willgabe
Topic Starter
Wireless keyboard keeps missing letters. Running Vista Home Premium. Driving me nuts! Have changed batteries and it is right next to optical receiver. Have used scans via Norton 360 and ThreatFire but no joy there. Any help gratefully accepted. Files copied and attached as pe instructions. Any other info required just let me know.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/30 13:00
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
——————-
Name: catchme.sys
Image Path: C:\Users\office\AppData\Local\Temp\catchme.sys
Address: 0x933F2000 Size: 31744 File Visible: No Signed: -
Status: -
Name: crcdisk.sys
Image Path: C:\Windows\system32\drivers\crcdisk.sys
Address: 0x885C6000 Size: 36864 File Visible: - Signed: -
Status: Hidden from the Windows API!
Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x88309000 Size: 815104 File Visible: No Signed: -
Status: -
Name: mchInjDrv.sys
Image Path: C:\Windows\system32\Drivers\mchInjDrv.sys
Address: 0xA2802000 Size: 2560 File Visible: No Signed: -
Status: -
Name: PROCEXP90.SYS
Image Path: C:\Windows\system32\Drivers\PROCEXP90.SYS
Address: 0xA2800000 Size: 6464 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x8C400000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1172 Status: Locked to the Windows API!
SSDT
——————-
#: 013 Function Name: NtAlertResumeThread
Status: Hooked by "" at address 0x874b0e58
#: 014 Function Name: NtAlertThread
Status: Hooked by "" at address 0x873b2df8
#: 018 Function Name: NtAllocateVirtualMemory
Status: Hooked by "" at address 0x87f4e1b0
#: 021 Function Name: NtAlpcConnectPort
Status: Hooked by "" at address 0x872bc008
#: 042 Function Name: NtAssignProcessToJobObject
Status: Hooked by "" at address 0x877fa048
#: 067 Function Name: NtCreateMutant
Status: Hooked by "" at address 0x87f56ac0
#: 077 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "" at address 0x87f5bfc0
#: 078 Function Name: NtCreateThread
Status: Hooked by "" at address 0x8738f678
#: 116 Function Name: NtDebugActiveProcess
Status: Hooked by "" at address 0x87393da8
#: 129 Function Name: NtDuplicateObject
Status: Hooked by "" at address 0x87f4e388
#: 147 Function Name: NtFreeVirtualMemory
Status: Hooked by "" at address 0x87f4fa30
#: 156 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "" at address 0x8736b8e8
#: 158 Function Name: NtImpersonateThread
Status: Hooked by "" at address 0x87362468
#: 165 Function Name: NtLoadDriver
Status: Hooked by "" at address 0x872b7a78
#: 177 Function Name: NtMapViewOfSection
Status: Hooked by "" at address 0x87f4f890
#: 184 Function Name: NtOpenEvent
Status: Hooked by "" at address 0x8739f108
#: 194 Function Name: NtOpenProcess
Status: Hooked by "" at address 0x87f4e668
#: 195 Function Name: NtOpenProcessToken
Status: Hooked by "" at address 0x87332798
#: 197 Function Name: NtOpenSection
Status: Hooked by "" at address 0x873b1658
#: 201 Function Name: NtOpenThread
Status: Hooked by "" at address 0x87f4e4d8
#: 210 Function Name: NtProtectVirtualMemory
Status: Hooked by "" at address 0x87f5acc0
#: 282 Function Name: NtResumeThread
Status: Hooked by "" at address 0x87319718
#: 289 Function Name: NtSetContextThread
Status: Hooked by "" at address 0x87362108
#: 305 Function Name: NtSetInformationProcess
Status: Hooked by "" at address 0x87f4f638
#: 317 Function Name: NtSetSystemInformation
Status: Hooked by "" at address 0x87512728
#: 330 Function Name: NtSuspendProcess
Status: Hooked by "" at address 0x8738c200
#: 331 Function Name: NtSuspendThread
Status: Hooked by "" at address 0x8736b850
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Windows\system32\drivers\TfSysMon.sys" at address 0x8df70adc
#: 335 Function Name: NtTerminateThread
Status: Hooked by "" at address 0x87365068
#: 348 Function Name: NtUnmapViewOfSection
Status: Hooked by "" at address 0x87900810
#: 358 Function Name: NtWriteVirtualMemory
Status: Hooked by "" at address 0x87f4fd40
#: 382 Function Name: NtCreateThreadEx
Status: Hooked by "" at address 0x87f5a4e0
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 12:52:24.26 on 30/08/2009
Internet Explorer: 8.0.6001.18813 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2046.852 [GMT 1:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\atashost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Kontiki\KService.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehRecvr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Explorer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\DllHost.exe
C:\Users\office\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=71&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.0.0.134\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
uRun: [kdx] c:\program files\kontiki\KHost.exe -all
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Sony Ericsson PC Suite] "c:\program files\sony ericsson\sony ericsson pc suite\SEPCSuite.exe" /systray /nologon
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [kdx] "c:\program files\kontiki\KHost.exe" -all
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [D-Link D-Link Wireless N DWA-140] c:\program files\d-link\d-link wireless n dwa-140\AirNCFG.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [ThreatFire] c:\program files\threatfire\TFTray.exe
mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
Trusted Zone: microsoft.com\office
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.co.uk/SnapfishUKActivia.cab
DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin2.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://esignal.webex.com/client/T26L/support/ieatgpc1.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://spinpalace.microgaming.com/spinpalace/FlashAX2.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.0.0.134\CoIEPlg.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\office\appdata\roaming\mozilla\firefox\profiles\b3clwva2.default\
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npicaN.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0300000.086\SymEFA.sys [2009-8-17 310320]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-8-29 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-8-29 46864]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0300000.086\BHDrvx86.sys [2009-8-17 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0300000.086\cchpx86.sys [2009-8-17 482352]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090810.001\IDSvix86.sys [2009-8-17 293424]
R2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2008-4-7 19864]
R2 DQLWinService;DQLWinService;c:\program files\common files\intel\inteldh\nms\adpplugins\DQLWinService.exe [2006-9-3 208896]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.0.0.134\ccSvcHst.exe [2009-8-17 115560]
R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\ralink\common\RalinkRegistryWriter.exe [2008-11-6 75040]
R2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service –> c:\program files\threatfire\TFService.exe service [?]
R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [2007-1-26 2831232]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-26 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0300000.086\symndisv.sys [2009-8-17 39984]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-8-29 33552]
S2 IntelDHSvcConf;Intel DH Service;c:\program files\intel\inteldh\intel media server\tools\IntelDHSvcConf.exe [2006-5-10 29696]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-8-8 13224]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2008-11-6 710144]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2008-11-5 476416]
=============== Created Last 30 ================
2009-08-29 00:26 –d—– c:\programdata\TEMP
2009-08-29 00:26 51,984 a——- c:\windows\system32\drivers\TfFsMon.sys
2009-08-29 00:26 46,864 a——- c:\windows\system32\drivers\TfSysMon.sys
2009-08-29 00:26 33,552 a——- c:\windows\system32\drivers\TfNetMon.sys
2009-08-29 00:26 –d—– c:\programdata\PC Tools
2009-08-29 00:26 –d—– c:\program files\ThreatFire
2009-08-29 00:26 –d—– c:\progra~2\PC Tools
2009-08-28 16:24 –dsh— C:\$RECYCLE.BIN
2009-08-28 16:13 229,376 a——- c:\windows\PEV.exe
2009-08-28 16:13 161,792 a——- c:\windows\SWREG.exe
2009-08-28 16:13 98,816 a——- c:\windows\sed.exe
2009-08-28 16:12 –ds—- C:\ComboFix
2009-08-27 03:03 2,048 a——- c:\windows\system32\tzres.dll
2009-08-26 08:03 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-08-26 08:03 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-25 23:42 –d—– c:\windows\system32\eu-ES
2009-08-25 23:42 –d—– c:\windows\system32\ca-ES
2009-08-25 23:42 –d—– c:\program files\Microsoft Games
2009-08-25 23:42 –d—– c:\windows\system32\vi-VN
2009-08-25 22:39 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-08-25 22:39 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-25 22:39 –d—– c:\program files\iPod
2009-08-25 22:39 –d—– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-25 22:39 –d—– c:\program files\iTunes
2009-08-25 22:39 –d—– c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-25 22:38 –d—– c:\program files\Bonjour
2009-08-25 22:09 –d—– c:\windows\system32\EventProviders
2009-08-25 22:07 12,240,896 a——- c:\windows\system32\NlsLexicons0007.dll
2009-08-25 22:07 3,408,896 a——- c:\windows\system32\SLsvc.exe
2009-08-25 22:07 1,081,344 a——- c:\windows\system32\SLCExt.dll
2009-08-25 22:07 2,134,528 a——- c:\windows\system32\FunctionDiscoveryFolder.dll
2009-08-25 22:07 65,536 a——- c:\windows\system32\DevicePairingWizard.exe
2009-08-25 22:05 1,502,720 a——- c:\windows\system32\certmgr.dll
2009-08-25 22:04 247,808 a——- c:\windows\system32\drvstore.dll
2009-08-25 10:15 –d–r– c:\program files\Norton Support
2009-08-22 21:29 122,880 a——- c:\windows\system32\dmdskres32.dll
2009-08-19 21:14 –d—– c:\windows\pss
2009-08-19 17:49 –d—– c:\program files\common files\DivX Shared
2009-08-19 13:13 –d—– c:\program files\My Company Name
2009-08-19 13:03 –d—– c:\windows\system32\AGEIA
2009-08-17 16:38 –d—– c:\users\office\appdata\roaming\LimeWire
2009-08-17 16:37 –d—– c:\program files\LimeWire
2009-08-17 15:29 25,136 a—-r– c:\windows\system32\drivers\SymIMV.sys
2009-08-17 15:29 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-08-17 15:29 7,386 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-08-17 15:29 805 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-08-17 15:29 –d—– c:\program files\Symantec
2009-08-17 15:28 –d—– c:\windows\system32\drivers\N360
2009-08-17 15:28 –d—– c:\program files\Norton 360
2009-08-17 15:28 –d—– c:\program files\NortonInstaller
2009-08-15 12:19 –d—– c:\users\office\appdata\roaming\HpUpdate
2009-08-15 12:19 –d—– c:\windows\Hewlett-Packard
2009-08-13 10:37 1,259,008 a——- c:\windows\system32\lsasrv.dll
2009-08-13 10:37 499,712 a——- c:\windows\system32\kerberos.dll
2009-08-13 10:37 218,624 a——- c:\windows\system32\msv1_0.dll
2009-08-13 10:37 270,848 a——- c:\windows\system32\schannel.dll
2009-08-13 10:37 175,104 a——- c:\windows\system32\wdigest.dll
2009-08-13 10:37 439,864 a——- c:\windows\system32\drivers\ksecdd.sys
2009-08-13 10:37 72,704 a——- c:\windows\system32\secur32.dll
2009-08-13 10:37 9,728 a——- c:\windows\system32\lsass.exe
2009-08-13 10:25 3,840 a——- c:\windows\system32\drivers\BANTExt.sys
2009-08-13 10:25 –d—– c:\program files\Belarc
2009-08-12 15:43 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-08-12 15:43 136,192 a——- c:\windows\system32\aaclient.dll
2009-08-12 15:43 53,248 a——- c:\windows\system32\tsgqec.dll
2009-08-12 15:43 160,256 a——- c:\windows\system32\wkssvc.dll
2009-08-12 15:43 71,680 a——- c:\windows\system32\atl.dll
2009-08-12 15:43 91,136 a——- c:\windows\system32\avifil32.dll
2009-08-12 15:43 71,168 a——- c:\windows\system32\telnet.exe
2009-08-12 15:42 313,344 a——- c:\windows\system32\wmpdxm.dll
2009-08-12 15:42 4,096 a——- c:\windows\system32\msdxm.ocx
2009-08-12 15:42 4,096 a——- c:\windows\system32\dxmasf.dll
2009-08-12 15:42 7,680 a——- c:\windows\system32\spwmp.dll
2009-08-12 15:42 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-08-12 15:42 43,520 a——- c:\windows\system32\msdxm.tlb
2009-08-12 15:42 18,432 a——- c:\windows\system32\amcompat.tlb
2009-08-08 16:13 1,112,288 a——- c:\windows\system32\WdfCoInstaller01007.dll
2009-08-08 16:13 25,512 a——- c:\windows\system32\drivers\ggsemc.sys
2009-08-08 16:13 13,224 a——- c:\windows\system32\drivers\ggflt.sys
==================== Find3M ====================
2009-08-25 23:49 143,360 a——- c:\windows\inf\infstrng.dat
2009-08-25 23:49 143,360 a——- c:\windows\inf\infstor.dat
2009-08-25 23:49 51,200 a——- c:\windows\inf\infpub.dat
2009-08-25 23:42 665,600 a——- c:\windows\inf\drvindex.dat
2009-08-22 14:31 26,618 a——- c:\users\office\appdata\roaming\wklnhst.dat
2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll
2009-07-24 17:48 0 a—h— c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2009-07-21 22:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-21 22:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-21 22:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-21 21:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-06-27 21:13 3,440,038 a——- c:\users\office\hq.exe
2009-06-15 15:53 156,672 a——- c:\windows\system32\t2embed.dll
2009-06-15 15:52 23,552 a——- c:\windows\system32\lpk.dll
2009-06-15 15:52 72,704 a——- c:\windows\system32\fontsub.dll
2009-06-15 15:51 10,240 a——- c:\windows\system32\dciman32.dll
2009-06-15 13:42 289,792 a——- c:\windows\system32\atmfd.dll
2009-06-05 12:56 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-06-05 12:56 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2009-06-05 12:56 542,720 a——- c:\windows\apppatch\AcLayers.dll
2009-06-05 12:56 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2009-02-19 16:47 60,744 a——- c:\users\office\g2mdlhlpx.exe
2008-11-13 21:56 69,544 a——- c:\users\office\appdata\roaming\GDIPFONTCACHEV1.DAT
2008-07-23 10:27 174 a–sh— c:\program files\desktop.ini
2007-12-12 20:06 1,786,691 a——- c:\users\office\HiNetRecorderSetup.exe
2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
1999-06-25 10:55 149,504 a——- c:\program files\UNWISE.EXE
============= FINISH: 12:53:34.20 ===============