This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Win32.Zafi.B virus removal!

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, and thanks for all of your help in advance! I seem to have unwittingly downloaded (somehow) a particularly nasty virus that goes under the name of "Win32.Zafi.B". The symptoms are:
- when I open Internet explorer or Windows Live Messenger (indeed any internet based programs including Live Mail etc.) they close within the next few seconds. When I open Internet explorer for the first time, a message pops up informing me that a firewall has blocked the virus name (as stated above) and offers protection under the name of "Perfect Defender 2009". However this time I was a bit more cautious and managed to look up this Perfect Defender on Internet Explorer in the few seconds I had till it closed. Instantly I was told not to download this! So I haven't…
- When I have tried to launch a System Restore, the PC instantly restarts, so I get a message telling me it cannot restore because the Windows System is shutting down.

I am getting increasingly frustrated - I am having to write this on another uninfected computer because there is no way to do this on my infected PC! So we have to keep in mind that I may have to download programs and transfer them to my other PC…

Fortunately (if of any help) I managed to run the HijackThis program (which I already had installed) and then saved the log of this onto a USB memory stick. Here it is:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:13:20, on 09/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\drivers\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\D-link AirPlus G DWL-G120 Wireless USB\120UTIL.exe
C:\Program Files\AzureBay\AzureBay Screen Saver\WPChanger.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.1.240
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: D-link AirPlus G DWL-G120 Wireless USB.lnk = ?
O4 - Global Startup: Register.lnk = C:\Program Files\AzureBay\AzureBay Screen Saver\Register.exe
O4 - Global Startup: Wallpaper Changer.lnk = C:\Program Files\AzureBay\AzureBay Screen Saver\WPChanger.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://thayney.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Desktop Manager 5.7.805.16405 (GoogleDesktopManager-051608-133132) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

–
End of file - 10724 bytes


Thankyou for taking your time to read this and to help me.
Regards and Best Wishes for the new year,
T-man7
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
Just to confirm, I download SDFix onto this computer (with working internet) and save it to a USB before transferring it to my infected computer? Thanks for you speedy reply. t-man7
Here is the 'report' as requested:


SDFix: Version 1.240
Run by [removed] on 10/01/2009 at 16:47

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\Temp\1cb\syscheck.log - Deleted
C:\WINDOWS\system32\drivers\svchost.exe - Deleted



Folder C:\Temp\1cb - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-10 16:56:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"="C:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe:*:Disabled:Jedi Academy MultiPlayer"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"="C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"="C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
"C:\\Program Files\\LucasArts\\Star Wars Galactic Battlegrounds Saga\\Game\\Battlegrounds.exe"="C:\\Program Files\\LucasArts\\Star Wars Galactic Battlegrounds Saga\\Game\\Battlegrounds.exe:*:Enabled:Star Wars Galactic Battlegrounds"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"="C:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault"
"C:\\UT2004\\System\\UT2004.exe"="C:\\UT2004\\System\\UT2004.exe:*:Enabled:UT2004"
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"="C:\\Program Files\\GameSpy Arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"="C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe:*:Disabled:BearShare"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\system32\\drivers\\svchost.exe"="%windir%\\system32\\drivers\\svchost.exe:*:Enabled:svchost"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"%windir%\\system32\\drivers\\svchost.exe"="%windir%\\system32\\drivers\\svchost.exe:*:Enabled:svchost"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Fri 9 Jan 2009 88 ..SHR — "C:\WINDOWS\system32\36F26ECF49.sys"
Wed 31 Dec 2008 56 ..SHR — "C:\WINDOWS\system32\49CF6EF236.sys"
Fri 9 Jan 2009 6,580 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Tue 12 Dec 2006 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 12 Dec 2006 401 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv18.bak"
Tue 12 Dec 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 25 Aug 2006 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Fri 25 Aug 2006 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Fri 25 Aug 2006 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Fri 25 Aug 2006 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"
Fri 25 Aug 2006 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"

Finished!
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
This is the OTListIT report:

OTListIt logfile created on: 10/01/2009 17:22:34 - Run
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\Thayney\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 75.03% Memory free
3.32 Gb Paging File | 2.98 Gb Available in Paging File | 89.88% Paging File free
Paging file location(s): C:\pagefile.sys 1512 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.30 Gb Total Space | 39.89 Gb Free Space | 55.95% Space Free | Partition Type: NTFS
Drive D: | 495.22 Mb Total Space | 323.37 Mb Free Space | 65.30% Space Free | Partition Type: FAT
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: THAYNEYDESKTOP
Current User Name: Thayney
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\Grisoft\AVG Free\avgamsvr.exe (GRISOFT, s.r.o.)
C:\Program Files\Grisoft\AVG Free\avgupsvc.exe (GRISOFT, s.r.o.)
C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
C:\WINDOWS\system32\searchindexer.exe (Microsoft Corporation)
C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
C:\Program Files\Grisoft\AVG Free\avgcc.exe (GRISOFT, s.r.o.)
C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
C:\Program Files\D-link AirPlus G DWL-G120 Wireless USB\120UTIL.exe (D-Link)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\AzureBay\AzureBay Screen Saver\WPChanger.exe (AzureBay)
C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
C:\WINDOWS\system32\searchprotocolhost.exe (Microsoft Corporation)
C:\WINDOWS\system32\searchfilterhost.exe (Microsoft Corporation)
C:\Documents and Settings\Thayney\Desktop\OTListIt2.exe (OldTimer Tools)

========== (O23) Win32 Services (SafeList) ==========

(Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
(Avg7Alrt [Auto | Running]) – C:\Program Files\Grisoft\AVG Free\avgamsvr.exe (GRISOFT, s.r.o.)
(Avg7UpdSvc [Auto | Running]) – C:\Program Files\Grisoft\AVG Free\avgupsvc.exe (GRISOFT, s.r.o.)
(bgsvcgen [Auto | Running]) – C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
(Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
(GoogleDesktopManager-051608-133132 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
(gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
(IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
(idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
(iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
(MSCamSvc [Auto | Running]) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
(NetSvc [On_Demand | Stopped]) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
(NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
(ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
(Roxio UPnP Renderer 9 [On_Demand | Stopped]) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe (Sonic Solutions)
(Roxio Upnp Server 9 [Auto | Stopped]) – C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe (Sonic Solutions)
(RoxLiveShare9 [Auto | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (Sonic Solutions)
(RoxMediaDB9 [On_Demand | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
(RoxWatch9 [Auto | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
(usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
(WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
(WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
(WSearch [Auto | Running]) – C:\WINDOWS\system32\searchindexer.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
(amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\amdagp.sys (Advanced Micro Devices, Inc.)
(asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
(asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
(ASCTRM [Auto | Running]) – C:\WINDOWS\system32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
(Avg7Core [System | Running]) – C:\WINDOWS\system32\drivers\avg7core.sys (GRISOFT, s.r.o.)
(Avg7RsW [System | Running]) – C:\WINDOWS\system32\drivers\avg7rsw.sys (GRISOFT, s.r.o.)
(Avg7RsXP [System | Running]) – C:\WINDOWS\system32\drivers\avg7rsxp.sys (GRISOFT, s.r.o.)
(AvgClean [System | Running]) – C:\WINDOWS\system32\drivers\avgclean.sys (GRISOFT, s.r.o.)
(catchme [On_Demand | Running]) – File not found
(cdrbsdrv [System | Running]) – C:\WINDOWS\system32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
(CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
(dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
(DSproct [On_Demand | Stopped]) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
(E100B [On_Demand | Running]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
(GEARAspiWDM [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
(HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
(ialm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
(kbdhid [System | Running]) – C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
(mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
(nmwcd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
(nmwcdc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
(nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
(PRISM_A02 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PRISMA02.sys (GlobespanVirata, Inc.)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
(ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
(ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
(ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
(RimUsb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\RimUsb.sys (Research In Motion Limited)
(RimVSerPort [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
(RkHit [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\RKHit.sys ()
(ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rootmdm.sys (Microsoft Corporation)
(Secdrv [Auto | Running]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sfdrv01 [Boot | Running]) – C:\WINDOWS\system32\drivers\sfdrv01.sys (Protection Technology)
(sfhlp02 [Boot | Running]) – C:\WINDOWS\system32\drivers\sfhlp02.sys (Protection Technology)
(sfsync03 [Boot | Running]) – C:\WINDOWS\system32\drivers\sfsync03.sys (Protection Technology)
(sfvfs02 [Boot | Running]) – C:\WINDOWS\system32\drivers\sfvfs02.sys (Protection Technology)
(sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sisagp.sys (Silicon Integrated Systems Corporation)
(Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
(ssm_bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ssm_bus.sys (MCCI)
(ssm_mdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ssm_mdfl.sys (MCCI)
(ssm_mdm [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ssm_mdm.sys (MCCI)
(StarOpen [System | Running]) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
(STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
(symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
(symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
(sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
(sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
(ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
(usbaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
(usbser [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbser.sys (Microsoft Corporation)
(UsbserFilt [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
(usbvideo [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbvideo.sys (Microsoft Corporation)
(VX3000 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\VX3000.sys (Microsoft Corporation)
(Wdf01000 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wdf01000.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o.)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER (RealNetworks, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" (Sonic Solutions)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VX3000] C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler (Macrovision Corporation)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-link AirPlus G DWL-G120 Wireless USB.lnk = C:\Program Files\D-link AirPlus G DWL-G120 Wireless USB\120UTIL.exe (D-Link)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Register.lnk = C:\Program Files\AzureBay\AzureBay Screen Saver\Register.exe (AzureBay)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wallpaper Changer.lnk = C:\Program Files\AzureBay\AzureBay Screen Saver\WPChanger.exe (AzureBay)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll [2001/08/01 17:05:42 | 00,270,336 | —- | M] (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://thayney.spaces.live.com/PhotoUpload/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab (CBreakshotControl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap11 - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wlmailhtml - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

========== AppInit_DLLs ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls" = C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
>C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)

========== HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)

"UserInit" = C:\WINDOWS\system32\userinit.exe,
>C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

"UIHost" = logonui.exe
>C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)

"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)


========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
crypt32chain: "DllName" = crypt32.dll – C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll – C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll – C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
dimsntfy: "DllName" = %SystemRoot%\System32\dimsntfy.dll – C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
igfxcui: "DllName" = igfxdev.dll – C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
ScCertProp: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll – C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
WgaLogon: "DllName" = WgaLogon.dll – C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)

========== IFEO "Debugger" Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}" (HKLM) – C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) – C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c360728-c21f-11dd-89a6-000f3d4bb35b}\Shell]
"" = AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c360728-c21f-11dd-89a6-000f3d4bb35b}\Shell\AutoRun]
"" = Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c360728-c21f-11dd-89a6-000f3d4bb35b}\Shell\AutoRun\command]
"" = D:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/10 17:21:47 | 00,419,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Thayney\Desktop\OTListIt2.exe
[2009/01/10 16:53:20 | 21,371,49440 | -HS- | C] () – C:\hiberfil.sys
[2009/01/10 16:43:22 | 00,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2009/01/10 16:39:49 | 01,529,241 | —- | C] () – C:\Documents and Settings\Thayney\Desktop\SDFix.exe
[2009/01/10 16:35:40 | 00,000,000 | —D | C] – C:\SDFix
[2009/01/04 13:25:37 | 00,030,208 | —- | C] () – C:\Documents and Settings\Thayney\My Documents\What have exams turned into lecture.doc
[2009/01/04 13:25:18 | 00,025,088 | —- | C] () – C:\Documents and Settings\Thayney\My Documents\All exams seem to do to children of the new generation 1.doc
[2009/01/03 21:45:47 | 00,028,672 | —- | C] () – C:\Documents and Settings\Thayney\My Documents\IS TOO MUCH PRESSURE PUT ON CHILDREN TODAY WITH EXAM1.doc
[2009/01/02 22:01:10 | 00,019,968 | —- | C] () – C:\Documents and Settings\Thayney\My Documents\IS TOO MUCH PRESSURE PUT ON CHILDREN TODAY WITH EXAMS.doc
[2009/01/01 21:59:33 | 00,018,944 | —- | C] () – C:\Documents and Settings\Thayney\My Documents\Bike fitness schedule.xls
[2008/12/31 13:38:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Thayney\My Documents\My PSP Files
[2008/12/30 17:37:05 | 00,000,000 | —D | C] – C:\New Folder
[2008/12/29 20:17:07 | 06,516,300 | —- | C] () – C:\Program Files\Lily_Allen_-_The_Fear.mp3
[2008/12/27 21:42:35 | 00,000,000 | R–D | C] – C:\Documents and Settings\Thayney\My Documents\LifeCam Files
[2008/12/18 21:44:22 | 07,393,524 | —- | C] () – C:\Program Files\Usher_-_Moving_Mountains.mp3
[2008/12/18 21:35:20 | 06,012,011 | —- | C] () – C:\Program Files\Usher_-_Yeah!.mp3
[2008/12/18 21:14:54 | 05,333,467 | —- | C] () – C:\Program Files\02-Us_Against_The_World.mp3
[2008/12/16 22:33:05 | 00,078,848 | —- | C] () – C:\Documents and Settings\Thayney\My Documents\moore art.doc
[2008/12/16 21:25:10 | 00,116,224 | —- | C] (Xerox) – C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2008/12/16 21:25:06 | 00,023,040 | —- | C] (Xerox Corporation) – C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2008/12/16 21:25:05 | 00,018,944 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2008/12/16 21:25:02 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2008/12/16 21:24:58 | 00,004,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2008/12/16 21:24:54 | 00,099,865 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\xlog.exe
[2008/12/16 21:24:54 | 00,028,288 | —- | C] () – C:\WINDOWS\System32\dllcache\xjis.nls
[2008/12/16 21:24:50 | 00,016,970 | —- | C] (US Robotics MCD (Megahertz)) – C:\WINDOWS\System32\dllcache\xem336n5.sys
[2008/12/16 21:24:44 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshirda.dll
[2008/12/16 21:24:34 | 00,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiacpi.sys
[2008/12/16 21:24:32 | 00,154,624 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\wlluc48.sys
[2008/12/16 21:24:28 | 00,034,890 | —- | C] (Raytheon Corp.) – C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2008/12/16 21:24:22 | 00,771,581 | —- | C] (Rockwell) – C:\WINDOWS\System32\dllcache\winacisa.sys
[2008/12/16 21:24:18 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2008/12/16 21:24:15 | 00,087,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2008/12/16 21:24:14 | 00,041,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\weitekp9.dll
[2008/12/16 21:24:14 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\weitekp9.sys
[2008/12/16 21:24:08 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2008/12/16 21:24:05 | 00,035,871 | —- | C] (Winbond Electronics Corp.) – C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2008/12/16 21:23:53 | 00,016,925 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w940nd.sys
[2008/12/16 21:23:50 | 00,019,016 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w926nd.sys
[2008/12/16 21:23:47 | 00,019,528 | —- | C] (Winbond Electronics Corporation) – C:\WINDOWS\System32\dllcache\w840nd.sys
[2008/12/16 21:23:46 | 00,048,256 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\w32.dll
[2008/12/16 21:23:43 | 00,064,605 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vvoice.sys
[2008/12/16 21:23:39 | 00,397,502 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\vpctcom.sys
[2008/12/16 21:23:35 | 00,604,253 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\vmodem.sys
[2008/12/16 21:23:31 | 00,249,402 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\vinwm.sys
[2008/12/16 21:23:22 | 00,687,999 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2008/12/16 21:23:18 | 00,765,884 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usrti.sys
[2008/12/16 21:23:14 | 00,113,762 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usrpda.sys
[2008/12/16 21:23:11 | 00,007,556 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usroslba.sys
[2008/12/16 21:23:06 | 00,224,802 | —- | C] (U.S. Robotics Corporation) – C:\WINDOWS\System32\dllcache\usr1807a.sys
[2008/12/16 21:23:02 | 00,794,399 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806v.sys
[2008/12/16 21:22:59 | 00,793,598 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1806.sys
[2008/12/16 21:22:55 | 00,794,654 | —- | C] (U.S. Robotics, Inc.) – C:\WINDOWS\System32\dllcache\usr1801.sys
[2008/12/16 21:22:53 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2008/12/16 21:22:52 | 00,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbohci.sys
[2008/12/16 21:22:50 | 00,032,384 | —- | C] (KLSI USA, Inc.) – C:\WINDOWS\System32\dllcache\usb101et.sys
[2008/12/16 21:22:45 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxud32.dll
[2008/12/16 21:22:41 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu40.dll
[2008/12/16 21:22:37 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu22.dll
[2008/12/16 21:22:33 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxu12.dll
[2008/12/16 21:22:29 | 00,050,688 | —- | C] (UMAX DATA SYSTEMS INC.) – C:\WINDOWS\System32\dllcache\umaxscan.dll
[2008/12/16 21:22:25 | 00,022,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2008/12/16 21:22:22 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxp60.dll
[2008/12/16 21:22:18 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\umaxcam.dll
[2008/12/16 21:22:15 | 00,211,968 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um54scan.dll
[2008/12/16 21:22:11 | 00,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2008/12/16 21:22:07 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tsprof.exe
[2008/12/16 21:22:01 | 00,166,784 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxpm.sys
[2008/12/16 21:21:58 | 00,525,568 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridxp.dll
[2008/12/16 21:21:54 | 00,159,232 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkbm.sys
[2008/12/16 21:21:51 | 00,440,576 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tridkb.dll
[2008/12/16 21:21:47 | 00,222,336 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3dm.sys
[2008/12/16 21:21:44 | 00,315,520 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\trid3d.dll
[2008/12/16 21:21:18 | 00,123,995 | —- | C] (Tiger Jet Network) – C:\WINDOWS\System32\dllcache\tjisdn.sys
[2008/12/16 21:21:17 | 00,185,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\thawbrkr.dll
[2008/12/16 21:21:13 | 00,138,528 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2008/12/16 21:21:10 | 00,081,408 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\tgiul50.dll
[2008/12/16 21:21:09 | 00,149,376 | —- | C] (M-Systems) – C:\WINDOWS\System32\dllcache\tffsport.sys
[2008/12/16 21:21:08 | 00,019,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdspx.sys
[2008/12/16 21:21:05 | 00,017,129 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2008/12/16 21:21:02 | 00,037,961 | —- | C] (TDK Corporation) – C:\WINDOWS\System32\dllcache\tdk100b.sys
[2008/12/16 21:21:01 | 00,021,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdipx.sys
[2008/12/16 21:21:01 | 00,013,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdasync.sys
[2008/12/16 21:20:53 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tandqic.sys
[2008/12/16 21:20:49 | 00,036,640 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2008/12/16 21:20:46 | 00,172,768 | —- | C] (Number Nine Visual Technology) – C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2008/12/16 21:20:40 | 00,094,293 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sxports.dll
[2008/12/16 21:20:37 | 00,103,936 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\sx.sys
[2008/12/16 21:20:34 | 00,003,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swusbflt.sys
[2008/12/16 21:20:30 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpidflt.dll
[2008/12/16 21:20:27 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2008/12/16 21:20:24 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2008/12/16 21:20:20 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sw_effct.dll
[2008/12/16 21:20:16 | 00,155,648 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnprop.dll
[2008/12/16 21:20:12 | 00,053,248 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlncoin.dll
[2008/12/16 21:20:09 | 00,285,760 | —- | C] (Stallion Technologies) – C:\WINDOWS\System32\dllcache\stlnata.sys
[2008/12/16 21:20:05 | 00,016,896 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\stcusb.sys
[2008/12/16 21:20:01 | 00,048,736 | —- | C] (3Com) – C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2008/12/16 21:19:57 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusbusd.dll
[2008/12/16 21:19:57 | 00,099,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srusd.dll
[2008/12/16 21:19:52 | 00,024,660 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spxupchk.dll
[2008/12/16 21:19:48 | 00,061,824 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\speed.sys
[2008/12/16 21:19:45 | 00,106,584 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\dllcache\spdports.dll
[2008/12/16 21:19:29 | 00,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonymc.sys
[2008/12/16 21:19:28 | 00,143,422 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\softkey.dll
[2008/12/16 21:19:28 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sonyait.sys
[2008/12/16 21:19:25 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2008/12/16 21:19:24 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\snmpstup.dll
[2008/12/16 21:19:24 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll
[2008/12/16 21:19:22 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll
[2008/12/16 21:19:21 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smimsgif.dll
[2008/12/16 21:19:18 | 00,058,368 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smiminib.sys
[2008/12/16 21:19:18 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smierrsm.dll
[2008/12/16 21:19:18 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smierrsy.dll
[2008/12/16 21:19:15 | 00,147,200 | —- | C] (Silicon Motion Inc.) – C:\WINDOWS\System32\dllcache\smidispb.dll
[2008/12/16 21:19:12 | 00,025,034 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2008/12/16 21:19:09 | 00,035,913 | —- | C] (SMC) – C:\WINDOWS\System32\dllcache\smcirda.sys
[2008/12/16 21:19:05 | 00,024,576 | —- | C] (SMC Networks, Inc.) – C:\WINDOWS\System32\dllcache\smc8000n.sys
[2008/12/16 21:19:02 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbhc.sys
[2008/12/16 21:19:01 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbclass.sys
[2008/12/16 21:19:00 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb6w.dll
[2008/12/16 21:19:00 | 00,016,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smbbatt.sys
[2008/12/16 21:18:57 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb3w.dll
[2008/12/16 21:18:54 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smb0w.dll
[2008/12/16 21:18:54 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma3w.dll
[2008/12/16 21:18:51 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sma0w.dll
[2008/12/16 21:18:50 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm9aw.dll
[2008/12/16 21:18:50 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm93w.dll
[2008/12/16 21:18:50 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm92w.dll
[2008/12/16 21:18:47 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm91w.dll
[2008/12/16 21:18:47 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm90w.dll
[2008/12/16 21:18:47 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8dw.dll
[2008/12/16 21:18:46 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm87w.dll
[2008/12/16 21:18:46 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm81w.dll
[2008/12/16 21:18:46 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8cw.dll
[2008/12/16 21:18:46 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm8aw.dll
[2008/12/16 21:18:46 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm89w.dll
[2008/12/16 21:18:46 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sm59w.dll
[2008/12/16 21:18:44 | 00,063,547 | —- | C] (Symbol Technologies) – C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2008/12/16 21:18:41 | 00,091,294 | —- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) – C:\WINDOWS\System32\dllcache\skfpwin.sys
[2008/12/16 21:18:38 | 00,094,698 | —- | C] (SysKonnect GmbH.) – C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2008/12/16 21:18:30 | 00,032,768 | —- | C] (SiS Corporation) – C:\WINDOWS\System32\dllcache\sisnic.sys
[2008/12/16 21:18:10 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\simptcp.dll
[2008/12/16 21:18:04 | 00,161,568 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2008/12/16 21:18:01 | 00,018,400 | —- | C] (Micro Systemation) – C:\WINDOWS\System32\dllcache\sgsmld.sys
[2008/12/16 21:17:57 | 00,098,080 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2008/12/16 21:17:54 | 00,386,560 | —- | C] (Trident Microsystems Inc.) – C:\WINDOWS\System32\dllcache\sgiul50.dll
[2008/12/16 21:17:46 | 00,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2008/12/16 21:17:42 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2008/12/16 21:17:41 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_seos.dll
[2008/12/16 21:17:38 | 00,006,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2008/12/16 21:17:37 | 00,011,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiscan.sys
[2008/12/16 21:17:34 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_scripto.dll
[2008/12/16 21:17:34 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2008/12/16 21:17:30 | 00,017,280 | —- | C] (SCM Microsystems) – C:\WINDOWS\System32\dllcache\scr111.sys
[2008/12/16 21:17:27 | 00,016,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scmstcs.sys
[2008/12/16 21:17:24 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2008/12/16 21:17:21 | 00,023,936 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2008/12/16 21:17:20 | 00,043,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sbp2port.sys
[2008/12/16 21:17:07 | 00,077,824 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2008/12/16 21:17:04 | 00,198,400 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav4.dll
[2008/12/16 21:17:01 | 00,061,504 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2008/12/16 21:16:58 | 00,179,264 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2008/12/16 21:16:55 | 00,210,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2008/12/16 21:16:52 | 00,062,496 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2008/12/16 21:16:49 | 00,041,216 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2008/12/16 21:16:46 | 00,182,272 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2008/12/16 21:16:43 | 00,166,720 | —- | C] (S3 Incorporated) – C:\WINDOWS\System32\dllcache\s3m.sys
[2008/12/16 21:16:40 | 00,065,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.sys
[2008/12/16 21:16:37 | 00,082,432 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia450.dll
[2008/12/16 21:16:34 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia430.dll
[2008/12/16 21:16:33 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia330.dll
[2008/12/16 21:16:33 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia001.dll
[2008/12/16 21:16:32 | 00,029,696 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw450ext.dll
[2008/12/16 21:16:31 | 00,027,648 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw430ext.dll
[2008/12/16 21:16:29 | 00,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8139.sys
[2008/12/16 21:16:27 | 00,019,017 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\dllcache\rtl8029.sys
[2008/12/16 21:16:20 | 00,009,216 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2008/12/16 21:16:15 | 00,079,104 | —- | C] (Comtrol Corporation) – C:\WINDOWS\System32\dllcache\rocket.sys
[2008/12/16 21:16:12 | 00,037,563 | —- | C] (RadioLAN) – C:\WINDOWS\System32\dllcache\rlnet5.sys
[2008/12/16 21:16:08 | 00,086,097 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\reslog32.dll
[2008/12/16 21:16:08 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe
[2008/12/16 21:16:07 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\register.exe
[2008/12/16 21:16:02 | 00,019,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasirda.sys
[2008/12/16 21:15:58 | 00,714,762 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2008/12/16 21:15:55 | 00,899,146 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2008/12/16 21:15:52 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qvusd.dll
[2008/12/16 21:15:49 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\quser.exe
[2008/12/16 21:15:49 | 00,003,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qv2kux.sys
[2008/12/16 21:15:48 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\query.exe
[2008/12/16 21:15:45 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qic157.sys
[2008/12/16 21:15:41 | 00,130,942 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlv.sys
[2008/12/16 21:15:38 | 00,112,574 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserlp.sys
[2008/12/16 21:15:36 | 00,128,286 | —- | C] (PCTEL, INC.) – C:\WINDOWS\System32\dllcache\ptserli.sys
[2008/12/16 21:15:35 | 00,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusd.dll
[2008/12/16 21:15:32 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ptpusb.dll
[2008/12/16 21:15:30 | 00,033,280 | —- | C] () – C:\WINDOWS\System32\dllcache\psisrndr.ax
[2008/12/16 21:15:27 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\psisload.dll
[2008/12/16 21:15:26 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\dllcache\psisdecd.dll
[2008/12/16 21:15:23 | 00,016,128 | —- | C] (SCM Microsystems, Inc.) – C:\WINDOWS\System32\dllcache\pscr.sys
[2008/12/16 21:15:21 | 00,083,748 | —- | C] () – C:\WINDOWS\System32\dllcache\prcp.nls
[2008/12/16 21:15:21 | 00,083,748 | —- | C] () – C:\WINDOWS\System32\dllcache\prc.nls
[2008/12/16 21:15:20 | 00,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa3.sys
[2008/12/16 21:15:16 | 00,017,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ppa.sys
[2008/12/16 21:15:15 | 00,008,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\powerfil.sys
[2008/12/16 21:15:12 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pnrmc.sys
[2008/12/16 21:15:11 | 00,131,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxviceo.dll
[2008/12/16 21:15:11 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxmcro.dll
[2008/12/16 21:15:11 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pmxgl.dll
[2008/12/16 21:15:06 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phvfwext.dll
[2008/12/16 21:15:02 | 00,019,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philtune.sys
[2008/12/16 21:14:59 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phildec.sys
[2008/12/16 21:14:56 | 00,173,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam2.sys
[2008/12/16 21:14:53 | 00,075,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.sys
[2008/12/16 21:14:50 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\philcam1.dll
[2008/12/16 21:14:46 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\phdsext.ax
[2008/12/16 21:14:45 | 00,259,328 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3dd.dll
[2008/12/16 21:14:45 | 00,028,032 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm3.sys
[2008/12/16 21:14:44 | 00,211,584 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2dll.dll
[2008/12/16 21:14:43 | 00,027,904 | —- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) – C:\WINDOWS\System32\dllcache\perm2.sys
[2008/12/16 21:14:41 | 00,169,984 | —- | C] (Cisco Systems) – C:\WINDOWS\System32\dllcache\pcx500.sys
[2008/12/16 21:14:38 | 00,086,016 | —- | C] (PCtel, Inc.) – C:\WINDOWS\System32\dllcache\pctspk.exe
[2008/12/16 21:14:35 | 00,035,328 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntpci5.sys
[2008/12/16 21:14:32 | 00,029,769 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5m.sys
[2008/12/16 21:14:29 | 00,030,282 | —- | C] (AMD Inc.) – C:\WINDOWS\System32\dllcache\pcntn5hl.sys
[2008/12/16 21:14:26 | 00,026,153 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2008/12/16 21:14:25 | 00,029,502 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\pca200e.sys
[2008/12/16 21:14:22 | 00,030,495 | —- | C] (Linksys) – C:\WINDOWS\System32\dllcache\pc100nds.sys
[2008/12/16 21:14:21 | 00,036,927 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\padrs411.dll
[2008/12/16 21:14:21 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\padrs412.dll
[2008/12/16 21:14:17 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2rc.dll
[2008/12/16 21:14:14 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovui2.dll
[2008/12/16 21:14:11 | 00,025,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovsound2.sys
[2008/12/16 21:14:08 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcoms.exe
[2008/12/16 21:14:05 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcomc.dll
[2008/12/16 21:14:03 | 00,351,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodek2.sys
[2008/12/16 21:14:00 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcodec2.dll
[2008/12/16 21:13:57 | 00,031,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovce.sys
[2008/12/16 21:13:54 | 00,028,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcd.sys
[2008/12/16 21:13:51 | 00,048,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovcam2.sys
[2008/12/16 21:13:47 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ovca.sys
[2008/12/16 21:13:44 | 00,054,186 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otcsercb.sys
[2008/12/16 21:13:40 | 00,043,689 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otceth5.sys
[2008/12/16 21:13:38 | 00,027,209 | —- | C] (Ositech Communications, Inc.) – C:\WINDOWS\System32\dllcache\otc06x5.sys
[2008/12/16 21:13:33 | 00,054,528 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\opl3sax.sys
[2008/12/16 21:13:31 | 00,061,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ohci1394.sys
[2008/12/16 21:13:17 | 00,051,552 | —- | C] (Kensington Technology Group) – C:\WINDOWS\System32\dllcache\ntgrip.sys
[2008/12/16 21:13:17 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll
[2008/12/16 21:13:14 | 00,009,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntapm.sys
[2008/12/16 21:13:11 | 00,007,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nsmmc.sys
[2008/12/16 21:13:06 | 00,087,040 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2008/12/16 21:13:04 | 00,126,080 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2008/12/16 21:13:00 | 00,132,695 | —- | C] (802.11b) – C:\WINDOWS\System32\dllcache\netwlan5.sys
[2008/12/16 21:13:00 | 00,032,840 | —- | C] (NETGEAR Corporation.) – C:\WINDOWS\System32\dllcache\ngrpci.sys
[2008/12/16 21:12:56 | 00,065,278 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\netflx3.sys
[2008/12/16 21:12:52 | 00,039,264 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.sys
[2008/12/16 21:12:49 | 00,060,480 | —- | C] (NeoMagic Corporation) – C:\WINDOWS\System32\dllcache\neo20xx.dll
[2008/12/16 21:12:47 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ne2000.sys
[2008/12/16 21:12:43 | 00,091,488 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2008/12/16 21:12:40 | 00,027,936 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i3d.sys
[2008/12/16 21:12:37 | 00,033,088 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2008/12/16 21:12:34 | 00,059,104 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2008/12/16 21:12:32 | 00,013,664 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.sys
[2008/12/16 21:12:29 | 00,035,392 | —- | C] (Number Nine Visual Technology Corp.) – C:\WINDOWS\System32\dllcache\n9i128.dll
[2008/12/16 21:12:26 | 00,128,000 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n100325.sys
[2008/12/16 21:12:23 | 00,052,255 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\n1000nt5.sys
[2008/12/16 21:12:20 | 00,075,520 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxport.sys
[2008/12/16 21:12:17 | 00,007,168 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxport.dll
[2008/12/16 21:12:15 | 00,019,968 | —- | C] (Macronix International Co., Ltd. ) – C:\WINDOWS\System32\dllcache\mxnic.sys
[2008/12/16 21:12:12 | 00,019,968 | —- | C] (Moxa Technologies Co., Ltd) – C:\WINDOWS\System32\dllcache\mxicfg.dll
[2008/12/16 21:12:09 | 00,229,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\multibox.dll
[2008/12/16 21:12:09 | 00,021,888 | —- | C] (Moxa Technologies Co., Ltd.) – C:\WINDOWS\System32\dllcache\mxcard.sys
[2008/12/16 21:12:05 | 00,103,296 | —- | C] (Matrox Graphics Inc) – C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2008/12/16 21:11:59 | 00,049,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstape.sys
[2008/12/16 21:11:54 | 00,012,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msriffwv.sys
[2008/12/16 21:11:48 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msmpu401.sys
[2008/12/16 21:11:46 | 01,875,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msir3jp.lex
[2008/12/16 21:11:46 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msir3jp.dll
[2008/12/16 21:11:46 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msircomm.sys
[2008/12/16 21:11:39 | 00,035,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msgame.sys
[2008/12/16 21:11:36 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2008/12/16 21:11:36 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfsio.sys
[2008/12/16 21:11:35 | 00,051,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdv.sys
[2008/12/16 21:11:32 | 00,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpe.sys
[2008/12/16 21:11:28 | 00,016,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\modemcsa.sys
[2008/12/16 21:11:23 | 00,006,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\miniqic.sys
[2008/12/16 21:11:21 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\migisol.exe
[2008/12/16 21:11:15 | 00,092,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mga.sys
[2008/12/16 21:11:15 | 00,092,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mga.dll
[2008/12/16 21:11:11 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memgrp.dll
[2008/12/16 21:11:09 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\memcard.sys
[2008/12/16 21:11:06 | 00,164,586 | —- | C] (Madge Networks Ltd) – C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2008/12/16 21:11:02 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll
[2008/12/16 21:11:02 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mammoth.sys
[2008/12/16 21:10:56 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3092dc.dll
[2008/12/16 21:10:54 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\m3091dc.dll
[2008/12/16 21:10:48 | 00,797,500 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltsmt.sys
[2008/12/16 21:10:45 | 00,802,683 | —- | C] (Lucent Technologies) – C:\WINDOWS\System32\dllcache\ltsm.sys
[2008/12/16 21:10:45 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ltotape.sys
[2008/12/16 21:10:44 | 00,420,992 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2008/12/16 21:10:42 | 00,576,746 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2008/12/16 21:10:41 | 00,606,684 | —- | C] (LT) – C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2008/12/16 21:10:39 | 00,727,786 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ltck000c.sys
[2008/12/16 21:10:35 | 00,004,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\loop.sys
[2008/12/16 21:10:32 | 00,070,730 | —- | C] (Linksys Group, Inc.) – C:\WINDOWS\System32\dllcache\lne100tx.sys
[2008/12/16 21:10:29 | 00,020,573 | —- | C] (The Linksts Group ) – C:\WINDOWS\System32\dllcache\lne100.sys
[2008/12/16 21:10:27 | 00,025,065 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\lmndis3.sys
[2008/12/16 21:10:24 | 00,015,744 | —- | C] (Litronic Industries) – C:\WINDOWS\System32\dllcache\lit220p.sys
[2008/12/16 21:10:21 | 00,026,442 | —- | C] (SMSC) – C:\WINDOWS\System32\dllcache\lanepic5.sys
[2008/12/16 21:10:18 | 00,019,016 | —- | C] (Kingston Technology Company ) – C:\WINDOWS\System32\dllcache\ktc111.sys
[2008/12/16 21:10:17 | 00,047,066 | —- | C] () – C:\WINDOWS\System32\dllcache\ksc.nls
[2008/12/16 21:10:14 | 01,158,818 | —- | C] () – C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2008/12/16 21:10:14 | 00,070,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\korwbrkr.dll
[2008/12/16 21:10:14 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kousd.dll
[2008/12/16 21:10:13 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsusd.dll
[2008/12/16 21:10:12 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kdsui.dll
[2008/12/16 21:10:12 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdusa.dll
[2008/12/16 21:10:09 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdnecat.dll
[2008/12/16 21:10:09 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdnecnt.dll
[2008/12/16 21:10:09 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdnec95.dll
[2008/12/16 21:10:05 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdkor.dll
[2008/12/16 21:10:02 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdjpn.dll
[2008/12/16 21:09:56 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd106.dll
[2008/12/16 21:09:53 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd103.dll
[2008/12/16 21:09:51 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101c.dll
[2008/12/16 21:09:48 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jupiw.dll
[2008/12/16 21:09:48 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101b.dll
[2008/12/16 21:09:48 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101a.dll
[2008/12/16 21:09:42 | 00,018,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irsir.sys
[2008/12/16 21:09:41 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irmon.dll
[2008/12/16 21:09:39 | 00,151,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irftp.exe
[2008/12/16 21:09:39 | 00,023,552 | —- | C] (MKNet Corporation) – C:\WINDOWS\System32\dllcache\irmk7.sys
[2008/12/16 21:09:38 | 00,088,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irda.sys
[2008/12/16 21:09:34 | 00,045,632 | —- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) – C:\WINDOWS\System32\dllcache\ip5515.sys
[2008/12/16 21:09:31 | 00,090,200 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8ports.dll
[2008/12/16 21:09:29 | 00,038,784 | —- | C] (Perle Systems Ltd. ) – C:\WINDOWS\System32\dllcache\io8.sys
[2008/12/16 21:09:26 | 00,013,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inport.sys
[2008/12/16 21:09:24 | 00,471,102 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imskdic.dll
[2008/12/16 21:09:23 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imkrinst.exe
[2008/12/16 21:09:23 | 00,045,109 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpuex.exe
[2008/12/16 21:09:21 | 00,057,398 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imjpdadm.exe
[2008/12/16 21:09:20 | 00,311,359 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imepadsv.exe
[2008/12/16 21:09:20 | 00,102,463 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imepadsm.dll
[2008/12/16 21:09:19 | 00,134,339 | —- | C] () – C:\WINDOWS\System32\dllcache\imekr.lex
[2008/12/16 21:09:19 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imekrmig.exe
[2008/12/16 21:09:13 | 00,372,824 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\iconf32.dll
[2008/12/16 21:09:10 | 00,100,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5usb.sys
[2008/12/16 21:09:08 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5ext.dll
[2008/12/16 21:09:06 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam5com.dll
[2008/12/16 21:09:03 | 00,154,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4usb.sys
[2008/12/16 21:09:01 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4ext.dll
[2008/12/16 21:08:58 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam4com.dll
[2008/12/16 21:08:56 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3ext.dll
[2008/12/16 21:08:54 | 00,141,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icam3.sys
[2008/12/16 21:08:51 | 00,038,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ibmvcap.sys
[2008/12/16 21:08:33 | 10,129,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hwxkor.dll
[2008/12/16 21:08:31 | 10,096,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hwxcht.dll
[2008/12/16 21:07:57 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hr1w.dll
[2008/12/16 21:07:54 | 00,005,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpt4qic.sys
[2008/12/16 21:07:52 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpsjmcro.dll
[2008/12/16 21:07:50 | 00,324,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpojwia.dll
[2008/12/16 21:07:48 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgtmcro.dll
[2008/12/16 21:07:45 | 00,068,608 | —- | C] (Avisioin) – C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2008/12/16 21:07:43 | 00,165,888 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt53.dll
[2008/12/16 21:07:41 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt42tk.dll
[2008/12/16 21:07:39 | 00,093,696 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt42.dll
[2008/12/16 21:07:36 | 00,126,976 | —- | C] (Hewlett Packard) – C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2008/12/16 21:07:34 | 00,101,376 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt34.dll
[2008/12/16 21:07:32 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt33tk.dll
[2008/12/16 21:07:30 | 00,089,088 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt33.dll
[2008/12/16 21:07:27 | 00,123,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpgt21tk.dll
[2008/12/16 21:07:25 | 00,083,968 | —- | C] () – C:\WINDOWS\System32\dllcache\hpgt21.dll
[2008/12/16 21:07:23 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hpdigwia.dll
[2008/12/16 21:07:20 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2008/12/16 21:07:20 | 00,002,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidswvd.sys
[2008/12/16 21:07:17 | 00,020,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidbatt.sys
[2008/12/16 21:07:17 | 00,008,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidgame.sys
[2008/12/16 21:07:14 | 00,036,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hanjadic.dll
[2008/12/16 21:07:13 | 00,108,827 | —- | C] () – C:\WINDOWS\System32\dllcache\hanja.lex
[2008/12/16 21:07:13 | 00,028,288 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grserial.sys
[2008/12/16 21:07:10 | 00,082,304 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\grclass.sys
[2008/12/16 21:07:08 | 00,017,408 | —- | C] (Gemplus) – C:\WINDOWS\System32\dllcache\gpr400.sys
[2008/12/16 21:07:07 | 00,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gckernel.sys
[2008/12/16 21:07:07 | 00,010,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gameenum.sys
[2008/12/16 21:06:56 | 00,454,912 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fxusbase.sys
[2008/12/16 21:06:53 | 00,092,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fuusd.dll
[2008/12/16 21:06:51 | 00,455,296 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fusbbase.sys
[2008/12/16 21:06:49 | 00,455,680 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fus2base.sys
[2008/12/16 21:06:49 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ftlx041e.dll
[2008/12/16 21:06:46 | 00,442,240 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2008/12/16 21:06:44 | 00,441,728 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2008/12/16 21:06:42 | 00,444,416 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\fpcibase.sys
[2008/12/16 21:06:41 | 00,034,173 | —- | C] (Marconi Communications, Inc.) – C:\WINDOWS\System32\dllcache\forehe.sys
[2008/12/16 21:06:39 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fnfilter.dll
[2008/12/16 21:06:38 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\flattemp.exe
[2008/12/16 21:06:30 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll
[2008/12/16 21:06:28 | 00,024,618 | —- | C] (NETGEAR) – C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2008/12/16 21:06:24 | 00,011,850 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2008/12/16 21:06:22 | 00,012,362 | —- | C] (FUJITSU LIMITED) – C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2008/12/16 21:06:19 | 00,007,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\exabyte2.sys
[2008/12/16 21:06:16 | 00,045,056 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunid.dll
[2008/12/16 21:06:16 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\et4000.sys
[2008/12/16 21:06:14 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunib.dll
[2008/12/16 21:06:12 | 00,057,856 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimgd.dll
[2008/12/16 21:06:12 | 00,045,568 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuni.dll
[2008/12/16 21:06:10 | 00,034,816 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimg.dll
[2008/12/16 21:06:10 | 00,031,744 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucmd.dll
[2008/12/16 21:06:08 | 00,043,008 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucm.dll
[2008/12/16 21:05:56 | 00,072,192 | —- | C] (ESS Technology Inc.) – C:\WINDOWS\System32\dllcache\es1969.sys
[2008/12/16 21:05:42 | 00,114,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epstw2k.sys
[2008/12/16 21:05:39 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\epcfw2k.sys
[2008/12/16 21:05:38 | 00,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\enum1394.sys
[2008/12/16 21:05:29 | 00,007,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\elmsmc.sys
[2008/12/16 21:05:10 | 00,514,587 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\edb500.dll
[2008/12/16 21:05:03 | 00,334,208 | —- | C] (Yamaha Corp.) – C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2008/12/16 21:05:00 | 00,028,062 | —- | C] (National Semiconductor Coproration) – C:\WINDOWS\System32\dllcache\dp83820.sys
[2008/12/16 21:04:59 | 00,023,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4usb.sys
[2008/12/16 21:04:58 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4scan.sys
[2008/12/16 21:04:57 | 00,012,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4prt.sys
[2008/12/16 21:04:56 | 00,206,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dot4.sys
[2008/12/16 21:04:53 | 00,029,696 | —- | C] (CNet Technology, Inc. ) – C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2008/12/16 21:04:52 | 00,008,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dlttape.sys
[2008/12/16 21:04:51 | 00,026,698 | —- | C] (D-Link Corporation) – C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2008/12/16 21:04:49 | 00,952,007 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diwan.sys
[2008/12/16 21:04:48 | 00,029,768 | —- | C] () – C:\WINDOWS\System32\dllcache\divasu.dll
[2008/12/16 21:04:47 | 00,037,962 | —- | C] () – C:\WINDOWS\System32\dllcache\divaprop.dll
[2008/12/16 21:04:45 | 00,006,216 | —- | C] () – C:\WINDOWS\System32\dllcache\divaci.dll
[2008/12/16 21:04:44 | 00,236,060 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\ditrace.exe
[2008/12/16 21:04:43 | 00,038,985 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvsu.dll
[2008/12/16 21:04:42 | 00,031,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvpp.dll
[2008/12/16 21:04:41 | 00,006,729 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\disrvci.dll
[2008/12/16 21:04:39 | 00,091,305 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\dimaint.sys
[2008/12/16 21:04:19 | 00,024,649 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650d.sys
[2008/12/16 21:04:18 | 00,024,648 | —- | C] (D-Link) – C:\WINDOWS\System32\dllcache\dfe650.sys
[2008/12/16 21:04:14 | 00,020,928 | —- | C] (Digital Networks, LLC) – C:\WINDOWS\System32\dllcache\defpa.sys
[2008/12/16 21:04:13 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddsmc.sys
[2008/12/16 21:04:11 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc260usd.dll
[2008/12/16 21:04:10 | 00,086,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc240usd.dll
[2008/12/16 21:04:08 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210usd.dll
[2008/12/16 21:04:07 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dc210_32.dll
[2008/12/16 21:04:03 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzports.dll
[2008/12/16 21:04:02 | 00,049,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzport.sys
[2008/12/16 21:04:00 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyzcoins.dll
[2008/12/16 21:03:59 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyports.dll
[2008/12/16 21:03:58 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyyport.sys
[2008/12/16 21:03:57 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyycoins.dll
[2008/12/16 21:03:56 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclom-y.sys
[2008/12/16 21:03:55 | 00,017,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cyclad-z.sys
[2008/12/16 21:03:54 | 00,048,640 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2008/12/16 21:03:53 | 00,093,952 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2008/12/16 21:03:52 | 00,111,872 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcspud.sys
[2008/12/16 21:03:51 | 00,003,584 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2008/12/16 21:03:50 | 00,072,832 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2008/12/16 21:03:49 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2008/12/16 21:03:48 | 00,003,072 | —- | C] (Crystal Semiconductor Corp.) – C:\WINDOWS\System32\dllcache\cwbase.sys
[2008/12/16 21:03:46 | 00,249,856 | —- | C] (Comtrol® Corporation) – C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2008/12/16 21:03:41 | 00,175,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\csamsp.dll
[2008/12/16 21:03:39 | 00,216,064 | —- | C] (COMPAQ Inc.) – C:\WINDOWS\System32\dllcache\cpscan.dll
[2008/12/16 21:03:39 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cprofile.exe
[2008/12/16 21:03:38 | 00,060,970 | —- | C] (Compaq Computer Corp.) – C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2008/12/16 21:03:37 | 00,021,533 | —- | C] (Compaq Computer Corporation) – C:\WINDOWS\System32\dllcache\cpqndis5.sys
[2008/12/16 21:03:35 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\compbatt.sys
[2008/12/16 21:03:32 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnusd.dll
[2008/12/16 21:03:30 | 00,020,736 | —- | C] (OMNIKEY AG) – C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2008/12/16 21:03:30 | 00,013,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cmbatt.sys
[2008/12/16 21:03:29 | 00,248,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546xm.sys
[2008/12/16 21:03:28 | 00,170,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl546x.dll
[2008/12/16 21:03:27 | 00,111,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cl5465.dll
[2008/12/16 21:03:27 | 00,045,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.sys
[2008/12/16 21:03:26 | 00,091,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cirrus.dll
[2008/12/16 21:03:24 | 00,272,640 | —- | C] (RAVISENT Technologies Inc.) – C:\WINDOWS\System32\dllcache\cinemclc.sys
[2008/12/16 21:03:23 | 00,980,034 | —- | C] (Xircom) – C:\WINDOWS\System32\dllcache\cicap.sys
[2008/12/16 21:03:22 | 00,838,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chtbrkr.dll
[2008/12/16 21:03:21 | 01,677,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chsbrkr.dll
[2008/12/16 21:03:20 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chgport.exe
[2008/12/16 21:03:20 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chgusr.exe
[2008/12/16 21:03:20 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\chglogon.exe
[2008/12/16 21:03:19 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\change.exe
[2008/12/16 21:03:19 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\changer.sys
[2008/12/16 21:03:18 | 00,049,182 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem56n5.sys
[2008/12/16 21:03:17 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem33n5.sys
[2008/12/16 21:03:17 | 00,022,044 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cem28n5.sys
[2008/12/16 21:03:16 | 00,027,164 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce3n5.sys
[2008/12/16 21:03:15 | 00,021,530 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\ce2n5.sys
[2008/12/16 21:03:14 | 00,714,698 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2008/12/16 21:03:13 | 00,046,108 | —- | C] (Xircom, Inc.) – C:\WINDOWS\System32\dllcache\cben5.sys
[2008/12/16 21:03:13 | 00,039,680 | —- | C] (Silicom Ltd.) – C:\WINDOWS\System32\dllcache\cb325.sys
[2008/12/16 21:03:12 | 00,037,916 | —- | C] (Fast Ethernet Controller Provider) – C:\WINDOWS\System32\dllcache\cb102.sys
[2008/12/16 21:03:10 | 00,032,256 | —- | C] (Eicon Technology Corporation) – C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2008/12/16 21:03:09 | 00,164,923 | —- | C] (Eicon Technology) – C:\WINDOWS\System32\dllcache\diapi2.sys
[2008/12/16 21:03:09 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.dll
[2008/12/16 21:03:09 | 00,054,528 | —- | C] (Philips Semiconductors GmbH) – C:\WINDOWS\System32\dllcache\cap7146.sys
[2008/12/16 21:03:08 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext30.ax
[2008/12/16 21:03:07 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.ax
[2008/12/16 21:03:07 | 00,236,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camext20.dll
[2008/12/16 21:03:06 | 00,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.dll
[2008/12/16 21:03:05 | 00,171,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv30.sys
[2008/12/16 21:03:05 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camexo20.ax
[2008/12/16 21:03:04 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdrv21.sys
[2008/12/16 21:03:03 | 00,314,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\camdro21.sys
[2008/12/16 21:03:01 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_iscii.dll
[2008/12/16 21:03:01 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_is2022.dll
[2008/12/16 21:03:00 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_864.nls
[2008/12/16 21:03:00 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_862.nls
[2008/12/16 21:03:00 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_870.nls
[2008/12/16 21:02:59 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_858.nls
[2008/12/16 21:02:59 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_720.nls
[2008/12/16 21:02:59 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_708.nls
[2008/12/16 21:02:58 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_28596.nls
[2008/12/16 21:02:57 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_21027.nls
[2008/12/16 21:02:57 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_21025.nls
[2008/12/16 21:02:56 | 00,180,770 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20932.nls
[2008/12/16 21:02:56 | 00,177,698 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20949.nls
[2008/12/16 21:02:56 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20936.nls
[2008/12/16 21:02:55 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20924.nls
[2008/12/16 21:02:55 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20880.nls
[2008/12/16 21:02:54 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20871.nls
[2008/12/16 21:02:54 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20838.nls
[2008/12/16 21:02:54 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20833.nls
[2008/12/16 21:02:54 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20424.nls
[2008/12/16 21:02:53 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20423.nls
[2008/12/16 21:02:53 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20420.nls
[2008/12/16 21:02:53 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20297.nls
[2008/12/16 21:02:53 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20290.nls
[2008/12/16 21:02:53 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20285.nls
[2008/12/16 21:02:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20284.nls
[2008/12/16 21:02:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20280.nls
[2008/12/16 21:02:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20278.nls
[2008/12/16 21:02:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20277.nls
[2008/12/16 21:02:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20273.nls
[2008/12/16 21:02:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20269.nls
[2008/12/16 21:02:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20108.nls
[2008/12/16 21:02:50 | 00,187,938 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20005.nls
[2008/12/16 21:02:50 | 00,180,258 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20004.nls
[2008/12/16 21:02:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20107.nls
[2008/12/16 21:02:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20106.nls
[2008/12/16 21:02:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20105.nls
[2008/12/16 21:02:49 | 00,186,402 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20001.nls
[2008/12/16 21:02:49 | 00,185,378 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20003.nls
[2008/12/16 21:02:49 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20002.nls
[2008/12/16 21:02:48 | 00,189,986 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1361.nls
[2008/12/16 21:02:48 | 00,180,258 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20000.nls
[2008/12/16 21:02:47 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1149.nls
[2008/12/16 21:02:47 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1148.nls
[2008/12/16 21:02:47 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1147.nls
[2008/12/16 21:02:46 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1146.nls
[2008/12/16 21:02:46 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1145.nls
[2008/12/16 21:02:46 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1144.nls
[2008/12/16 21:02:46 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1143.nls
[2008/12/16 21:02:45 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1142.nls
[2008/12/16 21:02:45 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1141.nls
[2008/12/16 21:02:45 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1140.nls
[2008/12/16 21:02:45 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1047.nls
[2008/12/16 21:02:44 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10008.nls
[2008/12/16 21:02:44 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10021.nls
[2008/12/16 21:02:43 | 00,177,698 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10003.nls
[2008/12/16 21:02:43 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10005.nls
[2008/12/16 21:02:43 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10004.nls
[2008/12/16 21:02:42 | 00,195,618 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10002.nls
[2008/12/16 21:02:42 | 00,162,850 | —- | C] () – C:\WINDOWS\System32\dllcache\c_10001.nls
[2008/12/16 21:02:41 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bulltlp3.sys
[2008/12/16 21:02:40 | 00,031,529 | —- | C] (BreezeCOM) – C:\WINDOWS\System32\dllcache\brzwlan.sys
[2008/12/16 21:02:40 | 00,010,368 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbscn.sys
[2008/12/16 21:02:39 | 00,060,416 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brserwdm.sys
[2008/12/16 21:02:39 | 00,011,008 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2008/12/16 21:02:38 | 00,009,728 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brserif.dll
[2008/12/16 21:02:38 | 00,005,120 | —- | C] (Brother Industries,Ltd.) – C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2008/12/16 21:02:37 | 00,039,552 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparwdm.sys
[2008/12/16 21:02:36 | 00,003,168 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brparimg.sys
[2008/12/16 21:02:35 | 00,041,472 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfusb.dll
[2008/12/16 21:02:35 | 00,032,256 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2008/12/16 21:02:34 | 00,081,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\brmfcwia.dll
[2008/12/16 21:02:34 | 00,029,696 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmflpt.dll
[2008/12/16 21:02:33 | 00,015,360 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2008/12/16 21:02:33 | 00,003,968 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltup.sys
[2008/12/16 21:02:32 | 00,012,160 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2008/12/16 21:02:32 | 00,002,944 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brfilt.sys
[2008/12/16 21:02:31 | 00,012,800 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brevif.dll
[2008/12/16 21:02:30 | 00,082,172 | —- | C] () – C:\WINDOWS\System32\dllcache\bopomofo.nls
[2008/12/16 21:02:30 | 00,019,456 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\dllcache\brbidiif.dll
[2008/12/16 21:02:30 | 00,009,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\dllcache\brcoinst.dll
[2008/12/16 21:02:29 | 00,102,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\binlsvc.dll
[2008/12/16 21:02:29 | 00,066,728 | —- | C] () – C:\WINDOWS\System32\dllcache\big5.nls
[2008/12/16 21:02:28 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2008/12/16 21:02:28 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdasup.sys
[2008/12/16 21:02:27 | 00,871,388 | —- | C] (BCM) – C:\WINDOWS\System32\dllcache\bcmdm.sys
[2008/12/16 21:02:25 | 00,014,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\battc.sys
[2008/12/16 21:02:24 | 00,342,336 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.dll
[2008/12/16 21:02:24 | 00,036,128 | —- | C] (3Dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\banshee.sys
[2008/12/16 21:02:23 | 00,089,952 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\b1cbase.sys
[2008/12/16 21:02:22 | 00,037,568 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmwan.sys
[2008/12/16 21:02:22 | 00,036,992 | —- | C] (Aztech Systems Ltd) – C:\WINDOWS\System32\dllcache\aztw2320.sys
[2008/12/16 21:02:21 | 00,144,384 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmenum.dll
[2008/12/16 21:02:21 | 00,087,552 | —- | C] (AVM GmbH) – C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2008/12/16 21:02:20 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avc.sys
[2008/12/16 21:02:20 | 00,036,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcaudio.sys
[2008/12/16 21:02:20 | 00,013,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avcstrm.sys
[2008/12/16 21:02:18 | 00,023,552 | —- | C] () – C:\WINDOWS\System32\dllcache\atixbar.sys
[2008/12/16 21:02:17 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\dllcache\ativxbar.sys
[2008/12/16 21:02:17 | 00,019,456 | —- | C] () – C:\WINDOWS\System32\dllcache\ativttxx.sys
[2008/12/16 21:02:16 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2008/12/16 21:02:16 | 00,009,472 | —- | C] () – C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2008/12/16 21:02:15 | 00,026,880 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2008/12/16 21:02:15 | 00,017,152 | —- | C] () – C:\WINDOWS\System32\dllcache\atitunep.sys
[2008/12/16 21:02:14 | 00,049,920 | —- | C] () – C:\WINDOWS\System32\dllcache\atirtcap.sys
[2008/12/16 21:02:13 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2008/12/16 21:02:11 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atievxx.exe
[2008/12/16 21:02:09 | 00,046,464 | —- | C] () – C:\WINDOWS\System32\dllcache\atibt829.sys
[2008/12/16 21:02:07 | 00,096,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ati.dll
[2008/12/16 21:02:07 | 00,077,568 | —- | C] (ATI Technologies, Inc.) – C:\WINDOWS\System32\dllcache\ati.sys
[2008/12/16 21:02:06 | 00,097,354 | —- | C] (Bay Networks, Inc.) – C:\WINDOWS\System32\dllcache\aspndis3.sys
[2008/12/16 21:02:05 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2008/12/16 21:02:05 | 00,006,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\apmbatt.sys
[2008/12/16 21:02:04 | 00,016,969 | —- | C] (AmbiCom, Inc.) – C:\WINDOWS\System32\dllcache\amb8002.sys
[2008/12/16 21:01:59 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agcgauge.ax
[2008/12/16 21:01:57 | 00,046,112 | —- | C] (Adaptec, Inc ) – C:\WINDOWS\System32\dllcache\adptsf50.sys
[2008/12/16 21:01:57 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2008/12/16 21:01:56 | 00,747,392 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8830.sys
[2008/12/16 21:01:56 | 00,553,984 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8820.sys
[2008/12/16 21:01:56 | 00,010,880 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\admjoy.sys
[2008/12/16 21:01:55 | 00,584,448 | —- | C] (Aureal, Inc.) – C:\WINDOWS\System32\dllcache\adm8810.sys
[2008/12/16 21:01:55 | 00,020,160 | —- | C] (ADMtek Incorporated) – C:\WINDOWS\System32\dllcache\adm8511.sys
[2008/12/16 21:01:54 | 00,061,440 | —- | C] (Color Flatbed Scanner) – C:\WINDOWS\System32\dllcache\acerscad.dll
[2008/12/16 21:01:54 | 00,007,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adicvls.sys
[2008/12/16 21:01:53 | 00,297,728 | —- | C] (Silicon Integrated Systems Corp.) – C:\WINDOWS\System32\dllcache\ac97sis.sys
[2008/12/16 21:01:52 | 00,462,848 | —- | C] (Aureal Inc.) – C:\WINDOWS\System32\dllcache\a3dapi.dll
[2008/12/16 21:01:51 | 00,098,304 | —- | C] (Aureal Semiconductor) – C:\WINDOWS\System32\dllcache\a3d.dll
[2008/12/16 21:01:51 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\61883.sys
[2008/12/16 21:01:51 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\8514a.dll
[2008/12/16 21:01:51 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\4mmdat.sys
[2008/12/16 21:01:50 | 00,762,780 | —- | C] (3Com, Inc.) – C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2008/12/16 21:01:50 | 00,689,216 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2008/12/16 21:01:50 | 00,148,352 | —- | C] (3dfx Interactive, Inc.) – C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2008/12/16 21:01:49 | 00,053,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394bus.sys
[2008/12/16 21:01:49 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\1394vdbg.sys
[2008/12/16 21:01:32 | 00,066,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\s3legacy.dll
[2008/12/16 20:19:36 | 00,000,000 | —D | C] – C:\Program Files\Fix_CD_Drive
[2008/12/16 19:44:14 | 00,000,284 | —- | C] () – C:\Program Files\Fix_CD_Drive.zip
[2008/12/16 19:41:19 | 00,000,000 | —D | C] – C:\Program Files\AskBarDis
[2008/12/16 19:41:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Thayney\Application Data\Mozilla
[2008/12/16 19:40:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\comodo
[2008/12/16 19:40:00 | 00,000,000 | —D | C] – C:\Program Files\COMODO
[2008/12/16 16:27:40 | 00,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2008/12/15 21:36:18 | 01,137,360 | —- | C] (F-Secure Corporation) – C:\Program Files\fsbl.exe
[2008/12/15 21:33:11 | 00,000,000 | —D | C] – C:\Program Files\ACW
[2008/12/14 22:19:06 | 00,001,734 | —- | C] () – C:\Documents and Settings\Thayney\Desktop\HijackThis.lnk
[2008/12/14 22:19:06 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2008/12/14 22:16:09 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Program Files\HJTInstall.exe
[2008/12/13 15:15:32 | 00,000,000 | —D | C] – C:\Documents and Settings\Thayney\Application Data\Malwarebytes
[2008/12/13 15:15:30 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2008/12/13 15:15:30 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/12/13 15:15:28 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/12/13 15:15:27 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2008/12/13 15:15:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/12/12 21:39:32 | 00,030,080 | —- | C] () – C:\WINDOWS\System32\drivers\RKHit.sys
[2008/12/12 21:39:26 | 00,000,042 | —- | C] () – C:\WINDOWS\System32\AK083E209605E394C.lie
[2008/12/11 22:46:37 | 00,000,000 | —D | C] – C:\443d37d90cf7294f0034bd72e0
[2008/12/11 21:01:26 | 00,000,000 | —D | C] – C:\WINDOWS\System32\ma1
[2008/12/11 21:01:21 | 00,000,000 | —D | C] – C:\Temp
[2008/12/11 21:01:18 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Thayney\Local Settings\Application Data\.#

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/10 17:20:32 | 00,419,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Thayney\Desktop\OTListIt2.exe
[2009/01/10 16:53:36 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/10 16:53:23 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/10 16:53:21 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/01/10 16:53:20 | 21,371,49440 | -HS- | M] () – C:\hiberfil.sys
[2009/01/10 16:48:00 | 00,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/01/10 16:40:18 | 05,328,786 | -H– | M] () – C:\Documents and Settings\Thayney\Local Settings\Application Data\IconCache.db
[2009/01/10 16:38:50 | 01,529,241 | —- | M] () – C:\Documents and Settings\Thayney\Desktop\SDFix.exe
[2009/01/09 21:43:27 | 00,006,580 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/01/09 21:43:25 | 00,000,088 | RHS- | M] () – C:\WINDOWS\System32\36F26ECF49.sys
[2009/01/09 20:47:05 | 00,000,576 | —- | M] () – C:\Documents and Settings\Thayney\My Documents\My Sharing Folders.lnk
[2009/01/07 21:57:06 | 00,000,256 | —- | M] () – C:\WINDOWS\System32\pool.bin
[2009/01/04 15:44:08 | 00,030,208 | —- | M] () – C:\Documents and Settings\Thayney\My Documents\What have exams turned into lecture.doc
[2009/01/04 13:25:18 | 00,025,088 | —- | M] () – C:\Documents and Settings\Thayney\My Documents\All exams seem to do to children of the new generation 1.doc
[2009/01/04 12:51:19 | 00,028,672 | —- | M] () – C:\Documents and Settings\Thayney\My Documents\IS TOO MUCH PRESSURE PUT ON CHILDREN TODAY WITH EXAM1.doc
[2009/01/02 22:01:12 | 00,019,968 | —- | M] () – C:\Documents and Settings\Thayney\My Documents\IS TOO MUCH PRESSURE PUT ON CHILDREN TODAY WITH EXAMS.doc
[2009/01/02 19:26:23 | 00,000,412 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan.job
[2009/01/02 13:04:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/01 22:01:02 | 00,018,944 | —- | M] () – C:\Documents and Settings\Thayney\My Documents\Bike fitness schedule.xls
[2008/12/31 17:58:23 | 00,598,608 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2008/12/31 17:58:23 | 00,502,518 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2008/12/31 17:58:23 | 00,087,774 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2008/12/31 13:38:35 | 00,000,056 | RHS- | M] () – C:\WINDOWS\System32\49CF6EF236.sys
[2008/12/30 17:37:53 | 00,045,056 | —- | M] () – C:\Documents and Settings\Thayney\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/16 22:36:44 | 00,078,848 | —- | M] () – C:\Documents and Settings\Thayney\My Documents\moore art.doc
[2008/12/14 22:19:07 | 00,001,734 | —- | M] () – C:\Documents and Settings\Thayney\Desktop\HijackThis.lnk
[2008/12/13 15:15:30 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/12/13 06:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 06:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/12 21:39:26 | 00,000,042 | —- | M] () – C:\WINDOWS\System32\AK083E209605E394C.lie

========== LOP Check ==========

[2008/12/16 19:40:01 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/11/25 21:23:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/04/17 19:01:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/09/03 19:25:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/07/01 11:16:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/12/15 16:46:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2007/02/09 16:20:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg7
[2008/12/16 19:40:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\comodo
[2008/12/19 18:24:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2006/09/03 19:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/04/29 16:38:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2006/08/25 18:55:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/02/03 10:41:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/12/13 15:15:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2006/08/25 19:00:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006/08/25 18:59:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2006/09/01 20:38:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2007/10/24 11:24:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2008/12/04 16:39:47 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/01/02 09:52:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2008/08/06 13:09:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pixelStorm
[2007/03/29 15:10:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2006/08/25 18:57:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/12/06 21:42:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Roxio
[2004/08/10 12:13:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/10/25 21:07:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2006/09/03 18:56:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/12/06 16:49:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/08/25 18:57:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/09/06 17:35:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2006/12/03 10:30:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2008/07/06 16:22:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/01/09 21:42:50 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Thayney\Application Data
[2009/01/09 21:43:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Adobe
[2009/01/09 21:43:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\AdobeUM
[2006/09/03 19:24:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\AOL
[2007/08/04 15:18:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Apple Computer
[2009/01/09 21:47:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\AVG7
[2009/01/09 21:43:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Blackberry Desktop
[2009/01/09 21:43:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\ConvertTemp
[2009/01/09 21:43:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Corel
[2006/11/12 18:09:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Corel Photo Album
[2009/01/09 21:46:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Google
[2006/08/25 19:05:03 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Thayney\Application Data\Gtek
[2004/08/10 12:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Identities
[2008/10/25 21:09:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\InstallShield
[2008/01/02 10:05:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\InterTrust
[2007/12/08 13:02:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Macromedia
[2008/12/13 15:15:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Malwarebytes
[2006/09/01 20:38:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\McAfee.com Personal Firewall
[2008/12/15 21:34:26 | 00,000,000 | –SD | M] – C:\Documents and Settings\Thayney\Application Data\Microsoft
[2008/12/16 19:41:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Mozilla
[2008/10/25 21:12:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Research In Motion
[2008/12/06 21:42:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Roxio
[2006/12/02 13:41:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Samsung
[2006/09/06 18:23:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Sun
[2006/08/25 18:54:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Symantec
[2007/01/18 16:32:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Temporary
[2007/01/14 16:14:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\TransRender
[2008/12/09 17:34:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\U3
[2007/10/03 16:28:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Viewpoint
[2008/08/07 11:02:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Windows Desktop Search
[2008/08/09 13:46:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Windows Search
[2007/02/18 21:29:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\Xfire
[2006/08/25 18:57:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Thayney\Application Data\You've Got Pictures Screensaver
[2009/01/02 13:04:01 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 04:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/01/02 19:26:23 | 00,000,412 | —- | M] () – C:\WINDOWS\Tasks\Norton Security Scan.job
[2009/01/10 16:53:23 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> %ProgramFiles%\Usher_-_Yeah!.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> %ProgramFiles%\Usher_-_Moving_Mountains.mp3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> %ProgramFiles%\Lily_Allen_-_The_Fear.mp3:Roxio EMC Stream
< End of report >

and the extras report:

OTListIt Extras logfile created on: 10/01/2009 17:22:34 - Run
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\Thayney\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 75.03% Memory free
3.32 Gb Paging File | 2.98 Gb Available in Paging File | 89.88% Paging File free
Paging file location(s): C:\pagefile.sys 1512 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.30 Gb Total Space | 39.89 Gb Free Space | 55.95% Space Free | Partition Type: NTFS
Drive D: | 495.22 Mb Total Space | 323.37 Mb Free Space | 65.30% Space Free | Partition Type: FAT
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: THAYNEYDESKTOP
Current User Name: Thayney
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL File not found
C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
%windir%\system32\drivers\svchost.exe:*:Enabled:svchost File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL File not found
C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL File not found
C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe (GRISOFT, s.r.o.)
C:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe:*:Disabled:Jedi Academy MultiPlayer File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Enabled:avgamsvr.exe (GRISOFT, s.r.o.)
C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Enabled:avgcc.exe (GRISOFT, s.r.o.)
C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe (Microsoft Corporation)
C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe (Microsoft Corporation)
C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade File not found
C:\Program Files\LucasArts\Star Wars Galactic Battlegrounds Saga\Game\Battlegrounds.exe:*:Enabled:Star Wars Galactic Battlegrounds File not found
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\EA GAMES\MOHAA\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault File not found
C:\UT2004\System\UT2004.exe:*:Enabled:UT2004 File not found
C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade File not found
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Disabled:BearShare File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
%windir%\system32\drivers\svchost.exe:*:Enabled:svchost File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07070EAB-9349-4F6C-AC13-AEFE436F9775}" = D-link AirPlus G DWL-G120 Wireless USB Adapter
"{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates!
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1967D67C-6F3F-4001-9644-BAC704F7EE84}" = Samsung PC Studio
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1D3C662A-F6C6-4767-A788-7AA43A9A1317}" = ARTEuro
"{1DBA14FA-90C0-455B-91FB-94B6CC649840}" = MotionSD STUDIO 1.1E
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2604C0F9-BFD3-4BA0-9EB5-22537C648F03}" = MobileMe Control Panel
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3846E811-639D-4DE1-844B-30491C0A6C0C}" = Dell Support 3.2
"{3AF89A79-EEF7-41C2-80C1-E62BF0801EEE}" = BlackBerry Desktop Software 4.2.2
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{66D171AA-670F-4309-9C74-5BA7F7DBA0B3}" = Roxio Media Manager
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{8CFC7570-DD90-486E-A239-E31D455BDE93}" = Microsoft LifeCam
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{958A793F-F1D2-4A90-B6A5-C52E2D74E8FE}" = AzureBay Screen Saver 3.4
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}" = Windows Live Sign-in Assistant
"{B0C5A4B9-396E-45AE-A774-2C6647CA4EF6}" = Panasonic SD Video Camera Web Driver
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7AC5A96-C8BC-431C-B661-27A09781DFA8}" = Wanadoo Europe Installer
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{DA15D535-5E1D-4076-B520-8571346D6238}" = Norton Security Scan
"{DC33D3D7-E641-4F17-A562-D572A1FD579B}" = Google Desktop MSN Plugin
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist
"{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}" = Star Wars Republic Commando
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"AoA DVD Ripper_is1" = AoA DVD Ripper
"AVG7Uninstall" = AVG Free Edition
"BlackBerry_{3AF89A79-EEF7-41C2-80C1-E62BF0801EEE}" = BlackBerry Desktop Software 4.2.2
"DrawPad for Google Desktop_is1" = DrawPad 0.8
"Google Desktop" = Google Desktop
"HijackThis" = HijackThis 2.0.2
"Homeworld2" = Homeworld2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates!
"InstallShield_{B0C5A4B9-396E-45AE-A774-2C6647CA4EF6}" = Panasonic SD Video Camera Web Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Connections Drivers
"prunnet" = Advertisement Service
"RealPlayer 6.0" = RealPlayer Basic
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"ShockwaveFlash" = Adobe Flash Player 9
"SmartMusic 9" = SmartMusic 9
"StreetPlugin" = Learn2 Player (Uninstall Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Vodafone 804SS USB driver" = SAMSUNG Mobile USB Modem ^^
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 19/12/2008 18:38:48 | Computer Name = THAYNEYDESKTOP | Source = RIMDeviceFileAccess | ID = 268379920
Description =

Error - 27/12/2008 17:57:18 | Computer Name = THAYNEYDESKTOP | Source = Windows Live Messenger | ID = 1000
Description =

Error - 05/01/2009 17:55:39 | Computer Name = THAYNEYDESKTOP | Source = Windows Search Service | ID = 3013
Description = The entry PLAYER\#SHAREDOBJECTS\W8UG9LQ2\S.YTIMG.COM\SOUNDDATA.SOL> in the hash map cannot
be updated. Context: Application, SystemIndex Catalog Details: A device attached
to the system is not functioning. (0x8007001f)

Error - 05/01/2009 17:55:39 | Computer Name = THAYNEYDESKTOP | Source = Windows Search Service | ID = 3013
Description = The entry PLAYER\#SHAREDOBJECTS\W8UG9LQ2\S.YTIMG.COM\SOUNDDATA.SOL> in the hash map cannot
be updated. Context: Application, SystemIndex Catalog Details: A device attached
to the system is not functioning. (0x8007001f)

Error - 07/01/2009 18:06:03 | Computer Name = THAYNEYDESKTOP | Source = RIMDeviceFileAccess | ID = 268379920
Description =

Error - 09/01/2009 17:45:41 | Computer Name = THAYNEYDESKTOP | Source = Windows Live Messenger | ID = 1000
Description =

Error - 09/01/2009 17:46:06 | Computer Name = THAYNEYDESKTOP | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16762, faulting
module ptnptn.dll, version 0.0.0.0, fault address 0x00001bfa.

Error - 09/01/2009 18:00:16 | Computer Name = THAYNEYDESKTOP | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16762, faulting
module ptnptn.dll, version 0.0.0.0, fault address 0x000022ed.

Error - 09/01/2009 18:01:56 | Computer Name = THAYNEYDESKTOP | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16762, faulting
module ptnptn.dll, version 0.0.0.0, fault address 0x00001c1e.

Error - 09/01/2009 18:02:03 | Computer Name = THAYNEYDESKTOP | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

[ System Events ]
Error - 10/01/2009 12:42:24 | Computer Name = THAYNEYDESKTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/01/2009 12:42:31 | Computer Name = THAYNEYDESKTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 10/01/2009 12:42:50 | Computer Name = THAYNEYDESKTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/01/2009 12:43:03 | Computer Name = THAYNEYDESKTOP | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31

Error - 10/01/2009 12:43:03 | Computer Name = THAYNEYDESKTOP | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31

Error - 10/01/2009 12:43:03 | Computer Name = THAYNEYDESKTOP | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31

Error - 10/01/2009 12:43:03 | Computer Name = THAYNEYDESKTOP | Source = Service Control Manager | ID = 7001
Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 10/01/2009 12:43:03 | Computer Name = THAYNEYDESKTOP | Source = Service Control Manager | ID = 7001
Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 10/01/2009 12:43:03 | Computer Name = THAYNEYDESKTOP | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 10/01/2009 12:43:03 | Computer Name = THAYNEYDESKTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Avg7Core Avg7RsW Avg7RsXP Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss StarOpen
Tcpip


< End of report >
hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    %windir%\system32\drivers\svchost.exe=-
    :Files
    C:\WINDOWS\System32\ma1
    C:\Documents and Settings\Thayney\Local Settings\Application Data\.#
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Here is the OTMoveIt3 log: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\drivers\svchost.exe deleted successfully. ========== FILES ========== C:\WINDOWS\System32\ma1 moved successfully. C:\Documents and Settings\Thayney\Local Settings\Application Data\.# moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Thayney\LOCALS~1\Temp\~DFA4F5.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Thayney\LOCALS~1\Temp\~DFEE40.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01102009_204255 Files moved on Reboot… C:\DOCUME~1\Thayney\LOCALS~1\Temp\~DFA4F5.tmp moved successfully. C:\DOCUME~1\Thayney\LOCALS~1\Temp\~DFEE40.tmp moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
A I don't have Internet Explorer on the infected PC, is there anyway to run the Online Kapersky Scan without actually going online (saving to a memory stick?) Thanks, t-man7

Update: Progress is seen!! I can open internet explorer and it is not exited at all. Now I will be able to perform the kapersky scan, which will be posted after the Mbam log. Thanks, t-man7
As requested, the Mbam log, however it did tell me to reboot so it could delete two files - and an error window appeared telling me the windows station was shutting down. (this is a symptom of the virus) so am not totally sure if Mbam did delete the files.

Malwarebytes' Anti-Malware 1.32
Database version: 1616
Windows 5.1.2600 Service Pack 3

11/01/2009 10:52:31
mbam-log-2009-01-11 (10-52-31).txt

Scan type: Quick Scan
Objects scanned: 60012
Time elapsed: 5 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prunnet (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Thayney\Application Data\Google\ptnptn.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\Documents and Settings\Thayney\Application Data\Google\jxzub5410451.exe (Trojan.FakeAlert) -> Delete on reboot.

Edit: Kapersky report log:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, January 11, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, January 11, 2009 11:26:41
Records in database: 1602210
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\

Scan statistics:
Files scanned: 78568
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:35:15


File name / Threat name / Threats count
C:\Documents and Settings\Thayney\Desktop\ithelpdesk.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c 1

The selected area was scanned.
hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\Thayney\Application Data\Google\ptnptn.dll 
    C:\Documents and Settings\Thayney\Application Data\Google\jxzub5410451.exe
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Also post a new HJT Log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI