This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] A:jgh exe

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I Runned OTL and GMer, here are the results:

OTL

OTL logfile created on: 2010/02/15 05:13:42 p.m. - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\bs0715\My Documents\Descargas
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000080A | Country: Mexico | Language: ESM | Date Format: yyyy/MM/dd

1,015.00 Mb Total Physical Memory | 270.00 Mb Available Physical Memory | 27.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 37.48 Gb Free Space | 50.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 971.61 Mb Total Space | 665.78 Mb Free Space | 68.52% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CNU7450MCC
Current User Name: gilcota.m
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\bs0715\My Documents\Descargas\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\eBoostr\eBoostrCP.exe (eBoostr.com)
PRC - C:\Program Files\eBoostr\EBstrSvc.exe (eBoostr.com)
PRC - C:\Documents and Settings\bs0715\Local Settings\Temp\Jgh.exe ()
PRC - C:\Documents and Settings\bs0715\Local Settings\Apps\2.0\TRJZ9Z5O.A9Z\D4EJHYXZ.VT8\mygb..tion_2d5cbbe57c5571c9_0001.0006_e7d4b949681440da\myGBP.exe (Procter and Gamble)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\marimba\Castanet Tuner\lib\minituner.exe (BMC Software, Inc.)
PRC - C:\Program Files\marimba\Castanet Tuner\Tuner.exe (BMC Software, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\NlsSrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files\Pointsec\Pointsec for PC\P95tray.exe (Check Point Software Tech Ltd)
PRC - C:\WINDOWS\system32\pstartSr.exe ()
PRC - C:\WINDOWS\system32\Prot_srv.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\JobTrigger.exe (Hewlett Packard)
PRC - C:\Program Files\ISS\Proventia Desktop\blackice.exe (Internet Security Systems, Inc.)
PRC - C:\Program Files\ISS\Proventia Desktop\blackd.exe (Internet Security Systems, Inc.)
PRC - C:\Program Files\ISS\Proventia Desktop\RapApp.exe (Internet Security Systems, Inc.)
PRC - C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe (Internet Security Systems, Inc.)
PRC - C:\Program Files\ISS\Proventia Desktop\vpatch.exe (Internet Security Systems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\eSupport\eSupport.exe ( )
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
PRC - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe (iPass, Inc.)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - c:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - c:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ntvdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\EXECUSER.EXE ()
PRC - C:\WINDOWS\system32\WinPwdHelper.exe ()
PRC - C:\Program Files\Firebird\bin\ibguard.exe (FirebirdSQL Project)
PRC - C:\Program Files\Firebird\bin\ibserver.exe (FirebirdSQL Project)
PRC - C:\Program Files\Altiris\eXpress\NS Client\AeXSWDUsr.exe (Altiris)
PRC - C:\Program Files\Altiris\eXpress\NS Client\AeXNSClient.exe (Altiris)
PRC - C:\Program Files\Altiris\eXpress\NS Client\AeXNSClientTransport.exe (Altiris)
PRC - C:\WINDOWS\system32\nwtray.exe (Novell, Inc.)
PRC - C:\Program Files\Qcard\QCnotify.exe (Usability Sciences Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\bs0715\My Documents\Descargas\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\AeXPrcssAppInitNT.dll (Altiris Inc.)
MOD - C:\Program Files\Qcard\QCDLL32.DLL (Usability Sciences Corp.)


========== Win32 Services (SafeList) ==========

SRV - (VPatch) – File not found
SRV - (RapApp) – File not found
SRV - (BlackICE) – File not found
SRV - (EBOOSTRSVC) – C:\Program Files\eBoostr\EBstrSvc.exe (eBoostr.com)
SRV - (SSHNAS) – C:\WINDOWS\system32\sshnas21.dll ()
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (workspace) – C:\Program Files\marimba\Castanet Tuner\Tuner.exe (BMC Software, Inc.)
SRV - (nlsX86cc) – C:\WINDOWS\system32\NlsSrv32.exe (Nalpeiron Ltd.)
SRV - (Pointsec_start) – C:\WINDOWS\system32\pstartSr.exe ()
SRV - (Pointsec) – C:\WINDOWS\system32\Prot_srv.exe ()
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (JobTrigger) – C:\WINDOWS\system32\JobTrigger.exe (Hewlett Packard)
SRV - (hpqwmiex) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZIPM12.DLL (Hewlett-Packard)
SRV - (btwdins) – c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (iPassConnectEngine) – C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateApp) – C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateService) – C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe (iPass, Inc.)
SRV - (cusrvc) – C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
SRV - (SavRoam) – c:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – c:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – c:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (SPBBCSvc) – c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)
SRV - (SNDSrvc) – c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (WinPwdReset) – C:\WINDOWS\System32\WinPwdHelper.exe ()
SRV - (ose) – c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (AeXNSClient) – C:\Program Files\Altiris\eXpress\NS Client\AeXNSClient.exe (Altiris)
SRV - (AeXNSClientTransport) – C:\Program Files\Altiris\eXpress\NS Client\AeXNSClientTransport.exe (Altiris)


========== Driver Services (SafeList) ==========

DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\eengine\eeCtrl.sys (Symantec Corporation)
DRV - (iPassP) iPass Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\iPassP.sys (Meetinghouse Data Communications)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100210.004\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100210.004\NAVENG.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eBoost) – C:\WINDOWS\system32\drivers\eBoost.sys (eBoostr.com)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (prot_2k) – C:\WINDOWS\system32\drivers\prot_2k.sys ()
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (black) – C:\WINDOWS\system32\drivers\Blackcat.sys (Internet Security Systems, Inc.)
DRV - (MakoNT) – C:\WINDOWS\system32\drivers\isskboep.sys (Internet Security Systems Inc.)
DRV - (rap) – C:\WINDOWS\system32\drivers\RapDrv.sys (Internet Security Systems, Inc.)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (KR10I) – C:\WINDOWS\system32\DRIVERS\KR10I.sys (TOSHIBA CORPORATION)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (HpqKbFiltr) – C:\WINDOWS\system32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (vmscsi) – C:\WINDOWS\system32\DRIVERS\vmscsi.sys (VMware, Inc.)
DRV - (Eacfilt) – C:\WINDOWS\system32\drivers\eacfilt.sys (Nortel Networks)
DRV - (IPSECSHM) – C:\WINDOWS\system32\drivers\ipsecw2k.sys (Nortel Networks NA, Inc.)
DRV - (IPSECEXT) – C:\WINDOWS\system32\drivers\ipsecw2k.sys (Nortel Networks NA, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (IFXTPM) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (ADIHdAudAddService) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (NetwareWorkstation) – C:\WINDOWS\system32\NetWare\nwfs.sys (Novell, Inc.)
DRV - (wceusbsh) – C:\WINDOWS\system32\drivers\wceusbsh.sys (Microsoft Corporation)
DRV - (NWDNS) – C:\WINDOWS\system32\NetWare\nwdns.sys (Novell, Inc.)
DRV - (SRVLOC) – C:\WINDOWS\system32\NetWare\srvloc.sys (Novell, Inc.)
DRV - (AEAudio) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (Accelerometer) – C:\WINDOWS\system32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (hpdskflt) – C:\WINDOWS\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (megasas) – C:\WINDOWS\system32\DRIVERS\megasas.sys (LSI Logic Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (AES2500) – C:\WINDOWS\system32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (NICM) – C:\WINDOWS\system32\drivers\nicm.sys (Novell, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SAVRTPEL) – c:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – c:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (NWDHCP) – C:\WINDOWS\system32\NetWare\nwdhcp.sys (Novell, Inc.)
DRV - (Symmpi) – C:\WINDOWS\system32\DRIVERS\symmpi.sys (LSI Logic)
DRV - (NWSIPX32) – C:\WINDOWS\system32\NetWare\nwsipx32.sys (Novell, Inc.)
DRV - (NWHOST) – C:\WINDOWS\system32\NetWare\nwhost.sys (Novell, Inc.)
DRV - (NWSNS) – C:\WINDOWS\system32\NetWare\nwsns.sys (Novell, Inc.)
DRV - (NWFILTER) – C:\WINDOWS\system32\NetWare\nwfilter.sys (Novell, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (NWSLP) – C:\WINDOWS\system32\NetWare\nwslp.sys (Novell, Inc.)
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (RESMGR) – C:\WINDOWS\system32\NetWare\resmgr.sys (Novell, Inc.)
DRV - (NWSAP) – C:\WINDOWS\system32\NetWare\nwsap.sys ()
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.pg.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.pg.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://dc.pg.com/portal/server.pt?open=512…amp;cached=true
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://dc.pg.com/portal/server.pt?open=512&objID;=368&mode;=2∈_hi_userid=41395&cached;=true"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:1.4.5.1
FF - prefs.js..network.proxy.autoconfig_url: "http://autoproxy.pg.com:8080/"
FF - prefs.js..network.proxy.http: "http://autoproxy.pg.com:8080"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.type: 2

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/04 10:42:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/05 09:24:37 | 000,000,000 | —D | M]

[2010/02/04 10:43:26 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\Mozilla\Extensions
[2010/02/14 20:24:51 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\Mozilla\Firefox\Profiles\2adxesw2.default\extensions
[2010/02/05 10:43:06 | 000,000,000 | —D | M] (IE View) – C:\Documents and Settings\bs0715\Application Data\Mozilla\Firefox\Profiles\2adxesw2.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010/02/08 11:25:14 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\bs0715\Application Data\Mozilla\Firefox\Profiles\2adxesw2.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/02/14 15:26:01 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/02/08 11:25:24 | 000,002,204 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/01/15 19:30:43 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-es.xml
[2010/01/15 19:30:43 | 000,000,798 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-mx.xml

O1 HOSTS File: ([2001/08/23 00:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (APHelper Class) - {08C63920-DC18-11D2-9E1E-00A0247061AB} - C:\Program Files\Internet Explorer\Autopass\APHelper.dll (Hewlett-Packard Co.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [ExecUser] C:\WINDOWS\System32\ExecUser.exe ()
O4 - HKLM..\Run: [Firebird] C:\Program Files\Firebird\bin\ibguard.exe (FirebirdSQL Project)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\IMKR6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NWTRAY] C:\WINDOWS\System32\nwtray.exe (Novell, Inc.)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Pointsec Tray] c:\Program Files\Pointsec\Pointsec for PC\P95tray.exe (Check Point Software Tech Ltd)
O4 - HKLM..\Run: [QlbCtrl] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TuneUp] C:\WINDOWS\System32\TuneUp\TuneUp.exe (HP)
O4 - HKLM..\Run: [vptray] c:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKCU..\Run: [COMMUNICATOR] C:\Program Files\Microsoft Office Communicator\Communicator.exe (Microsoft Corporation)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\Wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [TOY5KNQ8OC] C:\Documents and Settings\bs0715\Local Settings\Temp\Jgh.exe ()
O4 - HKCU..\Run: [TuneUp] C:\WINDOWS\System32\TuneUp\TuneUp.exe (HP)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe (eBoostr.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Proventia Desktop Agent.lnk = C:\Program Files\ISS\Proventia Desktop\blackice.exe (Internet Security Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QC Notifier.lnk = C:\Program Files\Qcard\QCnotify.exe (Usability Sciences Corp.)
O4 - Startup: C:\Documents and Settings\bs0715\Start Menu\Programs\Startup\myGBP.appref-ms ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 1
O8 - Extra context menu item: Send to &Bluetooth; Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: @shdoclc.dll,-866@1033,Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864@1033,Show &Related; Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - Reg Error: Value error. File not found
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\NetWare\nwws2nds.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\WINDOWS\system32\NetWare\nwws2sap.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\WINDOWS\system32\NetWare\nwws2slp.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: gillette.com ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: gillette.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: gillette.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: pg.com ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: pg.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: pg.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: wella.com ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: wella.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: wella.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: gillette.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: gillette.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: gillette.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: pg.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: pg.com ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: pg.com ([]https in Local intranet)
O15 - HKCU\..Trusted Domains: wella.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: wella.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: wella.com ([]https in Trusted sites)
O16 - DPF: {00100000-2004-0003-85AA-828F11E00F28} Reg Error: Key error. (Reg Error: Value error.)
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} http://download.macromedia.com/pub/shockwa…are/awswaxf.cab (Macromedia Authorware Web Player Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {86DCCE9E-E6A3-48B4-BA36-500638B8C5DD} http://pctradeup.pg.com/PCTradeup/SEWPAssessment.CAB (SEWPAssessment.Assessment)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {C3CBFE35-9BE8-11D1-B31B-006008948294} http://www.timevision.com/codebase30/OrgPubX.cab (OrgPublisher PluginX)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Oracle Sales Analyzer 6,4,0 Patch 6 http://osaweb_nala_mdo3.internal.pg.com/os…java/osa640.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = na.pg.com
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP AG, Walldorf)
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP AG, Walldorf)
O20 - AppInit_DLLs: (AeXPrcssAppInitNT.dll) - C:\WINDOWS\System32\AeXPrcssAppInitNT.dll (Altiris Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (NWGINA.DLL) - C:\WINDOWS\System32\nwgina.dll (Novell, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - c:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\bs0715\Desktop\Fondo de escritorio.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\bs0715\Desktop\Fondo de escritorio.bmp
O30 - LSA: Authentication Packages - (nwv1_0) - C:\WINDOWS\System32\nwv1_0.dll (Novell, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/21 16:10:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4cf9095f-1276-11df-a656-444553544200}\Shell\AutoRun\command - "" = AUTORUN\setup.exe
O33 - MountPoints2\{4cf9095f-1276-11df-a656-444553544200}\Shell\open\command - "" = AUTORUN\setup.exe
O33 - MountPoints2\{ccd9781d-1198-11df-a652-444553544200}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\application.exe – File not found
O33 - MountPoints2\{ccd9781d-1198-11df-a652-444553544200}\Shell\open\command - "" = F:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\application.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/02/15 16:41:06 | 000,000,000 | —D | C] – C:\Program Files\eBoostr
[2010/02/15 15:17:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\eboostr
[2010/02/15 10:37:02 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Desktop\Visuales
[2010/02/15 08:08:25 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Desktop\Shortcuts
[2010/02/13 19:58:01 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Media Player Classic
[2010/02/13 19:08:10 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\HighAndes
[2010/02/13 19:08:10 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\HighAndes
[2010/02/13 19:08:10 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\HighAndes
[2010/02/13 19:08:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HighAndes
[2010/02/13 18:58:19 | 000,014,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2010/02/13 18:55:19 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2010/02/13 18:55:19 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/02/13 18:53:41 | 000,061,440 | —- | C] (Nalpeiron Ltd.) – C:\WINDOWS\System32\NlsSrv32.exe
[2010/02/13 18:53:28 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Blue Cat Audio
[2010/02/13 18:52:46 | 000,000,000 | —D | C] – C:\Program Files\HighAndes
[2010/02/13 18:23:32 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\WMTools Downloaded Files
[2010/02/13 11:24:55 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2010/02/13 11:24:47 | 000,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2010/02/13 11:24:43 | 000,031,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2010/02/13 10:46:14 | 000,000,000 | —D | C] – C:\Program Files\PCB Wizard 3.50 Pro Unlimited
[2010/02/13 10:42:01 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\Labcenter Electronics
[2010/02/13 10:42:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Downloaded Data Sheets
[2010/02/13 10:40:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Labcenter Electronics
[2010/02/13 10:39:38 | 000,000,000 | —D | C] – C:\Program Files\Labcenter Electronics
[2010/02/12 12:16:50 | 000,389,120 | —- | C] (http://www.mp3dev.org/) – C:\WINDOWS\System32\lameACM.acm
[2010/02/12 12:16:49 | 000,217,088 | —- | C] (www.helixcommunity.org) – C:\WINDOWS\System32\yv12vfw.dll
[2010/02/12 12:16:49 | 000,118,784 | —- | C] (fccHandler) – C:\WINDOWS\System32\ac3acm.acm
[2010/02/12 12:16:47 | 000,081,920 | —- | C] (DivX, Inc.) – C:\WINDOWS\System32\dpl100.dll
[2010/02/12 12:16:46 | 000,739,840 | —- | C] (DivX, Inc.) – C:\WINDOWS\System32\divx.dll
[2010/02/12 12:16:42 | 000,000,000 | —D | C] – C:\Program Files\K-Lite Codec Pack
[2010/02/10 17:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\Help
[2010/02/10 17:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Help
[2010/02/09 09:59:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2010/02/09 09:57:41 | 000,139,264 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hpu4rtcp.dll
[2010/02/09 09:57:40 | 000,311,296 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hpu4pm.DLL
[2010/02/09 09:57:40 | 000,212,992 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hpu4mlui.DLL
[2010/02/09 09:57:40 | 000,131,072 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hpu4HSJA.DLL
[2010/02/09 09:57:40 | 000,049,152 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\fxcompchannel.dll
[2010/02/09 09:57:40 | 000,033,280 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPZIPR12.DLL
[2010/02/09 09:57:40 | 000,029,696 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPZIPT12.DLL
[2010/02/09 09:57:40 | 000,020,480 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPZISN12.DLL
[2010/02/09 09:57:39 | 000,053,248 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPZIPM12.DLL
[2010/02/09 09:57:39 | 000,049,252 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPMNQUE.DLL
[2010/02/09 09:57:39 | 000,049,250 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPMNNDPS.DLL
[2010/02/09 09:57:39 | 000,049,152 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPZIDR12.DLL
[2010/02/09 09:57:39 | 000,045,056 | —- | C] (HP) – C:\WINDOWS\System32\HPPAPTS0.DLL
[2010/02/09 09:57:39 | 000,043,520 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPZINW12.DLL
[2010/02/09 09:57:39 | 000,036,864 | —- | C] (HP) – C:\WINDOWS\System32\HPPASNM0.DLL
[2010/02/09 09:57:39 | 000,036,864 | —- | C] (HP) – C:\WINDOWS\System32\HPPAPML0.DLL
[2010/02/09 09:57:38 | 000,204,800 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPMCPMW.DLL
[2010/02/09 09:57:37 | 000,163,840 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPJCMN2U.DLL
[2010/02/09 09:57:37 | 000,094,208 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPJIPX1U.DLL
[2010/02/09 09:57:37 | 000,049,152 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPBNRAC2.DLL
[2010/02/09 09:57:37 | 000,039,424 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\HPBPRO.DLL
[2010/02/09 09:57:37 | 000,025,600 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\HPBOID.DLL
[2010/02/09 09:57:37 | 000,007,680 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\HPBPROPS.DLL
[2010/02/09 09:57:37 | 000,007,680 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\HPBOIDPS.DLL
[2010/02/09 09:57:36 | 000,241,721 | —- | C] (Hewlett-Packard) – C:\WINDOWS\System32\HPBMINI.DLL
[2010/02/09 09:57:36 | 000,024,576 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\HPBMIAPI.DLL
[2010/02/09 09:37:24 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\Identities
[2010/02/08 22:11:27 | 000,000,000 | —D | C] – C:\Program Files\Guitar Pro 5
[2010/02/08 11:25:11 | 000,000,000 | —D | C] – C:\Program Files\Babylon
[2010/02/08 09:18:34 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\myGBP
[2010/02/08 09:16:47 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\Deployment
[2010/02/08 00:05:24 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\Downloads
[2010/02/08 00:03:09 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/02/08 00:01:11 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\uTorrent
[2010/02/07 22:56:57 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\USB Backup
[2010/02/06 14:51:30 | 000,000,000 | —D | C] – C:\WINDOWS\lhsp
[2010/02/06 14:51:03 | 000,000,000 | —D | C] – C:\Program Files\TheLearningPit
[2010/02/06 14:49:41 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\WinRAR
[2010/02/06 08:43:23 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\CutePDF Writer
[2010/02/06 08:42:35 | 000,000,000 | —D | C] – C:\Program Files\GPLGS
[2010/02/06 08:33:52 | 000,000,000 | —D | C] – C:\Program Files\Acro Software
[2010/02/06 08:31:50 | 000,000,000 | —D | C] – C:\Program Files\Festo Fluidsim
[2010/02/05 13:11:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ESRI
[2010/02/05 12:23:11 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\My Received Files
[2010/02/05 09:03:42 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/02/05 09:01:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/02/05 09:01:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/02/05 09:01:07 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/02/05 09:01:06 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/02/05 09:01:06 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/02/05 09:01:06 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/02/05 09:01:06 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/02/05 08:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Sun
[2010/02/04 16:48:38 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2010/02/04 16:48:38 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usb8023x.sys
[2010/02/04 16:03:41 | 000,025,992 | —- | C] (Sysinternals - www.sysinternals.com) – C:\WINDOWS\System32\pgdfgsvc.exe
[2010/02/04 14:40:12 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\Descargas
[2010/02/04 14:21:05 | 000,000,000 | —D | C] – C:\Program Files\WebTracker
[2010/02/04 13:33:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\udx
[2010/02/04 13:23:50 | 001,048,576 | —- | C] (Blue Sky Software Corporation.) – C:\WINDOWS\System32\ROBOEX32.DLL
[2010/02/04 13:23:50 | 000,049,152 | —- | C] (Blue Sky Software Corporation.) – C:\WINDOWS\System32\INETWH32.DLL
[2010/02/04 13:23:44 | 000,000,000 | —D | C] – C:\Program Files\AClient
[2010/02/04 13:23:09 | 000,000,000 | —D | C] – C:\Program Files\jre6
[2010/02/04 13:22:49 | 000,000,000 | —D | C] – C:\Program Files\LDS Church
[2010/02/04 13:22:46 | 000,000,000 | -H-D | C] – C:\Program Files\Zero G Registry
[2010/02/04 13:22:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\bs0715\InstallAnywhere
[2010/02/04 12:27:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\WinMain
[2010/02/04 12:27:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\JDA
[2010/02/04 12:24:59 | 000,000,000 | —D | C] – C:\Program Files\JDA
[2010/02/04 11:59:43 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Macromedia
[2010/02/04 11:30:47 | 000,000,000 | —D | C] – C:\Program Files\S5Training
[2010/02/04 10:52:05 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\SapWorkDir
[2010/02/04 10:42:07 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\Mozilla
[2010/02/04 10:42:05 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Mozilla
[2010/02/04 10:41:38 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/02/04 10:30:28 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\Personales
[2010/02/04 10:28:40 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\My Videos
[2010/02/04 10:27:12 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\Mis archivos recibidos
[2010/02/04 10:22:15 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\P&G;
[2010/02/04 10:21:58 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\Adobe
[2010/02/04 10:09:22 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\Mis historiales de conversación
[2010/02/04 09:55:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2010/02/04 09:55:17 | 000,000,000 | —D | C] – C:\Program Files\Messenger Plus! Live
[2010/02/04 09:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Tracing
[2010/02/04 09:41:34 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office Outlook Connector
[2010/02/04 09:40:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2010/02/04 09:40:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2010/02/04 09:40:11 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2010/02/04 09:39:39 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/02/04 09:23:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2010/02/04 09:17:21 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Adobe
[2010/02/04 09:16:51 | 000,000,000 | –SD | C] – C:\Documents and Settings\bs0715\UserData
[2010/02/04 08:22:04 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/02/02 08:59:04 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\iPassConnect
[2010/01/29 17:21:24 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\WinBatch
[2010/01/29 16:19:44 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/01/29 16:16:40 | 000,000,000 | —D | C] – C:\WINDOWS\SchCache
[2010/01/29 16:15:07 | 000,000,000 | —D | C] – C:\Program Files\Enable Outlook Encryption
[2010/01/29 16:15:06 | 000,000,000 | —D | C] – C:\Program Files\JoinAD
[2010/01/29 16:14:24 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\osawid_1.1
[2010/01/29 16:12:42 | 000,000,000 | —D | C] – C:\WINDOWS\SAPwksta
[2010/01/29 16:10:59 | 000,000,000 | —D | C] – C:\Program Files\SAP640
[2010/01/29 16:10:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SAP Shared
[2010/01/29 15:51:40 | 000,822,272 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\drivers\BCMWL5.SYS
[2010/01/29 15:49:03 | 000,000,000 | —D | C] – C:\Program Files\Pointsec
[2010/01/29 15:48:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Pointsec
[2010/01/29 15:47:04 | 000,000,000 | —D | C] – C:\swsetup
[2010/01/29 15:43:32 | 000,000,000 | —D | C] – C:\CONF
[2010/01/29 15:34:53 | 000,040,960 | —- | C] (Hewlet Packard) – C:\WINDOWS\System32\CollectActionInfo.exe
[2010/01/29 15:34:30 | 000,000,000 | —D | C] – C:\Program Files\MigrationWizard
[2010/01/29 15:34:29 | 001,384,448 | —- | C] (HP) – C:\WINDOWS\System32\Migrate.exe
[2010/01/29 15:30:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Amex
[2010/01/29 15:30:21 | 000,000,000 | —D | C] – C:\Program Files\SysAmex
[2010/01/29 15:21:50 | 000,827,392 | —- | C] (Novell, Inc.) – C:\WINDOWS\System32\ccsw32.dll
[2010/01/29 15:21:50 | 000,000,000 | —D | C] – C:\WINDOWS\System32\novell
[2010/01/29 15:21:00 | 000,000,000 | —D | C] – C:\WINDOWS\System\nls
[2010/01/29 15:20:56 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NetWare
[2010/01/29 15:20:56 | 000,000,000 | —D | C] – C:\Program Files\CUAgent
[2010/01/29 15:20:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nls
[2010/01/29 15:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\ApplicationHistory
[2010/01/29 15:18:37 | 000,000,000 | —D | C] – C:\Program Files\Qcard
[2010/01/29 15:18:37 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Qcard
[2010/01/29 15:18:06 | 000,000,000 | —D | C] – C:\Program Files\Ora95_2
[2010/01/29 15:17:46 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2010/01/29 15:15:00 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxres.dll
[2010/01/29 14:05:12 | 000,000,000 | —D | C] – C:\Program Files\SAP
[2010/01/29 14:03:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\OleSvr
[2010/01/29 14:01:03 | 000,000,000 | —D | C] – C:\Program Files\Notes5
[2010/01/29 14:00:36 | 000,000,000 | —D | C] – C:\Program Files\Foe
[2010/01/29 14:00:36 | 000,000,000 | —D | C] – C:\DMI
[2010/01/29 14:00:01 | 000,000,000 | —D | C] – C:\Program Files\Firebird
[2010/01/29 13:54:39 | 000,000,000 | —D | C] – C:\Program Files\ISS
[2010/01/29 13:52:49 | 000,155,152 | —- | C] (Nortel Networks NA, Inc.) – C:\WINDOWS\System32\drivers\ipsecw2k.sys
[2010/01/29 13:52:49 | 000,038,939 | —- | C] (Nortel Networks) – C:\WINDOWS\System32\eacfilt.dll
[2010/01/29 13:52:49 | 000,032,837 | —- | C] (Nortel Networks NA, Inc.) – C:\WINDOWS\System32\exthook.dll
[2010/01/29 13:52:49 | 000,026,137 | —- | C] (Nortel Networks) – C:\WINDOWS\System32\drivers\eacfilt.sys
[2010/01/29 13:52:45 | 000,000,000 | —D | C] – C:\Program Files\Nortel Networks
[2010/01/29 13:52:36 | 000,000,000 | —D | C] – C:\Program Files\iPassConnect Quick Demo
[2010/01/29 13:52:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\iPass
[2010/01/29 13:52:11 | 000,021,419 | —- | C] (Meetinghouse Data Communications) – C:\WINDOWS\System32\drivers\iPassP.sys
[2010/01/29 13:51:29 | 000,000,000 | —D | C] – C:\Program Files\iPass
[2010/01/29 13:50:19 | 000,000,000 | —D | C] – C:\HP
[2010/01/29 13:50:19 | 000,000,000 | —D | C] – C:\Program Files\DomainInterfaceProject
[2010/01/29 13:50:18 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2010/01/29 13:50:18 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CSPolicy
[2010/01/29 13:49:54 | 000,000,000 | —D | C] – C:\Program Files\UPHClean
[2010/01/29 13:48:51 | 000,000,000 | —D | C] – C:\Program Files\InterVideo
[2010/01/29 13:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Bluetooth Software
[2010/01/29 13:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents\Bluetooth Exchange Folder
[2010/01/29 13:47:58 | 000,863,402 | —- | C] (Broadcom Corporation.) – C:\WINDOWS\System32\drivers\btkrnl.sys
[2010/01/29 13:47:58 | 000,106,557 | —- | C] (Broadcom Corporation.) – C:\WINDOWS\System32\btw_ci.dll
[2010/01/29 13:47:58 | 000,067,672 | —- | C] (Broadcom Corporation.) – C:\WINDOWS\System32\drivers\btwusb.sys
[2010/01/29 13:47:54 | 000,000,000 | —D | C] – C:\Program Files\WIDCOMM
[2010/01/29 13:47:27 | 000,325,120 | —- | C] (Hewlett-Packard Corporation) – C:\WINDOWS\System32\accelerometercp.CPL
[2010/01/29 13:47:27 | 000,124,928 | —- | C] (Hewlett-Packard Corporation) – C:\WINDOWS\System32\accelerometerST.exe
[2010/01/29 13:47:27 | 000,007,680 | —- | C] (Hewlett-Packard Corporation) – C:\WINDOWS\System32\accelerometerdll.DLL
[2010/01/29 13:47:06 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2010/01/29 13:47:02 | 000,196,608 | —- | C] (Synaptics, Inc.) – C:\WINDOWS\System32\SynCtrl.dll
[2010/01/29 13:47:02 | 000,181,432 | —- | C] (Synaptics, Inc.) – C:\WINDOWS\System32\drivers\SynTP.sys
[2010/01/29 13:47:02 | 000,163,840 | —- | C] (Synaptics, Inc.) – C:\WINDOWS\System32\SynCOM.dll
[2010/01/29 13:47:02 | 000,143,360 | —- | C] (Synaptics, Inc.) – C:\WINDOWS\System32\SynTPAPI.dll
[2010/01/29 13:47:02 | 000,110,592 | —- | C] (Synaptics, Inc.) – C:\WINDOWS\System32\SynTPCo4.dll
[2010/01/29 13:46:02 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdhid.sys
[2010/01/29 13:45:59 | 000,009,472 | —- | C] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\System32\drivers\CPQBttn.sys
[2010/01/29 13:45:56 | 001,560,576 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\BttnCmns_64.dll
[2010/01/29 13:45:56 | 001,560,576 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\BttnCmns.dll
[2010/01/29 13:45:56 | 001,419,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wdfcoinstaller01005.dll
[2010/01/29 13:45:56 | 000,987,136 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\BttnCmn.dll
[2010/01/29 13:45:56 | 000,016,768 | —- | C] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\System32\drivers\HpqKbFiltr.sys
[2010/01/29 13:45:45 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\InstallShield
[2010/01/29 13:45:03 | 005,700,096 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\drivers\igxpmp32.sys
[2010/01/29 13:45:03 | 002,555,904 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igxpdx32.dll
[2010/01/29 13:45:03 | 002,383,872 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\ig4icd32.dll
[2010/01/29 13:45:03 | 001,612,576 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igxpdv32.dll
[2010/01/29 13:45:03 | 001,486,848 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\ig4dev32.dll
[2010/01/29 13:45:03 | 000,528,384 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxcfg.exe
[2010/01/29 13:45:03 | 000,245,760 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxsrvc.exe
[2010/01/29 13:45:03 | 000,204,800 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxdev.dll
[2010/01/29 13:45:03 | 000,200,704 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxpph.dll
[2010/01/29 13:45:03 | 000,192,512 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrell.lrc
[2010/01/29 13:45:03 | 000,192,512 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrdeu.lrc
[2010/01/29 13:45:03 | 000,188,416 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrnld.lrc
[2010/01/29 13:45:03 | 000,188,416 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrita.lrc
[2010/01/29 13:45:03 | 000,188,416 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxresp.lrc
[2010/01/29 13:45:03 | 000,184,320 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrfra.lrc
[2010/01/29 13:45:03 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrrus.lrc
[2010/01/29 13:45:03 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrptg.lrc
[2010/01/29 13:45:03 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrptb.lrc
[2010/01/29 13:45:03 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrhun.lrc
[2010/01/29 13:45:03 | 000,176,128 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrsky.lrc
[2010/01/29 13:45:03 | 000,176,128 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrfin.lrc
[2010/01/29 13:45:03 | 000,176,128 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrcsy.lrc
[2010/01/29 13:45:03 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrtrk.lrc
[2010/01/29 13:45:03 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrsve.lrc
[2010/01/29 13:45:03 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrslv.lrc
[2010/01/29 13:45:03 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrnor.lrc
[2010/01/29 13:45:03 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrenu.lrc
[2010/01/29 13:45:03 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrdan.lrc
[2010/01/29 13:45:03 | 000,163,840 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxzoom.exe
[2010/01/29 13:45:03 | 000,163,840 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrtha.lrc
[2010/01/29 13:45:03 | 000,159,744 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrara.lrc
[2010/01/29 13:45:03 | 000,159,744 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxext.exe
[2010/01/29 13:45:03 | 000,155,648 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrheb.lrc
[2010/01/29 13:45:03 | 000,155,648 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\hkcmd.exe
[2010/01/29 13:45:03 | 000,149,504 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igxpgd32.dll
[2010/01/29 13:45:03 | 000,131,072 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxtray.exe
[2010/01/29 13:45:03 | 000,131,072 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrjpn.lrc
[2010/01/29 13:45:03 | 000,131,072 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxpers.exe
[2010/01/29 13:45:03 | 000,126,976 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrkor.lrc
[2010/01/29 13:45:03 | 000,122,880 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxcpl.cpl
[2010/01/29 13:45:03 | 000,110,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrcht.lrc
[2010/01/29 13:45:03 | 000,110,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrchs.lrc
[2010/01/29 13:45:03 | 000,102,400 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\hccutils.dll
[2010/01/29 13:45:03 | 000,057,344 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igxprd32.dll
[2010/01/29 13:45:03 | 000,047,616 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxsrvc.dll
[2010/01/29 13:45:03 | 000,024,576 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxexps.dll
[2010/01/29 13:45:02 | 003,293,184 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxress.dll
[2010/01/29 13:45:02 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrplk.lrc
[2010/01/29 13:45:02 | 000,135,168 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxdo.dll
[2010/01/29 13:44:43 | 001,160,320 | R— | C] (Agere Systems) – C:\WINDOWS\System32\drivers\AGRSM.sys
[2010/01/29 13:44:43 | 000,068,096 | R— | C] (Agere Systems) – C:\WINDOWS\agrsmdel.exe
[2010/01/29 13:44:38 | 000,000,000 | —D | C] – C:\WINDOWS\Options
[2010/01/29 13:44:22 | 000,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\splitter.sys
[2010/01/29 13:44:21 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wdmaud.sys
[2010/01/29 13:44:20 | 000,052,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmusic.sys
[2010/01/29 13:44:19 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swmidi.sys
[2010/01/29 13:44:18 | 000,172,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kmixer.sys
[2010/01/29 13:44:18 | 000,142,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aec.sys
[2010/01/29 13:44:17 | 000,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\drmkaud.sys
[2010/01/29 13:44:16 | 000,060,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sysaudio.sys
[2010/01/29 13:44:15 | 000,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mskssrv.sys
[2010/01/29 13:44:14 | 000,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mspqm.sys
[2010/01/29 13:44:13 | 000,005,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mspclock.sys
[2010/01/29 13:44:10 | 000,130,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ksproxy.ax
[2010/01/29 13:44:10 | 000,130,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ksproxy.ax
[2010/01/29 13:44:10 | 000,060,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\drmk.sys
[2010/01/29 13:44:10 | 000,060,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\drmk.sys
[2010/01/29 13:44:10 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ksuser.dll
[2010/01/29 13:44:10 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ksuser.dll
[2010/01/29 13:44:05 | 001,285,632 | —- | C] (Analog Devices) – C:\WINDOWS\System32\SMMedia.dll
[2010/01/29 13:44:05 | 000,053,248 | —- | C] (Analog Devices Inc.) – C:\WINDOWS\System32\wdmioctl.dll
[2010/01/29 13:44:05 | 000,049,152 | —- | C] (Analog Devices Inc.) – C:\WINDOWS\System32\DSndUp.exe
[2010/01/29 13:44:05 | 000,045,056 | —- | C] (adi) – C:\WINDOWS\System32\CleanUp.exe
[2010/01/29 13:44:05 | 000,000,000 | —D | C] – C:\Program Files\Analog Devices
[2010/01/29 13:43:07 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\difxapi.dll
[2010/01/29 13:43:00 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\InstallShield
[2010/01/29 13:42:17 | 000,000,000 | —D | C] – C:\Program Files\Intel
[2010/01/29 13:42:13 | 000,000,000 | —D | C] – C:\Intel
[2010/01/29 13:41:40 | 000,000,000 | —D | C] – C:\WINDOWS\System32\HWChannel
[2010/01/29 13:41:23 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/01/29 13:41:18 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/01/29 13:41:03 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ApplicationHistory
[2010/01/29 13:41:01 | 000,000,000 | —D | C] – C:\Program Files\eSupport
[2010/01/29 13:40:41 | 000,000,000 | —D | C] – C:\Program Files\Miramar
[2010/01/29 13:39:09 | 000,000,000 | RH-D | C] – C:\CEBios32Clm.exe
[2010/01/29 13:39:00 | 000,000,000 | —D | C] – C:\WINDOWS\System32\TuneUp
[2010/01/29 13:39:00 | 000,000,000 | —D | C] – C:\Program Files\JPJ
[2010/01/29 13:34:33 | 000,000,000 | —D | C] – C:\Program Files\Windows Journal Viewer
[2010/01/29 13:32:30 | 000,000,000 | -H-D | C] – C:\WINDOWS\$hf_mig$
[2010/01/29 13:21:43 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/01/29 13:16:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2010/01/29 13:09:14 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2010/01/29 13:04:10 | 000,000,000 | —D | C] – C:\Program Files\MSXML 6.0
[2010/01/29 13:00:51 | 000,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2010/01/29 12:55:46 | 000,000,000 | –SD | C] – C:\Documents and Settings\bs0715\Cookies
[2010/01/29 12:55:46 | 000,000,000 | RH-D | C] – C:\Documents and Settings\bs0715\SendTo
[2010/01/29 12:55:46 | 000,000,000 | RH-D | C] – C:\Documents and Settings\bs0715\Recent
[2010/01/29 12:55:46 | 000,000,000 | R–D | C] – C:\Documents and Settings\bs0715\My Documents\My Pictures
[2010/01/29 12:55:46 | 000,000,000 | R–D | C] – C:\Documents and Settings\bs0715\My Documents\My Music
[2010/01/29 12:55:46 | 000,000,000 | R–D | C] – C:\Documents and Settings\bs0715\Favorites
[2010/01/29 12:55:46 | 000,000,000 | -H-D | C] – C:\Documents and Settings\bs0715\PrintHood
[2010/01/29 12:55:46 | 000,000,000 | -H-D | C] – C:\Documents and Settings\bs0715\NetHood
[2010/01/29 12:55:46 | 000,000,000 | -H-D | C] – C:\Documents and Settings\bs0715\Local Settings
[2010/01/29 12:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\Symantec
[2010/01/29 12:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\My Documents
[2010/01/29 12:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Local Settings\Application Data\Microsoft
[2010/01/29 12:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Microsoft
[2010/01/29 12:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data\Identities
[2010/01/29 12:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Desktop
[2010/01/29 12:55:46 | 000,000,000 | —D | C] – C:\Documents and Settings\bs0715\Application Data
[2010/01/29 12:55:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\bs0715\Start Menu
[2010/01/29 12:55:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\bs0715\Templates
[2010/01/29 11:53:27 | 000,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\enum1394.sys
[2010/01/29 11:53:26 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\1394bus.sys
[2010/01/29 11:52:50 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2009/11/11 01:22:19 | 003,145,728 | —- | C] (SAP Technology,Inc) – C:\Program Files\Common Files\sapxlhelper.dll
[2009/11/11 01:22:19 | 000,192,512 | —- | C] (SAP Tech Inc.) – C:\Program Files\Common Files\sapconsr3.dll
[2009/11/11 01:22:18 | 000,626,688 | —- | C] (SAP AG) – C:\Program Files\Common Files\sapconsaccess.dll
[2009/11/11 01:22:18 | 000,040,960 | —- | C] (SAP-TECHNOLOGY) – C:\Program Files\Common Files\DigitalSignature.ocx
[2007/08/21 16:53:03 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2007/08/21 16:32:06 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/08/21 16:13:40 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/08/21 16:13:39 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2005/03/21 14:43:34 | 000,089,088 | —- | C] ( ) – C:\WINDOWS\System32\UNZDLL.DLL
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/02/15 17:19:08 | 004,980,736 | -H– | M] () – C:\Documents and Settings\bs0715\NTUSER.DAT
[2010/02/15 17:03:43 | 000,000,011 | —- | M] () – C:\WINDOWS\NetWare.INI
[2010/02/15 17:03:23 | 000,000,292 | -H– | M] () – C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
[2010/02/15 17:00:38 | 000,000,248 | -H– | M] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/02/15 16:59:52 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/15 16:59:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/15 16:42:37 | 000,000,376 | -HS- | M] () – C:\Documents and Settings\bs0715\ntuser.ini
[2010/02/15 16:41:17 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eBoostr Control Panel.lnk
[2010/02/15 16:31:37 | 000,155,648 | —- | M] () – C:\WINDOWS\msa.exe
[2010/02/15 16:31:35 | 000,193,024 | —- | M] () – C:\WINDOWS\System32\sshnas21.dll
[2010/02/15 15:03:02 | 000,000,298 | —- | M] () – C:\WINDOWS\tasks\TuneUp3.job
[2010/02/15 11:41:29 | 000,000,841 | —- | M] () – C:\WINDOWS\win.ini
[2010/02/15 11:41:24 | 000,133,657 | —- | M] () – C:\Invtree.new
[2010/02/15 11:41:14 | 000,196,994 | —- | M] () – C:\Invtree
[2010/02/15 11:39:26 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\TuneUp2.job
[2010/02/15 11:09:36 | 000,182,648 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\5362_MeridaMEX_hr.jpg
[2010/02/15 11:08:31 | 000,217,240 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\5382_guadalajaraMEX_hr.jpg
[2010/02/15 10:52:52 | 001,227,691 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\Mormon_Church_in_Puerto_Princesa.jpg
[2010/02/15 10:00:09 | 000,000,298 | —- | M] () – C:\WINDOWS\tasks\TuneUp1.job
[2010/02/14 07:54:46 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/14 07:52:52 | 004,771,950 | -H– | M] () – C:\Documents and Settings\bs0715\Local Settings\Application Data\IconCache.db
[2010/02/13 22:20:44 | 000,011,264 | —- | M] () – C:\Documents and Settings\bs0715\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/13 18:57:20 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010/02/13 18:55:29 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/02/13 18:47:15 | 000,000,896 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\WinRAR.exe.lnk
[2010/02/13 18:39:42 | 000,000,135 | —- | M] () – C:\WINDOWS\Mp3CutterJoiner.ini
[2010/02/13 18:39:42 | 000,000,005 | —- | M] () – C:\WINDOWS\System32\SySMP3CutJoin.dat
[2010/02/13 18:35:42 | 000,297,909 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\DSC00123.JPG
[2010/02/13 18:35:04 | 000,816,424 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\Johnson Cycle.3GP
[2010/02/13 13:03:24 | 000,133,632 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\Manual_fuente.DOC
[2010/02/13 12:07:32 | 000,000,099 | —- | M] () – C:\WINDOWS\festo.ini
[2010/02/13 10:46:29 | 000,000,250 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/13 08:46:39 | 000,024,064 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\Máquinas y Equipo Eléctrico.xls
[2010/02/12 14:00:05 | 000,000,388 | —- | M] () – C:\WINDOWS\tasks\PCHScanEngine.job
[2010/02/12 13:13:01 | 000,012,890 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\kit_koleston.jpg
[2010/02/12 13:06:24 | 000,012,456 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\Koleston.jpg
[2010/02/12 13:06:24 | 000,012,456 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\Copy of Koleston.jpg
[2010/02/12 11:48:48 | 000,001,737 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PC Health.lnk
[2010/02/12 11:20:53 | 000,058,973 | —- | M] () – C:\Documents and Settings\bs0715\My Documents\bookmarks-2010-02-12.json
[2010/02/12 11:16:18 | 000,000,527 | —- | M] () – C:\Documents and Settings\bs0715\Desktop\Shortcut to Trabajo Actual.lnk
[2010/02/10 22:18:45 | 000,212,880 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/10 10:00:08 | 000,000,420 | —- | M] () – C:\WINDOWS\tasks\DiskDefrag.job
[2010/02/09 09:59:49 | 000,000,000 | —- | M] () – C:\WINDOWS\HPMProp.INI
[2010/02/08 09:18:31 | 000,000,328 | —- | M] () – C:\Documents and Settings\bs0715\Start Menu\Programs\Startup\myGBP.appref-ms
[2010/02/05 09:50:39 | 000,023,217 | —- | M] () – C:\WINDOWS\System32\drivers\etc\services.CGS
[2010/02/05 09:50:39 | 000,023,217 | —- | M] () – C:\WINDOWS\System32\drivers\etc\services
[2010/02/05 09:00:52 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/02/05 09:00:52 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/02/05 09:00:52 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/02/05 09:00:52 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/02/05 09:00:52 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/02/04 16:49:24 | 000,002,528 | —- | M] () – C:\Documents and Settings\bs0715\Application Data\$_hpcst$.hpc
[2010/02/04 16:03:41 | 000,025,992 | —- | M] (Sysinternals - www.sysinternals.com) – C:\WINDOWS\System32\pgdfgsvc.exe
[2010/02/04 14:32:36 | 000,000,175 | —- | M] () – C:\WINDOWS\sapshortcut.ini
[2010/02/04 10:42:36 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2010/02/04 10:41:51 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/02/02 09:37:45 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\default_user_class.dat
[2010/02/02 09:36:54 | 000,000,000 | —- | M] () – C:\WINDOWS\vpc32.INI
[2010/01/29 18:27:47 | 000,478,534 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/01/29 18:27:47 | 000,409,300 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/01/29 18:27:47 | 000,064,526 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/01/29 17:23:02 | 000,001,380 | RHS- | M] () – C:\Documents and Settings\bs0715\ntuser.pol
[2010/01/29 17:22:27 | 000,004,864 | RHS- | M] () – C:\Documents and Settings\All Users\ntuser.pol
[2010/01/29 15:49:50 | 000,000,464 | —- | M] () – C:\WINDOWS\System32\OEMINFO.INI
[2010/01/29 15:48:59 | 002,097,152 | RHS- | M] () – C:\PROT_INS.SYS
[2010/01/29 15:48:46 | 000,000,512 | —- | M] () – C:\BOOT_SAV.BOT
[2010/01/29 15:48:43 | 000,000,006 | —- | M] () – C:\VOL_CHAR.DAT
[2010/01/29 15:29:12 | 000,000,733 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/01/29 15:21:02 | 000,001,754 | —- | M] () – C:\WINDOWS\System32\AUTOEXEC.NT
[2010/01/29 15:20:14 | 000,002,717 | —- | M] () – C:\WINDOWS\System32\rdrstats.ini
[2010/01/29 15:19:36 | 000,000,025 | —- | M] () – C:\WINDOWS\rsnapi.ini
[2010/01/29 15:18:37 | 000,000,693 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QC Notifier.lnk
[2010/01/29 15:18:37 | 000,000,543 | —- | M] () – C:\WINDOWS\Qt.ini
[2010/01/29 15:13:17 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\mswsock_dll.iss
[2010/01/29 15:13:16 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\msasn1_dll.iss
[2010/01/29 15:13:15 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\shlwapi_dll.iss
[2010/01/29 15:13:13 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\user32_dll.iss
[2010/01/29 15:13:12 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\wininet_dll.iss
[2010/01/29 15:13:11 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\urlmon_dll.iss
[2010/01/29 15:13:11 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\shell32_dll.iss
[2010/01/29 15:13:04 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\rpcrt4_dll.iss
[2010/01/29 15:13:02 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\gdi32_dll.iss
[2010/01/29 13:55:04 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\ntdll_dll.iss
[2010/01/29 13:55:01 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\kernel32_dll.iss
[2010/01/29 13:55:01 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\advapi32_dll.iss
[2010/01/29 13:54:59 | 000,000,028 | —- | M] () – C:\WINDOWS\System32\oleaut32_dll.iss
[2010/01/29 13:54:44 | 000,001,687 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Proventia Desktop Agent.lnk
[2010/01/29 13:52:11 | 000,021,419 | —- | M] (Meetinghouse Data Communications) – C:\WINDOWS\System32\drivers\iPassP.sys
[2010/01/29 13:50:32 | 000,000,218 | —- | M] () – C:\WINDOWS\System32\corpset.ini
[2010/01/29 13:47:55 | 000,000,637 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
[2010/01/29 13:46:28 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
[2010/01/29 13:46:27 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/01/29 13:38:45 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/29 12:54:42 | 000,038,517 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/01/29 12:54:40 | 000,262,144 | —- | M] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/01/29 12:54:09 | 000,000,215 | RHS- | M] () – C:\boot.ini
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/15 16:41:17 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eBoostr Control Panel.lnk
[2010/02/15 16:31:59 | 000,000,292 | -H– | C] () – C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
[2010/02/15 16:31:52 | 000,155,648 | —- | C] () – C:\WINDOWS\msa.exe
[2010/02/15 16:31:41 | 000,000,248 | -H– | C] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/02/15 16:31:35 | 000,193,024 | —- | C] () – C:\WINDOWS\System32\sshnas21.dll
[2010/02/15 11:09:36 | 000,182,648 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\5362_MeridaMEX_hr.jpg
[2010/02/15 11:08:30 | 000,217,240 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\5382_guadalajaraMEX_hr.jpg
[2010/02/15 10:52:51 | 001,227,691 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\Mormon_Church_in_Puerto_Princesa.jpg
[2010/02/14 22:50:27 | 000,004,284 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\Dadi, Marcel - Waltz For Paula.gp3
[2010/02/13 23:49:23 | 000,297,909 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\DSC00123.JPG
[2010/02/13 23:48:38 | 000,816,424 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\Johnson Cycle.3GP
[2010/02/13 18:55:29 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/02/13 18:47:15 | 000,000,896 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\WinRAR.exe.lnk
[2010/02/13 18:39:42 | 000,000,135 | —- | C] () – C:\WINDOWS\Mp3CutterJoiner.ini
[2010/02/13 18:18:18 | 000,000,005 | —- | C] () – C:\WINDOWS\System32\SySMP3CutJoin.dat
[2010/02/13 10:31:52 | 000,133,632 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\Manual_fuente.DOC
[2010/02/13 08:34:27 | 000,024,064 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\Máquinas y Equipo Eléctrico.xls
[2010/02/12 13:13:01 | 000,012,890 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\kit_koleston.jpg
[2010/02/12 13:11:47 | 000,012,456 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\Copy of Koleston.jpg
[2010/02/12 13:06:23 | 000,012,456 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\Koleston.jpg
[2010/02/12 12:16:53 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/02/12 12:16:50 | 000,000,414 | —- | C] () – C:\WINDOWS\System32\lame_acm.xml
[2010/02/12 12:16:48 | 001,559,040 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/02/12 12:16:48 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2010/02/12 12:16:47 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2010/02/12 12:16:44 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/02/12 12:16:44 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010/02/12 11:20:53 | 000,058,973 | —- | C] () – C:\Documents and Settings\bs0715\My Documents\bookmarks-2010-02-12.json
[2010/02/12 11:16:18 | 000,000,527 | —- | C] () – C:\Documents and Settings\bs0715\Desktop\Shortcut to Trabajo Actual.lnk
[2010/02/09 09:59:49 | 000,000,000 | —- | C] () – C:\WINDOWS\HPMProp.INI
[2010/02/09 09:57:37 | 000,018,747 | —- | C] () – C:\WINDOWS\System32\HPCEAC06.HPI
[2010/02/08 09:18:33 | 000,000,328 | —- | C] () – C:\Documents and Settings\bs0715\Start Menu\Programs\Startup\myGBP.appref-ms
[2010/02/06 08:33:59 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2010/02/06 08:32:12 | 000,000,099 | —- | C] () – C:\WINDOWS\festo.ini
[2010/02/05 08:38:27 | 000,002,528 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2010/02/04 16:49:24 | 000,002,528 | —- | C] () – C:\Documents and Settings\bs0715\Application Data\$_hpcst$.hpc
[2010/02/04 14:32:36 | 000,000,175 | —- | C] () – C:\WINDOWS\sapshortcut.ini
[2010/02/04 12:34:26 | 000,000,388 | —- | C] () – C:\WINDOWS\tasks\PCHScanEngine.job
[2010/02/04 12:34:22 | 000,001,737 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PC Health.lnk
[2010/02/04 10:57:47 | 000,011,264 | —- | C] () – C:\Documents and Settings\bs0715\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/04 10:42:36 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/02/04 10:41:51 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/02/02 09:36:54 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2010/02/02 09:03:26 | 000,196,994 | —- | C] () – C:\Invtree
[2010/02/02 09:03:26 | 000,133,657 | —- | C] () – C:\Invtree.new
[2010/01/29 15:52:44 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat
[2010/01/29 15:49:53 | 000,000,308 | —- | C] () – C:\WINDOWS\tasks\TuneUp2.job
[2010/01/29 15:49:50 | 000,000,464 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2010/01/29 15:49:39 | 000,000,298 | —- | C] () – C:\WINDOWS\tasks\TuneUp3.job
[2010/01/29 15:49:38 | 000,000,298 | —- | C] () – C:\WINDOWS\tasks\TuneUp1.job
[2010/01/29 15:48:46 | 000,000,512 | —- | C] () – C:\BOOT_SAV.BOT
[2010/01/29 15:48:44 | 002,097,152 | RHS- | C] () – C:\PROT_INS.SYS
[2010/01/29 15:48:43 | 000,000,006 | —- | C] () – C:\VOL_CHAR.DAT
[2010/01/29 15:40:50 | 000,000,011 | —- | C] () – C:\WINDOWS\NetWare.INI
[2010/01/29 15:20:14 | 000,002,717 | —- | C] () – C:\WINDOWS\System32\rdrstats.ini
[2010/01/29 15:19:36 | 000,000,025 | —- | C] () – C:\WINDOWS\rsnapi.ini
[2010/01/29 15:18:37 | 000,000,693 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QC Notifier.lnk
[2010/01/29 15:18:37 | 000,000,543 | —- | C] () – C:\WINDOWS\Qt.ini
[2010/01/29 15:15:14 | 000,000,000 | —- | C] () – C:\Documents and Settings\bs0715\Local Settings\Application Data\QSwitch.txt
[2010/01/29 15:15:14 | 000,000,000 | —- | C] () – C:\Documents and Settings\bs0715\Local Settings\Application Data\DSwitch.txt
[2010/01/29 15:15:14 | 000,000,000 | —- | C] () – C:\Documents and Settings\bs0715\Local Settings\Application Data\AtStart.txt
[2010/01/29 13:54:44 | 000,001,687 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Proventia Desktop Agent.lnk
[2010/01/29 13:50:31 | 000,089,529 | —- | C] () – C:\Documents and Settings\All Users\Application Data\NETINST2.VBS
[2010/01/29 13:50:31 | 000,004,864 | RHS- | C] () – C:\Documents and Settings\All Users\ntuser.pol
[2010/01/29 13:50:31 | 000,001,380 | RHS- | C] () – C:\Documents and Settings\bs0715\ntuser.pol
[2010/01/29 13:50:31 | 000,000,218 | —- | C] () – C:\WINDOWS\System32\corpset.ini
[2010/01/29 13:48:57 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/01/29 13:48:57 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/01/29 13:48:57 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/01/29 13:48:57 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/01/29 13:48:57 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/01/29 13:48:57 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/01/29 13:47:55 | 000,000,637 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
[2010/01/29 13:47:27 | 000,000,195 | RHS- | C] () – C:\WINDOWS\System32\vssver2.scc
[2010/01/29 13:47:02 | 001,060,424 | —- | C] () – C:\WINDOWS\System32\WdfCoInstaller01000.dll
[2010/01/29 13:46:28 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
[2010/01/29 13:46:27 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/01/29 13:45:03 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4785.dll
[2010/01/29 13:45:03 | 000,025,376 | —- | C] () – C:\WINDOWS\System32\igxpxs32.vp
[2010/01/29 13:45:03 | 000,002,096 | —- | C] () – C:\WINDOWS\System32\igxpxk32.vp
[2010/01/29 13:45:02 | 000,701,840 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2010/01/29 13:00:52 | 000,000,420 | —- | C] () – C:\WINDOWS\tasks\DiskDefrag.job
[2010/01/29 12:55:45 | 004,980,736 | -H– | C] () – C:\Documents and Settings\bs0715\NTUSER.DAT
[2010/01/29 12:55:45 | 000,000,376 | -HS- | C] () – C:\Documents and Settings\bs0715\ntuser.ini
[2010/01/29 12:54:40 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/01/12 19:52:43 | 000,111,610 | —- | C] () – C:\WINDOWS\saplogon.ini
[2009/11/11 01:22:18 | 000,955,904 | —- | C] () – C:\Program Files\Common Files\SAPActiveXL.xlt
[2009/11/11 01:22:18 | 000,949,760 | —- | C] () – C:\Program Files\Common Files\SAPActiveXL_nosig.xlt
[2009/11/11 01:21:41 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\h5tool32.dll
[2009/11/11 01:21:40 | 001,064,960 | —- | C] () – C:\WINDOWS\System32\h5krnl32.dll
[2009/11/11 01:21:40 | 000,188,928 | —- | C] () – C:\WINDOWS\System32\h5icon32.dll
[2009/11/11 01:21:40 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\h5menu32.dll
[2009/11/11 01:21:40 | 000,095,744 | —- | C] () – C:\WINDOWS\System32\h5rtf32.dll
[2009/11/10 22:37:04 | 000,000,259 | —- | C] () – C:\WINDOWS\saproute.ini
[2009/11/10 22:36:56 | 000,005,163 | —- | C] () – C:\WINDOWS\sapmsg.ini
[2008/10/15 08:41:06 | 000,141,888 | —- | C] () – C:\WINDOWS\System32\NovPwd32.dll
[2008/10/15 08:40:12 | 000,217,024 | —- | C] () – C:\WINDOWS\System32\drivers\prot_2k.sys
[2008/01/14 15:47:06 | 000,099,712 | —- | C] () – C:\WINDOWS\HPBroker.dll
[2007/12/14 21:10:08 | 000,008,814 | —- | C] () – C:\WINDOWS\System32\Regmod.ini
[2007/08/21 17:56:10 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/08/21 17:29:15 | 000,000,370 | —- | C] () – C:\WINDOWS\System32\vpscan.ini
[2007/08/21 17:23:56 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\AeXSystemPerformance.dll
[2007/08/21 16:37:23 | 000,000,733 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/08/21 16:28:47 | 000,002,484 | —- | C] () – C:\WINDOWS\System32\IMGApps.Ini
[2007/01/22 09:39:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\nwslog32.dll
[2007/01/22 09:39:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\setupw2k.dll
[2007/01/22 09:39:16 | 000,245,843 | —- | C] () – C:\WINDOWS\System32\nwshlxnt.dll
[2007/01/22 09:39:14 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\lgncon32.dll
[2007/01/22 09:38:58 | 000,216,064 | —- | C] () – C:\WINDOWS\System32\lgnwnt32.dll
[2007/01/22 09:38:58 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\prtwin32.dll
[2007/01/22 09:38:58 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\nwpsrv32.dll
[2006/12/11 16:19:08 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/03/21 14:43:34 | 000,097,280 | —- | C] () – C:\WINDOWS\System32\ZIPDLL.DLL
[2005/02/17 11:41:32 | 000,000,603 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 11:41:30 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2004/07/21 01:59:29 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\vtssm32.dll
[2003/10/09 13:39:46 | 000,005,686 | —- | C] () – C:\Documents and Settings\All Users\Application Data\MUset.vbs
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 12:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/10/17 14:27:14 | 000,254,464 | —- | C] () – C:\WINDOWS\System32\MSVCRT2X.DLL
[1998/12/30 07:33:00 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\cp211_graphicsmed8.dll
[1998/12/30 07:33:00 | 000,057,856 | —- | C] () – C:\WINDOWS\System32\cp211_graphicssmall8.dll
[1998/12/30 07:33:00 | 000,057,856 | —- | C] () – C:\WINDOWS\System32\cp211_graphicssmall16.dll
[1998/12/30 07:33:00 | 000,013,312 | —- | C] () – C:\WINDOWS\System32\cp211_graphicspos.dll
[1998/12/30 07:32:58 | 000,285,184 | —- | C] () – C:\WINDOWS\System32\cp211_graphicslarge8.dll
[1998/12/30 07:32:58 | 000,285,184 | —- | C] () – C:\WINDOWS\System32\cp211_graphicslarge16.dll
[1998/12/30 07:32:58 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\cp211_graphicsmed16.dll
[1998/12/30 07:32:56 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\cp211_lang.dll
[1998/12/30 07:32:54 | 000,226,304 | —- | C] () – C:\WINDOWS\System32\cp211_msjava.dll
[1998/12/30 07:22:48 | 000,252,416 | —- | C] () – C:\WINDOWS\System32\cp211_javascript.dll
[1998/12/30 07:20:32 | 000,779,776 | —- | C] () – C:\WINDOWS\System32\cp211_main.dll
[1998/12/30 07:06:28 | 000,133,120 | —- | C] () – C:\WINDOWS\System32\cp211_vrml1to2.dll
[1998/12/30 07:05:56 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\cp211_basic.dll
[1998/12/01 12:38:22 | 000,052,224 | —- | C] () – C:\WINDOWS\System32\ActPanel.dll
[1993/11/19 00:00:00 | 000,077,664 | —- | C] () – C:\WINDOWS\System32\ir21_r.dll

========== LOP Check ==========

[2010/02/15 17:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eboostr
[2010/02/13 19:08:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HighAndes
[2010/02/05 08:24:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iPass
[2010/02/04 09:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2010/01/29 15:48:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pointsec
[2010/02/04 13:33:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\udx
[2010/02/13 18:53:35 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\Blue Cat Audio
[2010/02/13 19:08:10 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\HighAndes
[2010/02/02 08:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\iPassConnect
[2010/02/05 08:45:09 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\osawid_1.1
[2010/01/29 15:18:37 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\Qcard
[2010/02/14 21:47:31 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\uTorrent
[2010/01/29 17:21:24 | 000,000,000 | —D | M] – C:\Documents and Settings\bs0715\Application Data\WinBatch
[2010/02/10 10:00:08 | 000,000,420 | —- | M] () – C:\WINDOWS\Tasks\DiskDefrag.job
[2010/02/12 14:00:05 | 000,000,388 | —- | M] () – C:\WINDOWS\Tasks\PCHScanEngine.job
[2010/02/15 10:00:09 | 000,000,298 | —- | M] () – C:\WINDOWS\Tasks\TuneUp1.job
[2010/02/15 11:39:26 | 000,000,308 | —- | M] () – C:\WINDOWS\Tasks\TuneUp2.job
[2010/02/15 15:03:02 | 000,000,298 | —- | M] () – C:\WINDOWS\Tasks\TuneUp3.job
[2010/02/15 17:00:38 | 000,000,248 | -H– | M] () – C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/02/15 17:03:23 | 000,000,292 | -H– | M] () – C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

========== Purity Check ==========


< End of report >


And here is the GMER log


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-15 17:12:21
Windows 5.1.2600 Service Pack 2
Running: e1br3i0c.exe; Driver: C:\DOCUME~1\bs0715\LOCALS~1\Temp\pflcrfod.sys


—- System - GMER 1.0.15 —-

SSDT 8529FDC8 ZwAlertResumeThread
SSDT 8529FE88 ZwAlertThread
SSDT 8573EF80 ZwAllocateVirtualMemory
SSDT 859598F8 ZwConnectPort
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwCreateKey [0xA998DF0C]
SSDT 852A8B58 ZwCreateMutant
SSDT 852AD368 ZwCreateThread
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwDebugActiveProcess [0xA998D8AE]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAA493CC0]
SSDT 8529B280 ZwFreeVirtualMemory
SSDT 852A8C18 ZwImpersonateAnonymousToken
SSDT 852A8CD8 ZwImpersonateThread
SSDT 85953DA8 ZwMapViewOfSection
SSDT 852A8580 ZwOpenEvent
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwOpenKey [0xA998E056]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwOpenProcess [0xA998D8C0]
SSDT 85940990 ZwOpenProcessToken
SSDT 859B2E00 ZwOpenThreadToken
SSDT 852A84B0 ZwQueryValueKey
SSDT 859538B0 ZwResumeThread
SSDT 852B3DF8 ZwSetContextThread
SSDT 859B2EC0 ZwSetInformationProcess
SSDT 852B3D38 ZwSetInformationThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAA493F20]
SSDT 852A83F0 ZwSuspendProcess
SSDT 8529FF90 ZwSuspendThread
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwTerminateProcess [0xA998D750]
SSDT 852B3C78 ZwTerminateThread
SSDT \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys ZwUnloadKey [0xA95E26D0]
SSDT 852AE280 ZwUnmapViewOfSection
SSDT 8573EEB0 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \FileSystem\Ntfs \Ntfs eBoost.sys (eBoostr Filter Driver/eBoostr.com)
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

Device \FileSystem\Fastfat \FatCdrom RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \Driver\Tcpip \Device\Ip RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\Tcp RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\IpFilterDriver \Device\IPFILTERDRIVER BlackCat.sys (Network Packet Driver/Internet Security Systems, Inc.)
Device \Driver\Tcpip \Device\Udp RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\RawIp RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \Driver\Tcpip \Device\IPMULTICAST RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \FileSystem\MRxSmb \Device\LanmanRedirector RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \FileSystem\Fastfat \Fat RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.15 —-

Service C:\Program Files\ISS\Proventia Desktop\blackd.exe (*** hidden *** ) [AUTO] BlackICE <– ROOTKIT !!!
Service C:\Program Files\ISS\Proventia Desktop\RapApp.exe (*** hidden *** ) [AUTO] RapApp <– ROOTKIT !!!
Service C:\Program Files\ISS\Proventia Desktop\vpatch.exe (*** hidden *** ) [AUTO] VPatch <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE@Type 16
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE@ImagePath "C:\Program Files\ISS\Proventia Desktop\blackd.exe"
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE@DisplayName BlackICE
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE@BlackDrvCnt 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE@BounceCheck 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\BlackICE\Security@Security 0x01 0x00 0x14 0x80 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016411c6352
Reg HKLM\SYSTEM\CurrentControlSet\Services\RapApp@Type 272
Reg HKLM\SYSTEM\CurrentControlSet\Services\RapApp@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\RapApp@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\RapApp@ImagePath C:\Program Files\ISS\Proventia Desktop\RapApp.exe
Reg HKLM\SYSTEM\CurrentControlSet\Services\RapApp@DisplayName Application Protection
Reg HKLM\SYSTEM\CurrentControlSet\Services\RapApp@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\RapApp\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\RapApp\Security@Security 0x01 0x00 0x14 0x80 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\VPatch@Type 272
Reg HKLM\SYSTEM\CurrentControlSet\Services\VPatch@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\VPatch@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\VPatch@ImagePath C:\Program Files\ISS\Proventia Desktop\vpatch.exe
Reg HKLM\SYSTEM\CurrentControlSet\Services\VPatch@DisplayName ISS Buffer Overflow Exploit Prevention
Reg HKLM\SYSTEM\CurrentControlSet\Services\VPatch@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\VPatch\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\VPatch\Security@Security 0x01 0x00 0x14 0x80 …
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE@Type 16
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE@ImagePath "C:\Program Files\ISS\Proventia Desktop\blackd.exe"
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE@DisplayName BlackICE
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE@BlackDrvCnt 0
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE@BounceCheck 0
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BlackICE\Security@Security 0x01 0x00 0x14 0x80 …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0016411c6352 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\RapApp@Type 272
Reg HKLM\SYSTEM\ControlSet003\Services\RapApp@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\RapApp@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet003\Services\RapApp@ImagePath C:\Program Files\ISS\Proventia Desktop\RapApp.exe
Reg HKLM\SYSTEM\ControlSet003\Services\RapApp@DisplayName Application Protection
Reg HKLM\SYSTEM\ControlSet003\Services\RapApp@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\RapApp\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\RapApp\Security@Security 0x01 0x00 0x14 0x80 …
Reg HKLM\SYSTEM\ControlSet003\Services\VPatch@Type 272
Reg HKLM\SYSTEM\ControlSet003\Services\VPatch@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\VPatch@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet003\Services\VPatch@ImagePath C:\Program Files\ISS\Proventia Desktop\vpatch.exe
Reg HKLM\SYSTEM\ControlSet003\Services\VPatch@DisplayName ISS Buffer Overflow Exploit Prevention
Reg HKLM\SYSTEM\ControlSet003\Services\VPatch@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\VPatch\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\VPatch\Security@Security 0x01 0x00 0x14 0x80 …

—- EOF - GMER 1.0.15 —-




Thankx for your support
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI