This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] very slow.. pop ups.. nothing helps

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My friend walked me through using this MRI5.0 geeksquad program to try to get rid of all the viruses and spyware/adware.. We ran it twice, and i still don't think it helped much at all.. I've cleaned up all the temp files/folders.. and this laptop is still running super slow. It also has pop-up problems in both IE and mozilla firefox. Any help would be greatly appreciated. Here's the Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:23:31 PM, on 1/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlido11custreg?clid=1033
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: eGames Toolbar - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\PROGRA~1\EGAMES~1\EGAMES~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CPM6359ad97] Rundll32.exe "c:\windows\system32\lavufanu.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} (CPlayFirstFashionDasControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…eb.1.0.0.21.cab
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) - http://www.worldwinner.com/games/v50/tpir/tpir.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts Control) - http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.48.cab
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} (Abx(gh) Control) - http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://legacy.aolsvc.aol.com/onlinegames/g…bugs/axhost.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v67/swapit/swapit.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://aolsvc.aol.com/onlinegames/pandacraze/gpcontrol.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://aolsvc.aol.com/onlinegames/dinerdas…sh.1.0.0.93.cab
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - http://aolsvc.aol.com/onlinegames/oberonma…ameLauncher.cab
O20 - AppInit_DLLs: c:\windows\system32\lavufanu.dll c:\windows\system32\yibabofi.dll
O20 - Winlogon Notify: iastUI - iastUI.dll (file missing)
O20 - Winlogon Notify: iifcAQhG - iifcAQhG.dll (file missing)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lavufanu.dll
O22 - SharedTaskScheduler: {93ac7c30-3878-4eaa-9420-7977285df5b1} - cinnamomum - (no file)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lavufanu.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe

–
End of file - 11640 bytes
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
I tried to run the kaspersky online scanner and its stuck like at: file scanned 7 duration of the scan 02:08 Scan is running 3% Now scanning cfgmgr32.dll Location C:\ARCSOFT\DirectX and it's been exactly like that for the past 20 minutes if not more. I've tried to redo it, but same thing happens..
Post the MBAM log

Do this as well

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

I am going to attempt the kaspersky online one more time.. Here is the mbam log: Malwarebytes' Anti-Malware 1.31 Database version: 1604 Windows 5.1.2600 Service Pack 3 1/3/2009 9:14:11 PM mbam-log-2009-01-03 (21-14-11).txt Scan type: Full Scan (C:\|) Objects scanned: 115057 Time elapsed: 30 minute(s), 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 12 Registry Values Infected: 5 Registry Data Items Infected: 3 Folders Infected: 1 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\WINDOWS\system32\lavufanu.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{014da6ca-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-0000-0000-0000-100005000004} (Rogue.Installer) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{6316efc7-cf13-43ce-b445-0e3c9d110895} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6316efc7-cf13-43ce-b445-0e3c9d110895} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\bfgtoolbar (Adware.OneToolBar) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm6359ad97 (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\lavufanu.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\lavufanu.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\rqrldbqp -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\user\Application Data\gadcom (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\system32\lavufanu.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\gibetate.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\juvewehu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\rqRLdBqp.VIR (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tohogohe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
I started AVP at 1:32 today and the est. finish time is Wednesday at 7:00 AM… should i continue with it? update.. the time moved until 7pm on wed night.. lol
Leave that

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
logs as requested :

OTListIt logfile created on: 1/5/2009 6:22:49 PM - Run
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.17 Mb Total Physical Memory | 102.40 Mb Available Physical Memory | 22.95% Memory free
1.03 Gb Paging File | 0.64 Gb Available in Paging File | 62.18% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.29 Gb Total Space | 59.32 Gb Free Space | 79.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LEON-NGUYEN
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
C:\WINDOWS\system32\drivers\CDAC11BA.EXE (C-Dilla Ltd)
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\WINDOWS\system32\HPZipm12.exe (HP)
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
C:\WINDOWS\agrsmmsg.exe (Agere Systems)
C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\AIM\aim.exe (America Online, Inc.)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
C:\Documents and Settings\user\Desktop\OTListIt2.exe (OldTimer Tools)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\WINDOWS\system32\scrnsave.scr (Microsoft Corporation)

========== (O23) Win32 Services (SafeList) ==========

(ACS [Auto | Stopped]) – C:\WINDOWS\system32\acs.exe ()
(Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ()
(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
(aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
(Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
(avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
(avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
(avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
(C-DillaCdaC11BA [Auto | Running]) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE (C-Dilla Ltd)
(CFSvcs [Auto | Running]) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
(DVD-RAM_Service [Auto | Running]) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
(IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
(iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
(JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
(NBService [On_Demand | Stopped]) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
(Pml Driver HPZ12 [Unknown | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
(Swupdtmr [Auto | Running]) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
(TAPPSRV [Auto | Running]) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
(UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(Aavmker4 [System | Running]) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
(AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
(AgereSoftModem [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
(AR5211 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
(ASCTRM [Auto | Running]) – C:\WINDOWS\system32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
(aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
(aswMon2 [Auto | Running]) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
(aswRdr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
(aswSP [System | Running]) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
(aswTdi [System | Running]) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
(ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
(BVRPMPR5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
(CdaC15BA [Auto | Running]) – C:\WINDOWS\system32\drivers\CDAC15BA.SYS ()
(DLABOIOM [Auto | Running]) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
(DLACDBHM [System | Running]) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
(DLADResN [Auto | Running]) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
(DLAIFS_M [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
(DLAOPIOM [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
(DLAPoolM [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
(DLARTL_N [System | Running]) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
(DLAUDFAM [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
(DLAUDF_M [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
(DRVMCDB [Boot | Running]) – C:\WINDOWS\system32\drivers\DRVMCDB.SYS (Sonic Solutions)
(DRVNDDM [Auto | Running]) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
(GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
(HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
(IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
(is-0H1O9drv [System | Running]) – C:\WINDOWS\system32\drivers\15332086.sys (Kaspersky Lab)
(is-7CTGVdrv [System | Running]) – C:\WINDOWS\system32\drivers\55586384.sys (Kaspersky Lab)
(KR10N [Boot | Running]) – C:\WINDOWS\system32\drivers\KR10N.sys (TOSHIBA CORPORATION)
(meiudf [System | Running]) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
(Netdevio [Auto | Running]) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
(pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
(Point32 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\point32.sys (Microsoft Corporation)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
(RTL8023xp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
(rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
(Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(snapman [Boot | Running]) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
(SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
(SynTP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
(tbiosdrv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tbiosdrv.sys ()
(TVALD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NBSMI.sys (Toshiba Corporation)
(Tvs [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Tvs.sys (TOSHIBA Corporation)
(usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
(wanatw [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
(WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (732 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon File not found
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon File not found
O4 - HKLM..\Run: [CPM6359ad97] Rundll32.exe "c:\windows\system32\yibabofi.dll",a File not found
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run (TOSHIBA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER (RealNetworks, Inc.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup File not found
O4 - HKCU..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl File not found
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\is-0H1O9.lnk = C:\Documents and Settings\user\Desktop\Virus Removal Tool1\is-0H1O9\startup.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: objects.aol.com (* is out of zone range - 5)
O15 - HKCU\..Trusted Sites: stumbleupon.com (* in Trusted sites)
O15 - HKCU\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} http://aolsvc.aol.com/onlinegames/free-tri…eb.1.0.0.21.cab (CPlayFirstFashionDasControl Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab (WildTangent Active Launcher)
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} http://www.gamehouse.com/ghdlctl.cab (dldisplay Class)
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab (WWHearts Control)
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.48.cab (CPlayFirstDinerDash2Control Object)
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab (Abx(gh) Control)
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} http://legacy.aolsvc.aol.com/onlinegames/g…bugs/axhost.cab (WildfireActiveXHost Class)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} http://www.worldwinner.com/games/v67/swapit/swapit.cab (SwapIt Control)
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab (Zylom Games Player)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} https://disney.go.com/games/downloads/gamem…GameManager.cab (CGameManagerCtrl Object)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://aolsvc.aol.com/onlinegames/pandacraze/gpcontrol.cab (TikGames Online Control)
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} http://aolsvc.aol.com/onlinegames/dinerdas…sh.1.0.0.93.cab (CPlayFirstDinerDashControl Object)
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} http://aolsvc.aol.com/onlinegames/oberonma…ameLauncher.cab (Playtime Games Launcher)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdo - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: ({93ac7c30-3878-4eaa-9420-7977285df5b1}) - cinnamomum - Reg Error: Key does not exist or could not be opened. File not found

========== AppInit_DLLs ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls" = c:\windows\system32\yibabofi.dll
>c:\windows\system32\yibabofi.dll File not found

========== HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)

"UserInit" = C:\WINDOWS\SYSTEM32\userinit.exe,
>C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

"UIHost" = logonui.exe
>C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)

"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)


========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll – C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
crypt32chain: "DllName" = crypt32.dll – C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll – C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll – C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
dimsntfy: "DllName" = %SystemRoot%\System32\dimsntfy.dll – C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
iastUI: "DllName" = iastUI.dll – File not found
iifcAQhG: "DllName" = iifcAQhG.dll – File not found
ScCertProp: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll – C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
WgaLogon: "DllName" = WgaLogon.dll – C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)

========== IFEO "Debugger" Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) – C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
> File not found

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[2009/01/05 18:17:30 | 00,419,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTListIt2.exe
[2009/01/05 18:10:29 | 46,791,4752 | -HS- | C] () – C:\hiberfil.sys
[2009/01/05 13:26:34 | 00,001,867 | —- | C] () – C:\Documents and Settings\user\Start Menu\Programs\Startup\is-0H1O9.lnk
[2009/01/05 13:25:20 | 00,148,496 | —- | C] (Kaspersky Lab) – C:\WINDOWS\System32\drivers\15332086.sys
[2009/01/05 13:25:20 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\Virus Removal Tool1
[2009/01/05 13:18:08 | 00,706,592 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009/01/05 13:18:08 | 00,001,556 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009/01/05 13:17:53 | 00,148,496 | —- | C] (Kaspersky Lab) – C:\WINDOWS\System32\drivers\55586384.sys
[2009/01/05 13:17:51 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\Virus Removal Tool
[2009/01/05 12:49:29 | 31,379,928 | —- | C] ( ) – C:\Documents and Settings\user\Desktop\setup_7.0.0.290_05.01.2009_17-40.exe
[2009/01/04 22:03:02 | 17,593,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/03 21:18:45 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\KEEP OUT!!
[2009/01/03 19:57:39 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/01/03 19:57:37 | 00,050,864 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/01/03 19:57:35 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/01/03 19:57:30 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/01/03 19:57:29 | 00,111,184 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/01/03 19:57:29 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/01/03 19:57:29 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/01/03 19:57:29 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/01/03 19:56:58 | 01,236,208 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/01/03 19:56:58 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/01/03 19:43:53 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Malwarebytes
[2009/01/03 19:43:46 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/03 19:43:43 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/03 19:43:42 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/03 19:43:41 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/03 19:42:46 | 02,539,400 | —- | C] (Malwarebytes Corporation ) – C:\mbam-setup.exe
[2009/01/03 19:17:39 | 00,116,224 | —- | C] (Xerox) – C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2009/01/03 19:17:32 | 00,023,040 | —- | C] (Xerox Corporation) – C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2009/01/03 19:17:30 | 00,018,944 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2009/01/03 19:17:23 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2009/01/03 19:17:16 | 00,004,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2009/01/03 19:17:08 | 00,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2009/01/03 19:17:00 | 00,016,970 | —- | C] (US Robotics MCD (Megahertz)) – C:\WINDOWS\System32\dllcache\xem336n5.sys
[2009/01/03 19:16:52 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshirda.dll
[2009/01/03 19:16:37 | 00,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiacpi.sys
[2009/01/03 19:16:33 | 00,154,624 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\wlluc48.sys
[2009/01/03 19:16:26 | 00,034,890 | —- | C] (Raytheon Corp.) – C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2009/01/03 19:16:16 | 00,771,581 | —- | C] (Rockwell) – C:\WINDOWS\System32\dllcache\winacisa.sys
[2009/01/03 19:16:08 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2009/01/03 19:16:01 | 00,087,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2009/01/03 19:16:00 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\weitekp9.sys
[2009/01/03 19:15:59 | 00,041,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\weitekp9.dll
[2009/01/03 19:15:47 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2009/01/03 19:15:41 | 00,035,871 | —- | C] (Winbond Electronics Corp.) – C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2009/01/03 19:15:20 | 00,016,925 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w940nd.sys
[2009/01/03 19:15:13 | 00,019,016 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w926nd.sys
[2009/01/03 19:15:06 | 00,048,256 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\w32.dll
[2009/01/03 19:15:06 | 00,019,528 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w840nd.sys
[2009/01/03 19:14:59 | 00,064,605 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vvoice.sys
[2009/01/03 19:14:51 | 00,397,502 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vpctcom.sys
[2009/01/03 19:14:44 | 00,604,253 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\vmodem.sys
[2009/01/03 19:14:37 | 00,249,402 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\vinwm.sys
[2009/01/03 19:14:28 | 00,005,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\viaide.sys
[2009/01/03 19:14:20 | 00,687,999 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2009/01/03 19:14:13 | 00,765,884 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usrti.sys
[2009/01/03 19:14:06 | 00,113,762 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrpda.sys
[2009/01/03 19:14:00 | 00,007,556 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usroslba.sys
[2009/01/03 19:13:53 | 00,224,802 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usr1807a.sys
[2009/01/03 19:13:46 | 00,794,399 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806v.sys
[2009/01/03 19:13:39 | 00,793,598 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806.sys
[2009/01/03 19:13:33 | 00,794,654 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1801.sys
[2009/01/03 19:13:30 | 00,020,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbuhci.sys
[2009/01/03 19:13:28 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbser.sys
[2009/01/03 19:13:26 | 00,032,384 | —- | C] (KLSI USA, Inc.) – C:\WINDOWS\System32\dllcache\usb101et.sys
[2009/01/03 19:13:17 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxud32.dll
[2009/01/03 18:23:17 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/01/03 18:22:49 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\HJTInstall.exe
[2009/01/03 18:17:00 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu40.dll
[2009/01/03 18:16:52 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu22.dll
[2009/01/03 18:16:45 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu12.dll
[2009/01/03 18:16:38 | 00,050,688 | —- | C] (UMAX DATA SYSTEMS INC.) – C:\WINDOWS\System32\dllcache\umaxscan.dll
[2009/01/03 18:16:31 | 00,022,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2009/01/03 18:16:24 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxp60.dll
[2009/01/03 18:16:16 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxcam.dll
[2009/01/03 18:16:08 | 00,211,968 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um54scan.dll
[2009/01/03 18:16:00 | 00,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2009/01/03 18:15:43 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tsprof.exe
[2009/01/03 18:15:35 | 00,166,784 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxpm.sys
[2009/01/03 18:15:27 | 00,525,568 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxp.dll
[2009/01/03 18:15:20 | 00,159,232 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkbm.sys
[2009/01/03 18:15:12 | 00,440,576 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkb.dll
[2009/01/03 18:15:05 | 00,222,336 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3dm.sys
[2009/01/03 18:14:57 | 00,315,520 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3d.dll
[2009/01/03 18:14:23 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\toside.sys
[2009/01/03 18:13:54 | 00,123,995 | —- | C] (Tiger Jet Network) – C:\WINDOWS\System32\dllcache\tjisdn.sys
[2009/01/03 18:13:52 | 00,185,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\thawbrkr.dll
[2009/01/03 18:13:45 | 00,138,528 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2009/01/03 18:13:38 | 00,081,408 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiul50.dll
[2009/01/03 18:13:36 | 00,149,376 | —- | C] (M-Systems) – C:\WINDOWS\System32\dllcache\tffsport.sys
[2009/01/03 18:13:35 | 00,019,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdspx.sys
[2009/01/03 18:13:28 | 00,017,129 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2009/01/03 18:13:21 | 00,037,961 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdk100b.sys
[2009/01/03 18:13:21 | 00,021,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdipx.sys
[2009/01/03 18:13:20 | 00,013,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdasync.sys
[2009/01/03 18:13:05 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tandqic.sys
[2009/01/03 18:12:58 | 00,036,640 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2009/01/03 18:12:51 | 00,172,768 | —- | C] (Number Nine Visual Technology) – C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2009/01/03 18:12:17 | 00,094,293 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sxports.dll
[2009/01/03 18:12:11 | 00,103,936 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sx.sys
[2009/01/03 18:12:04 | 00,003,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swusbflt.sys
[2009/01/03 18:11:58 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpidflt.dll
[2009/01/03 18:11:52 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2009/01/03 18:11:46 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2009/01/03 18:11:40 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_effct.dll
[2009/01/03 18:11:33 | 00,155,648 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnprop.dll
[2009/01/03 18:11:27 | 00,053,248 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlncoin.dll
[2009/01/03 18:11:21 | 00,285,760 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnata.sys
[2009/01/03 18:11:15 | 00,016,896 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\stcusb.sys
[2009/01/03 18:11:07 | 00,048,736 | —- | C] (3Com) – C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2009/01/03 18:11:01 | 00,099,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusd.dll
[2009/01/03 18:11:00 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusbusd.dll
[2009/01/03 18:10:52 | 00,024,660 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spxupchk.dll
[2009/01/03 18:10:45 | 00,061,824 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\speed.sys
[2009/01/03 18:10:39 | 00,106,584 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spdports.dll
[2009/01/03 18:10:33 | 00,019,072 | —- | C] (Adaptec, Inc.) – C:\WINDOWS\System32\dllcache\sparrow.sys
[2009/01/03 18:10:06 | 00,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonymc.sys
[2009/01/03 18:10:03 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonyait.sys
[2009/01/03 18:09:55 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll
[2009/01/03 18:09:55 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2009/01/03 18:09:53 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpstup.dll
[2009/01/03 18:09:49 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll
[2009/01/03 18:09:48 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smimsgif.dll
[2009/01/03 18:09:41 | 00,058,368 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smiminib.sys
[2009/01/03 18:09:40 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smierrsm.dll
[2009/01/03 18:09:40 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smierrsy.dll
[2009/01/03 18:09:34 | 00,147,200 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smidispb.dll
[2009/01/03 18:09:26 | 00,025,034 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2009/01/03 18:09:19 | 00,035,913 | —- | C] (SMC) – C:\WINDOWS\System32\dllcache\smcirda.sys
[2009/01/03 18:09:13 | 00,024,576 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smc8000n.sys
[2009/01/03 18:09:06 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbhc.sys
[2009/01/03 18:09:04 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbclass.sys
[2009/01/03 18:09:02 | 00,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbbatt.sys
[2009/01/03 18:09:01 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb6w.dll
[2009/01/03 18:08:55 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb3w.dll
[2009/01/03 18:08:49 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb0w.dll
[2009/01/03 18:08:49 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma3w.dll
[2009/01/03 18:08:42 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm9aw.dll
[2009/01/03 18:08:42 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma0w.dll
[2009/01/03 18:08:41 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm93w.dll
[2009/01/03 18:08:41 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm92w.dll
[2009/01/03 18:08:34 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm91w.dll
[2009/01/03 18:08:34 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm90w.dll
[2009/01/03 18:08:33 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8dw.dll
[2009/01/03 18:08:32 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8cw.dll
[2009/01/03 18:08:32 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8aw.dll
[2009/01/03 18:08:31 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm89w.dll
[2009/01/03 18:08:30 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm87w.dll
[2009/01/03 18:08:30 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm81w.dll
[2009/01/03 18:08:29 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm59w.dll
[2009/01/03 18:08:25 | 00,063,547 | —- | C] (Symbol Technologies) – C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2009/01/03 18:08:19 | 00,091,294 | —- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) – C:\WINDOWS\System32\dllcache\skfpwin.sys
[2009/01/03 18:08:13 | 00,094,698 | —- | C] (SysKonnect GmbH.) – C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2009/01/03 18:07:58 | 00,032,768 | —- | C] (SiS Corporation) – C:\WINDOWS\System32\dllcache\sisnic.sys
[2009/01/03 18:07:23 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\simptcp.dll
[2009/01/03 18:07:08 | 00,161,568 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2009/01/03 18:07:01 | 00,018,400 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmld.sys
[2009/01/03 18:06:56 | 00,098,080 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2009/01/03 18:06:49 | 00,386,560 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiul50.dll
[2009/01/03 18:06:34 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2009/01/03 18:06:29 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2009/01/03 18:06:28 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_seos.dll
[2009/01/03 18:06:21 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2009/01/03 18:06:19 | 00,011,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiscan.sys
[2009/01/03 18:06:13 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2009/01/03 18:06:12 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_scripto.dll
[2009/01/03 18:06:06 | 00,017,280 | —- | C] (SCM Microsystems) – C:\WINDOWS\System32\dllcache\scr111.sys
[2009/01/03 18:06:01 | 00,016,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scmstcs.sys
[2009/01/03 18:05:54 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2009/01/03 18:05:48 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2009/01/03 18:05:45 | 00,043,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sbp2port.sys
[2009/01/03 18:05:20 | 00,077,824 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2009/01/03 18:05:14 | 00,198,400 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4.dll
[2009/01/03 18:05:09 | 00,061,504 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2009/01/03 18:05:02 | 00,179,264 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2009/01/03 18:04:57 | 00,210,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2009/01/03 18:04:52 | 00,062,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2009/01/03 18:04:47 | 00,041,216 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2009/01/03 18:04:42 | 00,182,272 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2009/01/03 18:04:38 | 00,166,720 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3m.sys
[2009/01/03 18:04:34 | 00,065,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.sys
[2009/01/03 18:04:28 | 00,082,432 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia450.dll
[2009/01/03 18:04:19 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia430.dll
[2009/01/03 18:04:19 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia330.dll
[2009/01/03 18:04:18 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia001.dll
[2009/01/03 18:04:17 | 00,029,696 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw450ext.dll
[2009/01/03 18:04:09 | 00,027,648 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw430ext.dll
[2009/01/03 18:04:02 | 00,019,017 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8029.sys
[2009/01/03 18:03:52 | 00,009,216 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2009/01/03 18:03:37 | 00,079,104 | —- | C] (Comtrol Corporation) – C:\WINDOWS\System32\dllcache\rocket.sys
[2009/01/03 18:03:31 | 00,037,563 | —- | C] (RadioLAN) – C:\WINDOWS\System32\dllcache\rlnet5.sys
[2009/01/03 18:03:24 | 00,086,097 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\reslog32.dll
[2009/01/03 18:03:21 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe
[2009/01/03 18:03:20 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\register.exe
[2009/01/03 18:03:07 | 00,019,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasirda.sys
[2009/01/03 18:02:58 | 00,714,762 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2009/01/03 18:02:52 | 00,899,146 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2009/01/03 18:02:44 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qvusd.dll
[2009/01/03 18:02:37 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\quser.exe
[2009/01/03 18:02:37 | 00,003,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qv2kux.sys
[2009/01/03 18:02:36 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\query.exe
[2009/01/03 18:02:20 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql1240.sys
[2009/01/03 18:02:09 | 00,033,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql10wnt.sys
[2009/01/03 18:02:02 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qic157.sys
[2009/01/03 18:01:55 | 00,130,942 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlv.sys
[2009/01/03 18:01:49 | 00,112,574 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlp.sys
[2009/01/03 18:01:44 | 00,128,286 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserli.sys
[2009/01/03 18:01:43 | 00,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusd.dll
[2009/01/03 18:01:38 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusb.dll
[2009/01/03 18:01:36 | 00,033,280 | —- | C] () – C:\WINDOWS\System32\dllcache\psisrndr.ax
[2009/01/03 18:01:30 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\psisload.dll
[2009/01/03 18:01:28 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\dllcache\psisdecd.dll
[2009/01/03 18:01:23 | 00,016,128 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\pscr.sys
[2009/01/03 18:01:19 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa3.sys
[2009/01/03 18:01:14 | 00,017,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa.sys
[2009/01/03 18:01:13 | 00,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\powerfil.sys
[2009/01/03 18:01:07 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pnrmc.sys
[2009/01/03 18:01:06 | 00,131,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxviceo.dll
[2009/01/03 18:01:06 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxmcro.dll
[2009/01/03 18:01:05 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxgl.dll
[2009/01/03 18:00:53 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phvfwext.dll
[2009/01/03 18:00:48 | 00,019,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philtune.sys
[2009/01/03 18:00:42 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phildec.sys
[2009/01/03 18:00:35 | 00,173,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam2.sys
[2009/01/03 18:00:29 | 00,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.sys
[2009/01/03 18:00:24 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.dll
[2009/01/03 18:00:17 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phdsext.ax
[2009/01/03 18:00:16 | 00,259,328 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3dd.dll
[2009/01/03 18:00:14 | 00,028,032 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3.sys
[2009/01/03 18:00:13 | 00,211,584 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2dll.dll
[2009/01/03 18:00:11 | 00,027,904 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2.sys
[2009/01/03 18:00:05 | 00,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2hib.sys
[2009/01/03 18:00:00 | 00,027,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2.sys
[2009/01/03 17:59:57 | 00,169,984 | —- | C] (Cisco Systems) – C:\WINDOWS\System32\dllcache\pcx500.sys
[2009/01/03 17:59:50 | 00,086,016 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\pctspk.exe
[2009/01/03 17:59:45 | 00,035,328 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2009/01/03 17:59:39 | 00,029,769 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2009/01/03 17:59:34 | 00,030,282 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2009/01/03 17:59:29 | 00,026,153 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2009/01/03 17:59:27 | 00,029,502 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\pca200e.sys
[2009/01/03 17:59:21 | 00,030,495 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pc100nds.sys
[2009/01/03 17:59:14 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2rc.dll
[2009/01/03 17:59:09 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2.dll
[2009/01/03 17:59:03 | 00,025,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovsound2.sys
[2009/01/03 17:58:58 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcoms.exe
[2009/01/03 17:58:53 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcomc.dll
[2009/01/03 17:58:48 | 00,351,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodek2.sys
[2009/01/03 17:58:43 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodec2.dll
[2009/01/03 17:58:38 | 00,031,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovce.sys
[2009/01/03 17:58:33 | 00,028,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcd.sys
[2009/01/03 17:58:27 | 00,048,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcam2.sys
[2009/01/03 17:58:22 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovca.sys
[2009/01/03 17:58:18 | 00,054,186 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otcsercb.sys
[2009/01/03 17:58:12 | 00,043,689 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otceth5.sys
[2009/01/03 17:58:08 | 00,027,209 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otc06x5.sys
[2009/01/03 17:58:02 | 00,054,528 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\opl3sax.sys
[2009/01/03 17:57:37 | 00,051,552 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\dllcache\ntgrip.sys
[2009/01/03 17:57:36 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll
[2009/01/03 17:57:31 | 00,009,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntapm.sys
[2009/01/03 17:57:27 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsmmc.sys
[2009/01/03 17:57:20 | 00,087,040 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2009/01/03 17:57:14 | 00,126,080 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2009/01/03 17:57:08 | 00,032,840 | —- | C] (NETGEAR Corporation.) – C:\WINDOWS\System32\dllcache\ngrpci.sys
[2009/01/03 17:57:06 | 00,132,695 | —- | C] (802.11b) – C:\WINDOWS\System32\dllcache\netwlan5.sys
[2009/01/03 17:56:57 | 00,065,278 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\netflx3.sys
[2009/01/03 17:56:51 | 00,039,264 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.sys
[2009/01/03 17:56:47 | 00,060,480 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.dll
[2009/01/03 17:56:42 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ne2000.sys
[2009/01/03 17:56:34 | 00,091,488 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2009/01/03 17:56:29 | 00,027,936 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3d.sys
[2009/01/03 17:56:25 | 00,033,088 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2009/01/03 17:56:21 | 00,059,104 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2009/01/03 17:56:17 | 00,013,664 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.sys
[2009/01/03 17:56:13 | 00,035,392 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.dll
[2009/01/03 17:56:09 | 00,128,000 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n100325.sys
[2009/01/03 17:56:06 | 00,052,255 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2009/01/03 17:56:02 | 00,075,520 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxport.sys
[2009/01/03 17:55:58 | 00,007,168 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxport.dll
[2009/01/03 17:55:54 | 00,019,968 | —- | C] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\dllcache\mxnic.sys
[2009/01/03 17:55:51 | 00,019,968 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxicfg.dll
[2009/01/03 17:55:47 | 00,021,888 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxcard.sys
[2009/01/03 17:55:41 | 00,103,296 | —- | C] (Matrox Graphics Inc) – C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2009/01/03 17:55:24 | 00,049,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstape.sys
[2009/01/03 17:55:16 | 00,012,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msriffwv.sys
[2009/01/03 17:54:55 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msmpu401.sys
[2009/01/03 17:54:49 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msircomm.sys
[2009/01/03 17:54:32 | 00,035,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msgame.sys
[2009/01/03 17:54:27 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfsio.sys
[2009/01/03 17:54:26 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2009/01/03 17:54:26 | 00,051,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdv.sys
[2009/01/03 17:54:17 | 00,017,280 | —- | C] (American Megatrends Inc.) – C:\WINDOWS\System32\dllcache\mraid35x.sys
[2009/01/03 17:54:14 | 00,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpe.sys
[2009/01/03 17:54:07 | 00,016,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\modemcsa.sys
[2009/01/03 17:53:59 | 00,006,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\miniqic.sys
[2009/01/03 17:53:57 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\migisol.exe
[2009/01/03 17:53:46 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mga.sys
[2009/01/03 17:53:46 | 00,092,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mga.dll
[2009/01/03 17:53:38 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memgrp.dll
[2009/01/03 17:53:34 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memcard.sys
[2009/01/03 17:53:29 | 00,164,586 | —- | C] (Madge Networks Ltd) – C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2009/01/03 17:53:23 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mammoth.sys
[2009/01/03 17:53:22 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll
[2009/01/03 17:53:13 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3092dc.dll
[2009/01/03 17:53:08 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3091dc.dll
[2009/01/03 17:52:58 | 00,797,500 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltsmt.sys
[2009/01/03 17:52:54 | 00,802,683 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\ltsm.sys
[2009/01/03 17:52:53 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ltotape.sys
[2009/01/03 17:52:52 | 00,420,992 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2009/01/03 17:52:48 | 00,576,746 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2009/01/03 17:52:47 | 00,606,684 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2009/01/03 17:52:43 | 00,727,786 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ltck000c.sys
[2009/01/03 17:52:38 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\loop.sys
[2009/01/03 17:52:33 | 00,070,730 | —- | C] (Linksys Group, Inc.) – C:\WINDOWS\System32\dllcache\lne100tx.sys
[2009/01/03 17:52:29 | 00,020,573 | —- | C] (The Linksts Group ) – C:\WINDOWS\System32\dllcache\lne100.sys
[2009/01/03 17:52:25 | 00,025,065 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\lmndis3.sys
[2009/01/03 17:52:21 | 00,015,744 | —- | C] (Litronic Industries) – C:\WINDOWS\System32\dllcache\lit220p.sys
[2009/01/03 17:52:16 | 00,026,442 | —- | C] (SMSC) – C:\WINDOWS\System32\dllcache\lanepic5.sys
[2009/01/03 17:52:13 | 00,019,016 | —- | C] (Kingston Technology Company ) – C:\WINDOWS\System32\dllcache\ktc111.sys
[2009/01/03 17:52:08 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kousd.dll
[2009/01/03 17:52:06 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsusd.dll
[2009/01/03 17:52:06 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsui.dll
[2009/01/03 17:52:04 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdusa.dll
[2009/01/03 17:51:56 | 00,014,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdhid.sys
[2009/01/03 17:51:49 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jupiw.dll
[2009/01/03 17:51:40 | 00,018,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irsir.sys
[2009/01/03 17:51:39 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irmon.dll
[2009/01/03 17:51:35 | 00,151,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irftp.exe
[2009/01/03 17:51:35 | 00,023,552 | —- | C] (MKNet Corporation) – C:\WINDOWS\System32\dllcache\irmk7.sys
[2009/01/03 17:51:34 | 00,088,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irda.sys
[2009/01/03 17:51:15 | 00,045,632 | —- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) – C:\WINDOWS\System32\dllcache\ip5515.sys
[2009/01/03 17:51:11 | 00,090,200 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8ports.dll
[2009/01/03 17:51:07 | 00,038,784 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8.sys
[2009/01/03 17:51:06 | 00,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\intelide.sys
[2009/01/03 17:51:02 | 00,013,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inport.sys
[2009/01/03 17:51:02 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/01/03 17:50:58 | 00,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ini910u.sys
[2009/01/03 17:50:37 | 00,372,824 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\iconf32.dll
[2009/01/03 17:50:32 | 00,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5usb.sys
[2009/01/03 17:50:28 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5ext.dll
[2009/01/03 17:50:24 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5com.dll
[2009/01/03 17:50:20 | 00,154,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4usb.sys
[2009/01/03 17:50:16 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4ext.dll
[2009/01/03 17:50:12 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4com.dll
[2009/01/03 17:50:08 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3ext.dll
[2009/01/03 17:50:05 | 00,141,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3.sys
[2009/01/03 17:50:01 | 00,038,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2009/01/03 17:49:34 | 00,018,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omp.sys
[2009/01/03 17:49:33 | 00,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2009/01/03 17:48:30 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hr1w.dll
[2009/01/03 17:48:26 | 00,005,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpt4qic.sys
[2009/01/03 17:48:22 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2009/01/03 17:48:19 | 00,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2009/01/03 17:48:15 | 00,025,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpn.sys
[2009/01/03 17:48:12 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2009/01/03 17:48:08 | 00,068,608 | —- | C] (Avisioin) – C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2009/01/03 17:48:05 | 00,165,888 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt53.dll
[2009/01/03 17:48:02 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2009/01/03 17:47:58 | 00,093,696 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt42.dll
[2009/01/03 17:47:55 | 00,126,976 | —- | C] (Hewlett Packard) – C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2009/01/03 17:47:51 | 00,101,376 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt34.dll
[2009/01/03 17:47:48 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2009/01/03 17:47:45 | 00,089,088 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt33.dll
[2009/01/03 17:47:42 | 00,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2009/01/03 17:47:39 | 00,083,968 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt21.dll
[2009/01/03 17:47:35 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2009/01/03 17:47:34 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\HJTsetup.exe
[2009/01/03 17:47:31 | 00,002,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidswvd.sys
[2009/01/03 17:47:28 | 00,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidgame.sys
[2009/01/03 17:47:27 | 00,020,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidbatt.sys
[2009/01/03 17:47:20 | 00,028,288 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grserial.sys
[2009/01/03 17:47:18 | 00,082,304 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grclass.sys
[2009/01/03 17:47:15 | 00,017,408 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\gpr400.sys
[2009/01/03 17:47:11 | 00,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gckernel.sys
[2009/01/03 17:47:10 | 00,010,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gameenum.sys
[2009/01/03 17:46:55 | 00,454,912 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fxusbase.sys
[2009/01/03 17:46:49 | 00,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fuusd.dll
[2009/01/03 17:46:47 | 00,455,296 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fusbbase.sys
[2009/01/03 17:46:44 | 00,455,680 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fus2base.sys
[2009/01/03 17:46:43 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ftlx041e.dll
[2009/01/03 17:46:40 | 00,442,240 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2009/01/03 17:46:37 | 00,441,728 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2009/01/03 17:46:34 | 00,444,416 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcibase.sys
[2009/01/03 17:46:33 | 00,034,173 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\forehe.sys
[2009/01/03 17:46:30 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fnfilter.dll
[2009/01/03 17:46:29 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\flattemp.exe
[2009/01/03 17:46:18 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll
[2009/01/03 17:46:15 | 00,024,618 | —- | C] (NETGEAR) – C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2009/01/03 17:46:10 | 00,011,850 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2009/01/03 17:46:08 | 00,012,362 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2009/01/03 17:46:05 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exabyte2.sys
[2009/01/03 17:46:00 | 00,045,056 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunid.dll
[2009/01/03 17:46:00 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\et4000.sys
[2009/01/03 17:45:58 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunib.dll
[2009/01/03 17:45:55 | 00,057,856 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009/01/03 17:45:55 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuni.dll
[2009/01/03 17:45:52 | 00,034,816 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimg.dll
[2009/01/03 17:45:52 | 00,031,744 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucmd.dll
[2009/01/03 17:45:49 | 00,043,008 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucm.dll
[2009/01/03 17:45:31 | 00,072,192 | —- | C] (ESS Technology Inc.) – C:\WINDOWS\System32\dllcache\es1969.sys
[2009/01/03 17:45:14 | 00,114,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epstw2k.sys
[2009/01/03 17:45:09 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2009/01/03 17:44:58 | 00,007,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\elmsmc.sys
[2009/01/03 17:44:33 | 00,514,587 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\edb500.dll
[2009/01/03 17:44:16 | 00,334,208 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2009/01/03 17:44:12 | 00,020,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpti2o.sys
[2009/01/03 17:44:09 | 00,028,062 | —- | C] (National Semiconductor Coproration) – C:\WINDOWS\System32\dllcache\dp83820.sys
[2009/01/03 17:44:07 | 00,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2009/01/03 17:44:06 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2009/01/03 17:44:04 | 00,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2009/01/03 17:44:03 | 00,206,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4.sys
[2009/01/03 17:43:51 | 00,029,696 | —- | C] (CNet Technology, Inc. ) – C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2009/01/03 17:43:51 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dlttape.sys
[2009/01/03 17:43:49 | 00,026,698 | —- | C] (D-Link Corporation) – C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2009/01/03 17:43:47 | 00,952,007 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diwan.sys
[2009/01/03 17:43:46 | 00,029,768 | —- | C] () – C:\WINDOWS\System32\dllcache\divasu.dll
[2009/01/03 17:43:44 | 00,037,962 | —- | C] () – C:\WINDOWS\System32\dllcache\divaprop.dll
[2009/01/03 17:43:43 | 00,006,216 | —- | C] () – C:\WINDOWS\System32\dllcache\divaci.dll
[2009/01/03 17:43:41 | 00,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2009/01/03 17:43:40 | 00,038,985 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvsu.dll
[2009/01/03 17:43:38 | 00,031,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvpp.dll
[2009/01/03 17:43:37 | 00,006,729 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvci.dll
[2009/01/03 17:43:32 | 00,091,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\dimaint.sys
[2009/01/03 17:42:50 | 00,024,649 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650d.sys
[2009/01/03 17:42:48 | 00,024,648 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650.sys
[2009/01/03 17:42:42 | 00,020,928 | —- | C] (Digital Networks, LLC) – C:\WINDOWS\System32\dllcache\defpa.sys
[2009/01/03 17:42:41 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddsmc.sys
[2009/01/03 17:42:38 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc260usd.dll
[2009/01/03 17:42:36 | 00,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc240usd.dll
[2009/01/03 17:42:33 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210usd.dll
[2009/01/03 17:42:32 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210_32.dll
[2009/01/03 17:42:26 | 00,014,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dac960nt.sys
[2009/01/03 17:42:16 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzports.dll
[2009/01/03 17:42:15 | 00,049,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzport.sys
[2009/01/03 17:42:14 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzcoins.dll
[2009/01/03 17:42:12 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyports.dll
[2009/01/03 17:42:11 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyport.sys
[2009/01/03 17:42:09 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyycoins.dll
[2009/01/03 17:42:08 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclom-y.sys
[2009/01/03 17:42:06 | 00,048,640 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2009/01/03 17:42:06 | 00,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclad-z.sys
[2009/01/03 17:42:04 | 00,093,952 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2009/01/03 17:42:03 | 00,111,872 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcspud.sys
[2009/01/03 17:42:01 | 00,003,584 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2009/01/03 17:42:00 | 00,072,832 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2009/01/03 17:41:58 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2009/01/03 17:41:57 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbase.sys
[2009/01/03 17:41:54 | 00,249,856 | —- | C] (Comtrol® Corporation) – C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2009/01/03 17:41:48 | 00,175,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\csamsp.dll
[2009/01/03 17:41:44 | 00,216,064 | —- | C] (COMPAQ Inc.) – C:\WINDOWS\System32\dllcache\cpscan.dll
[2009/01/03 17:41:43 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cprofile.exe
[2009/01/03 17:41:42 | 00,060,970 | —- | C] (Compaq Computer Corp.) – C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2009/01/03 17:41:41 | 00,021,533 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2009/01/03 17:41:39 | 00,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cpqarray.sys
[2009/01/03 17:41:27 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnusd.dll
[2009/01/03 17:41:22 | 00,020,736 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2009/01/03 17:41:20 | 00,248,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546xm.sys
[2009/01/03 17:41:19 | 00,170,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546x.dll
[2009/01/03 17:41:18 | 00,111,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl5465.dll
[2009/01/03 17:41:17 | 00,045,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.sys
[2009/01/03 17:41:16 | 00,091,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.dll
[2009/01/03 17:41:14 | 00,272,640 | —- | C] (RAVISENT Technologies Inc.) – C:\WINDOWS\System32\dllcache\cinemclc.sys
[2009/01/03 17:41:11 | 00,980,034 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\cicap.sys
[2009/01/03 17:41:05 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chgusr.exe
[2009/01/03 17:41:04 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chgport.exe
[2009/01/03 17:41:04 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chglogon.exe
[2009/01/03 17:41:03 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\change.exe
[2009/01/03 17:41:03 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\changer.sys
[2009/01/03 17:41:00 | 00,049,182 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem56n5.sys
[2009/01/03 17:40:59 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem33n5.sys
[2009/01/03 17:40:59 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem28n5.sys
[2009/01/03 17:40:58 | 00,027,164 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce3n5.sys
[2009/01/03 17:40:57 | 00,021,530 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce2n5.sys
[2009/01/03 17:40:54 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cd20xrnt.sys
[2009/01/03 17:40:53 | 00,714,698 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2009/01/03 17:40:52 | 00,046,108 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cben5.sys
[2009/01/03 17:40:51 | 00,039,680 | —- | C] (Silicom Ltd.) – C:\WINDOWS\System32\dllcache\cb325.sys
[2009/01/03 17:40:50 | 00,037,916 | —- | C] (Fast Ethernet Controller Provider) – C:\WINDOWS\System32\dllcache\cb102.sys
[2009/01/03 17:40:47 | 00,032,256 | —- | C] (Eicon Technology Corporation) – C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2009/01/03 17:40:43 | 00,164,923 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diapi2.sys
[2009/01/03 17:40:43 | 00,054,528 | —- | C] (Philips Semiconductors GmbH) – C:\WINDOWS\System32\dllcache\cap7146.sys
[2009/01/03 17:40:42 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.dll
[2009/01/03 17:40:41 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.ax
[2009/01/03 17:40:40 | 00,236,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.dll
[2009/01/03 17:40:39 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.ax
[2009/01/03 17:40:38 | 00,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.dll
[2009/01/03 17:40:37 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.ax
[2009/01/03 17:40:36 | 00,171,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv30.sys
[2009/01/03 17:40:35 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv21.sys
[2009/01/03 17:40:34 | 00,314,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdro21.sys
[2009/01/03 17:40:32 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_iscii.dll
[2009/01/03 17:40:30 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_870.nls
[2009/01/03 17:40:29 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_864.nls
[2009/01/03 17:40:29 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_862.nls
[2009/01/03 17:40:28 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_858.nls
[2009/01/03 17:40:26 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_720.nls
[2009/01/03 17:40:26 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_708.nls
[2009/01/03 17:40:24 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_28596.nls
[2009/01/03 17:40:23 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_21025.nls
[2009/01/03 17:40:21 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20924.nls
[2009/01/03 17:40:21 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20880.nls
[2009/01/03 17:40:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20871.nls
[2009/01/03 17:40:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20838.nls
[2009/01/03 17:40:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20833.nls
[2009/01/03 17:40:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20424.nls
[2009/01/03 17:40:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20423.nls
[2009/01/03 17:40:18 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20420.nls
[2009/01/03 17:40:18 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20297.nls
[2009/01/03 17:40:17 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20285.nls
[2009/01/03 17:40:17 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20284.nls
[2009/01/03 17:40:16 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20280.nls
[2009/01/03 17:40:16 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20278.nls
[2009/01/03 17:40:15 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20277.nls
[2009/01/03 17:40:15 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20273.nls
[2009/01/03 17:40:14 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20269.nls
[2009/01/03 17:40:14 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20108.nls
[2009/01/03 17:40:13 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20107.nls
[2009/01/03 17:40:13 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20106.nls
[2009/01/03 17:40:12 | 00,187,938 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20005.nls
[2009/01/03 17:40:12 | 00,180,258 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20004.nls
[2009/01/03 17:40:12 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20105.nls
[2009/01/03 17:40:11 | 00,185,378 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20003.nls
[2009/01/03 17:40:11 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20002.nls
[2009/01/03 17:40:10 | 00,186,402 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20001.nls
[2009/01/03 17:40:09 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1149.nls
[2009/01/03 17:40:09 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1148.nls
[2009/01/03 17:40:08 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1147.nls
[2009/01/03 17:40:08 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1146.nls
[2009/01/03 17:40:07 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1145.nls
[2009/01/03 17:40:07 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1144.nls
[2009/01/03 17:40:07 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1143.nls
[2009/01/03 17:40:06 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1142.nls
[2009/01/03 17:40:06 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1141.nls
[2009/01/03 17:40:05 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1140.nls
[2009/01/03 17:40:05 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1047.nls
[2009/01/03 17:40:04 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10021.nls
[2009/01/03 17:40:03 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10005.nls
[2009/01/03 17:40:03 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10004.nls
[2009/01/03 17:40:01 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2009/01/03 17:40:00 | 00,031,529 | —- | C] (BreezeCOM) – C:\WINDOWS\System32\dllcache\brzwlan.sys
[2009/01/03 17:39:59 | 00,010,368 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbscn.sys
[2009/01/03 17:39:58 | 00,011,008 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2009/01/03 17:39:57 | 00,060,416 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brserwdm.sys
[2009/01/03 17:39:56 | 00,009,728 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brserif.dll
[2009/01/03 17:39:55 | 00,005,120 | —- | C] (Brother Industries,Ltd.) – C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2009/01/03 17:39:54 | 00,039,552 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparwdm.sys
[2009/01/03 17:39:53 | 00,003,168 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparimg.sys
[2009/01/03 17:39:52 | 00,041,472 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfusb.dll
[2009/01/03 17:39:51 | 00,032,256 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2009/01/03 17:39:50 | 00,029,696 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmflpt.dll
[2009/01/03 17:39:49 | 00,081,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2009/01/03 17:39:48 | 00,015,360 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2009/01/03 17:39:48 | 00,003,968 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltup.sys
[2009/01/03 17:39:47 | 00,012,160 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2009/01/03 17:39:46 | 00,002,944 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brfilt.sys
[2009/01/03 17:39:45 | 00,012,800 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brevif.dll
[2009/01/03 17:39:44 | 00,009,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brcoinst.dll
[2009/01/03 17:39:43 | 00,019,456 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brbidiif.dll
[2009/01/03 17:39:41 | 00,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\binlsvc.dll
[2009/01/03 17:39:40 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2009/01/03 17:39:40 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdasup.sys
[2009/01/03 17:39:39 | 00,871,388 | —- | C] (BCM) – C:\WINDOWS\System32\dllcache\bcmdm.sys
[2009/01/03 17:39:34 | 00,036,128 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.sys
[2009/01/03 17:39:33 | 00,342,336 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.dll
[2009/01/03 17:39:32 | 00,089,952 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\b1cbase.sys
[2009/01/03 17:39:31 | 00,036,992 | —- | C] (Aztech Systems Ltd) – C:\WINDOWS\System32\dllcache\aztw2320.sys
[2009/01/03 17:39:30 | 00,037,568 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmwan.sys
[2009/01/03 17:39:29 | 00,144,384 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmenum.dll
[2009/01/03 17:39:29 | 00,087,552 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2009/01/03 17:39:28 | 00,013,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcstrm.sys
[2009/01/03 17:39:27 | 00,036,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcaudio.sys
[2009/01/03 17:39:26 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avc.sys
[2009/01/03 17:39:23 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\dllcache\ativxbar.sys
[2009/01/03 17:39:23 | 00,023,552 | —- | C] () – C:\WINDOWS\System32\dllcache\atixbar.sys
[2009/01/03 17:39:22 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\dllcache\ativttxx.sys
[2009/01/03 17:39:21 | 00,009,472 | —- | C] () – C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2009/01/03 17:39:20 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2009/01/03 17:39:19 | 00,026,880 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2009/01/03 17:39:19 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitunep.sys
[2009/01/03 17:39:18 | 00,049,920 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtcap.sys
[2009/01/03 17:39:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2009/01/03 17:39:13 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atievxx.exe
[2009/01/03 17:39:10 | 00,046,464 | —- | C] () – C:\WINDOWS\System32\dllcache\atibt829.sys
[2009/01/03 17:39:06 | 00,096,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ati.dll
[2009/01/03 17:39:06 | 00,077,568 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ati.sys
[2009/01/03 17:39:05 | 00,097,354 | —- | C] (Bay Networks, Inc.) – C:\WINDOWS\System32\dllcache\aspndis3.sys
[2009/01/03 17:39:03 | 00,022,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asc3350p.sys
[2009/01/03 17:39:02 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2009/01/03 17:39:00 | 00,006,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\apmbatt.sys
[2009/01/03 17:38:59 | 00,012,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\amsint.sys
[2009/01/03 17:38:58 | 00,016,969 | —- | C] (AmbiCom, Inc.) – C:\WINDOWS\System32\dllcache\amb8002.sys
[2009/01/03 17:38:55 | 00,056,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78xx.sys
[2009/01/03 17:38:55 | 00,055,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78u2.sys
[2009/01/03 17:38:54 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aha154x.sys
[2009/01/03 17:38:50 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2009/01/03 17:38:49 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2009/01/03 17:38:48 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adpu160m.sys
[2009/01/03 17:38:47 | 00,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2009/01/03 17:38:47 | 00,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2009/01/03 17:38:46 | 00,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2009/01/03 17:38:45 | 00,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2009/01/03 17:38:45 | 00,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2009/01/03 17:38:44 | 00,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2009/01/03 17:38:43 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2009/01/03 17:38:42 | 00,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2009/01/03 17:38:40 | 00,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2009/01/03 17:38:39 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\abp480n5.sys
[2009/01/03 17:38:38 | 00,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2009/01/03 17:38:38 | 00,098,304 | —- | C] (Aureal Semiconductor) – C:\WINDOWS\System32\dllcache\a3d.dll
[2009/01/03 17:38:37 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\61883.sys
[2009/01/03 17:38:37 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2009/01/03 17:38:36 | 00,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2009/01/03 17:38:36 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\4mmdat.sys
[2009/01/03 17:38:35 | 00,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2009/01/03 17:38:34 | 00,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2009/01/03 17:38:34 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2009/01/03 17:38:08 | 00,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2009/01/03 15:29:58 | 00,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/01/03 14:49:01 | 07,518,240 | —- | C] (Mozilla) – C:\Firefox Setup 3.0.5.exe
[2009/01/03 11:30:13 | 00,000,000 | —D | C] – C:\batt_en3.tos
[2008/12/30 15:23:19 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2008/12/30 00:51:13 | 01,262,640 | -HS- | C] () – C:\WINDOWS\System32\evameyah.ini
[2008/12/29 22:56:02 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2008/12/29 22:51:17 | 29,775,112 | —- | C] () – C:\setupeng.exe
[2008/12/29 22:43:10 | 00,000,000 | —D | C] – C:\Program Files\RegistryFix7
[2008/12/29 22:42:41 | 01,109,376 | —- | C] (Registry Fix ) – C:\registryfix.exe
[2008/12/29 21:55:31 | 01,307,934 | -HS- | C] () – C:\WINDOWS\System32\rakinakp.ini
[2008/12/26 19:16:46 | 01,299,082 | -HS- | C] () – C:\WINDOWS\System32\geqygfne.ini
[2008/12/26 19:15:51 | 00,671,820 | -HS- | C] () – C:\WINDOWS\System32\pqBdLRqr.ini2
[2008/12/26 19:15:51 | 00,671,820 | -HS- | C] () – C:\WINDOWS\System32\pqBdLRqr.ini
[2008/12/18 16:16:46 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\SlimBrowser
[2008/12/18 16:12:24 | 01,982,908 | —- | C] () – C:\sbsetup.exe
[2008/12/18 15:09:51 | 00,000,571 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to aim.lnk
[2008/12/18 15:08:42 | 00,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\filelib
[2008/12/18 15:07:41 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Aim
[2008/12/18 14:45:27 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\IObit
[2008/12/18 14:45:26 | 00,000,000 | —D | C] – C:\Program Files\IObit
[2008/12/18 11:21:29 | 01,665,243 | -HS- | C] () – C:\WINDOWS\System32\pcboreod.ini
[2008/12/18 10:15:23 | 01,647,120 | -HS- | C] () – C:\WINDOWS\System32\sibvpogc.ini
[2008/12/14 17:38:59 | 01,647,120 | -HS- | C] () – C:\WINDOWS\System32\yfcrbhyw.ini
[2008/12/12 13:33:20 | 01,647,120 | -HS- | C] () – C:\WINDOWS\System32\xdvgnmqx.ini
[2008/12/12 12:17:32 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/12/11 13:33:01 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\dgfbuxaa.ini
[2008/12/08 22:23:41 | 01,598,743 | -HS- | C] () – C:\WINDOWS\System32\ynxdarup.ini
[2008/12/07 22:22:44 | 01,598,743 | -HS- | C] () – C:\WINDOWS\System32\nlabqffc.ini
[2008/12/07 22:19:23 | 00,018,010 | -HS- | C] () – C:\WINDOWS\System32\PoWvwyxx.ini2
[2008/12/07 22:19:23 | 00,018,010 | -HS- | C] () – C:\WINDOWS\System32\PoWvwyxx.ini
[2008/12/07 22:14:14 | 00,000,292 | —- | C] () – C:\WINDOWS\tasks\xynjxgip.job

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/05 18:25:42 | 00,710,688 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009/01/05 18:17:31 | 00,419,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTListIt2.exe
[2009/01/05 18:14:32 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/01/05 18:13:24 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/05 18:12:14 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/01/05 18:10:59 | 00,000,292 | —- | M] () – C:\WINDOWS\tasks\xynjxgip.job
[2009/01/05 18:10:59 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/05 18:10:38 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/01/05 18:10:29 | 46,791,4752 | -HS- | M] () – C:\hiberfil.sys
[2009/01/05 18:09:34 | 01,930,896 | -H– | M] () – C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2009/01/05 18:09:24 | 00,000,811 | —- | M] () – C:\WINDOWS\win.ini
[2009/01/05 18:09:24 | 00,000,285 | —- | M] () – C:\WINDOWS\system.ini
[2009/01/05 18:09:24 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/01/05 13:26:34 | 00,001,867 | —- | M] () – C:\Documents and Settings\user\Start Menu\Programs\Startup\is-0H1O9.lnk
[2009/01/05 13:20:40 | 00,001,556 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009/01/05 13:04:33 | 31,379,928 | —- | M] ( ) – C:\Documents and Settings\user\Desktop\setup_7.0.0.290_05.01.2009_17-40.exe
[2009/01/04 22:06:16 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/03 19:43:02 | 02,539,400 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup.exe
[2009/01/03 18:23:05 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\HJTInstall.exe
[2009/01/03 17:48:09 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\HJTsetup.exe
[2009/01/03 15:29:58 | 00,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/01/03 15:29:32 | 07,518,240 | —- | M] (Mozilla) – C:\Firefox Setup 3.0.5.exe
[2009/01/02 10:14:15 | 01,262,640 | -HS- | M] () – C:\WINDOWS\System32\evameyah.ini
[2009/01/02 09:52:45 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\delayagu
[2009/01/02 09:52:37 | 00,069,730 | -HS- | M] () – C:\WINDOWS\System32\moyofilu.dll
[2008/12/30 23:16:49 | 00,001,744 | -H– | M] () – C:\nirolugo
[2008/12/30 12:18:36 | 00,000,920 | —- | M] () – C:\Documents and Settings\user\Application Data\wklnhst.dat
[2008/12/29 23:24:06 | 00,671,820 | -HS- | M] () – C:\WINDOWS\System32\pqBdLRqr.ini
[2008/12/29 23:22:52 | 00,671,820 | -HS- | M] () – C:\WINDOWS\System32\pqBdLRqr.ini2
[2008/12/29 22:54:55 | 29,775,112 | —- | M] () – C:\setupeng.exe
[2008/12/29 22:42:42 | 01,109,376 | —- | M] (Registry Fix ) – C:\registryfix.exe
[2008/12/29 21:55:41 | 01,307,934 | -HS- | M] () – C:\WINDOWS\System32\rakinakp.ini
[2008/12/26 19:16:49 | 01,299,082 | -HS- | M] () – C:\WINDOWS\System32\geqygfne.ini
[2008/12/19 14:50:37 | 00,018,010 | -HS- | M] () – C:\WINDOWS\System32\PoWvwyxx.ini
[2008/12/19 14:48:03 | 00,018,010 | -HS- | M] () – C:\WINDOWS\System32\PoWvwyxx.ini2
[2008/12/18 16:18:43 | 01,982,908 | —- | M] () – C:\sbsetup.exe
[2008/12/18 15:09:51 | 00,000,571 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to aim.lnk
[2008/12/18 11:24:11 | 01,665,243 | -HS- | M] () – C:\WINDOWS\System32\pcboreod.ini
[2008/12/18 10:15:28 | 01,647,120 | -HS- | M] () – C:\WINDOWS\System32\sibvpogc.ini
[2008/12/14 17:39:41 | 01,647,120 | -HS- | M] () – C:\WINDOWS\System32\yfcrbhyw.ini
[2008/12/14 17:33:11 | 01,647,120 | -HS- | M] () – C:\WINDOWS\System32\xdvgnmqx.ini
[2008/12/13 10:39:34 | 00,000,085 | —- | M] () – C:\WINDOWS\EmperorEdit.INI
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/12 12:29:58 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2008/12/12 12:17:32 | 00,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2008/12/11 18:09:22 | 00,089,600 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/11 13:33:01 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\dgfbuxaa.ini
[2008/12/09 15:24:38 | 17,593,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2008/12/08 22:23:51 | 01,598,743 | -HS- | M] () – C:\WINDOWS\System32\ynxdarup.ini
[2008/12/08 22:23:19 | 01,598,743 | -HS- | M] () – C:\WINDOWS\System32\nlabqffc.ini
[2008/12/08 21:40:37 | 00,077,368 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

========== LOP Check ==========

[2009/01/03 21:37:42 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2006/12/04 17:38:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/01/03 21:27:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/07/10 06:24:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/04/17 23:06:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/10/15 12:25:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blg
[2008/12/30 15:23:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2008/04/19 16:22:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii
[2008/12/18 13:56:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/05/09 17:05:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/09/16 18:43:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2005/11/04 23:05:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/01/03 19:43:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/12/18 14:36:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/10/14 10:02:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/01/02 17:25:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/03/16 10:42:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/05/13 12:11:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Games
[2008/10/15 13:30:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2006/12/18 10:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayTime
[2006/12/04 16:37:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2005/11/04 23:09:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2006/03/02 22:19:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/04/30 16:02:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2008/04/19 23:18:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2006/12/15 20:12:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/12/18 16:50:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/05/18 09:21:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2005/11/04 23:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/11/20 15:54:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2006/05/26 08:02:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/01/11 10:10:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2008/12/12 11:56:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2006/12/04 14:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[2009/01/03 21:35:23 | 00,000,000 | -H-D | M] – C:\Documents and Settings\user\Application Data
[2008/02/10 13:55:25 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Adobe
[2006/07/06 08:48:55 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\AdobeUM
[2006/11/21 12:22:46 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Ahead
[2008/12/18 15:07:55 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Aim
[2005/11/04 23:18:53 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\AOL
[2007/04/21 01:02:42 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Apple Computer
[2006/03/06 00:36:44 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ArcSoft
[2005/11/29 17:25:22 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ATI
[2008/10/15 12:25:49 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\blg
[2008/09/12 23:23:37 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Canon
[2007/10/27 09:57:03 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\dvdcss
[2007/10/23 17:32:20 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\FFSJ
[2006/09/22 14:32:08 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\FlashFXP
[2008/10/14 10:09:38 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Gamelab
[2007/01/15 17:34:54 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\GetRightToGo
[2006/10/20 10:52:02 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Google
[2006/08/06 10:23:58 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Help
[2007/05/09 17:06:14 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\HP
[2005/11/04 21:30:09 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Identities
[2006/03/02 00:14:19 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\InterVideo
[2005/11/04 23:05:12 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Intuit
[2008/12/18 14:45:27 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\IObit
[2008/09/19 17:35:18 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Lavasoft
[2006/12/13 15:41:49 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Macromedia
[2009/01/03 19:43:53 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Malwarebytes
[2006/07/21 17:30:21 | 00,000,000 | –SD | M] – C:\Documents and Settings\user\Application Data\Microsoft
[2008/12/18 17:59:36 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Mozilla
[2006/12/14 15:22:56 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\MysteryStudio
[2006/11/20 16:00:40 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Nova Development
[2008/05/13 12:11:13 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Oberon Games
[2006/07/21 15:08:25 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\PC Tools
[2008/10/15 13:30:36 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\PlayFirst
[2008/06/20 17:46:42 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Real
[2008/03/08 00:09:32 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Roxio
[2008/04/30 16:01:27 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sandlot Games
[2008/04/19 23:18:41 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ScanSoft
[2008/03/24 21:43:35 | 00,000,000 | RH-D | M] – C:\Documents and Settings\user\Application Data\SecuROM
[2008/12/18 16:39:22 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\SlimBrowser
[2006/09/22 14:20:09 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\SmartFTP
[2006/03/01 23:16:52 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sonic
[2007/03/20 23:28:41 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\StumbleUpon
[2006/03/09 11:38:19 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sun
[2006/03/02 01:02:38 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Template
[2008/02/23 13:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\toshiba
[2006/12/29 01:17:22 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\vlc
[2007/01/17 11:39:53 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Wildfire
[2008/12/18 18:52:55 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Yahoo!
[2005/11/04 23:10:34 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\You've Got Pictures Screensaver
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/01/05 18:10:59 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/01/05 18:10:59 | 00,000,292 | —- | M] () – C:\WINDOWS\Tasks\xynjxgip.job

========== Purity Check ==========

[2006/07/21 17:05:19 | 00,000,000 | —D | M] – C:\Program Files\ѕystem32
** - C:\Program Files\?ystem32

========== Alternate Data Streams ==========

@Alternate Data Stream - 218 bytes -> %AllUsersProfile%\Application Data\TEMP:6677D85A
@Alternate Data Stream - 209 bytes -> %AllUsersProfile%\Application Data\TEMP:483AC68A
@Alternate Data Stream - 206 bytes -> %AllUsersProfile%\Application Data\TEMP:CEE4A457
@Alternate Data Stream - 204 bytes -> %AllUsersProfile%\Application Data\TEMP:3A6BC948
@Alternate Data Stream - 152 bytes -> %AllUsersProfile%\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 120 bytes -> %AllUsersProfile%\Application Data\TEMP:89C2A42C
@Alternate Data Stream - 120 bytes -> %AllUsersProfile%\Application Data\TEMP:225C4FFC
@Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:E36F5B57
@Alternate Data Stream - 112 bytes -> %AllUsersProfile%\Application Data\TEMP:F67AAFC5
@Alternate Data Stream - 104 bytes -> %AllUsersProfile%\Application Data\TEMP:23FA878E
@Alternate Data Stream - 102 bytes -> %AllUsersProfile%\Application Data\TEMP:BDF08FAF
@Alternate Data Stream - 0 bytes -> %AllUsersProfile%\Application Data\TEMP:22741C1F
< End of report >

OTListIt Extras logfile created on: 1/5/2009 6:22:49 PM - Run
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.17 Mb Total Physical Memory | 102.40 Mb Available Physical Memory | 22.95% Memory free
1.03 Gb Paging File | 0.64 Gb Available in Paging File | 62.18% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.29 Gb Total Space | 59.32 Gb Free Space | 79.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LEON-NGUYEN
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = SlimBrowserHtml] – C:\Program Files\SlimBrowser\sbrowser.exe File not found
========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 (IniCom Networks, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrade Engine (TOSHIBA Corporation)
C:\TOSHIBA\IVP\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger (TOSHIBA Corporation)
C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL File not found
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 (IniCom Networks, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{05832D65-6EDB-4D32-BA78-BCD0E2B91C02}" = Atheros Wireless LAN MiniPCI card Driver
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{20749F76-4228-43AD-8AB5-E7B20D8040C4}" = hph_readme
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}" = iTunes
"{5D96E2B1-D9AC-46E0-9073-425C5F63E338}" = Touch and Launch
"{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = TOSHIBA Zooming Utility
"{64DD71BC-3109-4C88-9AD3-D5422644B722}" = TOSHIBA Hotkey Utility
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{69BE47C2-36FE-4397-8199-85D8EAE69982}" = TOSHIBA TouchPad ON/Off Utility
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}" = Atheros Client Utility
"{78C68CB9-3DF5-44F3-AB9D-FA305C5EB85C}" = TOSHIBA Utilities
"{821DABD6-26F2-49E5-AE55-40A589ADBE6D}" = Emperor: Rise of the Middle Kingdom
"{868F24EB-5CA7-4285-B39B-3617CF37462A}" = D2300_Help
"{8B12BA86-ADAC-4BA6-B441-FFC591087252}" = TOSHIBA Virtual Sound
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.7
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{BE3F89C0-42D5-11D5-A40A-00105AC8331A}" = Metamail (Toshiba Registration Utility)
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EECDDEA0-DB76-4488-8E52-0EF1DF63700A}" = Microsoft IntelliPoint 5.4
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F14B8ECC-BDA0-4987-9201-D7B7DBE11033}" = Nero 7 Premium
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"All ATI Software" = ATI - Software Uninstall Utility
"AOL Instant Messenger" = AOL Instant Messenger
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"Canon MP160 User Registration" = Canon MP160 User Registration
"CdaC13Ba" = Cda Product Service - shared component
"File Splitter and Joiner_is1" = File Splitter and Joiner (FFSJ v3.1)
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Lame MP3 Codec (for the ACM)" = Lame ACM MP3 Codec
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.5)" = Mozilla Firefox (3.0.5)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool
"Power Saver" = TOSHIBA Power Saver
"RealPlayer 6.0" = RealPlayer Basic
"Registry Fix_is1" = RegistryFix v7.0
"sat_screensaver_30mb.scr" = sat_screensaver_30mb
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Ultra AVI Converter_is1" = Ultra AVI Converter 3.2.6
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"XviD_is1" = XviD MPEG-4 Video Codec

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/19/2008 4:57:31 PM | Computer Name = LEON-NGUYEN | Source = Application Error | ID = 1000
Description = Faulting application avscan.exe, version 8.1.4.10, faulting module
avscan.exe, version 8.1.4.10, fault address 0x0000c87a.

Error - 12/19/2008 5:05:20 PM | Computer Name = LEON-NGUYEN | Source = Application Error | ID = 1000
Description = Faulting application avscan.exe, version 8.1.4.10, faulting module
msvcr71.dll, version 7.10.3052.4, fault address 0x00010513.

Error - 12/19/2008 5:06:08 PM | Computer Name = LEON-NGUYEN | Source = Application Error | ID = 1000
Description = Faulting application avscan.exe, version 8.1.4.10, faulting module
avscan.exe, version 8.1.4.10, fault address 0x00009390.

Error - 12/19/2008 5:08:12 PM | Computer Name = LEON-NGUYEN | Source = Application Error | ID = 1000
Description = Faulting application avscan.exe, version 8.1.4.10, faulting module
avscan.exe, version 8.1.4.10, fault address 0x00009390.

Error - 12/19/2008 6:04:39 PM | Computer Name = LEON-NGUYEN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16735, faulting
module ieui.dll, version 7.0.5730.11, fault address 0x000061b1.

Error - 12/19/2008 6:04:43 PM | Computer Name = LEON-NGUYEN | Source = Application Error | ID = 1001
Description = Fault bucket 968348041.

Error - 12/19/2008 8:02:14 PM | Computer Name = LEON-NGUYEN | Source = Application Error | ID = 1000
Description = Faulting application avscan.exe, version 8.1.4.10, faulting module
msvcr71.dll, version 7.10.3052.4, fault address 0x00010513.

Error - 1/3/2009 8:48:03 PM | Computer Name = LEON-NGUYEN | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/3/2009 8:48:04 PM | Computer Name = LEON-NGUYEN | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/3/2009 8:50:15 PM | Computer Name = LEON-NGUYEN | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3257, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 1/5/2009 3:17:59 PM | Computer Name = LEON-NGUYEN | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/5/2009 3:18:03 PM | Computer Name = LEON-NGUYEN | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/5/2009 3:18:07 PM | Computer Name = LEON-NGUYEN | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/5/2009 3:18:15 PM | Computer Name = LEON-NGUYEN | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/5/2009 3:18:19 PM | Computer Name = LEON-NGUYEN | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/5/2009 3:18:23 PM | Computer Name = LEON-NGUYEN | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/5/2009 3:18:27 PM | Computer Name = LEON-NGUYEN | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 1/5/2009 7:09:39 PM | Computer Name = LEON-NGUYEN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/5/2009 7:11:14 PM | Computer Name = LEON-NGUYEN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Atheros Configuration
Service service to connect.

Error - 1/5/2009 7:11:14 PM | Computer Name = LEON-NGUYEN | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
oreans32


< End of report >
hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
    
    :files
    C:\WINDOWS\System32\evameyah.ini
    C:\WINDOWS\System32\rakinakp.ini
    C:\WINDOWS\System32\geqygfne.ini
    C:\WINDOWS\System32\pqBdLRqr.ini2
    C:\WINDOWS\System32\pqBdLRqr.ini
    C:\WINDOWS\System32\pcboreod.ini
    C:\WINDOWS\System32\sibvpogc.ini
    C:\WINDOWS\System32\yfcrbhyw.ini
    C:\WINDOWS\System32\xdvgnmqx.ini
    C:\WINDOWS\System32\dgfbuxaa.ini
    C:\WINDOWS\System32\ynxdarup.ini
    C:\WINDOWS\System32\nlabqffc.ini
    C:\WINDOWS\System32\PoWvwyxx.ini2
    C:\WINDOWS\System32\PoWvwyxx.ini
    C:\WINDOWS\tasks\xynjxgip.job
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Please download DirLook by jpshortstuff from here.
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the main textfield:

    C:\Documents and Settings\All Users\Application Data\Geek Squad /s
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\dl_log.txt)
Note: Scanning may take longer for large folders.
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\"SecurityProviders"|"msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" /E : value set successfully! ========== FILES ========== C:\WINDOWS\System32\evameyah.ini moved successfully. C:\WINDOWS\System32\rakinakp.ini moved successfully. C:\WINDOWS\System32\geqygfne.ini moved successfully. C:\WINDOWS\System32\pqBdLRqr.ini2 moved successfully. C:\WINDOWS\System32\pqBdLRqr.ini moved successfully. C:\WINDOWS\System32\pcboreod.ini moved successfully. C:\WINDOWS\System32\sibvpogc.ini moved successfully. C:\WINDOWS\System32\yfcrbhyw.ini moved successfully. C:\WINDOWS\System32\xdvgnmqx.ini moved successfully. C:\WINDOWS\System32\dgfbuxaa.ini moved successfully. C:\WINDOWS\System32\ynxdarup.ini moved successfully. C:\WINDOWS\System32\nlabqffc.ini moved successfully. C:\WINDOWS\System32\PoWvwyxx.ini2 moved successfully. C:\WINDOWS\System32\PoWvwyxx.ini moved successfully. C:\WINDOWS\tasks\xynjxgip.job moved successfully. ========== COMMANDS ========== C:\Program Files\ѕystem32 moved successfully. File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\etilqs_3rT7lX1P1MGxfziF0hEK scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\etilqs_PFXugp3ZesvFvApMGMdq scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\etilqs_PFXugp3ZesvFvApMGMdq-journal scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_558.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7f0.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\68vhwod7.default\OfflineCache\index.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\68vhwod7.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\68vhwod7.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01052009_200242 Files moved on Reboot… File C:\DOCUME~1\user\LOCALS~1\Temp\etilqs_3rT7lX1P1MGxfziF0hEK not found! File C:\DOCUME~1\user\LOCALS~1\Temp\etilqs_PFXugp3ZesvFvApMGMdq not found! File C:\DOCUME~1\user\LOCALS~1\Temp\etilqs_PFXugp3ZesvFvApMGMdq-journal not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\Perflib_Perfdata_558.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_7f0.dat not found! C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\68vhwod7.default\OfflineCache\index.sqlite moved successfully. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\68vhwod7.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\68vhwod7.default\XUL.mfl moved successfully.
DirLook.exe v2.0 by jpshortstuff
Log created at 20:14 on 05/01/2009
==================================
Contents of "C:\Documents and Settings\All Users\Application Data\Geek Squad"

—FOLDERS—

MRI (Created on 30/12/2008 at 20:23) d—–

—FILES—

(none found)

—Sub-Directories—

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI

EventLog.gsl (908 bytes - created on 30/12/2008 at 20:24, modified on 03/01/2009 at 18:18) –a—

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\Automation Reports (Created on 30/12/2008 at 20:25) d—–

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\Automation Reports\2008.12.30_0325PM (Created on 30/12/2008 at 20:25) d—–

OperationEventLog.gsl (6462 bytes - created on 30/12/2008 at 23:59, modified on 31/12/2008 at 04:21) –a—
OperationReport.gsl (16044 bytes - created on 30/12/2008 at 20:53, modified on 31/12/2008 at 04:21) –a—
OperationSettings.rtf (1770 bytes - created on 30/12/2008 at 20:25, modified on 30/12/2008 at 20:25) –a—

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\Automation Reports\2008.12.30_0325PM\Application Logs (Created on 30/12/2008 at 23:56) d—–

Chkdsk Drive C.log (1224 bytes - created on 30/12/2008 at 23:59, modified on 30/12/2008 at 23:58) –a—
Defrag Final Analysis Drive C.log (1371 bytes - created on 31/12/2008 at 04:21, modified on 31/12/2008 at 04:21) –a—
Defrag Initial Analysis Drive C.log (1374 bytes - created on 30/12/2008 at 23:59, modified on 30/12/2008 at 23:59) –a—
Ewido Thorough Scan.txt (6114 bytes - created on 31/12/2008 at 03:22, modified on 31/12/2008 at 04:01) –a—
Kaspersky Antivirus - Thorough Scan.txt (1416 bytes - created on 31/12/2008 at 03:21, modified on 31/12/2008 at 03:21) –a—

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\Automation Reports\2009.01.02_1018AM (Created on 02/01/2009 at 15:18) d—–

OperationEventLog.gsl (10254 bytes - created on 02/01/2009 at 18:42, modified on 03/01/2009 at 07:47) –a—
OperationReport.gsl (16948 bytes - created on 02/01/2009 at 15:36, modified on 03/01/2009 at 07:47) –a—
OperationSettings.rtf (1770 bytes - created on 02/01/2009 at 15:18, modified on 02/01/2009 at 15:18) –a—

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\Automation Reports\2009.01.02_1018AM\Application Logs (Created on 02/01/2009 at 18:39) d—–

A-Squared Thorough Scan.txt (5843 bytes - created on 03/01/2009 at 06:49, modified on 03/01/2009 at 06:49) –a—
Chkdsk Drive C.log (1233 bytes - created on 02/01/2009 at 18:42, modified on 02/01/2009 at 18:41) –a—
Defrag Final Analysis Drive C.log (1371 bytes - created on 03/01/2009 at 07:47, modified on 03/01/2009 at 07:47) –a—
Defrag Initial Analysis Drive C.log (1375 bytes - created on 02/01/2009 at 18:42, modified on 02/01/2009 at 18:42) –a—
Ewido Thorough Scan.txt (1620 bytes - created on 03/01/2009 at 06:50, modified on 03/01/2009 at 07:39) –a—
Kaspersky Antivirus - Thorough Scan.txt (1283 bytes - created on 02/01/2009 at 22:25, modified on 02/01/2009 at 22:25) –a—
McAfee Thorough Scan.txt (1886 bytes - created on 03/01/2009 at 00:31, modified on 03/01/2009 at 01:36) –a—
Panda_Maximum_Scan.txt (721 bytes - created on 02/01/2009 at 22:26, modified on 03/01/2009 at 00:31) –a—
Spyware Doctor - Thorough Scan.html (18658 bytes - created on 03/01/2009 at 03:58, modified on 03/01/2009 at 03:58) –a—
Trend Micro Thorough Scan.txt (1125 bytes - created on 03/01/2009 at 01:36, modified on 03/01/2009 at 02:38) –a—
Webroot System Analyzer.log (15560 bytes - created on 03/01/2009 at 02:59, modified on 03/01/2009 at 02:59) –a—

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\System File Backups (Created on 30/12/2008 at 20:51) d—–

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\System File Backups\Boot Files (Created on 30/12/2008 at 20:51) d—–

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\System File Backups\Boot Files\Drive C - 2008.12.30_0351PM (Created on 30/12/2008 at 20:51) d—–

boot.ini (211 bytes - created on 05/11/2005 at 00:54, modified on 30/12/2008 at 03:33) -rahs-
ntldr (237952 bytes - created on 05/11/2005 at 00:53, modified on 17/09/2008 at 16:33) -rahs-

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\System File Backups\Boot Files\Drive C - 2009.01.02_1034AM (Created on 02/01/2009 at 15:34) d—–

boot.ini (211 bytes - created on 05/11/2005 at 00:54, modified on 30/12/2008 at 03:33) -rahs-
ntldr (237952 bytes - created on 05/11/2005 at 00:53, modified on 17/09/2008 at 16:33) -rahs-

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\System File Backups\Registry Hives (Created on 30/12/2008 at 20:51) d—–

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\System File Backups\Registry Hives\Current - 2008.12.30_0351PM (Created on 30/12/2008 at 20:51) d—–

default (786432 bytes - created on 04/11/2005 at 18:21, modified on 30/12/2008 at 17:29) –a—
default.LOG (303104 bytes - created on 04/11/2005 at 18:21, modified on 30/12/2008 at 18:01) –ah–
default.sav (94208 bytes - created on 04/11/2005 at 18:21, modified on 04/11/2005 at 18:21) –a—
SAM (262144 bytes - created on 04/11/2005 at 18:22, modified on 30/12/2008 at 06:20) –a—
SAM.LOG (16384 bytes - created on 04/11/2005 at 18:22, modified on 30/12/2008 at 17:55) –ah–
SECURITY (262144 bytes - created on 04/11/2005 at 18:22, modified on 30/12/2008 at 06:20) –a—
SECURITY.LOG (16384 bytes - created on 04/11/2005 at 18:22, modified on 30/12/2008 at 17:53) –ah–
software (32768000 bytes - created on 04/11/2005 at 18:21, modified on 30/12/2008 at 06:20) –a—
software.LOG (118784 bytes - created on 04/11/2005 at 18:21, modified on 30/12/2008 at 20:51) –ah–
software.sav (634880 bytes - created on 04/11/2005 at 18:21, modified on 04/11/2005 at 18:21) –a—
system (8912896 bytes - created on 04/11/2005 at 18:21, modified on 30/12/2008 at 17:53) –a—
system.LOG (1949696 bytes - created on 04/11/2005 at 18:21, modified on 30/12/2008 at 18:01) –ah–
system.sav (876544 bytes - created on 04/11/2005 at 18:21, modified on 04/11/2005 at 18:21) –a—

C:\Documents and Settings\All Users\Application Data\Geek Squad\MRI\System File Backups\Registry Hives\Current - 2009.01.02_1034AM (Created on 02/01/2009 at 15:34) d—–

default (786432 bytes - created on 04/11/2005 at 18:21, modified on 31/12/2008 at 03:23) –a—
default.LOG (73728 bytes - created on 04/11/2005 at 18:21, modified on 02/01/2009 at 15:21) –ah–
Default.LOG1 (262144 bytes - created on 30/12/2008 at 23:59, modified on 31/12/2008 at 03:23) –ah–
Default.LOG2 (0 bytes - created on 30/12/2008 at 23:59, modified on 30/12/2008 at 23:59) –ah–
default.sav (94208 bytes - created on 04/11/2005 at 18:21, modified on 04/11/2005 at 18:21) –a—
SAM (262144 bytes - created on 04/11/2005 at 18:22, modified on 02/01/2009 at 15:12) –a—
SAM.LOG (16384 bytes - created on 04/11/2005 at 18:22, modified on 02/01/2009 at 15:13) –ah–
SAM.LOG1 (5120 bytes - created on 30/12/2008 at 23:59, modified on 31/12/2008 at 03:23) –ah–
SAM.LOG2 (0 bytes - created on 30/12/2008 at 23:59, modified on 30/12/2008 at 23:59) –ah–
SECURITY (262144 bytes - created on 04/11/2005 at 18:22, modified on 02/01/2009 at 15:12) –a—
SECURITY.LOG (16384 bytes - created on 04/11/2005 at 18:22, modified on 02/01/2009 at 15:13) –ah–
Security.LOG1 (262144 bytes - created on 30/12/2008 at 23:59, modified on 31/12/2008 at 03:23) –ah–
Security.LOG2 (0 bytes - created on 30/12/2008 at 23:59, modified on 30/12/2008 at 23:59) –ah–
software (32768000 bytes - created on 04/11/2005 at 18:21, modified on 02/01/2009 at 15:12) –a—
software.LOG (106496 bytes - created on 04/11/2005 at 18:21, modified on 02/01/2009 at 15:21) –ah–
Software.LOG1 (262144 bytes - created on 30/12/2008 at 23:59, modified on 31/12/2008 at 03:23) –ah–
Software.LOG2 (0 bytes - created on 30/12/2008 at 23:59, modified on 30/12/2008 at 23:59) –ah–
software.sav (634880 bytes - created on 04/11/2005 at 18:21, modified on 04/11/2005 at 18:21) –a—
system (8912896 bytes - created on 04/11/2005 at 18:21, modified on 02/01/2009 at 15:12) –a—
system.LOG (2670592 bytes - created on 04/11/2005 at 18:21, modified on 02/01/2009 at 15:21) –ah–
System.LOG1 (262144 bytes - created on 30/12/2008 at 23:59, modified on 31/12/2008 at 03:22) –ah–
System.LOG2 (0 bytes - created on 30/12/2008 at 23:59, modified on 30/12/2008 at 23:59) –ah–
system.sav (876544 bytes - created on 04/11/2005 at 18:21, modified on 04/11/2005 at 18:21) –a—

==================================
=EOF=
Im am getting this error message when I turn on my laptop now. RUNDLL Error loading C:\windows\system32\yibabofi.dll Also I was reading around the forum and read that maybe this is other thing in my start up is infected? : msmsgs C:\program files\messenger\msmsgs.exe I just wanted to add those before I closed everything out for the scan
And the very short log… lol


OTListIt logfile created on: 1/6/2009 10:52:13 AM - Run 4
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.17 Mb Total Physical Memory | 164.06 Mb Available Physical Memory | 36.77% Memory free
1.03 Gb Paging File | 0.72 Gb Available in Paging File | 70.15% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.29 Gb Total Space | 59.32 Gb Free Space | 79.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LEON-NGUYEN
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
C:\WINDOWS\system32\drivers\CDAC11BA.EXE (C-Dilla Ltd)
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\WINDOWS\system32\HPZipm12.exe (HP)
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
C:\WINDOWS\agrsmmsg.exe (Agere Systems)
C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Documents and Settings\user\Desktop\OTListIt2.exe (OldTimer Tools)

========== (O23) Win32 Services (SafeList) ==========

(ACS [Auto | Stopped]) – C:\WINDOWS\system32\acs.exe ()
(Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ()
(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
(aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
(Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
(avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
(avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
(avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
(C-DillaCdaC11BA [Auto | Running]) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE (C-Dilla Ltd)
(CFSvcs [Auto | Running]) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
(DVD-RAM_Service [Auto | Running]) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
(IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
(iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
(JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
(NBService [On_Demand | Stopped]) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
(Pml Driver HPZ12 [Unknown | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
(Swupdtmr [Auto | Running]) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
(TAPPSRV [Auto | Running]) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
(UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(Aavmker4 [System | Running]) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
(AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
(AgereSoftModem [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
(AR5211 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
(ASCTRM [Auto | Running]) – C:\WINDOWS\system32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
(aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
(aswMon2 [Auto | Running]) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
(aswRdr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
(aswSP [System | Running]) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
(aswTdi [System | Running]) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
(ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
(BVRPMPR5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
(CdaC15BA [Auto | Running]) – C:\WINDOWS\system32\drivers\CDAC15BA.SYS ()
(DLABOIOM [Auto | Running]) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
(DLACDBHM [System | Running]) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
(DLADResN [Auto | Running]) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
(DLAIFS_M [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
(DLAOPIOM [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
(DLAPoolM [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
(DLARTL_N [System | Running]) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
(DLAUDFAM [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
(DLAUDF_M [Auto | Running]) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
(DRVMCDB [Boot | Running]) – C:\WINDOWS\system32\drivers\DRVMCDB.SYS (Sonic Solutions)
(DRVNDDM [Auto | Running]) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
(GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
(HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
(IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
(is-7CTGVdrv [System | Running]) – C:\WINDOWS\system32\drivers\55586384.sys (Kaspersky Lab)
(KR10N [Boot | Running]) – C:\WINDOWS\system32\drivers\KR10N.sys (TOSHIBA CORPORATION)
(meiudf [System | Running]) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
(Netdevio [Auto | Running]) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
(pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
(Point32 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\point32.sys (Microsoft Corporation)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
(RTL8023xp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
(rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
(Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(snapman [Boot | Running]) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
(SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
(SynTP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
(tbiosdrv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tbiosdrv.sys ()
(TVALD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NBSMI.sys (Toshiba Corporation)
(Tvs [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Tvs.sys (TOSHIBA Corporation)
(usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
(wanatw [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
(WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (732 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon File not found
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon File not found
O4 - HKLM..\Run: [CPM6359ad97] Rundll32.exe "c:\windows\system32\yibabofi.dll",a File not found
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run (TOSHIBA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER (RealNetworks, Inc.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup File not found
O4 - HKCU..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl File not found
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: objects.aol.com (* is out of zone range - 5)
O15 - HKCU\..Trusted Sites: stumbleupon.com (* in Trusted sites)
O15 - HKCU\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} http://aolsvc.aol.com/onlinegames/free-tri…eb.1.0.0.21.cab (CPlayFirstFashionDasControl Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab (WildTangent Active Launcher)
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} http://www.gamehouse.com/ghdlctl.cab (dldisplay Class)
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab (WWHearts Control)
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.48.cab (CPlayFirstDinerDash2Control Object)
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab (Abx(gh) Control)
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} http://legacy.aolsvc.aol.com/onlinegames/g…bugs/axhost.cab (WildfireActiveXHost Class)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} http://www.worldwinner.com/games/v67/swapit/swapit.cab (SwapIt Control)
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab (Zylom Games Player)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} https://disney.go.com/games/downloads/gamem…GameManager.cab (CGameManagerCtrl Object)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://aolsvc.aol.com/onlinegames/pandacraze/gpcontrol.cab (TikGames Online Control)
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} http://aolsvc.aol.com/onlinegames/dinerdas…sh.1.0.0.93.cab (CPlayFirstDinerDashControl Object)
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} http://aolsvc.aol.com/onlinegames/oberonma…ameLauncher.cab (Playtime Games Launcher)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdo - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: ({93ac7c30-3878-4eaa-9420-7977285df5b1}) - cinnamomum - Reg Error: Key does not exist or could not be opened. File not found

========== AppInit_DLLs ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls" = c:\windows\system32\yibabofi.dll
>c:\windows\system32\yibabofi.dll File not found

========== HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)

"UserInit" = C:\WINDOWS\SYSTEM32\userinit.exe,
>C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

"UIHost" = logonui.exe
>C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)

"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)


========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll – C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
crypt32chain: "DllName" = crypt32.dll – C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll – C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll – C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
dimsntfy: "DllName" = %SystemRoot%\System32\dimsntfy.dll – C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
iastUI: "DllName" = iastUI.dll – File not found
iifcAQhG: "DllName" = iifcAQhG.dll – File not found
ScCertProp: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll – C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
WgaLogon: "DllName" = WgaLogon.dll – C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)

========== IFEO "Debugger" Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) – C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[2009/01/05 20:13:46 | 00,199,680 | —- | C] () – C:\Documents and Settings\user\Desktop\DirLook.exe
[2009/01/05 20:02:43 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/01/05 20:01:16 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTMoveIt3.exe
[2009/01/05 18:17:30 | 00,419,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTListIt2.exe
[2009/01/05 18:10:29 | 46,791,4752 | -HS- | C] () – C:\hiberfil.sys
[2009/01/05 13:18:08 | 02,756,640 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009/01/05 13:18:08 | 00,027,620 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009/01/05 13:17:53 | 00,148,496 | —- | C] (Kaspersky Lab) – C:\WINDOWS\System32\drivers\55586384.sys
[2009/01/05 13:17:51 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\Virus Removal Tool
[2009/01/05 12:49:29 | 31,379,928 | —- | C] ( ) – C:\Documents and Settings\user\Desktop\setup_7.0.0.290_05.01.2009_17-40.exe
[2009/01/04 22:03:02 | 17,593,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/03 21:18:45 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\KEEP OUT!!
[2009/01/03 19:57:39 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/01/03 19:57:37 | 00,050,864 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/01/03 19:57:35 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/01/03 19:57:30 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/01/03 19:57:29 | 00,111,184 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/01/03 19:57:29 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/01/03 19:57:29 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/01/03 19:57:29 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/01/03 19:56:58 | 01,236,208 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/01/03 19:56:58 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/01/03 19:43:53 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Malwarebytes
[2009/01/03 19:43:46 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/03 19:43:43 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/03 19:43:42 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/03 19:43:41 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/03 19:42:46 | 02,539,400 | —- | C] (Malwarebytes Corporation ) – C:\mbam-setup.exe
[2009/01/03 19:17:39 | 00,116,224 | —- | C] (Xerox) – C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2009/01/03 19:17:32 | 00,023,040 | —- | C] (Xerox Corporation) – C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2009/01/03 19:17:30 | 00,018,944 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2009/01/03 19:17:23 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2009/01/03 19:17:16 | 00,004,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2009/01/03 19:17:08 | 00,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2009/01/03 19:17:00 | 00,016,970 | —- | C] (US Robotics MCD (Megahertz)) – C:\WINDOWS\System32\dllcache\xem336n5.sys
[2009/01/03 19:16:52 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshirda.dll
[2009/01/03 19:16:37 | 00,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiacpi.sys
[2009/01/03 19:16:33 | 00,154,624 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\wlluc48.sys
[2009/01/03 19:16:26 | 00,034,890 | —- | C] (Raytheon Corp.) – C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2009/01/03 19:16:16 | 00,771,581 | —- | C] (Rockwell) – C:\WINDOWS\System32\dllcache\winacisa.sys
[2009/01/03 19:16:08 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2009/01/03 19:16:01 | 00,087,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2009/01/03 19:16:00 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\weitekp9.sys
[2009/01/03 19:15:59 | 00,041,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\weitekp9.dll
[2009/01/03 19:15:47 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2009/01/03 19:15:41 | 00,035,871 | —- | C] (Winbond Electronics Corp.) – C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2009/01/03 19:15:20 | 00,016,925 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w940nd.sys
[2009/01/03 19:15:13 | 00,019,016 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w926nd.sys
[2009/01/03 19:15:06 | 00,048,256 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\w32.dll
[2009/01/03 19:15:06 | 00,019,528 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w840nd.sys
[2009/01/03 19:14:59 | 00,064,605 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vvoice.sys
[2009/01/03 19:14:51 | 00,397,502 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vpctcom.sys
[2009/01/03 19:14:44 | 00,604,253 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\vmodem.sys
[2009/01/03 19:14:37 | 00,249,402 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\vinwm.sys
[2009/01/03 19:14:28 | 00,005,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\viaide.sys
[2009/01/03 19:14:20 | 00,687,999 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2009/01/03 19:14:13 | 00,765,884 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usrti.sys
[2009/01/03 19:14:06 | 00,113,762 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrpda.sys
[2009/01/03 19:14:00 | 00,007,556 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usroslba.sys
[2009/01/03 19:13:53 | 00,224,802 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usr1807a.sys
[2009/01/03 19:13:46 | 00,794,399 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806v.sys
[2009/01/03 19:13:39 | 00,793,598 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806.sys
[2009/01/03 19:13:33 | 00,794,654 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1801.sys
[2009/01/03 19:13:30 | 00,020,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbuhci.sys
[2009/01/03 19:13:28 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbser.sys
[2009/01/03 19:13:26 | 00,032,384 | —- | C] (KLSI USA, Inc.) – C:\WINDOWS\System32\dllcache\usb101et.sys
[2009/01/03 19:13:17 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxud32.dll
[2009/01/03 18:23:17 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/01/03 18:22:49 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\HJTInstall.exe
[2009/01/03 18:17:00 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu40.dll
[2009/01/03 18:16:52 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu22.dll
[2009/01/03 18:16:45 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu12.dll
[2009/01/03 18:16:38 | 00,050,688 | —- | C] (UMAX DATA SYSTEMS INC.) – C:\WINDOWS\System32\dllcache\umaxscan.dll
[2009/01/03 18:16:31 | 00,022,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2009/01/03 18:16:24 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxp60.dll
[2009/01/03 18:16:16 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxcam.dll
[2009/01/03 18:16:08 | 00,211,968 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um54scan.dll
[2009/01/03 18:16:00 | 00,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2009/01/03 18:15:43 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tsprof.exe
[2009/01/03 18:15:35 | 00,166,784 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxpm.sys
[2009/01/03 18:15:27 | 00,525,568 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxp.dll
[2009/01/03 18:15:20 | 00,159,232 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkbm.sys
[2009/01/03 18:15:12 | 00,440,576 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkb.dll
[2009/01/03 18:15:05 | 00,222,336 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3dm.sys
[2009/01/03 18:14:57 | 00,315,520 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3d.dll
[2009/01/03 18:14:23 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\toside.sys
[2009/01/03 18:13:54 | 00,123,995 | —- | C] (Tiger Jet Network) – C:\WINDOWS\System32\dllcache\tjisdn.sys
[2009/01/03 18:13:52 | 00,185,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\thawbrkr.dll
[2009/01/03 18:13:45 | 00,138,528 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2009/01/03 18:13:38 | 00,081,408 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiul50.dll
[2009/01/03 18:13:36 | 00,149,376 | —- | C] (M-Systems) – C:\WINDOWS\System32\dllcache\tffsport.sys
[2009/01/03 18:13:35 | 00,019,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdspx.sys
[2009/01/03 18:13:28 | 00,017,129 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2009/01/03 18:13:21 | 00,037,961 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdk100b.sys
[2009/01/03 18:13:21 | 00,021,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdipx.sys
[2009/01/03 18:13:20 | 00,013,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdasync.sys
[2009/01/03 18:13:05 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tandqic.sys
[2009/01/03 18:12:58 | 00,036,640 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2009/01/03 18:12:51 | 00,172,768 | —- | C] (Number Nine Visual Technology) – C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2009/01/03 18:12:17 | 00,094,293 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sxports.dll
[2009/01/03 18:12:11 | 00,103,936 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sx.sys
[2009/01/03 18:12:04 | 00,003,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swusbflt.sys
[2009/01/03 18:11:58 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpidflt.dll
[2009/01/03 18:11:52 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2009/01/03 18:11:46 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2009/01/03 18:11:40 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_effct.dll
[2009/01/03 18:11:33 | 00,155,648 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnprop.dll
[2009/01/03 18:11:27 | 00,053,248 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlncoin.dll
[2009/01/03 18:11:21 | 00,285,760 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnata.sys
[2009/01/03 18:11:15 | 00,016,896 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\stcusb.sys
[2009/01/03 18:11:07 | 00,048,736 | —- | C] (3Com) – C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2009/01/03 18:11:01 | 00,099,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusd.dll
[2009/01/03 18:11:00 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusbusd.dll
[2009/01/03 18:10:52 | 00,024,660 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spxupchk.dll
[2009/01/03 18:10:45 | 00,061,824 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\speed.sys
[2009/01/03 18:10:39 | 00,106,584 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spdports.dll
[2009/01/03 18:10:33 | 00,019,072 | —- | C] (Adaptec, Inc.) – C:\WINDOWS\System32\dllcache\sparrow.sys
[2009/01/03 18:10:06 | 00,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonymc.sys
[2009/01/03 18:10:03 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonyait.sys
[2009/01/03 18:09:55 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll
[2009/01/03 18:09:55 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2009/01/03 18:09:53 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpstup.dll
[2009/01/03 18:09:49 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll
[2009/01/03 18:09:48 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smimsgif.dll
[2009/01/03 18:09:41 | 00,058,368 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smiminib.sys
[2009/01/03 18:09:40 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smierrsm.dll
[2009/01/03 18:09:40 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smierrsy.dll
[2009/01/03 18:09:34 | 00,147,200 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smidispb.dll
[2009/01/03 18:09:26 | 00,025,034 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2009/01/03 18:09:19 | 00,035,913 | —- | C] (SMC) – C:\WINDOWS\System32\dllcache\smcirda.sys
[2009/01/03 18:09:13 | 00,024,576 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smc8000n.sys
[2009/01/03 18:09:06 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbhc.sys
[2009/01/03 18:09:04 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbclass.sys
[2009/01/03 18:09:02 | 00,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbbatt.sys
[2009/01/03 18:09:01 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb6w.dll
[2009/01/03 18:08:55 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb3w.dll
[2009/01/03 18:08:49 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb0w.dll
[2009/01/03 18:08:49 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma3w.dll
[2009/01/03 18:08:42 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm9aw.dll
[2009/01/03 18:08:42 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma0w.dll
[2009/01/03 18:08:41 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm93w.dll
[2009/01/03 18:08:41 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm92w.dll
[2009/01/03 18:08:34 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm91w.dll
[2009/01/03 18:08:34 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm90w.dll
[2009/01/03 18:08:33 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8dw.dll
[2009/01/03 18:08:32 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8cw.dll
[2009/01/03 18:08:32 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8aw.dll
[2009/01/03 18:08:31 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm89w.dll
[2009/01/03 18:08:30 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm87w.dll
[2009/01/03 18:08:30 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm81w.dll
[2009/01/03 18:08:29 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm59w.dll
[2009/01/03 18:08:25 | 00,063,547 | —- | C] (Symbol Technologies) – C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2009/01/03 18:08:19 | 00,091,294 | —- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) – C:\WINDOWS\System32\dllcache\skfpwin.sys
[2009/01/03 18:08:13 | 00,094,698 | —- | C] (SysKonnect GmbH.) – C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2009/01/03 18:07:58 | 00,032,768 | —- | C] (SiS Corporation) – C:\WINDOWS\System32\dllcache\sisnic.sys
[2009/01/03 18:07:23 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\simptcp.dll
[2009/01/03 18:07:08 | 00,161,568 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2009/01/03 18:07:01 | 00,018,400 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmld.sys
[2009/01/03 18:06:56 | 00,098,080 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2009/01/03 18:06:49 | 00,386,560 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiul50.dll
[2009/01/03 18:06:34 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2009/01/03 18:06:29 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2009/01/03 18:06:28 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_seos.dll
[2009/01/03 18:06:21 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2009/01/03 18:06:19 | 00,011,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiscan.sys
[2009/01/03 18:06:13 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2009/01/03 18:06:12 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_scripto.dll
[2009/01/03 18:06:06 | 00,017,280 | —- | C] (SCM Microsystems) – C:\WINDOWS\System32\dllcache\scr111.sys
[2009/01/03 18:06:01 | 00,016,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scmstcs.sys
[2009/01/03 18:05:54 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2009/01/03 18:05:48 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2009/01/03 18:05:45 | 00,043,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sbp2port.sys
[2009/01/03 18:05:20 | 00,077,824 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2009/01/03 18:05:14 | 00,198,400 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4.dll
[2009/01/03 18:05:09 | 00,061,504 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2009/01/03 18:05:02 | 00,179,264 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2009/01/03 18:04:57 | 00,210,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2009/01/03 18:04:52 | 00,062,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2009/01/03 18:04:47 | 00,041,216 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2009/01/03 18:04:42 | 00,182,272 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2009/01/03 18:04:38 | 00,166,720 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3m.sys
[2009/01/03 18:04:34 | 00,065,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.sys
[2009/01/03 18:04:28 | 00,082,432 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia450.dll
[2009/01/03 18:04:19 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia430.dll
[2009/01/03 18:04:19 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia330.dll
[2009/01/03 18:04:18 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia001.dll
[2009/01/03 18:04:17 | 00,029,696 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw450ext.dll
[2009/01/03 18:04:09 | 00,027,648 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw430ext.dll
[2009/01/03 18:04:02 | 00,019,017 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8029.sys
[2009/01/03 18:03:52 | 00,009,216 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2009/01/03 18:03:37 | 00,079,104 | —- | C] (Comtrol Corporation) – C:\WINDOWS\System32\dllcache\rocket.sys
[2009/01/03 18:03:31 | 00,037,563 | —- | C] (RadioLAN) – C:\WINDOWS\System32\dllcache\rlnet5.sys
[2009/01/03 18:03:24 | 00,086,097 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\reslog32.dll
[2009/01/03 18:03:21 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe
[2009/01/03 18:03:20 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\register.exe
[2009/01/03 18:03:07 | 00,019,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasirda.sys
[2009/01/03 18:02:58 | 00,714,762 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2009/01/03 18:02:52 | 00,899,146 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2009/01/03 18:02:44 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qvusd.dll
[2009/01/03 18:02:37 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\quser.exe
[2009/01/03 18:02:37 | 00,003,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qv2kux.sys
[2009/01/03 18:02:36 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\query.exe
[2009/01/03 18:02:20 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql1240.sys
[2009/01/03 18:02:09 | 00,033,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ql10wnt.sys
[2009/01/03 18:02:02 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qic157.sys
[2009/01/03 18:01:55 | 00,130,942 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlv.sys
[2009/01/03 18:01:49 | 00,112,574 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlp.sys
[2009/01/03 18:01:44 | 00,128,286 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserli.sys
[2009/01/03 18:01:43 | 00,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusd.dll
[2009/01/03 18:01:38 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusb.dll
[2009/01/03 18:01:36 | 00,033,280 | —- | C] () – C:\WINDOWS\System32\dllcache\psisrndr.ax
[2009/01/03 18:01:30 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\psisload.dll
[2009/01/03 18:01:28 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\dllcache\psisdecd.dll
[2009/01/03 18:01:23 | 00,016,128 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\pscr.sys
[2009/01/03 18:01:19 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa3.sys
[2009/01/03 18:01:14 | 00,017,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa.sys
[2009/01/03 18:01:13 | 00,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\powerfil.sys
[2009/01/03 18:01:07 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pnrmc.sys
[2009/01/03 18:01:06 | 00,131,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxviceo.dll
[2009/01/03 18:01:06 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxmcro.dll
[2009/01/03 18:01:05 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxgl.dll
[2009/01/03 18:00:53 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phvfwext.dll
[2009/01/03 18:00:48 | 00,019,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philtune.sys
[2009/01/03 18:00:42 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phildec.sys
[2009/01/03 18:00:35 | 00,173,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam2.sys
[2009/01/03 18:00:29 | 00,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.sys
[2009/01/03 18:00:24 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.dll
[2009/01/03 18:00:17 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phdsext.ax
[2009/01/03 18:00:16 | 00,259,328 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3dd.dll
[2009/01/03 18:00:14 | 00,028,032 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3.sys
[2009/01/03 18:00:13 | 00,211,584 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2dll.dll
[2009/01/03 18:00:11 | 00,027,904 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2.sys
[2009/01/03 18:00:05 | 00,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2hib.sys
[2009/01/03 18:00:00 | 00,027,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\perc2.sys
[2009/01/03 17:59:57 | 00,169,984 | —- | C] (Cisco Systems) – C:\WINDOWS\System32\dllcache\pcx500.sys
[2009/01/03 17:59:50 | 00,086,016 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\pctspk.exe
[2009/01/03 17:59:45 | 00,035,328 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2009/01/03 17:59:39 | 00,029,769 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2009/01/03 17:59:34 | 00,030,282 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2009/01/03 17:59:29 | 00,026,153 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2009/01/03 17:59:27 | 00,029,502 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\pca200e.sys
[2009/01/03 17:59:21 | 00,030,495 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pc100nds.sys
[2009/01/03 17:59:14 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2rc.dll
[2009/01/03 17:59:09 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2.dll
[2009/01/03 17:59:03 | 00,025,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovsound2.sys
[2009/01/03 17:58:58 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcoms.exe
[2009/01/03 17:58:53 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcomc.dll
[2009/01/03 17:58:48 | 00,351,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodek2.sys
[2009/01/03 17:58:43 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodec2.dll
[2009/01/03 17:58:38 | 00,031,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovce.sys
[2009/01/03 17:58:33 | 00,028,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcd.sys
[2009/01/03 17:58:27 | 00,048,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcam2.sys
[2009/01/03 17:58:22 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovca.sys
[2009/01/03 17:58:18 | 00,054,186 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otcsercb.sys
[2009/01/03 17:58:12 | 00,043,689 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otceth5.sys
[2009/01/03 17:58:08 | 00,027,209 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otc06x5.sys
[2009/01/03 17:58:02 | 00,054,528 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\opl3sax.sys
[2009/01/03 17:57:37 | 00,051,552 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\dllcache\ntgrip.sys
[2009/01/03 17:57:36 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll
[2009/01/03 17:57:31 | 00,009,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntapm.sys
[2009/01/03 17:57:27 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsmmc.sys
[2009/01/03 17:57:20 | 00,087,040 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2009/01/03 17:57:14 | 00,126,080 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2009/01/03 17:57:08 | 00,032,840 | —- | C] (NETGEAR Corporation.) – C:\WINDOWS\System32\dllcache\ngrpci.sys
[2009/01/03 17:57:06 | 00,132,695 | —- | C] (802.11b) – C:\WINDOWS\System32\dllcache\netwlan5.sys
[2009/01/03 17:56:57 | 00,065,278 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\netflx3.sys
[2009/01/03 17:56:51 | 00,039,264 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.sys
[2009/01/03 17:56:47 | 00,060,480 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.dll
[2009/01/03 17:56:42 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ne2000.sys
[2009/01/03 17:56:34 | 00,091,488 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2009/01/03 17:56:29 | 00,027,936 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3d.sys
[2009/01/03 17:56:25 | 00,033,088 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2009/01/03 17:56:21 | 00,059,104 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2009/01/03 17:56:17 | 00,013,664 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.sys
[2009/01/03 17:56:13 | 00,035,392 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.dll
[2009/01/03 17:56:09 | 00,128,000 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n100325.sys
[2009/01/03 17:56:06 | 00,052,255 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2009/01/03 17:56:02 | 00,075,520 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxport.sys
[2009/01/03 17:55:58 | 00,007,168 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxport.dll
[2009/01/03 17:55:54 | 00,019,968 | —- | C] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\dllcache\mxnic.sys
[2009/01/03 17:55:51 | 00,019,968 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxicfg.dll
[2009/01/03 17:55:47 | 00,021,888 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxcard.sys
[2009/01/03 17:55:41 | 00,103,296 | —- | C] (Matrox Graphics Inc) – C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2009/01/03 17:55:24 | 00,049,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstape.sys
[2009/01/03 17:55:16 | 00,012,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msriffwv.sys
[2009/01/03 17:54:55 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msmpu401.sys
[2009/01/03 17:54:49 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msircomm.sys
[2009/01/03 17:54:32 | 00,035,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msgame.sys
[2009/01/03 17:54:27 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfsio.sys
[2009/01/03 17:54:26 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2009/01/03 17:54:26 | 00,051,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdv.sys
[2009/01/03 17:54:17 | 00,017,280 | —- | C] (American Megatrends Inc.) – C:\WINDOWS\System32\dllcache\mraid35x.sys
[2009/01/03 17:54:14 | 00,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpe.sys
[2009/01/03 17:54:07 | 00,016,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\modemcsa.sys
[2009/01/03 17:53:59 | 00,006,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\miniqic.sys
[2009/01/03 17:53:57 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\migisol.exe
[2009/01/03 17:53:46 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mga.sys
[2009/01/03 17:53:46 | 00,092,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mga.dll
[2009/01/03 17:53:38 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memgrp.dll
[2009/01/03 17:53:34 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memcard.sys
[2009/01/03 17:53:29 | 00,164,586 | —- | C] (Madge Networks Ltd) – C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2009/01/03 17:53:23 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mammoth.sys
[2009/01/03 17:53:22 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll
[2009/01/03 17:53:13 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3092dc.dll
[2009/01/03 17:53:08 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3091dc.dll
[2009/01/03 17:52:58 | 00,797,500 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltsmt.sys
[2009/01/03 17:52:54 | 00,802,683 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\ltsm.sys
[2009/01/03 17:52:53 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ltotape.sys
[2009/01/03 17:52:52 | 00,420,992 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2009/01/03 17:52:48 | 00,576,746 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2009/01/03 17:52:47 | 00,606,684 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2009/01/03 17:52:43 | 00,727,786 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ltck000c.sys
[2009/01/03 17:52:38 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\loop.sys
[2009/01/03 17:52:33 | 00,070,730 | —- | C] (Linksys Group, Inc.) – C:\WINDOWS\System32\dllcache\lne100tx.sys
[2009/01/03 17:52:29 | 00,020,573 | —- | C] (The Linksts Group ) – C:\WINDOWS\System32\dllcache\lne100.sys
[2009/01/03 17:52:25 | 00,025,065 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\lmndis3.sys
[2009/01/03 17:52:21 | 00,015,744 | —- | C] (Litronic Industries) – C:\WINDOWS\System32\dllcache\lit220p.sys
[2009/01/03 17:52:16 | 00,026,442 | —- | C] (SMSC) – C:\WINDOWS\System32\dllcache\lanepic5.sys
[2009/01/03 17:52:13 | 00,019,016 | —- | C] (Kingston Technology Company ) – C:\WINDOWS\System32\dllcache\ktc111.sys
[2009/01/03 17:52:08 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kousd.dll
[2009/01/03 17:52:06 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsusd.dll
[2009/01/03 17:52:06 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsui.dll
[2009/01/03 17:52:04 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdusa.dll
[2009/01/03 17:51:56 | 00,014,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdhid.sys
[2009/01/03 17:51:49 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jupiw.dll
[2009/01/03 17:51:40 | 00,018,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irsir.sys
[2009/01/03 17:51:39 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irmon.dll
[2009/01/03 17:51:35 | 00,151,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irftp.exe
[2009/01/03 17:51:35 | 00,023,552 | —- | C] (MKNet Corporation) – C:\WINDOWS\System32\dllcache\irmk7.sys
[2009/01/03 17:51:34 | 00,088,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irda.sys
[2009/01/03 17:51:15 | 00,045,632 | —- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) – C:\WINDOWS\System32\dllcache\ip5515.sys
[2009/01/03 17:51:11 | 00,090,200 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8ports.dll
[2009/01/03 17:51:07 | 00,038,784 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8.sys
[2009/01/03 17:51:06 | 00,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\intelide.sys
[2009/01/03 17:51:02 | 00,013,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inport.sys
[2009/01/03 17:51:02 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/01/03 17:50:58 | 00,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ini910u.sys
[2009/01/03 17:50:37 | 00,372,824 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\iconf32.dll
[2009/01/03 17:50:32 | 00,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5usb.sys
[2009/01/03 17:50:28 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5ext.dll
[2009/01/03 17:50:24 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5com.dll
[2009/01/03 17:50:20 | 00,154,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4usb.sys
[2009/01/03 17:50:16 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4ext.dll
[2009/01/03 17:50:12 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4com.dll
[2009/01/03 17:50:08 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3ext.dll
[2009/01/03 17:50:05 | 00,141,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3.sys
[2009/01/03 17:50:01 | 00,038,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2009/01/03 17:49:34 | 00,018,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omp.sys
[2009/01/03 17:49:33 | 00,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2009/01/03 17:48:30 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hr1w.dll
[2009/01/03 17:48:26 | 00,005,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpt4qic.sys
[2009/01/03 17:48:22 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2009/01/03 17:48:19 | 00,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2009/01/03 17:48:15 | 00,025,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpn.sys
[2009/01/03 17:48:12 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2009/01/03 17:48:08 | 00,068,608 | —- | C] (Avisioin) – C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2009/01/03 17:48:05 | 00,165,888 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt53.dll
[2009/01/03 17:48:02 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2009/01/03 17:47:58 | 00,093,696 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt42.dll
[2009/01/03 17:47:55 | 00,126,976 | —- | C] (Hewlett Packard) – C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2009/01/03 17:47:51 | 00,101,376 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt34.dll
[2009/01/03 17:47:48 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2009/01/03 17:47:45 | 00,089,088 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt33.dll
[2009/01/03 17:47:42 | 00,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2009/01/03 17:47:39 | 00,083,968 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt21.dll
[2009/01/03 17:47:35 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2009/01/03 17:47:34 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\HJTsetup.exe
[2009/01/03 17:47:31 | 00,002,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidswvd.sys
[2009/01/03 17:47:28 | 00,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidgame.sys
[2009/01/03 17:47:27 | 00,020,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidbatt.sys
[2009/01/03 17:47:20 | 00,028,288 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grserial.sys
[2009/01/03 17:47:18 | 00,082,304 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grclass.sys
[2009/01/03 17:47:15 | 00,017,408 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\gpr400.sys
[2009/01/03 17:47:11 | 00,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gckernel.sys
[2009/01/03 17:47:10 | 00,010,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gameenum.sys
[2009/01/03 17:46:55 | 00,454,912 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fxusbase.sys
[2009/01/03 17:46:49 | 00,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fuusd.dll
[2009/01/03 17:46:47 | 00,455,296 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fusbbase.sys
[2009/01/03 17:46:44 | 00,455,680 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fus2base.sys
[2009/01/03 17:46:43 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ftlx041e.dll
[2009/01/03 17:46:40 | 00,442,240 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2009/01/03 17:46:37 | 00,441,728 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2009/01/03 17:46:34 | 00,444,416 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcibase.sys
[2009/01/03 17:46:33 | 00,034,173 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\forehe.sys
[2009/01/03 17:46:30 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fnfilter.dll
[2009/01/03 17:46:29 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\flattemp.exe
[2009/01/03 17:46:18 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll
[2009/01/03 17:46:15 | 00,024,618 | —- | C] (NETGEAR) – C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2009/01/03 17:46:10 | 00,011,850 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2009/01/03 17:46:08 | 00,012,362 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2009/01/03 17:46:05 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exabyte2.sys
[2009/01/03 17:46:00 | 00,045,056 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunid.dll
[2009/01/03 17:46:00 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\et4000.sys
[2009/01/03 17:45:58 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunib.dll
[2009/01/03 17:45:55 | 00,057,856 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009/01/03 17:45:55 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuni.dll
[2009/01/03 17:45:52 | 00,034,816 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimg.dll
[2009/01/03 17:45:52 | 00,031,744 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucmd.dll
[2009/01/03 17:45:49 | 00,043,008 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucm.dll
[2009/01/03 17:45:31 | 00,072,192 | —- | C] (ESS Technology Inc.) – C:\WINDOWS\System32\dllcache\es1969.sys
[2009/01/03 17:45:14 | 00,114,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epstw2k.sys
[2009/01/03 17:45:09 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2009/01/03 17:44:58 | 00,007,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\elmsmc.sys
[2009/01/03 17:44:33 | 00,514,587 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\edb500.dll
[2009/01/03 17:44:16 | 00,334,208 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2009/01/03 17:44:12 | 00,020,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpti2o.sys
[2009/01/03 17:44:09 | 00,028,062 | —- | C] (National Semiconductor Coproration) – C:\WINDOWS\System32\dllcache\dp83820.sys
[2009/01/03 17:44:07 | 00,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2009/01/03 17:44:06 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2009/01/03 17:44:04 | 00,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2009/01/03 17:44:03 | 00,206,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4.sys
[2009/01/03 17:43:51 | 00,029,696 | —- | C] (CNet Technology, Inc. ) – C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2009/01/03 17:43:51 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dlttape.sys
[2009/01/03 17:43:49 | 00,026,698 | —- | C] (D-Link Corporation) – C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2009/01/03 17:43:47 | 00,952,007 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diwan.sys
[2009/01/03 17:43:46 | 00,029,768 | —- | C] () – C:\WINDOWS\System32\dllcache\divasu.dll
[2009/01/03 17:43:44 | 00,037,962 | —- | C] () – C:\WINDOWS\System32\dllcache\divaprop.dll
[2009/01/03 17:43:43 | 00,006,216 | —- | C] () – C:\WINDOWS\System32\dllcache\divaci.dll
[2009/01/03 17:43:41 | 00,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2009/01/03 17:43:40 | 00,038,985 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvsu.dll
[2009/01/03 17:43:38 | 00,031,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvpp.dll
[2009/01/03 17:43:37 | 00,006,729 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvci.dll
[2009/01/03 17:43:32 | 00,091,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\dimaint.sys
[2009/01/03 17:42:50 | 00,024,649 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650d.sys
[2009/01/03 17:42:48 | 00,024,648 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650.sys
[2009/01/03 17:42:42 | 00,020,928 | —- | C] (Digital Networks, LLC) – C:\WINDOWS\System32\dllcache\defpa.sys
[2009/01/03 17:42:41 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddsmc.sys
[2009/01/03 17:42:38 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc260usd.dll
[2009/01/03 17:42:36 | 00,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc240usd.dll
[2009/01/03 17:42:33 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210usd.dll
[2009/01/03 17:42:32 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210_32.dll
[2009/01/03 17:42:26 | 00,014,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dac960nt.sys
[2009/01/03 17:42:16 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzports.dll
[2009/01/03 17:42:15 | 00,049,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzport.sys
[2009/01/03 17:42:14 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzcoins.dll
[2009/01/03 17:42:12 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyports.dll
[2009/01/03 17:42:11 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyport.sys
[2009/01/03 17:42:09 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyycoins.dll
[2009/01/03 17:42:08 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclom-y.sys
[2009/01/03 17:42:06 | 00,048,640 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2009/01/03 17:42:06 | 00,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclad-z.sys
[2009/01/03 17:42:04 | 00,093,952 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2009/01/03 17:42:03 | 00,111,872 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcspud.sys
[2009/01/03 17:42:01 | 00,003,584 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2009/01/03 17:42:00 | 00,072,832 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2009/01/03 17:41:58 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2009/01/03 17:41:57 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbase.sys
[2009/01/03 17:41:54 | 00,249,856 | —- | C] (Comtrol® Corporation) – C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2009/01/03 17:41:48 | 00,175,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\csamsp.dll
[2009/01/03 17:41:44 | 00,216,064 | —- | C] (COMPAQ Inc.) – C:\WINDOWS\System32\dllcache\cpscan.dll
[2009/01/03 17:41:43 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cprofile.exe
[2009/01/03 17:41:42 | 00,060,970 | —- | C] (Compaq Computer Corp.) – C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2009/01/03 17:41:41 | 00,021,533 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2009/01/03 17:41:39 | 00,014,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cpqarray.sys
[2009/01/03 17:41:27 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnusd.dll
[2009/01/03 17:41:22 | 00,020,736 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2009/01/03 17:41:20 | 00,248,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546xm.sys
[2009/01/03 17:41:19 | 00,170,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546x.dll
[2009/01/03 17:41:18 | 00,111,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl5465.dll
[2009/01/03 17:41:17 | 00,045,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.sys
[2009/01/03 17:41:16 | 00,091,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.dll
[2009/01/03 17:41:14 | 00,272,640 | —- | C] (RAVISENT Technologies Inc.) – C:\WINDOWS\System32\dllcache\cinemclc.sys
[2009/01/03 17:41:11 | 00,980,034 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\cicap.sys
[2009/01/03 17:41:05 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chgusr.exe
[2009/01/03 17:41:04 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chgport.exe
[2009/01/03 17:41:04 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chglogon.exe
[2009/01/03 17:41:03 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\change.exe
[2009/01/03 17:41:03 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\changer.sys
[2009/01/03 17:41:00 | 00,049,182 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem56n5.sys
[2009/01/03 17:40:59 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem33n5.sys
[2009/01/03 17:40:59 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem28n5.sys
[2009/01/03 17:40:58 | 00,027,164 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce3n5.sys
[2009/01/03 17:40:57 | 00,021,530 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce2n5.sys
[2009/01/03 17:40:54 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cd20xrnt.sys
[2009/01/03 17:40:53 | 00,714,698 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2009/01/03 17:40:52 | 00,046,108 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cben5.sys
[2009/01/03 17:40:51 | 00,039,680 | —- | C] (Silicom Ltd.) – C:\WINDOWS\System32\dllcache\cb325.sys
[2009/01/03 17:40:50 | 00,037,916 | —- | C] (Fast Ethernet Controller Provider) – C:\WINDOWS\System32\dllcache\cb102.sys
[2009/01/03 17:40:47 | 00,032,256 | —- | C] (Eicon Technology Corporation) – C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2009/01/03 17:40:43 | 00,164,923 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diapi2.sys
[2009/01/03 17:40:43 | 00,054,528 | —- | C] (Philips Semiconductors GmbH) – C:\WINDOWS\System32\dllcache\cap7146.sys
[2009/01/03 17:40:42 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.dll
[2009/01/03 17:40:41 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.ax
[2009/01/03 17:40:40 | 00,236,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.dll
[2009/01/03 17:40:39 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.ax
[2009/01/03 17:40:38 | 00,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.dll
[2009/01/03 17:40:37 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.ax
[2009/01/03 17:40:36 | 00,171,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv30.sys
[2009/01/03 17:40:35 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv21.sys
[2009/01/03 17:40:34 | 00,314,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdro21.sys
[2009/01/03 17:40:32 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_iscii.dll
[2009/01/03 17:40:30 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_870.nls
[2009/01/03 17:40:29 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_864.nls
[2009/01/03 17:40:29 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_862.nls
[2009/01/03 17:40:28 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_858.nls
[2009/01/03 17:40:26 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_720.nls
[2009/01/03 17:40:26 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_708.nls
[2009/01/03 17:40:24 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_28596.nls
[2009/01/03 17:40:23 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_21025.nls
[2009/01/03 17:40:21 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20924.nls
[2009/01/03 17:40:21 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20880.nls
[2009/01/03 17:40:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20871.nls
[2009/01/03 17:40:20 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20838.nls
[2009/01/03 17:40:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20833.nls
[2009/01/03 17:40:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20424.nls
[2009/01/03 17:40:19 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20423.nls
[2009/01/03 17:40:18 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20420.nls
[2009/01/03 17:40:18 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20297.nls
[2009/01/03 17:40:17 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20285.nls
[2009/01/03 17:40:17 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20284.nls
[2009/01/03 17:40:16 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20280.nls
[2009/01/03 17:40:16 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20278.nls
[2009/01/03 17:40:15 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20277.nls
[2009/01/03 17:40:15 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20273.nls
[2009/01/03 17:40:14 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20269.nls
[2009/01/03 17:40:14 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20108.nls
[2009/01/03 17:40:13 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20107.nls
[2009/01/03 17:40:13 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20106.nls
[2009/01/03 17:40:12 | 00,187,938 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20005.nls
[2009/01/03 17:40:12 | 00,180,258 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20004.nls
[2009/01/03 17:40:12 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20105.nls
[2009/01/03 17:40:11 | 00,185,378 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20003.nls
[2009/01/03 17:40:11 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20002.nls
[2009/01/03 17:40:10 | 00,186,402 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20001.nls
[2009/01/03 17:40:09 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1149.nls
[2009/01/03 17:40:09 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1148.nls
[2009/01/03 17:40:08 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1147.nls
[2009/01/03 17:40:08 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1146.nls
[2009/01/03 17:40:07 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1145.nls
[2009/01/03 17:40:07 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1144.nls
[2009/01/03 17:40:07 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1143.nls
[2009/01/03 17:40:06 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1142.nls
[2009/01/03 17:40:06 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1141.nls
[2009/01/03 17:40:05 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1140.nls
[2009/01/03 17:40:05 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1047.nls
[2009/01/03 17:40:04 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10021.nls
[2009/01/03 17:40:03 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10005.nls
[2009/01/03 17:40:03 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10004.nls
[2009/01/03 17:40:01 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2009/01/03 17:40:00 | 00,031,529 | —- | C] (BreezeCOM) – C:\WINDOWS\System32\dllcache\brzwlan.sys
[2009/01/03 17:39:59 | 00,010,368 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbscn.sys
[2009/01/03 17:39:58 | 00,011,008 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2009/01/03 17:39:57 | 00,060,416 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brserwdm.sys
[2009/01/03 17:39:56 | 00,009,728 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brserif.dll
[2009/01/03 17:39:55 | 00,005,120 | —- | C] (Brother Industries,Ltd.) – C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2009/01/03 17:39:54 | 00,039,552 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparwdm.sys
[2009/01/03 17:39:53 | 00,003,168 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparimg.sys
[2009/01/03 17:39:52 | 00,041,472 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfusb.dll
[2009/01/03 17:39:51 | 00,032,256 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2009/01/03 17:39:50 | 00,029,696 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmflpt.dll
[2009/01/03 17:39:49 | 00,081,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2009/01/03 17:39:48 | 00,015,360 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2009/01/03 17:39:48 | 00,003,968 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltup.sys
[2009/01/03 17:39:47 | 00,012,160 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2009/01/03 17:39:46 | 00,002,944 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brfilt.sys
[2009/01/03 17:39:45 | 00,012,800 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brevif.dll
[2009/01/03 17:39:44 | 00,009,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brcoinst.dll
[2009/01/03 17:39:43 | 00,019,456 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brbidiif.dll
[2009/01/03 17:39:41 | 00,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\binlsvc.dll
[2009/01/03 17:39:40 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2009/01/03 17:39:40 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdasup.sys
[2009/01/03 17:39:39 | 00,871,388 | —- | C] (BCM) – C:\WINDOWS\System32\dllcache\bcmdm.sys
[2009/01/03 17:39:34 | 00,036,128 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.sys
[2009/01/03 17:39:33 | 00,342,336 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.dll
[2009/01/03 17:39:32 | 00,089,952 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\b1cbase.sys
[2009/01/03 17:39:31 | 00,036,992 | —- | C] (Aztech Systems Ltd) – C:\WINDOWS\System32\dllcache\aztw2320.sys
[2009/01/03 17:39:30 | 00,037,568 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmwan.sys
[2009/01/03 17:39:29 | 00,144,384 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmenum.dll
[2009/01/03 17:39:29 | 00,087,552 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2009/01/03 17:39:28 | 00,013,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcstrm.sys
[2009/01/03 17:39:27 | 00,036,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcaudio.sys
[2009/01/03 17:39:26 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avc.sys
[2009/01/03 17:39:23 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\dllcache\ativxbar.sys
[2009/01/03 17:39:23 | 00,023,552 | —- | C] () – C:\WINDOWS\System32\dllcache\atixbar.sys
[2009/01/03 17:39:22 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\dllcache\ativttxx.sys
[2009/01/03 17:39:21 | 00,009,472 | —- | C] () – C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2009/01/03 17:39:20 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2009/01/03 17:39:19 | 00,026,880 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2009/01/03 17:39:19 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitunep.sys
[2009/01/03 17:39:18 | 00,049,920 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtcap.sys
[2009/01/03 17:39:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2009/01/03 17:39:13 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atievxx.exe
[2009/01/03 17:39:10 | 00,046,464 | —- | C] () – C:\WINDOWS\System32\dllcache\atibt829.sys
[2009/01/03 17:39:06 | 00,096,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ati.dll
[2009/01/03 17:39:06 | 00,077,568 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ati.sys
[2009/01/03 17:39:05 | 00,097,354 | —- | C] (Bay Networks, Inc.) – C:\WINDOWS\System32\dllcache\aspndis3.sys
[2009/01/03 17:39:03 | 00,022,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asc3350p.sys
[2009/01/03 17:39:02 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2009/01/03 17:39:00 | 00,006,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\apmbatt.sys
[2009/01/03 17:38:59 | 00,012,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\amsint.sys
[2009/01/03 17:38:58 | 00,016,969 | —- | C] (AmbiCom, Inc.) – C:\WINDOWS\System32\dllcache\amb8002.sys
[2009/01/03 17:38:55 | 00,056,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78xx.sys
[2009/01/03 17:38:55 | 00,055,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aic78u2.sys
[2009/01/03 17:38:54 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aha154x.sys
[2009/01/03 17:38:50 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2009/01/03 17:38:49 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2009/01/03 17:38:48 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adpu160m.sys
[2009/01/03 17:38:47 | 00,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2009/01/03 17:38:47 | 00,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2009/01/03 17:38:46 | 00,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2009/01/03 17:38:45 | 00,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2009/01/03 17:38:45 | 00,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2009/01/03 17:38:44 | 00,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2009/01/03 17:38:43 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2009/01/03 17:38:42 | 00,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2009/01/03 17:38:40 | 00,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2009/01/03 17:38:39 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\abp480n5.sys
[2009/01/03 17:38:38 | 00,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2009/01/03 17:38:38 | 00,098,304 | —- | C] (Aureal Semiconductor) – C:\WINDOWS\System32\dllcache\a3d.dll
[2009/01/03 17:38:37 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\61883.sys
[2009/01/03 17:38:37 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2009/01/03 17:38:36 | 00,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2009/01/03 17:38:36 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\4mmdat.sys
[2009/01/03 17:38:35 | 00,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2009/01/03 17:38:34 | 00,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2009/01/03 17:38:34 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2009/01/03 17:38:08 | 00,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2009/01/03 15:29:58 | 00,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/01/03 14:49:01 | 07,518,240 | —- | C] (Mozilla) – C:\Firefox Setup 3.0.5.exe
[2009/01/03 11:30:13 | 00,000,000 | —D | C] – C:\batt_en3.tos
[2008/12/30 15:23:19 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2008/12/29 22:56:02 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2008/12/29 22:51:17 | 29,775,112 | —- | C] () – C:\setupeng.exe
[2008/12/29 22:43:10 | 00,000,000 | —D | C] – C:\Program Files\RegistryFix7
[2008/12/29 22:42:41 | 01,109,376 | —- | C] (Registry Fix ) – C:\registryfix.exe
[2008/12/18 16:16:46 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\SlimBrowser
[2008/12/18 16:12:24 | 01,982,908 | —- | C] () – C:\sbsetup.exe
[2008/12/18 15:09:51 | 00,000,571 | —- | C] () – C:\Documents and Settings\user\Desktop\Shortcut to aim.lnk
[2008/12/18 15:08:42 | 00,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\filelib
[2008/12/18 15:07:41 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Aim
[2008/12/18 14:45:27 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\IObit
[2008/12/18 14:45:26 | 00,000,000 | —D | C] – C:\Program Files\IObit
[2008/12/12 12:17:32 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/06 10:52:02 | 02,756,640 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009/01/06 10:39:48 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/01/06 10:38:35 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/01/06 10:38:07 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/06 10:37:30 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/06 10:37:23 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/01/06 10:37:20 | 46,791,4752 | -HS- | M] () – C:\hiberfil.sys
[2009/01/06 10:36:36 | 00,027,620 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009/01/06 10:25:01 | 04,317,808 | -H– | M] () – C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2009/01/06 10:15:53 | 00,251,088 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/05 20:13:48 | 00,199,680 | —- | M] () – C:\Documents and Settings\user\Desktop\DirLook.exe
[2009/01/05 20:01:17 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTMoveIt3.exe
[2009/01/05 18:17:31 | 00,419,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTListIt2.exe
[2009/01/05 18:09:24 | 00,000,811 | —- | M] () – C:\WINDOWS\win.ini
[2009/01/05 18:09:24 | 00,000,285 | —- | M] () – C:\WINDOWS\system.ini
[2009/01/05 18:09:24 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/01/05 13:04:33 | 31,379,928 | —- | M] ( ) – C:\Documents and Settings\user\Desktop\setup_7.0.0.290_05.01.2009_17-40.exe
[2009/01/04 22:06:16 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/03 19:43:02 | 02,539,400 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup.exe
[2009/01/03 18:23:05 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\HJTInstall.exe
[2009/01/03 17:48:09 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\HJTsetup.exe
[2009/01/03 15:29:58 | 00,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/01/03 15:29:32 | 07,518,240 | —- | M] (Mozilla) – C:\Firefox Setup 3.0.5.exe
[2009/01/02 09:52:45 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\delayagu
[2009/01/02 09:52:37 | 00,069,730 | -HS- | M] () – C:\WINDOWS\System32\moyofilu.dll
[2008/12/30 23:16:49 | 00,001,744 | -H– | M] () – C:\nirolugo
[2008/12/30 12:18:36 | 00,000,920 | —- | M] () – C:\Documents and Settings\user\Application Data\wklnhst.dat
[2008/12/29 22:54:55 | 29,775,112 | —- | M] () – C:\setupeng.exe
[2008/12/29 22:42:42 | 01,109,376 | —- | M] (Registry Fix ) – C:\registryfix.exe
[2008/12/18 16:18:43 | 01,982,908 | —- | M] () – C:\sbsetup.exe
[2008/12/18 15:09:51 | 00,000,571 | —- | M] () – C:\Documents and Settings\user\Desktop\Shortcut to aim.lnk
[2008/12/13 10:39:34 | 00,000,085 | —- | M] () – C:\WINDOWS\EmperorEdit.INI
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/12 12:29:58 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2008/12/12 12:17:32 | 00,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2008/12/11 18:09:22 | 00,089,600 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/09 15:24:38 | 17,593,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2008/12/08 21:40:37 | 00,077,368 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

========== LOP Check ==========

[2009/01/03 21:37:42 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2006/12/04 17:38:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/01/03 21:27:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/07/10 06:24:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/04/17 23:06:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/10/15 12:25:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blg
[2008/12/30 15:23:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2008/04/19 16:22:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii
[2008/12/18 13:56:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/05/09 17:05:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/09/16 18:43:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2005/11/04 23:05:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/01/03 19:43:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/12/18 14:36:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/10/14 10:02:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/01/02 17:25:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/03/16 10:42:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/05/13 12:11:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Games
[2008/10/15 13:30:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2006/12/18 10:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayTime
[2006/12/04 16:37:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2005/11/04 23:09:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2006/03/02 22:19:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/04/30 16:02:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2008/04/19 23:18:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2006/12/15 20:12:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/12/18 16:50:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/05/18 09:21:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2005/11/04 23:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/11/20 15:54:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2006/05/26 08:02:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/01/11 10:10:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2008/12/12 11:56:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2006/12/04 14:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[2009/01/03 21:35:23 | 00,000,000 | -H-D | M] – C:\Documents and Settings\user\Application Data
[2008/02/10 13:55:25 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Adobe
[2006/07/06 08:48:55 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\AdobeUM
[2006/11/21 12:22:46 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Ahead
[2008/12/18 15:07:55 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Aim
[2005/11/04 23:18:53 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\AOL
[2007/04/21 01:02:42 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Apple Computer
[2006/03/06 00:36:44 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ArcSoft
[2005/11/29 17:25:22 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ATI
[2008/10/15 12:25:49 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\blg
[2008/09/12 23:23:37 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Canon
[2007/10/27 09:57:03 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\dvdcss
[2007/10/23 17:32:20 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\FFSJ
[2006/09/22 14:32:08 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\FlashFXP
[2008/10/14 10:09:38 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Gamelab
[2007/01/15 17:34:54 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\GetRightToGo
[2006/10/20 10:52:02 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Google
[2006/08/06 10:23:58 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Help
[2007/05/09 17:06:14 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\HP
[2005/11/04 21:30:09 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Identities
[2006/03/02 00:14:19 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\InterVideo
[2005/11/04 23:05:12 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Intuit
[2008/12/18 14:45:27 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\IObit
[2008/09/19 17:35:18 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Lavasoft
[2006/12/13 15:41:49 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Macromedia
[2009/01/03 19:43:53 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Malwarebytes
[2006/07/21 17:30:21 | 00,000,000 | –SD | M] – C:\Documents and Settings\user\Application Data\Microsoft
[2008/12/18 17:59:36 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Mozilla
[2006/12/14 15:22:56 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\MysteryStudio
[2006/11/20 16:00:40 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Nova Development
[2008/05/13 12:11:13 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Oberon Games
[2006/07/21 15:08:25 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\PC Tools
[2008/10/15 13:30:36 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\PlayFirst
[2008/06/20 17:46:42 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Real
[2008/03/08 00:09:32 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Roxio
[2008/04/30 16:01:27 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sandlot Games
[2008/04/19 23:18:41 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ScanSoft
[2008/03/24 21:43:35 | 00,000,000 | RH-D | M] – C:\Documents and Settings\user\Application Data\SecuROM
[2008/12/18 16:39:22 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\SlimBrowser
[2006/09/22 14:20:09 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\SmartFTP
[2006/03/01 23:16:52 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sonic
[2007/03/20 23:28:41 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\StumbleUpon
[2006/03/09 11:38:19 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sun
[2006/03/02 01:02:38 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Template
[2008/02/23 13:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\toshiba
[2006/12/29 01:17:22 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\vlc
[2007/01/17 11:39:53 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Wildfire
[2008/12/18 18:52:55 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Yahoo!
[2005/11/04 23:10:34 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\You've Got Pictures Screensaver
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/01/06 10:37:30 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 218 bytes -> %AllUsersProfile%\Application Data\TEMP:6677D85A
@Alternate Data Stream - 209 bytes -> %AllUsersProfile%\Application Data\TEMP:483AC68A
@Alternate Data Stream - 206 bytes -> %AllUsersProfile%\Application Data\TEMP:CEE4A457
@Alternate Data Stream - 204 bytes -> %AllUsersProfile%\Application Data\TEMP:3A6BC948
@Alternate Data Stream - 152 bytes -> %AllUsersProfile%\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 120 bytes -> %AllUsersProfile%\Application Data\TEMP:89C2A42C
@Alternate Data Stream - 120 bytes -> %AllUsersProfile%\Application Data\TEMP:225C4FFC
@Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:E36F5B57
@Alternate Data Stream - 112 bytes -> %AllUsersProfile%\Application Data\TEMP:F67AAFC5
@Alternate Data Stream - 104 bytes -> %AllUsersProfile%\Application Data\TEMP:23FA878E
@Alternate Data Stream - 102 bytes -> %AllUsersProfile%\Application Data\TEMP:BDF08FAF
@Alternate Data Stream - 0 bytes -> %AllUsersProfile%\Application Data\TEMP:22741C1F
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI