This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ipak.exe/volim.exe still inside my laptop [Solved]

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi!
I have just stumbled here in your forum looking for help/tips to get rid of this Ipak.exe file. I first saw this after my brother used his flashdrive to my laptop. Then all of a sudden, all my folder files in my external hard drive were read by my anitvirus as a .exe file and kept blocking my files.
I was forced to reformat all my drives including the laptop. Even my brother's flashdrive. Then again when all is already reformatted and re-installed. The reformatted flashdrive was used by my brother to transfer some of my files back to my laptop I saw the Ipak folder again. weird thing is we both use same anitivirus both fully updated and yet only my laptop is affected by it. after the transfer of my files I again reformatted the flashdrive to make sure my brother's pc won't get affected.

Now I want to get rid of that Ipak.exe file from my computer. here is from HiJack log file. Please help me.
I will also highlight the filepath being detected by my antivirus.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:41:12 AM, on 6/21/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Drive Space Indicator\DrvSpace.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\WINDOWS\system32\taskbarshuffle.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\UnHackMe\hackmon.exe
C:\ppApps\VisualTaskTips\VisualTaskTips.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\AVG\AVG2012\avgidsagent.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Sandboxie\SandboxieRpcSs.exe
C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe
C:\Program Files\BitTorrent\BitTorrent.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Sandboxie\SandboxieCrypto.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents\My Documents\Downloads\HiJackThis.exe
C:\Program Files\Sandboxie\SbieSvc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = IE
R3 - URLSearchHook: BitTorrentBar2 Toolbar - {656461ef-40f6-4115-9ff1-bced9812ccbb} - C:\Program Files\BitTorrentBar2\prxtbBitT.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: BitTorrentBar2 - {656461ef-40f6-4115-9ff1-bced9812ccbb} - C:\Program Files\BitTorrentBar2\prxtbBitT.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O3 - Toolbar: BitTorrentBar2 Toolbar - {656461ef-40f6-4115-9ff1-bced9812ccbb} - C:\Program Files\BitTorrentBar2\prxtbBitT.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [DriveSpace] C:\Program Files\Drive Space Indicator\DrvSpace.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RemoveIT Pro v7Ent] C:\Program Files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [Taskbar Shuffle] C:\WINDOWS\system32\taskbarshuffle.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [UnHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Visual Task Tips.lnk = C:\ppApps\VisualTaskTips\VisualTaskTips.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AutoExNT - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 10108 bytes

also inside my antivirus quarantine

"Virus identified Worm/Autoit.ECL";"c:\System Volume Information\_restore{4223E946-4233-4501-BB21-AC755593AA6D}\RP19\A0022351.exe";"Moved to Virus Vault";"6/21/2012, 12:12:43 AM";"file";"C:\WINDOWS\system32\svchost.exe"
"Virus identified Worm/Autoit.ECL";"c:\System Volume Information\_restore{4223E946-4233-4501-BB21-AC755593AA6D}\RP19\A0022351.exe";"Infected";"6/19/2012, 6:20:09 AM";"file";"C:\WINDOWS\system32\svchost.exe"
"Virus identified Worm/Autoit.ECL";"c:\System Volume Information\_restore{4223E946-4233-4501-BB21-AC755593AA6D}\RP19\A0022351.exe";"Infected";"6/19/2012, 6:02:42 AM";"file";"C:\WINDOWS\system32\svchost.exe"
"Trojan horse Cryptic.PH";"c:\Users\Administrator\ctfmon.exe";"Infected";"6/19/2012, 12:04:44 AM";"file";"C:\WINDOWS\system32\MRT.exe"
"Trojan horse Cryptic.PH";"c:\Users\Administrator\ctfmon.exe";"Moved to Virus Vault";"6/19/2012, 12:04:13 AM";"file";"C:\WINDOWS\system32\MRT.exe"
"Virus identified Worm/Autoit.ECL";"c:\WINDOWS\system32\UpxGui.exe";"Moved to Virus Vault";"6/18/2012, 11:32:50 PM";"file";"C:\WINDOWS\explorer.exe"

"Warning";"Found registry key with reference to infected file C:\Users\Administrator\ctfmon.exe";"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Taskman";"N/A";"6/19/2012, 12:04:29 AM"
"Infection";"Trojan horse Cryptic.PH";"c:\Users\Administrator\ctfmon.exe";"N/A";"6/19/2012, 12:04:29 AM"
"Infection";"Virus identified Worm/Autoit.ECL";"c:\System Volume Information\_restore{4223E946-4233-4501-BB21-AC755593AA6D}\RP19\A0022351.exe";"N/A";"6/21/2012, 12:30:35 AM"


"";"F:\ipak\volim.exe";"Trojan horse Cryptic.PH";"Infected" (my brother's flashdrive was detected)

mmm.exe was also found and was quarantined by my antivirus.

That's all I guess. Thanks.

=ShayeDrake
Hello ShayeDrake and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again ShayeDrake

P2P - I see you have P2P software, (BitTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection.

It almost certainly contributed to your current situation as the infection on your computer is a worm that is passed from computer to computer using P2P and networking.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Start, Settings, Control Panel, Add or Remove Programs

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Please download Flash_Disinfector.exe by sUBs from here and save it to your desktop.

This tool will protect both the flash drive and the PC by disabling the autorun feature. Disabling autorun won't prevent infected files from getting into your removable drive but it does prevent these files from launching automatically. Without getting launched, these infected files lie dormant on the drive, and are pretty much harmless unless you double click on them.

Run this tool on all usb drives and computers:
  • double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • the utility may ask you to insert your flash drive and/or other removable drives: please do so and allow the utility to clean up those drives as well.
  • hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • wait until it has finished scanning and then exit the program.
  • reboot your computer when done.
Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder…it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.

===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
Satchfan
Hello again ShayeDrake

P2P - I see you have P2P software, (BitTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection.

It almost certainly contributed to your current situation as the infection on your computer is a worm that is passed from computer to computer using P2P and networking.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Start, Settings, Control Panel, Add or Remove Programs

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Please download Flash_Disinfector.exe by sUBs from here and save it to your desktop.

This tool will protect both the flash drive and the PC by disabling the autorun feature. Disabling autorun won't prevent infected files from getting into your removable drive but it does prevent these files from launching automatically. Without getting launched, these infected files lie dormant on the drive, and are pretty much harmless unless you double click on them.

Run this tool on all usb drives and computers:
  • double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • the utility may ask you to insert your flash drive and/or other removable drives: please do so and allow the utility to clean up those drives as well.
  • hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • wait until it has finished scanning and then exit the program.
  • reboot your computer when done.
Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder…it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.

===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
Satchfan
Hello SatchFan. Thank You for replying as soon as possible. Before I start with the whole process. I would like to verify first one of my most concerns. Please correct me if I get it wrong. 1. Flash Drive of my brother can be dis infected as you assured including the unit (laptop) I am using right now will be dis infected in the process of course. 2. Yes, I will uninstall the P2P program I have 3. IF I will also insert a different flash drive and also my other external hard drive. I understand they will also be dis infected in the process "Will this process affect the files inside of the two other drives I mentioned above? Like be deleted or never again be accessed (irrecoverable?). Because the file inside my unit (laptop) and inside my brother's Flash Drive IS not as important as with the other two Drives I mentioned above. 4. I seriously want to have a cleaned unit and external paraphernalia too. 5. I am looking forward for our joint force in removing these issues. ShayeDrake

IF I will also insert a different flash drive and also my other external hard drive. I understand they will also be dis infected in the process "Will this process affect the files inside of the two other drives I mentioned above?

Running Flash Disinfector will not protect any files or folders on any drive.

What it does is stop any bad processes automatically starting up when you select the drive as the one you want to use.

I would suggest that you restrict yourself at this time to using the hard drive on the computer that you want cleaned.
Good Day to You, SatchFan.

Again, thank you for your fast reply.

First things first. I did Uninstalled my P2P program as I said earlier and followed your suggestion.

If the two other drives were infected also or not, comes second. Our main target is the unit (laptop) and my brother's flash drive (where I think this started).

I attached the OTL the next post will be the Extra .Txt file.

Here's what happened after I ran the two program I was asked to download.
In Flash Disinfector program my antivirus detected it and was asked to allow it or not. Of course I allowed because if not I can not run it.
All went well, I think. It scanned my unit (laptop) and my brother's flash drive then I reboot my unit (laptop).
Next I ran OTL as instructed and followed the steps accordingly. When I read the txt file I saw my P2P Program again, so I checked if I was able to uninstall the program and yes it was already uninstalled, must be a leftover folder (I thought) so I followed the path and deleted it. re ran OTL program and now I'm posting it..

Attachments:

Here is the second file *(Extra .txt file) I made two post just to be sure. Please tell me what we have to do next or if I made any mistakes. Again, Thank you SatchFan ShayeDrake

Attachments:

Hi ShayeDrake

Please leave your flash drive plugged in for these scans.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O33 - MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\Shell\AutoRun\command - "" = F:\ipak\\volim.exe
    O33 - MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\Shell\explore\command - "" = F:\ipak\volim.exe
    O33 - MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\Shell\install\command - "" = F:\ipak\volim.exe
    O33 - MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\Shell\open\command - "" = F:\ipak\volim.exe
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\BitTorrent\BitTorrent.exe" =-
    
    :Commands
    [PURITY] 
    [EMPTYTEMP]
    [EMPTYFLASH]
    [RESETHOSTS] 
    [CREATERESTOREPOINT]
    [CLEARALLRESTOREPOINTS]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

=============================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe DIRECTLY to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Logs to include in the next post:

OTL fix log
New OTL log
ComboFix.txt


Please do not attach them - copy and paste them in the post

Thanks

Satchfan
Hello again, SatchFan.

Forgive me. I realized I sent you a reply with file not pasted but attached when you replied back. I'm really sorry it slipped my mind.


Anyway, back to our joint force. here's what happened:
> copied and pasted in custom scan
>clicked Run Fix
>reboot, done
>>about the new OTL log referred (5th bullet under Run OTL) . I am not sure about it. But from what I understood is I am being asked to run a new scan after the Run Fix is done after the system reboots.
>Ran a new scan with checked box (scan all users)
>> OTL Fix Log I ran earlier, I just followed the exact direction I was given. But when I was doing a new run after the Run Fix and reboot, I remember that I was checked to do a run scan with the (scan all users) is checked. So, I did the same thing for the new OTL Log.
>>LOP check or Purity was never used from the start. Meaning from when we started I was asked not to change anything unless instructed to.

I actually fell asleep. I took ages for combofix to finish its task. Here is the OTL Fix Log first:


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
File F:\ipak\\volim.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
File F:\ipak\volim.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
File F:\ipak\volim.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f605b1c-b826-11e1-a11d-0018f3295486}\ not found.
File F:\ipak\volim.exe not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BitTorrent\BitTorrent.exe deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 357570 bytes
->Temporary Internet Files folder emptied: 2295678 bytes
->Google Chrome cache emptied: 22123398 bytes
->Flash cache emptied: 15257946 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56478 bytes

User: LocalService
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2434812 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 53072094 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 91.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.52.0 log created on 06252012_031231

Files\Folders moved on Reboot…
C:\WINDOWS\temp\Perflib_Perfdata_d1c.dat moved successfully.

Registry entries deleted on Reboot…


NEXT

The New OTL Log

OTL logfile created on: 6/25/2012 3:36:01 AM - Run 2
OTL by OldTimer - Version 3.2.52.0 Folder = D:\Documents\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00003409 | Country: Republic of the Philippines | Language: ENP | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 63.96% Memory free
3.84 Gb Paging File | 3.04 Gb Available in Paging File | 79.12% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 17.70 Gb Free Space | 60.44% Space Free | Partition Type: NTFS
Drive D: | 39.14 Gb Total Space | 4.19 Gb Free Space | 10.69% Space Free | Partition Type: NTFS
Drive F: | 7.50 Gb Total Space | 5.20 Gb Free Space | 69.37% Space Free | Partition Type: FAT32

Computer Name: EyeC4Ndy | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/24 07:25:57 | 000,596,480 | —- | M] (OldTimer Tools) – D:\Documents\Desktop\OTL.exe
PRC - [2012/06/07 16:14:45 | 001,239,576 | —- | M] (Google Inc.) – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2012/04/05 05:12:34 | 002,587,008 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/02/14 04:53:38 | 000,193,288 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/11/23 21:17:14 | 000,018,704 | —- | M] (SANDBOXIE L.T.D) – C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe
PRC - [2011/11/23 21:17:14 | 000,015,632 | —- | M] (SANDBOXIE L.T.D) – C:\Program Files\Sandboxie\SandboxieCrypto.exe
PRC - [2011/11/23 21:17:12 | 000,024,336 | —- | M] (SANDBOXIE L.T.D) – C:\Program Files\Sandboxie\SandboxieRpcSs.exe
PRC - [2011/11/23 21:17:10 | 000,442,640 | —- | M] (SANDBOXIE L.T.D) – C:\Program Files\Sandboxie\SbieCtrl.exe
PRC - [2011/11/23 21:17:10 | 000,072,976 | —- | M] (SANDBOXIE L.T.D) – C:\Program Files\Sandboxie\SbieSvc.exe
PRC - [2008/08/26 15:58:12 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/08/26 15:58:10 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/05/17 08:20:58 | 000,371,626 | —- | M] () – C:\Program Files\Drive Space Indicator\DrvSpace.exe
PRC - [2008/05/05 17:00:00 | 001,572,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/05/02 14:15:48 | 000,015,872 | —- | M] () – C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2008/04/17 01:28:48 | 000,818,176 | —- | M] (Jay Elaraj) – C:\WINDOWS\system32\taskbarshuffle.exe
PRC - [2008/03/09 20:12:04 | 000,061,440 | —- | M] (VisualTaskTips.com) – C:\ppApps\VisualTaskTips\VisualTaskTips.exe
PRC - [2007/08/25 12:00:00 | 000,210,432 | —- | M] () – C:\WINDOWS\system32\Notepad2.exe
PRC - [2007/05/14 14:23:32 | 001,191,936 | —- | M] (Dell Inc) – C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2007/05/10 10:22:32 | 000,405,504 | —- | M] (SigmaTel, Inc.) – C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe
PRC - [2006/08/04 14:59:16 | 000,062,976 | —- | M] (Alexander Avdonin) – C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/20 02:18:08 | 004,050,944 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\1.0.0.2\libGLESv2.dll
MOD - [2012/06/20 02:18:08 | 000,100,864 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\1.0.0.2\libEGL.dll
MOD - [2012/06/18 23:54:34 | 005,771,264 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\83ae14d3e7c9e270ab08b5ade09dd514\System.Xml.ni.dll
MOD - [2012/06/18 23:48:47 | 008,286,208 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\0bef22abea49ae8cc98b8ebcba10f07a\System.ni.dll
MOD - [2012/06/18 23:48:10 | 011,436,032 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\709b207f778a3f7053329a6f3e17859c\mscorlib.ni.dll
MOD - [2012/06/07 16:14:43 | 000,441,880 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\ppgooglenaclpluginchrome.dll
MOD - [2012/06/07 16:14:42 | 003,922,456 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\pdf.dll
MOD - [2012/06/07 16:13:16 | 000,134,696 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\avutil-51.dll
MOD - [2012/06/07 16:13:15 | 000,250,408 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\avformat-54.dll
MOD - [2012/06/07 16:13:14 | 002,375,720 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\avcodec-54.dll
MOD - [2012/06/07 15:23:19 | 009,252,040 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
MOD - [2011/11/03 23:28:36 | 001,292,288 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2008/05/17 08:20:58 | 000,371,626 | —- | M] () – C:\Program Files\Drive Space Indicator\DrvSpace.exe
MOD - [2008/05/05 17:00:00 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2008/05/05 17:00:00 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2008/05/02 14:15:48 | 000,015,872 | —- | M] () – C:\Program Files\Unlocker\UnlockerAssistant.exe
MOD - [2008/05/02 14:15:36 | 000,004,608 | —- | M] () – C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2008/04/13 15:32:14 | 000,165,376 | —- | M] () – C:\WINDOWS\system32\tbhookin.dll
MOD - [2008/03/09 20:11:56 | 000,008,192 | —- | M] () – C:\ppApps\VisualTaskTips\VttHooks.dll
MOD - [2007/10/17 20:32:24 | 000,106,496 | —- | M] () – C:\WINDOWS\system32\ShellExt\FolderSize.dll
MOD - [2007/10/09 19:17:44 | 000,139,264 | —- | M] () – C:\WINDOWS\system32\preflib.dll
MOD - [2007/10/09 19:17:36 | 000,753,664 | —- | M] () – C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2007/08/25 12:00:00 | 000,210,432 | —- | M] () – C:\WINDOWS\system32\Notepad2.exe
MOD - [2007/05/14 14:24:00 | 000,098,304 | —- | M] () – C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2007/03/31 04:30:46 | 000,122,880 | —- | M] () – C:\WINDOWS\system32\ShellExt\FileExtToggle.dll
MOD - [2007/03/31 04:27:44 | 000,126,976 | —- | M] () – C:\WINDOWS\system32\ShellExt\HiddenFilesToggle.dll
MOD - [2007/03/31 04:20:28 | 000,122,880 | —- | M] () – C:\WINDOWS\system32\ShellExt\BrowserBack.dll
MOD - [2007/03/31 04:14:18 | 000,122,880 | —- | M] () – C:\WINDOWS\system32\ShellExt\SelectAll.dll
MOD - [2005/10/13 13:53:36 | 000,090,223 | —- | M] () – C:\Program Files\Dell\QuickSet\preflibcl.dll
MOD - [2004/08/10 14:00:00 | 000,268,288 | —- | M] () – C:\WINDOWS\system32\sbe.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – %SystemRoot%\System32\hidserv.dll – (HidServ)
SRV - File not found [Auto | Stopped] – C:\WINDOWS\system32\AutoExNT.Exe – (AutoExNT)
SRV - [2012/06/18 22:30:30 | 000,257,224 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/30 09:44:38 | 005,106,744 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG2012\avgidsagent.exe – (AVGIDSAgent)
SRV - [2012/02/14 04:53:38 | 000,193,288 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/11/23 21:17:10 | 000,072,976 | —- | M] (SANDBOXIE L.T.D) [Auto | Running] – C:\Program Files\Sandboxie\SbieSvc.exe – (SbieSvc)
SRV - [2008/08/26 15:58:12 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\vfhuhmou.sys – (vfhuhmou)
DRV - File not found [Kernel | Boot | Stopped] – system32\DRIVERS\usbohci.sys – (usbohci)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\UIUSYS.SYS – (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - [2012/06/19 05:36:09 | 000,035,816 | —- | M] (Greatis Software) [Kernel | Boot | Unknown] – C:\WINDOWS\system32\drivers\Partizan.sys – (Partizan)
DRV - [2012/04/19 04:50:26 | 000,024,896 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\avgidshx.sys – (AVGIDSHX)
DRV - [2012/03/19 05:17:28 | 000,301,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2012/02/22 05:25:32 | 000,235,216 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2012/01/31 04:46:50 | 000,031,952 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\avgrkx86.sys – (Avgrkx86)
DRV - [2011/12/23 13:32:14 | 000,041,040 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2011/12/23 13:32:08 | 000,017,232 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\avgidsshimx.sys – (AVGIDSShim)
DRV - [2011/12/23 13:32:06 | 000,024,144 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\avgidsfilterx.sys – (AVGIDSFilter)
DRV - [2011/12/23 13:32:00 | 000,139,856 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\avgidsdriverx.sys – (AVGIDSDriver)
DRV - [2011/11/23 21:17:08 | 000,131,856 | —- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] – C:\Program Files\Sandboxie\SbieDrv.sys – (SbieDrv)
DRV - [2008/05/05 17:00:00 | 000,088,320 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnkipx.sys – (NwlnkIpx)
DRV - [2008/05/05 17:00:00 | 000,063,232 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnknb.sys – (NwlnkNb)
DRV - [2008/05/05 17:00:00 | 000,055,936 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnkspx.sys – (NwlnkSpx)
DRV - [2007/10/09 19:17:42 | 001,123,328 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/05/21 15:29:26 | 000,235,648 | R— | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8187.sys – (RTLWUSB)
DRV - [2007/05/17 15:46:00 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/05/17 15:45:42 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/05/17 15:45:36 | 000,042,496 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2007/05/10 10:24:34 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2006/11/21 04:25:44 | 000,045,568 | R— | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\bcm4sbxp.sys – (bcm4sbxp)
DRV - [2006/07/19 19:27:26 | 000,013,568 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\L8042Kbd.sys – (L8042Kbd)
DRV - [2005/08/12 17:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\APPDRV.SYS – (APPDRV)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-823518204-616249376-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-823518204-616249376-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKU\S-1-5-21-823518204-616249376-1606980848-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-823518204-616249376-1606980848-500\..\SearchScopes,DefaultScope = {9EA44D8B-84D5-478A-9639-9E066F9F50A7}
IE - HKU\S-1-5-21-823518204-616249376-1606980848-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-823518204-616249376-1606980848-500\..\SearchScopes\{9EA44D8B-84D5-478A-9639-9E066F9F50A7}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKU\S-1-5-21-823518204-616249376-1606980848-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\npctrl.1.0.30401.0.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Administrator\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Administrator\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/06/18 22:56:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/06/18 22:56:08 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\npctrl.1.0.30401.0.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Administrator\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Crystal Saga = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ccbadcdoippjkpjckifngelnbjanhcak\1.4_0\
CHR - Extension: Google Search = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Metal Slug 3 = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\
CHR - Extension: AVG Safe Search = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: Bleach Ichigo = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kikkflgioiojgepdmooipgceijnfffpn\1_0\
CHR - Extension: Advanced Extensions = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\knchccdpckooledklhnooegnniofcfip\1.1_1\
CHR - Extension: AVG Do Not Track = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: Gmail = C:\Users\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/06/25 03:12:58 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DriveSpace] C:\Program Files\Drive Space Indicator\DrvSpace.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SystemTray] C:\WINDOWS\System32\systray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKU\S-1-5-21-823518204-616249376-1606980848-500..\Run: [RemoveIT Pro v7Ent] C:\Program Files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe File not found
O4 - HKU\S-1-5-21-823518204-616249376-1606980848-500..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKU\S-1-5-21-823518204-616249376-1606980848-500..\Run: [Taskbar Shuffle] C:\WINDOWS\system32\taskbarshuffle.exe (Jay Elaraj)
O4 - HKU\S-1-5-21-823518204-616249376-1606980848-500..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
O4 - HKU\.DEFAULT..\RunOnce: [NewUser] C:\WINDOWS\LastXP\NewUser.cmd ()
O4 - HKU\S-1-5-18..\RunOnce: [NewUser] C:\WINDOWS\LastXP\NewUser.cmd ()
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O4 - Startup: C:\Users\Administrator\Start Menu\Programs\Startup\Visual Task Tips.lnk = C:\ppApps\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-21-823518204-616249376-1606980848-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-823518204-616249376-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKU\S-1-5-21-823518204-616249376-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKU\S-1-5-21-823518204-616249376-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKU\Sandbox_Administrator_DefaultBox\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windows…b?1340028728796 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{05FBE011-1AA5-4438-8577-E9ADADCDA7A1}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Users\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/06/15 04:55:31 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2012/06/24 20:09:46 | 000,000,000 | RHSD | M] - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2012/06/24 20:09:46 | 000,000,000 | RHSD | M] - D:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2012/06/24 20:09:48 | 000,000,000 | RHSD | M] - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O34 - HKLM BootExecute: (Partizan)
O34 - HKLM BootExecute: (s2\{b6a3a84a-b69d-11e1-98da-806d6172696f}\Shell)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/25 03:21:47 | 004,567,243 | —- | C] (Swearware) – D:\Documents\Desktop\ComboFix.exe
[2012/06/24 20:09:46 | 000,000,000 | RHSD | C] – C:\autorun.inf
[2012/06/24 07:25:00 | 000,596,480 | —- | C] (OldTimer Tools) – D:\Documents\Desktop\OTL.exe
[2012/06/21 14:14:07 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\vlc
[2012/06/21 14:10:44 | 000,000,000 | —D | C] – C:\Program Files\vlc-2.0.1
[2012/06/20 12:34:37 | 000,000,000 | —D | C] – C:\Program Files\Wacraft III
[2012/06/20 12:29:23 | 000,000,000 | —D | C] – C:\Program Files\InCode Solutions
[2012/06/20 02:20:09 | 000,000,000 | —D | C] – D:\Documents\My Documents\Downloads
[2012/06/20 02:11:04 | 000,000,000 | —D | C] – C:\Users\Administrator\Start Menu\Programs\Google Chrome
[2012/06/20 01:57:56 | 000,000,000 | —D | C] – C:\Users\Administrator\Local Settings\Application Data\Google
[2012/06/20 01:57:09 | 000,000,000 | —D | C] – C:\Users\Administrator\Local Settings\Application Data\Deployment
[2012/06/19 05:36:09 | 000,039,184 | —- | C] (Greatis Software) – C:\WINDOWS\System32\Partizan.exe
[2012/06/19 05:36:09 | 000,035,816 | —- | C] (Greatis Software) – C:\WINDOWS\System32\drivers\Partizan.sys
[2012/06/19 05:35:58 | 000,000,000 | —D | C] – D:\Documents\My Documents\RegRun2
[2012/06/19 05:35:48 | 000,012,800 | —- | C] (Greatis Software, LLC.) – C:\WINDOWS\System32\drivers\UnHackMeDrv.sys
[2012/06/19 05:35:48 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\UnHackMe
[2012/06/19 05:35:48 | 000,000,000 | —D | C] – C:\Users\All Users\Documents\regruninfo
[2012/06/19 05:35:39 | 000,000,000 | —D | C] – C:\Program Files\UnHackMe
[2012/06/19 04:14:27 | 000,000,000 | —D | C] – C:\Users\Administrator\Start Menu\Programs\Accessories
[2012/06/19 00:13:44 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2012/06/19 00:12:27 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2012/06/19 00:12:13 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2012/06/19 00:12:12 | 011,111,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2012/06/19 00:12:12 | 002,000,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2012/06/19 00:12:12 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2012/06/19 00:12:12 | 000,629,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2012/06/19 00:10:04 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2012/06/18 23:55:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2012/06/18 23:47:41 | 000,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2012/06/18 23:23:18 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2012/06/18 22:58:27 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\AVG2012
[2012/06/18 22:57:03 | 000,000,000 | -H-D | C] – C:\Users\All Users\Application Data\Common Files
[2012/06/18 22:56:50 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\AVG
[2012/06/18 22:56:38 | 000,456,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2012/06/18 22:56:26 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2012/06/18 22:55:59 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/06/18 22:55:59 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\AVG2012
[2012/06/18 22:55:59 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2012/06/18 22:55:51 | 000,759,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2012/06/18 22:55:11 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/06/18 22:55:09 | 000,235,648 | R— | C] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\drivers\RTL8187.sys
[2012/06/18 22:53:13 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2012/06/18 22:45:07 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2012/06/18 22:45:05 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\MFAData
[2012/06/18 22:44:48 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2012/06/18 22:44:47 | 003,879,304 | —- | C] (AVG Technologies) – D:\Documents\My Documents\avg_free_stb_all_2012_2180_cnet.exe
[2012/06/18 22:43:33 | 000,590,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2012/06/18 22:43:12 | 000,978,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2012/06/18 22:43:12 | 000,954,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2012/06/18 22:43:12 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2012/06/18 22:41:13 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2012/06/18 22:40:25 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2012/06/18 22:39:47 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2012/06/18 22:38:35 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2012/06/18 22:38:35 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2012/06/18 22:37:03 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2012/06/18 22:36:30 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\Adobe
[2012/06/18 22:36:18 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\Adobe
[2012/06/18 22:36:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2012/06/18 22:36:05 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2012/06/18 22:34:19 | 000,000,000 | —D | C] – C:\Users\Administrator\Local Settings\Application Data\Adobe
[2012/06/18 22:30:48 | 002,148,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2012/06/18 22:30:48 | 000,730,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2012/06/18 22:30:47 | 002,192,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2012/06/18 22:30:47 | 002,026,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2012/06/18 22:30:37 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\Adobe
[2012/06/18 22:30:29 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/06/18 22:30:29 | 000,070,344 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/06/18 22:28:45 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2012/06/18 22:28:07 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2012/06/18 22:27:50 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\Macromedia
[2012/06/18 22:27:14 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2012/06/18 22:27:08 | 000,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rmcast.sys
[2012/06/18 22:15:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2012/06/18 22:15:07 | 000,000,000 | -H-D | C] – C:\WINDOWS\$hf_mig$
[2012/06/18 22:12:42 | 000,015,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2012/06/18 22:12:42 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2012/06/18 18:27:55 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2012/06/18 05:35:08 | 000,000,000 | R–D | C] – C:\Sandbox
[2012/06/18 05:28:44 | 000,000,000 | R–D | C] – C:\Users\Administrator\Start Menu\Programs\Administrative Tools
[2012/06/18 05:07:54 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\Sandboxie
[2012/06/18 05:07:54 | 000,000,000 | —D | C] – C:\Program Files\Sandboxie
[2012/06/18 05:03:48 | 000,000,000 | —D | C] – C:\Users\Administrator\Local Settings\Application Data\SupportSoft
[2012/06/18 05:03:22 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\SupportSoft
[2012/06/18 05:03:19 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\Dell Support Center
[2012/06/18 05:03:18 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\PCDr
[2012/06/18 05:03:18 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\PC-Doctor
[2012/06/18 05:02:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\supportsoft
[2012/06/18 05:02:47 | 000,000,000 | —D | C] – C:\Program Files\Dell Support Center
[2012/06/18 05:02:27 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\Dell
[2012/06/18 04:59:37 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2012/06/18 04:57:08 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\Dell Wireless
[2012/06/18 04:57:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ReinstallBackups
[2012/06/18 04:56:59 | 000,806,912 | —- | C] (Dell Inc.) – C:\WINDOWS\System32\BCMLogon.dll
[2012/06/18 04:56:57 | 000,033,664 | —- | C] (CACE Technologies) – C:\WINDOWS\System32\drivers\BCMWLNPF.SYS
[2012/06/18 04:56:56 | 004,743,168 | —- | C] (Dell Inc.) – C:\WINDOWS\System32\BCMWLCPL.CPL
[2012/06/18 04:56:56 | 002,682,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vcredist_x86.exe
[2012/06/18 04:56:56 | 000,278,528 | —- | C] (Dell Inc.) – C:\WINDOWS\System32\bcmwlu00.exe
[2012/06/18 04:56:56 | 000,069,632 | —- | C] (CACE Technologies) – C:\WINDOWS\System32\bcmwlpkt.dll
[2012/06/18 04:56:56 | 000,065,536 | —- | C] (Broadcom Corporation) – C:\WINDOWS\System32\wltrynt.dll
[2012/06/18 04:56:55 | 002,670,592 | —- | C] (BCGSoft Ltd) – C:\WINDOWS\System32\WLBCGCBPRO731.DLL
[2012/06/17 10:44:28 | 000,000,000 | R–D | C] – D:\Documents\My Documents\My Videos
[2012/06/17 10:44:28 | 000,000,000 | R–D | C] – D:\Documents\My Documents\My Pictures
[2012/06/17 10:44:28 | 000,000,000 | R–D | C] – D:\Documents\My Documents\My Music
[2012/06/17 10:44:27 | 000,000,000 | R–D | C] – C:\Users\All Users\Documents\My Videos
[2012/06/16 12:55:07 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\evntagnt.dll
[2012/06/16 12:55:07 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\evntwin.exe
[2012/06/16 12:55:07 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\evntcmd.exe
[2012/06/16 12:55:07 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\snmpmib.dll
[2012/06/16 12:55:06 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\hostmib.dll
[2012/06/16 12:55:05 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\lmmib2.dll
[2012/06/16 11:32:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2012/06/15 12:45:39 | 000,000,000 | —D | C] – C:\Program Files\CONEXANT
[2012/06/15 12:45:36 | 004,952,064 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\stacgui.cpl
[2012/06/15 12:45:36 | 001,601,536 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\stlang.dll
[2012/06/15 12:45:36 | 000,405,504 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe
[2012/06/15 12:45:36 | 000,000,000 | —D | C] – C:\Program Files\Sigmatel
[2012/06/15 12:45:33 | 000,146,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\portcls.sys
[2012/06/15 12:45:33 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ksproxy.ax
[2012/06/15 12:45:33 | 000,060,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\drmk.sys
[2012/06/15 12:45:33 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ksuser.dll
[2012/06/15 12:44:30 | 000,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\enum1394.sys
[2012/06/15 12:43:17 | 000,920,088 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\igxpun.exe
[2012/06/15 12:43:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\x64
[2012/06/15 12:43:05 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\difxapi.dll
[2012/06/15 12:43:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2012/06/15 12:42:31 | 000,083,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\usbui.dll
[2012/06/15 12:42:08 | 000,014,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\battc.sys
[2012/06/15 12:37:57 | 000,000,000 | R–D | C] – C:\Users\All Users\Documents\My Music
[2012/06/15 12:37:32 | 000,000,000 | -HSD | C] – C:\WINDOWS\Installer
[2012/06/15 12:37:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ODBC
[2012/06/15 12:37:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeechEngines
[2012/06/15 12:37:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Microsoft Shared
[2012/06/15 12:37:24 | 000,000,000 | —D | C] – C:\Program Files
[2012/06/15 12:37:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files
[2012/06/15 12:37:19 | 000,006,144 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdtuq.dll
[2012/06/15 12:37:19 | 000,006,144 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdtuf.dll
[2012/06/15 12:37:19 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdazel.dll
[2012/06/15 12:37:16 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbduzb.dll
[2012/06/15 12:37:16 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdtat.dll
[2012/06/15 12:37:16 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdmon.dll
[2012/06/15 12:37:16 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdkyr.dll
[2012/06/15 12:37:16 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdaze.dll
[2012/06/15 12:37:15 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdycc.dll
[2012/06/15 12:37:15 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdur.dll
[2012/06/15 12:37:15 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdru1.dll
[2012/06/15 12:37:15 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdru.dll
[2012/06/15 12:37:15 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdkaz.dll
[2012/06/15 12:37:15 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbu.dll
[2012/06/15 12:37:15 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdblr.dll
[2012/06/15 12:37:12 | 000,008,192 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdhept.dll
[2012/06/15 12:37:12 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdhela3.dll
[2012/06/15 12:37:12 | 000,006,144 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdhela2.dll
[2012/06/15 12:37:12 | 000,006,144 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdgkl.dll
[2012/06/15 12:37:12 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdhe319.dll
[2012/06/15 12:37:12 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdhe220.dll
[2012/06/15 12:37:12 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdhe.dll
[2012/06/15 12:37:10 | 000,006,144 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdlv1.dll
[2012/06/15 12:37:10 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdlt1.dll
[2012/06/15 12:37:10 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdlt.dll
[2012/06/15 12:37:09 | 000,006,144 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdlv.dll
[2012/06/15 12:37:09 | 000,006,144 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdest.dll
[2012/06/15 12:37:07 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdsl1.dll
[2012/06/15 12:37:07 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdsl.dll
[2012/06/15 12:37:07 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpl.dll
[2012/06/15 12:37:07 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdhu.dll
[2012/06/15 12:37:07 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdcz2.dll
[2012/06/15 12:37:07 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdro.dll
[2012/06/15 12:37:07 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpl1.dll
[2012/06/15 12:37:07 | 000,005,632 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdhu1.dll
[2012/06/15 12:37:06 | 000,007,168 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdcz.dll
[2012/06/15 12:37:06 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdycl.dll
[2012/06/15 12:37:06 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdcz1.dll
[2012/06/15 12:37:06 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdcr.dll
[2012/06/15 12:37:06 | 000,006,656 | R— | C] (Microsoft Corporation) – C:\WINDOWS\System32\KBDAL.DLL
[2012/06/15 12:36:59 | 000,176,157 | —- | C] (Digi International, Inc.) – C:\WINDOWS\System32\dgrpsetu.dll
[2012/06/15 12:36:59 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\irclass.dll
[2012/06/15 12:36:58 | 000,103,424 | —- | C] (Equinox Systems Inc.) – C:\WINDOWS\System32\EqnClass.Dll
[2012/06/15 12:36:58 | 000,085,020 | —- | C] (Digi International) – C:\WINDOWS\System32\dgsetup.dll
[2012/06/15 12:36:58 | 000,024,661 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\spxcoins.dll
[2012/06/15 12:36:58 | 000,013,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\WFWNET.DRV
[2012/06/15 12:36:57 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\OLESVR.DLL
[2012/06/15 12:36:57 | 000,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\TAPI.DLL
[2012/06/15 12:36:57 | 000,009,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\VER.DLL
[2012/06/15 12:36:57 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\SHELL.DLL
[2012/06/15 12:36:57 | 000,004,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\TIMER.DRV
[2012/06/15 12:36:57 | 000,003,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\SYSTEM.DRV
[2012/06/15 12:36:57 | 000,002,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\VGA.DRV
[2012/06/15 12:36:57 | 000,001,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\SOUND.DRV
[2012/06/15 12:36:56 | 000,126,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MSVIDEO.DLL
[2012/06/15 12:36:56 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\OLECLI.DLL
[2012/06/15 12:36:56 | 000,073,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MCIAVI.DRV
[2012/06/15 12:36:56 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MCIWAVE.DRV
[2012/06/15 12:36:56 | 000,025,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MCISEQ.DRV
[2012/06/15 12:36:56 | 000,002,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MOUSE.DRV
[2012/06/15 12:36:56 | 000,002,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\KEYBOARD.DRV
[2012/06/15 12:36:56 | 000,001,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MMTASK.TSK
[2012/06/15 12:36:55 | 000,109,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\AVIFILE.DLL
[2012/06/15 12:36:55 | 000,069,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\AVICAP.DLL
[2012/06/15 12:36:55 | 000,032,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\COMMDLG.DLL
[2012/06/15 12:36:55 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\TASKMAN.EXE
[2012/06/15 12:36:55 | 000,009,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\LZEXPAND.DLL
[2012/06/15 12:36:54 | 000,146,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\WINSPOOL.DRV
[2012/06/15 12:36:54 | 000,068,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MMSYSTEM.DLL
[2012/06/15 12:36:54 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\batt.dll
[2012/06/15 12:36:53 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\storprop.dll
[2012/06/15 12:36:43 | 000,000,000 | R–D | C] – C:\Users\All Users\Start Menu\Programs\Startup
[2012/06/15 12:36:43 | 000,000,000 | R–D | C] – C:\Users\All Users\Start Menu
[2012/06/15 12:36:43 | 000,000,000 | R–D | C] – C:\Users\All Users\Documents
[2012/06/15 12:36:43 | 000,000,000 | -H-D | C] – C:\Users\All Users\Templates
[2012/06/15 12:36:43 | 000,000,000 | —D | C] – C:\Users\All Users\Favorites
[2012/06/15 12:36:43 | 000,000,000 | —D | C] – C:\Users\All Users\Desktop
[2012/06/15 12:36:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot2
[2012/06/15 12:36:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot
[2012/06/15 12:36:19 | 000,000,000 | –SD | C] – C:\Users\All Users\Application Data\Microsoft
[2012/06/15 12:36:19 | 000,000,000 | RH-D | C] – C:\Users\All Users\Application Data
[2012/06/15 12:34:45 | 001,123,328 | —- | C] (Broadcom Corp.) – C:\WINDOWS\System32\drivers\BCMWL5.SYS
[2012/06/15 12:33:48 | 001,222,840 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\drivers\sthda.sys
[2012/06/15 12:33:42 | 000,270,336 | —- | C] (SigmaTel, Inc.) – C:\WINDOWS\System32\stacapi.dll
[2012/06/15 12:33:42 | 000,146,944 | —- | C] (IDT, Inc.) – C:\WINDOWS\System32\st325602.dll
[2012/06/15 12:31:12 | 000,090,112 | —- | C] (Sony Corporation) – C:\WINDOWS\System32\snymsico.dll
[2012/06/15 12:31:12 | 000,042,496 | —- | C] (REDC) – C:\WINDOWS\System32\drivers\rimsptsk.sys
[2012/06/15 12:31:12 | 000,039,936 | —- | C] (REDC) – C:\WINDOWS\System32\drivers\rimmptsk.sys
[2012/06/15 12:31:12 | 000,037,376 | —- | C] (REDC) – C:\WINDOWS\System32\drivers\rixdptsk.sys
[2012/06/15 12:30:43 | 000,114,688 | —- | C] (Conexant Systems, Inc) – C:\WINDOWS\System32\Uci32103.dll
[2012/06/15 12:30:43 | 000,086,016 | —- | C] (Conexant) – C:\WINDOWS\System32\mdmxsdk.dll
[2012/06/15 12:29:58 | 000,045,568 | R— | C] (Broadcom Corporation) – C:\WINDOWS\System32\drivers\bcm4sbxp.sys
[2012/06/15 12:29:42 | 000,013,568 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\drivers\L8042Kbd.sys
[2012/06/15 12:27:47 | 000,524,288 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxcfg.exe
[2012/06/15 12:27:47 | 000,163,840 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxzoom.exe
[2012/06/15 12:27:26 | 002,643,456 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igxpdx32.dll
[2012/06/15 12:27:26 | 001,670,144 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igxpdv32.dll
[2012/06/15 12:27:26 | 000,151,040 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igxpgd32.dll
[2012/06/15 12:27:26 | 000,057,344 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igxprd32.dll
[2012/06/15 12:27:14 | 002,334,720 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\iglicd32.dll
[2012/06/15 12:27:13 | 003,293,184 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxress.dll
[2012/06/15 12:27:13 | 000,294,912 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igldev32.dll
[2012/06/15 12:27:13 | 000,204,800 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxpph.dll
[2012/06/15 12:27:13 | 000,135,168 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxdo.dll
[2012/06/15 12:27:13 | 000,048,128 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxsrvc.dll
[2012/06/15 12:27:13 | 000,024,576 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxexps.dll
[2012/06/15 12:27:11 | 000,102,400 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\hccutils.dll
[2012/06/15 12:26:51 | 000,188,416 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrnld.lrc
[2012/06/15 12:26:51 | 000,188,416 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrita.lrc
[2012/06/15 12:26:51 | 000,188,416 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxresp.lrc
[2012/06/15 12:26:51 | 000,184,320 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrfra.lrc
[2012/06/15 12:26:51 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrrus.lrc
[2012/06/15 12:26:51 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrptg.lrc
[2012/06/15 12:26:51 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrptb.lrc
[2012/06/15 12:26:51 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrplk.lrc
[2012/06/15 12:26:51 | 000,180,224 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrhun.lrc
[2012/06/15 12:26:51 | 000,176,128 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrsky.lrc
[2012/06/15 12:26:51 | 000,176,128 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrnor.lrc
[2012/06/15 12:26:51 | 000,176,128 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrfin.lrc
[2012/06/15 12:26:51 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrtrk.lrc
[2012/06/15 12:26:51 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrsve.lrc
[2012/06/15 12:26:51 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrslv.lrc
[2012/06/15 12:26:51 | 000,163,840 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrtha.lrc
[2012/06/15 12:26:51 | 000,155,648 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrheb.lrc
[2012/06/15 12:26:51 | 000,131,072 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrjpn.lrc
[2012/06/15 12:26:51 | 000,126,976 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrkor.lrc
[2012/06/15 12:26:50 | 000,192,512 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrell.lrc
[2012/06/15 12:26:50 | 000,192,512 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrdeu.lrc
[2012/06/15 12:26:50 | 000,176,128 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrcsy.lrc
[2012/06/15 12:26:50 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrenu.lrc
[2012/06/15 12:26:50 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrdan.lrc
[2012/06/15 12:26:50 | 000,159,744 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrara.lrc
[2012/06/15 12:26:50 | 000,110,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrcht.lrc
[2012/06/15 12:26:50 | 000,110,592 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxrchs.lrc
[2012/06/15 12:26:47 | 000,122,880 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxcpl.cpl
[2012/06/15 12:21:48 | 000,000,000 | —D | C] – C:\ppGames
[2012/06/15 12:21:48 | 000,000,000 | —D | C] – C:\ppApps
[2012/06/15 12:21:37 | 000,094,208 | —- | C] (Sysinternals - www.sysinternals.com) – C:\WINDOWS\System32\pskill.exe
[2012/06/15 12:21:37 | 000,034,816 | —- | C] (NirSoft) – C:\WINDOWS\System32\myuninst.exe
[2012/06/15 12:21:37 | 000,028,160 | —- | C] (NirSoft) – C:\WINDOWS\System32\nircmd.exe
[2012/06/15 12:21:37 | 000,027,136 | —- | C] (NirSoft) – C:\WINDOWS\System32\nircmdc.exe
[2012/06/15 12:21:36 | 000,116,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\calc.exe
[2012/06/15 12:21:36 | 000,051,200 | —- | C] (n7Epsilon) – C:\WINDOWS\System32\cWnd.exe
[2012/06/15 12:21:35 | 000,254,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Tweakui.exe
[2012/06/15 12:21:35 | 000,028,672 | —- | C] (Home) – C:\WINDOWS\System32\MyCleaner.exe
[2012/06/15 12:21:35 | 000,028,672 | —- | C] (Camtech 2000) – C:\WINDOWS\System32\Refresh.exe
[2012/06/15 12:21:34 | 000,081,920 | —- | C] (Home) – C:\WINDOWS\System32\ChangeWallpaper.exe
[2012/06/15 12:21:08 | 000,000,000 | —D | C] – C:\WINDOWS\LastXP
[2012/06/15 12:21:04 | 001,066,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mscomctl32.ocx
[2012/06/15 12:21:03 | 001,071,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mscomctl.ocx
[2012/06/15 12:21:03 | 000,152,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comdlg32.ocx
[2012/06/15 12:20:52 | 000,000,000 | —D | C] – C:\Users
[2012/06/15 12:10:33 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2012/06/15 12:09:36 | 000,000,000 | –SD | C] – C:\WINDOWS\Downloaded Program Files
[2012/06/15 12:09:36 | 000,000,000 | R-SD | C] – C:\WINDOWS\Fonts
[2012/06/15 12:09:36 | 000,000,000 | R–D | C] – C:\WINDOWS\Offline Web Pages
[2012/06/15 12:09:36 | 000,000,000 | -H-D | C] – C:\WINDOWS\inf
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\WinSxS
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\wins
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Web
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\wbem
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\usmt
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\twain_32
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Temp
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\system32
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\system
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\spool
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ShellExt
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Setup
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\security
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Resources
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\repair
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ras
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Provisioning
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\PeerNet
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\pchealth
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\oobe
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\npp
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Network Diagnostic
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\mui
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\mui
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\msapps
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\msagent
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Media
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\L2Schemas
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\java
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\inetsrv
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\IME
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\ime
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\icsxml
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ias
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Help
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\export
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\etc
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Driver Cache
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\disdn
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\dhcp
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Debug
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Cursors
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Connection Wizard
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\config
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\Config
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\AppPatch
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\addins
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\3com_dmi
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\3076
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\2052
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1054
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1042
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1041
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1037
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1033
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1031
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1028
[2012/06/15 12:09:36 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1025
[2012/06/15 08:02:23 | 000,000,000 | -HSD | C] – C:\Users\All Users\Documents\MCE Logs
[2012/06/15 06:43:01 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\Windows Genuine Advantage
[2012/06/15 06:13:29 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\Broadcom
[2012/06/15 06:13:28 | 000,000,000 | —D | C] – C:\Program Files\Broadcom
[2012/06/15 06:12:40 | 000,000,000 | —D | C] – C:\WINDOWS\Downloaded Installations
[2012/06/15 06:10:19 | 000,000,000 | —D | C] – C:\Intel
[2012/06/15 06:10:07 | 000,000,000 | —D | C] – C:\Program Files\Dell
[2012/06/15 06:10:06 | 000,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2012/06/15 06:10:06 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\Dell QuickSet
[2012/06/15 06:09:53 | 000,016,128 | —- | C] (Dell Inc) – C:\WINDOWS\System32\drivers\APPDRV.SYS
[2012/06/15 06:09:52 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\InstallShield
[2012/06/15 06:09:10 | 000,000,000 | —D | C] – C:\dell
[2012/06/15 06:07:22 | 000,000,000 | —D | C] – C:\Program Files\DELL Drivers
[2012/06/15 06:04:06 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/06/15 05:31:32 | 000,000,000 | —D | C] – C:\Users\All Users\Documents\Recorded TV
[2012/06/15 05:31:31 | 000,380,928 | —- | C] (LastOS) – C:\WINDOWS\System32\Settings.exe
[2012/06/15 05:31:31 | 000,147,968 | —- | C] (Igor Pavlov) – C:\WINDOWS\System32\7z.exe
[2012/06/15 05:31:30 | 000,006,144 | —- | C] (NirSoft) – C:\WINDOWS\System32\2apply.exe
[2012/06/15 05:31:24 | 000,172,032 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxres.dll
[2012/06/15 05:31:10 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\Identities
[2012/06/15 05:24:23 | 000,000,000 | —D | C] – C:\Program Files\Drive Space Indicator
[2012/06/15 05:24:13 | 000,000,000 | —D | C] – C:\Program Files\DiskTrix
[2012/06/15 05:23:45 | 000,000,000 | —D | C] – C:\Program Files\SetupSetupS
[2012/06/15 05:23:40 | 000,773,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bubbles.scr
[2012/06/15 05:23:40 | 000,478,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ssmaze.scr
[2012/06/15 05:23:40 | 000,241,152 | —- | C] (Sencesa Group) – C:\WINDOWS\System32\HypnogenicRain.scr
[2012/06/15 05:23:40 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ribbons.scr
[2012/06/15 05:23:40 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Mystify.scr
[2012/06/15 05:23:40 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Boxes.scr
[2012/06/15 05:23:40 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Glass.scr
[2012/06/15 05:23:40 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bezier.scr
[2012/06/15 05:23:40 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ssflywin.scr
[2012/06/15 05:23:39 | 001,263,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aurora.scr
[2012/06/15 05:23:21 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\Nero
[2012/06/15 05:23:15 | 000,127,488 | —- | C] (Ahead Software AG) – C:\WINDOWS\System32\drivers\imagesrv.sys
[2012/06/15 05:23:15 | 000,005,888 | —- | C] (Ahead Software AG) – C:\WINDOWS\System32\drivers\imagedrv.sys
[2012/06/15 05:23:00 | 000,364,544 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\TwnLib4.dll
[2012/06/15 05:23:00 | 000,106,496 | —- | C] (Pegasus Software) – C:\WINDOWS\System32\TwnLib20.dll
[2012/06/15 05:22:59 | 001,568,768 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\ImagX7.dll
[2012/06/15 05:22:59 | 000,476,320 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\ImagXpr7.dll
[2012/06/15 05:22:59 | 000,471,040 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\ImagXRA7.dll
[2012/06/15 05:22:59 | 000,262,144 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\ImagXR7.dll
[2012/06/15 05:22:59 | 000,155,648 | —- | C] (Nero AG) – C:\WINDOWS\System32\NeroCheck.exe
[2012/06/15 05:22:59 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Ahead
[2012/06/15 05:22:58 | 000,000,000 | —D | C] – C:\Program Files\Ahead
[2012/06/15 05:22:20 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2012/06/15 05:22:20 | 000,185,688 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2012/06/15 05:22:20 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2012/06/15 05:22:20 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2012/06/15 05:22:18 | 000,389,120 | —- | C] (http://www.mp3dev.org/) – C:\WINDOWS\System32\lameACM.acm
[2012/06/15 05:22:18 | 000,118,784 | —- | C] (fccHandler) – C:\WINDOWS\System32\ac3acm.acm
[2012/06/15 05:22:17 | 000,217,088 | —- | C] (www.helixcommunity.org) – C:\WINDOWS\System32\yv12vfw.dll
[2012/06/15 05:22:16 | 000,682,496 | —- | C] (DivX, Inc.) – C:\WINDOWS\System32\divx.dll
[2012/06/15 05:22:16 | 000,081,920 | —- | C] (DivX, Inc.) – C:\WINDOWS\System32\dpl100.dll
[2012/06/15 05:22:14 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\Real
[2012/06/15 05:22:14 | 000,000,000 | —D | C] – C:\Users\Administrator\Local Settings\Application Data\Real
[2012/06/15 05:22:14 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\Real
[2012/06/15 05:22:14 | 000,000,000 | —D | C] – C:\Program Files\K-Lite Codec Pack
[2012/06/15 05:22:01 | 000,000,000 | —D | C] – C:\Program Files\irfanview
[2012/06/15 05:21:55 | 000,000,000 | —D | C] – C:\Program Files\ieSpell
[2012/06/15 05:21:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2012/06/15 05:21:20 | 000,000,000 | —D | C] – C:\Program Files\Opera
[2012/06/15 05:21:17 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/06/15 05:21:06 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/06/15 05:20:56 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2012/06/15 05:19:33 | 000,864,256 | —- | C] (Abysmal Software) – C:\WINDOWS\System32\DevIL.dll
[2012/06/15 05:19:33 | 000,818,176 | —- | C] (Jay Elaraj) – C:\WINDOWS\System32\taskbarshuffle.exe
[2012/06/15 05:19:33 | 000,081,920 | —- | C] (Abysmal Software) – C:\WINDOWS\System32\ILU.dll
[2012/06/15 05:19:33 | 000,036,864 | —- | C] (Abysmal Software) – C:\WINDOWS\System32\ILUT.dll
[2012/06/15 05:19:33 | 000,014,848 | —- | C] (BKHN) – C:\WINDOWS\System32\GLUE.exe
[2012/06/15 05:19:19 | 000,000,000 | —D | C] – C:\Program Files\Unlocker
[2012/06/15 05:19:19 | 000,000,000 | —D | C] – C:\Program Files\TaskSwitchXP
[2012/06/15 05:19:18 | 000,000,000 | —D | C] – C:\Program Files\Attribute Changer
[2012/06/15 05:19:16 | 000,323,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wiaaut.dll
[2012/06/15 05:19:16 | 000,122,880 | —- | C] (n7Epsilon) – C:\WINDOWS\System32\FGCBA.exe
[2012/06/15 05:19:16 | 000,110,592 | —- | C] (Diskassy Designs) – C:\WINDOWS\System32\AcleanA.exe
[2012/06/15 05:19:16 | 000,102,400 | —- | C] (Exodus Development, Inc.) – C:\WINDOWS\System32\WhyReboot.exe
[2012/06/15 05:19:16 | 000,098,304 | —- | C] (XPero) – C:\WINDOWS\System32\EXPander.exe
[2012/06/15 05:19:16 | 000,094,208 | —- | C] (n7Epsilon) – C:\WINDOWS\System32\FGCBAHandler.exe
[2012/06/15 05:19:16 | 000,077,824 | —- | C] (XPero) – C:\WINDOWS\System32\RegFileMerger.exe
[2012/06/15 05:19:16 | 000,065,536 | —- | C] (n7Epsilon) – C:\WINDOWS\System32\Reg2Inf.exe
[2012/06/15 05:19:16 | 000,053,248 | —- | C] (Lucersoft) – C:\WINDOWS\System32\LCISOCreator.exe
[2012/06/15 05:18:52 | 000,000,000 | —D | C] – C:\Program Files\System
[2012/06/15 05:18:45 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\directx.cpl
[2012/06/15 05:17:22 | 000,000,000 | —D | C] – C:\Users\Administrator\Local Settings\Application Data\ApplicationHistory
[2012/06/15 05:17:15 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\igdetect.dll
[2012/06/15 05:15:17 | 000,000,000 | —D | C] – C:\WINDOWS\EHOME
[2012/06/15 05:13:19 | 000,000,000 | –SD | C] – C:\Users\Administrator\Start Menu\Programs\- Video
[2012/06/15 05:13:19 | 000,000,000 | –SD | C] – C:\Users\Administrator\Start Menu\Programs\- Games
[2012/06/15 05:13:19 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- Other
[2012/06/15 05:13:18 | 000,000,000 | –SD | C] – C:\Users\Administrator\Start Menu\Programs\- Devices
[2012/06/15 05:13:18 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- Sound
[2012/06/15 05:13:17 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- Security
[2012/06/15 05:13:17 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- Office
[2012/06/15 05:13:16 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- System
[2012/06/15 05:13:16 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- Internet
[2012/06/15 05:13:16 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- Graphics
[2012/06/15 05:13:16 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- Disk
[2012/06/15 05:13:16 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- Development
[2012/06/15 05:13:16 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\- CD & DVD
[2012/06/15 05:11:57 | 000,000,000 | —D | C] – C:\Program Files\Utilities
[2012/06/15 05:11:57 | 000,000,000 | —D | C] – C:\Downloads
[2012/06/15 05:11:46 | 000,000,000 | –SD | C] – C:\Users\Administrator\Local Settings\Application Data\Microsoft
[2012/06/15 05:11:46 | 000,000,000 | –SD | C] – C:\Users\Administrator\Application Data\Microsoft
[2012/06/15 05:11:46 | 000,000,000 | R-SD | C] – C:\Users\Administrator\Start Menu\Programs\Startup
[2012/06/15 05:11:46 | 000,000,000 | RH-D | C] – C:\Users\Administrator\SendTo
[2012/06/15 05:11:46 | 000,000,000 | RH-D | C] – C:\Users\Administrator\Recent
[2012/06/15 05:11:46 | 000,000,000 | RH-D | C] – C:\Users\Administrator\Application Data
[2012/06/15 05:11:46 | 000,000,000 | R–D | C] – C:\Users\Administrator\Start Menu
[2012/06/15 05:11:46 | 000,000,000 | R–D | C] – C:\Users\Administrator\My Documents
[2012/06/15 05:11:46 | 000,000,000 | R–D | C] – C:\Users\Administrator\Favorites
[2012/06/15 05:11:46 | 000,000,000 | -HSD | C] – C:\Users\Administrator\Cookies
[2012/06/15 05:11:46 | 000,000,000 | -H-D | C] – C:\Users\Administrator\Templates
[2012/06/15 05:11:46 | 000,000,000 | -H-D | C] – C:\Users\Administrator\PrintHood
[2012/06/15 05:11:46 | 000,000,000 | -H-D | C] – C:\Users\Administrator\NetHood
[2012/06/15 05:11:46 | 000,000,000 | -H-D | C] – C:\Users\Administrator\Local Settings
[2012/06/15 05:11:46 | 000,000,000 | —D | C] – C:\Users\Administrator\Desktop
[2012/06/15 05:10:39 | 000,000,000 | —D | C] – C:\WINDOWS\SoftwareDistribution
[2012/06/15 05:10:32 | 000,000,000 | –SD | C] – C:\WINDOWS\System32\Microsoft
[2012/06/15 05:10:32 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2012/06/15 05:10:21 | 000,000,000 | –SD | C] – C:\Users\NetworkService\Local Settings\Application Data\Microsoft
[2012/06/15 05:10:21 | 000,000,000 | –SD | C] – C:\Users\NetworkService\Application Data\Microsoft
[2012/06/15 05:07:17 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/06/15 05:07:09 | 000,139,264 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/06/15 05:07:09 | 000,135,168 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/06/15 05:07:09 | 000,135,168 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/06/15 05:07:09 | 000,069,632 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/06/15 05:06:44 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/06/15 05:06:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/06/15 05:06:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\InstallShield
[2012/06/15 05:00:29 | 000,000,000 | –SD | C] – C:\Users\LocalService\Local Settings\Application Data\Microsoft
[2012/06/15 05:00:29 | 000,000,000 | –SD | C] – C:\Users\LocalService\Application Data\Microsoft
[2012/06/15 05:00:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2012/06/15 05:00:12 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2012/06/15 05:00:08 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2012/06/15 05:00:00 | 000,014,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg2.dll
[2012/06/15 04:57:50 | 000,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2012/06/15 04:57:50 | 000,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2012/06/15 04:57:48 | 000,000,000 | —D | C] – C:\WINDOWS\System32\URTTemp
[2012/06/15 04:57:41 | 001,683,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XpsSvcs.dll
[2012/06/15 04:57:41 | 001,683,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\XpsSvcs.dll
[2012/06/15 04:57:41 | 000,583,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\XPSSHHDR.dll
[2012/06/15 04:57:25 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2012/06/15 04:57:02 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\FilterPipelinePrintProc.dll
[2012/06/15 04:57:01 | 000,677,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\PrintFilterPipelineSvc.exe
[2012/06/15 04:56:07 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2012/06/15 04:56:04 | 000,026,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spupdsvc.exe
[2012/06/15 04:56:04 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2012/06/15 04:55:49 | 000,000,000 | —D | C] – C:\Program Files\Alky for Applications
[2012/06/15 04:55:10 | 000,198,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mapi32.dll
[2012/06/15 04:55:10 | 000,000,000 | —D | C] – C:\WINDOWS\System32\dllcache
[2012/06/15 04:54:19 | 000,000,000 | -HSD | C] – C:\Users\All Users\DRM
[2012/06/15 04:53:53 | 000,000,000 | -H-D | C] – C:\Program Files\WindowsUpdate
[2012/06/15 04:53:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DirectX
[2012/06/15 04:53:04 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\atrace.dll
[2012/06/15 04:52:53 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\nmevtmsg.dll
[2012/06/15 04:52:52 | 000,109,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\acctres.dll
[2012/06/15 04:52:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Services
[2012/06/15 04:52:47 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\icfgnt5.dll
[2012/06/15 04:52:47 | 000,000,000 | –SD | C] – C:\WINDOWS\Tasks
[2012/06/15 04:52:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\MSSoap
[2012/06/15 04:52:38 | 000,000,000 | —D | C] – C:\WINDOWS\srchasst
[2012/06/15 04:52:37 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Macromed
[2012/06/15 04:52:34 | 000,327,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll
[2012/06/15 04:52:33 | 000,183,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuaueng1.dll
[2012/06/15 04:52:32 | 000,344,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuauclt1.exe
[2012/06/15 04:52:32 | 000,035,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups.dll
[2012/06/15 04:52:31 | 000,575,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll
[2012/06/15 04:52:31 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2012/06/15 04:52:30 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qmgrprxy.dll
[2012/06/15 04:52:30 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx2.dll
[2012/06/15 04:52:30 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx3.dll
[2012/06/15 04:52:24 | 000,000,000 | —D | C] – C:\Program Files\Movie Maker
[2012/06/15 04:51:55 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\safrslv.dll
[2012/06/15 04:51:55 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\safrcdlg.dll
[2012/06/15 04:51:55 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\racpldlg.dll
[2012/06/15 04:51:55 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\safrdm.dll
[2012/06/15 04:51:48 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\fltMc.exe
[2012/06/15 04:51:47 | 000,265,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\srrstr.dll
[2012/06/15 04:51:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Restore
[2012/06/15 04:51:46 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ils.dll
[2012/06/15 04:51:46 | 000,032,768 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\isrdbg32.dll
[2012/06/15 04:51:45 | 000,131,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msconf.dll
[2012/06/15 04:51:45 | 000,034,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mnmdd.dll
[2012/06/15 04:51:45 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\nmmkcert.dll
[2012/06/15 04:51:40 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msoert2.dll
[2012/06/15 04:51:40 | 000,000,000 | —D | C] – C:\Program Files\NetMeeting
[2012/06/15 04:51:39 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msoeacct.dll
[2012/06/15 04:51:37 | 000,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\inetres.dll
[2012/06/15 04:51:33 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mstinit.exe
[2012/06/15 04:51:33 | 000,000,000 | —D | C] – C:\Program Files\Outlook Express
[2012/06/15 04:51:32 | 000,925,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\inetcfg.dll
[2012/06/15 04:51:32 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\icwdial.dll
[2012/06/15 04:51:32 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\isign32.dll
[2012/06/15 04:51:32 | 000,065,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\icwphbk.dll
[2012/06/15 04:51:22 | 000,000,000 | —D | C] – C:\Program Files\Common Files\System
[2012/06/15 04:51:19 | 000,000,000 | —D | C] – C:\Program Files\Internet Explorer
[2012/06/15 04:51:16 | 000,000,000 | R–D | C] – C:\Users\All Users\Documents\My Pictures
[2012/06/15 04:50:46 | 000,000,000 | -H-D | C] – C:\Program Files\Uninstall Information
[2012/06/15 04:50:30 | 000,000,000 | —D | C] – C:\Program Files\ComPlus Applications
[2012/06/15 04:50:21 | 000,000,000 | R–D | C] – C:\Users\All Users\Start Menu\Programs\Administrative Tools
[2012/06/15 04:50:21 | 000,000,000 | —D | C] – C:\WINDOWS\Registration
[2012/06/15 04:49:55 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Connect 2
[2012/06/15 04:49:54 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Player
[2012/06/15 04:49:53 | 001,872,666 | —- | C] (Red Hat) – C:\WINDOWS\System32\cygwin1.dll
[2012/06/15 04:49:52 | 001,351,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comctl32.ocx
[2012/06/15 04:49:52 | 000,416,528 | —- | C] (Microsoft Corporation ) – C:\WINDOWS\System32\comct332.ocx
[2012/06/15 04:49:52 | 000,294,920 | —- | C] (AutoIt Team) – C:\WINDOWS\System32\autoitx3.dll
[2012/06/15 04:49:52 | 000,164,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comct232.ocx
[2012/06/15 04:49:52 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\atl71.dll
[2012/06/15 04:49:51 | 000,413,696 | —- | C] (Creative Labs) – C:\WINDOWS\System32\wrap_oal.dll
[2012/06/15 04:49:51 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\atl70.dll
[2012/06/15 04:49:50 | 000,722,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vb40032.dll
[2012/06/15 04:49:50 | 000,398,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\vbrun300.dll
[2012/06/15 04:49:50 | 000,356,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\vbrun200.dll
[2012/06/15 04:49:49 | 000,935,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\vb40016.dll
[2012/06/15 04:49:49 | 000,224,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tabctl32.ocx
[2012/06/15 04:49:49 | 000,196,608 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\ssleay32.dll
[2012/06/15 04:49:49 | 000,067,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sysinfo.ocx
[2012/06/15 04:49:48 | 000,212,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2012/06/15 04:49:48 | 000,124,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mswinsck.ocx
[2012/06/15 04:49:48 | 000,083,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\picclp32.ocx
[2012/06/15 04:49:48 | 000,032,768 | —- | C] (Adobe Systems, Inc.) – C:\WINDOWS\System\PLUGIN.DLL
[2012/06/15 04:49:48 | 000,021,504 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\openal32.dll
[2012/06/15 04:49:47 | 000,487,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcp70.dll
[2012/06/15 04:49:47 | 000,339,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcr70.dll
[2012/06/15 04:49:47 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvci70.dll
[2012/06/15 04:49:46 | 000,260,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msflxgrd.ocx
[2012/06/15 04:49:46 | 000,232,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msdatlst.ocx
[2012/06/15 04:49:46 | 000,166,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msmask32.ocx
[2012/06/15 04:49:46 | 000,132,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msinet.ocx
[2012/06/15 04:49:46 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msstdfmt.dll
[2012/06/15 04:49:46 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msstkprp.dll
[2012/06/15 04:49:45 | 000,275,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msdatgrd.ocx
[2012/06/15 04:49:45 | 000,103,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mscomm32.ocx
[2012/06/15 04:49:44 | 001,060,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfc71.dll
[2012/06/15 04:49:44 | 001,053,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfc71u.dll
[2012/06/15 04:49:44 | 000,662,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mscomct2.ocx
[2012/06/15 04:49:43 | 001,024,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfc70.dll
[2012/06/15 04:49:43 | 001,017,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfc70u.dll
[2012/06/15 04:49:42 | 002,887,680 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\libmmd.dll
[2012/06/15 04:49:41 | 000,198,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mci32.ocx
[2012/06/15 04:49:41 | 000,196,608 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\libssl32.dll
[2012/06/15 04:49:41 | 000,101,888 | —- | C] (GNU ) – C:\WINDOWS\System32\libintl3.dll
[2012/06/15 04:49:40 | 001,015,808 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\libeay32.dll
[2012/06/15 04:49:40 | 000,898,048 | —- | C] (GNU ) – C:\WINDOWS\System32\libiconv2.dll
[2012/06/15 04:49:40 | 000,200,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dblist32.ocx
[2012/06/15 04:49:33 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\write.exe
[2012/06/15 04:49:24 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sndvol32.exe
[2012/06/15 04:49:23 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winchat.exe
[2012/06/15 04:49:23 | 000,046,592 | —- | C] (Hilgraeve, Inc.) – C:\WINDOWS\System32\hticons.dll
[2012/06/15 04:49:13 | 000,605,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\getuname.dll
[2012/06/15 04:49:12 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\charmap.exe
[2012/06/15 04:49:11 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sol.exe
[2012/06/15 04:49:10 | 000,129,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshearts.exe
[2012/06/15 04:49:10 | 000,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winmine.exe
[2012/06/15 04:49:10 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\freecell.exe
[2012/06/15 04:49:09 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsshutdn.exe
[2012/06/15 04:49:09 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tskill.exe
[2012/06/15 04:49:09 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsdiscon.exe
[2012/06/15 04:49:09 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tscon.exe
[2012/06/15 04:49:09 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\shadow.exe
[2012/06/15 04:49:09 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\reset.exe
[2012/06/15 04:49:08 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\regini.exe
[2012/06/15 04:49:08 | 000,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qwinsta.exe
[2012/06/15 04:49:08 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msg.exe
[2012/06/15 04:49:08 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qappsrv.exe
[2012/06/15 04:49:08 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwinsta.exe
[2012/06/15 04:49:08 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\logoff.exe
[2012/06/15 04:49:08 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rdpcfgex.dll
[2012/06/15 04:49:07 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\cdmodem.dll
[2012/06/15 04:48:58 | 000,000,000 | —D | C] – C:\Program Files\Windows NT
[2012/06/15 04:48:57 | 000,447,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\accwiz.exe
[2012/06/15 04:48:57 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mplay32.exe
[2012/06/15 04:48:57 | 000,180,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sndrec32.exe
[2012/06/15 04:48:57 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\access.cpl
[2012/06/15 04:48:56 | 000,347,136 | —- | C] (Hilgraeve, Inc.) – C:\WINDOWS\System32\hypertrm.dll
[2012/06/15 04:48:56 | 000,343,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mspaint.exe
[2012/06/15 04:48:55 | 001,564,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spider.exe
[2012/06/15 04:48:53 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2012/06/15 04:48:53 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2012/06/15 04:48:53 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tscfgwmi.dll
[2012/06/15 04:48:53 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2012/06/15 04:48:51 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rdshost.exe
[2012/06/15 04:48:51 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rdsaddin.exe
[2012/06/15 04:48:50 | 000,147,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rdchost.dll
[2012/06/15 04:48:50 | 000,087,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rdpwsx.dll
[2012/06/15 04:48:50 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rdpclip.exe
[2012/06/15 04:48:50 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rdpsnd.dll
[2012/06/15 04:48:50 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qprocess.exe
[2012/06/15 04:48:49 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msdtcuiu.dll
[2012/06/15 04:48:49 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\cfgbkend.dll
[2012/06/15 04:48:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MsDtc
[2012/06/15 04:48:48 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msdtctm.dll
[2012/06/15 04:48:48 | 000,428,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msdtcprx.dll
[2012/06/15 04:48:48 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msdtclog.dll
[2012/06/15 04:48:48 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xolehlp.dll
[2012/06/15 04:48:47 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dcomcnfg.exe
[2012/06/15 04:48:46 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comrepl.dll
[2012/06/15 04:48:46 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mtxlegih.dll
[2012/06/15 04:48:46 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mtxdm.dll
[2012/06/15 04:48:46 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comaddin.dll
[2012/06/15 04:48:46 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mtxex.dll
[2012/06/15 04:48:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Com
[2012/06/15 04:48:45 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\clbcatex.dll
[2012/06/15 04:48:45 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\catsrvps.dll
[2012/06/15 04:48:45 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\stclient.dll
[2012/06/15 04:48:44 | 000,539,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comuid.dll
[2012/06/15 04:48:43 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsnap.dll
[2012/06/15 04:48:33 | 000,141,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\servdeps.dll
[2012/06/15 04:48:33 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmfutil.dll
[2012/06/15 04:48:32 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\cmprops.dll
[2012/06/15 04:48:32 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\licwmi.dll
[2012/05/31 21:22:09 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll

========== Files - Modified Within 30 Days ==========

[2012/06/25 03:29:02 | 004,567,243 | —- | M] (Swearware) – D:\Documents\Desktop\ComboFix.exe
[2012/06/25 03:15:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/25 03:12:58 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2012/06/25 03:12:01 | 000,000,976 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-1606980848-500UA.job
[2012/06/25 02:51:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/25 00:14:08 | 000,139,507 | —- | M] () – D:\Documents\Desktop\Ipak.exe volim.exe still inside my laptop.htm
[2012/06/25 00:12:00 | 000,000,924 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-1606980848-500Core.job
[2012/06/24 21:34:06 | 000,000,678 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\vlc.exe.lnk
[2012/06/24 19:58:00 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/06/24 18:25:30 | 100,677,902 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/06/24 07:25:57 | 000,596,480 | —- | M] (OldTimer Tools) – D:\Documents\Desktop\OTL.exe
[2012/06/24 07:24:17 | 000,132,597 | —- | M] () – D:\Documents\Desktop\Flash_Disinfector.exe
[2012/06/24 06:02:44 | 000,001,634 | —- | M] () – C:\WINDOWS\Sandboxie.ini
[2012/06/21 03:12:30 | 000,029,654 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/06/20 12:38:10 | 000,000,662 | —- | M] () – D:\Documents\Desktop\Frozen Throne.lnk
[2012/06/20 00:58:44 | 000,000,375 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2012/06/20 00:53:48 | 000,442,334 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/06/20 00:53:48 | 000,071,912 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/06/20 00:46:12 | 000,115,553 | —- | M] () – D:\Documents\My Documents\Network Connections Folder was unable to retrieve the list of Network adapters - Windows XP Network & Web.htm
[2012/06/19 06:23:55 | 000,000,119 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\fusioncache.dat
[2012/06/19 06:23:55 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/06/19 05:36:09 | 000,039,184 | —- | M] (Greatis Software) – C:\WINDOWS\System32\Partizan.exe
[2012/06/19 05:36:09 | 000,035,816 | —- | M] (Greatis Software) – C:\WINDOWS\System32\drivers\Partizan.sys
[2012/06/19 05:35:59 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012/06/19 05:35:59 | 000,001,688 | —- | M] () – C:\WINDOWS\System32\AUTOEXEC.NT
[2012/06/19 05:35:59 | 000,000,002 | RHS- | M] () – C:\WINDOWS\winstart.bat
[2012/06/19 05:35:52 | 000,000,540 | —- | M] () – D:\Documents\Desktop\UnHackMe.lnk
[2012/06/19 04:13:13 | 000,309,992 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/19 00:17:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/06/18 23:56:44 | 000,001,734 | —- | M] () – C:\Users\All Users\Desktop\Adobe Reader X.lnk
[2012/06/18 23:08:18 | 011,347,294 | —- | M] () – D:\Documents\My Documents\unhackme.zip
[2012/06/18 23:05:37 | 000,014,382 | —- | M] () – D:\Documents\My Documents\mmm_exe ThreatExpert statistics.htm
[2012/06/18 23:03:57 | 000,013,052 | —- | M] () – D:\Documents\My Documents\mmm_exe - Dangerous.htm
[2012/06/18 23:00:36 | 000,034,764 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\dt.dat
[2012/06/18 22:56:50 | 000,000,702 | —- | M] () – C:\Users\All Users\Desktop\AVG 2012.lnk
[2012/06/18 22:44:47 | 003,879,304 | —- | M] (AVG Technologies) – D:\Documents\My Documents\avg_free_stb_all_2012_2180_cnet.exe
[2012/06/18 22:30:29 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/06/18 22:30:29 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/06/18 05:07:54 | 000,000,766 | —- | M] () – D:\Documents\Desktop\Sandboxed Web Browser.lnk
[2012/06/18 05:07:54 | 000,000,766 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnk
[2012/06/18 05:03:19 | 000,001,980 | —- | M] () – C:\Users\All Users\Desktop\Dell Support Center.lnk
[2012/06/18 04:56:51 | 000,022,729 | —- | M] () – C:\newkey
[2012/06/18 04:56:51 | 000,022,729 | —- | M] () – C:\newfile.enc
[2012/06/16 12:58:52 | 000,000,006 | —- | M] () – C:\WINDOWS\LastXPSetupSMenu.ini
[2012/06/16 12:58:52 | 000,000,005 | —- | M] () – C:\WINDOWS\ppGameDrive.ini
[2012/06/16 12:58:52 | 000,000,005 | —- | M] () – C:\WINDOWS\ppAppDrive.ini
[2012/06/16 12:58:47 | 000,000,297 | —- | M] () – C:\WINDOWS\System32\StartAU.cmd
[2012/06/16 12:57:33 | 000,000,004 | —- | M] () – C:\Fade.ini
[2012/06/15 12:37:37 | 000,004,444 | —- | M] () – C:\WINDOWS\System32\pid.PNF
[2012/06/15 12:35:22 | 000,000,009 | —- | M] () – C:\ShowWPI.ini
[2012/06/15 08:02:20 | 000,001,396 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\MEDIA_CENTER.LNK
[2012/06/15 06:11:31 | 000,000,005 | —- | M] () – C:\WINDOWS\System32\drivers\DELL_XPS_MM061 .MRK
[2012/06/15 06:11:31 | 000,000,005 | —- | M] () – C:\WINDOWS\System32\drivers\1028_DELL_XPS_MM061 .MRK
[2012/06/15 05:31:18 | 000,000,079 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/06/15 05:31:12 | 000,000,800 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/06/15 05:26:07 | 000,000,681 | –S- | M] () – C:\Users\Administrator\Start Menu\Programs\Startup\Visual Task Tips.lnk
[2012/06/15 05:10:26 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2012/06/15 05:08:54 | 000,001,954 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2012/06/15 04:55:31 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/06/15 04:55:31 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/06/15 04:55:31 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/06/15 04:55:31 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/06/15 04:55:23 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2012/06/15 04:55:23 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2012/06/15 04:55:21 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012/06/15 04:55:10 | 000,004,161 | —- | M] () – C:\WINDOWS\ODBCINST.INI
[2012/06/15 04:50:42 | 000,021,640 | —- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2012/06/15 04:46:40 | 000,000,231 | -HS- | M] () – C:\boot.ini
[2012/05/31 21:22:09 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll

========== Files Created - No Company Name ==========

[2012/06/25 00:14:08 | 000,139,507 | —- | C] () – D:\Documents\Desktop\Ipak.exe volim.exe still inside my laptop.htm
[2012/06/24 21:34:06 | 000,000,678 | —- | C] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\vlc.exe.lnk
[2012/06/24 18:25:30 | 100,677,902 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/06/24 07:24:14 | 000,132,597 | —- | C] () – D:\Documents\Desktop\Flash_Disinfector.exe
[2012/06/21 03:12:30 | 000,029,654 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/06/20 12:38:13 | 000,000,662 | —- | C] () – D:\Documents\Desktop\Frozen Throne.lnk
[2012/06/20 01:58:02 | 000,000,976 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-1606980848-500UA.job
[2012/06/20 01:58:00 | 000,000,924 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-1606980848-500Core.job
[2012/06/20 00:46:12 | 000,115,553 | —- | C] () – D:\Documents\My Documents\Network Connections Folder was unable to retrieve the list of Network adapters - Windows XP Network & Web.htm
[2012/06/19 20:05:14 | 000,000,375 | —- | C] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2012/06/19 06:23:55 | 000,000,119 | —- | C] () – C:\Users\Administrator\Local Settings\Application Data\fusioncache.dat
[2012/06/19 05:35:59 | 000,000,002 | RHS- | C] () – C:\WINDOWS\winstart.bat
[2012/06/19 05:35:52 | 000,000,540 | —- | C] () – D:\Documents\Desktop\UnHackMe.lnk
[2012/06/19 04:14:27 | 000,000,803 | —- | C] () – C:\Users\Administrator\Start Menu\Programs\Internet Explorer.lnk
[2012/06/18 23:56:44 | 000,001,734 | —- | C] () – C:\Users\All Users\Desktop\Adobe Reader X.lnk
[2012/06/18 23:56:41 | 000,001,804 | —- | C] () – C:\Users\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/06/18 23:12:31 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/06/18 23:12:31 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/06/18 23:08:18 | 011,347,294 | —- | C] () – D:\Documents\My Documents\unhackme.zip
[2012/06/18 23:05:36 | 000,014,382 | —- | C] () – D:\Documents\My Documents\mmm_exe ThreatExpert statistics.htm
[2012/06/18 23:03:57 | 000,013,052 | —- | C] () – D:\Documents\My Documents\mmm_exe - Dangerous.htm
[2012/06/18 23:00:36 | 000,034,764 | —- | C] () – C:\Users\Administrator\Local Settings\Application Data\dt.dat
[2012/06/18 22:56:50 | 000,000,702 | —- | C] () – C:\Users\All Users\Desktop\AVG 2012.lnk
[2012/06/18 22:30:31 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/18 22:15:11 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012/06/18 05:08:10 | 000,000,766 | —- | C] () – D:\Documents\Desktop\Sandboxed Web Browser.lnk
[2012/06/18 05:08:10 | 000,000,766 | —- | C] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnk
[2012/06/18 05:08:07 | 000,001,634 | —- | C] () – C:\WINDOWS\Sandboxie.ini
[2012/06/18 05:03:19 | 000,001,980 | —- | C] () – C:\Users\All Users\Desktop\Dell Support Center.lnk
[2012/06/18 04:56:56 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2012/06/18 04:56:56 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\vcredist_x86.bat
[2012/06/18 04:56:55 | 000,753,664 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2012/06/18 04:56:55 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\WLTRYSVC.EXE
[2012/06/18 04:56:51 | 000,022,729 | —- | C] () – C:\newkey
[2012/06/18 04:56:51 | 000,022,729 | —- | C] () – C:\newfile.enc
[2012/06/16 12:57:07 | 000,000,004 | —- | C] () – C:\Fade.ini
[2012/06/16 12:55:11 | 000,049,275 | —- | C] () – C:\WINDOWS\System32\wfospf.mib
[2012/06/16 12:55:11 | 000,038,608 | —- | C] () – C:\WINDOWS\System32\nipx.mib
[2012/06/16 12:55:11 | 000,034,317 | —- | C] () – C:\WINDOWS\System32\msiprip2.mib
[2012/06/16 12:55:11 | 000,026,236 | —- | C] () – C:\WINDOWS\System32\wins.mib
[2012/06/16 12:55:11 | 000,013,767 | —- | C] () – C:\WINDOWS\System32\msipbtp.mib
[2012/06/16 12:55:11 | 000,010,313 | —- | C] () – C:\WINDOWS\System32\mripsap.mib
[2012/06/16 12:55:11 | 000,004,332 | —- | C] () – C:\WINDOWS\System32\smi.mib
[2012/06/16 12:55:11 | 000,000,581 | —- | C] () – C:\WINDOWS\System32\msft.mib
[2012/06/16 12:55:10 | 000,107,882 | —- | C] () – C:\WINDOWS\System32\mib_ii.mib
[2012/06/16 12:55:10 | 000,048,593 | —- | C] () – C:\WINDOWS\System32\hostmib.mib
[2012/06/16 12:55:10 | 000,030,448 | —- | C] () – C:\WINDOWS\System32\mcastmib.mib
[2012/06/16 12:55:10 | 000,026,100 | —- | C] () – C:\WINDOWS\System32\lmmib2.mib
[2012/06/16 12:55:10 | 000,021,386 | —- | C] () – C:\WINDOWS\System32\mipx.mib
[2012/06/16 12:55:10 | 000,020,079 | —- | C] () – C:\WINDOWS\System32\http.mib
[2012/06/16 12:55:10 | 000,015,799 | —- | C] () – C:\WINDOWS\System32\ipforwd.mib
[2012/06/16 12:55:10 | 000,000,698 | —- | C] () – C:\WINDOWS\System32\inetsrv.mib
[2012/06/16 12:55:09 | 000,016,617 | —- | C] () – C:\WINDOWS\System32\authserv.mib
[2012/06/16 12:55:09 | 000,015,597 | —- | C] () – C:\WINDOWS\System32\accserv.mib
[2012/06/16 12:55:09 | 000,006,179 | —- | C] () – C:\WINDOWS\System32\ftp.mib
[2012/06/16 12:55:09 | 000,004,597 | —- | C] () – C:\WINDOWS\System32\dhcp.mib
[2012/06/15 12:37:37 | 000,004,444 | —- | C] () – C:\WINDOWS\System32\pid.PNF
[2012/06/15 12:37:31 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2012/06/15 12:36:54 | 000,001,688 | —- | C] () – C:\WINDOWS\System32\AUTOEXEC.NT
[2012/06/15 12:35:21 | 000,000,009 | —- | C] () – C:\ShowWPI.ini
[2012/06/15 12:31:12 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2012/06/15 12:30:23 | 000,141,497 | —- | C] () – C:\WINDOWS\System32\drivers\del1028.cty
[2012/06/15 12:27:26 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2012/06/15 12:26:52 | 000,026,992 | —- | C] () – C:\WINDOWS\System32\igxpxs32.vp
[2012/06/15 12:26:52 | 000,002,096 | —- | C] () – C:\WINDOWS\System32\igxpxk32.vp
[2012/06/15 12:21:37 | 000,185,516 | —- | C] () – C:\WINDOWS\System32\cmdhide.exe
[2012/06/15 12:21:37 | 000,014,281 | —- | C] () – C:\WINDOWS\System32\sleep.exe
[2012/06/15 12:21:37 | 000,000,143 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2012/06/15 12:21:36 | 000,013,339 | —- | C] () – C:\WINDOWS\System32\WAIT.EXE
[2012/06/15 12:21:35 | 000,031,493 | —- | C] () – C:\WINDOWS\System32\NirCmd.chm
[2012/06/15 12:21:34 | 000,027,222 | —- | C] () – C:\WINDOWS\System32\Calc.chm
[2012/06/15 12:21:34 | 000,019,083 | —- | C] () – C:\WINDOWS\System32\DELTREE.EXE
[2012/06/15 12:21:11 | 000,000,794 | —- | C] () – C:\WINDOWS\Removes.ini
[2012/06/15 12:21:04 | 000,265,728 | —- | C] () – C:\WINDOWS\System32\mscomctl32.oca
[2012/06/15 12:20:51 | 000,309,992 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/15 12:19:35 | 000,000,231 | -HS- | C] () – C:\boot.ini
[2012/06/15 12:19:30 | 000,001,954 | —- | C] () – C:\WINDOWS\System32\$winnt$.inf
[2012/06/15 08:04:58 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2012/06/15 06:11:31 | 000,000,005 | —- | C] () – C:\WINDOWS\System32\drivers\DELL_XPS_MM061 .MRK
[2012/06/15 06:11:31 | 000,000,005 | —- | C] () – C:\WINDOWS\System32\drivers\1028_DELL_XPS_MM061 .MRK
[2012/06/15 06:11:26 | 000,000,666 | —- | C] () – C:\WINDOWS\speed.reg
[2012/06/15 06:06:35 | 000,000,734 | —- | C] () – C:\WINDOWS\System32\drivers\etc\hosts1.bak
[2012/06/15 06:04:40 | 000,034,064 | —- | C] () – C:\WINDOWS\Instexnt.exe
[2012/06/15 06:04:40 | 000,005,904 | —- | C] () – C:\WINDOWS\Autoexnt.exe
[2012/06/15 06:04:40 | 000,002,364 | —- | C] () – C:\WINDOWS\1.reg
[2012/06/15 06:04:40 | 000,002,320 | —- | C] () – C:\WINDOWS\Servmess.dll
[2012/06/15 06:04:40 | 000,000,175 | —- | C] () – C:\WINDOWS\Autoexnt.bat
[2012/06/15 05:45:33 | 000,000,005 | —- | C] () – C:\WINDOWS\ppGameDrive.ini
[2012/06/15 05:45:33 | 000,000,005 | —- | C] () – C:\WINDOWS\ppAppDrive.ini
[2012/06/15 05:45:25 | 000,000,297 | —- | C] () – C:\WINDOWS\System32\StartAU.cmd
[2012/06/15 05:31:35 | 000,000,801 | –S- | C] () – C:\Users\Administrator\Start Menu\Programs\Link Luster Clean.lnk
[2012/06/15 05:31:33 | 000,000,275 | —- | C] () – C:\WINDOWS\System32\WiFiON.reg
[2012/06/15 05:31:32 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\renuser.exe
[2012/06/15 05:31:32 | 000,004,840 | —- | C] () – C:\WINDOWS\System32\1ViewIconDefault.reg
[2012/06/15 05:31:32 | 000,004,246 | —- | C] () – C:\WINDOWS\System32\1ViewList.reg
[2012/06/15 05:31:32 | 000,004,246 | —- | C] () – C:\WINDOWS\System32\1ViewDetail.reg
[2012/06/15 05:31:32 | 000,001,708 | —- | C] () – C:\WINDOWS\System32\MoveFoldersD.reg
[2012/06/15 05:31:32 | 000,000,818 | —- | C] () – C:\WINDOWS\System32\SysResON.reg
[2012/06/15 05:31:32 | 000,000,684 | —- | C] () – C:\WINDOWS\System32\SysResOFF.reg
[2012/06/15 05:31:32 | 000,000,276 | —- | C] () – C:\WINDOWS\System32\WiFiOFF.reg
[2012/06/15 05:31:30 | 000,000,860 | —- | C] () – C:\WINDOWS\System32\ChangeVLKey.vbs
[2012/06/15 05:31:18 | 000,000,079 | —- | C] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/06/15 05:31:11 | 000,000,800 | —- | C] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/06/15 05:26:07 | 000,000,681 | –S- | C] () – C:\Users\Administrator\Start Menu\Programs\Startup\Visual Task Tips.lnk
[2012/06/15 05:23:40 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\Helios.scr
[2012/06/15 05:23:40 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\Euphoria.scr
[2012/06/15 05:23:40 | 000,095,744 | —- | C] () – C:\WINDOWS\System32\Cyclone.scr
[2012/06/15 05:23:40 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\SolarWinds.scr
[2012/06/15 05:23:40 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\Flux.scr
[2012/06/15 05:23:39 | 001,634,304 | —- | C] () – C:\WINDOWS\System32\3D Windows XP.scr
[2012/06/15 05:22:19 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2012/06/15 05:22:18 | 000,000,414 | —- | C] () – C:\WINDOWS\System32\lame_acm.xml
[2012/06/15 05:22:17 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2012/06/15 05:22:17 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2012/06/15 05:22:16 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2012/06/15 05:22:16 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2012/06/15 05:19:33 | 000,221,184 | —- | C] () – C:\WINDOWS\System32\ThumbView_Lite.dll
[2012/06/15 05:19:33 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\tbhookin.dll
[2012/06/15 05:19:33 | 000,000,092 | —- | C] () – C:\WINDOWS\System32\ts_settings.ini
[2012/06/15 05:19:16 | 001,152,165 | —- | C] () – C:\WINDOWS\System32\HFExtract.exe
[2012/06/15 05:19:16 | 000,708,272 | —- | C] () – C:\WINDOWS\System32\Universal Silent Switch Finder.exe
[2012/06/15 05:19:16 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\PCalc.exe
[2012/06/15 05:19:16 | 000,210,432 | —- | C] () – C:\WINDOWS\System32\Notepad2.exe
[2012/06/15 05:19:16 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\mmm.dll
[2012/06/15 05:19:16 | 000,163,840 | —- | C] () – C:\WINDOWS\System32\metapath.exe
[2012/06/15 05:19:16 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\Cabarc.exe
[2012/06/15 05:19:16 | 000,110,085 | —- | C] () – C:\WINDOWS\System32\cdimage.exe
[2012/06/15 05:19:16 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\WallChan.exe
[2012/06/15 05:19:16 | 000,020,992 | —- | C] () – C:\WINDOWS\System32\Cabtool.exe
[2012/06/15 05:19:16 | 000,018,030 | —- | C] () – C:\WINDOWS\System32\Replacer.cmd
[2012/06/15 05:19:16 | 000,015,344 | —- | C] () – C:\WINDOWS\System32\Calcpt.chm
[2012/06/15 05:19:16 | 000,008,636 | —- | C] () – C:\WINDOWS\System32\modifyPE.exe
[2012/06/15 05:19:16 | 000,002,048 | —- | C] () – C:\WINDOWS\System32\xpBoot.img
[2012/06/15 05:19:16 | 000,001,546 | —- | C] () – C:\WINDOWS\System32\Universal Silent Switch Finder.lnk
[2012/06/15 05:19:16 | 000,001,503 | —- | C] () – C:\WINDOWS\System32\makeiso.cmd
[2012/06/15 05:19:16 | 000,001,373 | —- | C] () – C:\WINDOWS\System32\Reg2InfHandler.cmd
[2012/06/15 05:19:16 | 000,001,128 | —- | C] () – C:\WINDOWS\System32\WC.com
[2012/06/15 05:19:16 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\Notepad2.ini
[2012/06/15 05:18:45 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\cttune.cpl
[2012/06/15 05:18:45 | 000,131,072 | —- | C] ( ) – C:\WINDOWS\System32\drvback.cpl
[2012/06/15 05:18:45 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\Startup.cpl
[2012/06/15 05:18:45 | 000,005,446 | —- | C] () – C:\WINDOWS\System32\drvback.cpi
[2012/06/15 05:18:44 | 000,180,224 | —- | C] ( ) – C:\WINDOWS\System32\driverbackup.exe
[2012/06/15 05:18:38 | 000,494,557 | —- | C] () – C:\WINDOWS\System32\dxgi.dll
[2012/06/15 05:18:38 | 000,025,037 | —- | C] () – C:\WINDOWS\System32\Nucleus.dll
[2012/06/15 05:18:36 | 000,566,624 | —- | C] () – C:\WINDOWS\System32\d3d10.dll
[2012/06/15 05:18:36 | 000,519,912 | —- | C] () – C:\WINDOWS\System32\d3dx10.dll
[2012/06/15 05:18:18 | 000,001,396 | —- | C] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\MEDIA_CENTER.LNK
[2012/06/15 05:18:16 | 000,001,334 | –S- | C] () – C:\Users\Administrator\Start Menu\Programs\Media Center.lnk
[2012/06/15 05:15:18 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\WSTRENDR.AX
[2012/06/15 05:13:21 | 000,000,006 | —- | C] () – C:\WINDOWS\SetupSMenu.ini
[2012/06/15 05:13:21 | 000,000,006 | —- | C] () – C:\WINDOWS\LastXPSetupSMenu.ini
[2012/06/15 05:13:16 | 000,001,610 | –S- | C] () – C:\Users\Administrator\Start Menu\Programs\Clean Start Menu.lnk
[2012/06/15 05:10:26 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD
[2012/06/15 05:08:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2012/06/15 05:00:34 | 000,068,936 | —- | C] () – C:\Users\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/06/15 04:55:31 | 000,002,577 | —- | C] () – C:\WINDOWS\System32\CONFIG.NT
[2012/06/15 04:55:31 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2012/06/15 04:55:31 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2012/06/15 04:55:31 | 000,000,000 | —- | C] () – C:\CONFIG.SYS
[2012/06/15 04:55:31 | 000,000,000 | —- | C] () – C:\AUTOEXEC.BAT
[2012/06/15 04:55:23 | 000,023,392 | —- | C] () – C:\WINDOWS\System32\nscompat.tlb
[2012/06/15 04:55:23 | 000,016,832 | —- | C] () – C:\WINDOWS\System32\amcompat.tlb
[2012/06/15 04:55:21 | 000,316,640 | —- | C] () – C:\WINDOWS\WMSysPr9.prx
[2012/06/15 04:53:03 | 000,048,680 | -HS- | C] () – C:\WINDOWS\winnt256.bmp
[2012/06/15 04:53:03 | 000,048,680 | -HS- | C] () – C:\WINDOWS\winnt.bmp
[2012/06/15 04:50:42 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2012/06/15 04:49:50 | 000,271,264 | —- | C] () – C:\WINDOWS\System\vbrun100.dll
[2012/06/15 04:49:48 | 000,210,944 | —- | C] () – C:\WINDOWS\System\MSVCRT10.DLL
[2012/06/15 04:49:39 | 000,394,752 | —- | C] () – C:\WINDOWS\System32\cygwinb19.dll
[2012/06/15 04:49:15 | 000,065,954 | —- | C] () – C:\WINDOWS\Prairie Wind.bmp
[2012/06/15 04:49:15 | 000,065,832 | —- | C] () – C:\WINDOWS\Santa Fe Stucco.bmp
[2012/06/15 04:49:15 | 000,026,680 | —- | C] () – C:\WINDOWS\River Sumida.bmp
[2012/06/15 04:49:15 | 000,026,582 | —- | C] () – C:\WINDOWS\Greenstone.bmp
[2012/06/15 04:49:15 | 000,017,362 | —- | C] () – C:\WINDOWS\Rhododendron.bmp
[2012/06/15 04:49:15 | 000,009,522 | —- | C] () – C:\WINDOWS\Zapotec.bmp
[2012/06/15 04:49:14 | 000,065,978 | —- | C] () – C:\WINDOWS\Soap Bubbles.bmp
[2012/06/15 04:49:14 | 000,017,336 | —- | C] () – C:\WINDOWS\Gone Fishing.bmp
[2012/06/15 04:49:14 | 000,017,062 | —- | C] () – C:\WINDOWS\Coffee Bean.bmp
[2012/06/15 04:49:14 | 000,016,730 | —- | C] () – C:\WINDOWS\FeatherTexture.bmp
[2012/06/15 04:49:14 | 000,001,272 | —- | C] () – C:\WINDOWS\Blue Lace 16.bmp
[2012/06/15 04:49:09 | 000,003,286 | —- | C] () – C:\WINDOWS\System32\tslabels.h
[2012/06/15 04:49:09 | 000,001,161 | —- | C] () – C:\WINDOWS\System32\usrlogon.cmd
[2012/06/15 04:49:07 | 000,000,768 | —- | C] () – C:\WINDOWS\System32\msdtcprf.h
[2012/06/15 04:48:59 | 000,062,694 | —- | C] () – C:\WINDOWS\System32\wmimgmt.msc

< End of report >

NEXT

The ComboFix.Txt


ComboFix 12-06-24.03 - Administrator 06/25/2012 7:38.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.63.1033.18.2038.1442 [GMT 8:00]
Running from: d:\documents\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\1.reg
c:\windows\system32\drivers\1028_DELL_XPS_MM061 .MRK
c:\windows\system32\drivers\DELL_XPS_MM061 .MRK
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\settings.exe
c:\windows\system32\ShellExt\CmdOpen.dll
.
c:\windows\system32\LogonUI.exe . . . is infected!!
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_FAD
.
.
((((((((((((((((((((((((( Files Created from 2012-05-24 to 2012-06-24 )))))))))))))))))))))))))))))))
.
.
2012-06-18 14:55 . 2012-06-18 14:55 ——– d—–w- C:\$AVG
2012-06-17 21:35 . 2012-06-17 21:35 ——– d—–r- C:\Sandbox
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-31 13:22 . 2008-05-05 09:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2008-05-05 09:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-15 13:20 . 2008-05-05 09:00 1863168 —-a-w- c:\windows\system32\win32k.sys
2012-05-11 14:42 . 2008-05-05 09:00 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2008-05-05 09:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2008-05-05 09:00 385024 ——w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2008-05-05 09:00 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2008-04-14 00:01 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-23 14:45 . 2012-04-23 14:46 78336 ——w- c:\windows\system32\ieencode.dll
2012-04-18 20:50 . 2012-04-18 20:50 24896 —-a-w- c:\windows\system32\drivers\avgidshx.sys
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys
.
[7] 2008-05-05 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys
.
[7] 2008-05-05 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys
.
[7] 2008-04-14 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys
.
[7] 2008-05-05 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys
.
[7] 2008-05-05 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys
.
[7] 2008-05-05 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys
.
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\ff0686f2f699fa07ed5ad0848fa3055b\sp3qfe\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\ff0686f2f699fa07ed5ad0848fa3055b\sp3gdr\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-05-05 . C6BFEC6CC1DD2389D9334EE7838944FE . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2509553$\tcpip.sys
.
[7] 2008-05-05 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll
.
[7] 2008-05-05 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe
.
[7] 2008-05-05 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll
.
[-] 2008-05-05 09:00 . B6B7F218F51A3AA0AB2F300AEE1B1CE5 . 1526784 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[7] 2008-05-05 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll
.
[7] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\rpcss.dll
[7] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll
[7] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll
[7] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[7] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\rpcss.dll
[7] 2009-02-09 . 01095FEBF33BEEA00C2A0730B9B3EC28 . 399360 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\rpcss.dll
[7] 2009-02-09 . 24B5D53B9ACCC1E2EDCF0A878D6659D4 . 401408 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\rpcss.dll
[7] 2008-05-05 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\rpcss.dll
.
[7] 2009-02-06 . 37561F8D4160D62DA86D24AE41FAE8DE . 110592 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\services.exe
[7] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\services.exe
[7] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\services.exe
[7] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe
[7] 2009-02-06 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[7] 2009-02-06 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\services.exe
[7] 2009-02-06 . 4712531AB7A01B7EE059853CA17D39BD . 110592 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\services.exe
[7] 2008-05-05 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\services.exe
.
[7] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[7] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\SoftwareDistribution\Download\9460002f6d8231358fc1eb590f9b1dce\sp3qfe\spoolsv.exe
[7] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\SoftwareDistribution\Download\9460002f6d8231358fc1eb590f9b1dce\sp3gdr\spoolsv.exe
[7] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\spoolsv.exe
[7] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\dllcache\spoolsv.exe
[7] 2008-05-05 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2347290$\spoolsv.exe
.
[-] 2008-05-05 . 7DD9CE78DD441EEA2BBAFF6D3EEAAD08 . 557056 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
.
[7] 2009-08-06 . 62BB79160F86CD962F312C68C6239BFD . 53472 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
.
[7] 2008-05-05 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ipsec.sys
.
[7] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\21cbd3f70584651805685eba1753505f\SP3QFE\comctl32.dll
[7] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll
[7] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll
[7] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\21cbd3f70584651805685eba1753505f\asms\60\msft\windows\common\controls\comctl32.dll
[7] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\21cbd3f70584651805685eba1753505f\SP3QFE\asms\60\msft\windows\common\controls\comctl32.dll
[7] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
[-] 2008-05-05 . 247DFD6CBC939742D3EC7B53C120946F . 643072 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll
[7] 2008-05-05 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[7] 2008-05-05 . BD38D1EBE24A46BD3EDA059560AFBA12 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
.
[7] 2008-05-05 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll
.
[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\sp3gdr\es.dll
[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll
[7] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[7] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[7] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\sp3qfe\es.dll
[7] 2008-05-05 09:00 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\$NtUninstallKB950974$\es.dll
.
[7] 2008-05-05 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll
.
[7] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\SoftwareDistribution\Download\022593ca08eb4cd8e9681a7116f902d9\sp3gdr\kernel32.dll
[7] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll
[7] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll
[7] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[7] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\SoftwareDistribution\Download\022593ca08eb4cd8e9681a7116f902d9\sp3qfe\kernel32.dll
[7] 2008-05-05 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB959426$\kernel32.dll
.
[7] 2008-05-05 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll
.
[7] 2008-05-05 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll
.
[7] 2012-05-11 . 886B62A906B3967CBBF0FD2C833A30BF . 6007808 . . [8.00.6001.19258] . . c:\windows\SoftwareDistribution\Download\8ac5fac233c627c0171059130fa7b89a\SP3GDR\mshtml.dll
[7] 2012-05-11 . 886B62A906B3967CBBF0FD2C833A30BF . 6007808 . . [8.00.6001.19258] . . c:\windows\system32\mshtml.dll
[7] 2012-05-11 . 886B62A906B3967CBBF0FD2C833A30BF . 6007808 . . [8.00.6001.19258] . . c:\windows\system32\dllcache\mshtml.dll
[7] 2012-05-11 . 55F148B94246A77FB4AC33346671CAC8 . 6009344 . . [8.00.6001.23345] . . c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\mshtml.dll
[7] 2012-05-11 . 55F148B94246A77FB4AC33346671CAC8 . 6009344 . . [8.00.6001.23345] . . c:\windows\SoftwareDistribution\Download\8ac5fac233c627c0171059130fa7b89a\SP3QFE\mshtml.dll
[7] 2012-04-23 . 5EBAE291AA1351E68855E23E7A3C3DB8 . 3618816 . . [7.00.6000.17110] . . c:\windows\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3gdr\mshtml.dll
[7] 2012-04-23 . 80992CCC608A36B5C228B280B0E6124A . 3620864 . . [7.00.6000.21312] . . c:\windows\$hf_mig$\KB2699988-IE7\SP3QFE\mshtml.dll
[7] 2012-04-23 . 80992CCC608A36B5C228B280B0E6124A . 3620864 . . [7.00.6000.21312] . . c:\windows\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3qfe\mshtml.dll
[7] 2011-11-04 . DD8D655E1881B70A5259A23A6018A6C2 . 5978112 . . [8.00.6001.19170] . . c:\windows\ie8updates\KB2699988-IE8\mshtml.dll
[7] 2011-11-04 . DD8D655E1881B70A5259A23A6018A6C2 . 5978112 . . [8.00.6001.19170] . . c:\windows\SoftwareDistribution\Download\a6632ea9734d3683d8cc4b4a30215873\SP3GDR\mshtml.dll
[7] 2011-11-04 . 699421E2E1313C18671A703953CAE14B . 5978624 . . [8.00.6001.23266] . . c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtml.dll
[7] 2011-11-04 . 699421E2E1313C18671A703953CAE14B . 5978624 . . [8.00.6001.23266] . . c:\windows\SoftwareDistribution\Download\a6632ea9734d3683d8cc4b4a30215873\SP3QFE\mshtml.dll
[7] 2010-05-06 . C7B7A88CC7D7ABA5C395145BF92F46F7 . 5950976 . . [8.00.6001.18928] . . c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
[7] 2010-05-06 . C7B7A88CC7D7ABA5C395145BF92F46F7 . 5950976 . . [8.00.6001.18928] . . c:\windows\SoftwareDistribution\Download\e9e3bc7b49018c1f53cc0d1bd73cad37\SP3GDR\mshtml.dll
[7] 2010-05-06 . 9BE28F749A7FE7F8F177C6AA2E9DA609 . 5953024 . . [8.00.6001.23019] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll
[7] 2010-05-06 . 9BE28F749A7FE7F8F177C6AA2E9DA609 . 5953024 . . [8.00.6001.23019] . . c:\windows\SoftwareDistribution\Download\e9e3bc7b49018c1f53cc0d1bd73cad37\SP3QFE\mshtml.dll
[7] 2009-03-07 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB982381-IE8\mshtml.dll
[-] 2008-05-05 . 8B551F39D754995BED950112E21ADD02 . 4090368 . . [7.00.6000.20772] . . c:\windows\ie8\mshtml.dll
.
[7] 2008-05-05 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll
[7] 2008-05-05 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll
[7] 2008-05-05 . D7075E95AA599EE77B7A89D39296BD3D . 343040 . . [7.0.2600.5512] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
.
[7] 2008-06-20 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\mswsock.dll
[7] 2008-06-20 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\ff0686f2f699fa07ed5ad0848fa3055b\sp3qfe\mswsock.dll
[7] 2008-06-20 . 943337D786A56729263071623BBB9DE5 . 245248 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\ff0686f2f699fa07ed5ad0848fa3055b\sp3gdr\mswsock.dll
[7] 2008-06-20 . 943337D786A56729263071623BBB9DE5 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll
[7] 2008-06-20 . 943337D786A56729263071623BBB9DE5 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll
[7] 2008-05-05 . B4138E99236F0F57D4CF49BAE98A0746 . 245248 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2509553$\mswsock.dll
.
[7] 2008-05-05 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll
.
[7] 2008-05-05 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll
.
[7] 2008-05-05 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll
.
[7] 2008-05-05 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll
.
[7] 2008-05-05 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
.
[7] 2008-05-05 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll
.
[-] 2008-05-05 . 894B313C52589628BB996E175B581E3A . 578048 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
.
[7] 2008-05-05 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
.
[7] 2012-05-16 . 6B1774334E2975AA60596E54F5EA1430 . 916992 . . [8.00.6001.19272] . . c:\windows\SoftwareDistribution\Download\8ac5fac233c627c0171059130fa7b89a\SP3GDR\wininet.dll
[7] 2012-05-16 . 6B1774334E2975AA60596E54F5EA1430 . 916992 . . [8.00.6001.19272] . . c:\windows\system32\wininet.dll
[7] 2012-05-16 . 6B1774334E2975AA60596E54F5EA1430 . 916992 . . [8.00.6001.19272] . . c:\windows\system32\dllcache\wininet.dll
[7] 2012-05-16 . 553AD35768CD27959391DD5AA82CEF6F . 920064 . . [8.00.6001.23359] . . c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\wininet.dll
[7] 2012-05-16 . 553AD35768CD27959391DD5AA82CEF6F . 920064 . . [8.00.6001.23359] . . c:\windows\SoftwareDistribution\Download\8ac5fac233c627c0171059130fa7b89a\SP3QFE\wininet.dll
[7] 2012-05-15 . 4728B67CC9190C8F46500A9DF97F1490 . 832512 . . [7.00.6000.17111] . . c:\windows\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3gdr\wininet.dll
[7] 2012-05-15 . 30EC18A4F840E14B3753CDBEC6DA4178 . 841216 . . [7.00.6000.21313] . . c:\windows\$hf_mig$\KB2699988-IE7\SP3QFE\wininet.dll
[7] 2012-05-15 . 30EC18A4F840E14B3753CDBEC6DA4178 . 841216 . . [7.00.6000.21313] . . c:\windows\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3qfe\wininet.dll
[7] 2011-11-04 . 552263502EA8C24D301A0C43FF90B3ED . 916992 . . [8.00.6001.19165] . . c:\windows\ie8updates\KB2699988-IE8\wininet.dll
[7] 2011-11-04 . 552263502EA8C24D301A0C43FF90B3ED . 916992 . . [8.00.6001.19165] . . c:\windows\SoftwareDistribution\Download\a6632ea9734d3683d8cc4b4a30215873\SP3GDR\wininet.dll
[7] 2011-11-04 . 4E4716CAF514717814D07113AD0425B6 . 919552 . . [8.00.6001.23261] . . c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\wininet.dll
[7] 2011-11-04 . 4E4716CAF514717814D07113AD0425B6 . 919552 . . [8.00.6001.23261] . . c:\windows\SoftwareDistribution\Download\a6632ea9734d3683d8cc4b4a30215873\SP3QFE\wininet.dll
[7] 2010-05-06 . 2D9C7B010409372C34F725DA5CCED083 . 916480 . . [8.00.6001.18923] . . c:\windows\ie8updates\KB2618444-IE8\wininet.dll
[7] 2010-05-06 . 2D9C7B010409372C34F725DA5CCED083 . 916480 . . [8.00.6001.18923] . . c:\windows\SoftwareDistribution\Download\e9e3bc7b49018c1f53cc0d1bd73cad37\SP3GDR\wininet.dll
[7] 2010-05-06 . C1490F68B44AF8B781F52F12F564625D . 919040 . . [8.00.6001.23014] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll
[7] 2010-05-06 . C1490F68B44AF8B781F52F12F564625D . 919040 . . [8.00.6001.23014] . . c:\windows\SoftwareDistribution\Download\e9e3bc7b49018c1f53cc0d1bd73cad37\SP3QFE\wininet.dll
[7] 2009-03-07 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB982381-IE8\wininet.dll
[-] 2008-05-05 . 62850E0C92990F9D3A91CB67A3F2C3F5 . 893952 . . [7.00.6000.20772] . . c:\windows\ie8\wininet.dll
.
[7] 2008-05-05 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll
.
[7] 2008-05-05 . 9789E95E1D88EEB4B922BF3EA7779C28 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\ws2help.dll
.
[-] 2008-05-05 . 5F7009A7CB02AE2685746B34B063D3DD . 1572352 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-05-05 . 010557F708034EB8E614D1AF93ED74E1 . 275456 . . [5.1.2600.5512] . . c:\windows\regedit.exe
.
[7] 2011-11-01 . 6BAD1BED9872E62049E487FB91AE2F3A . 1288704 . . [5.1.2600.6168] . . c:\windows\SoftwareDistribution\Download\1dfa26aa7c55425acf0fd8a07e6aaee7\sp3gdr\ole32.dll
[7] 2011-11-01 . 6BAD1BED9872E62049E487FB91AE2F3A . 1288704 . . [5.1.2600.6168] . . c:\windows\system32\ole32.dll
[7] 2011-11-01 . 6BAD1BED9872E62049E487FB91AE2F3A . 1288704 . . [5.1.2600.6168] . . c:\windows\system32\dllcache\ole32.dll
[7] 2011-11-01 . 7D9DDE1AB4B00DDB173F5A16E9206517 . 1289216 . . [5.1.2600.6168] . . c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll
[7] 2011-11-01 . 7D9DDE1AB4B00DDB173F5A16E9206517 . 1289216 . . [5.1.2600.6168] . . c:\windows\SoftwareDistribution\Download\1dfa26aa7c55425acf0fd8a07e6aaee7\sp3qfe\ole32.dll
[7] 2010-07-16 . 7A6A7900B5E322763430BA6FD9A31224 . 1288192 . . [5.1.2600.6010] . . c:\windows\$NtUninstallKB2624667$\ole32.dll
[7] 2010-07-16 . 7A6A7900B5E322763430BA6FD9A31224 . 1288192 . . [5.1.2600.6010] . . c:\windows\SoftwareDistribution\Download\e104dcd29adf1c6c473a5efad2d509be\sp3gdr\ole32.dll
[7] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\$hf_mig$\KB979687\SP3QFE\ole32.dll
[7] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\SoftwareDistribution\Download\e104dcd29adf1c6c473a5efad2d509be\sp3qfe\ole32.dll
[7] 2008-05-05 . ECCE74BC6168375016450A86A164D976 . 1287168 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB979687$\ole32.dll
.
[-] 2008-05-05 . 3122DAF86B33ED8AC4662D07593025D7 . 501760 . . [1.0626.6001.18000] . . c:\windows\system32\usp10.dll
.
[7] 2008-04-13 . 9B9F1C38D559047B8AC0DBA2D5FEBDE9 . 4096 . . [5.3.2600.5512] . . c:\windows\system32\ksuser.dll
.
[-] 2008-05-05 . C1D50243355A290CB3AA684FD8B38170 . 40448 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
.
[7] 2009-07-27 . 99BC0B50F511924348BE19C7C7313BBF . 135168 . . [6.00.2900.5853] . . c:\windows\SoftwareDistribution\Download\cedca0128a48437390192d906f83a717\sp3gdr\shsvcs.dll
[7] 2009-07-27 . 99BC0B50F511924348BE19C7C7313BBF . 135168 . . [6.00.2900.5853] . . c:\windows\system32\shsvcs.dll
[7] 2009-07-27 . 99BC0B50F511924348BE19C7C7313BBF . 135168 . . [6.00.2900.5853] . . c:\windows\system32\dllcache\shsvcs.dll
[7] 2009-07-27 . 888CD7B39C37E13A2419BECFAAF0A28C . 135168 . . [6.00.2900.5853] . . c:\windows\$hf_mig$\KB971029\SP3QFE\shsvcs.dll
[7] 2009-07-27 . 888CD7B39C37E13A2419BECFAAF0A28C . 135168 . . [6.00.2900.5853] . . c:\windows\SoftwareDistribution\Download\cedca0128a48437390192d906f83a717\sp3qfe\shsvcs.dll
[7] 2008-05-05 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB971029$\shsvcs.dll
.
[7] 2008-05-05 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll
.
[7] 2008-05-05 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
.
[7] 2008-05-05 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll
.
[7] 2008-05-05 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll
.
[7] 2008-05-05 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
[7] 2008-05-05 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ipsec.sys
.
[7] 2008-05-05 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll
.
[7] 2008-05-05 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll
.
[7] 2008-05-05 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll
.
[7] 2008-05-05 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
.
[7] 2008-05-05 . 3CB32D3B8CBE79899D63280BB7A83CD9 . 344064 . . [5.1.2600.5512] . . c:\windows\system32\hnetcfg.dll
.
[7] 2008-05-05 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\system32\appmgmts.dll
.
[7] 2008-05-05 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys
.
[7] 2008-04-13 22:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys
.
[7] 2008-05-05 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys
.
[7] 2010-09-18 07:18 . 842900DEDBC8E3E8DBCCCB298FD88F65 . 953856 . . [4.1.6151] . . c:\windows\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll
[7] 2010-09-18 07:18 . 842900DEDBC8E3E8DBCCCB298FD88F65 . 953856 . . [4.1.6151] . . c:\windows\SoftwareDistribution\Download\b91377d1d56820d9d699c0c2dc7c8e80\SP3QFE\mfc40u.dll
[7] 2010-09-18 06:53 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . c:\windows\SoftwareDistribution\Download\b91377d1d56820d9d699c0c2dc7c8e80\SP3GDR\mfc40u.dll
[7] 2010-09-18 06:53 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . c:\windows\system32\mfc40u.dll
[7] 2010-09-18 06:53 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . c:\windows\system32\dllcache\mfc40u.dll
[7] 2008-05-05 09:00 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\$NtUninstallKB2387149$\mfc40u.dll
.
[7] 2008-05-05 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll
.
[7] 2008-05-05 09:00 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
.
[7] 2012-05-04 . 8E99A0CE02C1BEDA6C0935A4DDE9CEAA . 2069120 . . [5.1.2600.6223] . . c:\windows\$hf_mig$\KB2707511\SP3QFE\ntkrnlpa.exe
[7] 2012-05-04 . 8E99A0CE02C1BEDA6C0935A4DDE9CEAA . 2069120 . . [5.1.2600.6223] . . c:\windows\SoftwareDistribution\Download\08dc6fdd6e5cdbc939c4d8b98c94c9fd\sp3qfe\ntkrnlpa.exe
[7] 2012-05-04 . 5DD80D56AF1CEFBFF4F25951069B55BB . 2069120 . . [5.1.2600.6223] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[7] 2012-05-04 . 5DD80D56AF1CEFBFF4F25951069B55BB . 2069120 . . [5.1.2600.6223] . . c:\windows\SoftwareDistribution\Download\08dc6fdd6e5cdbc939c4d8b98c94c9fd\sp3gdr\ntkrnlpa.exe
[7] 2012-05-04 . 87763BB6C95901818050E52C378C9E15 . 2026496 . . [5.1.2600.6223] . . c:\windows\system32\ntkrnlpa.exe
[7] 2012-05-04 . 5DD80D56AF1CEFBFF4F25951069B55BB . 2069120 . . [5.1.2600.6223] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[7] 2012-04-11 . 063A0F8A90D8E2B802E5243FE9AABCF3 . 2069120 . . [5.1.2600.6206] . . c:\windows\$hf_mig$\KB2676562\SP3QFE\ntkrnlpa.exe
[7] 2012-04-11 . 063A0F8A90D8E2B802E5243FE9AABCF3 . 2069120 . . [5.1.2600.6206] . . c:\windows\SoftwareDistribution\Download\888bd630a02581b550845dde5f47a0ee\sp3qfe\ntkrnlpa.exe
[7] 2012-04-11 . 0C9E44D256948FA68AE10D67984862CE . 2069120 . . [5.1.2600.6206] . . c:\windows\SoftwareDistribution\Download\888bd630a02581b550845dde5f47a0ee\sp3gdr\ntkrnlpa.exe
[7] 2012-04-11 . 61CCE48F7BD00E0E4D5CDE206F2DDC1B . 2026496 . . [5.1.2600.6206] . . c:\windows\$NtUninstallKB2707511$\ntkrnlpa.exe
[7] 2010-12-09 . 9ED77E2307F6EC6F174C063C15AA3B8C . 2027008 . . [5.1.2600.6055] . . c:\windows\$NtUninstallKB2676562$\ntkrnlpa.exe
[7] 2010-12-09 . 84FF488E249DBD2050EB39EA81C6F5C2 . 2069376 . . [5.1.2600.6055] . . c:\windows\SoftwareDistribution\Download\f35839bf00bc83543dbda7acaf1e2a3b\SP3GDR\ntkrnlpa.exe
[7] 2010-12-09 . F67CD97282E0ABFAF91A9A1359B16F2D . 2069376 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntkrnlpa.exe
[7] 2010-12-09 . F67CD97282E0ABFAF91A9A1359B16F2D . 2069376 . . [5.1.2600.6055] . . c:\windows\SoftwareDistribution\Download\f35839bf00bc83543dbda7acaf1e2a3b\SP3QFE\ntkrnlpa.exe
[7] 2009-02-07 . 5BA7F2141BC6DB06100D0E5A732C617A . 2066048 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntkrnlpa.exe
[7] 2009-02-06 . 3006410E24772CC6953F0B5C01BEB35F . 2057728 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntkrnlpa.exe
[7] 2009-02-06 . 65D4220799E6FC2CB079070A6393CC0E . 2023936 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB2393802$\ntkrnlpa.exe
[7] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[7] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntkrnlpa.exe
[7] 2009-02-06 . 9D832AF3FD1917DB0E1E8B2F000A2E3A . 2062976 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntkrnlpa.exe
[-] 2008-05-05 . 2CD0BB34636A23A12A6013EFBB52FFB1 . 2185216 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe
.
[7] 2008-05-05 09:00 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll
.
[7] 2008-05-05 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll
.
[7] 2008-05-05 . 4D83ED8BDDEC431FC8AD907B47CFB6E3 . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dsound.dll
.
[7] 2008-05-05 . 0607CBC6FA20114CB491EFE4B2F9EFAD . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\d3d9.dll
.
[7] 2008-05-05 . A340CD71EB535A3DD751B5F28723E50C . 279552 . . [5.03.2600.5512] . . c:\windows\system32\ddraw.dll
.
[7] 2008-05-05 09:00 . 5652F6CE1D9E9D8068B9D29BC21B5409 . 84992 . . [5.1.2600.5512] . . c:\windows\system32\olepro32.dll
.
[7] 2008-05-05 . DBE2B62353660ECCA0D75EA307A717E9 . 39936 . . [5.1.2600.5512] . . c:\windows\system32\perfctrs.dll
.
[7] 2008-05-05 . C7CE131408739B0B3A318BE2D0032719 . 18944 . . [5.1.2600.5512] . . c:\windows\system32\version.dll
.
[7] 2012-04-22 . 0A39EEAD063CCDFF36AC9F0B8F800956 . 634488 . . [7.00.6000.17110] . . c:\windows\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3gdr\iexplore.exe
[7] 2012-04-22 . CE2379FC341C65CAD88FF8264A791AB5 . 634488 . . [7.00.6000.21312] . . c:\windows\$hf_mig$\KB2699988-IE7\SP3QFE\iexplore.exe
[7] 2012-04-22 . CE2379FC341C65CAD88FF8264A791AB5 . 634488 . . [7.00.6000.21312] . . c:\windows\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3qfe\iexplore.exe
[7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe
[-] 2008-05-05 . 2B871F81648C6DF2B65E48124DE5FB04 . 817152 . . [7.00.6000.20772] . . c:\windows\ie8\iexplore.exe
.
[7] 2012-05-04 . 099A0F80A563EBE935F4A9750F96C219 . 2192640 . . [5.1.2600.6223] . . c:\windows\$hf_mig$\KB2707511\SP3QFE\ntoskrnl.exe
[7] 2012-05-04 . 099A0F80A563EBE935F4A9750F96C219 . 2192640 . . [5.1.2600.6223] . . c:\windows\SoftwareDistribution\Download\08dc6fdd6e5cdbc939c4d8b98c94c9fd\sp3qfe\ntoskrnl.exe
[7] 2012-05-04 . AC4B3C4A6DC31867034C66663B9B8A38 . 2148352 . . [5.1.2600.6223] . . c:\windows\system32\ntoskrnl.exe
[7] 2012-05-04 . DDF0CB8CD3C6007CDF4AD8F0409ED930 . 2192640 . . [5.1.2600.6223] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[7] 2012-05-04 . DDF0CB8CD3C6007CDF4AD8F0409ED930 . 2192640 . . [5.1.2600.6223] . . c:\windows\SoftwareDistribution\Download\08dc6fdd6e5cdbc939c4d8b98c94c9fd\sp3gdr\ntoskrnl.exe
[7] 2012-05-04 . DDF0CB8CD3C6007CDF4AD8F0409ED930 . 2192640 . . [5.1.2600.6223] . . c:\windows\system32\dllcache\ntoskrnl.exe
[7] 2012-04-11 . 8D061BB825BC606C2B1C6F7452D1BAAA . 2192640 . . [5.1.2600.6206] . . c:\windows\$hf_mig$\KB2676562\SP3QFE\ntoskrnl.exe
[7] 2012-04-11 . 8D061BB825BC606C2B1C6F7452D1BAAA . 2192640 . . [5.1.2600.6206] . . c:\windows\SoftwareDistribution\Download\888bd630a02581b550845dde5f47a0ee\sp3qfe\ntoskrnl.exe
[7] 2012-04-11 . A144D60B35E6DD14CCB9649B5E0D1092 . 2148352 . . [5.1.2600.6206] . . c:\windows\$NtUninstallKB2707511$\ntoskrnl.exe
[7] 2012-04-11 . 536168936EBF326E36C655EC5AE34B03 . 2192640 . . [5.1.2600.6206] . . c:\windows\SoftwareDistribution\Download\888bd630a02581b550845dde5f47a0ee\sp3gdr\ntoskrnl.exe
[7] 2010-12-09 . A531BBD3DE13121C1380ED7DC99082DB . 2192768 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntoskrnl.exe
[7] 2010-12-09 . A531BBD3DE13121C1380ED7DC99082DB . 2192768 . . [5.1.2600.6055] . . c:\windows\SoftwareDistribution\Download\f35839bf00bc83543dbda7acaf1e2a3b\SP3QFE\ntoskrnl.exe
[7] 2010-12-09 . 60E16152D847D7A7B7D3DA4C4B8E2120 . 2148864 . . [5.1.2600.6055] . . c:\windows\$NtUninstallKB2676562$\ntoskrnl.exe
[7] 2010-12-09 . 64C1ADF6DF629F340C5A439FE0EF8ED1 . 2192768 . . [5.1.2600.6055] . . c:\windows\SoftwareDistribution\Download\f35839bf00bc83543dbda7acaf1e2a3b\SP3GDR\ntoskrnl.exe
[7] 2009-02-07 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[7] 2009-02-07 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntoskrnl.exe
[7] 2009-02-06 . FACEBB0CA3154F77009CDFEE78A00BBB . 2180480 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntoskrnl.exe
[7] 2009-02-06 . 7A95B10A73737EBF24139AAA63F5212B . 2189056 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntoskrnl.exe
[7] 2009-02-06 . 0CBA44D0938D57F334C0862424148B70 . 2145280 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB2393802$\ntoskrnl.exe
[7] 2009-02-06 . 6A936E9D7BADAF3CAAEED1E1966EC1B0 . 2186112 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntoskrnl.exe
[-] 2008-05-05 . B007CF3F9F24937DF0780408EADC32DC . 2306560 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\ntoskrnl.exe
.
[7] 2008-05-05 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll
.
[7] 2008-05-05 . 54AF4B1D5459500EF0937F6D33B1914F . 175104 . . [5.1.2600.5512] . . c:\windows\system32\w32time.dll
.
[7] 2008-05-05 . 8BAD69CBAC032D4BBACFCE0306174C30 . 333824 . . [5.1.2600.5512] . . c:\windows\system32\wiaservc.dll
.
[7] 2008-05-05 . 5C12660A97822F6E61576943B49AAAD6 . 18944 . . [5.1.2600.5512] . . c:\windows\system32\midimap.dll
.
[7] 2008-05-05 . 6F9BEF24C578D5D6740E080BEDD6A448 . 7680 . . [5.1.2600.5512] . . c:\windows\system32\rasadhlp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
"Taskbar Shuffle"="c:\windows\system32\taskbarshuffle.exe" [2008-04-16 818176]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2011-11-23 442640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-09 59392]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"DriveSpace"="c:\program files\Drive Space Indicator\DrvSpace.exe" [2008-05-17 371626]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-26 206064]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-04 2587008]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-05-05 40448]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-07 128512]
"NewUser"="c:\windows\LastXP\NewUser.cmd" [2008-05-05 2094]
.
c:\users\Administrator\Start Menu\Programs\Startup\
Visual Task Tips.lnk - c:\ppapps\VisualTaskTips\VisualTaskTips.exe [2012-6-15 61440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart\0Partizan
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\7-Zip\\7zFM.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 4:50 AM 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [1/31/2012 4:46 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2/22/2012 5:25 AM 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [3/19/2012 5:17 AM 301248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [4/30/2012 9:44 AM 5106744]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 4:53 AM 193288]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 1:32 PM 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 1:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 1:32 PM 17232]
S1 vfhuhmou;vfhuhmou;\??\c:\windows\system32\drivers\vfhuhmou.sys –> c:\windows\system32\drivers\vfhuhmou.sys [?]
S2 AutoExNT;AutoExNT;c:\windows\system32\AutoExNT.Exe –> c:\windows\system32\AutoExNT.Exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6/18/2012 10:30 PM 257224]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [6/18/2012 10:55 PM 235648]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
*Deregistered* - Partizan
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-18 14:30]
.
2012-06-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-1606980848-500Core.job
- c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-06-19 17:57]
.
2012-06-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-1606980848-500UA.job
- c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-06-19 17:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
TCP: DhcpNameServer = 192.168.1.1
.
.
——- File Associations ——-
.
inifile=c:\windows\system32\Notepad2.exe %1
txtfile=c:\windows\system32\Notepad2.exe %1
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-RemoveIT Pro v7Ent - c:\program files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-25 07:46
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-823518204-616249376-1606980848-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,46,6e,23,26,d2,58,49,41,b7,84,a8,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,46,6e,23,26,d2,58,49,41,b7,84,a8,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1052)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\COMRes.dll
c:\windows\System32\BCMLogon.dll
c:\windows\system32\cscui.dll
.
- - - - - - - > 'lsass.exe'(1112)
c:\windows\system32\setupapi.dll
.
- - - - - - - > 'explorer.exe'(3788)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\ppapps\VisualTaskTips\VttHooks.dll
c:\windows\system32\msctfime.ime
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\netshell.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
.
———————— Other Running Processes ————————
.
c:\program files\Sandboxie\SbieSvc.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\windows\System32\snmp.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\program files\AVG\AVG2012\avgrsx.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2012-06-25 07:49:31 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-24 23:49
.
Pre-Run: 18,944,090,112 bytes free
Post-Run: 18,881,167,360 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff
.
- - End Of File - - 9CA9536712E68BC6A79F5B96A5360E15


That is all SatchFan. I hope I did nothing wrong. ;)

ShayeDrake
Some strange reading in that log. It also shows an infected file that will need to be replaced.

Run TDSSKiller

Please download TDSSKiller.zip
  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan

    only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.

  • click Continue > Reboot now

  • copy and paste the log in your next reply
  • a copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)

======================================

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2
  • double-click SystemLook.exe to run it.
  • copy the content of the following codebox into the main textfield - please make sure you include the colon, (:), at the beginning.:

    :filefind
    *logonui*

  • click the Look button to start the scan.
  • when finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Logs to include with next post:

TDSSKiller log
SystemLook.txt[


Satchfan
Hey there, SatchFan.

How are we doing today?


Just finished the task I was asked for and here what's happened:
> Downloaded, unzipped TDSSKiller, and ran it.
> No malicious object so clicked continue and reboot.

Here's the TDSSKiller Log :

18:24:16.0000 0812 TDSS rootkit removing tool 2.7.41.0 Jun 20 2012 20:53:32
18:24:17.0171 0812 ============================================================
18:24:17.0171 0812 Current date / time: 2012/06/25 18:24:17.0171
18:24:17.0171 0812 SystemInfo:
18:24:17.0171 0812
18:24:17.0171 0812 OS Version: 5.1.2600 ServicePack: 3.0
18:24:17.0171 0812 Product type: Workstation
18:24:17.0171 0812 ComputerName: EyeC4Ndy
18:24:17.0171 0812 UserName: Administrator
18:24:17.0171 0812 Windows directory: C:\WINDOWS
18:24:17.0171 0812 System windows directory: C:\WINDOWS
18:24:17.0171 0812 Processor architecture: Intel x86
18:24:17.0171 0812 Number of processors: 2
18:24:17.0171 0812 Page size: 0x1000
18:24:17.0171 0812 Boot type: Normal boot
18:24:17.0171 0812 ============================================================
18:24:20.0125 0812 Drive \Device\Harddisk0\DR0 - Size: 0x1248119400 (73.13 Gb), SectorSize: 0x200, Cylinders: 0x254A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
18:24:20.0156 0812 Drive \Device\Harddisk1\DR5 - Size: 0x1E150DE00 (7.52 Gb), SectorSize: 0x200, Cylinders: 0x3D5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
18:24:20.0156 0812 ============================================================
18:24:20.0156 0812 \Device\Harddisk0\DR0:
18:24:20.0156 0812 MBR partitions:
18:24:20.0156 0812 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0x3A962F0
18:24:20.0171 0812 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3AADBB5, BlocksNum 0x4E46176
18:24:20.0171 0812 \Device\Harddisk1\DR5:
18:24:20.0171 0812 MBR partitions:
18:24:20.0171 0812 \Device\Harddisk1\DR5\Partition0: MBR, Type 0xB, StartLBA 0x3F, BlocksNum 0xF07956
18:24:20.0171 0812 ============================================================
18:24:20.0296 0812 C: <-> \Device\Harddisk0\DR0\Partition0
18:24:20.0343 0812 D: <-> \Device\Harddisk0\DR0\Partition1
18:24:20.0343 0812 ============================================================
18:24:20.0343 0812 Initialize success
18:24:20.0343 0812 ============================================================
18:24:53.0515 4032 ============================================================
18:24:53.0515 4032 Scan started
18:24:53.0515 4032 Mode: Manual;
18:24:53.0515 4032 ============================================================
18:24:53.0750 4032 Abiosdsk - ok
18:24:53.0765 4032 abp480n5 - ok
18:24:53.0796 4032 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:24:53.0796 4032 ACPI - ok
18:24:53.0828 4032 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
18:24:53.0828 4032 ACPIEC - ok
18:24:53.0906 4032 AdobeFlashPlayerUpdateSvc (f3cd7b20b27d1772c946df993ff3635c) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:24:53.0906 4032 AdobeFlashPlayerUpdateSvc - ok
18:24:53.0906 4032 adpu160m - ok
18:24:53.0968 4032 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
18:24:53.0968 4032 aec - ok
18:24:54.0015 4032 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
18:24:54.0015 4032 AFD - ok
18:24:54.0031 4032 Aha154x - ok
18:24:54.0031 4032 aic78u2 - ok
18:24:54.0031 4032 aic78xx - ok
18:24:54.0078 4032 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
18:24:54.0078 4032 Alerter - ok
18:24:54.0109 4032 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
18:24:54.0109 4032 ALG - ok
18:24:54.0109 4032 AliIde - ok
18:24:54.0125 4032 amsint - ok
18:24:54.0156 4032 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
18:24:54.0156 4032 APPDRV - ok
18:24:54.0187 4032 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll
18:24:54.0203 4032 AppMgmt - ok
18:24:54.0203 4032 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
18:24:54.0203 4032 Arp1394 - ok
18:24:54.0218 4032 asc - ok
18:24:54.0218 4032 asc3350p - ok
18:24:54.0234 4032 asc3550 - ok
18:24:54.0328 4032 aspnet_state (4eabf511b1af176a971c3271e48fa3a8) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
18:24:54.0343 4032 aspnet_state - ok
18:24:54.0375 4032 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:24:54.0375 4032 AsyncMac - ok
18:24:54.0421 4032 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
18:24:54.0421 4032 atapi - ok
18:24:54.0421 4032 Atdisk - ok
18:24:54.0453 4032 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:24:54.0453 4032 Atmarpc - ok
18:24:54.0484 4032 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
18:24:54.0484 4032 AudioSrv - ok
18:24:54.0515 4032 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
18:24:54.0531 4032 audstub - ok
18:24:54.0531 4032 AutoExNT - ok
18:24:55.0062 4032 AVGIDSAgent (ba60fd7a64b9759a14c0fba4a9ed4c7b) C:\Program Files\AVG\AVG2012\avgidsagent.exe
18:24:55.0171 4032 AVGIDSAgent - ok
18:24:55.0328 4032 AVGIDSDriver (1074f787080068c71303b61fae7e7ca4) C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys
18:24:55.0328 4032 AVGIDSDriver - ok
18:24:55.0343 4032 AVGIDSFilter (61a7e0b02f82cff3db2445bbe50b3589) C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys
18:24:55.0343 4032 AVGIDSFilter - ok
18:24:55.0359 4032 AVGIDSHX (d63d83659eedf60b3a3e620281a888e5) C:\WINDOWS\system32\DRIVERS\avgidshx.sys
18:24:55.0359 4032 AVGIDSHX - ok
18:24:55.0375 4032 AVGIDSShim (baf975b72062f53d327788e99d64197e) C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys
18:24:55.0375 4032 AVGIDSShim - ok
18:24:55.0406 4032 Avgldx86 (dda6a2a18841e4c9172bb85958b8d948) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
18:24:55.0421 4032 Avgldx86 - ok
18:24:55.0421 4032 Avgmfx86 (ccdd61545aaea265977e4b1efdc74e8c) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
18:24:55.0437 4032 Avgmfx86 - ok
18:24:55.0437 4032 Avgrkx86 (1fd90b28d2c3100bf4500199c8ad6358) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
18:24:55.0437 4032 Avgrkx86 - ok
18:24:55.0468 4032 Avgtdix (1263f2554ace925c237a40b4c568d815) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
18:24:55.0484 4032 Avgtdix - ok
18:24:55.0562 4032 avgwd (ea1145debcd508fd25bd1e95c4346929) C:\Program Files\AVG\AVG2012\avgwdsvc.exe
18:24:55.0562 4032 avgwd - ok
18:24:55.0703 4032 BCM43XX (e9ea635b8432d68f0005b3f6cebab837) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
18:24:55.0750 4032 BCM43XX - ok
18:24:55.0781 4032 bcm4sbxp (cd4646067cc7dcba1907fa0acf7e3966) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
18:24:55.0781 4032 bcm4sbxp - ok
18:24:55.0828 4032 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
18:24:55.0828 4032 Beep - ok
18:24:55.0890 4032 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
18:24:55.0921 4032 BITS - ok
18:24:55.0968 4032 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
18:24:55.0968 4032 Browser - ok
18:24:55.0984 4032 catchme - ok
18:24:56.0000 4032 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
18:24:56.0000 4032 cbidf2k - ok
18:24:56.0015 4032 cd20xrnt - ok
18:24:56.0015 4032 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
18:24:56.0031 4032 Cdaudio - ok
18:24:56.0046 4032 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
18:24:56.0062 4032 Cdfs - ok
18:24:56.0078 4032 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:24:56.0078 4032 Cdrom - ok
18:24:56.0078 4032 Changer - ok
18:24:56.0109 4032 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
18:24:56.0109 4032 CiSvc - ok
18:24:56.0125 4032 ClipSrv (2cc07f4116c8bb9e138ad5c13a126a32) C:\WINDOWS\system32\clipsrv.exe
18:24:56.0125 4032 ClipSrv - ok
18:24:56.0203 4032 clr_optimization_v2.0.50727_32 (234b1bc2796483e1f5c3f26649fb3388) c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:24:56.0250 4032 clr_optimization_v2.0.50727_32 - ok
18:24:56.0281 4032 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
18:24:56.0281 4032 CmBatt - ok
18:24:56.0296 4032 CmdIde - ok
18:24:56.0296 4032 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
18:24:56.0296 4032 Compbatt - ok
18:24:56.0312 4032 COMSysApp - ok
18:24:56.0328 4032 Cpqarray - ok
18:24:56.0343 4032 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
18:24:56.0343 4032 CryptSvc - ok
18:24:56.0343 4032 dac2w2k - ok
18:24:56.0359 4032 dac960nt - ok
18:24:56.0421 4032 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
18:24:56.0437 4032 DcomLaunch - ok
18:24:56.0453 4032 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
18:24:56.0453 4032 Dhcp - ok
18:24:56.0468 4032 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
18:24:56.0468 4032 Disk - ok
18:24:56.0468 4032 dmadmin - ok
18:24:56.0546 4032 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
18:24:56.0562 4032 dmboot - ok
18:24:56.0593 4032 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
18:24:56.0609 4032 dmio - ok
18:24:56.0640 4032 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
18:24:56.0640 4032 dmload - ok
18:24:56.0640 4032 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
18:24:56.0640 4032 dmserver - ok
18:24:56.0671 4032 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
18:24:56.0671 4032 DMusic - ok
18:24:56.0703 4032 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
18:24:56.0718 4032 Dnscache - ok
18:24:56.0750 4032 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
18:24:56.0750 4032 Dot3svc - ok
18:24:56.0750 4032 dpti2o - ok
18:24:56.0765 4032 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
18:24:56.0765 4032 drmkaud - ok
18:24:56.0781 4032 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
18:24:56.0781 4032 EapHost - ok
18:24:56.0859 4032 ehRecvr (27434c42a13c11f92ca45840b720d671) C:\WINDOWS\eHome\ehRecvr.exe
18:24:56.0875 4032 ehRecvr - ok
18:24:56.0890 4032 ehSched (16910f8b482919bb6035ed053b691692) C:\WINDOWS\eHome\ehSched.exe
18:24:56.0890 4032 ehSched - ok
18:24:56.0906 4032 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
18:24:56.0906 4032 ERSvc - ok
18:24:56.0921 4032 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
18:24:56.0937 4032 Eventlog - ok
18:24:57.0015 4032 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll
18:24:57.0015 4032 EventSystem - ok
18:24:57.0031 4032 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
18:24:57.0031 4032 Fastfat - ok
18:24:57.0078 4032 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
18:24:57.0093 4032 FastUserSwitchingCompatibility - ok
18:24:57.0125 4032 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
18:24:57.0125 4032 Fdc - ok
18:24:57.0156 4032 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
18:24:57.0156 4032 Fips - ok
18:24:57.0171 4032 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
18:24:57.0171 4032 Flpydisk - ok
18:24:57.0218 4032 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
18:24:57.0218 4032 FltMgr - ok
18:24:57.0296 4032 FontCache3.0.0.0 (993883524aa9cf1c90e1545411a9ac9c) c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:24:57.0296 4032 FontCache3.0.0.0 - ok
18:24:57.0312 4032 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:24:57.0312 4032 Fs_Rec - ok
18:24:57.0343 4032 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:24:57.0343 4032 Ftdisk - ok
18:24:57.0390 4032 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:24:57.0390 4032 Gpc - ok
18:24:57.0406 4032 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:24:57.0421 4032 HDAudBus - ok
18:24:57.0468 4032 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
18:24:57.0468 4032 helpsvc - ok
18:24:57.0468 4032 HidServ - ok
18:24:57.0500 4032 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:24:57.0500 4032 hidusb - ok
18:24:57.0531 4032 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
18:24:57.0531 4032 hkmsvc - ok
18:24:57.0546 4032 hpn - ok
18:24:57.0656 4032 HSF_DPV (e8ec1767ea315a39a0dd8989952ca0e9) C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys
18:24:57.0671 4032 HSF_DPV - ok
18:24:57.0687 4032 HSXHWAZL (61478fa42ee04562e7f11f4dca87e9c8) C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys
18:24:57.0703 4032 HSXHWAZL - ok
18:24:57.0750 4032 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
18:24:57.0750 4032 HTTP - ok
18:24:57.0781 4032 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
18:24:57.0796 4032 HTTPFilter - ok
18:24:57.0796 4032 i2omgmt - ok
18:24:57.0796 4032 i2omp - ok
18:24:57.0843 4032 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:24:57.0843 4032 i8042prt - ok
18:24:58.0328 4032 ialm (0f68e2ec713f132ffb19e45415b09679) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
18:24:58.0437 4032 ialm - ok
18:24:58.0500 4032 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
18:24:58.0500 4032 IDriverT - ok
18:24:58.0703 4032 idsvc (e7cc3aeaed9893a88876744cd439f76c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:24:58.0718 4032 idsvc - ok
18:24:58.0828 4032 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
18:24:58.0828 4032 Imapi - ok
18:24:58.0859 4032 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
18:24:58.0875 4032 ImapiService - ok
18:24:58.0875 4032 ini910u - ok
18:24:58.0890 4032 IntelIde - ok
18:24:58.0906 4032 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:24:58.0906 4032 intelppm - ok
18:24:58.0937 4032 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
18:24:58.0937 4032 Ip6Fw - ok
18:24:58.0984 4032 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:24:58.0984 4032 IpFilterDriver - ok
18:24:58.0984 4032 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:24:58.0984 4032 IpInIp - ok
18:24:59.0015 4032 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:24:59.0015 4032 IpNat - ok
18:24:59.0031 4032 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:24:59.0031 4032 IPSec - ok
18:24:59.0062 4032 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
18:24:59.0062 4032 IRENUM - ok
18:24:59.0109 4032 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:24:59.0109 4032 isapnp - ok
18:24:59.0140 4032 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:24:59.0140 4032 Kbdclass - ok
18:24:59.0171 4032 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
18:24:59.0187 4032 kmixer - ok
18:24:59.0203 4032 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
18:24:59.0203 4032 KSecDD - ok
18:24:59.0218 4032 L8042Kbd (0f5ae6805ef05dbbe205e5b196cadf31) C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
18:24:59.0218 4032 L8042Kbd - ok
18:24:59.0250 4032 LanmanServer (f385f4b02c535bffe1d70cab80838123) C:\WINDOWS\System32\srvsvc.dll
18:24:59.0250 4032 LanmanServer - ok
18:24:59.0296 4032 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
18:24:59.0296 4032 lanmanworkstation - ok
18:24:59.0312 4032 lbrtfdc - ok
18:24:59.0343 4032 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
18:24:59.0343 4032 LmHosts - ok
18:24:59.0390 4032 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
18:24:59.0390 4032 mdmxsdk - ok
18:24:59.0437 4032 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
18:24:59.0437 4032 Messenger - ok
18:24:59.0468 4032 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
18:24:59.0468 4032 mnmdd - ok
18:24:59.0515 4032 mnmsrvc (1b7be25bca8702589fd02fc774f5dbab) C:\WINDOWS\system32\mnmsrvc.exe
18:24:59.0515 4032 mnmsrvc - ok
18:24:59.0515 4032 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
18:24:59.0531 4032 Modem - ok
18:24:59.0562 4032 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:24:59.0562 4032 Mouclass - ok
18:24:59.0578 4032 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
18:24:59.0593 4032 mouhid - ok
18:24:59.0593 4032 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
18:24:59.0593 4032 MountMgr - ok
18:24:59.0609 4032 mraid35x - ok
18:24:59.0625 4032 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:24:59.0640 4032 MRxDAV - ok
18:24:59.0703 4032 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:24:59.0718 4032 MRxSmb - ok
18:24:59.0734 4032 MSDTC (d189fdf74f7834e627e6993db3c2dffa) C:\WINDOWS\system32\msdtc.exe
18:24:59.0750 4032 MSDTC - ok
18:24:59.0765 4032 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
18:24:59.0765 4032 Msfs - ok
18:24:59.0765 4032 MSIServer - ok
18:24:59.0796 4032 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:24:59.0812 4032 MSKSSRV - ok
18:24:59.0828 4032 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:24:59.0828 4032 MSPCLOCK - ok
18:24:59.0843 4032 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
18:24:59.0843 4032 MSPQM - ok
18:24:59.0875 4032 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:24:59.0937 4032 mssmbios - ok
18:25:00.0062 4032 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
18:25:00.0093 4032 Mup - ok
18:25:00.0140 4032 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
18:25:00.0140 4032 napagent - ok
18:25:00.0171 4032 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
18:25:00.0187 4032 NDIS - ok
18:25:00.0234 4032 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:25:00.0234 4032 NdisTapi - ok
18:25:00.0250 4032 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:25:00.0250 4032 Ndisuio - ok
18:25:00.0265 4032 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:25:00.0265 4032 NdisWan - ok
18:25:00.0281 4032 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
18:25:00.0281 4032 NDProxy - ok
18:25:00.0296 4032 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
18:25:00.0296 4032 NetBIOS - ok
18:25:00.0328 4032 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
18:25:00.0328 4032 NetBT - ok
18:25:00.0359 4032 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
18:25:00.0359 4032 NetDDE - ok
18:25:00.0375 4032 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
18:25:00.0375 4032 NetDDEdsdm - ok
18:25:00.0406 4032 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
18:25:00.0406 4032 Netlogon - ok
18:25:00.0437 4032 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
18:25:00.0453 4032 Netman - ok
18:25:00.0546 4032 NetTcpPortSharing (f9102685f97f9ba85f4a70afcf722cfe) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:25:00.0546 4032 NetTcpPortSharing - ok
18:25:00.0578 4032 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
18:25:00.0578 4032 NIC1394 - ok
18:25:00.0640 4032 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
18:25:00.0640 4032 Nla - ok
18:25:00.0656 4032 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
18:25:00.0671 4032 Npfs - ok
18:25:00.0734 4032 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
18:25:00.0750 4032 Ntfs - ok
18:25:00.0750 4032 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
18:25:00.0765 4032 NtLmSsp - ok
18:25:00.0812 4032 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
18:25:00.0828 4032 NtmsSvc - ok
18:25:00.0843 4032 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
18:25:00.0859 4032 Null - ok
18:25:00.0875 4032 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:25:00.0875 4032 NwlnkFlt - ok
18:25:00.0890 4032 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:25:00.0890 4032 NwlnkFwd - ok
18:25:00.0921 4032 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
18:25:00.0921 4032 NwlnkIpx - ok
18:25:00.0937 4032 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
18:25:00.0937 4032 NwlnkNb - ok
18:25:00.0968 4032 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
18:25:00.0968 4032 NwlnkSpx - ok
18:25:01.0015 4032 NwSapAgent (4b83fcbbe72af5f99d109798653e8b78) C:\WINDOWS\System32\ipxsap.dll
18:25:01.0015 4032 NwSapAgent - ok
18:25:01.0046 4032 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
18:25:01.0046 4032 ohci1394 - ok
18:25:01.0078 4032 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
18:25:01.0078 4032 Parport - ok
18:25:01.0109 4032 Partizan (6ddcf3f801ec15fe698f6a215cf30a1f) C:\WINDOWS\system32\drivers\Partizan.sys
18:25:01.0109 4032 Partizan - ok
18:25:01.0140 4032 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
18:25:01.0140 4032 PartMgr - ok
18:25:01.0171 4032 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
18:25:01.0171 4032 ParVdm - ok
18:25:01.0187 4032 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
18:25:01.0187 4032 PCI - ok
18:25:01.0187 4032 PCIDump - ok
18:25:01.0203 4032 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
18:25:01.0218 4032 PCIIde - ok
18:25:01.0234 4032 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
18:25:01.0250 4032 Pcmcia - ok
18:25:01.0250 4032 PDCOMP - ok
18:25:01.0250 4032 PDFRAME - ok
18:25:01.0265 4032 PDRELI - ok
18:25:01.0281 4032 PDRFRAME - ok
18:25:01.0281 4032 perc2 - ok
18:25:01.0296 4032 perc2hib - ok
18:25:01.0343 4032 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
18:25:01.0359 4032 PlugPlay - ok
18:25:01.0375 4032 Point32 (dcdf0421a1c14f2923e298a30fd7636d) C:\WINDOWS\system32\DRIVERS\point32.sys
18:25:01.0375 4032 Point32 - ok
18:25:01.0375 4032 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
18:25:01.0375 4032 PolicyAgent - ok
18:25:01.0421 4032 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:25:01.0421 4032 PptpMiniport - ok
18:25:01.0437 4032 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
18:25:01.0437 4032 ProtectedStorage - ok
18:25:01.0453 4032 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
18:25:01.0453 4032 PSched - ok
18:25:01.0468 4032 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:25:01.0468 4032 Ptilink - ok
18:25:01.0468 4032 ql1080 - ok
18:25:01.0484 4032 Ql10wnt - ok
18:25:01.0484 4032 ql12160 - ok
18:25:01.0500 4032 ql1240 - ok
18:25:01.0500 4032 ql1280 - ok
18:25:01.0546 4032 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:25:01.0546 4032 RasAcd - ok
18:25:01.0562 4032 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
18:25:01.0578 4032 RasAuto - ok
18:25:01.0609 4032 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:25:01.0609 4032 Rasl2tp - ok
18:25:01.0640 4032 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
18:25:01.0640 4032 RasMan - ok
18:25:01.0671 4032 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:25:01.0671 4032 RasPppoe - ok
18:25:01.0687 4032 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
18:25:01.0687 4032 Raspti - ok
18:25:01.0718 4032 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:25:01.0718 4032 Rdbss - ok
18:25:01.0718 4032 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:25:01.0734 4032 RDPCDD - ok
18:25:01.0750 4032 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
18:25:01.0765 4032 rdpdr - ok
18:25:01.0796 4032 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys
18:25:01.0796 4032 RDPWD - ok
18:25:01.0843 4032 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
18:25:01.0859 4032 RDSessMgr - ok
18:25:01.0875 4032 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
18:25:01.0875 4032 redbook - ok
18:25:01.0906 4032 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
18:25:01.0906 4032 RemoteAccess - ok
18:25:01.0953 4032 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll
18:25:01.0953 4032 RemoteRegistry - ok
18:25:01.0968 4032 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
18:25:01.0968 4032 rimmptsk - ok
18:25:02.0000 4032 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
18:25:02.0000 4032 rimsptsk - ok
18:25:02.0015 4032 rismxdp (d231b577024aa324af13a42f3a807d10) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
18:25:02.0015 4032 rismxdp - ok
18:25:02.0031 4032 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
18:25:02.0031 4032 RpcLocator - ok
18:25:02.0093 4032 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll
18:25:02.0109 4032 RpcSs - ok
18:25:02.0140 4032 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
18:25:02.0156 4032 RSVP - ok
18:25:02.0203 4032 RTLWUSB (0b3b199ab00cfa82747d0892c027c077) C:\WINDOWS\system32\DRIVERS\RTL8187.sys
18:25:02.0203 4032 RTLWUSB - ok
18:25:02.0218 4032 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
18:25:02.0218 4032 SamSs - ok
18:25:02.0296 4032 SbieDrv (3ab6cad1ddfa84cd7bc3d1a759b1e81e) C:\Program Files\Sandboxie\SbieDrv.sys
18:25:02.0312 4032 SbieDrv - ok
18:25:02.0328 4032 SbieSvc (833539963e31edd4dc0063fe9cf95701) C:\Program Files\Sandboxie\SbieSvc.exe
18:25:02.0328 4032 SbieSvc - ok
18:25:02.0359 4032 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
18:25:02.0375 4032 SCardSvr - ok
18:25:02.0421 4032 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
18:25:02.0421 4032 Schedule - ok
18:25:02.0437 4032 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
18:25:02.0437 4032 sdbus - ok
18:25:02.0468 4032 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:25:02.0468 4032 Secdrv - ok
18:25:02.0484 4032 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
18:25:02.0500 4032 seclogon - ok
18:25:02.0500 4032 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
18:25:02.0515 4032 SENS - ok
18:25:02.0531 4032 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
18:25:02.0531 4032 Serial - ok
18:25:02.0562 4032 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
18:25:02.0562 4032 sffdisk - ok
18:25:02.0578 4032 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
18:25:02.0578 4032 sffp_sd - ok
18:25:02.0609 4032 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
18:25:02.0609 4032 Sfloppy - ok
18:25:02.0656 4032 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
18:25:02.0671 4032 SharedAccess - ok
18:25:02.0718 4032 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
18:25:02.0718 4032 ShellHWDetection - ok
18:25:02.0718 4032 Simbad - ok
18:25:02.0781 4032 SNMP (60c377be6b3cc83f6a8584934b181d2e) C:\WINDOWS\System32\snmp.exe
18:25:02.0781 4032 SNMP - ok
18:25:02.0796 4032 SNMPTRAP (80a050795a107a76c2b1cd4cfbe010e6) C:\WINDOWS\System32\snmptrap.exe
18:25:02.0828 4032 SNMPTRAP - ok
18:25:02.0828 4032 Sparrow - ok
18:25:02.0859 4032 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
18:25:02.0859 4032 splitter - ok
18:25:02.0890 4032 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
18:25:02.0906 4032 Spooler - ok
18:25:03.0000 4032 sprtsvc_DellSupportCenter (777115c9cc675bd98127660712d2f784) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
18:25:03.0015 4032 sprtsvc_DellSupportCenter - ok
18:25:03.0062 4032 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
18:25:03.0062 4032 sr - ok
18:25:03.0093 4032 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
18:25:03.0093 4032 srservice - ok
18:25:03.0156 4032 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
18:25:03.0171 4032 Srv - ok
18:25:03.0187 4032 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
18:25:03.0187 4032 SSDPSRV - ok
18:25:03.0312 4032 STHDA (951801dfb54d86f611f0af47825476f9) C:\WINDOWS\system32\drivers\sthda.sys
18:25:03.0343 4032 STHDA - ok
18:25:03.0390 4032 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
18:25:03.0406 4032 stisvc - ok
18:25:03.0437 4032 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
18:25:03.0453 4032 swenum - ok
18:25:03.0484 4032 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
18:25:03.0484 4032 swmidi - ok
18:25:03.0500 4032 SwPrv - ok
18:25:03.0515 4032 symc810 - ok
18:25:03.0515 4032 symc8xx - ok
18:25:03.0531 4032 sym_hi - ok
18:25:03.0531 4032 sym_u3 - ok
18:25:03.0578 4032 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
18:25:03.0593 4032 sysaudio - ok
18:25:03.0625 4032 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
18:25:03.0640 4032 SysmonLog - ok
18:25:03.0671 4032 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
18:25:03.0671 4032 TapiSrv - ok
18:25:03.0734 4032 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:25:03.0734 4032 Tcpip - ok
18:25:03.0781 4032 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
18:25:03.0781 4032 TDPIPE - ok
18:25:03.0796 4032 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
18:25:03.0796 4032 TDTCP - ok
18:25:03.0812 4032 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
18:25:03.0812 4032 TermDD - ok
18:25:03.0859 4032 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
18:25:03.0875 4032 TermService - ok
18:25:03.0906 4032 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
18:25:03.0906 4032 Themes - ok
18:25:03.0968 4032 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe
18:25:03.0968 4032 TlntSvr - ok
18:25:03.0984 4032 TosIde - ok
18:25:04.0015 4032 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
18:25:04.0015 4032 TrkWks - ok
18:25:04.0046 4032 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
18:25:04.0046 4032 Udfs - ok
18:25:04.0046 4032 UIUSys - ok
18:25:04.0062 4032 ultra - ok
18:25:04.0125 4032 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
18:25:04.0125 4032 Update - ok
18:25:04.0171 4032 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
18:25:04.0171 4032 upnphost - ok
18:25:04.0187 4032 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
18:25:04.0203 4032 UPS - ok
18:25:04.0234 4032 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:25:04.0234 4032 usbehci - ok
18:25:04.0250 4032 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:25:04.0250 4032 usbhub - ok
18:25:04.0250 4032 usbohci - ok
18:25:04.0296 4032 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:25:04.0296 4032 USBSTOR - ok
18:25:04.0312 4032 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:25:04.0312 4032 usbuhci - ok
18:25:04.0328 4032 vfhuhmou - ok
18:25:04.0375 4032 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
18:25:04.0375 4032 VgaSave - ok
18:25:04.0375 4032 ViaIde - ok
18:25:04.0390 4032 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
18:25:04.0390 4032 VolSnap - ok
18:25:04.0437 4032 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
18:25:04.0453 4032 VSS - ok
18:25:04.0484 4032 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
18:25:04.0484 4032 W32Time - ok
18:25:04.0500 4032 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:25:04.0500 4032 Wanarp - ok
18:25:04.0500 4032 WDICA - ok
18:25:04.0546 4032 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
18:25:04.0546 4032 wdmaud - ok
18:25:04.0562 4032 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
18:25:04.0578 4032 WebClient - ok
18:25:04.0671 4032 winachsf (ba6b6fb242a6ba4068c8b763063beb63) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys
18:25:04.0687 4032 winachsf - ok
18:25:04.0765 4032 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
18:25:04.0765 4032 winmgmt - ok
18:25:04.0781 4032 wltrysvc - ok
18:25:04.0828 4032 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\mspmsnsv.dll
18:25:04.0828 4032 WmdmPmSN - ok
18:25:04.0921 4032 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll
18:25:04.0937 4032 Wmi - ok
18:25:04.0984 4032 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
18:25:05.0000 4032 WmiApSrv - ok
18:25:05.0125 4032 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
18:25:05.0140 4032 WMPNetworkSvc - ok
18:25:05.0187 4032 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:25:05.0187 4032 WS2IFSL - ok
18:25:05.0234 4032 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll
18:25:05.0234 4032 wscsvc - ok
18:25:05.0265 4032 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
18:25:05.0265 4032 wuauserv - ok
18:25:05.0296 4032 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:25:05.0296 4032 WudfPf - ok
18:25:05.0312 4032 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:25:05.0328 4032 WudfRd - ok
18:25:05.0343 4032 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
18:25:05.0359 4032 WudfSvc - ok
18:25:05.0406 4032 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
18:25:05.0421 4032 WZCSVC - ok
18:25:05.0453 4032 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
18:25:05.0468 4032 xmlprov - ok
18:25:05.0500 4032 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
18:25:06.0031 4032 \Device\Harddisk0\DR0 - ok
18:25:06.0046 4032 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk1\DR5
18:25:08.0984 4032 \Device\Harddisk1\DR5 - ok
18:25:08.0984 4032 Boot (0x1200) (f1fcedaa4131f5edcc5d7a895d19d4c7) \Device\Harddisk0\DR0\Partition0
18:25:08.0984 4032 \Device\Harddisk0\DR0\Partition0 - ok
18:25:09.0015 4032 Boot (0x1200) (3e08949d7f3223c0311ccf4d6f046bf6) \Device\Harddisk0\DR0\Partition1
18:25:09.0015 4032 \Device\Harddisk0\DR0\Partition1 - ok
18:25:09.0031 4032 Boot (0x1200) (95620f2cbdaa46bf9985a76419883d2e) \Device\Harddisk1\DR5\Partition0
18:25:09.0031 4032 \Device\Harddisk1\DR5\Partition0 - ok
18:25:09.0031 4032 ============================================================
18:25:09.0031 4032 Scan finished
18:25:09.0031 4032 ============================================================
18:25:09.0046 0868 Detected object count: 0
18:25:09.0046 0868 Actual detected object count: 0
18:36:29.0625 3604 Deinitialize success


NEXT


>Downloaded System Look from mirror 2. Ran the SystemLook.exe
> Copied the Code inside the box of SystemLook. Made sure all symbols were copied properly;
>Clicked Look

Here it is: SystemLook.Txt

SystemLook 30.07.11 by jpshortstuff
Log created at 18:45 on 25/06/2012 by Administrator
Administrator - Elevation successful

========== filefind ==========

Searching for "*logonui*"
C:\WINDOWS\Prefetch\LOGONUI.EXE-312BE1BF.pf –a—- 27942 bytes [10:39 25/06/2012] [10:39 25/06/2012] BC3A6EF2342CE35276F4AF632CB37F76
C:\WINDOWS\system32\LogonUI.exe –a—- 8071872 bytes [09:00 05/05/2008] [06:42 11/05/2008] 5A40D82A8DCB1B85F9602FD2B2168806
C:\WINDOWS\system32\logonui.exe.manifest -rah— 488 bytes [20:54 14/06/2012] [20:54 14/06/2012] 5D76C3FB736514E1D7C88791E7322784

-= EOF =-


That is all SatchFan. Thank you for your quick reply.

ShayeDrake :thumbup:
Hi there ShayeDrake

One of your files is infected and needs to be replaced. Do you hav a copy of the XP disc or access to another computer that runs Windows XP.

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
c:\windows\system32\drivers\vfhuhmou.sys

Driver::
vfhuhmou

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

Satchfan
OKAY…

I'm Back, SatchFan. Sorry to keep you waiting.

I hope you are having a nice day there. It's raining here and my net connection slowed down.


I'm really hoping to fix the issue as soon as possible. The process I was asked to do is to re-run ComboFix using another given set of codes.


Here's what I did:
>Closed all browser/s
>Disabled my Antivirus
>Copied Codes to notepad (no word wrap) saved it as CFScript.txt where ComboFix.exe is located.
>Made sure all the symbols are properly copied
>Dragged the file CFScript,txt to ComboFix.exe then watched it do its work.
>I was asked to use/download a much updated ComboFix.exe; I clicked No to proceed since we are already using ComboFix

Here is the new ComboFix.Txt


ComboFix 12-06-24.03 - Administrator 06/26/2012 0:08.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.63.1033.18.2038.1560 [GMT 8:00]
Running from: d:\documents\Desktop\ComboFix.exe
Command switches used :: d:\documents\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
FILE ::
"c:\windows\system32\drivers\vfhuhmou.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\LogonUI.exe . . . is infected!!
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_vfhuhmou
.
.
((((((((((((((((((((((((( Files Created from 2012-05-25 to 2012-06-25 )))))))))))))))))))))))))))))))
.
.
2012-06-18 14:55 . 2012-06-18 14:55 ——– d—–w- C:\$AVG
2012-06-17 21:35 . 2012-06-17 21:35 ——– d—–r- C:\Sandbox
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-31 13:22 . 2008-05-05 09:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2008-05-05 09:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-15 13:20 . 2008-05-05 09:00 1863168 —-a-w- c:\windows\system32\win32k.sys
2012-05-11 14:42 . 2008-05-05 09:00 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2008-05-05 09:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2008-05-05 09:00 385024 ——w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2008-05-05 09:00 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2008-04-14 00:01 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-23 14:45 . 2012-04-23 14:46 78336 ——w- c:\windows\system32\ieencode.dll
2012-04-18 20:50 . 2012-04-18 20:50 24896 —-a-w- c:\windows\system32\drivers\avgidshx.sys
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
Cryptography Services Error !!
.
((((((((((((((((((((((((((((( SnapShot@2012-06-24_23.43.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-06-25 10:43 . 2012-06-25 10:43 16384 c:\windows\Temp\Perflib_Perfdata_784.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
"Taskbar Shuffle"="c:\windows\system32\taskbarshuffle.exe" [2008-04-16 818176]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2011-11-23 442640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-09 59392]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"DriveSpace"="c:\program files\Drive Space Indicator\DrvSpace.exe" [2008-05-17 371626]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-26 206064]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-04 2587008]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-05-05 40448]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-07 128512]
"NewUser"="c:\windows\LastXP\NewUser.cmd" [2008-05-05 2094]
.
c:\users\Administrator\Start Menu\Programs\Startup\
Visual Task Tips.lnk - c:\ppapps\VisualTaskTips\VisualTaskTips.exe [2012-6-15 61440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart\0Partizan
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\7-Zip\\7zFM.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\ppApps\\Flashget\\flashget.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
.
R2 AutoExNT;AutoExNT;c:\windows\system32\AutoExNT.Exe [x]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [2012-04-30 5106744]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2012-02-13 193288]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-18 257224]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2011-12-23 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfilterx.sys [2011-12-23 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2011-12-23 17232]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2007-05-21 235648]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2012-04-18 24896]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2012-01-30 31952]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2012-02-21 235216]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2012-03-18 301248]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MDMXSDK
*NewlyCreated* - PARPORT
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-18 14:30]
.
2012-06-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-1606980848-500Core.job
- c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-06-19 17:57]
.
2012-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-616249376-1606980848-500UA.job
- c:\users\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-06-19 17:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: &Download All with FlashGet - c:\ppapps\Flashget\jc_all.htm
IE: &Download with FlashGet - c:\ppapps\Flashget\jc_link.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-26 00:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-823518204-616249376-1606980848-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,46,6e,23,26,d2,58,49,41,b7,84,a8,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,46,6e,23,26,d2,58,49,41,b7,84,a8,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1056)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\COMRes.dll
c:\windows\System32\BCMLogon.dll
c:\windows\system32\cscui.dll
.
- - - - - - - > 'lsass.exe'(1112)
c:\windows\system32\setupapi.dll
.
- - - - - - - > 'explorer.exe'(3056)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\ppapps\VisualTaskTips\VttHooks.dll
c:\windows\system32\msctfime.ime
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\tbhookin.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\netshell.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
.
———————— Other Running Processes ————————
.
c:\program files\Sandboxie\SbieSvc.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 2012-06-26 00:17:23 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-25 16:17
.
Pre-Run: 18,860,449,792 bytes free
Post-Run: 18,855,092,224 bytes free
.
- - End Of File - - 3A7CA3297438980116FB74DE5E81566A


That is all. I hope I did not do any mistake.

Thank you, SatchFan.

ShayeDrake :blush:

PS: Yes we can borrow the CD used for installing my OS and we also have my brother's PC running XP too.
Hi ShayeDrake

It’s not very nice here either but not raining.

Fortunately I have BT Infinity which uses cable so the weather doesn’t afeect my connection.


With regard to the XP file, you need to locate a copy of logonui.exe and copy it to your root directory, ie C:\logonui.exe

If you are unsure how to do this I’ll send instructions later as I have to leave for a while now.

I’ll also have looked at your new log but at a brief glance, it seems to have got rid of the bad files so you did very well. :thumbup:

Please tell me what problems remain at the moment.

Thanks

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI