This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Win:Small-NAD [Trj]

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys,


A few days ago I had an error code 731 (0,6) from MBAM whilst running a scan.
The scan found 50 infections to my surprise, then before I could react my system crashed to a BSOD.

The message on screen read as follows:
Disable or uninstall any AV, disk defrag or back utils, check HD config, check for any updated drivers.
Run chkdsk /f to check for HD corruption.
Stop: 0x00000024 (0x 0019 0292, 0x A8CC 69B8, 0x A8CC 66B4, 0x 804E E88C)

After allowing the system to dump the memory to disk and reboot,
I then run MBAM again, this time it found nothing and showed no errors.

So, I run a full scan using avast, it returned a warning that "A Trojan Horse Was Found"
File name: C\WINDOWS\MEMORY.DMP
Malware name: Win32:Small-NAD [Trj]
VPS version: 1001 22-0,01/22/2010 (This version is from today, new scan.)

Recommended action: Move to chest

My issue with moving to the chest is that when I attempt to, I receive a message from avast "There is not enough space on the disk"

Should I just navigate to the C\WINDOWS\MEMORY.DMP and delete
Then remove all restore points and start over.?

FYI: I also run ESET Online scanner and it didn't find anything.

So false positive or does the memory.dmp contain something ? :(

Thank you,

Jkc73 :notworthy:
Hello Jkc73, Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I will post back shortly with instructions.

I will do my best to keep it as short as possible.

Thanks inzanity :)

My thoughts about this are that it is something to do with the COMODO Anti-SPAM program that I have been trialing of recent.

I have disabled almost everything except the avast AV on start up to find out what causes the BSOD.

Since this I am yet to experience another BSOD.

I did forget to mention that there was another Critical Stop after I attempted my 1st ESET scan.
The details are below:
STOP: 0x 0000 008E (0x 0000 0005, 0xBA6E AA66, 0x A8AB CB0C, 0x 0000 0000 )
sr.sys .Address BA6E AA66 base at BA6E 7000, DATE STAMP 48 02 52 C2
If these details above are any help then you will have to tell me how, cause I could not find any relative info, especially with putting it together. :wacko:

Thanks again, :wavey:

Jkc73


PS: Unfortunate if the cause is a clash of malware programs, and how unfortunate that I find it in the pursuit of justice. ( Regarding PM from Jan 14 2010 )
Hi, :)

Stop: 0x00000024 refers to the NTFS file system when an error occurs in that area.
Source: http://support.microsoft.com/kb/228888

My issue with moving to the chest is that when I attempt to, I receive a message from avast "There is not enough space on the disk"

That may be because it is too big to fit in Avast's chest. It can be created when a BSOD occurs. It is used to debug the problem.
Source:
http://www.gthelp.com/showthread.php?t=73410
http://social.answers.microsoft.com/Forums…c5-95b8c8d5d6a9

Let's do some scans. :)

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on to insert the attachment into your post
Please post both DDS logs in your next reply.

–Next–

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop
To post in your next reply:
1. DDS logs.
2. GMER log.
Hi, inzanity

Stop: 0x00000024 refers to the NTFS file system when an error occurs in that area.
Source: http://support.microsoft.com/kb/228888

The message below displays when I visit the above link.

This article applies to a different version of Windows than the one you are using. Content in this article may not be relevant to you.
Visit the Windows XP Solution Center

Error message in Windows 2000: "Stop 0x24" or "NTFS_FILE_SYSTEM"
Does this message also apply to my system, if so why does Microsoft display this message? :huh:


That may be because it is too big to fit in Avast's chest. It can be created when a BSOD occurs. It is used to debug the problem.
Source:
http://www.gthelp.com/showthread.php?t=73410
http://social.answers.microsoft.com/Forums…c5-95b8c8d5d6a9

From these links above I understand that it is OK to delete the file C\WINDOWS\MEMORY.DMP, so I run Ccleaner by Piriform to delete the file C\WINDOWS\MEMORY.DMP .


I downloaded DDS.scr though I had some trouble with running it.
I disabled all programs, though as I clicked on DDS icon to run the tool it displayed the following dialog box for less than 1 second, I waited for approx. 5-6 minutes for result, with no attach.txt or report of any kind.
📎DDS.JPG



Below are the results of an Avast scan showing 0 infections, MBAM quick scan showing 0 infections.
Avast reports some corruption.
GMER did not report any Rootkits.

* Task 'Simple user interface' used
* Started on Saturday, January 23, 2010 10:58:27 PM
* VPS: 100123-0, 01/23/2010
*

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\LocalService\NTUSER.DAT [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\LocalService\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\NetworkService\NTUSER.DAT [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\NetworkService\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\parent.lock [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\{4fc6c8cf-5940-489b-8e66-8246d5c01f64}\DBStore\contacts.edb [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\{4fc6c8cf-5940-489b-8e66-8246d5c01f64}\DBStore\LogFiles\edb.log [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\{4fc6c8cf-5940-489b-8e66-8246d5c01f64}\DBStore\tempedb.edb [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\{bb9885c7-176c-43b6-9831-072f661c6763}\DBStore\contacts.edb [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\{bb9885c7-176c-43b6-9831-072f661c6763}\DBStore\LogFiles\edb.log [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\{bb9885c7-176c-43b6-9831-072f661c6763}\DBStore\tempedb.edb [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Mail\Calendars\**************.com\DBStore\LogFiles\edb.log [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Mail\Calendars\**************.com\DBStore\tempedb.edb [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Mail\Calendars\**************.com\DBStore\WLCalendarStore.edb [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Mail\edb.log [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Mail\Mail.MSMessageStore [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Mail\tmp.edb [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\ntuser.dat [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\pagefile.sys [E] The process cannot access the file because it is being used by another process (32)
C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\test\testtar.tar\ [E] TAR archive is corrupted. (42128)
C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\test\testtar.tar\ [E] TAR archive is corrupted. (42128)
C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\test\testtar.tar\ [E] TAR archive is corrupted. (42128)
C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\test\testtar.tar\30 atime=1041808783.000000000
30 ctime=1041808783.000000000
30 mtime=1041808783.000000000
11 uid=123 [E] TAR archive is corrupted. (42128)

C:\WINDOWS\system32\config\default [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\default.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\SAM [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\SAM.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\SECURITY [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\SECURITY.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\software [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\software.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\system [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\system.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\Temp\Perflib_Perfdata_598.dat [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\Temp\_avast4_\Webshlock.txt [E] The process cannot access the file because it is being used by another process (32)
D:\pagefile.sys [E] The process cannot access the file because it is being used by another process (32)
Infected files: 0
Total files: 218819
Total folders: 7242
Total size: 38.0 GB

*
* Task stopped: Saturday, January 23, 2010 11:50:00 PM
* Run-time was 51 minute(s), 33 second(s)
*



Malwarebytes' Anti-Malware 1.44
Database version: 3620
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/24/2010 1:57:00 AM
mbam-log-2010-01-24 (01-57-00).txt

Scan type: Quick Scan
Objects scanned: 108339
Time elapsed: 3 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2010-01-24 14:27:39
Windows 5.1.2600 Service Pack 3
Running: 2j7vxcyy.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\uxddqpog.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA9CC06B8]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwCreateKey [0xBA6D482E]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwDeleteKey [0xBA6D553A]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwDeleteValueKey [0xBA6D4F4E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA9CC014C]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwOpenKey [0xBA6D4ACC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA9CC008C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA9CC00F0]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwQueryValueKey [0xBA6D4D52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA9CC072E]
SSDT cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) ZwSetValueKey [0xBA6D52CA]

Code 89695BAC ZwRequestPort
Code 89695C4C ZwRequestWaitReplyPort
Code 89695B0C ZwTraceEvent
Code 89695BAB NtRequestPort
Code 89695C4B NtRequestWaitReplyPort
Code 89695B0B NtTraceEvent

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!NtTraceEvent 80531838 5 Bytes JMP 89695B10
PAGE ntkrnlpa.exe!NtRequestPort 80597DE2 5 Bytes JMP 89695BB0
PAGE ntkrnlpa.exe!NtRequestWaitReplyPort 8059810E 5 Bytes JMP 89695C50
.text win32k.sys!EngAcquireSemaphore + 20E2 BF8082E1 5 Bytes JMP 896954D0
.text win32k.sys!EngFreeUserMem + 5BD2 BF80EE68 5 Bytes JMP 89695430
.text win32k.sys!BRUSHOBJ_pvAllocRbrush + 322E BF81E77A 5 Bytes JMP 896959D0
.text win32k.sys!EngSetLastError + 768F BF8286CB 5 Bytes JMP 89695610
.text win32k.sys!EngCreateBitmap + DDB2 BF845CCB 5 Bytes JMP 896956B0
.text win32k.sys!EngMultiByteToWideChar + 2F32 BF852C47 5 Bytes JMP 89695890
.text win32k.sys!XLATEOBJ_iXlate + 3A50 BF86368D 5 Bytes JMP 89695570
.text win32k.sys!FONTOBJ_pxoGetXform + CC3E BF8C31D6 5 Bytes JMP 89695750
.text win32k.sys!PATHOBJ_vGetBounds + 74EE BF8F00FB 5 Bytes JMP 89695930
.text win32k.sys!EngCreateClip + 19C1 BF91313E 3 Bytes JMP 89695A70
.text win32k.sys!EngCreateClip + 19C5 BF913142 1 Byte [C9]
.text win32k.sys!EngCreateClip + 2597 BF913D14 5 Bytes JMP 896957F0

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\system32\services.exe[680] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[680] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [006A4F70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleHandleA] [006A4FC0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleHandleA] [006A4FC0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetModuleHandleA] [006A4FC0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [006A4F70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleHandleA] [006A4FC0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [006A4F70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleHandleA] [006A4FC0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [006A4F70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [006A4F20] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [006A4AD0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [006A46D0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [006A4B60] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!RegisterClassW] [006A4CD0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [006A4710] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DrawFrameControl] [006A4E10] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DrawEdge] [006A3E90] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SystemParametersInfoW] [006A4D30] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetScrollInfo] [006A4920] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!CallWindowProcW] [006A4990] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetScrollInfo] [006A47F0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleA] [006A4FC0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [006A4F20] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [006A4F70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [006A4AD0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [006A4B60] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [006A46D0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!RegisterClassA] [006A4C70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!RegisterClassW] [006A4CD0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SystemParametersInfoW] [006A4D30] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcW] [006A4990] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcA] [006A4A30] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [006A4F70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [006A4F20] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SystemParametersInfoW] [006A4D30] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetSysColor] [006A46D0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CallWindowProcW] [006A4990] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!RegisterClassW] [006A4CD0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DefWindowProcW] [006A4B60] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\IPHLPAPI.DLL [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\IPHLPAPI.DLL [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [006A4EE0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CreateThread] [006A4BF0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetModuleHandleA] [006A4FC0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [006A4F70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [006A5050] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [006A4E70] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!DefWindowProcA] [006A4AD0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)
IAT C:\Program Files\Comodo\AntiSpam\CAS32.exe[2976] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!RegisterClassW] [006A4CD0] C:\Program Files\Comodo\AntiSpam\CasInit.dll (Comodo Initialization DLL/C.O.M.O.D.O.)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat cfrmd.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

—- EOF - GMER 1.0.15 —-






Thanks :)
Jkc73
additional info:

Avast scan finds Win32:Zbot-AVH Overview here

Please refer to Replies (especially#6 on: April 10, 2009, 12:18:49 AM) @ Avast

*
* avast! Report
* This file is generated automatically
*
* Task 'Simple user interface' used
* Started on Monday, January 25, 2010 8:43:01 PM
* VPS: 100124-1, 01/24/2010
*

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\LocalService\NTUSER.DAT [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\LocalService\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\NetworkService\NTUSER.DAT [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\NetworkService\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\ntuser.dat [E] The process cannot access the file because it is being used by another process (32)
C:\Documents and Settings\Owner\ntuser.dat.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\pagefile.sys [E] The process cannot access the file because it is being used by another process (32)
C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\test\testtar.tar\ [E] TAR archive is corrupted. (42128)
C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\test\testtar.tar\ [E] TAR archive is corrupted. (42128)
C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\test\testtar.tar\ [E] TAR archive is corrupted. (42128)
C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\test\testtar.tar\30 atime=1041808783.000000000
30 ctime=1041808783.000000000
30 mtime=1041808783.000000000
11 uid=123 [E] TAR archive is corrupted. (42128)
C:\WINDOWS\system32\config\default [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\default.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\SAM [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\SAM.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\SECURITY [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\SECURITY.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\software [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\software.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\system [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\system32\config\system.LOG [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\Temp\Perflib_Perfdata_598.dat [E] The process cannot access the file because it is being used by another process (32)
C:\WINDOWS\Temp\_avast4_\Webshlock.txt [E] The process cannot access the file because it is being used by another process (32)
D:\pagefile.sys [L] Win32:Zbot-AVH [Trj] (0)
While moving file to chest, error occurred: There is not enough space on the disk
File was successfully deleted…
Infected files: 1

Total files: 244779
Total folders: 7248
Total size: 44.6 GB

*
* Task stopped: Monday, January 25, 2010 9:36:37 PM
* Run-time was 53 minute(s), 36 second(s)
*


Results for scan of drive/partition D: after turning off system restore on drive/partition D: and the deletion of D:\pagefile.sys [L] Win32:Zbot-AVH [Trj]

*
* avast! Report
* This file is generated automatically
*
* Task 'Simple user interface' used
* Started on Monday, January 25, 2010 11:07:08 PM
* VPS: 100124-1, 01/24/2010
*

Infected files: 0
Total files: 61
Total folders: 6
Total size: 888.0 MB

*
* Task stopped: Monday, January 25, 2010 11:07:48 PM
* Run-time was 40 second(s)
*

*
* avast! Report
* This file is generated automatically
*
* Task 'Simple user interface' used
* Started on Tuesday, January 26, 2010 2:00:48 PM
* VPS: 100125-2, 01/25/2010
*

Infected files: 0
Total files: 61
Total folders: 6
Total size: 888.0 MB

*
* Task stopped: Tuesday, January 26, 2010 2:01:39 PM
* Run-time was 51 second(s)
*


latest mbam log~

Malwarebytes' Anti-Malware 1.44
Database version: 3632
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/26/2010 2:40:17 PM
mbam-log-2010-01-26 (14-40-17).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 158453
Time elapsed: 25 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Thanks again,
Jkc73 :)
Additional info:

Avast intercepted the following after I processed the mail in Mailwasher Free, this was not appearing in the list.
So Mailwasher may have just checked my mailbox after it opened my email program.


File Name: Incoming email 'UPS Delivery Problem NR 65207. From UPS Support "blah blah blah"<[removed]>, To: <[removed]>:)> I have the rest of these details if you require.
Malware Name: Win32:Zbot-MOY[Trj]
Recommended Action: Delete
Note: if you press the "No Action" button, the message will be delivered to your mailbox, including the dangerous content!


After dealing with this Trojan, I ran the following from normal boot and from safe boot, avast full scan finds nothing( remembering that avast has its own rootkit search ), followed by MBAM that also found nothing.

Though after rebooting up after being in safe mode the avast warning appeared again, Win32:Zbot-MOY[Trj] so I deleted it again. I am puzzled, so I removed a few programs that I figured could possibly be harvesting such a thing.
They where COMODO's anti-spam along with everything COMODO to make sure, I also removed all programs that come with adware options that I had installed in the last month.


Thanks again,
Jkc73
Hi,

Does this message also apply to my system, if so why does Microsoft display this message?

Here is an article regarding the stop message in XP, it also pertains to the NTFS_FILE_SYSTEM.

From these links above I understand that it is OK to delete the file C\WINDOWS\MEMORY.DMP, so I run Ccleaner by Piriform to delete the file C\WINDOWS\MEMORY.DMP .

That is also my understanding, but to be sure, you try and rename the file to C\WINDOWS\MEMORY.DMP.vir then see how it goes.

Avast may have trouble opening some of Open Office's files, that may be the cause of as to why it is flagging Open Office as corrupt.

I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


  • Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text into the box under Custom Scan

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    /md5stop
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of the OTL.txt and post it with your next reply along with the OTL fix log.
Just a note: I have had problems with firefox.exe still running in the Task Manager after closing the browser.(CPU Usage runs at 100%)
Maybe a conflict between add-ons ? :scratch: I have not yet run it with no add-ons :blush: though for some reason I did completely lose No-Script the other day. :angry:
Had to reinstall it. :wacko:

And as I type this, Google is telling me this page is in Danish. Translate it using Google Toolbar? :wacko: Go figure… :huh:


OTL.Txt and Extras.Txt.

As follows~
OTL logfile created on: 1/27/2010 8:08:09 PM - Run 1
OTL by OldTimer - Version 3.1.27.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 61.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.71 Gb Total Space | 18.97 Gb Free Space | 35.99% Space Free | Partition Type: NTFS
Drive D: | 18.61 Gb Total Space | 17.68 Gb Free Space | 95.00% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BEDROOM
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (tzuk)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\FireTrust\MailWasher Free\MailWasher.exe (Firetrust Ltd)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (0266161264177044mcinstcleanup) McAfee Application Installer Cleanup (0266161264177044) – File not found
SRV - (gupdate) Google Update Service (gupdate) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (tzuk)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (tzuk)
DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (StarOpen) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (GEARAspiWDM) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (cercsr6) – C:\WINDOWS\system32\drivers\cercsr6.sys (Adaptec, Inc.)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - Reg Error: Value error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Search Powered by Google"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2384137&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 49
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.45
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems: {6614d11d-d21d-b211-ae23-815234e1ebb5}:1.0.21
FF - prefs.js..extensions.enabledItems: FasterFox_Lite@BigRedBrent:3.8.2Lite
FF - prefs.js..extensions.enabledItems: [removed]:2.0.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {29c4afe1-db19-4298-8785-fcc94d1d6c1d}:0.6.2009110501
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..extensions.enabledItems: [removed]:0.54
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..extensions.enabledItems: [removed]:3.4.6
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/16 04:12:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/26 22:06:56 | 00,000,000 | —D | M]

[2009/12/02 10:44:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/01/27 01:19:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions
[2010/01/12 13:00:03 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{27c60876-b5c9-4335-b4f3-52b26782220c}
[2010/01/03 00:29:11 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2009/12/03 18:25:35 | 00,000,000 | —D | M] (Dr.Web anti-virus link checker) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2010/01/27 01:19:26 | 00,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/01/21 20:43:38 | 00,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
[2010/01/16 04:23:31 | 00,000,000 | —D | M] (WOT) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/01/11 13:50:05 | 00,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/12/05 06:03:02 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010/01/01 12:25:49 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/01/12 13:00:02 | 00,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/12/03 20:49:55 | 00,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009/12/02 19:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\FasterFox_Lite@BigRedBrent
[2009/12/10 17:10:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\[removed]
[2009/12/05 23:08:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\[removed]
[2009/12/03 18:25:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\[removed]
[2009/12/02 14:38:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\extensions\[removed]
[2009/10/21 19:01:26 | 00,000,866 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\95a3oo0a.default\searchplugins\conduit.xml
[2010/01/27 01:19:34 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/01/03 14:16:57 | 00,002,024 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml

O1 HOSTS File: ([2009/12/08 08:06:45 | 00,614,865 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 ads.active.com
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 data2.activshopper.com #[Trackware.ActivShopper]
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 127.0.0.1 ads.ad2games.com
O1 - Hosts: 127.0.0.1 content.ad20.net
O1 - Hosts: 16153 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\MailWasherFree.lnk = C:\Program Files\FireTrust\MailWasher Free\MailWasher.exe (Firetrust Ltd)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = [binary data]
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_5F1A57F0B9B89E2E.dll (Google Inc.)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: secunia.com ([psi] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 34 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1259503907390 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1259504172593 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2009/11/29 20:28:10 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/11/30 07:25:20 | 00,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)

========== Files/Folders - Created Within 30 Days ==========

[2010/01/27 03:29:11 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Auslogics
[2010/01/27 03:29:02 | 00,000,000 | —D | C] – C:\Program Files\Auslogics
[2010/01/27 03:25:20 | 02,259,880 | —- | C] (Auslogics Software Pty Ltd ) – C:\Documents and Settings\Owner\Desktop\disk-defrag-setup.exe
[2010/01/27 03:16:43 | 00,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2010/01/26 17:35:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/01/26 17:35:28 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/01/26 17:35:08 | 00,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/01/26 17:35:08 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/01/26 17:35:08 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/01/25 09:34:00 | 04,179,293 | —- | C] (Lavalys, Inc. ) – C:\Documents and Settings\Owner\Desktop\everesthome220.exe
[2010/01/21 23:06:49 | 00,548,864 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/21 14:13:13 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Comodo
[2010/01/19 16:42:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Canneverbe_Limited
[2010/01/19 16:42:32 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/01/19 16:42:06 | 00,000,000 | —D | C] – C:\Program Files\CDBurnerXP
[2010/01/19 14:13:04 | 00,000,000 | —D | C] – C:\Program Files\CodeStuff
[2010/01/19 13:24:09 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidserv.dll
[2010/01/18 03:15:33 | 00,116,224 | —- | C] (Xerox) – C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2010/01/18 03:15:29 | 00,023,040 | —- | C] (Xerox Corporation) – C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2010/01/18 03:15:21 | 00,004,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2010/01/18 03:15:16 | 00,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2010/01/18 03:15:11 | 00,016,970 | —- | C] (US Robotics MCD (Megahertz)) – C:\WINDOWS\System32\dllcache\xem336n5.sys
[2010/01/18 03:15:10 | 00,019,455 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wvchntxx.sys
[2010/01/18 03:15:06 | 00,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wstcodec.sys
[2010/01/18 03:15:05 | 00,012,063 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wsiintxx.sys
[2010/01/18 03:15:03 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshirda.dll
[2010/01/18 03:14:44 | 00,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiacpi.sys
[2010/01/18 03:14:41 | 00,154,624 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\wlluc48.sys
[2010/01/18 03:14:37 | 00,034,890 | —- | C] (Raytheon Corp.) – C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2010/01/18 03:14:29 | 00,771,581 | —- | C] (Rockwell) – C:\WINDOWS\System32\dllcache\winacisa.sys
[2010/01/18 03:14:24 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2010/01/18 03:14:20 | 00,087,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2010/01/18 03:14:15 | 00,701,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\wdhaalba.sys
[2010/01/18 03:14:14 | 00,023,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wch7xxnt.sys
[2010/01/18 03:14:13 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2010/01/18 03:14:10 | 00,035,871 | —- | C] (Winbond Electronics Corp.) – C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2010/01/18 03:14:08 | 00,033,599 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv04nt.sys
[2010/01/18 03:14:06 | 00,019,551 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv02nt.sys
[2010/01/18 03:14:05 | 00,029,311 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv01nt.sys
[2010/01/18 03:14:04 | 00,011,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv05nt.sys
[2010/01/18 03:14:03 | 00,012,127 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv02nt.sys
[2010/01/18 03:14:02 | 00,012,415 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv01nt.sys
[2010/01/18 03:13:58 | 00,016,925 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w940nd.sys
[2010/01/18 03:13:55 | 00,019,016 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w926nd.sys
[2010/01/18 03:13:51 | 00,019,528 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w840nd.sys
[2010/01/18 03:13:44 | 00,064,605 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vvoice.sys
[2010/01/18 03:13:41 | 00,397,502 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vpctcom.sys
[2010/01/18 03:13:36 | 00,604,253 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\vmodem.sys
[2010/01/18 03:13:32 | 00,249,402 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\vinwm.sys
[2010/01/18 03:13:28 | 00,024,576 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\viairda.sys
[2010/01/18 03:13:27 | 00,005,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\viaide.sys
[2010/01/18 03:13:25 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2010/01/18 03:13:20 | 00,687,999 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2010/01/18 03:13:16 | 00,765,884 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usrti.sys
[2010/01/18 03:13:13 | 00,113,762 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrpda.sys
[2010/01/18 03:13:09 | 00,007,556 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usroslba.sys
[2010/01/18 03:13:06 | 00,224,802 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usr1807a.sys
[2010/01/18 03:13:02 | 00,794,399 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806v.sys
[2010/01/18 03:12:59 | 00,793,598 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806.sys
[2010/01/18 03:12:56 | 00,794,654 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1801.sys
[2010/01/18 03:12:54 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbser.sys
[2010/01/18 03:12:53 | 00,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2010/01/18 03:12:52 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2010/01/18 03:12:51 | 00,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbohci.sys
[2010/01/18 03:12:49 | 00,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2010/01/18 03:12:48 | 00,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/01/18 03:12:47 | 00,032,384 | —- | C] (KLSI USA, Inc.) – C:\WINDOWS\System32\dllcache\usb101et.sys
[2010/01/18 03:12:41 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxud32.dll
[2010/01/18 03:12:38 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu40.dll
[2010/01/18 03:12:35 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu22.dll
[2010/01/18 03:12:32 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu12.dll
[2010/01/18 03:12:28 | 00,050,688 | —- | C] (UMAX DATA SYSTEMS INC.) – C:\WINDOWS\System32\dllcache\umaxscan.dll
[2010/01/18 03:12:25 | 00,022,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2010/01/18 03:12:22 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxp60.dll
[2010/01/18 03:12:19 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxcam.dll
[2010/01/18 03:12:16 | 00,211,968 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um54scan.dll
[2010/01/18 03:12:12 | 00,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2010/01/18 03:12:09 | 00,036,736 | —- | C] (Promise Technology, Inc.) – C:\WINDOWS\System32\dllcache\ultra.sys
[2010/01/18 03:12:05 | 00,011,520 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\twotrack.sys
[2010/01/18 03:12:00 | 00,166,784 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxpm.sys
[2010/01/18 03:11:56 | 00,525,568 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxp.dll
[2010/01/18 03:11:53 | 00,159,232 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkbm.sys
[2010/01/18 03:11:50 | 00,440,576 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkb.dll
[2010/01/18 03:11:47 | 00,222,336 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3dm.sys
[2010/01/18 03:11:44 | 00,315,520 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3d.dll
[2010/01/18 03:11:40 | 00,034,375 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\tpro4.sys
[2010/01/18 03:11:37 | 00,042,496 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4res.dll
[2010/01/18 03:11:36 | 00,082,944 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4mon.exe
[2010/01/18 03:11:33 | 00,031,744 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4.dll
[2010/01/18 03:11:29 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\toside.sys
[2010/01/18 03:11:25 | 00,230,912 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd03.sys
[2010/01/18 03:11:22 | 00,241,664 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd02.sys
[2010/01/18 03:11:19 | 00,028,232 | —- | C] (TOSHIBA Corporation) – C:\WINDOWS\System32\dllcache\tos4mo.sys
[2010/01/18 03:11:15 | 00,123,995 | —- | C] (Tiger Jet Network) – C:\WINDOWS\System32\dllcache\tjisdn.sys
[2010/01/18 03:11:09 | 00,138,528 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2010/01/18 03:11:06 | 00,081,408 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiul50.dll
[2010/01/18 03:11:05 | 00,149,376 | —- | C] (M-Systems) – C:\WINDOWS\System32\dllcache\tffsport.sys
[2010/01/18 03:11:00 | 00,017,129 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2010/01/18 03:10:57 | 00,037,961 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdk100b.sys
[2010/01/18 03:10:50 | 00,030,464 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tbatm155.sys
[2010/01/18 03:10:46 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tandqic.sys
[2010/01/18 03:10:42 | 00,036,640 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2010/01/18 03:10:39 | 00,172,768 | —- | C] (Number Nine Visual Technology) – C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2010/01/18 03:10:34 | 00,032,640 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\symc8xx.sys
[2010/01/18 03:10:31 | 00,016,256 | —- | C] (Symbios Logic Inc.) – C:\WINDOWS\System32\dllcache\symc810.sys
[2010/01/18 03:10:28 | 00,030,688 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\sym_u3.sys
[2010/01/18 03:10:25 | 00,028,384 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\sym_hi.sys
[2010/01/18 03:10:22 | 00,094,293 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sxports.dll
[2010/01/18 03:10:19 | 00,103,936 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sx.sys
[2010/01/18 03:10:16 | 00,003,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swusbflt.sys
[2010/01/18 03:10:13 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpidflt.dll
[2010/01/18 03:10:11 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2010/01/18 03:10:08 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2010/01/18 03:10:05 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_effct.dll
[2010/01/18 03:10:04 | 00,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\streamip.sys
[2010/01/18 03:10:00 | 00,155,648 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnprop.dll
[2010/01/18 03:09:58 | 00,053,248 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlncoin.dll
[2010/01/18 03:09:54 | 00,285,760 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnata.sys
[2010/01/18 03:09:51 | 00,016,896 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\stcusb.sys
[2010/01/18 03:09:46 | 00,048,736 | —- | C] (3Com) – C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2010/01/18 03:09:43 | 00,099,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusd.dll
[2010/01/18 03:09:38 | 00,024,660 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spxupchk.dll
[2010/01/18 03:09:34 | 00,061,824 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\speed.sys
[2010/01/18 03:09:31 | 00,106,584 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spdports.dll
[2010/01/18 03:09:28 | 00,019,072 | —- | C] (Adaptec, Inc.) – C:\WINDOWS\System32\dllcache\sparrow.sys
[2010/01/18 03:09:25 | 00,007,552 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2010/01/18 03:09:22 | 00,037,040 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.sys
[2010/01/18 03:09:19 | 00,114,688 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.dll
[2010/01/18 03:09:15 | 00,020,752 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonync.sys
[2010/01/18 03:09:12 | 00,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonymc.sys
[2010/01/18 03:09:11 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonyait.sys
[2010/01/18 03:09:07 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2010/01/18 03:09:00 | 00,058,368 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smiminib.sys
[2010/01/18 03:08:57 | 00,147,200 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smidispb.dll
[2010/01/18 03:08:53 | 00,025,034 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2010/01/18 03:08:50 | 00,035,913 | —- | C] (SMC) – C:\WINDOWS\System32\dllcache\smcirda.sys
[2010/01/18 03:08:47 | 00,024,576 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smc8000n.sys
[2010/01/18 03:08:44 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbhc.sys
[2010/01/18 03:08:43 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbclass.sys
[2010/01/18 03:08:42 | 00,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbbatt.sys
[2010/01/18 03:08:38 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb3w.dll
[2010/01/18 03:08:35 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb0w.dll
[2010/01/18 03:08:32 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma0w.dll
[2010/01/18 03:08:28 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm91w.dll
[2010/01/18 03:08:24 | 00,011,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\slip.sys
[2010/01/18 03:08:23 | 00,063,547 | —- | C] (Symbol Technologies) – C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2010/01/18 03:08:20 | 00,091,294 | —- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) – C:\WINDOWS\System32\dllcache\skfpwin.sys
[2010/01/18 03:08:17 | 00,094,698 | —- | C] (SysKonnect GmbH.) – C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2010/01/18 03:08:14 | 00,157,696 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv256.dll
[2010/01/18 03:08:11 | 00,050,432 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv.sys
[2010/01/18 03:08:10 | 00,032,768 | —- | C] (SiS Corporation) – C:\WINDOWS\System32\dllcache\sisnic.sys
[2010/01/18 03:08:08 | 00,238,592 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrv.dll
[2010/01/18 03:08:05 | 00,104,064 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrp.sys
[2010/01/18 03:08:02 | 00,150,144 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306v.dll
[2010/01/18 03:07:59 | 00,068,608 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306p.sys
[2010/01/18 03:07:56 | 00,252,032 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300iv.dll
[2010/01/18 03:07:53 | 00,101,760 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300ip.sys
[2010/01/18 03:07:45 | 00,161,568 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2010/01/18 03:07:42 | 00,018,400 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmld.sys
[2010/01/18 03:07:39 | 00,098,080 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2010/01/18 03:07:37 | 00,386,560 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiul50.dll
[2010/01/18 03:07:34 | 00,036,480 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\sfmanm.sys
[2010/01/18 03:07:29 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2010/01/18 03:07:26 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2010/01/18 03:07:19 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2010/01/18 03:07:18 | 00,011,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiscan.sys
[2010/01/18 03:07:15 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2010/01/18 03:07:11 | 00,017,280 | —- | C] (SCM Microsystems) – C:\WINDOWS\System32\dllcache\scr111.sys
[2010/01/18 03:07:08 | 00,016,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scmstcs.sys
[2010/01/18 03:07:05 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2010/01/18 03:07:02 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2010/01/18 03:07:00 | 00,043,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sbp2port.sys
[2010/01/18 03:06:58 | 00,495,616 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\sblfx.dll
[2010/01/18 03:06:53 | 00,075,392 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmxm.sys
[2010/01/18 03:06:50 | 00,245,632 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmx.dll
[2010/01/18 03:06:47 | 00,077,824 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2010/01/18 03:06:44 | 00,198,400 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4.dll
[2010/01/18 03:06:42 | 00,061,504 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2010/01/18 03:06:39 | 00,179,264 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2010/01/18 03:06:36 | 00,210,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2010/01/18 03:06:33 | 00,062,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2010/01/18 03:06:30 | 00,041,216 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2010/01/18 03:06:28 | 00,182,272 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2010/01/18 03:06:25 | 00,166,720 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3m.sys
[2010/01/18 03:06:22 | 00,065,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.sys
[2010/01/18 03:06:18 | 00,082,432 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia450.dll
[2010/01/18 03:06:15 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia430.dll
[2010/01/18 03:06:14 | 00,029,696 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw450ext.dll
[2010/01/18 03:06:13 | 00,027,648 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw430ext.dll
[2010/01/18 03:06:10 | 00,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8139.sys
[2010/01/18 03:06:07 | 00,019,017 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8029.sys
[2010/01/18 03:06:04 | 00,030,720 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rthwcls.sys
[2010/01/18 03:06:00 | 00,009,216 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2010/01/18 03:05:57 | 00,003,840 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rpfun.sys
[2010/01/18 03:05:54 | 00,079,104 | —- | C] (Comtrol Corporation) – C:\WINDOWS\System32\dllcache\rocket.sys
[2010/01/18 03:05:51 | 00,037,563 | —- | C] (RadioLAN) – C:\WINDOWS\System32\dllcache\rlnet5.sys
[2010/01/18 03:05:47 | 00,086,097 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\reslog32.dll
[2010/01/18 03:05:40 | 00,019,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasirda.sys
[2010/01/18 03:05:36 | 00,714,762 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2010/01/18 03:05:33 | 00,899,146 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2010/01/18 03:05:30 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qvusd.dll
[2010/01/18 03:05:28 | 00,003,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qv2kux.sys
[2010/01/18 03:05:22 | 00,049,024 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql1280.sys
[2010/01/18 03:05:19 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql1240.sys
[2010/01/18 03:05:17 | 00,045,312 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql12160.sys
[2010/01/18 03:05:14 | 00,033,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql10wnt.sys
[2010/01/18 03:05:11 | 00,040,320 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql1080.sys
[2010/01/18 03:05:10 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qic157.sys
[2010/01/18 03:05:07 | 00,130,942 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlv.sys
[2010/01/18 03:05:04 | 00,112,574 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlp.sys
[2010/01/18 03:05:01 | 00,128,286 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserli.sys
[2010/01/18 03:05:00 | 00,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusd.dll
[2010/01/18 03:04:57 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusb.dll
[2010/01/18 03:04:53 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\psisload.dll
[2010/01/18 03:04:49 | 00,016,128 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\pscr.sys
[2010/01/18 03:04:43 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa3.sys
[2010/01/18 03:04:40 | 00,017,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa.sys
[2010/01/18 03:04:39 | 00,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\powerfil.sys
[2010/01/18 03:04:35 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pnrmc.sys
[2010/01/18 03:04:27 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phvfwext.dll
[2010/01/18 03:04:24 | 00,019,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philtune.sys
[2010/01/18 03:04:21 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phildec.sys
[2010/01/18 03:04:18 | 00,173,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam2.sys
[2010/01/18 03:04:15 | 00,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.sys
[2010/01/18 03:04:13 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.dll
[2010/01/18 03:04:10 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phdsext.ax
[2010/01/18 03:04:09 | 00,259,328 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3dd.dll
[2010/01/18 03:04:08 | 00,028,032 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3.sys
[2010/01/18 03:04:07 | 00,211,584 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2dll.dll
[2010/01/18 03:04:06 | 00,027,904 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2.sys
[2010/01/18 03:04:03 | 00,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2hib.sys
[2010/01/18 03:04:01 | 00,027,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2.sys
[2010/01/18 03:03:59 | 00,169,984 | —- | C] (Cisco Systems) – C:\WINDOWS\System32\dllcache\pcx500.sys
[2010/01/18 03:03:57 | 00,086,016 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\pctspk.exe
[2010/01/18 03:03:54 | 00,035,328 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2010/01/18 03:03:51 | 00,029,769 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2010/01/18 03:03:49 | 00,030,282 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2010/01/18 03:03:46 | 00,026,153 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2010/01/18 03:03:44 | 00,029,502 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\pca200e.sys
[2010/01/18 03:03:42 | 00,030,495 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pc100nds.sys
[2010/01/18 03:03:37 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2rc.dll
[2010/01/18 03:03:34 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2.dll
[2010/01/18 03:03:32 | 00,025,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovsound2.sys
[2010/01/18 03:03:29 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcoms.exe
[2010/01/18 03:03:27 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcomc.dll
[2010/01/18 03:03:24 | 00,351,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodek2.sys
[2010/01/18 03:03:21 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodec2.dll
[2010/01/18 03:03:19 | 00,031,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovce.sys
[2010/01/18 03:03:16 | 00,028,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcd.sys
[2010/01/18 03:03:13 | 00,048,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcam2.sys
[2010/01/18 03:03:11 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovca.sys
[2010/01/18 03:03:08 | 00,054,186 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otcsercb.sys
[2010/01/18 03:03:05 | 00,043,689 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otceth5.sys
[2010/01/18 03:03:03 | 00,027,209 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otc06x5.sys
[2010/01/18 03:02:59 | 00,054,528 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\opl3sax.sys
[2010/01/18 03:02:57 | 00,061,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ohci1394.sys
[2010/01/18 03:02:50 | 00,198,144 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.sys
[2010/01/18 03:02:48 | 00,123,776 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.dll
[2010/01/18 03:02:39 | 00,051,552 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\dllcache\ntgrip.sys
[2010/01/18 03:02:35 | 00,009,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntapm.sys
[2010/01/18 03:02:32 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsmmc.sys
[2010/01/18 03:02:31 | 00,028,672 | —- | C] (National Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\nscirda.sys
[2010/01/18 03:02:27 | 00,087,040 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2010/01/18 03:02:24 | 00,126,080 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2010/01/18 03:02:20 | 00,032,840 | —- | C] (NETGEAR Corporation.) – C:\WINDOWS\System32\dllcache\ngrpci.sys
[2010/01/18 03:02:19 | 00,132,695 | —- | C] (802.11b) – C:\WINDOWS\System32\dllcache\netwlan5.sys
[2010/01/18 03:02:14 | 00,065,278 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\netflx3.sys
[2010/01/18 03:02:11 | 00,039,264 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.sys
[2010/01/18 03:02:08 | 00,060,480 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.dll
[2010/01/18 03:02:05 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ne2000.sys
[2010/01/18 03:02:05 | 00,010,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndisip.sys
[2010/01/18 03:02:03 | 00,085,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nabtsfec.sys
[2010/01/18 03:02:00 | 00,091,488 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2010/01/18 03:01:58 | 00,027,936 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3d.sys
[2010/01/18 03:01:55 | 00,033,088 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2010/01/18 03:01:53 | 00,059,104 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2010/01/18 03:01:50 | 00,013,664 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.sys
[2010/01/18 03:01:48 | 00,035,392 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.dll
[2010/01/18 03:01:45 | 00,128,000 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n100325.sys
[2010/01/18 03:01:43 | 00,052,255 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2010/01/18 03:01:40 | 00,075,520 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxport.sys
[2010/01/18 03:01:38 | 00,007,168 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxport.dll
[2010/01/18 03:01:35 | 00,019,968 | —- | C] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\dllcache\mxnic.sys
[2010/01/18 03:01:32 | 00,019,968 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxicfg.dll
[2010/01/18 03:01:30 | 00,021,888 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxcard.sys
[2010/01/18 03:01:26 | 00,103,296 | —- | C] (Matrox Graphics Inc) – C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2010/01/18 03:01:19 | 00,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstee.sys
[2010/01/18 03:01:18 | 00,049,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstape.sys
[2010/01/18 03:01:14 | 00,012,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msriffwv.sys
[2010/01/18 03:01:08 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msmpu401.sys
[2010/01/18 03:01:07 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msircomm.sys
[2010/01/18 03:00:59 | 00,035,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msgame.sys
[2010/01/18 03:00:56 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfsio.sys
[2010/01/18 03:00:55 | 00,051,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdv.sys
[2010/01/18 03:00:48 | 00,017,280 | —- | C] (American Megatrends Inc.) – C:\WINDOWS\System32\dllcache\mraid35x.sys
[2010/01/18 03:00:46 | 00,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpe.sys
[2010/01/18 03:00:37 | 00,006,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\miniqic.sys
[2010/01/18 03:00:32 | 00,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaum.sys
[2010/01/18 03:00:29 | 00,235,648 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaud.dll
[2010/01/18 03:00:27 | 00,026,112 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\memstpci.sys
[2010/01/18 03:00:25 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memgrp.dll
[2010/01/18 03:00:21 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memcard.sys
[2010/01/18 03:00:18 | 00,164,586 | —- | C] (Madge Networks Ltd) – C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2010/01/18 03:00:14 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mammoth.sys
[2010/01/18 03:00:11 | 00,048,768 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\maestro.sys
[2010/01/18 03:00:08 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3092dc.dll
[2010/01/18 03:00:06 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3091dc.dll
[2010/01/18 03:00:03 | 00,022,848 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwusbhid.sys
[2010/01/18 03:00:02 | 00,020,864 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwadihid.sys
[2010/01/18 03:00:00 | 00,797,500 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltsmt.sys
[2010/01/18 02:59:57 | 00,802,683 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\ltsm.sys
[2010/01/18 02:59:57 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ltotape.sys
[2010/01/18 02:59:56 | 00,420,992 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2010/01/18 02:59:54 | 00,576,746 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2010/01/18 02:59:53 | 00,606,684 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2010/01/18 02:59:51 | 00,727,786 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ltck000c.sys
[2010/01/18 02:59:48 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\loop.sys
[2010/01/18 02:59:45 | 00,070,730 | —- | C] (Linksys Group, Inc.) – C:\WINDOWS\System32\dllcache\lne100tx.sys
[2010/01/18 02:59:42 | 00,020,573 | —- | C] (The Linksts Group ) – C:\WINDOWS\System32\dllcache\lne100.sys
[2010/01/18 02:59:40 | 00,025,065 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\lmndis3.sys
[2010/01/18 02:59:37 | 00,034,688 | —- | C] (Toshiba Corp.) – C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2010/01/18 02:59:37 | 00,015,744 | —- | C] (Litronic Industries) – C:\WINDOWS\System32\dllcache\lit220p.sys
[2010/01/18 02:59:34 | 00,026,442 | —- | C] (SMSC) – C:\WINDOWS\System32\dllcache\lanepic5.sys
[2010/01/18 02:59:32 | 00,019,016 | —- | C] (Kingston Technology Company ) – C:\WINDOWS\System32\dllcache\ktc111.sys
[2010/01/18 02:59:31 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kswdmcap.ax
[2010/01/18 02:59:31 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ksxbar.ax
[2010/01/18 02:59:30 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kstvtune.ax
[2010/01/18 02:59:26 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kousd.dll
[2010/01/18 02:59:23 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsusd.dll
[2010/01/18 02:59:22 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsui.dll
[2010/01/18 02:59:13 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdkor.dll
[2010/01/18 02:59:11 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdjpn.dll
[2010/01/18 02:59:01 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd106.dll
[2010/01/18 02:58:58 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd103.dll
[2010/01/18 02:58:56 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101c.dll
[2010/01/18 02:58:54 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101b.dll
[2010/01/18 02:58:49 | 00,026,624 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\dllcache\irstusb.sys
[2010/01/18 02:58:46 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irmon.dll
[2010/01/18 02:58:46 | 00,018,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irsir.sys
[2010/01/18 02:58:44 | 00,023,552 | —- | C] (MKNet Corporation) – C:\WINDOWS\System32\dllcache\irmk7.sys
[2010/01/18 02:58:43 | 00,151,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irftp.exe
[2010/01/18 02:58:43 | 00,088,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irda.sys
[2010/01/18 02:58:41 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ipsink.ax
[2010/01/18 02:58:37 | 00,045,632 | —- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) – C:\WINDOWS\System32\dllcache\ip5515.sys
[2010/01/18 02:58:34 | 00,090,200 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8ports.dll
[2010/01/18 02:58:32 | 00,038,784 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8.sys
[2010/01/18 02:58:29 | 00,013,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inport.sys
[2010/01/18 02:58:26 | 00,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ini910u.sys
[2010/01/18 02:58:06 | 00,372,824 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\iconf32.dll
[2010/01/18 02:58:04 | 00,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5usb.sys
[2010/01/18 02:58:02 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5ext.dll
[2010/01/18 02:57:59 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5com.dll
[2010/01/18 02:57:57 | 00,154,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4usb.sys
[2010/01/18 02:57:55 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4ext.dll
[2010/01/18 02:57:53 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4com.dll
[2010/01/18 02:57:51 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3ext.dll
[2010/01/18 02:57:48 | 00,141,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3.sys
[2010/01/18 02:57:46 | 00,038,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2010/01/18 02:57:44 | 00,109,085 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtrp.sys
[2010/01/18 02:57:42 | 00,100,936 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtok.sys
[2010/01/18 02:57:40 | 00,009,216 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmsgnet.dll
[2010/01/18 02:57:37 | 00,028,700 | —- | C] (IBM Corp.) – C:\WINDOWS\System32\dllcache\ibmexmp.sys
[2010/01/18 02:57:36 | 00,161,020 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\i81xnt5.sys
[2010/01/18 02:57:35 | 00,702,845 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\i81xdnt5.dll
[2010/01/18 02:57:32 | 00,058,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740nt5.sys
[2010/01/18 02:57:30 | 00,353,184 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740dnt5.dll
[2010/01/18 02:57:30 | 00,018,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omp.sys
[2010/01/18 02:57:29 | 00,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2010/01/18 02:57:09 | 00,488,383 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_v124.sys
[2010/01/18 02:57:07 | 00,050,751 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_tone.sys
[2010/01/18 02:57:05 | 00,073,279 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_spkp.sys
[2010/01/18 02:57:03 | 00,044,863 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_soar.sys
[2010/01/18 02:57:01 | 00,057,471 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_samp.sys
[2010/01/18 02:56:58 | 00,542,879 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_msft.sys
[2010/01/18 02:56:56 | 00,391,199 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_k56k.sys
[2010/01/18 02:56:54 | 00,009,759 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_inst.dll
[2010/01/18 02:56:52 | 00,115,807 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fsks.sys
[2010/01/18 02:56:50 | 00,199,711 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_faxx.sys
[2010/01/18 02:56:48 | 00,289,887 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fall.sys
[2010/01/18 02:56:45 | 00,067,167 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_bsc2.sys
[2010/01/18 02:56:43 | 00,150,239 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_amos.sys
[2010/01/18 02:56:40 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hr1w.dll
[2010/01/18 02:56:38 | 00,005,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpt4qic.sys
[2010/01/18 02:56:36 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2010/01/18 02:56:34 | 00,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2010/01/18 02:56:32 | 00,025,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpn.sys
[2010/01/18 02:56:30 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2010/01/18 02:56:28 | 00,068,608 | —- | C] (Avisioin) – C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2010/01/18 02:56:24 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2010/01/18 02:56:20 | 00,126,976 | —- | C] (Hewlett Packard) – C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2010/01/18 02:56:16 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2010/01/18 02:56:12 | 00,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2010/01/18 02:56:08 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2010/01/18 02:56:05 | 00,002,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidswvd.sys
[2010/01/18 02:56:03 | 00,020,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidbatt.sys
[2010/01/18 02:56:03 | 00,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidgame.sys
[2010/01/18 02:55:59 | 00,907,456 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hcf_msft.sys
[2010/01/18 02:55:58 | 00,028,288 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grserial.sys
[2010/01/18 02:55:56 | 00,082,304 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grclass.sys
[2010/01/18 02:55:54 | 00,017,408 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\gpr400.sys
[2010/01/18 02:55:52 | 00,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gckernel.sys
[2010/01/18 02:55:52 | 00,010,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gameenum.sys
[2010/01/18 02:55:50 | 00,322,432 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400m.sys
[2010/01/18 02:55:48 | 01,733,120 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400d.dll
[2010/01/18 02:55:46 | 00,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200m.sys
[2010/01/18 02:55:44 | 00,470,144 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200d.dll
[2010/01/18 02:55:42 | 00,454,912 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fxusbase.sys
[2010/01/18 02:55:34 | 00,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fuusd.dll
[2010/01/18 02:55:32 | 00,455,296 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fusbbase.sys
[2010/01/18 02:55:31 | 00,455,680 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fus2base.sys
[2010/01/18 02:55:28 | 00,442,240 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2010/01/18 02:55:26 | 00,441,728 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2010/01/18 02:55:23 | 00,444,416 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcibase.sys
[2010/01/18 02:55:22 | 00,034,173 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\forehe.sys
[2010/01/18 02:55:20 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fnfilter.dll
[2010/01/18 02:55:16 | 00,027,165 | —- | C] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\dllcache\fetnd5.sys
[2010/01/18 02:55:11 | 00,022,090 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\fem556n5.sys
[2010/01/18 02:55:05 | 00,024,618 | —- | C] (NETGEAR) – C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2010/01/18 02:55:04 | 00,016,074 | —- | C] (NETGEAR Corp.) – C:\WINDOWS\System32\dllcache\fa312nd5.sys
[2010/01/18 02:55:02 | 00,011,850 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2010/01/18 02:55:00 | 00,012,362 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2010/01/18 02:54:58 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exabyte2.sys
[2010/01/18 02:54:56 | 00,016,998 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ex10.sys
[2010/01/18 02:54:53 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunib.dll
[2010/01/18 02:54:52 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuni.dll
[2010/01/18 02:54:50 | 00,034,816 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimg.dll
[2010/01/18 02:54:46 | 00,043,008 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucm.dll
[2010/01/18 02:54:45 | 00,137,088 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\essm2e.sys
[2010/01/18 02:54:44 | 00,063,360 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\ess.sys
[2010/01/18 02:54:41 | 00,347,550 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56tpi.sys
[2010/01/18 02:54:40 | 00,594,238 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56hpi.sys
[2010/01/18 02:54:38 | 00,595,647 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56cvmp.sys
[2010/01/18 02:54:36 | 00,174,464 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es198x.sys
[2010/01/18 02:54:34 | 00,072,192 | —- | C] (ESS Technology Inc.) – C:\WINDOWS\System32\dllcache\es1969.sys
[2010/01/18 02:54:33 | 00,040,704 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1371mp.sys
[2010/01/18 02:54:31 | 00,037,120 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1370mp.sys
[2010/01/18 02:54:29 | 00,061,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnloop.exe
[2010/01/18 02:54:28 | 00,051,200 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnlogr.exe
[2010/01/18 02:54:26 | 00,053,248 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqndiag.exe
[2010/01/18 02:54:24 | 00,629,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqn.sys
[2010/01/18 02:54:23 | 00,114,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epstw2k.sys
[2010/01/18 02:54:21 | 00,018,503 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\epro4.sys
[2010/01/18 02:54:20 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2010/01/18 02:54:18 | 00,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\enum1394.sys
[2010/01/18 02:54:17 | 00,283,904 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\emu10k1m.sys
[2010/01/18 02:54:14 | 00,019,996 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\em556n4.sys
[2010/01/18 02:54:13 | 00,025,159 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\elnk3.sys
[2010/01/18 02:54:12 | 00,007,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\elmsmc.sys
[2010/01/18 02:54:10 | 00,171,520 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el99xn51.sys
[2010/01/18 02:54:09 | 00,070,174 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el98xn5.sys
[2010/01/18 02:54:08 | 00,455,199 | —- | C] (3Com Corporation.) – C:\WINDOWS\System32\dllcache\el985n51.sys
[2010/01/18 02:54:07 | 00,153,631 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xnd5.sys
[2010/01/18 02:54:06 | 00,066,591 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xbc5.sys
[2010/01/18 02:54:05 | 00,241,206 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656se5.sys
[2010/01/18 02:54:04 | 00,077,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656nd5.sys
[2010/01/18 02:54:02 | 00,634,134 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656ct5.sys
[2010/01/18 02:54:01 | 00,069,194 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656cd5.sys
[2010/01/18 02:54:00 | 00,026,141 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el589nd5.sys
[2010/01/18 02:53:59 | 00,069,692 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el575nd5.sys
[2010/01/18 02:53:58 | 00,024,653 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el574nd4.sys
[2010/01/18 02:53:57 | 00,055,999 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el556nd5.sys
[2010/01/18 02:53:55 | 00,044,103 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el515.sys
[2010/01/18 02:53:54 | 00,019,594 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e100isa4.sys
[2010/01/18 02:53:52 | 00,050,719 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e1000nt5.sys
[2010/01/18 02:53:48 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dshowext.ax
[2010/01/18 02:53:46 | 00,334,208 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2010/01/18 02:53:43 | 00,020,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpti2o.sys
[2010/01/18 02:53:40 | 00,028,062 | —- | C] (National Semiconductor Coproration) – C:\WINDOWS\System32\dllcache\dp83820.sys
[2010/01/18 02:53:39 | 00,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2010/01/18 02:53:38 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2010/01/18 02:53:37 | 00,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2010/01/18 02:53:36 | 00,206,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4.sys
[2010/01/18 02:53:31 | 00,029,696 | —- | C] (CNet Technology, Inc. ) – C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2010/01/18 02:53:31 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dlttape.sys
[2010/01/18 02:53:30 | 00,026,698 | —- | C] (D-Link Corporation) – C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2010/01/18 02:53:29 | 00,952,007 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diwan.sys
[2010/01/18 02:53:25 | 00,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2010/01/18 02:53:24 | 00,038,985 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvsu.dll
[2010/01/18 02:53:23 | 00,031,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvpp.dll
[2010/01/18 02:53:22 | 00,006,729 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvci.dll
[2010/01/18 02:53:20 | 00,091,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\dimaint.sys
[2010/01/18 02:53:19 | 00,614,429 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiview.exe
[2010/01/18 02:53:18 | 00,042,432 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.sys
[2010/01/18 02:53:17 | 00,110,621 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.dll
[2010/01/18 02:53:16 | 00,021,606 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.sys
[2010/01/18 02:53:15 | 00,041,046 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.dll
[2010/01/18 02:53:14 | 00,102,484 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiinf.dll
[2010/01/18 02:53:13 | 00,159,828 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digihlc.dll
[2010/01/18 02:53:12 | 00,229,462 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifwrk.dll
[2010/01/18 02:53:11 | 00,090,525 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifep5.sys
[2010/01/18 02:53:10 | 00,103,044 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidxb.sys
[2010/01/18 02:53:09 | 00,131,156 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidbp.dll
[2010/01/18 02:53:08 | 00,037,735 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.sys
[2010/01/18 02:53:07 | 00,065,622 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.dll
[2010/01/18 02:53:05 | 00,419,357 | —- | C] (Digi International) – C:\WINDOWS\System32\dllcache\dgconfig.dll
[2010/01/18 02:53:04 | 00,029,531 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\dgapci.sys
[2010/01/18 02:53:02 | 00,024,649 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650d.sys
[2010/01/18 02:53:01 | 00,024,648 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650.sys
[2010/01/18 02:53:00 | 00,024,064 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\devldr32.exe
[2010/01/18 02:52:59 | 00,256,512 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\devcon32.dll
[2010/01/18 02:52:58 | 00,020,928 | —- | C] (Digital Networks, LLC) – C:\WINDOWS\System32\dllcache\defpa.sys
[2010/01/18 02:52:57 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddsmc.sys
[2010/01/18 02:52:55 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc260usd.dll
[2010/01/18 02:52:54 | 00,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc240usd.dll
[2010/01/18 02:52:53 | 00,063,208 | —- | C] (Intel Corporation.) – C:\WINDOWS\System32\dllcache\dc21x4.sys
[2010/01/18 02:52:52 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210usd.dll
[2010/01/18 02:52:52 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210_32.dll
[2010/01/18 02:52:49 | 00,014,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dac960nt.sys
[2010/01/18 02:52:48 | 00,179,584 | —- | C] (Mylex Corporation) – C:\WINDOWS\System32\dllcache\dac2w2k.sys
[2010/01/18 02:52:46 | 00,117,760 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\d100ib5.sys
[2010/01/18 02:52:45 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzports.dll
[2010/01/18 02:52:44 | 00,049,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzport.sys
[2010/01/18 02:52:43 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzcoins.dll
[2010/01/18 02:52:42 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyports.dll
[2010/01/18 02:52:41 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyport.sys
[2010/01/18 02:52:40 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyycoins.dll
[2010/01/18 02:52:40 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclom-y.sys
[2010/01/18 02:52:39 | 00,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclad-z.sys
[2010/01/18 02:52:38 | 00,048,640 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2010/01/18 02:52:37 | 00,093,952 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2010/01/18 02:52:36 | 00,111,872 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcspud.sys
[2010/01/18 02:52:36 | 00,003,584 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2010/01/18 02:52:35 | 00,072,832 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2010/01/18 02:52:34 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2010/01/18 02:52:33 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbase.sys
[2010/01/18 02:52:32 | 00,249,856 | —- | C] (Comtrol® Corporation) – C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2010/01/18 02:52:32 | 00,004,096 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctwdm32.dll
[2010/01/18 02:52:31 | 00,096,256 | —- | C] (Copyright © Creative Technology Ltd. 1994-2001) – C:\WINDOWS\System32\dllcache\ctlsb16.sys
[2010/01/18 02:52:29 | 00,006,912 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctlfacem.sys
[2010/01/18 02:52:29 | 00,003,712 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctljystk.sys
[2010/01/18 02:52:27 | 00,175,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\csamsp.dll
[2010/01/18 02:52:26 | 00,042,112 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\crtaud.sys
[2010/01/18 02:52:25 | 00,216,064 | —- | C] (COMPAQ Inc.) – C:\WINDOWS\System32\dllcache\cpscan.dll
[2010/01/18 02:52:24 | 00,060,970 | —- | C] (Compaq Computer Corp.) – C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2010/01/18 02:52:23 | 00,021,533 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2010/01/18 02:52:22 | 00,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cpqarray.sys
[2010/01/18 02:52:20 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\compbatt.sys
[2010/01/18 02:52:18 | 00,039,936 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\cnxt1803.sys
[2010/01/18 02:52:17 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnusd.dll
[2010/01/18 02:52:15 | 00,020,736 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2010/01/18 02:52:15 | 00,006,656 | —- | C] (CMD Technology, Inc.) – C:\WINDOWS\System32\dllcache\cmdide.sys
[2010/01/18 02:52:14 | 00,013,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cmbatt.sys
[2010/01/18 02:52:13 | 00,248,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546xm.sys
[2010/01/18 02:52:12 | 00,170,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546x.dll
[2010/01/18 02:52:12 | 00,111,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl5465.dll
[2010/01/18 02:52:11 | 00,045,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.sys
[2010/01/18 02:52:10 | 00,091,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.dll
[2010/01/18 02:52:09 | 00,272,640 | —- | C] (RAVISENT Technologies Inc.) – C:\WINDOWS\System32\dllcache\cinemclc.sys
[2010/01/18 02:52:08 | 00,980,034 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\cicap.sys
[2010/01/18 02:52:03 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\changer.sys
[2010/01/18 02:52:00 | 00,049,182 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem56n5.sys
[2010/01/18 02:52:00 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem33n5.sys
[2010/01/18 02:51:59 | 00,027,164 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce3n5.sys
[2010/01/18 02:51:59 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem28n5.sys
[2010/01/18 02:51:58 | 00,021,530 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce2n5.sys
[2010/01/18 02:51:56 | 00,017,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ccdecode.sys
[2010/01/18 02:51:56 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cd20xrnt.sys
[2010/01/18 02:51:54 | 00,714,698 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2010/01/18 02:51:54 | 00,046,108 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cben5.sys
[2010/01/18 02:51:53 | 00,039,680 | —- | C] (Silicom Ltd.) – C:\WINDOWS\System32\dllcache\cb325.sys
[2010/01/18 02:51:53 | 00,037,916 | —- | C] (Fast Ethernet Controller Provider) – C:\WINDOWS\System32\dllcache\cb102.sys
[2010/01/18 02:51:51 | 00,032,256 | —- | C] (Eicon Technology Corporation) – C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2010/01/18 02:51:50 | 00,164,923 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diapi2.sys
[2010/01/18 02:51:48 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.dll
[2010/01/18 02:51:48 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.ax
[2010/01/18 02:51:47 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.ax
[2010/01/18 02:51:47 | 00,236,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.dll
[2010/01/18 02:51:46 | 00,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.dll
[2010/01/18 02:51:46 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.ax
[2010/01/18 02:51:45 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv21.sys
[2010/01/18 02:51:45 | 00,171,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv30.sys
[2010/01/18 02:51:44 | 00,314,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdro21.sys
[2010/01/18 02:51:26 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2010/01/18 02:51:25 | 00,031,529 | —- | C] (BreezeCOM) – C:\WINDOWS\System32\dllcache\brzwlan.sys
[2010/01/18 02:51:25 | 00,010,368 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbscn.sys
[2010/01/18 02:51:24 | 00,060,416 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brserwdm.sys
[2010/01/18 02:51:24 | 00,011,008 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2010/01/18 02:51:23 | 00,009,728 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brserif.dll
[2010/01/18 02:51:23 | 00,005,120 | —- | C] (Brother Industries,Ltd.) – C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2010/01/18 02:51:22 | 00,039,552 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparwdm.sys
[2010/01/18 02:51:22 | 00,003,168 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparimg.sys
[2010/01/18 02:51:21 | 00,041,472 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfusb.dll
[2010/01/18 02:51:20 | 00,032,256 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2010/01/18 02:51:20 | 00,029,696 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmflpt.dll
[2010/01/18 02:51:19 | 00,081,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2010/01/18 02:51:19 | 00,015,360 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2010/01/18 02:51:18 | 00,012,160 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2010/01/18 02:51:18 | 00,003,968 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltup.sys
[2010/01/18 02:51:17 | 00,012,800 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brevif.dll
[2010/01/18 02:51:17 | 00,002,944 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brfilt.sys
[2010/01/18 02:51:16 | 00,019,456 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brbidiif.dll
[2010/01/18 02:51:16 | 00,009,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brcoinst.dll
[2010/01/18 02:51:15 | 00,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\binlsvc.dll
[2010/01/18 02:51:14 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdasup.sys
[2010/01/18 02:51:13 | 00,871,388 | —- | C] (BCM) – C:\WINDOWS\System32\dllcache\bcmdm.sys
[2010/01/18 02:51:13 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2010/01/18 02:51:12 | 00,066,557 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42u.sys
[2010/01/18 02:51:12 | 00,054,271 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42xx5.sys
[2010/01/18 02:51:12 | 00,026,568 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm4e5.sys
[2010/01/18 02:51:11 | 00,014,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\battc.sys
[2010/01/18 02:51:10 | 00,342,336 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.dll
[2010/01/18 02:51:10 | 00,036,128 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.sys
[2010/01/18 02:51:09 | 00,096,640 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\b57xp32.sys
[2010/01/18 02:51:09 | 00,089,952 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\b1cbase.sys
[2010/01/18 02:51:08 | 00,037,568 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmwan.sys
[2010/01/18 02:51:08 | 00,036,992 | —- | C] (Aztech Systems Ltd) – C:\WINDOWS\System32\dllcache\aztw2320.sys
[2010/01/18 02:51:07 | 00,144,384 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmenum.dll
[2010/01/18 02:51:06 | 00,087,552 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2010/01/18 02:51:05 | 00,036,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcaudio.sys
[2010/01/18 02:51:05 | 00,013,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcstrm.sys
[2010/01/18 02:51:04 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avc.sys
[2010/01/18 02:50:59 | 00,070,528 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiragem.sys
[2010/01/18 02:50:58 | 00,104,832 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiraged.dll
[2010/01/18 02:50:57 | 00,281,600 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimtai.sys
[2010/01/18 02:50:56 | 00,289,664 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpab.sys
[2010/01/18 02:50:56 | 00,075,136 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpae.sys
[2010/01/18 02:50:56 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atievxx.exe
[2010/01/18 02:50:55 | 00,268,160 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidvai.dll
[2010/01/18 02:50:55 | 00,137,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrae.dll
[2010/01/18 02:50:54 | 00,382,592 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrab.dll
[2010/01/18 02:50:52 | 00,096,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ati.dll
[2010/01/18 02:50:52 | 00,077,568 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ati.sys
[2010/01/18 02:50:51 | 00,097,354 | —- | C] (Bay Networks, Inc.) – C:\WINDOWS\System32\dllcache\aspndis3.sys
[2010/01/18 02:50:50 | 00,026,496 | —- | C] (Advanced System Products, Inc.) – C:\WINDOWS\System32\dllcache\asc.sys
[2010/01/18 02:50:50 | 00,022,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asc3350p.sys
[2010/01/18 02:50:50 | 00,014,848 | —- | C] (Advanced System Products, Inc.) – C:\WINDOWS\System32\dllcache\asc3550.sys
[2010/01/18 02:50:49 | 00,006,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\apmbatt.sys
[2010/01/18 02:50:48 | 00,036,224 | —- | C] (ADMtek Incorporated.) – C:\WINDOWS\System32\dllcache\an983.sys
[2010/01/18 02:50:48 | 00,012,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\amsint.sys
[2010/01/18 02:50:47 | 00,016,969 | —- | C] (AmbiCom, Inc.) – C:\WINDOWS\System32\dllcache\amb8002.sys
[2010/01/18 02:50:46 | 00,026,624 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\alifir.sys
[2010/01/18 02:50:46 | 00,005,248 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\aliide.sys
[2010/01/18 02:50:45 | 00,056,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78xx.sys
[2010/01/18 02:50:45 | 00,055,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78u2.sys
[2010/01/18 02:50:45 | 00,027,678 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ali5261.sys
[2010/01/18 02:50:44 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aha154x.sys
[2010/01/18 02:50:41 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2010/01/18 02:48:10 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adpu160m.sys
[2010/01/18 02:48:09 | 00,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2010/01/18 02:48:09 | 00,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2010/01/18 02:48:08 | 00,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2010/01/18 02:48:08 | 00,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2010/01/18 02:48:08 | 00,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2010/01/18 02:48:07 | 00,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2010/01/18 02:48:07 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2010/01/18 02:48:06 | 00,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2010/01/18 02:48:05 | 00,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2010/01/18 02:48:05 | 00,096,256 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ac97intc.sys
[2010/01/18 02:48:05 | 00,084,480 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ac97via.sys
[2010/01/18 02:48:04 | 00,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2010/01/18 02:48:04 | 00,231,552 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ac97ali.sys
[2010/01/18 02:48:04 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\abp480n5.sys
[2010/01/18 02:48:03 | 00,098,304 | —- | C] (Aureal Semiconductor) – C:\WINDOWS\System32\dllcache\a3d.dll
[2010/01/18 02:48:03 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\61883.sys
[2010/01/18 02:48:03 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2010/01/18 02:48:03 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\4mmdat.sys
[2010/01/18 02:48:02 | 00,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2010/01/18 02:48:02 | 00,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2010/01/18 02:48:02 | 00,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2010/01/18 02:48:02 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2010/01/18 02:48:01 | 00,053,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394bus.sys
[2010/01/18 02:47:43 | 00,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2010/01/18 02:07:37 | 00,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/01/16 05:50:44 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Comodo
[2010/01/16 04:44:17 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Comodo
[2010/01/16 04:09:02 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Comodo
[2010/01/16 03:16:20 | 40,603,920 | —- | C] (COMODO) – C:\Documents and Settings\Owner\Desktop\CIS_Setup_3.13.125662.579_XP_Vista_x32.exe
[2010/01/16 02:47:55 | 03,299,576 | —- | C] (Comodo CA Ltd.) – C:\Documents and Settings\Owner\Desktop\vengine.exe
[2010/01/16 02:40:12 | 00,018,184 | —- | C] (COMODO Security Solutions Inc.) – C:\WINDOWS\System32\cnat.exe
[2010/01/16 02:40:08 | 00,000,000 | —D | C] – C:\Program Files\COMODO
[2010/01/16 00:14:59 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Google SketchUp 7 Videos
[2010/01/14 00:28:21 | 00,000,000 | —D | C] – C:\My Movies
[2010/01/13 03:28:09 | 00,172,040 | —- | C] (Reimage®) – C:\Documents and Settings\Owner\Desktop\ReimageRepair.exe
[2010/01/10 14:56:00 | 00,000,000 | R–D | C] – C:\Sandbox
[2010/01/10 14:53:46 | 00,000,000 | —D | C] – C:\Program Files\Sandboxie
[2010/01/10 13:14:50 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\IsolatedStorage
[2010/01/10 13:14:19 | 00,000,000 | —D | C] – C:\Program Files\Virtual Earth 3D
[2010/01/07 11:55:11 | 00,118,784 | —- | C] (fccHandler) – C:\WINDOWS\System32\AC3ACM.acm
[2010/01/07 10:28:11 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GSpot270a
[2010/01/05 16:00:52 | 00,000,000 | —D | C] – C:\Program Files\Paint.NET
[2010/01/05 16:00:47 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Paint.NET
[2010/01/05 10:10:10 | 00,266,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TweakUI.exe
[2010/01/05 09:54:02 | 00,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2010/01/04 21:39:11 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\ImgBurn
[2010/01/04 19:19:11 | 00,000,000 | —D | C] – C:\Program Files\ImgBurn
[2010/01/04 19:14:40 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Nero
[2010/01/04 19:09:24 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Nero
[2010/01/04 19:09:23 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Nero
[2010/01/04 18:39:02 | 00,000,000 | —D | C] – C:\Program Files\ShrinkTo5Basic
[2010/01/04 18:36:53 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2010/01/04 18:36:52 | 00,000,000 | —D | C] – C:\Program Files\DVD Shrink
[2010/01/04 18:32:17 | 00,000,000 | —D | C] – C:\Program Files\Recuva
[2010/01/04 16:42:44 | 13,451,4912 | —- | C] ( ) – C:\Documents and Settings\Owner\Desktop\CyberLink.2201(BDTrial)_DVD090929-03.exe
[2010/01/04 16:25:23 | 04,730,740 | —- | C] (ratDVD) – C:\Documents and Settings\Owner\Desktop\ratDVDSetup-0.78.1444.exe
[2010/01/04 15:26:43 | 00,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/01/04 13:27:23 | 00,087,552 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System\url.dll
[2010/01/04 13:27:23 | 00,009,728 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System\rnaph.dll
[2010/01/04 13:27:23 | 00,000,000 | —D | C] – C:\WINDOWS\wb
[2010/01/04 03:12:21 | 00,000,000 | —D | C] – C:\Program Files\SpywareGuard
[2010/01/04 02:34:52 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/01/04 02:15:12 | 00,181,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/01/04 02:14:36 | 00,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/01/03 11:46:04 | 00,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2010/01/03 11:45:43 | 00,000,000 | —D | C] – C:\Program Files\McAfee
[2010/01/03 11:45:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2010/01/02 12:18:54 | 00,000,000 | —D | C] – C:\Program Files\RegSeeker
[2009/12/31 17:37:22 | 00,314,880 | —- | C] (InstallShield Software Corporation) – C:\WINDOWS\IsUninst.exe
[2009/12/31 17:36:57 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\WINDOWS
[2009/12/28 23:18:01 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/12/01 20:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/12/01 20:16:34 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/11/30 10:22:54 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/11/30 01:43:59 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/11/29 20:30:50 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

========== Files - Modified Within 30 Days ==========

[2010/01/27 20:13:38 | 00,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{42CFC73D-77FB-4A38-8871-5C2A3B534A4F}.job
[2010/01/27 19:53:52 | 00,548,864 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/27 13:03:26 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/01/27 12:33:46 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/01/27 12:13:16 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/27 12:13:11 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/27 03:57:05 | 04,718,592 | —- | M] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/01/27 03:57:05 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/01/27 03:57:01 | 04,838,938 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/01/27 03:26:18 | 02,259,880 | —- | M] (Auslogics Software Pty Ltd ) – C:\Documents and Settings\Owner\Desktop\disk-defrag-setup.exe
[2010/01/27 03:17:33 | 00,004,272 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20100127_031714.reg
[2010/01/27 02:23:46 | 00,001,030 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20100127_022327.reg
[2010/01/25 19:26:27 | 00,000,600 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20100125_192615.reg
[2010/01/25 16:45:14 | 00,029,184 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/25 09:34:01 | 04,179,293 | —- | M] (Lavalys, Inc. ) – C:\Documents and Settings\Owner\Desktop\everesthome220.exe
[2010/01/24 19:55:20 | 00,000,843 | —- | M] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\MailWasherFree.lnk
[2010/01/24 14:54:22 | 00,043,921 | —- | M] () – C:\Documents and Settings\Owner\Desktop\DDS.JPG
[2010/01/23 03:28:05 | 00,005,822 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20100123_032759.reg
[2010/01/22 19:11:10 | 00,000,528 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/22 19:11:10 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/22 19:11:10 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2010/01/21 20:44:38 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/20 22:08:31 | 00,005,540 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20100120_220824.reg
[2010/01/20 21:57:31 | 04,456,448 | —- | M] () – C:\Documents and Settings\Owner\ntuser.bak
[2010/01/19 16:42:08 | 00,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CDBurnerXP.lnk
[2010/01/19 14:13:05 | 00,001,724 | —- | M] () – C:\Documents and Settings\Owner\Desktop\CodeStuff Starter.lnk
[2010/01/19 13:24:36 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2010/01/19 13:24:32 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/01/19 00:20:54 | 00,002,162 | —- | M] () – C:\WINDOWS\Sandboxie.ini
[2010/01/18 12:15:37 | 00,006,848 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Sharon Russell Resume.rtf
[2010/01/17 16:40:35 | 03,299,576 | —- | M] (Comodo CA Ltd.) – C:\Documents and Settings\Owner\Desktop\vengine.exe
[2010/01/17 15:21:09 | 00,262,144 | —- | M] () – C:\Documents and Settings\All Users\NTUSER.dat
[2010/01/16 14:19:01 | 00,004,119 | —- | M] () – C:\Documents and Settings\Owner\My Documents\contacts.csv
[2010/01/16 14:03:56 | 00,119,875 | —- | M] () – C:\WINDOWS\System32\sgmain.JPG
[2010/01/16 04:43:49 | 40,603,920 | —- | M] (COMODO) – C:\Documents and Settings\Owner\Desktop\CIS_Setup_3.13.125662.579_XP_Vista_x32.exe
[2010/01/15 23:20:06 | 00,001,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google SketchUp 7.lnk
[2010/01/14 11:12:06 | 00,181,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/01/13 03:29:57 | 00,000,332 | —- | M] () – C:\WINDOWS\System32\Compress.res
[2010/01/13 03:29:51 | 00,000,232 | —- | M] () – C:\WINDOWS\reimage.ini
[2010/01/11 14:36:28 | 00,069,851 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Financial Services Guide.pdf
[2010/01/11 14:35:21 | 00,253,679 | —- | M] () – C:\Documents and Settings\Owner\My Documents\ElectronicBanking_ADB2426.pdf
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/07 12:34:57 | 00,292,352 | —- | M] () – C:\Documents and Settings\Owner\Desktop\2j7vxcyy.exe
[2010/01/07 09:27:24 | 00,018,184 | —- | M] (COMODO Security Solutions Inc.) – C:\WINDOWS\System32\cnat.exe
[2010/01/05 16:04:05 | 00,000,812 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Paint.NET.lnk
[2010/01/05 15:44:12 | 00,113,108 | —- | M] () – C:\Documents and Settings\Owner\My Documents\BMI Calculation.pdf
[2010/01/04 18:36:53 | 00,000,670 | —- | M] () – C:\Documents and Settings\Owner\Desktop\DVD Shrink 3.2.lnk
[2010/01/04 18:32:18 | 00,001,512 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Recuva.lnk
[2010/01/04 03:25:26 | 00,005,274 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20100104_032522.reg
[2010/01/03 21:02:57 | 00,000,495 | —- | M] () – C:\WINDOWS\cfplogvw.INI
[2010/01/03 19:27:54 | 00,000,870 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20100103_192749.reg
[2010/01/02 10:45:11 | 00,078,160 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\Microsoft AutoPlay Repair Wizard.exe
[2010/01/01 09:48:04 | 00,000,688 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20100101_094144.reg
[2009/12/28 23:21:29 | 00,003,044 | —- | M] () – C:\Documents and Settings\Owner\My Documents\cc_20091228_232114.reg

========== Files Created - No Company Name ==========

[2010/01/27 03:17:17 | 00,004,272 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20100127_031714.reg
[2010/01/27 02:23:35 | 00,001,030 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20100127_022327.reg
[2010/01/25 19:26:16 | 00,000,600 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20100125_192615.reg
[2010/01/24 19:55:20 | 00,000,843 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\MailWasherFree.lnk
[2010/01/24 14:54:22 | 00,043,921 | —- | C] () – C:\Documents and Settings\Owner\Desktop\DDS.JPG
[2010/01/23 21:31:25 | 00,524,288 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/01/23 03:28:02 | 00,005,822 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20100123_032759.reg
[2010/01/20 22:08:26 | 00,005,540 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20100120_220824.reg
[2010/01/20 19:49:20 | 04,718,592 | —- | C] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/01/19 16:42:08 | 00,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CDBurnerXP.lnk
[2010/01/19 16:42:07 | 00,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/01/19 14:13:05 | 00,001,724 | —- | C] () – C:\Documents and Settings\Owner\Desktop\CodeStuff Starter.lnk
[2010/01/19 13:24:36 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2010/01/19 13:24:32 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/01/18 12:15:37 | 00,006,848 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Sharon Russell Resume.rtf
[2010/01/18 03:15:28 | 00,018,944 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2010/01/18 03:15:24 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2010/01/18 03:04:56 | 00,033,280 | —- | C] () – C:\WINDOWS\System32\dllcache\psisrndr.ax
[2010/01/18 03:04:52 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\dllcache\psisdecd.dll
[2010/01/18 03:00:55 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2010/01/18 02:56:26 | 00,165,888 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt53.dll
[2010/01/18 02:56:22 | 00,093,696 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt42.dll
[2010/01/18 02:56:18 | 00,101,376 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt34.dll
[2010/01/18 02:56:14 | 00,089,088 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt33.dll
[2010/01/18 02:56:10 | 00,083,968 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt21.dll
[2010/01/18 02:53:28 | 00,029,768 | —- | C] () – C:\WINDOWS\System32\dllcache\divasu.dll
[2010/01/18 02:53:27 | 00,037,962 | —- | C] () – C:\WINDOWS\System32\dllcache\divaprop.dll
[2010/01/18 02:53:26 | 00,006,216 | —- | C] () – C:\WINDOWS\System32\dllcache\divaci.dll
[2010/01/18 02:51:02 | 00,023,552 | —- | C] () – C:\WINDOWS\System32\dllcache\atixbar.sys
[2010/01/18 02:51:01 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\dllcache\ativxbar.sys
[2010/01/18 02:51:01 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\dllcache\ativttxx.sys
[2010/01/18 02:51:00 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2010/01/18 02:51:00 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitunep.sys
[2010/01/18 02:51:00 | 00,009,472 | —- | C] () – C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2010/01/18 02:50:59 | 00,049,920 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtcap.sys
[2010/01/18 02:50:59 | 00,026,880 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2010/01/18 02:50:58 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2010/01/18 02:50:54 | 00,046,464 | —- | C] () – C:\WINDOWS\System32\dllcache\atibt829.sys
[2010/01/17 15:21:08 | 00,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.dat
[2010/01/16 14:18:59 | 00,004,119 | —- | C] () – C:\Documents and Settings\Owner\My Documents\contacts.csv
[2010/01/16 14:03:56 | 00,119,875 | —- | C] () – C:\WINDOWS\System32\sgmain.JPG
[2010/01/15 23:20:06 | 00,001,762 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google SketchUp 7.lnk
[2010/01/11 14:36:28 | 00,069,851 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Financial Services Guide.pdf
[2010/01/11 14:35:21 | 00,253,679 | —- | C] () – C:\Documents and Settings\Owner\My Documents\ElectronicBanking_ADB2426.pdf
[2010/01/10 14:54:41 | 00,002,162 | —- | C] () – C:\WINDOWS\Sandboxie.ini
[2010/01/05 16:01:04 | 00,000,812 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Paint.NET.lnk
[2010/01/05 15:44:12 | 00,113,108 | —- | C] () – C:\Documents and Settings\Owner\My Documents\BMI Calculation.pdf
[2010/01/05 10:10:10 | 00,160,217 | —- | C] () – C:\WINDOWS\System32\PowerToysLicense.rtf
[2010/01/04 18:36:53 | 00,000,670 | —- | C] () – C:\Documents and Settings\Owner\Desktop\DVD Shrink 3.2.lnk
[2010/01/04 18:32:18 | 00,001,512 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Recuva.lnk
[2010/01/04 03:25:25 | 00,005,274 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20100104_032522.reg
[2010/01/04 02:17:41 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/01/03 20:01:40 | 00,000,495 | —- | C] () – C:\WINDOWS\cfplogvw.INI
[2010/01/03 19:27:51 | 00,000,870 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20100103_192749.reg
[2010/01/01 09:47:45 | 00,000,688 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20100101_094144.reg
[2009/12/28 23:21:17 | 00,003,044 | —- | C] () – C:\Documents and Settings\Owner\My Documents\cc_20091228_232114.reg
[2009/12/17 12:58:46 | 00,029,184 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/11 12:04:25 | 00,068,728 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/12/11 07:52:48 | 00,000,232 | —- | C] () – C:\WINDOWS\reimage.ini
[2009/12/05 22:52:42 | 12,201,984 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sandra.mda

========== LOP Check ==========

[2010/01/19 16:42:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/01/25 02:33:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/01 12:41:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/01/27 03:29:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Auslogics
[2010/01/19 16:42:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canneverbe_Limited
[2009/12/11 17:58:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/01/05 01:11:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ImgBurn
[2009/12/04 19:25:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IObit
[2010/01/27 15:48:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MailWasherFree
[2009/12/09 15:29:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2009/11/29 21:02:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Transcend
[2009/12/11 08:17:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uniblue
[2010/01/27 12:33:46 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/01/27 20:13:38 | 00,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{42CFC73D-77FB-4A38-8871-5C2A3B534A4F}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 20:00:00 | 18,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/11/30 01:16:43 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/11/30 01:16:43 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 04:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 04:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/14 04:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 20:00:00 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/04 20:00:00 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\backup\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 20:00:00 | 18,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/11/30 01:16:43 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/11/30 01:16:43 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 04:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 04:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 04:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 20:00:00 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 20:00:00 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\backup\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 10:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 10:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 10:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 20:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2004/08/04 20:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\backup\eventlog.dll

< MD5 for: IASTOR.SYS >
[2006/02/22 08:44:30 | 00,250,368 | —- | M] (Intel Corporation) MD5=88B1943ECFF661F765228099138CF6AB – C:\WINDOWS\dell\iastor\iastor.sys
[2005/06/17 07:33:40 | 00,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\DELL\drivers\R104931\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 10:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 10:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 10:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2009/02/07 04:46:09 | 00,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/07 04:46:09 | 00,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 20:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2004/08/04 20:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\backup\netlogon.dll
[2004/08/04 20:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\SoftwareDistribution\Download\3a2773ed0185d9cc0572da01353f3b98\backup\sp2qfe\netlogon.dll
[2004/08/04 20:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\SoftwareDistribution\Download\8cb3a5dc2e5ce55afbfdfd38e49058d5\backup\sp2qfe\netlogon.dll

< MD5 for: NVATABUS.SYS >
[2006/03/17 10:51:32 | 00,099,840 | —- | M] (NVIDIA Corporation) MD5=B7FB72492B753930EC70A0F49D04F12F – C:\WINDOWS\dell\nvraid\NvAtaBus.sys
[2006/03/17 10:51:32 | 00,099,840 | —- | M] (NVIDIA Corporation) MD5=B7FB72492B753930EC70A0F49D04F12F – C:\WINDOWS\system32\drivers\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 20:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2004/08/04 20:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\backup\scecli.dll
[2008/04/14 10:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 10:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 10:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\Desktop\vengine.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\Desktop\CIS_Setup_3.13.125662.579_XP_Vista_x32.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\Desktop\2j7vxcyy.exe:SummaryInformation
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >







———————————————————————————————————









OTL Extras logfile created on: 1/27/2010 8:08:09 PM - Run 1
OTL by OldTimer - Version 3.1.27.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 61.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 3057 3057 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.71 Gb Total Space | 18.97 Gb Free Space | 35.99% Space Free | Partition Type: NTFS
Drive D: | 18.61 Gb Total Space | 17.68 Gb Free Space | 95.00% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BEDROOM
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 18
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F77F6EE-2C99-49F7-940A-2E9C208C3BE1}" = Paint.NET v3.5.2
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{597E70FF-7C46-4EED-8092-91B7C2E0529D}" = Google SketchUp 7
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 4.1
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2009.10.22
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"AC3ACM" = AC-3 ACM Codec
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ares" = Ares 2.1.2
"avast!" = avast! Antivirus
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"CodeStuff Starter" = CodeStuff Starter
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DVD Shrink_is1" = DVD Shrink 3.2
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"MailWasher Free_is1" = MailWasher Free 6.5.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"PokerStars" = PokerStars
"PROSet" = Intel® PRO Network Connections Drivers
"Recuva" = Recuva
"Sandboxie" = Sandboxie 3.42
"Secunia PSI" = Secunia PSI
"ShrinkTo5Basic" = ShrinkTo5Basic
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SpywareGuard_is1" = SpywareGuard v2.2
"Tweak UI 2.10" = Tweak UI
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/18/2010 6:51:14 PM | Computer Name = BEDROOM | Source = Google Update | ID = 20
Description =

Error - 1/18/2010 6:57:57 PM | Computer Name = BEDROOM | Source = Google Update | ID = 20
Description =

Error - 1/18/2010 7:51:14 PM | Computer Name = BEDROOM | Source = Google Update | ID = 20
Description =

Error - 1/18/2010 7:57:57 PM | Computer Name = BEDROOM | Source = Google Update | ID = 20
Description =

Error - 1/18/2010 8:53:14 PM | Computer Name = BEDROOM | Source = Google Update | ID = 20
Description =

Error - 1/18/2010 8:59:55 PM | Computer Name = BEDROOM | Source = Google Update | ID = 20
Description =

Error - 1/22/2010 4:14:36 AM | Computer Name = BEDROOM | Source = Application Error | ID = 1000
Description = Faulting application cas32.exe, version 2.7.0.0, faulting module kernel32.dll,
version 5.1.2600.5781, fault address 0x00009e32.

Error - 1/22/2010 4:14:48 AM | Computer Name = BEDROOM | Source = Application Error | ID = 1001
Description = Fault bucket 1535861697.

Error - 1/23/2010 6:56:21 AM | Computer Name = BEDROOM | Source = Application Error | ID = 1000
Description = Faulting application cas32.exe, version 2.7.0.0, faulting module msvcr80.dll,
version 8.0.50727.4053, fault address 0x000144dc.

Error - 1/23/2010 6:56:29 AM | Computer Name = BEDROOM | Source = Application Error | ID = 1001
Description = Fault bucket 1541613555.

[ System Events ]
Error - 1/26/2010 8:11:12 AM | Computer Name = BEDROOM | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSP Fips intelppm

Error - 1/26/2010 10:54:54 AM | Computer Name = BEDROOM | Source = Service Control Manager | ID = 7031
Description = The Windows Defender service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 15000 milliseconds:
Restart the service.

Error - 1/26/2010 10:57:15 AM | Computer Name = BEDROOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/26/2010 1:12:03 PM | Computer Name = BEDROOM | Source = Service Control Manager | ID = 7031
Description = The Windows Defender service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 15000 milliseconds:
Restart the service.

Error - 1/26/2010 1:12:03 PM | Computer Name = BEDROOM | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 1/26/2010 1:12:03 PM | Computer Name = BEDROOM | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 1/26/2010 1:12:03 PM | Computer Name = BEDROOM | Source = Service Control Manager | ID = 7034
Description = The Sandboxie Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 1/26/2010 1:12:03 PM | Computer Name = BEDROOM | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 1/26/2010 1:12:03 PM | Computer Name = BEDROOM | Source = Service Control Manager | ID = 7034
Description = The NMSAccessU service terminated unexpectedly. It has done this
1 time(s).

Error - 1/26/2010 10:58:53 PM | Computer Name = BEDROOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gusvc with
arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}


< End of report >


:thumbup:
Hi,

  • Open Malwarebytes.
  • Click on the Update tab.
  • Click Check for Updates button.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
–Next–

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
To post in your next reply:
1. MBAM log.
2. Kaspersky log.

To post in your next reply:
1. MBAM log.
2. Kaspersky log

Malwarebytes' Anti-Malware 1.44
Database version: 3657
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/29/2010 10:03:06 PM
mbam-log-2010-01-29 (22-03-06).txt

Scan type: Quick Scan
Objects scanned: 108770
Time elapsed: 3 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, January 30, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Friday, January 29, 2010 11:35:13
Records in database: 3384188
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Objects scanned: 42414
Threats found: 0
Infected objects found: 0
Suspicious objects found: 0
Scan duration: 00:40:53

No threats found. Scanned area is clean.

Selected area has been scanned.
Hi,

It would seem that no more malware is residing in your computer. It would be best if you could create a new topic at the Microsoft Windows section of the forum.
Please read this article before creating a new topic as it would greatly help our Tech Team in determining your problem. Also, please provide a link to your new topic back here in order for the team there to review your logs. Thank you.

–Next–

Please delete DDS, GMER and all the logs we've created.

–Next–

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
–Next–

You need to create a new Clean restore point.
Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

–Next–

To keep your operating system up to date visit
  • Secunia Software inspector to check your program update status.
  • Microsoft Windows Update .

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

6. SpywareBlaster - Download and install SpywareBlaster. This program prevents the installation of ActiveX-based spyware and other potentially unwanted programs.

7. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

8. Some excellent free firewalls. Note: Use only one firewall at a time.
Agnitum Outpost Firewall
Comodo Firewall - If you are installing this and already have an anti spyware then please do not install Comodo's anti spyware program.
Online Armor Personal Firewall

9. And finally, please read these excellent articles:
Malware: Help prevent the Infection by Sandi Hardmeier,
Preventing Malware - Tools and Practices for Safe Computing

For more safe computing tips please read the guide by Rorschach112 on how to prevent malware and about safe computing here.



Good luck, happy computing and stay clean! ^_^
Hi inzanity :wavey:

Before I can create a new topic, I just need to clarify a few things 1st. :scratch:

It would seem that no more malware is residing in your computer. It would be best if you could create a new topic at the Microsoft Windows section of the forum.
Please read this article before creating a new topic as it would greatly help our Tech Team in determining your problem. Also, please provide a link to your new topic back here in order for the team there to review your logs. Thank you.

Are you referring to:
  • "Stop 0x00000024 or NTFS_FILE_SYSTEM", or
  • Just a note: I have had problems with firefox.exe still running in the Task Manager after closing the browser.(CPU Usage runs at 100%)
    Maybe a conflict between add-ons ? headscratch.gif I have not yet run it with no add-ons blush.gif though for some reason I did completely lose No-Script the other day. mad.gif
    Had to reinstall it. wacko.gif
    And as I type this, Google is telling me this page is in Danish. Translate it using Google Toolbar? wacko.gif Go figure… huh.gif

  • or did you notice some other non-malware related problems? :blush:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Can I post a fresh HJT Log for a reference(regarding my new topic), or

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<



I have followed the advice listed below:

  • You need to create a new Clean restore point.
  • Remove all previous Restore Points
  • Hide file extensions for known file types."
  • Uncheck "Show hidden files and folders."
  • Check "Hide protected operating system files."


    To keep my operating system up to date:
  • Secunia Software inspector to check your program update status.
  • Microsoft Windows Update .
  • Make your Internet Explorer More Secure
  • Update your Anti-Virus Software
  • Make sure you keep your Windows OS current
  • MVPS HOSTS.(fixed by disable the DNS Client,etc.. ) :blush:
  • Download and install the free version of WinPatrol. :thumbup:
  • SpywareBlaster (updated)
  • SandboxIE.(Need to read the Getting Started guide on their website, again) :blush:
  • Installed Online Armor Personal Firewall :thumbup:


Thanks for your help. :)




Jkc73 ;)
Hi,

Let's try setting IE as the default browser for now. To do this:
  • Click on Start then Control Panel.
  • Double click on Internet Options to open it.
  • Click on Programs tab then under "Default web browser", click Make default button.
  • Clikc OK.
–Next–

Reboot your computer. Upon logging back in, check if IE loads or if the process is duplicated in the Task Manager.

–Next–

Please do the following:
  • Click on Start then Run.
  • Copy and paste the following command (except the word "QUOTE") into the run box and click OK.

    regedit /e C:\RegLook.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components"

  • A text file named RegLook.txt will be created in C:\. Post the contents in your next reply.
To post in your next reply:
1. Has IE loaded upon reboot? Is the process duplicated in the Task Manager?
2. RegLook.txt
  • 📎iexplore_duplicated.JPG

  • Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
    @="Internet Explorer Version Update"
    "ComponentID"="IEUDINIT"
    "DontAsk"=dword:00000002
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "StubPath"="C:\\WINDOWS\\system32\\ieudinit.exe"
    "Version"="8,0,6001,0"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    "DontAsk"=dword:00000002
    "Version"="11,0,5721,5145"
    "IsInstalled"=dword:00000000
    "Stubpath"="C:\\WINDOWS\\inf\\unregmp2.exe /ShowWMP"
    @="Windows Media Player"
    "ComponentID"="WMPACCESS"
    "Locale"="*"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    @="Internet Explorer"
    "ComponentID"="IEACCESS"
    "Dontask"=dword:00000002
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "StubPath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\
    74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
    00,68,00,6d,00,67,00,72,00,61,00,74,00,65,00,2e,00,65,00,78,00,65,00,20,00,\
    4f,00,43,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,55,00,73,00,65,00,72,\
    00,43,00,6f,00,6e,00,66,00,69,00,67,00,49,00,45,00,00,00
    "Version"="2,0,0,0"
    "LocalizedName"="@C:\\WINDOWS\\system32\\ie4uinit.exe.mui,-21"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    @="Browser Customizations"
    "ComponentiD"="BRANDING.CAB"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "LocalizedName"="@C:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3052"
    "StubPath"="\"C:\\WINDOWS\\system32\\rundll32.exe\" \"C:\\WINDOWS\\system32\\iedkcs32.dll\",BrandIEActiveSetup SIGNUP"
    "Version"="8,0,6001,18702"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    @="Browser Customizations"
    "ComponentID"="BRANDING.CAB"
    "StubPath"="RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP"
    "Version"="6,0,2900,2180"
    "Locale"="*"
    "IsInstalled"=dword:00000001

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    @="Outlook Express"
    "ComponentID"="OEACCESS"
    "Dontask"=dword:00000002
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "StubPath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\
    74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
    00,68,00,6d,00,67,00,72,00,61,00,74,00,65,00,2e,00,65,00,78,00,65,00,20,00,\
    4f,00,43,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,55,00,73,00,65,00,72,\
    00,43,00,6f,00,6e,00,66,00,69,00,67,00,4f,00,45,00,00,00
    "Version"="2,0,0,0"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
    @="Java (Sun)"
    "ComponentID"="JAVAVM"
    "IsInstalled"=dword:00000001
    "KeyFileName"="C:\\Program Files\\Java\\jre6\\bin\\regutils.dll"
    "Version"="5,0,5000,0"
    "Locale"="EN"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
    @="Vector Graphics Rendering (VML)"
    "ComponentID"="MSVML"
    "Version"="6,0,2462,0001"
    "IsInstalled"=hex:01,00,00,00
    "Locale"="EN"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
    @=""
    "ComponentID"="NetShow"
    "IsInstalled"=dword:00000001
    "DontAsk"=dword:00000002
    "Locale"="EN"
    "StubPath"=""
    "Version"="11,0,5721,5145"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    "ComponentID"="Microsoft Windows Media Player"
    "DontAsk"=dword:00000002
    "Locale"="ENU"
    "StubPath"=""
    "IsInstalled"=dword:00000001
    @="Microsoft Windows Media Player 6.4"
    "Version"="11,0,5721,5145"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
    @="DirectAnimation"
    "IsInstalled"=dword:00000001
    "Version"="6,0,3,531"
    "Locale"="EN"
    "ComponentID"="DirectAnimation"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    @="Themes Setup"
    "ComponentID"="Theme Component"
    "IsInstalled"=dword:00000001
    "Locale"="EN"
    "StubPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
    74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,72,\
    00,65,00,67,00,73,00,76,00,72,00,33,00,32,00,2e,00,65,00,78,00,65,00,20,00,\
    2f,00,73,00,20,00,2f,00,6e,00,20,00,2f,00,69,00,3a,00,2f,00,55,00,73,00,65,\
    00,72,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,20,00,25,00,53,00,79,00,\
    73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,\
    00,74,00,65,00,6d,00,33,00,32,00,5c,00,74,00,68,00,65,00,6d,00,65,00,75,00,\
    69,00,2e,00,64,00,6c,00,6c,00,00,00
    "Version"="1,1,1,7"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
    @="Dynamic HTML Data Binding for Java"
    "ComponentID"="TridataJava"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="4,7,0,0320"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}]
    "Version"="8,0,6001,18702"
    @="Offline Browsing Pack"
    "ComponentID"="MobilePk"
    "IsInstalled"=dword:00000001
    "Locale"="*"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
    @="Uniscribe"
    "ComponentID"="USP10"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="1,397,2406,1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4278c270-a269-11d1-b5bf-0000f8051515}]
    @="Advanced Authoring"
    "ComponentID"="AdvAuth"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="6,0,2900,2180"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    "Version"="6,0,2900,5512"
    @="Microsoft Outlook Express 6"
    "IsInstalled"=dword:00000001
    "Locale"="EN"
    "ComponentID"="MailNews"
    "CloneUser"=dword:00000001
    "StubPath"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,\
    69,00,6c,00,65,00,73,00,25,00,5c,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,\
    00,20,00,45,00,78,00,70,00,72,00,65,00,73,00,73,00,5c,00,73,00,65,00,74,00,\
    75,00,70,00,35,00,30,00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,41,00,50,\
    00,50,00,3a,00,4f,00,45,00,20,00,2f,00,43,00,41,00,4c,00,4c,00,45,00,52,00,\
    3a,00,57,00,49,00,4e,00,4e,00,54,00,20,00,2f,00,75,00,73,00,65,00,72,00,20,\
    00,2f,00,69,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,00,00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    @="NetMeeting 3.01"
    "ComponentID"="NetMeeting"
    "IsInstalled"=hex:01,00,00,00
    "Version"="4,4,0,3400"
    "Locale"="EN"
    "StubPath"="rundll32.exe advpack.dll,LaunchINFSection C:\\WINDOWS\\INF\\msnetmtg.inf,NetMtg.Install.PerUser.NT"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
    @="DirectShow"
    "ComponentID"="activemovie"
    "IsInstalled"=dword:00000001
    "DontAsk"=dword:00000002
    "Locale"="EN"
    "Version"="11,0,5721,5145"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
    @="DirectDrawEx"
    "ComponentID"="DirectDrawEx"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="4,71,1113,0"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
    @="Internet Explorer Help"
    "ComponentID"="HelpCont"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="8,0,6001,18702"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
    @="DirectAnimation Java Classes"
    "ComponentID"="DAJava"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="6,00,01,0223"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
    @="Microsoft Windows Script 5.6"
    "ComponentID"="MSVBScript"
    "IsInstalled"=dword:00000001
    "Locale"="EN"
    "Version"="5,6,0,8820"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}]
    @="Security Update for Windows XP (KB923789)"
    "IsInstalled"=dword:00000001
    "Version"="6,0,88,0"
    "ComponentID"="KB923789"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    @="Windows Messenger 4.7"
    "ComponentID"="Messenger"
    "StubPath"="rundll32.exe advpack.dll,LaunchINFSection C:\\WINDOWS\\INF\\msmsgs.inf,BLC.QuietInstall.PerUser"
    "Locale"="EN"
    "Version"="4,7,0,3000"
    "IsInstalled"=dword:00000001
    "KeyFileName"="C:\\Program Files\\Messenger\\msmsgs.exe"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
    "(Default)"="Internet Connection Wizard"
    "ComponentID"="ICW"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="5,00,2918,1900"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
    @="Internet Explorer Setup Tools"
    "ComponentID"="GenSetup"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="8,0,6001,18702"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
    "Version"="8,0,6001,18702"
    @="Browsing Enhancements"
    "ComponentID"="ExtraPack"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "KeyFileName"="C:\\WINDOWS\\system32\\msieftp.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    @="Microsoft Windows Media Player"
    "ComponentID"="Microsoft Windows Media Player"
    "DontAsk"=dword:00000002
    "Locale"="ENU"
    "StubPath"="rundll32.exe advpack.dll,LaunchINFSection C:\\WINDOWS\\INF\\wmp11.inf,PerUserStub"
    "IsInstalled"=dword:00000001
    "Version"="11,0,5721,5145"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
    @="MSN Site Access"
    "ComponentID"="MSN_Auth"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="4,9,9,2"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
    "ComponentID"=".NETFramework"
    @=".NET Framework"
    "Locale"=""
    "Version"="2,0,50727,0"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    "Version"="6,0,2900,5512"
    @="Address Book 6"
    "IsInstalled"=dword:00000001
    "Locale"="EN"
    "ComponentID"="WAB"
    "StubPath"=hex(2):22,00,25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,\
    69,00,6c,00,65,00,73,00,25,00,5c,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,\
    00,20,00,45,00,78,00,70,00,72,00,65,00,73,00,73,00,5c,00,73,00,65,00,74,00,\
    75,00,70,00,35,00,30,00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,00,41,00,50,\
    00,50,00,3a,00,57,00,41,00,42,00,20,00,2f,00,43,00,41,00,4c,00,4c,00,45,00,\
    52,00,3a,00,57,00,49,00,4e,00,4e,00,54,00,20,00,2f,00,75,00,73,00,65,00,72,\
    00,20,00,2f,00,69,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,00,00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    "Version"="6,0,2900,2180"
    @="Windows Desktop Update"
    "ComponentID"="IE4Shell_NT"
    "IsInstalled"=dword:00000001
    "Locale"="en"
    "StubPath"=hex(2):72,00,65,00,67,00,73,00,76,00,72,00,33,00,32,00,2e,00,65,00,\
    78,00,65,00,20,00,2f,00,73,00,20,00,2f,00,6e,00,20,00,2f,00,69,00,3a,00,55,\
    00,20,00,73,00,68,00,65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,\
    00,00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    "Version"="8,0,6001,18702"
    @="Internet Explorer"
    "ComponentID"="BASEIE40_W2K"
    "IsInstalled"=dword:00000001
    "Locale"="en"
    "StubPath"="C:\\WINDOWS\\system32\\ie4uinit.exe -BaseSettings"
    "LocalizedName"="@C:\\WINDOWS\\system32\\ie4uinit.exe.mui,-20"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}\AuthorizedCDFPrefix]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    "DontAsk"=dword:00000002
    "StubPath"="c:\\WINDOWS\\system32\\Rundll32.exe c:\\WINDOWS\\system32\\mscories.dll,Install"
    "IsInstalled"=dword:00000001
    "ComponentID"="DOTNETFRAMEWORKS"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
    @="Dynamic HTML Data Binding"
    "ComponentID"="Tridata"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="8,0,6001,18702"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
    "Locale"=""
    "Version"="2,0,50727,0"
    "ComponentID"=".NETFramework"
    @=".NET Framework"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}]
    @="Internet Explorer Core Fonts"
    "ComponentID"="Fontcore"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="8,0,6001,18702"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
    @="Task Scheduler"
    "ComponentID"="MSTASK"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="4,71,1968,1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
    "ComponentID"="Windows Movie Maker v2.1"
    "IsInstalled"=hex:01,00,00,00
    "Version"="2,1,4026,0"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @="Adobe Flash Player"
    "ComponentID"="Flash"
    "IsInstalled"=hex:01,00,00,00
    "Version"="10.0.42.34"
    "Locale"="EN"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
    @="HTML Help"
    "ComponentID"="HTMLHelp"
    "IsInstalled"=dword:00000001
    "Locale"="*"
    "Version"="6,0,6001,18702"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
    @="Active Directory Service Interface"
    "ComponentID"="ADSI"
    "IsInstalled"=hex:01,00,00,00
    "Locale"="EN"
    "Version"="5,0,00,0"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI