This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google search brings up wrong webpages

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Sorry, I meant to ask you to .zip it first, like we did the other one. Right-click and Send To >> Compressed Folder - upload that one.

By the way, have you installed Avira? Having multiple AntiViruses may seem like a good idea, but multiple AntiVirus programs running at the same time can conflict with each other as well as slowing your system down unnecessarily. I recommend you pick one of them and remove the other.

Thanks.
Hi there,

OK, that is definitely suspicious. Please do the following:

1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

@echo off
del /Q "c:\documents and settings\administrator\application data\mozilla\firefox\profiles\n7xx419v.default\extensions.ini"
echo [ExtensionDirs]>"c:\documents and settings\administrator\application data\mozilla\firefox\profiles\n7xx419v.default\extensions.ini"
echo Extension0=C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}>>"c:\documents and settings\administrator\application data\mozilla\firefox\profiles\n7xx419v.default\extensions.ini"
echo [ThemeDirs]>>"c:\documents and settings\administrator\application data\mozilla\firefox\profiles\n7xx419v.default\extensions.ini"
echo Extension0=C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}>>"c:\documents and settings\administrator\application data\mozilla\firefox\profiles\n7xx419v.default\extensions.ini"

ren "C:\Program Files\Mozilla Firefox\extensions\{D96F1D71-4F95-443A-8AF3-541BFDBA096D}" "{D96F1D71-4F95-443A-8AF3-541BFDBA096D}.bak"
del /Q "C:\Program Files\Mozilla Firefox\extensions\_D96F1D71-4F95-443A-8AF3-541BFDBA096D_.zip"

Start DDS.scr /ihatewhitelists

del /Q %0

3. Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes. Once saved, the icon to click should look like this on your desktop: [external image: Posted Image]

4. Close all Firefox Windows. Wait for 10 seconds after closing them.

5. Double click fix.bat.

6. DDS will start. When it finished, please restart Firefox and post the resulting log (DDS.txt). Please check for redirects.

Thanks.
DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 15:08:42.90 on 10/02/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1516 [GMT 0:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Vtune\TBPanel.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\DNA\btdna.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\RALINK\Common\RaUI.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\AVG\AVG8\avgui.exe C:\Program Files\iTunes\iTunes.exe C:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.co.uk/ uSearch Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch mDefault_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 mDefault_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 mSearch Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 mLocal Page = %SystemRoot%\system32\blank.htm mStart Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 uInternet Connection Wizard,ShellNext = hxxp://windowsupdate.microsoft.com/ uInternet Settings,ProxyOverride = *.local mSearchAssistant = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm mCustomizeSearch = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm uURLSearchHooks: Microsoft Url Search Hook: {cfbfae00-17a6-11d0-99cb-00c04fd64497} - c:\windows\system32\ieframe.dll mWinlogon: Shell=Explorer.exe mWinlogon: Userinit=c:\windows\system32\userinit.exe, mWinlogon: UIHost=logonui.exe mWinlogon: SFCDisable=0 (0x0) BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll EB: &Tip of the Day: {4d5c8c25-d075-11d0-b416-00c04fb90376} - %SystemRoot%\system32\shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [TBPanel] c:\program files\vtune\TBPanel.exe /A uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [Comrade.exe] c:\program files\gamespy\comrade\Comrade.exe uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe uPolicies-explorer: NoDriveTypeAutoRun = 145 (0x91) mPolicies-system: dontdisplaylastusername = 0 (0x0) mPolicies-system: legalnoticecaption = mPolicies-system: legalnoticetext = mPolicies-system: shutdownwithoutlogon = 1 (0x1) mPolicies-system: undockwithoutlogon = 1 (0x1) dPolicies-explorer: NoDriveTypeAutoRun = 145 (0x91) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: %SystemRoot%\system32\mswsock.dll LSP: %SystemRoot%\system32\rsvpsp.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201162107984 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab TCP: {60D251E4-B862-469B-A1B4-7554C9CDF31A} = 192.168.0.1 Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - c:\windows\system32\mscoree.dll Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - c:\windows\system32\mscoree.dll Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - c:\windows\system32\mscoree.dll Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - c:\windows\system32\urlmon.dll Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - c:\windows\system32\urlmon.dll Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - c:\windows\system32\msvidctl.dll Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - c:\progra~1\wi1f86~1\messen~1\MSGRAP~1.DLL Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - c:\progra~1\wi1f86~1\messen~1\MSGRAP~1.DLL Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - c:\windows\system32\msvidctl.dll Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - c:\windows\system32\wiascr.dll Name-Space Handler: mk\* - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll Notify: crypt32chain - crypt32.dll Notify: cryptnet - cryptnet.dll Notify: cscdll - cscdll.dll Notify: igfxcui - igfxdev.dll Notify: ScCertProp - wlnotify.dll Notify: Schedule - wlnotify.dll Notify: sclgntfy - sclgntfy.dll Notify: SensLogn - WlNotify.dll Notify: termsrv - wlnotify.dll Notify: WgaLogon - WgaLogon.dll Notify: wlballoon - wlnotify.dll AppInit_DLLs: avgrsstx.dll SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - c:\windows\system32\webcheck.dll SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - c:\windows\system32\stobject.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll STS: Browseui preloader: {438755c2-a8ba-11d1-b96b-00a0c90312e1} - %SystemRoot%\system32\browseui.dll STS: Component Categories cache daemon: {8c7461ef-2b13-11d2-be35-3078302c2030} - %SystemRoot%\system32\browseui.dll SEH: URL Exec Hook: {aeb6717e-7e19-11d0-97ee-00c04fd91972} - shell32.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll LSA: Authentication Packages = msv1_0 LSA: Notification Packages = scecli SubSystems: Windows = basesrv ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\jhtjlx45.default\ FF - component: c:\program files\mozilla firefox\components\browserdirprovider.dll FF - component: c:\program files\mozilla firefox\components\brwsrcmp.dll FF - plugin: c:\program files\divx\divx player\npDivxPlayerPlugin.dll FF - plugin: c:\program files\divx\divx web player\npdivx32.dll FF - plugin: c:\program files\dna\plugins\npbtdna.dll FF - plugin: c:\program files\itunes\mozilla plugins\npitunes.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeploytk.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeploytk.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdivx32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npDivxPlayerPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npLegitCheckPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npnul32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin3.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin4.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin5.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin6.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin7.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin2.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin3.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin4.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin5.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin6.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin7.dll FF - plugin: c:\program files\windows media player\npdrmv2.dll FF - plugin: c:\program files\windows media player\npdsplay.dll FF - plugin: c:\program files\windows media player\npwmsdrm.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32.dll —- Add-ons/Extensions Installed —- Default Java Console Java Quick Starter ============= SERVICES / DRIVERS =============== R0 ACPI;Microsoft ACPI Driver;c:\windows\system32\drivers\acpi.sys [2004-8-4 187776] R0 atapi;Standard IDE/ESDI Hard Disk Controller;c:\windows\system32\drivers\atapi.sys [2004-8-4 95360] R0 Disk;Disk Driver;c:\windows\system32\drivers\disk.sys [2004-8-4 36352] R0 dmio;Logical Disk Manager Driver;c:\windows\system32\drivers\dmio.sys [2004-8-4 153344] R0 dmload;dmload;c:\windows\system32\drivers\dmload.sys [2001-8-17 5888] R0 FltMgr;FltMgr;c:\windows\system32\drivers\fltmgr.sys [2004-8-4 128896] R0 Ftdisk;Volume Manager Driver;c:\windows\system32\drivers\ftdisk.sys [2001-8-17 125056] R0 isapnp;PnP ISA/EISA Bus Driver;c:\windows\system32\drivers\isapnp.sys [2001-8-17 35840] R0 KSecDD;KSecDD;c:\windows\system32\drivers\ksecdd.sys [2008-1-24 92032] R0 MountMgr;MountMgr;c:\windows\system32\drivers\mountmgr.sys [2004-8-4 42240] R0 Mup;Mup;c:\windows\system32\drivers\mup.sys [2004-8-4 107904] R0 NDIS;NDIS System Driver;c:\windows\system32\drivers\ndis.sys [2004-8-4 182912] R0 PartMgr;PartMgr;c:\windows\system32\drivers\partmgr.sys [2001-8-18 18688] R0 PCI;PCI Bus Driver;c:\windows\system32\drivers\pci.sys [2004-8-4 68224] R0 PCIIde;PCIIde;c:\windows\system32\drivers\pciide.sys [2001-8-17 3328] R0 PxHelp20;PxHelp20;c:\windows\system32\drivers\PxHelp20.sys [2008-12-20 43528] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-1-14 717296] R0 sr;System Restore Filter Driver;c:\windows\system32\drivers\sr.sys [2004-8-4 73472] R0 VolSnap;VolSnap;c:\windows\system32\drivers\volsnap.sys [2004-8-4 52352] R1 AFD;AFD;c:\windows\system32\drivers\afd.sys [2004-8-4 138368] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-17 96520] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-8-17 26824] R1 Beep;Beep;c:\windows\system32\drivers\beep.sys [2001-8-17 4224] R1 Cdrom;CD-ROM Driver;c:\windows\system32\drivers\cdrom.sys [2004-8-4 49536] R1 Fips;Fips;c:\windows\system32\drivers\fips.sys [2001-8-18 34944] R1 i8042prt;i8042 Keyboard and PS/2 Mouse Port Driver;c:\windows\system32\drivers\i8042prt.sys [2004-8-4 52736] R1 intelppm;Intel Processor Driver;c:\windows\system32\drivers\intelppm.sys [2004-8-4 36096] R1 IPSec;IPSEC driver;c:\windows\system32\drivers\ipsec.sys [2004-8-4 74752] R1 Kbdclass;Keyboard Class Driver;c:\windows\system32\drivers\kbdclass.sys [2004-8-4 24576] R1 mnmdd;mnmdd;c:\windows\system32\drivers\mnmdd.sys [2001-8-17 4224] R1 Mouclass;Mouse Class Driver;c:\windows\system32\drivers\mouclass.sys [2004-8-4 23040] R1 MRxSmb;MRXSMB;c:\windows\system32\drivers\mrxsmb.sys [2004-8-4 453632] R1 Msfs;Msfs;c:\windows\system32\drivers\msfs.sys [2004-8-4 19072] R1 NetBIOS;NetBIOS Interface;c:\windows\system32\drivers\netbios.sys [2004-8-4 34560] R1 NetBT;NetBios over Tcpip;c:\windows\system32\drivers\netbt.sys [2004-8-4 162816] R1 Npfs;Npfs;c:\windows\system32\drivers\npfs.sys [2004-8-4 30848] R1 Null;Null;c:\windows\system32\drivers\null.sys [2001-8-17 2944] R1 RasAcd;Remote Access Auto Connection Driver;c:\windows\system32\drivers\rasacd.sys [2001-8-17 8832] R1 Rdbss;Rdbss;c:\windows\system32\drivers\rdbss.sys [2004-8-4 174592] R1 RDPCDD;RDPCDD;c:\windows\system32\drivers\rdpcdd.sys [2001-8-17 4224] R1 redbook;Digital CD Audio Playback Filter Driver;c:\windows\system32\drivers\redbook.sys [2008-1-24 57472] R1 SCDEmu;SCDEmu;c:\windows\system32\drivers\scdemu.sys [2008-11-2 56572] R1 Serial;Serial port driver;c:\windows\system32\drivers\serial.sys [2004-8-4 64896] R1 Tcpip;TCP/IP Protocol Driver;c:\windows\system32\drivers\tcpip.sys [2004-8-4 360320] R1 TermDD;Terminal Device Driver;c:\windows\system32\drivers\termdd.sys [2004-8-4 40840] R1 VgaSave;VgaSave;c:\windows\system32\drivers\vga.sys [2004-8-4 20992] R1 WmiAcpi;Microsoft Windows Management Interface for ACPI;c:\windows\system32\drivers\wmiacpi.sys [2008-1-24 8832] R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0;c:\windows\system32\drivers\AegisP.sys [2008-8-14 21275] R2 Apple Mobile Device;Apple Mobile Device;c:\program files\common files\apple\mobile device support\bin\AppleMobileDeviceService.exe [2008-11-7 132424] R2 AudioSrv;Windows Audio;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-8-17 873752] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-17 231192] R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-8-17 76040] R2 Bonjour Service;Bonjour Service;c:\program files\bonjour\mDNSResponder.exe [2008-8-29 238888] R2 CryptSvc;Cryptographic Services;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 DcomLaunch;DCOM Server Process Launcher;c:\windows\system32\svchost -k dcomlaunch –> c:\windows\system32\svchost -k DcomLaunch [?] R2 Dhcp;DHCP Client;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 dmserver;Logical Disk Manager;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 Dnscache;DNS Client;c:\windows\system32\svchost.exe -k NetworkService [2004-8-4 14336] R2 ERSvc;Error Reporting Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 Eventlog;Event Log;c:\windows\system32\services.exe [2004-8-4 108032] R2 helpsvc;Help and Support;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 HidServ;HID Input Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 JavaQuickStarterService;Java Quick Starter;c:\program files\java\jre6\bin\jqs.exe [2009-2-9 152984] R2 lanmanserver;Server;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 lanmanworkstation;Workstation;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 LmHosts;TCP/IP NetBIOS Helper;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R2 nvcap;nVidia WDM Video Capture (universal);c:\windows\system32\drivers\NVCAP.SYS [2008-12-3 141246] R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2008-12-11 3575808] R2 NVSvc;NVIDIA Display Driver Service;c:\windows\system32\nvsvc32.exe [2008-9-11 163908] R2 NVXBAR;nVidia WDM A/V Crossbar;c:\windows\system32\drivers\NVXBAR.SYS [2008-12-3 16176] R2 PlugPlay;Plug and Play;c:\windows\system32\services.exe [2004-8-4 108032] R2 PnkBstrA;PnkBstrA;c:\windows\system32\PnkBstrA.exe [2008-8-16 66872] R2 PolicyAgent;IPSEC Services;c:\windows\system32\lsass.exe [2004-8-4 13312] R2 ProtectedStorage;Protected Storage;c:\windows\system32\lsass.exe [2004-8-4 13312] R2 RemoteRegistry;Remote Registry;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R2 RpcSs;Remote Procedure Call (RPC);c:\windows\system32\svchost -k rpcss –> c:\windows\system32\svchost -k rpcss [?] R2 SamSs;Security Accounts Manager;c:\windows\system32\lsass.exe [2004-8-4 13312] R2 Schedule;Task Scheduler;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 seclogon;Secondary Logon;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 SENS;System Event Notification;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 SharedAccess;Windows Firewall/Internet Connection Sharing (ICS);c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 ShellHWDetection;Shell Hardware Detection;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 SoundMAX Agent Service (default);SoundMAX Agent Service;c:\program files\analog devices\soundmax\SMAgent.exe [2008-1-24 45056] R2 Spooler;Print Spooler;c:\windows\system32\spoolsv.exe [2004-8-4 57856] R2 srservice;System Restore Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 TBPanel;TBPanel;c:\windows\system32\drivers\TBPanel.sys [2008-12-2 12256] R2 Themes;Themes;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 TrkWks;Distributed Link Tracking Client;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 W32Time;Windows Time;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 WebClient;WebClient;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R2 winmgmt;Windows Management Instrumentation;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 wscsvc;Security Center;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 aeaudio;aeaudio;c:\windows\system32\drivers\aeaudio.sys [2008-1-24 100384] R3 ALG;Application Layer Gateway Service;c:\windows\system32\alg.exe [2004-8-4 44544] R3 audstub;Audio Stub Driver;c:\windows\system32\drivers\audstub.sys [2001-8-17 3072] R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet;c:\windows\system32\drivers\b57xp32.sys [2008-1-24 186112] R3 EventSystem;COM+ Event System;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 FastUserSwitchingCompatibility;Fast User Switching Compatibility;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 Fdc;Floppy Disk Controller Driver;c:\windows\system32\drivers\fdc.sys [2004-8-4 27392] R3 GEARAspiWDM;GEAR ASPI Filter Driver;c:\windows\system32\drivers\GEARAspiWDM.sys [2008-1-29 15464] R3 Gpc;Generic Packet Classifier;c:\windows\system32\drivers\msgpc.sys [2004-8-4 35072] R3 HidUsb;Microsoft HID Class Driver;c:\windows\system32\drivers\hidusb.sys [2008-1-24 9600] R3 HTTP;HTTP;c:\windows\system32\drivers\http.sys [2004-8-4 262784] R3 HTTPFilter;HTTP SSL;c:\windows\system32\svchost.exe -k HTTPFilter [2004-8-4 14336] R3 IpNat;IP Network Address Translator;c:\windows\system32\drivers\ipnat.sys [2004-8-4 134912] R3 iPod Service;iPod Service;c:\program files\ipod\bin\iPodService.exe [2008-11-20 536872] R3 kmixer;Microsoft Kernel Wave Audio Mixer;c:\windows\system32\drivers\kmixer.sys [2004-8-4 172416] R3 mouhid;Mouse HID Driver;c:\windows\system32\drivers\mouhid.sys [2008-1-24 12160] R3 MRxDAV;WebDav Client Redirector;c:\windows\system32\drivers\mrxdav.sys [2004-8-4 181248] R3 mssmbios;Microsoft System Management BIOS Driver;c:\windows\system32\drivers\mssmbios.sys [2004-8-4 15488] R3 NdisTapi;Remote Access NDIS TAPI Driver;c:\windows\system32\drivers\ndistapi.sys [2001-8-17 9600] R3 NdisWan;Remote Access NDIS WAN Driver;c:\windows\system32\drivers\ndiswan.sys [2004-8-4 91776] R3 NDProxy;NDIS Proxy;c:\windows\system32\drivers\ndproxy.sys [2001-8-17 38016] R3 Netman;Network Connections;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 Nla;Network Location Awareness (NLA);c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 nv;nv;c:\windows\system32\drivers\nv4_mini.sys [2008-9-11 6301344] R3 Parport;Parallel port driver;c:\windows\system32\drivers\parport.sys [2004-8-4 80128] R3 PptpMiniport;WAN Miniport (PPTP);c:\windows\system32\drivers\raspptp.sys [2004-8-4 48384] R3 PSched;QoS Packet Scheduler;c:\windows\system32\drivers\psched.sys [2004-8-4 69120] R3 Ptilink;Direct Parallel Link Driver;c:\windows\system32\drivers\ptilink.sys [2001-8-17 17792] R3 RasAuto;Remote Access Auto Connection Manager;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 Rasl2tp;WAN Miniport (L2TP);c:\windows\system32\drivers\rasl2tp.sys [2004-8-4 51328] R3 RasMan;Remote Access Connection Manager;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 RasPppoe;Remote Access PPPOE Driver;c:\windows\system32\drivers\raspppoe.sys [2004-8-4 41472] R3 Raspti;Direct Parallel;c:\windows\system32\drivers\raspti.sys [2001-8-17 16512] R3 rdpdr;Terminal Server Device Redirector Driver;c:\windows\system32\drivers\rdpdr.sys [2004-8-4 196864] R3 RT73;RT73 USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt73.sys [2008-8-14 344064] R3 serenum;Serenum Filter Driver;c:\windows\system32\drivers\serenum.sys [2004-8-4 15488] R3 smwdm;smwdm;c:\windows\system32\drivers\smwdm.sys [2008-1-24 612416] R3 Srv;Srv;c:\windows\system32\drivers\srv.sys [2004-8-4 333056] R3 SSDPSRV;SSDP Discovery Service;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R3 swenum;Software Bus Driver;c:\windows\system32\drivers\swenum.sys [2004-8-4 4352] R3 sysaudio;Microsoft Kernel System Audio Device;c:\windows\system32\drivers\sysaudio.sys [2004-8-4 60800] R3 TapiSrv;Telephony;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 TermService;Terminal Services;c:\windows\system32\svchost -k dcomlaunch –> c:\windows\system32\svchost -k DComLaunch [?] R3 Update;Microcode Update Driver;c:\windows\system32\drivers\update.sys [2004-8-4 364160] R3 upnphost;Universal Plug and Play Device Host;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver;c:\windows\system32\drivers\usbehci.sys [2008-1-24 26624] R3 usbhub;USB2 Enabled Hub;c:\windows\system32\drivers\usbhub.sys [2004-8-4 57600] R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver;c:\windows\system32\drivers\usbuhci.sys [2004-8-4 20480] R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\windows live\messenger\usnsvc.exe [2007-10-18 98328] R3 Wanarp;Remote Access IP ARP Driver;c:\windows\system32\drivers\wanarp.sys [2004-8-4 34560] R3 wdmaud;Microsoft WINMM WDM Audio Compatibility Driver;c:\windows\system32\drivers\wdmaud.sys [2004-8-4 82944] R4 Cdfs;Cdfs;c:\windows\system32\drivers\cdfs.sys [2004-8-4 63744] R4 Ntfs;Ntfs;c:\windows\system32\drivers\ntfs.sys [2008-1-24 574464] S1 Cdaudio;Cdaudio;c:\windows\system32\drivers\cdaudio.sys [2004-8-4 18688] S1 Changer;Changer; [x] S1 i2omgmt;i2omgmt; [x] S1 Imapi;CD-Burning Filter Driver;c:\windows\system32\drivers\imapi.sys [2004-8-4 41856] S1 kbdhid;Keyboard HID Driver;c:\windows\system32\drivers\kbdhid.sys [2008-7-25 14848] S1 lbrtfdc;lbrtfdc; [x] S1 P3;Intel PentiumIII Processor Driver;c:\windows\system32\drivers\p3.sys [2004-8-4 42496] S1 PCIDump;PCIDump; [x] S2 Browser;Computer Browser;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 ac97intc;Intel® 82801 Audio Driver Install Service (WDM);c:\windows\system32\drivers\ac97intc.sys [2001-8-17 96256] S3 aec;Microsoft Kernel Acoustic Echo Canceller;c:\windows\system32\drivers\aec.sys [2004-8-4 142464] S3 AppMgmt;Application Management;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 aspnet_state;ASP.NET State Service;c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800] S3 AsyncMac;RAS Asynchronous Media Driver;c:\windows\system32\drivers\asyncmac.sys [2004-8-4 14336] S3 Atmarpc;ATM ARP Client Protocol;c:\windows\system32\drivers\atmarpc.sys [2004-8-4 59904] S3 BITS;Background Intelligent Transfer Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 Blfp;Broadcom Advanced Server Program Driver;c:\windows\system32\drivers\baspxp32.sys [2004-2-4 51584] S3 CCDECODE;Closed Caption Decoder;c:\windows\system32\drivers\CCDECODE.sys [2008-12-5 17024] S3 CiSvc;Indexing Service;c:\windows\system32\cisvc.exe [2004-8-4 5632] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86;c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144] S3 COMSysApp;COM+ System Application;c:\windows\system32\dllhost.exe [2004-8-4 5120] S3 dmadmin;Logical Disk Manager Administrative Service;c:\windows\system32\dmadmin.exe [2004-8-4 224768] S3 DMusic;Microsoft Kernel DLS Syntheiszer;c:\windows\system32\drivers\DMusic.sys [2004-8-4 52864] S3 drmkaud;Microsoft Kernel DRM Audio Descrambler;c:\windows\system32\drivers\drmkaud.sys [2004-8-4 2944] S3 E100B;Intel® PRO Adapter Driver;c:\windows\system32\drivers\e100b325.sys [2001-8-17 117760] S3 Flpydisk;Floppy Disk Driver;c:\windows\system32\drivers\flpydisk.sys [2004-8-4 20480] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;c:\windows\microsoft.net\framework\v3.0\wpf\PresentationFontCache.exe [2007-10-9 36864] S3 gmer;gmer;c:\windows\system32\drivers\gmer.sys [2009-2-9 85969] S3 i81x;i81x;c:\windows\system32\drivers\i81xnt5.sys [2004-8-4 161020] S3 iAimFP0;iAimFP0;c:\windows\system32\drivers\wADV01nt.sys [2004-8-4 12415] S3 iAimFP1;iAimFP1;c:\windows\system32\drivers\wADV02NT.sys [2004-8-4 12127] S3 iAimFP2;iAimFP2;c:\windows\system32\drivers\wADV05NT.sys [2004-8-4 11775] S3 iAimFP3;iAimFP3;c:\windows\system32\drivers\wSiINTxx.sys [2004-8-4 12063] S3 iAimFP4;iAimFP4;c:\windows\system32\drivers\wVchNTxx.sys [2004-8-4 19455] S3 iAimFP5;iAimFP5;c:\windows\system32\drivers\wADV07nt.sys [2004-8-4 11807] S3 iAimFP6;iAimFP6;c:\windows\system32\drivers\wADV08NT.sys [2004-8-4 11295] S3 iAimFP7;iAimFP7;c:\windows\system32\drivers\wADV09NT.sys [2004-8-4 11871] S3 iAimTV0;iAimTV0;c:\windows\system32\drivers\wATV01nt.sys [2004-8-4 29311] S3 iAimTV1;iAimTV1;c:\windows\system32\drivers\wATV02NT.sys [2004-8-4 19551] S3 iAimTV3;iAimTV3;c:\windows\system32\drivers\wATV04nt.sys [2004-8-4 33599] S3 iAimTV4;iAimTV4;c:\windows\system32\drivers\wCh7xxNT.sys [2004-8-4 23615] S3 iAimTV5;iAimTV5;c:\windows\system32\drivers\wATV10nt.sys [2004-8-4 25471] S3 iAimTV6;iAimTV6;c:\windows\system32\drivers\wATV06nt.sys [2004-8-4 22271] S3 ialm;ialm;c:\windows\system32\drivers\ialmnt5.sys [2004-5-6 1302332] S3 IDriverT;InstallDriver Table Manager;c:\program files\common files\installshield\driver\11\intel 32\IDriverT.exe [2005-4-4 69632] S3 idsvc;Windows CardSpace;c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe [2007-10-11 864256] S3 ImapiService;IMAPI CD-Burning COM Service;c:\windows\system32\imapi.exe [2004-8-4 150016] S3 Ip6Fw;IPv6 Windows Firewall Driver;c:\windows\system32\drivers\ip6fw.sys [2004-8-4 29056] S3 IpFilterDriver;IP Traffic Filter Driver;c:\windows\system32\drivers\ipfltdrv.sys [2001-8-17 32896] S3 IpInIp;IP in IP Tunnel Driver;c:\windows\system32\drivers\ipinip.sys [2004-8-4 20992] S3 IRENUM;IR Enumerator Service;c:\windows\system32\drivers\irenum.sys [2004-8-4 11264] S3 mnmsrvc;NetMeeting Remote Desktop Sharing;c:\windows\system32\mnmsrvc.exe [2004-8-4 32768] S3 Modem;Modem;c:\windows\system32\drivers\modem.sys [2004-8-4 30080] S3 MSDTC;Distributed Transaction Coordinator;c:\windows\system32\msdtc.exe [2004-8-4 6144] S3 MSIServer;Windows Installer;c:\windows\system32\msiexec.exe [2004-8-4 78848] S3 MSKSSRV;Microsoft Streaming Service Proxy;c:\windows\system32\drivers\MSKSSRV.sys [2004-8-4 7552] S3 MSPCLOCK;Microsoft Streaming Clock Proxy;c:\windows\system32\drivers\MSPCLOCK.sys [2004-8-4 5376] S3 MSPQM;Microsoft Streaming Quality Manager Proxy;c:\windows\system32\drivers\MSPQM.sys [2004-8-4 4992] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter;c:\windows\system32\drivers\MSTEE.sys [2008-12-5 5504] S3 NABTSFEC;NABTS/FEC VBI Codec;c:\windows\system32\drivers\NABTSFEC.sys [2008-12-5 85376] S3 NdisIP;Microsoft TV/Video Connection;c:\windows\system32\drivers\NdisIP.sys [2008-12-5 10880] S3 Ndisuio;NDIS Usermode I/O Protocol;c:\windows\system32\drivers\ndisuio.sys [2004-8-4 12928] S3 Netlogon;Net Logon;c:\windows\system32\lsass.exe [2004-8-4 13312] S3 NtLmSsp;NT LM Security Support Provider;c:\windows\system32\lsass.exe [2004-8-4 13312] S3 NtmsSvc;Removable Storage;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 NwlnkFlt;IPX Traffic Filter Driver;c:\windows\system32\drivers\nwlnkflt.sys [2001-8-17 12416] S3 NwlnkFwd;IPX Traffic Forwarder Driver;c:\windows\system32\drivers\nwlnkfwd.sys [2001-8-17 32512] S3 PDCOMP;PDCOMP; [x] S3 PDFRAME;PDFRAME; [x] S3 PDRELI;PDRELI; [x] S3 PDRFRAME;PDRFRAME; [x] S3 RDPWD;RDPWD;c:\windows\system32\drivers\rdpwd.sys [2004-8-4 139528] S3 RDSessMgr;Remote Desktop Help Session Manager;c:\windows\system32\sessmgr.exe [2004-8-4 140800] S3 RpcLocator;Remote Procedure Call (RPC) Locator;c:\windows\system32\locator.exe [2004-8-4 75264] S3 RSVP;QoS RSVP;c:\windows\system32\rsvp.exe [2001-8-18 132608] S3 SCardSvr;Smart Card;c:\windows\system32\scardsvr.exe [2004-8-4 95744] S3 Secdrv;Secdrv;c:\windows\system32\drivers\secdrv.sys [2004-7-17 20480] S3 Sfloppy;High-Capacity Floppy Disk Drive;c:\windows\system32\drivers\sfloppy.sys [2004-8-4 11392] S3 SLIP;BDA Slip De-Framer;c:\windows\system32\drivers\SLIP.sys [2008-12-5 11136] S3 splitter;Microsoft Kernel Audio Splitter;c:\windows\system32\drivers\splitter.sys [2004-8-4 6400] S3 stisvc;Windows Image Acquisition (WIA);c:\windows\system32\svchost.exe -k imgsvc [2004-8-4 14336] S3 streamip;BDA IPSink;c:\windows\system32\drivers\StreamIP.sys [2008-12-5 15360] S3 swmidi;Microsoft Kernel GS Wavetable Synthesizer;c:\windows\system32\drivers\swmidi.sys [2001-8-17 54272] S3 SwPrv;MS Software Shadow Copy Provider;c:\windows\system32\dllhost.exe [2004-8-4 5120] S3 SysmonLog;Performance Logs and Alerts;c:\windows\system32\smlogsvc.exe [2004-8-4 89600] S3 TDPIPE;TDPIPE;c:\windows\system32\drivers\tdpipe.sys [2004-8-4 12040] S3 TDTCP;TDTCP;c:\windows\system32\drivers\tdtcp.sys [2004-8-4 21896] S3 UPS;Uninterruptible Power Supply;c:\windows\system32\ups.exe [2004-8-4 18432] S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [2008-8-17 32000] S3 usbccgp;Microsoft USB Generic Parent Driver;c:\windows\system32\drivers\usbccgp.sys [2008-7-25 31616] S3 USBSTOR;USB Mass Storage Driver;c:\windows\system32\drivers\USBSTOR.SYS [2008-1-25 26496] S3 VSS;Volume Shadow Copy;c:\windows\system32\vssvc.exe [2004-8-4 289792] S3 Wdf01000;Wdf01000;c:\windows\system32\drivers\wdf01000.sys [2006-4-20 479200] S3 WDICA;WDICA; [x] S3 WLSetupSvc;Windows Live Setup Service;c:\program files\windows live\installer\WLSetupSvc.exe [2007-10-25 266240] S3 WmdmPmSN;Portable Media Serial Number Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 Wmi;Windows Management Instrumentation Driver Extensions;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 WmiApSrv;WMI Performance Adapter;c:\windows\system32\wbem\wmiapsrv.exe [2004-8-4 126464] S3 WMPNetworkSvc;Windows Media Player Network Sharing Service;c:\program files\windows media player\wmpnetwk.exe [2006-10-18 913408] S3 WSTCODEC;World Standard Teletext Codec;c:\windows\system32\drivers\WSTCODEC.SYS [2008-12-5 19328] S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver;c:\windows\system32\drivers\WudfPf.sys [2006-9-28 77568] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector;c:\windows\system32\drivers\WudfRd.sys [2006-9-28 82944] S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework;c:\windows\system32\svchost.exe -k WudfServiceGroup [2004-8-4 14336] S3 WZCSVC;Wireless Zero Configuration;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 xmlprov;Network Provisioning Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21;c:\windows\system32\drivers\xusb21.sys [2008-12-25 61984] S4 Abiosdsk;Abiosdsk; [x] S4 abp480n5;abp480n5; [x] S4 ACPIEC;ACPIEC;c:\windows\system32\drivers\acpiec.sys [2001-8-17 11648] S4 adpu160m;adpu160m;c:\windows\system32\drivers\adpu160m.sys [2001-8-17 101888] S4 adpu320;adpu320;c:\windows\system32\drivers\adpu320.sys [2002-5-9 105472] S4 Aha154x;Aha154x; [x] S4 aic78u2;aic78u2;c:\windows\system32\drivers\aic78u2.sys [2001-8-17 55168] S4 aic78xx;aic78xx;c:\windows\system32\drivers\aic78xx.sys [2001-8-17 56960] S4 Alerter;Alerter;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] S4 AliIde;AliIde; [x] S4 amsint;amsint; [x] S4 asc;asc; [x] S4 asc3350p;asc3350p; [x] S4 asc3550;asc3550; [x] S4 Atdisk;Atdisk; [x] S4 cbidf2k;cbidf2k;c:\windows\system32\drivers\cbidf2k.sys [2001-8-17 13952] S4 cd20xrnt;cd20xrnt; [x] S4 ClipSrv;ClipBook;c:\windows\system32\clipsrv.exe [2004-8-4 33280] S4 CmdIde;CmdIde; [x] S4 Cpqarray;Cpqarray; [x] S4 dac960nt;dac960nt; [x] S4 dmboot;dmboot;c:\windows\system32\drivers\dmboot.sys [2004-8-4 799744] S4 dpti2o;dpti2o;c:\windows\system32\drivers\dpti2o.sys [2001-8-17 20192] S4 Fastfat;Fastfat;c:\windows\system32\drivers\fastfat.sys [2004-8-4 143360] S4 hpn;hpn; [x] S4 i2omp;i2omp; [x] S4 ini910u;ini910u; [x] S4 IntelIde;IntelIde;c:\windows\system32\drivers\intelide.sys [2004-8-4 5504] S4 Messenger;Messenger;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S4 mraid35x;mraid35x; [x] S4 NetDDE;Network DDE;c:\windows\system32\netdde.exe [2004-8-4 111104] S4 NetDDEdsdm;Network DDE DSDM;c:\windows\system32\netdde.exe [2004-8-4 111104] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"c:\windows\microsoft.net\framework\v3.0\windows communication foundation\SMSvcHost.exe" [2007-10-11 122880] S4 ParVdm;ParVdm;c:\windows\system32\drivers\parvdm.sys [2001-8-17 6784] S4 Pcmcia;Pcmcia;c:\windows\system32\drivers\pcmcia.sys [2004-8-4 119936] S4 perc2;perc2; [x] S4 perc2hib;perc2hib; [x] S4 ql1080;ql1080; [x] S4 Ql10wnt;Ql10wnt; [x] S4 ql12160;ql12160; [x] S4 ql1240;ql1240; [x] S4 ql1280;ql1280; [x] S4 RemoteAccess;Routing and Remote Access;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S4 Simbad;Simbad; [x] S4 Sparrow;Sparrow; [x] S4 sym_hi;sym_hi;c:\windows\system32\drivers\sym_hi.sys [2001-8-17 28384] S4 sym_u3;sym_u3;c:\windows\system32\drivers\sym_u3.sys [2001-8-17 30688] S4 symc810;symc810;c:\windows\system32\drivers\symc810.sys [2001-8-17 16256] S4 symc8xx;symc8xx;c:\windows\system32\drivers\symc8xx.sys [2001-8-17 32640] S4 Symmpi;Symmpi;c:\windows\system32\drivers\symmpi.sys [2004-8-10 28416] S4 TlntSvr;Telnet;c:\windows\system32\tlntsvr.exe [2004-8-4 73216] S4 TosIde;TosIde; [x] S4 Udfs;Udfs;c:\windows\system32\drivers\udfs.sys [2004-8-4 66176] S4 ultra;ultra; [x] S4 ViaIde;ViaIde;c:\windows\system32\drivers\viaide.sys [2004-8-4 5376] S4 wuauserv;Automatic Updates;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] ============== File Associations =============== batfile="%1" %* chm.file="c:\windows\hh.exe" %1 cmdfile="%1" %* comfile="%1" %* exefile="%1" %* inffile=%SystemRoot%\System32\NOTEPAD.EXE %1 inifile=%SystemRoot%\System32\NOTEPAD.EXE %1 JSEFile=%SystemRoot%\System32\WScript.exe "%1" %* piffile="%1" %* regedit=regedit.exe %1 regfile=regedit.exe "%1" scrfile="%1" /S txtfile=%SystemRoot%\system32\NOTEPAD.EXE %1 VBEFile=%SystemRoot%\System32\WScript.exe "%1" %* VBSFile=%SystemRoot%\System32\WScript.exe "%1" %* =============== Created Last 30 ================ 2009-02-09 22:00 –d—– c:\program files\Avira 2009-02-09 17:36 250 a——- c:\windows\gmer.ini 2009-02-09 17:36 884,736 a——- c:\windows\gmer.dll 2009-02-09 17:36 811,008 a——- c:\windows\gmer.exe 2009-02-09 17:36 85,969 a——- c:\windows\system32\drivers\gmer.sys 2009-02-09 17:36 80 a——- c:\windows\gmer_uninstall.cmd 2009-02-09 14:40 73,728 a——- c:\windows\system32\javacpl.cpl 2009-02-09 14:40 410,984 a——- c:\windows\system32\deploytk.dll 2009-02-09 14:40 148,888 a——- c:\windows\system32\javaws.exe 2009-02-09 14:40 144,792 a——- c:\windows\system32\javaw.exe 2009-02-09 14:40 144,792 a——- c:\windows\system32\java.exe 2009-02-09 14:23 -cd—– C:\_OTMoveIt 2009-02-09 01:44 -cd-hr– c:\documents and settings\administrator\Recent 2009-02-08 21:44 -cd—– c:\docume~1\admini~1\applic~1\Malwarebytes 2009-02-08 21:44 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-02-08 21:44 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-08 21:44 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-02-08 21:44 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-02-08 18:55 –d—– c:\program files\Spybot - Search & Destroy 2009-02-08 18:55 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-02-08 18:29 –d—– c:\program files\Windows Defender 2009-02-08 16:17 –d—– c:\program files\Trojan Remover 2009-02-08 16:00 -cd—– C:\VundoFix Backups 2009-02-07 17:51 -cd-h— C:\$AVG8.VAULT$ 2009-01-26 12:35 –d—– c:\docume~1\alluse~1\applic~1\Electronic Arts 2009-01-20 19:37 –d—– c:\docume~1\alluse~1\applic~1\Fallout3 2009-01-20 19:37 –d—– c:\program files\Bethesda Softworks 2009-01-20 19:35 –d—– c:\windows\system32\xlive 2009-01-20 02:16 -cd—– c:\docume~1\admini~1\applic~1\vlc 2009-01-20 01:30 –d—– c:\program files\Mozilla ActiveX Control v1.7.12 2009-01-20 01:06 -cd—– c:\docume~1\admini~1\applic~1\Graboid Inc 2009-01-16 16:31 268 ac–h— C:\sqmdata01.sqm 2009-01-16 16:31 244 ac–h— C:\sqmnoopt01.sqm 2009-01-14 22:25 –d—– c:\program files\Activision 2009-01-14 22:00 –dsh— c:\windows\ftpcache 2009-01-14 21:44 –d—– c:\program files\PowerISO 2009-01-14 21:42 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Pro 2009-01-14 21:42 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools 2009-01-14 21:41 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite 2009-01-14 21:40 –d—– c:\program files\DAEMON Tools Lite 2009-01-14 21:22 717,296 a——- c:\windows\system32\drivers\sptd.sys 2009-01-14 21:22 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Lite 2009-01-12 18:49 -cd—– c:\docume~1\admini~1\applic~1\DNA 2009-01-12 18:49 –d—– c:\program files\DNA 2009-01-11 15:13 1,456 a——- c:\windows\system32\ealregsnapshot1.reg ==================== Find3M ==================== 2009-02-10 15:08 48,906 a——- c:\windows\prefetch\WMIPRVSE.EXE-28F301A9.pf 2009-02-10 15:08 55,256 a——- c:\windows\prefetch\DDS.SCR-1E2538DD.pf 2009-02-10 15:08 5,114 a——- c:\windows\prefetch\EDS.EXE-127E2E21.pf 2009-02-10 15:08 13,558 a——- c:\windows\prefetch\SORT.EXE-194AE83C.pf 2009-02-10 15:08 13,062 a——- c:\windows\prefetch\FI.EXE-38C91696.pf 2009-02-10 15:08 37,998 a——- c:\windows\prefetch\CSCRIPT.EXE-1C26180C.pf 2009-02-10 15:08 9,248 a——- c:\windows\prefetch\WREGS.EXE-2BA81225.pf 2009-02-10 15:08 22,698 a——- c:\windows\prefetch\ETPATHS.EXE-33A5FCDB.pf 2009-02-10 15:08 13,528 a——- c:\windows\prefetch\FINDSTR.EXE-0CA6274B.pf 2009-02-10 15:08 12,180 a——- c:\windows\prefetch\FIND.EXE-0EC32F1E.pf 2009-02-10 15:08 61,440 a—h— c:\documents and settings\administrator\ntuser.dat.LOG 2009-02-10 15:08 15,948 a——- c:\windows\prefetch\CMD.EXE-087B4001.pf 2009-02-10 15:06 51,932 a——- c:\windows\prefetch\NOTEPAD.EXE-336351A9.pf 2009-02-10 15:00 10,116 a——- c:\windows\prefetch\AVGCMGR.EXE-1D29CBA8.pf 2009-02-10 14:51 25,426 a——- c:\windows\prefetch\RUNONCE.EXE-2803F297.pf 2009-02-10 14:51 17,736 a——- c:\windows\prefetch\RUNDLL32.EXE-20A8C272.pf 2009-02-10 14:51 15,476 a——- c:\windows\prefetch\REGSVR32.EXE-25EEFE2F.pf 2009-02-10 14:51 13,070 a——- c:\windows\prefetch\GRPCONV.EXE-111CD845.pf 2009-02-10 14:51 19,088 a——- c:\windows\prefetch\RUNDLL32.EXE-37EEC05D.pf 2009-02-10 14:51 32,420 a——- c:\windows\prefetch\AVWSC.EXE-347FCF75.pf 2009-02-10 14:50 22,290 a——- c:\windows\prefetch\VERCLSID.EXE-3667BD89.pf 2009-02-10 14:50 24,862 a——- c:\windows\prefetch\SETUP.EXE-3964771D.pf 2009-02-10 14:50 67,194 a——- c:\windows\prefetch\ANTIVIR_WORKSTATION_WINU_EN_H-0F73AF70.pf 2009-02-10 14:49 22,392 a——- c:\windows\prefetch\TASKMGR.EXE-20256C55.pf 2009-02-10 14:47 8,168 a——- c:\windows\prefetch\JQSNOTIFY.EXE-24AE4A36.pf 2009-02-10 14:41 37,398 a——- c:\windows\prefetch\WLLOGINPROXY.EXE-1781D844.pf 2009-02-10 14:41 72,146 a——- c:\windows\prefetch\IEXPLORE.EXE-27122324.pf 2009-02-10 14:23 30,598 a——- c:\windows\prefetch\AVZ.EXE-02BAEA71.pf 2009-02-10 14:23 47,210 a——- c:\windows\prefetch\WINRAR.EXE-39C6DAD9.pf 2009-02-10 14:10 123,144 a——- c:\windows\prefetch\ITUNES.EXE-1A268432.pf 2009-02-10 13:31 49,250 a——- c:\windows\prefetch\AVGSCANX.EXE-006AF2EC.pf 2009-02-10 13:25 35,116 a——- c:\windows\prefetch\AVGUPD.EXE-01C5DD2A.pf 2009-02-10 13:25 43,404 a——- c:\windows\prefetch\AVGUI.EXE-388E181A.pf 2009-02-10 13:24 38,228 a——- c:\windows\prefetch\AVGTRAY.EXE-17920267.pf 2009-02-10 13:24 45,502 a——- c:\windows\prefetch\SETUP.EXE-0CAF207E.pf 2009-02-10 13:06 44,278 a——- c:\windows\prefetch\MPCMDRUN.EXE-1F9D1CA1.pf 2009-02-10 13:00 29,286 a——- c:\windows\prefetch\CHECKER.EXE-1B259BA4.pf 2009-02-10 12:56 111,346 a——- c:\windows\prefetch\FIREFOX.EXE-28641590.pf 2009-02-10 12:56 66,404 a——- c:\windows\prefetch\USNSVC.EXE-2DF2835C.pf 2009-02-10 12:55 89,576 a——- c:\windows\prefetch\JAVA.EXE-0C263507.pf 2009-02-10 12:51 56,730 a——- c:\windows\prefetch\CSC.EXE-1113BFA6.pf 2009-02-10 12:51 5,942 a——- c:\windows\prefetch\CVTRES.EXE-13DEB540.pf 2009-02-10 12:51 23,728 a——- c:\windows\prefetch\RAUI.EXE-0812E922.pf 2009-02-10 12:51 81,676 a——- c:\windows\prefetch\MSNMSGR.EXE-030AB647.pf 2009-02-10 12:49 53,194 a——- c:\windows\prefetch\EXPLORER.EXE-082F38A9.pf 2009-02-10 12:49 43,024 a——- c:\windows\prefetch\WGATRAY.EXE-0ED38BED.pf 2009-02-10 12:49 15,306 a——- c:\windows\prefetch\USERINIT.EXE-30B18140.pf 2009-02-10 12:49 17,608 a——- c:\windows\prefetch\WSCNTFY.EXE-1B24F5EB.pf 2009-02-10 12:47 1,127,288 a——- c:\windows\prefetch\NTOSBOOT-B00DFAAD.pf 2009-02-10 12:46 2,048 a–s—- c:\windows\bootstat.dat 2009-02-10 12:46 792,723,456 a–sh— C:\pagefile.sys 2009-02-10 01:16 62,202 a——- c:\windows\prefetch\GUARDGUI.EXE-2C20A958.pf 2009-02-09 23:48 45,250 a——- c:\windows\prefetch\MBAM.EXE-0BEE0439.pf 2009-02-09 23:18 30,070 a——- c:\windows\prefetch\RUNDLL32.EXE-1340EF7F.pf 2009-02-09 23:18 15,494 a——- c:\windows\prefetch\XBOXSTAT.EXE-30BFD955.pf 2009-02-09 23:18 12,976 a——- c:\windows\prefetch\SMTRAY.EXE-025A616B.pf 2009-02-09 23:18 8,578 a——- c:\windows\prefetch\SETREFRESH.EXE-0C1D851C.pf 2009-02-09 23:18 30,386 a——- c:\windows\prefetch\RUNDLL32.EXE-35A483DA.pf 2009-02-09 23:18 24,558 a——- c:\windows\prefetch\RUNDLL32.EXE-1619A94E.pf 2009-02-09 23:18 21,154 a——- c:\windows\prefetch\ALG.EXE-0F138680.pf 2009-02-09 23:18 15,450 a——- c:\windows\prefetch\SVCHOST.EXE-3530F672.pf 2009-02-09 23:17 102,232 a——- c:\windows\system32\FNTCACHE.DAT 2009-02-09 22:51 23,452 a——- c:\windows\prefetch\DIVXSM.EXE-3407AB62.pf 2009-02-09 22:50 54,728 a——- c:\windows\prefetch\WMPLAYER.EXE-18DDEFA4.pf 2009-02-09 22:50 11,944 a——- c:\windows\prefetch\DIVXCODECVERSIONCHECKER.EXE-06B73480.pf 2009-02-09 22:03 47,842 a——- c:\windows\prefetch\AVSCAN.EXE-181AB66D.pf 2009-02-09 22:03 43,562 a——- c:\windows\prefetch\AVCENTER.EXE-058B10AA.pf 2009-02-09 22:01 56,928 a——- c:\windows\prefetch\AVNOTIFY.EXE-32FAE179.pf 2009-02-09 22:01 54,270 a——- c:\windows\prefetch\UPDATE.EXE-264167D5.pf 2009-02-09 22:01 17,572 a——- c:\windows\prefetch\PREUPD.EXE-0C5BC219.pf 2009-02-09 22:00 29,418 a——- c:\windows\prefetch\SCHED.EXE-0CAE1E50.pf 2009-02-09 22:00 49,540 a——- c:\windows\prefetch\AVGUARD.EXE-188FB0FF.pf 2009-02-09 22:00 18,074 a——- c:\windows\prefetch\RUNDLL32.EXE-2CBA7525.pf 2009-02-09 22:00 18,094 a——- c:\windows\prefetch\RUNDLL32.EXE-26C2C861.pf 2009-02-09 22:00 22,862 a——- c:\windows\prefetch\FACT.EXE-2E5E67C0.pf 2009-02-09 21:16 170,976 a——- c:\windows\pchealth\helpctr\config\cache\Professional_32_1033.dat.bak 2009-02-09 21:16 13,136 a——- c:\windows\pchealth\helpctr\config\news\newsver.xml 2009-02-09 21:15 26,554 a——- c:\windows\prefetch\HELPHOST.EXE-247D2792.pf 2009-02-09 21:15 26,062 a——- c:\windows\prefetch\HELPSVC.EXE-2878DDA2.pf 2009-02-09 21:15 61,358 a——- c:\windows\prefetch\HELPCTR.EXE-3862B6F5.pf 2009-02-09 20:31 12,870 a——- c:\windows\prefetch\SYSTEMLOOK.EXE-2EE5A6C3.pf 2009-02-09 20:30 8,782 a——- c:\windows\prefetch\WREGS.EXE-1CD746DD.pf 2009-02-09 20:30 11,460 a——- c:\windows\prefetch\FI.EXE-27F08F22.pf 2009-02-09 20:30 5,114 a——- c:\windows\prefetch\EDS.EXE-1207C288.pf 2009-02-09 20:30 22,734 a——- c:\windows\prefetch\ETPATHS.EXE-15F5AFAC.pf 2009-02-09 20:05 8,782 a——- c:\windows\prefetch\WREGS.EXE-2373CC13.pf 2009-02-09 20:04 13,182 a——- c:\windows\prefetch\FI.EXE-00203718.pf 2009-02-09 20:04 5,098 a——- c:\windows\prefetch\EDS.EXE-119156EF.pf 2009-02-09 20:04 22,832 a——- c:\windows\prefetch\ETPATHS.EXE-23F6922C.pf 2009-02-09 18:56 224,030 a——- c:\windows\prefetch\layout.ini 2009-02-09 18:41 21,834 a——- c:\windows\prefetch\LOGONUI.EXE-0AF22957.pf 2009-02-09 17:57 8,782 a——- c:\windows\prefetch\WREGS.EXE-250B8CEF.pf 2009-02-09 17:56 5,110 a——- c:\windows\prefetch\EDS.EXE-111AEB56.pf 2009-02-09 17:56 12,882 a——- c:\windows\prefetch\FI.EXE-24FEA499.pf 2009-02-09 17:56 23,190 a——- c:\windows\prefetch\ETPATHS.EXE-1B382D3F.pf 2009-02-09 17:56 68,448 a——- c:\windows\prefetch\SCANNINGPROCESS.EXE-0D88C742.pf 2009-02-09 17:38 62,340 a——- c:\windows\prefetch\GMER.EXE-1300037F.pf 2009-02-09 17:24 22,824 a——- c:\windows\prefetch\HIJACKTHIS.EXE-235DF147.pf 2009-02-09 14:41 12,036 a——- c:\windows\prefetch\JAVAWS.EXE-021AC9A9.pf 2009-02-09 14:41 21,098 a——- c:\windows\prefetch\JQS.EXE-1D781F77.pf 2009-02-09 14:41 88,640 a——- c:\windows\prefetch\JAVAW.EXE-2DC32ABC.pf 2009-02-09 14:40 55,574 a——- c:\windows\prefetch\UNPACK200.EXE-16F2D239.pf 2009-02-09 14:40 72,366 a——- c:\windows\prefetch\MSIEXEC.EXE-2F8A8CAE.pf 2009-02-09 14:40 49,420 a——- c:\windows\prefetch\ZIPPER.EXE-2C9C69B1.pf 2009-02-09 14:40 7,470 a——- c:\windows\prefetch\MSI42.TMP-1ED9CA03.pf 2009-02-09 14:40 53,544 a——- c:\windows\prefetch\JRE-6U12-WINDOWS-I586-P.EXE-151E20DB.pf 2009-02-09 14:39 36,958 a——- c:\windows\prefetch\JAVAW.EXE-222468CF.pf 2009-02-09 14:39 25,312 a——- c:\windows\prefetch\JAVAWS.EXE-25F11D4D.pf 2009-02-09 14:38 52,570 a——- c:\windows\prefetch\RUNDLL32.EXE-2CD85FD3.pf 2009-02-09 14:24 3,407,872 a—h— c:\documents and settings\administrator\NTUSER.DAT 2009-02-09 14:24 178 -c-sh— c:\documents and settings\administrator\ntuser.ini 2009-02-09 13:58 15,226 a——- c:\windows\prefetch\REGEDIT.EXE-1B606482.pf 2009-02-09 13:41 1,024 a—h— c:\documents and settings\all users\ntuser.dat.LOG 2009-02-04 20:31 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_667.xml 2009-02-04 20:31 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_657.xml 2009-02-03 19:27 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_637.xml 2009-02-03 19:27 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_627.xml 2009-02-02 15:40 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_607.xml 2009-02-02 15:40 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_597.xml 2009-01-31 02:14 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_577.xml 2009-01-31 02:14 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_567.xml 2009-01-29 23:54 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_547.xml 2009-01-29 23:54 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_537.xml 2009-01-27 22:17 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_517.xml 2009-01-27 22:17 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_507.xml 2009-01-25 20:38 3,836 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_493.xml 2009-01-25 20:38 2,150 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_487.xml 2009-01-25 20:38 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_477.xml 2009-01-25 03:11 98,304 a——- c:\windows\system32\CmdLineExt.dll 2009-01-25 02:17 138,464 a——- c:\windows\system32\drivers\PnkBstrK.sys 2009-01-25 02:17 111,928 a——- c:\windows\system32\PnkBstrB.exe 2009-01-24 19:23 5,682 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_465.xml 2009-01-24 19:23 3,734 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_457.xml 2009-01-24 19:22 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_447.xml 2009-01-23 18:23 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_427.xml 2009-01-23 18:23 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_417.xml 2009-01-22 17:02 3,702 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_397.xml 2009-01-22 17:02 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_387.xml 2009-01-21 15:04 3,692 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_373.xml 2009-01-21 15:04 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_367.xml 2009-01-21 15:04 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_357.xml 2009-01-20 04:59 10,414 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_343.xml 2009-01-20 04:59 3,708 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_337.xml 2009-01-20 04:59 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_327.xml 2009-01-18 21:08 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_307.xml 2009-01-18 21:08 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_297.xml 2009-01-15 19:58 7,248 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_283.xml 2009-01-15 19:58 5,424 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_285.xml 2009-01-15 19:58 1,776 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_279.xml 2009-01-15 19:58 9,874 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_277.xml 2009-01-15 19:58 9,024 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_275.xml 2009-01-15 19:57 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_267.xml 2009-01-14 22:40 22,328 ac—— c:\docume~1\admini~1\applic~1\PnkBstrK.sys 2009-01-14 22:40 682,280 a——- c:\windows\system32\pbsvc.exe 2009-01-14 22:40 66,872 a——- c:\windows\system32\PnkBstrA.exe 2009-01-14 21:37 1,412,752 a——- c:\windows\inf\INFCACHE.1 2009-01-13 23:55 19,748 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_253.xml 2009-01-13 23:55 2,932 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_255.xml 2009-01-13 23:55 2,118 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_247.xml 2009-01-13 23:55 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_237.xml 2009-01-09 10:05 128,516 a——- c:\windows\inf\oem30.PNF 2009-01-09 09:56 192,468 a——- c:\windows\inf\oem29.PNF 2009-01-06 20:04 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_207.xml 2009-01-05 17:58 9,134 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_193.xml 2009-01-05 17:58 2,838 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_195.xml 2009-01-05 17:58 1,776 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_187.xml 2009-01-05 17:58 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_177.xml 2009-01-02 06:07 59,500 a——- c:\windows\inf\oem28.PNF 2009-01-02 03:34 244 ac–h— C:\sqmnoopt00.sqm 2009-01-02 03:34 232 ac–h— C:\sqmdata00.sqm 2008-12-31 23:40 5,318 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_157.xml 2008-12-31 23:40 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_147.xml 2008-12-27 20:00 24,572 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_133.xml 2008-12-27 20:00 2,968 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_135.xml 2008-12-27 20:00 8,572 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_127.xml 2008-12-27 20:00 2,040 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_117.xml 2008-12-26 19:20 153,823 a——- c:\windows\inf\oem29.inf 2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf 2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf 2008-12-25 10:12 5,496 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_105.xml 2008-12-25 10:12 29,702 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_103.xml 2008-12-25 10:12 8,598 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_97.xml 2008-12-25 10:12 2,442 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_77.xml 2008-12-25 10:12 2,040 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_87.xml 2008-12-25 09:54 8,606 a——- c:\windows\inf\oem27.PNF 2008-12-25 09:54 4,776 a——- c:\windows\inf\xinput1_3_x86.PNF 2008-12-25 09:50 4,676 a——- c:\windows\inf\branches.PNF 2008-12-23 21:58 453,152 a——- c:\windows\system32\NVUNINST.EXE 2008-12-19 07:27 2,832 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_75.xml 2008-12-19 07:27 7,118 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_67.xml 2008-12-19 07:27 2,040 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_57.xml 2008-12-12 14:47 586,756 a——- c:\windows\system32\TZLog.log 2008-12-09 23:24 17,593,280 a——- c:\windows\system32\MRT.exe 2008-12-09 19:40 8,990 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_43.xml 2008-12-09 19:40 2,112 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_37.xml 2008-12-09 19:40 2,040 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_27.xml 2008-12-05 14:27 8,580 a——- c:\windows\inf\oem17.PNF 2008-12-05 14:24 8,584 a——- c:\windows\inf\oem26.PNF 2008-12-05 14:16 1,066,494 a——- c:\windows\setupapi.log.0.old 2008-12-05 14:00 20,236 a——- c:\windows\inf\bda.PNF 2008-12-05 13:58 11,956 a——- c:\windows\inf\streamip.PNF 2008-12-05 13:58 9,096 a——- c:\windows\inf\ndisip.PNF 2008-12-05 13:58 9,200 a——- c:\windows\inf\wstcodec.PNF 2008-12-05 13:58 9,196 a——- c:\windows\inf\slip.PNF 2008-12-05 13:58 9,644 a——- c:\windows\inf\ccdecode.PNF 2008-12-05 13:58 9,636 a——- c:\windows\inf\nabtsfec.PNF 2008-12-05 01:08 52,612 a——- c:\windows\inf\oem25.PNF 2008-12-03 22:02 43,500 a——- c:\windows\inf\kscaptur.PNF 2008-12-03 22:00 7,590 a——- c:\windows\inf\oem22.PNF 2008-12-03 21:59 12,148 a——- c:\windows\inf\oem21.PNF 2008-12-02 15:11 121,260 a——- c:\windows\inf\oem20.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_6_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_5_x86.PNF 2008-12-02 15:09 4,856 a——- c:\windows\inf\d3dx9_32_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_4_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_3_x86.PNF 2008-12-02 15:09 4,856 a——- c:\windows\inf\d3dx9_31_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_2_x86.PNF 2008-12-02 15:09 4,776 a——- c:\windows\inf\xinput1_2_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_1_x86.PNF 2008-12-02 15:09 4,776 a——- c:\windows\inf\xinput1_1_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_30_x86.PNF 2008-12-02 15:08 5,176 a——- c:\windows\inf\xact_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_29_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_28_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_27_x86.PNF 2008-12-02 15:08 4,792 a——- c:\windows\inf\xinput9_1_0_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_26_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_25_x86.PNF 2008-12-02 15:08 4,888 a——- c:\windows\inf\d3dx9_24_x86.PNF 2008-11-24 15:13 522,530 a——- c:\windows\system32\PerfStringBackup.INI 2008-11-24 15:13 441,624 a——- c:\windows\system32\perfh009.dat 2008-11-24 15:13 71,308 a——- c:\windows\system32\perfc009.dat 2008-11-21 21:46 1,044,480 a——- c:\windows\system32\libdivx.dll 2008-11-21 21:46 200,704 a——- c:\windows\system32\ssldivx.dll 2008-11-21 21:44 161,096 a——- c:\windows\system32\DivXCodecVersionChecker.exe 2008-11-21 21:44 12,288 a——- c:\windows\system32\DivXWMPExtType.dll 2008-11-12 14:54 33,072 a——- c:\windows\inf\oem28.inf 2008-11-12 14:54 28,683 a——- c:\windows\inf\oem25.inf 2008-11-07 14:23 3,138 a——- c:\windows\inf\oem26.inf 2008-10-16 14:04 54,440 a——- c:\windows\inf\wuau.adm 2008-09-11 09:13 78,749 a—-r– c:\windows\inf\oem20.inf 2008-09-11 09:13 11,706 a—-r– c:\windows\inf\oem21.inf 2008-09-11 09:13 2,491 a—-r– c:\windows\inf\oem22.inf 2008-08-17 14:28 87,608 ac—— c:\docume~1\admini~1\applic~1\inst.exe 2008-08-17 14:28 47,360 ac—— c:\docume~1\admini~1\applic~1\pcouffin.sys 2008-08-17 14:28 7,887 ac—— c:\docume~1\admini~1\applic~1\pcouffin.cat 2008-08-17 14:28 1,144 ac—— c:\docume~1\admini~1\applic~1\pcouffin.inf 2008-08-17 14:28 55 ac—— c:\docume~1\admini~1\applic~1\pcouffin.log 2008-08-17 13:27 5,900 a——- c:\windows\inf\GEARAspiWDM.PNF 2008-08-17 12:47 587 ac—— c:\docume~1\admini~1\applic~1\AutoGK.ini 2008-08-17 10:33 62,236 a——- c:\windows\inf\font.PNF 2008-08-17 07:32 424,000 a——- c:\windows\inf\intl.PNF 2008-08-16 01:27 4,684 a——- c:\windows\inf\Erma.PNF 2008-08-15 16:23 39,228 a——- c:\windows\inf\oem14.PNF 2008-08-15 16:23 35,850 a——- c:\windows\inf\oem13.PNF 2008-08-15 15:20 20,028 a——- c:\windows\inf\oem15.PNF 2008-08-14 18:06 13,824 a——- c:\windows\inf\AegisP.inf 2008-08-14 18:06 9,992 a——- c:\windows\inf\AegisP.PNF 2008-07-25 01:19 12,720 a——- c:\windows\inf\hidserv.PNF 2008-07-25 01:18 44,496 a——- c:\windows\inf\usb.PNF 2008-04-17 13:12 2,761 a——- c:\windows\inf\oem17.inf 2008-01-25 13:50 37,024 a——- c:\windows\inf\usbstor.PNF 2008-01-25 00:23 4,624 a——- c:\windows\inf\msxpsdrv.PNF 2008-01-25 00:15 12,016 a——- c:\windows\inf\wpdmtp.PNF 2008-01-25 00:15 5,256 a——- c:\windows\inf\WPDMTPHW.PNF 2008-01-25 00:15 8,012 a——- c:\windows\inf\wmp11.PNF 2008-01-25 00:15 3,988 a——- c:\windows\inf\wmsetsdk.PNF 2008-01-25 00:15 6,020 a——- c:\windows\inf\skins.PNF 2008-01-25 00:15 4,352 a——- c:\windows\inf\lhtsc.PNF 2008-01-25 00:09 4,424 a——- c:\windows\inf\ieaccess.PNF 2008-01-24 23:33 44,964 a——- c:\windows\inf\printupg.PNF 2008-01-24 23:28 10,922 a——- c:\windows\inf\oem12.PNF 2008-01-24 23:22 78,556 a——- c:\windows\inf\oem11.PNF 2008-01-24 23:21 10,524 a——- c:\windows\inf\WPD10.PNF 2008-01-24 23:21 22,146 a——- c:\windows\inf\WMDM10.PNF 2008-01-24 23:21 10,744 a——- c:\windows\inf\WMFSDK10.PNF 2008-01-24 23:21 13,082 a——- c:\windows\inf\codecs10.PNF 2008-01-24 23:21 6,770 a——- c:\windows\inf\DRM10.PNF 2008-01-24 23:21 6,178 a——- c:\windows\inf\MPPRE10.PNF 2008-01-24 15:40 3,764 a——- c:\windows\inf\minioc.PNF 2008-01-24 15:36 4,524 a——- c:\windows\inf\ProfSec.Inf 2008-01-24 15:32 7,290 a——- c:\windows\inf\oem8.PNF 2008-01-24 15:32 6,082 a——- c:\windows\inf\oem7.PNF 2008-01-24 15:25 112,360 a——- c:\windows\inf\monitor8.PNF 2008-01-24 08:11 48,316 a——- c:\windows\inf\accessor.PNF 2008-01-24 08:08 63,112 a——- c:\windows\inf\msmouse.PNF 2008-01-24 08:08 100,612 a——- c:\windows\inf\syssetup.PNF 2008-01-24 08:07 100,124 a——- c:\windows\inf\input.PNF 2008-01-24 07:44 21,352 a——- c:\windows\inf\wab50.PNF 2008-01-24 07:44 87,456 a——- c:\windows\inf\msmsgs.PNF 2008-01-24 07:44 56,940 a——- c:\windows\inf\wmp.PNF 2008-01-24 07:44 83,728 a——- c:\windows\inf\ie.PNF 2008-01-24 07:44 1,051,064 a——- c:\windows\inf\layout.PNF 2008-01-24 07:44 60,940 a——- c:\windows\inf\msnetmtg.PNF 2008-01-24 07:44 108,188 a——- c:\windows\inf\monitor.PNF 2008-01-24 07:44 35,964 a——- c:\windows\inf\msoe50.PNF 2008-01-24 07:44 8,136 a——- c:\windows\inf\ProfSec.PNF 2008-01-24 07:42 262,144 a——- c:\documents and settings\all users\ntuser.dat 2008-01-24 07:40 55,068 a——- c:\windows\inf\oem9.PNF 2008-01-24 07:40 222,180 a——- c:\windows\inf\drvindex.PNF 2008-01-24 07:40 54,620 a——- c:\windows\inf\oem3.PNF 2008-01-24 07:40 7,800 a——- c:\windows\inf\certclas.PNF 2007-02-20 11:50 35,940 a——- c:\windows\inf\oem15.inf 2007-02-17 01:41 6,838 a——- c:\windows\inf\oem27.inf 2006-11-02 12:41 2,037 a——- c:\windows\inf\skins.inf 2006-10-03 02:43 2,402,550 a——- c:\windows\inf\inetres.adm 2006-09-28 12:53 20,044 a——- c:\windows\inf\windowsdefender.adm 2006-09-11 17:00 8,019 a——- c:\windows\inf\wpdmtp.inf 2006-09-01 08:55 37,836 ——– c:\windows\inf\iem\0409\inetset.iem 2006-09-01 08:55 13,696 ——– c:\windows\inf\iem\0409\inetcorp.iem 2006-08-31 01:01 2,204 a——- c:\windows\inf\msxpsdrv.inf 2006-08-25 17:09 2,428 ——– c:\windows\inf\wmp11.inf 2006-08-24 08:35 5,412 a——- c:\windows\inf\oem12.inf 2006-06-08 09:53 37,776 a——- c:\windows\inf\oem13.inf 2006-04-25 10:10 69,612 a——- c:\windows\inf\wmplayer.adm 2006-04-25 10:09 1,816 ——– c:\windows\inf\WPDMTPHW.INF 2005-12-05 14:19 56,644 a——- c:\windows\inf\oem11.inf 2005-10-17 18:43 41,297 a——- c:\windows\inf\oem14.inf 2005-01-28 13:44 16,724 a——- c:\windows\inf\WMDM10.inf 2005-01-28 13:44 4,668 a——- c:\windows\inf\WMFSDK10.inf 2005-01-28 13:44 4,395 a——- c:\windows\inf\codecs10.inf 2005-01-28 13:44 3,954 a——- c:\windows\inf\wpd10.inf 2005-01-28 13:44 1,911 a——- c:\windows\inf\DRM10.inf 2004-09-14 04:09 33,672 a——- c:\windows\inf\AER_1025.ADM 2004-08-09 06:21 62 a–sh— c:\docume~1\alluse~1\applic~1\desktop.ini 2004-08-09 06:21 62 a–sh— c:\docume~1\admini~1\applic~1\desktop.ini 2004-08-04 15:00 81,775 a——- c:\windows\inf\comnt5.inf 2004-08-04 15:00 6,398 a——- c:\windows\inf\msmqocm.inf 2004-08-04 15:00 3,284 a——- c:\windows\inf\dtcnt5.inf 2004-08-04 12:00 1,498,946 a——- c:\windows\inf\ntprint.inf 2004-08-04 12:00 849,768 a——- c:\windows\inf\intl.inf 2004-08-04 12:00 408,529 a——- c:\windows\inf\layout.inf 2004-08-04 12:00 67,816 a——- c:\windows\inf\drvindex.inf 2004-08-04 12:00 48,044 a——- c:\windows\inf\biosinfo.inf 2004-08-04 12:00 6,464 a——- c:\windows\inf\mstask.inf 2004-08-04 08:07 114,810 a——- c:\windows\inf\tsoc.inf 2004-08-04 08:07 25,815 a——- c:\windows\inf\accessor.inf 2004-08-04 08:07 8,047 a——- c:\windows\inf\wordpad.inf 2004-08-04 08:07 5,748 a——- c:\windows\inf\multimed.inf 2004-08-04 08:07 3,928 a——- c:\windows\inf\msnmsn.inf 2004-08-04 08:07 836,490 a——- c:\windows\inf\iis.inf 2004-08-04 08:07 50,680 a——- c:\windows\inf\fxsocm.inf 2004-08-04 08:04 48,885 a——- c:\windows\inf\ims.inf 2004-08-04 05:51 28,806 a——- c:\windows\inf\wmp.inf 2004-08-04 05:51 18,286 a——- c:\windows\inf\mplayer2.inf 2004-08-04 05:51 17,272 a——- c:\windows\inf\wmdm.inf 2004-08-04 05:51 3,637 a——- c:\windows\inf\mymusic.inf 2004-08-04 05:41 85,069 a——- c:\windows\inf\mdmhamrw.inf 2004-08-04 05:41 60,733 a——- c:\windows\inf\mdmlt3.inf 2004-08-04 05:41 28,128 a——- c:\windows\inf\mdmntstm.inf 2004-08-04 05:41 299,444 a——- c:\windows\inf\mdmrpci.inf 2004-08-04 05:39 2,938 a——- c:\windows\inf\netrndis.inf 2004-08-04 05:34 8,847 a——- c:\windows\inf\netnm.inf 2004-08-04 05:31 17,503 a——- c:\windows\inf\netwlan.inf 2004-08-04 05:31 9,030 a——- c:\windows\inf\netwlan2.inf 2004-08-04 05:31 9,022 a——- c:\windows\inf\netrtsnt.inf 2004-08-04 05:31 10,068 a——- c:\windows\inf\netwv48.inf 2004-08-04 05:31 8,810 a——- c:\windows\inf\netklsi.inf 2004-08-04 05:23 7,379 a——- c:\windows\inf\moviemk.inf 2004-08-04 05:23 51,427 a——- c:\windows\inf\msmsgs.inf 2004-08-04 05:11 3,612 a——- c:\windows\inf\wstcodec.inf 2004-08-04 05:11 6,091 a——- c:\windows\inf\au.inf 2004-08-04 05:11 11,985 a——- c:\windows\inf\usbvideo.inf 2004-08-04 05:11 23,708 a——- c:\windows\inf\usbport.inf 2004-08-04 05:09 53,259 a——- c:\windows\inf\pnpscsi.inf 2004-08-04 05:09 5,089 a——- c:\windows\inf\pchealth.inf 2004-08-04 05:09 6,592 a——- c:\windows\inf\p2p.inf 2004-08-04 05:09 6,344 a——- c:\windows\inf\oobe.inf 2004-08-04 05:09 3,998 a——- c:\windows\inf\netwzc.inf 2004-08-04 05:09 3,243 a——- c:\windows\inf\netupnph.inf 2004-08-04 05:09 24,187 a——- c:\windows\inf\nettcpip.inf 2004-08-04 05:09 39,025 a——- c:\windows\inf\netrass.inf 2004-08-04 05:09 9,074 a——- c:\windows\inf\netoc.inf 2004-08-04 05:09 11,747 a——- c:\windows\inf\netmscli.inf 2004-08-04 05:09 6,151 a——- c:\windows\inf\netip6.inf 2004-08-04 05:07 4,433 a——- c:\windows\inf\hidserv.inf 2004-08-04 05:07 3,751 a——- c:\windows\inf\HidDigi.inf 2004-08-04 05:06 315,309 a——- c:\windows\inf\dwup.inf 2004-08-04 05:06 39,513 a——- c:\windows\inf\devxprop.inf 2004-08-04 05:06 5,327 a——- c:\windows\inf\disk.inf 2004-08-04 05:06 295,169 a——- c:\windows\inf\defltwk.inf 2004-08-04 05:06 8,134 a——- c:\windows\inf\cpu.inf 2004-08-04 05:06 35,450 a——- c:\windows\inf\cdrom.inf 2004-08-04 05:06 3,776 a——- c:\windows\inf\ccdecode.inf 2004-08-04 05:05 9,921 a——- c:\windows\inf\bda.inf 2004-08-04 05:05 5,442 a——- c:\windows\inf\battery.inf 2004-08-04 05:05 3,976 a——- c:\windows\inf\agp.inf 2004-08-04 05:05 4,727 a——- c:\windows\inf\acpi.inf 2004-08-04 05:02 49,661 a——- c:\windows\inf\mdmusrk1.inf 2004-08-04 05:02 15,527 a——- c:\windows\inf\mdmvv.inf 2004-08-04 05:02 27,971 a——- c:\windows\inf\mdmsuprv.inf 2004-08-04 05:02 49,296 a——- c:\windows\inf\mdmgen.inf 2004-08-04 05:02 41,011 a——- c:\windows\inf\mdmetech.inf 2004-08-04 05:02 26,756 a——- c:\windows\inf\mdmbtmdm.inf 2004-08-04 05:02 4,473 a——- c:\windows\inf\tdibth.inf 2004-08-04 05:02 11,681 a——- c:\windows\inf\bth.inf 2004-08-04 05:01 79,843 a——- c:\windows\inf\mdmirmdm.inf 2004-08-04 05:00 2,563 a——- c:\windows\inf\bthpan.inf 2004-08-04 05:00 46,281 a——- c:\windows\inf\msnetmtg.inf 2004-08-04 05:00 24,371 a——- c:\windows\inf\wdma_int.inf 2004-08-04 05:00 18,736 a——- c:\windows\inf\wdma_via.inf 2004-08-04 05:00 63,294 a——- c:\windows\inf\wdma_ali.inf 2004-08-04 04:59 111,115 a——- c:\windows\inf\netfxocm.inf 2004-07-18 05:55 50,067 a——- c:\windows\inf\mdmcxsf2.inf 2004-07-18 05:54 1,744,202 a——- c:\windows\inf\system.adm 2004-07-18 05:54 10,865 a——- c:\windows\inf\nvts.inf 2004-07-17 18:45 6,769 a——- c:\windows\inf\wmfsdk.inf 2004-07-17 18:42 40,282 a——- c:\windows\inf\conf.adm 2004-07-17 18:41 18,516 a——- c:\windows\inf\inetset.adm 2004-07-17 18:40 6,140 a——- c:\windows\inf\qmgr.inf 2004-07-17 18:40 7,946 a——- c:\windows\inf\fp40ext.inf 2004-07-17 18:37 43,229 a——- c:\windows\inf\setupqry.inf 2004-07-06 09:28 44,229 a——- c:\windows\inf\oem9.inf 2004-06-16 11:45 28,037 a——- c:\windows\inf\oem6.inf 2004-05-07 10:43 44,236 a——- c:\windows\inf\oem3.inf 2004-05-04 17:31 36,680 a——- c:\windows\inf\oem0.inf 2004-04-05 16:19 4,824 a——- c:\windows\inf\oem1.inf 2004-03-11 10:21 3,891 a——- c:\windows\inf\oem5.inf 2004-03-11 10:21 3,548 a——- c:\windows\inf\oem4.inf 2004-03-11 10:21 3,627 a——- c:\windows\inf\oem2.inf 2004-02-04 19:26 2,963 a——- c:\windows\inf\oem7.inf 2004-02-04 19:26 3,845 a——- c:\windows\inf\oem8.inf 2003-07-18 14:42 39,132 a——- c:\windows\inf\AER_1040.ADM 2003-07-18 14:37 38,066 a——- c:\windows\inf\AER_3082.ADM 2003-07-12 02:55 23,748 a——- c:\windows\inf\AER_2052.ADM 2003-07-12 02:52 26,616 a——- c:\windows\inf\AER_1042.ADM 2003-07-12 02:48 23,282 a——- c:\windows\inf\AER_1028.ADM 2003-07-12 02:43 26,292 a——- c:\windows\inf\AER_1041.ADM 2003-07-12 02:40 39,516 a——- c:\windows\inf\AER_1031.ADM 2003-01-13 16:11 39,366 a——- c:\windows\inf\AER_1036.ADM 2002-10-10 08:44 34,066 a——- c:\windows\inf\AER_1033.ADM 2001-08-17 21:26 8,860 a——- c:\windows\inf\games.inf 2001-08-17 21:26 8,842 a——- c:\windows\inf\communic.inf 2001-08-17 21:26 7,316 a——- c:\windows\inf\optional.inf 2001-08-17 21:26 6,324 a——- c:\windows\inf\igames.inf 2001-08-17 21:26 5,839 a——- c:\windows\inf\wbemoc.inf 2001-08-17 21:26 3,551 a——- c:\windows\inf\pinball.inf 2001-08-17 20:28 48,940 a——- c:\windows\inf\mdmxircc.inf 2001-08-17 20:28 46,837 a——- c:\windows\inf\mdmxirmp.inf 2001-08-17 20:28 57,364 a——- c:\windows\inf\mdmusrgl.inf 2001-08-17 20:28 38,179 a——- c:\windows\inf\mdmpctel.inf 2001-08-17 20:28 29,028 a——- c:\windows\inf\mdmosice.inf 2001-08-17 20:28 49,556 a——- c:\windows\inf\mdmltsft.inf 2001-08-17 20:28 48,980 a——- c:\windows\inf\mdmltleo.inf 2001-08-17 20:28 13,982 a——- c:\windows\inf\mdmsgsmu.inf 2001-08-17 20:28 1,544,841 a——- c:\windows\inf\mdmrpciw.inf 2001-08-17 20:28 43,975 a——- c:\windows\inf\mdmess.inf 2001-08-17 20:28 620,730 a——- c:\windows\inf\mdmcxsft.inf 2001-08-17 20:28 48,170 a——- c:\windows\inf\mdmbcmsm.inf 2001-08-17 20:27 55,764 a——- c:\windows\inf\mdm3mini.inf 2001-08-17 20:27 30,934 a——- c:\windows\inf\mdm656n5.inf 2001-08-17 19:56 2,447 a——- c:\windows\inf\ndisuio.inf 2001-08-17 19:18 7,611 a——- c:\windows\inf\mpsstln.inf 2001-08-17 19:18 2,565 a——- c:\windows\inf\stalport.inf 2001-08-17 19:17 9,856 a——- c:\windows\inf\spxports.inf 2001-08-17 19:17 14,782 a——- c:\windows\inf\spx.inf 2001-08-17 19:17 7,450 a——- c:\windows\inf\asynceqn.inf 2001-08-17 19:17 3,207 a——- c:\windows\inf\eqnport.inf 2001-08-17 19:17 4,671 a——- c:\windows\inf\digirp.inf 2001-08-17 19:17 3,999 a——- c:\windows\inf\digirprt.inf 2001-08-17 19:17 19,125 a——- c:\windows\inf\mdmdigi.inf 2001-08-17 19:17 14,981 a——- c:\windows\inf\dgasync.inf 2001-08-17 19:17 14,952 a——- c:\windows\inf\dgaport.inf 2001-08-17 19:16 7,159 a——- c:\windows\inf\ctmaport.inf 2001-08-17 19:16 5,095 a——- c:\windows\inf\netctmrk.inf 2001-08-17 19:14 6,520 a——- c:\windows\inf\nettiger.inf 2001-08-17 19:12 4,637 a——- c:\windows\inf\nettb155.inf 2001-08-17 19:11 8,339 a——- c:\windows\inf\netibm2.inf 2001-08-17 19:10 7,072 a——- c:\windows\inf\netel90a.inf 2001-08-17 19:08 2,597 a——- c:\windows\inf\netepvcm.inf 2001-08-17 19:08 2,134 a——- c:\windows\inf\netepvcp.inf 2001-08-17 19:08 2,300 a——- c:\windows\inf\net1394.inf 2001-08-17 19:03 4,673 a——- c:\windows\inf\mfsocket.inf 2001-08-17 19:02 16,592 a——- c:\windows\inf\dvd.inf 2001-08-17 19:02 3,816 a——- c:\windows\inf\dshowext.inf 2001-08-17 19:02 2,243 a——- c:\windows\inf\dot4prt.inf 2001-08-17 19:02 42,416 a——- c:\windows\inf\dot4.inf 2001-08-17 19:02 33,702 a——- c:\windows\inf\display.inf 2001-08-17 19:02 11,373 a——- c:\windows\inf\dimaps.inf 2001-08-17 19:02 2,139 a——- c:\windows\inf\dfrg.inf 2001-08-17 19:02 7,813 a——- c:\windows\inf\cyzport.inf 2001-08-17 19:02 4,627 a——- c:\windows\inf\cyyport.inf 2001-08-17 19:02 2,589 a——- c:\windows\inf\cyclom-y.inf 2001-08-17 19:02 2,418 a——- c:\windows\inf\cyclad-z.inf 2001-08-17 19:02 2,186 a——- c:\windows\inf\certclas.inf 2001-08-17 18:58 3,651 a——- c:\windows\inf\fsvga.inf 2001-08-17 18:58 24,491 a——- c:\windows\inf\netnf3.inf 2001-08-17 18:57 4,898 a——- c:\windows\inf\viafir2k.inf 2001-08-17 18:57 4,701 a——- c:\windows\inf\irmk7w2k.inf 2001-08-17 18:57 4,228 a——- c:\windows\inf\irdaalif.inf 2001-08-17 18:57 3,711 a——- c:\windows\inf\irstusb.inf 2001-08-17 18:55 86,985 a——- c:\windows\inf\wdma_aur.inf 2001-08-17 18:55 16,408 a——- c:\windows\inf\wdma_azt.inf 2001-08-17 18:55 267,903 a——- c:\windows\inf\wdma10k1.inf 2001-08-17 18:55 23,685 a——- c:\windows\inf\wdmaudio.inf 2001-08-17 18:55 3,581 a——- c:\windows\inf\wave.inf 2001-08-02 00:21 4,177 a——- c:\windows\inf\nv3.inf 2001-07-30 23:47 25,633 a——- c:\windows\inf\atim128.inf 2001-07-26 23:19 14,340 a——- c:\windows\inf\tshoot.inf 2001-07-22 01:58 4,422 a——- c:\windows\inf\perm3.inf 2001-07-22 01:58 6,131 a——- c:\windows\inf\perm2.inf 2001-07-22 01:58 60,593 a——- c:\windows\inf\monitor5.inf 2001-07-22 01:58 52,670 a——- c:\windows\inf\monitor8.inf 2001-07-22 01:58 45,673 a——- c:\windows\inf\monitor6.inf 2001-07-22 01:58 41,883 a——- c:\windows\inf\monitor3.inf 2001-07-22 01:58 40,439 a——- c:\windows\inf\monitor7.inf 2001-07-22 01:58 40,054 a——- c:\windows\inf\monitor4.inf 2001-07-22 01:58 52,117 a——- c:\windows\inf\monitor.inf 2001-07-22 01:58 47,730 a——- c:\windows\inf\monitor2.inf 2001-07-22 01:41 11,209 a——- c:\windows\inf\neo20xx.inf 2001-07-22 01:41 3,322 a——- c:\windows\inf\mgau.inf 2001-07-22 01:41 3,085 a——- c:\windows\inf\mtxvideo.inf 2001-07-22 01:41 3,874 a——- c:\windows\inf\g200.inf 2001-07-22 01:41 2,773 a——- c:\windows\inf\i740nt5.inf 2001-07-22 01:40 29,798 a——- c:\windows\inf\atividin.inf 2001-07-22 01:40 3,046 a——- c:\windows\inf\atirage3.inf 2001-07-22 01:40 32,342 a——- c:\windows\inf\atimpab.inf 2001-07-22 01:39 17,675 a——- c:\windows\inf\3dfxvs2k.inf 2001-07-22 01:39 3,149 a——- c:\windows\inf\banshee.inf 2001-07-22 01:32 7,072 a——- c:\windows\inf\netel980.inf 2001-07-21 21:32 6,823 a——- c:\windows\inf\inetcorp.adm 2001-07-21 21:32 2,762 a——- c:\windows\inf\iereset.inf 2001-07-21 21:15 8,463 a——- c:\windows\inf\corelist.inf 2004-08-04 08:00 48,680 ac-sh— c:\windows\winnt.bmp 2004-08-04 08:00 48,680 ac-sh— c:\windows\winnt256.bmp 2008-01-24 15:29 227 a–shr– c:\windows\assembly\Desktop.ini 2004-08-09 13:32 67 ac-sh— c:\windows\fonts\desktop.ini 2004-08-04 08:00 2,737,914 ac-shr– c:\windows\pchealth\helpctr\packagestore\instance_Professional_32_1033.cab 2004-08-09 13:32 727 ac-shr– c:\windows\pchealth\helpctr\packagestore\package_1.cab 2004-08-09 13:32 19,854 ac-shr– c:\windows\pchealth\helpctr\packagestore\package_2.cab 2004-08-09 13:32 244,933 ac-shr– c:\windows\pchealth\helpctr\packagestore\package_3.cab 2004-08-04 08:00 7,068 ac-shr– c:\windows\pchealth\helpctr\packagestore\package_4.cab 2008-01-24 15:33 68,327 a–shr– c:\windows\pchealth\helpctr\packagestore\package_5.cab 2008-01-24 15:33 305,145 a–shr– c:\windows\pchealth\helpctr\packagestore\package_6.cab 2008-01-24 15:34 7,079 a–shr– c:\windows\pchealth\helpctr\packagestore\package_7.cab 2008-01-24 15:34 59,928 a–shr– c:\windows\pchealth\helpctr\packagestore\package_8.cab 2004-08-09 06:21 62 a–sh— c:\windows\system32\config\systemprofile\application data\desktop.ini 2004-08-09 13:41 2,570 a–sh— c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\Desktop.htt 2004-08-09 13:42 119 a–sh— c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\quick launch\desktop.ini 2004-08-09 13:42 122 a–sh— c:\windows\system32\config\systemprofile\favorites\Desktop.ini 2008-01-24 15:27 62 a–sh— c:\windows\system32\config\systemprofile\local settings\desktop.ini 2008-01-24 15:38 113 —sh— c:\windows\system32\config\systemprofile\local settings\history\desktop.ini 2008-01-24 15:38 113 —sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\desktop.ini 2008-01-24 15:38 67 —sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\desktop.ini 2008-01-24 15:38 67 —sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\desktop.ini 2008-01-24 15:38 67 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\d4zbshqv\desktop.ini 2008-01-24 15:38 67 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\dtcd8uvn\desktop.ini 2008-01-24 15:38 67 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\qk37zt06\desktop.ini 2008-01-24 15:38 67 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\xsn0aq3m\desktop.ini 2004-08-09 13:42 84 a–sh— c:\windows\system32\config\systemprofile\my documents\desktop.ini 2004-08-09 13:42 189 a–sh— c:\windows\system32\config\systemprofile\my documents\my music\Desktop.ini 2004-08-09 13:42 191 a–sh— c:\windows\system32\config\systemprofile\my documents\my pictures\Desktop.ini 2004-08-09 13:42 150 a–sh— c:\windows\system32\config\systemprofile\recent\Desktop.ini 2004-08-09 13:31 181 a–sh— c:\windows\system32\config\systemprofile\sendto\desktop.ini 2004-08-09 06:21 62 a–sh— c:\windows\system32\config\systemprofile\start menu\desktop.ini 2004-08-09 13:42 234 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\desktop.ini 2004-08-09 13:41 542 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\accessories\desktop.ini 2004-08-09 13:34 348 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\accessories\accessibility\desktop.ini 2004-08-09 13:34 84 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\accessories\entertainment\desktop.ini 2004-08-09 13:34 84 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\startup\desktop.ini 2008-01-24 15:35 1,663 a–shr– c:\windows\system32\drivers\103C_HP_BPC_HP Compaq dc7100 SFF(PL216E)_YB_0CBD_QCZC509_EU_46_I097Ch_SHP_V_B786C1 v01.05_T040616_WXP2_L409_M504_J40_7Intel_8Pentium 4_92.8_#080124_N14E41677_(PL216E)_X_CD4_Z_2_G80862582_OSAMSUNG CD-ROM SC-148A.MRK 2004-08-04 08:00 19,528 —shr– c:\windows\system32\restore\filelist.xml ============= FINISH: 15:09:05.32 =============== NO REDIRECTS!
Hi Jackus

Fantastic!

Log looks good :thumbup:

It was that XUL Cache extension after all, must've been a bit stubborn. You can now delete this folder and rid yourself of it for good:
C:\Program Files\Mozilla Firefox\extensions\{D96F1D71-4F95-443A-8AF3-541BFDBA096D}.bak

Clean up with OTMoveIt3
  • Double-click OTMoveIt3.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Set correct settings for files that should be hidden in Windows XP
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please checkHide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK

Re-enable TeaTimer:
  • Open Spybot
  • Click on Tools in bottom left hand corner.
  • Click on Resident.
  • Check Resident "TeaTimer" box.
  • Click on Allow change ONLY to popup box with:
  • Entry: SpybotSD Teatimer
  • Click on Mode, select Default mode
  • Close Spybot

Now that your system appears to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • System restore:
    We will now clear your existing system restore points and establish a new clean restore point:
    • Go to Start > All Programs > Accessories > System Tools > System Restore
    • Select Create a restore point, and Ok it.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and OK it.

      This will remove all restore points except the new one you just created.
    Make sure you do this now, as your System Restore currently has infected files in it.

  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • You don't appear to be running any third party Firewall software.

    Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
    1) Comodo
    2) Agnitum
    3) Sunbelt/Kerio
  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI