This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unknown infection

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok, I have been cleaning viruses for some while but this has me scratching my head….. Whatever I have has disabled the scan function in AVG Free, disabled downloads in IE8 and Google Chrome, prevents me reinstalling xp service pack 3. Puts (This report from AVG Virus Vault) "Infection";"Virus identified Packed.DelfCrypt";"C:\Documents and Settings\Dario\Application Data\SystemProc\lsass.exe" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\CFRegExp32.dll" "Infection";"Virus identified Packed.DelfCrypt";"C:\Documents and Settings\Dario\Application Data\SystemProc\lsass.exe" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\clusapi32.dll" "Infection";"Virus identified Packed.DelfCrypt";"C:\Documents and Settings\Dario\Application Data\SystemProc\lsass.exe" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\cfvalidator32.dll" "Infection";"Virus identified Packed.DelfCrypt";"C:\Documents and Settings\Dario\Application Data\SystemProc\lsass.exe" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\commdlg32.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\cmsetacl32.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\CmdLineExt0332.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\cmprops32.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\cfmlvalidator32.dll" "Infection";"Virus identified Packed.DelfCrypt";"C:\Documents and Settings\Dario\Application Data\SystemProc\lsass.exe" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\cfmlvalidator32.dll" "Infection";"Virus identified Packed.DelfCrypt";"C:\Documents and Settings\Dario\Application Data\SystemProc\lsass.exe" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\cfvalidator32.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\clb32.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\cmdial3232.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\CmdLineExt0332.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\comdlg3232.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\comaddin32.dll" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\commdlg32.dll" "Infection";"Virus identified Packed.DelfCrypt";"C:\Documents and Settings\Dario\Application Data\SystemProc\lsass.exe" "Infection";"Trojan horse Crypt.TSE";"C:\WINDOWS\system32\dhcpcsvc32.dll" you can see that the "lsass.exe is recuring. I am picking up things but cant seem to find the root cause. Also get from IO360 Name RTHDBPL Path C:\DOCUME~1\Dario\LOCALS~1\Temp\509.tmp Description Unknown start up item Process 509.tmp normally if this runs then there is constant activity on the internet (at least it seems to be this) this time it cam up as 509.tmp but next time may be 43.tmp when I delete them it says they are system files. Pfffffffff…… any clues to what I might have. Regards to all Dario R
Hello and :welcome:

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 48 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


Let's start with these:

OTL:
  • Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text into the box under Custom Scan

    netsvcs
    %SYSTEMDRIVE%\*.exe
    c:\windows\system32\drivers\*.sys /90
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    /md5stop
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of the OTL.txt and post it with your next reply along with the Extras.txt log.

–Next–

[external image: Posted Image]
Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.

To post in your next reply:
1. OTL logs.
2. GMER log.
Ok Gmer keeps restarting my system first time after a few seconds, second time after 30 mins, third time after about 1 hr and 4th time after 2hrs

but here are the logs from OTL

Extras..
OTL Extras logfile created on: 22/04/2010 10:31:06 - Run 1
OTL by OldTimer - Version 3.2.2.0 Folder = C:\Documents and Settings\Dario\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 238.00 Mb Available Physical Memory | 23.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.27 Gb Total Space | 13.78 Gb Free Space | 26.35% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 93.16 Gb Total Space | 16.34 Gb Free Space | 17.53% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: FENIXINK
Current User Name: Dario
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.txt [@ = NFOPad] – C:\Program Files\NFOPad\NFOPad.exe (True Human Design)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Windows Shell – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\WINDOWS\system32\dpnsvr.exe" = C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server – (Microsoft Corporation)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\WINDOWS\system32\dxdiag.exe" = C:\WINDOWS\system32\dxdiag.exe:*:Disabled:Microsoft DirectX Diagnostic Tool – (Microsoft Corporation)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\IncrediMail\bin\IncMail.exe" = C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe" = C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup – (Nero AG)
"C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe" = C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime – (Nero AG)
"C:\Program Files\IncrediMail\bin\IMApp.exe" = C:\Program Files\IncrediMail\bin\IMApp.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe:*:Enabled:Dreamweaver MX 2004 – (Macromedia, Inc.)
"C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" = C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe:*:Enabled:VoipStunt – (VoipStunt)
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze – (Vuze Inc.)
"C:\Program Files\EwisoftWeb\bin\WebsiteBuilderP.exe" = C:\Program Files\EwisoftWeb\bin\WebsiteBuilderP.exe:*:Enabled:Ewisoft Website Builder – (Ewisoft Co.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\EwisoftWebcom\bin\WebsiteBuilderP.exe" = C:\Program Files\EwisoftWebcom\bin\WebsiteBuilderP.exe:*:Enabled:Ewisoft Website Builder – (Ewisoft Co.)
"C:\Program Files\IncrediMail\bin\ImpCnt.exe" = C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Disabled:hpfccopy.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Disabled:hpoews01.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Disabled:hpofxm08.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Disabled:hposfx08.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Disabled:hposid01.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Disabled:hpqcopy.exe – File not found
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Disabled:hpqdia.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Disabled:hpqkygrp.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Disabled:hpqnrs08.exe – File not found
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Disabled:hpqphunl.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Disabled:hpqscnvw.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Disabled:hpqste08.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Disabled:hpqtra08.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Disabled:hpzwiz01.exe – File not found
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Windows Shell – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02D29CDE-779D-3082-85C9-4086A49A9390}" = Microsoft Visual C++ 2010 Beta 2 x86 Runtime - 10.0.21006
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam™
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08C0729E-3E50-11DF-9D81-005056806466}" = Google Earth
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{15EFEBF6-E414-33EB-8710-A04AD1302BF8}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Web - enu
"{17283B95-21A8-4996-97DA-547A48DB266F}" = DisplayManager
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1CB92574-96F2-467B-B793-5CEB35C40C29}" = Image Resizer Powertoy for Windows XP
"{1E2F8AE3-3437-44E6-BB75-E95751D6B83F}" = Picture Package
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = PowerStarter
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
"{2F353D44-73BB-4971-B31D-F7642E9E9531}" = Macromedia Flash MX 2004
"{300B9E83-E406-4DF7-8A21-E8A90E4F8B91}_is1" = Convert DVD to AVI 1.1
"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33AE9E89-47C9-4A0D-9E9D-BDD6966A3804}" = Microsoft SQL Server 2008 RsFx Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3E230069-DA0A-442E-9B8B-9D9A805D2BDD}" = PHP 5.2.12
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{40653574-F426-36BB-A1DC-3AD075E1EB3C}" = Microsoft Help 3.0 Beta 2
"{43FFE159-3199-4188-A1CD-629166AD1033}" = Nero 7
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{49F00501-E02F-458F-8AED-85949AB9656F}" = MioTransfer
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4F44B5AE-82A6-4A8A-A3E3-E24D489728E3}" = Microsoft SQL Server 2008 Native Client
"{53FA14B9-A754-4568-819E-BE4270FDEE13}" = SQL Server 2008 R2 Management Objects
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57EC5BFE-7CB7-3057-8385-C9D72918511C}" = Microsoft .NET Framework 4 Client Profile Beta 2
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{5E4B86E5-CD0E-4D3D-BE21-45A30326850A}" = Microsoft Search Enhancement Pack
"{5EC786D5-C0CA-42E0-AF88-5379EF9D91EC}" = First Step Guide
"{5EFFD8C8-BE42-3A47-A5A6-1B3985FD1EC0}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{5FD88490-011C-4DF1-B886-F298D955171B}" = MySQL Connector Net 5.2.5
"{616CE695-5413-4CBF-8EF2-A8312E196D32}" = Karma
"{61D3AAE1-D521-4CD7-939B-37813DE8F955}" = SpyHunter
"{622E0760-2CB0-4BA7-A57D-6D0B952EE04D}" = eM Client
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{650D1904-ED7F-4F37-9325-33C2815D260C}" = MioMap v3 Updater
"{656BD496-2C81-4456-B524-71268114771C}" = Bing Bar Platform
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6E405B40-3879-3C9B-9286-8D5E71258C35}" = Microsoft .NET Framework 4 Extended Beta 2
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Samsung Battery Manager
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8D3562E7-C795-4B5D-A091-6DAA3FF0DF3B}" = Macromedia HomeSite+
"{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}" = Camera RAW Plug-In for EPSON Creativity Suite
"{8E7A8F89-9A8C-48A5-8A03-BDAE191D7B1A}" = MySQL Server 5.1
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-0021-0409-0000-0000000FF1CE}_VisualWebDeveloper_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{913B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Project Professional 2002
"{92042FD5-5588-43A1-A2A7-DDF1979829D6}" = Windows Cache Extension 1.0 for PHP 5.2
"{939740B5-0064-4779-854A-8C1086181C05}" = Macromedia FreeHand MXa
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9527450C-64B3-11D5-9B31-000021116B62}" = SmartCamera Ver 2.1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.3
"{9B4F367E-94AD-40A4-8060-460CE4A98C45}" = SageAcc
"{9C9D0F85-5658-4A5E-95A9-65F7DB2916EE}" = Broadcom 440x 10/100 Integrated Controller
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{A0DB4D2C-E85B-4C23-A4F2-F1B95D3C3BE8}" = Crystal Reports 10
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7}" = Samsung Update Plus
"{A737E831-9ECF-456F-81EA-EEEB5B9922A7}" = Microsoft ASP.NET MVC 2
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA74ED37-681C-4AE8-8D1D-5485EBB3ED3D}" = SQL Server System CLR Types
"{ABE6EF98-9D69-471F-A52D-CE5E86B84FFC}" = PC Camera (6005 CIF)
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B5924CA6-24A7-48F5-BC9C-8BFA94ED4564}" = LightScribe [removed]
"{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}" = EPSON Easy Photo Print
"{B67C01B3-8502-4BE7-AEAB-BBDE910AD3EE}" = Microsoft Web Platform Installer 2.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{B95B1BA9-F887-4B3C-8D3A-CCD4C4675120}" = Microsoft Default Manager
"{BA4DA261-CB60-4690-B202-44998DFC6986}" = Microsoft SQL Server 2008 Setup Support Files
"{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard
"{BFD36C6B-D6A2-3487-BD98-90FABA5D5266}" = Microsoft Visual Web Developer 2010 Express Beta 2 - ENU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}" = Search Settings 1.2
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DA1A4DBF-48A1-4ABE-8890-DD60DF92B498}" = MySQL Connector/ODBC 3.51
"{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"{E165168F-0604-45E4-9C28-B9544406E3D0}" = Microsoft ASP.NET MVC 2 - VWD Express 2010 Tools
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E583ED6F-BD99-4066-A420-C815BF692B69}" = Macromedia Fireworks MX 2004
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EE3E60BC-F29F-4E7B-A110-B538387D34DA}" = No One Lives Forever - Game of the Year Edition
"{EF99C14B-17C2-4994-B5C1-EB204A343A6F}" = User's Guide
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8C6BABF-0837-4EA0-AD6C-8E5A392A7538}" = ImageMixer VCD2
"{FC2C89A7-76E2-32F1-A2C2-428B480F570E}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools Beta 2
"{fe7ccec2-0f76-4921-bc75-caaf255cbbf2}" = DFX for Windows Media Player
"{FF4FC099-35C9-6C23-94DB-C6126ADDD94A}" = Search Assistant Precisead
"6fe92d1e-7bee-73ea-22af-07e6cd6c2945" = Contextual Tool Egoads
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Agere Systems Soft Modem" = SENS LT56ADW Modem
"Audacity_is1" = Audacity 1.2.6
"AVG9Uninstall" = AVG Free 9.0
"CX4300_5500_DX4400 manual" = CX4300_5500_DX4400 manual
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"Ewisoft Website Builder (include eCommerce Builder)_is1" = Ewisoft Website Builder (include eCommerce Builder) Version 5
"FileZilla Client" = FileZilla Client 3.3.1
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 1.7.3
"Google Desktop" = Google Desktop
"Harmony_Hollow_Software Toolbar" = Harmony_Hollow_Software Toolbar
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IncrediMail" = IncrediMail Xe
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{9B4F367E-94AD-40A4-8060-460CE4A98C45}" = Sage Accounts V11.00
"InstallShield_{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7}" = Samsung Update Plus
"InstallShield_{BA7AF70A-F81B-40EF-9268-741A7DE3D608}" = AVStation Premium 3.75
"InstallShield_{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735}" = Samsung Network Manager 2.0
"IObit Security 360_is1" = IObit Security 360
"IObitCom Toolbar" = IObitCom Toolbar
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.33
"LimeWire" = LimeWire 5.4.6
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"mediaconverter.org" = Media Converter SA Edition
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile Beta 2" = Microsoft .NET Framework 4 Client Profile Beta 2
"Microsoft .NET Framework 4 Extended Beta 2" = Microsoft .NET Framework 4 Extended Beta 2
"Microsoft Help 3.0 Beta 2" = Microsoft Help 3.0 Beta 2
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual Web Developer 2010 Express Beta 2 - ENU" = Microsoft Visual Web Developer 2010 Express Beta 2 - ENU
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NFOPad" = NFOPad 1.57
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PCFriendly" = PCFriendly
"PDF Editor 3" = PDF Editor 3
"Picasa2" = Picasa 2
"ProInst" = Intel® PROSet/Wireless Software
"RestoreIT!" = Recover Pro
"Sage MIS 3.01" = Sage MIS 3.01
"Shockwave" = Shockwave
"Smart Defrag_is1" = Smart Defrag
"Some PDF to Word Converter_is1" = Some PDF to Word Converter 1.5
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"uTorrent" = µTorrent
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"VLC media player" = VideoLAN VLC media player 0.8.6d
"VMidi" = vanBasco's Karaoke Player
"VoipStunt_is1" = VoipStunt
"Vuze_Remote Toolbar" = Vuze_Remote Toolbar
"WavePad" = WavePad Sound Editor
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 19/04/2010 02:42:46 | Computer Name = FENIXINK | Source = IS360service | ID = 0
Description =

Error - 19/04/2010 02:48:41 | Computer Name = FENIXINK | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module bthci32.dll, version 0.0.0.0, fault address 0x0000f771.

Error - 19/04/2010 08:14:25 | Computer Name = FENIXINK | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module , version 0.0.0.0, fault address 0x00000000.

Error - 19/04/2010 10:18:08 | Computer Name = FENIXINK | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00001278.

Error - 19/04/2010 17:02:12 | Computer Name = FENIXINK | Source = pctsSvc.exe | ID = 0
Description =

Error - 19/04/2010 20:03:50 | Computer Name = FENIXINK | Source = ESENT | ID = 490
Description = svchost (1320) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read / write access failed with system error 32 (0x00000020): "The process
cannot access the file because it is being used by another process. ". The open
file operation will fail with error -1032 (0xfffffbf8).

Error - 19/04/2010 20:03:50 | Computer Name = FENIXINK | Source = ESENT | ID = 439
Description = Catalog Database (1320) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb. Error
-1032.

Error - 19/04/2010 20:03:50 | Computer Name = FENIXINK | Source = ESENT | ID = 473
Description = Catalog Database (1320) Database C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
was partially detached. Error -1032 encountered updating database headers.

Error - 20/04/2010 02:28:22 | Computer Name = FENIXINK | Source = pctsSvc.exe | ID = 0
Description =

Error - 20/04/2010 10:17:05 | Computer Name = FENIXINK | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 21/04/2010 20:03:02 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7000
Description = The FBAPI service failed to start due to the following error: %%2

Error - 21/04/2010 20:03:02 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7023
Description = The Installer Manager service terminated with the following error:
%%126

Error - 21/04/2010 20:03:02 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7023
Description = The Installer Universal service terminated with the following error:
%%126

Error - 21/04/2010 20:03:02 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7023
Description = The Security Support service terminated with the following error:
%%126

Error - 21/04/2010 20:03:11 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
prodrv06

Error - 21/04/2010 20:15:33 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7000
Description = The FBAPI service failed to start due to the following error: %%2

Error - 21/04/2010 20:15:33 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7023
Description = The Installer Manager service terminated with the following error:
%%126

Error - 21/04/2010 20:15:33 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7023
Description = The Installer Universal service terminated with the following error:
%%126

Error - 21/04/2010 20:15:33 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7023
Description = The Security Support service terminated with the following error:
%%126

Error - 21/04/2010 20:15:33 | Computer Name = FENIXINK | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
prodrv06


< End of report >

OTL..
OTL logfile created on: 22/04/2010 10:31:06 - Run 1
OTL by OldTimer - Version 3.2.2.0 Folder = C:\Documents and Settings\Dario\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 238.00 Mb Available Physical Memory | 23.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.27 Gb Total Space | 13.78 Gb Free Space | 26.35% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 93.16 Gb Total Space | 16.34 Gb Free Space | 17.53% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: FENIXINK
Current User Name: Dario
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Dario\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
PRC - C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\IObit\IObit Security 360\is360tray.exe (IObit)
PRC - C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe ()
PRC - C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
PRC - C:\Program Files\Samsung\DisplayManager\DisplayManager.exe (SAMSUNG)
PRC - C:\Program Files\Samsung\MagicKBD\MagicKBD.exe (SAMSUNG Electronics Co., Ltd.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Samsung\Samsung Network Manager\SNMWLANService.exe ()
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 5.0\Distillr\acrotray.exe (Adobe Systems Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Dario\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\IObit\IObit Security 360\is360mon.dll (IObit)
MOD - C:\WINDOWS\system32\dsound.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (MsDepSvc) – C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (IS360service) – C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.21006_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\SMSvcHost.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (MSSQLServerADHelper100) – c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE (Microsoft Corporation)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE (Microsoft Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SNMP) – C:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (Iprip) – C:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
SRV - (GoogleDesktopManager) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (InCDsrv) – C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (SNM WLAN Service) – C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe ()
SRV - (SimpTcp) – C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ()
DRV - (RsFx0103) – C:\WINDOWS\system32\drivers\RsFx0103.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (incdrm) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (MRV6X32U) – C:\WINDOWS\system32\drivers\MRVW23B.sys (TVISTO)
DRV - (SRS_SSCFilter) SRS Labs Audio Sandbox (WDM) – C:\WINDOWS\system32\drivers\SRS_SSCFilter.sys ()
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (ADIHdAudAddService) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (MRVW225) – C:\WINDOWS\system32\drivers\MRVW225.sys (TVISTO)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTSLBCSP) – C:\WINDOWS\system32\drivers\btslbcsp.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (VVBackd5) – C:\WINDOWS\system32\drivers\VVBackd5.sys ()
DRV - (k750obex) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (k750mgmt) – C:\WINDOWS\system32\drivers\k750mgmt.sys (MCCI)
DRV - (k750mdm) – C:\WINDOWS\system32\drivers\k750mdm.sys (MCCI)
DRV - (k750mdfl) – C:\WINDOWS\system32\drivers\k750mdfl.sys (MCCI)
DRV - (k750bus) Sony Ericsson 750 driver (WDM) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (RITCPT) – C:\WINDOWS\system32\drivers\RITCPT.SYS ()
DRV - (cdrbsdrv) – C:\WINDOWS\system32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prosync1) – C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
DRV - (SNCT511) PC Camera (6005 CIF) – C:\WINDOWS\system32\drivers\snct511.sys ()
DRV - (sonypvs1) – C:\WINDOWS\system32\drivers\sonypvs1.sys (Sony Corporation)
DRV - (MMRTKRNL) – C:\WINDOWS\system32\drivers\mmrtkrnl.sys (ALCATech GmbH)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (MarxDev3) – C:\WINDOWS\system32\drivers\MARXDEV3.SYS ()
DRV - (MarxDev2) – C:\WINDOWS\system32\drivers\MARXDEV2.SYS ()
DRV - (MarxDev1) – C:\WINDOWS\system32\drivers\MARXDEV1.SYS ()
DRV - (DOSMEMIO) – C:\WINDOWS\system32\MEMIO.SYS ()
DRV - (Aspi32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = http://www.Google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page Restore =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/?st=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb,en-us;q=0.5
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 DB 29 66 A0 DB CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.nl/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = FF 98 16 08 A3 21 DD 49 95 87 CA DF 10 BF AF EA [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Google Powered Search"
FF - prefs.js..browser.search.defaulturl: "http://www.dymasearch.com/search.php?src=tops&q;="
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/search?sourceid=navclient&ie;=UTF-8&rlz;=1R0GGGL_en-GB&q;=fenixink%2Ees+domain"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: avg@igeared:4.002.023.004
FF - prefs.js..extensions.enabledItems: {9CE11043-9A15-4207-A565-0C94C42D590D}:11.3.7.0
FF - prefs.js..extensions.enabledItems: {C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}:2.3.54
FF - prefs.js..extensions.enabledItems: [removed]:5.0
FF - prefs.js..extensions.enabledItems: [removed]:1.19
FF - prefs.js..extensions.enabledItems: {420ed894-c19f-4318-a83f-bacae374db28}:0.4.3
FF - prefs.js..extensions.enabledItems: [removed]:1.3.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3303e956-2a3a-48e0-be39-2e0ef11a2f44}:[removed]
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:[removed]
FF - prefs.js..extensions.enabledItems: {66741aa5-35e0-4abc-b573-52639b5af841}:1.0
FF - prefs.js..extensions.enabledItems: {f0d461c0-aff8-490e-9bf6-cee080be8d4f}:1.0
FF - prefs.js..extensions.enabledItems: {f4742f63-801e-49a1-b37f-0d6d0f778666}:1.0
FF - prefs.js..extensions.enabledItems: {94c6d36d-4827-6502-b227-da71ad46a8fd}:4.6.6.3
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q;="

FF - user.js..keyword.enabled: true

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\Firefox [2010/02/17 01:46:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/02/17 01:47:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/04/21 18:28:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/04/20 16:18:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/21 18:48:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/21 18:48:53 | 000,000,000 | —D | M]

[2009/12/25 21:41:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Extensions
[2009/12/25 21:41:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Extensions\[removed]
[2009/10/09 12:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Extensions\[removed]
[2010/04/22 10:27:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions
[2010/04/22 10:26:48 | 000,000,000 | —D | M] (Screengrab) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2009/09/03 22:18:30 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/25 21:53:53 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/09/22 10:34:24 | 000,000,000 | —D | M] (Power Karaoke Toolbar) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{3303e956-2a3a-48e0-be39-2e0ef11a2f44}
[2008/08/07 15:31:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2009/08/03 11:57:58 | 000,000,000 | —D | M] (Codetch) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{420ed894-c19f-4318-a83f-bacae374db28}
[2010/04/18 13:36:22 | 000,000,000 | —D | M] (XUL Cache) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}
[2010/02/23 02:30:19 | 000,000,000 | —D | M] (Vuze Remote Toolbar) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/04/22 10:26:50 | 000,000,000 | —D | M] (Answers) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2010/04/18 15:27:43 | 000,000,000 | —D | M] (XUL Cache) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}
[2010/04/22 09:15:57 | 000,000,000 | —D | M] (XUL Cache) – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}
[2008/08/07 15:31:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\[removed]
[2010/04/22 10:26:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\[removed]
[2006/07/26 22:45:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\[removed]
[2006/07/26 22:46:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\[removed]
[2008/08/14 14:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\[removed]
[2010/01/17 23:43:59 | 000,000,215 | —- | M] () – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\searchplugins\4.6.6.2.xml
[2008/08/18 00:27:18 | 000,001,622 | —- | M] () – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\searchplugins\ask.xml
[2010/03/07 17:03:30 | 000,000,911 | —- | M] () – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\searchplugins\conduit.xml
[2010/03/25 01:15:17 | 000,002,149 | —- | M] () – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\searchplugins\MyStart Search.xml
[2010/03/20 16:51:42 | 000,000,254 | —- | M] () – C:\Documents and Settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\searchplugins\Search.xml
[2010/04/22 10:27:00 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2006/07/21 22:05:17 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/02/14 00:47:18 | 000,000,000 | —D | M] (z) – C:\Program Files\Mozilla Firefox\extensions\{94c6d36d-4827-6502-b227-da71ad46a8fd}
[2010/04/18 15:43:13 | 000,000,000 | —D | M] (Adobe Flash Plugin) – C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}
[2010/02/14 00:44:43 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/02/14 00:44:43 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/02/14 00:44:43 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/02/14 00:44:43 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/04/21 19:02:27 | 000,000,021 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {081698FF-21A3-49DD-9587-CADF10BFAFEa} - C:\WINDOWS\system32\d3drm32.dll ()
O2 - BHO: (IObitCom Toolbar) - {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\tbIOb1.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (IObitCom Toolbar) - {31C7D459-9CC3-44F2-9DCA-FC11795309B4} - C:\Program Files\IObitCom\tbIOb1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVStation Premium 3.75] C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe ()
O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe ()
O4 - HKLM..\Run: [Bing Bar] C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DMLoader.exe (SAMSUNG)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\Samsung\MagicKBD\PreMKbd.exe ()
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RestoreIT!] C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE (FarStone Tech. Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SUPBackGround] C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe ()
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnceEx: [Register Homesite+.exe] C:\Program Files\Macromedia\HomeSite+\Homesite+.exe (Macromedia, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: RTHDBPL = C:\DOCUME~1\Dario\LOCALS~1\Temp\195.tmp File not found
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Send To &Bluetooth; - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe File not found
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/0/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://renatomd.spaces.live.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\WINDOWS\System32\bthci32.dll) - C:\WINDOWS\system32\bthci32.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\6069ab3d879: DllName - C:\WINDOWS\System32\bthci32.dll - C:\WINDOWS\system32\bthci32.dll ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\ddcbbXnk: DllName - ddcbbXnk.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Dario\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dario\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {758F6D53-DCC7-4CCF-9080-4B6F9389F641} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/23 03:12:03 | 000,000,090 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{435ff5b8-1b04-11de-b9a7-001377057366}\Shell\AutoRun\command - "" = E:\wd_windows_tools\WDSetup.exe – File not found
O33 - MountPoints2\{46fdfde0-5f1b-11de-b9d7-001377057366}\Shell - "" = AutoRun
O33 - MountPoints2\{46fdfde0-5f1b-11de-b9d7-001377057366}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{46fdfde1-5f1b-11de-b9d7-001377057366}\Shell - "" = AutoRun
O33 - MountPoints2\{46fdfde1-5f1b-11de-b9d7-001377057366}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5bca0aa9-63c6-11dd-b8f6-001377057366}\Shell - "" = Autorun
O33 - MountPoints2\{5bca0aa9-63c6-11dd-b8f6-001377057366}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5bca0aa9-63c6-11dd-b8f6-001377057366}\Shell\Open\command - "" = G:\resycled\boot.com – File not found
O33 - MountPoints2\{67a75122-a255-11db-b895-0013020f77ea}\Shell\AutoRun\command - "" = E:\setup.exe – [2003/07/15 07:57:58 | 000,416,824 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{67a75122-a255-11db-b895-0013020f77ea}\Shell\configure\command - "" = E:\SETUP.EXE – [2003/07/15 07:57:58 | 000,416,824 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{67a75122-a255-11db-b895-0013020f77ea}\Shell\install\command - "" = E:\SETUP.EXE – [2003/07/15 07:57:58 | 000,416,824 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{685056c2-acc8-11db-b89c-0013020f77ea}\Shell\AutoRun\command - "" = C:\WINDOWS\explorer.exe – [2008/04/14 02:12:19 | 001,033,728 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{72122d7f-038e-11df-ba87-001377057366}\Shell - "" = AutoRun
O33 - MountPoints2\{72122d7f-038e-11df-ba87-001377057366}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c98d5b36-6ea6-11dd-b8fd-001377057366}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe – File not found
O33 - MountPoints2\{eb3282de-0a7a-11de-b99e-001377057366}\Shell - "" = AutoRun
O33 - MountPoints2\{eb3282de-0a7a-11de-b99e-001377057366}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (MACHINE BootExecut) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/09/10 22:09:49 | 000,000,000 | —D | M]
NetSvcs: Iprip - C:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: SSHNAS - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (30131433259401216)

========== Files/Folders - Created Within 30 Days ==========

[2010/04/22 10:28:06 | 000,562,176 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dario\Desktop\OTL.exe
[2010/04/22 08:34:50 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/04/22 01:48:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Dario\BackUp
[2010/04/22 01:47:02 | 000,116,224 | —- | C] (Xerox) – C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2010/04/22 01:46:57 | 000,023,040 | —- | C] (Xerox Corporation) – C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2010/04/22 01:46:44 | 000,004,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2010/04/22 01:46:07 | 000,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2010/04/22 01:46:01 | 000,016,970 | —- | C] (US Robotics MCD (Megahertz)) – C:\WINDOWS\System32\dllcache\xem336n5.sys
[2010/04/22 01:45:59 | 000,019,455 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wvchntxx.sys
[2010/04/22 01:45:54 | 000,012,063 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wsiintxx.sys
[2010/04/22 01:45:30 | 000,154,624 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\wlluc48.sys
[2010/04/22 01:45:24 | 000,034,890 | —- | C] (Raytheon Corp.) – C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2010/04/22 01:45:12 | 000,771,581 | —- | C] (Rockwell) – C:\WINDOWS\System32\dllcache\winacisa.sys
[2010/04/22 01:45:05 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2010/04/22 01:45:00 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2010/04/22 01:44:52 | 000,701,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\wdhaalba.sys
[2010/04/22 01:44:50 | 000,023,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wch7xxnt.sys
[2010/04/22 01:44:45 | 000,035,871 | —- | C] (Winbond Electronics Corp.) – C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2010/04/22 01:44:41 | 000,033,599 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv04nt.sys
[2010/04/22 01:44:39 | 000,019,551 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv02nt.sys
[2010/04/22 01:44:38 | 000,029,311 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv01nt.sys
[2010/04/22 01:44:36 | 000,011,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv05nt.sys
[2010/04/22 01:44:34 | 000,012,127 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv02nt.sys
[2010/04/22 01:44:33 | 000,012,415 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv01nt.sys
[2010/04/22 01:44:26 | 000,016,925 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w940nd.sys
[2010/04/22 01:44:21 | 000,019,016 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w926nd.sys
[2010/04/22 01:44:16 | 000,019,528 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w840nd.sys
[2010/04/22 01:44:09 | 000,064,605 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vvoice.sys
[2010/04/22 01:44:03 | 000,397,502 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vpctcom.sys
[2010/04/22 01:43:57 | 000,604,253 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\vmodem.sys
[2010/04/22 01:43:52 | 000,249,402 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\vinwm.sys
[2010/04/22 01:43:46 | 000,024,576 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\viairda.sys
[2010/04/22 01:43:37 | 000,687,999 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2010/04/22 01:43:31 | 000,765,884 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usrti.sys
[2010/04/22 01:43:24 | 000,113,762 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrpda.sys
[2010/04/22 01:43:19 | 000,007,556 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usroslba.sys
[2010/04/22 01:43:11 | 000,224,802 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usr1807a.sys
[2010/04/22 01:43:05 | 000,794,399 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806v.sys
[2010/04/22 01:43:00 | 000,793,598 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806.sys
[2010/04/22 01:42:54 | 000,794,654 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1801.sys
[2010/04/22 01:42:48 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbser.sys
[2010/04/22 01:42:44 | 000,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbohci.sys
[2010/04/22 01:42:39 | 000,032,384 | —- | C] (KLSI USA, Inc.) – C:\WINDOWS\System32\dllcache\usb101et.sys
[2010/04/22 01:42:25 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxud32.dll
[2010/04/22 01:42:18 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu40.dll
[2010/04/22 01:42:11 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu22.dll
[2010/04/22 01:42:04 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu12.dll
[2010/04/22 01:41:57 | 000,050,688 | —- | C] (UMAX DATA SYSTEMS INC.) – C:\WINDOWS\System32\dllcache\umaxscan.dll
[2010/04/22 01:41:50 | 000,022,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2010/04/22 01:41:44 | 000,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxp60.dll
[2010/04/22 01:41:37 | 000,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxcam.dll
[2010/04/22 01:41:30 | 000,211,968 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um54scan.dll
[2010/04/22 01:41:23 | 000,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2010/04/22 01:41:14 | 000,011,520 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\twotrack.sys
[2010/04/22 01:41:00 | 000,166,784 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxpm.sys
[2010/04/22 01:40:54 | 000,525,568 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxp.dll
[2010/04/22 01:40:47 | 000,159,232 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkbm.sys
[2010/04/22 01:40:40 | 000,440,576 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkb.dll
[2010/04/22 01:40:33 | 000,222,336 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3dm.sys
[2010/04/22 01:40:27 | 000,315,520 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3d.dll
[2010/04/22 01:40:19 | 000,034,375 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\tpro4.sys
[2010/04/22 01:40:12 | 000,042,496 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4res.dll
[2010/04/22 01:40:11 | 000,082,944 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4mon.exe
[2010/04/22 01:40:04 | 000,031,744 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4.dll
[2010/04/22 01:39:56 | 000,230,912 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd03.sys
[2010/04/22 01:39:49 | 000,241,664 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd02.sys
[2010/04/22 01:39:42 | 000,028,232 | —- | C] (TOSHIBA Corporation) – C:\WINDOWS\System32\dllcache\tos4mo.sys
[2010/04/22 01:39:34 | 000,123,995 | —- | C] (Tiger Jet Network) – C:\WINDOWS\System32\dllcache\tjisdn.sys
[2010/04/22 01:39:25 | 000,138,528 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2010/04/22 01:39:18 | 000,081,408 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiul50.dll
[2010/04/22 01:39:16 | 000,149,376 | —- | C] (M-Systems) – C:\WINDOWS\System32\dllcache\tffsport.sys
[2010/04/22 01:39:09 | 000,017,129 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2010/04/22 01:39:02 | 000,037,961 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdk100b.sys
[2010/04/22 01:38:53 | 000,030,464 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tbatm155.sys
[2010/04/22 01:38:45 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tandqic.sys
[2010/04/22 01:38:39 | 000,036,640 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2010/04/22 01:38:33 | 000,172,768 | —- | C] (Number Nine Visual Technology) – C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2010/04/22 01:38:21 | 000,094,293 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sxports.dll
[2010/04/22 01:38:15 | 000,103,936 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sx.sys
[2010/04/22 01:38:09 | 000,003,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swusbflt.sys
[2010/04/22 01:38:02 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpidflt.dll
[2010/04/22 01:37:56 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2010/04/22 01:37:50 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2010/04/22 01:37:44 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_effct.dll
[2010/04/22 01:37:36 | 000,155,648 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnprop.dll
[2010/04/22 01:37:30 | 000,053,248 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlncoin.dll
[2010/04/22 01:37:24 | 000,285,760 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnata.sys
[2010/04/22 01:37:17 | 000,016,896 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\stcusb.sys
[2010/04/22 01:37:08 | 000,048,736 | —- | C] (3Com) – C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2010/04/22 01:37:02 | 000,099,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusd.dll
[2010/04/22 01:36:52 | 000,024,660 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spxupchk.dll
[2010/04/22 01:36:44 | 000,061,824 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\speed.sys
[2010/04/22 01:36:37 | 000,106,584 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spdports.dll
[2010/04/22 01:36:30 | 000,007,552 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2010/04/22 01:36:24 | 000,037,040 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.sys
[2010/04/22 01:36:18 | 000,114,688 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.dll
[2010/04/22 01:36:12 | 000,020,752 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonync.sys
[2010/04/22 01:36:06 | 000,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonymc.sys
[2010/04/22 01:36:04 | 000,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonyait.sys
[2010/04/22 01:36:03 | 000,143,422 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\softkey.dll
[2010/04/22 01:35:57 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2010/04/22 01:35:47 | 000,058,368 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smiminib.sys
[2010/04/22 01:35:41 | 000,147,200 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smidispb.dll
[2010/04/22 01:35:34 | 000,025,034 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2010/04/22 01:35:28 | 000,035,913 | —- | C] (SMC) – C:\WINDOWS\System32\dllcache\smcirda.sys
[2010/04/22 01:35:22 | 000,024,576 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smc8000n.sys
[2010/04/22 01:35:16 | 000,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbhc.sys
[2010/04/22 01:35:14 | 000,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbclass.sys
[2010/04/22 01:35:12 | 000,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbbatt.sys
[2010/04/22 01:35:06 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb3w.dll
[2010/04/22 01:35:00 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb0w.dll
[2010/04/22 01:34:53 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma0w.dll
[2010/04/22 01:34:46 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm91w.dll
[2010/04/22 01:34:38 | 000,063,547 | —- | C] (Symbol Technologies) – C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2010/04/22 01:34:32 | 000,091,294 | —- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) – C:\WINDOWS\System32\dllcache\skfpwin.sys
[2010/04/22 01:34:25 | 000,094,698 | —- | C] (SysKonnect GmbH.) – C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2010/04/22 01:34:19 | 000,157,696 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv256.dll
[2010/04/22 01:34:13 | 000,050,432 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv.sys
[2010/04/22 01:34:11 | 000,032,768 | —- | C] (SiS Corporation) – C:\WINDOWS\System32\dllcache\sisnic.sys
[2010/04/22 01:34:05 | 000,238,592 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrv.dll
[2010/04/22 01:33:59 | 000,104,064 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrp.sys
[2010/04/22 01:33:53 | 000,150,144 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306v.dll
[2010/04/22 01:33:47 | 000,068,608 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306p.sys
[2010/04/22 01:33:41 | 000,252,032 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300iv.dll
[2010/04/22 01:33:35 | 000,101,760 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300ip.sys
[2010/04/22 01:33:20 | 000,161,568 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2010/04/22 01:33:15 | 000,018,400 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmld.sys
[2010/04/22 01:33:09 | 000,098,080 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2010/04/22 01:33:02 | 000,386,560 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiul50.dll
[2010/04/22 01:32:56 | 000,036,480 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\sfmanm.sys
[2010/04/22 01:32:42 | 000,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2010/04/22 01:32:36 | 000,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2010/04/22 01:32:26 | 000,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2010/04/22 01:32:22 | 000,011,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiscan.sys
[2010/04/22 01:32:16 | 000,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2010/04/22 01:32:07 | 000,017,280 | —- | C] (SCM Microsystems) – C:\WINDOWS\System32\dllcache\scr111.sys
[2010/04/22 01:32:01 | 000,016,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scmstcs.sys
[2010/04/22 01:31:52 | 000,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2010/04/22 01:31:46 | 000,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2010/04/22 01:31:36 | 000,495,616 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\sblfx.dll
[2010/04/22 01:31:25 | 000,075,392 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmxm.sys
[2010/04/22 01:31:19 | 000,245,632 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmx.dll
[2010/04/22 01:31:13 | 000,077,824 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2010/04/22 01:31:07 | 000,198,400 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4.dll
[2010/04/22 01:31:01 | 000,061,504 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2010/04/22 01:30:55 | 000,179,264 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2010/04/22 01:30:49 | 000,210,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2010/04/22 01:30:43 | 000,062,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2010/04/22 01:30:37 | 000,041,216 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2010/04/22 01:30:31 | 000,182,272 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2010/04/22 01:30:25 | 000,166,720 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3m.sys
[2010/04/22 01:30:19 | 000,065,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.sys
[2010/04/22 01:30:11 | 000,082,432 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia450.dll
[2010/04/22 01:30:05 | 000,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia430.dll
[2010/04/22 01:30:01 | 000,029,696 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw450ext.dll
[2010/04/22 01:30:00 | 000,027,648 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw430ext.dll
[2010/04/22 01:29:53 | 000,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8139.sys
[2010/04/22 01:29:48 | 000,019,017 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8029.sys
[2010/04/22 01:29:42 | 000,030,720 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rthwcls.sys
[2010/04/22 01:29:31 | 000,009,216 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2010/04/22 01:29:25 | 000,003,840 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rpfun.sys
[2010/04/22 01:29:21 | 000,079,104 | —- | C] (Comtrol Corporation) – C:\WINDOWS\System32\dllcache\rocket.sys
[2010/04/22 01:29:15 | 000,037,563 | —- | C] (RadioLAN) – C:\WINDOWS\System32\dllcache\rlnet5.sys
[2010/04/22 01:29:07 | 000,086,097 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\reslog32.dll
[2010/04/22 01:28:45 | 000,019,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasirda.sys
[2010/04/22 01:28:35 | 000,714,762 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2010/04/22 01:28:29 | 000,899,146 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2010/04/22 01:28:22 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qvusd.dll
[2010/04/22 01:28:16 | 000,003,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qv2kux.sys
[2010/04/22 01:28:08 | 000,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qic157.sys
[2010/04/22 01:27:58 | 000,130,942 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlv.sys
[2010/04/22 01:27:53 | 000,112,574 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlp.sys
[2010/04/22 01:27:47 | 000,128,286 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserli.sys
[2010/04/22 01:27:44 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusd.dll
[2010/04/22 01:27:39 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusb.dll
[2010/04/22 01:27:30 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\psisload.dll
[2010/04/22 01:27:23 | 000,016,128 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\pscr.sys
[2010/04/22 01:27:18 | 000,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa3.sys
[2010/04/22 01:27:13 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa.sys
[2010/04/22 01:27:12 | 000,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\powerfil.sys
[2010/04/22 01:27:07 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pnrmc.sys
[2010/04/22 01:26:58 | 000,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phvfwext.dll
[2010/04/22 01:26:54 | 000,019,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philtune.sys
[2010/04/22 01:26:49 | 000,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phildec.sys
[2010/04/22 01:26:45 | 000,173,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam2.sys
[2010/04/22 01:26:41 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.sys
[2010/04/22 01:26:36 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.dll
[2010/04/22 01:26:32 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phdsext.ax
[2010/04/22 01:26:31 | 000,259,328 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3dd.dll
[2010/04/22 01:26:30 | 000,028,032 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3.sys
[2010/04/22 01:26:28 | 000,211,584 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2dll.dll
[2010/04/22 01:26:27 | 000,027,904 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2.sys
[2010/04/22 01:26:25 | 000,169,984 | —- | C] (Cisco Systems) – C:\WINDOWS\System32\dllcache\pcx500.sys
[2010/04/22 01:26:20 | 000,086,016 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\pctspk.exe
[2010/04/22 01:26:16 | 000,035,328 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2010/04/22 01:26:12 | 000,029,769 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2010/04/22 01:26:07 | 000,030,282 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2010/04/22 01:26:03 | 000,026,153 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2010/04/22 01:26:01 | 000,029,502 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\pca200e.sys
[2010/04/22 01:25:57 | 000,030,495 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pc100nds.sys
[2010/04/22 01:25:55 | 000,036,927 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\padrs411.dll
[2010/04/22 01:25:55 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\padrs412.dll
[2010/04/22 01:25:49 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2rc.dll
[2010/04/22 01:25:45 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2.dll
[2010/04/22 01:25:41 | 000,025,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovsound2.sys
[2010/04/22 01:25:36 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcoms.exe
[2010/04/22 01:25:32 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcomc.dll
[2010/04/22 01:25:28 | 000,351,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodek2.sys
[2010/04/22 01:25:24 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodec2.dll
[2010/04/22 01:25:19 | 000,031,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovce.sys
[2010/04/22 01:25:15 | 000,028,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcd.sys
[2010/04/22 01:25:11 | 000,048,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcam2.sys
[2010/04/22 01:25:07 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovca.sys
[2010/04/22 01:25:02 | 000,054,186 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otcsercb.sys
[2010/04/22 01:24:58 | 000,043,689 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otceth5.sys
[2010/04/22 01:24:54 | 000,027,209 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otc06x5.sys
[2010/04/22 01:24:49 | 000,054,528 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\opl3sax.sys
[2010/04/22 01:24:36 | 000,198,144 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.sys
[2010/04/22 01:24:32 | 000,123,776 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.dll
[2010/04/22 01:24:24 | 000,051,552 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\dllcache\ntgrip.sys
[2010/04/22 01:24:18 | 000,009,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntapm.sys
[2010/04/22 01:24:14 | 000,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsmmc.sys
[2010/04/22 01:24:13 | 000,028,672 | —- | C] (National Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\nscirda.sys
[2010/04/22 01:24:06 | 000,087,040 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2010/04/22 01:24:02 | 000,126,080 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2010/04/22 01:23:56 | 000,032,840 | —- | C] (NETGEAR Corporation.) – C:\WINDOWS\System32\dllcache\ngrpci.sys
[2010/04/22 01:23:55 | 000,132,695 | —- | C] (802.11b) – C:\WINDOWS\System32\dllcache\netwlan5.sys
[2010/04/22 01:23:48 | 000,065,278 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\netflx3.sys
[2010/04/22 01:23:43 | 000,039,264 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.sys
[2010/04/22 01:23:39 | 000,060,480 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.dll
[2010/04/22 01:23:34 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ne2000.sys
[2010/04/22 01:23:27 | 000,091,488 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2010/04/22 01:23:23 | 000,027,936 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3d.sys
[2010/04/22 01:23:19 | 000,033,088 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2010/04/22 01:23:15 | 000,059,104 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2010/04/22 01:23:11 | 000,013,664 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.sys
[2010/04/22 01:23:07 | 000,035,392 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.dll
[2010/04/22 01:23:03 | 000,128,000 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n100325.sys
[2010/04/22 01:22:59 | 000,052,255 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2010/04/22 01:22:55 | 000,075,520 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxport.sys
[2010/04/22 01:22:51 | 000,007,168 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxport.dll
[2010/04/22 01:22:47 | 000,019,968 | —- | C] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\dllcache\mxnic.sys
[2010/04/22 01:22:43 | 000,019,968 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxicfg.dll
[2010/04/22 01:22:39 | 000,021,888 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxcard.sys
[2010/04/22 01:22:38 | 000,229,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\multibox.dll
[2010/04/22 01:22:34 | 000,103,296 | —- | C] (Matrox Graphics Inc) – C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2010/04/22 01:22:22 | 000,049,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstape.sys
[2010/04/22 01:22:16 | 000,012,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msriffwv.sys
[2010/04/22 01:22:07 | 000,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msmpu401.sys
[2010/04/22 01:22:05 | 001,875,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msir3jp.lex
[2010/04/22 01:22:05 | 000,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msircomm.sys
[2010/04/22 01:22:04 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msir3jp.dll
[2010/04/22 01:21:53 | 000,035,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msgame.sys
[2010/04/22 01:21:49 | 000,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfsio.sys
[2010/04/22 01:21:47 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdv.sys
[2010/04/22 01:21:34 | 000,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpe.sys
[2010/04/22 01:21:26 | 000,016,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\modemcsa.sys
[2010/04/22 01:21:18 | 000,006,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\miniqic.sys
[2010/04/22 01:21:11 | 000,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaum.sys
[2010/04/22 01:21:07 | 000,235,648 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaud.dll
[2010/04/22 01:21:05 | 000,026,112 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\memstpci.sys
[2010/04/22 01:21:01 | 000,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memgrp.dll
[2010/04/22 01:20:57 | 000,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memcard.sys
[2010/04/22 01:20:52 | 000,164,586 | —- | C] (Madge Networks Ltd) – C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2010/04/22 01:20:46 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mammoth.sys
[2010/04/22 01:20:41 | 000,048,768 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\maestro.sys
[2010/04/22 01:20:37 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3092dc.dll
[2010/04/22 01:20:33 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3091dc.dll
[2010/04/22 01:20:29 | 000,022,848 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwusbhid.sys
[2010/04/22 01:20:29 | 000,020,864 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwadihid.sys
[2010/04/22 01:20:24 | 000,797,500 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltsmt.sys
[2010/04/22 01:20:20 | 000,802,683 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\ltsm.sys
[2010/04/22 01:20:20 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ltotape.sys
[2010/04/22 01:20:19 | 000,420,992 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2010/04/22 01:20:15 | 000,576,746 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2010/04/22 01:20:14 | 000,606,684 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2010/04/22 01:20:10 | 000,727,786 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ltck000c.sys
[2010/04/22 01:20:06 | 000,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\loop.sys
[2010/04/22 01:20:00 | 000,070,730 | —- | C] (Linksys Group, Inc.) – C:\WINDOWS\System32\dllcache\lne100tx.sys
[2010/04/22 01:19:56 | 000,020,573 | —- | C] (The Linksts Group ) – C:\WINDOWS\System32\dllcache\lne100.sys
[2010/04/22 01:19:52 | 000,025,065 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\lmndis3.sys
[2010/04/22 01:19:49 | 000,015,744 | —- | C] (Litronic Industries) – C:\WINDOWS\System32\dllcache\lit220p.sys
[2010/04/22 01:19:45 | 000,034,688 | —- | C] (Toshiba Corp.) – C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2010/04/22 01:19:42 | 000,026,442 | —- | C] (SMSC) – C:\WINDOWS\System32\dllcache\lanepic5.sys
[2010/04/22 01:19:38 | 000,019,016 | —- | C] (Kingston Technology Company ) – C:\WINDOWS\System32\dllcache\ktc111.sys
[2010/04/22 01:19:33 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kousd.dll
[2010/04/22 01:19:32 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\korwbrkr.dll
[2010/04/22 01:19:30 | 000,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsusd.dll
[2010/04/22 01:19:30 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsui.dll
[2010/04/22 01:19:00 | 000,026,624 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\dllcache\irstusb.sys
[2010/04/22 01:18:57 | 000,018,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irsir.sys
[2010/04/22 01:18:53 | 000,023,552 | —- | C] (MKNet Corporation) – C:\WINDOWS\System32\dllcache\irmk7.sys
[2010/04/22 01:18:52 | 000,088,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irda.sys
[2010/04/22 01:18:45 | 000,045,632 | —- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) – C:\WINDOWS\System32\dllcache\ip5515.sys
[2010/04/22 01:18:41 | 000,090,200 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8ports.dll
[2010/04/22 01:18:37 | 000,038,784 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8.sys
[2010/04/22 01:18:33 | 000,013,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inport.sys
[2010/04/22 01:18:30 | 000,471,102 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imskdic.dll
[2010/04/22 01:18:29 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imkrinst.exe
[2010/04/22 01:18:28 | 000,045,109 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpuex.exe
[2010/04/22 01:18:26 | 000,057,398 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpdadm.exe
[2010/04/22 01:18:24 | 000,311,359 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imepadsv.exe
[2010/04/22 01:18:24 | 000,102,463 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imepadsm.dll
[2010/04/22 01:18:23 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imekrmig.exe
[2010/04/22 01:18:12 | 000,372,824 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\iconf32.dll
[2010/04/22 01:18:08 | 000,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5usb.sys
[2010/04/22 01:18:04 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5ext.dll
[2010/04/22 01:18:01 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5com.dll
[2010/04/22 01:17:58 | 000,154,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4usb.sys
[2010/04/22 01:17:54 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4ext.dll
[2010/04/22 01:17:51 | 000,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4com.dll
[2010/04/22 01:17:47 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3ext.dll
[2010/04/22 01:17:44 | 000,141,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3.sys
[2010/04/22 01:17:40 | 000,038,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2010/04/22 01:17:37 | 000,109,085 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtrp.sys
[2010/04/22 01:17:33 | 000,100,936 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtok.sys
[2010/04/22 01:17:30 | 000,009,216 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmsgnet.dll
[2010/04/22 01:17:26 | 000,028,700 | —- | C] (IBM Corp.) – C:\WINDOWS\System32\dllcache\ibmexmp.sys
[2010/04/22 01:17:24 | 000,702,845 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\i81xdnt5.dll
[2010/04/22 01:17:24 | 000,161,020 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\i81xnt5.sys
[2010/04/22 01:17:20 | 000,058,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740nt5.sys
[2010/04/22 01:17:17 | 000,353,184 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740dnt5.dll
[2010/04/22 01:17:15 | 010,129,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hwxkor.dll
[2010/04/22 01:17:11 | 010,096,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hwxcht.dll
[2010/04/22 01:17:06 | 000,488,383 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_v124.sys
[2010/04/22 01:17:02 | 000,050,751 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_tone.sys
[2010/04/22 01:16:59 | 000,073,279 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_spkp.sys
[2010/04/22 01:16:55 | 000,044,863 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_soar.sys
[2010/04/22 01:16:52 | 000,057,471 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_samp.sys
[2010/04/22 01:16:48 | 000,542,879 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_msft.sys
[2010/04/22 01:16:45 | 000,391,199 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_k56k.sys
[2010/04/22 01:16:42 | 000,009,759 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_inst.dll
[2010/04/22 01:16:38 | 000,115,807 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fsks.sys
[2010/04/22 01:16:35 | 000,199,711 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_faxx.sys
[2010/04/22 01:16:31 | 000,289,887 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fall.sys
[2010/04/22 01:16:28 | 000,067,167 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_bsc2.sys
[2010/04/22 01:16:25 | 000,150,239 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_amos.sys
[2010/04/22 01:16:20 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hr1w.dll
[2010/04/22 01:16:16 | 000,005,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpt4qic.sys
[2010/04/22 01:16:13 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2010/04/22 01:16:10 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2010/04/22 01:16:06 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2010/04/22 01:16:03 | 000,068,608 | —- | C] (Avisioin) – C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2010/04/22 01:15:57 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2010/04/22 01:15:50 | 000,126,976 | —- | C] (Hewlett Packard) – C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2010/04/22 01:15:44 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2010/04/22 01:15:37 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2010/04/22 01:15:31 | 000,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2010/04/22 01:15:27 | 000,002,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidswvd.sys
[2010/04/22 01:15:23 | 000,020,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidbatt.sys
[2010/04/22 01:15:23 | 000,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidgame.sys
[2010/04/22 01:15:18 | 000,907,456 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hcf_msft.sys
[2010/04/22 01:15:17 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hanjadic.dll
[2010/04/22 01:15:16 | 000,028,288 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grserial.sys
[2010/04/22 01:15:13 | 000,082,304 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grclass.sys
[2010/04/22 01:15:09 | 000,017,408 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\gpr400.sys
[2010/04/22 01:15:06 | 000,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gckernel.sys
[2010/04/22 01:15:05 | 000,010,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gameenum.sys
[2010/04/22 01:15:02 | 000,322,432 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400m.sys
[2010/04/22 01:14:59 | 001,733,120 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400d.dll
[2010/04/22 01:14:56 | 000,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200m.sys
[2010/04/22 01:14:54 | 000,470,144 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200d.dll
[2010/04/22 01:14:51 | 000,454,912 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fxusbase.sys
[2010/04/22 01:14:40 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fuusd.dll
[2010/04/22 01:14:37 | 000,455,296 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fusbbase.sys
[2010/04/22 01:14:35 | 000,455,680 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fus2base.sys
[2010/04/22 01:14:28 | 000,442,240 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2010/04/22 01:14:25 | 000,441,728 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2010/04/22 01:14:22 | 000,444,416 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcibase.sys
[2010/04/22 01:14:21 | 000,034,173 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\forehe.sys
[2010/04/22 01:14:17 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fnfilter.dll
[2010/04/22 01:14:13 | 000,027,165 | —- | C] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\dllcache\fetnd5.sys
[2010/04/22 01:14:05 | 000,022,090 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\fem556n5.sys
[2010/04/22 01:14:01 | 000,024,618 | —- | C] (NETGEAR) – C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2010/04/22 01:13:58 | 000,016,074 | —- | C] (NETGEAR Corp.) – C:\WINDOWS\System32\dllcache\fa312nd5.sys
[2010/04/22 01:13:55 | 000,011,850 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2010/04/22 01:13:53 | 000,012,362 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2010/04/22 01:13:49 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exabyte2.sys
[2010/04/22 01:13:47 | 000,016,998 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ex10.sys
[2010/04/22 01:13:41 | 000,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunib.dll
[2010/04/22 01:13:38 | 000,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuni.dll
[2010/04/22 01:13:35 | 000,034,816 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimg.dll
[2010/04/22 01:13:32 | 000,137,088 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\essm2e.sys
[2010/04/22 01:13:32 | 000,043,008 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucm.dll
[2010/04/22 01:13:29 | 000,063,360 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\ess.sys
[2010/04/22 01:13:26 | 000,347,550 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56tpi.sys
[2010/04/22 01:13:23 | 000,594,238 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56hpi.sys
[2010/04/22 01:13:20 | 000,595,647 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56cvmp.sys
[2010/04/22 01:13:18 | 000,174,464 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es198x.sys
[2010/04/22 01:13:15 | 000,072,192 | —- | C] (ESS Technology Inc.) – C:\WINDOWS\System32\dllcache\es1969.sys
[2010/04/22 01:13:13 | 000,040,704 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1371mp.sys
[2010/04/22 01:13:10 | 000,037,120 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1370mp.sys
[2010/04/22 01:13:04 | 000,061,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnloop.exe
[2010/04/22 01:13:01 | 000,051,200 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnlogr.exe
[2010/04/22 01:12:58 | 000,053,248 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqndiag.exe
[2010/04/22 01:12:55 | 000,629,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqn.sys
[2010/04/22 01:12:52 | 000,114,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epstw2k.sys
[2010/04/22 01:12:50 | 000,018,503 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\epro4.sys
[2010/04/22 01:12:48 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2010/04/22 01:12:46 | 000,283,904 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\emu10k1m.sys
[2010/04/22 01:12:40 | 000,019,996 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\em556n4.sys
[2010/04/22 01:12:38 | 000,025,159 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\elnk3.sys
[2010/04/22 01:12:36 | 000,007,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\elmsmc.sys
[2010/04/22 01:12:35 | 000,171,520 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el99xn51.sys
[2010/04/22 01:12:33 | 000,070,174 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el98xn5.sys
[2010/04/22 01:12:31 | 000,455,199 | —- | C] (3Com Corporation.) – C:\WINDOWS\System32\dllcache\el985n51.sys
[2010/04/22 01:12:29 | 000,153,631 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xnd5.sys
[2010/04/22 01:12:27 | 000,066,591 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xbc5.sys
[2010/04/22 01:12:26 | 000,241,206 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656se5.sys
[2010/04/22 01:12:24 | 000,077,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656nd5.sys
[2010/04/22 01:12:22 | 000,634,134 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656ct5.sys
[2010/04/22 01:12:20 | 000,069,194 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656cd5.sys
[2010/04/22 01:12:18 | 000,026,141 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el589nd5.sys
[2010/04/22 01:12:17 | 000,069,692 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el575nd5.sys
[2010/04/22 01:12:15 | 000,024,653 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el574nd4.sys
[2010/04/22 01:12:13 | 000,055,999 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el556nd5.sys
[2010/04/22 01:12:11 | 000,044,103 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el515.sys
[2010/04/22 01:12:08 | 000,019,594 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e100isa4.sys
[2010/04/22 01:12:06 | 000,117,760 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e100b325.sys
[2010/04/22 01:12:05 | 000,050,719 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e1000nt5.sys
[2010/04/22 01:11:56 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dshowext.ax
[2010/04/22 01:11:54 | 000,334,208 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2010/04/22 01:11:47 | 000,028,062 | —- | C] (National Semiconductor Coproration) – C:\WINDOWS\System32\dllcache\dp83820.sys
[2010/04/22 01:11:46 | 000,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2010/04/22 01:11:44 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2010/04/22 01:11:42 | 000,206,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4.sys
[2010/04/22 01:11:42 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2010/04/22 01:11:35 | 000,029,696 | —- | C] (CNet Technology, Inc. ) – C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2010/04/22 01:11:35 | 000,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dlttape.sys
[2010/04/22 01:11:33 | 000,026,698 | —- | C] (D-Link Corporation) – C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2010/04/22 01:11:31 | 000,952,007 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diwan.sys
[2010/04/22 01:11:25 | 000,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2010/04/22 01:11:23 | 000,038,985 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvsu.dll
[2010/04/22 01:11:22 | 000,031,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvpp.dll
[2010/04/22 01:11:20 | 000,006,729 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvci.dll
[2010/04/22 01:11:17 | 000,091,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\dimaint.sys
[2010/04/22 01:11:15 | 000,614,429 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiview.exe
[2010/04/22 01:11:14 | 000,042,432 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.sys
[2010/04/22 01:11:12 | 000,110,621 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.dll
[2010/04/22 01:11:11 | 000,021,606 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.sys
[2010/04/22 01:11:09 | 000,041,046 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.dll
[2010/04/22 01:11:08 | 000,102,484 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiinf.dll
[2010/04/22 01:11:06 | 000,159,828 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digihlc.dll
[2010/04/22 01:11:05 | 000,229,462 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifwrk.dll
[2010/04/22 01:11:03 | 000,090,525 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifep5.sys
[2010/04/22 01:11:01 | 000,103,044 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidxb.sys
[2010/04/22 01:11:00 | 000,131,156 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidbp.dll
[2010/04/22 01:10:58 | 000,037,735 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.sys
[2010/04/22 01:10:57 | 000,065,622 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.dll
[2010/04/22 01:10:53 | 000,419,357 | —- | C] (Digi International) – C:\WINDOWS\System32\dllcache\dgconfig.dll
[2010/04/22 01:10:52 | 000,029,531 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\dgapci.sys
[2010/04/22 01:10:49 | 000,024,649 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650d.sys
[2010/04/22 01:10:48 | 000,024,648 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650.sys
[2010/04/22 01:10:46 | 000,024,064 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\devldr32.exe
[2010/04/22 01:10:45 | 000,256,512 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\devcon32.dll
[2010/04/22 01:10:42 | 000,020,928 | —- | C] (Digital Networks, LLC) – C:\WINDOWS\System32\dllcache\defpa.sys
[2010/04/22 01:10:41 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddsmc.sys
[2010/04/22 01:10:39 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc260usd.dll
[2010/04/22 01:10:37 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc240usd.dll
[2010/04/22 01:10:36 | 000,063,208 | —- | C] (Intel Corporation.) – C:\WINDOWS\System32\dllcache\dc21x4.sys
[2010/04/22 01:10:34 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210usd.dll
[2010/04/22 01:10:33 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210_32.dll
[2010/04/22 01:10:27 | 000,117,760 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\d100ib5.sys
[2010/04/22 01:10:25 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzports.dll
[2010/04/22 01:10:24 | 000,049,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzport.sys
[2010/04/22 01:10:23 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzcoins.dll
[2010/04/22 01:10:21 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyports.dll
[2010/04/22 01:10:20 | 000,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyport.sys
[2010/04/22 01:10:18 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyycoins.dll
[2010/04/22 01:10:17 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclom-y.sys
[2010/04/22 01:10:15 | 000,048,640 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2010/04/22 01:10:15 | 000,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclad-z.sys
[2010/04/22 01:10:13 | 000,093,952 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2010/04/22 01:10:12 | 000,111,872 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcspud.sys
[2010/04/22 01:10:10 | 000,003,584 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2010/04/22 01:10:09 | 000,072,832 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2010/04/22 01:10:07 | 000,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2010/04/22 01:10:06 | 000,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbase.sys
[2010/04/22 01:10:04 | 000,249,856 | —- | C] (Comtrol® Corporation) – C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2010/04/22 01:10:04 | 000,004,096 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctwdm32.dll
[2010/04/22 01:10:02 | 000,096,256 | —- | C] (Copyright © Creative Technology Ltd. 1994-2001) – C:\WINDOWS\System32\dllcache\ctlsb16.sys
[2010/04/22 01:10:01 | 000,003,712 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctljystk.sys
[2010/04/22 01:10:00 | 000,006,912 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\ctlfacem.sys
[2010/04/22 01:09:57 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\csamsp.dll
[2010/04/22 01:09:55 | 000,042,112 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\crtaud.sys
[2010/04/22 01:09:54 | 000,216,064 | —- | C] (COMPAQ Inc.) – C:\WINDOWS\System32\dllcache\cpscan.dll
[2010/04/22 01:09:52 | 000,060,970 | —- | C] (Compaq Computer Corp.) – C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2010/04/22 01:09:51 | 000,021,533 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2010/04/22 01:09:43 | 000,039,936 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\cnxt1803.sys
[2010/04/22 01:09:42 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnusd.dll
[2010/04/22 01:09:38 | 000,020,736 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2010/04/22 01:09:36 | 000,248,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546xm.sys
[2010/04/22 01:09:35 | 000,170,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546x.dll
[2010/04/22 01:09:34 | 000,111,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl5465.dll
[2010/04/22 01:09:33 | 000,045,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.sys
[2010/04/22 01:09:32 | 000,091,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.dll
[2010/04/22 01:09:30 | 000,272,640 | —- | C] (RAVISENT Technologies Inc.) – C:\WINDOWS\System32\dllcache\cinemclc.sys
[2010/04/22 01:09:28 | 000,980,034 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\cicap.sys
[2010/04/22 01:09:26 | 001,677,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chsbrkr.dll
[2010/04/22 01:09:26 | 000,838,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chtbrkr.dll
[2010/04/22 01:09:23 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\changer.sys
[2010/04/22 01:09:21 | 000,049,182 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem56n5.sys
[2010/04/22 01:09:20 | 000,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem33n5.sys
[2010/04/22 01:09:19 | 000,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem28n5.sys
[2010/04/22 01:09:18 | 000,027,164 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce3n5.sys
[2010/04/22 01:09:17 | 000,021,530 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce2n5.sys
[2010/04/22 01:09:15 | 000,714,698 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2010/04/22 01:09:14 | 000,046,108 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cben5.sys
[2010/04/22 01:09:13 | 000,039,680 | —- | C] (Silicom Ltd.) – C:\WINDOWS\System32\dllcache\cb325.sys
[2010/04/22 01:09:12 | 000,037,916 | —- | C] (Fast Ethernet Controller Provider) – C:\WINDOWS\System32\dllcache\cb102.sys
[2010/04/22 01:09:09 | 000,032,256 | —- | C] (Eicon Technology Corporation) – C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2010/04/22 01:09:08 | 000,164,923 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diapi2.sys
[2010/04/22 01:09:06 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.dll
[2010/04/22 01:09:06 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.ax
[2010/04/22 01:09:05 | 000,236,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.dll
[2010/04/22 01:09:04 | 000,244,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.ax
[2010/04/22 01:09:03 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.dll
[2010/04/22 01:09:02 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.ax
[2010/04/22 01:09:01 | 000,171,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv30.sys
[2010/04/22 01:09:00 | 000,314,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdro21.sys
[2010/04/22 01:09:00 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv21.sys
[2010/04/22 01:08:34 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2010/04/22 01:08:32 | 000,031,529 | —- | C] (BreezeCOM) – C:\WINDOWS\System32\dllcache\brzwlan.sys
[2010/04/22 01:08:31 | 000,010,368 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbscn.sys
[2010/04/22 01:08:30 | 000,011,008 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2010/04/22 01:08:29 | 000,060,416 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brserwdm.sys
[2010/04/22 01:08:29 | 000,009,728 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brserif.dll
[2010/04/22 01:08:28 | 000,005,120 | —- | C] (Brother Industries,Ltd.) – C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2010/04/22 01:08:27 | 000,039,552 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparwdm.sys
[2010/04/22 01:08:26 | 000,003,168 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparimg.sys
[2010/04/22 01:08:24 | 000,041,472 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfusb.dll
[2010/04/22 01:08:24 | 000,032,256 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2010/04/22 01:08:23 | 000,029,696 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmflpt.dll
[2010/04/22 01:08:22 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2010/04/22 01:08:21 | 000,015,360 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2010/04/22 01:08:20 | 000,012,160 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2010/04/22 01:08:20 | 000,003,968 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltup.sys
[2010/04/22 01:08:19 | 000,002,944 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brfilt.sys
[2010/04/22 01:08:18 | 000,012,800 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brevif.dll
[2010/04/22 01:08:17 | 000,019,456 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brbidiif.dll
[2010/04/22 01:08:17 | 000,009,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brcoinst.dll
[2010/04/22 01:08:14 | 000,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\binlsvc.dll
[2010/04/22 01:08:13 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdasup.sys
[2010/04/22 01:08:12 | 000,871,388 | —- | C] (BCM) – C:\WINDOWS\System32\dllcache\bcmdm.sys
[2010/04/22 01:08:12 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2010/04/22 01:08:11 | 000,026,568 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm4e5.sys
[2010/04/22 01:08:10 | 000,066,557 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42u.sys
[2010/04/22 01:08:10 | 000,054,271 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42xx5.sys
[2010/04/22 01:08:07 | 000,036,128 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.sys
[2010/04/22 01:08:06 | 000,342,336 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.dll
[2010/04/22 01:08:06 | 000,096,640 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\b57xp32.sys
[2010/04/22 01:08:05 | 000,089,952 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\b1cbase.sys
[2010/04/22 01:08:04 | 000,036,992 | —- | C] (Aztech Systems Ltd) – C:\WINDOWS\System32\dllcache\aztw2320.sys
[2010/04/22 01:08:03 | 000,144,384 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmenum.dll
[2010/04/22 01:08:03 | 000,037,568 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmwan.sys
[2010/04/22 01:08:02 | 000,087,552 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2010/04/22 01:08:01 | 000,013,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcstrm.sys
[2010/04/22 01:08:00 | 000,036,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcaudio.sys
[2010/04/22 01:07:59 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avc.sys
[2010/04/22 01:07:49 | 000,070,528 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiragem.sys
[2010/04/22 01:07:48 | 000,104,832 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiraged.dll
[2010/04/22 01:07:46 | 000,281,600 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimtai.sys
[2010/04/22 01:07:45 | 000,289,664 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpab.sys
[2010/04/22 01:07:45 | 000,075,136 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpae.sys
[2010/04/22 01:07:44 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atievxx.exe
[2010/04/22 01:07:43 | 000,268,160 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidvai.dll
[2010/04/22 01:07:43 | 000,137,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrae.dll
[2010/04/22 01:07:42 | 000,382,592 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrab.dll
[2010/04/22 01:07:38 | 000,077,568 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ati.sys
[2010/04/22 01:07:37 | 000,096,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ati.dll
[2010/04/22 01:07:35 | 000,097,354 | —- | C] (Bay Networks, Inc.) – C:\WINDOWS\System32\dllcache\aspndis3.sys
[2010/04/22 01:07:32 | 000,006,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\apmbatt.sys
[2010/04/22 01:07:31 | 000,036,224 | —- | C] (ADMtek Incorporated.) – C:\WINDOWS\System32\dllcache\an983.sys
[2010/04/22 01:07:30 | 000,016,969 | —- | C] (AmbiCom, Inc.) – C:\WINDOWS\System32\dllcache\amb8002.sys
[2010/04/22 01:07:29 | 000,026,624 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\alifir.sys
[2010/04/22 01:07:29 | 000,005,248 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\aliide.sys
[2010/04/22 01:07:28 | 000,027,678 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ali5261.sys
[2010/04/22 01:07:20 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2010/04/22 01:07:16 | 000,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2010/04/22 01:07:15 | 000,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2010/04/22 01:07:15 | 000,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2010/04/22 01:07:14 | 000,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2010/04/22 01:07:14 | 000,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2010/04/22 01:07:13 | 000,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2010/04/22 01:07:13 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2010/04/22 01:07:11 | 000,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2010/04/22 01:07:10 | 000,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2010/04/22 01:07:10 | 000,084,480 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ac97via.sys
[2010/04/22 01:07:09 | 000,231,552 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ac97ali.sys
[2010/04/22 01:07:09 | 000,096,256 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ac97intc.sys
[2010/04/22 01:07:07 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\61883.sys
[2010/04/22 01:07:07 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2010/04/22 01:07:07 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\4mmdat.sys
[2010/04/22 01:07:06 | 000,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2010/04/22 01:07:06 | 000,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2010/04/22 01:07:05 | 000,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2010/04/22 01:07:05 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2010/04/22 01:06:37 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2010/04/21 09:37:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Dario\DoctorWeb
[2010/04/21 09:03:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Dario\Local Settings\Application Data\AVG Security Toolbar
[2010/04/20 16:29:58 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/04/20 16:18:50 | 000,242,896 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/04/20 16:18:50 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/04/20 16:18:43 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/04/20 16:18:42 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/04/20 16:18:30 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/04/20 16:18:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/04/20 16:18:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/04/20 08:57:10 | 000,000,000 | —D | C] – C:\sh4ldr
[2010/04/20 08:57:10 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2010/04/20 08:55:45 | 000,000,000 | —D | C] – C:\WINDOWS\61D3AAE1D5214CD7939B37813DE8F955.TMP
[2010/04/20 00:12:04 | 000,000,000 | —D | C] – C:\WINDOWS\BDOSCAN8
[2010/04/20 00:06:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Dario\Local Settings\Application Data\Threat Expert
[2010/04/19 23:50:00 | 000,000,000 | —D | C] – C:\Program Files\NFOPad
[2010/04/19 23:23:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Dario\Application Data\Toolbar4
[2010/04/19 23:23:57 | 000,000,000 | —D | C] – C:\Program Files\f3setupinstall
[2010/04/19 23:22:54 | 000,000,000 | —D | C] – C:\sysmon
[2010/04/19 01:32:28 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2010/04/18 15:43:15 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dario\Application Data\SystemProc
[2010/04/18 12:12:28 | 083,010,552 | —- | C] (AVG Technologies) – C:\Documents and Settings\Dario\Desktop\avg_free_stf_en_90_790a2730.exe
[2010/04/18 10:03:03 | 000,157,712 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/04/17 20:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Dario\Application Data\WinRAR
[2010/04/17 20:22:28 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1381747802
[2010/03/26 01:05:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Dario\My Documents\Tarrot
[2010/03/24 20:38:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Dario\Application Data\Microsoft Corporation
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/22 10:33:11 | 000,003,631 | -HS- | M] () – C:\Documents and Settings\Dario\Application Data\020000007f692e36879P.manifest
[2010/04/22 10:28:10 | 000,562,176 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dario\Desktop\OTL.exe
[2010/04/22 10:27:01 | 000,000,020 | —- | M] () – C:\WINDOWS\System32\30e9ac3a
[2010/04/22 10:20:07 | 013,631,488 | —- | M] () – C:\Documents and Settings\Dario\NTUSER.DAT
[2010/04/22 10:17:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/22 10:12:02 | 000,000,976 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-330226422-998270827-2084254949-1004UA.job
[2010/04/22 09:22:17 | 000,050,688 | —- | M] () – C:\Documents and Settings\Dario\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/22 09:15:55 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\d3drm32.dll
[2010/04/22 09:08:50 | 059,117,484 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/04/22 09:00:06 | 000,000,182 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/04/22 08:15:49 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\cryptui32.dll
[2010/04/22 07:15:47 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\cryptdll32.dll
[2010/04/22 04:15:53 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\d3dim32.dll
[2010/04/22 03:15:57 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\datime3232.dll
[2010/04/22 02:16:04 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\bootvid32.dll
[2010/04/22 02:15:33 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/22 02:14:56 | 000,000,077 | -HS- | M] () – C:\cj.ini
[2010/04/22 02:14:13 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/22 02:13:55 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/22 02:13:55 | 000,000,051 | -HS- | M] () – C:\Documents and Settings\Dario\Application Data\020000007f692e36879C.manifest
[2010/04/22 02:13:55 | 000,000,011 | -HS- | M] () – C:\Documents and Settings\Dario\Application Data\020000007f692e36879S.manifest
[2010/04/22 02:13:55 | 000,000,011 | -HS- | M] () – C:\Documents and Settings\Dario\Application Data\020000007f692e36879O.manifest
[2010/04/22 02:13:46 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/22 02:13:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/22 02:13:40 | 1071,828,992 | -HS- | M] () – C:\hiberfil.sys
[2010/04/22 02:11:59 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Dario\ntuser.ini
[2010/04/22 00:53:48 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\dsdmoprp32.dll
[2010/04/22 00:53:35 | 000,000,817 | —- | M] () – C:\WINDOWS\System32\1617537853
[2010/04/22 00:53:08 | 000,001,057 | -HS- | M] () – C:\WINDOWS\System32\809106285
[2010/04/21 17:30:49 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\devmgr32.dll
[2010/04/21 16:31:03 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\capicom32.dll
[2010/04/21 14:12:01 | 000,000,924 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-330226422-998270827-2084254949-1004Core.job
[2010/04/21 12:30:30 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\CRxmlx0932.dll
[2010/04/21 11:30:29 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\crxml19r32.dll
[2010/04/21 10:30:32 | 000,280,576 | —- | M] () – C:\WINDOWS\System32\cryptsvc32.dll
[2010/04/21 09:19:39 | 037,966,136 | —- | M] () – C:\Documents and Settings\Dario\Desktop\drweb-cureit.exe
[2010/04/21 09:10:09 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/04/21 09:07:33 | 002,889,800 | —- | M] () – C:\Documents and Settings\Dario\Desktop\rmvirut.exe
[2010/04/21 09:06:57 | 000,495,104 | —- | M] () – C:\Documents and Settings\Dario\Desktop\rmvirut.nt
[2010/04/20 16:18:50 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/04/20 16:18:50 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/04/20 16:18:43 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/04/20 16:18:42 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/04/20 16:18:42 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/04/20 09:51:58 | 007,079,678 | -H– | M] () – C:\Documents and Settings\Dario\Local Settings\Application Data\IconCache.db
[2010/04/20 08:57:30 | 000,001,973 | —- | M] () – C:\Documents and Settings\Dario\Desktop\SpyHunter.lnk
[2010/04/19 23:50:02 | 000,000,654 | —- | M] () – C:\Documents and Settings\Dario\Desktop\NFOPad.lnk
[2010/04/19 23:49:34 | 000,587,470 | —- | M] () – C:\Documents and Settings\Dario\Desktop\nfopad157.exe
[2010/04/19 00:36:17 | 000,000,384 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag.job
[2010/04/18 18:13:04 | 000,005,488 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2010/04/18 17:05:42 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/18 13:36:19 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\crbas1932.dll
[2010/04/18 12:49:21 | 083,010,552 | —- | M] (AVG Technologies) – C:\Documents and Settings\Dario\Desktop\avg_free_stf_en_90_790a2730.exe
[2010/04/18 11:36:32 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\d3dx9_2732.dll
[2010/04/18 10:36:04 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\cfgbkend32.dll
[2010/04/18 10:18:02 | 000,010,752 | —- | M] () – C:\WINDOWS\DCEBoot.exe
[2010/04/18 09:50:41 | 000,000,036 | —- | M] () – C:\Documents and Settings\Dario\Local Settings\Application Data\housecall.guid.cache
[2010/04/18 09:23:12 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\cards32.dll
[2010/04/18 09:17:39 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\crbas19r32.dll
[2010/04/18 09:09:10 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\bitsprx432.dll
[2010/04/18 06:23:47 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\dbgeng3232.dll
[2010/04/18 05:23:46 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\datime32.dll
[2010/04/18 03:23:02 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\BTNeighborhood32.dll
[2010/04/18 02:23:08 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\BtWizard32.dll
[2010/04/17 21:13:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/17 20:22:42 | 000,000,113 | —- | M] () – C:\WINDOWS\System32\sl1373137407
[2010/04/17 20:22:36 | 000,239,616 | —- | M] () – C:\WINDOWS\System32\CRxmlx09r32.dll
[2010/04/17 20:22:28 | 000,203,776 | -HS- | M] () – C:\WINDOWS\System32\unrar.exe
[2010/04/17 20:22:01 | 000,140,288 | —- | M] () – C:\WINDOWS\System32\bthci32.dll
[2010/04/16 19:52:29 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/04/14 23:30:04 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/04/07 08:57:08 | 000,039,424 | —- | M] () – C:\Documents and Settings\Dario\My Documents\Friends and Lovers for Dario Renato Melkuhn and Margaretha Niestadt.doc
[2010/04/05 18:17:27 | 000,769,804 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/05 18:17:27 | 000,622,326 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/05 18:17:27 | 000,132,340 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/05 18:15:23 | 000,002,201 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Karma.lnk
[2010/04/05 06:59:38 | 735,600,640 | —- | M] () – C:\Documents and Settings\Dario\Desktop\P.S I Love You[2007]DvDrip-aXXo.avi
[2010/04/03 22:15:19 | 018,390,203 | —- | M] () – C:\Documents and Settings\Dario\Desktop\ATTRACT_GIRL.wmv
[2010/04/03 22:08:15 | 021,486,341 | —- | M] () – C:\Documents and Settings\Dario\Desktop\MONEY_MM.wmv
[2010/04/03 13:52:09 | 000,026,112 | —- | M] () – C:\Documents and Settings\Dario\My Documents\Life Is Not A Dream Song.doc
[2010/04/02 13:10:17 | 000,024,576 | —- | M] () – C:\Documents and Settings\Dario\My Documents\Missing you is what I do.doc
[2010/04/02 12:27:30 | 000,025,600 | —- | M] () – C:\Documents and Settings\Dario\My Documents\Every night I go to bed.doc
[2010/04/02 00:12:45 | 000,002,284 | —- | M] () – C:\Documents and Settings\Dario\Desktop\Google Chrome.lnk
[2010/03/26 17:12:37 | 000,025,600 | —- | M] () – C:\Documents and Settings\Dario\My Documents\Part 1 of 3.doc
[2010/03/25 19:38:54 | 000,002,179 | —- | M] () – C:\Documents and Settings\Dario\Desktop\eM Client.lnk
[2010/03/25 19:00:57 | 000,056,320 | —- | M] () – C:\Documents and Settings\Dario\Desktop\GoodLife Dealer Excel.doc
[2010/03/25 18:52:55 | 000,121,479 | —- | M] () – C:\Documents and Settings\Dario\Desktop\GoodLife Dealer Excel.rtf
[2010/03/25 17:28:26 | 000,027,410 | —- | M] () – C:\Documents and Settings\Dario\Desktop\GoodLife Dealer Excel.pdf
[2010/03/25 14:59:48 | 000,777,216 | —- | M] () – C:\Documents and Settings\Dario\My Documents\brand used laptop.doc
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/22 09:15:55 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\d3drm32.dll
[2010/04/22 08:15:49 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\cryptui32.dll
[2010/04/22 07:15:47 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\cryptdll32.dll
[2010/04/22 04:15:53 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\d3dim32.dll
[2010/04/22 03:15:57 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\datime3232.dll
[2010/04/22 02:16:04 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\bootvid32.dll
[2010/04/22 01:46:55 | 000,018,944 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2010/04/22 01:46:50 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2010/04/22 01:27:36 | 000,033,280 | —- | C] () – C:\WINDOWS\System32\dllcache\psisrndr.ax
[2010/04/22 01:27:28 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\dllcache\psisdecd.dll
[2010/04/22 01:21:48 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2010/04/22 01:19:33 | 001,158,818 | —- | C] () – C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010/04/22 01:18:22 | 000,134,339 | —- | C] () – C:\WINDOWS\System32\dllcache\imekr.lex
[2010/04/22 01:16:00 | 000,165,888 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt53.dll
[2010/04/22 01:15:53 | 000,093,696 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt42.dll
[2010/04/22 01:15:47 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt34.dll
[2010/04/22 01:15:41 | 000,089,088 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt33.dll
[2010/04/22 01:15:34 | 000,083,968 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt21.dll
[2010/04/22 01:15:17 | 000,108,827 | —- | C] () – C:\WINDOWS\System32\dllcache\hanja.lex
[2010/04/22 01:11:30 | 000,029,768 | —- | C] () – C:\WINDOWS\System32\dllcache\divasu.dll
[2010/04/22 01:11:28 | 000,037,962 | —- | C] () – C:\WINDOWS\System32\dllcache\divaprop.dll
[2010/04/22 01:11:26 | 000,006,216 | —- | C] () – C:\WINDOWS\System32\dllcache\divaci.dll
[2010/04/22 01:07:54 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\dllcache\ativxbar.sys
[2010/04/22 01:07:54 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\dllcache\atixbar.sys
[2010/04/22 01:07:53 | 000,019,456 | —- | C] () – C:\WINDOWS\System32\dllcache\ativttxx.sys
[2010/04/22 01:07:52 | 000,009,472 | —- | C] () – C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2010/04/22 01:07:51 | 000,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2010/04/22 01:07:51 | 000,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitunep.sys
[2010/04/22 01:07:50 | 000,026,880 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2010/04/22 01:07:49 | 000,049,920 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtcap.sys
[2010/04/22 01:07:48 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2010/04/22 01:07:41 | 000,046,464 | —- | C] () – C:\WINDOWS\System32\dllcache\atibt829.sys
[2010/04/22 00:53:48 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\dsdmoprp32.dll
[2010/04/21 17:30:49 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\devmgr32.dll
[2010/04/21 16:31:03 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\capicom32.dll
[2010/04/21 12:30:30 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\CRxmlx0932.dll
[2010/04/21 11:30:29 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\crxml19r32.dll
[2010/04/21 10:30:32 | 000,280,576 | —- | C] () – C:\WINDOWS\System32\cryptsvc32.dll
[2010/04/21 09:09:05 | 037,966,136 | —- | C] () – C:\Documents and Settings\Dario\Desktop\drweb-cureit.exe
[2010/04/21 09:06:56 | 000,495,104 | —- | C] () – C:\Documents and Settings\Dario\Desktop\rmvirut.nt
[2010/04/21 09:06:39 | 002,889,800 | —- | C] () – C:\Documents and Settings\Dario\Desktop\rmvirut.exe
[2010/04/20 16:18:50 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/04/20 16:18:42 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/04/20 16:18:30 | 059,117,484 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/04/20 08:57:30 | 000,001,973 | —- | C] () – C:\Documents and Settings\Dario\Desktop\SpyHunter.lnk
[2010/04/19 23:50:02 | 000,000,654 | —- | C] () – C:\Documents and Settings\Dario\Desktop\NFOPad.lnk
[2010/04/19 23:49:27 | 000,587,470 | —- | C] () – C:\Documents and Settings\Dario\Desktop\nfopad157.exe
[2010/04/19 09:53:32 | 000,000,020 | —- | C] () – C:\WINDOWS\System32\30e9ac3a
[2010/04/18 20:32:18 | 1071,828,992 | -HS- | C] () – C:\hiberfil.sys
[2010/04/18 13:36:19 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\crbas1932.dll
[2010/04/18 11:36:32 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\d3dx9_2732.dll
[2010/04/18 10:36:04 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\cfgbkend32.dll
[2010/04/18 10:18:02 | 000,010,752 | —- | C] () – C:\WINDOWS\DCEBoot.exe
[2010/04/18 09:50:41 | 000,000,036 | —- | C] () – C:\Documents and Settings\Dario\Local Settings\Application Data\housecall.guid.cache
[2010/04/18 09:23:12 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\cards32.dll
[2010/04/18 09:17:39 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\crbas19r32.dll
[2010/04/18 09:09:10 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\bitsprx432.dll
[2010/04/18 06:23:47 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\dbgeng3232.dll
[2010/04/18 05:23:46 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\datime32.dll
[2010/04/18 03:23:02 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood32.dll
[2010/04/18 02:23:08 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\BtWizard32.dll
[2010/04/17 20:23:43 | 000,001,057 | -HS- | C] () – C:\WINDOWS\System32\809106285
[2010/04/17 20:23:42 | 000,000,817 | —- | C] () – C:\WINDOWS\System32\1617537853
[2010/04/17 20:22:42 | 000,000,113 | —- | C] () – C:\WINDOWS\System32\sl1373137407
[2010/04/17 20:22:36 | 000,239,616 | —- | C] () – C:\WINDOWS\System32\CRxmlx09r32.dll
[2010/04/17 20:22:28 | 000,203,776 | -HS- | C] () – C:\WINDOWS\System32\unrar.exe
[2010/04/17 20:22:03 | 000,003,631 | -HS- | C] () – C:\Documents and Settings\Dario\Application Data\020000007f692e36879P.manifest
[2010/04/17 20:22:03 | 000,000,051 | -HS- | C] () – C:\Documents and Settings\Dario\Application Data\020000007f692e36879C.manifest
[2010/04/17 20:22:03 | 000,000,011 | -HS- | C] () – C:\Documents and Settings\Dario\Application Data\020000007f692e36879S.manifest
[2010/04/17 20:22:03 | 000,000,011 | -HS- | C] () – C:\Documents and Settings\Dario\Application Data\020000007f692e36879O.manifest
[2010/04/17 20:22:01 | 000,140,288 | —- | C] () – C:\WINDOWS\System32\bthci32.dll
[2010/04/14 23:30:04 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/04/06 09:06:54 | 000,039,424 | —- | C] () – C:\Documents and Settings\Dario\My Documents\Friends and Lovers for Dario Renato Melkuhn and Margaretha Niestadt.doc
[2010/04/05 22:32:21 | 735,600,640 | —- | C] () – C:\Documents and Settings\Dario\Desktop\P.S I Love You[2007]DvDrip-aXXo.avi
[2010/04/03 22:15:19 | 018,390,203 | —- | C] () – C:\Documents and Settings\Dario\Desktop\ATTRACT_GIRL.wmv
[2010/04/03 22:08:15 | 021,486,341 | —- | C] () – C:\Documents and Settings\Dario\Desktop\MONEY_MM.wmv
[2010/04/02 13:10:17 | 000,024,576 | —- | C] () – C:\Documents and Settings\Dario\My Documents\Missing you is what I do.doc
[2010/04/02 12:31:47 | 000,026,112 | —- | C] () – C:\Documents and Settings\Dario\My Documents\Life Is Not A Dream Song.doc
[2010/03/26 19:23:15 | 000,025,600 | —- | C] () – C:\Documents and Settings\Dario\My Documents\Every night I go to bed.doc
[2010/03/26 17:12:34 | 000,025,600 | —- | C] () – C:\Documents and Settings\Dario\My Documents\Part 1 of 3.doc
[2010/03/25 19:00:57 | 000,056,320 | —- | C] () – C:\Documents and Settings\Dario\Desktop\GoodLife Dealer Excel.doc
[2010/03/25 18:52:55 | 000,121,479 | —- | C] () – C:\Documents and Settings\Dario\Desktop\GoodLife Dealer Excel.rtf
[2010/03/25 18:51:46 | 000,027,410 | —- | C] () – C:\Documents and Settings\Dario\Desktop\GoodLife Dealer Excel.pdf
[2010/03/17 16:03:26 | 000,000,067 | —- | C] () – C:\WINDOWS\pdf2text.INI
[2010/02/23 10:41:11 | 000,000,000 | —- | C] () – C:\WINDOWS\cedt.INI
[2010/02/16 10:56:48 | 000,000,099 | —- | C] () – C:\WINDOWS\ANS2000.INI
[2010/02/16 10:56:48 | 000,000,020 | -H– | C] () – C:\WINDOWS\akebook.ini
[2010/02/16 10:56:48 | 000,000,004 | -H– | C] () – C:\WINDOWS\a3kebook.ini
[2009/10/17 17:50:27 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\Margo_KBD.ini
[2009/10/02 18:34:06 | 000,183,159 | —- | C] () – C:\WINDOWS\System32\drivers\VVBackd5.sys
[2009/08/13 17:20:18 | 000,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/06/22 15:02:27 | 000,000,050 | —- | C] () – C:\WINDOWS\Winamp.ini
[2009/06/22 15:02:14 | 000,000,041 | —- | C] () – C:\WINDOWS\winampa.ini
[2009/06/09 15:39:53 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2009/03/27 21:36:27 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\kareoke_KBD.ini
[2008/10/28 09:53:17 | 000,393,216 | —- | C] () – C:\WINDOWS\System32\TAGDLL.dll
[2008/10/28 09:53:17 | 000,221,184 | —- | C] () – C:\WINDOWS\System32\ewaudio.dll
[2008/10/28 09:53:16 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\wavedest.dll
[2008/10/19 09:44:23 | 000,008,864 | —- | C] () – C:\WINDOWS\System32\drivers\MARXDEV3.SYS
[2008/10/19 09:44:23 | 000,008,864 | —- | C] () – C:\WINDOWS\System32\drivers\MARXDEV2.SYS
[2008/10/19 09:44:23 | 000,008,864 | —- | C] () – C:\WINDOWS\System32\drivers\MARXDEV1.SYS
[2008/10/19 09:44:14 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2008/08/26 12:15:22 | 000,000,000 | —- | C] () – C:\WINDOWS\frontpg.ini
[2008/08/26 12:13:10 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2008/08/26 12:13:10 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2008/08/26 12:12:45 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2008/08/26 12:12:45 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2008/08/26 12:12:44 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2008/08/25 19:58:42 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\administrator_KBD.ini
[2008/08/19 23:07:56 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\DBQARM.dll
[2008/08/06 16:13:52 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/08/06 16:10:52 | 000,000,027 | —- | C] () – C:\WINDOWS\CDE DX4400DEFGIPS.ini
[2007/10/10 03:04:39 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/05/14 22:44:54 | 000,000,182 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/12/11 11:44:40 | 000,000,167 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/12/08 02:47:37 | 000,000,256 | —- | C] () – C:\WINDOWS\MYOBP.INI
[2006/12/08 02:47:37 | 000,000,121 | —- | C] () – C:\WINDOWS\SwDrvs.ini
[2006/12/08 02:47:37 | 000,000,039 | —- | C] () – C:\WINDOWS\MYOB.INI
[2006/12/08 02:42:16 | 000,000,000 | —- | C] () – C:\WINDOWS\drvxl32.INI
[2006/12/08 02:42:15 | 000,000,000 | —- | C] () – C:\WINDOWS\drvwd32.INI
[2006/12/08 01:02:22 | 000,000,081 | —- | C] () – C:\WINDOWS\SGREP32.INI
[2006/11/21 18:46:40 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2006/10/18 10:08:56 | 000,015,493 | —- | C] () – C:\WINDOWS\snct511.ini
[2006/10/18 10:08:55 | 000,229,376 | —- | C] () – C:\WINDOWS\System32\drivers\snct511.sys
[2006/10/18 10:08:55 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dsnct511.dll
[2006/10/18 10:08:55 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\vsnct511.dll
[2006/09/22 16:42:19 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/09/22 03:22:03 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/09/11 17:20:04 | 000,033,920 | —- | C] () – C:\WINDOWS\System32\drivers\SRS_SSCFilter.sys
[2006/09/11 17:20:02 | 000,041,216 | —- | C] () – C:\WINDOWS\System32\drivers\Surroundhp_kern_i386.sys
[2006/09/11 17:20:02 | 000,036,992 | —- | C] () – C:\WINDOWS\System32\drivers\csiidecoder_kern_i386.sys
[2006/09/11 17:20:00 | 000,042,624 | —- | C] () – C:\WINDOWS\System32\drivers\tsxt_kern_i386.sys
[2006/07/24 12:11:23 | 000,777,728 | —- | C] () – C:\WINDOWS\System32\SSLSVC.DLL
[2006/07/24 12:11:23 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\xmltok.dll
[2006/07/24 12:11:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\cfmsg.dll
[2006/07/24 12:11:23 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\xmlparse.dll
[2006/07/24 12:11:22 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\lang_cfml.dll
[2006/07/24 12:11:22 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\xml_datagrove.dll
[2006/07/23 03:10:11 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2006/07/22 20:05:02 | 000,000,138 | —- | C] () – C:\WINDOWS\usrwiz.ini
[2006/07/22 06:58:38 | 000,000,617 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/07/22 02:39:05 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\Dario_KBD.ini
[2006/07/22 00:00:50 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2006/07/22 00:00:29 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\adistres.dll
[2006/07/21 20:55:12 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\TaskKeyHook.dll
[2006/07/21 16:47:13 | 000,884,736 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2006/07/21 16:47:13 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/07/21 16:47:13 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/07/21 16:47:13 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\oggds.dll
[2006/07/21 16:47:13 | 000,157,696 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/07/21 16:47:13 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/07/21 16:47:13 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2006/07/21 16:47:13 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\vorbisfile.dll
[2006/07/21 16:47:13 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2006/07/21 16:47:12 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/06/01 23:00:35 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/13 03:50:53 | 000,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2006/05/13 03:50:53 | 000,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2006/05/13 03:48:15 | 000,000,683 | —- | C] () – C:\WINDOWS\InstNapster.ini
[2006/05/13 03:47:44 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2006/05/13 03:47:42 | 000,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2006/05/13 03:47:42 | 000,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2006/05/13 03:47:42 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2006/05/13 03:47:42 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2006/05/13 03:47:42 | 000,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2006/05/13 03:47:42 | 000,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2006/05/13 03:47:42 | 000,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2006/05/13 03:47:42 | 000,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2006/05/13 03:47:42 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2006/05/13 03:47:42 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2006/05/13 03:47:42 | 000,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2006/05/13 03:47:42 | 000,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2006/05/13 03:47:42 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2006/05/13 03:47:42 | 000,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2006/05/13 03:45:26 | 000,043,512 | —- | C] () – C:\WINDOWS\System32\drivers\RITCPT.SYS
[2006/05/13 03:40:03 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006/05/13 03:39:56 | 000,000,508 | —- | C] () – C:\WINDOWS\SamsungBluetooth.ini
[2006/05/13 03:29:19 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/05/13 03:29:19 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/05/13 03:29:17 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/05/13 03:29:15 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/05/13 03:29:12 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/01/26 00:00:50 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\AVSAudioAmp.dll
[2006/01/26 00:00:50 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\AVSAudioWideStereoDMO.dll
[2005/09/19 16:50:42 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/09/10 23:35:11 | 000,004,300 | R— | C] () – C:\WINDOWS\System32\MEMIO.SYS
[2005/09/10 22:11:47 | 000,000,241 | —- | C] () – C:\WINDOWS\region.ini
[2005/09/10 21:57:05 | 000,000,780 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/08/24 12:29:56 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\SDOApp.dll
[2004/08/12 12:22:10 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\SGSchemeXP.dll
[2004/08/12 12:22:02 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\SGSchemeManager.dll
[2004/08/12 12:21:44 | 000,086,063 | —- | C] () – C:\WINDOWS\System32\SGCOM32.DLL
[2004/08/12 12:21:40 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\SGSchemeDefault.dll
[2004/08/12 12:21:26 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\SGWebBrowser.dll
[2004/08/12 12:21:20 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\SGCtrlEx.dll
[2004/08/12 12:21:08 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\SageFolderBrowser.dll
[2004/08/12 12:21:04 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\SGTBAR32.DLL
[2004/08/12 12:20:54 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\SGSTAT32.DLL
[2004/08/12 12:20:52 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\SGJPEG32.dll
[2004/08/12 12:20:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\SGLOGO32.DLL
[2004/08/12 12:20:42 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\SGCDLG32.DLL
[2004/08/12 12:20:24 | 000,278,528 | —- | C] () – C:\WINDOWS\System32\SGLIST32.DLL
[2004/08/12 12:20:06 | 000,274,432 | —- | C] () – C:\WINDOWS\System32\SGTOOL32.DLL
[2004/08/12 12:19:56 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\SGINTL32.DLL
[2004/08/12 12:19:54 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\SGDT32.DLL
[2004/08/12 12:19:52 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\SGHELP32.DLL
[2004/08/12 12:19:48 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\SGAPPBAR.DLL
[2004/08/12 12:19:24 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\SG3D32.DLL
[2004/08/10 17:29:02 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\SGLCH32.DLL
[2004/08/10 17:27:00 | 001,630,208 | —- | C] () – C:\WINDOWS\System32\SGREP32.DLL
[2004/07/08 09:19:56 | 000,001,187 | —- | C] () – C:\WINDOWS\Sageintl.ini
[2003/06/11 18:39:12 | 006,270,976 | —- | C] () – C:\WINDOWS\System32\cricu19.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/05/16 00:29:04 | 000,000,607 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2002/04/16 12:27:54 | 000,000,005 | -HS- | C] () – C:\WINDOWS\System32\CdI5T.drv
[2002/04/01 19:45:50 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\ODBCMON.DLL
[2002/02/27 10:41:28 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\nsldappr32v50.dll
[2002/02/27 10:41:26 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\nsldap32v50.dll
[2002/02/27 10:41:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\nsldapssl32v50.dll
[2001/11/23 19:18:00 | 000,000,597 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/07/07 05:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1999/10/25 11:53:58 | 000,006,318 | —- | C] () – C:\WINDOWS\Sage.ini
[1998/10/11 01:07:38 | 000,088,576 | —- | C] () – C:\WINDOWS\System32\Iticheck.dll
[1998/03/26 02:12:00 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\SgHmZLib.dll

========== LOP Check ==========

[2009/02/26 15:05:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2010/04/20 16:19:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/04/20 16:18:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/02/23 02:32:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2007/07/03 23:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BeInSync Settings
[2008/08/06 16:12:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2010/02/24 00:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2008/12/11 11:18:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GatherBird
[2008/11/09 20:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2008/11/22 10:29:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ilktcpwx
[2010/03/02 00:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2009/08/13 16:55:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Latshaw Systems
[2008/11/09 20:58:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Launcher
[2010/01/08 22:02:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MipKukSoft
[2010/02/23 19:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MySQL
[2006/07/23 03:15:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/11/05 18:11:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/07/13 11:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2006/09/25 01:14:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SRS Labs
[2008/09/11 17:04:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SWiSHMax2WorkFolder
[2010/04/20 08:28:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/08/19 23:10:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TheDevShop
[2008/08/06 16:19:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2006/10/09 10:26:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Abuse
[2010/02/23 10:30:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Azureus
[2010/03/25 19:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\eM Client
[2009/06/09 15:39:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\EPSON
[2010/02/26 21:10:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\FileZilla
[2008/12/11 11:18:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\GatherBird
[2006/07/21 23:58:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\InterTrust
[2010/03/02 01:24:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\IObit
[2007/04/05 07:57:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Itsth
[2010/03/20 18:46:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\KomaMail
[2010/01/08 22:08:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Kybtec Software
[2008/08/27 21:23:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Likno
[2010/04/19 23:58:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\LimeWire
[2007/03/27 00:30:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\MessengerSkinner
[2010/01/08 22:05:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\MipKukSoft
[2009/11/05 18:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\NCH Swift Sound
[2010/03/04 22:39:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\NetSpell
[2010/03/23 03:25:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\nswb
[2010/03/09 22:17:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\PCTV4Me
[2008/10/24 21:33:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Search Settings
[2010/01/12 22:00:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\SWiSH Max3
[2010/04/21 09:30:35 | 000,000,000 | -HSD | M] – C:\Documents and Settings\Dario\Application Data\SystemProc
[2010/03/02 00:38:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\TmpRecentIcons
[2010/04/20 08:21:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\Toolbar4
[2010/04/17 18:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\uTorrent
[2010/02/27 16:31:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Dario\Application Data\VoipStunt
[2010/04/19 00:36:17 | 000,000,384 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< c:\windows\system32\drivers\*.sys /90 >
[2010/04/20 16:18:43 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys
[2010/04/20 16:18:42 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys
[2010/04/21 09:10:09 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgtdix.sys
[2010/02/24 15:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/02/11 14:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys


< MD5 for: AGP440.SYS >
[2004/08/04 14:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/26 12:57:51 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 14:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/08/26 12:57:51 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 20:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 20:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 20:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 08:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 14:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/26 12:57:51 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 14:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/08/26 12:57:51 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 20:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 07:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 07:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 02:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 02:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 02:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 14:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/14 02:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 02:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 02:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 14:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 14:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 02:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 02:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 02:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >


I will keep trying GMER and if it succeeds will send report


Thanks
Dario
Hi,

Why do you need to reinstall SP3?

I advise you to also uninstall IObit as you already have Malwarebytes, Spyhunter and AVG and it is also considered as rougue.

Also, running more than one anti spyware at the same time does not only slow down your computer but provides less protection than they are programmed to do, due to the fact that they will be conflicting with each other rather than providing sufficient protection for your computer. Please uninstall one of your anti spyware before proceeding with any of the fixes.

–Next–

Run GMER with the settings provided above but now click on "Files" to uncheck it. If that still won't work run it in safe mode.
To do this,
  • Restart your computer.
  • Keep on tapping f8 when windows starts to boot. Do this before you see the windows screen.
  • When a list of menu appears, scroll to Safe Mode using the arrow keys then press Enter.
I know running more than one av is detremental, I run avg free the others are only run/activated if I have a problem, I have only just stared using IOBIT and am not impressed. I have been cleaning viruses for many years its just that once in a while you come across something and end up scratching your head pfffffffff…. like this one. Yesterday it came to a head even though avg scan was disabled it was picking up bthci32.dll, it was so bad popping up every 30 seconds or so, This is what I did. Disabled AVG removed google chrome removed ie8 rebooted Ran MalwareBytes full scan (took hours) rebooted turned off restore turned on restore to create new restore point Ran MalwareBytes (quick scan) rebooted reinstalled ie8 (lucky I have firefox installed) reinstalled Google Chrome. rebooted Now the scan function in AVG works again Download function in IE8 and Chrome work IE8 seems to be blocking certain sites like cnet download anyway will try to run gmer now again and send report to you regards Dario
Hi,

Please do not run any more fixes or scans other than what is advised as it will be difficult in determining what is happening in your computer and your computer is severely infected.

Your log shows signs of a trojan infection. The capabilities of this particular trojan include keylogging and password stealing so I advise you to take all precautions to safeguard your accounts, passwords, and sensitive data. If you have entered any credit card details or use your computer for financial/banking transactions, you should notify your banks and financial institutions that you may have been a victim of identity theft and to put a watch on your accounts. For more information, please read How to report ID theft, fraud, drive-by installs, hijacking and malware. I also recommend that you change your online passwords for email, banks, etc., immediately – from a clean computer. It bears repeating to change passwords from a clean computer only.

Many experts believe that once a computer has been infected with this type of Trojan, it is best to reformat and reinstall the Operating System. The reason is that even after cleaning, there may be some remnants left in the system. It is hard to discern how much damage has been done. Only you can decide whether it would be best to reformat and start over. We can proceed with the cleanup process if you prefer. If you decide to reformat, be sure save your important data to backup media but make sure that you scan it all before you put it back on a clean system. Please read the following: When should I re-format? How should I reinstall?

If you wish to continue with the clean up, please proceed with the following:

–Next–

You have LimeWire and µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/d/security-centra…-p-id-theft-103

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall LimeWire and µTorrent, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx

–Next–

Please go to VirSCAN
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box:
    C:\WINDOWS\System32\unrar.exe
  • Click Submit. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Please post the results in your next reply.

–Next–

Download Combofix from any of the links below. You must rename it before saving it. Save it as SubsFix.exe

* IMPORTANT !!! Save SubsFix.exe to your Desktop

Link 1
Link 2

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

To post in your next reply:
1. VirSCAN log.
2. Combofix log.
3. GMER log.
Fortunatley my banking is very secure there are three passwords which change regularly and to do any transactions I have an electronic password authorisation creator that works with my debit card. So security is very tight.

Unfortunatley I do need Utorrent and LimeWire but I never leave them running, I download what I need then close them and always comprehensivley check all downloads for infections.

GMER will still not run, seems like my system does not like it. my system either freezes or just reboots and once had blue screen. should I try it in safe mode?

The symptoms I had seem to be gone for the moment, however I dont know if the core virus is still lurking waiting to pounce. I still have some problems with IE8, I can download again but locations as CNET/Downloads just give me a blank screen……. Chrome seems to work ok now

Here is the VirScan Report

VirSCAN.org Scanned Report :
Scanned time : 2010/04/23 11:16:49 (CEST)
Scanner results: Scanners did not find malware!
File Name : unrar.exe
File Size : 203776 byte
File Type : PE32 executable for MS Windows (console) Intel 80386 32-bit
MD5 : f7c23cd5d2ea3c77c68405111b8616c6
SHA1 : e39924883889955aaff215323c2e27b616380c0a
Online report : http://virscan.org/report/599714956e30b99f…4f723a0ed8.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100423053124 2010-04-23 40.13 -
AhnLab V3 2010.04.23.00 2010.04.23 2010-04-23 40.12 -
AntiVir 8.2.1.220 7.10.6.175 2010-04-22 0.27 -
Antiy 2.0.18 20100422.4243894 2010-04-22 0.12 -
Arcavir 2009 201004221602 2010-04-22 0.12 -
Authentium 5.1.1 201004222253 2010-04-22 2.34 -
AVAST! 4.7.4 100422-1 2010-04-22 0.02 -
AVG 8.5.720 271.1.1/2829 2010-04-23 0.26 -
BitDefender 7.81008.5686597 7.31345 2010-04-23 3.67 -
ClamAV 0.95.3 10793 2010-04-23 0.05 -
Comodo 3.13.579 4668 2010-04-22 40.13 -
CP Secure 1.3.0.5 2010.04.20 2010-04-20 0.07 -
Dr.Web 5.0.2.3300 2010.04.23 2010-04-23 6.74 -
F-Prot 4.4.4.56 20100422 2010-04-22 2.21 -
F-Secure 7.02.73807 2010.04.23.03 2010-04-23 0.18 -
Fortinet 4.0.14 11.735 2010-04-22 40.13 -
GData 21.11/21.4 20100423 2010-04-23 40.13 -
ViRobot 20100422 2010.04.22 2010-04-22 40.13 -
Ikarus T3.1.01.80 2010.04.23.75694 2010-04-23 5.83 -
JiangMin 13.0.900 2010.04.23 2010-04-23 40.13 -
Kaspersky 5.5.10 2010.04.22 2010-04-22 0.13 -
KingSoft 2009.2.5.15 2010.4.23.9 2010-04-23 40.12 -
McAfee 5400.1158 5955 2010-04-18 0.02 -
Microsoft 1.5703 2010.04.22 2010-04-22 40.15 -
Norman 6.04.11 6.04.00 2010-04-22 8.01 -
Panda 9.05.01 2010.04.22 2010-04-22 40.13 -
Trend Micro 9.120-1004 7.122.07 2010-04-23 0.04 -
Quick Heal 10.00 2010.04.23 2010-04-23 40.12 -
Rising 20.0 22.44.04.03 2010-04-23 40.13 -
Sophos 3.06.0 4.52 2010-04-23 3.92 -
Sunbelt 3.9.2418.2 6211 2010-04-22 40.14 -
Symantec 1.3.0.24 20100422.002 2010-04-22 23.57 -
nProtect 20100421.01 8037035 2010-04-21 40.13 -
The Hacker 6.5.2.0 v00267 2010-04-22 40.13 -
VBA32 3.12.12.4 20100422.0906 2010-04-22 3.14 -
VirusBuster 4.5.11.10 10.124.25/2031751 2010-04-22 2.55 -
Hi,

Good to know that your passwords are secure, but please don't use the infected computer to do banking transactions and using P2P programs until we're through. :thumbup:

GMER will still not run, seems like my system does not like it. my system either freezes or just reboots and once had blue screen. should I try it in safe mode?

Yes please, if that still won't work then uncheck "Files" and run it in safe mode.

How about Combofix? Were you able to run it? If so, please post the log.
GMER wont run even in safe mode with files unticked

Combifix report
ComboFix 10-04-21.01 - Dario 23/04/2010 12:32:51.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.384 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\SubsFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\Administrator\Application Data\020000007f692e36879C.manifest
c:\documents and settings\Administrator\Application Data\020000007f692e36879O.manifest
c:\documents and settings\Administrator\Application Data\020000007f692e36879P.manifest
c:\documents and settings\Administrator\Application Data\020000007f692e36879S.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2tbq3h3z.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}\install.rdf
c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
c:\documents and settings\Dario\Application Data\020000007f692e36879C.manifest
c:\documents and settings\Dario\Application Data\020000007f692e36879O.manifest
c:\documents and settings\Dario\Application Data\020000007f692e36879P.manifest
c:\documents and settings\Dario\Application Data\020000007f692e36879S.manifest
c:\documents and settings\Dario\Application Data\MessengerSkinner\Userdata\defaultPack.cab
c:\documents and settings\Dario\Application Data\MessengerSkinner\Userdata\languages.xml
c:\documents and settings\Dario\Application Data\MessengerSkinner\Userdata\pack1.cab
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}\chrome.manifest
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}\chrome\xulcache.jar
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}\defaults\preferences\xulcache.js
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{66741aa5-35e0-4abc-b573-52639b5af841}\install.rdf
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}\chrome.manifest
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}\chrome\xulcache.jar
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}\defaults\preferences\xulcache.js
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f0d461c0-aff8-490e-9bf6-cee080be8d4f}\install.rdf
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}\chrome.manifest
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}\chrome\xulcache.jar
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}\defaults\preferences\xulcache.js
c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{f4742f63-801e-49a1-b37f-0d6d0f778666}\install.rdf
c:\documents and settings\drm ent\AUTORUN.INF
c:\program files\f3setupinstall\f3initialsetup1.0.1.1.inf
c:\program files\Search Settings\kb127\SearchSettingsRes409.dll
c:\program files\Search Settings\SearchSettings.exe
c:\sysmon\f3install\vnnha82414.exe
c:\sysmon\fajf2411\nxae2714.exe
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\pack.epk
c:\windows\system32\1381747802\new.i0
c:\windows\system32\1381747802\new.i4
c:\windows\system32\capicom32.dll
c:\windows\system32\credui32.dll
c:\windows\system32\crxml19r32.dll
c:\windows\system32\CRxmlx0932.dll
c:\windows\system32\cryptdll32.dll
c:\windows\system32\cryptsvc32.dll
c:\windows\system32\datime3232.dll
c:\windows\system32\dbgeng3232.dll
c:\windows\system32\dsprop32.dll
c:\windows\system32\dsprop3232.dll
c:\windows\system32\eappprxy32.dll
c:\windows\system32\install.exe
c:\windows\system32\Temp\Kara_K5V.dll
c:\windows\system32\tmp.reg
c:\windows\system32\unrar.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IPRIP
——-\Legacy_NPF
——-\Legacy_SSHNAS
——-\Service_Iprip
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2010-03-23 to 2010-04-23 )))))))))))))))))))))))))))))))
.

2010-04-22 21:04 . 2010-04-22 21:06 ——– dc—-w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-22 21:02 . 2010-04-22 21:02 ——– dc—-w- c:\documents and settings\Dario\Application Data\Windows Desktop Search
2010-04-22 20:43 . 2010-04-22 20:43 ——– dc—-w- c:\program files\Windows Desktop Search
2010-04-22 20:24 . 2010-02-23 12:04 1664256 -c–a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-04-22 20:10 . 2010-04-22 20:11 ——– dc-h–w- c:\windows\ie8
2010-04-21 23:48 . 2010-04-21 23:48 ——– dc—-w- c:\documents and settings\Dario\BackUp
2010-04-21 23:47 . 2008-04-14 00:12 116224 -c–a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-04-21 23:46 . 2001-08-17 20:36 23040 -c–a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-04-21 23:46 . 2008-04-14 00:12 18944 -c–a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-04-21 23:46 . 2001-08-17 20:37 27648 -c–a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-04-21 23:46 . 2001-08-17 20:37 4608 -c–a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-04-21 23:46 . 2001-08-17 20:37 99865 -c–a-w- c:\windows\system32\dllcache\xlog.exe
2010-04-21 23:46 . 2001-08-17 10:11 16970 -c–a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-04-21 23:45 . 2004-08-03 20:29 19455 -c–a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-04-21 23:45 . 2004-08-03 20:29 12063 -c–a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-04-21 23:45 . 2004-08-03 20:31 154624 -c–a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-04-21 23:45 . 2001-08-17 10:12 34890 -c–a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-04-21 23:45 . 2001-08-17 11:28 771581 -c–a-w- c:\windows\system32\dllcache\winacisa.sys
2010-04-21 23:45 . 2001-08-17 20:36 53760 -c–a-w- c:\windows\system32\dllcache\wiamsmud.dll
2010-04-21 23:45 . 2001-08-17 20:36 87040 -c–a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-04-21 23:43 . 2001-08-17 11:28 604253 -c–a-w- c:\windows\system32\dllcache\vmodem.sys
2010-04-21 23:43 . 2001-08-17 10:14 249402 -c–a-w- c:\windows\system32\dllcache\vinwm.sys
2010-04-21 23:43 . 2001-08-17 11:49 24576 -c–a-w- c:\windows\system32\dllcache\viairda.sys
2010-04-21 23:43 . 2001-08-17 11:28 687999 -c–a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2010-04-21 23:43 . 2001-08-17 11:28 765884 -c–a-w- c:\windows\system32\dllcache\usrti.sys
2010-04-21 23:43 . 2001-08-17 11:28 113762 -c–a-w- c:\windows\system32\dllcache\usrpda.sys
2010-04-21 23:43 . 2001-08-17 11:28 7556 -c–a-w- c:\windows\system32\dllcache\usroslba.sys
2010-04-21 23:43 . 2001-08-17 11:28 224802 -c–a-w- c:\windows\system32\dllcache\usr1807a.sys
2010-04-21 23:43 . 2001-08-17 11:28 794399 -c–a-w- c:\windows\system32\dllcache\usr1806v.sys
2010-04-21 23:43 . 2001-08-17 11:28 793598 -c–a-w- c:\windows\system32\dllcache\usr1806.sys
2010-04-21 23:42 . 2001-08-17 11:28 794654 -c–a-w- c:\windows\system32\dllcache\usr1801.sys
2010-04-21 23:42 . 2008-04-13 18:45 26112 -c–a-w- c:\windows\system32\dllcache\usbser.sys
2010-04-21 23:42 . 2008-04-13 18:45 17152 -c–a-w- c:\windows\system32\dllcache\usbohci.sys
2010-04-21 23:42 . 2004-08-03 20:31 32384 -c–a-w- c:\windows\system32\dllcache\usb101et.sys
2010-04-21 23:42 . 2001-08-17 20:36 94720 -c–a-w- c:\windows\system32\dllcache\umaxud32.dll
2010-04-21 23:42 . 2001-08-17 20:36 28160 -c–a-w- c:\windows\system32\dllcache\umaxu40.dll
2010-04-21 23:42 . 2001-08-17 20:36 26624 -c–a-w- c:\windows\system32\dllcache\umaxu22.dll
2010-04-21 23:42 . 2001-08-17 20:36 69632 -c–a-w- c:\windows\system32\dllcache\umaxu12.dll
2010-04-21 23:41 . 2001-08-17 20:36 50688 -c–a-w- c:\windows\system32\dllcache\umaxscan.dll
2010-04-21 23:41 . 2001-08-17 11:58 22912 -c–a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-04-21 23:41 . 2001-08-17 20:36 50176 -c–a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-04-21 23:41 . 2001-08-17 20:36 47616 -c–a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-04-21 23:41 . 2001-08-17 20:36 211968 -c–a-w- c:\windows\system32\dllcache\um54scan.dll
2010-04-21 23:41 . 2001-08-17 20:36 216064 -c–a-w- c:\windows\system32\dllcache\um34scan.dll
2010-04-21 23:41 . 2001-08-17 11:48 11520 -c–a-w- c:\windows\system32\dllcache\twotrack.sys
2010-04-21 23:41 . 2001-08-17 10:51 166784 -c–a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-04-21 23:40 . 2001-08-17 20:36 525568 -c–a-w- c:\windows\system32\dllcache\tridxp.dll
2010-04-21 23:40 . 2001-08-17 10:51 159232 -c–a-w- c:\windows\system32\dllcache\tridkbm.sys
2010-04-21 23:40 . 2001-08-17 12:56 440576 -c–a-w- c:\windows\system32\dllcache\tridkb.dll
2010-04-21 23:40 . 2001-08-17 10:51 222336 -c–a-w- c:\windows\system32\dllcache\trid3dm.sys
2010-04-21 23:40 . 2001-08-17 12:56 315520 -c–a-w- c:\windows\system32\dllcache\trid3d.dll
2010-04-21 23:40 . 2001-08-17 10:12 34375 -c–a-w- c:\windows\system32\dllcache\tpro4.sys
2010-04-21 23:40 . 2001-08-17 20:35 42496 -c–a-w- c:\windows\system32\dllcache\tp4res.dll
2010-04-21 23:40 . 2008-04-14 00:12 82944 -c–a-w- c:\windows\system32\dllcache\tp4mon.exe
2010-04-21 23:40 . 2001-08-17 20:36 31744 -c–a-w- c:\windows\system32\dllcache\tp4.dll
2010-04-21 23:39 . 2001-08-17 12:02 230912 -c–a-w- c:\windows\system32\dllcache\tosdvd03.sys
2010-04-21 23:39 . 2001-08-17 12:01 241664 -c–a-w- c:\windows\system32\dllcache\tosdvd02.sys
2010-04-21 23:39 . 2001-08-17 10:10 28232 -c–a-w- c:\windows\system32\dllcache\tos4mo.sys
2010-04-21 23:39 . 2001-08-17 10:14 123995 -c–a-w- c:\windows\system32\dllcache\tjisdn.sys
2010-04-21 23:39 . 2001-08-17 10:51 138528 -c–a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2010-04-21 23:39 . 2001-08-17 12:56 81408 -c–a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-04-21 23:39 . 2008-04-13 18:40 149376 -c–a-w- c:\windows\system32\dllcache\tffsport.sys
2010-04-21 23:39 . 2001-08-17 10:13 17129 -c–a-w- c:\windows\system32\dllcache\tdkcd31.sys
2010-04-21 23:39 . 2001-08-17 10:13 37961 -c–a-w- c:\windows\system32\dllcache\tdk100b.sys
2010-04-21 23:38 . 2001-08-17 11:49 30464 -c–a-w- c:\windows\system32\dllcache\tbatm155.sys
2010-04-21 23:38 . 2001-08-17 11:52 7040 -c–a-w- c:\windows\system32\dllcache\tandqic.sys
2010-04-21 23:38 . 2001-08-17 10:50 36640 -c–a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-04-21 23:38 . 2001-08-17 12:56 172768 -c–a-w- c:\windows\system32\dllcache\t2r4disp.dll
2010-04-21 23:38 . 2001-08-17 20:36 94293 -c–a-w- c:\windows\system32\dllcache\sxports.dll
2010-04-21 23:38 . 2001-08-17 11:50 103936 -c–a-w- c:\windows\system32\dllcache\sx.sys
2010-04-21 23:38 . 2001-08-17 12:02 3968 -c–a-w- c:\windows\system32\dllcache\swusbflt.sys
2010-04-21 23:38 . 2001-08-17 20:36 10240 -c–a-w- c:\windows\system32\dllcache\swpidflt.dll
2010-04-21 23:37 . 2001-08-17 20:36 10240 -c–a-w- c:\windows\system32\dllcache\swpdflt2.dll
2010-04-21 23:37 . 2001-08-17 20:36 53760 -c–a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-04-21 23:37 . 2001-08-17 20:36 41472 -c–a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-04-21 23:37 . 2001-08-17 20:36 155648 -c–a-w- c:\windows\system32\dllcache\stlnprop.dll
2010-04-21 23:37 . 2001-08-17 20:36 53248 -c–a-w- c:\windows\system32\dllcache\stlncoin.dll
2010-04-21 23:37 . 2001-08-17 10:18 285760 -c–a-w- c:\windows\system32\dllcache\stlnata.sys
2010-04-21 23:37 . 2001-08-17 11:51 16896 -c–a-w- c:\windows\system32\dllcache\stcusb.sys
2010-04-21 23:37 . 2001-08-17 10:11 48736 -c–a-w- c:\windows\system32\dllcache\srwlnd5.sys
2010-04-21 23:37 . 2001-08-17 20:36 99328 -c–a-w- c:\windows\system32\dllcache\srusd.dll
2010-04-21 23:36 . 2001-08-17 20:36 24660 -c–a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-04-21 23:36 . 2001-08-17 11:51 61824 -c–a-w- c:\windows\system32\dllcache\speed.sys
2010-04-21 23:36 . 2001-08-17 20:36 106584 -c–a-w- c:\windows\system32\dllcache\spdports.dll
2010-04-21 23:36 . 2001-08-17 11:56 7552 -c–a-w- c:\windows\system32\dllcache\sonypvu1.sys
2010-04-21 23:36 . 2001-08-17 10:51 37040 -c–a-w- c:\windows\system32\dllcache\sonypi.sys
2010-04-21 23:36 . 2001-08-17 20:36 114688 -c–a-w- c:\windows\system32\dllcache\sonypi.dll
2010-04-21 23:36 . 2001-08-17 10:51 20752 -c–a-w- c:\windows\system32\dllcache\sonync.sys
2010-04-21 23:36 . 2001-08-17 11:53 9600 -c–a-w- c:\windows\system32\dllcache\sonymc.sys
2010-04-21 23:36 . 2008-04-13 18:40 7552 -c–a-w- c:\windows\system32\dllcache\sonyait.sys
2010-04-21 23:36 . 2004-08-04 12:00 143422 -c–a-w- c:\windows\system32\dllcache\softkey.dll
2010-04-21 23:35 . 2001-08-17 11:53 7040 -c–a-w- c:\windows\system32\dllcache\snyaitmc.sys
2010-04-21 23:35 . 2001-08-17 10:51 58368 -c–a-w- c:\windows\system32\dllcache\smiminib.sys
2010-04-21 23:35 . 2001-08-17 12:56 147200 -c–a-w- c:\windows\system32\dllcache\smidispb.dll
2010-04-21 23:35 . 2001-08-17 10:12 25034 -c–a-w- c:\windows\system32\dllcache\smcpwr2n.sys
2010-04-21 23:35 . 2001-08-17 10:10 35913 -c–a-w- c:\windows\system32\dllcache\smcirda.sys
2010-04-21 23:35 . 2001-08-17 10:12 24576 -c–a-w- c:\windows\system32\dllcache\smc8000n.sys
2010-04-21 23:35 . 2001-08-17 11:57 6784 -c–a-w- c:\windows\system32\dllcache\smbhc.sys
2010-04-21 23:35 . 2008-04-13 18:36 6912 -c–a-w- c:\windows\system32\dllcache\smbclass.sys
2010-04-21 23:35 . 2008-04-13 18:36 16000 -c–a-w- c:\windows\system32\dllcache\smbbatt.sys
2010-04-21 23:35 . 2001-08-17 20:36 45568 -c–a-w- c:\windows\system32\dllcache\smb3w.dll
2010-04-21 23:35 . 2001-08-17 20:36 33792 -c–a-w- c:\windows\system32\dllcache\smb0w.dll
2010-04-21 23:34 . 2001-08-17 20:36 28672 -c–a-w- c:\windows\system32\dllcache\sma0w.dll
2010-04-21 23:34 . 2001-08-17 20:36 28160 -c–a-w- c:\windows\system32\dllcache\sm91w.dll
2010-04-21 23:34 . 2004-08-03 20:31 63547 -c–a-w- c:\windows\system32\dllcache\sla30nd5.sys
2010-04-21 23:34 . 2001-08-17 10:12 91294 -c–a-w- c:\windows\system32\dllcache\skfpwin.sys
2010-04-21 23:34 . 2001-08-17 10:12 94698 -c–a-w- c:\windows\system32\dllcache\sk98xwin.sys
2010-04-21 23:34 . 2001-08-17 12:56 157696 -c–a-w- c:\windows\system32\dllcache\sisv256.dll
2010-04-21 23:34 . 2001-08-17 10:50 50432 -c–a-w- c:\windows\system32\dllcache\sisv.sys
2010-04-21 23:34 . 2004-08-03 20:31 32768 -c–a-w- c:\windows\system32\dllcache\sisnic.sys
2010-04-21 23:34 . 2001-08-17 20:36 238592 -c–a-w- c:\windows\system32\dllcache\sisgrv.dll
2010-04-21 23:33 . 2001-08-17 10:50 104064 -c–a-w- c:\windows\system32\dllcache\sisgrp.sys
2010-04-21 23:33 . 2001-08-17 12:56 150144 -c–a-w- c:\windows\system32\dllcache\sis6306v.dll
2010-04-21 23:33 . 2001-08-17 10:50 68608 -c–a-w- c:\windows\system32\dllcache\sis6306p.sys
2010-04-21 23:33 . 2001-08-17 12:56 252032 -c–a-w- c:\windows\system32\dllcache\sis300iv.dll
2010-04-21 23:33 . 2001-08-17 10:50 101760 -c–a-w- c:\windows\system32\dllcache\sis300ip.sys
2010-04-21 23:33 . 2001-07-21 12:29 161568 -c–a-w- c:\windows\system32\dllcache\sgsmusb.sys
2010-04-21 23:33 . 2001-07-21 12:29 18400 -c–a-w- c:\windows\system32\dllcache\sgsmld.sys
2010-04-21 23:33 . 2001-08-17 10:51 98080 -c–a-w- c:\windows\system32\dllcache\sgiulnt5.sys
2010-04-21 23:33 . 2001-08-17 20:36 386560 -c–a-w- c:\windows\system32\dllcache\sgiul50.dll
2010-04-21 23:32 . 2001-08-17 10:19 36480 -c–a-w- c:\windows\system32\dllcache\sfmanm.sys
2010-04-21 23:32 . 2001-08-17 11:53 6784 -c–a-w- c:\windows\system32\dllcache\serscan.sys
2010-04-21 23:32 . 2001-08-17 11:48 17664 -c–a-w- c:\windows\system32\dllcache\sermouse.sys
2010-04-21 23:32 . 2001-08-17 11:53 6912 -c–a-w- c:\windows\system32\dllcache\seaddsmc.sys
2010-04-21 23:32 . 2008-04-13 18:45 11520 -c–a-w- c:\windows\system32\dllcache\scsiscan.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-22 20:44 . 2010-02-16 23:47 ——– dc—-w- c:\program files\Microsoft
2010-04-22 19:51 . 2006-07-22 05:19 ——– dc—-w- c:\program files\Google
2010-04-22 06:46 . 2006-10-30 10:05 ——– dc—-w- c:\program files\Windows Live Safety Center
2010-04-20 06:55 . 2006-09-24 12:05 ——– dc—-w- c:\program files\Common Files\Wise Installation Wizard
2010-04-20 06:35 . 2007-07-17 22:46 ——– dc—-w- c:\program files\FLV Player
2010-04-20 06:28 . 2008-10-19 10:21 ——– dc–a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-20 06:26 . 2006-05-13 01:45 ——– dc—-w- c:\program files\Samsung
2010-04-20 06:24 . 2008-11-09 18:57 ——– dc—-w- c:\program files\Graboid
2010-04-19 21:59 . 2008-08-26 00:59 ——– dc—-w- c:\program files\LimeWire
2010-04-19 21:58 . 2008-08-26 01:00 ——– dc—-w- c:\documents and settings\Dario\Application Data\LimeWire
2010-04-19 21:58 . 2008-11-29 18:10 ——– dc—-w- c:\program files\Incomplete
2010-04-19 21:36 . 2010-04-21 16:46 170878 -c–a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2010-04-17 16:46 . 2010-02-28 22:39 ——– dc—-w- c:\documents and settings\Dario\Application Data\uTorrent
2010-04-13 13:00 . 2010-03-10 15:33 ——– dc—-w- c:\documents and settings\All Users\Application Data\NOS
2010-04-05 15:44 . 2010-03-23 06:02 866623 -c–a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-330226422-998270827-2084254949-1004-0.dat
2010-04-05 15:44 . 2010-03-23 06:02 383450 -c–a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2010-03-25 17:40 . 2010-03-03 18:28 ——– dc—-w- c:\documents and settings\Dario\Application Data\eM Client
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\documents and settings\Dario\Application Data\Malwarebytes
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\program files\Malwarebytes' Anti-Malware
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-23 01:25 . 2010-03-23 01:25 ——– dc—-w- c:\documents and settings\Dario\Application Data\nswb
2010-03-22 16:02 . 2010-03-22 16:02 ——– dc—-w- c:\program files\Microsoft Help
2010-03-22 16:02 . 2010-03-22 15:45 571712 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\VWDExpress\10.0\1033\ResourceCache.dll
2010-03-22 15:59 . 2010-03-22 15:38 ——– dc—-w- c:\program files\Microsoft Visual Studio 10.0
2010-03-22 15:46 . 2010-02-23 17:33 ——– dc—-w- c:\program files\Microsoft SDKs
2010-03-22 15:42 . 2010-03-22 15:42 ——– dc—-w- c:\program files\Microsoft ASP.NET
2010-03-22 12:15 . 2006-07-22 04:57 ——– dc—-w- c:\program files\Microsoft.NET
2010-03-22 10:27 . 2010-02-23 14:35 ——– dc—-w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-22 10:27 . 2010-02-23 13:49 ——– dc—-w- c:\program files\Microsoft Visual Studio 9.0
2010-03-20 18:16 . 2010-03-20 18:13 ——– dc—-w- c:\program files\Windows Live
2010-03-20 18:15 . 2006-07-22 01:14 ——– dc—-w- c:\program files\MSN Messenger
2010-03-20 18:14 . 2010-03-20 18:14 ——– dc—-w- c:\program files\Windows Live SkyDrive
2010-03-20 17:55 . 2010-03-20 17:55 ——– dc—-w- c:\program files\Common Files\Windows Live
2010-03-20 16:46 . 2010-03-04 07:52 ——– dc—-w- c:\documents and settings\Dario\Application Data\KomaMail
2010-03-18 23:55 . 2006-07-22 01:32 119760 -c–a-w- c:\documents and settings\Dario\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-17 14:12 . 2010-03-17 14:12 ——– dc—-w- c:\program files\SomePDF
2010-03-17 13:59 . 2006-05-13 01:48 ——– dc—-w- c:\program files\Common Files\Adobe
2010-03-17 13:48 . 2010-02-21 18:41 ——– dc—-w- c:\program files\PDF Editor 3
2010-03-17 11:51 . 2010-02-23 22:34 ——– dc—-w- c:\program files\Harmony_Hollow_Software
2010-03-13 11:57 . 2010-03-13 11:57 ——– dc—-w- c:\program files\MSECache
2010-03-12 09:53 . 2006-07-22 18:07 ——– dc—-w- c:\documents and settings\Dario\Application Data\Skype
2010-03-12 09:50 . 2008-08-27 15:15 ——– dc—-w- c:\documents and settings\Dario\Application Data\skypePM
2010-03-11 23:32 . 2010-03-11 23:32 ——– dc—-w- c:\program files\vanBasco's Karaoke Player
2010-03-10 14:04 . 2010-02-28 22:39 ——– dc—-w- c:\program files\uTorrent
2010-03-10 06:15 . 2005-09-10 19:56 420352 -c–a-w- c:\windows\system32\vbscript.dll
2010-03-09 20:17 . 2007-05-07 22:09 ——– dc—-w- c:\documents and settings\Dario\Application Data\PCTV4Me
2010-03-09 20:17 . 2006-07-21 19:56 ——– dc—-w- c:\program files\IncrediMail
2010-03-09 20:17 . 2006-07-21 21:41 ——– dc—-w- c:\program files\Informer50
2010-03-06 13:59 . 2010-03-04 11:31 664 -c–a-w- c:\windows\system32\d3d9caps.dat
2010-03-04 23:35 . 2010-03-04 23:35 ——– dc—-w- c:\program files\eM Client
2010-03-04 20:39 . 2010-03-04 20:39 ——– dc—-w- c:\documents and settings\Dario\Application Data\NetSpell
2010-03-02 07:24 . 2010-03-01 22:33 ——– dc—-w- c:\program files\IObitCom
2010-03-01 23:24 . 2010-03-01 22:29 ——– dc—-w- c:\documents and settings\Dario\Application Data\IObit
2010-03-01 22:33 . 2010-03-01 22:29 ——– dc—-w- c:\program files\IObit
2010-03-01 22:32 . 2010-03-01 22:32 ——– dc—-w- c:\documents and settings\All Users\Application Data\IObit
2010-03-01 22:26 . 2009-11-05 15:53 ——– dc—-w- c:\program files\NCH Swift Sound
2010-03-01 10:34 . 2010-03-01 10:34 ——– dc—-w- c:\program files\EwisoftWebcom
2010-02-27 14:31 . 2010-02-23 00:03 ——– dc—-w- c:\documents and settings\Dario\Application Data\VoipStunt
2010-02-27 14:26 . 2006-05-13 01:39 ——– dc-h–w- c:\program files\InstallShield Installation Information
2010-02-26 19:10 . 2010-02-19 22:54 ——– dc—-w- c:\documents and settings\Dario\Application Data\FileZilla
2010-02-25 06:24 . 2005-09-10 19:56 916480 -c–a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2005-09-10 19:56 455680 -c–a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 23:06 . 2010-02-23 22:33 ——– dc—-w- c:\program files\EwisoftWeb
2010-02-23 22:33 . 2010-02-23 22:33 ——– dc—-w- c:\documents and settings\All Users\Application Data\EwisoftWeb
2010-02-23 17:56 . 2010-02-23 17:40 ——– dc—-w- c:\program files\MySQL
2010-02-23 17:56 . 2010-02-23 17:56 ——– dc—-w- c:\documents and settings\All Users\Application Data\MySQL
2010-02-23 17:43 . 2010-02-23 17:42 ——– dc—-w- c:\program files\PHP
2010-02-23 17:38 . 2010-02-23 14:41 488576 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\VWDExpress\9.0\1033\ResourceCache.dll
2010-02-23 17:37 . 2010-02-23 14:40 416 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-02-23 16:58 . 2010-02-23 13:46 ——– dc—-w- c:\program files\Microsoft SQL Server
2010-02-23 15:03 . 2010-02-23 15:03 ——– dc—-w- c:\program files\IIS
2010-02-23 14:35 . 2010-02-23 14:35 ——– dc—-w- c:\program files\Microsoft Web Designer Tools
2010-02-23 09:49 . 2010-02-23 00:30 ——– dc—-w- c:\program files\Vuze
2010-02-23 08:30 . 2010-02-23 00:32 ——– dc—-w- c:\documents and settings\Dario\Application Data\Azureus
2010-02-23 01:09 . 2010-01-12 19:04 ——– dc—-w- c:\program files\SWiSH Max3
2010-02-23 01:08 . 2010-02-23 01:04 ——– dc—-w- c:\documents and settings\All Users\Application Data\Norton
2010-02-23 01:04 . 2006-05-13 01:43 ——– dc—-w- c:\documents and settings\All Users\Application Data\Symantec
2010-02-23 01:04 . 2010-02-23 01:04 ——– dc—-w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-02-23 01:03 . 2010-02-23 01:03 ——– dc—-w- c:\program files\Emerald Editor Community
2010-02-23 00:32 . 2010-02-23 00:32 ——– dc—-w- c:\documents and settings\All Users\Application Data\Azureus
2010-02-23 00:30 . 2010-02-23 00:30 52224 -c–a-w- c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
2010-02-23 00:30 . 2010-02-23 00:30 101376 -c–a-w- c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
2010-02-23 00:30 . 2010-02-23 00:30 ——– dc—-w- c:\program files\Vuze_Remote
2010-02-23 00:00 . 2010-02-23 00:00 ——– dc—-w- c:\program files\VoipStunt.com
2010-02-21 18:41 . 2010-02-21 18:41 75776 -c–a-w- c:\windows\cadkasdeinst01e.exe
2010-02-16 14:08 . 2005-09-10 19:56 2146304 -c–a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2024448 -c–a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-13 22:47 . 2009-09-18 15:51 103382 -c–a-w- c:\windows\system32\6fe92d1e-7bee-73ea-22af-07e6cd6c2945.exe
2010-02-12 10:03 . 2010-03-06 21:55 293376 -c—-w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2005-09-10 19:56 100864 -c–a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2005-09-10 19:56 226880 -c–a-w- c:\windows\system32\drivers\tcpip6.sys
2008-08-26 00:59 . 2008-08-26 00:59 4898704 -c–a-w- c:\program files\LimeWireWin.exe
2002-04-16 10:27 . 2002-04-16 10:27 5 -csha-w- c:\windows\system32\CdI5T.drv
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]
2010-03-02 07:25 2349080 -c–a-w- c:\program files\IObitCom\tbIOb1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 12:04 1664256 -c–a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
"{31C7D459-9CC3-44F2-9DCA-FC11795309B4}"= "c:\program files\IObitCom\tbIOb1.dll" [2010-03-02 2349080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]
"Google Update"="c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-18 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-07 761947]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 88204]
"RestoreIT!"="c:\program files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" [2004-09-23 114688]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2005-04-11 151552]
"BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2006-04-25 2764800]
"AVStation Premium 3.75"="c:\program files\Samsung\AVStation Premium 3.75\AVSAgent.exe" [2006-04-27 155648]
"DisplayManager"="c:\program files\Samsung\DisplayManager\DMLoader.exe" [2006-03-29 1118208]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-03-12 1055792]
"QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe" [2007-04-27 282624]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"SUPBackGround"="c:\program files\Samsung\Samsung Update Plus\SUPBackGround.exe" [2010-02-03 294912]
"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe" [2010-01-26 243032]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-12-24 1280272]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-17 7585792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"NvMediaCenter"="NvMCTray.dll" [2007-03-17 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-7-22 82026]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-7-23 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-20 14:18 12464 -c–a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dario^Start Menu^Programs^Startup^YPOPs.lnk]
path=c:\documents and settings\Dario\Start Menu\Programs\Startup\YPOPs.lnk
backup=c:\windows\pss\YPOPs.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"c:\\Program Files\\VoipStunt.com\\VoipStunt\\VoipStunt.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\EwisoftWeb\\bin\\WebsiteBuilderP.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\EwisoftWebcom\\bin\\WebsiteBuilderP.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R0 RITCPT;RITCPT;c:\windows\system32\drivers\RITCPT.SYS [13/05/2006 03:45 43512]
R0 VVBackd5;VVBackd5;c:\windows\system32\drivers\VVBackd5.sys [02/10/2009 18:34 183159]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [20/04/2010 16:18 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [20/04/2010 16:18 242896]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [20/04/2010 16:18 308064]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [10/09/2005 23:35 4300]
R2 MarxDev1;MarxDev1;c:\windows\system32\drivers\MARXDEV1.SYS [19/10/2008 09:44 8864]
R2 MarxDev2;MarxDev2;c:\windows\system32\drivers\MARXDEV2.SYS [19/10/2008 09:44 8864]
R2 MarxDev3;MarxDev3;c:\windows\system32\drivers\MARXDEV3.SYS [19/10/2008 09:44 8864]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [24/03/2010 18:48 323992]
S2 clr_optimization_v4.0.21006_32;Microsoft .NET Framework NGEN v4.0.21006_X86;c:\windows\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe [07/10/2009 03:44 129856]
S2 FBAPI;FBAPI;\??\c:\windows\system32\drivers\FBAPI.sys –> c:\windows\system32\drivers\FBAPI.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30/08/2009 11:56 133104]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [02/03/2010 00:32 311568]
S2 iwsfp;Installer Manager;c:\windows\system32\svchost.exe -k netsvcs [10/09/2005 21:56 14336]
S2 lnxxtw;Installer Universal;c:\windows\system32\svchost.exe -k netsvcs [10/09/2005 21:56 14336]
S2 slovaax;Security Support;c:\windows\system32\svchost.exe -k netsvcs [10/09/2005 21:56 14336]
S2 SNM WLAN Service;SNM WLAN Service;c:\program files\Samsung\Samsung Network Manager\SNMWLANService.exe [28/05/2005 17:35 36864]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [20/04/2010 16:18 369920]
S3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [27/01/2010 18:10 5248]
S3 Lmhptm;Lmhptm; [x]
S3 MRV6X32U;Vista 32-bits Native WiFi Driver - USB;c:\windows\system32\drivers\MRVW23B.sys [09/08/2008 13:23 231040]
S3 MRVW225;TVT-RWUSB54 Wireless LAN Dirver for Windows XP;c:\windows\system32\drivers\MRVW225.sys [09/08/2008 13:23 299904]
S3 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [19/01/2010 18:49 55184]
S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [18/10/2006 10:08 229376]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe [07/10/2009 03:44 752984]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [31/03/2009 10:44 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [30/03/2009 04:09 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30/03/2009 04:23 366936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
lnxxtw
slovaax
iwsfp
.
Contents of the 'Scheduled Tasks' folder

2010-04-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 13:42]

2010-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-30 09:55]

2010-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-30 09:55]

2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-330226422-998270827-2084254949-1004Core.job
- c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-18 15:17]

2010-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-330226422-998270827-2084254949-1004UA.job
- c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-18 15:17]

2010-04-18 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-03-01 14:30]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {236145DF-E1AE-40EB-8F0F-C90AD79855C6} = 80.58.61.250,80.58.61.254
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.dymasearch.com/search.php?src=tops&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q=
FF - component: c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{3303e956-2a3a-48e0-be39-2e0ef11a2f44}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{94c6d36d-4827-6502-b227-da71ad46a8fd}\components\4ce9239f-6ddf-d6cd-2823-42157ce2dac1.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\MSN Toolbar\Platform\5.0.1363.0\Firefox\components\DomBridge.dll
FF - plugin: c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Microsoft\Web Platform Installer\NPWPIDetector.dll
FF - plugin: c:\program files\MSN Toolbar\Platform\5.0.1363.0\npwinext.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: keyword.enabled - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
.
——- File Associations ——-
.
.txt=NFOPad
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)
WebBrowser-{3806B089-6759-411D-B2C3-B7995A9F34D7} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-6069ab3d879 - c:\windows\System32\bthci32.dll
Notify-ddcbbXnk - ddcbbXnk.dll
MSConfigStartUp-BitTorrent DNA - c:\program files\DNA\btdna.exe
MSConfigStartUp-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
MSConfigStartUp-Veoh - c:\program files\Veoh Networks\Veoh\VeohClient.exe
MSConfigStartUp-VeohPlugin - c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-23 12:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(6604)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-04-23 12:45:44
ComboFix-quarantined-files.txt 2010-04-23 10:45

Pre-Run: 15,010,594,816 bytes free
Post-Run: 14,997,520,384 bytes free

- - End Of File - - 95CABE129CE418EBF4BC4EAF0E063019
Hi,

The infections may be preventing GMER from running.

Please go to VirSCAN
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box:
    c:\windows\system32\drivers\FBAPI.sys
  • Click Submit. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Please post the results in your next reply.

–Next–

Please do the following:

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/Unknown_infe…385#entry649385

Collect::
C:\WINDOWS\61D3AAE1D5214CD7939B37813DE8F955.TMP
C:\Documents and Settings\Dario\Application Data\SystemProc
C:\WINDOWS\System32\30e9ac3a
C:\WINDOWS\System32\d3drm32.dll
C:\WINDOWS\System32\cryptui32.dll
C:\WINDOWS\System32\d3dim32.dll
C:\WINDOWS\System32\bootvid32.dll
C:\cj.ini
C:\WINDOWS\System32\dsdmoprp32.dll
C:\WINDOWS\System32\1617537853
C:\WINDOWS\System32\809106285
C:\WINDOWS\System32\devmgr32.dll
C:\WINDOWS\System32\crbas1932.dll
C:\WINDOWS\System32\d3dx9_2732.dll
C:\WINDOWS\System32\cfgbkend32.dll
C:\WINDOWS\DCEBoot.exe
C:\WINDOWS\System32\cards32.dll
C:\WINDOWS\System32\crbas19r32.dll
C:\WINDOWS\System32\bitsprx432.dll
C:\WINDOWS\System32\datime32.dll
C:\WINDOWS\System32\BTNeighborhood32.dll
C:\WINDOWS\System32\BtWizard32.dll
C:\WINDOWS\System32\sl1373137407
C:\WINDOWS\System32\CRxmlx09r32.dll
C:\WINDOWS\System32\d3drm32.dll
C:\WINDOWS\System32\cryptui32.dll
C:\WINDOWS\System32\d3dim32.dll

FOLDER::
C:\Program Files\f3setupinstall
C:\sysmon
C:\WINDOWS\System32\1381747802

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs]
"lnxxtw"=-
"slovaax"=-
"iwsfp"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{081698FF-21A3-49DD-9587-CADF10BFAFEa}]
[HKey_Local_Machine\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{758F6D53-DCC7-4CCF-9080-4B6F9389F641}"=-

Driver::
lnxxtw
slovaax
iwsfp

ADS::
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\All Users\Application Data\TEMP

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


To post in your next reply:
1. VirSCAN log.
2. Combofix log.
Ok done what you asked… really do appreciate your help on this

c:\windows\system32\drivers\FBAPI.sys file does not exist so could not run VirScan

ComboFix 10-04-21.01 - Dario 25/04/2010 11:33:38.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.377 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\SubsFix.exe
Command switches used :: c:\documents and settings\Dario\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: C:\cj.ini
file zipped: c:\windows\DCEBoot.exe
file zipped: c:\windows\System32\1617537853
file zipped: c:\windows\System32\30e9ac3a
file zipped: c:\windows\System32\809106285
file zipped: c:\windows\System32\bitsprx432.dll
file zipped: c:\windows\System32\BTNeighborhood32.dll
file zipped: c:\windows\System32\BtWizard32.dll
file zipped: c:\windows\System32\cards32.dll
file zipped: c:\windows\System32\cfgbkend32.dll
file zipped: c:\windows\System32\crbas1932.dll
file zipped: c:\windows\System32\crbas19r32.dll
file zipped: c:\windows\System32\CRxmlx09r32.dll
file zipped: c:\windows\System32\d3dx9_2732.dll
file zipped: c:\windows\System32\sl1373137407
.
ADS - TEMP: deleted 389 bytes in 3 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\cj.ini
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\DCEBoot.exe
c:\windows\System32\1617537853
c:\windows\System32\30e9ac3a
c:\windows\System32\809106285
c:\windows\System32\bitsprx432.dll
c:\windows\System32\BTNeighborhood32.dll
c:\windows\System32\BtWizard32.dll
c:\windows\System32\cards32.dll
c:\windows\System32\cfgbkend32.dll
c:\windows\System32\crbas1932.dll
c:\windows\System32\crbas19r32.dll
c:\windows\System32\CRxmlx09r32.dll
c:\windows\System32\d3dx9_2732.dll
c:\windows\System32\sl1373137407

—– BITS: Possible infected sites —–

hxxp://download.yimg.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IWSFP
——-\Legacy_LNXXTW
——-\Legacy_SLOVAAX
——-\Service_iwsfp
——-\Service_lnxxtw
——-\Service_slovaax


((((((((((((((((((((((((( Files Created from 2010-03-25 to 2010-04-25 )))))))))))))))))))))))))))))))
.

2010-04-24 17:27 . 2010-04-24 17:27 ——– dc—-w- c:\documents and settings\Dario\Application Data\MusicIP
2010-04-24 15:49 . 2010-04-24 15:49 ——– dc—-w- c:\program files\MusicIP
2010-04-24 15:47 . 2010-04-24 15:47 ——– dc—-w- c:\program files\TagScanner
2010-04-24 13:21 . 2010-04-24 13:21 ——– dc—-w- c:\documents and settings\Dario\Application Data\AVG9
2010-04-23 22:11 . 2010-04-23 22:11 ——– dc—-w- c:\documents and settings\Dario\Application Data\Windows Search
2010-04-23 21:59 . 2010-04-24 10:53 ——– dc—-w- c:\documents and settings\Dario\Local Settings\Application Data\Yahoo
2010-04-23 21:57 . 2010-04-24 13:07 ——– dc—-w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-04-23 21:56 . 2009-12-14 15:52 607472 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2010-04-22 21:04 . 2010-04-22 21:06 ——– dc—-w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-22 21:02 . 2010-04-22 21:02 ——– dc—-w- c:\documents and settings\Dario\Application Data\Windows Desktop Search
2010-04-22 20:43 . 2010-04-23 16:36 ——– dc—-w- c:\program files\Windows Desktop Search
2010-04-22 20:24 . 2010-02-23 12:04 1664256 -c–a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-04-22 20:10 . 2010-04-22 20:11 ——– dc-h–w- c:\windows\ie8
2010-04-21 23:48 . 2010-04-21 23:48 ——– dc—-w- c:\documents and settings\Dario\BackUp
2010-04-21 23:47 . 2008-04-14 00:12 116224 -c–a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-04-21 23:46 . 2001-08-17 20:36 23040 -c–a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-04-21 23:46 . 2008-04-14 00:12 18944 -c–a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-04-21 23:46 . 2001-08-17 20:37 27648 -c–a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-04-21 23:46 . 2001-08-17 20:37 4608 -c–a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-04-21 23:46 . 2001-08-17 20:37 99865 -c–a-w- c:\windows\system32\dllcache\xlog.exe
2010-04-21 23:46 . 2001-08-17 10:11 16970 -c–a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-04-21 23:45 . 2004-08-03 20:29 19455 -c–a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-04-21 23:45 . 2004-08-03 20:29 12063 -c–a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-04-21 23:45 . 2004-08-03 20:31 154624 -c–a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-04-21 23:45 . 2001-08-17 10:12 34890 -c–a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-04-21 23:45 . 2001-08-17 11:28 771581 -c–a-w- c:\windows\system32\dllcache\winacisa.sys
2010-04-21 23:45 . 2001-08-17 20:36 53760 -c–a-w- c:\windows\system32\dllcache\wiamsmud.dll
2010-04-21 23:45 . 2001-08-17 20:36 87040 -c–a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-04-21 23:43 . 2001-08-17 11:28 604253 -c–a-w- c:\windows\system32\dllcache\vmodem.sys
2010-04-21 23:43 . 2001-08-17 10:14 249402 -c–a-w- c:\windows\system32\dllcache\vinwm.sys
2010-04-21 23:43 . 2001-08-17 11:49 24576 -c–a-w- c:\windows\system32\dllcache\viairda.sys
2010-04-21 23:43 . 2001-08-17 11:28 687999 -c–a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2010-04-21 23:43 . 2001-08-17 11:28 765884 -c–a-w- c:\windows\system32\dllcache\usrti.sys
2010-04-21 23:43 . 2001-08-17 11:28 113762 -c–a-w- c:\windows\system32\dllcache\usrpda.sys
2010-04-21 23:43 . 2001-08-17 11:28 7556 -c–a-w- c:\windows\system32\dllcache\usroslba.sys
2010-04-21 23:43 . 2001-08-17 11:28 224802 -c–a-w- c:\windows\system32\dllcache\usr1807a.sys
2010-04-21 23:43 . 2001-08-17 11:28 794399 -c–a-w- c:\windows\system32\dllcache\usr1806v.sys
2010-04-21 23:43 . 2001-08-17 11:28 793598 -c–a-w- c:\windows\system32\dllcache\usr1806.sys
2010-04-21 23:42 . 2001-08-17 11:28 794654 -c–a-w- c:\windows\system32\dllcache\usr1801.sys
2010-04-21 23:42 . 2008-04-13 18:45 26112 -c–a-w- c:\windows\system32\dllcache\usbser.sys
2010-04-21 23:42 . 2008-04-13 18:45 17152 -c–a-w- c:\windows\system32\dllcache\usbohci.sys
2010-04-21 23:42 . 2004-08-03 20:31 32384 -c–a-w- c:\windows\system32\dllcache\usb101et.sys
2010-04-21 23:42 . 2001-08-17 20:36 94720 -c–a-w- c:\windows\system32\dllcache\umaxud32.dll
2010-04-21 23:42 . 2001-08-17 20:36 28160 -c–a-w- c:\windows\system32\dllcache\umaxu40.dll
2010-04-21 23:42 . 2001-08-17 20:36 26624 -c–a-w- c:\windows\system32\dllcache\umaxu22.dll
2010-04-21 23:42 . 2001-08-17 20:36 69632 -c–a-w- c:\windows\system32\dllcache\umaxu12.dll
2010-04-21 23:41 . 2001-08-17 20:36 50688 -c–a-w- c:\windows\system32\dllcache\umaxscan.dll
2010-04-21 23:41 . 2001-08-17 11:58 22912 -c–a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-04-21 23:41 . 2001-08-17 20:36 50176 -c–a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-04-21 23:41 . 2001-08-17 20:36 47616 -c–a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-04-21 23:41 . 2001-08-17 20:36 211968 -c–a-w- c:\windows\system32\dllcache\um54scan.dll
2010-04-21 23:41 . 2001-08-17 20:36 216064 -c–a-w- c:\windows\system32\dllcache\um34scan.dll
2010-04-21 23:41 . 2001-08-17 11:48 11520 -c–a-w- c:\windows\system32\dllcache\twotrack.sys
2010-04-21 23:41 . 2001-08-17 10:51 166784 -c–a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-04-21 23:40 . 2001-08-17 20:36 525568 -c–a-w- c:\windows\system32\dllcache\tridxp.dll
2010-04-21 23:40 . 2001-08-17 10:51 159232 -c–a-w- c:\windows\system32\dllcache\tridkbm.sys
2010-04-21 23:40 . 2001-08-17 12:56 440576 -c–a-w- c:\windows\system32\dllcache\tridkb.dll
2010-04-21 23:40 . 2001-08-17 10:51 222336 -c–a-w- c:\windows\system32\dllcache\trid3dm.sys
2010-04-21 23:40 . 2001-08-17 12:56 315520 -c–a-w- c:\windows\system32\dllcache\trid3d.dll
2010-04-21 23:40 . 2001-08-17 10:12 34375 -c–a-w- c:\windows\system32\dllcache\tpro4.sys
2010-04-21 23:40 . 2001-08-17 20:35 42496 -c–a-w- c:\windows\system32\dllcache\tp4res.dll
2010-04-21 23:40 . 2008-04-14 00:12 82944 -c–a-w- c:\windows\system32\dllcache\tp4mon.exe
2010-04-21 23:40 . 2001-08-17 20:36 31744 -c–a-w- c:\windows\system32\dllcache\tp4.dll
2010-04-21 23:39 . 2001-08-17 12:02 230912 -c–a-w- c:\windows\system32\dllcache\tosdvd03.sys
2010-04-21 23:39 . 2001-08-17 12:01 241664 -c–a-w- c:\windows\system32\dllcache\tosdvd02.sys
2010-04-21 23:39 . 2001-08-17 10:10 28232 -c–a-w- c:\windows\system32\dllcache\tos4mo.sys
2010-04-21 23:39 . 2001-08-17 10:14 123995 -c–a-w- c:\windows\system32\dllcache\tjisdn.sys
2010-04-21 23:39 . 2001-08-17 10:51 138528 -c–a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2010-04-21 23:39 . 2001-08-17 12:56 81408 -c–a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-04-21 23:39 . 2008-04-13 18:40 149376 -c–a-w- c:\windows\system32\dllcache\tffsport.sys
2010-04-21 23:39 . 2001-08-17 10:13 17129 -c–a-w- c:\windows\system32\dllcache\tdkcd31.sys
2010-04-21 23:39 . 2001-08-17 10:13 37961 -c–a-w- c:\windows\system32\dllcache\tdk100b.sys
2010-04-21 23:38 . 2001-08-17 11:49 30464 -c–a-w- c:\windows\system32\dllcache\tbatm155.sys
2010-04-21 23:38 . 2001-08-17 11:52 7040 -c–a-w- c:\windows\system32\dllcache\tandqic.sys
2010-04-21 23:38 . 2001-08-17 10:50 36640 -c–a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-04-21 23:38 . 2001-08-17 12:56 172768 -c–a-w- c:\windows\system32\dllcache\t2r4disp.dll
2010-04-21 23:38 . 2001-08-17 20:36 94293 -c–a-w- c:\windows\system32\dllcache\sxports.dll
2010-04-21 23:38 . 2001-08-17 11:50 103936 -c–a-w- c:\windows\system32\dllcache\sx.sys
2010-04-21 23:38 . 2001-08-17 12:02 3968 -c–a-w- c:\windows\system32\dllcache\swusbflt.sys
2010-04-21 23:38 . 2001-08-17 20:36 10240 -c–a-w- c:\windows\system32\dllcache\swpidflt.dll
2010-04-21 23:37 . 2001-08-17 20:36 10240 -c–a-w- c:\windows\system32\dllcache\swpdflt2.dll
2010-04-21 23:37 . 2001-08-17 20:36 53760 -c–a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-04-21 23:37 . 2001-08-17 20:36 41472 -c–a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-04-21 23:37 . 2001-08-17 20:36 155648 -c–a-w- c:\windows\system32\dllcache\stlnprop.dll
2010-04-21 23:37 . 2001-08-17 20:36 53248 -c–a-w- c:\windows\system32\dllcache\stlncoin.dll
2010-04-21 23:37 . 2001-08-17 10:18 285760 -c–a-w- c:\windows\system32\dllcache\stlnata.sys
2010-04-21 23:37 . 2001-08-17 11:51 16896 -c–a-w- c:\windows\system32\dllcache\stcusb.sys
2010-04-21 23:37 . 2001-08-17 10:11 48736 -c–a-w- c:\windows\system32\dllcache\srwlnd5.sys
2010-04-21 23:37 . 2001-08-17 20:36 99328 -c–a-w- c:\windows\system32\dllcache\srusd.dll
2010-04-21 23:36 . 2001-08-17 20:36 24660 -c–a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-04-21 23:36 . 2001-08-17 11:51 61824 -c–a-w- c:\windows\system32\dllcache\speed.sys
2010-04-21 23:36 . 2001-08-17 20:36 106584 -c–a-w- c:\windows\system32\dllcache\spdports.dll
2010-04-21 23:36 . 2001-08-17 11:56 7552 -c–a-w- c:\windows\system32\dllcache\sonypvu1.sys
2010-04-21 23:36 . 2001-08-17 10:51 37040 -c–a-w- c:\windows\system32\dllcache\sonypi.sys
2010-04-21 23:36 . 2001-08-17 20:36 114688 -c–a-w- c:\windows\system32\dllcache\sonypi.dll
2010-04-21 23:36 . 2001-08-17 10:51 20752 -c–a-w- c:\windows\system32\dllcache\sonync.sys
2010-04-21 23:36 . 2001-08-17 11:53 9600 -c–a-w- c:\windows\system32\dllcache\sonymc.sys
2010-04-21 23:36 . 2008-04-13 18:40 7552 -c–a-w- c:\windows\system32\dllcache\sonyait.sys
2010-04-21 23:36 . 2004-08-04 12:00 143422 -c–a-w- c:\windows\system32\dllcache\softkey.dll
2010-04-21 23:35 . 2001-08-17 11:53 7040 -c–a-w- c:\windows\system32\dllcache\snyaitmc.sys
2010-04-21 23:35 . 2001-08-17 10:51 58368 -c–a-w- c:\windows\system32\dllcache\smiminib.sys
2010-04-21 23:35 . 2001-08-17 12:56 147200 -c–a-w- c:\windows\system32\dllcache\smidispb.dll
2010-04-21 23:35 . 2001-08-17 10:12 25034 -c–a-w- c:\windows\system32\dllcache\smcpwr2n.sys
2010-04-21 23:35 . 2001-08-17 10:10 35913 -c–a-w- c:\windows\system32\dllcache\smcirda.sys
2010-04-21 23:35 . 2001-08-17 10:12 24576 -c–a-w- c:\windows\system32\dllcache\smc8000n.sys
2010-04-21 23:35 . 2001-08-17 11:57 6784 -c–a-w- c:\windows\system32\dllcache\smbhc.sys
2010-04-21 23:35 . 2008-04-13 18:36 6912 -c–a-w- c:\windows\system32\dllcache\smbclass.sys
2010-04-21 23:35 . 2008-04-13 18:36 16000 -c–a-w- c:\windows\system32\dllcache\smbbatt.sys
2010-04-21 23:35 . 2001-08-17 20:36 45568 -c–a-w- c:\windows\system32\dllcache\smb3w.dll
2010-04-21 23:35 . 2001-08-17 20:36 33792 -c–a-w- c:\windows\system32\dllcache\smb0w.dll
2010-04-21 23:34 . 2001-08-17 20:36 28672 -c–a-w- c:\windows\system32\dllcache\sma0w.dll
2010-04-21 23:34 . 2001-08-17 20:36 28160 -c–a-w- c:\windows\system32\dllcache\sm91w.dll
2010-04-21 23:34 . 2004-08-03 20:31 63547 -c–a-w- c:\windows\system32\dllcache\sla30nd5.sys
2010-04-21 23:34 . 2001-08-17 10:12 91294 -c–a-w- c:\windows\system32\dllcache\skfpwin.sys
2010-04-21 23:34 . 2001-08-17 10:12 94698 -c–a-w- c:\windows\system32\dllcache\sk98xwin.sys
2010-04-21 23:34 . 2001-08-17 12:56 157696 -c–a-w- c:\windows\system32\dllcache\sisv256.dll
2010-04-21 23:34 . 2001-08-17 10:50 50432 -c–a-w- c:\windows\system32\dllcache\sisv.sys
2010-04-21 23:34 . 2004-08-03 20:31 32768 -c–a-w- c:\windows\system32\dllcache\sisnic.sys
2010-04-21 23:34 . 2001-08-17 20:36 238592 -c–a-w- c:\windows\system32\dllcache\sisgrv.dll
2010-04-21 23:33 . 2001-08-17 10:50 104064 -c–a-w- c:\windows\system32\dllcache\sisgrp.sys
2010-04-21 23:33 . 2001-08-17 12:56 150144 -c–a-w- c:\windows\system32\dllcache\sis6306v.dll
2010-04-21 23:33 . 2001-08-17 10:50 68608 -c–a-w- c:\windows\system32\dllcache\sis6306p.sys
2010-04-21 23:33 . 2001-08-17 12:56 252032 -c–a-w- c:\windows\system32\dllcache\sis300iv.dll
2010-04-21 23:33 . 2001-08-17 10:50 101760 -c–a-w- c:\windows\system32\dllcache\sis300ip.sys
2010-04-21 23:33 . 2001-07-21 12:29 161568 -c–a-w- c:\windows\system32\dllcache\sgsmusb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-24 21:09 . 2008-10-19 10:21 ——– dc–a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-24 17:56 . 2009-08-10 10:18 ——– dc—-w- c:\program files\Karma
2010-04-24 13:11 . 2008-08-26 00:59 ——– dc—-w- c:\program files\LimeWire
2010-04-23 21:59 . 2009-10-09 10:03 ——– dc—-w- c:\documents and settings\Dario\Application Data\Yahoo!
2010-04-23 21:57 . 2007-03-04 17:09 ——– dc—-w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-04-23 21:57 . 2007-03-04 17:06 ——– dc—-w- c:\program files\Yahoo!
2010-04-22 20:44 . 2010-02-16 23:47 ——– dc—-w- c:\program files\Microsoft
2010-04-22 19:51 . 2006-07-22 05:19 ——– dc—-w- c:\program files\Google
2010-04-22 06:46 . 2006-10-30 10:05 ——– dc—-w- c:\program files\Windows Live Safety Center
2010-04-20 06:55 . 2006-09-24 12:05 ——– dc—-w- c:\program files\Common Files\Wise Installation Wizard
2010-04-20 06:35 . 2007-07-17 22:46 ——– dc—-w- c:\program files\FLV Player
2010-04-20 06:26 . 2006-05-13 01:45 ——– dc—-w- c:\program files\Samsung
2010-04-20 06:24 . 2008-11-09 18:57 ——– dc—-w- c:\program files\Graboid
2010-04-19 21:58 . 2008-08-26 01:00 ——– dc—-w- c:\documents and settings\Dario\Application Data\LimeWire
2010-04-19 21:58 . 2008-11-29 18:10 ——– dc—-w- c:\program files\Incomplete
2010-04-19 21:36 . 2010-04-21 16:46 170878 -c–a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2010-04-17 16:46 . 2010-02-28 22:39 ——– dc—-w- c:\documents and settings\Dario\Application Data\uTorrent
2010-04-13 13:00 . 2010-03-10 15:33 ——– dc—-w- c:\documents and settings\All Users\Application Data\NOS
2010-04-05 15:44 . 2010-03-23 06:02 866623 -c–a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-330226422-998270827-2084254949-1004-0.dat
2010-04-05 15:44 . 2010-03-23 06:02 383450 -c–a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2010-03-25 17:40 . 2010-03-03 18:28 ——– dc—-w- c:\documents and settings\Dario\Application Data\eM Client
2010-03-24 18:38 . 2010-03-24 18:38 ——– dc—-w- c:\documents and settings\Dario\Application Data\Microsoft Corporation
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\documents and settings\Dario\Application Data\Malwarebytes
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\program files\Malwarebytes' Anti-Malware
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-23 01:25 . 2010-03-23 01:25 ——– dc—-w- c:\documents and settings\Dario\Application Data\nswb
2010-03-22 16:02 . 2010-03-22 16:02 ——– dc—-w- c:\program files\Microsoft Help
2010-03-22 16:02 . 2010-03-22 15:45 571712 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\VWDExpress\10.0\1033\ResourceCache.dll
2010-03-22 15:59 . 2010-03-22 15:38 ——– dc—-w- c:\program files\Microsoft Visual Studio 10.0
2010-03-22 15:46 . 2010-02-23 17:33 ——– dc—-w- c:\program files\Microsoft SDKs
2010-03-22 15:42 . 2010-03-22 15:42 ——– dc—-w- c:\program files\Microsoft ASP.NET
2010-03-22 12:15 . 2006-07-22 04:57 ——– dc—-w- c:\program files\Microsoft.NET
2010-03-22 10:27 . 2010-02-23 14:35 ——– dc—-w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-22 10:27 . 2010-02-23 13:49 ——– dc—-w- c:\program files\Microsoft Visual Studio 9.0
2010-03-20 18:16 . 2010-03-20 18:13 ——– dc—-w- c:\program files\Windows Live
2010-03-20 18:15 . 2006-07-22 01:14 ——– dc—-w- c:\program files\MSN Messenger
2010-03-20 18:14 . 2010-03-20 18:14 ——– dc—-w- c:\program files\Windows Live SkyDrive
2010-03-20 17:55 . 2010-03-20 17:55 ——– dc—-w- c:\program files\Common Files\Windows Live
2010-03-20 16:46 . 2010-03-04 07:52 ——– dc—-w- c:\documents and settings\Dario\Application Data\KomaMail
2010-03-19 15:55 . 2010-03-19 15:55 57344 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\Messenger\resources\en-GB\PhotoRes.dll
2010-03-19 15:55 . 2010-03-19 15:55 225280 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\Messenger\resources\en-GB\StpWd.dll
2010-03-19 15:55 . 2010-03-19 15:55 1228800 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\Messenger\resources\en-GB\res_msgr.dll
2010-03-18 23:55 . 2006-07-22 01:32 119760 -c–a-w- c:\documents and settings\Dario\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-17 14:12 . 2010-03-17 14:12 ——– dc—-w- c:\program files\SomePDF
2010-03-17 13:59 . 2006-05-13 01:48 ——– dc—-w- c:\program files\Common Files\Adobe
2010-03-17 13:48 . 2010-02-21 18:41 ——– dc—-w- c:\program files\PDF Editor 3
2010-03-17 11:51 . 2010-02-23 22:34 ——– dc—-w- c:\program files\Harmony_Hollow_Software
2010-03-13 11:57 . 2010-03-13 11:57 ——– dc—-w- c:\program files\MSECache
2010-03-12 09:53 . 2006-07-22 18:07 ——– dc—-w- c:\documents and settings\Dario\Application Data\Skype
2010-03-12 09:50 . 2008-08-27 15:15 ——– dc—-w- c:\documents and settings\Dario\Application Data\skypePM
2010-03-11 23:32 . 2010-03-11 23:32 ——– dc—-w- c:\program files\vanBasco's Karaoke Player
2010-03-10 14:04 . 2010-02-28 22:39 ——– dc—-w- c:\program files\uTorrent
2010-03-10 06:15 . 2005-09-10 19:56 420352 -c–a-w- c:\windows\system32\vbscript.dll
2010-03-09 20:17 . 2007-05-07 22:09 ——– dc—-w- c:\documents and settings\Dario\Application Data\PCTV4Me
2010-03-09 20:17 . 2006-07-21 19:56 ——– dc—-w- c:\program files\IncrediMail
2010-03-09 20:17 . 2006-07-21 21:41 ——– dc—-w- c:\program files\Informer50
2010-03-06 13:59 . 2010-03-04 11:31 664 -c–a-w- c:\windows\system32\d3d9caps.dat
2010-03-04 23:35 . 2010-03-04 23:35 ——– dc—-w- c:\program files\eM Client
2010-03-04 20:39 . 2010-03-04 20:39 ——– dc—-w- c:\documents and settings\Dario\Application Data\NetSpell
2010-03-02 07:24 . 2010-03-01 22:33 ——– dc—-w- c:\program files\IObitCom
2010-03-01 23:24 . 2010-03-01 22:29 ——– dc—-w- c:\documents and settings\Dario\Application Data\IObit
2010-03-01 22:33 . 2010-03-01 22:29 ——– dc—-w- c:\program files\IObit
2010-03-01 22:32 . 2010-03-01 22:32 ——– dc—-w- c:\documents and settings\All Users\Application Data\IObit
2010-03-01 22:26 . 2009-11-05 15:53 ——– dc—-w- c:\program files\NCH Swift Sound
2010-03-01 10:34 . 2010-03-01 10:34 ——– dc—-w- c:\program files\EwisoftWebcom
2010-02-27 14:31 . 2010-02-23 00:03 ——– dc—-w- c:\documents and settings\Dario\Application Data\VoipStunt
2010-02-27 14:26 . 2006-05-13 01:39 ——– dc-h–w- c:\program files\InstallShield Installation Information
2010-02-26 19:10 . 2010-02-19 22:54 ——– dc—-w- c:\documents and settings\Dario\Application Data\FileZilla
2010-02-25 06:24 . 2005-09-10 19:56 916480 -c–a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2005-09-10 19:56 455680 -c–a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 17:38 . 2010-02-23 14:41 488576 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\VWDExpress\9.0\1033\ResourceCache.dll
2010-02-23 17:37 . 2010-02-23 14:40 416 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-02-23 00:30 . 2010-02-23 00:30 52224 -c–a-w- c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
2010-02-23 00:30 . 2010-02-23 00:30 101376 -c–a-w- c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
2010-02-21 18:41 . 2010-02-21 18:41 75776 -c–a-w- c:\windows\cadkasdeinst01e.exe
2010-02-16 14:08 . 2005-09-10 19:56 2146304 -c–a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2024448 -c–a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-13 22:47 . 2009-09-18 15:51 103382 -c–a-w- c:\windows\system32\6fe92d1e-7bee-73ea-22af-07e6cd6c2945.exe
2010-02-12 10:03 . 2010-03-06 21:55 293376 -c—-w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2005-09-10 19:56 100864 -c–a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2005-09-10 19:56 226880 -c–a-w- c:\windows\system32\drivers\tcpip6.sys
2008-08-26 00:59 . 2008-08-26 00:59 4898704 -c–a-w- c:\program files\LimeWireWin.exe
2002-04-16 10:27 . 2002-04-16 10:27 5 -csha-w- c:\windows\system32\CdI5T.drv
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]
2010-03-02 07:25 2349080 -c–a-w- c:\program files\IObitCom\tbIOb1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 12:04 1664256 -c–a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
"{31C7D459-9CC3-44F2-9DCA-FC11795309B4}"= "c:\program files\IObitCom\tbIOb1.dll" [2010-03-02 2349080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]
"Google Update"="c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-18 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-07 761947]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 88204]
"RestoreIT!"="c:\program files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" [2004-09-23 114688]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2005-04-11 151552]
"BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2006-04-25 2764800]
"AVStation Premium 3.75"="c:\program files\Samsung\AVStation Premium 3.75\AVSAgent.exe" [2006-04-27 155648]
"DisplayManager"="c:\program files\Samsung\DisplayManager\DMLoader.exe" [2006-03-29 1118208]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-03-12 1055792]
"QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe" [2007-04-27 282624]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"SUPBackGround"="c:\program files\Samsung\Samsung Update Plus\SUPBackGround.exe" [2010-02-03 294912]
"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe" [2010-01-26 243032]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-12-24 1280272]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-17 7585792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"NvMediaCenter"="NvMCTray.dll" [2007-03-17 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-7-22 82026]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-7-23 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-20 14:18 12464 -c–a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dario^Start Menu^Programs^Startup^YPOPs.lnk]
path=c:\documents and settings\Dario\Start Menu\Programs\Startup\YPOPs.lnk
backup=c:\windows\pss\YPOPs.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"c:\\Program Files\\VoipStunt.com\\VoipStunt\\VoipStunt.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\EwisoftWeb\\bin\\WebsiteBuilderP.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\EwisoftWebcom\\bin\\WebsiteBuilderP.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R0 RITCPT;RITCPT;c:\windows\system32\drivers\RITCPT.SYS [13/05/2006 03:45 43512]
R0 VVBackd5;VVBackd5;c:\windows\system32\drivers\VVBackd5.sys [02/10/2009 18:34 183159]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [20/04/2010 16:18 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [20/04/2010 16:18 242896]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [20/04/2010 16:18 308064]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [10/09/2005 23:35 4300]
R2 MarxDev1;MarxDev1;c:\windows\system32\drivers\MARXDEV1.SYS [19/10/2008 09:44 8864]
R2 MarxDev2;MarxDev2;c:\windows\system32\drivers\MARXDEV2.SYS [19/10/2008 09:44 8864]
R2 MarxDev3;MarxDev3;c:\windows\system32\drivers\MARXDEV3.SYS [19/10/2008 09:44 8864]
R2 SNM WLAN Service;SNM WLAN Service;c:\program files\Samsung\Samsung Network Manager\SNMWLANService.exe [28/05/2005 17:35 36864]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [24/03/2010 18:48 323992]
S2 clr_optimization_v4.0.21006_32;Microsoft .NET Framework NGEN v4.0.21006_X86;c:\windows\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe [07/10/2009 03:44 129856]
S2 FBAPI;FBAPI;\??\c:\windows\system32\drivers\FBAPI.sys –> c:\windows\system32\drivers\FBAPI.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30/08/2009 11:56 133104]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [02/03/2010 00:32 311568]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [20/04/2010 16:18 369920]
S3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [27/01/2010 18:10 5248]
S3 Lmhptm;Lmhptm; [x]
S3 MRV6X32U;Vista 32-bits Native WiFi Driver - USB;c:\windows\system32\drivers\MRVW23B.sys [09/08/2008 13:23 231040]
S3 MRVW225;TVT-RWUSB54 Wireless LAN Dirver for Windows XP;c:\windows\system32\drivers\MRVW225.sys [09/08/2008 13:23 299904]
S3 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [19/01/2010 18:49 55184]
S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [18/10/2006 10:08 229376]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe [07/10/2009 03:44 752984]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [31/03/2009 10:44 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [30/03/2009 04:09 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30/03/2009 04:23 366936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2010-04-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 13:42]

2010-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-30 09:55]

2010-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-30 09:55]

2010-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-330226422-998270827-2084254949-1004Core.job
- c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-18 15:17]

2010-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-330226422-998270827-2084254949-1004UA.job
- c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-18 15:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/ig?hl=en&source=iglk
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {236145DF-E1AE-40EB-8F0F-C90AD79855C6} = 80.58.61.250,80.58.61.254
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.dymasearch.com/search.php?src=tops&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://es.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_es&p=
FF - component: c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{3303e956-2a3a-48e0-be39-2e0ef11a2f44}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\0hyns5zm.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{94c6d36d-4827-6502-b227-da71ad46a8fd}\components\4ce9239f-6ddf-d6cd-2823-42157ce2dac1.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\MSN Toolbar\Platform\5.0.1363.0\Firefox\components\DomBridge.dll
FF - plugin: c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Microsoft\Web Platform Installer\NPWPIDetector.dll
FF - plugin: c:\program files\MSN Toolbar\Platform\5.0.1363.0\npwinext.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: keyword.enabled - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-ZortamMp3MediaStudio - c:\program files\Zortam Mp3 Media Studio\zmmspro.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-25 11:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1088)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\MySQL\MySQL Server 5.1\bin\mysqld.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\rundll32.exe
c:\program files\SAMSUNG\MagicKBD\MagicKBD.exe
c:\program files\Samsung\DisplayManager\DisplayManager.exe
c:\windows\system32\RunDLL32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2010-04-25 11:57:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-25 09:57
ComboFix2.txt 2010-04-23 10:45

Pre-Run: 14,710,771,712 bytes free
Post-Run: 14,727,880,704 bytes free

- - End Of File - - C86D318E5B2FC7231306A06D57E9A951
Hi,

Please do the following:

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

Driver::
Lmhptm

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

–Next–

Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/Unknown_infection_t111689.html&pid=649532#entry649532

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip ( the * denotes Date and Time stamp )
Select this file and click Open
In the Largest box please put
File Requested By inzanity
Failed Submit::

Finally click SendFile

Please return here and let me know when that file has been uploaded.

–Next–

Try running GMER now, be sure to disable your security programs before doing so. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs. Uncheck "Files" and run it in safe mode if it won't run in normal mode.

If that still won't work then do the following:
We Need to check for Rootkits with RootRepeal
Please download RootRepeal one of these locations and save it to your desktop
Here
Here
Here
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check just these boxes:
  • [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:, and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.
To post in your next reply:
1. Combofix log.
2. Were you able to upload the file?
3. How is your computer?
Ok

Gmer ran with files unticked

GMER report:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-26 13:47:35
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Dario\LOCALS~1\Temp\uxldypog.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\mmrtkrnl.sys (MMRTKRNL.SYS/ALCATech GmbH) ZwClose [0xF68CFCA6]
SSDT \SystemRoot\system32\drivers\mmrtkrnl.sys (MMRTKRNL.SYS/ALCATech GmbH) ZwCreateKey [0xF68CFC5E]
SSDT \SystemRoot\system32\drivers\mmrtkrnl.sys (MMRTKRNL.SYS/ALCATech GmbH) ZwOpenKey [0xF68CFC22]
SSDT \SystemRoot\system32\drivers\mmrtkrnl.sys (MMRTKRNL.SYS/ALCATech GmbH) ZwSetValueKey [0xF68CFCBC]

Code \??\C:\DOCUME~1\Dario\LOCALS~1\Temp\catchme.sys pIofCallDriver

—- Kernel code sections - GMER 1.0.15 —-

? Combo-Fix.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF64D7360, 0x22678D, 0xE8000020]
init C:\WINDOWS\system32\drivers\mmrtkrnl.sys entry point in "init" section [0xF68D3C80]
? C:\DOCUME~1\Dario\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3324] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\SearchIndexer.exe[3632] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\WINDOWS\system32\RunDLL32.exe[3680] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BB0001
.text C:\WINDOWS\system32\RunDLL32.exe[3680] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\RunDLL32.exe[3680] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\RunDLL32.exe[3680] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003E0001
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3700] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Documents and Settings\Dario\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe[4352] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003D0001
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe[4620] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AB0001
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe[4656] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[4796] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BF0001
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[5316] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003D0001
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5376] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\AGRSMMSG.exe[5452] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\AGRSMMSG.exe[5452] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\WINDOWS\AGRSMMSG.exe[5452] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\AGRSMMSG.exe[5452] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\WINDOWS\AGRSMMSG.exe[5452] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B30001
.text C:\WINDOWS\AGRSMMSG.exe[5452] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\AGRSMMSG.exe[5452] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\AGRSMMSG.exe[5452] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\AGRSMMSG.exe[5452] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\AGRSMMSG.exe[5452] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\WINDOWS\AGRSMMSG.exe[5452] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\AGRSMMSG.exe[5452] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\ctfmon.exe[5512] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[5512] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\WINDOWS\system32\ctfmon.exe[5512] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[5512] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\WINDOWS\system32\ctfmon.exe[5512] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AC0001
.text C:\WINDOWS\system32\ctfmon.exe[5512] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\ctfmon.exe[5512] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[5512] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\ctfmon.exe[5512] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[5512] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\ctfmon.exe[5512] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\ctfmon.exe[5512] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009B0001
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\Samsung\AVStation Premium 3.75\AVSAgent.exe[5816] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\rundll32.exe[5868] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[5868] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\WINDOWS\system32\rundll32.exe[5868] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[5868] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\WINDOWS\system32\rundll32.exe[5868] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BB0001
.text C:\WINDOWS\system32\rundll32.exe[5868] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\rundll32.exe[5868] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\rundll32.exe[5868] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\WINDOWS\system32\rundll32.exe[5868] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[5868] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\rundll32.exe[5868] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\rundll32.exe[5868] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F70001
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[5932] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B50001
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\Nero\Nero 7\InCD\InCD.exe[5964] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ntdll.dll!NtCreateKey 7C90D0EE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ntdll.dll!NtCreateKey + 4 7C90D0F2 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ntdll.dll!NtSetValueKey 7C90DDCE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ntdll.dll!NtSetValueKey + 4 7C90DDD2 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009E0001
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes JMP 5F100F5A
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ADVAPI32.dll!CreateProcessWithLogonW 77E15FFD 3 Bytes [FF, 25, 1E]
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ADVAPI32.dll!CreateProcessWithLogonW + 4 77E16001 2 Bytes [05, 5F]
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ADVAPI32.dll!CreateServiceA 77E37211 6 Bytes JMP 5F190F5A
.text C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe[6136] ADVAPI32.dll!CreateServiceW 77E373A9 6 Bytes JMP 5F1C0F5A

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device InCDFs.sys (InCD File System Driver/Nero AG)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016cef2b27e
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0016cef2b27e (not active ControlSet)

—- EOF - GMER 1.0.15 —-

Combifix report:

ComboFix 10-04-21.01 - Dario 26/04/2010 13:12:53.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.379 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\SubsFix.exe
Command switches used :: c:\documents and settings\Dario\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\docume~1\Dario\LOCALS~1\Temp\install_flash_player.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_Lmhptm


((((((((((((((((((((((((( Files Created from 2010-03-26 to 2010-04-26 )))))))))))))))))))))))))))))))
.

2010-04-25 11:51 . 2010-04-25 11:51 242696 -c–a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-04-25 11:46 . 2010-04-25 11:46 1685784 -c–a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-04-25 11:46 . 2010-04-25 11:46 1035032 -c–a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-04-25 10:59 . 2010-04-25 10:59 ——– dc—-w- c:\documents and settings\Dario\Local Settings\Application Data\Mozilla
2010-04-25 10:50 . 2010-04-25 10:50 ——– dc—-w- c:\program files\CCleaner
2010-04-24 17:27 . 2010-04-24 17:27 ——– dc—-w- c:\documents and settings\Dario\Application Data\MusicIP
2010-04-24 15:49 . 2010-04-24 15:49 ——– dc—-w- c:\program files\MusicIP
2010-04-24 15:47 . 2010-04-24 15:47 ——– dc—-w- c:\program files\TagScanner
2010-04-24 13:21 . 2010-04-24 13:21 ——– dc—-w- c:\documents and settings\Dario\Application Data\AVG9
2010-04-23 22:11 . 2010-04-23 22:11 ——– dc—-w- c:\documents and settings\Dario\Application Data\Windows Search
2010-04-23 21:59 . 2010-04-24 10:53 ——– dc—-w- c:\documents and settings\Dario\Local Settings\Application Data\Yahoo
2010-04-23 21:57 . 2010-04-24 13:07 ——– dc—-w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-04-23 21:56 . 2009-12-14 15:52 607472 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2010-04-22 21:04 . 2010-04-22 21:06 ——– dc—-w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-22 21:02 . 2010-04-22 21:02 ——– dc—-w- c:\documents and settings\Dario\Application Data\Windows Desktop Search
2010-04-22 20:43 . 2010-04-23 16:36 ——– dc—-w- c:\program files\Windows Desktop Search
2010-04-22 20:24 . 2010-02-23 12:04 1664256 -c–a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-04-22 20:10 . 2010-04-22 20:11 ——– dc-h–w- c:\windows\ie8
2010-04-21 23:48 . 2010-04-21 23:48 ——– dc—-w- c:\documents and settings\Dario\BackUp
2010-04-21 23:47 . 2008-04-14 00:12 116224 -c–a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-04-21 23:46 . 2001-08-17 20:36 23040 -c–a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-04-21 23:46 . 2008-04-14 00:12 18944 -c–a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-04-21 23:46 . 2001-08-17 20:37 27648 -c–a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-04-21 23:46 . 2001-08-17 20:37 4608 -c–a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-04-21 23:46 . 2001-08-17 20:37 99865 -c–a-w- c:\windows\system32\dllcache\xlog.exe
2010-04-21 23:46 . 2001-08-17 10:11 16970 -c–a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-04-21 23:45 . 2004-08-03 20:29 19455 -c–a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-04-21 23:45 . 2004-08-03 20:29 12063 -c–a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-04-21 23:45 . 2004-08-03 20:31 154624 -c–a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-04-21 23:45 . 2001-08-17 10:12 34890 -c–a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-04-21 23:45 . 2001-08-17 11:28 771581 -c–a-w- c:\windows\system32\dllcache\winacisa.sys
2010-04-21 23:45 . 2001-08-17 20:36 53760 -c–a-w- c:\windows\system32\dllcache\wiamsmud.dll
2010-04-21 23:45 . 2001-08-17 20:36 87040 -c–a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-04-21 23:43 . 2001-08-17 11:28 604253 -c–a-w- c:\windows\system32\dllcache\vmodem.sys
2010-04-21 23:43 . 2001-08-17 10:14 249402 -c–a-w- c:\windows\system32\dllcache\vinwm.sys
2010-04-21 23:43 . 2001-08-17 11:49 24576 -c–a-w- c:\windows\system32\dllcache\viairda.sys
2010-04-21 23:43 . 2001-08-17 11:28 687999 -c–a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2010-04-21 23:43 . 2001-08-17 11:28 765884 -c–a-w- c:\windows\system32\dllcache\usrti.sys
2010-04-21 23:43 . 2001-08-17 11:28 113762 -c–a-w- c:\windows\system32\dllcache\usrpda.sys
2010-04-21 23:43 . 2001-08-17 11:28 7556 -c–a-w- c:\windows\system32\dllcache\usroslba.sys
2010-04-21 23:43 . 2001-08-17 11:28 224802 -c–a-w- c:\windows\system32\dllcache\usr1807a.sys
2010-04-21 23:43 . 2001-08-17 11:28 794399 -c–a-w- c:\windows\system32\dllcache\usr1806v.sys
2010-04-21 23:43 . 2001-08-17 11:28 793598 -c–a-w- c:\windows\system32\dllcache\usr1806.sys
2010-04-21 23:42 . 2001-08-17 11:28 794654 -c–a-w- c:\windows\system32\dllcache\usr1801.sys
2010-04-21 23:42 . 2008-04-13 18:45 26112 -c–a-w- c:\windows\system32\dllcache\usbser.sys
2010-04-21 23:42 . 2008-04-13 18:45 17152 -c–a-w- c:\windows\system32\dllcache\usbohci.sys
2010-04-21 23:42 . 2004-08-03 20:31 32384 -c–a-w- c:\windows\system32\dllcache\usb101et.sys
2010-04-21 23:42 . 2001-08-17 20:36 94720 -c–a-w- c:\windows\system32\dllcache\umaxud32.dll
2010-04-21 23:42 . 2001-08-17 20:36 28160 -c–a-w- c:\windows\system32\dllcache\umaxu40.dll
2010-04-21 23:42 . 2001-08-17 20:36 26624 -c–a-w- c:\windows\system32\dllcache\umaxu22.dll
2010-04-21 23:42 . 2001-08-17 20:36 69632 -c–a-w- c:\windows\system32\dllcache\umaxu12.dll
2010-04-21 23:41 . 2001-08-17 20:36 50688 -c–a-w- c:\windows\system32\dllcache\umaxscan.dll
2010-04-21 23:41 . 2001-08-17 11:58 22912 -c–a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-04-21 23:41 . 2001-08-17 20:36 50176 -c–a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-04-21 23:41 . 2001-08-17 20:36 47616 -c–a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-04-21 23:41 . 2001-08-17 20:36 211968 -c–a-w- c:\windows\system32\dllcache\um54scan.dll
2010-04-21 23:41 . 2001-08-17 20:36 216064 -c–a-w- c:\windows\system32\dllcache\um34scan.dll
2010-04-21 23:41 . 2001-08-17 11:48 11520 -c–a-w- c:\windows\system32\dllcache\twotrack.sys
2010-04-21 23:41 . 2001-08-17 10:51 166784 -c–a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-04-21 23:40 . 2001-08-17 20:36 525568 -c–a-w- c:\windows\system32\dllcache\tridxp.dll
2010-04-21 23:40 . 2001-08-17 10:51 159232 -c–a-w- c:\windows\system32\dllcache\tridkbm.sys
2010-04-21 23:40 . 2001-08-17 12:56 440576 -c–a-w- c:\windows\system32\dllcache\tridkb.dll
2010-04-21 23:40 . 2001-08-17 10:51 222336 -c–a-w- c:\windows\system32\dllcache\trid3dm.sys
2010-04-21 23:40 . 2001-08-17 12:56 315520 -c–a-w- c:\windows\system32\dllcache\trid3d.dll
2010-04-21 23:40 . 2001-08-17 10:12 34375 -c–a-w- c:\windows\system32\dllcache\tpro4.sys
2010-04-21 23:40 . 2001-08-17 20:35 42496 -c–a-w- c:\windows\system32\dllcache\tp4res.dll
2010-04-21 23:40 . 2008-04-14 00:12 82944 -c–a-w- c:\windows\system32\dllcache\tp4mon.exe
2010-04-21 23:40 . 2001-08-17 20:36 31744 -c–a-w- c:\windows\system32\dllcache\tp4.dll
2010-04-21 23:39 . 2001-08-17 12:02 230912 -c–a-w- c:\windows\system32\dllcache\tosdvd03.sys
2010-04-21 23:39 . 2001-08-17 12:01 241664 -c–a-w- c:\windows\system32\dllcache\tosdvd02.sys
2010-04-21 23:39 . 2001-08-17 10:10 28232 -c–a-w- c:\windows\system32\dllcache\tos4mo.sys
2010-04-21 23:39 . 2001-08-17 10:14 123995 -c–a-w- c:\windows\system32\dllcache\tjisdn.sys
2010-04-21 23:39 . 2001-08-17 10:51 138528 -c–a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2010-04-21 23:39 . 2001-08-17 12:56 81408 -c–a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-04-21 23:39 . 2008-04-13 18:40 149376 -c–a-w- c:\windows\system32\dllcache\tffsport.sys
2010-04-21 23:39 . 2001-08-17 10:13 17129 -c–a-w- c:\windows\system32\dllcache\tdkcd31.sys
2010-04-21 23:39 . 2001-08-17 10:13 37961 -c–a-w- c:\windows\system32\dllcache\tdk100b.sys
2010-04-21 23:38 . 2001-08-17 11:49 30464 -c–a-w- c:\windows\system32\dllcache\tbatm155.sys
2010-04-21 23:38 . 2001-08-17 11:52 7040 -c–a-w- c:\windows\system32\dllcache\tandqic.sys
2010-04-21 23:38 . 2001-08-17 10:50 36640 -c–a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-04-21 23:38 . 2001-08-17 12:56 172768 -c–a-w- c:\windows\system32\dllcache\t2r4disp.dll
2010-04-21 23:38 . 2001-08-17 20:36 94293 -c–a-w- c:\windows\system32\dllcache\sxports.dll
2010-04-21 23:38 . 2001-08-17 11:50 103936 -c–a-w- c:\windows\system32\dllcache\sx.sys
2010-04-21 23:38 . 2001-08-17 12:02 3968 -c–a-w- c:\windows\system32\dllcache\swusbflt.sys
2010-04-21 23:38 . 2001-08-17 20:36 10240 -c–a-w- c:\windows\system32\dllcache\swpidflt.dll
2010-04-21 23:37 . 2001-08-17 20:36 10240 -c–a-w- c:\windows\system32\dllcache\swpdflt2.dll
2010-04-21 23:37 . 2001-08-17 20:36 53760 -c–a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-04-21 23:37 . 2001-08-17 20:36 41472 -c–a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-04-21 23:37 . 2001-08-17 20:36 155648 -c–a-w- c:\windows\system32\dllcache\stlnprop.dll
2010-04-21 23:37 . 2001-08-17 20:36 53248 -c–a-w- c:\windows\system32\dllcache\stlncoin.dll
2010-04-21 23:37 . 2001-08-17 10:18 285760 -c–a-w- c:\windows\system32\dllcache\stlnata.sys
2010-04-21 23:37 . 2001-08-17 11:51 16896 -c–a-w- c:\windows\system32\dllcache\stcusb.sys
2010-04-21 23:37 . 2001-08-17 10:11 48736 -c–a-w- c:\windows\system32\dllcache\srwlnd5.sys
2010-04-21 23:37 . 2001-08-17 20:36 99328 -c–a-w- c:\windows\system32\dllcache\srusd.dll
2010-04-21 23:36 . 2001-08-17 20:36 24660 -c–a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-04-21 23:36 . 2001-08-17 11:51 61824 -c–a-w- c:\windows\system32\dllcache\speed.sys
2010-04-21 23:36 . 2001-08-17 20:36 106584 -c–a-w- c:\windows\system32\dllcache\spdports.dll
2010-04-21 23:36 . 2001-08-17 11:56 7552 -c–a-w- c:\windows\system32\dllcache\sonypvu1.sys
2010-04-21 23:36 . 2001-08-17 10:51 37040 -c–a-w- c:\windows\system32\dllcache\sonypi.sys
2010-04-21 23:36 . 2001-08-17 20:36 114688 -c–a-w- c:\windows\system32\dllcache\sonypi.dll
2010-04-21 23:36 . 2001-08-17 10:51 20752 -c–a-w- c:\windows\system32\dllcache\sonync.sys
2010-04-21 23:36 . 2001-08-17 11:53 9600 -c–a-w- c:\windows\system32\dllcache\sonymc.sys
2010-04-21 23:36 . 2008-04-13 18:40 7552 -c–a-w- c:\windows\system32\dllcache\sonyait.sys
2010-04-21 23:36 . 2004-08-04 12:00 143422 -c–a-w- c:\windows\system32\dllcache\softkey.dll
2010-04-21 23:35 . 2001-08-17 11:53 7040 -c–a-w- c:\windows\system32\dllcache\snyaitmc.sys
2010-04-21 23:35 . 2001-08-17 10:51 58368 -c–a-w- c:\windows\system32\dllcache\smiminib.sys
2010-04-21 23:35 . 2001-08-17 12:56 147200 -c–a-w- c:\windows\system32\dllcache\smidispb.dll
2010-04-21 23:35 . 2001-08-17 10:12 25034 -c–a-w- c:\windows\system32\dllcache\smcpwr2n.sys
2010-04-21 23:35 . 2001-08-17 10:10 35913 -c–a-w- c:\windows\system32\dllcache\smcirda.sys
2010-04-21 23:35 . 2001-08-17 10:12 24576 -c–a-w- c:\windows\system32\dllcache\smc8000n.sys
2010-04-21 23:35 . 2001-08-17 11:57 6784 -c–a-w- c:\windows\system32\dllcache\smbhc.sys
2010-04-21 23:35 . 2008-04-13 18:36 6912 -c–a-w- c:\windows\system32\dllcache\smbclass.sys
2010-04-21 23:35 . 2008-04-13 18:36 16000 -c–a-w- c:\windows\system32\dllcache\smbbatt.sys
2010-04-21 23:35 . 2001-08-17 20:36 45568 -c–a-w- c:\windows\system32\dllcache\smb3w.dll
2010-04-21 23:35 . 2001-08-17 20:36 33792 -c–a-w- c:\windows\system32\dllcache\smb0w.dll
2010-04-21 23:34 . 2001-08-17 20:36 28672 -c–a-w- c:\windows\system32\dllcache\sma0w.dll
2010-04-21 23:34 . 2001-08-17 20:36 28160 -c–a-w- c:\windows\system32\dllcache\sm91w.dll
2010-04-21 23:34 . 2004-08-03 20:31 63547 -c–a-w- c:\windows\system32\dllcache\sla30nd5.sys
2010-04-21 23:34 . 2001-08-17 10:12 91294 -c–a-w- c:\windows\system32\dllcache\skfpwin.sys
2010-04-21 23:34 . 2001-08-17 10:12 94698 -c–a-w- c:\windows\system32\dllcache\sk98xwin.sys
2010-04-21 23:34 . 2001-08-17 12:56 157696 -c–a-w- c:\windows\system32\dllcache\sisv256.dll
2010-04-21 23:34 . 2001-08-17 10:50 50432 -c–a-w- c:\windows\system32\dllcache\sisv.sys
2010-04-21 23:34 . 2004-08-03 20:31 32768 -c–a-w- c:\windows\system32\dllcache\sisnic.sys
2010-04-21 23:34 . 2001-08-17 20:36 238592 -c–a-w- c:\windows\system32\dllcache\sisgrv.dll
2010-04-21 23:33 . 2001-08-17 10:50 104064 -c–a-w- c:\windows\system32\dllcache\sisgrp.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-25 10:52 . 2010-02-23 00:32 ——– dc—-w- c:\documents and settings\Dario\Application Data\Azureus
2010-04-24 21:09 . 2008-10-19 10:21 ——– dc–a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-24 17:56 . 2009-08-10 10:18 ——– dc—-w- c:\program files\Karma
2010-04-24 13:11 . 2008-08-26 00:59 ——– dc—-w- c:\program files\LimeWire
2010-04-23 21:59 . 2009-10-09 10:03 ——– dc—-w- c:\documents and settings\Dario\Application Data\Yahoo!
2010-04-23 21:57 . 2007-03-04 17:09 ——– dc—-w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-04-23 21:57 . 2007-03-04 17:06 ——– dc—-w- c:\program files\Yahoo!
2010-04-22 20:44 . 2010-02-16 23:47 ——– dc—-w- c:\program files\Microsoft
2010-04-22 19:51 . 2006-07-22 05:19 ——– dc—-w- c:\program files\Google
2010-04-22 06:46 . 2006-10-30 10:05 ——– dc—-w- c:\program files\Windows Live Safety Center
2010-04-20 06:55 . 2006-09-24 12:05 ——– dc—-w- c:\program files\Common Files\Wise Installation Wizard
2010-04-20 06:35 . 2007-07-17 22:46 ——– dc—-w- c:\program files\FLV Player
2010-04-20 06:26 . 2006-05-13 01:45 ——– dc—-w- c:\program files\Samsung
2010-04-20 06:24 . 2008-11-09 18:57 ——– dc—-w- c:\program files\Graboid
2010-04-19 21:58 . 2008-08-26 01:00 ——– dc—-w- c:\documents and settings\Dario\Application Data\LimeWire
2010-04-19 21:58 . 2008-11-29 18:10 ——– dc—-w- c:\program files\Incomplete
2010-04-19 21:36 . 2010-04-21 16:46 170878 -c–a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2010-04-17 16:46 . 2010-02-28 22:39 ——– dc—-w- c:\documents and settings\Dario\Application Data\uTorrent
2010-04-13 13:00 . 2010-03-10 15:33 ——– dc—-w- c:\documents and settings\All Users\Application Data\NOS
2010-04-05 15:44 . 2010-03-23 06:02 866623 -c–a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-330226422-998270827-2084254949-1004-0.dat
2010-04-05 15:44 . 2010-03-23 06:02 383450 -c–a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2010-03-25 17:40 . 2010-03-03 18:28 ——– dc—-w- c:\documents and settings\Dario\Application Data\eM Client
2010-03-24 18:38 . 2010-03-24 18:38 ——– dc—-w- c:\documents and settings\Dario\Application Data\Microsoft Corporation
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\documents and settings\Dario\Application Data\Malwarebytes
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\program files\Malwarebytes' Anti-Malware
2010-03-23 01:45 . 2010-03-23 01:45 ——– dc—-w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-23 01:25 . 2010-03-23 01:25 ——– dc—-w- c:\documents and settings\Dario\Application Data\nswb
2010-03-22 16:02 . 2010-03-22 16:02 ——– dc—-w- c:\program files\Microsoft Help
2010-03-22 16:02 . 2010-03-22 15:45 571712 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\VWDExpress\10.0\1033\ResourceCache.dll
2010-03-22 15:59 . 2010-03-22 15:38 ——– dc—-w- c:\program files\Microsoft Visual Studio 10.0
2010-03-22 15:46 . 2010-02-23 17:33 ——– dc—-w- c:\program files\Microsoft SDKs
2010-03-22 15:42 . 2010-03-22 15:42 ——– dc—-w- c:\program files\Microsoft ASP.NET
2010-03-22 12:15 . 2006-07-22 04:57 ——– dc—-w- c:\program files\Microsoft.NET
2010-03-22 10:27 . 2010-02-23 14:35 ——– dc—-w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-22 10:27 . 2010-02-23 13:49 ——– dc—-w- c:\program files\Microsoft Visual Studio 9.0
2010-03-20 18:16 . 2010-03-20 18:13 ——– dc—-w- c:\program files\Windows Live
2010-03-20 18:15 . 2006-07-22 01:14 ——– dc—-w- c:\program files\MSN Messenger
2010-03-20 18:14 . 2010-03-20 18:14 ——– dc—-w- c:\program files\Windows Live SkyDrive
2010-03-20 17:55 . 2010-03-20 17:55 ——– dc—-w- c:\program files\Common Files\Windows Live
2010-03-20 16:46 . 2010-03-04 07:52 ——– dc—-w- c:\documents and settings\Dario\Application Data\KomaMail
2010-03-19 15:55 . 2010-03-19 15:55 57344 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\Messenger\resources\en-GB\PhotoRes.dll
2010-03-19 15:55 . 2010-03-19 15:55 225280 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\Messenger\resources\en-GB\StpWd.dll
2010-03-19 15:55 . 2010-03-19 15:55 1228800 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\Messenger\resources\en-GB\res_msgr.dll
2010-03-18 23:55 . 2006-07-22 01:32 119760 -c–a-w- c:\documents and settings\Dario\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-17 14:12 . 2010-03-17 14:12 ——– dc—-w- c:\program files\SomePDF
2010-03-17 13:59 . 2006-05-13 01:48 ——– dc—-w- c:\program files\Common Files\Adobe
2010-03-17 13:48 . 2010-02-21 18:41 ——– dc—-w- c:\program files\PDF Editor 3
2010-03-17 11:51 . 2010-02-23 22:34 ——– dc—-w- c:\program files\Harmony_Hollow_Software
2010-03-13 11:57 . 2010-03-13 11:57 ——– dc—-w- c:\program files\MSECache
2010-03-12 09:53 . 2006-07-22 18:07 ——– dc—-w- c:\documents and settings\Dario\Application Data\Skype
2010-03-12 09:50 . 2008-08-27 15:15 ——– dc—-w- c:\documents and settings\Dario\Application Data\skypePM
2010-03-11 23:32 . 2010-03-11 23:32 ——– dc—-w- c:\program files\vanBasco's Karaoke Player
2010-03-10 14:04 . 2010-02-28 22:39 ——– dc—-w- c:\program files\uTorrent
2010-03-10 06:15 . 2005-09-10 19:56 420352 -c–a-w- c:\windows\system32\vbscript.dll
2010-03-09 20:17 . 2007-05-07 22:09 ——– dc—-w- c:\documents and settings\Dario\Application Data\PCTV4Me
2010-03-09 20:17 . 2006-07-21 19:56 ——– dc—-w- c:\program files\IncrediMail
2010-03-09 20:17 . 2006-07-21 21:41 ——– dc—-w- c:\program files\Informer50
2010-03-06 13:59 . 2010-03-04 11:31 664 -c–a-w- c:\windows\system32\d3d9caps.dat
2010-03-04 23:35 . 2010-03-04 23:35 ——– dc—-w- c:\program files\eM Client
2010-03-04 20:39 . 2010-03-04 20:39 ——– dc—-w- c:\documents and settings\Dario\Application Data\NetSpell
2010-03-02 07:24 . 2010-03-01 22:33 ——– dc—-w- c:\program files\IObitCom
2010-03-01 23:24 . 2010-03-01 22:29 ——– dc—-w- c:\documents and settings\Dario\Application Data\IObit
2010-03-01 22:33 . 2010-03-01 22:29 ——– dc—-w- c:\program files\IObit
2010-03-01 22:32 . 2010-03-01 22:32 ——– dc—-w- c:\documents and settings\All Users\Application Data\IObit
2010-03-01 22:26 . 2009-11-05 15:53 ——– dc—-w- c:\program files\NCH Swift Sound
2010-03-01 10:34 . 2010-03-01 10:34 ——– dc—-w- c:\program files\EwisoftWebcom
2010-02-27 14:31 . 2010-02-23 00:03 ——– dc—-w- c:\documents and settings\Dario\Application Data\VoipStunt
2010-02-27 14:26 . 2006-05-13 01:39 ——– dc-h–w- c:\program files\InstallShield Installation Information
2010-02-26 19:10 . 2010-02-19 22:54 ——– dc—-w- c:\documents and settings\Dario\Application Data\FileZilla
2010-02-25 06:24 . 2005-09-10 19:56 916480 -c–a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2005-09-10 19:56 455680 -c–a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 17:38 . 2010-02-23 14:41 488576 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\VWDExpress\9.0\1033\ResourceCache.dll
2010-02-23 17:37 . 2010-02-23 14:40 416 -c–a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-02-21 18:41 . 2010-02-21 18:41 75776 -c–a-w- c:\windows\cadkasdeinst01e.exe
2010-02-16 14:08 . 2005-09-10 19:56 2146304 -c–a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2024448 -c–a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-13 22:47 . 2009-09-18 15:51 103382 -c–a-w- c:\windows\system32\6fe92d1e-7bee-73ea-22af-07e6cd6c2945.exe
2010-02-12 10:03 . 2010-03-06 21:55 293376 -c—-w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2005-09-10 19:56 100864 -c–a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2005-09-10 19:56 226880 -c–a-w- c:\windows\system32\drivers\tcpip6.sys
2008-08-26 00:59 . 2008-08-26 00:59 4898704 -c–a-w- c:\program files\LimeWireWin.exe
2002-04-16 10:27 . 2002-04-16 10:27 5 -csha-w- c:\windows\system32\CdI5T.drv
.

((((((((((((((((((((((((((((( SnapShot@2010-04-23_10.41.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-26 10:38 . 2010-04-26 10:38 16384 c:\windows\temp\Perflib_Perfdata_b80.dat
+ 2010-04-26 10:38 . 2010-04-26 10:38 16384 c:\windows\temp\Perflib_Perfdata_674.dat
- 2006-05-13 01:38 . 2009-01-07 16:21 26144 c:\windows\system32\spupdsvc.exe
+ 2006-05-13 01:38 . 2009-05-12 13:12 26144 c:\windows\system32\spupdsvc.exe
+ 2006-12-31 22:12 . 2009-05-12 13:12 16928 c:\windows\system32\spmsg.dll
- 2006-12-31 22:12 . 2009-01-07 16:20 16928 c:\windows\system32\spmsg.dll
+ 2008-05-26 20:18 . 2009-05-24 22:24 350208 c:\windows\system32\mssph.dll
- 2008-05-26 20:18 . 2008-05-26 20:18 350208 c:\windows\system32\mssph.dll
+ 2010-04-20 14:25 . 2010-04-26 10:38 228725 c:\windows\system32\inetsrv\MetaBase.bin
- 2010-04-20 14:18 . 2010-04-21 07:10 242896 c:\windows\system32\drivers\avgtdix.sys
+ 2010-04-20 14:18 . 2010-04-25 11:50 242896 c:\windows\system32\drivers\avgtdix.sys
+ 2010-04-24 17:56 . 2010-04-24 17:56 168022 c:\windows\Installer\{AFD3AD1F-606A-4A83-9C7A-E3505535A6F9}\_D707CE1C009F1381803C2C.exe
+ 2010-04-24 17:56 . 2010-04-24 17:56 168022 c:\windows\Installer\{AFD3AD1F-606A-4A83-9C7A-E3505535A6F9}\_C7EFEC170C2E3BE8B9D183.exe
+ 2010-04-24 17:56 . 2010-04-24 17:56 168022 c:\windows\Installer\{AFD3AD1F-606A-4A83-9C7A-E3505535A6F9}\_934312A2105DE40686D86A.exe
+ 2010-04-24 17:56 . 2010-04-24 17:56 168022 c:\windows\Installer\{AFD3AD1F-606A-4A83-9C7A-E3505535A6F9}\_6FEFF9B68218417F98F549.exe
+ 2010-04-24 17:56 . 2010-04-24 17:56 168022 c:\windows\Installer\{AFD3AD1F-606A-4A83-9C7A-E3505535A6F9}\_68FA2F28E243283F94E761.exe
+ 2010-04-24 17:56 . 2010-04-24 17:56 168022 c:\windows\Installer\{AFD3AD1F-606A-4A83-9C7A-E3505535A6F9}\_3F1A9F7FBC86D802D41501.exe
+ 2010-04-24 17:56 . 2010-04-24 17:56 168022 c:\windows\Installer\{AFD3AD1F-606A-4A83-9C7A-E3505535A6F9}\_21F3885A18D238E15AAE81.exe
+ 2010-04-24 17:56 . 2010-04-24 17:56 1563648 c:\windows\Installer\101a57f.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]
2010-03-02 07:25 2349080 -c–a-w- c:\program files\IObitCom\tbIOb1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 12:04 1664256 -c–a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
"{31C7D459-9CC3-44F2-9DCA-FC11795309B4}"= "c:\program files\IObitCom\tbIOb1.dll" [2010-03-02 2349080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{31c7d459-9cc3-44f2-9dca-fc11795309b4}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]
"Google Update"="c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-18 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-07 761947]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 88204]
"RestoreIT!"="c:\program files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" [2004-09-23 114688]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2005-04-11 151552]
"BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2006-04-25 2764800]
"AVStation Premium 3.75"="c:\program files\Samsung\AVStation Premium 3.75\AVSAgent.exe" [2006-04-27 155648]
"DisplayManager"="c:\program files\Samsung\DisplayManager\DMLoader.exe" [2006-03-29 1118208]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-03-12 1055792]
"QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe" [2007-04-27 282624]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"SUPBackGround"="c:\program files\Samsung\Samsung Update Plus\SUPBackGround.exe" [2010-02-03 294912]
"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1363.0\mswinext.exe" [2010-01-26 243032]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-17 7585792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"NvMediaCenter"="NvMCTray.dll" [2007-03-17 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-7-22 82026]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-7-23 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-20 14:18 12464 -c–a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dario^Start Menu^Programs^Startup^YPOPs.lnk]
path=c:\documents and settings\Dario\Start Menu\Programs\Startup\YPOPs.lnk
backup=c:\windows\pss\YPOPs.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"c:\\Program Files\\VoipStunt.com\\VoipStunt\\VoipStunt.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\EwisoftWeb\\bin\\WebsiteBuilderP.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\EwisoftWebcom\\bin\\WebsiteBuilderP.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=

R0 RITCPT;RITCPT;c:\windows\system32\drivers\RITCPT.SYS [13/05/2006 03:45 43512]
R0 VVBackd5;VVBackd5;c:\windows\system32\drivers\VVBackd5.sys [02/10/2009 18:34 183159]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [20/04/2010 16:18 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [20/04/2010 16:18 242896]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [25/04/2010 13:18 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [20/04/2010 16:18 308064]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [10/09/2005 23:35 4300]
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [02/03/2010 00:32 311568]
R2 MarxDev1;MarxDev1;c:\windows\system32\drivers\MARXDEV1.SYS [19/10/2008 09:44 8864]
R2 MarxDev2;MarxDev2;c:\windows\system32\drivers\MARXDEV2.SYS [19/10/2008 09:44 8864]
R2 MarxDev3;MarxDev3;c:\windows\system32\drivers\MARXDEV3.SYS [19/10/2008 09:44 8864]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [24/03/2010 18:48 323992]
S2 clr_optimization_v4.0.21006_32;Microsoft .NET Framework NGEN v4.0.21006_X86;c:\windows\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe [07/10/2009 03:44 129856]
S2 FBAPI;FBAPI;\??\c:\windows\system32\drivers\FBAPI.sys –> c:\windows\system32\drivers\FBAPI.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30/08/2009 11:56 133104]
S2 SNM WLAN Service;SNM WLAN Service;c:\program files\Samsung\Samsung Network Manager\SNMWLANService.exe [28/05/2005 17:35 36864]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [25/04/2010 13:18 369920]
S3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [27/01/2010 18:10 5248]
S3 MRV6X32U;Vista 32-bits Native WiFi Driver - USB;c:\windows\system32\drivers\MRVW23B.sys [09/08/2008 13:23 231040]
S3 MRVW225;TVT-RWUSB54 Wireless LAN Dirver for Windows XP;c:\windows\system32\drivers\MRVW225.sys [09/08/2008 13:23 299904]
S3 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [19/01/2010 18:49 55184]
S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [18/10/2006 10:08 229376]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe [07/10/2009 03:44 752984]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [31/03/2009 10:44 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [30/03/2009 04:09 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30/03/2009 04:23 366936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2010-04-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 13:42]

2010-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-30 09:55]

2010-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-30 09:55]

2010-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-330226422-998270827-2084254949-1004Core.job
- c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-18 15:17]

2010-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-330226422-998270827-2084254949-1004UA.job
- c:\documents and settings\Dario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-18 15:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/ig?hl=en&source=iglk
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {236145DF-E1AE-40EB-8F0F-C90AD79855C6} = 80.58.61.250,80.58.61.254
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Dario\Application Data\Mozilla\Firefox\Profiles\6qelqp1h.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig?hl=en&source=iglk
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin5.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-26 13:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(508)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-04-26 13:25:07
ComboFix-quarantined-files.txt 2010-04-26 11:25
ComboFix2.txt 2010-04-25 09:57
ComboFix3.txt 2010-04-23 10:45

Pre-Run: 14,709,678,080 bytes free
Post-Run: 14,689,378,304 bytes free

- - End Of File - - 274916995464157F267E7E63FA824C8B

File uploaded as requested

How is my computer now…….

I am not getting virus found pop ups anymore, have noticed that I can not uninstall many programs that I want to get rid off, the uninstall logs/scripts are corrupt. even tried command line removal but looks like the command line is corrupt also.

still some pages in IE8 come up blank but when I close the page the content flashes up just before the page closes.

Apart from that usb mouse keeps disabling have to unplug and replug to activate it.

Sytem seems a little faster overall by the way I have a Samsung R55 with 1gig ram, 90 gig hd running windows xp pro and ubuntu linux. most data is kept on external usb drives one 90gig and one 500gig.

Have you any Idea of what I had or have got…..

TIA
Dario
Hi,

Are there any error messages when you try to uninstall them? Also with the command line, you can't run the command prompt?

Your pc was infected by a bunch of nasty trojans, they may have corrupted some of your files or drivers. Let's deal with the malware first then tackle the other problems later.

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

–Next–

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
To post in your next reply:
1. Malwarebytes' log.
2. Kaspersky log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI