This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very slow PC

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, here is my Hijack this log. My computer is running very slow recently and believe there is a virus.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:39:02 PM, on 8/27/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Hiram\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hiram\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hiram\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hiram\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hiram\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.latimes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Hiram\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2…15106/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 9510 bytes
Hi icecold240, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

I see 3 or at least remnants of 3 antivirus programs installed. You have AVG9, a bit of AVast and when you installed Comodo Internet Security Suite did you install the antivirus too?

Make sure these settings are correct.

Open Internet Explorer
  • at the top click Tools
  • Click Internet Options
  • Click Connections tab
  • Click Lan Settings button
  • Make sure the box beside "Use a proxy sever for your Lan" is UNchecked
  • OK your way out.

Next

Open hijackthis, do a system scan only and checkmark these lines, if present

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode

Next

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
  • Please answer question regarding antivirus program.
Thanks
I installed AVG. I dont know about the Avast and when I installed Comodo it was with the antivirus.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-01 09:47:23
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Hiram\LOCALS~1\Temp\kxtdypog.sys


—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10008B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10008A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\winlogon.exe[244] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\services.exe[288] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10008450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10008590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] SHELL32.dll!ShellExecuteExW 7CA0991B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] SHELL32.dll!ShellExecuteEx 7CA40E7D 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] SHELL32.dll!ShellExecuteA 7CA411A8 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\lsass.exe[300] SHELL32.dll!ShellExecuteW 7CAB5E68 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10008B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10008A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10008450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10008590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] SHELL32.dll!ShellExecuteExW 7CA0991B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] SHELL32.dll!ShellExecuteEx 7CA40E7D 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] SHELL32.dll!ShellExecuteA 7CA411A8 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[456] SHELL32.dll!ShellExecuteW 7CAB5E68 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10008B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10008A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10008450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10008590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] SHELL32.dll!ShellExecuteExW 7CA0991B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] SHELL32.dll!ShellExecuteEx 7CA40E7D 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] SHELL32.dll!ShellExecuteA 7CA411A8 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[516] SHELL32.dll!ShellExecuteW 7CAB5E68 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10008B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10008A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10008450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10008590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] SHELL32.dll!ShellExecuteExW 7CA0991B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] SHELL32.dll!ShellExecuteEx 7CA40E7D 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] SHELL32.dll!ShellExecuteA 7CA411A8 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[576] SHELL32.dll!ShellExecuteW 7CAB5E68 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10008B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10008A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[648] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10008B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10008A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10008450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10008590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 10001E30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 10001E50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] SHELL32.dll!ShellExecuteExW 7CA0991B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] SHELL32.dll!ShellExecuteEx 7CA40E7D 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] SHELL32.dll!ShellExecuteA 7CA411A8 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\Explorer.EXE[932] SHELL32.dll!ShellExecuteW 7CAB5E68 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10008B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10008A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10008450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10008590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] shell32.dll!ShellExecuteExW 7CA0991B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] shell32.dll!ShellExecuteEx 7CA40E7D 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] shell32.dll!ShellExecuteA 7CA411A8 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Documents and Settings\Hiram\Desktop\New Folder\gmer.exe[1200] shell32.dll!ShellExecuteW 7CAB5E68 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)

—- EOF - GMER 1.0.15 —-
OTL logfile created on: 9/1/2010 9:54:43 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Hiram\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 307.00 Mb Available Physical Memory | 30.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.60 Gb Total Space | 175.70 Gb Free Space | 47.15% Space Free | Partition Type: NTFS
Drive D: | 36.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SATURN
Current User Name: Hiram
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Hiram\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Hiram\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe (ExtendMedia Inc.)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Hiram\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (OpenCASE Media Agent) – C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe (ExtendMedia Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (InCDRm) – C:\WINDOWS\System32\drivers\InCDRm.sys File not found
DRV - (InCDPass) – C:\WINDOWS\System32\drivers\InCDPass.sys File not found
DRV - (InCDFs) – C:\WINDOWS\System32\drivers\InCDFs.sys File not found
DRV - (EraserUtilDrv10821) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10821.sys File not found
DRV - (catchme) – C:\DOCUME~1\Hiram\LOCALS~1\Temp\catchme.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdguard.sys (COMODO)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (w600obex) – C:\WINDOWS\system32\drivers\w600obex.sys (MCCI)
DRV - (w600mgmt) – C:\WINDOWS\system32\drivers\w600mgmt.sys (MCCI)
DRV - (w600mdm) – C:\WINDOWS\system32\drivers\w600mdm.sys (MCCI)
DRV - (w600mdfl) – C:\WINDOWS\system32\drivers\w600mdfl.sys (MCCI)
DRV - (w600bus) Sony Ericsson W600 driver (WDM) – C:\WINDOWS\system32\drivers\w600bus.sys (MCCI)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (WFIOCTL) – C:\Program Files\WinFast\WFTVFM\WFIOCTL.sys (Leadtek Research Inc.)
DRV - (ULCDRHlp) – C:\WINDOWS\system32\drivers\ULCDRHlp.sys (Ulead Systems, Inc.)
DRV - (tv2ktunr) – C:\WINDOWS\system32\drivers\wf2ktunr.sys (Leadtek Research Inc.)
DRV - (Tv2kXbar) – C:\WINDOWS\system32\drivers\wf2kXbar.sys (Leadtek Research Inc.)
DRV - (BT848) – C:\WINDOWS\system32\drivers\wf2kvcap.sys (Leadtek Research Inc.)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = http://www.google.com/
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.latimes.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.latimes.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.10.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.51
FF - prefs.js..keyword.URL: "http://search.search-go.net/?sid=10101053100&s="

FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "http://search.search-go.net/?sid=10101053100&s="

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/08/26 22:06:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/30 22:33:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/30 22:33:41 | 000,000,000 | —D | M]

[2008/06/18 03:48:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Mozilla\Extensions
[2010/08/29 21:21:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions
[2009/09/27 12:43:36 | 000,000,000 | —D | M] (Screengrab) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2009/06/12 16:09:33 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/09/27 12:43:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2007/11/29 04:40:49 | 000,000,000 | —D | M] (Aquatint Black) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{526fd696-27a0-11dc-8314-0800200c9a66}
[2009/09/27 12:43:37 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2008/04/18 23:14:27 | 000,000,000 | —D | M] (Blue Ice 2) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}
[2009/08/11 19:31:30 | 000,000,000 | —D | M] (Password Exporter) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2009/09/27 12:43:40 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/08/13 14:41:48 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/07/01 13:44:18 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/02/19 17:08:19 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2008/03/25 14:59:36 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2008/12/16 02:24:45 | 000,000,891 | —- | M] () – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\searchplugins\dictionarycom.xml
[2010/08/29 12:32:48 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/24 21:06:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/08/24 21:06:35 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2005/12/06 00:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll

O1 HOSTS File: ([2010/08/25 17:29:24 | 000,416,183 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14390 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] C:\Program Files\Alwil Software\Avast4\ashDisp.exe File not found
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.lizardtech.com/download/files/w…ntrol_en_US.cab (DjVuCtl Class)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su2…15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/09/04 18:58:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/10/28 05:48:06 | 000,000,045 | R— | M] () - D:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/01 09:53:14 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Hiram\Desktop\OTL.exe
[2010/08/30 22:33:15 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/08/30 22:29:26 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/08/30 22:29:07 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/08/30 22:29:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/08/30 22:21:22 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/08/30 13:51:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Pics - Summer 2010
[2010/08/30 13:03:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Application Data\VirtualStore
[2010/08/29 20:02:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Tosh.0 - S02E18 - Peter Pan Girls
[2010/08/29 20:01:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Tosh.0.S02E19.HDTV.XviD-aAF [NO-RAR] - [ www.torrentday.com ]
[2010/08/29 20:00:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Tosh.0 - S02E21 - American Idol Girls
[2010/08/29 14:02:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Walt Disney's Monsters Inc
[2010/08/29 02:25:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Application Data\Acapela Group
[2010/08/29 02:25:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Local Settings\Application Data\Xtranormal
[2010/08/29 02:23:21 | 000,000,000 | —D | C] – C:\Program Files\Xtranormal
[2010/08/29 02:22:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Application Data\Xtranormal
[2010/08/27 23:22:45 | 000,000,000 | —D | C] – C:\Program Files\RegCure
[2010/08/27 23:18:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\RegCure 3.0.2 Software + Crack
[2010/08/27 23:02:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/08/27 16:58:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Application Data\Office Genuine Advantage
[2010/08/26 22:08:38 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/08/26 22:08:35 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/08/26 22:08:27 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/08/26 22:08:24 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/08/26 22:08:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/08/26 22:04:20 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/08/26 22:03:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/08/26 20:32:23 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/08/26 19:19:21 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2010/08/26 19:19:21 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpcdll.dll
[2010/08/26 19:19:21 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2010/08/26 19:19:14 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\irbus.sys
[2010/08/26 19:19:13 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2010/08/26 19:19:13 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2010/08/26 19:19:13 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2010/08/26 19:19:12 | 000,229,376 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2cqag.dll
[2010/08/26 19:19:12 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2010/08/26 19:19:11 | 001,888,992 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3duag.dll
[2010/08/26 19:19:11 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2010/08/26 19:19:11 | 000,516,768 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ativvaxx.dll
[2010/08/26 19:19:11 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2010/08/26 19:19:11 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2010/08/26 19:19:11 | 000,201,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvag.dll
[2010/08/26 19:19:11 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2010/08/26 19:19:11 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2010/08/26 19:19:11 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2010/08/26 19:19:11 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2010/08/26 19:19:11 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2010/08/26 19:19:11 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2010/08/26 19:19:11 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2010/08/26 19:19:11 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2010/08/26 19:19:11 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2010/08/26 19:19:11 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2010/08/26 19:19:10 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2010/08/26 19:19:10 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2010/08/26 19:19:10 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2010/08/26 19:19:10 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2010/08/26 19:19:10 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2010/08/26 19:19:10 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2010/08/26 19:19:10 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2010/08/26 19:19:10 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2010/08/26 19:19:10 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2010/08/26 19:19:10 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2010/08/26 19:19:10 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2010/08/26 19:19:09 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2010/08/26 19:19:09 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2010/08/26 19:19:09 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2010/08/26 19:19:09 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2010/08/26 19:19:09 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2010/08/26 19:19:08 | 004,274,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nv4_disp.dll
[2010/08/26 19:19:08 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2010/08/26 19:19:08 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2010/08/26 19:19:08 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2010/08/26 19:19:08 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2010/08/26 19:19:08 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2010/08/26 19:19:08 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2010/08/26 19:19:08 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2010/08/26 19:19:08 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2010/08/26 19:19:08 | 000,086,016 | —- | C] (Conexant) – C:\WINDOWS\System32\mdmxsdk.dll
[2010/08/26 19:19:08 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2010/08/26 19:19:08 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2010/08/26 19:19:08 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2010/08/26 19:19:07 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2010/08/26 19:19:07 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2010/08/26 19:19:07 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2010/08/26 19:19:07 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2010/08/26 19:19:07 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2010/08/26 19:19:07 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2010/08/26 19:19:07 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2010/08/26 19:19:07 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2010/08/26 19:19:07 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2010/08/26 19:19:07 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2010/08/26 19:19:07 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2010/08/26 19:19:07 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2010/08/26 19:19:07 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2010/08/26 19:19:06 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2010/08/26 19:19:05 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2010/08/26 19:19:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/08/26 19:19:04 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/08/26 19:19:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2010/08/26 19:19:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2010/08/26 19:15:23 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2010/08/26 19:15:23 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2010/08/26 19:15:23 | 000,043,008 | —- | C] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\drivers\amdagp.sys
[2010/08/26 19:15:23 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2010/08/26 19:15:23 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2010/08/26 19:15:23 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2010/08/26 19:15:23 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2010/08/26 19:15:23 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2010/08/26 19:15:23 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2010/08/26 19:15:23 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2010/08/26 19:15:23 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2010/08/26 19:15:23 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2010/08/26 19:15:23 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2010/08/26 19:15:23 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2010/08/26 19:15:23 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2010/08/26 19:15:23 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2010/08/26 19:15:22 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtag.sys
[2010/08/26 19:15:22 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2010/08/26 19:15:22 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2010/08/26 19:15:22 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2010/08/26 19:15:22 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2010/08/26 19:15:22 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2010/08/26 19:15:22 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2010/08/26 19:15:22 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2010/08/26 19:15:22 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2010/08/26 19:15:22 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2010/08/26 19:15:22 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2010/08/26 19:15:22 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2010/08/26 19:15:22 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2010/08/26 19:15:22 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2010/08/26 19:15:22 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2010/08/26 19:15:22 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2010/08/26 19:15:22 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2010/08/26 19:15:22 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2010/08/26 19:15:22 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2010/08/26 19:15:21 | 000,144,384 | —- | C] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\drivers\hdaudbus.sys
[2010/08/26 19:15:21 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2010/08/26 19:15:21 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2010/08/26 19:15:20 | 001,897,408 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\drivers\nv4_mini.sys
[2010/08/26 19:15:20 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2010/08/26 19:15:20 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2010/08/26 19:15:20 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2010/08/26 19:15:20 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2010/08/26 19:15:20 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2010/08/26 19:15:20 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2010/08/26 19:15:20 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2010/08/26 19:15:19 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2010/08/26 19:15:19 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2010/08/26 19:15:19 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2010/08/26 19:15:19 | 000,040,960 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\drivers\sisagp.sys
[2010/08/26 19:15:19 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2010/08/26 19:15:19 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2010/08/26 19:15:19 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2010/08/26 19:15:18 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2010/08/26 19:15:18 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2010/08/26 19:15:18 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2010/08/26 19:15:18 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2010/08/26 19:15:18 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2010/08/26 19:15:18 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2010/08/26 19:15:18 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2010/08/26 19:09:29 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2010/08/26 17:34:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/08/25 17:02:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\monthly maintenance
[2010/08/24 21:07:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/08/24 21:07:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/08/24 21:06:49 | 000,423,656 | —- | C] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/24 21:06:49 | 000,153,376 | —- | C] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/08/24 21:06:49 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/08/24 21:06:49 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/08/24 21:06:49 | 000,073,728 | —- | C] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/08/24 20:56:54 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Hiram\IECompatCache
[2010/08/24 20:56:18 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Hiram\PrivacIE
[2010/08/24 13:29:51 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/08/24 13:25:41 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/08/24 13:12:46 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/08/24 13:07:51 | 000,023,040 | —- | C] (Xerox Corporation) – C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2010/08/24 13:07:50 | 000,004,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2010/08/24 13:07:38 | 000,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2010/08/24 13:07:38 | 000,016,970 | —- | C] (US Robotics MCD (Megahertz)) – C:\WINDOWS\System32\dllcache\xem336n5.sys
[2010/08/24 13:07:36 | 000,019,455 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wvchntxx.sys
[2010/08/24 13:07:33 | 000,012,063 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wsiintxx.sys
[2010/08/24 13:07:19 | 000,154,624 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\wlluc48.sys
[2010/08/24 13:07:18 | 000,034,890 | —- | C] (Raytheon Corp.) – C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2010/08/24 13:07:14 | 000,771,581 | —- | C] (Rockwell) – C:\WINDOWS\System32\dllcache\winacisa.sys
[2010/08/24 13:07:11 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2010/08/24 13:07:11 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2010/08/24 13:07:08 | 000,701,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\wdhaalba.sys
[2010/08/24 13:07:07 | 000,023,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wch7xxnt.sys
[2010/08/24 13:07:06 | 000,035,871 | —- | C] (Winbond Electronics Corp.) – C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2010/08/24 13:07:03 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv10nt.sys
[2010/08/24 13:07:02 | 000,033,599 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv04nt.sys
[2010/08/24 13:07:02 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv06nt.sys
[2010/08/24 13:07:01 | 000,019,551 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv02nt.sys
[2010/08/24 13:07:00 | 000,029,311 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv01nt.sys
[2010/08/24 13:06:57 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv11nt.sys
[2010/08/24 13:06:57 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv09nt.sys
[2010/08/24 13:06:56 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv08nt.sys
[2010/08/24 13:06:55 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv07nt.sys
[2010/08/24 13:06:54 | 000,011,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv05nt.sys
[2010/08/24 13:06:53 | 000,012,127 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv02nt.sys
[2010/08/24 13:06:52 | 000,012,415 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv01nt.sys
[2010/08/24 13:06:49 | 000,019,528 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w840nd.sys
[2010/08/24 13:06:49 | 000,019,016 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w926nd.sys
[2010/08/24 13:06:49 | 000,016,925 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w940nd.sys
[2010/08/24 13:06:42 | 000,064,605 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vvoice.sys
[2010/08/24 13:06:41 | 000,397,502 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vpctcom.sys
[2010/08/24 13:06:40 | 000,604,253 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\vmodem.sys
[2010/08/24 13:06:39 | 000,249,402 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\vinwm.sys
[2010/08/24 13:06:39 | 000,024,576 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\viairda.sys
[2010/08/24 13:06:33 | 000,765,884 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usrti.sys
[2010/08/24 13:06:33 | 000,687,999 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2010/08/24 13:06:32 | 000,113,762 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrpda.sys
[2010/08/24 13:06:32 | 000,007,556 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usroslba.sys
[2010/08/24 13:06:31 | 000,224,802 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usr1807a.sys
[2010/08/24 13:06:30 | 000,794,399 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806v.sys
[2010/08/24 13:06:30 | 000,793,598 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806.sys
[2010/08/24 13:06:29 | 000,794,654 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1801.sys
[2010/08/24 13:06:22 | 000,032,384 | —- | C] (KLSI USA, Inc.) – C:\WINDOWS\System32\dllcache\usb101et.sys
[2010/08/24 13:06:19 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxud32.dll
[2010/08/24 13:06:19 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu40.dll
[2010/08/24 13:06:18 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu12.dll
[2010/08/24 13:06:18 | 000,050,688 | —- | C] (UMAX DATA SYSTEMS INC.) – C:\WINDOWS\System32\dllcache\umaxscan.dll
[2010/08/24 13:06:18 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu22.dll
[2010/08/24 13:06:17 | 000,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxp60.dll
[2010/08/24 13:06:17 | 000,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxcam.dll
[2010/08/24 13:06:17 | 000,022,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2010/08/24 13:06:15 | 000,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2010/08/24 13:06:15 | 000,211,968 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um54scan.dll
[2010/08/24 13:06:15 | 000,036,736 | —- | C] (Promise Technology, Inc.) – C:\WINDOWS\System32\dllcache\ultra.sys
[2010/08/24 13:06:11 | 000,011,520 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\twotrack.sys
[2010/08/24 13:06:09 | 000,166,784 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxpm.sys
[2010/08/24 13:06:08 | 000,525,568 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxp.dll
[2010/08/24 13:06:08 | 000,440,576 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkb.dll
[2010/08/24 13:06:08 | 000,159,232 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkbm.sys
[2010/08/24 13:06:07 | 000,315,520 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3d.dll
[2010/08/24 13:06:07 | 000,222,336 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3dm.sys
[2010/08/24 13:06:06 | 000,042,496 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4res.dll
[2010/08/24 13:06:06 | 000,034,375 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\tpro4.sys
[2010/08/24 13:06:04 | 000,031,744 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4.dll
[2010/08/24 13:06:03 | 000,241,664 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd02.sys
[2010/08/24 13:06:03 | 000,230,912 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd03.sys
[2010/08/24 13:06:03 | 000,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\toside.sys
[2010/08/24 13:06:02 | 000,028,232 | —- | C] (TOSHIBA Corporation) – C:\WINDOWS\System32\dllcache\tos4mo.sys
[2010/08/24 13:06:01 | 000,123,995 | —- | C] (Tiger Jet Network) – C:\WINDOWS\System32\dllcache\tjisdn.sys
[2010/08/24 13:05:59 | 000,138,528 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2010/08/24 13:05:59 | 000,081,408 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiul50.dll
[2010/08/24 13:05:56 | 000,017,129 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2010/08/24 13:05:55 | 000,037,961 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdk100b.sys
[2010/08/24 13:05:53 | 000,030,464 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tbatm155.sys
[2010/08/24 13:05:51 | 000,036,640 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2010/08/24 13:05:51 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tandqic.sys
[2010/08/24 13:05:50 | 000,172,768 | —- | C] (Number Nine Visual Technology) – C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2010/08/24 13:05:48 | 000,032,640 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\symc8xx.sys
[2010/08/24 13:05:47 | 000,030,688 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\sym_u3.sys
[2010/08/24 13:05:47 | 000,028,384 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\sym_hi.sys
[2010/08/24 13:05:47 | 000,016,256 | —- | C] (Symbios Logic Inc.) – C:\WINDOWS\System32\dllcache\symc810.sys
[2010/08/24 13:05:45 | 000,103,936 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sx.sys
[2010/08/24 13:05:45 | 000,094,293 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sxports.dll
[2010/08/24 13:05:45 | 000,003,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swusbflt.sys
[2010/08/24 13:05:44 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpidflt.dll
[2010/08/24 13:05:44 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2010/08/24 13:05:43 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2010/08/24 13:05:43 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_effct.dll
[2010/08/24 13:05:41 | 000,285,760 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnata.sys
[2010/08/24 13:05:41 | 000,155,648 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnprop.dll
[2010/08/24 13:05:41 | 000,053,248 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlncoin.dll
[2010/08/24 13:05:40 | 000,016,896 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\stcusb.sys
[2010/08/24 13:05:36 | 000,048,736 | —- | C] (3Com) – C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2010/08/24 13:05:34 | 000,099,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusd.dll
[2010/08/24 13:05:32 | 000,024,660 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spxupchk.dll
[2010/08/24 13:05:30 | 000,061,824 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\speed.sys
[2010/08/24 13:05:29 | 000,106,584 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spdports.dll
[2010/08/24 13:05:29 | 000,019,072 | —- | C] (Adaptec, Inc.) – C:\WINDOWS\System32\dllcache\sparrow.sys
[2010/08/24 13:05:28 | 000,037,040 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.sys
[2010/08/24 13:05:28 | 000,007,552 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2010/08/24 13:05:27 | 000,114,688 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.dll
[2010/08/24 13:05:27 | 000,020,752 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonync.sys
[2010/08/24 13:05:27 | 000,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonymc.sys
[2010/08/24 13:05:25 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2010/08/24 13:05:10 | 000,058,368 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smiminib.sys
[2010/08/24 13:05:09 | 000,147,200 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smidispb.dll
[2010/08/24 13:05:08 | 000,025,034 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2010/08/24 13:05:07 | 000,035,913 | —- | C] (SMC) – C:\WINDOWS\System32\dllcache\smcirda.sys
[2010/08/24 13:05:07 | 000,024,576 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smc8000n.sys
[2010/08/24 13:05:07 | 000,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbhc.sys
[2010/08/24 13:05:04 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb3w.dll
[2010/08/24 13:05:03 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb0w.dll
[2010/08/24 13:05:02 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma0w.dll
[2010/08/24 13:05:01 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm91w.dll
[2010/08/24 13:04:56 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slwdmsup.sys
[2010/08/24 13:04:54 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slnthal.sys
[2010/08/24 13:04:53 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slntamr.sys
[2010/08/24 13:04:53 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slnt7554.sys
[2010/08/24 13:04:49 | 000,094,698 | —- | C] (SysKonnect GmbH.) – C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2010/08/24 13:04:49 | 000,091,294 | —- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) – C:\WINDOWS\System32\dllcache\skfpwin.sys
[2010/08/24 13:04:49 | 000,063,547 | —- | C] (Symbol Technologies) – C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2010/08/24 13:04:48 | 000,157,696 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv256.dll
[2010/08/24 13:04:48 | 000,050,432 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv.sys
[2010/08/24 13:04:47 | 000,032,768 | —- | C] (SiS Corporation) – C:\WINDOWS\System32\dllcache\sisnic.sys
[2010/08/24 13:04:46 | 000,238,592 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrv.dll
[2010/08/24 13:04:46 | 000,104,064 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrp.sys
[2010/08/24 13:04:45 | 000,150,144 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306v.dll
[2010/08/24 13:04:45 | 000,068,608 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306p.sys
[2010/08/24 13:04:44 | 000,252,032 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300iv.dll
[2010/08/24 13:04:44 | 000,101,760 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300ip.sys
[2010/08/24 13:04:37 | 000,161,568 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2010/08/24 13:04:37 | 000,018,400 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmld.sys
[2010/08/24 13:04:36 | 000,386,560 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiul50.dll
[2010/08/24 13:04:36 | 000,098,080 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2010/08/24 13:04:34 | 000,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2010/08/24 13:04:34 | 000,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2010/08/24 13:04:25 | 000,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2010/08/24 13:04:24 | 000,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2010/08/24 13:03:30 | 000,017,280 | —- | C] (SCM Microsystems) – C:\WINDOWS\System32\dllcache\scr111.sys
[2010/08/24 13:03:29 | 000,016,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scmstcs.sys
[2010/08/24 13:03:28 | 000,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2010/08/24 13:03:28 | 000,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2010/08/24 13:03:25 | 000,075,392 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmxm.sys
[2010/08/24 13:03:24 | 000,245,632 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmx.dll
[2010/08/24 13:03:24 | 000,198,400 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4.dll
[2010/08/24 13:03:24 | 000,077,824 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2010/08/24 13:03:23 | 000,210,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2010/08/24 13:03:23 | 000,179,264 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2010/08/24 13:03:23 | 000,061,504 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2010/08/24 13:03:22 | 000,182,272 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2010/08/24 13:03:22 | 000,062,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2010/08/24 13:03:22 | 000,041,216 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2010/08/24 13:03:21 | 000,166,720 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3m.sys
[2010/08/24 13:03:21 | 000,065,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.sys
[2010/08/24 13:03:20 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3gnbm.sys
[2010/08/24 13:03:19 | 000,082,432 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia450.dll
[2010/08/24 13:03:18 | 000,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia430.dll
[2010/08/24 13:03:14 | 000,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8139.sys
[2010/08/24 13:03:13 | 000,030,720 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rthwcls.sys
[2010/08/24 13:03:13 | 000,019,017 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8029.sys
[2010/08/24 13:03:12 | 000,009,216 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2010/08/24 13:03:11 | 000,003,840 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rpfun.sys
[2010/08/24 13:03:03 | 000,037,563 | —- | C] (RadioLAN) – C:\WINDOWS\System32\dllcache\rlnet5.sys
[2010/08/24 13:03:01 | 000,086,097 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\reslog32.dll
[2010/08/24 12:58:34 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\recagent.sys
[2010/08/24 12:58:31 | 000,019,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasirda.sys
[2010/08/24 12:58:28 | 000,714,762 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2010/08/24 12:58:27 | 000,899,146 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2010/08/24 12:58:27 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qvusd.dll
[2010/08/24 12:58:27 | 000,003,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qv2kux.sys
[2010/08/24 12:58:24 | 000,049,024 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql1280.sys
[2010/08/24 12:58:24 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql1240.sys
[2010/08/24 12:58:23 | 000,045,312 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql12160.sys
[2010/08/24 12:58:23 | 000,040,320 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql1080.sys
[2010/08/24 12:58:23 | 000,033,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql10wnt.sys
[2010/08/24 12:58:20 | 000,130,942 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlv.sys
[2010/08/24 12:58:19 | 000,128,286 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserli.sys
[2010/08/24 12:58:19 | 000,112,574 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlp.sys
[2010/08/24 12:58:17 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusb.dll
[2010/08/24 12:58:16 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\psisload.dll
[2010/08/24 12:58:15 | 000,016,128 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\pscr.sys
[2010/08/24 12:58:12 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa.sys
[2010/08/24 12:58:11 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pnrmc.sys
[2010/08/24 12:58:09 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\plugin.ocx
[2010/08/24 12:58:07 | 000,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phvfwext.dll
[2010/08/24 12:58:07 | 000,019,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philtune.sys
[2010/08/24 12:58:06 | 000,173,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam2.sys
[2010/08/24 12:58:06 | 000,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phildec.sys
[2010/08/24 12:58:06 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.sys
[2010/08/24 12:58:05 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phdsext.ax
[2010/08/24 12:58:05 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.dll
[2010/08/24 12:58:00 | 000,027,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2.sys
[2010/08/24 12:58:00 | 000,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2hib.sys
[2010/08/24 12:57:58 | 000,169,984 | —- | C] (Cisco Systems) – C:\WINDOWS\System32\dllcache\pcx500.sys
[2010/08/24 12:57:58 | 000,086,016 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\pctspk.exe
[2010/08/24 12:57:57 | 000,035,328 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2010/08/24 12:57:57 | 000,030,282 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2010/08/24 12:57:57 | 000,029,769 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2010/08/24 12:57:56 | 000,026,153 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2010/08/24 12:57:55 | 000,030,495 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pc100nds.sys
[2010/08/24 12:57:55 | 000,029,502 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\pca200e.sys
[2010/08/24 12:57:49 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2rc.dll
[2010/08/24 12:57:48 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2.dll
[2010/08/24 12:57:48 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcoms.exe
[2010/08/24 12:57:48 | 000,025,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovsound2.sys
[2010/08/24 12:57:47 | 000,351,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodek2.sys
[2010/08/24 12:57:47 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodec2.dll
[2010/08/24 12:57:47 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcomc.dll
[2010/08/24 12:57:46 | 000,048,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcam2.sys
[2010/08/24 12:57:46 | 000,031,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovce.sys
[2010/08/24 12:57:46 | 000,028,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcd.sys
[2010/08/24 12:57:45 | 000,054,186 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otcsercb.sys
[2010/08/24 12:57:45 | 000,043,689 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otceth5.sys
[2010/08/24 12:57:45 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovca.sys
[2010/08/24 12:57:44 | 000,027,209 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otc06x5.sys
[2010/08/24 12:57:43 | 000,054,528 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\opl3sax.sys
[2010/08/24 12:57:36 | 001,897,408 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv4_mini.sys
[2010/08/24 12:57:35 | 000,198,144 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.sys
[2010/08/24 12:57:34 | 000,123,776 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.dll
[2010/08/24 12:57:33 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\ntmtlfax.sys
[2010/08/24 12:57:30 | 000,051,552 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\dllcache\ntgrip.sys
[2010/08/24 12:51:17 | 000,009,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntapm.sys
[2010/08/24 12:51:17 | 000,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsmmc.sys
[2010/08/24 12:51:13 | 000,126,080 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2010/08/24 12:51:13 | 000,087,040 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2010/08/24 12:51:12 | 000,032,840 | —- | C] (NETGEAR Corporation.) – C:\WINDOWS\System32\dllcache\ngrpci.sys
[2010/08/24 12:51:10 | 000,132,695 | —- | C] (802.11b) – C:\WINDOWS\System32\dllcache\netwlan5.sys
[2010/08/24 12:51:07 | 000,065,278 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\netflx3.sys
[2010/08/24 12:51:06 | 000,039,264 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.sys
[2010/08/24 12:51:05 | 000,060,480 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.dll
[2010/08/24 12:51:05 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ne2000.sys
[2010/08/24 12:51:02 | 000,091,488 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2010/08/24 12:51:02 | 000,027,936 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3d.sys
[2010/08/24 12:51:01 | 000,059,104 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2010/08/24 12:51:01 | 000,033,088 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2010/08/24 12:51:01 | 000,013,664 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.sys
[2010/08/24 12:51:00 | 000,128,000 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n100325.sys
[2010/08/24 12:51:00 | 000,035,392 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.dll
[2010/08/24 12:50:59 | 000,075,520 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxport.sys
[2010/08/24 12:50:59 | 000,052,255 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2010/08/24 12:50:59 | 000,007,168 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxport.dll
[2010/08/24 12:50:58 | 000,019,968 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxicfg.dll
[2010/08/24 12:50:58 | 000,019,968 | —- | C] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\dllcache\mxnic.sys
[2010/08/24 12:50:57 | 000,021,888 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxcard.sys
[2010/08/24 12:50:55 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mtxparhm.sys
[2010/08/24 12:50:55 | 000,103,296 | —- | C] (Matrox Graphics Inc) – C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2010/08/24 12:50:51 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\mtlstrm.sys
[2010/08/24 12:50:50 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\mtlmnt5.sys
[2010/08/24 12:50:43 | 000,012,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msriffwv.sys
[2010/08/24 12:50:40 | 000,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msmpu401.sys
[2010/08/24 12:50:27 | 000,035,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msgame.sys
[2010/08/24 12:50:26 | 000,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfsio.sys
[2010/08/24 12:50:19 | 000,017,280 | —- | C] (American Megatrends Inc.) – C:\WINDOWS\System32\dllcache\mraid35x.sys
[2010/08/24 12:50:14 | 000,016,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\modemcsa.sys
[2010/08/24 12:50:11 | 000,006,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\miniqic.sys
[2010/08/24 12:50:07 | 000,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaum.sys
[2010/08/24 12:50:07 | 000,235,648 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaud.dll
[2010/08/24 12:50:04 | 000,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memgrp.dll
[2010/08/24 12:50:03 | 000,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memcard.sys
[2010/08/24 12:50:02 | 000,164,586 | —- | C] (Madge Networks Ltd) – C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2010/08/24 12:49:57 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mammoth.sys
[2010/08/24 12:48:59 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3092dc.dll
[2010/08/24 12:48:59 | 000,048,768 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\maestro.sys
[2010/08/24 12:48:58 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3091dc.dll
[2010/08/24 12:48:57 | 000,022,848 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwusbhid.sys
[2010/08/24 12:48:56 | 000,020,864 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwadihid.sys
[2010/08/24 12:48:55 | 000,802,683 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\ltsm.sys
[2010/08/24 12:48:55 | 000,797,500 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltsmt.sys
[2010/08/24 12:48:53 | 000,576,746 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2010/08/24 12:48:53 | 000,420,992 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2010/08/24 12:48:52 | 000,727,786 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ltck000c.sys
[2010/08/24 12:48:52 | 000,606,684 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2010/08/24 12:48:50 | 000,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\loop.sys
[2010/08/24 12:48:48 | 000,070,730 | —- | C] (Linksys Group, Inc.) – C:\WINDOWS\System32\dllcache\lne100tx.sys
[2010/08/24 12:48:47 | 000,025,065 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\lmndis3.sys
[2010/08/24 12:48:47 | 000,020,573 | —- | C] (The Linksts Group ) – C:\WINDOWS\System32\dllcache\lne100.sys
[2010/08/24 12:48:46 | 000,015,744 | —- | C] (Litronic Industries) – C:\WINDOWS\System32\dllcache\lit220p.sys
[2010/08/24 12:48:43 | 000,026,442 | —- | C] (SMSC) – C:\WINDOWS\System32\dllcache\lanepic5.sys
[2010/08/24 12:48:43 | 000,019,016 | —- | C] (Kingston Technology Company ) – C:\WINDOWS\System32\dllcache\ktc111.sys
[2010/08/24 12:48:41 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kousd.dll
[2010/08/24 12:48:14 | 000,026,624 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\dllcache\irstusb.sys
[2010/08/24 12:48:14 | 000,018,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irsir.sys
[2010/08/24 12:48:12 | 000,023,552 | —- | C] (MKNet Corporation) – C:\WINDOWS\System32\dllcache\irmk7.sys
[2010/08/24 12:48:06 | 000,045,632 | —- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) – C:\WINDOWS\System32\dllcache\ip5515.sys
[2010/08/24 12:48:05 | 000,090,200 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8ports.dll
[2010/08/24 12:48:05 | 000,038,784 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8.sys
[2010/08/24 12:48:04 | 000,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ini910u.sys
[2010/08/24 12:48:04 | 000,013,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inport.sys
[2010/08/24 12:47:49 | 000,372,824 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\iconf32.dll
[2010/08/24 12:47:47 | 000,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5usb.sys
[2010/08/24 12:47:47 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5com.dll
[2010/08/24 12:47:47 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5ext.dll
[2010/08/24 12:47:46 | 000,154,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4usb.sys
[2010/08/24 12:47:46 | 000,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4com.dll
[2010/08/24 12:47:46 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4ext.dll
[2010/08/24 12:47:45 | 000,141,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3.sys
[2010/08/24 12:47:45 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3ext.dll
[2010/08/24 12:47:44 | 000,109,085 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtrp.sys
[2010/08/24 12:47:44 | 000,100,936 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtok.sys
[2010/08/24 12:47:44 | 000,038,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2010/08/24 12:47:43 | 000,028,700 | —- | C] (IBM Corp.) – C:\WINDOWS\System32\dllcache\ibmexmp.sys
[2010/08/24 12:47:43 | 000,009,216 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmsgnet.dll
[2010/08/24 12:47:41 | 000,161,020 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\i81xnt5.sys
[2010/08/24 12:47:40 | 000,353,184 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740dnt5.dll
[2010/08/24 12:47:40 | 000,058,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740nt5.sys
[2010/08/24 12:47:32 | 001,041,536 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfdpsp2.sys
[2010/08/24 12:47:30 | 000,685,056 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfcxts2.sys
[2010/08/24 12:47:28 | 000,488,383 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_v124.sys
[2010/08/24 12:47:28 | 000,220,032 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfbs2s2.sys
[2010/08/24 12:47:27 | 000,073,279 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_spkp.sys
[2010/08/24 12:47:27 | 000,050,751 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_tone.sys
[2010/08/24 12:47:27 | 000,044,863 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_soar.sys
[2010/08/24 12:47:26 | 000,542,879 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_msft.sys
[2010/08/24 12:47:26 | 000,391,199 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_k56k.sys
[2010/08/24 12:47:26 | 000,057,471 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_samp.sys
[2010/08/24 12:47:25 | 000,115,807 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fsks.sys
[2010/08/24 12:47:25 | 000,009,759 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_inst.dll
[2010/08/24 12:47:24 | 000,289,887 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fall.sys
[2010/08/24 12:47:24 | 000,199,711 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_faxx.sys
[2010/08/24 12:47:24 | 000,067,167 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_bsc2.sys
[2010/08/24 12:47:23 | 000,150,239 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_amos.sys
[2010/08/24 12:47:23 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hr1w.dll
[2010/08/24 12:47:22 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2010/08/24 12:47:22 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2010/08/24 12:47:22 | 000,005,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpt4qic.sys
[2010/08/24 12:47:21 | 000,068,608 | —- | C] (Avisioin) – C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2010/08/24 12:47:21 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2010/08/24 12:47:21 | 000,025,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpn.sys
[2010/08/24 12:47:20 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2010/08/24 12:47:19 | 000,126,976 | —- | C] (Hewlett Packard) – C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2010/08/24 12:47:19 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2010/08/24 12:47:18 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2010/08/24 12:47:17 | 000,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2010/08/24 12:47:15 | 000,002,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidswvd.sys
[2010/08/24 12:47:13 | 000,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidgame.sys
[2010/08/24 12:47:09 | 000,907,456 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hcf_msft.sys
[2010/08/24 12:47:06 | 000,082,304 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grclass.sys
[2010/08/24 12:47:06 | 000,017,408 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\gpr400.sys
[2010/08/24 12:47:02 | 001,733,120 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400d.dll
[2010/08/24 12:47:02 | 000,322,432 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400m.sys
[2010/08/24 12:47:01 | 000,470,144 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200d.dll
[2010/08/24 12:47:01 | 000,454,912 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fxusbase.sys
[2010/08/24 12:47:01 | 000,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200m.sys
[2010/08/24 12:46:49 | 000,455,296 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fusbbase.sys
[2010/08/24 12:46:49 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fuusd.dll
[2010/08/24 12:46:48 | 000,455,680 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fus2base.sys
[2010/08/24 12:46:45 | 000,442,240 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2010/08/24 12:46:45 | 000,441,728 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2010/08/24 12:46:44 | 000,444,416 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcibase.sys
[2010/08/24 12:46:42 | 000,034,173 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\forehe.sys
[2010/08/24 12:46:41 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fnfilter.dll
[2010/08/24 12:46:35 | 000,027,165 | —- | C] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\dllcache\fetnd5.sys
[2010/08/24 12:46:34 | 000,022,090 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\fem556n5.sys
[2010/08/24 12:44:46 | 000,024,618 | —- | C] (NETGEAR) – C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2010/08/24 12:44:46 | 000,016,074 | —- | C] (NETGEAR Corp.) – C:\WINDOWS\System32\dllcache\fa312nd5.sys
[2010/08/24 12:44:45 | 000,012,362 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2010/08/24 12:44:45 | 000,011,850 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2010/08/24 12:44:42 | 000,016,998 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ex10.sys
[2010/08/24 12:44:42 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exabyte2.sys
[2010/08/24 12:44:38 | 000,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunib.dll
[2010/08/24 12:44:38 | 000,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuni.dll
[2010/08/24 12:44:37 | 000,034,816 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimg.dll
[2010/08/24 12:44:36 | 000,137,088 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\essm2e.sys
[2010/08/24 12:44:36 | 000,043,008 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucm.dll
[2010/08/24 12:44:35 | 000,063,360 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\ess.sys
[2010/08/24 12:44:34 | 000,347,550 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56tpi.sys
[2010/08/24 12:44:33 | 000,595,647 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56cvmp.sys
[2010/08/24 12:44:33 | 000,594,238 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56hpi.sys
[2010/08/24 12:44:32 | 000,174,464 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es198x.sys
[2010/08/24 12:44:32 | 000,072,192 | —- | C] (ESS Technology Inc.) – C:\WINDOWS\System32\dllcache\es1969.sys
[2010/08/24 12:44:32 | 000,040,704 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1371mp.sys
[2010/08/24 12:44:31 | 000,061,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnloop.exe
[2010/08/24 12:44:31 | 000,051,200 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnlogr.exe
[2010/08/24 12:44:31 | 000,037,120 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1370mp.sys
[2010/08/24 12:44:30 | 000,629,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqn.sys
[2010/08/24 12:44:30 | 000,053,248 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqndiag.exe
[2010/08/24 12:44:29 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2010/08/24 12:44:29 | 000,114,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epstw2k.sys
[2010/08/24 12:44:29 | 000,018,503 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\epro4.sys
[2010/08/24 12:44:28 | 000,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\enum1394.sys
[2010/08/24 12:44:27 | 000,025,159 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\elnk3.sys
[2010/08/24 12:44:27 | 000,019,996 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\em556n4.sys
[2010/08/24 12:44:26 | 000,171,520 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el99xn51.sys
[2010/08/24 12:44:26 | 000,070,174 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el98xn5.sys
[2010/08/24 12:44:26 | 000,007,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\elmsmc.sys
[2010/08/24 12:44:25 | 000,455,199 | —- | C] (3Com Corporation.) – C:\WINDOWS\System32\dllcache\el985n51.sys
[2010/08/24 12:44:25 | 000,153,631 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xnd5.sys
[2010/08/24 12:44:24 | 000,241,206 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656se5.sys
[2010/08/24 12:44:24 | 000,066,591 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xbc5.sys
[2010/08/24 12:44:23 | 000,634,134 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656ct5.sys
[2010/08/24 12:44:23 | 000,077,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656nd5.sys
[2010/08/24 12:44:23 | 000,069,194 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656cd5.sys
[2010/08/24 12:44:22 | 000,069,692 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el575nd5.sys
[2010/08/24 12:44:22 | 000,026,141 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el589nd5.sys
[2010/08/24 12:44:21 | 000,055,999 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el556nd5.sys
[2010/08/24 12:44:21 | 000,024,653 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el574nd4.sys
[2010/08/24 12:44:20 | 000,044,103 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el515.sys
[2010/08/24 12:44:15 | 000,050,719 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e1000nt5.sys
[2010/08/24 12:44:15 | 000,019,594 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e100isa4.sys
[2010/08/24 12:44:10 | 000,334,208 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2010/08/24 12:44:09 | 000,020,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpti2o.sys
[2010/08/24 12:44:07 | 000,028,062 | —- | C] (National Semiconductor Coproration) – C:\WINDOWS\System32\dllcache\dp83820.sys
[2010/08/24 12:44:07 | 000,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2010/08/24 12:44:07 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2010/08/24 12:44:06 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2010/08/24 12:44:02 | 000,029,696 | —- | C] (CNet Technology, Inc. ) – C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2010/08/24 12:44:01 | 000,026,698 | —- | C] (D-Link Corporation) – C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2010/08/24 12:44:00 | 000,952,007 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diwan.sys
[2010/08/24 12:43:59 | 000,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2010/08/24 12:43:59 | 000,038,985 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvsu.dll
[2010/08/24 12:43:58 | 000,031,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvpp.dll
[2010/08/24 12:43:58 | 000,006,729 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvci.dll
[2010/08/24 12:43:56 | 000,091,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\dimaint.sys
[2010/08/24 12:43:55 | 000,614,429 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiview.exe
[2010/08/24 12:43:55 | 000,110,621 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.dll
[2010/08/24 12:43:55 | 000,042,432 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.sys
[2010/08/24 12:43:54 | 000,102,484 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiinf.dll
[2010/08/24 12:43:54 | 000,041,046 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.dll
[2010/08/24 12:43:54 | 000,021,606 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.sys
[2010/08/24 12:43:53 | 000,229,462 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifwrk.dll
[2010/08/24 12:43:53 | 000,159,828 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digihlc.dll
[2010/08/24 12:43:53 | 000,090,525 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifep5.sys
[2010/08/24 12:43:52 | 000,131,156 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidbp.dll
[2010/08/24 12:43:52 | 000,103,044 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidxb.sys
[2010/08/24 12:43:52 | 000,037,735 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.sys
[2010/08/24 12:43:51 | 000,065,622 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.dll
[2010/08/24 12:43:49 | 000,419,357 | —- | C] (Digi International) – C:\WINDOWS\System32\dllcache\dgconfig.dll
[2010/08/24 12:43:49 | 000,029,531 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\dgapci.sys
[2010/08/24 12:43:48 | 000,024,649 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650d.sys
[2010/08/24 12:43:47 | 000,024,648 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650.sys
[2010/08/24 12:43:46 | 000,020,928 | —- | C] (Digital Networks, LLC) – C:\WINDOWS\System32\dllcache\defpa.sys
[2010/08/24 12:43:45 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddsmc.sys
[2010/08/24 12:43:44 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc260usd.dll
[2010/08/24 12:43:44 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc240usd.dll
[2010/08/24 12:43:44 | 000,063,208 | —- | C] (Intel Corporation.) – C:\WINDOWS\System32\dllcache\dc21x4.sys
[2010/08/24 12:43:43 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210usd.dll
[2010/08/24 12:43:43 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210_32.dll
[2010/08/24 12:43:40 | 000,179,584 | —- | C] (Mylex Corporation) – C:\WINDOWS\System32\dllcache\dac2w2k.sys
[2010/08/24 12:43:40 | 000,014,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dac960nt.sys
[2010/08/24 12:43:38 | 000,117,760 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\d100ib5.sys
[2010/08/24 12:43:38 | 000,049,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzport.sys
[2010/08/24 12:43:38 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzports.dll
[2010/08/24 12:43:37 | 000,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyport.sys
[2010/08/24 12:43:37 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyports.dll
[2010/08/24 12:43:37 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzcoins.dll
[2010/08/24 12:43:36 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyycoins.dll
[2010/08/24 12:43:36 | 000,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclad-z.sys
[2010/08/24 12:43:36 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclom-y.sys
[2010/08/24 12:43:35 | 000,093,952 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2010/08/24 12:43:35 | 000,048,640 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2010/08/24 12:43:34 | 000,111,872 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcspud.sys
[2010/08/24 12:43:34 | 000,072,832 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2010/08/24 12:43:34 | 000,003,584 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2010/08/24 12:43:33 | 000,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2010/08/24 12:43:33 | 000,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbase.sys
[2010/08/24 12:43:32 | 000,096,256 | —- | C] (Copyright © Creative Technology Ltd. 1994-2001) – C:\WINDOWS\System32\dllcache\ctlsb16.sys
[2010/08/24 12:43:30 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\csamsp.dll
[2010/08/24 12:43:30 | 000,042,112 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\crtaud.sys
[2010/08/24 12:43:29 | 000,216,064 | —- | C] (COMPAQ Inc.) – C:\WINDOWS\System32\dllcache\cpscan.dll
[2010/08/24 12:43:28 | 000,060,970 | —- | C] (Compaq Computer Corp.) – C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2010/08/24 12:43:28 | 000,021,533 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2010/08/24 12:43:28 | 000,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cpqarray.sys
[2010/08/24 12:43:21 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnusd.dll
[2010/08/24 12:43:21 | 000,039,936 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\cnxt1803.sys
[2010/08/24 12:43:19 | 000,020,736 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2010/08/24 12:43:19 | 000,006,656 | —- | C] (CMD Technology, Inc.) – C:\WINDOWS\System32\dllcache\cmdide.sys
[2010/08/24 12:43:16 | 000,248,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546xm.sys
[2010/08/24 12:43:16 | 000,170,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546x.dll
[2010/08/24 12:43:15 | 000,111,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl5465.dll
[2010/08/24 12:43:15 | 000,045,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.sys
[2010/08/24 12:43:14 | 000,091,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.dll
[2010/08/24 12:43:13 | 000,272,640 | —- | C] (RAVISENT Technologies Inc.) – C:\WINDOWS\System32\dllcache\cinemclc.sys
[2010/08/24 12:43:12 | 000,980,034 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\cicap.sys
[2010/08/24 12:43:06 | 000,049,182 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem56n5.sys
[2010/08/24 12:43:06 | 000,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem33n5.sys
[2010/08/24 12:43:05 | 000,027,164 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce3n5.sys
[2010/08/24 12:43:05 | 000,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem28n5.sys
[2010/08/24 12:43:05 | 000,021,530 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce2n5.sys
[2010/08/24 12:43:03 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cd20xrnt.sys
[2010/08/24 12:43:02 | 000,714,698 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2010/08/24 12:43:02 | 000,046,108 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cben5.sys
[2010/08/24 12:43:01 | 000,039,680 | —- | C] (Silicom Ltd.) – C:\WINDOWS\System32\dllcache\cb325.sys
[2010/08/24 12:43:01 | 000,037,916 | —- | C] (Fast Ethernet Controller Provider) – C:\WINDOWS\System32\dllcache\cb102.sys
[2010/08/24 12:42:59 | 000,164,923 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diapi2.sys
[2010/08/24 12:42:59 | 000,032,256 | —- | C] (Eicon Technology Corporation) – C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2010/08/24 12:42:58 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.ax
[2010/08/24 12:42:57 | 000,244,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.ax
[2010/08/24 12:42:57 | 000,236,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.dll
[2010/08/24 12:42:57 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.dll
[2010/08/24 12:42:56 | 000,171,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv30.sys
[2010/08/24 12:42:56 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.ax
[2010/08/24 12:42:55 | 000,314,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdro21.sys
[2010/08/24 12:42:55 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv21.sys
[2010/08/24 12:42:31 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2010/08/24 12:42:27 | 000,031,529 | —- | C] (BreezeCOM) – C:\WINDOWS\System32\dllcache\brzwlan.sys
[2010/08/24 12:42:27 | 000,011,008 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2010/08/24 12:42:27 | 000,010,368 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbscn.sys
[2010/08/24 12:42:26 | 000,060,416 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brserwdm.sys
[2010/08/24 12:42:26 | 000,009,728 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brserif.dll
[2010/08/24 12:42:26 | 000,005,120 | —- | C] (Brother Industries,Ltd.) – C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2010/08/24 12:42:25 | 000,039,552 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparwdm.sys
[2010/08/24 12:42:25 | 000,003,168 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparimg.sys
[2010/08/24 12:42:23 | 000,041,472 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfusb.dll
[2010/08/24 12:42:22 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2010/08/24 12:42:22 | 000,032,256 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2010/08/24 12:42:22 | 000,029,696 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmflpt.dll
[2010/08/24 12:42:21 | 000,015,360 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2010/08/24 12:42:21 | 000,003,968 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltup.sys
[2010/08/24 12:42:20 | 000,012,800 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brevif.dll
[2010/08/24 12:42:20 | 000,012,160 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2010/08/24 12:42:20 | 000,002,944 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brfilt.sys
[2010/08/24 12:42:19 | 000,019,456 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brbidiif.dll
[2010/08/24 12:42:19 | 000,009,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brcoinst.dll
[2010/08/24 12:42:18 | 000,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\binlsvc.dll
[2010/08/24 12:42:16 | 000,871,388 | —- | C] (BCM) – C:\WINDOWS\System32\dllcache\bcmdm.sys
[2010/08/24 12:42:16 | 000,026,568 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm4e5.sys
[2010/08/24 12:42:15 | 000,066,557 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42u.sys
[2010/08/24 12:42:15 | 000,054,271 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42xx5.sys
[2010/08/24 12:42:13 | 000,342,336 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.dll
[2010/08/24 12:42:13 | 000,096,640 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\b57xp32.sys
[2010/08/24 12:42:13 | 000,036,128 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.sys
[2010/08/24 12:42:12 | 000,089,952 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\b1cbase.sys
[2010/08/24 12:42:12 | 000,036,992 | —- | C] (Aztech Systems Ltd) – C:\WINDOWS\System32\dllcache\aztw2320.sys
[2010/08/24 12:42:11 | 000,144,384 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmenum.dll
[2010/08/24 12:42:11 | 000,087,552 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2010/08/24 12:42:11 | 000,037,568 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmwan.sys
[2010/08/24 12:42:09 | 000,036,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcaudio.sys
[2010/08/24 12:41:53 | 000,104,832 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiraged.dll
[2010/08/24 12:41:53 | 000,070,528 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiragem.sys
[2010/08/24 12:41:52 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinxsxx.sys
[2010/08/24 12:41:50 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinxbxx.sys
[2010/08/24 12:41:49 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atintuxx.sys
[2010/08/24 12:41:49 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinttxx.sys
[2010/08/24 12:41:48 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinsnxx.sys
[2010/08/24 12:41:46 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinrvxx.sys
[2010/08/24 12:41:46 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinraxx.sys
[2010/08/24 12:41:45 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinpdxx.sys
[2010/08/24 12:41:45 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinmdxx.sys
[2010/08/24 12:41:44 | 000,281,600 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimtai.sys
[2010/08/24 12:41:44 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinbtxx.sys
[2010/08/24 12:41:43 | 000,289,664 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpab.sys
[2010/08/24 12:41:43 | 000,075,136 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpae.sys
[2010/08/24 12:41:43 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atievxx.exe
[2010/08/24 12:41:42 | 000,268,160 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidvai.dll
[2010/08/24 12:41:42 | 000,137,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrae.dll
[2010/08/24 12:41:41 | 000,382,592 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrab.dll
[2010/08/24 12:41:38 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati2mtag.sys
[2010/08/24 12:41:37 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati2mtaa.sys
[2010/08/24 12:41:35 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xsxx.sys
[2010/08/24 12:41:34 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xbxx.sys
[2010/08/24 12:41:33 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1tuxx.sys
[2010/08/24 12:41:32 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1snxx.sys
[2010/08/24 12:41:32 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1ttxx.sys
[2010/08/24 12:41:31 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1rvxx.sys
[2010/08/24 12:41:30 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1raxx.sys
[2010/08/24 12:41:30 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1pdxx.sys
[2010/08/24 12:41:29 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1mdxx.sys
[2010/08/24 12:41:28 | 000,077,568 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ati.sys
[2010/08/24 12:41:28 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1btxx.sys
[2010/08/24 12:41:27 | 000,096,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ati.dll
[2010/08/24 12:41:26 | 000,097,354 | —- | C] (Bay Networks, Inc.) – C:\WINDOWS\System32\dllcache\aspndis3.sys
[2010/08/24 12:41:25 | 000,014,848 | —- | C] (Advanced System Products, Inc.) – C:\WINDOWS\System32\dllcache\asc3550.sys
[2010/08/24 12:41:24 | 000,026,496 | —- | C] (Advanced System Products, Inc.) – C:\WINDOWS\System32\dllcache\asc.sys
[2010/08/24 12:41:24 | 000,022,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asc3350p.sys
[2010/08/24 12:40:44 | 000,006,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\apmbatt.sys
[2010/08/24 12:40:43 | 000,036,224 | —- | C] (ADMtek Incorporated.) – C:\WINDOWS\System32\dllcache\an983.sys
[2010/08/24 12:40:43 | 000,012,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\amsint.sys
[2010/08/24 12:40:41 | 000,016,969 | —- | C] (AmbiCom, Inc.) – C:\WINDOWS\System32\dllcache\amb8002.sys
[2010/08/24 12:40:40 | 000,005,248 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\aliide.sys
[2010/08/24 12:40:39 | 000,056,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78xx.sys
[2010/08/24 12:40:39 | 000,027,678 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ali5261.sys
[2010/08/24 12:40:39 | 000,026,624 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\alifir.sys
[2010/08/24 12:40:38 | 000,055,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78u2.sys
[2010/08/24 12:40:38 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aha154x.sys
[2010/08/24 12:40:27 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2010/08/24 12:39:00 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adpu160m.sys
[2010/08/24 12:38:59 | 000,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2010/08/24 12:38:58 | 000,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2010/08/24 12:38:53 | 000,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2010/08/24 12:38:53 | 000,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2010/08/24 12:38:52 | 000,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2010/08/24 12:38:52 | 000,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2010/08/24 12:38:52 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2010/08/24 12:38:51 | 000,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2010/08/24 12:38:49 | 000,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2010/08/24 12:38:49 | 000,096,256 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ac97intc.sys
[2010/08/24 12:38:49 | 000,084,480 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ac97via.sys
[2010/08/24 12:38:48 | 000,231,552 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ac97ali.sys
[2010/08/24 12:38:47 | 000,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2010/08/24 12:38:47 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\abp480n5.sys
[2010/08/24 12:38:46 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2010/08/24 12:38:44 | 000,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2010/08/24 12:38:44 | 000,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2010/08/24 12:38:43 | 000,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2010/08/24 12:38:43 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2010/08/24 12:38:23 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2010/08/24 08:51:53 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Hiram\IETldCache
[2010/08/24 08:22:51 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2010/08/24 08:22:22 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/24 08:20:32 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/08/24 07:55:18 | 000,000,000 | —D | C] – C:\Program Files\CleanUp!
[2010/08/24 02:02:46 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/08/24 01:55:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\My Documents\MANONIGHT COMPUTERS
[2010/08/24 01:30:37 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/08/24 01:30:37 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/08/24 01:30:37 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/08/24 01:30:37 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/08/23 23:37:03 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/08/21 18:15:05 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/08/20 00:14:25 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/08/19 23:18:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Update
[2010/08/17 00:00:12 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/08/16 08:35:47 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/08/16 08:08:59 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/08/16 00:27:47 | 000,327,472 | —- | C] (BitTorrent, Inc.) – C:\Documents and Settings\Hiram\Desktop\utorrent.exe
[2010/08/10 05:15:58 | 000,094,208 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2002/04/11 12:41:06 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/01 09:57:01 | 064,153,839 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/09/01 09:53:15 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Hiram\Desktop\OTL.exe
[2010/09/01 09:50:20 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/09/01 09:50:18 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/01 09:50:13 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/01 09:50:11 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/01 09:47:30 | 011,534,336 | —- | M] () – C:\Documents and Settings\Hiram\ntuser.dat
[2010/09/01 00:18:28 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Hiram\ntuser.ini
[2010/08/31 23:36:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/31 23:20:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-796845957-861567501-1801674531-1003UA.job
[2010/08/31 20:05:33 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/31 17:00:00 | 000,000,390 | —- | M] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2010/08/31 11:58:47 | 000,002,447 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\HiJackThis.lnk
[2010/08/31 11:20:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-796845957-861567501-1801674531-1003Core.job
[2010/08/30 22:33:32 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/30 22:30:22 | 000,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/08/30 22:30:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/30 13:45:12 | 367,120,172 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\White.Collar.S02E07.Prisoners.Dilemma.HDTV.XviD-FQM.avi
[2010/08/29 23:29:05 | 000,204,288 | —- | M] () – C:\Documents and Settings\Hiram\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/29 15:41:10 | 1172,612,850 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\Monster.Inc.2001.m-HD.x264.mkv
[2010/08/29 12:02:12 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/29 10:58:25 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/29 10:57:11 | 000,000,372 | —- | M] () – C:\WINDOWS\tasks\RegCure.job
[2010/08/29 02:23:27 | 000,000,763 | —- | M] () – C:\Documents and Settings\All Users\Desktop\State.lnk
[2010/08/27 23:22:45 | 000,000,738 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RegCure.lnk
[2010/08/27 00:43:52 | 000,144,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/26 22:42:26 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/26 22:40:46 | 000,488,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/26 22:40:46 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/26 22:40:46 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/26 22:22:21 | 000,000,603 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/26 22:08:41 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/08/26 22:08:40 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/08/26 22:08:38 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/08/26 22:08:27 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/08/26 22:08:27 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/08/26 22:08:24 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/08/26 20:35:03 | 000,031,256 | —- | M] () – C:\Documents and Settings\Hiram\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/08/26 20:33:16 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010/08/26 20:30:16 | 002,164,092 | —- | M] () – C:\WINDOWS\iis6.BAK
[2010/08/26 19:14:58 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/26 11:14:42 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/08/25 17:29:24 | 000,416,183 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/24 21:06:34 | 000,153,376 | —- | M] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/08/24 21:06:34 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/08/24 21:06:33 | 000,423,656 | —- | M] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/24 21:06:33 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/08/24 21:06:33 | 000,073,728 | —- | M] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/08/24 18:42:22 | 000,000,292 | RHS- | M] () – C:\boot.ini
[2010/08/24 18:42:22 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/24 08:51:46 | 000,000,815 | —- | M] () – C:\Documents and Settings\Hiram\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/24 02:19:07 | 000,416,119 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100825-172924.backup
[2010/08/24 01:45:58 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100824-021907.backup
[2010/08/20 15:56:03 | 000,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/20 12:35:23 | 000,000,005 | —- | M] () – C:\zrpt.xml
[2010/08/17 12:39:46 | 000,019,979 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\MyTeamLogo.jpg
[2010/08/17 12:33:53 | 000,251,359 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\Philadelphia_Eagles(1).jpg
[2010/08/17 01:04:48 | 000,000,501 | —- | M] () – C:\Documents and Settings\Hiram\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to mplayerc.exe.lnk
[2010/08/17 00:00:19 | 000,000,630 | —- | M] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/08/16 23:45:56 | 000,002,483 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\Microsoft Word.lnk
[2010/08/16 00:27:48 | 000,327,472 | —- | M] (BitTorrent, Inc.) – C:\Documents and Settings\Hiram\Desktop\utorrent.exe
[2010/08/10 05:15:58 | 000,094,208 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/30 22:33:32 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/30 22:30:22 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/08/30 13:38:20 | 367,120,172 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\White.Collar.S02E07.Prisoners.Dilemma.HDTV.XviD-FQM.avi
[2010/08/29 14:46:58 | 1172,612,850 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\Monster.Inc.2001.m-HD.x264.mkv
[2010/08/29 02:23:27 | 000,000,763 | —- | C] () – C:\Documents and Settings\All Users\Desktop\State.lnk
[2010/08/27 23:23:20 | 000,000,390 | —- | C] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2010/08/27 23:23:20 | 000,000,372 | —- | C] () – C:\WINDOWS\tasks\RegCure.job
[2010/08/27 23:22:45 | 000,000,738 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RegCure.lnk
[2010/08/27 17:37:30 | 000,002,447 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\HiJackThis.lnk
[2010/08/26 22:08:41 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/08/26 22:08:24 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/08/26 22:08:17 | 064,153,839 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/08/26 19:15:22 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2010/08/26 19:15:21 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2010/08/26 19:15:20 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2010/08/26 17:34:46 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/08/24 13:07:50 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2010/08/24 12:47:20 | 000,165,888 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt53.dll
[2010/08/24 12:47:20 | 000,093,696 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt42.dll
[2010/08/24 12:47:19 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt34.dll
[2010/08/24 12:47:18 | 000,089,088 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt33.dll
[2010/08/24 12:47:18 | 000,083,968 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt21.dll
[2010/08/24 12:44:00 | 000,037,962 | —- | C] () – C:\WINDOWS\System32\dllcache\divaprop.dll
[2010/08/24 12:44:00 | 000,029,768 | —- | C] () – C:\WINDOWS\System32\dllcache\divasu.dll
[2010/08/24 12:43:59 | 000,006,216 | —- | C] () – C:\WINDOWS\System32\dllcache\divaci.dll
[2010/08/24 12:42:00 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\dllcache\ativxbar.sys
[2010/08/24 12:42:00 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\dllcache\atixbar.sys
[2010/08/24 12:41:58 | 000,019,456 | —- | C] () – C:\WINDOWS\System32\dllcache\ativttxx.sys
[2010/08/24 12:41:55 | 000,009,472 | —- | C] () – C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2010/08/24 12:41:54 | 000,026,880 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2010/08/24 12:41:54 | 000,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2010/08/24 12:41:54 | 000,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitunep.sys
[2010/08/24 12:41:53 | 000,049,920 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtcap.sys
[2010/08/24 12:41:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2010/08/24 12:41:41 | 000,046,464 | —- | C] () – C:\WINDOWS\System32\dllcache\atibt829.sys
[2010/08/24 07:56:14 | 000,067,993 | —- | C] () – C:\Documents and Settings\Hiram\Application Data\CleanUp!.log
[2010/08/24 01:30:37 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/08/24 01:30:37 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/08/24 01:30:37 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/08/24 01:30:37 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/08/24 01:30:37 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/08/21 01:15:49 | 011,534,336 | —- | C] () – C:\Documents and Settings\Hiram\ntuser.dat
[2010/08/20 15:56:03 | 000,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/20 12:35:23 | 000,000,005 | —- | C] () – C:\zrpt.xml
[2010/08/17 12:39:45 | 000,019,979 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\MyTeamLogo.jpg
[2010/08/17 12:33:53 | 000,251,359 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\Philadelphia_Eagles(1).jpg
[2010/08/17 01:04:48 | 000,000,501 | —- | C] () – C:\Documents and Settings\Hiram\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to mplayerc.exe.lnk
[2010/08/17 00:00:19 | 000,000,630 | —- | C] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/05/15 22:00:59 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/01/13 17:38:19 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/01/13 17:36:40 | 000,000,084 | —- | C] () – C:\WINDOWS\EPSPRX595.ini
[2008/12/28 02:31:43 | 000,000,028 | —- | C] () – C:\WINDOWS\System32\WFD_List.ini
[2008/12/28 01:30:08 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2008/12/23 05:05:15 | 000,000,011 | —- | C] () – C:\WINDOWS\OSA.INI
[2008/12/19 06:57:18 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/12/19 06:57:18 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/12/17 02:39:57 | 000,000,002 | —- | C] () – C:\WINDOWS\System32\Dvbpws.dll
[2008/12/10 04:15:55 | 003,086,336 | —- | C] () – C:\WINDOWS\System32\NCMedia.dll
[2008/12/10 04:15:55 | 003,086,336 | —- | C] () – C:\WINDOWS\System32\flvvideo.dll
[2008/12/10 04:15:55 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/12/10 04:15:55 | 000,383,238 | —- | C] () – C:\WINDOWS\System32\libmp3lame-0.dll
[2008/12/02 01:31:40 | 000,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2008/06/26 18:38:21 | 000,001,659 | —- | C] () – C:\WINDOWS\tefview.ini
[2008/05/31 17:59:12 | 000,038,999 | —- | C] () – C:\Documents and Settings\Hiram\Application Data\Microsoft Access.ADR
[2008/05/29 18:59:21 | 000,002,528 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2008/05/29 18:50:46 | 000,002,528 | —- | C] () – C:\Documents and Settings\Hiram\Application Data\$_hpcst$.hpc
[2007/10/17 02:52:20 | 000,002,917 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/18 05:51:41 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/09/12 04:53:27 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS5y.DLL
[2007/09/04 20:48:33 | 000,204,288 | —- | C] () – C:\Documents and Settings\Hiram\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/09/04 19:30:16 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/09/04 19:19:37 | 000,005,663 | —- | C] () – C:\WINDOWS\System32\Ludap17.ini
[2007/09/04 19:19:37 | 000,000,075 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/09/04 19:18:04 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2007/09/04 19:06:40 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2005/05/03 21:38:42 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\P17.DLL
[2004/10/05 17:37:20 | 000,258,048 | —- | C] () – C:\WINDOWS\System32\Manipulate.dll
[2003/10/02 21:48:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2003/08/07 14:01:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2002/03/21 16:39:02 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\UNACEV2.DLL

========== LOP Check ==========

[2007/09/05 21:43:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2008/02/25 01:10:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Austhink Software
[2010/08/26 22:04:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/12/18 05:19:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/09/08 21:59:38 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/09/16 23:28:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2009/09/08 22:09:43 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2010/09/01 09:50:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2010/08/17 12:18:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2007/11/12 19:25:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ExtendMedia
[2010/08/27 23:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2008/08/21 02:45:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/09/04 19:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/08/20 15:18:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Update
[2010/08/30 22:30:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/02/12 21:19:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/26 22:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/08/21 02:49:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{E0FD8DB4-0B1B-427B-B11A-E920A60A344E}
[2009/08/20 19:26:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\.anki
[2010/08/29 02:25:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Acapela Group
[2007/09/12 23:10:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\acccore
[2007/09/05 21:43:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\ACD Systems
[2008/02/25 01:11:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Austhink Software
[2010/08/24 07:58:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Azureus
[2009/03/27 22:27:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Conceptworld
[2009/01/13 18:47:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\EPSON
[2009/01/13 17:56:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Leadertech
[2007/12/16 03:45:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\MyPhoneExplorer
[2008/08/21 02:49:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Seven Zip
[2009/07/31 14:30:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\SystemRequirementsLab
[2007/12/16 03:29:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Teleca
[2010/08/30 17:48:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\uTorrent
[2010/08/30 13:03:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\VirtualStore
[2010/08/29 02:25:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Xtranormal
[2010/09/01 09:50:20 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
[2010/08/31 17:00:00 | 000,000,390 | —- | M] () – C:\WINDOWS\Tasks\RegCure Program Check.job
[2010/08/29 10:57:11 | 000,000,372 | —- | M] () – C:\WINDOWS\Tasks\RegCure.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/05/31 16:53:10 | 000,023,216 | —- | M] () – C:\ASLog.txt
[2007/09/04 18:58:56 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/24 18:42:22 | 000,000,292 | RHS- | M] () – C:\boot.ini
[2004/08/04 01:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2007/09/04 18:58:56 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/22 14:13:15 | 000,000,808 | —- | M] () – C:\config.txt
[2009/08/11 14:36:57 | 000,000,000 | —- | M] () – C:\DTSHDSpOut.txt
[2009/06/09 15:39:25 | 000,000,289 | —- | M] () – C:\FileCheck.txt
[2007/09/04 18:58:56 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/09/12 23:14:56 | 000,001,572 | -H– | M] () – C:\IPH.PH
[2007/09/04 18:58:56 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/08/22 14:09:19 | 000,004,579 | —- | M] () – C:\netsh-resetlog.txt
[2008/05/20 22:10:26 | 000,003,325 | —- | M] () – C:\NoLop.log
[2004/08/04 00:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/26 19:14:58 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/01 09:50:08 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2008/05/20 21:40:17 | 068,328,262 | —- | M] () – C:\SYM_REGISTRY_BACKUP.reg
[2010/08/20 12:35:23 | 000,000,005 | —- | M] () – C:\zrpt.xml

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2007/09/04 18:58:35 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/04/23 00:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD5y.DLL
[2008/05/20 00:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD99.DLL
[2004/04/23 00:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP5y.DLL
[2008/05/20 00:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP99.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2007/09/04 11:45:49 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/09/04 11:45:49 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/09/04 11:45:49 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/26 19:20:07 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/09/04 19:04:05 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Hiram\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/09/07 18:37:17 | 000,000,101 | —- | M] () – C:\Documents and Settings\Hiram\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/03/20 17:37:00 | 005,689,344 | —- | M] (Gabest) – C:\Documents and Settings\Hiram\Desktop\mplayerc.exe
[2010/09/01 09:53:15 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Hiram\Desktop\OTL.exe
[2010/08/16 00:27:48 | 000,327,472 | —- | M] (BitTorrent, Inc.) – C:\Documents and Settings\Hiram\Desktop\utorrent.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-27 03:42:38

========== Alternate Data Streams ==========

@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4BF2F6B5
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
< End of report >




OTL Extras logfile created on: 9/1/2010 9:54:43 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Hiram\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 307.00 Mb Available Physical Memory | 30.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.60 Gb Total Space | 175.70 Gb Free Space | 47.15% Space Free | Partition Type: NTFS
Drive D: | 36.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SATURN
Current User Name: Hiram
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\Program Files\ACD Systems\ACDSee\8.0.Pro\ACDSee8Pro.exe" "%1" (ACD Systems Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0D6D96F4-0CAF-4522-B05F-70A88EDECDFD}" = ArcSoft Print Creations
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3600_series" = Canon iP3600 series Printer Driver
"{1696C54E-599A-4BA2-9941-BB70C4727887}" = Xtranormal State - Voicepack-English-UK-Daniel
"{1771FDC8-D846-4B77-996A-C80DAD42C03F}" = OpenCASE Media Agent
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{232FDC0C-12DE-41F2-9701-27EFCA18BEF9}" = MediaJoin
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{32A3A4F4-B792-11D6-A78A-00B0D0160140}" = Java™ SE Development Kit 6 Update 14
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{467A3BF8-4C87-4E68-835C-CE5318C157C2}" = Xtranormal State - Voicepack-English-US-Tom
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{838A22DF-81CA-4452-9BDD-A1745224D960}" = Xtranormal State - Voicepack-English-UK-Serena
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{863641E8-E9B2-49DF-A096-538DF33D0442}" = ConceptDraw MINDMAP Professional
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8D2C1E44-7685-4D05-8342-B0DC6422FA47}" = Ulead Straight-to-Disc SDK
"{8EC4F64D-92E4-4274-9495-4C887D49DEC3}" = Xtranormal State
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{912536C4-273C-416F-B42C-BBC5B72114D7}" = Xtranormal State - Voicepack-English-US-Samantha
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{926C96FB-9D0A-4504-8000-C6D3A4A3118E}" = Java DB 10.4.2.1
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5C314F7-928B-44E3-A8A3-169648B1077D}" = Xtranormal State - SoundPack-Starter Kit
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C93369CB-B4E9-E095-9289-E6B5AE941033}" = Nero 7 Demo
"{CD22E980-3E4F-11DF-B0D7-005056806466}" = Google Earth Plug-in
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03E7B00-CA85-4684-9321-1888873C34BD}" = ArcSoft PhotoImpression 6
"{D28CB048-A0AB-4F98-909F-69F3F25AA87D}" = Xtranormal State - Showpak-Playgoz-Preview
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{F99F74B4-972B-4B06-B893-6B3B0DB0128B}" = ACDSee Pro
"{FC053571-8507-44E4-8B6D-AACEAB8CA57C}" = Sansa Media Converter
"Absolute MP3 Splitter_is1" = Absolute MP3 Splitter version 2.7.3
"Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AIM_6" = AIM 6
"AP Tuner 3.08" = AP Tuner 3.08
"AVG9Uninstall" = AVG Free 9.0
"AVI MPEG RM WMV Splitter_is1" = AVI/MPEG/RM/WMV Splitter 4.28
"BatchPhoto_is1" = BatchPhoto v2.3.1
"Canon iP3600 series User Registration" = Canon iP3600 series User Registration
"CANONIJPLM100" = Inkjet Printer/Scanner Extended Survey Program
"CanonMyPrinter" = Canon Utilities My Printer
"CleanUp!" = CleanUp!
"COMODO Internet Security" = COMODO Internet Security
"Device Control" = Device Control
"DjVu" = Lizardtech DjVu Control (autoinstall)
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"EAXSet" = Creative EAX Settings
"FLV Player" = FLV Player 2.0, build 23
"Free FLV to AVI Converter_is1" = Free FLV to AVI Converter V1.5
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"Free Studio_is1" = Free Studio version 4.1
"Free YouTube to Mp3 Converter_is1" = Free YouTube to Mp3 Converter version 3.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Java Web Start" = Java Web Start
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.3.4 (Standard)
"Magic ISO Maker v5.5 (build 0273)" = Magic ISO Maker v5.5 (build 0273)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaJoin" = MediaJoin
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MPE" = MyPhoneExplorer
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NoteZilla_is1" = NoteZilla 7.0
"Picasa2" = Picasa 2
"PowerISO" = PowerISO
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"RegCure" = RegCure
"SPEAKER" = Creative Speaker Settings
"SystemRequirementsLab" = System Requirements Lab
"TEFView_is1" = TEFView 2.65
"The Rosetta Stone" = The Rosetta Stone
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.17
"VLC media player" = VLC media player 0.9.6
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/31/2010 2:52:39 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1953

Error - 8/31/2010 2:52:41 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/31/2010 2:52:41 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3938

Error - 8/31/2010 2:52:41 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3938

Error - 8/31/2010 9:29:02 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/31/2010 9:29:02 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 23785031

Error - 8/31/2010 9:29:02 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 23785031

Error - 9/1/2010 10:50:20 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: Received from 192.168.0.101:49152 4 Saturn.local.
Addr 192.168.0.101

Error - 9/1/2010 10:50:20 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: ProbeCount 2; will rename 4 saturn.local.
Addr 192.168.0.100

Error - 9/1/2010 10:50:20 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Local Hostname saturn.local already in use; will try saturn-2.local
instead

[ System Events ]
Error - 9/1/2010 1:20:53 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31

Error - 9/1/2010 1:20:53 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7001
Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 9/1/2010 1:20:53 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7001
Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 9/1/2010 1:20:53 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 9/1/2010 1:20:53 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD AvgLdx86 AvgMfx86 AvgTdiX cmdGuard cmdHlp Fips intelppm IPSec MRxSmb NetBIOS NetBT OMCI
RasAcd
Rdbss
SASDIFSV
SASKUTIL
SCDEmu
Tcpip

Error - 9/1/2010 10:45:02 AM | Computer Name = SATURN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 9/1/2010 10:50:31 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM Video Capture service failed to start due
to the following error: %%1058

Error - 9/1/2010 10:50:31 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126

Error - 9/1/2010 10:50:31 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM TVTuner service failed to start due to the
following error: %%1058

Error - 9/1/2010 10:50:31 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM Crossbar service failed to start due to
the following error: %%1058


< End of report >
Hi icecold,

C:\Documents and Settings\Hiram\Desktop\RegCure 3.0.2 Software + Crack
We do not support the use of cracked programs. See the following link

http://forums.whatthetech.com/index.php?showtopic=92526


Please click your start button > Control Panel > Add/Remove Programs and Uninstall

RegCure


Once you have finished the uninstall please rerun OTL with the following settings.

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the Extra Registry box change it to All
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Thanks
OTL logfile created on: 9/2/2010 12:24:36 AM - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Hiram\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 346.00 Mb Available Physical Memory | 34.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.60 Gb Total Space | 175.55 Gb Free Space | 47.11% Space Free | Partition Type: NTFS
Drive D: | 36.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SATURN
Current User Name: Hiram
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Hiram\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Hiram\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe (ExtendMedia Inc.)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Hiram\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (OpenCASE Media Agent) – C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe (ExtendMedia Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (InCDRm) – C:\WINDOWS\System32\drivers\InCDRm.sys File not found
DRV - (InCDPass) – C:\WINDOWS\System32\drivers\InCDPass.sys File not found
DRV - (InCDFs) – C:\WINDOWS\System32\drivers\InCDFs.sys File not found
DRV - (EraserUtilDrv10821) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10821.sys File not found
DRV - (catchme) – C:\DOCUME~1\Hiram\LOCALS~1\Temp\catchme.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdguard.sys (COMODO)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (w600obex) – C:\WINDOWS\system32\drivers\w600obex.sys (MCCI)
DRV - (w600mgmt) – C:\WINDOWS\system32\drivers\w600mgmt.sys (MCCI)
DRV - (w600mdm) – C:\WINDOWS\system32\drivers\w600mdm.sys (MCCI)
DRV - (w600mdfl) – C:\WINDOWS\system32\drivers\w600mdfl.sys (MCCI)
DRV - (w600bus) Sony Ericsson W600 driver (WDM) – C:\WINDOWS\system32\drivers\w600bus.sys (MCCI)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (WFIOCTL) – C:\Program Files\WinFast\WFTVFM\WFIOCTL.sys (Leadtek Research Inc.)
DRV - (ULCDRHlp) – C:\WINDOWS\system32\drivers\ULCDRHlp.sys (Ulead Systems, Inc.)
DRV - (tv2ktunr) – C:\WINDOWS\system32\drivers\wf2ktunr.sys (Leadtek Research Inc.)
DRV - (Tv2kXbar) – C:\WINDOWS\system32\drivers\wf2kXbar.sys (Leadtek Research Inc.)
DRV - (BT848) – C:\WINDOWS\system32\drivers\wf2kvcap.sys (Leadtek Research Inc.)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = http://www.google.com/
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.latimes.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.latimes.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.10.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.51
FF - prefs.js..keyword.URL: "http://search.search-go.net/?sid=10101053100&s="

FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "http://search.search-go.net/?sid=10101053100&s="

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/08/26 22:06:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/30 22:33:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/30 22:33:41 | 000,000,000 | —D | M]

[2008/06/18 03:48:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Mozilla\Extensions
[2010/08/29 21:21:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions
[2009/09/27 12:43:36 | 000,000,000 | —D | M] (Screengrab) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2009/06/12 16:09:33 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/09/27 12:43:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2007/11/29 04:40:49 | 000,000,000 | —D | M] (Aquatint Black) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{526fd696-27a0-11dc-8314-0800200c9a66}
[2009/09/27 12:43:37 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2008/04/18 23:14:27 | 000,000,000 | —D | M] (Blue Ice 2) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{a8dd47cf-239f-48c4-8379-e6b4cbafdcfa}
[2009/08/11 19:31:30 | 000,000,000 | —D | M] (Password Exporter) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2009/09/27 12:43:40 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/08/13 14:41:48 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/07/01 13:44:18 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/02/19 17:08:19 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2008/03/25 14:59:36 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2008/12/16 02:24:45 | 000,000,891 | —- | M] () – C:\Documents and Settings\Hiram\Application Data\Mozilla\Firefox\Profiles\f6wr6v7r.default\searchplugins\dictionarycom.xml
[2010/08/29 12:32:48 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/24 21:06:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/08/24 21:06:35 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2005/12/06 00:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll

O1 HOSTS File: ([2010/08/25 17:29:24 | 000,416,183 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14390 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] C:\Program Files\Alwil Software\Avast4\ashDisp.exe File not found
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.lizardtech.com/download/files/w…ntrol_en_US.cab (DjVuCtl Class)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su2…15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/09/04 18:58:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/10/28 05:48:06 | 000,000,045 | R— | M] () - D:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/09/02 00:27:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DivX
[2010/09/01 12:31:15 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/09/01 09:53:14 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Hiram\Desktop\OTL.exe
[2010/08/30 22:33:15 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/08/30 22:29:26 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/08/30 22:29:07 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/08/30 22:29:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/08/30 22:21:22 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/08/30 13:51:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Pics - Summer 2010
[2010/08/30 13:03:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Application Data\VirtualStore
[2010/08/29 20:02:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Tosh.0 - S02E18 - Peter Pan Girls
[2010/08/29 20:01:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Tosh.0.S02E19.HDTV.XviD-aAF [NO-RAR] - [ www.torrentday.com ]
[2010/08/29 20:00:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Tosh.0 - S02E21 - American Idol Girls
[2010/08/29 14:02:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\Walt Disney's Monsters Inc
[2010/08/29 02:25:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Application Data\Acapela Group
[2010/08/29 02:25:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Local Settings\Application Data\Xtranormal
[2010/08/29 02:23:21 | 000,000,000 | —D | C] – C:\Program Files\Xtranormal
[2010/08/29 02:22:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Application Data\Xtranormal
[2010/08/27 23:18:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\tosh.0
[2010/08/27 23:02:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/08/27 16:58:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Application Data\Office Genuine Advantage
[2010/08/26 22:08:38 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/08/26 22:08:35 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/08/26 22:08:27 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/08/26 22:08:24 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/08/26 22:08:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/08/26 22:04:20 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/08/26 22:03:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/08/26 20:32:23 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/08/26 19:19:21 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2010/08/26 19:19:21 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpcdll.dll
[2010/08/26 19:19:21 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2010/08/26 19:19:14 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\irbus.sys
[2010/08/26 19:19:13 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2010/08/26 19:19:13 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2010/08/26 19:19:13 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2010/08/26 19:19:12 | 000,229,376 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2cqag.dll
[2010/08/26 19:19:12 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2010/08/26 19:19:11 | 001,888,992 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3duag.dll
[2010/08/26 19:19:11 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2010/08/26 19:19:11 | 000,516,768 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ativvaxx.dll
[2010/08/26 19:19:11 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2010/08/26 19:19:11 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2010/08/26 19:19:11 | 000,201,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvag.dll
[2010/08/26 19:19:11 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2010/08/26 19:19:11 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2010/08/26 19:19:11 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2010/08/26 19:19:11 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2010/08/26 19:19:11 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2010/08/26 19:19:11 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2010/08/26 19:19:11 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2010/08/26 19:19:11 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2010/08/26 19:19:11 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2010/08/26 19:19:11 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2010/08/26 19:19:10 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2010/08/26 19:19:10 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2010/08/26 19:19:10 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2010/08/26 19:19:10 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2010/08/26 19:19:10 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2010/08/26 19:19:10 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2010/08/26 19:19:10 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2010/08/26 19:19:10 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2010/08/26 19:19:10 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2010/08/26 19:19:10 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2010/08/26 19:19:10 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2010/08/26 19:19:09 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2010/08/26 19:19:09 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2010/08/26 19:19:09 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2010/08/26 19:19:09 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2010/08/26 19:19:09 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2010/08/26 19:19:08 | 004,274,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nv4_disp.dll
[2010/08/26 19:19:08 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2010/08/26 19:19:08 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2010/08/26 19:19:08 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2010/08/26 19:19:08 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2010/08/26 19:19:08 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2010/08/26 19:19:08 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2010/08/26 19:19:08 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2010/08/26 19:19:08 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2010/08/26 19:19:08 | 000,086,016 | —- | C] (Conexant) – C:\WINDOWS\System32\mdmxsdk.dll
[2010/08/26 19:19:08 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2010/08/26 19:19:08 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2010/08/26 19:19:08 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2010/08/26 19:19:07 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2010/08/26 19:19:07 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2010/08/26 19:19:07 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2010/08/26 19:19:07 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2010/08/26 19:19:07 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2010/08/26 19:19:07 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2010/08/26 19:19:07 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2010/08/26 19:19:07 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2010/08/26 19:19:07 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2010/08/26 19:19:07 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2010/08/26 19:19:07 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2010/08/26 19:19:07 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2010/08/26 19:19:07 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2010/08/26 19:19:06 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2010/08/26 19:19:05 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2010/08/26 19:19:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/08/26 19:19:04 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/08/26 19:19:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2010/08/26 19:19:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2010/08/26 19:15:23 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2010/08/26 19:15:23 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2010/08/26 19:15:23 | 000,043,008 | —- | C] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\drivers\amdagp.sys
[2010/08/26 19:15:23 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2010/08/26 19:15:23 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2010/08/26 19:15:23 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2010/08/26 19:15:23 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2010/08/26 19:15:23 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2010/08/26 19:15:23 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2010/08/26 19:15:23 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2010/08/26 19:15:23 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2010/08/26 19:15:23 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2010/08/26 19:15:23 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2010/08/26 19:15:23 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2010/08/26 19:15:23 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2010/08/26 19:15:23 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2010/08/26 19:15:22 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtag.sys
[2010/08/26 19:15:22 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2010/08/26 19:15:22 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2010/08/26 19:15:22 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2010/08/26 19:15:22 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2010/08/26 19:15:22 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2010/08/26 19:15:22 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2010/08/26 19:15:22 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2010/08/26 19:15:22 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2010/08/26 19:15:22 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2010/08/26 19:15:22 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2010/08/26 19:15:22 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2010/08/26 19:15:22 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2010/08/26 19:15:22 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2010/08/26 19:15:22 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2010/08/26 19:15:22 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2010/08/26 19:15:22 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2010/08/26 19:15:22 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2010/08/26 19:15:22 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2010/08/26 19:15:21 | 000,144,384 | —- | C] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\drivers\hdaudbus.sys
[2010/08/26 19:15:21 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2010/08/26 19:15:21 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2010/08/26 19:15:20 | 001,897,408 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\drivers\nv4_mini.sys
[2010/08/26 19:15:20 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2010/08/26 19:15:20 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2010/08/26 19:15:20 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2010/08/26 19:15:20 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2010/08/26 19:15:20 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2010/08/26 19:15:20 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2010/08/26 19:15:20 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2010/08/26 19:15:19 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2010/08/26 19:15:19 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2010/08/26 19:15:19 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2010/08/26 19:15:19 | 000,040,960 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\drivers\sisagp.sys
[2010/08/26 19:15:19 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2010/08/26 19:15:19 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2010/08/26 19:15:19 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2010/08/26 19:15:18 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2010/08/26 19:15:18 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2010/08/26 19:15:18 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2010/08/26 19:15:18 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2010/08/26 19:15:18 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2010/08/26 19:15:18 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2010/08/26 19:15:18 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2010/08/26 19:09:29 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2010/08/26 17:34:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/26 17:34:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/08/25 17:02:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\Desktop\monthly maintenance
[2010/08/24 21:07:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/08/24 21:07:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/08/24 21:06:49 | 000,423,656 | —- | C] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/24 21:06:49 | 000,153,376 | —- | C] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/08/24 21:06:49 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/08/24 21:06:49 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/08/24 21:06:49 | 000,073,728 | —- | C] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/08/24 20:56:54 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Hiram\IECompatCache
[2010/08/24 20:56:18 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Hiram\PrivacIE
[2010/08/24 13:29:51 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/08/24 13:25:41 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/08/24 13:12:46 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/08/24 13:07:51 | 000,023,040 | —- | C] (Xerox Corporation) – C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2010/08/24 13:07:50 | 000,004,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2010/08/24 13:07:38 | 000,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2010/08/24 13:07:38 | 000,016,970 | —- | C] (US Robotics MCD (Megahertz)) – C:\WINDOWS\System32\dllcache\xem336n5.sys
[2010/08/24 13:07:36 | 000,019,455 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wvchntxx.sys
[2010/08/24 13:07:33 | 000,012,063 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wsiintxx.sys
[2010/08/24 13:07:19 | 000,154,624 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\wlluc48.sys
[2010/08/24 13:07:18 | 000,034,890 | —- | C] (Raytheon Corp.) – C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2010/08/24 13:07:14 | 000,771,581 | —- | C] (Rockwell) – C:\WINDOWS\System32\dllcache\winacisa.sys
[2010/08/24 13:07:11 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2010/08/24 13:07:11 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2010/08/24 13:07:08 | 000,701,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\wdhaalba.sys
[2010/08/24 13:07:07 | 000,023,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wch7xxnt.sys
[2010/08/24 13:07:06 | 000,035,871 | —- | C] (Winbond Electronics Corp.) – C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2010/08/24 13:07:03 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv10nt.sys
[2010/08/24 13:07:02 | 000,033,599 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv04nt.sys
[2010/08/24 13:07:02 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv06nt.sys
[2010/08/24 13:07:01 | 000,019,551 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv02nt.sys
[2010/08/24 13:07:00 | 000,029,311 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv01nt.sys
[2010/08/24 13:06:57 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv11nt.sys
[2010/08/24 13:06:57 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv09nt.sys
[2010/08/24 13:06:56 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv08nt.sys
[2010/08/24 13:06:55 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv07nt.sys
[2010/08/24 13:06:54 | 000,011,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv05nt.sys
[2010/08/24 13:06:53 | 000,012,127 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv02nt.sys
[2010/08/24 13:06:52 | 000,012,415 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv01nt.sys
[2010/08/24 13:06:49 | 000,019,528 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w840nd.sys
[2010/08/24 13:06:49 | 000,019,016 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w926nd.sys
[2010/08/24 13:06:49 | 000,016,925 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w940nd.sys
[2010/08/24 13:06:42 | 000,064,605 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vvoice.sys
[2010/08/24 13:06:41 | 000,397,502 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vpctcom.sys
[2010/08/24 13:06:40 | 000,604,253 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\vmodem.sys
[2010/08/24 13:06:39 | 000,249,402 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\vinwm.sys
[2010/08/24 13:06:39 | 000,024,576 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\viairda.sys
[2010/08/24 13:06:33 | 000,765,884 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usrti.sys
[2010/08/24 13:06:33 | 000,687,999 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2010/08/24 13:06:32 | 000,113,762 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrpda.sys
[2010/08/24 13:06:32 | 000,007,556 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usroslba.sys
[2010/08/24 13:06:31 | 000,224,802 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usr1807a.sys
[2010/08/24 13:06:30 | 000,794,399 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806v.sys
[2010/08/24 13:06:30 | 000,793,598 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806.sys
[2010/08/24 13:06:29 | 000,794,654 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1801.sys
[2010/08/24 13:06:22 | 000,032,384 | —- | C] (KLSI USA, Inc.) – C:\WINDOWS\System32\dllcache\usb101et.sys
[2010/08/24 13:06:19 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxud32.dll
[2010/08/24 13:06:19 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu40.dll
[2010/08/24 13:06:18 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu12.dll
[2010/08/24 13:06:18 | 000,050,688 | —- | C] (UMAX DATA SYSTEMS INC.) – C:\WINDOWS\System32\dllcache\umaxscan.dll
[2010/08/24 13:06:18 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu22.dll
[2010/08/24 13:06:17 | 000,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxp60.dll
[2010/08/24 13:06:17 | 000,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxcam.dll
[2010/08/24 13:06:17 | 000,022,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2010/08/24 13:06:15 | 000,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2010/08/24 13:06:15 | 000,211,968 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um54scan.dll
[2010/08/24 13:06:15 | 000,036,736 | —- | C] (Promise Technology, Inc.) – C:\WINDOWS\System32\dllcache\ultra.sys
[2010/08/24 13:06:11 | 000,011,520 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\twotrack.sys
[2010/08/24 13:06:09 | 000,166,784 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxpm.sys
[2010/08/24 13:06:08 | 000,525,568 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxp.dll
[2010/08/24 13:06:08 | 000,440,576 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkb.dll
[2010/08/24 13:06:08 | 000,159,232 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkbm.sys
[2010/08/24 13:06:07 | 000,315,520 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3d.dll
[2010/08/24 13:06:07 | 000,222,336 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3dm.sys
[2010/08/24 13:06:06 | 000,042,496 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4res.dll
[2010/08/24 13:06:06 | 000,034,375 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\tpro4.sys
[2010/08/24 13:06:04 | 000,031,744 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\tp4.dll
[2010/08/24 13:06:03 | 000,241,664 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd02.sys
[2010/08/24 13:06:03 | 000,230,912 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tosdvd03.sys
[2010/08/24 13:06:03 | 000,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\toside.sys
[2010/08/24 13:06:02 | 000,028,232 | —- | C] (TOSHIBA Corporation) – C:\WINDOWS\System32\dllcache\tos4mo.sys
[2010/08/24 13:06:01 | 000,123,995 | —- | C] (Tiger Jet Network) – C:\WINDOWS\System32\dllcache\tjisdn.sys
[2010/08/24 13:05:59 | 000,138,528 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2010/08/24 13:05:59 | 000,081,408 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiul50.dll
[2010/08/24 13:05:56 | 000,017,129 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2010/08/24 13:05:55 | 000,037,961 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdk100b.sys
[2010/08/24 13:05:53 | 000,030,464 | —- | C] (Toshiba Corporation) – C:\WINDOWS\System32\dllcache\tbatm155.sys
[2010/08/24 13:05:51 | 000,036,640 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2010/08/24 13:05:51 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tandqic.sys
[2010/08/24 13:05:50 | 000,172,768 | —- | C] (Number Nine Visual Technology) – C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2010/08/24 13:05:48 | 000,032,640 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\symc8xx.sys
[2010/08/24 13:05:47 | 000,030,688 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\sym_u3.sys
[2010/08/24 13:05:47 | 000,028,384 | —- | C] (LSI Logic) – C:\WINDOWS\System32\dllcache\sym_hi.sys
[2010/08/24 13:05:47 | 000,016,256 | —- | C] (Symbios Logic Inc.) – C:\WINDOWS\System32\dllcache\symc810.sys
[2010/08/24 13:05:45 | 000,103,936 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sx.sys
[2010/08/24 13:05:45 | 000,094,293 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sxports.dll
[2010/08/24 13:05:45 | 000,003,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swusbflt.sys
[2010/08/24 13:05:44 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpidflt.dll
[2010/08/24 13:05:44 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2010/08/24 13:05:43 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2010/08/24 13:05:43 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_effct.dll
[2010/08/24 13:05:41 | 000,285,760 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnata.sys
[2010/08/24 13:05:41 | 000,155,648 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnprop.dll
[2010/08/24 13:05:41 | 000,053,248 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlncoin.dll
[2010/08/24 13:05:40 | 000,016,896 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\stcusb.sys
[2010/08/24 13:05:36 | 000,048,736 | —- | C] (3Com) – C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2010/08/24 13:05:34 | 000,099,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusd.dll
[2010/08/24 13:05:32 | 000,024,660 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spxupchk.dll
[2010/08/24 13:05:30 | 000,061,824 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\speed.sys
[2010/08/24 13:05:29 | 000,106,584 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spdports.dll
[2010/08/24 13:05:29 | 000,019,072 | —- | C] (Adaptec, Inc.) – C:\WINDOWS\System32\dllcache\sparrow.sys
[2010/08/24 13:05:28 | 000,037,040 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.sys
[2010/08/24 13:05:28 | 000,007,552 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2010/08/24 13:05:27 | 000,114,688 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonypi.dll
[2010/08/24 13:05:27 | 000,020,752 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\dllcache\sonync.sys
[2010/08/24 13:05:27 | 000,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonymc.sys
[2010/08/24 13:05:25 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2010/08/24 13:05:10 | 000,058,368 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smiminib.sys
[2010/08/24 13:05:09 | 000,147,200 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smidispb.dll
[2010/08/24 13:05:08 | 000,025,034 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2010/08/24 13:05:07 | 000,035,913 | —- | C] (SMC) – C:\WINDOWS\System32\dllcache\smcirda.sys
[2010/08/24 13:05:07 | 000,024,576 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smc8000n.sys
[2010/08/24 13:05:07 | 000,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbhc.sys
[2010/08/24 13:05:04 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb3w.dll
[2010/08/24 13:05:03 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb0w.dll
[2010/08/24 13:05:02 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma0w.dll
[2010/08/24 13:05:01 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm91w.dll
[2010/08/24 13:04:56 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slwdmsup.sys
[2010/08/24 13:04:54 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slnthal.sys
[2010/08/24 13:04:53 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slntamr.sys
[2010/08/24 13:04:53 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slnt7554.sys
[2010/08/24 13:04:49 | 000,094,698 | —- | C] (SysKonnect GmbH.) – C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2010/08/24 13:04:49 | 000,091,294 | —- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) – C:\WINDOWS\System32\dllcache\skfpwin.sys
[2010/08/24 13:04:49 | 000,063,547 | —- | C] (Symbol Technologies) – C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2010/08/24 13:04:48 | 000,157,696 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv256.dll
[2010/08/24 13:04:48 | 000,050,432 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisv.sys
[2010/08/24 13:04:47 | 000,032,768 | —- | C] (SiS Corporation) – C:\WINDOWS\System32\dllcache\sisnic.sys
[2010/08/24 13:04:46 | 000,238,592 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrv.dll
[2010/08/24 13:04:46 | 000,104,064 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sisgrp.sys
[2010/08/24 13:04:45 | 000,150,144 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306v.dll
[2010/08/24 13:04:45 | 000,068,608 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis6306p.sys
[2010/08/24 13:04:44 | 000,252,032 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300iv.dll
[2010/08/24 13:04:44 | 000,101,760 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\dllcache\sis300ip.sys
[2010/08/24 13:04:37 | 000,161,568 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2010/08/24 13:04:37 | 000,018,400 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmld.sys
[2010/08/24 13:04:36 | 000,386,560 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiul50.dll
[2010/08/24 13:04:36 | 000,098,080 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2010/08/24 13:04:34 | 000,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2010/08/24 13:04:34 | 000,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2010/08/24 13:04:25 | 000,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2010/08/24 13:04:24 | 000,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2010/08/24 13:03:30 | 000,017,280 | —- | C] (SCM Microsystems) – C:\WINDOWS\System32\dllcache\scr111.sys
[2010/08/24 13:03:29 | 000,016,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scmstcs.sys
[2010/08/24 13:03:28 | 000,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2010/08/24 13:03:28 | 000,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2010/08/24 13:03:25 | 000,075,392 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmxm.sys
[2010/08/24 13:03:24 | 000,245,632 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3savmx.dll
[2010/08/24 13:03:24 | 000,198,400 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4.dll
[2010/08/24 13:03:24 | 000,077,824 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2010/08/24 13:03:23 | 000,210,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2010/08/24 13:03:23 | 000,179,264 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2010/08/24 13:03:23 | 000,061,504 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2010/08/24 13:03:22 | 000,182,272 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2010/08/24 13:03:22 | 000,062,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2010/08/24 13:03:22 | 000,041,216 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2010/08/24 13:03:21 | 000,166,720 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3m.sys
[2010/08/24 13:03:21 | 000,065,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.sys
[2010/08/24 13:03:20 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\dllcache\s3gnbm.sys
[2010/08/24 13:03:19 | 000,082,432 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia450.dll
[2010/08/24 13:03:18 | 000,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia430.dll
[2010/08/24 13:03:14 | 000,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8139.sys
[2010/08/24 13:03:13 | 000,030,720 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rthwcls.sys
[2010/08/24 13:03:13 | 000,019,017 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8029.sys
[2010/08/24 13:03:12 | 000,009,216 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2010/08/24 13:03:11 | 000,003,840 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\rpfun.sys
[2010/08/24 13:03:03 | 000,037,563 | —- | C] (RadioLAN) – C:\WINDOWS\System32\dllcache\rlnet5.sys
[2010/08/24 13:03:01 | 000,086,097 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\reslog32.dll
[2010/08/24 12:58:34 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\recagent.sys
[2010/08/24 12:58:31 | 000,019,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasirda.sys
[2010/08/24 12:58:28 | 000,714,762 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2010/08/24 12:58:27 | 000,899,146 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2010/08/24 12:58:27 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qvusd.dll
[2010/08/24 12:58:27 | 000,003,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qv2kux.sys
[2010/08/24 12:58:24 | 000,049,024 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql1280.sys
[2010/08/24 12:58:24 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql1240.sys
[2010/08/24 12:58:23 | 000,045,312 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql12160.sys
[2010/08/24 12:58:23 | 000,040,320 | —- | C] (QLogic Corporation) – C:\WINDOWS\System32\dllcache\ql1080.sys
[2010/08/24 12:58:23 | 000,033,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql10wnt.sys
[2010/08/24 12:58:20 | 000,130,942 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlv.sys
[2010/08/24 12:58:19 | 000,128,286 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserli.sys
[2010/08/24 12:58:19 | 000,112,574 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlp.sys
[2010/08/24 12:58:17 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusb.dll
[2010/08/24 12:58:16 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\psisload.dll
[2010/08/24 12:58:15 | 000,016,128 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\pscr.sys
[2010/08/24 12:58:12 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa.sys
[2010/08/24 12:58:11 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pnrmc.sys
[2010/08/24 12:58:09 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\plugin.ocx
[2010/08/24 12:58:07 | 000,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phvfwext.dll
[2010/08/24 12:58:07 | 000,019,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philtune.sys
[2010/08/24 12:58:06 | 000,173,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam2.sys
[2010/08/24 12:58:06 | 000,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phildec.sys
[2010/08/24 12:58:06 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.sys
[2010/08/24 12:58:05 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phdsext.ax
[2010/08/24 12:58:05 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.dll
[2010/08/24 12:58:00 | 000,027,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2.sys
[2010/08/24 12:58:00 | 000,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2hib.sys
[2010/08/24 12:57:58 | 000,169,984 | —- | C] (Cisco Systems) – C:\WINDOWS\System32\dllcache\pcx500.sys
[2010/08/24 12:57:58 | 000,086,016 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\pctspk.exe
[2010/08/24 12:57:57 | 000,035,328 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2010/08/24 12:57:57 | 000,030,282 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2010/08/24 12:57:57 | 000,029,769 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2010/08/24 12:57:56 | 000,026,153 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2010/08/24 12:57:55 | 000,030,495 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pc100nds.sys
[2010/08/24 12:57:55 | 000,029,502 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\pca200e.sys
[2010/08/24 12:57:49 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2rc.dll
[2010/08/24 12:57:48 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2.dll
[2010/08/24 12:57:48 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcoms.exe
[2010/08/24 12:57:48 | 000,025,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovsound2.sys
[2010/08/24 12:57:47 | 000,351,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodek2.sys
[2010/08/24 12:57:47 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodec2.dll
[2010/08/24 12:57:47 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcomc.dll
[2010/08/24 12:57:46 | 000,048,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcam2.sys
[2010/08/24 12:57:46 | 000,031,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovce.sys
[2010/08/24 12:57:46 | 000,028,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcd.sys
[2010/08/24 12:57:45 | 000,054,186 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otcsercb.sys
[2010/08/24 12:57:45 | 000,043,689 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otceth5.sys
[2010/08/24 12:57:45 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovca.sys
[2010/08/24 12:57:44 | 000,027,209 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otc06x5.sys
[2010/08/24 12:57:43 | 000,054,528 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\opl3sax.sys
[2010/08/24 12:57:36 | 001,897,408 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv4_mini.sys
[2010/08/24 12:57:35 | 000,198,144 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.sys
[2010/08/24 12:57:34 | 000,123,776 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\dllcache\nv3.dll
[2010/08/24 12:57:33 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\ntmtlfax.sys
[2010/08/24 12:57:30 | 000,051,552 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\dllcache\ntgrip.sys
[2010/08/24 12:51:17 | 000,009,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntapm.sys
[2010/08/24 12:51:17 | 000,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsmmc.sys
[2010/08/24 12:51:13 | 000,126,080 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2010/08/24 12:51:13 | 000,087,040 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2010/08/24 12:51:12 | 000,032,840 | —- | C] (NETGEAR Corporation.) – C:\WINDOWS\System32\dllcache\ngrpci.sys
[2010/08/24 12:51:10 | 000,132,695 | —- | C] (802.11b) – C:\WINDOWS\System32\dllcache\netwlan5.sys
[2010/08/24 12:51:07 | 000,065,278 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\netflx3.sys
[2010/08/24 12:51:06 | 000,039,264 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.sys
[2010/08/24 12:51:05 | 000,060,480 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.dll
[2010/08/24 12:51:05 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ne2000.sys
[2010/08/24 12:51:02 | 000,091,488 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2010/08/24 12:51:02 | 000,027,936 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3d.sys
[2010/08/24 12:51:01 | 000,059,104 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2010/08/24 12:51:01 | 000,033,088 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2010/08/24 12:51:01 | 000,013,664 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.sys
[2010/08/24 12:51:00 | 000,128,000 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n100325.sys
[2010/08/24 12:51:00 | 000,035,392 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.dll
[2010/08/24 12:50:59 | 000,075,520 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxport.sys
[2010/08/24 12:50:59 | 000,052,255 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2010/08/24 12:50:59 | 000,007,168 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxport.dll
[2010/08/24 12:50:58 | 000,019,968 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxicfg.dll
[2010/08/24 12:50:58 | 000,019,968 | —- | C] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\dllcache\mxnic.sys
[2010/08/24 12:50:57 | 000,021,888 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxcard.sys
[2010/08/24 12:50:55 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mtxparhm.sys
[2010/08/24 12:50:55 | 000,103,296 | —- | C] (Matrox Graphics Inc) – C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2010/08/24 12:50:51 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\mtlstrm.sys
[2010/08/24 12:50:50 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\mtlmnt5.sys
[2010/08/24 12:50:43 | 000,012,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msriffwv.sys
[2010/08/24 12:50:40 | 000,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msmpu401.sys
[2010/08/24 12:50:27 | 000,035,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msgame.sys
[2010/08/24 12:50:26 | 000,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfsio.sys
[2010/08/24 12:50:19 | 000,017,280 | —- | C] (American Megatrends Inc.) – C:\WINDOWS\System32\dllcache\mraid35x.sys
[2010/08/24 12:50:14 | 000,016,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\modemcsa.sys
[2010/08/24 12:50:11 | 000,006,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\miniqic.sys
[2010/08/24 12:50:07 | 000,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaum.sys
[2010/08/24 12:50:07 | 000,235,648 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\mgaud.dll
[2010/08/24 12:50:04 | 000,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memgrp.dll
[2010/08/24 12:50:03 | 000,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memcard.sys
[2010/08/24 12:50:02 | 000,164,586 | —- | C] (Madge Networks Ltd) – C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2010/08/24 12:49:57 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mammoth.sys
[2010/08/24 12:48:59 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3092dc.dll
[2010/08/24 12:48:59 | 000,048,768 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\maestro.sys
[2010/08/24 12:48:58 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3091dc.dll
[2010/08/24 12:48:57 | 000,022,848 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwusbhid.sys
[2010/08/24 12:48:56 | 000,020,864 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\dllcache\lwadihid.sys
[2010/08/24 12:48:55 | 000,802,683 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\ltsm.sys
[2010/08/24 12:48:55 | 000,797,500 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltsmt.sys
[2010/08/24 12:48:53 | 000,576,746 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2010/08/24 12:48:53 | 000,420,992 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2010/08/24 12:48:52 | 000,727,786 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ltck000c.sys
[2010/08/24 12:48:52 | 000,606,684 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2010/08/24 12:48:50 | 000,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\loop.sys
[2010/08/24 12:48:48 | 000,070,730 | —- | C] (Linksys Group, Inc.) – C:\WINDOWS\System32\dllcache\lne100tx.sys
[2010/08/24 12:48:47 | 000,025,065 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\lmndis3.sys
[2010/08/24 12:48:47 | 000,020,573 | —- | C] (The Linksts Group ) – C:\WINDOWS\System32\dllcache\lne100.sys
[2010/08/24 12:48:46 | 000,015,744 | —- | C] (Litronic Industries) – C:\WINDOWS\System32\dllcache\lit220p.sys
[2010/08/24 12:48:43 | 000,026,442 | —- | C] (SMSC) – C:\WINDOWS\System32\dllcache\lanepic5.sys
[2010/08/24 12:48:43 | 000,019,016 | —- | C] (Kingston Technology Company ) – C:\WINDOWS\System32\dllcache\ktc111.sys
[2010/08/24 12:48:41 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kousd.dll
[2010/08/24 12:48:14 | 000,026,624 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\dllcache\irstusb.sys
[2010/08/24 12:48:14 | 000,018,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irsir.sys
[2010/08/24 12:48:12 | 000,023,552 | —- | C] (MKNet Corporation) – C:\WINDOWS\System32\dllcache\irmk7.sys
[2010/08/24 12:48:06 | 000,045,632 | —- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) – C:\WINDOWS\System32\dllcache\ip5515.sys
[2010/08/24 12:48:05 | 000,090,200 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8ports.dll
[2010/08/24 12:48:05 | 000,038,784 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8.sys
[2010/08/24 12:48:04 | 000,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ini910u.sys
[2010/08/24 12:48:04 | 000,013,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inport.sys
[2010/08/24 12:47:49 | 000,372,824 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\iconf32.dll
[2010/08/24 12:47:47 | 000,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5usb.sys
[2010/08/24 12:47:47 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5com.dll
[2010/08/24 12:47:47 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5ext.dll
[2010/08/24 12:47:46 | 000,154,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4usb.sys
[2010/08/24 12:47:46 | 000,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4com.dll
[2010/08/24 12:47:46 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4ext.dll
[2010/08/24 12:47:45 | 000,141,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3.sys
[2010/08/24 12:47:45 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3ext.dll
[2010/08/24 12:47:44 | 000,109,085 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtrp.sys
[2010/08/24 12:47:44 | 000,100,936 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmtok.sys
[2010/08/24 12:47:44 | 000,038,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2010/08/24 12:47:43 | 000,028,700 | —- | C] (IBM Corp.) – C:\WINDOWS\System32\dllcache\ibmexmp.sys
[2010/08/24 12:47:43 | 000,009,216 | —- | C] (IBM Corporation) – C:\WINDOWS\System32\dllcache\ibmsgnet.dll
[2010/08/24 12:47:41 | 000,161,020 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\i81xnt5.sys
[2010/08/24 12:47:40 | 000,353,184 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740dnt5.dll
[2010/08/24 12:47:40 | 000,058,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\i740nt5.sys
[2010/08/24 12:47:32 | 001,041,536 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfdpsp2.sys
[2010/08/24 12:47:30 | 000,685,056 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfcxts2.sys
[2010/08/24 12:47:28 | 000,488,383 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_v124.sys
[2010/08/24 12:47:28 | 000,220,032 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\hsfbs2s2.sys
[2010/08/24 12:47:27 | 000,073,279 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_spkp.sys
[2010/08/24 12:47:27 | 000,050,751 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_tone.sys
[2010/08/24 12:47:27 | 000,044,863 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_soar.sys
[2010/08/24 12:47:26 | 000,542,879 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_msft.sys
[2010/08/24 12:47:26 | 000,391,199 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_k56k.sys
[2010/08/24 12:47:26 | 000,057,471 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_samp.sys
[2010/08/24 12:47:25 | 000,115,807 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fsks.sys
[2010/08/24 12:47:25 | 000,009,759 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_inst.dll
[2010/08/24 12:47:24 | 000,289,887 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_fall.sys
[2010/08/24 12:47:24 | 000,199,711 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_faxx.sys
[2010/08/24 12:47:24 | 000,067,167 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_bsc2.sys
[2010/08/24 12:47:23 | 000,150,239 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hsf_amos.sys
[2010/08/24 12:47:23 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hr1w.dll
[2010/08/24 12:47:22 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2010/08/24 12:47:22 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2010/08/24 12:47:22 | 000,005,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpt4qic.sys
[2010/08/24 12:47:21 | 000,068,608 | —- | C] (Avisioin) – C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2010/08/24 12:47:21 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2010/08/24 12:47:21 | 000,025,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpn.sys
[2010/08/24 12:47:20 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2010/08/24 12:47:19 | 000,126,976 | —- | C] (Hewlett Packard) – C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2010/08/24 12:47:19 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2010/08/24 12:47:18 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2010/08/24 12:47:17 | 000,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2010/08/24 12:47:15 | 000,002,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidswvd.sys
[2010/08/24 12:47:13 | 000,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidgame.sys
[2010/08/24 12:47:09 | 000,907,456 | —- | C] (Conexant) – C:\WINDOWS\System32\dllcache\hcf_msft.sys
[2010/08/24 12:47:06 | 000,082,304 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grclass.sys
[2010/08/24 12:47:06 | 000,017,408 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\gpr400.sys
[2010/08/24 12:47:02 | 001,733,120 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400d.dll
[2010/08/24 12:47:02 | 000,322,432 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g400m.sys
[2010/08/24 12:47:01 | 000,470,144 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200d.dll
[2010/08/24 12:47:01 | 000,454,912 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fxusbase.sys
[2010/08/24 12:47:01 | 000,320,384 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\dllcache\g200m.sys
[2010/08/24 12:46:49 | 000,455,296 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fusbbase.sys
[2010/08/24 12:46:49 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fuusd.dll
[2010/08/24 12:46:48 | 000,455,680 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fus2base.sys
[2010/08/24 12:46:45 | 000,442,240 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2010/08/24 12:46:45 | 000,441,728 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2010/08/24 12:46:44 | 000,444,416 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcibase.sys
[2010/08/24 12:46:42 | 000,034,173 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\forehe.sys
[2010/08/24 12:46:41 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fnfilter.dll
[2010/08/24 12:46:35 | 000,027,165 | —- | C] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\dllcache\fetnd5.sys
[2010/08/24 12:46:34 | 000,022,090 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\fem556n5.sys
[2010/08/24 12:44:46 | 000,024,618 | —- | C] (NETGEAR) – C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2010/08/24 12:44:46 | 000,016,074 | —- | C] (NETGEAR Corp.) – C:\WINDOWS\System32\dllcache\fa312nd5.sys
[2010/08/24 12:44:45 | 000,012,362 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2010/08/24 12:44:45 | 000,011,850 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2010/08/24 12:44:42 | 000,016,998 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ex10.sys
[2010/08/24 12:44:42 | 000,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exabyte2.sys
[2010/08/24 12:44:38 | 000,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunib.dll
[2010/08/24 12:44:38 | 000,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuni.dll
[2010/08/24 12:44:37 | 000,034,816 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimg.dll
[2010/08/24 12:44:36 | 000,137,088 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\essm2e.sys
[2010/08/24 12:44:36 | 000,043,008 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucm.dll
[2010/08/24 12:44:35 | 000,063,360 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\ess.sys
[2010/08/24 12:44:34 | 000,347,550 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56tpi.sys
[2010/08/24 12:44:33 | 000,595,647 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56cvmp.sys
[2010/08/24 12:44:33 | 000,594,238 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es56hpi.sys
[2010/08/24 12:44:32 | 000,174,464 | —- | C] (ESS Technology, Inc.) – C:\WINDOWS\System32\dllcache\es198x.sys
[2010/08/24 12:44:32 | 000,072,192 | —- | C] (ESS Technology Inc.) – C:\WINDOWS\System32\dllcache\es1969.sys
[2010/08/24 12:44:32 | 000,040,704 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1371mp.sys
[2010/08/24 12:44:31 | 000,061,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnloop.exe
[2010/08/24 12:44:31 | 000,051,200 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqnlogr.exe
[2010/08/24 12:44:31 | 000,037,120 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1370mp.sys
[2010/08/24 12:44:30 | 000,629,952 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqn.sys
[2010/08/24 12:44:30 | 000,053,248 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\dllcache\eqndiag.exe
[2010/08/24 12:44:29 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2010/08/24 12:44:29 | 000,114,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epstw2k.sys
[2010/08/24 12:44:29 | 000,018,503 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\epro4.sys
[2010/08/24 12:44:28 | 000,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\enum1394.sys
[2010/08/24 12:44:27 | 000,025,159 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\elnk3.sys
[2010/08/24 12:44:27 | 000,019,996 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\em556n4.sys
[2010/08/24 12:44:26 | 000,171,520 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el99xn51.sys
[2010/08/24 12:44:26 | 000,070,174 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el98xn5.sys
[2010/08/24 12:44:26 | 000,007,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\elmsmc.sys
[2010/08/24 12:44:25 | 000,455,199 | —- | C] (3Com Corporation.) – C:\WINDOWS\System32\dllcache\el985n51.sys
[2010/08/24 12:44:25 | 000,153,631 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xnd5.sys
[2010/08/24 12:44:24 | 000,241,206 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656se5.sys
[2010/08/24 12:44:24 | 000,066,591 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el90xbc5.sys
[2010/08/24 12:44:23 | 000,634,134 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656ct5.sys
[2010/08/24 12:44:23 | 000,077,386 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656nd5.sys
[2010/08/24 12:44:23 | 000,069,194 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el656cd5.sys
[2010/08/24 12:44:22 | 000,069,692 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el575nd5.sys
[2010/08/24 12:44:22 | 000,026,141 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el589nd5.sys
[2010/08/24 12:44:21 | 000,055,999 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el556nd5.sys
[2010/08/24 12:44:21 | 000,024,653 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el574nd4.sys
[2010/08/24 12:44:20 | 000,044,103 | —- | C] (3Com Corporation) – C:\WINDOWS\System32\dllcache\el515.sys
[2010/08/24 12:44:15 | 000,050,719 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e1000nt5.sys
[2010/08/24 12:44:15 | 000,019,594 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\e100isa4.sys
[2010/08/24 12:44:10 | 000,334,208 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2010/08/24 12:44:09 | 000,020,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpti2o.sys
[2010/08/24 12:44:07 | 000,028,062 | —- | C] (National Semiconductor Coproration) – C:\WINDOWS\System32\dllcache\dp83820.sys
[2010/08/24 12:44:07 | 000,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2010/08/24 12:44:07 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2010/08/24 12:44:06 | 000,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2010/08/24 12:44:02 | 000,029,696 | —- | C] (CNet Technology, Inc. ) – C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2010/08/24 12:44:01 | 000,026,698 | —- | C] (D-Link Corporation) – C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2010/08/24 12:44:00 | 000,952,007 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diwan.sys
[2010/08/24 12:43:59 | 000,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2010/08/24 12:43:59 | 000,038,985 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvsu.dll
[2010/08/24 12:43:58 | 000,031,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvpp.dll
[2010/08/24 12:43:58 | 000,006,729 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvci.dll
[2010/08/24 12:43:56 | 000,091,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\dimaint.sys
[2010/08/24 12:43:55 | 000,614,429 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiview.exe
[2010/08/24 12:43:55 | 000,110,621 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.dll
[2010/08/24 12:43:55 | 000,042,432 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dllcache\digirlpt.sys
[2010/08/24 12:43:54 | 000,102,484 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiinf.dll
[2010/08/24 12:43:54 | 000,041,046 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.dll
[2010/08/24 12:43:54 | 000,021,606 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiisdn.sys
[2010/08/24 12:43:53 | 000,229,462 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifwrk.dll
[2010/08/24 12:43:53 | 000,159,828 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digihlc.dll
[2010/08/24 12:43:53 | 000,090,525 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digifep5.sys
[2010/08/24 12:43:52 | 000,131,156 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidbp.dll
[2010/08/24 12:43:52 | 000,103,044 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digidxb.sys
[2010/08/24 12:43:52 | 000,037,735 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.sys
[2010/08/24 12:43:51 | 000,065,622 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\digiasyn.dll
[2010/08/24 12:43:49 | 000,419,357 | —- | C] (Digi International) – C:\WINDOWS\System32\dllcache\dgconfig.dll
[2010/08/24 12:43:49 | 000,029,531 | —- | C] (Digi International Inc.) – C:\WINDOWS\System32\dllcache\dgapci.sys
[2010/08/24 12:43:48 | 000,024,649 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650d.sys
[2010/08/24 12:43:47 | 000,024,648 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650.sys
[2010/08/24 12:43:46 | 000,020,928 | —- | C] (Digital Networks, LLC) – C:\WINDOWS\System32\dllcache\defpa.sys
[2010/08/24 12:43:45 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddsmc.sys
[2010/08/24 12:43:44 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc260usd.dll
[2010/08/24 12:43:44 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc240usd.dll
[2010/08/24 12:43:44 | 000,063,208 | —- | C] (Intel Corporation.) – C:\WINDOWS\System32\dllcache\dc21x4.sys
[2010/08/24 12:43:43 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210usd.dll
[2010/08/24 12:43:43 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210_32.dll
[2010/08/24 12:43:40 | 000,179,584 | —- | C] (Mylex Corporation) – C:\WINDOWS\System32\dllcache\dac2w2k.sys
[2010/08/24 12:43:40 | 000,014,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dac960nt.sys
[2010/08/24 12:43:38 | 000,117,760 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\d100ib5.sys
[2010/08/24 12:43:38 | 000,049,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzport.sys
[2010/08/24 12:43:38 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzports.dll
[2010/08/24 12:43:37 | 000,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyport.sys
[2010/08/24 12:43:37 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyports.dll
[2010/08/24 12:43:37 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzcoins.dll
[2010/08/24 12:43:36 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyycoins.dll
[2010/08/24 12:43:36 | 000,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclad-z.sys
[2010/08/24 12:43:36 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclom-y.sys
[2010/08/24 12:43:35 | 000,093,952 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2010/08/24 12:43:35 | 000,048,640 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2010/08/24 12:43:34 | 000,111,872 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcspud.sys
[2010/08/24 12:43:34 | 000,072,832 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2010/08/24 12:43:34 | 000,003,584 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2010/08/24 12:43:33 | 000,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2010/08/24 12:43:33 | 000,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbase.sys
[2010/08/24 12:43:32 | 000,096,256 | —- | C] (Copyright © Creative Technology Ltd. 1994-2001) – C:\WINDOWS\System32\dllcache\ctlsb16.sys
[2010/08/24 12:43:30 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\csamsp.dll
[2010/08/24 12:43:30 | 000,042,112 | —- | C] (Conexant Systems Inc.) – C:\WINDOWS\System32\dllcache\crtaud.sys
[2010/08/24 12:43:29 | 000,216,064 | —- | C] (COMPAQ Inc.) – C:\WINDOWS\System32\dllcache\cpscan.dll
[2010/08/24 12:43:28 | 000,060,970 | —- | C] (Compaq Computer Corp.) – C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2010/08/24 12:43:28 | 000,021,533 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2010/08/24 12:43:28 | 000,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cpqarray.sys
[2010/08/24 12:43:21 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnusd.dll
[2010/08/24 12:43:21 | 000,039,936 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\dllcache\cnxt1803.sys
[2010/08/24 12:43:19 | 000,020,736 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2010/08/24 12:43:19 | 000,006,656 | —- | C] (CMD Technology, Inc.) – C:\WINDOWS\System32\dllcache\cmdide.sys
[2010/08/24 12:43:16 | 000,248,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546xm.sys
[2010/08/24 12:43:16 | 000,170,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546x.dll
[2010/08/24 12:43:15 | 000,111,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl5465.dll
[2010/08/24 12:43:15 | 000,045,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.sys
[2010/08/24 12:43:14 | 000,091,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.dll
[2010/08/24 12:43:13 | 000,272,640 | —- | C] (RAVISENT Technologies Inc.) – C:\WINDOWS\System32\dllcache\cinemclc.sys
[2010/08/24 12:43:12 | 000,980,034 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\cicap.sys
[2010/08/24 12:43:06 | 000,049,182 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem56n5.sys
[2010/08/24 12:43:06 | 000,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem33n5.sys
[2010/08/24 12:43:05 | 000,027,164 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce3n5.sys
[2010/08/24 12:43:05 | 000,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem28n5.sys
[2010/08/24 12:43:05 | 000,021,530 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce2n5.sys
[2010/08/24 12:43:03 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cd20xrnt.sys
[2010/08/24 12:43:02 | 000,714,698 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2010/08/24 12:43:02 | 000,046,108 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cben5.sys
[2010/08/24 12:43:01 | 000,039,680 | —- | C] (Silicom Ltd.) – C:\WINDOWS\System32\dllcache\cb325.sys
[2010/08/24 12:43:01 | 000,037,916 | —- | C] (Fast Ethernet Controller Provider) – C:\WINDOWS\System32\dllcache\cb102.sys
[2010/08/24 12:42:59 | 000,164,923 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diapi2.sys
[2010/08/24 12:42:59 | 000,032,256 | —- | C] (Eicon Technology Corporation) – C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2010/08/24 12:42:58 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.ax
[2010/08/24 12:42:57 | 000,244,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.ax
[2010/08/24 12:42:57 | 000,236,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.dll
[2010/08/24 12:42:57 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.dll
[2010/08/24 12:42:56 | 000,171,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv30.sys
[2010/08/24 12:42:56 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.ax
[2010/08/24 12:42:55 | 000,314,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdro21.sys
[2010/08/24 12:42:55 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv21.sys
[2010/08/24 12:42:31 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2010/08/24 12:42:27 | 000,031,529 | —- | C] (BreezeCOM) – C:\WINDOWS\System32\dllcache\brzwlan.sys
[2010/08/24 12:42:27 | 000,011,008 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2010/08/24 12:42:27 | 000,010,368 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbscn.sys
[2010/08/24 12:42:26 | 000,060,416 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brserwdm.sys
[2010/08/24 12:42:26 | 000,009,728 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brserif.dll
[2010/08/24 12:42:26 | 000,005,120 | —- | C] (Brother Industries,Ltd.) – C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2010/08/24 12:42:25 | 000,039,552 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparwdm.sys
[2010/08/24 12:42:25 | 000,003,168 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparimg.sys
[2010/08/24 12:42:23 | 000,041,472 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfusb.dll
[2010/08/24 12:42:22 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2010/08/24 12:42:22 | 000,032,256 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2010/08/24 12:42:22 | 000,029,696 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmflpt.dll
[2010/08/24 12:42:21 | 000,015,360 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2010/08/24 12:42:21 | 000,003,968 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltup.sys
[2010/08/24 12:42:20 | 000,012,800 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brevif.dll
[2010/08/24 12:42:20 | 000,012,160 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2010/08/24 12:42:20 | 000,002,944 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brfilt.sys
[2010/08/24 12:42:19 | 000,019,456 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brbidiif.dll
[2010/08/24 12:42:19 | 000,009,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brcoinst.dll
[2010/08/24 12:42:18 | 000,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\binlsvc.dll
[2010/08/24 12:42:16 | 000,871,388 | —- | C] (BCM) – C:\WINDOWS\System32\dllcache\bcmdm.sys
[2010/08/24 12:42:16 | 000,026,568 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm4e5.sys
[2010/08/24 12:42:15 | 000,066,557 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42u.sys
[2010/08/24 12:42:15 | 000,054,271 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\bcm42xx5.sys
[2010/08/24 12:42:13 | 000,342,336 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.dll
[2010/08/24 12:42:13 | 000,096,640 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\dllcache\b57xp32.sys
[2010/08/24 12:42:13 | 000,036,128 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.sys
[2010/08/24 12:42:12 | 000,089,952 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\b1cbase.sys
[2010/08/24 12:42:12 | 000,036,992 | —- | C] (Aztech Systems Ltd) – C:\WINDOWS\System32\dllcache\aztw2320.sys
[2010/08/24 12:42:11 | 000,144,384 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmenum.dll
[2010/08/24 12:42:11 | 000,087,552 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2010/08/24 12:42:11 | 000,037,568 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmwan.sys
[2010/08/24 12:42:09 | 000,036,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcaudio.sys
[2010/08/24 12:41:53 | 000,104,832 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiraged.dll
[2010/08/24 12:41:53 | 000,070,528 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atiragem.sys
[2010/08/24 12:41:52 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinxsxx.sys
[2010/08/24 12:41:50 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinxbxx.sys
[2010/08/24 12:41:49 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atintuxx.sys
[2010/08/24 12:41:49 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinttxx.sys
[2010/08/24 12:41:48 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinsnxx.sys
[2010/08/24 12:41:46 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinrvxx.sys
[2010/08/24 12:41:46 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinraxx.sys
[2010/08/24 12:41:45 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinpdxx.sys
[2010/08/24 12:41:45 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinmdxx.sys
[2010/08/24 12:41:44 | 000,281,600 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimtai.sys
[2010/08/24 12:41:44 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atinbtxx.sys
[2010/08/24 12:41:43 | 000,289,664 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpab.sys
[2010/08/24 12:41:43 | 000,075,136 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atimpae.sys
[2010/08/24 12:41:43 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atievxx.exe
[2010/08/24 12:41:42 | 000,268,160 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidvai.dll
[2010/08/24 12:41:42 | 000,137,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrae.dll
[2010/08/24 12:41:41 | 000,382,592 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\atidrab.dll
[2010/08/24 12:41:38 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati2mtag.sys
[2010/08/24 12:41:37 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati2mtaa.sys
[2010/08/24 12:41:35 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xsxx.sys
[2010/08/24 12:41:34 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xbxx.sys
[2010/08/24 12:41:33 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1tuxx.sys
[2010/08/24 12:41:32 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1snxx.sys
[2010/08/24 12:41:32 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1ttxx.sys
[2010/08/24 12:41:31 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1rvxx.sys
[2010/08/24 12:41:30 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1raxx.sys
[2010/08/24 12:41:30 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1pdxx.sys
[2010/08/24 12:41:29 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1mdxx.sys
[2010/08/24 12:41:28 | 000,077,568 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ati.sys
[2010/08/24 12:41:28 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1btxx.sys
[2010/08/24 12:41:27 | 000,096,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ati.dll
[2010/08/24 12:41:26 | 000,097,354 | —- | C] (Bay Networks, Inc.) – C:\WINDOWS\System32\dllcache\aspndis3.sys
[2010/08/24 12:41:25 | 000,014,848 | —- | C] (Advanced System Products, Inc.) – C:\WINDOWS\System32\dllcache\asc3550.sys
[2010/08/24 12:41:24 | 000,026,496 | —- | C] (Advanced System Products, Inc.) – C:\WINDOWS\System32\dllcache\asc.sys
[2010/08/24 12:41:24 | 000,022,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asc3350p.sys
[2010/08/24 12:40:44 | 000,006,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\apmbatt.sys
[2010/08/24 12:40:43 | 000,036,224 | —- | C] (ADMtek Incorporated.) – C:\WINDOWS\System32\dllcache\an983.sys
[2010/08/24 12:40:43 | 000,012,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\amsint.sys
[2010/08/24 12:40:41 | 000,016,969 | —- | C] (AmbiCom, Inc.) – C:\WINDOWS\System32\dllcache\amb8002.sys
[2010/08/24 12:40:40 | 000,005,248 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\aliide.sys
[2010/08/24 12:40:39 | 000,056,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78xx.sys
[2010/08/24 12:40:39 | 000,027,678 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ali5261.sys
[2010/08/24 12:40:39 | 000,026,624 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\alifir.sys
[2010/08/24 12:40:38 | 000,055,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78u2.sys
[2010/08/24 12:40:38 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aha154x.sys
[2010/08/24 12:40:27 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2010/08/24 12:39:00 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adpu160m.sys
[2010/08/24 12:38:59 | 000,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2010/08/24 12:38:58 | 000,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2010/08/24 12:38:53 | 000,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2010/08/24 12:38:53 | 000,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2010/08/24 12:38:52 | 000,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2010/08/24 12:38:52 | 000,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2010/08/24 12:38:52 | 000,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2010/08/24 12:38:51 | 000,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2010/08/24 12:38:49 | 000,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2010/08/24 12:38:49 | 000,096,256 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\dllcache\ac97intc.sys
[2010/08/24 12:38:49 | 000,084,480 | —- | C] (VIA Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ac97via.sys
[2010/08/24 12:38:48 | 000,231,552 | —- | C] (Acer Laboratories Inc.) – C:\WINDOWS\System32\dllcache\ac97ali.sys
[2010/08/24 12:38:47 | 000,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2010/08/24 12:38:47 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\abp480n5.sys
[2010/08/24 12:38:46 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2010/08/24 12:38:44 | 000,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2010/08/24 12:38:44 | 000,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2010/08/24 12:38:43 | 000,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2010/08/24 12:38:43 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2010/08/24 12:38:23 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2010/08/24 08:51:53 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Hiram\IETldCache
[2010/08/24 08:22:51 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2010/08/24 08:22:22 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/24 08:20:32 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/08/24 07:55:18 | 000,000,000 | —D | C] – C:\Program Files\CleanUp!
[2010/08/24 02:02:46 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/08/24 01:55:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Hiram\My Documents\MANONIGHT COMPUTERS
[2010/08/24 01:30:37 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/08/24 01:30:37 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/08/24 01:30:37 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/08/24 01:30:37 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/08/23 23:37:03 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/08/21 18:15:05 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/08/20 00:14:25 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/08/19 23:18:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Update
[2010/08/17 00:00:12 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/08/16 08:35:47 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/08/16 08:08:59 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/08/16 00:27:47 | 000,327,472 | —- | C] (BitTorrent, Inc.) – C:\Documents and Settings\Hiram\Desktop\utorrent.exe
[2010/08/10 05:15:58 | 000,094,208 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2002/04/11 12:41:06 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/02 00:31:55 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/09/02 00:27:20 | 011,534,336 | —- | M] () – C:\Documents and Settings\Hiram\ntuser.dat
[2010/09/02 00:20:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-796845957-861567501-1801674531-1003UA.job
[2010/09/01 23:36:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/01 18:25:14 | 064,183,591 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/09/01 13:00:57 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/09/01 13:00:54 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/01 13:00:49 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/01 13:00:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/01 12:59:35 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Hiram\ntuser.ini
[2010/09/01 11:20:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-796845957-861567501-1801674531-1003Core.job
[2010/09/01 09:53:15 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Hiram\Desktop\OTL.exe
[2010/08/31 11:58:47 | 000,002,447 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\HiJackThis.lnk
[2010/08/30 22:33:32 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/30 22:30:22 | 000,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/08/30 22:30:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/30 13:45:12 | 367,120,172 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\White.Collar.S02E07.Prisoners.Dilemma.HDTV.XviD-FQM.avi
[2010/08/29 23:29:05 | 000,204,288 | —- | M] () – C:\Documents and Settings\Hiram\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/29 15:41:10 | 1172,612,850 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\Monster.Inc.2001.m-HD.x264.mkv
[2010/08/29 12:02:12 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/29 10:58:25 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/29 02:23:27 | 000,000,763 | —- | M] () – C:\Documents and Settings\All Users\Desktop\State.lnk
[2010/08/27 00:43:52 | 000,144,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/26 22:42:26 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/26 22:40:46 | 000,488,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/26 22:40:46 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/26 22:40:46 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/26 22:22:21 | 000,000,603 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/26 22:08:41 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/08/26 22:08:40 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/08/26 22:08:38 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/08/26 22:08:27 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/08/26 22:08:27 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/08/26 22:08:24 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/08/26 20:35:03 | 000,031,256 | —- | M] () – C:\Documents and Settings\Hiram\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/08/26 20:33:16 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010/08/26 20:30:16 | 002,164,092 | —- | M] () – C:\WINDOWS\iis6.BAK
[2010/08/26 19:14:58 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/26 11:14:42 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/08/25 17:29:24 | 000,416,183 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/24 21:06:34 | 000,153,376 | —- | M] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/08/24 21:06:34 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/08/24 21:06:33 | 000,423,656 | —- | M] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/08/24 21:06:33 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/08/24 21:06:33 | 000,073,728 | —- | M] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/08/24 18:42:22 | 000,000,292 | RHS- | M] () – C:\boot.ini
[2010/08/24 18:42:22 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/24 08:51:46 | 000,000,815 | —- | M] () – C:\Documents and Settings\Hiram\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/24 02:19:07 | 000,416,119 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100825-172924.backup
[2010/08/24 01:45:58 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100824-021907.backup
[2010/08/20 15:56:03 | 000,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/20 12:35:23 | 000,000,005 | —- | M] () – C:\zrpt.xml
[2010/08/17 12:39:46 | 000,019,979 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\MyTeamLogo.jpg
[2010/08/17 12:33:53 | 000,251,359 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\Philadelphia_Eagles(1).jpg
[2010/08/17 01:04:48 | 000,000,501 | —- | M] () – C:\Documents and Settings\Hiram\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to mplayerc.exe.lnk
[2010/08/17 00:00:19 | 000,000,630 | —- | M] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/08/16 23:45:56 | 000,002,483 | —- | M] () – C:\Documents and Settings\Hiram\Desktop\Microsoft Word.lnk
[2010/08/16 00:27:48 | 000,327,472 | —- | M] (BitTorrent, Inc.) – C:\Documents and Settings\Hiram\Desktop\utorrent.exe
[2010/08/10 05:15:58 | 000,094,208 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/30 22:33:32 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/30 22:30:22 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/08/30 13:38:20 | 367,120,172 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\White.Collar.S02E07.Prisoners.Dilemma.HDTV.XviD-FQM.avi
[2010/08/29 14:46:58 | 1172,612,850 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\Monster.Inc.2001.m-HD.x264.mkv
[2010/08/29 02:23:27 | 000,000,763 | —- | C] () – C:\Documents and Settings\All Users\Desktop\State.lnk
[2010/08/27 17:37:30 | 000,002,447 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\HiJackThis.lnk
[2010/08/26 22:08:41 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/08/26 22:08:24 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/08/26 22:08:17 | 064,183,591 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/08/26 19:15:22 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2010/08/26 19:15:21 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2010/08/26 19:15:20 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2010/08/26 17:34:46 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/08/24 13:07:50 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2010/08/24 12:47:20 | 000,165,888 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt53.dll
[2010/08/24 12:47:20 | 000,093,696 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt42.dll
[2010/08/24 12:47:19 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt34.dll
[2010/08/24 12:47:18 | 000,089,088 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt33.dll
[2010/08/24 12:47:18 | 000,083,968 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt21.dll
[2010/08/24 12:44:00 | 000,037,962 | —- | C] () – C:\WINDOWS\System32\dllcache\divaprop.dll
[2010/08/24 12:44:00 | 000,029,768 | —- | C] () – C:\WINDOWS\System32\dllcache\divasu.dll
[2010/08/24 12:43:59 | 000,006,216 | —- | C] () – C:\WINDOWS\System32\dllcache\divaci.dll
[2010/08/24 12:42:00 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\dllcache\ativxbar.sys
[2010/08/24 12:42:00 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\dllcache\atixbar.sys
[2010/08/24 12:41:58 | 000,019,456 | —- | C] () – C:\WINDOWS\System32\dllcache\ativttxx.sys
[2010/08/24 12:41:55 | 000,009,472 | —- | C] () – C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2010/08/24 12:41:54 | 000,026,880 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2010/08/24 12:41:54 | 000,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2010/08/24 12:41:54 | 000,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitunep.sys
[2010/08/24 12:41:53 | 000,049,920 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtcap.sys
[2010/08/24 12:41:52 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2010/08/24 12:41:41 | 000,046,464 | —- | C] () – C:\WINDOWS\System32\dllcache\atibt829.sys
[2010/08/24 07:56:14 | 000,067,993 | —- | C] () – C:\Documents and Settings\Hiram\Application Data\CleanUp!.log
[2010/08/24 01:30:37 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/08/24 01:30:37 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/08/24 01:30:37 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/08/24 01:30:37 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/08/24 01:30:37 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/08/21 01:15:49 | 011,534,336 | —- | C] () – C:\Documents and Settings\Hiram\ntuser.dat
[2010/08/20 15:56:03 | 000,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/20 12:35:23 | 000,000,005 | —- | C] () – C:\zrpt.xml
[2010/08/17 12:39:45 | 000,019,979 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\MyTeamLogo.jpg
[2010/08/17 12:33:53 | 000,251,359 | —- | C] () – C:\Documents and Settings\Hiram\Desktop\Philadelphia_Eagles(1).jpg
[2010/08/17 01:04:48 | 000,000,501 | —- | C] () – C:\Documents and Settings\Hiram\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to mplayerc.exe.lnk
[2010/08/17 00:00:19 | 000,000,630 | —- | C] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/05/15 22:00:59 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/01/13 17:38:19 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/01/13 17:36:40 | 000,000,084 | —- | C] () – C:\WINDOWS\EPSPRX595.ini
[2008/12/28 02:31:43 | 000,000,028 | —- | C] () – C:\WINDOWS\System32\WFD_List.ini
[2008/12/28 01:30:08 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2008/12/23 05:05:15 | 000,000,011 | —- | C] () – C:\WINDOWS\OSA.INI
[2008/12/19 06:57:18 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/12/19 06:57:18 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/12/17 02:39:57 | 000,000,002 | —- | C] () – C:\WINDOWS\System32\Dvbpws.dll
[2008/12/10 04:15:55 | 003,086,336 | —- | C] () – C:\WINDOWS\System32\NCMedia.dll
[2008/12/10 04:15:55 | 003,086,336 | —- | C] () – C:\WINDOWS\System32\flvvideo.dll
[2008/12/10 04:15:55 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/12/10 04:15:55 | 000,383,238 | —- | C] () – C:\WINDOWS\System32\libmp3lame-0.dll
[2008/12/02 01:31:40 | 000,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2008/06/26 18:38:21 | 000,001,659 | —- | C] () – C:\WINDOWS\tefview.ini
[2008/05/31 17:59:12 | 000,038,999 | —- | C] () – C:\Documents and Settings\Hiram\Application Data\Microsoft Access.ADR
[2008/05/29 18:59:21 | 000,002,528 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2008/05/29 18:50:46 | 000,002,528 | —- | C] () – C:\Documents and Settings\Hiram\Application Data\$_hpcst$.hpc
[2007/10/17 02:52:20 | 000,002,917 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/18 05:51:41 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/09/12 04:53:27 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS5y.DLL
[2007/09/04 20:48:33 | 000,204,288 | —- | C] () – C:\Documents and Settings\Hiram\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/09/04 19:30:16 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/09/04 19:19:37 | 000,005,663 | —- | C] () – C:\WINDOWS\System32\Ludap17.ini
[2007/09/04 19:19:37 | 000,000,075 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/09/04 19:18:04 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2007/09/04 19:06:40 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2005/05/03 21:38:42 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\P17.DLL
[2004/10/05 17:37:20 | 000,258,048 | —- | C] () – C:\WINDOWS\System32\Manipulate.dll
[2003/10/02 21:48:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2003/08/07 14:01:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2002/03/21 16:39:02 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\UNACEV2.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4BF2F6B5
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
< End of report >
OTL Extras logfile created on: 9/2/2010 12:24:36 AM - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Hiram\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 346.00 Mb Available Physical Memory | 34.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.60 Gb Total Space | 175.55 Gb Free Space | 47.11% Space Free | Partition Type: NTFS
Drive D: | 36.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SATURN
Current User Name: Hiram
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] – C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\WINDOWS\system32\ieframe.DLL (Microsoft Corporation)
.js [@ = JSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\Program Files\ACD Systems\ACDSee\8.0.Pro\ACDSee8Pro.exe" "%1" (ACD Systems Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0D6D96F4-0CAF-4522-B05F-70A88EDECDFD}" = ArcSoft Print Creations
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3600_series" = Canon iP3600 series Printer Driver
"{1696C54E-599A-4BA2-9941-BB70C4727887}" = Xtranormal State - Voicepack-English-UK-Daniel
"{1771FDC8-D846-4B77-996A-C80DAD42C03F}" = OpenCASE Media Agent
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{232FDC0C-12DE-41F2-9701-27EFCA18BEF9}" = MediaJoin
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{32A3A4F4-B792-11D6-A78A-00B0D0160140}" = Java™ SE Development Kit 6 Update 14
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{467A3BF8-4C87-4E68-835C-CE5318C157C2}" = Xtranormal State - Voicepack-English-US-Tom
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{838A22DF-81CA-4452-9BDD-A1745224D960}" = Xtranormal State - Voicepack-English-UK-Serena
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{863641E8-E9B2-49DF-A096-538DF33D0442}" = ConceptDraw MINDMAP Professional
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8D2C1E44-7685-4D05-8342-B0DC6422FA47}" = Ulead Straight-to-Disc SDK
"{8EC4F64D-92E4-4274-9495-4C887D49DEC3}" = Xtranormal State
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{912536C4-273C-416F-B42C-BBC5B72114D7}" = Xtranormal State - Voicepack-English-US-Samantha
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{926C96FB-9D0A-4504-8000-C6D3A4A3118E}" = Java DB 10.4.2.1
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5C314F7-928B-44E3-A8A3-169648B1077D}" = Xtranormal State - SoundPack-Starter Kit
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C93369CB-B4E9-E095-9289-E6B5AE941033}" = Nero 7 Demo
"{CD22E980-3E4F-11DF-B0D7-005056806466}" = Google Earth Plug-in
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03E7B00-CA85-4684-9321-1888873C34BD}" = ArcSoft PhotoImpression 6
"{D28CB048-A0AB-4F98-909F-69F3F25AA87D}" = Xtranormal State - Showpak-Playgoz-Preview
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{F99F74B4-972B-4B06-B893-6B3B0DB0128B}" = ACDSee Pro
"{FC053571-8507-44E4-8B6D-AACEAB8CA57C}" = Sansa Media Converter
"Absolute MP3 Splitter_is1" = Absolute MP3 Splitter version 2.7.3
"Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AIM_6" = AIM 6
"AP Tuner 3.08" = AP Tuner 3.08
"AVG9Uninstall" = AVG Free 9.0
"AVI MPEG RM WMV Splitter_is1" = AVI/MPEG/RM/WMV Splitter 4.28
"BatchPhoto_is1" = BatchPhoto v2.3.1
"Canon iP3600 series User Registration" = Canon iP3600 series User Registration
"CANONIJPLM100" = Inkjet Printer/Scanner Extended Survey Program
"CanonMyPrinter" = Canon Utilities My Printer
"CleanUp!" = CleanUp!
"COMODO Internet Security" = COMODO Internet Security
"Device Control" = Device Control
"DjVu" = Lizardtech DjVu Control (autoinstall)
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"EAXSet" = Creative EAX Settings
"FLV Player" = FLV Player 2.0, build 23
"Free FLV to AVI Converter_is1" = Free FLV to AVI Converter V1.5
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"Free Studio_is1" = Free Studio version 4.1
"Free YouTube to Mp3 Converter_is1" = Free YouTube to Mp3 Converter version 3.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Java Web Start" = Java Web Start
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.3.4 (Standard)
"Magic ISO Maker v5.5 (build 0273)" = Magic ISO Maker v5.5 (build 0273)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaJoin" = MediaJoin
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MPE" = MyPhoneExplorer
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NoteZilla_is1" = NoteZilla 7.0
"Picasa2" = Picasa 2
"PowerISO" = PowerISO
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"SPEAKER" = Creative Speaker Settings
"SystemRequirementsLab" = System Requirements Lab
"TEFView_is1" = TEFView 2.65
"The Rosetta Stone" = The Rosetta Stone
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.17
"VLC media player" = VLC media player 0.9.6
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/31/2010 2:52:41 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/31/2010 2:52:41 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3938

Error - 8/31/2010 2:52:41 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3938

Error - 8/31/2010 9:29:02 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/31/2010 9:29:02 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 23785031

Error - 8/31/2010 9:29:02 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 23785031

Error - 9/1/2010 10:50:20 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: Received from 192.168.0.101:49152 4 Saturn.local.
Addr 192.168.0.101

Error - 9/1/2010 10:50:20 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = mDNSCoreReceiveResponse: ProbeCount 2; will rename 4 saturn.local.
Addr 192.168.0.100

Error - 9/1/2010 10:50:20 AM | Computer Name = SATURN | Source = Bonjour Service | ID = 100
Description = Local Hostname saturn.local already in use; will try saturn-2.local
instead

Error - 9/1/2010 11:49:41 PM | Computer Name = SATURN | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
gcswf32.dll, version 10.1.82.76, fault address 0x001810ab.

[ System Events ]
Error - 9/1/2010 1:20:53 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD AvgLdx86 AvgMfx86 AvgTdiX cmdGuard cmdHlp Fips intelppm IPSec MRxSmb NetBIOS NetBT OMCI
RasAcd
Rdbss
SASDIFSV
SASKUTIL
SCDEmu
Tcpip

Error - 9/1/2010 10:45:02 AM | Computer Name = SATURN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 9/1/2010 10:50:31 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM Video Capture service failed to start due
to the following error: %%1058

Error - 9/1/2010 10:50:31 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126

Error - 9/1/2010 10:50:31 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM TVTuner service failed to start due to the
following error: %%1058

Error - 9/1/2010 10:50:31 AM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM Crossbar service failed to start due to
the following error: %%1058

Error - 9/1/2010 2:01:02 PM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM Video Capture service failed to start due
to the following error: %%1058

Error - 9/1/2010 2:01:02 PM | Computer Name = SATURN | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126

Error - 9/1/2010 2:01:02 PM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM TVTuner service failed to start due to the
following error: %%1058

Error - 9/1/2010 2:01:02 PM | Computer Name = SATURN | Source = Service Control Manager | ID = 7000
Description = The WinFast TV2000 XP WDM Crossbar service failed to start due to
the following error: %%1058


< End of report >
Hi icecold240,

µTorrent

You haveµTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it. It's not the program itself but what can e downloaded with it, usually from an unknown source, that is the problem.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

I installed AVG. I dont know about the Avast and when I installed Comodo it was with the antivirus

Multiple antivirus programs do not mean more protection. It usually means less as the 2 will conflict. This can also lead to system slowdowns and lockups.

Please uninstall either AVG or Comodo Internet Security Suite. Please keep in mind that uninstalling Comodo will also result in uninstalling the firewall. If you wish to keep AVG you can always reinstall Comodo Internet Security without the antivirus portion later. That will give you the firewall back.

The Avast seems to be a remnant. We'll run the Avast removal tool just to clean things up a bit.

Download the Avast Removal Tool and save it to your desktop.
  • Double-click on the file ASWCLEAR and run it
  • When the window opens set the top box to Avast!4 Home/Profssional
  • In the second box use the browse button (small box just to the right of the second box) to navigate to the folder avast is installed in. Note: this is usually C:\Program Files\Avast
  • Be very careful which folder you choose since whatever folder is chosen will be completely deleted from your computer.
  • Click the uninstall button.
  • Please be patient as it may take a few minutes. t may not look as if anything is happening, the tool will notify you when it's done.
  • Once the uninstall has completed, reboot your computer



You have an old vulnerable version of java installed. Go to Add/Remove programs and uninstall

Java™ SE Development Kit 6 Update 14


Do not uninstall Java™ 6 Update 21



Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O4 - HKLM..\Run: [] C:\Program Files\Alwil Software\Avast4\ashDisp.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
[2010/08/27 23:02:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegCure

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Is the computer any better after uninstalling one antivirus program?

Thanks
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully. C:\Documents and Settings\All Users\Application Data\RegCure folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33237 bytes User: Hiram ->Temp folder emptied: 177937005 bytes ->Temporary Internet Files folder emptied: 6543273 bytes ->Java cache emptied: 254037 bytes ->FireFox cache emptied: 131756214 bytes ->Google Chrome cache emptied: 555362371 bytes ->Flash cache emptied: 4257777 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 11 bytes ->Flash cache emptied: 5180 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 5528081 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 173414 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 12814146 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 112094 bytes RecycleBin emptied: 740633950 bytes Total Files Cleaned = 1,560.00 mb OTL by OldTimer - Version 3.2.11.0 log created on 09022010_193904 Files\Folders moved on Reboot… File move failed. C:\WINDOWS\System32\config\systemprofile\Local Settings\Temp\WCESLog.log scheduled to be moved on reboot. Registry entries deleted on Reboot…
Hi icecold240,

Yes, computer seems to be running smoother.

Good.

The GMER log and OTL log do not show any signs of infection. I believe the problems you had were related to the 2 antivirus conflicting.

If no other problems we'll clan up the tools I had you download.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER.exe

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall
Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

If you kept AVG and uninstalled Comodo Internet Security you can reinstall it without the antivirus. See here for more details.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


We'll keep this thread ope for a couple of days. Please post back if you have any problems or if the origonal problem reappears.

Take care

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI