This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Not sure what i have, might be SKYNET

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I am not sure if its related or not, but when i plug anything in to my usb ports the computer freezes. that's what started, then whenever i tried to open an exe file it would ask what program to use to open. searching through various forums i found a exefix_xp. that solved the problem for i while, then i had to do it again. now i have a window pop up when my computer starts, and every time i open a program. "the application or DLL globalroot\systemroot\system32\SKYNETldmigiqj.dll is not a valid windows image. please check this against your installation diskette" and its the same message every time. also whenever i clink on a link in Google i will direct me to a random different site. not sure if it is related to any of this. and when i look at my file names for instance my documents the location is C:\Documents and Settings\TEMP\My Documents. and i don't know why they all have temp in the file locations, because it didn't use to be that way. I have used ad aware ccleaner, malware bytes, spybot, and avg. they have detected SKYNET as a trojan but non have removed it. i have a copy of my hijack this log any help would be gratefully appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:49:17 PM, on 8/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dvdpaly.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\sofatnet.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Documents and Settings\TEMP\Desktop\third.exe
C:\WINDOWS\system32\wiawow32.sys

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.220 intsecure.microsoft.com
O1 - Hosts: 91.212.127.220 intsecure-2009.com
O1 - Hosts: 91.212.127.220 www.intsecure-2009.com
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: (no name) - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - (no file)
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Guest')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Guest')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Guest')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MasterCook Web Import Bar - {E6EF5071-7647-4E85-9785-87B6CF5CB561} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://pconweb.darden.com/includes/smsx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O22 - SharedTaskScheduler: doctordom - {d1577581-2ed7-469f-99b1-72c1339e0ee0} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe
O23 - Service: sofatnet Service (sofatnet) - Sigma Designs In - C:\WINDOWS\system32\sofatnet.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 12877 bytes
dds log

DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 18:49:45.34 on Fri 08/14/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.894.200 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\sofatnet.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Documents and Settings\TEMP\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.comcast.net
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uWindow Title = Microsoft Internet Explorer presented by Comcast
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=laptop
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = www.google.com
mSearch Bar = hxxp://www.google.com/ie
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.comcast.net/toolbar2.0/search/
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - No File
TB: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
EB: MasterCook Bar: {c92041c1-6d22-4069-ba0e-66246aa752b0} - c:\windows\system32\shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [ccleaner] "c:\program files\ccleaner\ccleaner.exe" /AUTO
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LXBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBUtime.dll,_RunDLLEntry@16
mRun: [IPHSend] c:\program files\common files\aol\iphsend\IPHSend.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
dRun: [Monopod] c:\windows\temp\b.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {E6EF5071-7647-4E85-9785-87B6CF5CB561} - {C92041C1-6D22-4069-BA0E-66246AA752B0} - c:\windows\system32\shdocvw.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} - hxxp://housecall60.trendmicro.com/housecall/xscan60.cab
DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} - hxxp://pconweb.darden.com/includes/smsx.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} - hxxps://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/games/popcaploader_v6.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: {d1577581-2ed7-469f-99b1-72c1339e0ee0} - No File
SEH: {40847941-2F5E-4BEB-802C-74849B8BA2E4} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\temp\applic~1\mozilla\firefox\profiles\j9crvi4b.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPMySrWB.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-26 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-2 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-8-2 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-2 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-2 297752]
R2 EvdoServer;EvdoServer;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
R2 sofatnet;sofatnet Service;c:\windows\system32\sofatnet.exe [2004-8-4 94720]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-4-19 24652]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2005-8-22 231424]
RUnknown jcmgmfk;jcmgmfk; [x]
RUnknown xleltnph;xleltnph; [x]
S2 Ias;Microsoft Security Services Management;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\34.tmp –> c:\windows\system32\34.tmp [?]

=============== Created Last 30 ================

2009-08-13 20:39 –d—– c:\program files\Sophos
2009-08-13 14:08 1,061 a——- c:\windows\wininit.ini
2009-08-13 12:24 –d—– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-08-13 12:24 –d—– c:\program files\SDHelper (Spybot - Search & Destroy)
2009-08-13 12:24 –d—– c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-08-13 12:24 –d—– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-08-11 21:52 262,144 a——- c:\windows\system32\default_user_class.dat
2009-08-11 21:20 –d—– c:\docume~1\temp\applic~1\Malwarebytes
2009-08-11 21:17 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-11 21:17 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-11 21:17 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-11 21:17 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-10 12:44 27,136 a–sh— c:\windows\system32\LCB1F.tmp.exe
2009-08-10 12:09 27,136 a–sh— c:\windows\system32\L8A15.tmp.exe
2009-08-10 11:54 26,624 a–sh— c:\windows\system32\L9E8B.tmp.exe
2009-08-10 11:31 26,624 a–sh— c:\windows\system32\L4D64.tmp.exe
2009-08-10 10:44 26,624 a–sh— c:\windows\system32\L65A.tmp.exe
2009-08-10 08:15 26,624 a–sh— c:\windows\system32\LD5AA.tmp.exe
2009-08-10 07:39 26,624 a–sh— c:\windows\system32\LB2A2.tmp.exe
2009-08-10 06:31 26,624 a–sh— c:\windows\system32\LF98C.tmp.exe
2009-08-10 03:50 –d—– c:\program files\wxfrgh
2009-08-10 03:41 120 a——- c:\windows\system32\358361390.BAT
2009-08-10 00:54 –d—– c:\docume~1\temp\applic~1\McAfee
2009-08-09 23:25 27,136 a–sh— c:\windows\system32\L8BD7.tmp.exe
2009-08-09 22:45 27,136 a–sh— c:\windows\system32\LC1A1.tmp.exe
2009-08-09 21:53 27,136 a–sh— c:\windows\system32\LE20E.tmp.exe
2009-08-09 05:09 –d—– c:\program files\WinPcap
2009-08-07 00:25 27,136 a–sh— c:\windows\system32\L8F1D.tmp.exe
2009-08-06 21:27 27,136 a–sh— c:\windows\system32\L8283.tmp.exe
2009-08-06 20:43 27,136 a–sh— c:\windows\system32\L547.tmp.exe
2009-08-06 20:28 27,136 a–sh— c:\windows\system32\L8614.tmp.exe
2009-08-06 13:18 0 a–sh— c:\windows\system32\LB2EC.tmp.exe
2009-08-06 12:42 0 a–sh— c:\windows\system32\L8862.tmp.exe
2009-08-06 12:40 0 a–sh— c:\windows\system32\LD8.tmp.exe
2009-08-06 12:11 0 a–sh— c:\windows\system32\LDFF1.tmp.exe
2009-08-06 10:12 –d—– c:\program files\UPHClean
2009-08-06 10:03 116,224 a——- c:\windows\system32\dllcache\xrxwiadr.dll
2009-08-06 10:03 23,040 a——- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-08-06 10:03 17,408 a——- c:\windows\system32\dllcache\xrxscnui.dll
2009-08-06 10:03 27,648 a——- c:\windows\system32\dllcache\xrxftplt.exe
2009-08-06 10:03 4,608 a——- c:\windows\system32\dllcache\xrxflnch.exe
2009-08-06 10:01 53,760 a——- c:\windows\system32\dllcache\wiamsmud.dll
2009-08-06 10:00 249,402 a——- c:\windows\system32\dllcache\vinwm.sys
2009-08-06 09:59 94,720 a——- c:\windows\system32\dllcache\umaxud32.dll
2009-08-06 09:58 525,568 a——- c:\windows\system32\dllcache\tridxp.dll
2009-08-06 09:57 455,168 a——- c:\windows\system32\dllcache\tintsetp.exe
2009-08-06 09:56 30,688 a——- c:\windows\system32\dllcache\sym_u3.sys
2009-08-06 09:55 24,660 a——- c:\windows\system32\dllcache\spxupchk.dll
2009-08-06 09:54 24,576 a——- c:\windows\system32\dllcache\smc8000n.sys
2009-08-06 09:53 68,608 a——- c:\windows\system32\dllcache\sis6306p.sys
2009-08-06 09:52 17,280 a——- c:\windows\system32\dllcache\scr111.sys
2009-08-06 09:51 41,216 a——- c:\windows\system32\dllcache\s3mt3d.sys
2009-08-06 09:50 23,040 a——- c:\windows\system32\dllcache\EXCH_regtrace.exe
2009-08-06 09:49 159,232 a——- c:\windows\system32\dllcache\ptpusd.dll
2009-08-06 09:48 211,712 a——- c:\windows\system32\dllcache\perm2dll.dll
2009-08-06 09:47 31,872 a——- c:\windows\system32\dllcache\ovce.sys
2009-08-06 09:46 87,040 a——- c:\windows\system32\dllcache\nm6wdm.sys
2009-08-06 09:45 75,520 a——- c:\windows\system32\dllcache\mxport.sys
2009-08-06 09:44 35,200 a——- c:\windows\system32\dllcache\msgame.sys
2009-08-06 09:43 48,768 a——- c:\windows\system32\dllcache\maestro.sys
2009-08-06 09:42 47,066 a——- c:\windows\system32\dllcache\ksc.nls
2009-08-06 09:41 35,328 a——- c:\windows\system32\dllcache\iprip.dll
2009-08-06 09:40 91,136 a——- c:\windows\system32\dllcache\icam4com.dll
2009-08-06 09:39 1,041,536 a——- c:\windows\system32\dllcache\hsfdpsp2.sys
2009-08-06 09:38 32,768 a——- c:\windows\system32\dllcache\hpgtmcro.dll
2009-08-06 09:37 322,432 a——- c:\windows\system32\dllcache\g400m.sys
2009-08-06 09:36 11,850 a——- c:\windows\system32\dllcache\f3ab18xj.sys
2009-08-06 09:35 18,503 a——- c:\windows\system32\dllcache\epro4.sys
2009-08-06 09:34 26,698 a——- c:\windows\system32\dllcache\dlh5xnd5.sys
2009-08-06 09:33 117,760 a——- c:\windows\system32\dllcache\d100ib5.sys
2009-08-06 09:32 78,336 a——- c:\windows\system32\dllcache\chajei.ime
2009-08-06 09:31 60,416 a——- c:\windows\system32\dllcache\brserwdm.sys
2009-08-06 09:30 63,663 a——- c:\windows\system32\dllcache\ati1rvxx.sys
2009-08-06 09:29 32,827 a——- c:\windows\system32\dllcache\tcptest.exe
2009-08-04 19:57 –d—– c:\docume~1\temp\applic~1\CoreFTP
2009-08-02 20:07 –d-h— C:\$AVG8.VAULT$
2009-08-02 20:03 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-08-02 20:03 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-08-02 20:02 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-02 20:02 –d—– c:\windows\system32\drivers\Avg
2009-08-02 20:01 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2009-08-02 20:01 –d—– c:\program files\AVG
2009-08-02 20:01 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-08-02 19:39 –d—– c:\docume~1\temp\applic~1\AVG8
2009-08-01 20:57 a-d—– c:\windows\system32\images

==================== Find3M ====================

2009-08-11 21:45 825 —-h— c:\windows\fonts\mlog
2009-06-25 23:12 15,688 a——- c:\windows\system32\lsdelete.exe
2009-06-25 23:11 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-06-25 22:43 10,752 a——- c:\windows\DCEBoot.exe
2009-06-22 03:01 0 a——- C:\bwyi.exe
2009-06-22 03:01 0 a——- C:\fnwojc.exe
2009-06-22 03:01 0 a——- C:\qyvjuj.exe
2009-06-22 03:01 0 a——- C:\agutoq.exe
2009-04-16 18:03 0 a——- c:\docume~1\temp\applic~1\wklnhst.dat

============= FINISH: 18:59:33.34 ===============


gmer log

GMER 1.0.15.15020 [tewyfq4m.exe] - http://www.gmer.net
Rootkit scan 2009-08-14 19:14:42
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

Code 85603500 ZwEnumerateKey
Code 8555E440 ZwFlushInstructionCache
Code 85558CA6 IofCallDriver
Code 8552E4EE IofCompleteRequest

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 859651E8

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)

Device \Driver\usbohci \Device\USBPDO-0 857DE7A0
Device \Driver\usbohci \Device\USBPDO-1 857DE7A0
Device \Driver\usbehci \Device\USBPDO-2 857DF7A0

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\Ftdisk \Device\HarddiskVolume1 859D41E8
Device \Driver\atapi \Device\Ide\IdePort0 859661E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 859661E8
Device \Driver\atapi \Device\Ide\IdePort1 859661E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 859661E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 853921E8
Device \Driver\NetBT \Device\NetbiosSmb 853921E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{E78370EC-0FE6-4C7E-9B7D-EFBBD5801965} 853921E8

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\usbohci \Device\USBFDO-0 857DE7A0
Device \Driver\usbohci \Device\USBFDO-1 857DE7A0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8535E7A0
Device \Driver\usbehci \Device\USBFDO-2 857DF7A0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8535E7A0
Device \Driver\Ftdisk \Device\FtControl 859D41E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{65E63B54-612E-4313-961E-353B13798321} 853921E8
Device \FileSystem\Cdfs \Cdfs 856E51E8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC5 0x28 0xDA 0xB0 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x92 0xFD 0xD8 0x80 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x44 0xC3 0xDD 0x59 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC5 0x28 0xDA 0xB0 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x92 0xFD 0xD8 0x80 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x44 0xC3 0xDD 0x59 …
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd@imagepath \systemroot\system32\drivers\SKYNETkmqrsnto.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main@aid 10131
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main\connections (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\[removed] \systemroot\system32\drivers\SKYNETkmqrsnto.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETqowomnve.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETfdytpxvn.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETldmigiqj.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETupveoemp.dat
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC5 0x28 0xDA 0xB0 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x92 0xFD 0xD8 0x80 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x44 0xC3 0xDD 0x59 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC5 0x28 0xDA 0xB0 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x92 0xFD 0xD8 0x80 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x44 0xC3 0xDD 0x59 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd@imagepath \systemroot\system32\drivers\SKYNETkmqrsnto.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main@aid 10131
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main\connections
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\[removed] \systemroot\system32\drivers\SKYNETkmqrsnto.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETqowomnve.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETfdytpxvn.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETldmigiqj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETupveoemp.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC5 0x28 0xDA 0xB0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x92 0xFD 0xD8 0x80 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x44 0xC3 0xDD 0x59 …
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd@start 1
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd@type 1
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd@group file system
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd@imagepath \systemroot\system32\drivers\SKYNETkmqrsnto.sys
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main@aid 10131
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main@sid 0
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main\connections (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\[removed] \systemroot\system32\drivers\SKYNETkmqrsnto.sys
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETqowomnve.dll
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETfdytpxvn.dat
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETldmigiqj.dll
Reg HKLM\SYSTEM\ControlSet006\Services\SKYNETafysargd\[removed] \systemroot\system32\SKYNETupveoemp.dat
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC5 0x28 0xDA 0xB0 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x92 0xFD 0xD8 0x80 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x44 0xC3 0xDD 0x59 …
Reg HKLM\SOFTWARE\Classes\CETIUI.CETIUIContentManager@ CCETIUIContentManager Object
Reg HKLM\SOFTWARE\Classes\CETIUI.CETIUIContentManager\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.CETIUIContentManager\CLSID@ {136C3D0D-2722-4DEC-A865-26526C6A9081}
Reg HKLM\SOFTWARE\Classes\CETIUI.CETIUIContentManager\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.CETIUIContentManager\CurVer@ CETIUI.CETIUIContentManager.1
Reg HKLM\SOFTWARE\Classes\CETIUI.CETIUIContentManager.1@ CCETIUIContentManager Object
Reg HKLM\SOFTWARE\Classes\CETIUI.CETIUIContentManager.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.CETIUIContentManager.1\CLSID@ {136C3D0D-2722-4DEC-A865-26526C6A9081}
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIControl@ CETIUI Skin Control
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIControl\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIControl\CLSID@ {D657569D-3EE4-4EA9-90C7-9587809ED482}
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIControl\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIControl\CurVer@ CETIUI.CetiUIControl.1
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIControl.1@ CETIUI Skin Control
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIControl.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIControl.1\CLSID@ {D657569D-3EE4-4EA9-90C7-9587809ED482}
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIGraphicUtils@ CCetiUIGraphicUtils Object
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIGraphicUtils\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIGraphicUtils\CLSID@ {D1DAF049-2228-4E2E-8BDA-A80117B48BBD}
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIGraphicUtils\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIGraphicUtils\CurVer@ CETIUI.CetiUIGraphicUtils.1
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIGraphicUtils.1@ CCetiUIGraphicUtils Object
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIGraphicUtils.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIGraphicUtils.1\CLSID@ {D1DAF049-2228-4E2E-8BDA-A80117B48BBD}
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIPlugin@ CCetiUIPlugin Object
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIPlugin\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIPlugin\CLSID@ {F3B44E84-0371-4F00-B26D-1C897C09A14D}
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIPlugin\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIPlugin\CurVer@ CETIUI.CetiUIPlugin.1
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIPlugin.1@ CCetiUIPlugin Object
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIPlugin.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.CetiUIPlugin.1\CLSID@ {F3B44E84-0371-4F00-B26D-1C897C09A14D}
Reg HKLM\SOFTWARE\Classes\CETIUI.Controls@ CControls Object
Reg HKLM\SOFTWARE\Classes\CETIUI.Controls\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.Controls\CLSID@ {578695FE-928A-41A3-83EF-41B46BCF1C3F}
Reg HKLM\SOFTWARE\Classes\CETIUI.Controls\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.Controls\CurVer@ CETIUI.Controls.1
Reg HKLM\SOFTWARE\Classes\CETIUI.Controls.1@ CControls Object
Reg HKLM\SOFTWARE\Classes\CETIUI.Controls.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.Controls.1\CLSID@ {578695FE-928A-41A3-83EF-41B46BCF1C3F}
Reg HKLM\SOFTWARE\Classes\CETIUI.Form@ CForm Object
Reg HKLM\SOFTWARE\Classes\CETIUI.Form\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.Form\CLSID@ {8958B6A3-44E4-40DC-A574-EFC6C8783251}
Reg HKLM\SOFTWARE\Classes\CETIUI.Form\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.Form\CurVer@ CETIUI.Form.1
Reg HKLM\SOFTWARE\Classes\CETIUI.Form.1@ CForm Object
Reg HKLM\SOFTWARE\Classes\CETIUI.Form.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.Form.1\CLSID@ {8958B6A3-44E4-40DC-A574-EFC6C8783251}
Reg HKLM\SOFTWARE\Classes\CETIUI.Forms@ CForms Object
Reg HKLM\SOFTWARE\Classes\CETIUI.Forms\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.Forms\CLSID@ {50980323-6EBA-4F70-A897-80627E8B2EEB}
Reg HKLM\SOFTWARE\Classes\CETIUI.Forms\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.Forms\CurVer@ CETIUI.Forms.1
Reg HKLM\SOFTWARE\Classes\CETIUI.Forms.1@ CForms Object
Reg HKLM\SOFTWARE\Classes\CETIUI.Forms.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.Forms.1\CLSID@ {50980323-6EBA-4F70-A897-80627E8B2EEB}
Reg HKLM\SOFTWARE\Classes\CETIUI.ScriptController@ CScriptController Object
Reg HKLM\SOFTWARE\Classes\CETIUI.ScriptController\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.ScriptController\CLSID@ {7FD61FB8-4D11-417B-BFB8-0D246FA5AD8E}
Reg HKLM\SOFTWARE\Classes\CETIUI.ScriptController\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.ScriptController\CurVer@ CETIUI.ScriptController.2
Reg HKLM\SOFTWARE\Classes\CETIUI.ScriptController.2@ CScriptController Object
Reg HKLM\SOFTWARE\Classes\CETIUI.ScriptController.2\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.ScriptController.2\CLSID@ {7FD61FB8-4D11-417B-BFB8-0D246FA5AD8E}
Reg HKLM\SOFTWARE\Classes\CETIUI.Skin@ CSkin Object
Reg HKLM\SOFTWARE\Classes\CETIUI.Skin\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.Skin\CLSID@ {D67BE938-7D4C-4E1A-BF93-C41C763DA69E}
Reg HKLM\SOFTWARE\Classes\CETIUI.Skin\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.Skin\CurVer@ CETIUI.Skin.1
Reg HKLM\SOFTWARE\Classes\CETIUI.Skin.1@ CSkin Object
Reg HKLM\SOFTWARE\Classes\CETIUI.Skin.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.Skin.1\CLSID@ {D67BE938-7D4C-4E1A-BF93-C41C763DA69E}
Reg HKLM\SOFTWARE\Classes\CETIUI.SkinLoader@ CSkinLoader Object
Reg HKLM\SOFTWARE\Classes\CETIUI.SkinLoader\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.SkinLoader\CLSID@ {53054632-3FD4-4948-B2CB-3E608989E6F0}
Reg HKLM\SOFTWARE\Classes\CETIUI.SkinLoader\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUI.SkinLoader\CurVer@ CETIUI.SkinLoader.1
Reg HKLM\SOFTWARE\Classes\CETIUI.SkinLoader.1@ CSkinLoader Object
Reg HKLM\SOFTWARE\Classes\CETIUI.SkinLoader.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUI.SkinLoader.1\CLSID@ {53054632-3FD4-4948-B2CB-3E608989E6F0}
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtml@ CCETIUIHtml Object
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtml\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtml\CLSID@ {46523DDC-2C40-4032-8ED1-AFDEBC30D088}
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtml\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtml\CurVer@ CETIUIHtmlPlugin.CETIUIHtml.1
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtml.1@ CCETIUIHtml Object
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtml.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtml.1\CLSID@ {46523DDC-2C40-4032-8ED1-AFDEBC30D088}
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtmlHandlerSam.1@ CCETIUIHtmlHandlerSample Object
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtmlHandlerSam.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtmlHandlerSam.1\CLSID@ {A3BAA894-DA62-4345-8E7A-9DDAAEDC1EEA}
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtmlHandlerSampl@ CCETIUIHtmlHandlerSample Object
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtmlHandlerSampl\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtmlHandlerSampl\CLSID@ {A3BAA894-DA62-4345-8E7A-9DDAAEDC1EEA}
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtmlHandlerSampl\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUIHtmlPlugin.CETIUIHtmlHandlerSampl\CurVer@ CETIUIHtmlPlugin.CETIUIHtmlHandlerSam.1
Reg HKLM\SOFTWARE\Classes\CETIUIPluginPack1.CetiUIButton@ CCetiUIButton Object
Reg HKLM\SOFTWARE\Classes\CETIUIPluginPack1.CetiUIButton\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUIPluginPack1.CetiUIButton\CLSID@ {A179BD30-DE1E-445D-8AB2-22239F2911B2}
Reg HKLM\SOFTWARE\Classes\CETIUIPluginPack1.CetiUIButton\CurVer
Reg HKLM\SOFTWARE\Classes\CETIUIPluginPack1.CetiUIButton\CurVer@ CETIUIPluginPack1.CetiUIButton.1
Reg HKLM\SOFTWARE\Classes\CETIUIPluginPack1.CetiUIButton.1@ CCetiUIButton Object
Reg HKLM\SOFTWARE\Classes\CETIUIPluginPack1.CetiUIButton.1\CLSID
Reg HKLM\SOFTWARE\Classes\CETIUIPluginPack1.CetiUIButton.1\CLSID@ {A179BD30-DE1E-445D-8AB2-22239F2911B2}
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUIHtmlExternalHand@ CCETIUIHtmlExternalHandler Object
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUIHtmlExternalHand\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUIHtmlExternalHand\CLSID@ {FD3D03B4-7855-4D96-9991-9DA593389819}
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUIHtmlExternalHand\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUIHtmlExternalHand\CurVer@ HPCETI.CETIUIHtmlExternalHand.1
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUIHtmlExternalHand.1@ CCETIUIHtmlExternalHandler Object
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUIHtmlExternalHand.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUIHtmlExternalHand.1\CLSID@ {FD3D03B4-7855-4D96-9991-9DA593389819}
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUISkinUtilFunctions@ CCETIUISkinUtilFunctions Object
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUISkinUtilFunctions\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUISkinUtilFunctions\CLSID@ {084E6553-338B-4019-BEAC-74FA6D1DF545}
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUISkinUtilFunctions\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUISkinUtilFunctions\CurVer@ HPCETI.CETIUISkinUtilFunctions.1
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUISkinUtilFunctions.1@ CCETIUISkinUtilFunctions Object
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUISkinUtilFunctions.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.CETIUISkinUtilFunctions.1\CLSID@ {084E6553-338B-4019-BEAC-74FA6D1DF545}
Reg HKLM\SOFTWARE\Classes\HPCETI.DataArchive@ HPCETI DArC Class
Reg HKLM\SOFTWARE\Classes\HPCETI.DataArchive\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.DataArchive\CLSID@ {11EF5264-3529-4a73-8C0E-C8EC04DDCE8D}
Reg HKLM\SOFTWARE\Classes\HPCETI.DataArchive\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.DataArchive\CurVer@ HPCETI.DataArchive.1
Reg HKLM\SOFTWARE\Classes\HPCETI.DataArchive.1@ HPCETI DArC Class
Reg HKLM\SOFTWARE\Classes\HPCETI.DataArchive.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.DataArchive.1\CLSID@ {11EF5264-3529-4a73-8C0E-C8EC04DDCE8D}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPCompMgrService@ HPCompMgrService Class
Reg HKLM\SOFTWARE\Classes\HPCETI.HPCompMgrService\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPCompMgrService\CLSID@ {8A5339F3-EC14-4521-B132-83E952B19E80}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPCompMgrService\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPCompMgrService\CurVer@ HPCETI.HPCompMgrService.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPCompMgrService.1@ HPCompMgrService Class
Reg HKLM\SOFTWARE\Classes\HPCETI.HPCompMgrService.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPCompMgrService.1\CLSID@ {8A5339F3-EC14-4521-B132-83E952B19E80}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPDataTransmitter@ HP Data Transmission Component
Reg HKLM\SOFTWARE\Classes\HPCETI.HPDataTransmitter\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPDataTransmitter\CLSID@ {D8C17400-19B6-4A77-8040-19010CF1E50C}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPDataTransmitter\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPDataTransmitter\CurVer@ HPCETI.HPDataTransmitter.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPDataTransmitter.1@ HP Data Transmission Component
Reg HKLM\SOFTWARE\Classes\HPCETI.HPDataTransmitter.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPDataTransmitter.1\CLSID@ {D8C17400-19B6-4A77-8040-19010CF1E50C}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPHUT@ HPHUT Class
Reg HKLM\SOFTWARE\Classes\HPCETI.HPHUT\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPHUT\CLSID@ {97188423-CA6A-432F-A933-FB7B45DFAF17}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPHUT\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPHUT\CurVer@ HPCETI.HPHUT.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPHUT.1@ HPHUT Class
Reg HKLM\SOFTWARE\Classes\HPCETI.HPHUT.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPHUT.1\CLSID@ {97188423-CA6A-432F-A933-FB7B45DFAF17}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTask@ CHPScheduledTask Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTask\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTask\CLSID@ {72A5513A-3A66-44F2-BF3F-F2E88FF29E78}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTask\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTask\CurVer@ HPCETI.HPScheduledTask.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTask.1@ CHPScheduledTask Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTask.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTask.1\CLSID@ {72A5513A-3A66-44F2-BF3F-F2E88FF29E78}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskMonitor@ CHPScheduledTaskMonitor Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskMonitor\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskMonitor\CLSID@ {4BC953C2-80F3-45BB-B9EC-C46363F0DE35}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskMonitor\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskMonitor\CurVer@ HPCETI.HPScheduledTaskMonitor.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskMonitor.1@ CHPScheduledTaskMonitor Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskMonitor.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskMonitor.1\CLSID@ {4BC953C2-80F3-45BB-B9EC-C46363F0DE35}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskTrigger@ CHPScheduledTaskTrigger Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskTrigger\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskTrigger\CLSID@ {C8FC20BA-4E13-4C73-932E-B1DB49862F6D}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskTrigger\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskTrigger\CurVer@ HPCETI.HPScheduledTaskTrigger.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskTrigger.1@ CHPScheduledTaskTrigger Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskTrigger.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPScheduledTaskTrigger.1\CLSID@ {C8FC20BA-4E13-4C73-932E-B1DB49862F6D}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskMgr@ CHPTaskMgr Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskMgr\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskMgr\CLSID@ {66B093B7-B5E3-4CFE-B32B-FEB55F172481}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskMgr\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskMgr\CurVer@ HPCETI.HPTaskMgr.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskMgr.1@ CHPTaskMgr Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskMgr.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskMgr.1\CLSID@ {66B093B7-B5E3-4CFE-B32B-FEB55F172481}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskScheduler@ CHPTaskScheduler Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskScheduler\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskScheduler\CLSID@ {272CEA1E-DBFA-4E44-A28C-A8ED9ECA4399}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskScheduler\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskScheduler\CurVer@ HPCETI.HPTaskScheduler.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskScheduler.1@ CHPTaskScheduler Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskScheduler.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTaskScheduler.1\CLSID@ {272CEA1E-DBFA-4E44-A28C-A8ED9ECA4399}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMInetPlugin@ InetPlugin Class
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMInetPlugin\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMInetPlugin\CLSID@ {2B03BD97-99C5-4DA6-8564-F32861520F82}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMInetPlugin\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMInetPlugin\CurVer@ HPCETI.HPTMInetPlugin.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMInetPlugin.1@ InetPlugin Class
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMInetPlugin.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMInetPlugin.1\CLSID@ {2B03BD97-99C5-4DA6-8564-F32861520F82}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMSchedulePlugin@ CScheduler Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMSchedulePlugin\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMSchedulePlugin\CLSID@ {8E7E2652-0A15-423E-9E5E-02CFB1FE74AF}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMSchedulePlugin\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMSchedulePlugin\CurVer@ HPCETI.HPTMSchedulePlugin.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMSchedulePlugin.1@ CScheduler Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMSchedulePlugin.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPTMSchedulePlugin.1\CLSID@ {8E7E2652-0A15-423E-9E5E-02CFB1FE74AF}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPUIController@ CHPUIController Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPUIController\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPUIController\CLSID@ {FF052B6D-70D2-4130-BB0E-EDEF9825594D}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPUIController\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPUIController\CurVer@ HPCETI.HPUIController.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPUIController.1@ CHPUIController Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPUIController.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPUIController.1\CLSID@ {FF052B6D-70D2-4130-BB0E-EDEF9825594D}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPZipMgr@ CHPZipFile Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPZipMgr\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPZipMgr\CLSID@ {DCBED622-E42A-4265-A8D7-5C821C23F35A}
Reg HKLM\SOFTWARE\Classes\HPCETI.HPZipMgr\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.HPZipMgr\CurVer@ HPCETI.HPZipMgr.1
Reg HKLM\SOFTWARE\Classes\HPCETI.HPZipMgr.1@ CHPZipFile Object
Reg HKLM\SOFTWARE\Classes\HPCETI.HPZipMgr.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.HPZipMgr.1\CLSID@ {DCBED622-E42A-4265-A8D7-5C821C23F35A}
Reg HKLM\SOFTWARE\Classes\HPCETI.OverlandSolMgr@ HPCETI.OverlandSolMgr
Reg HKLM\SOFTWARE\Classes\HPCETI.OverlandSolMgr\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.OverlandSolMgr\CLSID@ {A02ED9E9-8D36-473A-98ED-C253A40765DE}
Reg HKLM\SOFTWARE\Classes\HPCETI.OverlandSolMgr\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.OverlandSolMgr\CurVer@ HPCETI.OverlandSolMgr.1
Reg HKLM\SOFTWARE\Classes\HPCETI.OverlandSolMgr.1@ HPCETI.OverlandSolMgr
Reg HKLM\SOFTWARE\Classes\HPCETI.OverlandSolMgr.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.OverlandSolMgr.1\CLSID@ {A02ED9E9-8D36-473A-98ED-C253A40765DE}
Reg HKLM\SOFTWARE\Classes\HPCETI.UIContentManager@ CContentManager Object
Reg HKLM\SOFTWARE\Classes\HPCETI.UIContentManager\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.UIContentManager\CLSID@ {12DB8D34-8419-4C47-A61A-33DE59E6ED75}
Reg HKLM\SOFTWARE\Classes\HPCETI.UIContentManager\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.UIContentManager\CurVer@ HPCETI.UIContentManager.1
Reg HKLM\SOFTWARE\Classes\HPCETI.UIContentManager.1@ CContentManager Object
Reg HKLM\SOFTWARE\Classes\HPCETI.UIContentManager.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.UIContentManager.1\CLSID@ {12DB8D34-8419-4C47-A61A-33DE59E6ED75}
Reg HKLM\SOFTWARE\Classes\HPCETI.UIZipProtocol@ CZipHandler Object
Reg HKLM\SOFTWARE\Classes\HPCETI.UIZipProtocol\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.UIZipProtocol\CLSID@ {CF184AD3-CDCB-4168-A3F7-8E447D129300}
Reg HKLM\SOFTWARE\Classes\HPCETI.UIZipProtocol\CurVer
Reg HKLM\SOFTWARE\Classes\HPCETI.UIZipProtocol\CurVer@ HPCETI.UIZipProtocol.1
Reg HKLM\SOFTWARE\Classes\HPCETI.UIZipProtocol.1@ CZipHandler Object
Reg HKLM\SOFTWARE\Classes\HPCETI.UIZipProtocol.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPCETI.UIZipProtocol.1\CLSID@ {CF184AD3-CDCB-4168-A3F7-8E447D129300}

—- EOF - GMER 1.0.15 —-

Attachments:

  • [attachment removed: Attach.zip]
Hello Kyle_M and welcome to the forums here at WTT!

You are definitely infected with a rootkit, and probably more. Let's see if combofix will run.

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.Close all other windows/browser first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do Not run combofix more than once. If you have problems please post back for further instructions.
3.CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.
Sorry for the late reply. i was out of town for a few days. here is the results of the combofix

ComboFix 09-08-10.06 - Kyle Mitchell 08/17/2009 12:35.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.894.361 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\agutoq.exe
C:\bwyi.exe
c:\documents and settings\All Users\Application Data\97533896.ini
c:\documents and settings\All Users\Start Menu\Programs\Windows Live Messenger .lnk
C:\fnwojc.exe
c:\program files\security toolbar
c:\program files\security toolbar\Uninstall.bat
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
C:\qyvjuj.exe
c:\recycler\S-1-5-21-1708537768-308236825-839522115-1003
c:\recycler\S-1-5-21-235812152-1293073212-1411892704-1003
c:\windows\7673d9ac.ocx
c:\windows\80f54c17.ocx
c:\windows\85a58256.ocx
c:\windows\c4e7b72c.ocx
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Fonts\mlog
c:\windows\Install.txt
c:\windows\Installer\3eaccc.msp
c:\windows\patch.exe
c:\windows\system32\_003415_.tmp.dll
c:\windows\system32\_003416_.tmp.dll
c:\windows\system32\_003417_.tmp.dll
c:\windows\system32\_003418_.tmp.dll
c:\windows\system32\_003425_.tmp.dll
c:\windows\system32\_003426_.tmp.dll
c:\windows\system32\_003427_.tmp.dll
c:\windows\system32\_003428_.tmp.dll
c:\windows\system32\_003430_.tmp.dll
c:\windows\system32\_003431_.tmp.dll
c:\windows\system32\_003434_.tmp.dll
c:\windows\system32\_003435_.tmp.dll
c:\windows\system32\_003437_.tmp.dll
c:\windows\system32\_003438_.tmp.dll
c:\windows\system32\_003439_.tmp.dll
c:\windows\system32\_003441_.tmp.dll
c:\windows\system32\_003444_.tmp.dll
c:\windows\system32\_003445_.tmp.dll
c:\windows\system32\_003449_.tmp.dll
c:\windows\system32\_003450_.tmp.dll
c:\windows\system32\_003452_.tmp.dll
c:\windows\system32\_003455_.tmp.dll
c:\windows\system32\_003457_.tmp.dll
c:\windows\system32\_003458_.tmp.dll
c:\windows\system32\_003459_.tmp.dll
c:\windows\system32\_003460_.tmp.dll
c:\windows\system32\_003461_.tmp.dll
c:\windows\system32\_003464_.tmp.dll
c:\windows\system32\_003465_.tmp.dll
c:\windows\system32\_003466_.tmp.dll
c:\windows\system32\_003467_.tmp.dll
c:\windows\system32\_003468_.tmp.dll
c:\windows\system32\_003473_.tmp.dll
c:\windows\system32\_003475_.tmp.dll
c:\windows\system32\_003476_.tmp.dll
c:\windows\system32\7158fcfb.ocx
c:\windows\system32\92cb8819.ocx
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\SKYNETkmqrsnto.sys
c:\windows\system32\ef841279.ocx
c:\windows\system32\FInstall.sys
c:\windows\system32\L4D64.tmp.exe
c:\windows\system32\L65A.tmp.exe
c:\windows\system32\L8862.tmp.exe
c:\windows\system32\L9E8B.tmp.exe
c:\windows\system32\LB2A2.tmp.exe
c:\windows\system32\LB2EC.tmp.exe
c:\windows\system32\LD5AA.tmp.exe
c:\windows\system32\LD8.tmp.exe
c:\windows\system32\LDFF1.tmp.exe
c:\windows\system32\LF98C.tmp.exe
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SKYNETfdytpxvn.dat
c:\windows\system32\SKYNETldmigiqj.dll
c:\windows\system32\SKYNETqowomnve.dll
c:\windows\system32\SKYNETupveoemp.dat
c:\windows\system32\WanPacket.dll
c:\windows\system32\wiawow32.sys
c:\windows\system32\wiwow64.exe
c:\windows\system32\wpcap.dll
c:\windows\TEMP\mpj57020.dll
c:\windows\TEMP\mta40723.dll


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETafysargd
——-\Legacy_SKYNETafysargd
——-\Legacy_6TO4
——-\Legacy_IAS
——-\Legacy_MSUPDATE
——-\Legacy_NETCARD
——-\Legacy_NPF
——-\Service_Ias
——-\Service_npf


((((((((((((((((((((((((( Files Created from 2009-07-17 to 2009-08-17 )))))))))))))))))))))))))))))))
.

2009-08-14 00:39 . 2009-08-14 00:39 ——– d—–w- c:\program files\Sophos
2009-08-13 18:16 . 2009-08-13 18:17 ——– d—–w- c:\documents and settings\TEMP\Local Settings\Application Data\AOL
2009-08-13 16:24 . 2009-08-13 16:24 ——– d—–w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-08-13 16:24 . 2009-08-13 16:24 ——– d—–w- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-08-13 16:24 . 2009-08-13 16:24 ——– d—–w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-08-13 16:24 . 2009-08-13 16:24 ——– d—–w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-08-13 15:59 . 2009-07-24 13:55 1090816 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-08-12 01:52 . 2009-08-12 01:52 262144 —-a-w- c:\windows\system32\default_user_class.dat
2009-08-12 01:20 . 2009-08-12 01:20 ——– d—–w- c:\documents and settings\TEMP\Application Data\Malwarebytes
2009-08-12 01:17 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-12 01:17 . 2009-08-14 00:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-12 01:17 . 2009-08-12 01:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-12 01:17 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-10 07:50 . 2009-08-12 01:54 ——– d—–w- c:\program files\wxfrgh
2009-08-10 07:41 . 2009-08-10 07:41 120 —-a-w- c:\windows\system32\358361390.BAT
2009-08-10 04:54 . 2009-08-12 17:23 ——– d—–w- c:\documents and settings\TEMP\Application Data\McAfee
2009-08-10 04:54 . 2009-08-10 04:54 127 —-a-w- c:\documents and settings\TEMP\Local Settings\Application Data\fusioncache.dat
2009-08-06 14:12 . 2009-08-06 14:12 ——– d—–w- c:\program files\UPHClean
2009-08-06 14:03 . 2004-08-04 04:56 116224 —-a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2009-08-06 14:03 . 2001-08-18 02:36 23040 —-a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-08-06 14:03 . 2001-08-18 02:36 17408 —-a-w- c:\windows\system32\dllcache\xrxscnui.dll
2009-08-06 14:03 . 2001-08-18 02:37 27648 —-a-w- c:\windows\system32\dllcache\xrxftplt.exe
2009-08-06 14:03 . 2001-08-18 02:37 4608 —-a-w- c:\windows\system32\dllcache\xrxflnch.exe
2009-08-06 14:02 . 2001-08-18 02:37 99865 —-a-w- c:\windows\system32\dllcache\xlog.exe
2009-08-06 14:02 . 2001-08-17 16:11 16970 —-a-w- c:\windows\system32\dllcache\xem336n5.sys
2009-08-06 14:02 . 2004-08-04 02:29 19455 —-a-w- c:\windows\system32\dllcache\wvchntxx.sys
2009-08-06 14:02 . 2004-08-04 02:29 12063 —-a-w- c:\windows\system32\dllcache\wsiintxx.sys
2009-08-06 14:02 . 2004-08-04 02:31 154624 —-a-w- c:\windows\system32\dllcache\wlluc48.sys
2009-08-06 14:02 . 2001-08-17 16:12 34890 —-a-w- c:\windows\system32\dllcache\wlandrv2.sys
2009-08-06 14:02 . 2001-08-17 17:28 771581 —-a-w- c:\windows\system32\dllcache\winacisa.sys
2009-08-06 14:00 . 2001-08-17 16:14 249402 —-a-w- c:\windows\system32\dllcache\vinwm.sys
2009-08-06 13:59 . 2001-08-18 02:36 94720 —-a-w- c:\windows\system32\dllcache\umaxud32.dll
2009-08-06 13:58 . 2001-08-18 02:36 525568 —-a-w- c:\windows\system32\dllcache\tridxp.dll
2009-08-06 13:57 . 2004-08-04 13:00 455168 —-a-w- c:\windows\system32\dllcache\tintsetp.exe
2009-08-06 13:56 . 2001-08-17 18:07 30688 —-a-w- c:\windows\system32\dllcache\sym_u3.sys
2009-08-06 13:55 . 2001-08-18 02:36 24660 —-a-w- c:\windows\system32\dllcache\spxupchk.dll
2009-08-06 13:54 . 2001-08-17 16:12 24576 —-a-w- c:\windows\system32\dllcache\smc8000n.sys
2009-08-06 13:53 . 2001-08-17 16:50 68608 —-a-w- c:\windows\system32\dllcache\sis6306p.sys
2009-08-06 13:52 . 2001-08-17 17:51 17280 —-a-w- c:\windows\system32\dllcache\scr111.sys
2009-08-06 13:51 . 2001-08-17 16:50 41216 —-a-w- c:\windows\system32\dllcache\s3mt3d.sys
2009-08-06 13:50 . 2001-08-18 02:36 23040 —-a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
2009-08-06 13:49 . 2004-08-04 04:56 159232 —-a-w- c:\windows\system32\dllcache\ptpusd.dll
2009-08-06 13:48 . 2004-08-04 04:56 211712 —-a-w- c:\windows\system32\dllcache\perm2dll.dll
2009-08-06 13:47 . 2001-08-17 18:05 31872 —-a-w- c:\windows\system32\dllcache\ovce.sys
2009-08-06 13:46 . 2001-08-17 16:20 87040 —-a-w- c:\windows\system32\dllcache\nm6wdm.sys
2009-08-06 13:45 . 2001-08-17 17:50 75520 —-a-w- c:\windows\system32\dllcache\mxport.sys
2009-08-06 13:44 . 2001-08-17 18:02 35200 —-a-w- c:\windows\system32\dllcache\msgame.sys
2009-08-06 13:43 . 2001-08-17 16:19 48768 —-a-w- c:\windows\system32\dllcache\maestro.sys
2009-08-06 13:42 . 2004-08-04 13:00 70656 —-a-w- c:\windows\system32\dllcache\korwbrkr.dll
2009-08-06 13:41 . 2004-08-04 13:00 35328 —-a-w- c:\windows\system32\dllcache\iprip.dll
2009-08-06 13:40 . 2001-08-18 02:36 91136 —-a-w- c:\windows\system32\dllcache\icam4com.dll
2009-08-06 13:39 . 2004-08-04 02:41 1041536 —-a-w- c:\windows\system32\dllcache\hsfdpsp2.sys
2009-08-06 13:38 . 2001-08-18 02:36 32768 —-a-w- c:\windows\system32\dllcache\hpgtmcro.dll
2009-08-06 13:37 . 2001-08-17 16:49 322432 —-a-w- c:\windows\system32\dllcache\g400m.sys
2009-08-06 13:36 . 2001-08-17 16:11 11850 —-a-w- c:\windows\system32\dllcache\f3ab18xj.sys
2009-08-06 13:35 . 2001-08-17 16:12 18503 —-a-w- c:\windows\system32\dllcache\epro4.sys
2009-08-06 13:34 . 2001-08-17 16:11 26698 —-a-w- c:\windows\system32\dllcache\dlh5xnd5.sys
2009-08-06 13:33 . 2001-08-17 16:12 117760 —-a-w- c:\windows\system32\dllcache\d100ib5.sys
2009-08-06 13:32 . 2004-08-04 13:00 9728 —-a-w- c:\windows\system32\dllcache\change.exe
2009-08-06 13:31 . 2001-08-18 02:36 9728 —-a-w- c:\windows\system32\dllcache\brserif.dll
2009-08-06 13:30 . 2004-08-04 02:29 63663 —-a-w- c:\windows\system32\dllcache\ati1rvxx.sys
2009-08-06 13:29 . 2003-03-24 20:52 16384 —-a-w- c:\windows\system32\dllcache\tcptsat.dll
2009-08-06 06:40 . 2009-08-06 06:40 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2009-08-06 06:40 . 2009-08-06 06:40 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2009-08-05 04:09 . 2009-08-05 04:09 ——– d-s—w- c:\documents and settings\LocalService\UserData
2009-08-04 23:57 . 2009-08-04 23:57 ——– d—–w- c:\documents and settings\TEMP\Application Data\CoreFTP
2009-08-03 00:07 . 2009-08-15 12:23 ——– d–h–w- C:\$AVG8.VAULT$
2009-08-03 00:06 . 2009-08-03 00:06 ——– d—–w- c:\documents and settings\TEMP\Local Settings\Application Data\AVG Security Toolbar
2009-08-03 00:03 . 2009-08-03 00:03 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-03 00:03 . 2009-08-03 00:03 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-03 00:02 . 2009-08-03 00:02 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-03 00:02 . 2009-08-03 00:02 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-03 00:02 . 2009-08-16 13:50 ——– d—–w- c:\windows\system32\drivers\Avg
2009-08-03 00:01 . 2009-08-13 15:59 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-03 00:01 . 2009-08-03 00:01 ——– d—–w- c:\program files\AVG
2009-08-03 00:01 . 2009-08-12 01:56 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-02 23:39 . 2009-08-02 23:39 ——– d—–w- c:\documents and settings\TEMP\Application Data\AVG8
2009-08-02 06:06 . 2009-08-02 06:06 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2009-08-02 06:05 . 2009-08-02 06:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-08-02 04:46 . 2009-08-02 04:46 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2009-08-02 04:44 . 2009-08-02 04:46 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-08-02 00:57 . 2008-11-27 22:47 ——– d—a-w- c:\windows\system32\images

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-17 17:14 . 2008-07-06 22:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-17 17:14 . 2006-02-25 17:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-13 18:08 . 2009-06-25 15:48 ——– d—–w- c:\documents and settings\All Users\Application Data\17523904
2009-08-13 16:45 . 2006-02-25 17:01 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-13 15:48 . 2008-06-17 04:26 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-02 16:11 . 2009-04-15 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverCure
2009-08-02 06:42 . 2009-06-25 15:48 ——– d—–w- c:\documents and settings\All Users\Application Data\97533896
2009-08-02 04:33 . 2009-04-13 02:32 101816 —-a-w- c:\documents and settings\TEMP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-27 06:12 . 2009-04-22 06:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-13 05:54 . 2007-05-14 04:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Juniper Networks
2009-07-10 04:13 . 2009-06-26 03:12 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-07-10 04:13 . 2009-06-26 03:12 1630560 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-07-10 04:13 . 2009-06-26 03:11 2353480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-06-30 22:17 . 2009-06-30 22:17 152576 —-a-w- c:\documents and settings\TEMP\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-26 03:12 . 2009-06-26 14:08 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-26 03:12 . 2009-06-26 03:12 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-06-26 03:11 . 2009-06-26 04:10 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-26 03:11 . 2009-06-26 03:11 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-06-26 03:08 . 2009-06-26 03:08 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-26 03:07 . 2006-02-24 20:36 ——– d—–w- c:\program files\Lavasoft
2009-06-26 02:43 . 2009-06-26 02:43 10752 —-a-w- c:\windows\DCEBoot.exe
2009-06-23 14:57 . 2009-04-14 03:31 ——– d—–w- c:\documents and settings\Kendra\Application Data\uTorrent
2009-06-23 14:37 . 2006-08-18 20:31 100904 —-a-w- c:\documents and settings\Kendra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-23 14:34 . 2009-04-15 02:59 ——– d—–w- c:\documents and settings\TEMP\Application Data\uTorrent
2009-06-22 06:28 . 2006-10-13 18:31 ——– d—–w- c:\program files\CCleaner
2009-06-22 06:25 . 2009-06-22 06:25 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-06-03 18:39 . 2009-06-03 18:39 390664 —-a-w- c:\documents and settings\TEMP\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-28 04:41 . 2009-05-28 04:33 2988592 —-a-w- c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\DriverCure\Temp\Update.exe
2007-01-17 05:34 . 2007-01-17 05:34 110592 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55 1090816 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-19 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2009-05-27 1573104]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-09-28 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"LXBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-11-02 69632]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-03 520024]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-03 2000152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-05-30 5419008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-03 00:03 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PreCast Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PreCast Monitor.lnk
backup=c:\windows\pss\PreCast Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Kyle Mitchell^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Kyle Mitchell\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1141244859\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1141244859\\ee\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Kendra\\Desktop\\utorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/26/2009 12:10 AM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/2/2009 8:02 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/2/2009 8:03 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/2/2009 8:01 PM 297752]
R2 EvdoServer;EvdoServer;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 4:00 AM 14336]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
R2 sofatnet;sofatnet Service;c:\windows\system32\sofatnet.exe [8/4/2004 4:00 AM 95232]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/19/2008 11:35 AM 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/22/2005 5:06 AM 231424]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\34.tmp –> c:\windows\system32\34.tmp [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - EVDOSERVER
*Deregistered* - uphcleanhlp
.
Contents of the 'Scheduled Tasks' folder

2009-08-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:12]

2009-08-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-08-17 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]

2009-08-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2009-08-16 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]

2009-08-17 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
.
- - - - ORPHANS REMOVED - - - -

SharedTaskScheduler-{d1577581-2ed7-469f-99b1-72c1339e0ee0} - (no file)
ShellExecuteHooks-{40847941-2F5E-4BEB-802C-74849B8BA2E4} - (no file)
Notify-dimsntfy - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = www.google.com
mSearch Bar = hxxp://www.google.com/ie
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
FF - ProfilePath - c:\documents and settings\TEMP\Application Data\Mozilla\Firefox\Profiles\j9crvi4b.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrWB.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-17 13:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\34.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2476)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\UPHClean\uphclean.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\TEMP\tmp0_560883264348.bk.old
c:\windows\system32\ati2evxx.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-08-17 13:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-17 17:24

Pre-Run: 7,986,196,480 bytes free
Post-Run: 8,580,300,800 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=5 Default=5 Failed=3 LastKnownGood=6 Sets=1,2,3,4,5,6
427 — E O F — 2009-07-03 01:09

Attachments:

Hi Kyle,

No problem on the delay, glad you were able to run cf as it removed quite a bit. More work to do though….

1. Open Notepad

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\windows\system32\sofatnet.exe
c:\windows\system32\34.tmp

Driver:::
EvdoServer
sofatnet
MEMSWEEP2


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Let me know how it's running at this point also.
Second combofix is complete. the computer responded slowly initally after completion. it is doing fine now. I have not checked the usb drives yet though. not sure if when plugging in a usb and the system freezing had anything to do with the rootkits.


ComboFix 09-08-10.06 - Kyle Mitchell 08/18/2009 0:35.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.894.332 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\TEMP\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\windows\system32\34.tmp"
"c:\windows\system32\sofatnet.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Install.txt
c:\windows\system32\FInstall.sys
c:\windows\system32\sofatnet.exe
c:\windows\system32\wiawow32.sys
c:\windows\system32\wiwow64.exe
c:\windows\TEMP\mpj114915.dll
c:\windows\TEMP\mta13187.dll
c:\windows\TEMP\mta29252.dll
c:\windows\TEMP\tmp0_854361274510.bk.old
c:\windows\TEMP\x1c40230.dll


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_EVDOSERVER
——-\Legacy_MEMSWEEP2
——-\Legacy_SOFATNET
——-\Service_EvdoServer
——-\Service_MEMSWEEP2
——-\Service_sofatnet


((((((((((((((((((((((((( Files Created from 2009-07-18 to 2009-08-18 )))))))))))))))))))))))))))))))
.

2009-08-14 00:39 . 2009-08-14 00:39 ——– d—–w- c:\program files\Sophos
2009-08-13 18:16 . 2009-08-13 18:17 ——– d—–w- c:\documents and settings\TEMP\Local Settings\Application Data\AOL
2009-08-13 16:24 . 2009-08-13 16:24 ——– d—–w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-08-13 16:24 . 2009-08-13 16:24 ——– d—–w- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-08-13 16:24 . 2009-08-13 16:24 ——– d—–w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-08-13 16:24 . 2009-08-13 16:24 ——– d—–w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-08-13 15:59 . 2009-07-24 13:55 1090816 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-08-12 01:52 . 2009-08-12 01:52 262144 —-a-w- c:\windows\system32\default_user_class.dat
2009-08-12 01:20 . 2009-08-12 01:20 ——– d—–w- c:\documents and settings\TEMP\Application Data\Malwarebytes
2009-08-12 01:17 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-12 01:17 . 2009-08-14 00:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-12 01:17 . 2009-08-12 01:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-12 01:17 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-10 07:50 . 2009-08-12 01:54 ——– d—–w- c:\program files\wxfrgh
2009-08-10 07:41 . 2009-08-10 07:41 120 —-a-w- c:\windows\system32\358361390.BAT
2009-08-10 04:54 . 2009-08-12 17:23 ——– d—–w- c:\documents and settings\TEMP\Application Data\McAfee
2009-08-10 04:54 . 2009-08-10 04:54 127 —-a-w- c:\documents and settings\TEMP\Local Settings\Application Data\fusioncache.dat
2009-08-06 14:12 . 2009-08-06 14:12 ——– d—–w- c:\program files\UPHClean
2009-08-06 14:03 . 2004-08-04 04:56 116224 —-a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2009-08-06 14:03 . 2001-08-18 02:36 23040 —-a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-08-06 14:03 . 2001-08-18 02:36 17408 —-a-w- c:\windows\system32\dllcache\xrxscnui.dll
2009-08-06 14:03 . 2001-08-18 02:37 27648 —-a-w- c:\windows\system32\dllcache\xrxftplt.exe
2009-08-06 14:03 . 2001-08-18 02:37 4608 —-a-w- c:\windows\system32\dllcache\xrxflnch.exe
2009-08-06 14:02 . 2001-08-18 02:37 99865 —-a-w- c:\windows\system32\dllcache\xlog.exe
2009-08-06 14:02 . 2001-08-17 16:11 16970 —-a-w- c:\windows\system32\dllcache\xem336n5.sys
2009-08-06 14:02 . 2004-08-04 02:29 19455 —-a-w- c:\windows\system32\dllcache\wvchntxx.sys
2009-08-06 14:02 . 2004-08-04 02:29 12063 —-a-w- c:\windows\system32\dllcache\wsiintxx.sys
2009-08-06 14:02 . 2004-08-04 02:31 154624 —-a-w- c:\windows\system32\dllcache\wlluc48.sys
2009-08-06 14:02 . 2001-08-17 16:12 34890 —-a-w- c:\windows\system32\dllcache\wlandrv2.sys
2009-08-06 14:02 . 2001-08-17 17:28 771581 —-a-w- c:\windows\system32\dllcache\winacisa.sys
2009-08-06 14:00 . 2001-08-17 16:14 249402 —-a-w- c:\windows\system32\dllcache\vinwm.sys
2009-08-06 13:59 . 2001-08-18 02:36 94720 —-a-w- c:\windows\system32\dllcache\umaxud32.dll
2009-08-06 13:58 . 2001-08-18 02:36 525568 —-a-w- c:\windows\system32\dllcache\tridxp.dll
2009-08-06 13:57 . 2004-08-04 13:00 455168 —-a-w- c:\windows\system32\dllcache\tintsetp.exe
2009-08-06 13:56 . 2001-08-17 18:07 30688 —-a-w- c:\windows\system32\dllcache\sym_u3.sys
2009-08-06 13:55 . 2001-08-18 02:36 24660 —-a-w- c:\windows\system32\dllcache\spxupchk.dll
2009-08-06 13:54 . 2001-08-17 16:12 24576 —-a-w- c:\windows\system32\dllcache\smc8000n.sys
2009-08-06 13:53 . 2001-08-17 16:50 68608 —-a-w- c:\windows\system32\dllcache\sis6306p.sys
2009-08-06 13:52 . 2001-08-17 17:51 17280 —-a-w- c:\windows\system32\dllcache\scr111.sys
2009-08-06 13:51 . 2001-08-17 16:50 41216 —-a-w- c:\windows\system32\dllcache\s3mt3d.sys
2009-08-06 13:50 . 2001-08-18 02:36 23040 —-a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
2009-08-06 13:49 . 2004-08-04 04:56 159232 —-a-w- c:\windows\system32\dllcache\ptpusd.dll
2009-08-06 13:48 . 2004-08-04 04:56 211712 —-a-w- c:\windows\system32\dllcache\perm2dll.dll
2009-08-06 13:47 . 2001-08-17 18:05 31872 —-a-w- c:\windows\system32\dllcache\ovce.sys
2009-08-06 13:46 . 2001-08-17 16:20 87040 —-a-w- c:\windows\system32\dllcache\nm6wdm.sys
2009-08-06 13:45 . 2001-08-17 17:50 75520 —-a-w- c:\windows\system32\dllcache\mxport.sys
2009-08-06 13:44 . 2001-08-17 18:02 35200 —-a-w- c:\windows\system32\dllcache\msgame.sys
2009-08-06 13:43 . 2001-08-17 16:19 48768 —-a-w- c:\windows\system32\dllcache\maestro.sys
2009-08-06 13:42 . 2004-08-04 13:00 70656 —-a-w- c:\windows\system32\dllcache\korwbrkr.dll
2009-08-06 13:41 . 2004-08-04 13:00 35328 —-a-w- c:\windows\system32\dllcache\iprip.dll
2009-08-06 13:40 . 2001-08-18 02:36 91136 —-a-w- c:\windows\system32\dllcache\icam4com.dll
2009-08-06 13:39 . 2004-08-04 02:41 1041536 —-a-w- c:\windows\system32\dllcache\hsfdpsp2.sys
2009-08-06 13:38 . 2001-08-18 02:36 32768 —-a-w- c:\windows\system32\dllcache\hpgtmcro.dll
2009-08-06 13:37 . 2001-08-17 16:49 322432 —-a-w- c:\windows\system32\dllcache\g400m.sys
2009-08-06 13:36 . 2001-08-17 16:11 11850 —-a-w- c:\windows\system32\dllcache\f3ab18xj.sys
2009-08-06 13:35 . 2001-08-17 16:12 18503 —-a-w- c:\windows\system32\dllcache\epro4.sys
2009-08-06 13:34 . 2001-08-17 16:11 26698 —-a-w- c:\windows\system32\dllcache\dlh5xnd5.sys
2009-08-06 13:33 . 2001-08-17 16:12 117760 —-a-w- c:\windows\system32\dllcache\d100ib5.sys
2009-08-06 13:32 . 2004-08-04 13:00 9728 —-a-w- c:\windows\system32\dllcache\change.exe
2009-08-06 13:31 . 2001-08-18 02:36 9728 —-a-w- c:\windows\system32\dllcache\brserif.dll
2009-08-06 13:30 . 2004-08-04 02:29 63663 —-a-w- c:\windows\system32\dllcache\ati1rvxx.sys
2009-08-06 13:29 . 2003-03-24 20:52 16384 —-a-w- c:\windows\system32\dllcache\tcptsat.dll
2009-08-06 06:40 . 2009-08-06 06:40 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2009-08-06 06:40 . 2009-08-06 06:40 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2009-08-05 04:09 . 2009-08-05 04:09 ——– d-s—w- c:\documents and settings\LocalService\UserData
2009-08-04 23:57 . 2009-08-04 23:57 ——– d—–w- c:\documents and settings\TEMP\Application Data\CoreFTP
2009-08-03 00:07 . 2009-08-17 19:03 ——– d–h–w- C:\$AVG8.VAULT$
2009-08-03 00:06 . 2009-08-03 00:06 ——– d—–w- c:\documents and settings\TEMP\Local Settings\Application Data\AVG Security Toolbar
2009-08-03 00:03 . 2009-08-03 00:03 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-03 00:03 . 2009-08-03 00:03 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-03 00:02 . 2009-08-03 00:02 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-03 00:02 . 2009-08-03 00:02 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-03 00:02 . 2009-08-17 21:43 ——– d—–w- c:\windows\system32\drivers\Avg
2009-08-03 00:01 . 2009-08-13 15:59 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-03 00:01 . 2009-08-03 00:01 ——– d—–w- c:\program files\AVG
2009-08-03 00:01 . 2009-08-12 01:56 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-02 23:39 . 2009-08-02 23:39 ——– d—–w- c:\documents and settings\TEMP\Application Data\AVG8
2009-08-02 06:06 . 2009-08-02 06:06 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2009-08-02 06:05 . 2009-08-02 06:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-08-02 04:46 . 2009-08-02 04:46 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2009-08-02 04:44 . 2009-08-02 04:46 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-08-02 00:57 . 2008-11-27 22:47 ——– d—a-w- c:\windows\system32\images

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-18 05:14 . 2008-07-06 22:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-17 17:14 . 2006-02-25 17:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-13 18:08 . 2009-06-25 15:48 ——– d—–w- c:\documents and settings\All Users\Application Data\17523904
2009-08-13 16:45 . 2006-02-25 17:01 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-13 15:48 . 2008-06-17 04:26 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-02 16:11 . 2009-04-15 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverCure
2009-08-02 06:42 . 2009-06-25 15:48 ——– d—–w- c:\documents and settings\All Users\Application Data\97533896
2009-08-02 04:33 . 2009-04-13 02:32 101816 —-a-w- c:\documents and settings\TEMP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-27 06:12 . 2009-04-22 06:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-13 05:54 . 2007-05-14 04:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Juniper Networks
2009-07-10 04:13 . 2009-06-26 03:12 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-07-10 04:13 . 2009-06-26 03:12 1630560 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-07-10 04:13 . 2009-06-26 03:11 2353480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-06-30 22:17 . 2009-06-30 22:17 152576 —-a-w- c:\documents and settings\TEMP\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-26 03:12 . 2009-06-26 14:08 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-26 03:12 . 2009-06-26 03:12 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-06-26 03:11 . 2009-06-26 04:10 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-26 03:11 . 2009-06-26 03:11 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-06-26 03:08 . 2009-06-26 03:08 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-26 03:07 . 2006-02-24 20:36 ——– d—–w- c:\program files\Lavasoft
2009-06-26 02:43 . 2009-06-26 02:43 10752 —-a-w- c:\windows\DCEBoot.exe
2009-06-23 14:57 . 2009-04-14 03:31 ——– d—–w- c:\documents and settings\Kendra\Application Data\uTorrent
2009-06-23 14:37 . 2006-08-18 20:31 100904 —-a-w- c:\documents and settings\Kendra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-23 14:34 . 2009-04-15 02:59 ——– d—–w- c:\documents and settings\TEMP\Application Data\uTorrent
2009-06-22 06:28 . 2006-10-13 18:31 ——– d—–w- c:\program files\CCleaner
2009-06-22 06:25 . 2009-06-22 06:25 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-06-03 18:39 . 2009-06-03 18:39 390664 —-a-w- c:\documents and settings\TEMP\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-28 04:41 . 2009-05-28 04:33 2988592 —-a-w- c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\DriverCure\Temp\Update.exe
2007-01-17 05:34 . 2007-01-17 05:34 110592 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-17_17.11.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-18 04:50 . 2009-08-18 04:50 16384 c:\windows\Temp\Perflib_Perfdata_200.dat
- 2009-08-17 16:57 . 2009-08-17 16:57 180224 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
+ 2009-08-18 04:48 . 2009-08-18 04:48 180224 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
+ 2009-08-18 04:48 . 2009-08-18 04:48 540672 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
- 2009-08-17 16:57 . 2009-08-17 16:57 540672 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
+ 2009-08-18 04:48 . 2009-08-18 04:48 548864 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
- 2009-08-17 16:57 . 2009-08-17 16:57 548864 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
+ 2009-08-18 04:48 . 2009-08-18 04:48 4734976 c:\windows\ERDNT\subs\Users\00000009\NTUSER.DAT
+ 2009-08-18 04:48 . 2009-08-18 04:48 4698112 c:\windows\ERDNT\subs\Users\00000008\NTUSER.DAT
+ 2009-08-18 04:48 . 2009-08-18 04:48 5541888 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
- 2009-08-17 16:57 . 2009-08-17 16:57 5541888 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
- 2009-08-17 16:57 . 2009-08-17 16:57 3301376 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-18 04:48 . 2009-08-18 04:48 3301376 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-18 04:48 . 2009-08-18 04:48 3301376 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
- 2009-08-17 16:57 . 2009-08-17 16:57 3301376 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
+ 2009-08-18 04:48 . 2009-08-18 04:48 10215424 c:\windows\ERDNT\subs\Users\00000007\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55 1090816 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-19 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2009-05-27 1573104]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-09-28 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"LXBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-11-02 69632]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-03 520024]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-03 2000152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-05-30 5419008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-03 00:03 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[BU]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PreCast Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PreCast Monitor.lnk
backup=c:\windows\pss\PreCast Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Kyle Mitchell^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Kyle Mitchell\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1141244859\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1141244859\\ee\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Kendra\\Desktop\\utorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/26/2009 12:10 AM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/2/2009 8:02 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/2/2009 8:03 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/2/2009 8:01 PM 297752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/19/2008 11:35 AM 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/22/2005 5:06 AM 231424]

— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp
.
Contents of the 'Scheduled Tasks' folder

2009-08-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:12]

2009-08-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-08-18 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]

2009-08-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2009-08-17 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]

2009-08-18 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = www.google.com
mSearch Bar = hxxp://www.google.com/ie
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
FF - ProfilePath - c:\documents and settings\TEMP\Application Data\Mozilla\Firefox\Profiles\j9crvi4b.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrWB.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-18 01:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2848)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\UPHClean\uphclean.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\ati2evxx.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-08-18 1:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-18 05:22
ComboFix2.txt 2009-08-17 17:24

Pre-Run: 8,588,529,664 bytes free
Post-Run: 8,523,825,152 bytes free

Current=5 Default=5 Failed=3 LastKnownGood=6 Sets=1,2,3,4,5,6
357 — E O F — 2009-07-03 01:09


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:29:16 AM, on 8/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\TEMP\Desktop\third.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: (no name) - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - (no file)
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Guest')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Guest')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Guest')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MasterCook Web Import Bar - {E6EF5071-7647-4E85-9785-87B6CF5CB561} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://pconweb.darden.com/includes/smsx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 12174 bytes
Hi Kyle,

No need to attach files unless asked to do so.

Like to get a closer look here before doing any cleanup scans.

Run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all seven boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
OTL won't run. For some reason all my folders have "TEMP" in them. "C:\Documents and Settings\TEMP\Desktop", "C:\Documents and Settings\TEMP\My Documents" , the message says that OTL cannot run form a temp folder. please download it to your desktop or other suitable folder. it is currently saved on my desktop.

For some reason all my folders have "TEMP" in them

All your folders??? Errr…..I've never seen that before. Have you noticed it before? Or do you think it happened with the infection? See if you can make a new folder somewhere and move OTL there.

I'll look into the temp folder issue a little more when I get a chance. Don't remove anything for now.
when i check the C drive it is fine, just the my docs, and i didn't know about the desktop till now. i can save it to the c drive and try that
OTL.txt
OTL logfile created on: 8/21/2009 1:02:46 AM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.17 Mb Total Physical Memory | 236.18 Mb Available Physical Memory | 26.41% Memory free
2.12 Gb Paging File | 1.56 Gb Available in Paging File | 73.66% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.32 Gb Total Space | 7.31 Gb Free Space | 9.83% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KYLESCOMPUTER
Current User Name: Kyle Mitchell
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [Auto | Running]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqwmi [On_Demand | Stopped]) – C:\Program Files\HPQ\SHARED\HPQWMI.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (lxbu_device [On_Demand | Stopped]) – C:\WINDOWS\System32\lxbucoms.exe (Lexmark International, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (UPHClean [Auto | Running]) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (uploadmgr [Auto | Stopped]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AegisP [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (AmdK8 [System | Running]) – C:\WINDOWS\System32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (BTWUSB [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CAMCAUD [On_Demand | Running]) – C:\WINDOWS\System32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (CAMCHALA [On_Demand | Running]) – C:\WINDOWS\System32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (eabfiltr [System | Running]) – C:\WINDOWS\System32\drivers\EABFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabusb [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\eabusb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (FileDisk [System | Running]) – C:\WINDOWS\System32\drivers\filedisk.sys (Bo Brantén)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWATI [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSFHWATI.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (PalmUSBD [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\PalmUSBD.sys (Palm, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (QCMerced [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCM.sys ()
DRV - (RimSerPort [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (RimUsb [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RimUsb.sys (Research In Motion Limited)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (RTL8023xp [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SMCIRDA [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\smcirda.sys (SMC)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21 [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: *{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - Reg Error: Key error. File not found
IE - URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: avg@igeared:2.507.024.001
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/08/02 20:01:06 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/08/02 20:01:56 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/18 15:13:16 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/06 13:38:30 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/06 13:38:30 | 00,000,000 | —D | M]

[2009/04/13 10:24:15 | 00,000,000 | —D | M] – C:\Documents and Settings\TEMP\Application Data\mozilla\Extensions
[2009/04/13 10:24:15 | 00,000,000 | —D | M] – C:\Documents and Settings\TEMP\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/20 13:27:30 | 00,000,000 | —D | M] – C:\Documents and Settings\TEMP\Application Data\mozilla\Firefox\Profiles\j9crvi4b.default\extensions
[2009/06/22 03:28:30 | 00,000,000 | —D | M] – C:\Documents and Settings\TEMP\Application Data\mozilla\Firefox\Profiles\j9crvi4b.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/08/20 13:27:31 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/06 13:38:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/11/07 05:18:03 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/03/29 11:34:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/08/06 13:38:21 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/06 13:38:21 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/01/17 01:34:24 | 00,110,592 | —- | M] () – C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll
[2006/09/03 14:12:48 | 00,049,152 | —- | M] (Adobe Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009/03/29 11:32:52 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2008/01/04 17:57:08 | 01,335,600 | —- | M] (DivX,Inc.) – C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2008/01/07 19:14:26 | 00,098,304 | —- | M] (DivX, Inc) – C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2006/02/11 14:50:28 | 00,024,576 | —- | M] (RealNetworks) – C:\Program Files\mozilla firefox\plugins\npgcplug.dll
[2006/11/29 17:32:30 | 01,440,560 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2006/07/01 03:07:51 | 00,024,576 | —- | M] (My Web Search) – C:\Program Files\mozilla firefox\plugins\NPMySrWB.dll
[2009/08/06 13:38:21 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2006/12/18 04:18:30 | 00,077,824 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/04/05 21:17:45 | 00,144,984 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009/05/03 11:50:45 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/05/03 11:50:45 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/05/03 11:50:45 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/05/03 11:50:45 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/05/03 11:50:46 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/05/03 11:50:46 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/05/03 11:50:46 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2005/04/27 16:10:49 | 00,102,400 | —- | M] (RealNetworks) – C:\Program Files\mozilla firefox\plugins\npracplug.dll
[2008/04/05 21:18:18 | 00,008,192 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2008/04/05 21:17:16 | 00,094,208 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2005/08/09 14:42:53 | 00,057,344 | —- | M] (America Online, Inc.) – C:\Program Files\mozilla firefox\plugins\npunagi2.dll
[2007/04/16 13:07:12 | 00,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2008/10/30 02:00:50 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/10/30 02:00:50 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/02 20:06:25 | 00,001,490 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg_igeared.xml
[2008/10/30 02:00:50 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/10/30 02:00:50 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/10/30 02:00:50 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/10/30 02:00:50 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe (America Online, Inc.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LXBUCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.DLL ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ccleaner] C:\Program Files\CCleaner\ccleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe (PC Tools)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} http://housecall60.trendmicro.com/housecall/xscan60.cab (HouseCall Control)
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} http://pconweb.darden.com/includes/smsx.cab (MeadCo ScriptX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab (InetDownload Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[257 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/08/21 00:59:18 | 00,472,064 | —- | C] ( ) – C:\Documents and Settings\TEMP\Desktop\RootRepeal.exe
[2009/08/20 13:26:26 | 00,000,104 | —- | C] () – C:\Documents and Settings\TEMP\Desktop\Internet.lnk
[2009/08/18 15:11:06 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/08/18 15:10:38 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/08/18 15:09:12 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/08/18 15:09:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/08/18 15:09:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/08/18 15:09:12 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/08/18 15:09:12 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/08/18 15:09:11 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/08/18 15:09:11 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/08/18 15:09:10 | 00,000,000 | —D | C] – C:\b53cfca89379a45a1b22ffd87600
[2009/08/18 15:04:00 | 00,000,000 | —D | C] – C:\Program Files\MSXML 6.0
[2009/08/18 12:48:40 | 00,000,000 | —D | C] – C:\Documents and Settings\TEMP\Desktop\New Folder
[2009/08/18 12:44:49 | 00,514,048 | —- | C] (OldTimer Tools) – C:\OTL.exe
[2009/08/18 01:12:43 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/08/17 13:21:25 | 01,580,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/08/17 13:21:25 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/08/17 13:21:25 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/08/17 13:21:25 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/08/17 13:21:25 | 00,574,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntfs.sys
[2009/08/17 13:21:25 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/08/17 13:21:25 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netlogon.dll
[2009/08/17 13:21:25 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/08/17 13:21:25 | 00,382,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\qmgr.dll
[2009/08/17 13:21:25 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\scecli.dll
[2009/08/17 13:21:25 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\srsvc.dll
[2009/08/17 13:21:25 | 00,142,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\aec.sys
[2009/08/17 13:21:25 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/08/17 13:21:25 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/08/17 13:21:25 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/08/17 13:21:25 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/08/17 13:21:25 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\asyncmac.sys
[2009/08/17 13:21:25 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wscntfy.exe
[2009/08/17 13:21:25 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/08/17 13:21:25 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/08/17 13:21:25 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/08/17 13:21:25 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/08/17 13:21:24 | 03,068,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mshtml.dll
[2009/08/17 13:21:24 | 02,186,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/08/17 13:21:24 | 02,062,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/08/17 13:21:24 | 01,033,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/08/17 13:21:24 | 00,986,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/08/17 13:21:24 | 00,668,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/08/17 13:21:24 | 00,577,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/08/17 13:21:24 | 00,502,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/08/17 13:21:24 | 00,360,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/08/17 13:21:24 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/08/17 13:21:24 | 00,182,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/08/17 13:21:24 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/08/17 13:21:24 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/08/17 13:21:24 | 00,082,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/08/17 13:21:24 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/08/17 13:21:24 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/08/17 13:21:24 | 00,029,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/08/17 13:21:24 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/08/17 13:21:24 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/08/17 13:21:24 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/08/17 13:21:24 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/08/17 13:21:24 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/08/17 13:21:24 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/08/17 12:20:33 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/08/17 12:20:14 | 00,260,272 | —- | C] () – C:\cmldr
[2009/08/17 12:20:06 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/08/17 12:16:55 | 00,216,064 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/17 12:16:55 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/17 12:16:54 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/17 12:16:54 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/17 12:16:54 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/17 12:16:54 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/17 12:16:54 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/17 12:16:54 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/17 12:16:19 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/17 12:14:11 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/17 12:09:39 | 03,124,187 | R— | C] () – C:\Documents and Settings\TEMP\Desktop\Combo-Fix.exe
[2009/08/14 19:19:18 | 00,005,630 | —- | C] () – C:\Documents and Settings\TEMP\Desktop\Attach.zip
[2009/08/14 18:47:43 | 00,287,744 | —- | C] () – C:\Documents and Settings\TEMP\Desktop\tewyfq4m.exe
[2009/08/14 18:46:54 | 00,359,932 | —- | C] () – C:\Documents and Settings\TEMP\Desktop\dds.scr
[2009/08/13 20:39:38 | 00,000,000 | —D | C] – C:\Program Files\Sophos
[2009/08/13 20:37:13 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\TEMP\Desktop\third.exe
[2009/08/13 20:33:36 | 01,339,288 | —- | C] () – C:\Documents and Settings\TEMP\Desktop\first.exe
[2009/08/13 14:16:45 | 00,000,000 | —D | C] – C:\Documents and Settings\TEMP\Local Settings\Application Data\AOL
[2009/08/13 14:08:13 | 00,001,061 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/08/13 12:43:05 | 00,000,933 | —- | C] () – C:\Documents and Settings\TEMP\Desktop\Spybot - Search & Destroy.lnk
[2009/08/13 12:25:05 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\TEMP\Desktop\setup-spybotsd162.exe
[2009/08/13 12:24:49 | 00,000,000 | —D | C] – C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
[2009/08/13 12:24:47 | 00,000,000 | —D | C] – C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2009/08/13 12:24:46 | 00,000,000 | —D | C] – C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2009/08/13 12:24:45 | 00,000,000 | —D | C] – C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2009/08/11 22:20:01 | 00,035,896 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\cc_20090811_221948.reg
[2009/08/11 21:52:35 | 00,262,144 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat
[2009/08/11 21:23:06 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\STKIT432.DLL
[2009/08/11 21:23:06 | 00,000,738 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Registry Mechanic.lnk
[2009/08/11 21:22:04 | 00,000,000 | —D | C] – C:\Program Files\Registry Mechanic
[2009/08/11 21:20:34 | 00,000,000 | —D | C] – C:\Documents and Settings\TEMP\Application Data\Malwarebytes
[2009/08/11 21:17:51 | 00,000,701 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/11 21:17:48 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/11 21:17:46 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/11 21:17:46 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/11 21:17:46 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/08/10 03:50:45 | 00,000,000 | —D | C] – C:\Program Files\wxfrgh
[2009/08/10 03:41:35 | 00,000,120 | —- | C] () – C:\WINDOWS\System32\358361390.BAT
[2009/08/10 00:54:42 | 00,000,000 | —D | C] – C:\Documents and Settings\TEMP\Application Data\McAfee
[2009/08/10 00:54:24 | 00,000,127 | —- | C] () – C:\Documents and Settings\TEMP\Local Settings\Application Data\fusioncache.dat
[2009/08/06 10:12:18 | 00,000,000 | —D | C] – C:\Program Files\UPHClean
[2009/08/06 10:03:25 | 00,116,224 | —- | C] (Xerox) – C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2009/08/06 10:03:21 | 00,023,040 | —- | C] (Xerox Corporation) – C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2009/08/06 10:03:17 | 00,017,408 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2009/08/06 10:03:12 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2009/08/06 10:03:07 | 00,004,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2009/08/06 10:02:59 | 00,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2009/08/06 10:02:58 | 00,028,288 | —- | C] () – C:\WINDOWS\System32\dllcache\xjis.nls
[2009/08/06 10:02:52 | 00,016,970 | —- | C] (US Robotics MCD (Megahertz)) – C:\WINDOWS\System32\dllcache\xem336n5.sys
[2009/08/06 10:02:51 | 00,019,455 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wvchntxx.sys
[2009/08/06 10:02:43 | 00,012,063 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wsiintxx.sys
[2009/08/06 10:02:19 | 00,154,624 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\wlluc48.sys
[2009/08/06 10:02:15 | 00,034,890 | —- | C] (Raytheon Corp.) – C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2009/08/06 10:02:13 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winzm.ime
[2009/08/06 10:02:11 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winsp.ime
[2009/08/06 10:02:10 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winpy.ime
[2009/08/06 10:02:09 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winime.ime
[2009/08/06 10:02:08 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wingb.ime
[2009/08/06 10:02:07 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winar30.ime
[2009/08/06 10:02:03 | 00,771,581 | —- | C] (Rockwell) – C:\WINDOWS\System32\dllcache\winacisa.sys
[2009/08/06 10:01:56 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2009/08/06 10:01:55 | 00,041,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\weitekp9.dll
[2009/08/06 10:01:55 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\weitekp9.sys
[2009/08/06 10:01:48 | 00,701,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\wdhaalba.sys
[2009/08/06 10:01:48 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2009/08/06 10:01:48 | 00,023,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wch7xxnt.sys
[2009/08/06 10:01:43 | 00,035,871 | —- | C] (Winbond Electronics Corp.) – C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2009/08/06 10:01:41 | 00,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv10nt.sys
[2009/08/06 10:01:40 | 00,033,599 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv04nt.sys
[2009/08/06 10:01:40 | 00,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv06nt.sys
[2009/08/06 10:01:39 | 00,019,551 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv02nt.sys
[2009/08/06 10:01:38 | 00,029,311 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv01nt.sys
[2009/08/06 10:01:36 | 00,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv11nt.sys
[2009/08/06 10:01:36 | 00,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv09nt.sys
[2009/08/06 10:01:36 | 00,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv08nt.sys
[2009/08/06 10:01:35 | 00,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv07nt.sys
[2009/08/06 10:01:34 | 00,012,127 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv02nt.sys
[2009/08/06 10:01:34 | 00,011,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv05nt.sys
[2009/08/06 10:01:33 | 00,012,415 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv01nt.sys
[2009/08/06 10:01:32 | 00,013,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wacompen.sys
[2009/08/06 10:01:26 | 00,016,925 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w940nd.sys
[2009/08/06 10:01:22 | 00,019,016 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w926nd.sys
[2009/08/06 10:01:17 | 00,048,256 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\w32.dll
[2009/08/06 10:01:17 | 00,019,528 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w840nd.sys
[2009/08/06 10:01:12 | 00,064,605 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vvoice.sys
[2009/08/06 10:01:07 | 00,426,041 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\voicepad.dll
[2009/08/06 10:01:07 | 00,397,502 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vpctcom.sys
[2009/08/06 10:01:07 | 00,086,073 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\voicesub.dll
[2009/08/06 10:01:02 | 00,604,253 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\vmodem.sys
[2009/08/06 10:00:58 | 00,249,402 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\vinwm.sys
[2009/08/06 10:00:53 | 00,042,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\viaagp.sys
[2009/08/06 10:00:53 | 00,024,576 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\viairda.sys
[2009/08/06 10:00:50 | 00,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\vchnt5.dll
[2009/08/06 10:00:46 | 00,687,999 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2009/08/06 10:00:41 | 00,765,884 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usrti.sys
[2009/08/06 10:00:36 | 00,113,762 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrpda.sys
[2009/08/06 10:00:32 | 00,007,556 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usroslba.sys
[2009/08/06 10:00:27 | 00,224,802 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usr1807a.sys
[2009/08/06 10:00:23 | 00,794,399 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806v.sys
[2009/08/06 10:00:18 | 00,793,598 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806.sys
[2009/08/06 10:00:14 | 00,794,654 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1801.sys
[2009/08/06 10:00:11 | 00,078,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbvideo.sys
[2009/08/06 10:00:11 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbser.sys
[2009/08/06 10:00:08 | 00,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usb8023x.sys
[2009/08/06 10:00:07 | 00,032,384 | —- | C] (KLSI USA, Inc.) – C:\WINDOWS\System32\dllcache\usb101et.sys
[2009/08/06 10:00:03 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\uniime.dll
[2009/08/06 10:00:03 | 00,065,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\unicdime.ime
[2009/08/06 09:59:59 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxud32.dll
[2009/08/06 09:59:54 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu40.dll
[2009/08/06 09:59:50 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu22.dll
[2009/08/06 09:59:46 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu12.dll
[2009/08/06 09:59:42 | 00,050,688 | —- | C] (UMAX DATA SYSTEMS INC.) – C:\WINDOWS\System32\dllcache\umaxscan.dll
[2009/08/06 09:59:38 | 00,022,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2009/08/06 09:59:33 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxp60.dll
[2009/08/06 09:59:29 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxcam.dll
[2009/08/06 09:59:25 | 00,211,968 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um54scan.dll
[2009/08/06 09:59:21 | 00,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2009/08/06 09:59:16 | 00,036,736 | —- | C] (Promise Technology, Inc.) – C:\WINDOWS\System32\dllcache\ultra.sys
[2009/08/06 09:59:14 | 00,044,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\uagp35.sys
[2009/08/06 09:59:09 | 00,011,520 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\twotrack.sys
[2009/08/06 09:59:08 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tsprof.exe
[2009/08/06 09:59:03 | 00,166,784 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxpm.sys
[2009/08/06 09:58:58 | 00,525,568 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxp.dll
[2009/08/06 09:58:54 | 00,159,232 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkbm.sys
[2009/08/06 09:58:50 | 00,440,576 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkb.dll
[2009/08/06 09:58:43 | 00,222,336 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3dm.sys
[2009/08/06 09:58:39 | 00,315,520 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3d.dll
[2009/08/06 09:58:35 | 00,034,375 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\tpro4.sys
[2009/08/06 09:58:30 | 00,082,432 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4mon.exe
[2009/08/06 09:58:30 | 00,042,496 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4res.dll
[2009/08/06 09:58:25 | 00,031,744 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4.dll
[2009/08/06 09:58:18 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\toside.sys
[2009/08/06 09:58:14 | 00,230,912 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd03.sys
[2009/08/06 09:58:09 | 00,241,664 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd02.sys
[2009/08/06 09:58:04 | 00,028,232 | —- | C] (TOSHIBA Corporation) – C:\WINDOWS\System32\dllcache\tos4mo.sys
[2009/08/06 09:58:04 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tmigrate.dll
[2009/08/06 09:57:59 | 00,455,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tintsetp.exe
[2009/08/06 09:57:59 | 00,123,995 | —- | C] (Tiger Jet Network) – C:\WINDOWS\System32\dllcache\tjisdn.sys
[2009/08/06 09:57:59 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tintlphr.exe
[2009/08/06 09:57:58 | 00,571,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tintlgnt.ime
[2009/08/06 09:57:52 | 00,138,528 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2009/08/06 09:57:45 | 00,081,408 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiul50.dll
[2009/08/06 09:57:44 | 00,149,376 | —- | C] (M-Systems) – C:\WINDOWS\System32\dllcache\tffsport.sys
[2009/08/06 09:57:40 | 00,019,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdspx.sys
[2009/08/06 09:57:36 | 00,017,129 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2009/08/06 09:57:32 | 00,037,961 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdk100b.sys
[2009/08/06 09:57:32 | 00,021,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdipx.sys
[2009/08/06 09:57:31 | 00,013,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdasync.sys
[2009/08/06 09:57:27 | 00,030,464 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tbatm155.sys
[2009/08/06 09:57:20 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tandqic.sys
[2009/08/06 09:57:17 | 00,036,640 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2009/08/06 09:57:13 | 00,172,768 | —- | C] (Number Nine Visual Technology) – C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2009/08/06 09:57:07 | 00,032,640 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\symc8xx.sys
[2009/08/06 09:57:03 | 00,016,256 | —- | C] (Symbios Logic Inc.) – C:\WINDOWS\System32\dllcache\symc810.sys
[2009/08/06 09:56:59 | 00,030,688 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\sym_u3.sys
[2009/08/06 09:56:55 | 00,028,384 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\sym_hi.sys
[2009/08/06 09:56:50 | 00,094,293 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sxports.dll
[2009/08/06 09:56:46 | 00,103,936 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sx.sys
[2009/08/06 09:56:43 | 00,003,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swusbflt.sys
[2009/08/06 09:56:39 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpidflt.dll
[2009/08/06 09:56:35 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2009/08/06 09:56:31 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2009/08/06 09:56:27 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_effct.dll
[2009/08/06 09:56:23 | 00,155,648 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnprop.dll
[2009/08/06 09:56:19 | 00,053,248 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlncoin.dll
[2009/08/06 09:56:15 | 00,285,760 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnata.sys
[2009/08/06 09:56:11 | 00,016,896 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\stcusb.sys
[2009/08/06 09:56:06 | 00,048,736 | —- | C] (3Com) – C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2009/08/06 09:56:01 | 00,099,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusd.dll
[2009/08/06 09:56:00 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusbusd.dll
[2009/08/06 09:55:54 | 00,024,660 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spxupchk.dll
[2009/08/06 09:55:48 | 00,061,824 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\speed.sys
[2009/08/06 09:55:44 | 00,106,584 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spdports.dll
[2009/08/06 09:55:40 | 00,019,072 | —- | C] (Adaptec, Inc.) – C:\WINDOWS\System32\dllcache\sparrow.sys
[2009/08/06 09:55:35 | 00,037,040 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.sys
[2009/08/06 09:55:31 | 00,114,688 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.dll
[2009/08/06 09:55:27 | 00,020,752 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonync.sys
[2009/08/06 09:55:24 | 00,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonymc.sys
[2009/08/06 09:55:23 | 00,143,422 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\softkey.dll
[2009/08/06 09:55:23 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonyait.sys
[2009/08/06 09:55:19 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2009/08/06 09:55:18 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpthrd.dll
[2009/08/06 09:55:18 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpstup.dll
[2009/08/06 09:55:18 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmptrap.exe
[2009/08/06 09:55:18 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll
[2009/08/06 09:55:17 | 00,358,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpincl.dll
[2009/08/06 09:55:17 | 00,259,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpcl.dll
[2009/08/06 09:55:17 | 00,188,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpsmir.dll
[2009/08/06 09:55:17 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpmib.dll
[2009/08/06 09:55:16 | 00,456,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpsvc.dll
[2009/08/06 09:55:16 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmp.exe
[2009/08/06 09:55:15 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll
[2009/08/06 09:55:15 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smimsgif.dll
[2009/08/06 09:55:11 | 00,058,368 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smiminib.sys
[2009/08/06 09:55:11 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smierrsm.dll
[2009/08/06 09:55:11 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smierrsy.dll
[2009/08/06 09:55:07 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smi2smir.exe
[2009/08/06 09:55:07 | 00,147,200 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smidispb.dll
[2009/08/06 09:55:03 | 00,025,034 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2009/08/06 09:54:59 | 00,024,576 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smc8000n.sys
[2009/08/06 09:54:55 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbhc.sys
[2009/08/06 09:54:54 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbclass.sys
[2009/08/06 09:54:53 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb6w.dll
[2009/08/06 09:54:53 | 00,016,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbbatt.sys
[2009/08/06 09:54:53 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbali.sys
[2009/08/06 09:54:49 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb3w.dll
[2009/08/06 09:54:45 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb0w.dll
[2009/08/06 09:54:45 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma3w.dll
[2009/08/06 09:54:41 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm9aw.dll
[2009/08/06 09:54:41 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma0w.dll
[2009/08/06 09:54:41 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm93w.dll
[2009/08/06 09:54:40 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm92w.dll
[2009/08/06 09:54:37 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm91w.dll
[2009/08/06 09:54:36 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8cw.dll
[2009/08/06 09:54:36 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm90w.dll
[2009/08/06 09:54:36 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8dw.dll
[2009/08/06 09:54:35 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm87w.dll
[2009/08/06 09:54:35 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8aw.dll
[2009/08/06 09:54:35 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm89w.dll
[2009/08/06 09:54:34 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm81w.dll
[2009/08/06 09:54:34 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm59w.dll
[2009/08/06 09:54:33 | 00,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slwdmsup.sys
[2009/08/06 09:54:32 | 00,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slserv.exe
[2009/08/06 09:54:32 | 00,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slrundll.exe
[2009/08/06 09:54:31 | 00,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slntamr.sys
[2009/08/06 09:54:31 | 00,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slnthal.sys
[2009/08/06 09:54:30 | 00,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slgen.dll
[2009/08/06 09:54:30 | 00,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slnt7554.sys
[2009/08/06 09:54:29 | 00,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slextspk.dll
[2009/08/06 09:54:29 | 00,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slcoinst.dll
[2009/08/06 09:54:28 | 00,063,547 | —- | C] (Symbol Technologies) – C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2009/08/06 09:54:24 | 00,091,294 | —- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) – C:\WINDOWS\System32\dllcache\skfpwin.sys
[2009/08/06 09:54:20 | 00,094,698 | —- | C] (SysKonnect GmbH.) – C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2009/08/06 09:54:17 | 00,157,696 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv256.dll
[2009/08/06 09:54:13 | 00,050,432 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv.sys
[2009/08/06 09:54:12 | 00,032,768 | —- | C] (SiS Corporation) – C:\WINDOWS\System32\dllcache\sisnic.sys
[2009/08/06 09:54:08 | 00,238,592 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrv.dll
[2009/08/06 09:54:04 | 00,104,064 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrp.sys
[2009/08/06 09:54:04 | 00,041,088 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisagp.sys
[2009/08/06 09:54:00 | 00,150,144 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306v.dll
[2009/08/06 09:53:56 | 00,068,608 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306p.sys
[2009/08/06 09:53:53 | 00,252,032 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300iv.dll
[2009/08/06 09:53:49 | 00,101,760 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300ip.sys
[2009/08/06 09:53:49 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\simptcp.dll
[2009/08/06 09:53:48 | 00,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\siint5.dll
[2009/08/06 09:53:38 | 00,161,568 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2009/08/06 09:53:34 | 00,018,400 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmld.sys
[2009/08/06 09:53:30 | 00,098,080 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2009/08/06 09:53:26 | 00,386,560 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiul50.dll
[2009/08/06 09:53:23 | 00,036,480 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\sfmanm.sys
[2009/08/06 09:53:17 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2009/08/06 09:53:14 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2009/08/06 09:53:13 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_seos.dll
[2009/08/06 09:53:09 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2009/08/06 09:53:05 | 00,010,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiscan.sys
[2009/08/06 09:53:01 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_scripto.dll
[2009/08/06 09:53:01 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2009/08/06 09:52:56 | 00,017,280 | —- | C] (SCM Microsystems) – C:\WINDOWS\System32\dllcache\scr111.sys
[2009/08/06 09:52:52 | 00,016,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scmstcs.sys
[2009/08/06 09:52:48 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2009/08/06 09:52:44 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2009/08/06 09:52:43 | 00,043,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sbp2port.sys
[2009/08/06 09:52:39 | 00,495,616 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\sblfx.dll
[2009/08/06 09:52:31 | 00,075,392 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmxm.sys
[2009/08/06 09:52:27 | 00,245,632 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmx.dll
[2009/08/06 09:52:23 | 00,077,824 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2009/08/06 09:52:20 | 00,198,400 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4.dll
[2009/08/06 09:52:15 | 00,061,504 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2009/08/06 09:52:11 | 00,179,264 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2009/08/06 09:52:04 | 00,210,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2009/08/06 09:52:00 | 00,062,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2009/08/06 09:51:57 | 00,041,216 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2009/08/06 09:51:53 | 00,182,272 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2009/08/06 09:51:49 | 00,166,720 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3m.sys
[2009/08/06 09:51:45 | 00,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3gnbm.sys
[2009/08/06 09:51:45 | 00,065,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.sys
[2009/08/06 09:51:44 | 00,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3gnb.dll
[2009/08/06 09:51:41 | 00,082,432 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia450.dll
[2009/08/06 09:51:37 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia430.dll
[2009/08/06 09:51:37 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia330.dll
[2009/08/06 09:51:36 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia001.dll
[2009/08/06 09:51:33 | 00,026,624 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw450ext.dll
[2009/08/06 09:51:29 | 00,026,624 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw330ext.dll
[2009/08/06 09:51:29 | 00,024,576 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw430ext.dll
[2009/08/06 09:51:29 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rw001ext.dll
[2009/08/06 09:51:27 | 00,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8139.sys
[2009/08/06 09:51:24 | 00,019,017 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8029.sys
[2009/08/06 09:51:20 | 00,030,720 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rthwcls.sys
[2009/08/06 09:51:16 | 00,009,216 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2009/08/06 09:51:12 | 00,003,840 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rpfun.sys
[2009/08/06 09:51:11 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\romanime.ime
[2009/08/06 09:51:10 | 00,079,104 | —- | C] (Comtrol Corporation) – C:\WINDOWS\System32\dllcache\rocket.sys
[2009/08/06 09:51:09 | 00,030,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rndismpx.sys
[2009/08/06 09:51:05 | 00,037,563 | —- | C] (RadioLAN) – C:\WINDOWS\System32\dllcache\rlnet5.sys
[2009/08/06 09:51:04 | 00,059,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rfcomm.sys
[2009/08/06 09:51:00 | 00,086,097 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\reslog32.dll
[2009/08/06 09:50:58 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe
[2009/08/06 09:50:57 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\register.exe
[2009/08/06 09:50:55 | 00,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\recagent.sys
[2009/08/06 09:50:49 | 00,020,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ramdisk.sys
[2009/08/06 09:50:45 | 00,714,762 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2009/08/06 09:50:41 | 00,899,146 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2009/08/06 09:50:37 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qvusd.dll
[2009/08/06 09:50:34 | 00,003,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qv2kux.sys
[2009/08/06 09:50:33 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\quick.ime
[2009/08/06 09:50:33 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\quser.exe
[2009/08/06 09:50:33 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\query.exe
[2009/08/06 09:50:27 | 00,049,024 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql1280.sys
[2009/08/06 09:50:23 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql1240.sys
[2009/08/06 09:50:19 | 00,045,312 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql12160.sys
[2009/08/06 09:50:16 | 00,033,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql10wnt.sys
[2009/08/06 09:50:12 | 00,040,320 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql1080.sys
[2009/08/06 09:50:11 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qic157.sys
[2009/08/06 09:50:07 | 00,130,942 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlv.sys
[2009/08/06 09:50:03 | 00,112,574 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlp.sys
[2009/08/06 09:50:00 | 00,128,286 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserli.sys
[2009/08/06 09:49:59 | 00,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusd.dll
[2009/08/06 09:49:55 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusb.dll
[2009/08/06 09:49:54 | 00,033,280 | —- | C] () – C:\WINDOWS\System32\dllcache\psisrndr.ax
[2009/08/06 09:49:51 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\psisload.dll
[2009/08/06 09:49:50 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\dllcache\psisdecd.dll
[2009/08/06 09:49:46 | 00,016,128 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\pscr.sys
[2009/08/06 09:49:43 | 00,083,748 | —- | C] () – C:\WINDOWS\System32\dllcache\prcp.nls
[2009/08/06 09:49:43 | 00,083,748 | —- | C] () – C:\WINDOWS\System32\dllcache\prc.nls
[2009/08/06 09:49:43 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa3.sys
[2009/08/06 09:49:39 | 00,017,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa.sys
[2009/08/06 09:49:36 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\powerfil.sys
[2009/08/06 09:49:30 | 00,131,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxviceo.dll
[2009/08/06 09:49:30 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxmcro.dll
[2009/08/06 09:49:30 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pnrmc.sys
[2009/08/06 09:49:29 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmigrate.dll
[2009/08/06 09:49:29 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxgl.dll
[2009/08/06 09:49:28 | 00,482,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pintlgnt.ime
[2009/08/06 09:49:28 | 00,070,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pintlphr.exe
[2009/08/06 09:49:28 | 00,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\plugin.ocx
[2009/08/06 09:49:28 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pintlcsd.dll
[2009/08/06 09:49:27 | 00,175,104 | —- | C] () – C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2009/08/06 09:49:23 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phvfwext.dll
[2009/08/06 09:49:23 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phon.ime
[2009/08/06 09:49:19 | 00,019,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philtune.sys
[2009/08/06 09:49:15 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phildec.sys
[2009/08/06 09:49:12 | 00,173,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam2.sys
[2009/08/06 09:49:08 | 00,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.sys
[2009/08/06 09:49:05 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.dll
[2009/08/06 09:49:01 | 00,259,328 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3dd.dll
[2009/08/06 09:49:01 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phdsext.ax
[2009/08/06 09:49:00 | 00,028,032 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3.sys
[2009/08/06 09:48:59 | 00,211,712 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2dll.dll
[2009/08/06 09:48:59 | 00,027,904 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2.sys
[2009/08/06 09:48:55 | 00,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2hib.sys
[2009/08/06 09:48:52 | 00,027,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2.sys
[2009/08/06 09:48:51 | 00,169,984 | —- | C] (Cisco Systems) – C:\WINDOWS\System32\dllcache\pcx500.sys
[2009/08/06 09:48:47 | 00,086,016 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\pctspk.exe
[2009/08/06 09:48:44 | 00,035,328 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2009/08/06 09:48:40 | 00,029,769 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2009/08/06 09:48:37 | 00,030,282 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2009/08/06 09:48:33 | 00,026,153 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2009/08/06 09:48:32 | 00,029,502 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\pca200e.sys
[2009/08/06 09:48:29 | 00,030,495 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pc100nds.sys
[2009/08/06 09:48:28 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\padrs804.dll
[2009/08/06 09:48:28 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\padrs412.dll
[2009/08/06 09:48:27 | 00,036,927 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\padrs411.dll
[2009/08/06 09:48:27 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\padrs404.dll
[2009/08/06 09:48:23 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2rc.dll
[2009/08/06 09:48:19 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2.dll
[2009/08/06 09:48:16 | 00,025,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovsound2.sys
[2009/08/06 09:48:12 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcoms.exe
[2009/08/06 09:48:09 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcomc.dll
[2009/08/06 09:48:05 | 00,351,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodek2.sys
[2009/08/06 09:48:02 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodec2.dll
[2009/08/06 09:47:58 | 00,031,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovce.sys
[2009/08/06 09:47:55 | 00,028,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcd.sys
[2009/08/06 09:47:51 | 00,048,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcam2.sys
[2009/08/06 09:47:48 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovca.sys
[2009/08/06 09:47:44 | 00,054,186 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otcsercb.sys
[2009/08/06 09:47:41 | 00,043,689 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otceth5.sys
[2009/08/06 09:47:37 | 00,027,209 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otc06x5.sys
[2009/08/06 09:47:33 | 00,054,528 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\opl3sax.sys
[2009/08/06 09:47:28 | 04,274,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv4_disp.dll
[2009/08/06 09:47:28 | 01,897,408 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv4_mini.sys
[2009/08/06 09:47:24 | 00,198,144 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.sys
[2009/08/06 09:47:19 | 00,123,776 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.dll
[2009/08/06 09:47:17 | 00,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\ntmtlfax.sys
[2009/08/06 09:47:10 | 00,051,552 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\dllcache\ntgrip.sys
[2009/08/06 09:47:10 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll
[2009/08/06 09:47:06 | 00,009,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntapm.sys
[2009/08/06 09:47:02 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsmmc.sys
[2009/08/06 09:47:01 | 00,028,672 | —- | C] (National Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\nscirda.sys
[2009/08/06 09:46:56 | 00,087,040 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2009/08/06 09:46:53 | 00,126,080 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2009/08/06 09:46:48 | 00,032,840 | —- | C] (NETGEAR Corporation.) – C:\WINDOWS\System32\dllcache\ngrpci.sys
[2009/08/06 09:46:46 | 00,132,695 | —- | C] (802.11b) – C:\WINDOWS\System32\dllcache\netwlan5.sys
[2009/08/06 09:46:41 | 00,065,278 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\netflx3.sys
[2009/08/06 09:46:36 | 00,039,264 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.sys
[2009/08/06 09:46:33 | 00,060,480 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.dll
[2009/08/06 09:46:29 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ne2000.sys
[2009/08/06 09:46:23 | 00,091,488 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2009/08/06 09:46:20 | 00,027,936 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3d.sys
[2009/08/06 09:46:17 | 00,033,088 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2009/08/06 09:46:13 | 00,059,104 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2009/08/06 09:46:10 | 00,013,664 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.sys
[2009/08/06 09:46:07 | 00,035,392 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.dll
[2009/08/06 09:46:04 | 00,128,000 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n100325.sys
[2009/08/06 09:46:00 | 00,052,255 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2009/08/06 09:45:57 | 00,075,520 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxport.sys
[2009/08/06 09:45:53 | 00,007,168 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxport.dll
[2009/08/06 09:45:50 | 00,019,968 | —- | C] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\dllcache\mxnic.sys
[2009/08/06 09:45:47 | 00,019,968 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxicfg.dll
[2009/08/06 09:45:44 | 00,021,888 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxcard.sys
[2009/08/06 09:45:43 | 00,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mutohpen.sys
[2009/08/06 09:45:42 | 00,229,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\multibox.dll
[2009/08/06 09:45:39 | 00,103,296 | —- | C] (Matrox Graphics Inc) – C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2009/08/06 09:45:38 | 00,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mtxparhm.sys
[2009/08/06 09:45:37 | 01,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mtxparhd.dll
[2009/08/06 09:45:37 | 00,111,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mtstocom.exe
[2009/08/06 09:45:35 | 01,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\mtlstrm.sys
[2009/08/06 09:45:34 | 00,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\mtlmnt5.sys
[2009/08/06 09:45:29 | 00,049,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstape.sys
[2009/08/06 09:45:21 | 00,012,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msriffwv.sys
[2009/08/06 09:45:13 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msmpu401.sys
[2009/08/06 09:45:10 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msiregmv.exe
[2009/08/06 09:45:10 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msircomm.sys
[2009/08/06 09:45:09 | 01,875,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msir3jp.lex
[2009/08/06 09:45:09 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msir3jp.dll
[2009/08/06 09:44:59 | 00,035,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msgame.sys
[2009/08/06 09:44:54 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2009/08/06 09:44:54 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfsio.sys
[2009/08/06 09:44:53 | 00,051,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdv.sys
[2009/08/06 09:44:42 | 00,017,280 | —- | C] (American Megatrends Inc.) – C:\WINDOWS\System32\dllcache\mraid35x.sys
[2009/08/06 09:44:41 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpe.sys
[2009/08/06 09:44:37 | 00,012,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mouhid.sys
[2009/08/06 09:44:33 | 00,016,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\modemcsa.sys
[2009/08/06 09:44:28 | 00,006,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\miniqic.sys
[2009/08/06 09:44:26 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\migregdb.exe
[2009/08/06 09:44:25 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\migisol.exe
[2009/08/06 09:44:20 | 00,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaum.sys
[2009/08/06 09:44:17 | 00,235,648 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaud.dll
[2009/08/06 09:44:16 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mga.sys
[2009/08/06 09:44:16 | 00,092,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mga.dll
[2009/08/06 09:44:14 | 00,026,112 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\memstpci.sys
[2009/08/06 09:44:11 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memgrp.dll
[2009/08/06 09:44:08 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memcard.sys
[2009/08/06 09:44:04 | 00,164,586 | —- | C] (Madge Networks Ltd) – C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2009/08/06 09:44:00 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll
[2009/08/06 09:44:00 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mammoth.sys
[2009/08/06 09:43:56 | 00,048,768 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\maestro.sys
[2009/08/06 09:43:53 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3092dc.dll
[2009/08/06 09:43:49 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3091dc.dll
[2009/08/06 09:43:46 | 00,022,848 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwusbhid.sys
[2009/08/06 09:43:45 | 00,020,864 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwadihid.sys
[2009/08/06 09:43:42 | 00,797,500 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltsmt.sys
[2009/08/06 09:43:39 | 00,802,683 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\ltsm.sys
[2009/08/06 09:43:38 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ltotape.sys
[2009/08/06 09:43:37 | 00,420,992 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2009/08/06 09:43:34 | 00,606,684 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2009/08/06 09:43:34 | 00,576,746 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2009/08/06 09:43:30 | 00,727,786 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ltck000c.sys
[2009/08/06 09:43:30 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lprmon.dll
[2009/08/06 09:43:29 | 00,022,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lpdsvc.dll
[2009/08/06 09:43:26 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\loop.sys
[2009/08/06 09:43:19 | 00,070,730 | —- | C] (Linksys Group, Inc.) – C:\WINDOWS\System32\dllcache\lne100tx.sys
[2009/08/06 09:43:16 | 00,020,573 | —- | C] (The Linksts Group ) – C:\WINDOWS\System32\dllcache\lne100.sys
[2009/08/06 09:43:13 | 00,025,065 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\lmndis3.sys
[2009/08/06 09:43:12 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lmmib2.dll
[2009/08/06 09:43:09 | 00,015,744 | —- | C] (Litronic Industries) – C:\WINDOWS\System32\dllcache\lit220p.sys
[2009/08/06 09:43:06 | 00,034,688 | —- | C] (Toshiba Corp.) – C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2009/08/06 09:43:03 | 00,026,442 | —- | C] (SMSC) – C:\WINDOWS\System32\dllcache\lanepic5.sys
[2009/08/06 09:43:00 | 00,019,016 | —- | C] (Kingston Technology Company ) – C:\WINDOWS\System32\dllcache\ktc111.sys
[2009/08/06 09:42:59 | 00,047,066 | —- | C] () – C:\WINDOWS\System32\dllcache\ksc.nls
[2009/08/06 09:42:55 | 01,158,818 | —- | C] () – C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2009/08/06 09:42:55 | 00,070,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\korwbrkr.dll
[2009/08/06 09:42:55 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kousd.dll
[2009/08/06 09:42:50 | 00,242,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsusd.dll
[2009/08/06 09:42:45 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsui.dll
[2009/08/06 09:42:43 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdnecat.dll
[2009/08/06 09:42:43 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdnecnt.dll
[2009/08/06 09:42:42 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdnec95.dll
[2009/08/06 09:42:40 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdlk41a.dll
[2009/08/06 09:42:40 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdlk41j.dll
[2009/08/06 09:42:36 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdkor.dll
[2009/08/06 09:42:33 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdjpn.dll
[2009/08/06 09:42:32 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdibm02.dll
[2009/08/06 09:42:31 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdhid.sys
[2009/08/06 09:42:27 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdax2.dll
[2009/08/06 09:42:27 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd106n.dll
[2009/08/06 09:42:24 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd106.dll
[2009/08/06 09:42:21 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd103.dll
[2009/08/06 09:42:18 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101c.dll
[2009/08/06 09:42:15 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101b.dll
[2009/08/06 09:42:15 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101a.dll
[2009/08/06 09:42:14 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101.dll
[2009/08/06 09:42:13 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jupiw.dll
[2009/08/06 09:42:08 | 00,026,624 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\dllcache\irstusb.sys
[2009/08/06 09:42:05 | 00,018,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irsir.sys
[2009/08/06 09:42:01 | 00,023,552 | —- | C] (MKNet Corporation) – C:\WINDOWS\System32\dllcache\irmk7.sys
[2009/08/06 09:41:58 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iprip.dll
[2009/08/06 09:41:52 | 00,045,632 | —- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) – C:\WINDOWS\System32\dllcache\ip5515.sys
[2009/08/06 09:41:49 | 00,090,200 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8ports.dll
[2009/08/06 09:41:46 | 00,038,784 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8.sys
[2009/08/06 09:41:42 | 00,013,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inport.sys
[2009/08/06 09:41:38 | 00,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ini910u.sys
[2009/08/06 09:41:36 | 00,315,452 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imskf.dll
[2009/08/06 09:41:35 | 00,471,102 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imskdic.dll
[2009/08/06 09:41:35 | 00,102,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imlang.dll
[2009/08/06 09:41:35 | 00,059,392 | —- | C] () – C:\WINDOWS\System32\dllcache\imscinst.exe
[2009/08/06 09:41:34 | 00,274,489 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjputyc.dll
[2009/08/06 09:41:34 | 00,262,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjputy.exe
[2009/08/06 09:41:34 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imkrinst.exe
[2009/08/06 09:41:33 | 00,233,527 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjprw.exe
[2009/08/06 09:41:33 | 00,045,109 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpuex.exe
[2009/08/06 09:41:32 | 00,307,257 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpdct.exe
[2009/08/06 09:41:32 | 00,208,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpmig.exe
[2009/08/06 09:41:32 | 00,196,665 | —- | C] () – C:\WINDOWS\System32\dllcache\imjpinst.exe
[2009/08/06 09:41:32 | 00,155,705 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpdsvr.exe
[2009/08/06 09:41:32 | 00,081,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpdct.dll
[2009/08/06 09:41:31 | 00,716,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpcus.dll
[2009/08/06 09:41:31 | 00,368,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpcic.dll
[2009/08/06 09:41:31 | 00,057,398 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpdadm.exe
[2009/08/06 09:41:30 | 00,811,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjp81k.dll
[2009/08/06 09:41:30 | 00,340,023 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjp81.ime
[2009/08/06 09:41:30 | 00,311,359 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imepadsv.exe
[2009/08/06 09:41:29 | 00,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imekrcic.dll
[2009/08/06 09:41:29 | 00,102,463 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imepadsm.dll
[2009/08/06 09:41:29 | 00,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imekrmbx.dll
[2009/08/06 09:41:29 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imekrmig.exe
[2009/08/06 09:41:28 | 00,134,339 | —- | C] () – C:\WINDOWS\System32\dllcache\imekr.lex
[2009/08/06 09:41:28 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imekr61.ime
[2009/08/06 09:41:18 | 00,372,824 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\iconf32.dll
[2009/08/06 09:41:13 | 00,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5usb.sys
[2009/08/06 09:41:10 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5ext.dll
[2009/08/06 09:41:07 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5com.dll
[2009/08/06 09:41:04 | 00,154,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4usb.sys
[2009/08/06 09:41:01 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4ext.dll
[2009/08/06 09:40:58 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4com.dll
[2009/08/06 09:40:54 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3ext.dll
[2009/08/06 09:40:51 | 00,141,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3.sys
[2009/08/06 09:40:48 | 00,038,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2009/08/06 09:40:45 | 00,109,085 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtrp.sys
[2009/08/06 09:40:42 | 00,100,936 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtok.sys
[2009/08/06 09:40:39 | 00,009,216 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmsgnet.dll
[2009/08/06 09:40:36 | 00,028,700 | —- | C] (IBM Corp.) – C:\WINDOWS\System32\dllcache\ibmexmp.sys
[2009/08/06 09:40:34 | 00,702,845 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\i81xdnt5.dll
[2009/08/06 09:40:34 | 00,161,020 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\i81xnt5.sys
[2009/08/06 09:40:31 | 00,058,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740nt5.sys
[2009/08/06 09:40:24 | 00,353,184 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740dnt5.dll
[2009/08/06 09:40:23 | 00,018,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omp.sys
[2009/08/06 09:40:22 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2009/08/06 09:40:18 | 10,129,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hwxkor.dll
[2009/08/06 09:40:08 | 13,463,552 | —- | C] () – C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2009/08/06 09:40:01 | 10,096,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hwxcht.dll
[2009/08/06 09:39:59 | 01,041,536 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfdpsp2.sys
[2009/08/06 09:39:58 | 00,685,056 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfcxts2.sys
[2009/08/06 09:39:57 | 00,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfcisp2.dll
[2009/08/06 09:39:56 | 00,220,032 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfbs2s2.sys
[2009/08/06 09:39:53 | 00,488,383 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_v124.sys
[2009/08/06 09:39:50 | 00,050,751 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_tone.sys
[2009/08/06 09:39:47 | 00,073,279 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_spkp.sys
[2009/08/06 09:39:44 | 00,044,863 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_soar.sys
[2009/08/06 09:39:41 | 00,057,471 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_samp.sys
[2009/08/06 09:39:37 | 00,542,879 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_msft.sys
[2009/08/06 09:39:35 | 00,391,199 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_k56k.sys
[2009/08/06 09:39:32 | 00,009,759 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_inst.dll
[2009/08/06 09:39:28 | 00,115,807 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fsks.sys
[2009/08/06 09:39:26 | 00,199,711 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_faxx.sys
[2009/08/06 09:39:22 | 00,289,887 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fall.sys
[2009/08/06 09:39:19 | 00,067,167 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_bsc2.sys
[2009/08/06 09:39:16 | 00,150,239 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_amos.sys
[2009/08/06 09:39:13 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hr1w.dll
[2009/08/06 09:39:10 | 00,005,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpt4qic.sys
[2009/08/06 09:39:07 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2009/08/06 09:39:05 | 00,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2009/08/06 09:39:02 | 00,025,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpn.sys
[2009/08/06 09:38:59 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2009/08/06 09:38:56 | 00,068,608 | —- | C] (Avisioin) – C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2009/08/06 09:38:54 | 00,165,888 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt53.dll
[2009/08/06 09:38:51 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2009/08/06 09:38:48 | 00,093,696 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt42.dll
[2009/08/06 09:38:45 | 00,126,976 | —- | C] (Hewlett Packard) – C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2009/08/06 09:38:43 | 00,101,376 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt34.dll
[2009/08/06 09:38:40 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2009/08/06 09:38:37 | 00,089,088 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt33.dll
[2009/08/06 09:38:35 | 00,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2009/08/06 09:38:32 | 00,083,968 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt21.dll
[2009/08/06 09:38:29 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2009/08/06 09:38:28 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hostmib.dll
[2009/08/06 09:38:24 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2009/08/06 09:38:24 | 00,002,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidswvd.sys
[2009/08/06 09:38:23 | 00,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidir.sys
[2009/08/06 09:38:20 | 00,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidgame.sys
[2009/08/06 09:38:18 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidbth.sys
[2009/08/06 09:38:16 | 00,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidbatt.sys
[2009/08/06 09:38:11 | 00,907,456 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hcf_msft.sys
[2009/08/06 09:38:11 | 00,036,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hanjadic.dll
[2009/08/06 09:38:10 | 00,108,827 | —- | C] () – C:\WINDOWS\System32\dllcache\hanja.lex
[2009/08/06 09:38:08 | 00,028,288 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grserial.sys
[2009/08/06 09:38:06 | 00,082,304 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grclass.sys
[2009/08/06 09:38:03 | 00,017,408 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\gpr400.sys
[2009/08/06 09:38:02 | 00,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gckernel.sys
[2009/08/06 09:38:01 | 00,010,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gameenum.sys
[2009/08/06 09:38:00 | 00,046,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gagp30kx.sys
[2009/08/06 09:37:57 | 00,322,432 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400m.sys
[2009/08/06 09:37:55 | 01,733,120 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400d.dll
[2009/08/06 09:37:53 | 00,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200m.sys
[2009/08/06 09:37:50 | 00,470,144 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200d.dll
[2009/08/06 09:37:48 | 00,454,912 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fxusbase.sys
[2009/08/06 09:37:47 | 00,400,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsxp32.dll
[2009/08/06 09:37:47 | 00,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxstiff.dll
[2009/08/06 09:37:47 | 00,246,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxst30.dll
[2009/08/06 09:37:47 | 00,192,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxswzrd.dll
[2009/08/06 09:37:47 | 00,154,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsui.dll
[2009/08/06 09:37:46 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsst.dll
[2009/08/06 09:37:46 | 00,267,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxssvc.exe
[2009/08/06 09:37:46 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxssend.exe
[2009/08/06 09:37:45 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsroute.dll
[2009/08/06 09:37:45 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsmon.dll
[2009/08/06 09:37:45 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsext32.dll
[2009/08/06 09:37:45 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsperf.dll
[2009/08/06 09:37:45 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsres.dll
[2009/08/06 09:37:44 | 00,285,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxscomex.dll
[2009/08/06 09:37:44 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxscover.exe
[2009/08/06 09:37:44 | 00,072,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxscom.dll
[2009/08/06 09:37:44 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsevent.dll
[2009/08/06 09:37:44 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsdrv.dll
[2009/08/06 09:37:43 | 00,143,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsclnt.exe
[2009/08/06 09:37:43 | 00,132,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsclntr.dll
[2009/08/06 09:37:43 | 00,111,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxscfgwz.dll
[2009/08/06 09:37:42 | 00,452,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fxsapi.dll
[2009/08/06 09:37:40 | 00,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fuusd.dll
[2009/08/06 09:37:38 | 00,455,296 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fusbbase.sys
[2009/08/06 09:37:35 | 00,455,680 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fus2base.sys
[2009/08/06 09:37:32 | 00,442,240 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2009/08/06 09:37:30 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\dllcache\fpencode.dll
[2009/08/06 09:37:28 | 00,441,728 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2009/08/06 09:37:25 | 00,444,416 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcibase.sys
[2009/08/06 09:37:25 | 00,024,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpadmcgi.exe
[2009/08/06 09:37:25 | 00,020,541 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpadmdll.dll
[2009/08/06 09:37:24 | 00,034,173 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\forehe.sys
[2009/08/06 09:37:19 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fnfilter.dll
[2009/08/06 09:37:17 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\flattemp.exe
[2009/08/06 09:37:15 | 00,027,165 | —- | C] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\dllcache\fetnd5.sys
[2009/08/06 09:37:08 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll
[2009/08/06 09:37:08 | 00,022,090 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\fem556n5.sys
[2009/08/06 09:37:04 | 00,024,618 | —- | C] (NETGEAR) – C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2009/08/06 09:37:01 | 00,016,074 | —- | C] (NETGEAR Corp.) – C:\WINDOWS\System32\dllcache\fa312nd5.sys
[2009/08/06 09:37:01 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\f3ahvoas.dll
[2009/08/06 09:36:58 | 00,011,850 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2009/08/06 09:36:56 | 00,012,362 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2009/08/06 09:36:49 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exabyte2.sys
[2009/08/06 09:36:47 | 00,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\evntwin.exe
[2009/08/06 09:36:47 | 00,016,998 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ex10.sys
[2009/08/06 09:36:46 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\evntagnt.dll
[2009/08/06 09:36:46 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\evntcmd.exe
[2009/08/06 09:36:45 | 00,045,056 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunid.dll
[2009/08/06 09:36:45 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\et4000.sys
[2009/08/06 09:36:43 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunib.dll
[2009/08/06 09:36:41 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuni.dll
[2009/08/06 09:36:40 | 00,057,856 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009/08/06 09:36:37 | 00,034,816 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimg.dll
[2009/08/06 09:36:37 | 00,031,744 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucmd.dll
[2009/08/06 09:36:34 | 00,137,088 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\essm2e.sys
[2009/08/06 09:36:34 | 00,043,008 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucm.dll
[2009/08/06 09:36:32 | 00,063,360 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\ess.sys
[2009/08/06 09:36:26 | 00,347,550 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56tpi.sys
[2009/08/06 09:36:24 | 00,594,238 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56hpi.sys
[2009/08/06 09:36:22 | 00,595,647 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56cvmp.sys
[2009/08/06 09:36:20 | 00,174,464 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es198x.sys
[2009/08/06 09:36:17 | 00,072,192 | —- | C] (ESS Technology Inc.) – C:\WINDOWS\System32\dllcache\es1969.sys
[2009/08/06 09:36:15 | 00,040,704 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1371mp.sys
[2009/08/06 09:36:13 | 00,037,120 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1370mp.sys
[2009/08/06 09:36:11 | 00,061,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnloop.exe
[2009/08/06 09:36:08 | 00,051,200 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnlogr.exe
[2009/08/06 09:36:06 | 00,053,248 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqndiag.exe
[2009/08/06 09:36:04 | 00,629,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqn.sys
[2009/08/06 09:36:01 | 00,114,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epstw2k.sys
[2009/08/06 09:35:58 | 00,018,503 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\epro4.sys
[2009/08/06 09:35:57 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2009/08/06 09:35:55 | 00,283,904 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\emu10k1m.sys
[2009/08/06 09:35:50 | 00,019,996 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\em556n4.sys
[2009/08/06 09:35:48 | 00,025,159 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\elnk3.sys
[2009/08/06 09:35:47 | 00,007,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\elmsmc.sys
[2009/08/06 09:35:45 | 00,171,520 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el99xn51.sys
[2009/08/06 09:35:44 | 00,070,174 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el98xn5.sys
[2009/08/06 09:35:42 | 00,455,199 | —- | C] (3Com Corporation.) – C:\WINDOWS\System32\dllcache\el985n51.sys
[2009/08/06 09:35:40 | 00,153,631 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xnd5.sys
[2009/08/06 09:35:39 | 00,066,591 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xbc5.sys
[2009/08/06 09:35:37 | 00,241,206 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656se5.sys
[2009/08/06 09:35:36 | 00,077,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656nd5.sys
[2009/08/06 09:35:34 | 00,634,134 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656ct5.sys
[2009/08/06 09:35:33 | 00,069,194 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656cd5.sys
[2009/08/06 09:35:31 | 00,026,141 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el589nd5.sys
[2009/08/06 09:35:29 | 00,069,692 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el575nd5.sys
[2009/08/06 09:35:28 | 00,024,653 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el574nd4.sys
[2009/08/06 09:35:26 | 00,055,999 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el556nd5.sys
[2009/08/06 09:35:25 | 00,044,103 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el515.sys
[2009/08/06 09:35:24 | 00,514,587 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\edb500.dll
[2009/08/06 09:35:23 | 00,019,594 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e100isa4.sys
[2009/08/06 09:35:22 | 00,117,760 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e100b325.sys
[2009/08/06 09:35:20 | 00,050,719 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e1000nt5.sys
[2009/08/06 09:35:16 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dshowext.ax
[2009/08/06 09:35:15 | 00,334,208 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2009/08/06 09:35:12 | 00,020,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpti2o.sys
[2009/08/06 09:35:10 | 00,028,062 | —- | C] (National Semiconductor Coproration) – C:\WINDOWS\System32\dllcache\dp83820.sys
[2009/08/06 09:35:09 | 00,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2009/08/06 09:35:07 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2009/08/06 09:35:06 | 00,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2009/08/06 09:35:05 | 00,207,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4.sys
[2009/08/06 09:35:00 | 00,029,696 | —- | C] (CNet Technology, Inc. ) – C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2009/08/06 09:35:00 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dlttape.sys
[2009/08/06 09:34:58 | 00,026,698 | —- | C] (D-Link Corporation) – C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2009/08/06 09:34:56 | 00,952,007 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diwan.sys
[2009/08/06 09:34:55 | 00,029,768 | —- | C] () – C:\WINDOWS\System32\dllcache\divasu.dll
[2009/08/06 09:34:54 | 00,037,962 | —- | C] () – C:\WINDOWS\System32\dllcache\divaprop.dll
[2009/08/06 09:34:52 | 00,006,216 | —- | C] () – C:\WINDOWS\System32\dllcache\divaci.dll
[2009/08/06 09:34:51 | 00,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2009/08/06 09:34:50 | 00,038,985 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvsu.dll
[2009/08/06 09:34:48 | 00,031,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvpp.dll
[2009/08/06 09:34:47 | 00,006,729 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvci.dll
[2009/08/06 09:34:44 | 00,091,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\dimaint.sys
[2009/08/06 09:34:43 | 00,614,429 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiview.exe
[2009/08/06 09:34:41 | 00,042,432 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.sys
[2009/08/06 09:34:40 | 00,110,621 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.dll
[2009/08/06 09:34:38 | 00,021,606 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.sys
[2009/08/06 09:34:37 | 00,041,046 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.dll
[2009/08/06 09:34:36 | 00,102,484 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiinf.dll
[2009/08/06 09:34:34 | 00,159,828 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digihlc.dll
[2009/08/06 09:34:33 | 00,229,462 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifwrk.dll
[2009/08/06 09:34:32 | 00,090,525 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifep5.sys
[2009/08/06 09:34:30 | 00,103,044 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidxb.sys
[2009/08/06 09:34:29 | 00,131,156 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidbp.dll
[2009/08/06 09:34:27 | 00,037,735 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.sys
[2009/08/06 09:34:26 | 00,065,622 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.dll
[2009/08/06 09:34:21 | 00,419,357 | —- | C] (Digi International) – C:\WINDOWS\System32\dllcache\dgconfig.dll
[2009/08/06 09:34:20 | 00,029,531 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\dgapci.sys
[2009/08/06 09:34:18 | 00,024,649 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650d.sys
[2009/08/06 09:34:17 | 00,024,648 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650.sys
[2009/08/06 09:34:15 | 00,024,064 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\devldr32.exe
[2009/08/06 09:34:14 | 00,256,512 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\devcon32.dll
[2009/08/06 09:34:13 | 00,020,928 | —- | C] (Digital Networks, LLC) – C:\WINDOWS\System32\dllcache\defpa.sys
[2009/08/06 09:34:11 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddsmc.sys
[2009/08/06 09:34:09 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc260usd.dll
[2009/08/06 09:34:08 | 00,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc240usd.dll
[2009/08/06 09:34:07 | 00,063,208 | —- | C] (Intel Corporation.) – C:\WINDOWS\System32\dllcache\dc21x4.sys
[2009/08/06 09:34:05 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210usd.dll
[2009/08/06 09:34:04 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210_32.dll
[2009/08/06 09:34:03 | 00,078,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dayi.ime
[2009/08/06 09:34:01 | 00,014,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dac960nt.sys
[2009/08/06 09:34:00 | 00,179,584 | —- | C] (Mylex Corporation) – C:\WINDOWS\System32\dllcache\dac2w2k.sys
[2009/08/06 09:33:58 | 00,117,760 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\d100ib5.sys
[2009/08/06 09:33:56 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzports.dll
[2009/08/06 09:33:55 | 00,049,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzport.sys
[2009/08/06 09:33:54 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzcoins.dll
[2009/08/06 09:33:53 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyports.dll
[2009/08/06 09:33:51 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyport.sys
[2009/08/06 09:33:50 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyycoins.dll
[2009/08/06 09:33:49 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclom-y.sys
[2009/08/06 09:33:47 | 00,048,640 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2009/08/06 09:33:47 | 00,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclad-z.sys
[2009/08/06 09:33:46 | 00,093,952 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2009/08/06 09:33:44 | 00,111,872 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcspud.sys
[2009/08/06 09:33:43 | 00,003,584 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2009/08/06 09:33:42 | 00,072,832 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2009/08/06 09:33:40 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2009/08/06 09:33:39 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbase.sys
[2009/08/06 09:33:37 | 00,004,096 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctwdm32.dll
[2009/08/06 09:33:36 | 00,249,856 | —- | C] (Comtrol® Corporation) – C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2009/08/06 09:33:35 | 00,096,256 | —- | C] (Copyright © Creative Technology Ltd. 1994-2001) – C:\WINDOWS\System32\dllcache\ctlsb16.sys
[2009/08/06 09:33:34 | 00,003,712 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctljystk.sys
[2009/08/06 09:33:33 | 00,006,912 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctlfacem.sys
[2009/08/06 09:33:30 | 00,175,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\csamsp.dll
[2009/08/06 09:33:28 | 00,042,112 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\crtaud.sys
[2009/08/06 09:33:27 | 00,216,064 | —- | C] (COMPAQ Inc.) – C:\WINDOWS\System32\dllcache\cpscan.dll
[2009/08/06 09:33:27 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cprofile.exe
[2009/08/06 09:33:25 | 00,060,970 | —- | C] (Compaq Computer Corp.) – C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2009/08/06 09:33:24 | 00,021,533 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2009/08/06 09:33:23 | 00,057,399 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cplexe.exe
[2009/08/06 09:33:23 | 00,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cpqarray.sys
[2009/08/06 09:33:18 | 00,039,936 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\cnxt1803.sys
[2009/08/06 09:33:17 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnusd.dll
[2009/08/06 09:33:15 | 00,006,656 | —- | C] (CMD Technology, Inc.) – C:\WINDOWS\System32\dllcache\cmdide.sys
[2009/08/06 09:33:14 | 00,020,736 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2009/08/06 09:33:12 | 00,248,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546xm.sys
[2009/08/06 09:33:11 | 00,170,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546x.dll
[2009/08/06 09:33:10 | 00,111,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl5465.dll
[2009/08/06 09:33:09 | 00,045,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.sys
[2009/08/06 09:33:08 | 00,091,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.dll
[2009/08/06 09:33:07 | 00,480,256 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cintsetp.exe
[2009/08/06 09:33:07 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cintlgnt.ime
[2009/08/06 09:33:06 | 00,272,640 | —- | C] (RAVISENT Technologies Inc.) – C:\WINDOWS\System32\dllcache\cinemclc.sys
[2009/08/06 09:33:06 | 00,198,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cintime.dll
[2009/08/06 09:33:04 | 00,980,034 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\cicap.sys
[2009/08/06 09:33:04 | 00,173,568 | —- | C] () – C:\WINDOWS\System32\dllcache\chtskf.dll
[2009/08/06 09:33:04 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chtskdic.dll
[2009/08/06 09:33:03 | 00,838,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chtbrkr.dll
[2009/08/06 09:33:03 | 00,097,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chtmbx.dll
[2009/08/06 09:33:02 | 01,677,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chsbrkr.dll
[2009/08/06 09:33:02 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chgusr.exe
[2009/08/06 09:33:01 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chgport.exe
[2009/08/06 09:33:01 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chglogon.exe
[2009/08/06 09:33:00 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\changer.sys
[2009/08/06 09:32:59 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chajei.ime
[2009/08/06 09:32:59 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\change.exe
[2009/08/06 09:32:58 | 00,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\ch7xxnt5.dll
[2009/08/06 09:32:57 | 00,049,182 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem56n5.sys
[2009/08/06 09:32:56 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem33n5.sys
[2009/08/06 09:32:55 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem28n5.sys
[2009/08/06 09:32:54 | 00,027,164 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce3n5.sys
[2009/08/06 09:32:53 | 00,021,530 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce2n5.sys
[2009/08/06 09:32:51 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cd20xrnt.sys
[2009/08/06 09:32:50 | 00,714,698 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2009/08/06 09:32:49 | 00,046,108 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cben5.sys
[2009/08/06 09:32:48 | 00,039,680 | —- | C] (Silicom Ltd.) – C:\WINDOWS\System32\dllcache\cb325.sys
[2009/08/06 09:32:47 | 00,037,916 | —- | C] (Fast Ethernet Controller Provider) – C:\WINDOWS\System32\dllcache\cb102.sys
[2009/08/06 09:32:45 | 00,032,256 | —- | C] (Eicon Technology Corporation) – C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2009/08/06 09:32:44 | 00,164,923 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diapi2.sys
[2009/08/06 09:32:43 | 00,054,528 | —- | C] (Philips Semiconductors GmbH) – C:\WINDOWS\System32\dllcache\cap7146.sys
[2009/08/06 09:32:42 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.dll
[2009/08/06 09:32:41 | 00,236,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.dll
[2009/08/06 09:32:41 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.ax
[2009/08/06 09:32:40 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.ax
[2009/08/06 09:32:39 | 00,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.dll
[2009/08/06 09:32:38 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.ax
[2009/08/06 09:32:37 | 00,171,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv30.sys
[2009/08/06 09:32:36 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv21.sys
[2009/08/06 09:32:35 | 00,314,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdro21.sys
[2009/08/06 09:32:34 | 00,218,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_g18030.dll
[2009/08/06 09:32:34 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_is2022.dll
[2009/08/06 09:32:33 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_870.nls
[2009/08/06 09:32:32 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_858.nls
[2009/08/06 09:32:30 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_21027.nls
[2009/08/06 09:32:30 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_21025.nls
[2009/08/06 09:32:29 | 00,177,698 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20949.nls
[2009/08/06 09:32:29 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20936.nls
[2009/08/06 09:32:28 | 00,180,770 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20932.nls
[2009/08/06 09:32:28 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20924.nls
[2009/08/06 09:32:26 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20880.nls
[2009/08/06 09:32:26 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20871.nls
[2009/08/06 09:32:25 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20838.nls
[2009/08/06 09:32:25 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20833.nls
[2009/08/06 09:32:25 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20424.nls
[2009/08/06 09:32:24 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20423.nls
[2009/08/06 09:32:24 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20420.nls
[2009/08/06 09:32:23 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20297.nls
[2009/08/06 09:32:23 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20290.nls
[2009/08/06 09:32:23 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20285.nls
[2009/08/06 09:32:22 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20284.nls
[2009/08/06 09:32:22 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20280.nls
[2009/08/06 09:32:22 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20278.nls
[2009/08/06 09:32:21 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20277.nls
[2009/08/06 09:32:21 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20273.nls
[2009/08/06 09:32:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20269.nls
[2009/08/06 09:32:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20108.nls
[2009/08/06 09:32:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20107.nls
[2009/08/06 09:32:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20106.nls
[2009/08/06 09:32:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20105.nls
[2009/08/06 09:32:18 | 00,187,938 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20005.nls
[2009/08/06 09:32:18 | 00,180,258 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20004.nls
[2009/08/06 09:32:17 | 00,186,402 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20001.nls
[2009/08/06 09:32:17 | 00,185,378 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20003.nls
[2009/08/06 09:32:17 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20002.nls
[2009/08/06 09:32:16 | 00,189,986 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1361.nls
[2009/08/06 09:32:16 | 00,180,258 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20000.nls
[2009/08/06 09:32:15 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1149.nls
[2009/08/06 09:32:15 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1148.nls
[2009/08/06 09:32:14 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1147.nls
[2009/08/06 09:32:14 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1146.nls
[2009/08/06 09:32:14 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1145.nls
[2009/08/06 09:32:13 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1144.nls
[2009/08/06 09:32:13 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1143.nls
[2009/08/06 09:32:13 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1142.nls
[2009/08/06 09:32:12 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1141.nls
[2009/08/06 09:32:12 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1140.nls
[2009/08/06 09:32:12 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1047.nls
[2009/08/06 09:32:11 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10008.nls
[2009/08/06 09:32:08 | 00,195,618 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10002.nls
[2009/08/06 09:32:08 | 00,177,698 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10003.nls
[2009/08/06 09:32:07 | 00,162,850 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10001.nls
[2009/08/06 09:32:06 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthusb.sys
[2009/08/06 09:32:06 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2009/08/06 09:32:05 | 00,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthpan.sys
[2009/08/06 09:32:05 | 00,035,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthprint.sys
[2009/08/06 09:32:04 | 00,038,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthmodem.sys
[2009/08/06 09:32:04 | 00,017,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthenum.sys
[2009/08/06 09:32:02 | 00,031,529 | —- | C] (BreezeCOM) – C:\WINDOWS\System32\dllcache\brzwlan.sys
[2009/08/06 09:32:01 | 00,010,368 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbscn.sys
[2009/08/06 09:32:00 | 00,011,008 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2009/08/06 09:31:59 | 00,060,416 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brserwdm.sys
[2009/08/06 09:31:59 | 00,009,728 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brserif.dll
[2009/08/06 09:31:58 | 00,005,120 | —- | C] (Brother Industries,Ltd.) – C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2009/08/06 09:31:57 | 00,039,552 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparwdm.sys
[2009/08/06 09:31:56 | 00,003,168 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparimg.sys
[2009/08/06 09:31:55 | 00,041,472 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfusb.dll
[2009/08/06 09:31:54 | 00,032,256 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2009/08/06 09:31:54 | 00,029,696 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmflpt.dll
[2009/08/06 09:31:53 | 00,081,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2009/08/06 09:31:52 | 00,015,360 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2009/08/06 09:31:51 | 00,003,968 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltup.sys
[2009/08/06 09:31:50 | 00,012,160 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2009/08/06 09:31:50 | 00,002,944 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brfilt.sys
[2009/08/06 09:31:49 | 00,012,800 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brevif.dll
[2009/08/06 09:31:48 | 00,009,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brcoinst.dll
[2009/08/06 09:31:47 | 00,082,172 | —- | C] () – C:\WINDOWS\System32\dllcache\bopomofo.nls
[2009/08/06 09:31:47 | 00,019,456 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brbidiif.dll
[2009/08/06 09:31:46 | 00,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\binlsvc.dll
[2009/08/06 09:31:45 | 00,066,728 | —- | C] () – C:\WINDOWS\System32\dllcache\big5.nls
[2009/08/06 09:31:45 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdasup.sys
[2009/08/06 09:31:44 | 00,871,388 | —- | C] (BCM) – C:\WINDOWS\System32\dllcache\bcmdm.sys
[2009/08/06 09:31:44 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2009/08/06 09:31:43 | 00,026,568 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm4e5.sys
[2009/08/06 09:31:42 | 00,066,557 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42u.sys
[2009/08/06 09:31:42 | 00,054,271 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42xx5.sys
[2009/08/06 09:31:40 | 00,342,336 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.dll
[2009/08/06 09:31:40 | 00,036,128 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.sys
[2009/08/06 09:31:39 | 00,096,640 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\b57xp32.sys
[2009/08/06 09:31:38 | 00,089,952 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\b1cbase.sys
[2009/08/06 09:31:38 | 00,036,992 | —- | C] (Aztech Systems Ltd) – C:\WINDOWS\System32\dllcache\aztw2320.sys
[2009/08/06 09:31:37 | 00,037,568 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmwan.sys
[2009/08/06 09:31:36 | 00,144,384 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmenum.dll
[2009/08/06 09:31:36 | 00,087,552 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2009/08/06 09:31:35 | 00,013,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcstrm.sys
[2009/08/06 09:31:34 | 00,036,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcaudio.sys
[2009/08/06 09:31:33 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avc.sys
[2009/08/06 09:31:30 | 00,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\atv10nt5.dll
[2009/08/06 09:31:30 | 00,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\atv06nt5.dll
[2009/08/06 09:31:29 | 00,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\atv04nt5.dll
[2009/08/06 09:31:28 | 00,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\atv02nt5.dll
[2009/08/06 09:31:27 | 00,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\atv01nt5.dll
[2009/08/06 09:31:26 | 00,023,552 | —- | C] () – C:\WINDOWS\System32\dllcache\atixbar.sys
[2009/08/06 09:31:25 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\dllcache\ativxbar.sys
[2009/08/06 09:31:25 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\dllcache\ativttxx.sys
[2009/08/06 09:31:23 | 00,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ativtmxx.dll
[2009/08/06 09:31:22 | 00,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ativmvxx.ax
[2009/08/06 09:31:21 | 00,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ativdaxx.ax
[2009/08/06 09:31:21 | 00,009,472 | —- | C] () – C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2009/08/06 09:31:20 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2009/08/06 09:31:20 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitunep.sys
[2009/08/06 09:31:19 | 00,026,880 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2009/08/06 09:31:18 | 00,070,528 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiragem.sys
[2009/08/06 09:31:18 | 00,049,920 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtcap.sys
[2009/08/06 09:31:17 | 00,104,832 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiraged.dll
[2009/08/06 09:31:16 | 00,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinxsxx.sys
[2009/08/06 09:31:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2009/08/06 09:31:15 | 00,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinxbxx.sys
[2009/08/06 09:31:14 | 00,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atintuxx.sys
[2009/08/06 09:31:14 | 00,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinttxx.sys
[2009/08/06 09:31:12 | 00,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinsnxx.sys
[2009/08/06 09:31:11 | 00,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinrvxx.sys
[2009/08/06 09:31:11 | 00,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinraxx.sys
[2009/08/06 09:31:11 | 00,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinpdxx.sys
[2009/08/06 09:31:11 | 00,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinmdxx.sys
[2009/08/06 09:31:10 | 00,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinbtxx.sys
[2009/08/06 09:31:09 | 00,281,600 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimtai.sys
[2009/08/06 09:31:09 | 00,075,136 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpae.sys
[2009/08/06 09:31:08 | 00,289,664 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpab.sys
[2009/08/06 09:31:07 | 00,268,160 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidvai.dll
[2009/08/06 09:31:07 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atievxx.exe
[2009/08/06 09:31:06 | 00,382,592 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrab.dll
[2009/08/06 09:31:06 | 00,137,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrae.dll
[2009/08/06 09:31:05 | 00,046,464 | —- | C] () – C:\WINDOWS\System32\dllcache\atibt829.sys
[2009/08/06 09:31:04 | 00,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\dllcache\ati3d1ag.dll
[2009/08/06 09:31:03 | 00,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati2mtaa.sys
[2009/08/06 09:31:02 | 00,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati2dvaa.dll
[2009/08/06 09:31:02 | 00,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xsxx.sys
[2009/08/06 09:31:02 | 00,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xbxx.sys
[2009/08/06 09:31:00 | 00,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1tuxx.sys
[2009/08/06 09:31:00 | 00,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1snxx.sys
[2009/08/06 09:31:00 | 00,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1ttxx.sys
[2009/08/06 09:30:59 | 00,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1rvxx.sys
[2009/08/06 09:30:59 | 00,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1raxx.sys
[2009/08/06 09:30:58 | 00,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1pdxx.sys
[2009/08/06 09:30:58 | 00,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1mdxx.sys
[2009/08/06 09:30:57 | 00,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1btxx.sys
[2009/08/06 09:30:56 | 00,096,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ati.dll
[2009/08/06 09:30:56 | 00,077,568 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ati.sys
[2009/08/06 09:30:55 | 00,097,354 | —- | C] (Bay Networks, Inc.) – C:\WINDOWS\System32\dllcache\aspndis3.sys
[2009/08/06 09:30:54 | 00,022,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asc3350p.sys
[2009/08/06 09:30:54 | 00,014,848 | —- | C] (Advanced System Products, Inc.) – C:\WINDOWS\System32\dllcache\asc3550.sys
[2009/08/06 09:30:53 | 00,026,496 | —- | C] (Advanced System Products, Inc.) – C:\WINDOWS\System32\dllcache\asc.sys
[2009/08/06 09:30:52 | 00,331,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aqueue.dll
[2009/08/06 09:30:52 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2009/08/06 09:30:51 | 00,006,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\apmbatt.sys
[2009/08/06 09:30:50 | 00,036,224 | —- | C] (ADMtek Incorporated.) – C:\WINDOWS\System32\dllcache\an983.sys
[2009/08/06 09:30:50 | 00,012,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\amsint.sys
[2009/08/06 09:30:49 | 00,043,008 | —- | C] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\dllcache\amdagp.sys
[2009/08/06 09:30:48 | 00,042,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\alim1541.sys
[2009/08/06 09:30:48 | 00,016,969 | —- | C] (AmbiCom, Inc.) – C:\WINDOWS\System32\dllcache\amb8002.sys
[2009/08/06 09:30:47 | 00,026,624 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\alifir.sys
[2009/08/06 09:30:46 | 00,056,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78xx.sys
[2009/08/06 09:30:46 | 00,027,678 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ali5261.sys
[2009/08/06 09:30:45 | 00,055,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78u2.sys
[2009/08/06 09:30:45 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aha154x.sys
[2009/08/06 09:30:44 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0804.dll
[2009/08/06 09:30:43 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0412.dll
[2009/08/06 09:30:43 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0411.dll
[2009/08/06 09:30:42 | 00,044,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agpcpq.sys
[2009/08/06 09:30:42 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0404.dll
[2009/08/06 09:30:41 | 00,042,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agp440.sys
[2009/08/06 09:30:39 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2009/08/06 09:30:37 | 00,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\adv11nt5.dll
[2009/08/06 09:30:36 | 00,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\adv09nt5.dll
[2009/08/06 09:30:35 | 00,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\adv07nt5.dll
[2009/08/06 09:30:35 | 00,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\adv08nt5.dll
[2009/08/06 09:30:34 | 00,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\adv05nt5.dll
[2009/08/06 09:30:33 | 00,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\adv01nt5.dll
[2009/08/06 09:30:33 | 00,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\adv02nt5.dll
[2009/08/06 09:30:32 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2009/08/06 09:30:31 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adpu160m.sys
[2009/08/06 09:30:31 | 00,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2009/08/06 09:30:30 | 00,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2009/08/06 09:30:29 | 00,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2009/08/06 09:30:29 | 00,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2009/08/06 09:30:28 | 00,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2009/08/06 09:30:28 | 00,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2009/08/06 09:30:27 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2009/08/06 09:30:26 | 00,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2009/08/06 09:30:25 | 00,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2009/08/06 09:30:25 | 00,084,480 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ac97via.sys
[2009/08/06 09:30:24 | 00,096,256 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ac97intc.sys
[2009/08/06 09:30:23 | 00,231,552 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ac97ali.sys
[2009/08/06 09:30:23 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\abp480n5.sys
[2009/08/06 09:30:22 | 00,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2009/08/06 09:30:22 | 00,098,304 | —- | C] (Aureal Semiconductor) – C:\WINDOWS\System32\dllcache\a3d.dll
[2009/08/06 09:30:21 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2009/08/06 09:30:19 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\61883.sys
[2009/08/06 09:30:18 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\4mmdat.sys
[2009/08/06 09:30:17 | 00,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2009/08/06 09:30:17 | 00,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2009/08/06 09:30:17 | 00,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2009/08/06 09:30:16 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2009/08/06 09:29:57 | 00,032,827 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tcptest.exe
[2009/08/06 09:29:57 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tcptsat.dll
[2009/08/06 09:29:56 | 00,016,437 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shtml.exe
[2009/08/06 09:29:55 | 00,020,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shtml.dll
[2009/08/06 09:29:45 | 00,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2009/08/06 09:29:29 | 00,020,538 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpremadm.exe
[2009/08/06 09:29:28 | 00,598,071 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpmmc.dll
[2009/08/06 09:29:28 | 00,208,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2009/08/06 09:29:28 | 00,188,494 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpcount.exe
[2009/08/06 09:29:28 | 00,020,541 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpexedll.dll
[2009/08/06 09:29:26 | 00,109,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp98swin.exe
[2009/08/06 09:29:25 | 00,876,653 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4awel.dll
[2009/08/06 09:29:25 | 00,049,212 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2009/08/06 09:29:25 | 00,032,826 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4avss.dll
[2009/08/06 09:29:25 | 00,014,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2009/08/06 09:29:24 | 00,147,513 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4apws.dll
[2009/08/06 09:29:24 | 00,102,509 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2009/08/06 09:29:24 | 00,049,210 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4areg.dll
[2009/08/06 09:29:24 | 00,041,020 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2009/08/06 09:29:23 | 00,184,435 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2009/08/06 09:29:23 | 00,082,035 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2009/08/06 09:29:20 | 00,188,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2009/08/06 09:29:20 | 00,020,540 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\author.dll
[2009/08/06 09:29:20 | 00,016,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\author.exe
[2009/08/06 09:29:19 | 00,016,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admin.exe
[2009/08/06 09:29:18 | 00,020,540 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admin.dll
[2009/08/05 23:33:32 | 93,767,6800 | -HS- | C] () – C:\hiberfil.sys
[2009/08/05 11:27:40 | 00,010,752 | —- | C] () – C:\Documents and Settings\TEMP\Desktop\exefix_xp.com
[2009/08/04 20:01:59 | 00,000,000 | —D | C] – C:\Documents and Settings\TEMP\My Documents\Kyle and Kendras Restaurant (Kyle)
[2009/08/04 19:57:22 | 00,000,000 | —D | C] – C:\Documents and Settings\TEMP\Application Data\CoreFTP
[2009/08/04 19:27:15 | 00,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Documents
[2009/08/02 20:07:11 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/08/02 20:06:25 | 00,000,000 | —D | C] – C:\Documents and Settings\TEMP\Local Settings\Application Data\AVG Security Toolbar
[2009/08/02 20:03:04 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/08/02 20:03:04 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/08/02 20:03:03 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/08/02 20:02:56 | 00,335,240 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/08/02 20:02:54 | 00,027,784 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/08/02 20:02:17 | 39,935,405 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/02 20:02:15 | 00,067,531 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/02 20:02:11 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/08/02 20:02:04 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/08/02 20:02:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/08/02 20:01:56 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/08/02 20:01:06 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/08/02 20:01:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/08/02 19:39:45 | 00,000,000 | —D | C] – C:\Documents and Settings\TEMP\Application Data\AVG8
[2009/08/01 20:57:14 | 00,000,000 | —D | C] – C:\WINDOWS\System32\images
[2009/07/27 02:42:10 | 00,404,992 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\Weekly Beer and Wine inventory sheet New.xls
[2009/07/27 02:41:37 | 00,510,464 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\Weekly liquor inventory Sheet New.xls
[2009/07/27 02:40:52 | 00,431,104 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly Beer and Wine inventory sheet New.xls
[2009/07/27 02:18:20 | 00,525,824 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly liquor inventory 7-26-09 new.xls
[2009/07/27 02:17:57 | 00,042,006 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly liquor inventory 7-26-09.xlsx
[2009/07/27 00:16:31 | 00,261,120 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\Copy of Copy of Excel Bev weekly tracking.xls
[2009/07/27 00:16:15 | 00,387,072 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly Beer and Wine inventory sheet 7-26-09.xls
[2009/07/27 00:15:58 | 00,092,160 | —- | C] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly liquor inventory 7-26-09.xls
[2009/01/23 13:06:39 | 00,000,149 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/06/10 20:48:07 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2008/06/10 20:47:18 | 00,001,575 | —- | C] () – C:\WINDOWS\System32\WLAN.INI
[2008/02/13 13:48:01 | 00,005,993 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/02/13 13:48:00 | 00,019,968 | R— | C] () – C:\WINDOWS\System32\drivers\LVUSBSta.sys
[2008/02/13 13:47:58 | 00,469,696 | R— | C] () – C:\WINDOWS\System32\drivers\lvcm.sys
[2008/01/04 17:58:50 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/01/04 17:57:22 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/01/04 17:57:22 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/01/04 17:56:24 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/08/26 01:01:55 | 00,030,464 | —- | C] () – C:\WINDOWS\macromix.dll
[2007/08/21 22:55:03 | 00,000,346 | —- | C] () – C:\WINDOWS\Champion.ini
[2007/06/05 22:09:09 | 00,682,232 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2006/12/17 18:27:25 | 02,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2006/12/17 18:27:25 | 00,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2006/12/17 18:27:25 | 00,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2006/12/17 18:27:25 | 00,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2006/12/07 01:03:53 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/07 01:01:13 | 00,000,025 | —- | C] () – C:\WINDOWS\EPCX7800.ini
[2006/12/04 03:59:19 | 00,000,020 | —- | C] () – C:\WINDOWS\LANG.INI
[2006/12/04 03:41:28 | 00,000,158 | —- | C] () – C:\WINDOWS\NAVPRESS.INI
[2006/10/25 00:31:36 | 00,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2006/10/24 23:54:25 | 00,000,124 | —- | C] () – C:\WINDOWS\JORACLE.INI
[2006/09/07 10:15:09 | 00,010,244 | —- | C] () – C:\WINDOWS\hpdj3600.ini
[2006/05/06 21:02:57 | 00,000,255 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2006/04/21 15:38:14 | 00,000,046 | —- | C] () – C:\WINDOWS\QTW.ini
[2006/03/01 16:25:42 | 00,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2006/02/24 17:06:20 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2006/02/11 23:16:30 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\LXPRMON.DLL
[2006/02/11 23:16:30 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\LXPMONUI.DLL
[2006/02/07 01:00:53 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/29 06:18:51 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/11/29 06:18:51 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/11/29 06:18:51 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/11/29 06:18:51 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/11/29 06:18:51 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/11/29 06:18:51 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/11/29 06:07:20 | 00,015,669 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/07/01 07:47:08 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/05/03 12:44:44 | 00,025,157 | —- | C] () – C:\WINDOWS\RMAgentOutput.dll
[2005/05/03 12:43:44 | 00,126,976 | —- | C] () – C:\WINDOWS\dllTSCLIBMT.dll
[2005/03/03 17:16:42 | 00,000,256 | —- | C] () – C:\WINDOWS\aucfg.ini
[2004/10/01 18:33:46 | 00,000,680 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/08/07 09:16:44 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/07 09:10:08 | 00,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/07 08:58:22 | 00,001,161 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/07 01:47:16 | 00,000,254 | —- | C] () – C:\WINDOWS\system.ini
[2003/07/11 09:55:28 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxbuvs.dll
[2002/07/04 16:05:34 | 00,000,269 | —- | C] () – C:\WINDOWS\tmupdate.ini
[2001/12/14 14:34:46 | 00,164,864 | —- | C] () – C:\WINDOWS\patchw32.dll
[1999/07/23 13:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 10:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/01/27 14:39:06 | 00,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[257 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/08/21 01:06:01 | 00,000,270 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/08/21 00:59:52 | 00,472,064 | —- | M] ( ) – C:\Documents and Settings\TEMP\Desktop\RootRepeal.exe
[2009/08/21 00:50:35 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/08/21 00:48:56 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/08/21 00:46:50 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/21 00:46:41 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/21 00:46:38 | 93,767,6800 | -HS- | M] () – C:\hiberfil.sys
[2009/08/21 00:12:15 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/20 13:26:26 | 00,000,104 | —- | M] () – C:\Documents and Settings\TEMP\Desktop\Internet.lnk
[2009/08/20 13:23:38 | 00,101,816 | —- | M] () – C:\Documents and Settings\TEMP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/20 13:16:03 | 01,621,320 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/18 15:19:24 | 00,506,068 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/08/18 15:19:24 | 00,444,596 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/08/18 15:19:24 | 00,072,306 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/08/18 12:45:01 | 00,514,048 | —- | M] (OldTimer Tools) – C:\OTL.exe
[2009/08/18 01:11:11 | 00,000,254 | —- | M] () – C:\WINDOWS\system.ini
[2009/08/18 01:10:40 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/08/18 00:33:00 | 00,000,432 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Update Version2.job
[2009/08/17 18:00:00 | 00,000,458 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Registration.job
[2009/08/17 17:43:41 | 39,935,405 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/17 17:43:41 | 00,067,531 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/17 12:20:33 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/08/17 12:10:30 | 03,124,187 | R— | M] () – C:\Documents and Settings\TEMP\Desktop\Combo-Fix.exe
[2009/08/15 12:11:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/14 19:19:18 | 00,005,630 | —- | M] () – C:\Documents and Settings\TEMP\Desktop\Attach.zip
[2009/08/14 18:47:50 | 00,287,744 | —- | M] () – C:\Documents and Settings\TEMP\Desktop\tewyfq4m.exe
[2009/08/14 18:47:03 | 00,359,932 | —- | M] () – C:\Documents and Settings\TEMP\Desktop\dds.scr
[2009/08/13 20:38:42 | 00,000,701 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/13 20:37:17 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\TEMP\Desktop\third.exe
[2009/08/13 20:34:20 | 01,339,288 | —- | M] () – C:\Documents and Settings\TEMP\Desktop\first.exe
[2009/08/13 18:48:36 | 00,001,061 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/08/13 12:43:05 | 00,000,933 | —- | M] () – C:\Documents and Settings\TEMP\Desktop\Spybot - Search & Destroy.lnk
[2009/08/13 12:36:59 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\TEMP\Desktop\setup-spybotsd162.exe
[2009/08/11 22:20:05 | 00,035,896 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\cc_20090811_221948.reg
[2009/08/11 21:52:36 | 00,262,144 | —- | M] () – C:\WINDOWS\System32\default_user_class.dat
[2009/08/11 21:23:06 | 00,000,738 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Registry Mechanic.lnk
[2009/08/11 21:19:28 | 00,000,150 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090813-130843.backup
[2009/08/10 03:41:35 | 00,000,120 | —- | M] () – C:\WINDOWS\System32\358361390.BAT
[2009/08/10 00:54:24 | 00,000,127 | —- | M] () – C:\Documents and Settings\TEMP\Local Settings\Application Data\fusioncache.dat
[2009/08/08 12:10:14 | 00,216,064 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/05 11:27:54 | 00,010,752 | —- | M] () – C:\Documents and Settings\TEMP\Desktop\exefix_xp.com
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/02 20:03:04 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/08/02 20:03:04 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/08/02 20:03:03 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/08/02 20:02:57 | 00,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/08/02 20:02:54 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/08/02 20:02:15 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/08/02 20:02:11 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/08/01 23:36:51 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/07/27 02:42:26 | 00,404,992 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\Weekly Beer and Wine inventory sheet New.xls
[2009/07/27 02:41:38 | 00,510,464 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\Weekly liquor inventory Sheet New.xls
[2009/07/27 02:40:54 | 00,431,104 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly Beer and Wine inventory sheet New.xls
[2009/07/27 02:38:19 | 00,387,072 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly Beer and Wine inventory sheet 7-26-09.xls
[2009/07/27 02:32:52 | 00,525,824 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly liquor inventory 7-26-09 new.xls
[2009/07/27 02:17:58 | 00,042,006 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly liquor inventory 7-26-09.xlsx
[2009/07/27 02:08:40 | 00,092,160 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\Copy of Weekly liquor inventory 7-26-09.xls
[2009/07/27 00:16:32 | 00,261,120 | —- | M] () – C:\Documents and Settings\TEMP\My Documents\Copy of Copy of Excel Bev weekly tracking.xls

========== LOP Check ==========

[2009/08/17 12:50:41 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/06/25 23:08:02 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/03 11:54:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/08/13 14:08:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\17523904
[2009/08/02 02:42:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\97533896
[2009/08/13 11:59:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/01/07 16:36:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/08/02 12:11:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2006/02/11 23:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FaxCtr
[2007/06/05 21:52:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/07/13 01:54:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2009/01/29 00:19:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2005/11/29 06:23:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/04/14 21:22:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/06/22 02:25:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2007/02/05 17:30:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2006/02/19 13:45:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2006/08/28 20:56:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2005/11/29 05:45:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/10/25 02:34:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/08/21 00:52:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/02/05 17:26:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2009/01/19 20:37:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/08/11 21:20:34 | 00,000,000 | RH-D | M] – C:\Documents and Settings\TEMP\Application Data
[2009/08/04 19:57:28 | 00,000,000 | —D | M] – C:\Documents and Settings\TEMP\Application Data\CoreFTP
[2009/04/14 21:24:18 | 00,000,000 | —D | M] – C:\Documents and Settings\TEMP\Application Data\DriverCure
[2009/06/23 10:34:33 | 00,000,000 | —D | M] – C:\Documents and Settings\TEMP\Application Data\uTorrent
[2009/08/21 00:12:15 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/08/15 12:11:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/08/21 01:06:01 | 00,000,270 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2004/08/04 04:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/08/21 00:50:35 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/08/17 18:00:00 | 00,000,458 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2009/08/18 00:33:00 | 00,000,432 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Update Version2.job
[2009/08/21 00:46:50 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CE7F3C9
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >

Extras.txt
OTL Extras logfile created on: 8/21/2009 1:02:46 AM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.17 Mb Total Physical Memory | 236.18 Mb Available Physical Memory | 26.41% Memory free
2.12 Gb Paging File | 1.56 Gb Available in Paging File | 73.66% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.32 Gb Total Space | 7.31 Gb Free Space | 9.83% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KYLESCOMPUTER
Current User Name: Kyle Mitchell
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] –

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\Common Files\AOL\1141244859\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1141244859\ee\aolsoftware.exe:*:Enabled:AOL Services – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1141244859\ee\aim6.exe" = C:\Program Files\Common Files\AOL\1141244859\ee\aim6.exe:*:Enabled:AIM – (America Online, Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Disabled:backWeb-8876480 – ()
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Documents and Settings\Kendra\Desktop\utorrent.exe" = C:\Documents and Settings\Kendra\Desktop\utorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{08B3B220-5C8A-47E5-B42F-1C7CFDA78B9F}" = MasterCook Deluxe 9.1
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{2157961D-0507-44A8-BCF2-1EE2D439E8DF}" = Civilization III
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3192A00C-7336-48C6-8BD7-54B9CFA6F7C1}" = Windows Rights Management Client
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{37C39957-B0B3-40DC-8BA4-2363241159ED}" = LightScribe [removed]
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 1.01 C1
"{43A6AA2A-74B5-4E1C-91DB-ECB2F99D9ED7}" = HP User Guides 0008
"{466B21EE-2858-4845-B2B3-056FC544DAA3}" = Logitech QuickCam
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{56DF5C9E-6392-46D3-B366-297B14E1DAAF}" = Bonjour Core for Windows
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{764C0C8F-B1B1-49BF-AEDC-4E48E857A667}" = Lexmark Fax Solutions
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{91A5B6C0-EF4E-4830-AC7D-6761C0A9B292}" = hp deskjet 3600
"{9B52B30C-F65C-4244-ABCE-215E46E27AF0}" = Palm Desktop
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}" = Windows Live Sign-in Assistant
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C7EEF2B9-8C16-4A04-B98D-B1A952A47E55}" = Linksys Wireless-G USB Network Adapter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}" = Quick Launch Buttons 5.20 D2
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E6A4F956-B433-4CC1-9074-338641CD4FCA}" = BlackBerry Desktop Software 4.1.1
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility
"{EDE721EC-870A-11D8-9D75-000129760D75}" = PowerDirector Express
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF6F491D-BC82-4DCC-A72F-1824957C6466}" = TIxx21
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM Search" = AIM Search
"AIM_6" = AIM 6
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.5
"Bible Explorer Bible Downloadable Edition" = Bible Explorer Bible Downloadable Edition
"BlackBerry_{E6A4F956-B433-4CC1-9074-338641CD4FCA}" = BlackBerry Desktop Software 4.1.1
"CCleaner" = CCleaner (remove only)
"CNXT_AUDIO" = Conexant AC-Link Audio
"CNXT_MODEM_PCI_VEN_1002&DEV_4378" = Soft Data Fax Modem with SmartCP
"ComcastToolbar" = Comcast Toolbar
"Core FTP LE 1.3c" = Core FTP LE 1.3c
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"FLV Player" = FLV Player 2.0, build 23
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"Google Desktop" = Google Desktop Search
"HijackThis" = HijackThis 2.0.2
"InstallShield_{08B3B220-5C8A-47E5-B42F-1C7CFDA78B9F}" = MasterCook Deluxe 9.1
"InstallShield_{2157961D-0507-44A8-BCF2-1EE2D439E8DF}" = Civilization III
"InstallShield_{764C0C8F-B1B1-49BF-AEDC-4E48E857A667}" = Lexmark Fax Solutions
"InstallShield_{FF6F491D-BC82-4DCC-A72F-1824957C6466}" = Texas Instruments PCIxx21/x515 drivers.
"IrfanView" = IrfanView (remove only)
"Lexmark 6200 Series" = Lexmark 6200 Series
"Logitech Print Service" = Logitech Print Service
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mitsubishi_caps" = Mitsubishi Computerized Automatic Parts Searching System (CAPS)
"Money2005b" = Microsoft Money 2005
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"MySpaceIM" = MySpaceIM
"QcDrv" = Logitech® Camera Driver
"RealArcade 1.2" = RealArcade
"RealPlayer 6.0" = RealPlayer
"Recover Files_is1" = Recover Files 2.1
"Registry Mechanic_is1" = Registry Mechanic 8.0
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Viewpoint Toolbar" = Viewpoint Toolbar
"ViewpointMediaPlayer" = Viewpoint Media Player
"WeatherBug" = WeatherBug
"WIC" = Windows Imaging Component
"WinAVIVideoConverter_is1" = WinAVIVideoConverter
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XChampChessDeinstKey" = Championship Chess
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Customizations" = Yahoo! extras
"Yahoo! Internet Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"WinImage" = WinImage

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/5/2009 12:15:26 AM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 8/5/2009 12:15:31 AM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 8/5/2009 12:15:48 AM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 8/5/2009 12:19:46 AM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 8/5/2009 12:21:46 AM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 8/7/2009 12:55:27 PM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application _ex-68.exe, version 0.0.0.0, faulting module
_ex-68.exe, version 0.0.0.0, fault address 0x00001f51.

Error - 8/7/2009 2:34:04 PM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1001
Description = Fault bucket 1387941314.

Error - 8/9/2009 5:18:58 AM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application _ex-68.exe, version 0.0.0.0, faulting module
_ex-68.exe, version 0.0.0.0, fault address 0x0002f1cd.

Error - 8/10/2009 9:46:22 AM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application b.exe, version 0.0.0.0, faulting module b.exe,
version 0.0.0.0, fault address 0x0000da02.

Error - 8/10/2009 2:06:04 PM | Computer Name = KYLESCOMPUTER | Source = Application Error | ID = 1000
Description = Faulting application b.exe, version 0.0.0.0, faulting module ntdll.dll,
version 5.1.2600.3520, fault address 0x0001ab0a.

[ System Events ]
Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .

Error - 8/21/2009 12:47:04 AM | Computer Name = KYLESCOMPUTER | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .


< End of report >
Root Repeal ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/21 01:24 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xEE0C5000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7A48000 Size: 8192 File Visible: No Signed: - Status: - Name: PCI_NTPNP6722 Image Path: \Driver\PCI_NTPNP6722 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xEB7CE000 Size: 49152 File Visible: No Signed: - Status: - Name: uphcleanhlp.sys Image Path: C:\WINDOWS\system32\Drivers\uphcleanhlp.sys Address: 0xEB9EA000 Size: 8960 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: c:\windows\temp\0131f65f-ec1d-416d-844c-3d3bbdf584df.tmp Status: Allocation size mismatch (API: 8, Raw: 0) SSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "Lbd.sys" at address 0xf754287e #: 071 Function Name: NtEnumerateKey Status: Hooked by "sptd.sys" at address 0xf72efe2c #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "sptd.sys" at address 0xf72f01ba #: 119 Function Name: NtOpenKey Status: Hooked by "sptd.sys" at address 0xf72ea0b0 #: 160 Function Name: NtQueryKey Status: Hooked by "sptd.sys" at address 0xf72f0292 #: 177 Function Name: NtQueryValueKey Status: Hooked by "sptd.sys" at address 0xf72f0112 #: 247 Function Name: NtSetValueKey Status: Hooked by "Lbd.sys" at address 0xf7542bfe #: 263 Function Name: NtUnloadKey Status: Hooked by "C:\WINDOWS\system32\Drivers\uphcleanhlp.sys" at address 0xeb9ea6d0 Stealth Objects ——————- Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x859651e8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE] Process: System Address: 0x859661e8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE] Process: System Address: 0x859661e8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x859661e8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x859661e8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_POWER] Process: System Address: 0x859661e8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x859661e8 Size: 121 Object: Hidden Code [Driver: atapi, IRP_MJ_PNP] Process: System Address: 0x859661e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP] Process: System Address: 0x857ef1e8 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE] Process: System Address: 0x857f57a0 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE] Process: System Address: 0x857f57a0 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x857f57a0 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x857f57a0 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER] Process: System Address: 0x857f57a0 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x857f57a0 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP] Process: System Address: 0x857f57a0 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP] Process: System Address: 0x859d41e8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE] Process: System Address: 0x855417a0 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE] Process: System Address: 0x855417a0 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x855417a0 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x855417a0 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP] Process: System Address: 0x855417a0 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP] Process: System Address: 0x855417a0 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE] Process: System Address: 0x858037a0 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE] Process: System Address: 0x858037a0 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x858037a0 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x858037a0 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER] Process: System Address: 0x858037a0 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x858037a0 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP] Process: System Address: 0x858037a0 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP] Process: System Address: 0x8527d1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_CREATE] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_CLOSE] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_READ] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_SET_INFORMATION] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_SHUTDOWN] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_CLEANUP] Process: System Address: 0x8559c1e8 Size: 121 Object: Hidden Code [Driver: CdfsЅఄ扏济Controller, IRP_MJ_PNP] Process: System Address: 0x8559c1e8 Size: 121 ==EOF==
Hi Kyle,

One of the things I noticed is you have 3 real time Antispyware processes running. Adwatch, Spybots' TeaTimer, and Win Defender. I would suggest you pick only one of those to run at one time as they may conflict and slow things down. I will temporarily stop them during the following fix so they do not interfear.

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
    PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
    PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
    IE - URLSearchHook: *{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - Reg Error: Key error. File not found
    IE - URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
    IE - URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O3 - HKLM\..\Toolbar: (no name) - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - No CLSID value found.
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log

Next, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:31:35 AM, on 8/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_Update.exe
C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_App.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Documents and Settings\TEMP\Desktop\third.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\m_bam.exe" /runcleanupscript
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-1008\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Kendra')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Guest')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Guest')
O4 - HKUS\S-1-5-21-3013673612-3101054561-2563110801-501\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Guest')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_Update.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MasterCook Web Import Bar - {E6EF5071-7647-4E85-9785-87B6CF5CB561} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://pconweb.darden.com/includes/smsx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 12594 bytes


Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 5.1.2600 Service Pack 2

8/22/2009 1:17:54 PM
mbam-log-2009-08-22 (13-17-54).txt

Scan type: Quick Scan
Objects scanned: 121358
Time elapsed: 13 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mEv (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\dvdpaly.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\EvdoServer.dll (Backdoor.Bot) -> Quarantined and deleted successfully.



OTL File
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named MsMpEng.exe was found!
No active process named AAWTray.exe was found!
No active process named TeaTimer.exe was found!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\*{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497} not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\*{EF99BD32-C1FB-11D2-892F-0090271D4F88} not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2}\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Application Data

User: Default User
->Temp folder emptied: 1008 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Guest
File delete failed. C:\Documents and Settings\Guest\Local Settings\Temp\hsperfdata_Guest\1940 scheduled to be deleted on reboot.
->Temp folder emptied: 65536 bytes
->Temporary Internet Files folder emptied: 702479 bytes
->Java cache emptied: 2496645 bytes
->FireFox cache emptied: 25258606 bytes

User: Kendra
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 95825 bytes
->Java cache emptied: 14474607 bytes
->FireFox cache emptied: 30913795 bytes

User: Kyle Mitchell
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 7934256 bytes
->Java cache emptied: 42576868 bytes
->FireFox cache emptied: 54755463 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 6570448 bytes
->FireFox cache emptied: 24156580 bytes

User: NetworkService
->Temp folder emptied: 5468 bytes
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 32969 bytes

User: TEMP
->Temp folder emptied: 41802066 bytes
->Temporary Internet Files folder emptied: 394432 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 50012005 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1053297 bytes
%systemroot%\System32 .tmp files removed: 66556641 bytes
File delete failed. C:\WINDOWS\temp\TMP00000001E7C9274A6DCCEC11 scheduled to be deleted on reboot.
Windows Temp folder emptied: 552050 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 353.28 mb


OTL by OldTimer - Version 3.0.10.7 log created on 08222009_115633

Files\Folders moved on Reboot…
File move failed. C:\Documents and Settings\Guest\Local Settings\Temp\hsperfdata_Guest\1940 scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\TMP00000001E7C9274A6DCCEC11 not found!

Registry entries deleted on Reboot…
Hi,

Some items were missed by OTL, not sure why.

Are you running HijackThis directly from the desktop, renamed as C:\Documents and Settings\TEMP\Desktop\third.exe? Looks like it….

You should move it to a permanent folder so the backups don't get inadvertently removed. You can do that or just remove the third.exe file and download a fresh copy as described below. It will install HJT into the programs directory.

[external image: Posted Image]Click here to download HJTInstall.exe
  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.

You will need to temporarily disable the real time protections you have on from Adwatch, Spybot, and Windows Defender. This is described for each in the following link.

http://www.bleepingcomputer.com/forums/ind…st&p=649847

Next, Run HijackThis.
Click Do a System Scan Only. Put a Check in the box on the left side on these:

R3 - URLSearchHook: (no name) - *{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

Then close all windows except HijackThis and press Fix checked.

Reboot and post a new HJT log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI