2010, 12:52:18 PM »
                      [2009/12/09 21:33:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
                      [2009/12/09 21:25:58 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
                      [2009/12/08 05:23:28 | 00,474,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shlwapi.dll
                      [2009/12/08 01:45:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\B things
                      [2009/12/08 01:44:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\3.Oneshot
                      [2009/12/08 01:43:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\Y
                      [2009/12/07 22:17:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
                      [2009/12/07 22:08:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\My Received Files
                      [2009/12/07 21:35:49 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
                      [2009/12/06 22:54:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\Airyoran_Gakuen_ch01
                      [2009/12/06 22:47:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\[Fantasy_Shrine]_Airyoran_Gakuen_ch02
                      [2009/12/06 22:43:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\Tracing
                      [2009/12/06 22:12:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\My Documents\Downloads
                      [2009/12/06 22:11:07 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\shon\IECompatCache
                      [2009/12/06 22:09:17 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\shon\PrivacIE
                      [2009/12/06 22:04:22 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\NetworkService\IETldCache
                      [2009/12/06 22:03:29 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\shon\IETldCache
                      [2009/12/06 21:22:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
                      [2009/12/06 21:21:31 | 00,000,000 | ---D | C] -- C:\WINDOWS\WBEM
                      [2009/12/06 21:19:51 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
                      [2009/12/06 21:19:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
                      [2009/12/06 20:57:40 | 00,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
                      [2009/12/06 20:57:32 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
                      [2009/12/06 20:57:32 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
                      [2009/12/06 20:57:31 | 01,985,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
                      [2009/12/06 20:57:31 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
                      [2009/12/06 20:57:30 | 00,247,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
                      [2009/12/06 20:57:28 | 11,070,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
                      [2009/12/06 20:28:40 | 00,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
                      [2009/12/06 20:24:16 | 00,046,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tzchange.exe
                      [2009/12/06 20:19:51 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll
                      [2009/12/06 20:19:51 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcss.dll
                      [2009/12/06 20:19:51 | 00,284,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll
                      [2009/12/06 20:19:51 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe
                      [2009/12/06 20:19:51 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe
                      [2009/12/06 20:19:51 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sc.exe
                      [2009/12/06 20:19:50 | 00,730,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll
                      [2009/12/06 20:19:50 | 00,714,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdll.dll
                      [2009/12/06 20:19:50 | 00,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advapi32.dll
                      [2009/12/06 20:19:50 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll
                      [2009/12/06 20:19:49 | 02,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
                      [2009/12/06 20:19:49 | 02,146,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
                      [2009/12/06 20:19:48 | 02,024,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
                      [2009/12/06 20:19:14 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\triedit.dll
                      [2009/12/06 20:17:18 | 00,128,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dhtmled.ocx
                      [2009/12/06 20:15:20 | 00,203,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rmcast.sys
                      [2009/12/06 20:15:16 | 00,455,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
                      [2009/12/06 20:15:10 | 00,353,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
                      [2009/12/06 20:15:05 | 00,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadce.dll
                      [2009/12/06 20:15:00 | 01,315,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msoe.dll
                      [2009/12/06 20:14:50 | 00,691,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcomm.dll
                      [2009/12/06 20:12:28 | 02,066,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstscax.dll
                      [2009/12/06 20:11:58 | 00,337,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netapi32.dll
                      [2009/12/06 20:11:26 | 01,172,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml3.dll
                      [2009/12/06 19:59:23 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe
                      [2009/12/06 19:56:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\Desktop\desktop items
                      [2009/12/06 19:54:14 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
                      [2009/12/06 19:54:12 | 00,026,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe
                      [2009/12/06 19:41:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
                      [2009/12/06 15:41:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
                      [2009/12/06 15:37:57 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\shon\Application Data
                      [2009/12/06 15:37:57 | 00,000,000 | R--D | C] -- C:\Documents and Settings\shon\Favorites
                      [2009/12/06 15:37:57 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\shon\Cookies
                      [2009/12/06 15:37:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\shon\Desktop
                      [2009/12/06 15:37:56 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\shon\SendTo
                      [2009/12/06 15:37:56 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\shon\Recent
                      [2009/12/06 15:37:56 | 00,000,000 | R--D | C] -- C:\Documents and Settings\shon\Start Menu
                      [2009/12/06 15:37:56 | 00,000,000 | R--D | C] -- C:\Documents and Settings\shon\My Documents\My Pictures
                      [2009/12/06 15:37:56 | 00,000,000 | R--D | C] -- C:\Documents and Settings\shon\My Documents\My Music
                      [2009/12/06 15:37:56 | 00,000,000 | R--D | C] -- C:\Documents and Settings\shon\My Documents
                      [2009/12/06 15:37:56 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\shon\Templates
                      [2009/12/06 15:37:56 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\shon\PrintHood
                      [2009/12/06 15:37:56 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\shon\NetHood
                      [2009/12/06 15:37:56 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\shon\Local Settings
                      [2009/11/27 13:11:44 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msyuv.dll
                      [2009/11/27 12:07:35 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msvidc32.dll
                      [2009/11/27 12:07:35 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsbyuv.dll
                      [2009/11/27 12:07:34 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iyuv_32.dll
                      [2009/11/27 12:07:34 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msrle32.dll
                      [2009/10/21 01:38:36 | 00,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\strmfilt.dll
                      [2009/10/21 01:38:36 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpapi.dll
                      [2009/10/20 12:20:16 | 00,265,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\http.sys
                      [2009/10/13 06:30:16 | 00,270,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oakley.dll
                      [2009/10/12 09:38:19 | 00,149,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rastls.dll
                      [2009/10/12 09:38:18 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\raschap.dll
                      [2009/09/04 17:03:36 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msasn1.dll
                      [2009/08/26 04:16:37 | 00,247,326 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\strmdll.dll
                      [2009/08/14 09:21:25 | 01,850,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
                      [2009/08/06 23:24:12 | 00,015,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaucpl.cpl.mui
                      [2009/08/05 05:01:48 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mswebdvd.dll
                      [2009/07/29 00:37:01 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\t2embed.dll
                      [2009/07/29 00:37:01 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fontsub.dll
                      [2009/07/17 14:55:28 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\atl.dll
                      [2009/07/17 12:22:18 | 01,435,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\query.dll
                      [2009/06/25 14:36:08 | 00,661,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqqm.dll
                      [2009/06/25 14:36:08 | 00,517,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqsnap.dll
                      [2009/06/25 14:36:08 | 00,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqutil.dll
                      [2009/06/25 14:36:08 | 00,225,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqoa.dll
                      [2009/06/25 14:36:08 | 00,186,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqtrig.dll
                      [2009/06/25 14:36:08 | 00,177,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqrt.dll
                      [2009/06/25 14:36:08 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msmqocm.dll
                      [2009/06/25 14:36:08 | 00,138,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqad.dll
                      [2009/06/25 14:36:08 | 00,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqrtdep.dll
                      [2009/06/25 14:36:08 | 00,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqsec.dll
                      [2009/06/25 14:36:08 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqupgrd.dll
                      [2009/06/25 14:36:08 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqdscli.dll
                      [2009/06/25 14:36:08 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqise.dll
                      [2009/06/25 04:25:26 | 00,301,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kerberos.dll
                      [2009/06/25 04:25:26 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msv1_0.dll
                      [2009/06/25 04:25:26 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wdigest.dll
                      [2009/06/24 07:18:41 | 00,092,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksecdd.sys
                      [2009/06/22 07:49:23 | 00,117,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqtgsvc.exe
                      [2009/06/22 07:49:23 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqbkup.exe
                      [2009/06/22 07:49:04 | 00,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqsvc.exe
                      [2009/06/22 07:48:44 | 00,091,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mqac.sys
                      [2009/06/12 08:31:40 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tlntsess.exe
                      [2009/06/12 08:31:39 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\telnet.exe
                      [2009/06/10 10:13:29 | 00,084,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avifil32.dll
                      [2009/06/10 02:14:49 | 00,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wkssvc.dll
                      [2009/05/07 11:32:35 | 00,345,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\localspl.dll
                      [2009/04/15 10:51:25 | 00,585,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcrt4.dll
                      [2009/03/21 10:06:58 | 00,989,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kernel32.dll
                      [2009/03/11 02:18:14 | 00,934,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WgaTray.exe

                      shoyou

                        Topic Starter


                        Beginner

                        Re: computer keep logging off
                        « Reply #14 on: May 09, 2010, 12:52:40 PM »
                        [2009/03/11 02:18:14 | 00,934,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\WgaTray.exe
                        [2009/03/11 02:18:00 | 00,239,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wgaLogon.dll
                        [2009/03/08 18:22:18 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mshta.exe.mui
                        [2009/03/08 18:21:06 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe.mui
                        [2009/03/08 18:09:26 | 00,638,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iexplore.exe
                        [2009/03/08 18:09:26 | 00,387,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
                        [2009/03/08 08:41:16 | 05,944,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
                        [2009/03/08 08:34:58 | 00,916,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
                        [2009/03/08 08:34:56 | 01,209,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
                        [2009/03/08 08:34:52 | 01,469,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
                        [2009/03/08 08:34:48 | 00,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\webcheck.dll
                        [2009/03/08 08:34:48 | 00,208,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WinFXDocObj.exe
                        [2009/03/08 08:34:30 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licmgr10.dll
                        [2009/03/08 08:34:28 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
                        [2009/03/08 08:34:18 | 00,206,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
                        [2009/03/08 08:34:18 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msrating.dll
                        [2009/03/08 08:33:48 | 00,759,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\VGX.dll
                        [2009/03/08 08:33:40 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\corpol.dll
                        [2009/03/08 08:33:26 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
                        [2009/03/08 08:33:16 | 00,726,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jscript.dll
                        [2009/03/08 08:33:08 | 00,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieaksie.dll
                        [2009/03/08 08:33:06 | 00,420,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vbscript.dll
                        [2009/03/08 08:33:02 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieakeng.dll
                        [2009/03/08 08:32:56 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admparse.dll
                        [2009/03/08 08:32:54 | 00,173,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe
                        [2009/03/08 08:32:52 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieakui.dll
                        [2009/03/08 08:32:52 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ieudinit.exe
                        [2009/03/08 08:32:50 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iesetup.dll
                        [2009/03/08 08:32:50 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iernonce.dll
                        [2009/03/08 08:32:48 | 00,128,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advpack.dll
                        [2009/03/08 08:32:46 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inseng.dll
                        [2009/03/08 08:32:04 | 00,611,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
                        [2009/03/08 08:31:56 | 00,184,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
                        [2009/03/08 08:31:54 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedssync.exe
                        [2009/03/08 08:31:44 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtmsft.dll
                        [2009/03/08 08:31:38 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtrans.dll
                        [2009/03/08 08:31:38 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imgutil.dll
                        [2009/03/08 08:31:36 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pngfilt.dll
                        [2009/03/08 08:31:26 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
                        [2009/03/08 08:31:18 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmler.dll
                        [2009/03/08 08:31:02 | 01,638,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.tlb
                        [2009/03/08 08:31:02 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshta.exe
                        [2009/03/08 08:30:56 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdc.ocx
                        [2009/03/08 08:24:28 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hmmapi.dll
                        [2009/03/08 08:22:38 | 00,156,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msls31.dll
                        [2009/02/27 00:56:38 | 00,177,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msctfime.ime
                        [2009/02/07 23:02:58 | 02,066,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
                        [2009/02/07 01:07:58 | 03,698,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ieapfltr.dat
                        [2009/02/03 15:59:07 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\secur32.dll
                        [2009/01/07 22:20:54 | 00,134,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sqmapi.dll
                        [2008/12/16 08:30:34 | 00,354,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winhttp.dll
                        [2008/12/05 02:54:55 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\schannel.dll
                        [2008/10/23 08:36:14 | 00,286,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gdi32.dll
                        [2008/07/30 00:10:04 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\TsWpfWrp.exe
                        [2008/07/29 23:35:46 | 00,326,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\PresentationHost.exe
                        [2008/07/29 22:24:50 | 00,622,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icardagt.exe
                        [2008/07/29 22:24:50 | 00,037,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\infocardcpl.cpl
                        [2008/07/10 12:23:36 | 00,238,888 | ---- | C] (Nero AG) -- C:\WINDOWS\NuNInst.exe
                        [2008/07/07 16:26:58 | 00,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\es.dll
                        [2008/06/24 19:06:56 | 00,972,072 | ---- | C] (Nero AG) -- C:\WINDOWS\UNNeroMediaHome.exe
                        [2008/06/24 12:43:16 | 00,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mscms.dll
                        [2008/06/20 13:46:57 | 00,245,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mswsock.dll
                        [2008/06/20 13:46:57 | 00,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dnsapi.dll
                        [2008/06/20 07:51:12 | 00,361,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip.sys
                        [2008/06/20 07:40:08 | 00,138,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\afd.sys
                        [2008/06/20 07:08:27 | 00,226,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip6.sys
                        [2008/06/17 15:02:19 | 08,461,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
                        [2008/06/12 10:23:32 | 00,956,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtctm.dll
                        [2008/06/12 10:23:32 | 00,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtcprx.dll
                        [2008/06/12 10:23:32 | 00,161,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtcuiu.dll
                        [2008/06/12 10:23:32 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtxoci.dll
                        [2008/06/12 10:23:32 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtxclu.dll
                        [2008/06/12 10:23:32 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtclog.dll
                        [2008/06/06 17:54:16 | 00,972,072 | ---- | C] (Nero AG) -- C:\WINDOWS\UNRecode.exe
                        [2008/05/09 19:23:42 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshom.ocx
                        [2008/05/09 06:53:40 | 00,172,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scrrun.dll
                        [2008/05/09 06:53:40 | 00,090,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshext.dll
                        [2008/05/09 06:53:39 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scrobj.dll
                        [2008/05/08 07:24:44 | 00,155,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wscript.exe
                        [2008/05/07 05:07:23 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cscript.exe
                        [2008/04/13 20:12:42 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax
                        [2008/04/13 20:12:42 | 00,023,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativmvxx.ax
                        [2008/04/13 20:12:42 | 00,009,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativdaxx.ax
                        [2008/04/13 20:12:38 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\verclsid.exe
                        [2008/04/13 20:12:36 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdwxp.exe
                        [2008/04/13 20:12:36 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spdwnwxp.exe
                        [2008/04/13 20:12:35 | 00,073,796 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slserv.exe
                        [2008/04/13 20:12:35 | 00,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slrundll.exe
                        [2008/04/13 20:12:35 | 00,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\slrundll.exe
                        [2008/04/13 20:12:35 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\setupn.exe
                        [2008/04/13 20:12:29 | 00,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napstat.exe
                        [2008/04/13 20:12:25 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcperf.exe
                        [2008/04/13 20:12:20 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\faxpatch.exe
                        [2008/04/13 20:12:01 | 01,372,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll
                        [2008/04/13 20:09:55 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpash.dll
                        [2008/04/13 20:09:55 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnepr.dll
                        [2008/04/13 14:43:32 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsdupd.exe
                        [2008/04/13 13:27:18 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6r.dll
                        [2007/04/02 14:26:00 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt040d.dll
                        [2007/04/02 14:25:59 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0401.dll
                        [2007/03/22 00:02:12 | 00,972,336 | ---- | C] (Nero AG) -- C:\WINDOWS\UNNeroVision.exe
                        [2007/02/28 19:41:02 | 00,972,336 | ---- | C] (Nero AG) -- C:\WINDOWS\UNNeroShowTime.exe
                        [2006/10/19 01:47:22 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\UMDF\wpdmtpdr.dll
                        [2006/10/19 00:00:46 | 00,249,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drmupgds.exe
                        [2006/10/19 00:00:14 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpdshextautoplay.exe
                        [2006/09/28 22:56:38 | 00,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WudfHost.exe
                        [2006/05/30 10:03:03 | 00,094,263 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\DLA.EXE
                        [2006/05/30 10:03:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DLA
                        [2006/05/30 09:55:55 | 00,184,320 | ---- | C] (Gteko Ltd.) -- C:\WINDOWS\System32\GTDownDE_113.ocx
                        [2006/05/30 09:55:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\Intuit
                        [2006/05/30 09:54:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\occache
                        [2006/05/30 09:54:14 | 01,495,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shdocvw.bak
                        [2006/05/30 09:54:13 | 00,086,016 | ---- | C] (MindVision) -- C:\WINDOWS\unvise32qt.exe
                        [2006/05/30 09:54:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\QuickTime
                        [2006/05/30 09:54:03 | 00,000,000 | ---D | C] -- C:\My Music
                        [2006/05/30 09:53:37 | 00,029,184 | ---- | C] (Blue Sky Software) -- C:\WINDOWS\System32\popup.ocx
                        [2006/05/30 09:51:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\RegisteredPackages
                        [2006/05/30 09:50:08 | 00,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
                        [2006/05/30 09:48:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
                        [2006/05/30 09:46:09 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
                        [2006/05/30 09:37:36 | 00,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
                        [2006/05/30 09:37:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
                        [2006/05/30 09:35:13 | 00,000,000 | ---D | C] -- C:\dell
                        [2006/05/30 09:31:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\system32
                        [2006/05/30 09:30:54 | 00,232,448 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\l3codecp.acm
                        [2006/05/30 09:30:54 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
                        [2006/05/30 09:30:54 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\uwdf.exe
                        [2006/05/30 09:29:26 | 00,000,000 | ---D | C] -- C:\drivers
                        [2006/05/30 09:29:13 | 00,000,000 | ---D | C] -- C:\WINDOWS