Jump to content

oashdihasidhasuidhiasdhiashdiuasdhasd and AGPro Infections


Recommended Posts

Hi.

I hope I am in the correct place; I followed the "I'm infected" link of another part of this site. I am having a problem with the constant returning of these items;

1) C:\Documents and Settings\LocalService\oashdihasidhasuidhiasdhiashdiuasdhasd ...a 1k file

2) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32

3) AGPro

I removed the actual Regedit trojan program (c:\windows\system32\regedit.exe) being called by the run command. The registry entry continues to return but it is referencing a program that does not exist any longer and has not returned (after my one delete). mbam will remove these 2 items and that prevents the repeated attempt to add the registry key (#2 above) and removes oashdihasidhasuidhiasdhiashdiuasdhasd ...until the next reboot. Additionally, my CD drive has disappeared from Windows Explorer and multiple instances of svchost.exe keep crashing and wreaking havoc with routine functions. I assume that this is the residual effects of the remaining items.

In the interest of full disclosure, this is a work laptop and I've just returned from working 4.5 weeks overseas where the offices' firewalls were less than stellar. I quickly picked up viruses, and running rkill/MBAM and ComboFix eventually became a daily necessity in order to have a semi-functioning laptop.

I am running Windows XP Pro with all the latest updates from Microsoft that had been pushed out by my work prior to my departure (other than IE8) on a Dell d630 laptop. I made sure mbam have up-to-date definition files. I'm running Norton Anti-Virus, though that started malfunctioning after one round of viruses as well.

Per the instructions of the general post, I am pasting the MBAM log and DDS log and attaching a WinZip with the GMER, Attach, and ComboFix logs. MBAM picks up the infected values; ComboFix does not. If I allow mbam to clean it; I think the initial reboot is clean and mbam finds nothing, but a subsequent reboot will have them back, identical to the previous infection.

Thank you for whatever time, effort and help you can provide. ---Arin Speed

--------------------------------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.44

Database version: 3774

Windows 5.1.2600 Service Pack 2 (Safe Mode)

Internet Explorer 8.0.6001.18702

02/23/2010 4:40:25 PM

mbam-log-2010-02-23 (16-40-05).txt

Scan type: Quick Scan

Objects scanned: 162639

Time elapsed: 4 minute(s), 33 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> No action taken.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\regedit32 (Trojan.Agent) -> No action taken.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Documents and Settings\aspeed\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> No action taken.

============================================================

DDS (Ver_09-12-01.01) - NTFSx86 NETWORK

Run by aspeed at 4:38:16.38 on 02/24/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.3099 [GMT -5:00]

AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\Program Files\Symantec AntiVirus\Smc.exe

c:\windows\system32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\Program Files\Symantec AntiVirus\Rtvscan.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Symantec AntiVirus\SmcGui.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Documents and Settings\aspeed\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = hxxp://www.msh.org/

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

BHO: Aide pour le lien d'Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

uRun: [GoToMeeting] c:\program files\citrix\gotomeeting\320\g2mstart.exe "/Trigger RunAtLogon"

uRun: [bitTorrent DNA] "c:\program files\dna\btdna.exe"

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRun: [syncMan] c:\documents and settings\aspeed\SyncMan.exe

mRun: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /installquiet

mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [sigmatelSysTrayApp] stsystra.exe

mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime

mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Apoint] c:\program files\apoint\Apoint.exe

mRun: [ChangeTPMAuth] c:\program files\wave systems corp\common\ChangeTPMAuth.exe /T:NTRU12

mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe

mRun: [Document Manager] c:\program files\wave systems corp\services manager\docmgr\bin\docmgr.exe

mRun: [EmbassySecurityCheck] "c:\program files\wave systems corp\embassy security setup\EMBASSYSecurityCheck.exe"

mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [intelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

mRun: [intelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"

mRun: [iSUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"

mRun: [secureUpgrade] c:\program files\wave systems corp\SecureUpgrade.exe

mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"

mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"

mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

mRun: [syncMan] c:\windows\system32\SyncMan.exe

mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\tcjnwkjfk .exe" /runcleanupscript

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-100000000002}\SC_Acrobat.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\powerg~1.lnk - c:\program files\concepts data systems\power ge'ez 2005\pg2005.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\totalm~1.lnk - c:\program files\arcsoft\totalmedia backup & record\uBBMonitor.exe

mPolicies-explorer: NoWelcomeScreen = 1 (0x1)

IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL

LSP: c:\windows\system32\biolsp.dll

Trusted Zone: msh.org\ctt

DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152710934850

DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} - hxxp://eroom.msh.org/eRoomSetup/client.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182874779218

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab

DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Notify: igfxcui - igfxdev.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

LSA: Authentication Packages = msv1_0 wvauth

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\aspeed\applic~1\mozilla\firefox\profiles\6iwleti0.default\

FF - prefs.js: browser.startup.homepage - www.google.com/ig

FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll

FF - plugin: c:\documents and settings\aspeed\application data\mozilla\firefox\profiles\6iwleti0.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll

FF - plugin: c:\program files\emusic download manager\plugin\npemusic.dll

FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npeRoom7.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-4-16 108392]

R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-4-16 108392]

R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec antivirus\Rtvscan.exe [2008-4-16 2189240]

S0 ktmsixpn;ktmsixpn;c:\windows\system32\drivers\pakc.sys --> c:\windows\system32\drivers\pakc.sys [?]

S1 cdfdrv;Cdfdrv;c:\windows\system32\drivers\cdfdrv.sys [2006-10-9 21744]

S2 ctxpidmn;ctxpidmn;c:\windows\system32\drivers\ctxpidmn.sys [2007-2-9 22952]

S2 CtxSbx;CtxSbx;c:\windows\system32\drivers\CtxSbx.sys [2007-2-9 161320]

S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-11 135664]

S2 iPCAgent;iPCAgent;c:\program files\ipass\ipassconnect cgnet travel access\iPCAgent.exe [2006-7-12 90112]

S2 RadeSvc;Citrix Streaming Service;c:\program files\citrix\streaming client\RadeSvc.exe [2007-2-9 241664]

S2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [2004-8-4 5120]

S3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [2006-11-2 97536]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-12 102448]

S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\googledesktop.exe [2008-10-8 30192]

S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100223.004\NAVENG.SYS [2010-2-23 84912]

S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100223.004\NAVEX15.SYS [2010-2-23 1324720]

S4 vsdatant;vsdatant;a --> a [?]

=============== Created Last 30 ================

2010-02-24 09:37:07 0 ----a-w- c:\documents and settings\aspeed\defogger_reenable

2010-02-24 08:43:28 0 d-----w- c:\program files\Trend Micro

2010-02-24 04:16:34 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-02-20 23:01:11 98816 ----a-w- c:\windows\sed.exe

2010-02-20 23:01:11 77312 ----a-w- c:\windows\MBR.exe

2010-02-20 23:01:11 261632 ----a-w- c:\windows\PEV.exe

2010-02-20 23:01:11 161792 ----a-w- c:\windows\SWREG.exe

2010-02-18 09:02:13 0 d-----w- C:\Autoruns

2010-02-17 10:33:14 6895599 ----a-w- C:\Quantimed_FRENCH_FINAL_9.28.07.zip

2010-02-15 17:24:13 19456 ----a-w- C:\Major and minor changes to the ADT.xls

2010-02-15 10:07:58 73728 ----a-w- c:\windows\system32\MouseWheelDVPNoReg.dll

2010-02-15 10:07:58 114688 ----a-w- c:\windows\system32\SNAPVIEW.OCX

2010-02-15 10:07:41 0 d-----w- c:\program files\SIGVIH

2010-02-10 16:29:30 0 d-----w- C:\Sample Data

2010-02-08 09:33:39 47616 ----a-w- C:\EDT Implementation Readiness Checklist and Assessment FINAL.doc

2010-02-05 14:23:28 0 d-----w- C:\EDT

2010-02-03 07:46:27 0 d-----w- C:\EDTBackup

2010-02-02 17:26:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-02-02 17:26:16 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-02 17:26:16 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-02-02 15:45:03 0 d-----w- c:\program files\Restoration

2010-02-02 09:26:02 0 d-----r- C:\GraviTy

2010-02-02 08:23:22 147968 ----a-w- c:\windows\7z.exe

2010-02-02 08:23:22 122880 ----a-w- c:\windows\system32\blat.dll

2010-01-26 14:34:15 126979 ----a-w- c:\windows\system32\nepalicalendar.ocx

2010-01-26 06:55:18 168 ----a-w- c:\windows\system32\VAT.SDC

2010-01-26 06:55:18 0 ----a-w- c:\windows\widsne.dll

2010-01-26 06:55:18 0 ----a-w- c:\windows\osdatt.ttf

2010-01-26 06:54:58 81920 ----a-w- c:\windows\system32\Flash_Button.ocx

2010-01-26 06:54:58 294912 ----a-w- c:\windows\system32\SkinControl.ocx

2010-01-26 06:54:58 135168 ----a-w- c:\windows\system32\Calendar.ocx

2010-01-26 06:54:57 0 d-----w- c:\program files\Concepts Data Systems

2010-01-26 06:54:43 0 d-----w- C:\POWER GEEZ 2005

2010-01-25 12:50:53 81987 ----a-w- c:\windows\system32\AUCPLMNT.DLL

==================== Find3M ====================

2010-02-19 08:18:17 13072 ----a-w- c:\windows\system32\nvModes.dat

2010-02-18 08:26:43 182912 ----a-w- c:\windows\system32\drivers\ndis.sys

2010-02-10 17:15:05 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL

2009-12-21 19:14:05 916480 ------w- c:\windows\system32\wininet.dll

2008-10-07 16:38:18 153088 ----a-w- c:\program files\screen shot.doc

============= FINISH: 4:38:42.05 ===============

ARK_and_Attach_and_CF.zip

Link to post
Share on other sites

Hello , and welcome to Malwarebytes forums!

P2P WARNING

-------------------

Going over your logs I noticed that you have BitTorrent installed.

[*] Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.

[*]They are a security risk which can make your computer susceptible to a sm

Link to post
Share on other sites

Hi:

Thank you very much for your help - sorry for the delay in replying.

1. I am able to access the internet, but I have to run my computer in safe mode and I have to run MBAM first in safe mode. This catches the AGPro infection in the registry. If I run my computer in normal mode, it's MBAM catches the previous three infections, and it's almost impossible to access the network, as something dominates the network signal.

2. I've removed the BitTorrent application.

3. I ran ComboFix in Safe Mode. The log is below.

Thanks again.

-Arin Speed

----------------------------------------------------------------------------------------------------------------

ComboFix 10-02-25.02 - aspeed 02/26/2010 10:59:37.15.1 - x86 NETWORK

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.3222 [GMT -5:00]

Running from: c:\documents and settings\aspeed\Desktop\ComboFix.exe

AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

-- Previous Run --

c:\windows\system32\drivers\cdrom.sys . . . is missing!!

--------

c:\windows\system32\drivers\cdrom.sys . . . is missing!!

.

((((((((((((((((((((((((( Files Created from 2010-01-26 to 2010-02-26 )))))))))))))))))))))))))))))))

.

2010-02-24 08:43 . 2010-02-24 08:43 -------- d-----w- c:\program files\Trend Micro

2010-02-24 04:16 . 2010-02-24 04:16 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-02-18 09:02 . 2010-02-18 09:02 -------- d-----w- C:\Autoruns

2010-02-17 10:33 . 2007-10-18 11:05 6895599 ----a-w- C:\Quantimed_FRENCH_FINAL_9.28.07.zip

2010-02-15 10:25 . 2010-02-15 10:25 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google

2010-02-15 10:07 . 2006-09-11 23:06 73728 ----a-w- c:\windows\system32\MouseWheelDVPNoReg.dll

2010-02-15 10:07 . 2010-02-22 10:04 -------- d-----w- c:\program files\SIGVIH

2010-02-11 08:55 . 2010-02-11 08:55 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google

2010-02-10 16:29 . 2010-02-10 16:29 -------- d-----w- C:\Sample Data

2010-02-05 14:23 . 2010-02-21 23:46 -------- d-----w- C:\EDT

2010-02-03 07:46 . 2010-02-03 07:46 -------- d-----w- C:\EDTBackup

2010-02-02 17:26 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-02-02 17:26 . 2010-02-18 14:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-02-02 17:26 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-02 15:45 . 2010-02-02 15:45 -------- d-----w- c:\program files\Restoration

2010-02-02 09:26 . 2010-02-02 09:26 -------- d-----r- C:\GraviTy

2010-02-02 08:23 . 2007-12-06 08:32 147968 ----a-w- c:\windows\7z.exe

2010-02-02 08:23 . 2007-02-25 17:06 122880 ----a-w- c:\windows\system32\blat.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-02-23 21:27 . 2008-10-08 21:23 -------- d-----w- c:\documents and settings\aspeed\Application Data\DNA

2010-02-23 05:41 . 2008-10-08 16:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Wave Systems Corp

2010-02-21 22:16 . 2008-10-08 16:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Skype

2010-02-21 22:14 . 2008-10-08 20:20 -------- d-----w- c:\documents and settings\aspeed\Application Data\skypePM

2010-02-19 08:18 . 2007-07-31 17:36 13072 ----a-w- c:\windows\system32\nvModes.dat

2010-02-18 14:24 . 2008-10-08 19:38 -------- d-----w- c:\program files\Winamp

2010-02-18 14:23 . 2007-07-31 17:11 -------- d-----w- c:\program files\Wave Systems Corp

2010-02-18 14:22 . 2009-10-23 05:32 -------- d-----w- c:\program files\iTunes

2010-02-18 14:13 . 2009-10-23 05:30 -------- d-----w- c:\program files\QuickTime

2010-02-18 14:10 . 2007-07-31 17:08 -------- d-----w- c:\program files\Apoint

2010-02-18 13:11 . 2006-07-12 16:35 -------- d-----w- c:\program files\Common Files\Symantec Shared

2010-02-18 08:26 . 2004-08-04 12:00 212736 ----a-w- c:\windows\system32\drivers\ndis.sys

2010-02-15 11:39 . 2007-07-31 17:40 68848 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-02-15 10:10 . 2008-04-07 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-02-15 10:08 . 2006-07-12 17:11 -------- d-----w- c:\program files\Common Files\Adobe

2010-02-11 08:55 . 2008-07-16 22:36 -------- d-----w- c:\program files\Google

2010-02-10 17:15 . 2008-10-17 18:00 -------- d-----w- c:\program files\Replay Music 3

2010-02-10 17:15 . 2008-10-17 18:00 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL

2010-01-26 06:54 . 2010-01-26 06:54 -------- d-----w- c:\program files\Concepts Data Systems

2010-01-26 06:54 . 2006-07-12 18:19 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-01-22 03:53 . 2008-10-08 19:16 -------- d-----w- c:\program files\7-Zip

2010-01-13 04:10 . 2010-01-13 04:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Malwarebytes

2010-01-13 04:06 . 2010-01-13 04:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-01-11 05:50 . 2009-04-04 19:49 3309072 ----a-w- c:\documents and settings\aspeed\Application Data\YouSendIt\Downloads\YouSendIt_Express.exe

2009-12-21 19:14 . 2004-08-04 12:00 916480 ------w- c:\windows\system32\wininet.dll

2008-10-07 16:38 . 2008-10-07 16:38 153088 ----a-w- c:\program files\screen shot.doc

2009-12-17 13:51 . 2008-10-08 20:47 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll

.

<pre>
c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray .exe
c:\program files\Common Files\Symantec Shared\ccapp .exe
c:\program files\Malwarebytes' Anti-Malware\tcjnwkjfk .exe
</pre>

------- Sigcheck -------

[-] 2010-02-18 . 30757ACD6B3BFE4335E73460FBA14DE1 . 212736 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ndis.sys

[-] 2010-02-18 08:26 . 1F4761387E0D5586FF86EBE19E00B86E . 212736 . . [------] . . c:\windows\system32\dllcache\ndis.sys

[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys

.

((((((((((((((((((((((((((((( SnapShot@2010-02-20_23.09.18 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-02-26 15:39 . 2010-02-26 15:39 16384 c:\windows\Temp\Perflib_Perfdata_1ec.dat

+ 2006-07-12 13:12 . 2010-02-23 19:55 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

- 2006-07-12 13:12 . 2010-02-20 16:14 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

+ 2006-07-12 13:12 . 2010-02-23 19:55 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

- 2006-07-12 13:12 . 2010-02-20 16:14 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GoToMeeting"="c:\program files\Citrix\GoToMeeting\320\g2mstart.exe" [2008-09-05 31552]

"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [N/A]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-17 68856]

"SyncMan"="c:\documents and settings\aspeed\SyncMan.exe" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]

"nwiz"="nwiz.exe" [2007-04-28 1626112]

"NVHotkey"="nvHotkey.dll" [2007-04-28 67584]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]

"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]

"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]

"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-25 159744]

"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2007-01-31 176128]

"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]

"Document Manager"="c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2007-01-30 102400]

"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2007-02-01 65536]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-17 30192]

"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]

"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]

"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-01-22 212992]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

"SyncMan"="c:\windows\system32\SyncMan.exe" [N/A]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\tcjnwkjfk .exe" [2010-02-02 1394000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2006-7-12 25214]

Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]

Power Ge'ez 2005.lnk - c:\program files\Concepts Data Systems\Power Ge'ez 2005\pg2005.exe [2010-1-26 454656]

TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-10-24 278528]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\MSN Messenger\\livecall.exe"=

"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=

"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

S0 ktmsixpn;ktmsixpn;c:\windows\system32\drivers\pakc.sys --> c:\windows\system32\drivers\pakc.sys [?]

S1 cdfdrv;Cdfdrv;c:\windows\system32\drivers\cdfdrv.sys [10/09/2006 11:27 AM 21744]

S2 ctxpidmn;ctxpidmn;c:\windows\system32\drivers\ctxpidmn.sys [02/09/2007 6:51 PM 22952]

S2 CtxSbx;CtxSbx;c:\windows\system32\drivers\CtxSbx.sys [02/09/2007 7:23 PM 161320]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [02/11/2010 3:55 AM 135664]

S2 iPCAgent;iPCAgent;c:\program files\iPass\iPassConnect CGNET Travel Access\iPCAgent.exe [07/12/2006 1:19 PM 90112]

S2 RadeSvc;Citrix Streaming Service;c:\program files\Citrix\Streaming Client\RadeSvc.exe [02/09/2007 6:55 PM 241664]

S2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [08/04/2004 7:00 AM 5120]

S3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/02/2006 11:32 AM 97536]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [01/12/2010 9:55 PM 102448]

S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\googledesktop.exe [10/08/2008 3:47 PM 30192]

.

Contents of the 'Scheduled Tasks' folder

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-11 08:55]

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-11 08:55]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = hxxp://www.msh.org/

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

LSP: c:\windows\system32\biolsp.dll

Trusted Zone: msh.org\ctt

DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} - hxxp://eroom.msh.org/eRoomSetup/client.cab

DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab

FF - ProfilePath - c:\documents and settings\aspeed\Application Data\Mozilla\Firefox\Profiles\6iwleti0.default\

FF - prefs.js: browser.startup.homepage - www.google.com/ig

FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll

FF - plugin: c:\documents and settings\aspeed\Application Data\Mozilla\Firefox\Profiles\6iwleti0.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll

FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll

FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npeRoom7.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-02-26 11:01

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\vsdatant]

"ImagePath"="a"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(860)

c:\windows\system32\wvauth.dll

c:\windows\system32\biolsp.dll

- - - - - - - > 'explorer.exe'(2088)

c:\windows\system32\WININET.dll

.

Completion time: 2010-02-26 11:03:53

ComboFix-quarantined-files.txt 2010-02-26 16:03

ComboFix2.txt 2010-02-24 18:36

ComboFix3.txt 2010-02-24 11:51

ComboFix4.txt 2010-02-24 10:17

ComboFix5.txt 2010-02-25 05:15

Pre-Run: 77,017,853,952 bytes free

Post-Run: 76,965,191,680 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 57962A3C1D082ABB35A3C1E1E43A3197

Link to post
Share on other sites

Hello, no need to apologize for the delay :)

We still have quite some work to do here, but first of all, I need to know if you have an XP CD at hand, we need to copy two files that are missing/corrupted. If you don't have a CD, maybe you can borrow one from a friend/family member.

Link to post
Share on other sites

Hello, welcome back :D

Please make sure you do the steps below in the order given, otherwise things will not work.

Insert your XP CD in the CD drive (I assume this is d:\, if not, please change the script below accordingly). I notice your log shows no CD drive, if this is the cause, post back here, do NOT continue!

If you can use your infected computers CD drive, you can continue safely.

Click Start > Run, type notepad in the runbox and press enter.

Copy/paste the text in the codebox below into Notepad and save it as copy.bat to your desktop.

@echo off
expand d:\i386\cdrom.sy_ c:\windows\system32\drivers\cdrom.sys
expand d:\i386\ndis.sy_ c:\windows\ndiscopy.sys

Exit Notepad and doubleclick on copy.bat to run it. This should copy two files to your computer. Afterwards, verify if the following file has been created: c:\windows\ndiscopy.sys

If this file has NOT been created, do NOT continue!

CF-SCRIPT

-------------

We need to execute a CF-script.

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Start > Run and in the box that opens type notepad and press enter. Copy/paste the text in the codebox below into it:

RenV::
c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray .exe
c:\program files\Common Files\Symantec Shared\ccapp .exe
c:\program files\Malwarebytes' Anti-Malware\tcjnwkjfk .exe

FCopy::
c:\windows\ndiscopy.sys | c:\windows\system32\drivers\ndis.sys

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Link to post
Share on other sites

Done and done. I've pasted the log below.

--------------------------------------------------------------------------------------------------------------------------------------------------------------------------

ComboFix 10-03-02.02 - aspeed 03/02/2010 18:49:42.16.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.2943 [GMT -5:00]

Running from: c:\documents and settings\aspeed\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\aspeed\Desktop\CFScript.txt

AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

--------------- FCopy ---------------

c:\windows\ndiscopy.sys --> c:\windows\system32\drivers\ndis.sys

.

((((((((((((((((((((((((( Files Created from 2010-02-02 to 2010-03-02 )))))))))))))))))))))))))))))))

.

2010-03-02 23:49 . 2010-03-02 23:49 -------- d-----w- c:\windows\LastGood

2010-03-02 23:44 . 2008-04-14 05:50 182656 ------w- c:\windows\ndiscopy.sys

2010-03-02 23:42 . 2004-08-04 03:59 49536 -c--a-w- c:\windows\system32\dllcache\cdrom.sys

2010-03-02 23:42 . 2004-08-04 03:59 49536 ----a-w- c:\windows\system32\drivers\cdrom.sys

2010-03-01 15:45 . 2010-03-01 16:49 -------- d-----w- C:\1-Flash Drive

2010-02-24 08:43 . 2010-02-24 08:43 -------- d-----w- c:\program files\Trend Micro

2010-02-24 04:16 . 2010-02-27 21:41 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-02-18 09:02 . 2010-02-18 09:02 -------- d-----w- C:\Autoruns

2010-02-17 10:33 . 2007-10-18 11:05 6895599 ----a-w- C:\Quantimed_FRENCH_FINAL_9.28.07.zip

2010-02-15 10:25 . 2010-02-15 10:25 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google

2010-02-15 10:07 . 2006-09-11 23:06 73728 ----a-w- c:\windows\system32\MouseWheelDVPNoReg.dll

2010-02-15 10:07 . 2010-02-22 10:04 -------- d-----w- c:\program files\SIGVIH

2010-02-11 08:55 . 2010-02-11 08:55 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google

2010-02-10 16:29 . 2010-02-10 16:29 -------- d-----w- C:\Sample Data

2010-02-05 14:23 . 2010-02-21 23:46 -------- d-----w- C:\EDT

2010-02-03 07:46 . 2010-02-03 07:46 -------- d-----w- C:\EDTBackup

2010-02-02 17:26 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-02-02 17:26 . 2010-03-02 23:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-02-02 17:26 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-02 15:45 . 2010-02-02 15:45 -------- d-----w- c:\program files\Restoration

2010-02-02 09:26 . 2010-02-02 09:26 -------- d-----r- C:\GraviTy

2010-02-02 08:23 . 2007-12-06 08:32 147968 ----a-w- c:\windows\7z.exe

2010-02-02 08:23 . 2007-02-25 17:06 122880 ----a-w- c:\windows\system32\blat.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-03-02 23:49 . 2006-07-12 16:35 -------- d-----w- c:\program files\Common Files\Symantec Shared

2010-03-02 23:34 . 2008-10-08 16:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Wave Systems Corp

2010-03-01 18:18 . 2008-10-08 16:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Skype

2010-03-01 16:09 . 2008-10-08 20:20 -------- d-----w- c:\documents and settings\aspeed\Application Data\skypePM

2010-02-23 21:27 . 2008-10-08 21:23 -------- d-----w- c:\documents and settings\aspeed\Application Data\DNA

2010-02-19 08:18 . 2007-07-31 17:36 13072 ----a-w- c:\windows\system32\nvModes.dat

2010-02-18 14:24 . 2008-10-08 19:38 -------- d-----w- c:\program files\Winamp

2010-02-18 14:23 . 2007-07-31 17:11 -------- d-----w- c:\program files\Wave Systems Corp

2010-02-18 14:22 . 2009-10-23 05:32 -------- d-----w- c:\program files\iTunes

2010-02-18 14:13 . 2009-10-23 05:30 -------- d-----w- c:\program files\QuickTime

2010-02-18 14:10 . 2007-07-31 17:08 -------- d-----w- c:\program files\Apoint

2010-02-15 11:39 . 2007-07-31 17:40 68848 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-02-15 10:10 . 2008-04-07 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-02-15 10:08 . 2006-07-12 17:11 -------- d-----w- c:\program files\Common Files\Adobe

2010-02-11 08:55 . 2008-07-16 22:36 -------- d-----w- c:\program files\Google

2010-02-10 17:15 . 2008-10-17 18:00 -------- d-----w- c:\program files\Replay Music 3

2010-02-10 17:15 . 2008-10-17 18:00 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL

2010-01-26 06:54 . 2010-01-26 06:54 -------- d-----w- c:\program files\Concepts Data Systems

2010-01-26 06:54 . 2006-07-12 18:19 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-01-22 03:53 . 2008-10-08 19:16 -------- d-----w- c:\program files\7-Zip

2010-01-13 04:10 . 2010-01-13 04:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Malwarebytes

2010-01-13 04:06 . 2010-01-13 04:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-01-11 05:50 . 2009-04-04 19:49 3309072 ----a-w- c:\documents and settings\aspeed\Application Data\YouSendIt\Downloads\YouSendIt_Express.exe

2009-12-21 19:14 . 2004-08-04 12:00 916480 ------w- c:\windows\system32\wininet.dll

2008-10-07 16:38 . 2008-10-07 16:38 153088 ----a-w- c:\program files\screen shot.doc

2009-12-17 13:51 . 2008-10-08 20:47 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll

.

------- Sigcheck -------

[-] 2010-02-18 08:26 . 1F4761387E0D5586FF86EBE19E00B86E . 212736 . . [------] . . c:\windows\system32\dllcache\ndis.sys

[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\LastGood\system32\drivers\ndis.sys

[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys

[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys

.

((((((((((((((((((((((((((((( SnapShot@2010-02-20_23.09.18 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-03-02 23:32 . 2010-03-02 23:32 16384 c:\windows\Temp\Perflib_Perfdata_a24.dat

+ 2010-03-02 23:31 . 2010-03-02 23:31 16384 c:\windows\Temp\Perflib_Perfdata_24c.dat

+ 2006-07-12 13:12 . 2010-02-27 16:19 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

- 2006-07-12 13:12 . 2010-02-20 16:14 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

+ 2006-07-12 13:12 . 2010-02-27 16:19 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

- 2006-07-12 13:12 . 2010-02-20 16:14 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2010-02-27 15:52 . 2010-02-27 16:19 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GoToMeeting"="c:\program files\Citrix\GoToMeeting\320\g2mstart.exe" [2008-09-05 31552]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-17 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]

"nwiz"="nwiz.exe" [2007-04-28 1626112]

"NVHotkey"="nvHotkey.dll" [2007-04-28 67584]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]

"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]

"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]

"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-25 159744]

"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2007-01-31 176128]

"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]

"Document Manager"="c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2007-01-30 102400]

"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2007-02-01 65536]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-17 30192]

"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]

"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]

"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-01-22 212992]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2006-7-12 25214]

Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]

Power Ge'ez 2005.lnk - c:\program files\Concepts Data Systems\Power Ge'ez 2005\pg2005.exe [2010-1-26 454656]

TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-10-24 278528]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\MSN Messenger\\livecall.exe"=

"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=

"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 cdfdrv;Cdfdrv;c:\windows\system32\drivers\cdfdrv.sys [10/09/2006 11:27 AM 21744]

R2 ctxpidmn;ctxpidmn;c:\windows\system32\drivers\ctxpidmn.sys [02/09/2007 6:51 PM 22952]

R2 CtxSbx;CtxSbx;c:\windows\system32\drivers\CtxSbx.sys [02/09/2007 7:23 PM 161320]

R2 iPCAgent;iPCAgent;c:\program files\iPass\iPassConnect CGNET Travel Access\iPCAgent.exe [07/12/2006 1:19 PM 90112]

R2 RadeSvc;Citrix Streaming Service;c:\program files\Citrix\Streaming Client\RadeSvc.exe [02/09/2007 6:55 PM 241664]

R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [08/04/2004 7:00 AM 5120]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [01/12/2010 9:55 PM 102448]

S0 ktmsixpn;ktmsixpn;c:\windows\system32\drivers\pakc.sys --> c:\windows\system32\drivers\pakc.sys [?]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [02/11/2010 3:55 AM 135664]

S3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/02/2006 11:32 AM 97536]

S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\googledesktop.exe [10/08/2008 3:47 PM 30192]

.

Contents of the 'Scheduled Tasks' folder

2010-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-11 08:55]

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-11 08:55]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = hxxp://www.msh.org/

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

LSP: c:\windows\system32\biolsp.dll

Trusted Zone: msh.org\ctt

DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} - hxxp://eroom.msh.org/eRoomSetup/client.cab

DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab

FF - ProfilePath - c:\documents and settings\aspeed\Application Data\Mozilla\Firefox\Profiles\6iwleti0.default\

FF - prefs.js: browser.startup.homepage - www.google.com/ig

FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll

FF - plugin: c:\documents and settings\aspeed\Application Data\Mozilla\Firefox\Profiles\6iwleti0.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll

FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll

FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npeRoom7.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-BitTorrent DNA - c:\program files\DNA\btdna.exe

HKCU-Run-SyncMan - c:\documents and settings\aspeed\SyncMan.exe

HKLM-Run-SyncMan - c:\windows\system32\SyncMan.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-03-02 18:54

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\vsdatant]

"ImagePath"="a"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(1264)

c:\windows\system32\wvauth.dll

c:\windows\system32\biolsp.dll

c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(4704)

c:\windows\system32\WININET.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\msi.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

Completion time: 2010-03-02 18:56:58

ComboFix-quarantined-files.txt 2010-03-02 23:56

ComboFix2.txt 2010-02-26 16:03

ComboFix3.txt 2010-02-24 18:36

ComboFix4.txt 2010-02-24 11:51

ComboFix5.txt 2010-03-02 23:48

Pre-Run: 73,215,651,840 bytes free

Post-Run: 73,165,524,992 bytes free

- - End Of File - - 3F65B92D37160AEDB0882FD84F4BFA60

Link to post
Share on other sites

Can you please let me know how everything is running now?

Before continuing, I want to have a closer look at ndis.sys. It seems that the file replacement we attempted with Combofix somehow did not work.

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1

Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    ndis.sys
    ndiscopy.sys


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

Link to post
Share on other sites

My computer is actually running fairly well, but there are still some lingering infections that keep popping up and slowing my machine down.

I've pasted the logfile from System Look below.

-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

SystemLook v1.0 by jpshortstuff (11.01.10)

Log created at 09:41 on 03/03/2010 by aspeed (Administrator - Elevation successful)

========== filefind ==========

Searching for "ndis.sys"

C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys --a--- 182656 bytes [22:18 17/09/2008] [19:20 13/04/2008] 1DF7F42665C94B825322FAE71721130D

C:\WINDOWS\system32\dllcache\ndis.sys --a--c 212736 bytes [12:00 04/08/2004] [08:26 18/02/2010] (Unable to calculate MD5)

C:\WINDOWS\system32\drivers\ndis.sys --a--- 182656 bytes [12:00 04/08/2004] [05:50 14/04/2008] 1DF7F42665C94B825322FAE71721130D

Searching for "ndiscopy.sys"

C:\WINDOWS\ndiscopy.sys ------ 182656 bytes [23:44 02/03/2010] [05:50 14/04/2008] 1DF7F42665C94B825322FAE71721130D

-=End Of File=-

Link to post
Share on other sites

As long as ndis.sys is still infected, it makes no sense to go after the other infections. The rootkit will protect them most likely.

Please try to rename c:\windows\ndiscopy.sys to ndis.sys

You can do that by right clicking on ndiscopy.sys and clicking "rename". ONLY if this is succesful, please re-run Combofix. Otherwise, post back here.

Link to post
Share on other sites

I renamed the file as requested without incident. I then re-ran CF (without using the script from the previous reply). The log file is below.

------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

ComboFix 10-03-03.03 - aspeed 03/03/2010 17:51:52.17.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.2814 [GMT -5:00]

Running from: c:\documents and settings\aspeed\Desktop\ComboFix.exe

AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

.

((((((((((((((((((((((((( Files Created from 2010-02-03 to 2010-03-03 )))))))))))))))))))))))))))))))

.

2010-03-03 05:21 . 2010-03-03 05:21 -------- d-----w- c:\program files\iPod

2010-03-03 05:21 . 2010-03-03 05:22 -------- d-----w- c:\program files\iTunes

2010-03-03 05:19 . 2010-03-03 05:19 -------- d-----w- c:\program files\QuickTime

2010-03-03 05:06 . 2010-03-03 05:06 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe

2010-03-02 23:44 . 2008-04-14 05:50 182656 ----a-w- c:\windows\ndis.sys

2010-03-02 23:42 . 2004-08-04 03:59 49536 -c--a-w- c:\windows\system32\dllcache\cdrom.sys

2010-03-02 23:42 . 2004-08-04 03:59 49536 ----a-w- c:\windows\system32\drivers\cdrom.sys

2010-03-01 15:45 . 2010-03-01 16:49 -------- d-----w- C:\1-Flash Drive

2010-02-24 08:43 . 2010-02-24 08:43 -------- d-----w- c:\program files\Trend Micro

2010-02-24 04:16 . 2010-02-27 21:41 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-02-18 09:02 . 2010-02-18 09:02 -------- d-----w- C:\Autoruns

2010-02-17 10:33 . 2007-10-18 11:05 6895599 ----a-w- C:\Quantimed_FRENCH_FINAL_9.28.07.zip

2010-02-15 10:25 . 2010-02-15 10:25 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google

2010-02-15 10:07 . 2006-09-11 23:06 73728 ----a-w- c:\windows\system32\MouseWheelDVPNoReg.dll

2010-02-15 10:07 . 2010-02-22 10:04 -------- d-----w- c:\program files\SIGVIH

2010-02-11 08:55 . 2010-02-11 08:55 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google

2010-02-10 16:29 . 2010-02-10 16:29 -------- d-----w- C:\Sample Data

2010-02-05 14:23 . 2010-02-21 23:46 -------- d-----w- C:\EDT

2010-02-03 07:46 . 2010-02-03 07:46 -------- d-----w- C:\EDTBackup

2010-02-02 17:26 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-02-02 17:26 . 2010-03-02 23:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-02-02 17:26 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-02 15:45 . 2010-02-02 15:45 -------- d-----w- c:\program files\Restoration

2010-02-02 09:26 . 2010-02-02 09:26 -------- d-----r- C:\GraviTy

2010-02-02 08:23 . 2007-12-06 08:32 147968 ----a-w- c:\windows\7z.exe

2010-02-02 08:23 . 2007-02-25 17:06 122880 ----a-w- c:\windows\system32\blat.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-03-03 22:49 . 2008-10-08 16:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Skype

2010-03-03 22:45 . 2008-10-08 20:20 -------- d-----w- c:\documents and settings\aspeed\Application Data\skypePM

2010-03-03 14:40 . 2006-07-12 17:11 -------- d-----w- c:\program files\Common Files\Adobe

2010-03-03 05:29 . 2008-10-08 19:19 -------- d-----w- c:\program files\EphPod

2010-03-03 05:21 . 2009-01-17 17:33 -------- d-----w- c:\program files\Common Files\Apple

2010-03-02 23:49 . 2006-07-12 16:35 -------- d-----w- c:\program files\Common Files\Symantec Shared

2010-03-02 23:34 . 2008-10-08 16:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Wave Systems Corp

2010-02-23 21:27 . 2008-10-08 21:23 -------- d-----w- c:\documents and settings\aspeed\Application Data\DNA

2010-02-19 08:18 . 2007-07-31 17:36 13072 ----a-w- c:\windows\system32\nvModes.dat

2010-02-18 14:24 . 2008-10-08 19:38 -------- d-----w- c:\program files\Winamp

2010-02-18 14:23 . 2007-07-31 17:11 -------- d-----w- c:\program files\Wave Systems Corp

2010-02-18 14:10 . 2007-07-31 17:08 -------- d-----w- c:\program files\Apoint

2010-02-15 11:39 . 2007-07-31 17:40 68848 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-02-15 10:10 . 2008-04-07 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-02-11 08:55 . 2008-07-16 22:36 -------- d-----w- c:\program files\Google

2010-02-10 17:15 . 2008-10-17 18:00 -------- d-----w- c:\program files\Replay Music 3

2010-02-10 17:15 . 2008-10-17 18:00 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL

2010-01-26 06:54 . 2010-01-26 06:54 -------- d-----w- c:\program files\Concepts Data Systems

2010-01-26 06:54 . 2006-07-12 18:19 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-01-22 03:53 . 2008-10-08 19:16 -------- d-----w- c:\program files\7-Zip

2010-01-13 04:10 . 2010-01-13 04:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Malwarebytes

2010-01-13 04:06 . 2010-01-13 04:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-01-11 05:50 . 2009-04-04 19:49 3309072 ----a-w- c:\documents and settings\aspeed\Application Data\YouSendIt\Downloads\YouSendIt_Express.exe

2009-12-21 19:14 . 2004-08-04 12:00 916480 ------w- c:\windows\system32\wininet.dll

2008-10-07 16:38 . 2008-10-07 16:38 153088 ----a-w- c:\program files\screen shot.doc

2009-12-17 13:51 . 2008-10-08 20:47 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll

.

------- Sigcheck -------

[-] 2010-02-18 08:26 . 1F4761387E0D5586FF86EBE19E00B86E . 212736 . . [------] . . c:\windows\system32\dllcache\ndis.sys

[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ndis.sys

[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys

[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys

.

((((((((((((((((((((((((((((( SnapShot@2010-02-20_23.09.18 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-03-03 05:41 . 2010-03-03 05:41 16384 c:\windows\Temp\Perflib_Perfdata_9b0.dat

+ 2010-03-03 05:40 . 2010-03-03 05:40 16384 c:\windows\Temp\Perflib_Perfdata_274.dat

+ 2006-07-12 13:12 . 2010-02-27 16:19 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

- 2006-07-12 13:12 . 2010-02-20 16:14 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

- 2006-07-12 13:12 . 2010-02-20 16:14 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2006-07-12 13:12 . 2010-02-27 16:19 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2010-03-03 00:00 . 2010-03-03 00:00 22528 c:\windows\Installer\1b0e57.msi

+ 2009-07-12 06:12 . 2009-07-12 06:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll

+ 2009-07-12 06:09 . 2009-07-12 06:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll

+ 2009-07-12 06:08 . 2009-07-12 06:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll

+ 2010-03-03 05:16 . 2010-03-03 05:16 796672 c:\windows\Installer\1358952.msi

+ 2010-03-03 05:22 . 2010-03-03 05:22 102400 c:\windows\Installer\{81063354-9060-42B2-A000-1EBE96778AA9}\iTunesIco.exe

+ 2010-03-03 05:22 . 2010-03-03 05:22 4449280 c:\windows\Installer\135937c.msi

+ 2010-03-03 05:19 . 2010-03-03 05:19 9473024 c:\windows\Installer\1358be2.msi

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GoToMeeting"="c:\program files\Citrix\GoToMeeting\320\g2mstart.exe" [2008-09-05 31552]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-17 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]

"nwiz"="nwiz.exe" [2007-04-28 1626112]

"NVHotkey"="nvHotkey.dll" [2007-04-28 67584]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]

"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]

"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-25 159744]

"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2007-01-31 176128]

"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]

"Document Manager"="c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2007-01-30 102400]

"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2007-02-01 65536]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-17 30192]

"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]

"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]

"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-01-22 212992]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2006-7-12 25214]

Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]

Power Ge'ez 2005.lnk - c:\program files\Concepts Data Systems\Power Ge'ez 2005\pg2005.exe [2010-1-26 454656]

TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-10-24 278528]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\MSN Messenger\\livecall.exe"=

"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=

"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 cdfdrv;Cdfdrv;c:\windows\system32\drivers\cdfdrv.sys [10/09/2006 11:27 AM 21744]

R2 ctxpidmn;ctxpidmn;c:\windows\system32\drivers\ctxpidmn.sys [02/09/2007 6:51 PM 22952]

R2 CtxSbx;CtxSbx;c:\windows\system32\drivers\CtxSbx.sys [02/09/2007 7:23 PM 161320]

R2 iPCAgent;iPCAgent;c:\program files\iPass\iPassConnect CGNET Travel Access\iPCAgent.exe [07/12/2006 1:19 PM 90112]

R2 RadeSvc;Citrix Streaming Service;c:\program files\Citrix\Streaming Client\RadeSvc.exe [02/09/2007 6:55 PM 241664]

R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [08/04/2004 7:00 AM 5120]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [01/12/2010 9:55 PM 102448]

S0 ktmsixpn;ktmsixpn;c:\windows\system32\drivers\pakc.sys --> c:\windows\system32\drivers\pakc.sys [?]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [02/11/2010 3:55 AM 135664]

S3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/02/2006 11:32 AM 97536]

S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\googledesktop.exe [10/08/2008 3:47 PM 30192]

.

Contents of the 'Scheduled Tasks' folder

2010-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-11 08:55]

2010-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-11 08:55]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = hxxp://www.msh.org/

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

LSP: c:\windows\system32\biolsp.dll

Trusted Zone: msh.org\ctt

DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} - hxxp://eroom.msh.org/eRoomSetup/client.cab

FF - ProfilePath - c:\documents and settings\aspeed\Application Data\Mozilla\Firefox\Profiles\6iwleti0.default\

FF - prefs.js: browser.startup.homepage - www.google.com/ig

FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll

FF - plugin: c:\documents and settings\aspeed\Application Data\Mozilla\Firefox\Profiles\6iwleti0.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll

FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll

FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npeRoom7.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-03-03 17:55

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\vsdatant]

"ImagePath"="a"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1208)

c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(1264)

c:\windows\system32\wvauth.dll

c:\windows\system32\biolsp.dll

c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(4108)

c:\windows\system32\WININET.dll

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

Completion time: 2010-03-03 17:57:25

ComboFix-quarantined-files.txt 2010-03-03 22:57

ComboFix2.txt 2010-03-02 23:56

ComboFix3.txt 2010-02-26 16:03

ComboFix4.txt 2010-02-24 18:36

ComboFix5.txt 2010-03-03 22:51

Pre-Run: 71,861,383,168 bytes free

Post-Run: 72,027,860,992 bytes free

- - End Of File - - 5DDDA03DB658B85373210A1AD3A528BC

Link to post
Share on other sites

We have one stubborn file here B) Lets see if we can replace it another way.

  • Please download TDSSKiller.zip and save it to your desktop.
  • Extract the zip file to your desktop (important, before continuing, make sure the file is located on your desktop, otherwise the following steps will not work!). Do NOT run the file yet!
  • Click Start > Run and copy paste the following bolded text in the run box
    "%userprofile%\desktop\tdsskiller.exe" -l report.txt
  • When it finished press any key to continue.
  • If needed reboot the computer.

A logfile (report.txt) will be created on your desktop. Please post its contents in your next reply.

Link to post
Share on other sites

Okay - completed. I'm pasting the logfile below.

---------------------------------------------------------------------------------------------------------------------------------------------------------------------

15:15:34:071 2760 TDSS rootkit removing tool 2.2.7.1 Feb 27 2010 13:29:25

15:15:34:071 2760 ================================================================================

15:15:34:071 2760 SystemInfo:

15:15:34:071 2760 OS Version: 5.1.2600 ServicePack: 2.0

15:15:34:071 2760 Product type: Workstation

15:15:34:071 2760 ComputerName: VA-ASPEED1

15:15:34:071 2760 UserName: aspeed

15:15:34:071 2760 Windows directory: C:\WINDOWS

15:15:34:071 2760 Processor architecture: Intel x86

15:15:34:071 2760 Number of processors: 1

15:15:34:071 2760 Page size: 0x1000

15:15:34:071 2760 Boot type: Normal boot

15:15:34:071 2760 ================================================================================

15:15:34:071 2760 UnloadDriverW: NtUnloadDriver error 2

15:15:34:071 2760 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2

15:15:34:101 2760 Initialize success

15:15:34:101 2760

15:15:34:101 2760 Scanning Services ...

15:15:34:101 2760 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system

15:15:34:101 2760 wfopen_ex: MyNtCreateFileW error 32 (C0000043)

15:15:34:101 2760 wfopen_ex: Trying to KLMD file open

15:15:34:101 2760 wfopen_ex: File opened ok (Flags 2)

15:15:34:101 2760 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software

15:15:34:101 2760 wfopen_ex: MyNtCreateFileW error 32 (C0000043)

15:15:34:101 2760 wfopen_ex: Trying to KLMD file open

15:15:34:101 2760 wfopen_ex: File opened ok (Flags 2)

15:15:34:241 2760 GetAdvancedServicesInfo: Raw services enum returned 404 services

15:15:34:241 2760 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system

15:15:34:241 2760 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software

15:15:34:241 2760

15:15:34:241 2760 Scanning Kernel memory ...

15:15:34:241 2760 Devices to scan: 2

15:15:34:241 2760

15:15:34:241 2760 Driver Name: Disk

15:15:34:241 2760 IRP_MJ_CREATE : BA18EC30

15:15:34:241 2760 IRP_MJ_CREATE_NAMED_PIPE : 804F3538

15:15:34:241 2760 IRP_MJ_CLOSE : BA18EC30

15:15:34:241 2760 IRP_MJ_READ : BA188D9B

15:15:34:241 2760 IRP_MJ_WRITE : BA188D9B

15:15:34:241 2760 IRP_MJ_QUERY_INFORMATION : 804F3538

15:15:34:241 2760 IRP_MJ_SET_INFORMATION : 804F3538

15:15:34:241 2760 IRP_MJ_QUERY_EA : 804F3538

15:15:34:241 2760 IRP_MJ_SET_EA : 804F3538

15:15:34:241 2760 IRP_MJ_FLUSH_BUFFERS : BA189366

15:15:34:241 2760 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F3538

15:15:34:241 2760 IRP_MJ_SET_VOLUME_INFORMATION : 804F3538

15:15:34:241 2760 IRP_MJ_DIRECTORY_CONTROL : 804F3538

15:15:34:241 2760 IRP_MJ_FILE_SYSTEM_CONTROL : 804F3538

15:15:34:241 2760 IRP_MJ_DEVICE_CONTROL : BA18944D

15:15:34:241 2760 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA18CFC3

15:15:34:241 2760 IRP_MJ_SHUTDOWN : BA189366

15:15:34:241 2760 IRP_MJ_LOCK_CONTROL : 804F3538

15:15:34:241 2760 IRP_MJ_CLEANUP : 804F3538

15:15:34:241 2760 IRP_MJ_CREATE_MAILSLOT : 804F3538

15:15:34:241 2760 IRP_MJ_QUERY_SECURITY : 804F3538

15:15:34:241 2760 IRP_MJ_SET_SECURITY : 804F3538

15:15:34:241 2760 IRP_MJ_POWER : BA18AEF3

15:15:34:241 2760 IRP_MJ_SYSTEM_CONTROL : BA18FA24

15:15:34:241 2760 IRP_MJ_DEVICE_CHANGE : 804F3538

15:15:34:241 2760 IRP_MJ_QUERY_QUOTA : 804F3538

15:15:34:241 2760 IRP_MJ_SET_QUOTA : 804F3538

15:15:34:241 2760 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code

15:15:34:241 2760 sion

15:15:34:262 2760 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean

15:15:34:262 2760

15:15:34:262 2760 Driver Name: iaStor

15:15:34:262 2760 IRP_MJ_CREATE : B9E8B818

15:15:34:262 2760 IRP_MJ_CREATE_NAMED_PIPE : 804F3538

15:15:34:262 2760 IRP_MJ_CLOSE : B9E8B818

15:15:34:262 2760 IRP_MJ_READ : 804F3538

15:15:34:262 2760 IRP_MJ_WRITE : 804F3538

15:15:34:262 2760 IRP_MJ_QUERY_INFORMATION : 804F3538

15:15:34:262 2760 IRP_MJ_SET_INFORMATION : 804F3538

15:15:34:262 2760 IRP_MJ_QUERY_EA : 804F3538

15:15:34:262 2760 IRP_MJ_SET_EA : 804F3538

15:15:34:262 2760 IRP_MJ_FLUSH_BUFFERS : 804F3538

15:15:34:262 2760 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F3538

15:15:34:262 2760 IRP_MJ_SET_VOLUME_INFORMATION : 804F3538

15:15:34:262 2760 IRP_MJ_DIRECTORY_CONTROL : 804F3538

15:15:34:262 2760 IRP_MJ_FILE_SYSTEM_CONTROL : 804F3538

15:15:34:262 2760 IRP_MJ_DEVICE_CONTROL : B9E89132

15:15:34:262 2760 IRP_MJ_INTERNAL_DEVICE_CONTROL : B9E86918

15:15:34:262 2760 IRP_MJ_SHUTDOWN : 804F3538

15:15:34:262 2760 IRP_MJ_LOCK_CONTROL : 804F3538

15:15:34:262 2760 IRP_MJ_CLEANUP : 804F3538

15:15:34:262 2760 IRP_MJ_CREATE_MAILSLOT : 804F3538

15:15:34:262 2760 IRP_MJ_QUERY_SECURITY : 804F3538

15:15:34:262 2760 IRP_MJ_SET_SECURITY : 804F3538

15:15:34:262 2760 IRP_MJ_POWER : B9E82AB4

15:15:34:262 2760 IRP_MJ_SYSTEM_CONTROL : B9E8207C

15:15:34:262 2760 IRP_MJ_DEVICE_CHANGE : 804F3538

15:15:34:262 2760 IRP_MJ_QUERY_QUOTA : 804F3538

15:15:34:262 2760 IRP_MJ_SET_QUOTA : 804F3538

15:15:34:262 2760 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code

15:15:34:262 2760 sion

15:15:34:272 2760 C:\WINDOWS\system32\drivers\iaStor.sys - Verdict: Clean

15:15:34:272 2760

15:15:34:272 2760 Completed

15:15:34:272 2760

15:15:34:272 2760 Results:

15:15:34:272 2760 Memory objects infected / cured / cured on reboot: 0 / 0 / 0

15:15:34:272 2760 Registry objects infected / cured / cured on reboot: 0 / 0 / 0

15:15:34:272 2760 File objects infected / cured / cured on reboot: 0 / 0 / 0

15:15:34:272 2760

15:15:34:272 2760 KLMD(ARK) unloaded successfully

Link to post
Share on other sites

Please click Start > Run, type sfc /scannow in the runbox and press enter.

Let the system file checker run unhindered and insert the XP CD if asked.

Afterwards, download a new copy of Combofix and run it. Post me the log please.

Link to post
Share on other sites

Okay. Results are split over two posts:

--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

ComboFix 10-03-09.04 - aspeed 03/09/2010 19:48:40.18.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.2753 [GMT -5:00]

Running from: c:\documents and settings\aspeed\Desktop\ComboFix.exe

AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

* Created a new restore point

.

((((((((((((((((((((((((( Files Created from 2010-02-10 to 2010-03-10 )))))))))))))))))))))))))))))))

.

2010-03-10 00:43 . 2004-08-04 05:56 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll

2010-03-10 00:43 . 2001-08-18 03:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll

2010-03-10 00:43 . 2001-08-18 03:36 17408 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll

2010-03-10 00:43 . 2001-08-18 03:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe

2010-03-10 00:43 . 2001-08-18 03:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe

2010-03-10 00:43 . 2001-08-18 03:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe

2010-03-10 00:43 . 2001-08-17 17:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys

2010-03-10 00:43 . 2004-08-04 03:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys

2010-03-10 00:43 . 2004-08-04 04:10 19328 -c--a-w- c:\windows\system32\dllcache\wstcodec.sys

2010-03-10 00:43 . 2004-08-04 03:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys

2010-03-10 00:43 . 2004-08-04 05:56 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll

2010-03-10 00:43 . 2004-08-04 03:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys

2010-03-10 00:41 . 2001-08-17 18:49 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys

2010-03-10 00:40 . 2001-08-18 03:36 211968 -c--a-w- c:\windows\system32\dllcache\um54scan.dll

2010-03-10 00:39 . 2001-08-17 17:13 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys

2010-03-10 00:38 . 2001-08-18 03:36 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll

2010-03-10 00:37 . 2001-08-18 03:36 28160 -c--a-w- c:\windows\system32\dllcache\sm91w.dll

2010-03-10 00:36 . 2001-08-17 18:53 6912 -c--a-w- c:\windows\system32\dllcache\seaddsmc.sys

2010-03-10 00:35 . 2001-08-18 03:36 79872 -c--a-w- c:\windows\system32\dllcache\rwia430.dll

2010-03-10 00:34 . 2001-08-17 18:28 130942 -c--a-w- c:\windows\system32\dllcache\ptserlv.sys

2010-03-10 00:33 . 2001-08-17 17:11 30282 -c--a-w- c:\windows\system32\dllcache\pcntn5hl.sys

2010-03-10 00:32 . 2001-08-17 17:50 198144 -c--a-w- c:\windows\system32\dllcache\nv3.sys

2010-03-10 00:31 . 2001-08-17 19:56 35392 -c--a-w- c:\windows\system32\dllcache\n9i128.dll

2010-03-10 00:30 . 2004-08-04 04:10 15360 -c--a-w- c:\windows\system32\dllcache\mpe.sys

2010-03-10 00:29 . 2001-08-17 17:12 20573 -c--a-w- c:\windows\system32\dllcache\lne100.sys

2010-03-10 00:28 . 2001-08-18 03:36 90200 -c--a-w- c:\windows\system32\dllcache\io8ports.dll

2010-03-10 00:27 . 2004-08-04 03:41 1041536 -c--a-w- c:\windows\system32\dllcache\hsfdpsp2.sys

2010-03-10 00:26 . 2001-08-18 03:36 123392 -c--a-w- c:\windows\system32\dllcache\hpgt21tk.dll

2010-03-10 00:25 . 2001-08-17 17:10 22090 -c--a-w- c:\windows\system32\dllcache\fem556n5.sys

2010-03-10 00:24 . 2001-08-17 18:28 241206 -c--a-w- c:\windows\system32\dllcache\el656se5.sys

2010-03-10 00:23 . 2001-08-18 03:36 256512 -c--a-w- c:\windows\system32\dllcache\devcon32.dll

2010-03-10 00:22 . 2004-08-04 04:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys

2010-03-10 00:21 . 2001-08-17 17:49 17152 -c--a-w- c:\windows\system32\dllcache\atitvsnd.sys

2010-03-10 00:20 . 2001-08-17 19:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll

2010-03-10 00:20 . 2010-03-10 00:43 -------- d-----w- c:\windows\LastGood

2010-03-03 05:21 . 2010-03-03 05:21 -------- d-----w- c:\program files\iPod

2010-03-03 05:21 . 2010-03-03 05:22 -------- d-----w- c:\program files\iTunes

2010-03-03 05:19 . 2010-03-03 05:19 -------- d-----w- c:\program files\QuickTime

2010-03-03 05:06 . 2010-03-03 05:06 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe

2010-03-02 23:44 . 2008-04-14 05:50 182656 ----a-w- c:\windows\ndis.sys

2010-03-02 23:42 . 2004-08-04 03:59 49536 -c--a-w- c:\windows\system32\dllcache\cdrom.sys

2010-03-02 23:42 . 2004-08-04 03:59 49536 ----a-w- c:\windows\system32\drivers\cdrom.sys

2010-03-01 15:45 . 2010-03-01 16:49 -------- d-----w- C:\1-Flash Drive

2010-02-24 08:43 . 2010-02-24 08:43 -------- d-----w- c:\program files\Trend Micro

2010-02-24 04:16 . 2010-02-27 21:41 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-02-18 09:02 . 2010-02-18 09:02 -------- d-----w- C:\Autoruns

2010-02-17 10:33 . 2007-10-18 11:05 6895599 ----a-w- C:\Quantimed_FRENCH_FINAL_9.28.07.zip

2010-02-15 10:25 . 2010-02-15 10:25 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google

2010-02-15 10:07 . 2006-09-11 23:06 73728 ----a-w- c:\windows\system32\MouseWheelDVPNoReg.dll

2010-02-15 10:07 . 2010-02-22 10:04 -------- d-----w- c:\program files\SIGVIH

2010-02-11 08:55 . 2010-02-11 08:55 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google

2010-02-10 16:29 . 2010-02-10 16:29 -------- d-----w- C:\Sample Data

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-03-10 00:19 . 2008-10-08 16:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Skype

2010-03-10 00:18 . 2008-10-08 20:20 -------- d-----w- c:\documents and settings\aspeed\Application Data\skypePM

2010-03-07 18:24 . 2008-10-08 16:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Wave Systems Corp

2010-03-04 12:03 . 2007-07-31 17:36 13072 ----a-w- c:\windows\system32\nvModes.dat

2010-03-03 14:40 . 2006-07-12 17:11 -------- d-----w- c:\program files\Common Files\Adobe

2010-03-03 05:29 . 2008-10-08 19:19 -------- d-----w- c:\program files\EphPod

2010-03-03 05:21 . 2009-01-17 17:33 -------- d-----w- c:\program files\Common Files\Apple

2010-03-02 23:49 . 2010-02-02 17:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-03-02 23:49 . 2006-07-12 16:35 -------- d-----w- c:\program files\Common Files\Symantec Shared

2010-02-23 21:27 . 2008-10-08 21:23 -------- d-----w- c:\documents and settings\aspeed\Application Data\DNA

2010-02-18 14:24 . 2008-10-08 19:38 -------- d-----w- c:\program files\Winamp

2010-02-18 14:23 . 2007-07-31 17:11 -------- d-----w- c:\program files\Wave Systems Corp

2010-02-18 14:10 . 2007-07-31 17:08 -------- d-----w- c:\program files\Apoint

2010-02-15 11:39 . 2007-07-31 17:40 68848 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-02-15 10:10 . 2008-04-07 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-02-11 08:55 . 2008-07-16 22:36 -------- d-----w- c:\program files\Google

2010-02-10 17:15 . 2008-10-17 18:00 -------- d-----w- c:\program files\Replay Music 3

2010-02-10 17:15 . 2008-10-17 18:00 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL

2010-02-02 15:45 . 2010-02-02 15:45 -------- d-----w- c:\program files\Restoration

2010-01-26 06:54 . 2010-01-26 06:54 -------- d-----w- c:\program files\Concepts Data Systems

2010-01-26 06:54 . 2006-07-12 18:19 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-01-22 03:53 . 2008-10-08 19:16 -------- d-----w- c:\program files\7-Zip

2010-01-13 04:10 . 2010-01-13 04:10 -------- d-----w- c:\documents and settings\aspeed\Application Data\Malwarebytes

2010-01-13 04:06 . 2010-01-13 04:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-01-11 05:50 . 2009-04-04 19:49 3309072 ----a-w- c:\documents and settings\aspeed\Application Data\YouSendIt\Downloads\YouSendIt_Express.exe

2010-01-07 21:07 . 2010-02-02 17:26 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-01-07 21:07 . 2010-02-02 17:26 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-12-21 19:14 . 2004-08-04 12:00 916480 ------w- c:\windows\system32\wininet.dll

2008-10-07 16:38 . 2008-10-07 16:38 153088 ----a-w- c:\program files\screen shot.doc

2009-12-17 13:51 . 2008-10-08 20:47 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll

2007-06-21 22:38 . 2007-06-21 22:38 30280 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll

2007-06-21 23:38 . 2007-06-21 23:38 79432 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll

2007-06-21 23:38 . 2007-06-21 23:38 71240 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll

2007-06-21 22:38 . 2007-06-21 22:38 140872 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll

2007-06-21 22:39 . 2007-06-21 22:39 38472 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll

2007-06-21 22:39 . 2007-06-21 22:39 46664 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll

2007-06-21 23:39 . 2007-06-21 23:39 34376 ----a-w- c:\program files\mozilla firefox\plugins\logging.dll

2007-06-21 22:39 . 2007-06-21 22:39 685640 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll

2007-06-21 23:40 . 2007-06-21 23:40 30280 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll

.

------- Sigcheck -------

[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ndis.sys

[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\LastGood\system32\drivers\ndis.sys

[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys

[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys

.

((((((((((((((((((((((((((((( SnapShot@2010-02-20_23.09.18 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-03-03 05:41 . 2010-03-03 05:41 16384 c:\windows\Temp\Perflib_Perfdata_9b0.dat

+ 2010-03-03 05:40 . 2010-03-03 05:40 16384 c:\windows\Temp\Perflib_Perfdata_274.dat

+ 2004-08-04 12:00 . 2004-08-04 12:00 69120 c:\windows\system32\notepad.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 13894 c:\windows\system32\dllcache\zonelibm.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 13894 c:\windows\system32\dllcache\zonelibm.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 29760 c:\windows\system32\dllcache\znetm.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 29760 c:\windows\system32\dllcache\znetm.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 41029 c:\windows\system32\dllcache\zcorem.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 41029 c:\windows\system32\dllcache\zcorem.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 36937 c:\windows\system32\dllcache\zclientm.exe

+ 2007-07-31 14:37 . 2008-04-14 12:00 36937 c:\windows\system32\dllcache\zclientm.exe

+ 2004-08-04 00:56 . 2004-08-04 12:00 51712 c:\windows\system32\dllcache\wzcsapi.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 13824 c:\windows\system32\dllcache\wowfaxui.dll

+ 2010-03-10 00:42 . 2001-08-17 17:12 34890 c:\windows\system32\dllcache\wlandrv2.sys

+ 2010-03-10 00:42 . 2001-08-18 03:36 53760 c:\windows\system32\dllcache\wiamsmud.dll

+ 2010-03-10 00:42 . 2001-08-18 03:36 87040 c:\windows\system32\dllcache\wiafbdrv.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 31232 c:\windows\system32\dllcache\weitekp9.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 31232 c:\windows\system32\dllcache\weitekp9.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 41600 c:\windows\system32\dllcache\weitekp9.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 41600 c:\windows\system32\dllcache\weitekp9.dll

+ 2004-08-03 23:15 . 2004-08-04 12:00 82944 c:\windows\system32\dllcache\wdmaud.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 23615 c:\windows\system32\dllcache\wch7xxnt.sys

+ 2010-03-10 00:42 . 2004-08-04 04:08 31744 c:\windows\system32\dllcache\wceusbsh.sys

+ 2010-03-10 00:42 . 2001-08-17 17:10 35871 c:\windows\system32\dllcache\wbfirdma.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 25471 c:\windows\system32\dllcache\watv10nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 22271 c:\windows\system32\dllcache\watv06nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 33599 c:\windows\system32\dllcache\watv04nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 19551 c:\windows\system32\dllcache\watv02nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 29311 c:\windows\system32\dllcache\watv01nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 11935 c:\windows\system32\dllcache\wadv11nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 11871 c:\windows\system32\dllcache\wadv09nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 11295 c:\windows\system32\dllcache\wadv08nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 11807 c:\windows\system32\dllcache\wadv07nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 11775 c:\windows\system32\dllcache\wadv05nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 12127 c:\windows\system32\dllcache\wadv02nt.sys

+ 2010-03-10 00:42 . 2004-08-04 03:29 12415 c:\windows\system32\dllcache\wadv01nt.sys

+ 2010-03-10 00:42 . 2004-08-04 04:04 13568 c:\windows\system32\dllcache\wacompen.sys

+ 2010-03-10 00:42 . 2001-08-17 17:13 16925 c:\windows\system32\dllcache\w940nd.sys

+ 2010-03-10 00:42 . 2001-08-17 17:13 19016 c:\windows\system32\dllcache\w926nd.sys

+ 2010-03-10 00:42 . 2001-08-17 17:13 19528 c:\windows\system32\dllcache\w840nd.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 73728 c:\windows\system32\dllcache\w3ext.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 73728 c:\windows\system32\dllcache\w3ext.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 48256 c:\windows\system32\dllcache\w32.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 48256 c:\windows\system32\dllcache\w32.dll

+ 2010-03-10 00:42 . 2001-08-17 18:28 64605 c:\windows\system32\dllcache\vvoice.sys

+ 2010-03-10 00:41 . 2004-08-04 05:56 53760 c:\windows\system32\dllcache\vfwwdm32.dll

+ 2001-08-17 14:02 . 2004-08-04 12:00 58112 c:\windows\system32\dllcache\vdmindvd.sys

+ 2010-03-10 00:41 . 2004-08-04 05:56 11325 c:\windows\system32\dllcache\vchnt5.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 49211 c:\windows\system32\dllcache\usrvpa.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 45116 c:\windows\system32\dllcache\usrvoica.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 49209 c:\windows\system32\dllcache\usrv80a.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 41019 c:\windows\system32\dllcache\usrsvpia.dll

+ 2001-08-17 22:37 . 2004-08-04 12:00 69700 c:\windows\system32\dllcache\usrshuta.exe

+ 2001-08-17 22:36 . 2004-08-04 12:00 49211 c:\windows\system32\dllcache\usrsdpia.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 77883 c:\windows\system32\dllcache\usrrtosa.dll

+ 2001-08-17 22:37 . 2004-08-04 12:00 61508 c:\windows\system32\dllcache\usrprbda.exe

+ 2001-08-17 22:37 . 2004-08-04 12:00 77891 c:\windows\system32\dllcache\usrmlnka.exe

+ 2001-08-17 22:36 . 2004-08-04 12:00 53305 c:\windows\system32\dllcache\usrlbva.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 86073 c:\windows\system32\dllcache\usrfaxa.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 77890 c:\windows\system32\dllcache\usrdpa.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 69699 c:\windows\system32\dllcache\usrcoina.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 61500 c:\windows\system32\dllcache\usrcntra.dll

+ 2010-03-10 00:41 . 2004-08-04 04:10 78464 c:\windows\system32\dllcache\usbvideo.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 26496 c:\windows\system32\dllcache\usbstor.sys

+ 2010-03-10 00:41 . 2004-08-04 04:08 25600 c:\windows\system32\dllcache\usbser.sys

+ 2010-03-10 00:41 . 2004-08-04 04:08 17024 c:\windows\system32\dllcache\usbohci.sys

+ 2004-08-03 23:08 . 2004-08-04 12:00 16000 c:\windows\system32\dllcache\usbintel.sys

+ 2001-08-17 14:03 . 2004-08-04 12:00 23936 c:\windows\system32\dllcache\usbcamd2.sys

+ 2001-08-17 14:03 . 2004-08-04 12:00 23808 c:\windows\system32\dllcache\usbcamd.sys

+ 2010-03-10 00:41 . 2004-08-04 04:04 12672 c:\windows\system32\dllcache\usb8023x.sys

+ 2010-03-10 00:41 . 2004-08-04 03:31 32384 c:\windows\system32\dllcache\usb101et.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 32339 c:\windows\system32\dllcache\uniansi.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 32339 c:\windows\system32\dllcache\uniansi.dll

+ 2010-03-10 00:41 . 2001-08-18 03:36 94720 c:\windows\system32\dllcache\umaxud32.dll

+ 2010-03-10 00:41 . 2001-08-18 03:36 28160 c:\windows\system32\dllcache\umaxu40.dll

+ 2010-03-10 00:41 . 2001-08-18 03:36 26624 c:\windows\system32\dllcache\umaxu22.dll

+ 2010-03-10 00:41 . 2001-08-18 03:36 69632 c:\windows\system32\dllcache\umaxu12.dll

+ 2010-03-10 00:41 . 2001-08-18 03:36 50688 c:\windows\system32\dllcache\umaxscan.dll

+ 2010-03-10 00:41 . 2001-08-17 18:58 22912 c:\windows\system32\dllcache\umaxpcls.sys

+ 2010-03-10 00:41 . 2001-08-18 03:36 50176 c:\windows\system32\dllcache\umaxp60.dll

+ 2010-03-10 00:41 . 2001-08-18 03:36 47616 c:\windows\system32\dllcache\umaxcam.dll

+ 2004-08-03 23:07 . 2004-08-04 12:00 44672 c:\windows\system32\dllcache\uagp35.sys

+ 2010-03-10 00:40 . 2001-08-17 18:48 11520 c:\windows\system32\dllcache\twotrack.sys

+ 2004-08-03 23:03 . 2004-08-04 12:00 12416 c:\windows\system32\dllcache\tunmp.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 14336 c:\windows\system32\dllcache\tsprof.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\tsprof.exe

+ 2001-08-17 14:06 . 2004-08-04 12:00 21376 c:\windows\system32\dllcache\tsbvcap.sys

+ 2010-03-10 00:40 . 2001-08-17 17:12 34375 c:\windows\system32\dllcache\tpro4.sys

+ 2010-03-10 00:40 . 2001-08-18 03:35 42496 c:\windows\system32\dllcache\tp4res.dll

+ 2010-03-10 00:40 . 2004-08-04 05:56 82432 c:\windows\system32\dllcache\tp4mon.exe

+ 2010-03-10 00:40 . 2001-08-18 03:36 31744 c:\windows\system32\dllcache\tp4.dll

+ 2001-08-17 14:01 . 2004-08-04 12:00 51712 c:\windows\system32\dllcache\tosdvd.sys

+ 2010-03-10 00:40 . 2001-08-17 17:10 28232 c:\windows\system32\dllcache\tos4mo.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 44032 c:\windows\system32\dllcache\tintlphr.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 44032 c:\windows\system32\dllcache\tintlphr.exe

+ 2010-03-10 00:40 . 2001-08-17 19:56 81408 c:\windows\system32\dllcache\tgiul50.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 19464 c:\windows\system32\dllcache\tdspx.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 19464 c:\windows\system32\dllcache\tdspx.sys

+ 2010-03-10 00:39 . 2001-08-17 17:13 37961 c:\windows\system32\dllcache\tdk100b.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 21896 c:\windows\system32\dllcache\tdipx.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 21896 c:\windows\system32\dllcache\tdipx.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 13192 c:\windows\system32\dllcache\tdasync.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 13192 c:\windows\system32\dllcache\tdasync.sys

- 2007-07-31 14:34 . 2003-03-24 20:52 16384 c:\windows\system32\dllcache\tcptsat.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 16384 c:\windows\system32\dllcache\tcptsat.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 32827 c:\windows\system32\dllcache\tcptest.exe

+ 2007-07-31 14:34 . 2003-03-24 21:52 32827 c:\windows\system32\dllcache\tcptest.exe

+ 2010-03-10 00:39 . 2001-08-17 18:49 30464 c:\windows\system32\dllcache\tbatm155.sys

+ 2010-03-10 00:39 . 2001-08-17 17:50 36640 c:\windows\system32\dllcache\t2r4mini.sys

+ 2004-08-03 23:15 . 2004-08-04 12:00 60800 c:\windows\system32\dllcache\sysaudio.sys

+ 2010-03-10 00:39 . 2001-08-18 03:36 94293 c:\windows\system32\dllcache\sxports.dll

+ 2010-03-10 00:39 . 2001-08-18 03:36 10240 c:\windows\system32\dllcache\swpidflt.dll

+ 2010-03-10 00:39 . 2001-08-18 03:36 10240 c:\windows\system32\dllcache\swpdflt2.dll

+ 2001-08-17 14:00 . 2004-08-04 12:00 54272 c:\windows\system32\dllcache\swmidi.sys

+ 2010-03-10 00:39 . 2001-08-18 03:36 53760 c:\windows\system32\dllcache\sw_wheel.dll

+ 2010-03-10 00:39 . 2001-08-18 03:36 41472 c:\windows\system32\dllcache\sw_effct.dll

+ 2010-03-10 00:39 . 2004-08-04 04:10 15360 c:\windows\system32\dllcache\streamip.sys

+ 2010-03-10 00:39 . 2001-08-18 03:36 53248 c:\windows\system32\dllcache\stlncoin.dll

+ 2010-03-10 00:39 . 2001-08-17 18:51 16896 c:\windows\system32\dllcache\stcusb.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 16896 c:\windows\system32\dllcache\status.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 16896 c:\windows\system32\dllcache\status.dll

+ 2010-03-10 00:39 . 2001-08-17 17:11 48736 c:\windows\system32\dllcache\srwlnd5.sys

+ 2010-03-10 00:39 . 2001-08-18 03:36 99328 c:\windows\system32\dllcache\srusd.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 72192 c:\windows\system32\dllcache\sprio800.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 70656 c:\windows\system32\dllcache\sprio600.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 69632 c:\windows\system32\dllcache\spnike.dll

+ 2010-03-10 00:38 . 2001-08-17 18:51 61824 c:\windows\system32\dllcache\speed.sys

+ 2010-03-10 00:38 . 2001-08-17 17:51 37040 c:\windows\system32\dllcache\sonypi.sys

+ 2010-03-10 00:38 . 2001-08-17 17:51 20752 c:\windows\system32\dllcache\sonync.sys

+ 2004-08-03 23:09 . 2004-08-04 12:00 25472 c:\windows\system32\dllcache\sonydcam.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 56832 c:\windows\system32\dllcache\sol.exe

+ 2007-07-31 14:37 . 2008-04-14 12:00 56832 c:\windows\system32\dllcache\sol.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 10240 c:\windows\system32\dllcache\snmpstup.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 10240 c:\windows\system32\dllcache\snmpstup.dll

+ 2010-03-10 00:38 . 2001-08-17 17:51 58368 c:\windows\system32\dllcache\smiminib.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 15872 c:\windows\system32\dllcache\smierrsm.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 15872 c:\windows\system32\dllcache\smierrsm.dll

+ 2010-03-10 00:38 . 2001-08-17 17:12 25034 c:\windows\system32\dllcache\smcpwr2n.sys

+ 2010-03-10 00:38 . 2001-08-17 17:10 35913 c:\windows\system32\dllcache\smcirda.sys

+ 2010-03-10 00:38 . 2001-08-17 17:12 24576 c:\windows\system32\dllcache\smc8000n.sys

+ 2010-03-10 00:38 . 2004-08-04 04:07 16128 c:\windows\system32\dllcache\smbbatt.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\smb6w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 31744 c:\windows\system32\dllcache\smb6w.dll

+ 2010-03-10 00:38 . 2001-08-18 03:36 45568 c:\windows\system32\dllcache\smb3w.dll

+ 2010-03-10 00:38 . 2001-08-18 03:36 33792 c:\windows\system32\dllcache\smb0w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 31744 c:\windows\system32\dllcache\sma3w.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\sma3w.dll

+ 2010-03-10 00:38 . 2001-08-18 03:36 28672 c:\windows\system32\dllcache\sma0w.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 38912 c:\windows\system32\dllcache\sm9aw.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 38912 c:\windows\system32\dllcache\sm9aw.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 26624 c:\windows\system32\dllcache\sm93w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 26624 c:\windows\system32\dllcache\sm93w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 26624 c:\windows\system32\dllcache\sm92w.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 26624 c:\windows\system32\dllcache\sm92w.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 26112 c:\windows\system32\dllcache\sm90w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 26112 c:\windows\system32\dllcache\sm90w.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 26112 c:\windows\system32\dllcache\sm8dw.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 26112 c:\windows\system32\dllcache\sm8dw.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 29184 c:\windows\system32\dllcache\sm8cw.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 29184 c:\windows\system32\dllcache\sm8cw.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 26112 c:\windows\system32\dllcache\sm8aw.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 26112 c:\windows\system32\dllcache\sm8aw.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 26112 c:\windows\system32\dllcache\sm89w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 26112 c:\windows\system32\dllcache\sm89w.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 30208 c:\windows\system32\dllcache\sm87w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 30208 c:\windows\system32\dllcache\sm87w.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 30208 c:\windows\system32\dllcache\sm81w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 30208 c:\windows\system32\dllcache\sm81w.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 25088 c:\windows\system32\dllcache\sm59w.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 25088 c:\windows\system32\dllcache\sm59w.dll

+ 2010-03-10 00:37 . 2004-08-04 03:41 13240 c:\windows\system32\dllcache\slwdmsup.sys

+ 2010-03-10 00:37 . 2004-08-04 05:56 73796 c:\windows\system32\dllcache\slserv.exe

+ 2010-03-10 00:37 . 2004-08-04 05:56 32866 c:\windows\system32\dllcache\slrundll.exe

+ 2010-03-10 00:37 . 2004-08-04 03:41 95424 c:\windows\system32\dllcache\slnthal.sys

+ 2010-03-10 00:37 . 2004-08-04 04:10 11136 c:\windows\system32\dllcache\slip.sys

+ 2010-03-10 00:37 . 2004-08-04 05:56 73832 c:\windows\system32\dllcache\slcoinst.dll

+ 2010-03-10 00:37 . 2004-08-04 03:31 63547 c:\windows\system32\dllcache\sla30nd5.sys

+ 2010-03-10 00:37 . 2001-08-17 17:12 91294 c:\windows\system32\dllcache\skfpwin.sys

+ 2010-03-10 00:37 . 2001-08-17 17:12 94698 c:\windows\system32\dllcache\sk98xwin.sys

+ 2010-03-10 00:37 . 2001-08-17 17:50 50432 c:\windows\system32\dllcache\sisv.sys

+ 2010-03-10 00:37 . 2004-08-04 03:31 32768 c:\windows\system32\dllcache\sisnic.sys

+ 2010-03-10 00:37 . 2001-08-17 17:50 68608 c:\windows\system32\dllcache\sis6306p.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 18944 c:\windows\system32\dllcache\simptcp.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 18944 c:\windows\system32\dllcache\simptcp.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 42573 c:\windows\system32\dllcache\shvlzm.exe

+ 2007-07-31 14:37 . 2008-04-14 12:00 42573 c:\windows\system32\dllcache\shvlzm.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 66113 c:\windows\system32\dllcache\shvl.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 66113 c:\windows\system32\dllcache\shvl.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 16437 c:\windows\system32\dllcache\shtml.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 16437 c:\windows\system32\dllcache\shtml.exe

+ 2007-07-31 14:34 . 2003-03-24 21:52 20536 c:\windows\system32\dllcache\shtml.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 20536 c:\windows\system32\dllcache\shtml.dll

+ 2010-03-10 00:37 . 2001-07-21 19:29 18400 c:\windows\system32\dllcache\sgsmld.sys

+ 2010-03-10 00:37 . 2001-08-17 17:51 98080 c:\windows\system32\dllcache\sgiulnt5.sys

+ 2010-03-10 00:37 . 2001-08-17 17:19 36480 c:\windows\system32\dllcache\sfmanm.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 11392 c:\windows\system32\dllcache\sfloppy.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 10240 c:\windows\system32\dllcache\sffp_sd.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 11136 c:\windows\system32\dllcache\sffdisk.sys

+ 2010-03-10 00:37 . 2001-08-17 18:48 17664 c:\windows\system32\dllcache\sermouse.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 64896 c:\windows\system32\dllcache\serial.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 15488 c:\windows\system32\dllcache\serenum.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 29184 c:\windows\system32\dllcache\sdhcinst.dll

+ 2004-08-04 12:00 . 2004-08-04 12:00 67584 c:\windows\system32\dllcache\sdbus.sys

+ 2010-03-10 00:36 . 2001-08-17 18:53 10880 c:\windows\system32\dllcache\scsiscan.sys

+ 2010-03-10 00:36 . 2001-08-17 18:52 11648 c:\windows\system32\dllcache\scsiprnt.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 96256 c:\windows\system32\dllcache\scsiport.sys

+ 2010-03-10 00:36 . 2001-08-17 18:51 17280 c:\windows\system32\dllcache\scr111.sys

+ 2010-03-10 00:36 . 2001-08-17 18:51 16640 c:\windows\system32\dllcache\scmstcs.sys

+ 2010-03-10 00:36 . 2001-08-17 18:51 23936 c:\windows\system32\dllcache\sccmusbm.sys

+ 2010-03-10 00:36 . 2001-08-17 18:51 23936 c:\windows\system32\dllcache\sccmn50m.sys

+ 2010-03-10 00:36 . 2004-08-04 03:59 43136 c:\windows\system32\dllcache\sbp2port.sys

+ 2010-03-10 00:36 . 2001-08-17 17:50 75392 c:\windows\system32\dllcache\s3savmxm.sys

+ 2010-03-10 00:36 . 2001-08-17 17:50 77824 c:\windows\system32\dllcache\s3sav4m.sys

+ 2010-03-10 00:36 . 2001-08-17 17:50 61504 c:\windows\system32\dllcache\s3sav3dm.sys

+ 2010-03-10 00:36 . 2001-08-18 03:36 62496 c:\windows\system32\dllcache\s3mtrio.dll

+ 2010-03-10 00:36 . 2001-08-17 17:50 41216 c:\windows\system32\dllcache\s3mt3d.sys

+ 2010-03-10 00:36 . 2001-08-17 18:57 65664 c:\windows\system32\dllcache\s3legacy.sys

+ 2010-03-10 00:36 . 2001-08-18 03:36 82432 c:\windows\system32\dllcache\rwia450.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 79872 c:\windows\system32\dllcache\rwia330.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 79872 c:\windows\system32\dllcache\rwia330.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 79872 c:\windows\system32\dllcache\rwia001.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 79872 c:\windows\system32\dllcache\rwia001.dll

+ 2010-03-10 00:35 . 2001-08-18 03:36 26624 c:\windows\system32\dllcache\rw450ext.dll

+ 2010-03-10 00:35 . 2001-08-18 03:36 24576 c:\windows\system32\dllcache\rw430ext.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 42574 c:\windows\system32\dllcache\rvsezm.exe

+ 2007-07-31 14:37 . 2008-04-14 12:00 42574 c:\windows\system32\dllcache\rvsezm.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 48706 c:\windows\system32\dllcache\rvse.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 48706 c:\windows\system32\dllcache\rvse.dll

+ 2010-03-10 00:35 . 2004-08-04 03:31 20992 c:\windows\system32\dllcache\rtl8139.sys

+ 2010-03-10 00:35 . 2001-08-17 17:12 19017 c:\windows\system32\dllcache\rtl8029.sys

+ 2010-03-10 00:35 . 2001-08-17 17:19 30720 c:\windows\system32\dllcache\rthwcls.sys

+ 2010-03-10 00:35 . 2004-08-04 03:59 79104 c:\windows\system32\dllcache\rocket.sys

+ 2010-03-10 00:35 . 2004-08-04 04:04 30080 c:\windows\system32\dllcache\rndismpx.sys

+ 2010-03-10 00:35 . 2001-08-17 17:12 37563 c:\windows\system32\dllcache\rlnet5.sys

+ 2001-08-17 13:24 . 2004-08-04 12:00 12032 c:\windows\system32\dllcache\riodrv.sys

+ 2001-08-17 13:24 . 2004-08-04 12:00 12032 c:\windows\system32\dllcache\rio8drv.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 59648 c:\windows\system32\dllcache\rfcomm.sys

+ 2010-03-10 00:35 . 2001-08-18 03:36 86097 c:\windows\system32\dllcache\reslog32.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 14848 c:\windows\system32\dllcache\register.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 14848 c:\windows\system32\dllcache\register.exe

+ 2006-07-12 08:38 . 2004-08-03 22:59 57472 c:\windows\system32\dllcache\redbook.sys

+ 2010-03-10 00:35 . 2004-08-04 03:41 13776 c:\windows\system32\dllcache\recagent.sys

+ 2010-03-10 00:35 . 2001-08-17 18:51 19584 c:\windows\system32\dllcache\rasirda.sys

+ 2010-03-10 00:35 . 2001-08-18 03:36 41472 c:\windows\system32\dllcache\qvusd.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 16384 c:\windows\system32\dllcache\quser.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 16384 c:\windows\system32\dllcache\quser.exe

+ 2010-03-10 00:34 . 2001-08-18 03:36 35328 c:\windows\system32\dllcache\psisload.dll

+ 2010-03-10 00:34 . 2001-08-17 18:51 16128 c:\windows\system32\dllcache\pscr.sys

+ 2004-08-03 22:59 . 2004-08-04 12:00 35328 c:\windows\system32\dllcache\processr.sys

+ 2010-03-10 00:34 . 2004-08-04 04:00 17664 c:\windows\system32\dllcache\ppa3.sys

+ 2010-03-10 00:34 . 2001-08-17 18:53 17792 c:\windows\system32\dllcache\ppa.sys

+ 2007-07-31 14:36 . 2008-04-14 12:00 11264 c:\windows\system32\dllcache\pmxmcro.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 11264 c:\windows\system32\dllcache\pmxmcro.dll

+ 2004-08-04 00:56 . 2004-08-04 12:00 15360 c:\windows\system32\dllcache\pjlmon.dll

+ 2004-08-04 00:56 . 2004-08-04 12:00 35328 c:\windows\system32\dllcache\pid.dll

+ 2010-03-10 00:34 . 2001-08-17 19:07 19840 c:\windows\system32\dllcache\philtune.sys

+ 2010-03-10 00:34 . 2001-08-17 19:04 92416 c:\windows\system32\dllcache\phildec.sys

+ 2010-03-10 00:34 . 2001-08-17 19:04 75776 c:\windows\system32\dllcache\philcam1.sys

+ 2010-03-10 00:34 . 2001-08-18 03:36 16384 c:\windows\system32\dllcache\philcam1.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 20992 c:\windows\system32\dllcache\permchk.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 20992 c:\windows\system32\dllcache\permchk.dll

+ 2010-03-10 00:34 . 2004-08-04 04:06 28032 c:\windows\system32\dllcache\perm3.sys

+ 2010-03-10 00:34 . 2004-08-04 04:06 27904 c:\windows\system32\dllcache\perm2.sys

+ 2010-03-10 00:34 . 2001-08-18 03:36 86016 c:\windows\system32\dllcache\pctspk.exe

+ 2007-06-26 15:31 . 2001-08-17 16:11 35328 c:\windows\system32\dllcache\pcntpci5.sys

+ 2010-03-10 00:34 . 2001-08-17 17:11 29769 c:\windows\system32\dllcache\pcntn5m.sys

+ 2010-03-10 00:33 . 2001-08-17 17:12 26153 c:\windows\system32\dllcache\pcmlm56.sys

+ 2010-03-10 00:33 . 2004-08-04 03:31 29502 c:\windows\system32\dllcache\pca200e.sys

+ 2010-03-10 00:33 . 2001-08-17 17:12 30495 c:\windows\system32\dllcache\pc100nds.sys

+ 2004-08-03 22:59 . 2004-08-04 12:00 80128 c:\windows\system32\dllcache\parport.sys

+ 2007-07-31 14:36 . 2008-04-14 12:00 31744 c:\windows\system32\dllcache\pagecnt.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\pagecnt.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 14336 c:\windows\system32\dllcache\padrs412.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\padrs412.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 36927 c:\windows\system32\dllcache\padrs411.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 36927 c:\windows\system32\dllcache\padrs411.dll

+ 2004-08-03 22:59 . 2004-08-04 12:00 42496 c:\windows\system32\dllcache\p3.sys

+ 2010-03-10 00:33 . 2001-08-18 03:36 41984 c:\windows\system32\dllcache\ovui2rc.dll

+ 2010-03-10 00:33 . 2001-08-18 03:36 44544 c:\windows\system32\dllcache\ovui2.dll

+ 2010-03-10 00:33 . 2001-08-17 19:05 25216 c:\windows\system32\dllcache\ovsound2.sys

+ 2010-03-10 00:33 . 2001-08-18 03:36 39424 c:\windows\system32\dllcache\ovcoms.exe

+ 2010-03-10 00:33 . 2001-08-18 03:36 20480 c:\windows\system32\dllcache\ovcomc.dll

+ 2010-03-10 00:33 . 2001-08-17 19:05 31872 c:\windows\system32\dllcache\ovce.sys

+ 2010-03-10 00:33 . 2001-08-17 19:05 28032 c:\windows\system32\dllcache\ovcd.sys

+ 2010-03-10 00:33 . 2001-08-17 19:05 48000 c:\windows\system32\dllcache\ovcam2.sys

+ 2010-03-10 00:33 . 2001-08-17 19:05 25088 c:\windows\system32\dllcache\ovca.sys

+ 2010-03-10 00:33 . 2001-08-17 18:28 54186 c:\windows\system32\dllcache\otcsercb.sys

+ 2010-03-10 00:33 . 2001-08-17 17:12 43689 c:\windows\system32\dllcache\otceth5.sys

+ 2010-03-10 00:33 . 2001-08-17 17:12 27209 c:\windows\system32\dllcache\otc06x5.sys

+ 2010-03-10 00:33 . 2001-08-17 17:20 54528 c:\windows\system32\dllcache\opl3sax.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 61056 c:\windows\system32\dllcache\ohci1394.sys

+ 2010-03-10 00:32 . 2001-08-17 17:49 51552 c:\windows\system32\dllcache\ntgrip.sys

+ 2010-03-10 00:32 . 2004-08-04 04:00 28672 c:\windows\system32\dllcache\nscirda.sys

+ 2010-03-10 00:32 . 2001-08-17 17:20 87040 c:\windows\system32\dllcache\nm6wdm.sys

+ 2001-08-17 13:24 . 2004-08-04 12:00 12032 c:\windows\system32\dllcache\nikedrv.sys

+ 2004-08-03 22:58 . 2004-08-04 12:00 61824 c:\windows\system32\dllcache\nic1394.sys

+ 2010-03-10 00:32 . 2001-08-17 17:12 32840 c:\windows\system32\dllcache\ngrpci.sys

- 2007-07-31 14:36 . 2004-08-04 12:00 53248 c:\windows\system32\dllcache\nextlink.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 53248 c:\windows\system32\dllcache\nextlink.dll

+ 2010-03-10 00:32 . 2001-08-17 17:11 65278 c:\windows\system32\dllcache\netflx3.sys

+ 2010-03-10 00:32 . 2001-08-17 17:50 39264 c:\windows\system32\dllcache\neo20xx.sys

+ 2010-03-10 00:32 . 2001-08-18 03:36 60480 c:\windows\system32\dllcache\neo20xx.dll

+ 2010-03-10 00:32 . 2001-08-17 18:49 15872 c:\windows\system32\dllcache\ne2000.sys

+ 2004-08-03 23:03 . 2004-08-04 12:00 12928 c:\windows\system32\dllcache\ndisuio.sys

+ 2010-03-10 00:32 . 2004-08-04 04:10 10880 c:\windows\system32\dllcache\ndisip.sys

+ 2010-03-10 00:32 . 2004-08-04 04:10 85376 c:\windows\system32\dllcache\nabtsfec.sys

+ 2010-03-10 00:32 . 2001-08-17 19:56 91488 c:\windows\system32\dllcache\n9i3disp.dll

+ 2010-03-10 00:32 . 2001-08-17 17:50 27936 c:\windows\system32\dllcache\n9i3d.sys

+ 2010-03-10 00:32 . 2001-08-17 17:50 33088 c:\windows\system32\dllcache\n9i128v2.sys

+ 2010-03-10 00:32 . 2001-08-18 03:36 59104 c:\windows\system32\dllcache\n9i128v2.dll

+ 2010-03-10 00:32 . 2001-08-17 17:50 13664 c:\windows\system32\dllcache\n9i128.sys

+ 2010-03-10 00:31 . 2001-08-17 17:11 52255 c:\windows\system32\dllcache\n1000nt5.sys

+ 2010-03-10 00:31 . 2001-08-17 18:50 75520 c:\windows\system32\dllcache\mxport.sys

+ 2010-03-10 00:31 . 2001-08-17 18:49 19968 c:\windows\system32\dllcache\mxnic.sys

+ 2010-03-10 00:31 . 2001-08-18 03:36 19968 c:\windows\system32\dllcache\mxicfg.dll

+ 2010-03-10 00:31 . 2001-08-17 18:50 21888 c:\windows\system32\dllcache\mxcard.sys

+ 2010-03-10 00:31 . 2004-08-04 04:04 12672 c:\windows\system32\dllcache\mutohpen.sys

+ 2004-08-04 00:56 . 2004-08-04 12:00 17408 c:\windows\system32\dllcache\msyuv.dll

+ 2010-03-10 00:31 . 2004-08-04 04:10 49024 c:\windows\system32\dllcache\mstape.sys

+ 2010-03-10 00:31 . 2001-08-17 18:48 12416 c:\windows\system32\dllcache\msriffwv.sys

+ 2010-03-10 00:31 . 2004-08-04 04:00 22016 c:\windows\system32\dllcache\msircomm.sys

- 2007-07-31 14:36 . 2004-08-04 12:00 98304 c:\windows\system32\dllcache\msir3jp.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 98304 c:\windows\system32\dllcache\msir3jp.dll

+ 2010-03-10 00:31 . 2001-08-17 19:02 35200 c:\windows\system32\dllcache\msgame.sys

+ 2010-03-10 00:31 . 2004-08-04 04:10 51328 c:\windows\system32\dllcache\msdv.sys

+ 2001-08-17 13:48 . 2004-08-04 12:00 12160 c:\windows\system32\dllcache\mouhid.sys

+ 2010-03-10 00:30 . 2001-08-17 18:57 16128 c:\windows\system32\dllcache\modemcsa.sys

+ 2004-08-03 23:08 . 2004-08-04 12:00 30080 c:\windows\system32\dllcache\modem.sys

- 2004-08-04 12:00 . 2004-08-04 12:00 34304 c:\windows\system32\dllcache\migisol.exe

+ 2004-08-04 12:00 . 2008-04-14 12:00 34304 c:\windows\system32\dllcache\migisol.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 92416 c:\windows\system32\dllcache\mga.sys

- 2007-07-31 14:36 . 2004-08-04 12:00 92416 c:\windows\system32\dllcache\mga.sys

+ 2007-07-31 14:36 . 2008-04-14 12:00 92032 c:\windows\system32\dllcache\mga.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 92032 c:\windows\system32\dllcache\mga.dll

+ 2004-08-03 23:07 . 2004-08-04 12:00 63744 c:\windows\system32\dllcache\mf.sys

+ 2010-03-10 00:30 . 2004-08-04 04:00 26112 c:\windows\system32\dllcache\memstpci.sys

+ 2010-03-10 00:30 . 2001-08-18 03:36 47616 c:\windows\system32\dllcache\memgrp.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 26624 c:\windows\system32\dllcache\mdsync.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 26624 c:\windows\system32\dllcache\mdsync.dll

+ 2010-03-10 00:30 . 2001-08-17 17:19 48768 c:\windows\system32\dllcache\maestro.sys

+ 2010-03-10 00:30 . 2001-08-18 03:36 58880 c:\windows\system32\dllcache\m3092dc.dll

+ 2010-03-10 00:30 . 2001-08-18 03:36 58368 c:\windows\system32\dllcache\m3091dc.dll

+ 2010-03-10 00:30 . 2001-08-17 17:49 22848 c:\windows\system32\dllcache\lwusbhid.sys

+ 2010-03-10 00:30 . 2004-08-04 03:39 20864 c:\windows\system32\dllcache\lwadihid.sys

- 2007-07-31 14:36 . 2004-08-04 12:00 22016 c:\windows\system32\dllcache\logscrpt.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 22016 c:\windows\system32\dllcache\logscrpt.dll

+ 2010-03-10 00:30 . 2001-08-17 17:12 70730 c:\windows\system32\dllcache\lne100tx.sys

+ 2010-03-10 00:29 . 2001-08-17 17:11 25065 c:\windows\system32\dllcache\lmndis3.sys

+ 2010-03-10 00:29 . 2001-08-17 18:51 15744 c:\windows\system32\dllcache\lit220p.sys

+ 2010-03-10 00:29 . 2004-08-04 03:59 34688 c:\windows\system32\dllcache\lbrtfdc.sys

+ 2010-03-10 00:29 . 2001-08-17 17:12 26442 c:\windows\system32\dllcache\lanepic5.sys

+ 2010-03-10 00:29 . 2001-08-17 17:12 19016 c:\windows\system32\dllcache\ktc111.sys

+ 2010-03-10 00:29 . 2001-08-18 03:36 37376 c:\windows\system32\dllcache\kousd.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 70656 c:\windows\system32\dllcache\korwbrkr.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 70656 c:\windows\system32\dllcache\korwbrkr.dll

+ 2010-03-10 00:29 . 2001-08-18 03:36 45568 c:\windows\system32\dllcache\kdsui.dll

+ 2004-08-04 12:00 . 2004-08-04 12:00 14848 c:\windows\system32\dllcache\kbdhid.sys

- 2007-07-31 14:36 . 2004-08-04 12:00 18432 c:\windows\system32\dllcache\jupiw.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 18432 c:\windows\system32\dllcache\jupiw.dll

+ 2004-08-04 00:56 . 2004-08-04 12:00 47616 c:\windows\system32\dllcache\iyuv_32.dll

+ 2010-03-10 00:29 . 2001-08-17 18:49 26624 c:\windows\system32\dllcache\irstusb.sys

+ 2010-03-10 00:29 . 2001-08-17 18:51 18688 c:\windows\system32\dllcache\irsir.sys

+ 2010-03-10 00:29 . 2004-08-04 05:56 27136 c:\windows\system32\dllcache\irmon.dll

+ 2010-03-10 00:29 . 2001-08-17 18:49 23552 c:\windows\system32\dllcache\irmk7.sys

+ 2010-03-10 00:29 . 2004-08-04 04:00 87424 c:\windows\system32\dllcache\irda.sys

+ 2010-03-10 00:29 . 2004-08-04 04:08 40832 c:\windows\system32\dllcache\irbus.sys

+ 2010-03-10 00:29 . 2001-08-17 17:12 45632 c:\windows\system32\dllcache\ip5515.sys

+ 2010-03-10 00:28 . 2001-08-17 18:50 38784 c:\windows\system32\dllcache\io8.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 36096 c:\windows\system32\dllcache\intelppm.sys

+ 2010-03-10 00:28 . 2001-08-17 18:47 13056 c:\windows\system32\dllcache\inport.sys

- 2007-07-31 14:34 . 2004-08-04 12:00 19968 c:\windows\system32\dllcache\inetsloc.dll

+ 2007-07-31 14:34 . 2008-04-14 12:00 19968 c:\windows\system32\dllcache\inetsloc.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 59392 c:\windows\system32\dllcache\imscinst.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 59392 c:\windows\system32\dllcache\imscinst.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 59904 c:\windows\system32\dllcache\imkrinst.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 59904 c:\windows\system32\dllcache\imkrinst.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 45109 c:\windows\system32\dllcache\imjpuex.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 45109 c:\windows\system32\dllcache\imjpuex.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 57398 c:\windows\system32\dllcache\imjpdadm.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 57398 c:\windows\system32\dllcache\imjpdadm.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 44032 c:\windows\system32\dllcache\imekrmig.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 44032 c:\windows\system32\dllcache\imekrmig.exe

+ 2004-08-04 12:00 . 2004-08-04 12:00 41856 c:\windows\system32\dllcache\imapi.sys

+ 2007-07-31 14:34 . 2008-04-14 12:00 14336 c:\windows\system32\dllcache\iisreset.exe

- 2007-07-31 14:34 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\iisreset.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 19456 c:\windows\system32\dllcache\iiscrmap.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 19456 c:\windows\system32\dllcache\iiscrmap.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 60928 c:\windows\system32\dllcache\iisclex4.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 60928 c:\windows\system32\dllcache\iisclex4.dll

+ 2010-03-10 00:28 . 2001-08-18 03:36 20480 c:\windows\system32\dllcache\icam5ext.dll

+ 2010-03-10 00:28 . 2001-08-18 03:36 45056 c:\windows\system32\dllcache\icam5com.dll

+ 2010-03-10 00:28 . 2001-08-18 03:36 61952 c:\windows\system32\dllcache\icam4ext.dll

+ 2010-03-10 00:28 . 2001-08-18 03:36 91136 c:\windows\system32\dllcache\icam4com.dll

+ 2010-03-10 00:28 . 2001-08-18 03:36 26624 c:\windows\system32\dllcache\icam3ext.dll

+ 2010-03-10 00:28 . 2001-08-17 19:06 38528 c:\windows\system32\dllcache\ibmvcap.sys

+ 2010-03-10 00:28 . 2001-08-17 17:11 28700 c:\windows\system32\dllcache\ibmexmp.sys

+ 2010-03-10 00:28 . 2001-08-17 17:49 58592 c:\windows\system32\dllcache\i740nt5.sys

+ 2010-03-10 00:27 . 2004-08-04 05:56 32285 c:\windows\system32\dllcache\hsfcisp2.dll

+ 2010-03-10 00:27 . 2001-08-17 18:28 50751 c:\windows\system32\dllcache\hsf_tone.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 73279 c:\windows\system32\dllcache\hsf_spkp.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 44863 c:\windows\system32\dllcache\hsf_soar.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 57471 c:\windows\system32\dllcache\hsf_samp.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 67167 c:\windows\system32\dllcache\hsf_bsc2.sys

- 2007-07-31 14:35 . 2004-08-04 12:00 42573 c:\windows\system32\dllcache\hrtzzm.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 42573 c:\windows\system32\dllcache\hrtzzm.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 57409 c:\windows\system32\dllcache\hrtz.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 57409 c:\windows\system32\dllcache\hrtz.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 19456 c:\windows\system32\dllcache\hr1w.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 13312 c:\windows\system32\dllcache\hpsjmcro.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 32768 c:\windows\system32\dllcache\hpgtmcro.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 68608 c:\windows\system32\dllcache\hpgt53tk.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 31232 c:\windows\system32\dllcache\hpgt42tk.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 93696 c:\windows\system32\dllcache\hpgt42.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 48128 c:\windows\system32\dllcache\hpgt33tk.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 89088 c:\windows\system32\dllcache\hpgt33.dll

+ 2010-03-10 00:26 . 2001-08-18 03:36 83968 c:\windows\system32\dllcache\hpgt21.dll

+ 2004-08-04 12:00 . 2004-08-04 12:00 24960 c:\windows\system32\dllcache\hidparse.sys

+ 2010-03-10 00:26 . 2004-08-04 04:08 15104 c:\windows\system32\dllcache\hidir.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 36224 c:\windows\system32\dllcache\hidclass.sys

+ 2010-03-10 00:26 . 2004-08-04 04:10 25600 c:\windows\system32\dllcache\hidbth.sys

+ 2010-03-10 00:26 . 2001-08-17 18:58 19200 c:\windows\system32\dllcache\hidbatt.sys

+ 2004-08-04 00:56 . 2004-08-04 12:00 20992 c:\windows\system32\dllcache\hid.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 36864 c:\windows\system32\dllcache\hanjadic.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 36864 c:\windows\system32\dllcache\hanjadic.dll

+ 2010-03-10 00:26 . 2004-08-04 03:59 28288 c:\windows\system32\dllcache\grserial.sys

+ 2010-03-10 00:26 . 2001-08-17 18:51 82304 c:\windows\system32\dllcache\grclass.sys

+ 2010-03-10 00:26 . 2001-08-17 18:51 17408 c:\windows\system32\dllcache\gpr400.sys

+ 2010-03-10 00:26 . 2004-08-04 04:08 59136 c:\windows\system32\dllcache\gckernel.sys

+ 2010-03-10 00:26 . 2004-08-04 04:08 10624 c:\windows\system32\dllcache\gameenum.sys

+ 2004-08-03 23:07 . 2004-08-04 12:00 46464 c:\windows\system32\dllcache\gagp30kx.sys

- 2007-07-31 14:35 . 2004-08-04 12:00 11264 c:\windows\system32\dllcache\fxssend.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 11264 c:\windows\system32\dllcache\fxssend.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 31744 c:\windows\system32\dllcache\fxsroute.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\fxsroute.dll

+ 2010-03-10 00:26 . 2001-08-18 03:36 92160 c:\windows\system32\dllcache\fuusd.dll

+ 2001-08-17 13:57 . 2004-08-04 12:00 12160 c:\windows\system32\dllcache\fsvga.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 55296 c:\windows\system32\dllcache\freecell.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 55296 c:\windows\system32\dllcache\freecell.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 20538 c:\windows\system32\dllcache\fpremadm.exe

+ 2007-07-31 14:34 . 2003-03-24 21:52 20538 c:\windows\system32\dllcache\fpremadm.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 20541 c:\windows\system32\dllcache\fpexedll.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 20541 c:\windows\system32\dllcache\fpexedll.dll

- 2007-07-31 14:35 . 2003-03-24 20:52 94208 c:\windows\system32\dllcache\fpencode.dll

+ 2007-07-31 14:35 . 2003-03-24 21:52 94208 c:\windows\system32\dllcache\fpencode.dll

- 2007-07-31 14:35 . 2003-03-24 20:52 20541 c:\windows\system32\dllcache\fpadmdll.dll

+ 2007-07-31 14:35 . 2003-03-24 21:52 20541 c:\windows\system32\dllcache\fpadmdll.dll

+ 2007-07-31 14:35 . 2003-03-24 21:52 24632 c:\windows\system32\dllcache\fpadmcgi.exe

- 2007-07-31 14:35 . 2003-03-24 20:52 24632 c:\windows\system32\dllcache\fpadmcgi.exe

+ 2007-07-31 14:34 . 2003-03-24 21:52 14608 c:\windows\system32\dllcache\fp98sadm.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 14608 c:\windows\system32\dllcache\fp98sadm.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 49212 c:\windows\system32\dllcache\fp4awebs.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 49212 c:\windows\system32\dllcache\fp4awebs.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 32826 c:\windows\system32\dllcache\fp4avss.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 32826 c:\windows\system32\dllcache\fp4avss.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 41020 c:\windows\system32\dllcache\fp4avnb.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 41020 c:\windows\system32\dllcache\fp4avnb.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 49210 c:\windows\system32\dllcache\fp4areg.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 49210 c:\windows\system32\dllcache\fp4areg.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 82035 c:\windows\system32\dllcache\fp4anscp.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 82035 c:\windows\system32\dllcache\fp4anscp.dll

+ 2010-03-10 00:26 . 2004-08-04 03:31 34173 c:\windows\system32\dllcache\forehe.sys

+ 2010-03-10 00:26 . 2001-08-18 03:36 71680 c:\windows\system32\dllcache\fnfilter.dll

+ 2004-08-04 12:00 . 2004-08-04 12:00 20480 c:\windows\system32\dllcache\flpydisk.sys

- 2007-07-31 14:35 . 2004-08-04 12:00 14848 c:\windows\system32\dllcache\flattemp.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 14848 c:\windows\system32\dllcache\flattemp.exe

+ 2010-03-10 00:26 . 2001-08-17 17:13 27165 c:\windows\system32\dllcache\fetnd5.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 27392 c:\windows\system32\dllcache\fdc.sys

+ 2010-03-10 00:25 . 2001-08-17 17:12 24618 c:\windows\system32\dllcache\fa410nd5.sys

+ 2010-03-10 00:25 . 2001-08-17 17:12 16074 c:\windows\system32\dllcache\fa312nd5.sys

+ 2010-03-10 00:25 . 2001-08-17 17:11 11850 c:\windows\system32\dllcache\f3ab18xj.sys

+ 2010-03-10 00:25 . 2001-08-17 17:11 12362 c:\windows\system32\dllcache\f3ab18xi.sys

- 2007-07-31 14:37 . 2001-08-18 02:36 12288 c:\windows\system32\dllcache\EXCH_smtpctrs.dll

+ 2007-07-31 14:37 . 2001-08-18 03:36 12288 c:\windows\system32\dllcache\EXCH_smtpctrs.dll

+ 2007-07-31 14:37 . 2001-08-18 03:36 26112 c:\windows\system32\dllcache\EXCH_seos.dll

- 2007-07-31 14:37 . 2001-08-18 02:36 26112 c:\windows\system32\dllcache\EXCH_seos.dll

- 2007-07-31 14:37 . 2001-08-18 02:36 57856 c:\windows\system32\dllcache\EXCH_scripto.dll

+ 2007-07-31 14:37 . 2001-08-18 03:36 57856 c:\windows\system32\dllcache\EXCH_scripto.dll

- 2007-07-31 14:37 . 2001-08-18 02:36 23040 c:\windows\system32\dllcache\EXCH_regtrace.exe

+ 2007-07-31 14:37 . 2001-08-18 03:36 23040 c:\windows\system32\dllcache\EXCH_regtrace.exe

+ 2007-07-31 14:36 . 2001-08-18 03:36 38912 c:\windows\system32\dllcache\EXCH_ntfsdrv.dll

- 2007-07-31 14:36 . 2001-08-18 02:36 38912 c:\windows\system32\dllcache\EXCH_ntfsdrv.dll

+ 2007-07-31 14:36 . 2001-08-18 03:36 65536 c:\windows\system32\dllcache\EXCH_mailmsg.dll

- 2007-07-31 14:36 . 2001-08-18 02:36 65536 c:\windows\system32\dllcache\EXCH_mailmsg.dll

+ 2007-07-31 14:35 . 2001-08-18 03:36 43520 c:\windows\system32\dllcache\EXCH_fcachdll.dll

- 2007-07-31 14:35 . 2001-08-18 02:36 43520 c:\windows\system32\dllcache\EXCH_fcachdll.dll

+ 2007-07-31 14:35 . 2001-08-18 03:36 45056 c:\windows\system32\dllcache\EXCH_aqadmin.dll

- 2007-07-31 14:35 . 2001-08-18 02:36 45056 c:\windows\system32\dllcache\EXCH_aqadmin.dll

+ 2010-03-10 00:25 . 2001-08-17 17:12 16998 c:\windows\system32\dllcache\ex10.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 25856 c:\windows\system32\dllcache\et4000.sys

- 2007-07-31 14:35 . 2004-08-04 12:00 25856 c:\windows\system32\dllcache\et4000.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 45056 c:\windows\system32\dllcache\esunid.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 45056 c:\windows\system32\dllcache\esunid.dll

+ 2010-03-10 00:25 . 2001-08-18 03:36 45568 c:\windows\system32\dllcache\esunib.dll

+ 2010-03-10 00:25 . 2001-08-18 03:36 45568 c:\windows\system32\dllcache\esuni.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 57856 c:\windows\system32\dllcache\esuimgd.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 57856 c:\windows\system32\dllcache\esuimgd.dll

+ 2010-03-10 00:25 . 2001-08-18 03:36 34816 c:\windows\system32\dllcache\esuimg.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\esucmd.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 31744 c:\windows\system32\dllcache\esucmd.dll

+ 2010-03-10 00:25 . 2001-08-18 03:36 43008 c:\windows\system32\dllcache\esucm.dll

+ 2010-03-10 00:25 . 2001-08-17 17:19 63360 c:\windows\system32\dllcache\ess.sys

+ 2010-03-10 00:25 . 2001-08-17 17:19 72192 c:\windows\system32\dllcache\es1969.sys

+ 2010-03-10 00:25 . 2001-08-17 17:19 40704 c:\windows\system32\dllcache\es1371mp.sys

+ 2010-03-10 00:25 . 2001-08-17 17:19 37120 c:\windows\system32\dllcache\es1370mp.sys

+ 2010-03-10 00:25 . 2001-08-18 03:36 61952 c:\windows\system32\dllcache\eqnloop.exe

+ 2010-03-10 00:25 . 2001-08-18 03:36 51200 c:\windows\system32\dllcache\eqnlogr.exe

+ 2010-03-10 00:25 . 2001-08-18 03:36 53248 c:\windows\system32\dllcache\eqndiag.exe

+ 2010-03-10 00:25 . 2001-08-17 17:12 18503 c:\windows\system32\dllcache\epro4.sys

+ 2010-03-10 00:25 . 2001-08-17 17:10 19996 c:\windows\system32\dllcache\em556n4.sys

+ 2010-03-10 00:25 . 2001-08-17 17:10 25159 c:\windows\system32\dllcache\elnk3.sys

+ 2010-03-10 00:25 . 2001-08-17 17:11 70174 c:\windows\system32\dllcache\el98xn5.sys

+ 2010-03-10 00:25 . 2001-08-17 17:11 66591 c:\windows\system32\dllcache\el90xbc5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:11 77386 c:\windows\system32\dllcache\el656nd5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:11 69194 c:\windows\system32\dllcache\el656cd5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:10 26141 c:\windows\system32\dllcache\el589nd5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:10 69692 c:\windows\system32\dllcache\el575nd5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:10 24653 c:\windows\system32\dllcache\el574nd4.sys

+ 2010-03-10 00:24 . 2001-08-17 17:10 55999 c:\windows\system32\dllcache\el556nd5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:10 44103 c:\windows\system32\dllcache\el515.sys

+ 2010-03-10 00:24 . 2001-08-17 17:12 19594 c:\windows\system32\dllcache\e100isa4.sys

+ 2010-03-10 00:24 . 2001-08-17 17:12 50719 c:\windows\system32\dllcache\e1000nt5.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 71040 c:\windows\system32\dllcache\dxg.sys

+ 2001-08-17 22:36 . 2004-08-04 12:00 55296 c:\windows\system32\dllcache\dvdplay.exe

+ 2010-03-10 00:24 . 2001-08-17 17:12 28062 c:\windows\system32\dllcache\dp83820.sys

+ 2010-03-10 00:24 . 2001-08-17 18:47 23808 c:\windows\system32\dllcache\dot4usb.sys

+ 2010-03-10 00:24 . 2001-08-17 18:47 12928 c:\windows\system32\dllcache\dot4prt.sys

+ 2004-08-04 00:56 . 2004-08-04 12:00 52224 c:\windows\system32\dllcache\dmutil.dll

+ 2010-03-10 00:24 . 2001-08-17 17:11 29696 c:\windows\system32\dllcache\dm9pci5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:11 26698 c:\windows\system32\dllcache\dlh5xnd5.sys

+ 2010-03-10 00:24 . 2001-08-18 03:36 29768 c:\windows\system32\dllcache\divasu.dll

+ 2010-03-10 00:24 . 2001-08-18 03:36 37962 c:\windows\system32\dllcache\divaprop.dll

+ 2010-03-10 00:24 . 2001-08-18 03:36 38985 c:\windows\system32\dllcache\disrvsu.dll

+ 2010-03-10 00:24 . 2001-08-18 03:36 31305 c:\windows\system32\dllcache\disrvpp.dll

+ 2004-08-04 12:00 . 2004-08-04 12:00 36352 c:\windows\system32\dllcache\disk.sys

+ 2010-03-10 00:24 . 2001-08-17 17:13 91305 c:\windows\system32\dllcache\dimaint.sys

+ 2010-03-10 00:24 . 2001-08-17 17:17 42432 c:\windows\system32\dllcache\digirlpt.sys

+ 2010-03-10 00:24 . 2001-08-17 17:14 21606 c:\windows\system32\dllcache\digiisdn.sys

+ 2010-03-10 00:24 . 2001-08-18 03:36 41046 c:\windows\system32\dllcache\digiisdn.dll

+ 2010-03-10 00:24 . 2001-08-17 17:17 90525 c:\windows\system32\dllcache\digifep5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:13 37735 c:\windows\system32\dllcache\digiasyn.sys

+ 2010-03-10 00:24 . 2001-08-18 03:36 65622 c:\windows\system32\dllcache\digiasyn.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 32256 c:\windows\system32\dllcache\diapi2NT.dll

+ 2010-03-10 00:24 . 2001-08-17 17:17 29531 c:\windows\system32\dllcache\dgapci.sys

+ 2010-03-10 00:24 . 2001-08-17 17:11 24649 c:\windows\system32\dllcache\dfe650d.sys

+ 2010-03-10 00:24 . 2001-08-17 17:11 24648 c:\windows\system32\dllcache\dfe650.sys

+ 2010-03-10 00:24 . 2001-08-18 03:36 24064 c:\windows\system32\dllcache\devldr32.exe

+ 2010-03-10 00:23 . 2001-08-17 17:11 20928 c:\windows\system32\dllcache\defpa.sys

+ 2010-03-10 00:23 . 2001-08-18 03:36 86016 c:\windows\system32\dllcache\dc240usd.dll

+ 2010-03-10 00:23 . 2001-08-17 17:12 63208 c:\windows\system32\dllcache\dc21x4.sys

+ 2010-03-10 00:23 . 2001-08-18 03:36 80896 c:\windows\system32\dllcache\dc210usd.dll

+ 2010-03-10 00:23 . 2001-08-18 03:36 25600 c:\windows\system32\dllcache\dc210_32.dll

+ 2010-03-10 00:23 . 2001-08-18 03:36 27648 c:\windows\system32\dllcache\cyzports.dll

+ 2010-03-10 00:23 . 2001-08-17 18:50 49792 c:\windows\system32\dllcache\cyzport.sys

+ 2010-03-10 00:23 . 2001-08-18 03:36 27136 c:\windows\system32\dllcache\cyzcoins.dll

+ 2010-03-10 00:23 . 2001-08-18 03:36 27648 c:\windows\system32\dllcache\cyyports.dll

+ 2010-03-10 00:23 . 2001-08-17 18:50 50176 c:\windows\system32\dllcache\cyyport.sys

+ 2010-03-10 00:23 . 2001-08-18 03:36 28672 c:\windows\system32\dllcache\cyycoins.dll

+ 2010-03-10 00:23 . 2001-08-17 18:50 14848 c:\windows\system32\dllcache\cyclom-y.sys

+ 2010-03-10 00:23 . 2001-08-17 18:50 17152 c:\windows\system32\dllcache\cyclad-z.sys

+ 2010-03-10 00:23 . 2004-08-04 03:32 48640 c:\windows\system32\dllcache\cwrwdm.sys

+ 2010-03-10 00:23 . 2001-08-17 17:19 93952 c:\windows\system32\dllcache\cwcwdm.sys

+ 2010-03-10 00:23 . 2001-08-17 17:19 72832 c:\windows\system32\dllcache\cwbwdm.sys

+ 2006-07-12 12:43 . 2005-01-28 17:44 28672 c:\windows\system32\dllcache\custsat.dll

+ 2010-03-10 00:23 . 2001-08-17 17:19 96256 c:\windows\system32\dllcache\ctlsb16.sys

+ 2004-08-03 22:59 . 2004-08-04 12:00 36480 c:\windows\system32\dllcache\crusoe.sys

+ 2010-03-10 00:23 . 2001-08-17 17:19 42112 c:\windows\system32\dllcache\crtaud.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 18944 c:\windows\system32\dllcache\cprofile.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 18944 c:\windows\system32\dllcache\cprofile.exe

+ 2010-03-10 00:23 . 2001-08-17 17:11 60970 c:\windows\system32\dllcache\cpqtrnd5.sys

+ 2010-03-10 00:23 . 2001-08-17 17:13 21533 c:\windows\system32\dllcache\cpqndis5.sys

+ 2001-08-17 13:24 . 2004-08-04 12:00 11776 c:\windows\system32\dllcache\cpqdap01.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 57399 c:\windows\system32\dllcache\cplexe.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 57399 c:\windows\system32\dllcache\cplexe.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 20480 c:\windows\system32\dllcache\counters.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 20480 c:\windows\system32\dllcache\counters.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 56320 c:\windows\system32\dllcache\convlog.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 56320 c:\windows\system32\dllcache\convlog.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 33792 c:\windows\system32\dllcache\controt.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 33792 c:\windows\system32\dllcache\controt.dll

+ 2010-03-10 00:23 . 2001-08-17 17:11 39936 c:\windows\system32\dllcache\cnxt1803.sys

+ 2010-03-10 00:23 . 2001-08-18 03:36 44032 c:\windows\system32\dllcache\cnusd.dll

+ 2004-08-04 00:56 . 2004-08-04 12:00 47104 c:\windows\system32\dllcache\cnbjmon.dll

+ 2010-03-10 00:23 . 2001-08-17 18:51 20736 c:\windows\system32\dllcache\cmbp0wdm.sys

+ 2004-08-03 23:07 . 2004-08-04 12:00 14080 c:\windows\system32\dllcache\cmbatt.sys

+ 2010-03-10 00:23 . 2001-08-17 18:57 45696 c:\windows\system32\dllcache\cirrus.sys

+ 2010-03-10 00:23 . 2001-08-17 19:56 91264 c:\windows\system32\dllcache\cirrus.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 42575 c:\windows\system32\dllcache\chkrzm.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 42575 c:\windows\system32\dllcache\chkrzm.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 40515 c:\windows\system32\dllcache\chkr.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 40515 c:\windows\system32\dllcache\chkr.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\chgusr.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 14336 c:\windows\system32\dllcache\chgusr.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 15872 c:\windows\system32\dllcache\chgport.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 15872 c:\windows\system32\dllcache\chgport.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 13312 c:\windows\system32\dllcache\chglogon.exe

+ 2007-07-31 14:35 . 2008-04-14 12:00 13312 c:\windows\system32\dllcache\chglogon.exe

+ 2010-03-10 00:22 . 2004-08-04 05:56 15423 c:\windows\system32\dllcache\ch7xxnt5.dll

+ 2010-03-10 00:22 . 2001-08-17 17:13 49182 c:\windows\system32\dllcache\cem56n5.sys

+ 2010-03-10 00:22 . 2001-08-17 17:13 22044 c:\windows\system32\dllcache\cem33n5.sys

+ 2010-03-10 00:22 . 2001-08-17 17:13 22044 c:\windows\system32\dllcache\cem28n5.sys

+ 2010-03-10 00:22 . 2001-08-17 17:13 27164 c:\windows\system32\dllcache\ce3n5.sys

+ 2010-03-10 00:22 . 2001-08-17 17:13 21530 c:\windows\system32\dllcache\ce2n5.sys

+ 2001-08-17 13:52 . 2004-08-04 12:00 18688 c:\windows\system32\dllcache\cdaudio.sys

+ 2010-03-10 00:22 . 2004-08-04 04:10 17024 c:\windows\system32\dllcache\ccdecode.sys

+ 2010-03-10 00:22 . 2001-08-17 17:13 46108 c:\windows\system32\dllcache\cben5.sys

+ 2010-03-10 00:22 . 2001-08-17 17:12 39680 c:\windows\system32\dllcache\cb325.sys

+ 2010-03-10 00:22 . 2001-08-17 17:12 37916 c:\windows\system32\dllcache\cb102.sys

- 2007-07-31 14:35 . 2004-08-04 12:00 54528 c:\windows\system32\dllcache\cap7146.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 54528 c:\windows\system32\dllcache\cap7146.sys

+ 2010-03-10 00:22 . 2001-08-18 03:36 74240 c:\windows\system32\dllcache\camexo20.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 10752 c:\windows\system32\dllcache\c_iscii.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 10752 c:\windows\system32\dllcache\c_iscii.dll

+ 2010-03-10 00:22 . 2001-08-17 18:51 13824 c:\windows\system32\dllcache\bulltlp3.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 18944 c:\windows\system32\dllcache\bthusb.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 30208 c:\windows\system32\dllcache\bthserv.dll

+ 2010-03-10 00:22 . 2004-08-04 04:10 35456 c:\windows\system32\dllcache\bthprint.sys

+ 2010-03-10 00:22 . 2004-08-04 04:10 38016 c:\windows\system32\dllcache\bthmodem.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 17024 c:\windows\system32\dllcache\bthenum.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 20992 c:\windows\system32\dllcache\bthci.dll

+ 2010-03-10 00:22 . 2001-08-17 17:11 31529 c:\windows\system32\dllcache\brzwlan.sys

+ 2010-03-10 00:22 . 2001-08-17 18:12 10368 c:\windows\system32\dllcache\brusbscn.sys

+ 2010-03-10 00:22 . 2001-08-17 18:12 11008 c:\windows\system32\dllcache\brusbmdm.sys

+ 2010-03-10 00:22 . 2001-08-17 18:12 60416 c:\windows\system32\dllcache\brserwdm.sys

+ 2010-03-10 00:22 . 2001-08-17 18:12 39552 c:\windows\system32\dllcache\brparwdm.sys

- 2007-07-31 14:35 . 2004-08-04 12:00 45568 c:\windows\system32\dllcache\browscap.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 45568 c:\windows\system32\dllcache\browscap.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 41472 c:\windows\system32\dllcache\brmfusb.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 32256 c:\windows\system32\dllcache\brmfrsmg.exe

+ 2010-03-10 00:22 . 2001-08-18 03:36 29696 c:\windows\system32\dllcache\brmflpt.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 81408 c:\windows\system32\dllcache\brmfcwia.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 15360 c:\windows\system32\dllcache\brmfbidi.dll

+ 2010-03-10 00:22 . 2001-08-17 18:12 12160 c:\windows\system32\dllcache\brfiltlo.sys

+ 2010-03-10 00:22 . 2001-08-18 03:36 12800 c:\windows\system32\dllcache\brevif.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 19456 c:\windows\system32\dllcache\brbidiif.dll

+ 2010-03-10 00:22 . 2004-08-04 04:10 11776 c:\windows\system32\dllcache\bdasup.sys

+ 2010-03-10 00:22 . 2001-08-17 17:11 26568 c:\windows\system32\dllcache\bcm4e5.sys

+ 2010-03-10 00:22 . 2001-08-17 17:11 54271 c:\windows\system32\dllcache\bcm42xx5.sys

+ 2010-03-10 00:22 . 2001-08-17 17:11 66557 c:\windows\system32\dllcache\bcm42u.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 42577 c:\windows\system32\dllcache\bckgzm.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 42577 c:\windows\system32\dllcache\bckgzm.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 82501 c:\windows\system32\dllcache\bckg.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 82501 c:\windows\system32\dllcache\bckg.dll

+ 2001-08-17 13:57 . 2004-08-04 12:00 14080 c:\windows\system32\dllcache\battc.sys

+ 2010-03-10 00:22 . 2001-08-17 17:48 36128 c:\windows\system32\dllcache\banshee.sys

+ 2010-03-10 00:22 . 2001-08-17 17:13 89952 c:\windows\system32\dllcache\b1cbase.sys

+ 2010-03-10 00:22 . 2001-08-17 17:19 36992 c:\windows\system32\dllcache\aztw2320.sys

+ 2010-03-10 00:22 . 2001-08-17 17:13 37568 c:\windows\system32\dllcache\avmwan.sys

+ 2010-03-10 00:22 . 2001-08-18 03:36 87552 c:\windows\system32\dllcache\avmcoxp.dll

+ 2010-03-10 00:22 . 2004-08-04 04:10 13696 c:\windows\system32\dllcache\avcstrm.sys

+ 2010-03-10 00:22 . 2001-08-17 19:01 36096 c:\windows\system32\dllcache\avcaudio.sys

+ 2010-03-10 00:22 . 2004-08-04 04:10 38912 c:\windows\system32\dllcache\avc.sys

- 2007-07-31 14:34 . 2003-03-24 20:52 16439 c:\windows\system32\dllcache\author.exe

+ 2007-07-31 14:34 . 2003-03-24 21:52 16439 c:\windows\system32\dllcache\author.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 20540 c:\windows\system32\dllcache\author.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 20540 c:\windows\system32\dllcache\author.dll

+ 2010-03-10 00:22 . 2004-08-04 05:56 17279 c:\windows\system32\dllcache\atv10nt5.dll

+ 2010-03-10 00:22 . 2004-08-04 05:56 14143 c:\windows\system32\dllcache\atv06nt5.dll

+ 2010-03-10 00:22 . 2004-08-04 05:56 25471 c:\windows\system32\dllcache\atv04nt5.dll

+ 2010-03-10 00:22 . 2004-08-04 05:56 11359 c:\windows\system32\dllcache\atv02nt5.dll

+ 2010-03-10 00:22 . 2004-08-04 05:56 21183 c:\windows\system32\dllcache\atv01nt5.dll

+ 2010-03-10 00:22 . 2001-08-17 17:49 23552 c:\windows\system32\dllcache\atixbar.sys

+ 2010-03-10 00:22 . 2001-08-17 17:49 26624 c:\windows\system32\dllcache\ativxbar.sys

+ 2010-03-10 00:22 . 2001-08-17 17:49 19456 c:\windows\system32\dllcache\ativttxx.sys

+ 2010-03-10 00:22 . 2004-08-04 05:56 32768 c:\windows\system32\dllcache\ativtmxx.dll

+ 2010-03-10 00:21 . 2001-08-17 17:49 17152 c:\windows\system32\dllcache\atitunep.sys

+ 2010-03-10 00:21 . 2001-08-17 17:49 26880 c:\windows\system32\dllcache\atirtsnd.sys

+ 2010-03-10 00:21 . 2001-08-17 17:49 49920 c:\windows\system32\dllcache\atirtcap.sys

+ 2010-03-10 00:21 . 2001-08-17 17:48 70528 c:\windows\system32\dllcache\atiragem.sys

+ 2010-03-10 00:21 . 2001-08-17 17:49 10240 c:\windows\system32\dllcache\atipcxxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 63488 c:\windows\system32\dllcache\atinxsxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 31744 c:\windows\system32\dllcache\atinxbxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 73216 c:\windows\system32\dllcache\atintuxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 13824 c:\windows\system32\dllcache\atinttxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 28672 c:\windows\system32\dllcache\atinsnxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 52224 c:\windows\system32\dllcache\atinraxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 14336 c:\windows\system32\dllcache\atinpdxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 13824 c:\windows\system32\dllcache\atinmdxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 57856 c:\windows\system32\dllcache\atinbtxx.sys

+ 2010-03-10 00:21 . 2001-08-17 17:49 75136 c:\windows\system32\dllcache\atimpae.sys

+ 2010-03-10 00:21 . 2001-08-18 03:36 37376 c:\windows\system32\dllcache\atievxx.exe

+ 2010-03-10 00:21 . 2001-08-17 17:49 46464 c:\windows\system32\dllcache\atibt829.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 34735 c:\windows\system32\dllcache\ati1xsxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 29455 c:\windows\system32\dllcache\ati1xbxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 36463 c:\windows\system32\dllcache\ati1tuxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 21343 c:\windows\system32\dllcache\ati1ttxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 26367 c:\windows\system32\dllcache\ati1snxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 63663 c:\windows\system32\dllcache\ati1rvxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 30671 c:\windows\system32\dllcache\ati1raxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 12047 c:\windows\system32\dllcache\ati1pdxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 11615 c:\windows\system32\dllcache\ati1mdxx.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 56623 c:\windows\system32\dllcache\ati1btxx.sys

+ 2010-03-10 00:21 . 2001-08-17 18:57 77568 c:\windows\system32\dllcache\ati.sys

+ 2010-03-10 00:21 . 2001-08-17 19:55 96128 c:\windows\system32\dllcache\ati.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 29184 c:\windows\system32\dllcache\asptxn.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 29184 c:\windows\system32\dllcache\asptxn.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 10240 c:\windows\system32\dllcache\aspperf.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 10240 c:\windows\system32\dllcache\aspperf.dll

+ 2010-03-10 00:21 . 2001-08-17 17:12 97354 c:\windows\system32\dllcache\aspndis3.sys

+ 2004-08-03 22:58 . 2004-08-04 12:00 60800 c:\windows\system32\dllcache\arp1394.sys

+ 2010-03-10 00:21 . 2004-08-04 03:31 36224 c:\windows\system32\dllcache\an983.sys

+ 2004-08-03 22:59 . 2004-08-04 12:00 37376 c:\windows\system32\dllcache\amdk7.sys

+ 2004-08-03 22:59 . 2004-08-04 12:00 36992 c:\windows\system32\dllcache\amdk6.sys

+ 2010-03-10 00:21 . 2001-08-17 17:11 16969 c:\windows\system32\dllcache\amb8002.sys

+ 2010-03-10 00:21 . 2001-08-17 18:49 26624 c:\windows\system32\dllcache\alifir.sys

+ 2010-03-10 00:21 . 2001-08-17 17:11 27678 c:\windows\system32\dllcache\ali5261.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 19456 c:\windows\system32\dllcache\agt0804.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 19456 c:\windows\system32\dllcache\agt0804.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 19456 c:\windows\system32\dllcache\agt0412.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 19456 c:\windows\system32\dllcache\agt0412.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 19456 c:\windows\system32\dllcache\agt0411.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 19456 c:\windows\system32\dllcache\agt0411.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 19456 c:\windows\system32\dllcache\agt040d.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 19456 c:\windows\system32\dllcache\agt040d.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 19456 c:\windows\system32\dllcache\agt0404.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 19456 c:\windows\system32\dllcache\agt0404.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 19456 c:\windows\system32\dllcache\agt0401.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 19456 c:\windows\system32\dllcache\agt0401.dll

- 2007-07-31 14:34 . 2004-08-04 12:00 49664 c:\windows\system32\dllcache\adrot.dll

+ 2007-07-31 14:34 . 2008-04-14 12:00 49664 c:\windows\system32\dllcache\adrot.dll

+ 2010-03-10 00:21 . 2001-08-17 17:11 46112 c:\windows\system32\dllcache\adptsf50.sys

+ 2010-03-10 00:21 . 2004-08-04 03:32 10880 c:\windows\system32\dllcache\admjoy.sys

+ 2007-07-31 14:34 . 2003-03-24 21:52 16439 c:\windows\system32\dllcache\admin.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 16439 c:\windows\system32\dllcache\admin.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 20540 c:\windows\system32\dllcache\admin.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 20540 c:\windows\system32\dllcache\admin.dll

+ 2010-03-10 00:21 . 2001-08-17 17:11 20160 c:\windows\system32\dllcache\adm8511.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 11648 c:\windows\system32\dllcache\acpiec.sys

+ 2010-03-10 00:21 . 2001-08-18 03:36 61440 c:\windows\system32\dllcache\acerscad.dll

+ 2010-03-10 00:21 . 2004-08-04 03:32 84480 c:\windows\system32\dllcache\ac97via.sys

+ 2010-03-10 00:21 . 2001-08-17 17:20 96256 c:\windows\system32\dllcache\ac97intc.sys

+ 2010-03-10 00:21 . 2001-08-18 03:36 98304 c:\windows\system32\dllcache\a3d.dll

+ 2010-03-10 00:21 . 2001-08-17 19:55 38400 c:\windows\system32\dllcache\8514a.dll

+ 2010-03-10 00:21 . 2004-08-04 04:10 48128 c:\windows\system32\dllcache\61883.sys

+ 2010-03-10 00:21 . 2004-08-04 04:00 12288 c:\windows\system32\dllcache\4mmdat.sys

+ 2010-03-10 00:21 . 2001-08-17 19:06 11264 c:\windows\system32\dllcache\1394vdbg.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 53248 c:\windows\system32\dllcache\1394bus.sys

Link to post
Share on other sites

Part 2

----------------------------------------------------------------------------------------------------------------------------------------------------

+ 2006-07-12 13:12 . 2010-02-27 16:19 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

- 2006-07-12 13:12 . 2010-02-20 16:14 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

- 2006-07-12 13:12 . 2010-02-20 16:14 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2006-07-12 13:12 . 2010-02-27 16:19 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2010-03-10 00:43 . 2004-08-04 12:00 13894 c:\windows\LastGood\system32\dllcache\zonelibm.dll

+ 2010-03-10 00:43 . 2004-08-04 12:00 29760 c:\windows\LastGood\system32\dllcache\znetm.dll

+ 2010-03-10 00:43 . 2004-08-04 12:00 41029 c:\windows\LastGood\system32\dllcache\zcorem.dll

+ 2010-03-10 00:43 . 2004-08-04 12:00 36937 c:\windows\LastGood\system32\dllcache\zclientm.exe

+ 2010-03-10 00:42 . 2004-08-04 12:00 31232 c:\windows\LastGood\system32\dllcache\weitekp9.sys

+ 2010-03-10 00:42 . 2004-08-04 12:00 41600 c:\windows\LastGood\system32\dllcache\weitekp9.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 53248 c:\windows\LastGood\system32\dllcache\wamreg51.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 76800 c:\windows\LastGood\system32\dllcache\wam51.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 73728 c:\windows\LastGood\system32\dllcache\w3ext.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 48256 c:\windows\LastGood\system32\dllcache\w32.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 86073 c:\windows\LastGood\system32\dllcache\voicesub.dll

+ 2010-03-10 00:41 . 2004-08-04 12:00 76288 c:\windows\LastGood\system32\dllcache\uniime.dll

+ 2010-03-10 00:41 . 2004-08-04 12:00 32339 c:\windows\LastGood\system32\dllcache\uniansi.dll

+ 2010-03-10 00:40 . 2004-08-04 12:00 14336 c:\windows\LastGood\system32\dllcache\tsprof.exe

+ 2010-03-10 00:40 . 2004-08-04 12:00 31232 c:\windows\LastGood\system32\dllcache\tools.dll

+ 2010-03-10 00:40 . 2004-08-04 12:00 10240 c:\windows\LastGood\system32\dllcache\tmigrate.dll

+ 2010-03-10 00:40 . 2004-08-04 12:00 44032 c:\windows\LastGood\system32\dllcache\tintlphr.exe

+ 2010-03-10 00:40 . 2004-08-04 12:00 19464 c:\windows\LastGood\system32\dllcache\tdspx.sys

+ 2010-03-10 00:39 . 2004-08-04 12:00 21896 c:\windows\LastGood\system32\dllcache\tdipx.sys

+ 2010-03-10 00:39 . 2004-08-04 12:00 13192 c:\windows\LastGood\system32\dllcache\tdasync.sys

+ 2010-03-10 00:21 . 2003-03-24 20:52 16384 c:\windows\LastGood\system32\dllcache\tcptsat.dll

+ 2010-03-10 00:21 . 2003-03-24 20:52 32827 c:\windows\LastGood\system32\dllcache\tcptest.exe

+ 2010-03-10 00:39 . 2004-08-04 12:00 46592 c:\windows\LastGood\system32\dllcache\svcext51.dll

+ 2010-03-10 00:39 . 2004-08-04 12:00 16896 c:\windows\LastGood\system32\dllcache\status.dll

+ 2010-03-10 00:39 . 2004-08-04 12:00 46592 c:\windows\LastGood\system32\dllcache\sspifilt.dll

+ 2010-03-10 00:39 . 2004-08-04 12:00 45056 c:\windows\LastGood\system32\dllcache\ssinc51.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 56832 c:\windows\LastGood\system32\dllcache\sol.exe

+ 2010-03-10 00:38 . 2004-08-04 12:00 40448 c:\windows\LastGood\system32\dllcache\snmpthrd.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 10240 c:\windows\LastGood\system32\dllcache\snmpstup.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 32768 c:\windows\LastGood\system32\dllcache\snmp.exe

+ 2010-03-10 00:38 . 2004-08-04 12:00 10752 c:\windows\LastGood\system32\dllcache\smtpapi.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 15872 c:\windows\LastGood\system32\dllcache\smierrsm.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 31744 c:\windows\LastGood\system32\dllcache\smb6w.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 31744 c:\windows\LastGood\system32\dllcache\sma3w.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 38912 c:\windows\LastGood\system32\dllcache\sm9aw.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 26624 c:\windows\LastGood\system32\dllcache\sm93w.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 26624 c:\windows\LastGood\system32\dllcache\sm92w.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 26112 c:\windows\LastGood\system32\dllcache\sm90w.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 26112 c:\windows\LastGood\system32\dllcache\sm8dw.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 29184 c:\windows\LastGood\system32\dllcache\sm8cw.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 26112 c:\windows\LastGood\system32\dllcache\sm8aw.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 26112 c:\windows\LastGood\system32\dllcache\sm89w.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 30208 c:\windows\LastGood\system32\dllcache\sm87w.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 30208 c:\windows\LastGood\system32\dllcache\sm81w.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 25088 c:\windows\LastGood\system32\dllcache\sm59w.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 18944 c:\windows\LastGood\system32\dllcache\simptcp.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 42573 c:\windows\LastGood\system32\dllcache\shvlzm.exe

+ 2010-03-10 00:37 . 2004-08-04 12:00 66113 c:\windows\LastGood\system32\dllcache\shvl.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 16437 c:\windows\LastGood\system32\dllcache\shtml.exe

+ 2010-03-10 00:20 . 2003-03-24 20:52 20536 c:\windows\LastGood\system32\dllcache\shtml.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 79872 c:\windows\LastGood\system32\dllcache\rwia330.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 79872 c:\windows\LastGood\system32\dllcache\rwia001.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 26624 c:\windows\LastGood\system32\dllcache\rw330ext.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 24576 c:\windows\LastGood\system32\dllcache\rw001ext.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 42574 c:\windows\LastGood\system32\dllcache\rvsezm.exe

+ 2010-03-10 00:35 . 2004-08-04 12:00 48706 c:\windows\LastGood\system32\dllcache\rvse.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 14848 c:\windows\LastGood\system32\dllcache\register.exe

+ 2010-03-10 00:35 . 2004-08-04 12:00 20736 c:\windows\LastGood\system32\dllcache\ramdisk.sys

+ 2010-03-10 00:35 . 2004-08-04 12:00 16384 c:\windows\LastGood\system32\dllcache\quser.exe

+ 2010-03-10 00:34 . 2004-08-04 12:00 11264 c:\windows\LastGood\system32\dllcache\pmxmcro.dll

+ 2010-03-10 00:34 . 2004-08-04 12:00 67584 c:\windows\LastGood\system32\dllcache\pmigrate.dll

+ 2010-03-10 00:34 . 2004-08-04 12:00 70144 c:\windows\LastGood\system32\dllcache\pintlphr.exe

+ 2010-03-10 00:34 . 2004-08-04 12:00 53760 c:\windows\LastGood\system32\dllcache\pintlcsd.dll

+ 2010-03-10 00:34 . 2004-08-04 12:00 20992 c:\windows\LastGood\system32\dllcache\permchk.dll

+ 2010-03-10 00:33 . 2004-08-04 12:00 31744 c:\windows\LastGood\system32\dllcache\pagecnt.dll

+ 2010-03-10 00:33 . 2004-08-04 12:00 15360 c:\windows\LastGood\system32\dllcache\padrs804.dll

+ 2010-03-10 00:33 . 2004-08-04 12:00 14336 c:\windows\LastGood\system32\dllcache\padrs412.dll

+ 2010-03-10 00:33 . 2004-08-04 12:00 36927 c:\windows\LastGood\system32\dllcache\padrs411.dll

+ 2010-03-10 00:33 . 2004-08-04 12:00 15872 c:\windows\LastGood\system32\dllcache\padrs404.dll

+ 2010-03-10 00:32 . 2004-08-04 12:00 44544 c:\windows\LastGood\system32\dllcache\nsepm.dll

+ 2010-03-10 00:32 . 2004-08-04 12:00 53248 c:\windows\LastGood\system32\dllcache\nextlink.dll

+ 2010-03-10 00:31 . 2004-08-04 12:00 98304 c:\windows\LastGood\system32\dllcache\msir3jp.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 34304 c:\windows\LastGood\system32\dllcache\migisol.exe

+ 2010-03-10 00:30 . 2004-08-04 12:00 92416 c:\windows\LastGood\system32\dllcache\mga.sys

+ 2010-03-10 00:30 . 2004-08-04 12:00 92032 c:\windows\LastGood\system32\dllcache\mga.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 85504 c:\windows\LastGood\system32\dllcache\metada51.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 26624 c:\windows\LastGood\system32\dllcache\mdsync.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 37888 c:\windows\LastGood\system32\dllcache\md5filt.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 18944 c:\windows\LastGood\system32\dllcache\lprmon.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 22528 c:\windows\LastGood\system32\dllcache\lpdsvc.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 13312 c:\windows\LastGood\system32\dllcache\lonsint.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 22016 c:\windows\LastGood\system32\dllcache\logscrpt.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 33792 c:\windows\LastGood\system32\dllcache\lmmib2.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 70656 c:\windows\LastGood\system32\dllcache\korwbrkr.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 18432 c:\windows\LastGood\system32\dllcache\jupiw.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 26624 c:\windows\LastGood\system32\dllcache\iscomlog.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 68608 c:\windows\LastGood\system32\dllcache\isatq.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 35328 c:\windows\LastGood\system32\dllcache\iprip.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 13312 c:\windows\LastGood\system32\dllcache\infoadmn.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 19968 c:\windows\LastGood\system32\dllcache\inetsloc.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 15872 c:\windows\LastGood\system32\dllcache\inetin51.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 59392 c:\windows\LastGood\system32\dllcache\imscinst.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 59904 c:\windows\LastGood\system32\dllcache\imkrinst.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 45109 c:\windows\LastGood\system32\dllcache\imjpuex.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 81976 c:\windows\LastGood\system32\dllcache\imjpdct.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 57398 c:\windows\LastGood\system32\dllcache\imjpdadm.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 44032 c:\windows\LastGood\system32\dllcache\imekrmig.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 86016 c:\windows\LastGood\system32\dllcache\imekrmbx.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 30720 c:\windows\LastGood\system32\dllcache\iisrstas.exe

+ 2010-03-10 00:20 . 2004-08-04 12:00 14336 c:\windows\LastGood\system32\dllcache\iisreset.exe

+ 2010-03-10 00:20 . 2004-08-04 12:00 64512 c:\windows\LastGood\system32\dllcache\iismap.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 79872 c:\windows\LastGood\system32\dllcache\iislog51.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 68608 c:\windows\LastGood\system32\dllcache\iisext51.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 19456 c:\windows\LastGood\system32\dllcache\iiscrmap.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 60928 c:\windows\LastGood\system32\dllcache\iisclex4.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 25088 c:\windows\LastGood\system32\dllcache\iisadmin.dll

+ 2010-03-10 00:27 . 2004-08-04 12:00 61440 c:\windows\LastGood\system32\dllcache\httpod51.dll

+ 2010-03-10 00:27 . 2004-08-04 12:00 42573 c:\windows\LastGood\system32\dllcache\hrtzzm.exe

+ 2010-03-10 00:27 . 2004-08-04 12:00 57409 c:\windows\LastGood\system32\dllcache\hrtz.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 39936 c:\windows\LastGood\system32\dllcache\hostmib.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 36864 c:\windows\LastGood\system32\dllcache\hanjadic.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 32256 c:\windows\LastGood\system32\dllcache\gzip.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 11264 c:\windows\LastGood\system32\dllcache\fxssend.exe

+ 2010-03-10 00:26 . 2004-08-04 12:00 31744 c:\windows\LastGood\system32\dllcache\fxsroute.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 23552 c:\windows\LastGood\system32\dllcache\fxsmon.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 23552 c:\windows\LastGood\system32\dllcache\fxsext32.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 55296 c:\windows\LastGood\system32\dllcache\fxsevent.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 27136 c:\windows\LastGood\system32\dllcache\fxsdrv.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 72192 c:\windows\LastGood\system32\dllcache\fxscom.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 55296 c:\windows\LastGood\system32\dllcache\freecell.exe

+ 2010-03-10 00:20 . 2003-03-24 20:52 20538 c:\windows\LastGood\system32\dllcache\fpremadm.exe

+ 2010-03-10 00:20 . 2003-03-24 20:52 20541 c:\windows\LastGood\system32\dllcache\fpexedll.dll

+ 2010-03-10 00:26 . 2003-03-24 20:52 94208 c:\windows\LastGood\system32\dllcache\fpencode.dll

+ 2010-03-10 00:26 . 2003-03-24 20:52 20541 c:\windows\LastGood\system32\dllcache\fpadmdll.dll

+ 2010-03-10 00:26 . 2003-03-24 20:52 24632 c:\windows\LastGood\system32\dllcache\fpadmcgi.exe

+ 2010-03-10 00:20 . 2003-03-24 20:52 14608 c:\windows\LastGood\system32\dllcache\fp98sadm.exe

+ 2010-03-10 00:20 . 2003-03-24 20:52 49212 c:\windows\LastGood\system32\dllcache\fp4awebs.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 32826 c:\windows\LastGood\system32\dllcache\fp4avss.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 41020 c:\windows\LastGood\system32\dllcache\fp4avnb.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 49210 c:\windows\LastGood\system32\dllcache\fp4areg.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 82035 c:\windows\LastGood\system32\dllcache\fp4anscp.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 14848 c:\windows\LastGood\system32\dllcache\flattemp.exe

+ 2010-03-10 00:26 . 2001-08-17 17:10 22090 c:\windows\LastGood\system32\dllcache\fem556n5.sys

+ 2010-03-10 00:25 . 2004-08-04 12:00 14336 c:\windows\LastGood\system32\dllcache\exstrace.dll

+ 2010-03-10 00:38 . 2001-08-18 02:36 12288 c:\windows\LastGood\system32\dllcache\EXCH_smtpctrs.dll

+ 2010-03-10 00:37 . 2001-08-18 02:36 26112 c:\windows\LastGood\system32\dllcache\EXCH_seos.dll

+ 2010-03-10 00:36 . 2001-08-18 02:36 57856 c:\windows\LastGood\system32\dllcache\EXCH_scripto.dll

+ 2010-03-10 00:35 . 2001-08-18 02:36 23040 c:\windows\LastGood\system32\dllcache\EXCH_regtrace.exe

+ 2010-03-10 00:32 . 2001-08-18 02:36 38912 c:\windows\LastGood\system32\dllcache\EXCH_ntfsdrv.dll

+ 2010-03-10 00:30 . 2001-08-18 02:36 65536 c:\windows\LastGood\system32\dllcache\EXCH_mailmsg.dll

+ 2010-03-10 00:25 . 2001-08-18 02:36 43520 c:\windows\LastGood\system32\dllcache\EXCH_fcachdll.dll

+ 2010-03-10 00:21 . 2001-08-18 02:36 45056 c:\windows\LastGood\system32\dllcache\EXCH_aqadmin.dll

+ 2010-03-10 00:25 . 2004-08-04 12:00 92160 c:\windows\LastGood\system32\dllcache\evntwin.exe

+ 2010-03-10 00:25 . 2004-08-04 12:00 24064 c:\windows\LastGood\system32\dllcache\evntcmd.exe

+ 2010-03-10 00:25 . 2004-08-04 12:00 25856 c:\windows\LastGood\system32\dllcache\et4000.sys

+ 2010-03-10 00:25 . 2004-08-04 12:00 45056 c:\windows\LastGood\system32\dllcache\esunid.dll

+ 2010-03-10 00:25 . 2004-08-04 12:00 57856 c:\windows\LastGood\system32\dllcache\esuimgd.dll

+ 2010-03-10 00:25 . 2004-08-04 12:00 31744 c:\windows\LastGood\system32\dllcache\esucmd.dll

+ 2010-03-10 00:25 . 2001-08-17 17:10 19996 c:\windows\LastGood\system32\dllcache\em556n4.sys

+ 2010-03-10 00:23 . 2004-08-04 12:00 42496 c:\windows\LastGood\system32\dllcache\davcdata.exe

+ 2010-03-10 00:23 . 2004-08-04 12:00 18944 c:\windows\LastGood\system32\dllcache\cprofile.exe

+ 2010-03-10 00:23 . 2004-08-04 12:00 57399 c:\windows\LastGood\system32\dllcache\cplexe.exe

+ 2010-03-10 00:23 . 2004-08-04 12:00 20480 c:\windows\LastGood\system32\dllcache\counters.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 56320 c:\windows\LastGood\system32\dllcache\convlog.exe

+ 2010-03-10 00:23 . 2004-08-04 12:00 33792 c:\windows\LastGood\system32\dllcache\controt.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 24064 c:\windows\LastGood\system32\dllcache\compfilt.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 46592 c:\windows\LastGood\system32\dllcache\coadmin.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 56320 c:\windows\LastGood\system32\dllcache\chtskdic.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 97792 c:\windows\LastGood\system32\dllcache\chtmbx.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 42575 c:\windows\LastGood\system32\dllcache\chkrzm.exe

+ 2010-03-10 00:23 . 2004-08-04 12:00 40515 c:\windows\LastGood\system32\dllcache\chkr.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 14336 c:\windows\LastGood\system32\dllcache\chgusr.exe

+ 2010-03-10 00:22 . 2004-08-04 12:00 15872 c:\windows\LastGood\system32\dllcache\chgport.exe

+ 2010-03-10 00:22 . 2004-08-04 12:00 13312 c:\windows\LastGood\system32\dllcache\chglogon.exe

+ 2010-03-10 00:22 . 2004-08-04 12:00 54528 c:\windows\LastGood\system32\dllcache\cap7146.sys

+ 2010-03-10 00:22 . 2004-08-04 12:00 10752 c:\windows\LastGood\system32\dllcache\c_iscii.dll

+ 2010-03-10 00:22 . 2004-08-04 12:00 45568 c:\windows\LastGood\system32\dllcache\browscap.dll

+ 2010-03-10 00:22 . 2004-08-04 12:00 42577 c:\windows\LastGood\system32\dllcache\bckgzm.exe

+ 2010-03-10 00:22 . 2004-08-04 12:00 82501 c:\windows\LastGood\system32\dllcache\bckg.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 16439 c:\windows\LastGood\system32\dllcache\author.exe

+ 2010-03-10 00:20 . 2003-03-24 20:52 20540 c:\windows\LastGood\system32\dllcache\author.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 29184 c:\windows\LastGood\system32\dllcache\asptxn.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 10240 c:\windows\LastGood\system32\dllcache\aspperf.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 19456 c:\windows\LastGood\system32\dllcache\agt0804.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 19456 c:\windows\LastGood\system32\dllcache\agt0412.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 19456 c:\windows\LastGood\system32\dllcache\agt0411.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 19456 c:\windows\LastGood\system32\dllcache\agt040d.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 19456 c:\windows\LastGood\system32\dllcache\agt0404.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 19456 c:\windows\LastGood\system32\dllcache\agt0401.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 49664 c:\windows\LastGood\system32\dllcache\adrot.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 43520 c:\windows\LastGood\system32\dllcache\admwprox.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 16439 c:\windows\LastGood\system32\dllcache\admin.exe

+ 2010-03-10 00:20 . 2003-03-24 20:52 20540 c:\windows\LastGood\system32\dllcache\admin.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 29696 c:\windows\LastGood\system32\dllcache\admexs.dll

+ 2010-03-03 00:00 . 2010-03-03 00:00 22528 c:\windows\Installer\1b0e57.msi

+ 2010-03-04 14:26 . 2010-03-04 14:26 26192 c:\windows\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Iconlights.ico.827545C6_7013_4DE1_8E6C_DAEE4C57F54A.exe

+ 2010-03-04 14:26 . 2010-03-04 14:26 38480 c:\windows\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Icon80951CEC.exe.C76E2E86_AE54_4AF5_997C_63EBB83C7651.exe

+ 2010-03-04 14:26 . 2010-03-04 14:26 38480 c:\windows\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Icon80951CEC.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe

+ 2010-03-04 14:26 . 2010-03-04 14:26 38480 c:\windows\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\ARPICON.80486C74_ABED_4227_AF5C_9B1791CFA89C.exe

+ 2007-07-31 14:37 . 2008-04-14 12:00 4677 c:\windows\system32\dllcache\zeeverm.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 4677 c:\windows\system32\dllcache\zeeverm.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 3200 c:\windows\system32\dllcache\wowfax.dll

+ 2004-08-03 23:07 . 2004-08-04 12:00 8832 c:\windows\system32\dllcache\wmiacpi.sys

+ 2007-07-31 14:34 . 2008-04-14 12:00 7168 c:\windows\system32\dllcache\wamregps.dll

- 2007-07-31 14:34 . 2004-08-04 12:00 7168 c:\windows\system32\dllcache\wamregps.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 9216 c:\windows\system32\dllcache\wamps51.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 9216 c:\windows\system32\dllcache\wamps51.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\w3svapi.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\w3svapi.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 4608 c:\windows\system32\dllcache\w3ctrs51.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 4608 c:\windows\system32\dllcache\w3ctrs51.dll

+ 2010-03-10 00:41 . 2001-08-17 18:28 7556 c:\windows\system32\dllcache\usroslba.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 4736 c:\windows\system32\dllcache\usbd.sys

+ 2001-08-17 22:36 . 2004-08-04 12:00 8192 c:\windows\system32\dllcache\tsbyuv.dll

+ 2010-03-10 00:39 . 2001-08-17 18:52 7040 c:\windows\system32\dllcache\tandqic.sys

+ 2010-03-10 00:39 . 2001-08-17 19:02 3968 c:\windows\system32\dllcache\swusbflt.sys

+ 2010-03-10 00:38 . 2001-08-17 18:56 7552 c:\windows\system32\dllcache\sonypvu1.sys

+ 2010-03-10 00:38 . 2001-08-17 18:53 9600 c:\windows\system32\dllcache\sonymc.sys

+ 2010-03-10 00:38 . 2004-08-04 04:00 7552 c:\windows\system32\dllcache\sonyait.sys

+ 2010-03-10 00:38 . 2001-08-17 18:53 7040 c:\windows\system32\dllcache\snyaitmc.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\smimsgif.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\smimsgif.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\smierrsy.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\smierrsy.dll

+ 2010-03-10 00:38 . 2001-08-17 18:57 6784 c:\windows\system32\dllcache\smbhc.sys

+ 2010-03-10 00:38 . 2004-08-04 04:07 6912 c:\windows\system32\dllcache\smbclass.sys

+ 2010-03-10 00:38 . 2004-08-04 04:07 6016 c:\windows\system32\dllcache\smbali.sys

+ 2010-03-10 00:37 . 2004-08-04 05:56 3901 c:\windows\system32\dllcache\siint5.dll

+ 2010-03-10 00:37 . 2001-08-17 18:53 6784 c:\windows\system32\dllcache\serscan.sys

+ 2010-03-10 00:35 . 2001-08-18 03:36 9216 c:\windows\system32\dllcache\rsmgrstr.dll

+ 2010-03-10 00:35 . 2001-08-17 17:19 3840 c:\windows\system32\dllcache\rpfun.sys

+ 2010-03-10 00:35 . 2001-08-17 18:53 3328 c:\windows\system32\dllcache\qv2kux.sys

- 2007-07-31 14:37 . 2004-08-04 12:00 9728 c:\windows\system32\dllcache\query.exe

+ 2007-07-31 14:37 . 2008-04-14 12:00 9728 c:\windows\system32\dllcache\query.exe

+ 2010-03-10 00:35 . 2004-08-04 04:00 6016 c:\windows\system32\dllcache\qic157.sys

+ 2010-03-10 00:34 . 2001-08-18 03:36 5632 c:\windows\system32\dllcache\ptpusb.dll

+ 2010-03-10 00:34 . 2001-08-17 18:53 7552 c:\windows\system32\dllcache\powerfil.sys

+ 2010-03-10 00:34 . 2001-08-17 18:53 7168 c:\windows\system32\dllcache\pnrmc.sys

+ 2007-07-31 14:36 . 2008-04-14 12:00 6144 c:\windows\system32\dllcache\pmxgl.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\pmxgl.dll

+ 2004-08-04 12:00 . 2004-08-04 12:00 3456 c:\windows\system32\dllcache\oprghdlr.sys

+ 2010-03-10 00:32 . 2001-08-17 18:47 9344 c:\windows\system32\dllcache\ntapm.sys

+ 2010-03-10 00:32 . 2001-08-17 18:53 7552 c:\windows\system32\dllcache\nsmmc.sys

+ 2010-03-10 00:31 . 2001-08-18 03:36 7168 c:\windows\system32\dllcache\mxport.dll

+ 2010-03-10 00:31 . 2004-08-04 03:58 5504 c:\windows\system32\dllcache\mstee.sys

+ 2010-03-10 00:31 . 2001-08-17 19:00 2944 c:\windows\system32\dllcache\msmpu401.sys

+ 2010-03-10 00:31 . 2001-08-17 18:48 6016 c:\windows\system32\dllcache\msfsio.sys

+ 2010-03-10 00:30 . 2001-08-17 18:52 6528 c:\windows\system32\dllcache\miniqic.sys

+ 2010-03-10 00:30 . 2001-08-17 18:58 8320 c:\windows\system32\dllcache\memcard.sys

+ 2010-03-10 00:30 . 2001-08-17 18:52 7424 c:\windows\system32\dllcache\mammoth.sys

+ 2010-03-10 00:30 . 2004-08-04 04:00 7040 c:\windows\system32\dllcache\ltotape.sys

+ 2010-03-10 00:30 . 2001-08-17 18:53 4992 c:\windows\system32\dllcache\loop.sys

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdvntc.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdvntc.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdusa.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdusa.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdurdu.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdurdu.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\kbdth3.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 6144 c:\windows\system32\dllcache\kbdth3.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\kbdth2.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 6144 c:\windows\system32\dllcache\kbdth2.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdth1.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdth1.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdth0.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdth0.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdsyr2.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdsyr2.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdsyr1.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdsyr1.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 7680 c:\windows\system32\dllcache\kbdnecnt.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 7680 c:\windows\system32\dllcache\kbdnecnt.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 9216 c:\windows\system32\dllcache\kbdnecat.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 9216 c:\windows\system32\dllcache\kbdnecat.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 7168 c:\windows\system32\dllcache\kbdnec95.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 7168 c:\windows\system32\dllcache\kbdnec95.dll

+ 2010-03-10 00:29 . 2001-08-18 03:36 8192 c:\windows\system32\dllcache\kbdkor.dll

+ 2010-03-10 00:29 . 2001-08-18 03:36 8704 c:\windows\system32\dllcache\kbdjpn.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdintel.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdintel.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdintam.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdintam.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\kbdinpun.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 6144 c:\windows\system32\dllcache\kbdinpun.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdinmar.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdinmar.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdinkan.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdinkan.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdinhin.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdinhin.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdinguj.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdinguj.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdindev.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdindev.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdheb.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdheb.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5120 c:\windows\system32\dllcache\kbdgeo.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5120 c:\windows\system32\dllcache\kbdgeo.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbdfa.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdfa.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbddiv2.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbddiv2.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbddiv1.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbddiv1.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5120 c:\windows\system32\dllcache\kbdarmw.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5120 c:\windows\system32\dllcache\kbdarmw.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5120 c:\windows\system32\dllcache\kbdarme.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5120 c:\windows\system32\dllcache\kbdarme.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbda3.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbda3.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbda2.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbda2.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\kbda1.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbda1.dll

+ 2010-03-10 00:29 . 2001-08-17 19:55 6144 c:\windows\system32\dllcache\kbd106.dll

+ 2010-03-10 00:29 . 2001-08-17 19:55 5632 c:\windows\system32\dllcache\kbd103.dll

+ 2010-03-10 00:29 . 2001-08-17 19:55 6144 c:\windows\system32\dllcache\kbd101c.dll

+ 2010-03-10 00:29 . 2001-08-17 19:55 6144 c:\windows\system32\dllcache\kbd101b.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 6144 c:\windows\system32\dllcache\kbd101a.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\kbd101a.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 9216 c:\windows\system32\dllcache\iwrps.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 9216 c:\windows\system32\dllcache\iwrps.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 7168 c:\windows\system32\dllcache\isapips.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 7168 c:\windows\system32\dllcache\isapips.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 8704 c:\windows\system32\dllcache\infoctrs.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 8704 c:\windows\system32\dllcache\infoctrs.dll

- 2007-07-31 14:34 . 2004-08-04 12:00 7680 c:\windows\system32\dllcache\inetmgr.exe

+ 2007-07-31 14:34 . 2008-04-14 12:00 7680 c:\windows\system32\dllcache\inetmgr.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 6656 c:\windows\system32\dllcache\iissync.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 6656 c:\windows\system32\dllcache\iissync.exe

+ 2007-07-31 14:34 . 2008-04-14 12:00 5632 c:\windows\system32\dllcache\iisrstap.dll

- 2007-07-31 14:34 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\iisrstap.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 3584 c:\windows\system32\dllcache\iismui.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 3584 c:\windows\system32\dllcache\iismui.dll

+ 2010-03-10 00:28 . 2001-08-18 03:34 9216 c:\windows\system32\dllcache\ibmsgnet.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 9759 c:\windows\system32\dllcache\hsf_inst.dll

+ 2010-03-10 00:27 . 2001-08-17 18:52 5760 c:\windows\system32\dllcache\hpt4qic.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 9600 c:\windows\system32\dllcache\hidusb.sys

+ 2010-03-10 00:26 . 2001-08-17 19:02 2688 c:\windows\system32\dllcache\hidswvd.sys

+ 2010-03-10 00:26 . 2001-08-17 19:02 8576 c:\windows\system32\dllcache\hidgame.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 7168 c:\windows\system32\dllcache\hccoin.dll

- 2007-07-31 14:34 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\ftpsapi2.dll

+ 2007-07-31 14:34 . 2008-04-14 12:00 6144 c:\windows\system32\dllcache\ftpsapi2.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 7680 c:\windows\system32\dllcache\ftpctrs2.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 7680 c:\windows\system32\dllcache\ftpctrs2.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\ftlx041e.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 6144 c:\windows\system32\dllcache\ftlx041e.dll

- 2007-07-31 14:37 . 2001-08-18 02:36 7168 c:\windows\system32\dllcache\EXCH_snprfdll.dll

+ 2007-07-31 14:37 . 2001-08-18 03:36 7168 c:\windows\system32\dllcache\EXCH_snprfdll.dll

- 2007-07-31 14:34 . 2001-08-18 02:36 5632 c:\windows\system32\dllcache\EXCH_adsiisex.dll

+ 2007-07-31 14:34 . 2001-08-18 03:36 5632 c:\windows\system32\dllcache\EXCH_adsiisex.dll

+ 2010-03-10 00:25 . 2001-08-17 18:52 7040 c:\windows\system32\dllcache\exabyte2.sys

+ 2007-07-31 13:36 . 2001-08-17 17:46 6400 c:\windows\system32\dllcache\enum1394.sys

+ 2010-03-10 00:25 . 2001-08-17 18:53 7296 c:\windows\system32\dllcache\elmsmc.sys

+ 2004-08-03 23:07 . 2004-08-04 12:00 2944 c:\windows\system32\dllcache\drmkaud.sys

+ 2010-03-10 00:24 . 2001-08-17 18:47 8704 c:\windows\system32\dllcache\dot4scan.sys

+ 2010-03-10 00:24 . 2004-08-04 04:00 8320 c:\windows\system32\dllcache\dlttape.sys

+ 2010-03-10 00:24 . 2001-08-18 03:36 6216 c:\windows\system32\dllcache\divaci.dll

+ 2010-03-10 00:24 . 2001-08-18 03:36 6729 c:\windows\system32\dllcache\disrvci.dll

+ 2010-03-10 00:23 . 2001-08-17 18:52 7424 c:\windows\system32\dllcache\ddsmc.sys

+ 2010-03-10 00:23 . 2001-08-17 17:19 3584 c:\windows\system32\dllcache\cwcosnt5.sys

+ 2010-03-10 00:23 . 2001-08-17 17:19 3072 c:\windows\system32\dllcache\cwbmidi.sys

+ 2010-03-10 00:23 . 2001-08-17 17:19 3072 c:\windows\system32\dllcache\cwbase.sys

+ 2010-03-10 00:23 . 2001-08-18 03:36 4096 c:\windows\system32\dllcache\ctwdm32.dll

+ 2010-03-10 00:23 . 2001-08-17 17:19 3712 c:\windows\system32\dllcache\ctljystk.sys

+ 2010-03-10 00:23 . 2001-08-17 17:19 6912 c:\windows\system32\dllcache\ctlfacem.sys

+ 2001-08-17 13:58 . 2004-08-04 12:00 9344 c:\windows\system32\dllcache\compbatt.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 9728 c:\windows\system32\dllcache\change.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 9728 c:\windows\system32\dllcache\change.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 6656 c:\windows\system32\dllcache\c_is2022.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 6656 c:\windows\system32\dllcache\c_is2022.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 9728 c:\windows\system32\dllcache\brserif.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 5120 c:\windows\system32\dllcache\brscnrsm.dll

+ 2010-03-10 00:22 . 2001-08-17 18:12 3168 c:\windows\system32\dllcache\brparimg.sys

+ 2010-03-10 00:22 . 2001-08-17 18:12 3968 c:\windows\system32\dllcache\brfiltup.sys

+ 2010-03-10 00:22 . 2001-08-17 18:12 2944 c:\windows\system32\dllcache\brfilt.sys

+ 2010-03-10 00:22 . 2001-08-18 03:36 9728 c:\windows\system32\dllcache\brcoinst.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 9216 c:\windows\system32\dllcache\authfilt.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 9216 c:\windows\system32\dllcache\authfilt.dll

+ 2006-07-12 08:39 . 2001-08-17 13:59 3072 c:\windows\system32\dllcache\audstub.sys

+ 2010-03-10 00:22 . 2001-08-17 17:49 9472 c:\windows\system32\dllcache\ativmdcd.sys

+ 2010-03-10 00:21 . 2001-08-17 18:47 6272 c:\windows\system32\dllcache\apmbatt.sys

+ 2010-03-10 00:21 . 2004-08-04 05:56 3775 c:\windows\system32\dllcache\adv11nt5.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 3711 c:\windows\system32\dllcache\adv09nt5.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 3135 c:\windows\system32\dllcache\adv08nt5.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 3647 c:\windows\system32\dllcache\adv07nt5.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 3615 c:\windows\system32\dllcache\adv05nt5.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 3967 c:\windows\system32\dllcache\adv02nt5.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 4255 c:\windows\system32\dllcache\adv01nt5.dll

+ 2007-07-31 14:34 . 2008-04-14 12:00 6144 c:\windows\system32\dllcache\admxprox.dll

- 2007-07-31 14:34 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\admxprox.dll

+ 2010-03-10 00:21 . 2001-08-17 18:53 7424 c:\windows\system32\dllcache\adicvls.sys

+ 2010-03-10 00:43 . 2004-08-04 12:00 4677 c:\windows\LastGood\system32\dllcache\zeeverm.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 7168 c:\windows\LastGood\system32\dllcache\wamregps.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 9216 c:\windows\LastGood\system32\dllcache\wamps51.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\w3svapi.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 4608 c:\windows\LastGood\system32\dllcache\w3ctrs51.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 8192 c:\windows\LastGood\system32\dllcache\staxmem.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 8704 c:\windows\LastGood\system32\dllcache\snmptrap.exe

+ 2010-03-10 00:38 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\snmpmib.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\smimsgif.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\smierrsy.dll

+ 2010-03-10 00:36 . 2004-08-04 12:00 9728 c:\windows\LastGood\system32\dllcache\rwnh.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 4096 c:\windows\LastGood\system32\dllcache\rpcref.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 9728 c:\windows\LastGood\system32\dllcache\query.exe

+ 2010-03-10 00:35 . 2004-08-04 12:00 7680 c:\windows\LastGood\system32\dllcache\pwsdata.dll

+ 2010-03-10 00:34 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\pmxgl.dll

+ 2010-03-10 00:30 . 2004-08-04 12:00 7680 c:\windows\LastGood\system32\dllcache\migregdb.exe

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdvntc.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdusa.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdurdu.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\kbdth3.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\kbdth2.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdth1.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdth0.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdsyr2.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdsyr1.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 7680 c:\windows\LastGood\system32\dllcache\kbdnecnt.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 9216 c:\windows\LastGood\system32\dllcache\kbdnecat.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 7168 c:\windows\LastGood\system32\dllcache\kbdnec95.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\kbdlk41j.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6656 c:\windows\LastGood\system32\dllcache\kbdlk41a.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdintel.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdintam.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\kbdinpun.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdinmar.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdinkan.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdinhin.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdinguj.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdindev.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 7168 c:\windows\LastGood\system32\dllcache\kbdibm02.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdheb.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5120 c:\windows\LastGood\system32\dllcache\kbdgeo.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdfa.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbddiv2.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbddiv1.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\kbdax2.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5120 c:\windows\LastGood\system32\dllcache\kbdarmw.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5120 c:\windows\LastGood\system32\dllcache\kbdarme.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbda3.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbda2.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\kbda1.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\kbd106n.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\kbd101a.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\kbd101.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 9216 c:\windows\LastGood\system32\dllcache\iwrps.dll

+ 2010-03-10 00:29 . 2004-08-04 12:00 7168 c:\windows\LastGood\system32\dllcache\isapips.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 8704 c:\windows\LastGood\system32\dllcache\infoctrs.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 7680 c:\windows\LastGood\system32\dllcache\inetmgr.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 6656 c:\windows\LastGood\system32\dllcache\iissync.exe

+ 2010-03-10 00:20 . 2004-08-04 12:00 5632 c:\windows\LastGood\system32\dllcache\iisrstap.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 3584 c:\windows\LastGood\system32\dllcache\iismui.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 7168 c:\windows\LastGood\system32\dllcache\iisfecnv.dll

+ 2010-03-10 00:27 . 2004-08-04 12:00 8192 c:\windows\LastGood\system32\dllcache\httpmb51.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 6656 c:\windows\LastGood\system32\dllcache\fxsres.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 8704 c:\windows\LastGood\system32\dllcache\fxsperf.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\ftpsapi2.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\ftpmib.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 7680 c:\windows\LastGood\system32\dllcache\ftpctrs2.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\ftlx041e.dll

+ 2010-03-10 00:25 . 2004-08-04 12:00 7168 c:\windows\LastGood\system32\dllcache\f3ahvoas.dll

+ 2010-03-10 00:38 . 2001-08-18 02:36 7168 c:\windows\LastGood\system32\dllcache\EXCH_snprfdll.dll

+ 2010-03-10 00:21 . 2001-08-18 02:36 5632 c:\windows\LastGood\system32\dllcache\EXCH_adsiisex.dll

+ 2010-03-10 00:22 . 2004-08-04 12:00 9728 c:\windows\LastGood\system32\dllcache\change.exe

+ 2010-03-10 00:22 . 2004-08-04 12:00 6656 c:\windows\LastGood\system32\dllcache\c_is2022.dll

+ 2010-03-10 00:22 . 2004-08-04 12:00 9216 c:\windows\LastGood\system32\dllcache\authfilt.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 6144 c:\windows\LastGood\system32\dllcache\admxprox.dll

+ 2009-07-12 06:12 . 2009-07-12 06:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll

+ 2009-07-12 06:09 . 2009-07-12 06:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll

+ 2009-07-12 06:08 . 2009-07-12 06:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll

+ 2004-08-04 12:00 . 2004-08-04 12:00 514560 c:\windows\system32\logonui.exe

+ 2004-08-04 12:00 . 2004-08-04 12:00 220672 c:\windows\system32\logon.scr

+ 2007-07-31 14:37 . 2008-04-14 12:00 113222 c:\windows\system32\dllcache\zoneclim.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 113222 c:\windows\system32\dllcache\zoneclim.dll

+ 2004-08-04 00:56 . 2004-08-04 12:00 359936 c:\windows\system32\dllcache\wzcsvc.dll

+ 2004-08-04 12:00 . 2004-08-04 12:00 108032 c:\windows\system32\dllcache\wshbth.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 119808 c:\windows\system32\dllcache\winmine.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 119808 c:\windows\system32\dllcache\winmine.exe

+ 2010-03-10 00:42 . 2001-08-17 18:28 771581 c:\windows\system32\dllcache\winacisa.sys

+ 2010-03-10 00:42 . 2001-08-17 18:28 701386 c:\windows\system32\dllcache\wdhaalba.sys

+ 2010-03-10 00:42 . 2001-08-17 18:28 397502 c:\windows\system32\dllcache\vpctcom.sys

+ 2010-03-10 00:42 . 2001-08-17 18:28 604253 c:\windows\system32\dllcache\vmodem.sys

+ 2010-03-10 00:42 . 2001-08-17 17:14 249402 c:\windows\system32\dllcache\vinwm.sys

+ 2010-03-10 00:41 . 2001-08-17 18:28 687999 c:\windows\system32\dllcache\usrwdxjs.sys

+ 2001-08-17 22:36 . 2004-08-04 12:00 102457 c:\windows\system32\dllcache\usrv42a.dll

+ 2010-03-10 00:41 . 2001-08-17 18:28 765884 c:\windows\system32\dllcache\usrti.sys

+ 2010-03-10 00:41 . 2001-08-17 18:28 113762 c:\windows\system32\dllcache\usrpda.sys

+ 2001-08-17 22:36 . 2004-08-04 12:00 323641 c:\windows\system32\dllcache\usrdtea.dll

+ 2010-03-10 00:41 . 2001-08-17 18:28 224802 c:\windows\system32\dllcache\usr1807a.sys

+ 2010-03-10 00:41 . 2001-08-17 18:28 794399 c:\windows\system32\dllcache\usr1806v.sys

+ 2010-03-10 00:41 . 2001-08-17 18:28 793598 c:\windows\system32\dllcache\usr1806.sys

+ 2010-03-10 00:41 . 2001-08-17 18:28 794654 c:\windows\system32\dllcache\usr1801.sys

+ 2010-03-10 00:40 . 2001-08-18 03:36 216064 c:\windows\system32\dllcache\um34scan.dll

+ 2010-03-10 00:40 . 2001-08-17 17:51 166784 c:\windows\system32\dllcache\tridxpm.sys

+ 2010-03-10 00:40 . 2001-08-18 03:36 525568 c:\windows\system32\dllcache\tridxp.dll

+ 2010-03-10 00:40 . 2001-08-17 17:51 159232 c:\windows\system32\dllcache\tridkbm.sys

+ 2010-03-10 00:40 . 2001-08-17 19:56 440576 c:\windows\system32\dllcache\tridkb.dll

+ 2010-03-10 00:40 . 2001-08-17 17:51 222336 c:\windows\system32\dllcache\trid3dm.sys

+ 2010-03-10 00:40 . 2001-08-17 19:56 315520 c:\windows\system32\dllcache\trid3d.dll

+ 2010-03-10 00:40 . 2001-08-17 19:02 230912 c:\windows\system32\dllcache\tosdvd03.sys

+ 2010-03-10 00:40 . 2001-08-17 19:01 241664 c:\windows\system32\dllcache\tosdvd02.sys

+ 2010-03-10 00:40 . 2001-08-17 17:14 123995 c:\windows\system32\dllcache\tjisdn.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 455168 c:\windows\system32\dllcache\tintsetp.exe

- 2007-07-31 14:37 . 2004-08-04 12:00 455168 c:\windows\system32\dllcache\tintsetp.exe

+ 2007-07-31 14:37 . 2008-04-14 12:00 185344 c:\windows\system32\dllcache\thawbrkr.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 185344 c:\windows\system32\dllcache\thawbrkr.dll

+ 2010-03-10 00:40 . 2001-08-17 17:51 138528 c:\windows\system32\dllcache\tgiulnt5.sys

+ 2010-03-10 00:40 . 2004-08-04 04:00 149376 c:\windows\system32\dllcache\tffsport.sys

+ 2010-03-10 00:39 . 2001-08-17 19:56 172768 c:\windows\system32\dllcache\t2r4disp.dll

+ 2010-03-10 00:39 . 2001-08-17 18:50 103936 c:\windows\system32\dllcache\sx.sys

+ 2010-03-10 00:39 . 2001-08-18 03:36 155648 c:\windows\system32\dllcache\stlnprop.dll

+ 2010-03-10 00:39 . 2001-08-17 17:18 285760 c:\windows\system32\dllcache\stlnata.sys

+ 2007-07-31 14:37 . 2008-04-14 12:00 101376 c:\windows\system32\dllcache\srusbusd.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 101376 c:\windows\system32\dllcache\srusbusd.dll

+ 2010-03-10 00:38 . 2001-08-18 03:36 106584 c:\windows\system32\dllcache\spdports.dll

+ 2010-03-10 00:38 . 2001-08-18 03:36 114688 c:\windows\system32\dllcache\sonypi.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 143422 c:\windows\system32\dllcache\softkey.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 143422 c:\windows\system32\dllcache\softkey.dll

+ 2010-03-10 00:38 . 2001-08-17 19:56 147200 c:\windows\system32\dllcache\smidispb.dll

+ 2010-03-10 00:37 . 2004-08-04 03:41 404990 c:\windows\system32\dllcache\slntamr.sys

+ 2010-03-10 00:37 . 2004-08-04 03:41 129535 c:\windows\system32\dllcache\slnt7554.sys

+ 2010-03-10 00:37 . 2004-08-04 05:56 188508 c:\windows\system32\dllcache\slgen.dll

+ 2010-03-10 00:37 . 2004-08-04 05:56 286792 c:\windows\system32\dllcache\slextspk.dll

+ 2010-03-10 00:37 . 2001-08-17 19:56 157696 c:\windows\system32\dllcache\sisv256.dll

+ 2010-03-10 00:37 . 2001-08-18 03:36 238592 c:\windows\system32\dllcache\sisgrv.dll

+ 2010-03-10 00:37 . 2001-08-17 17:50 104064 c:\windows\system32\dllcache\sisgrp.sys

+ 2010-03-10 00:37 . 2001-08-17 19:56 150144 c:\windows\system32\dllcache\sis6306v.dll

+ 2010-03-10 00:37 . 2001-08-17 19:56 252032 c:\windows\system32\dllcache\sis300iv.dll

+ 2010-03-10 00:37 . 2001-08-17 17:50 101760 c:\windows\system32\dllcache\sis300ip.sys

+ 2010-03-10 00:37 . 2001-07-21 19:29 161568 c:\windows\system32\dllcache\sgsmusb.sys

+ 2010-03-10 00:37 . 2001-08-18 03:36 386560 c:\windows\system32\dllcache\sgiul50.dll

+ 2010-03-10 00:36 . 2001-08-18 03:36 495616 c:\windows\system32\dllcache\sblfx.dll

+ 2010-03-10 00:36 . 2001-08-17 19:56 245632 c:\windows\system32\dllcache\s3savmx.dll

+ 2010-03-10 00:36 . 2001-08-17 19:56 198400 c:\windows\system32\dllcache\s3sav4.dll

+ 2010-03-10 00:36 . 2001-08-17 19:56 179264 c:\windows\system32\dllcache\s3sav3d.dll

+ 2010-03-10 00:36 . 2001-08-17 19:56 210496 c:\windows\system32\dllcache\s3mvirge.dll

+ 2010-03-10 00:36 . 2001-08-17 19:56 182272 c:\windows\system32\dllcache\s3mt3d.dll

+ 2010-03-10 00:36 . 2001-08-17 17:50 166720 c:\windows\system32\dllcache\s3m.sys

+ 2010-03-10 00:36 . 2004-08-04 03:29 166912 c:\windows\system32\dllcache\s3gnbm.sys

+ 2010-03-10 00:36 . 2004-08-04 05:56 397056 c:\windows\system32\dllcache\s3gnb.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 753236 c:\windows\system32\dllcache\rvseres.dll

+ 2007-07-31 14:37 . 2008-04-14 12:00 753236 c:\windows\system32\dllcache\rvseres.dll

+ 2010-03-10 00:35 . 2001-08-17 18:28 714762 c:\windows\system32\dllcache\r2mdmkxx.sys

+ 2010-03-10 00:35 . 2001-08-17 18:28 899146 c:\windows\system32\dllcache\r2mdkxga.sys

+ 2010-03-10 00:34 . 2001-08-17 18:28 112574 c:\windows\system32\dllcache\ptserlp.sys

+ 2010-03-10 00:34 . 2001-08-17 18:28 128286 c:\windows\system32\dllcache\ptserli.sys

+ 2010-03-10 00:34 . 2004-08-04 05:56 159232 c:\windows\system32\dllcache\ptpusd.dll

+ 2010-03-10 00:34 . 2004-08-04 05:56 363520 c:\windows\system32\dllcache\psisdecd.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 131584 c:\windows\system32\dllcache\pmxviceo.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 131584 c:\windows\system32\dllcache\pmxviceo.dll

+ 2010-03-10 00:34 . 2001-08-18 03:36 121344 c:\windows\system32\dllcache\phvfwext.dll

+ 2010-03-10 00:34 . 2001-08-17 19:04 173696 c:\windows\system32\dllcache\philcam2.sys

+ 2010-03-10 00:34 . 2004-08-04 05:56 259328 c:\windows\system32\dllcache\perm3dd.dll

+ 2010-03-10 00:34 . 2004-08-04 05:56 211712 c:\windows\system32\dllcache\perm2dll.dll

+ 2010-03-10 00:34 . 2004-08-04 03:06 169984 c:\windows\system32\dllcache\pcx500.sys

+ 2001-08-17 22:36 . 2004-08-04 12:00 157696 c:\windows\system32\dllcache\paqsp.dll

+ 2010-03-10 00:33 . 2001-08-17 19:05 351616 c:\windows\system32\dllcache\ovcodek2.sys

+ 2010-03-10 00:33 . 2001-08-18 03:36 116736 c:\windows\system32\dllcache\ovcodec2.dll

+ 2010-03-10 00:32 . 2001-08-18 03:36 123776 c:\windows\system32\dllcache\nv3.dll

+ 2010-03-10 00:32 . 2004-08-04 03:41 180360 c:\windows\system32\dllcache\ntmtlfax.sys

+ 2010-03-10 00:32 . 2001-08-17 17:20 126080 c:\windows\system32\dllcache\nm5a2wdm.sys

+ 2010-03-10 00:32 . 2004-08-04 03:31 132695 c:\windows\system32\dllcache\netwlan5.sys

+ 2010-03-10 00:31 . 2001-08-17 17:11 128000 c:\windows\system32\dllcache\n100325.sys

- 2007-07-31 14:36 . 2004-08-04 12:00 229439 c:\windows\system32\dllcache\multibox.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 229439 c:\windows\system32\dllcache\multibox.dll

+ 2010-03-10 00:31 . 2001-08-17 17:50 103296 c:\windows\system32\dllcache\mtxvideo.sys

+ 2010-03-10 00:31 . 2004-08-04 03:29 452736 c:\windows\system32\dllcache\mtxparhm.sys

+ 2010-03-10 00:31 . 2004-08-04 03:41 126686 c:\windows\system32\dllcache\mtlmnt5.sys

+ 2006-07-12 12:41 . 2006-11-07 08:06 600576 c:\windows\system32\dllcache\mstsc.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 126976 c:\windows\system32\dllcache\mshearts.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 126976 c:\windows\system32\dllcache\mshearts.exe

- 2008-09-05 18:34 . 2008-10-24 11:10 453632 c:\windows\system32\dllcache\mrxsmb.sys

+ 2004-08-04 12:00 . 2008-10-24 11:10 453632 c:\windows\system32\dllcache\mrxsmb.sys

+ 2010-03-10 00:30 . 2001-08-17 17:50 320384 c:\windows\system32\dllcache\mgaum.sys

+ 2010-03-10 00:30 . 2001-08-17 19:56 235648 c:\windows\system32\dllcache\mgaud.dll

+ 2001-08-17 22:36 . 2004-08-04 12:00 147968 c:\windows\system32\dllcache\mdwmdmsp.dll

+ 2010-03-10 00:30 . 2001-08-17 17:12 164586 c:\windows\system32\dllcache\mdgndis5.sys

+ 2010-03-10 00:30 . 2001-08-17 18:28 797500 c:\windows\system32\dllcache\ltsmt.sys

+ 2010-03-10 00:30 . 2001-08-17 18:28 802683 c:\windows\system32\dllcache\ltsm.sys

+ 2010-03-10 00:30 . 2004-08-04 03:41 420992 c:\windows\system32\dllcache\ltmdmntt.sys

+ 2010-03-10 00:30 . 2001-08-17 18:28 576746 c:\windows\system32\dllcache\ltmdmntl.sys

+ 2010-03-10 00:30 . 2004-08-04 03:41 606684 c:\windows\system32\dllcache\ltmdmnt.sys

+ 2010-03-10 00:30 . 2001-08-17 18:28 727786 c:\windows\system32\dllcache\ltck000c.sys

+ 2004-08-03 23:07 . 2004-08-04 12:00 171776 c:\windows\system32\dllcache\kmixer.sys

+ 2010-03-10 00:29 . 2001-08-18 03:36 242176 c:\windows\system32\dllcache\kdsusd.dll

+ 2010-03-10 00:29 . 2004-08-04 05:56 152576 c:\windows\system32\dllcache\irftp.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 471102 c:\windows\system32\dllcache\imskdic.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 471102 c:\windows\system32\dllcache\imskdic.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 262200 c:\windows\system32\dllcache\imjputy.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 262200 c:\windows\system32\dllcache\imjputy.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 233527 c:\windows\system32\dllcache\imjprw.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 233527 c:\windows\system32\dllcache\imjprw.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 208952 c:\windows\system32\dllcache\imjpmig.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 208952 c:\windows\system32\dllcache\imjpmig.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 196665 c:\windows\system32\dllcache\imjpinst.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 196665 c:\windows\system32\dllcache\imjpinst.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 155705 c:\windows\system32\dllcache\imjpdsvr.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 155705 c:\windows\system32\dllcache\imjpdsvr.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 307257 c:\windows\system32\dllcache\imjpdct.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 307257 c:\windows\system32\dllcache\imjpdct.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 311359 c:\windows\system32\dllcache\imepadsv.exe

- 2007-07-31 14:36 . 2004-08-04 12:00 311359 c:\windows\system32\dllcache\imepadsv.exe

+ 2007-07-31 14:36 . 2008-04-14 12:00 102463 c:\windows\system32\dllcache\imepadsm.dll

- 2007-07-31 14:36 . 2004-08-04 12:00 102463 c:\windows\system32\dllcache\imepadsm.dll

+ 2007-07-31 14:34 . 2008-04-14 12:00 169984 c:\windows\system32\dllcache\iisui.dll

- 2007-07-31 14:34 . 2004-08-04 12:00 169984 c:\windows\system32\dllcache\iisui.dll

+ 2010-03-10 00:28 . 2001-08-18 03:36 372824 c:\windows\system32\dllcache\iconf32.dll

+ 2010-03-10 00:28 . 2001-08-17 19:06 100992 c:\windows\system32\dllcache\icam5usb.sys

+ 2010-03-10 00:28 . 2001-08-17 19:06 154496 c:\windows\system32\dllcache\icam4usb.sys

+ 2010-03-10 00:28 . 2001-08-17 19:05 141056 c:\windows\system32\dllcache\icam3.sys

+ 2010-03-10 00:28 . 2001-08-17 17:12 109085 c:\windows\system32\dllcache\ibmtrp.sys

+ 2010-03-10 00:28 . 2001-08-17 17:12 100936 c:\windows\system32\dllcache\ibmtok.sys

+ 2010-03-10 00:28 . 2004-08-04 03:29 161020 c:\windows\system32\dllcache\i81xnt5.sys

+ 2010-03-10 00:28 . 2004-08-04 05:56 702845 c:\windows\system32\dllcache\i81xdnt5.dll

+ 2010-03-10 00:28 . 2001-08-17 19:56 353184 c:\windows\system32\dllcache\i740dnt5.dll

+ 2004-08-04 12:00 . 2009-10-20 14:58 263552 c:\windows\system32\dllcache\http.sys

- 2009-10-20 14:58 . 2009-10-20 14:58 263552 c:\windows\system32\dllcache\http.sys

+ 2010-03-10 00:27 . 2004-08-04 03:41 685056 c:\windows\system32\dllcache\hsfcxts2.sys

+ 2010-03-10 00:27 . 2004-08-04 03:41 220032 c:\windows\system32\dllcache\hsfbs2s2.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 488383 c:\windows\system32\dllcache\hsf_v124.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 542879 c:\windows\system32\dllcache\hsf_msft.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 391199 c:\windows\system32\dllcache\hsf_k56k.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 115807 c:\windows\system32\dllcache\hsf_fsks.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 199711 c:\windows\system32\dllcache\hsf_faxx.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 289887 c:\windows\system32\dllcache\hsf_fall.sys

+ 2010-03-10 00:27 . 2001-08-17 18:28 150239 c:\windows\system32\dllcache\hsf_amos.sys

+ 2010-03-10 00:27 . 2001-08-18 03:36 324608 c:\windows\system32\dllcache\hpojwia.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 165888 c:\windows\system32\dllcache\hpgt53.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 126976 c:\windows\system32\dllcache\hpgt34tk.dll

+ 2010-03-10 00:27 . 2001-08-18 03:36 101376 c:\windows\system32\dllcache\hpgt34.dll

+ 2010-03-10 00:26 . 2001-08-18 03:36 119296 c:\windows\system32\dllcache\hpdigwia.dll

+ 2010-03-10 00:26 . 2001-08-17 18:28 907456 c:\windows\system32\dllcache\hcf_msft.sys

+ 2010-03-10 00:26 . 2001-08-17 17:49 322432 c:\windows\system32\dllcache\g400m.sys

+ 2010-03-10 00:26 . 2001-08-17 17:49 320384 c:\windows\system32\dllcache\g200m.sys

+ 2010-03-10 00:26 . 2001-08-17 19:56 470144 c:\windows\system32\dllcache\g200d.dll

+ 2010-03-10 00:26 . 2001-08-17 17:15 454912 c:\windows\system32\dllcache\fxusbase.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 132608 c:\windows\system32\dllcache\fxsclntr.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 132608 c:\windows\system32\dllcache\fxsclntr.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 111104 c:\windows\system32\dllcache\fxscfgwz.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 111104 c:\windows\system32\dllcache\fxscfgwz.dll

+ 2010-03-10 00:26 . 2001-08-17 17:15 455296 c:\windows\system32\dllcache\fusbbase.sys

+ 2010-03-10 00:26 . 2001-08-17 17:15 455680 c:\windows\system32\dllcache\fus2base.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 193024 c:\windows\system32\dllcache\fsquirt.exe

+ 2010-03-10 00:26 . 2001-08-17 17:15 442240 c:\windows\system32\dllcache\fpnpbase.sys

- 2007-07-31 14:34 . 2003-03-24 20:52 208896 c:\windows\system32\dllcache\fpmmcsat.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 208896 c:\windows\system32\dllcache\fpmmcsat.dll

- 2007-07-31 14:34 . 2004-05-13 04:39 598071 c:\windows\system32\dllcache\fpmmc.dll

+ 2007-07-31 14:34 . 2004-05-13 05:39 598071 c:\windows\system32\dllcache\fpmmc.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 188494 c:\windows\system32\dllcache\fpcount.exe

+ 2007-07-31 14:34 . 2003-03-24 21:52 188494 c:\windows\system32\dllcache\fpcount.exe

+ 2010-03-10 00:26 . 2001-08-17 17:14 441728 c:\windows\system32\dllcache\fpcmbase.sys

+ 2010-03-10 00:26 . 2001-08-17 17:14 444416 c:\windows\system32\dllcache\fpcibase.sys

+ 2007-07-31 14:34 . 2003-03-24 21:52 109328 c:\windows\system32\dllcache\fp98swin.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 109328 c:\windows\system32\dllcache\fp98swin.exe

+ 2007-07-31 14:34 . 2004-05-13 05:39 876653 c:\windows\system32\dllcache\fp4awel.dll

- 2007-07-31 14:34 . 2004-05-13 04:39 876653 c:\windows\system32\dllcache\fp4awel.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 102509 c:\windows\system32\dllcache\fp4atxt.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 102509 c:\windows\system32\dllcache\fp4atxt.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 147513 c:\windows\system32\dllcache\fp4apws.dll

- 2007-07-31 14:34 . 2003-03-24 20:52 147513 c:\windows\system32\dllcache\fp4apws.dll

+ 2007-07-31 14:34 . 2004-05-13 05:39 184435 c:\windows\system32\dllcache\fp4amsft.dll

- 2007-07-31 14:34 . 2004-05-13 04:39 184435 c:\windows\system32\dllcache\fp4amsft.dll

+ 2010-03-10 00:25 . 2004-08-04 03:32 137088 c:\windows\system32\dllcache\essm2e.sys

+ 2010-03-10 00:25 . 2001-08-17 18:28 347550 c:\windows\system32\dllcache\es56tpi.sys

+ 2010-03-10 00:25 . 2001-08-17 18:28 594238 c:\windows\system32\dllcache\es56hpi.sys

+ 2010-03-10 00:25 . 2001-08-17 18:28 595647 c:\windows\system32\dllcache\es56cvmp.sys

+ 2010-03-10 00:25 . 2001-08-17 17:19 174464 c:\windows\system32\dllcache\es198x.sys

+ 2010-03-10 00:25 . 2001-08-17 17:17 629952 c:\windows\system32\dllcache\eqn.sys

+ 2010-03-10 00:25 . 2001-08-17 18:50 114944 c:\windows\system32\dllcache\epstw2k.sys

+ 2010-03-10 00:25 . 2001-08-17 18:50 144896 c:\windows\system32\dllcache\epcfw2k.sys

+ 2010-03-10 00:25 . 2001-08-17 17:19 283904 c:\windows\system32\dllcache\emu10k1m.sys

+ 2010-03-10 00:25 . 2001-08-17 17:11 171520 c:\windows\system32\dllcache\el99xn51.sys

+ 2010-03-10 00:25 . 2001-08-17 17:11 455199 c:\windows\system32\dllcache\el985n51.sys

+ 2010-03-10 00:25 . 2001-08-17 17:11 153631 c:\windows\system32\dllcache\el90xnd5.sys

+ 2010-03-10 00:24 . 2001-08-17 18:28 634134 c:\windows\system32\dllcache\el656ct5.sys

+ 2010-03-10 00:24 . 2001-08-17 17:12 117760 c:\windows\system32\dllcache\e100b325.sys

+ 2010-03-10 00:24 . 2001-08-17 17:20 334208 c:\windows\system32\dllcache\ds1wdm.sys

+ 2010-03-10 00:24 . 2004-08-04 03:58 207360 c:\windows\system32\dllcache\dot4.sys

+ 2010-03-10 00:24 . 2001-08-17 17:14 952007 c:\windows\system32\dllcache\diwan.sys

+ 2010-03-10 00:24 . 2001-08-18 03:36 236060 c:\windows\system32\dllcache\ditrace.exe

+ 2010-03-10 00:24 . 2001-08-18 03:36 614429 c:\windows\system32\dllcache\digiview.exe

+ 2010-03-10 00:24 . 2001-08-18 03:36 110621 c:\windows\system32\dllcache\digirlpt.dll

+ 2010-03-10 00:24 . 2001-08-18 03:36 102484 c:\windows\system32\dllcache\digiinf.dll

+ 2010-03-10 00:24 . 2001-08-18 03:36 159828 c:\windows\system32\dllcache\digihlc.dll

+ 2010-03-10 00:24 . 2001-08-18 03:36 229462 c:\windows\system32\dllcache\digifwrk.dll

+ 2010-03-10 00:24 . 2001-08-17 17:13 103044 c:\windows\system32\dllcache\digidxb.sys

+ 2010-03-10 00:24 . 2001-08-18 03:36 131156 c:\windows\system32\dllcache\digidbp.dll

+ 2010-03-10 00:22 . 2001-08-17 17:13 164923 c:\windows\system32\dllcache\diapi2.sys

+ 2010-03-10 00:24 . 2001-08-18 03:36 419357 c:\windows\system32\dllcache\dgconfig.dll

+ 2010-03-10 00:23 . 2001-08-18 03:36 110592 c:\windows\system32\dllcache\dc260usd.dll

+ 2010-03-10 00:23 . 2001-08-17 17:12 117760 c:\windows\system32\dllcache\d100ib5.sys

+ 2010-03-10 00:23 . 2001-08-17 17:19 111872 c:\windows\system32\dllcache\cwcspud.sys

+ 2010-03-10 00:23 . 2004-08-04 05:56 249856 c:\windows\system32\dllcache\ctmasetp.dll

+ 2010-03-10 00:23 . 2001-08-18 03:36 175104 c:\windows\system32\dllcache\csamsp.dll

+ 2010-03-10 00:23 . 2001-08-18 03:36 216064 c:\windows\system32\dllcache\cpscan.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 217160 c:\windows\system32\dllcache\cmnclim.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 217160 c:\windows\system32\dllcache\cmnclim.dll

+ 2010-03-10 00:23 . 2001-08-17 18:57 248064 c:\windows\system32\dllcache\cl546xm.sys

+ 2010-03-10 00:23 . 2001-08-17 19:56 170880 c:\windows\system32\dllcache\cl546x.dll

+ 2010-03-10 00:23 . 2001-08-17 19:56 111232 c:\windows\system32\dllcache\cl5465.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 480256 c:\windows\system32\dllcache\cintsetp.exe

- 2007-07-31 14:35 . 2004-08-04 12:00 480256 c:\windows\system32\dllcache\cintsetp.exe

+ 2001-08-17 14:02 . 2004-08-04 12:00 262528 c:\windows\system32\dllcache\cinemst2.sys

+ 2010-03-10 00:23 . 2001-08-17 19:02 272640 c:\windows\system32\dllcache\cinemclc.sys

+ 2010-03-10 00:23 . 2001-08-17 17:13 980034 c:\windows\system32\dllcache\cicap.sys

+ 2007-07-31 14:35 . 2008-04-14 12:00 838144 c:\windows\system32\dllcache\chtbrkr.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 838144 c:\windows\system32\dllcache\chtbrkr.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 780885 c:\windows\system32\dllcache\chkrres.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 780885 c:\windows\system32\dllcache\chkrres.dll

+ 2007-07-31 14:34 . 2003-03-24 21:52 188480 c:\windows\system32\dllcache\cfgwiz.exe

- 2007-07-31 14:34 . 2003-03-24 20:52 188480 c:\windows\system32\dllcache\cfgwiz.exe

+ 2010-03-10 00:22 . 2001-08-17 18:28 714698 c:\windows\system32\dllcache\cbmdmkxx.sys

+ 2010-03-10 00:22 . 2001-08-18 03:36 119296 c:\windows\system32\dllcache\camext30.dll

+ 2010-03-10 00:22 . 2001-08-18 03:36 236032 c:\windows\system32\dllcache\camext20.dll

+ 2010-03-10 00:22 . 2001-08-17 19:04 171264 c:\windows\system32\dllcache\camdrv30.sys

+ 2010-03-10 00:22 . 2001-08-17 19:04 223232 c:\windows\system32\dllcache\camdrv21.sys

+ 2010-03-10 00:22 . 2001-08-17 19:05 314752 c:\windows\system32\dllcache\camdro21.sys

- 2008-07-16 12:02 . 2008-06-13 13:10 272128 c:\windows\system32\dllcache\bthport.sys

+ 2004-08-04 12:00 . 2008-06-13 13:10 272128 c:\windows\system32\dllcache\bthport.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 100992 c:\windows\system32\dllcache\bthpan.sys

+ 2010-03-10 00:22 . 2001-08-18 03:36 102400 c:\windows\system32\dllcache\binlsvc.dll

+ 2010-03-10 00:22 . 2001-08-17 18:28 871388 c:\windows\system32\dllcache\bcmdm.sys

+ 2010-03-10 00:22 . 2001-08-17 19:56 342336 c:\windows\system32\dllcache\banshee.dll

+ 2006-06-19 17:04 . 2006-06-19 17:04 156160 c:\windows\system32\dllcache\b57xp32.sys

+ 2010-03-10 00:22 . 2001-08-18 03:36 144384 c:\windows\system32\dllcache\avmenum.dll

+ 2010-03-10 00:22 . 2004-08-04 05:56 516768 c:\windows\system32\dllcache\ativvaxx.dll

+ 2010-03-10 00:21 . 2001-08-17 19:56 104832 c:\windows\system32\dllcache\atiraged.dll

+ 2010-03-10 00:21 . 2004-08-04 03:29 104960 c:\windows\system32\dllcache\atinrvxx.sys

+ 2010-03-10 00:21 . 2001-08-17 17:48 281600 c:\windows\system32\dllcache\atimtai.sys

+ 2010-03-10 00:21 . 2001-08-17 17:48 289664 c:\windows\system32\dllcache\atimpab.sys

+ 2010-03-10 00:21 . 2001-08-17 19:56 268160 c:\windows\system32\dllcache\atidvai.dll

+ 2010-03-10 00:21 . 2001-08-17 19:56 137216 c:\windows\system32\dllcache\atidrae.dll

+ 2010-03-10 00:21 . 2001-08-17 19:55 382592 c:\windows\system32\dllcache\atidrab.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 870784 c:\windows\system32\dllcache\ati3d1ag.dll

+ 2010-03-10 00:21 . 2004-08-04 03:29 701440 c:\windows\system32\dllcache\ati2mtag.sys

+ 2010-03-10 00:21 . 2004-08-04 03:29 327040 c:\windows\system32\dllcache\ati2mtaa.sys

+ 2010-03-10 00:21 . 2004-08-04 05:56 201728 c:\windows\system32\dllcache\ati2dvag.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 377984 c:\windows\system32\dllcache\ati2dvaa.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 229376 c:\windows\system32\dllcache\ati2cqag.dll

+ 2010-03-10 00:21 . 2001-08-17 17:19 747392 c:\windows\system32\dllcache\adm8830.sys

+ 2010-03-10 00:21 . 2001-08-17 17:19 553984 c:\windows\system32\dllcache\adm8820.sys

+ 2010-03-10 00:21 . 2001-08-17 17:19 584448 c:\windows\system32\dllcache\adm8810.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 187776 c:\windows\system32\dllcache\acpi.sys

+ 2010-03-10 00:21 . 2001-08-17 17:20 297728 c:\windows\system32\dllcache\ac97sis.sys

+ 2010-03-10 00:21 . 2004-08-04 03:32 231552 c:\windows\system32\dllcache\ac97ali.sys

+ 2010-03-10 00:21 . 2001-08-18 03:36 462848 c:\windows\system32\dllcache\a3dapi.dll

+ 2010-03-10 00:21 . 2001-08-17 17:48 148352 c:\windows\system32\dllcache\3dfxvsm.sys

+ 2010-03-10 00:21 . 2001-08-17 19:55 689216 c:\windows\system32\dllcache\3dfxvs.dll

+ 2010-03-10 00:21 . 2001-08-17 18:28 762780 c:\windows\system32\dllcache\3cwmcru.sys

+ 2004-08-04 12:00 . 2004-08-04 12:00 388608 c:\windows\system32\cmd.exe

+ 2010-03-10 00:43 . 2004-08-04 12:00 113222 c:\windows\LastGood\system32\dllcache\zoneclim.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 119808 c:\windows\LastGood\system32\dllcache\winmine.exe

+ 2010-03-10 00:42 . 2004-08-04 12:00 363520 c:\windows\LastGood\system32\dllcache\w3svc.dll

+ 2010-03-10 00:42 . 2004-08-04 12:00 426041 c:\windows\LastGood\system32\dllcache\voicepad.dll

+ 2010-03-10 00:40 . 2004-08-04 12:00 103424 c:\windows\LastGood\system32\dllcache\uihelper.dll

+ 2010-03-10 00:40 . 2004-08-04 12:00 455168 c:\windows\LastGood\system32\dllcache\tintsetp.exe

+ 2010-03-10 00:40 . 2004-08-04 12:00 185344 c:\windows\LastGood\system32\dllcache\thawbrkr.dll

+ 2010-03-10 00:39 . 2004-08-04 12:00 101376 c:\windows\LastGood\system32\dllcache\srusbusd.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 538624 c:\windows\LastGood\system32\dllcache\spider.exe

+ 2010-03-10 00:38 . 2004-08-04 12:00 143422 c:\windows\LastGood\system32\dllcache\softkey.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 188416 c:\windows\LastGood\system32\dllcache\snmpsmir.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 358400 c:\windows\LastGood\system32\dllcache\snmpincl.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 259072 c:\windows\LastGood\system32\dllcache\snmpcl.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 456704 c:\windows\LastGood\system32\dllcache\smtpsvc.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 189440 c:\windows\LastGood\system32\dllcache\smtpadm.dll

+ 2010-03-10 00:38 . 2004-08-04 12:00 236544 c:\windows\LastGood\system32\dllcache\smi2smir.exe

+ 2010-03-10 00:37 . 2004-08-04 12:00 221696 c:\windows\LastGood\system32\dllcache\seo.dll

+ 2010-03-10 00:35 . 2004-08-04 12:00 753236 c:\windows\LastGood\system32\dllcache\rvseres.dll

+ 2010-03-10 00:34 . 2004-08-04 12:00 131584 c:\windows\LastGood\system32\dllcache\pmxviceo.dll

+ 2010-03-10 00:34 . 2004-08-04 12:00 175104 c:\windows\LastGood\system32\dllcache\pintlcsa.dll

+ 2010-03-10 00:34 . 2004-08-04 12:00 281088 c:\windows\LastGood\system32\dllcache\pinball.exe

+ 2010-03-10 00:31 . 2004-08-04 12:00 229439 c:\windows\LastGood\system32\dllcache\multibox.dll

+ 2010-03-10 00:31 . 2004-08-04 12:00 111104 c:\windows\LastGood\system32\dllcache\mtstocom.exe

+ 2010-03-10 00:31 . 2004-08-04 12:00 126976 c:\windows\LastGood\system32\dllcache\mshearts.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 257024 c:\windows\LastGood\system32\dllcache\infocomm.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 829440 c:\windows\LastGood\system32\dllcache\inetmgr.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 315452 c:\windows\LastGood\system32\dllcache\imskf.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 471102 c:\windows\LastGood\system32\dllcache\imskdic.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 102456 c:\windows\LastGood\system32\dllcache\imlang.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 274489 c:\windows\LastGood\system32\dllcache\imjputyc.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 262200 c:\windows\LastGood\system32\dllcache\imjputy.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 233527 c:\windows\LastGood\system32\dllcache\imjprw.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 208952 c:\windows\LastGood\system32\dllcache\imjpmig.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 196665 c:\windows\LastGood\system32\dllcache\imjpinst.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 155705 c:\windows\LastGood\system32\dllcache\imjpdsvr.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 307257 c:\windows\LastGood\system32\dllcache\imjpdct.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 716856 c:\windows\LastGood\system32\dllcache\imjpcus.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 368696 c:\windows\LastGood\system32\dllcache\imjpcic.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 811064 c:\windows\LastGood\system32\dllcache\imjp81k.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 311359 c:\windows\LastGood\system32\dllcache\imepadsv.exe

+ 2010-03-10 00:28 . 2004-08-04 12:00 102463 c:\windows\LastGood\system32\dllcache\imepadsm.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 106496 c:\windows\LastGood\system32\dllcache\imekrcic.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 169984 c:\windows\LastGood\system32\dllcache\iisui.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 133632 c:\windows\LastGood\system32\dllcache\iisrtl.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 145408 c:\windows\LastGood\system32\dllcache\iische51.dll

+ 2010-03-10 00:27 . 2004-08-04 12:00 268288 c:\windows\LastGood\system32\dllcache\httpext.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 400384 c:\windows\LastGood\system32\dllcache\fxsxp32.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 192512 c:\windows\LastGood\system32\dllcache\fxswzrd.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 154112 c:\windows\LastGood\system32\dllcache\fxsui.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 397312 c:\windows\LastGood\system32\dllcache\fxstiff.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 246272 c:\windows\LastGood\system32\dllcache\fxst30.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 267776 c:\windows\LastGood\system32\dllcache\fxssvc.exe

+ 2010-03-10 00:26 . 2004-08-04 12:00 562176 c:\windows\LastGood\system32\dllcache\fxsst.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 229376 c:\windows\LastGood\system32\dllcache\fxscover.exe

+ 2010-03-10 00:26 . 2004-08-04 12:00 285184 c:\windows\LastGood\system32\dllcache\fxscomex.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 132608 c:\windows\LastGood\system32\dllcache\fxsclntr.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 143360 c:\windows\LastGood\system32\dllcache\fxsclnt.exe

+ 2010-03-10 00:26 . 2004-08-04 12:00 111104 c:\windows\LastGood\system32\dllcache\fxscfgwz.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 452096 c:\windows\LastGood\system32\dllcache\fxsapi.dll

+ 2010-03-10 00:26 . 2004-08-04 12:00 125952 c:\windows\LastGood\system32\dllcache\ftpsv251.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 208896 c:\windows\LastGood\system32\dllcache\fpmmcsat.dll

+ 2010-03-10 00:20 . 2004-05-13 04:39 598071 c:\windows\LastGood\system32\dllcache\fpmmc.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 188494 c:\windows\LastGood\system32\dllcache\fpcount.exe

+ 2010-03-10 00:20 . 2003-03-24 20:52 109328 c:\windows\LastGood\system32\dllcache\fp98swin.exe

+ 2010-03-10 00:20 . 2004-05-13 04:39 876653 c:\windows\LastGood\system32\dllcache\fp4awel.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 102509 c:\windows\LastGood\system32\dllcache\fp4atxt.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 147513 c:\windows\LastGood\system32\dllcache\fp4apws.dll

+ 2010-03-10 00:20 . 2004-05-13 04:39 184435 c:\windows\LastGood\system32\dllcache\fp4amsft.dll

+ 2010-03-10 00:25 . 2004-08-04 12:00 101888 c:\windows\LastGood\system32\dllcache\evntagnt.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 217160 c:\windows\LastGood\system32\dllcache\cmnclim.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 480256 c:\windows\LastGood\system32\dllcache\cintsetp.exe

+ 2010-03-10 00:23 . 2004-08-04 12:00 198656 c:\windows\LastGood\system32\dllcache\cintime.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 173568 c:\windows\LastGood\system32\dllcache\chtskf.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 838144 c:\windows\LastGood\system32\dllcache\chtbrkr.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 780885 c:\windows\LastGood\system32\dllcache\chkrres.dll

+ 2010-03-10 00:20 . 2003-03-24 20:52 188480 c:\windows\LastGood\system32\dllcache\cfgwiz.exe

+ 2010-03-10 00:22 . 2004-08-04 12:00 218112 c:\windows\LastGood\system32\dllcache\c_g18030.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 369664 c:\windows\LastGood\system32\dllcache\asp51.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 331264 c:\windows\LastGood\system32\dllcache\aqueue.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 108544 c:\windows\LastGood\system32\dllcache\appconf.dll

+ 2010-03-10 00:20 . 2004-08-04 12:00 290816 c:\windows\LastGood\system32\dllcache\adsiis51.dll

+ 2010-03-03 05:16 . 2010-03-03 05:16 796672 c:\windows\Installer\1358952.msi

+ 2010-03-03 05:22 . 2010-03-03 05:22 102400 c:\windows\Installer\{81063354-9060-42B2-A000-1EBE96778AA9}\iTunesIco.exe

+ 2007-07-31 14:37 . 2008-04-14 12:00 2178131 c:\windows\system32\dllcache\shvlres.dll

- 2007-07-31 14:37 . 2004-08-04 12:00 2178131 c:\windows\system32\dllcache\shvlres.dll

+ 2004-08-04 12:00 . 2009-08-04 12:51 2185984 c:\windows\system32\dllcache\ntoskrnl.exe

- 2008-10-15 13:58 . 2009-08-04 12:51 2185984 c:\windows\system32\dllcache\ntoskrnl.exe

- 2008-10-15 13:57 . 2009-08-04 12:02 2062976 c:\windows\system32\dllcache\ntkrnlpa.exe

+ 2004-08-03 22:59 . 2009-08-04 12:02 2062976 c:\windows\system32\dllcache\ntkrnlpa.exe

+ 2010-03-10 00:31 . 2004-08-04 05:56 1737856 c:\windows\system32\dllcache\mtxparhd.dll

+ 2010-03-10 00:31 . 2004-08-04 03:41 1309184 c:\windows\system32\dllcache\mtlstrm.sys

- 2007-07-31 14:35 . 2004-08-04 12:00 1175635 c:\windows\system32\dllcache\hrtzres.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 1175635 c:\windows\system32\dllcache\hrtzres.dll

+ 2010-03-10 00:26 . 2001-08-17 19:56 1733120 c:\windows\system32\dllcache\g400d.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 1039955 c:\windows\system32\dllcache\cmnresm.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 1039955 c:\windows\system32\dllcache\cmnresm.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 1677824 c:\windows\system32\dllcache\chsbrkr.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 1677824 c:\windows\system32\dllcache\chsbrkr.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 1817687 c:\windows\system32\dllcache\bckgres.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 1817687 c:\windows\system32\dllcache\bckgres.dll

+ 2010-03-10 00:21 . 2004-08-04 05:56 1888992 c:\windows\system32\dllcache\ati3duag.dll

+ 2010-03-10 00:21 . 2004-08-04 12:00 2134528 c:\windows\LastGood\system32\dllcache\smtpsnap.dll

+ 2010-03-10 00:37 . 2004-08-04 12:00 2178131 c:\windows\LastGood\system32\dllcache\shvlres.dll

+ 2010-03-10 00:32 . 2009-08-04 12:02 2020864 c:\windows\LastGood\system32\dllcache\ntkrpamp.exe

+ 2010-03-10 00:20 . 2009-08-04 12:49 2142720 c:\windows\LastGood\system32\dllcache\ntkrnlmp.exe

+ 2010-03-10 00:27 . 2004-08-04 12:00 1175635 c:\windows\LastGood\system32\dllcache\hrtzres.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 1039955 c:\windows\LastGood\system32\dllcache\cmnresm.dll

+ 2010-03-10 00:23 . 2004-08-04 12:00 1677824 c:\windows\LastGood\system32\dllcache\chsbrkr.dll

+ 2010-03-10 00:22 . 2004-08-04 12:00 1817687 c:\windows\LastGood\system32\dllcache\bckgres.dll

+ 2010-03-04 14:26 . 2010-03-04 14:26 2145280 c:\windows\Installer\708cbf4.msi

+ 2010-03-03 05:22 . 2010-03-03 05:22 4449280 c:\windows\Installer\135937c.msi

+ 2010-03-03 05:19 . 2010-03-03 05:19 9473024 c:\windows\Installer\1358be2.msi

- 2007-07-31 14:36 . 2004-08-04 12:00 10129408 c:\windows\system32\dllcache\hwxkor.dll

+ 2007-07-31 14:36 . 2008-04-14 12:00 10129408 c:\windows\system32\dllcache\hwxkor.dll

+ 2007-07-31 14:35 . 2008-04-14 12:00 10096640 c:\windows\system32\dllcache\hwxcht.dll

- 2007-07-31 14:35 . 2004-08-04 12:00 10096640 c:\windows\system32\dllcache\hwxcht.dll

+ 2010-03-10 00:28 . 2004-08-04 12:00 10129408 c:\windows\LastGood\system32\dllcache\hwxkor.dll

+ 2010-03-10 00:27 . 2004-08-04 12:00 13463552 c:\windows\LastGood\system32\dllcache\hwxjpn.dll

+ 2010-03-10 00:27 . 2004-08-04 12:00 10096640 c:\windows\LastGood\system32\dllcache\hwxcht.dll

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GoToMeeting"="c:\program files\Citrix\GoToMeeting\320\g2mstart.exe" [2008-09-05 31552]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-17 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]

"nwiz"="nwiz.exe" [2007-04-28 1626112]

"NVHotkey"="nvHotkey.dll" [2007-04-28 67584]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]

"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]

"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-25 159744]

"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2007-01-31 176128]

"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]

"Document Manager"="c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2007-01-30 102400]

"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2007-02-01 65536]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-17 30192]

"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]

"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]

"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-01-22 212992]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2006-7-12 25214]

Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]

Power Ge'ez 2005.lnk - c:\program files\Concepts Data Systems\Power Ge'ez 2005\pg2005.exe [2010-1-26 454656]

TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-10-24 278528]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\MSN Messenger\\livecall.exe"=

"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=

"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 cdfdrv;Cdfdrv;c:\windows\system32\drivers\cdfdrv.sys [10/09/2006 11:27 AM 21744]

R2 ctxpidmn;ctxpidmn;c:\windows\system32\drivers\ctxpidmn.sys [02/09/2007 6:51 PM 22952]

R2 CtxSbx;CtxSbx;c:\windows\system32\drivers\CtxSbx.sys [02/09/2007 7:23 PM 161320]

R2 iPCAgent;iPCAgent;c:\program files\iPass\iPassConnect CGNET Travel Access\iPCAgent.exe [07/12/2006 1:19 PM 90112]

R2 RadeSvc;Citrix Streaming Service;c:\program files\Citrix\Streaming Client\RadeSvc.exe [02/09/2007 6:55 PM 241664]

R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [08/04/2004 7:00 AM 5120]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [01/12/2010 9:55 PM 102448]

S0 ktmsixpn;ktmsixpn;c:\windows\system32\drivers\pakc.sys --> c:\windows\system32\drivers\pakc.sys [?]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [02/11/2010 3:55 AM 135664]

S3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/02/2006 11:32 AM 97536]

S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\googledesktop.exe [10/08/2008 3:47 PM 30192]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - KLMD21

*Deregistered* - klmd21

.

Contents of the 'Scheduled Tasks' folder

2010-03-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-11 08:55]

2010-03-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-11 08:55]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = hxxp://www.msh.org/

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

LSP: c:\windows\system32\biolsp.dll

Trusted Zone: msh.org\ctt

DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} - hxxp://eroom.msh.org/eRoomSetup/client.cab

FF - ProfilePath - c:\documents and settings\aspeed\Application Data\Mozilla\Firefox\Profiles\6iwleti0.default\

FF - prefs.js: browser.startup.homepage - www.google.com/ig

FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll

FF - plugin: c:\documents and settings\aspeed\Application Data\Mozilla\Firefox\Profiles\6iwleti0.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll

FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll

FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npeRoom7.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-03-09 19:54

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\vsdatant]

"ImagePath"="a"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1208)

c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(1264)

c:\windows\system32\wvauth.dll

c:\windows\system32\biolsp.dll

c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(3580)

c:\windows\system32\WININET.dll

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

Completion time: 2010-03-09 19:56:37

ComboFix-quarantined-files.txt 2010-03-10 00:56

ComboFix2.txt 2010-03-03 22:57

ComboFix3.txt 2010-03-02 23:56

ComboFix4.txt 2010-02-26 16:03

ComboFix5.txt 2010-03-10 00:47

Pre-Run: 69,433,974,784 bytes free

Post-Run: 69,383,135,232 bytes free

- - End Of File - - 6DB175FCCD1EE2B3ECC4799B2166FEC4

Link to post
Share on other sites

Hello again,

Unfortunately that didn't do the trick either. We can continue in the command line (Recovery Console), but I prefer the following method. However that will require you download a large file and burn it to a CD. Please let me know if you are not able to do this. Otherwise follow the steps below.

OK this file is big Print these instruction out so that you know what you are doing

Two programs to download

First

ISOBurner this will allow you to burn OTLPE ISO to a cd and make it bootable. Just install the program, from there on in it is fairly automatic. Instructions

Second

  • Download OTLPE.iso and burn to a CD using ISO Burner. NOTE: This file is 292Mb in size so it may take some time to download.
  • When downloaded double click and this will then open ISOBurner to burn the file to CD
  • Reboot your system using the boot CD you just created.
    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to Use Safelist

    [*]Press Run Scan to start the scan.

    [*]When finished, the file will be saved in drive C:\OTL.txt

    [*]Copy this file to your USB drive if you do not have internet connection on this system

    [*]Please post the contents of the OTL.txt file in your reply.

Link to post
Share on other sites

And OTL log below.

--------------------------------------------------------------------------------------------------------------------------------------------------------------------------

OTL logfile created on: 3/11/2010 6:41:13 PM - Run

OTLPE by OldTimer - Version 3.1.35.0 Folder = X:\Programs\OTLPE

Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) - Type = SYSTEM

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 92.00% Memory free

3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 111.79 Gb Total Space | 65.08 Gb Free Space | 58.22% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Drive X: | 276.79 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REATOGO

Current User Name: SYSTEM

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

Using ControlSet: ControlSet002

========== Win32 Services (SafeList) ==========

SRV - [2009/12/17 08:51:27 | 000,030,192 | ---- | M] (Google) [On_Demand] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-110309-193829)

SRV - [2008/04/16 09:00:06 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)

SRV - [2008/04/16 09:00:06 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)

SRV - [2008/04/16 09:00:04 | 002,569,600 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec AntiVirus\Smc.exe -- (SmcService)

SRV - [2008/04/16 09:00:04 | 000,234,888 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Symantec AntiVirus\SNAC.EXE -- (SNAC)

SRV - [2008/04/16 09:00:02 | 002,189,240 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)

SRV - [2007/08/11 19:05:27 | 003,093,872 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)

SRV - [2007/02/21 10:28:36 | 000,643,072 | ---- | M] (Intel Corporation) [Auto] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®

SRV - [2007/02/21 10:19:40 | 000,294,912 | ---- | M] (Intel® Corporation) [Auto] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel®

SRV - [2007/02/21 10:16:48 | 000,983,040 | ---- | M] (Intel Corporation ) [Auto] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®

SRV - [2007/02/21 10:10:00 | 000,327,680 | ---- | M] (Intel Corporation) [Auto] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®

SRV - [2007/02/09 18:55:54 | 000,241,664 | ---- | M] (Citrix Systems, Inc.) [Auto] -- C:\Program Files\Citrix\Streaming Client\RadeSvc.exe -- (RadeSvc)

SRV - [2007/02/01 08:21:22 | 001,466,368 | ---- | M] () [Auto] -- C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe -- (tcsd_win32.exe)

SRV - [2007/01/29 20:59:58 | 000,487,424 | ---- | M] (Wave Systems Corp.) [On_Demand] -- C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe -- (SecureStorageService)

SRV - [2007/01/19 11:54:14 | 000,097,136 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc)

SRV - [2006/10/09 11:28:22 | 000,180,224 | ---- | M] (Citrix Systems, Inc.) [Auto] -- C:\Program Files\Common Files\Citrix\System32\CdfSvc.exe -- (CdfSvc)

SRV - [2006/08/03 18:50:46 | 000,380,928 | ---- | M] (Dell Inc.) [Auto] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)

SRV - [2006/01/20 10:08:24 | 001,089,536 | ---- | M] (iPass) [On_Demand] -- C:\Program Files\iPass\iPassConnect CGNET Travel Access\iPassConnectEngine.exe -- (iPassConnectEngine)

SRV - [2006/01/19 18:06:22 | 000,090,112 | ---- | M] (iPass, Inc.) [Auto] -- C:\Program Files\iPass\iPassConnect CGNET Travel Access\iPCAgent.exe -- (iPCAgent)

SRV - [2005/03/03 12:19:48 | 000,451,536 | ---- | M] (RealVNC Ltd.) [Auto] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)

========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand] -- -- (WDICA)

DRV - File not found [Kernel | On_Demand] -- -- (UIUSys)

DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)

DRV - File not found [Kernel | System] -- -- (PCIDump)

DRV - File not found [Kernel | Auto] -- -- (MCSTRM)

DRV - File not found [Kernel | System] -- -- (lbrtfdc)

DRV - File not found [Kernel | Boot] -- -- (ktmsixpn)

DRV - File not found [Kernel | System] -- -- (Changer)

DRV - File not found [Kernel | On_Demand] -- -- (catchme)

DRV - [2010/03/10 22:53:22 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)

DRV - [2010/02/16 04:00:00 | 001,324,720 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100310.037\NAVEX15.SYS -- (NAVEX15)

DRV - [2010/02/16 04:00:00 | 000,084,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100310.037\NAVENG.SYS -- (NAVENG)

DRV - [2010/01/18 18:25:46 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)

DRV - [2009/08/27 03:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)

DRV - [2008/10/08 10:42:34 | 000,136,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)

DRV - [2008/04/16 09:00:08 | 000,317,616 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)

DRV - [2008/04/16 09:00:08 | 000,279,088 | ---- | M] (Symantec Corporation) [File_System | System] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)

DRV - [2008/04/16 09:00:08 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)

DRV - [2008/04/16 09:00:00 | 000,191,544 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)

DRV - [2008/04/16 09:00:00 | 000,027,576 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)

DRV - [2008/04/16 08:59:58 | 000,418,864 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)

DRV - [2007/06/26 10:45:29 | 000,021,275 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\iPassP.sys -- (iPassP) iPass Protocol (IEEE 802.1x)

DRV - [2007/05/16 17:14:58 | 005,707,744 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)

DRV - [2007/04/28 18:05:00 | 006,727,136 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)

DRV - [2007/04/23 15:39:00 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tosrfbd.sys -- (tosrfbd)

DRV - [2007/04/10 19:29:42 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tosrfusb.sys -- (Tosrfusb)

DRV - [2007/03/21 07:58:56 | 000,304,920 | ---- | M] (Intel Corporation) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\iaStor.sys -- (iaStor)

DRV - [2007/03/16 17:10:46 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\bcmwl5.sys -- (BCM43XX)

DRV - [2007/02/25 05:05:24 | 002,203,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Intel®

DRV - [2007/02/23 14:47:34 | 000,056,576 | ---- | M] (O2Micro) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\oz776.sys -- (guardian2)

DRV - [2007/02/21 10:16:12 | 000,012,416 | ---- | M] (Intel Corporation) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)

DRV - [2007/02/19 13:27:34 | 001,228,296 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)

DRV - [2007/02/17 20:00:42 | 000,132,608 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)

DRV - [2007/02/09 19:23:58 | 000,161,320 | ---- | M] (Citrix Systems, Inc.) [File_System | Auto] -- C:\WINDOWS\system32\drivers\CtxSbx.sys -- (CtxSbx)

DRV - [2007/02/09 18:51:46 | 000,022,952 | ---- | M] (Citrix Systems, Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\ctxpidmn.sys -- (ctxpidmn)

DRV - [2007/01/16 09:22:00 | 000,031,744 | ---- | M] (CSR, plc) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\csrbcxp.sys -- (CSRBC)

DRV - [2006/11/20 16:55:16 | 000,036,480 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tosrfbnp.sys -- (tosrfbnp)

DRV - [2006/11/13 11:16:54 | 000,038,288 | ---- | M] (UPEK Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tcusb.sys -- (TcUsb)

DRV - [2006/11/02 17:47:36 | 000,989,696 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)

DRV - [2006/11/02 17:47:00 | 000,209,152 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)

DRV - [2006/11/02 17:46:56 | 000,730,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)

DRV - [2006/11/02 11:32:32 | 000,097,536 | ---- | M] (Knowles Acoustics) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\dxec01.sys -- (DXEC01)

DRV - [2006/10/10 18:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tosporte.sys -- (tosporte)

DRV - [2006/10/09 11:27:52 | 000,021,744 | ---- | M] (Citrix Systems, Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\cdfdrv.sys -- (cdfdrv)

DRV - [2006/10/05 15:07:46 | 000,073,600 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Tosrfhid.sys -- (Tosrfhid)

DRV - [2006/08/28 14:00:44 | 000,019,968 | ---- | M] (Dell Inc) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\PBADRV.sys -- (PBADRV)

DRV - [2006/06/22 16:40:28 | 000,018,432 | ---- | M] (Dell Inc.) [Kernel | System] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)

DRV - [2006/06/19 12:04:10 | 000,156,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)

DRV - [2006/04/04 16:20:00 | 000,009,344 | ---- | M] (Hewlett Packard) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\hpfxbulk.sys -- (HPFXBULK)

DRV - [2005/08/12 17:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)

DRV - [2005/08/01 15:45:00 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System] -- C:\WINDOWS\system32\drivers\tosrfcom.sys -- (Tosrfcom)

DRV - [2005/07/11 17:58:00 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Toshidpt.sys -- (toshidpt)

DRV - [2005/05/13 17:27:56 | 000,028,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbccid.sys -- (USBCCID)

DRV - [2005/02/23 13:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)

DRV - [2005/01/07 16:07:18 | 000,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)

DRV - [2005/01/06 12:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\tosrfnds.sys -- (tosrfnds)

DRV - [2004/08/03 22:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)

DRV - [2004/08/03 22:07:44 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\amdagp.sys -- (amdagp)

DRV - [2004/08/03 22:07:44 | 000,041,088 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\SISAGP.SYS -- (sisagp)

DRV - [2001/08/17 13:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sparrow.sys -- (Sparrow)

DRV - [2001/08/17 13:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sym_u3.sys -- (sym_u3)

DRV - [2001/08/17 13:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sym_hi.sys -- (sym_hi)

DRV - [2001/08/17 13:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\symc8xx.sys -- (symc8xx)

DRV - [2001/08/17 13:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\symc810.sys -- (symc810)

DRV - [2001/08/17 12:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\ultra.sys -- (ultra)

DRV - [2001/08/17 12:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\ql12160.sys -- (ql12160)

DRV - [2001/08/17 12:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\ql1080.sys -- (ql1080)

DRV - [2001/08/17 12:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\ql1280.sys -- (ql1280)

DRV - [2001/08/17 12:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\dac2w2k.sys -- (dac2w2k)

DRV - [2001/08/17 12:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\mraid35x.sys -- (mraid35x)

DRV - [2001/08/17 12:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\asc.sys -- (asc)

DRV - [2001/08/17 12:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\asc3550.sys -- (asc3550)

DRV - [2001/08/17 12:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\aliide.sys -- (AliIde)

DRV - [2001/08/17 12:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\cmdide.sys -- (CmdIde)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msh.org/

IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKU\aspeed_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\aspeed_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\Ctx_StreamingSvc_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msh.org/

IE - HKU\Ctx_StreamingSvc_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2010/03/03 00:19:17 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2010/03/03 09:40:45 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/04 09:26:54 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/04 09:26:54 | 000,000,000 | ---D | M]

[2010/03/10 23:09:21 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

[2007/06/21 18:38:54 | 000,079,432 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll

[2007/06/21 18:38:56 | 000,071,240 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll

[2007/06/21 18:39:18 | 000,034,376 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\logging.dll

[2008/01/07 19:45:16 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll

[2007/05/15 20:35:30 | 000,407,360 | ---- | M] (Documentum, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npeRoom7.dll

[2007/06/21 18:39:34 | 000,325,200 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll

[2007/06/21 18:40:02 | 000,030,280 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll

O1 HOSTS File: ([2010/02/20 18:09:13 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O3 - HKU\aspeed_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\aspeed_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O3 - HKU\Ctx_StreamingSvc_ON_C\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\apoint.exe (Alps Electric Co., Ltd.)

O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)

O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)

O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)

O4 - HKLM..\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe (Wave Systems Corp.)

O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)

O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)

O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)

O4 - HKLM..\Run: [intelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)

O4 - HKLM..\Run: [intelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)

O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)

O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()

O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)

O4 - HKLM..\Run: [secureUpgrade] C:\Program Files\Wave Systems Corp\secureupgrade.exe (Wave Systems Corp.)

O4 - HKLM..\Run: [sigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)

O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()

O4 - HKU\aspeed_ON_C..\Run: [GoToMeeting] C:\Program Files\Citrix\GoToMeeting\320\g2mstart.exe (Citrix Online, a division of Citrix Systems, Inc.)

O4 - HKU\aspeed_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\Administrator_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\arogosch_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\aspeed_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\aspeed_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\aspeed_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\aspeed_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\Ctx_StreamingSvc_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\Ctx_StreamingSvc_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\biolsp.dll (Wave Systems Corp.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\biolsp.dll (Wave Systems Corp.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\biolsp.dll (Wave Systems Corp.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\biolsp.dll (Wave Systems Corp.)

O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/...b?1152710934850 (WUWebControl Class)

O16 - DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} http://eroom.msh.org/eRoomSetup/client.cab (ERPageAddin Class)

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu...b?1182874779218 (MUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash...ent/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = us.msh.org

O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp

O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp

O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2006/07/12 07:45:44 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2010/02/18 04:02:13 | 000,000,000 | ---D | M] - C:\Autoruns -- [ NTFS ]

O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/10 22:53:22 | 000,691,696 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys

[2010/03/10 22:53:14 | 000,000,000 | ---D | C] -- C:\Program Files\LSoft Technologies

[2010/03/09 19:43:53 | 000,116,224 | ---- | C] (Xerox) -- C:\WINDOWS\System32\dllcache\xrxwiadr.dll

[2010/03/09 19:43:50 | 000,023,040 | ---- | C] (Xerox Corporation) -- C:\WINDOWS\System32\dllcache\xrxwbtmp.dll

[2010/03/09 19:43:41 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xrxflnch.exe

[2010/03/09 19:43:25 | 000,099,865 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\xlog.exe

[2010/03/09 19:43:22 | 000,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys

[2010/03/09 19:43:21 | 000,019,455 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wvchntxx.sys

[2010/03/09 19:43:19 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wstcodec.sys

[2010/03/09 19:43:18 | 000,012,063 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wsiintxx.sys

[2010/03/09 19:43:17 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshirda.dll

[2010/03/09 19:43:02 | 000,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys

[2010/03/09 19:42:59 | 000,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys

[2010/03/09 19:42:51 | 000,771,581 | ---- | C] (Rockwell) -- C:\WINDOWS\System32\dllcache\winacisa.sys

[2010/03/09 19:42:47 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiamsmud.dll

[2010/03/09 19:42:44 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiafbdrv.dll

[2010/03/09 19:42:39 | 000,701,386 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\wdhaalba.sys

[2010/03/09 19:42:38 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wceusbsh.sys

[2010/03/09 19:42:38 | 000,023,615 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wch7xxnt.sys

[2010/03/09 19:42:35 | 000,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys

[2010/03/09 19:42:33 | 000,033,599 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\watv04nt.sys

[2010/03/09 19:42:33 | 000,025,471 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\watv10nt.sys

[2010/03/09 19:42:33 | 000,022,271 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\watv06nt.sys

[2010/03/09 19:42:32 | 000,019,551 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\watv02nt.sys

[2010/03/09 19:42:31 | 000,029,311 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\watv01nt.sys

[2010/03/09 19:42:30 | 000,011,935 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wadv11nt.sys

[2010/03/09 19:42:29 | 000,011,871 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wadv09nt.sys

[2010/03/09 19:42:29 | 000,011,807 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wadv07nt.sys

[2010/03/09 19:42:29 | 000,011,295 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wadv08nt.sys

[2010/03/09 19:42:28 | 000,012,127 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wadv02nt.sys

[2010/03/09 19:42:28 | 000,011,775 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wadv05nt.sys

[2010/03/09 19:42:27 | 000,012,415 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\wadv01nt.sys

[2010/03/09 19:42:26 | 000,013,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wacompen.sys

[2010/03/09 19:42:23 | 000,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys

[2010/03/09 19:42:20 | 000,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys

[2010/03/09 19:42:17 | 000,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys

[2010/03/09 19:42:12 | 000,064,605 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vvoice.sys

[2010/03/09 19:42:09 | 000,397,502 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vpctcom.sys

[2010/03/09 19:42:05 | 000,604,253 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\vmodem.sys

[2010/03/09 19:42:02 | 000,249,402 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\vinwm.sys

[2010/03/09 19:42:01 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vidcap.ax

[2010/03/09 19:41:58 | 000,024,576 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\viairda.sys

[2010/03/09 19:41:57 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vfwwdm32.dll

[2010/03/09 19:41:56 | 000,011,325 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\vchnt5.dll

[2010/03/09 19:41:52 | 000,687,999 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usrwdxjs.sys

[2010/03/09 19:41:49 | 000,765,884 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usrti.sys

[2010/03/09 19:41:46 | 000,113,762 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usrpda.sys

[2010/03/09 19:41:43 | 000,007,556 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usroslba.sys

[2010/03/09 19:41:40 | 000,224,802 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usr1807a.sys

[2010/03/09 19:41:37 | 000,794,399 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806v.sys

[2010/03/09 19:41:34 | 000,793,598 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806.sys

[2010/03/09 19:41:31 | 000,794,654 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1801.sys

[2010/03/09 19:41:30 | 000,078,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbvideo.sys

[2010/03/09 19:41:30 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbser.sys

[2010/03/09 19:41:29 | 000,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbohci.sys

[2010/03/09 19:41:27 | 000,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys

[2010/03/09 19:41:27 | 000,012,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usb8023x.sys

[2010/03/09 19:41:21 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxud32.dll

[2010/03/09 19:41:18 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu40.dll

[2010/03/09 19:41:15 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu22.dll

[2010/03/09 19:41:13 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu12.dll

[2010/03/09 19:41:10 | 000,050,688 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\umaxscan.dll

[2010/03/09 19:41:07 | 000,022,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxpcls.sys

[2010/03/09 19:41:04 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxp60.dll

[2010/03/09 19:41:01 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxcam.dll

[2010/03/09 19:40:58 | 000,211,968 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um54scan.dll

[2010/03/09 19:40:56 | 000,216,064 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um34scan.dll

[2010/03/09 19:40:51 | 000,011,520 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\twotrack.sys

[2010/03/09 19:40:46 | 000,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys

[2010/03/09 19:40:43 | 000,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll

[2010/03/09 19:40:41 | 000,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys

[2010/03/09 19:40:38 | 000,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll

[2010/03/09 19:40:35 | 000,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys

[2010/03/09 19:40:32 | 000,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll

[2010/03/09 19:40:29 | 000,034,375 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\tpro4.sys

[2010/03/09 19:40:26 | 000,042,496 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4res.dll

[2010/03/09 19:40:25 | 000,082,432 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4mon.exe

[2010/03/09 19:40:23 | 000,031,744 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4.dll

[2010/03/09 19:40:19 | 000,230,912 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tosdvd03.sys

[2010/03/09 19:40:16 | 000,241,664 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tosdvd02.sys

[2010/03/09 19:40:13 | 000,028,232 | ---- | C] (TOSHIBA Corporation) -- C:\WINDOWS\System32\dllcache\tos4mo.sys

[2010/03/09 19:40:09 | 000,123,995 | ---- | C] (Tiger Jet Network) -- C:\WINDOWS\System32\dllcache\tjisdn.sys

[2010/03/09 19:40:05 | 000,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys

[2010/03/09 19:40:02 | 000,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll

[2010/03/09 19:40:01 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys

[2010/03/09 19:39:57 | 000,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys

[2010/03/09 19:39:55 | 000,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys

[2010/03/09 19:39:51 | 000,030,464 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tbatm155.sys

[2010/03/09 19:39:47 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tandqic.sys

[2010/03/09 19:39:44 | 000,036,640 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\t2r4mini.sys

[2010/03/09 19:39:42 | 000,172,768 | ---- | C] (Number Nine Visual Technology) -- C:\WINDOWS\System32\dllcache\t2r4disp.dll

[2010/03/09 19:39:37 | 000,094,293 | ---- | C] (Perle Systems Ltd. ) -- C:\WINDOWS\System32\dllcache\sxports.dll

[2010/03/09 19:39:34 | 000,103,936 | ---- | C] (Perle Systems Ltd. ) -- C:\WINDOWS\System32\dllcache\sx.sys

[2010/03/09 19:39:31 | 000,003,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swusbflt.sys

[2010/03/09 19:39:29 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpidflt.dll

[2010/03/09 19:39:26 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpdflt2.dll

[2010/03/09 19:39:24 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_wheel.dll

[2010/03/09 19:39:21 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_effct.dll

[2010/03/09 19:39:20 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\streamip.sys

[2010/03/09 19:39:17 | 000,155,648 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnprop.dll

[2010/03/09 19:39:14 | 000,053,248 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlncoin.dll

[2010/03/09 19:39:12 | 000,285,760 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnata.sys

[2010/03/09 19:39:09 | 000,016,896 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys

[2010/03/09 19:39:04 | 000,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys

[2010/03/09 19:39:01 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusd.dll

[2010/03/09 19:38:56 | 000,024,660 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spxupchk.dll

[2010/03/09 19:38:52 | 000,061,824 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\speed.sys

[2010/03/09 19:38:49 | 000,106,584 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spdports.dll

[2010/03/09 19:38:46 | 000,007,552 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypvu1.sys

[2010/03/09 19:38:43 | 000,037,040 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypi.sys

[2010/03/09 19:38:41 | 000,114,688 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypi.dll

[2010/03/09 19:38:38 | 000,020,752 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonync.sys

[2010/03/09 19:38:35 | 000,009,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sonymc.sys

[2010/03/09 19:38:35 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sonyait.sys

[2010/03/09 19:38:32 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snyaitmc.sys

[2010/03/09 19:38:24 | 000,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys

[2010/03/09 19:38:21 | 000,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll

[2010/03/09 19:38:18 | 000,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys

[2010/03/09 19:38:15 | 000,035,913 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys

[2010/03/09 19:38:13 | 000,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys

[2010/03/09 19:38:10 | 000,016,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbbatt.sys

[2010/03/09 19:38:10 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbclass.sys

[2010/03/09 19:38:10 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbhc.sys

[2010/03/09 19:38:09 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbali.sys

[2010/03/09 19:38:06 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb3w.dll

[2010/03/09 19:38:04 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb0w.dll

[2010/03/09 19:38:01 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma0w.dll

[2010/03/09 19:37:58 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm91w.dll

[2010/03/09 19:37:56 | 000,013,240 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slwdmsup.sys

[2010/03/09 19:37:55 | 000,095,424 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slnthal.sys

[2010/03/09 19:37:55 | 000,073,796 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slserv.exe

[2010/03/09 19:37:55 | 000,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slrundll.exe

[2010/03/09 19:37:54 | 000,404,990 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slntamr.sys

[2010/03/09 19:37:54 | 000,129,535 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slnt7554.sys

[2010/03/09 19:37:54 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\slip.sys

[2010/03/09 19:37:53 | 000,286,792 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slextspk.dll

[2010/03/09 19:37:53 | 000,188,508 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slgen.dll

[2010/03/09 19:37:53 | 000,073,832 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\slcoinst.dll

[2010/03/09 19:37:52 | 000,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys

[2010/03/09 19:37:49 | 000,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys

[2010/03/09 19:37:47 | 000,094,698 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys

[2010/03/09 19:37:44 | 000,157,696 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv256.dll

[2010/03/09 19:37:42 | 000,050,432 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv.sys

[2010/03/09 19:37:41 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys

[2010/03/09 19:37:38 | 000,238,592 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrv.dll

[2010/03/09 19:37:36 | 000,104,064 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrp.sys

[2010/03/09 19:37:33 | 000,150,144 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306v.dll

[2010/03/09 19:37:31 | 000,068,608 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306p.sys

[2010/03/09 19:37:28 | 000,252,032 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300iv.dll

[2010/03/09 19:37:26 | 000,101,760 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300ip.sys

[2010/03/09 19:37:25 | 000,003,901 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\siint5.dll

[2010/03/09 19:37:18 | 000,161,568 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmusb.sys

[2010/03/09 19:37:16 | 000,018,400 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmld.sys

[2010/03/09 19:37:13 | 000,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys

[2010/03/09 19:37:11 | 000,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll

[2010/03/09 19:37:08 | 000,036,480 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sfmanm.sys

[2010/03/09 19:37:04 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\serscan.sys

[2010/03/09 19:37:01 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sermouse.sys

[2010/03/09 19:36:54 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seaddsmc.sys

[2010/03/09 19:36:52 | 000,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiscan.sys

[2010/03/09 19:36:49 | 000,011,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiprnt.sys

[2010/03/09 19:36:46 | 000,017,280 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys

[2010/03/09 19:36:43 | 000,016,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scmstcs.sys

[2010/03/09 19:36:40 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys

[2010/03/09 19:36:38 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys

[2010/03/09 19:36:37 | 000,043,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sbp2port.sys

[2010/03/09 19:36:34 | 000,495,616 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sblfx.dll

[2010/03/09 19:36:30 | 000,075,392 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmxm.sys

[2010/03/09 19:36:28 | 000,245,632 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmx.dll

[2010/03/09 19:36:25 | 000,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys

[2010/03/09 19:36:23 | 000,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll

[2010/03/09 19:36:20 | 000,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys

[2010/03/09 19:36:18 | 000,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll

[2010/03/09 19:36:15 | 000,210,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mvirge.dll

[2010/03/09 19:36:13 | 000,062,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mtrio.dll

[2010/03/09 19:36:11 | 000,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys

[2010/03/09 19:36:08 | 000,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll

[2010/03/09 19:36:06 | 000,166,720 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3m.sys

[2010/03/09 19:36:03 | 000,166,912 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3gnbm.sys

[2010/03/09 19:36:03 | 000,065,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\s3legacy.sys

[2010/03/09 19:36:02 | 000,397,056 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3gnb.dll

[2010/03/09 19:36:00 | 000,082,432 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia450.dll

[2010/03/09 19:35:57 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia430.dll

[2010/03/09 19:35:54 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw450ext.dll

[2010/03/09 19:35:52 | 000,024,576 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw430ext.dll

[2010/03/09 19:35:50 | 000,020,992 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8139.sys

[2010/03/09 19:35:47 | 000,019,017 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8029.sys

[2010/03/09 19:35:45 | 000,030,720 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\rthwcls.sys

[2010/03/09 19:35:41 | 000,009,216 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\rsmgrstr.dll

[2010/03/09 19:35:38 | 000,003,840 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\rpfun.sys

[2010/03/09 19:35:36 | 000,079,104 | ---- | C] (Comtrol Corporation) -- C:\WINDOWS\System32\dllcache\rocket.sys

[2010/03/09 19:35:36 | 000,030,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rndismpx.sys

[2010/03/09 19:35:33 | 000,037,563 | ---- | C] (RadioLAN) -- C:\WINDOWS\System32\dllcache\rlnet5.sys

[2010/03/09 19:35:30 | 000,086,097 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\reslog32.dll

[2010/03/09 19:35:27 | 000,013,776 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\recagent.sys

[2010/03/09 19:35:19 | 000,019,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasirda.sys

[2010/03/09 19:35:14 | 000,714,762 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdmkxx.sys

[2010/03/09 19:35:12 | 000,899,146 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdkxga.sys

[2010/03/09 19:35:09 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qvusd.dll

[2010/03/09 19:35:07 | 000,003,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qv2kux.sys

[2010/03/09 19:35:03 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qic157.sys

[2010/03/09 19:34:58 | 000,130,942 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlv.sys

[2010/03/09 19:34:56 | 000,112,574 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlp.sys

[2010/03/09 19:34:53 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ptpusd.dll

[2010/03/09 19:34:53 | 000,128,286 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserli.sys

[2010/03/09 19:34:50 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ptpusb.dll

[2010/03/09 19:34:47 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\psisload.dll

[2010/03/09 19:34:44 | 000,016,128 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\pscr.sys

[2010/03/09 19:34:41 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ppa3.sys

[2010/03/09 19:34:39 | 000,017,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ppa.sys

[2010/03/09 19:34:37 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\powerfil.sys

[2010/03/09 19:34:33 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pnrmc.sys

[2010/03/09 19:34:31 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\plugin.ocx

[2010/03/09 19:34:24 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phvfwext.dll

[2010/03/09 19:34:21 | 000,019,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philtune.sys

[2010/03/09 19:34:19 | 000,092,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phildec.sys

[2010/03/09 19:34:16 | 000,173,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam2.sys

[2010/03/09 19:34:14 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam1.sys

[2010/03/09 19:34:11 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\philcam1.dll

[2010/03/09 19:34:09 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phdsext.ax

[2010/03/09 19:34:08 | 000,259,328 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm3dd.dll

[2010/03/09 19:34:08 | 000,211,712 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm2dll.dll

[2010/03/09 19:34:08 | 000,028,032 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm3.sys

[2010/03/09 19:34:07 | 000,027,904 | ---- | C] (Microsoft Corp., 3Dlabs Inc. Ltd.) -- C:\WINDOWS\System32\dllcache\perm2.sys

[2010/03/09 19:34:06 | 000,169,984 | ---- | C] (Cisco Systems) -- C:\WINDOWS\System32\dllcache\pcx500.sys

[2010/03/09 19:34:03 | 000,086,016 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\pctspk.exe

[2010/03/09 19:34:01 | 000,029,769 | ---- | C] (AMD Inc.) -- C:\WINDOWS\System32\dllcache\pcntn5m.sys

[2010/03/09 19:33:58 | 000,030,282 | ---- | C] (AMD Inc.) -- C:\WINDOWS\System32\dllcache\pcntn5hl.sys

[2010/03/09 19:33:56 | 000,026,153 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pcmlm56.sys

[2010/03/09 19:33:55 | 000,029,502 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\pca200e.sys

[2010/03/09 19:33:52 | 000,030,495 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pc100nds.sys

[2010/03/09 19:33:42 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovui2rc.dll

[2010/03/09 19:33:40 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovui2.dll

[2010/03/09 19:33:38 | 000,025,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovsound2.sys

[2010/03/09 19:33:35 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovcoms.exe

[2010/03/09 19:33:33 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovcomc.dll

[2010/03/09 19:33:30 | 000,351,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovcodek2.sys

[2010/03/09 19:33:28 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovcodec2.dll

[2010/03/09 19:33:26 | 000,031,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovce.sys

[2010/03/09 19:33:23 | 000,028,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovcd.sys

[2010/03/09 19:33:21 | 000,048,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovcam2.sys

[2010/03/09 19:33:18 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ovca.sys

[2010/03/09 19:33:16 | 000,054,186 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otcsercb.sys

[2010/03/09 19:33:14 | 000,043,689 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otceth5.sys

[2010/03/09 19:33:11 | 000,027,209 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otc06x5.sys

[2010/03/09 19:33:08 | 000,054,528 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\opl3sax.sys

[2010/03/09 19:32:57 | 000,198,144 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv3.sys

[2010/03/09 19:32:55 | 000,123,776 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\dllcache\nv3.dll

[2010/03/09 19:32:53 | 000,180,360 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\ntmtlfax.sys

[2010/03/09 19:32:48 | 000,051,552 | ---- | C] (Kensington Technology Group) -- C:\WINDOWS\System32\dllcache\ntgrip.sys

[2010/03/09 19:32:44 | 000,009,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntapm.sys

[2010/03/09 19:32:42 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nsmmc.sys

[2010/03/09 19:32:41 | 000,028,672 | ---- | C] (National Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\nscirda.sys

[2010/03/09 19:32:36 | 000,087,040 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm6wdm.sys

[2010/03/09 19:32:33 | 000,126,080 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm5a2wdm.sys

[2010/03/09 19:32:29 | 000,032,840 | ---- | C] (NETGEAR Corporation.) -- C:\WINDOWS\System32\dllcache\ngrpci.sys

[2010/03/09 19:32:28 | 000,132,695 | ---- | C] (802.11b) -- C:\WINDOWS\System32\dllcache\netwlan5.sys

[2010/03/09 19:32:23 | 000,065,278 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\netflx3.sys

[2010/03/09 19:32:19 | 000,039,264 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.sys

Link to post
Share on other sites

Part 2

---------------------------------------------------------------------------------------------------------------------------------------------------------------------

[2010/03/09 19:32:17 | 000,060,480 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.dll

[2010/03/09 19:32:15 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ne2000.sys

[2010/03/09 19:32:14 | 000,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndisip.sys

[2010/03/09 19:32:12 | 000,085,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nabtsfec.sys

[2010/03/09 19:32:09 | 000,091,488 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3disp.dll

[2010/03/09 19:32:07 | 000,027,936 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3d.sys

[2010/03/09 19:32:05 | 000,033,088 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.sys

[2010/03/09 19:32:03 | 000,059,104 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.dll

[2010/03/09 19:32:00 | 000,013,664 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.sys

[2010/03/09 19:31:58 | 000,035,392 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.dll

[2010/03/09 19:31:56 | 000,128,000 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\n100325.sys

[2010/03/09 19:31:54 | 000,052,255 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\dllcache\n1000nt5.sys

[2010/03/09 19:31:51 | 000,075,520 | ---- | C] (Moxa Technologies Co., Ltd.) -- C:\WINDOWS\System32\dllcache\mxport.sys

[2010/03/09 19:31:49 | 000,007,168 | ---- | C] (Moxa Technologies Co., Ltd) -- C:\WINDOWS\System32\dllcache\mxport.dll

[2010/03/09 19:31:47 | 000,019,968 | ---- | C] (Macronix International Co., Ltd. ) -- C:\WINDOWS\System32\dllcache\mxnic.sys

[2010/03/09 19:31:45 | 000,019,968 | ---- | C] (Moxa Technologies Co., Ltd) -- C:\WINDOWS\System32\dllcache\mxicfg.dll

[2010/03/09 19:31:42 | 000,021,888 | ---- | C] (Moxa Technologies Co., Ltd.) -- C:\WINDOWS\System32\dllcache\mxcard.sys

[2010/03/09 19:31:42 | 000,012,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mutohpen.sys

[2010/03/09 19:31:39 | 000,103,296 | ---- | C] (Matrox Graphics Inc) -- C:\WINDOWS\System32\dllcache\mtxvideo.sys

[2010/03/09 19:31:38 | 001,737,856 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mtxparhd.dll

[2010/03/09 19:31:38 | 000,452,736 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mtxparhm.sys

[2010/03/09 19:31:36 | 001,309,184 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\mtlstrm.sys

[2010/03/09 19:31:36 | 000,126,686 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\dllcache\mtlmnt5.sys

[2010/03/09 19:31:30 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstee.sys

[2010/03/09 19:31:29 | 000,049,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstape.sys

[2010/03/09 19:31:25 | 000,012,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msriffwv.sys

[2010/03/09 19:31:19 | 000,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msmpu401.sys

[2010/03/09 19:31:18 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msircomm.sys

[2010/03/09 19:31:09 | 000,035,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msgame.sys

[2010/03/09 19:31:06 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfsio.sys

[2010/03/09 19:31:05 | 000,051,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdv.sys

[2010/03/09 19:30:56 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mpe.sys

[2010/03/09 19:30:52 | 000,016,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\modemcsa.sys

[2010/03/09 19:30:47 | 000,006,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\miniqic.sys

[2010/03/09 19:30:43 | 000,320,384 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mgaum.sys

[2010/03/09 19:30:41 | 000,235,648 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\mgaud.dll

[2010/03/09 19:30:39 | 000,026,112 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\memstpci.sys

[2010/03/09 19:30:37 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\memgrp.dll

[2010/03/09 19:30:35 | 000,008,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\memcard.sys

[2010/03/09 19:30:32 | 000,164,586 | ---- | C] (Madge Networks Ltd) -- C:\WINDOWS\System32\dllcache\mdgndis5.sys

[2010/03/09 19:30:28 | 000,007,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mammoth.sys

[2010/03/09 19:30:25 | 000,048,768 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\maestro.sys

[2010/03/09 19:30:23 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\m3092dc.dll

[2010/03/09 19:30:21 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\m3091dc.dll

[2010/03/09 19:30:19 | 000,022,848 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\dllcache\lwusbhid.sys

[2010/03/09 19:30:18 | 000,020,864 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\dllcache\lwadihid.sys

[2010/03/09 19:30:16 | 000,797,500 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltsmt.sys

[2010/03/09 19:30:14 | 000,802,683 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\ltsm.sys

[2010/03/09 19:30:13 | 000,420,992 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntt.sys

[2010/03/09 19:30:13 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ltotape.sys

[2010/03/09 19:30:10 | 000,606,684 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmnt.sys

[2010/03/09 19:30:10 | 000,576,746 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntl.sys

[2010/03/09 19:30:08 | 000,727,786 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ltck000c.sys

[2010/03/09 19:30:05 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\loop.sys

[2010/03/09 19:30:01 | 000,070,730 | ---- | C] (Linksys Group, Inc.) -- C:\WINDOWS\System32\dllcache\lne100tx.sys

[2010/03/09 19:29:59 | 000,020,573 | ---- | C] (The Linksts Group ) -- C:\WINDOWS\System32\dllcache\lne100.sys

[2010/03/09 19:29:57 | 000,025,065 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\lmndis3.sys

[2010/03/09 19:29:54 | 000,015,744 | ---- | C] (Litronic Industries) -- C:\WINDOWS\System32\dllcache\lit220p.sys

[2010/03/09 19:29:53 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\dllcache\lbrtfdc.sys

[2010/03/09 19:29:51 | 000,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys

[2010/03/09 19:29:49 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksxbar.ax

[2010/03/09 19:29:49 | 000,019,016 | ---- | C] (Kingston Technology Company ) -- C:\WINDOWS\System32\dllcache\ktc111.sys

[2010/03/09 19:29:48 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kswdmcap.ax

[2010/03/09 19:29:48 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kstvtune.ax

[2010/03/09 19:29:45 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kousd.dll

[2010/03/09 19:29:41 | 000,242,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsusd.dll

[2010/03/09 19:29:39 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kdsui.dll

[2010/03/09 19:29:33 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkor.dll

[2010/03/09 19:29:31 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdjpn.dll

[2010/03/09 19:29:23 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd106.dll

[2010/03/09 19:29:21 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd103.dll

[2010/03/09 19:29:20 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101c.dll

[2010/03/09 19:29:18 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101b.dll

[2010/03/09 19:29:13 | 000,026,624 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\dllcache\irstusb.sys

[2010/03/09 19:29:11 | 000,018,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irsir.sys

[2010/03/09 19:29:10 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irmon.dll

[2010/03/09 19:29:08 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irftp.exe

[2010/03/09 19:29:08 | 000,023,552 | ---- | C] (MKNet Corporation) -- C:\WINDOWS\System32\dllcache\irmk7.sys

[2010/03/09 19:29:07 | 000,087,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irda.sys

[2010/03/09 19:29:06 | 000,040,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irbus.sys

[2010/03/09 19:29:05 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipsink.ax

[2010/03/09 19:29:01 | 000,045,632 | ---- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) -- C:\WINDOWS\System32\dllcache\ip5515.sys

[2010/03/09 19:28:59 | 000,090,200 | ---- | C] (Perle Systems Ltd. ) -- C:\WINDOWS\System32\dllcache\io8ports.dll

[2010/03/09 19:28:57 | 000,038,784 | ---- | C] (Perle Systems Ltd. ) -- C:\WINDOWS\System32\dllcache\io8.sys

[2010/03/09 19:28:55 | 000,013,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inport.sys

[2010/03/09 19:28:34 | 000,372,824 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\iconf32.dll

[2010/03/09 19:28:32 | 000,100,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5usb.sys

[2010/03/09 19:28:30 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5ext.dll

[2010/03/09 19:28:28 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam5com.dll

[2010/03/09 19:28:26 | 000,154,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4usb.sys

[2010/03/09 19:28:24 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4ext.dll

[2010/03/09 19:28:22 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam4com.dll

[2010/03/09 19:28:20 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam3ext.dll

[2010/03/09 19:28:18 | 000,141,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icam3.sys

[2010/03/09 19:28:16 | 000,038,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ibmvcap.sys

[2010/03/09 19:28:14 | 000,109,085 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmtrp.sys

[2010/03/09 19:28:12 | 000,100,936 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmtok.sys

[2010/03/09 19:28:10 | 000,009,216 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\ibmsgnet.dll

[2010/03/09 19:28:08 | 000,028,700 | ---- | C] (IBM Corp.) -- C:\WINDOWS\System32\dllcache\ibmexmp.sys

[2010/03/09 19:28:07 | 000,702,845 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\i81xdnt5.dll

[2010/03/09 19:28:07 | 000,161,020 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\dllcache\i81xnt5.sys

[2010/03/09 19:28:04 | 000,058,592 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\i740nt5.sys

[2010/03/09 19:28:03 | 000,353,184 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\i740dnt5.dll

[2010/03/09 19:27:51 | 001,041,536 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\dllcache\hsfdpsp2.sys

[2010/03/09 19:27:50 | 000,685,056 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\dllcache\hsfcxts2.sys

[2010/03/09 19:27:50 | 000,032,285 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\dllcache\hsfcisp2.dll

[2010/03/09 19:27:49 | 000,220,032 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\dllcache\hsfbs2s2.sys

[2010/03/09 19:27:47 | 000,488,383 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_v124.sys

[2010/03/09 19:27:45 | 000,050,751 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_tone.sys

[2010/03/09 19:27:43 | 000,073,279 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_spkp.sys

[2010/03/09 19:27:42 | 000,044,863 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_soar.sys

[2010/03/09 19:27:40 | 000,057,471 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_samp.sys

[2010/03/09 19:27:38 | 000,542,879 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_msft.sys

[2010/03/09 19:27:36 | 000,391,199 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_k56k.sys

[2010/03/09 19:27:34 | 000,009,759 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_inst.dll

[2010/03/09 19:27:32 | 000,115,807 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_fsks.sys

[2010/03/09 19:27:30 | 000,199,711 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_faxx.sys

[2010/03/09 19:27:28 | 000,289,887 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_fall.sys

[2010/03/09 19:27:26 | 000,067,167 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_bsc2.sys

[2010/03/09 19:27:24 | 000,150,239 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hsf_amos.sys

[2010/03/09 19:27:22 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hr1w.dll

[2010/03/09 19:27:20 | 000,005,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpt4qic.sys

[2010/03/09 19:27:18 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpsjmcro.dll

[2010/03/09 19:27:16 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpojwia.dll

[2010/03/09 19:27:14 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgtmcro.dll

[2010/03/09 19:27:13 | 000,068,608 | ---- | C] (Avisioin) -- C:\WINDOWS\System32\dllcache\hpgt53tk.dll

[2010/03/09 19:27:09 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt42tk.dll

[2010/03/09 19:27:06 | 000,126,976 | ---- | C] (Hewlett Packard) -- C:\WINDOWS\System32\dllcache\hpgt34tk.dll

[2010/03/09 19:27:02 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt33tk.dll

[2010/03/09 19:26:58 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpgt21tk.dll

[2010/03/09 19:26:55 | 000,119,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hpdigwia.dll

[2010/03/09 19:26:52 | 000,002,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidswvd.sys

[2010/03/09 19:26:51 | 000,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidir.sys

[2010/03/09 19:26:50 | 000,008,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidgame.sys

[2010/03/09 19:26:49 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidbth.sys

[2010/03/09 19:26:47 | 000,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidbatt.sys

[2010/03/09 19:26:44 | 000,907,456 | ---- | C] (Conexant) -- C:\WINDOWS\System32\dllcache\hcf_msft.sys

[2010/03/09 19:26:42 | 000,028,288 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grserial.sys

[2010/03/09 19:26:41 | 000,082,304 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grclass.sys

[2010/03/09 19:26:39 | 000,017,408 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\gpr400.sys

[2010/03/09 19:26:37 | 000,059,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gckernel.sys

[2010/03/09 19:26:36 | 000,010,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gameenum.sys

[2010/03/09 19:26:34 | 000,322,432 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g400m.sys

[2010/03/09 19:26:33 | 001,733,120 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g400d.dll

[2010/03/09 19:26:31 | 000,320,384 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g200m.sys

[2010/03/09 19:26:30 | 000,470,144 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\dllcache\g200d.dll

[2010/03/09 19:26:28 | 000,454,912 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fxusbase.sys

[2010/03/09 19:26:20 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fuusd.dll

[2010/03/09 19:26:18 | 000,455,296 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fusbbase.sys

[2010/03/09 19:26:17 | 000,455,680 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fus2base.sys

[2010/03/09 19:26:13 | 000,442,240 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpnpbase.sys

[2010/03/09 19:26:11 | 000,441,728 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcmbase.sys

[2010/03/09 19:26:09 | 000,444,416 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcibase.sys

[2010/03/09 19:26:08 | 000,034,173 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\forehe.sys

[2010/03/09 19:26:06 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fnfilter.dll

[2010/03/09 19:26:03 | 000,027,165 | ---- | C] (VIA Technologies, Inc. ) -- C:\WINDOWS\System32\dllcache\fetnd5.sys

[2010/03/09 19:25:59 | 000,022,090 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\fem556n5.sys

[2010/03/09 19:25:56 | 000,024,618 | ---- | C] (NETGEAR) -- C:\WINDOWS\System32\dllcache\fa410nd5.sys

[2010/03/09 19:25:54 | 000,016,074 | ---- | C] (NETGEAR Corp.) -- C:\WINDOWS\System32\dllcache\fa312nd5.sys

[2010/03/09 19:25:53 | 000,011,850 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xj.sys

[2010/03/09 19:25:51 | 000,012,362 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xi.sys

[2010/03/09 19:25:48 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\exabyte2.sys

[2010/03/09 19:25:47 | 000,016,998 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\ex10.sys

[2010/03/09 19:25:43 | 000,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunib.dll

[2010/03/09 19:25:42 | 000,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuni.dll

[2010/03/09 19:25:40 | 000,034,816 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimg.dll

[2010/03/09 19:25:34 | 000,137,088 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\essm2e.sys

[2010/03/09 19:25:34 | 000,043,008 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucm.dll

[2010/03/09 19:25:33 | 000,063,360 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\ess.sys

[2010/03/09 19:25:30 | 000,347,550 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\es56tpi.sys

[2010/03/09 19:25:29 | 000,594,238 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\es56hpi.sys

[2010/03/09 19:25:27 | 000,595,647 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\es56cvmp.sys

[2010/03/09 19:25:26 | 000,174,464 | ---- | C] (ESS Technology, Inc.) -- C:\WINDOWS\System32\dllcache\es198x.sys

[2010/03/09 19:25:24 | 000,072,192 | ---- | C] (ESS Technology Inc.) -- C:\WINDOWS\System32\dllcache\es1969.sys

[2010/03/09 19:25:23 | 000,040,704 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\es1371mp.sys

[2010/03/09 19:25:21 | 000,037,120 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\es1370mp.sys

[2010/03/09 19:25:20 | 000,061,952 | ---- | C] (Equinox Systems Inc.) -- C:\WINDOWS\System32\dllcache\eqnloop.exe

[2010/03/09 19:25:18 | 000,051,200 | ---- | C] (Equinox Systems Inc.) -- C:\WINDOWS\System32\dllcache\eqnlogr.exe

[2010/03/09 19:25:17 | 000,053,248 | ---- | C] (Equinox Systems Inc.) -- C:\WINDOWS\System32\dllcache\eqndiag.exe

[2010/03/09 19:25:15 | 000,629,952 | ---- | C] (Equinox Systems Inc.) -- C:\WINDOWS\System32\dllcache\eqn.sys

[2010/03/09 19:25:14 | 000,114,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\epstw2k.sys

[2010/03/09 19:25:12 | 000,018,503 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\epro4.sys

[2010/03/09 19:25:11 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\epcfw2k.sys

[2010/03/09 19:25:10 | 000,283,904 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\emu10k1m.sys

[2010/03/09 19:25:07 | 000,019,996 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\em556n4.sys

[2010/03/09 19:25:06 | 000,025,159 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\elnk3.sys

[2010/03/09 19:25:05 | 000,007,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\elmsmc.sys

[2010/03/09 19:25:04 | 000,171,520 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el99xn51.sys

[2010/03/09 19:25:03 | 000,070,174 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el98xn5.sys

[2010/03/09 19:25:02 | 000,455,199 | ---- | C] (3Com Corporation.) -- C:\WINDOWS\System32\dllcache\el985n51.sys

[2010/03/09 19:25:01 | 000,153,631 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el90xnd5.sys

[2010/03/09 19:25:00 | 000,066,591 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el90xbc5.sys

[2010/03/09 19:24:59 | 000,241,206 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el656se5.sys

[2010/03/09 19:24:58 | 000,077,386 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el656nd5.sys

[2010/03/09 19:24:57 | 000,634,134 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el656ct5.sys

[2010/03/09 19:24:56 | 000,069,194 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el656cd5.sys

[2010/03/09 19:24:55 | 000,026,141 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el589nd5.sys

[2010/03/09 19:24:54 | 000,069,692 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el575nd5.sys

[2010/03/09 19:24:53 | 000,024,653 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el574nd4.sys

[2010/03/09 19:24:52 | 000,055,999 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el556nd5.sys

[2010/03/09 19:24:51 | 000,044,103 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\el515.sys

[2010/03/09 19:24:49 | 000,019,594 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\e100isa4.sys

[2010/03/09 19:24:48 | 000,117,760 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\e100b325.sys

[2010/03/09 19:24:47 | 000,050,719 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\e1000nt5.sys

[2010/03/09 19:24:43 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dshowext.ax

[2010/03/09 19:24:42 | 000,334,208 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\ds1wdm.sys

[2010/03/09 19:24:38 | 000,028,062 | ---- | C] (National Semiconductor Coproration) -- C:\WINDOWS\System32\dllcache\dp83820.sys

[2010/03/09 19:24:37 | 000,023,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4usb.sys

[2010/03/09 19:24:36 | 000,012,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4prt.sys

[2010/03/09 19:24:36 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4scan.sys

[2010/03/09 19:24:35 | 000,207,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dot4.sys

[2010/03/09 19:24:29 | 000,029,696 | ---- | C] (CNet Technology, Inc. ) -- C:\WINDOWS\System32\dllcache\dm9pci5.sys

[2010/03/09 19:24:29 | 000,008,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dlttape.sys

[2010/03/09 19:24:28 | 000,026,698 | ---- | C] (D-Link Corporation) -- C:\WINDOWS\System32\dllcache\dlh5xnd5.sys

[2010/03/09 19:24:27 | 000,952,007 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diwan.sys

[2010/03/09 19:24:23 | 000,236,060 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\ditrace.exe

[2010/03/09 19:24:23 | 000,038,985 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvsu.dll

[2010/03/09 19:24:22 | 000,031,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvpp.dll

[2010/03/09 19:24:21 | 000,006,729 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvci.dll

[2010/03/09 19:24:18 | 000,091,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\dimaint.sys

[2010/03/09 19:24:17 | 000,614,429 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digiview.exe

[2010/03/09 19:24:16 | 000,042,432 | ---- | C] (Digi International, Inc.) -- C:\WINDOWS\System32\dllcache\digirlpt.sys

[2010/03/09 19:24:15 | 000,110,621 | ---- | C] (Digi International, Inc.) -- C:\WINDOWS\System32\dllcache\digirlpt.dll

[2010/03/09 19:24:14 | 000,041,046 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digiisdn.dll

[2010/03/09 19:24:14 | 000,021,606 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digiisdn.sys

[2010/03/09 19:24:13 | 000,102,484 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digiinf.dll

[2010/03/09 19:24:12 | 000,159,828 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digihlc.dll

[2010/03/09 19:24:11 | 000,229,462 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digifwrk.dll

[2010/03/09 19:24:10 | 000,090,525 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digifep5.sys

[2010/03/09 19:24:09 | 000,103,044 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digidxb.sys

[2010/03/09 19:24:08 | 000,131,156 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digidbp.dll

[2010/03/09 19:24:08 | 000,037,735 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digiasyn.sys

[2010/03/09 19:24:07 | 000,065,622 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\digiasyn.dll

[2010/03/09 19:24:04 | 000,419,357 | ---- | C] (Digi International) -- C:\WINDOWS\System32\dllcache\dgconfig.dll

[2010/03/09 19:24:03 | 000,029,531 | ---- | C] (Digi International Inc.) -- C:\WINDOWS\System32\dllcache\dgapci.sys

[2010/03/09 19:24:02 | 000,024,649 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650d.sys

[2010/03/09 19:24:01 | 000,024,648 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650.sys

[2010/03/09 19:24:00 | 000,024,064 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\devldr32.exe

[2010/03/09 19:23:59 | 000,256,512 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\devcon32.dll

[2010/03/09 19:23:58 | 000,020,928 | ---- | C] (Digital Networks, LLC) -- C:\WINDOWS\System32\dllcache\defpa.sys

[2010/03/09 19:23:57 | 000,007,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ddsmc.sys

[2010/03/09 19:23:56 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc260usd.dll

[2010/03/09 19:23:55 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc240usd.dll

[2010/03/09 19:23:54 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc210usd.dll

[2010/03/09 19:23:54 | 000,063,208 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\dllcache\dc21x4.sys

[2010/03/09 19:23:53 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dc210_32.dll

[2010/03/09 19:23:47 | 000,117,760 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\d100ib5.sys

[2010/03/09 19:23:47 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cyzports.dll

[2010/03/09 19:23:46 | 000,049,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cyzport.sys

[2010/03/09 19:23:45 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cyzcoins.dll

[2010/03/09 19:23:44 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cyyports.dll

[2010/03/09 19:23:43 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cyyport.sys

[2010/03/09 19:23:43 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cyycoins.dll

[2010/03/09 19:23:42 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cyclom-y.sys

[2010/03/09 19:23:41 | 000,048,640 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwrwdm.sys

[2010/03/09 19:23:41 | 000,017,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cyclad-z.sys

[2010/03/09 19:23:40 | 000,093,952 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcwdm.sys

[2010/03/09 19:23:39 | 000,111,872 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcspud.sys

[2010/03/09 19:23:38 | 000,072,832 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbwdm.sys

[2010/03/09 19:23:38 | 000,003,584 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcosnt5.sys

[2010/03/09 19:23:37 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbmidi.sys

[2010/03/09 19:23:36 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbase.sys

[2010/03/09 19:23:35 | 000,249,856 | ---- | C] (Comtrol

Link to post
Share on other sites

Results below:

---------------------------------------------------------------------------------------------------------------------------------------------------------

OTL logfile created on: 3/14/2010 1:26:42 AM - Run

OTLPE by OldTimer - Version 3.1.35.0 Folder = X:\Programs\OTLPE

Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) - Type = SYSTEM

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free

3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 111.79 Gb Total Space | 65.15 Gb Free Space | 58.28% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Drive X: | 276.79 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REATOGO

Current User Name: SYSTEM

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

Using ControlSet: ControlSet002

========== Standard Registry (All) ==========

========== Internet Explorer ==========

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch

IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Page_Transitions = 1

IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch

IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msh.org/

IE - HKU\Administrator_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,Page_Transitions = 1

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKU\aspeed_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKU\aspeed_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKU\aspeed_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\aspeed_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\Ctx_StreamingSvc_ON_C\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\Ctx_StreamingSvc_ON_C\Software\Microsoft\Internet Explorer\Main,Page_Transitions = 1

IE - HKU\Ctx_StreamingSvc_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch

IE - HKU\Ctx_StreamingSvc_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msh.org/

IE - HKU\Ctx_StreamingSvc_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKU\Ctx_StreamingSvc_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2010/03/03 00:19:17 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2010/03/03 09:40:45 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/02 17:20:45 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/12/17 18:12:14 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/12 01:52:15 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/12 01:52:14 | 000,000,000 | ---D | M]

[2010/03/13 14:55:51 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

[2010/03/12 01:52:14 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009/05/24 14:44:55 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

[2009/07/02 17:20:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

[2009/10/28 17:24:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

[2009/11/26 22:58:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

[2010/03/12 01:52:01 | 000,023,000 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll

[2010/03/12 01:52:01 | 000,138,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll

[2009/12/17 08:51:27 | 000,119,808 | ---- | M] (Google) -- C:\Program Files\Mozilla Firefox\components\GoogleDesktopMozilla.dll

[2007/06/21 17:38:52 | 000,030,280 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\cgpcfg.dll

[2007/06/21 18:38:54 | 000,079,432 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll

[2007/06/21 18:38:56 | 000,071,240 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll

[2007/06/21 17:38:58 | 000,140,872 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\ctxmui.dll

[2007/06/21 17:39:14 | 000,038,472 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\icafile.dll

[2007/06/21 17:39:16 | 000,046,664 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\icalogon.dll

[2007/06/21 18:39:18 | 000,034,376 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\logging.dll

[2008/01/07 19:45:16 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll

[2009/10/11 04:17:27 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll

[2008/11/06 11:33:48 | 001,332,224 | ---- | M] (DivX,Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll

[2008/12/10 19:33:34 | 000,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll

[2007/05/15 20:35:30 | 000,407,360 | ---- | M] (Documentum, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npeRoom7.dll

[2007/06/21 18:39:34 | 000,325,200 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll

[2010/03/12 01:52:07 | 000,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll

[2007/03/22 19:23:30 | 000,017,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL

[2010/03/03 00:19:57 | 000,1