DesignOtaku
Topic Starter
Howdie all,
Im running a reasonably old but up to date version of XP without too many troubles to date. Lately Im experiencing very slow performance and the occasion RAM issue. I use all the usual stuff like spybot resident / teatimer, avast onaccess scanner, and have recently been using bitdeffender as a friend mentioned it may solve my current problem. besides the fact that a bitdefender scan found some file that were downloaded yrs ago and decided they were malware (which I have since deleted) I cant find any other issues with those scans.
Heres my rootrepeal log -
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/06 16:42
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_diskdump.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_diskdump.sys
Address: 0xEF8FC000 Size: 16384 File Visible: No Signed: -
Status: -
Name: dump_SiSRaid.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_SiSRaid.sys
Address: 0xEFC6E000 Size: 45056 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEF339000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee1596b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee159574
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee159a52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15914c
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15964e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7ac90
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7ad7e
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15976e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15972e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee1598ae
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7abf4
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7aec4
==EOF==
Heres my DDS log -
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 16:38:59.79 on Sun 06/09/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.991.398 [GMT 10:00]
AV: avast! antivirus 4.8.1351 [VPS 090829-0] *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vsnp2std.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Burke\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.designotaku.com.au/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Click-to-Call BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - c:\program files\windows live\messenger\wlchtc.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 7\PcSync2.exe" /NoDialog
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [snp2std] c:\windows\vsnp2std.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [D-Link D-Link Wireless G DWA-510] c:\program files\d-link\d-link wireless g dwa-510\AirGCFG.exe
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2009\bdagent.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [UDC Integration]
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PcSync2.exe" /NoDialog
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148271823671
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} - file://c:\program files\autocad 2002\InstBanr.ocx
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file://c:\program files\autocad 2002\InstFred.ocx
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file://c:\program files\autocad 2002\AcPreview.ocx
TCP: {8C08D7CA-A295-42E2-AC81-D19F86BF5447} = 192.231.203.132,192.231.203.3
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\chrisb~1\applic~1\mozilla\firefox\profiles\frtmtv5u.chrisnew\
FF - prefs.js: browser.startup.homepage - www.designotaku.com.au
FF - component: c:\documents and settings\chris burke\application data\mozilla\firefox\profiles\frtmtv5u.chrisnew\extensions\[removed]\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\chris burke\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\common-use signing interface\bin\npCsiPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-30 114768]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-10-30 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-10-30 138680]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [2003-7-17 18848]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-10-30 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-10-30 352920]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2009-4-15 146312]
R3 VMHybrid;VMHybrid service;c:\windows\system32\drivers\VMHybrid.sys [2008-9-1 1060224]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-8-23 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-8-23 8320]
S3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664]
S4 TwonkyMedia;TwonkyMedia;c:\program files\nokia\nokia home media server\media server\twonkymedia.exe -serviceversion 0 –> c:\program files\nokia\nokia home media server\media server\TwonkyMedia.exe -serviceversion 0 [?]
=============== Created Last 30 ================
2009-09-04 09:56 116,224 a——- c:\windows\system32\pdfcmnnt.dll
2009-09-04 09:56 23,552 a——- c:\windows\system32\MSMPIDE.DLL
2009-09-04 09:56 –d—– c:\program files\PDFCreator
2009-09-04 09:55 21,192 a——- c:\windows\system32\dopdfmn6.dll
2009-09-04 09:55 18,632 a——- c:\windows\system32\dopdfmi6.dll
2009-09-04 09:55 7,537 a——- c:\windows\system32\dopdf6.ctm
2009-09-04 09:54 –d—– c:\program files\Softland
2009-09-04 09:22 5,632 a——- c:\windows\system32\udcpm.dll
2009-09-04 09:22 –d–r– C:\UDC Output Files
2009-09-04 09:22 –d—– c:\program files\Universal Document Converter
2009-09-03 15:52 –d—– c:\program files\MSECache
2009-09-01 17:54 –d—– C:\mhnnzqvu.default
2009-08-27 22:36 722 a——- c:\windows\system32\BDUpdateV1.xml
2009-08-27 17:58 81,984 a——- c:\windows\system32\bdod.bin
2009-08-27 17:27 850 a——- c:\windows\system32\ProductTweaks.xml
2009-08-27 17:27 385 a——- c:\windows\system32\user_gensett.xml
2009-08-27 17:27 23,392 a——- c:\windows\system32\nscompat.tlb
2009-08-27 17:27 16,832 a——- c:\windows\system32\amcompat.tlb
2009-08-27 17:23 –d—– c:\docume~1\chrisb~1\applic~1\BitDefender
2009-08-27 17:23 –d—– c:\program files\BitDefender
2009-08-27 17:23 –d—– c:\docume~1\alluse~1\applic~1\BitDefender
2009-08-27 17:22 –d—– c:\program files\common files\BitDefender
2009-08-27 10:36 18,816 a——- c:\windows\system32\drivers\pccsmcfd.sys
2009-08-27 10:33 –d—– c:\docume~1\chrisb~1\applic~1\HouseCall 6.6
2009-08-27 10:30 27,784 a——- c:\windows\system32\drivers\point32.sys
2009-08-27 10:29 –d—– c:\program files\Microsoft IntelliPoint
2009-08-26 23:51 54,156 a—h— c:\windows\QTFont.qfn
2009-08-26 23:51 1,409 a——- c:\windows\QTFont.for
2009-08-26 23:49 4,463,988 a——- c:\windows\setupapi.log.4.old
2009-08-26 08:45 3,587,641 a——- c:\windows\setupapi.log.1.old
2009-08-23 22:42 –d—– c:\program files\Free-Buttons.org
2009-08-23 21:25 -cd-h— c:\docume~1\alluse~1\applic~1\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-08-23 20:58 8,320 a——- c:\windows\system32\drivers\nmwcdnsuc.sys
2009-08-23 20:58 136,704 a——- c:\windows\system32\drivers\nmwcdnsu.sys
2009-08-23 20:58 7,808 a——- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-08-23 20:58 22,016 a——- c:\windows\system32\drivers\ccdcmbo.sys
2009-08-23 20:58 7,808 a——- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-08-23 20:58 1,112,288 a——- c:\windows\system32\wdfcoinstaller01007.dll
2009-08-23 20:58 659,968 a——- c:\windows\system32\nmwcdcocls.dll
2009-08-23 20:58 17,664 a——- c:\windows\system32\drivers\ccdcmb.sys
2009-08-23 17:42 –d—– c:\documents and settings\chris burke\ErrorLogs
2009-08-20 22:58 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-19 18:08 299,008 a——- c:\windows\system32\Msdbrptr.dll
2009-08-19 18:08 203,576 a——- c:\windows\system32\Richtx32.ocx
2009-08-19 18:08 102,912 a——- c:\windows\system32\Vb6stkit.dll
2009-08-19 18:08 166,200 a——- c:\windows\system32\Msmask32.ocx
2009-08-19 18:08 –d—– c:\program files\TWC
2009-08-19 18:07 –d—– c:\program files\RKET
2009-08-19 18:05 –d—– c:\program files\FileNet
2009-08-19 18:04 –d—– C:\ProgramData
2009-08-19 18:04 –d—– C:\Informed
2009-08-17 11:57 –d—– c:\docume~1\alluse~1\applic~1\ALM
2009-08-17 11:56 –d—– c:\program files\Bonjour
2009-08-17 11:44 –d—– c:\program files\common files\Macrovision Shared
2009-08-16 09:08 69,075,917 a——- c:\windows\setupapi.log.0.old
2009-08-08 11:19 18,261,833 a——- c:\windows\setupapi.log.3.old
2009-08-08 10:37 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat
==================== Find3M ====================
2009-09-03 15:53 90,224 ac—— c:\docume~1\chrisb~1\applic~1\GDIPFONTCACHEV1.DAT
2009-08-27 17:57 146,312 a——- c:\windows\system32\drivers\bdfm.sys
2009-08-05 19:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-25 05:23 411,368 ac—— c:\windows\system32\deploytk.dll
2009-07-18 05:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-04 03:09 915,456 a——- c:\windows\system32\wininet.dll
2009-06-25 18:25 730,112 a——- c:\windows\system32\lsasrv.dll
2009-06-25 18:25 301,568 a——- c:\windows\system32\kerberos.dll
2009-06-25 18:25 147,456 a——- c:\windows\system32\schannel.dll
2009-06-25 18:25 136,192 a——- c:\windows\system32\msv1_0.dll
2009-06-25 18:25 56,832 a——- c:\windows\system32\secur32.dll
2009-06-25 18:25 54,272 a——- c:\windows\system32\wdigest.dll
2009-06-17 00:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-17 00:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-12 22:31 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 22:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-11 00:13 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 16:14 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll
2008-04-15 08:46 32 ac—— c:\docume~1\alluse~1\applic~1\ezsid.dat
2006-08-30 11:15 154,412,622 a——- c:\documents and settings\chris burke\PC Games - The Sims 2 (Full Version).zip
============= FINISH: 16:40:51.26 ===============
Im running a reasonably old but up to date version of XP without too many troubles to date. Lately Im experiencing very slow performance and the occasion RAM issue. I use all the usual stuff like spybot resident / teatimer, avast onaccess scanner, and have recently been using bitdeffender as a friend mentioned it may solve my current problem. besides the fact that a bitdefender scan found some file that were downloaded yrs ago and decided they were malware (which I have since deleted) I cant find any other issues with those scans.
Heres my rootrepeal log -
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/06 16:42
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_diskdump.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_diskdump.sys
Address: 0xEF8FC000 Size: 16384 File Visible: No Signed: -
Status: -
Name: dump_SiSRaid.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_SiSRaid.sys
Address: 0xEFC6E000 Size: 45056 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEF339000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee1596b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee159574
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee159a52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15914c
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15964e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7ac90
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7ad7e
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15976e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15972e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee1598ae
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7abf4
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7aec4
==EOF==
Heres my DDS log -
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 16:38:59.79 on Sun 06/09/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.991.398 [GMT 10:00]
AV: avast! antivirus 4.8.1351 [VPS 090829-0] *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vsnp2std.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Burke\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.designotaku.com.au/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Click-to-Call BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - c:\program files\windows live\messenger\wlchtc.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 7\PcSync2.exe" /NoDialog
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [snp2std] c:\windows\vsnp2std.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [D-Link D-Link Wireless G DWA-510] c:\program files\d-link\d-link wireless g dwa-510\AirGCFG.exe
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2009\bdagent.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [UDC Integration]
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PcSync2.exe" /NoDialog
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148271823671
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} - file://c:\program files\autocad 2002\InstBanr.ocx
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file://c:\program files\autocad 2002\InstFred.ocx
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file://c:\program files\autocad 2002\AcPreview.ocx
TCP: {8C08D7CA-A295-42E2-AC81-D19F86BF5447} = 192.231.203.132,192.231.203.3
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\chrisb~1\applic~1\mozilla\firefox\profiles\frtmtv5u.chrisnew\
FF - prefs.js: browser.startup.homepage - www.designotaku.com.au
FF - component: c:\documents and settings\chris burke\application data\mozilla\firefox\profiles\frtmtv5u.chrisnew\extensions\[removed]\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\chris burke\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\common-use signing interface\bin\npCsiPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-30 114768]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-10-30 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-10-30 138680]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [2003-7-17 18848]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-10-30 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-10-30 352920]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2009-4-15 146312]
R3 VMHybrid;VMHybrid service;c:\windows\system32\drivers\VMHybrid.sys [2008-9-1 1060224]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-8-23 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-8-23 8320]
S3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664]
S4 TwonkyMedia;TwonkyMedia;c:\program files\nokia\nokia home media server\media server\twonkymedia.exe -serviceversion 0 –> c:\program files\nokia\nokia home media server\media server\TwonkyMedia.exe -serviceversion 0 [?]
=============== Created Last 30 ================
2009-09-04 09:56 116,224 a——- c:\windows\system32\pdfcmnnt.dll
2009-09-04 09:56 23,552 a——- c:\windows\system32\MSMPIDE.DLL
2009-09-04 09:56 –d—– c:\program files\PDFCreator
2009-09-04 09:55 21,192 a——- c:\windows\system32\dopdfmn6.dll
2009-09-04 09:55 18,632 a——- c:\windows\system32\dopdfmi6.dll
2009-09-04 09:55 7,537 a——- c:\windows\system32\dopdf6.ctm
2009-09-04 09:54 –d—– c:\program files\Softland
2009-09-04 09:22 5,632 a——- c:\windows\system32\udcpm.dll
2009-09-04 09:22 –d–r– C:\UDC Output Files
2009-09-04 09:22 –d—– c:\program files\Universal Document Converter
2009-09-03 15:52 –d—– c:\program files\MSECache
2009-09-01 17:54 –d—– C:\mhnnzqvu.default
2009-08-27 22:36 722 a——- c:\windows\system32\BDUpdateV1.xml
2009-08-27 17:58 81,984 a——- c:\windows\system32\bdod.bin
2009-08-27 17:27 850 a——- c:\windows\system32\ProductTweaks.xml
2009-08-27 17:27 385 a——- c:\windows\system32\user_gensett.xml
2009-08-27 17:27 23,392 a——- c:\windows\system32\nscompat.tlb
2009-08-27 17:27 16,832 a——- c:\windows\system32\amcompat.tlb
2009-08-27 17:23 –d—– c:\docume~1\chrisb~1\applic~1\BitDefender
2009-08-27 17:23 –d—– c:\program files\BitDefender
2009-08-27 17:23 –d—– c:\docume~1\alluse~1\applic~1\BitDefender
2009-08-27 17:22 –d—– c:\program files\common files\BitDefender
2009-08-27 10:36 18,816 a——- c:\windows\system32\drivers\pccsmcfd.sys
2009-08-27 10:33 –d—– c:\docume~1\chrisb~1\applic~1\HouseCall 6.6
2009-08-27 10:30 27,784 a——- c:\windows\system32\drivers\point32.sys
2009-08-27 10:29 –d—– c:\program files\Microsoft IntelliPoint
2009-08-26 23:51 54,156 a—h— c:\windows\QTFont.qfn
2009-08-26 23:51 1,409 a——- c:\windows\QTFont.for
2009-08-26 23:49 4,463,988 a——- c:\windows\setupapi.log.4.old
2009-08-26 08:45 3,587,641 a——- c:\windows\setupapi.log.1.old
2009-08-23 22:42 –d—– c:\program files\Free-Buttons.org
2009-08-23 21:25 -cd-h— c:\docume~1\alluse~1\applic~1\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-08-23 20:58 8,320 a——- c:\windows\system32\drivers\nmwcdnsuc.sys
2009-08-23 20:58 136,704 a——- c:\windows\system32\drivers\nmwcdnsu.sys
2009-08-23 20:58 7,808 a——- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-08-23 20:58 22,016 a——- c:\windows\system32\drivers\ccdcmbo.sys
2009-08-23 20:58 7,808 a——- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-08-23 20:58 1,112,288 a——- c:\windows\system32\wdfcoinstaller01007.dll
2009-08-23 20:58 659,968 a——- c:\windows\system32\nmwcdcocls.dll
2009-08-23 20:58 17,664 a——- c:\windows\system32\drivers\ccdcmb.sys
2009-08-23 17:42 –d—– c:\documents and settings\chris burke\ErrorLogs
2009-08-20 22:58 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-19 18:08 299,008 a——- c:\windows\system32\Msdbrptr.dll
2009-08-19 18:08 203,576 a——- c:\windows\system32\Richtx32.ocx
2009-08-19 18:08 102,912 a——- c:\windows\system32\Vb6stkit.dll
2009-08-19 18:08 166,200 a——- c:\windows\system32\Msmask32.ocx
2009-08-19 18:08 –d—– c:\program files\TWC
2009-08-19 18:07 –d—– c:\program files\RKET
2009-08-19 18:05 –d—– c:\program files\FileNet
2009-08-19 18:04 –d—– C:\ProgramData
2009-08-19 18:04 –d—– C:\Informed
2009-08-17 11:57 –d—– c:\docume~1\alluse~1\applic~1\ALM
2009-08-17 11:56 –d—– c:\program files\Bonjour
2009-08-17 11:44 –d—– c:\program files\common files\Macrovision Shared
2009-08-16 09:08 69,075,917 a——- c:\windows\setupapi.log.0.old
2009-08-08 11:19 18,261,833 a——- c:\windows\setupapi.log.3.old
2009-08-08 10:37 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat
==================== Find3M ====================
2009-09-03 15:53 90,224 ac—— c:\docume~1\chrisb~1\applic~1\GDIPFONTCACHEV1.DAT
2009-08-27 17:57 146,312 a——- c:\windows\system32\drivers\bdfm.sys
2009-08-05 19:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-25 05:23 411,368 ac—— c:\windows\system32\deploytk.dll
2009-07-18 05:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-04 03:09 915,456 a——- c:\windows\system32\wininet.dll
2009-06-25 18:25 730,112 a——- c:\windows\system32\lsasrv.dll
2009-06-25 18:25 301,568 a——- c:\windows\system32\kerberos.dll
2009-06-25 18:25 147,456 a——- c:\windows\system32\schannel.dll
2009-06-25 18:25 136,192 a——- c:\windows\system32\msv1_0.dll
2009-06-25 18:25 56,832 a——- c:\windows\system32\secur32.dll
2009-06-25 18:25 54,272 a——- c:\windows\system32\wdigest.dll
2009-06-17 00:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-17 00:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-12 22:31 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 22:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-11 00:13 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 16:14 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll
2008-04-15 08:46 32 ac—— c:\docume~1\alluse~1\applic~1\ezsid.dat
2006-08-30 11:15 154,412,622 a——- c:\documents and settings\chris burke\PC Games - The Sims 2 (Full Version).zip
============= FINISH: 16:40:51.26 ===============