Jump to content

Clean MBAM log, Avira Update Freeze, Rogue RECYCLER and Bit Defender


Recommended Posts

Complicated and daunting to describe but wishing it to the cornfield is not helping, so :wacko: *big exhale* here goes...

I tried to follow the initial directions (with some difficulty) after this post and things began looking up. As I stated in the thread, I had to run MBAM.exe from My Documents because the folder would not go to My Desktop no matter what I tried.

I was prompted that the text in MBAM.exe had changed (thus the confusion about encoding) but I ignored the prompt, clicked "No" to "Do you want to save the changes?" and continued with and executed the original file.

I had to do this from Safe Mode with Networking. Ran the MBAM quick scan with no results. This seemed to free me up from the re-directs but still too many funky files peppered my system.

In hindsight it was probably a bad idea, but since my system went wacky after my recent download of Bit-Defender (what I now suspect has bad juju) I tried to unload the monster system hog from Add/Remove Programs before I rebooted and downloaded Avira AntiVir Personal but it wouldn't let me remove Bit Defender in Safe Mode.

I rebooted and Bit Defender prompted me to update. I thought, "Oh, it's working now. Malwarebytes must have fixed that glitch too." But, naturally, the update link proved ineffective. Since anti virus software tends to clash, I thought it best to remove the useless program before I downloaded Avira. :angry: Here is where things probably went from bad to worse. but I went to Add/Remove Programs and removed Bit Defender. Deleted the shortcut from my desktop and rebooted. :( It was still there so I ran MBAM again with same "No infected files," result.

Okay, Pollyanna jokes aside... :blink:

I printed the instructions that Ron :) so kindly and quickly supplied, followed the directions, and downloaded Avira AntiVir from the link. Avira froze up on the Update with lots of time lapsed and zero files and bytes downloaded on the update. I can't remember which came first but frustrated, I ran a search for all files containing Bit Defender and ended up with a lengthy list. Could not delete the files. Also noticed a nasty a little file called "RECYCLER."

Went to Avira Help for guidance and followed the directions under manual updates by going to Avira's web page and downloaded the first VDF file here. Now I have the original Avira folder, the VDF zip file, and the extracted file on my Desktop but either can't figure out how to launch it or something else is keeping me from launching it.

Now, Avira is giving me the, "Avira has not been updated in 7 days" prompt with a link. I predict it freezes again.

Also, the nasty RECYCLER will not let me delete it, so I renamed it "repo" and it seemed to delete but RECYCLER reappeared. I renamed and deleted it again. :( Is is gone? I doubt it.

In the mean time, I still have a Bit Defender search results folder but cannot delete the files within the search file, even with File Assassin or by renaming it. More weird files are popping up with file extensions I'm not sure of and a few others that are obviously rogue.

I would like to follow up with the Defogger directions but I'm chicken. I can't afford the $180.00 minimum cost or time (need access to non-profit files this week) to take this baby (my laptop) to the shop. I suppose that everything I do beyond fixing this just makes it worse, right? Don't answer that.

I'll try to update Avira again. If that doesn't work, do I go back to square one ? I'm thinking a full MBAM scan will help but wonder if my system is too polluted with these pesky shape-shifter files. Is there another magic Malwarebytes fix or a miracle on line scanner, fixer, cleaner, or legal $20.00 bill printing machine?

Fingers crossed for an easy, uncomplicated fix. A wink of the eye and twinkle of the nose, perhaps? ;)

Thanks,

~Deb

Bewitched

I hope this convoluted explanation makes sense to someone.

Ooh look! A shiny thing...

Link to post
Share on other sites

Hello ,

And :wacko: My name is Elise and I'll be glad to help you with your computer problems.

I will be working on your malware issues, this may or may not solve other issues you may have with your machine.

Please note that whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.

  • The cleaning process is not instant. Logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happen.
  • Please reply using the Add/Reply button in the lower right hand corner of your screen. Do not start a new topic.
  • The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, send me or a moderator a personal message with the address of the thread or feel free to create a new one.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications.

-----------------------------------------------------------

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

If you have already posted a log, please do so again, as your situation may have changed.

Use the 'Add Reply' and add the new log to this thread.

We need to see some information about what is happening in your machine. Please perform the following scan:

  • Please download OTL from one of the following mirrors:

    [*]Save it to your desktop.

    [*]Double click on the otlDesktopIcon.png icon on your desktop.

    [*]Click the "Scan All Users" checkbox.

    [*]Push the Quick Scan button.

    [*]Two reports will open, copy and paste them in a reply here:

    • OTListIt.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

Please Download Rootkit Unhooker Save it to your desktop.

  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth,. Uncheck the rest. then Click OK.
  • Wait till the scanner has finished and then click File, Save Report.
  • Save the report somewhere where you can find it. Click Close.

Copy the entire contents of the report and paste it in a reply here.

Note - if you get the following warning, just ignore: "Rootkit Unhooker has detected a parasite inside itself!

It is recommended to remove parasite, okay?"

Click on Cancel, then Accept.

-------------------------------------------------------------

In the meantime please, do NOT install any new programs or update anything unless told to do so while we are fixing your problem

If you still need help, please include the following in your next reply

  • A detailed description of your problems
  • A new OTL log (don't forget extra.txt)
  • RKU log

Thanks and again sorry for the delay.

Link to post
Share on other sites

Hi Elise.

Thank you for the warm welcome and quick reply. Jeez, I'm blown away by the kind and quick professionalism here. :blink:

Although I couldn't update Avira after initial download, decided to scan files anyway. Currently, Luke File walker is 56% done - showing 3 Hidden Files and 5 detections. Last detection shown as JAVA/Agent.BD

:wacko: I need to get coffee made and breakfast/lunches fixed. So, if it's all the same to you, I'll let the scan finish out and return after everyone is off to work and school.

Then I can bring a cup-pa coffee (the good java) and try to wrap my head around this. Better chance of me following the instructions in at least a semi-coherent state of mind.

Thank you for being so quick and thorough.

I'll be back around 7:30 am barring any unforeseeable distractions or interruptions.

Again, thanks.

~Deb

Link to post
Share on other sites

Hi again Elise. Sorry that took so long. I cannot delete the remaining BitDefender files and the pesky RECYCLER file will is a stubborn parasite too. I could not get the Avira AntiVir to update but I ran a few scans with what I had. General scan showed 5 instances of BD Agent, another showed errors up the wazoo (49, I think) in my registry, and still another indicated 39 warnings. Ugh! This is worse than I thought. :)

Okay, here are the two logs resulting from the OTL scan:

* * * * * * *

OTL logfile created on: 2/4/2011 5:51:09 PM - Run 1

OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Owner\Desktop

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 326.00 Mb Available Physical Memory | 32.00% Memory free

2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 74.52 Gb Total Space | 10.20 Gb Free Space | 13.69% Space Free | Partition Type: NTFS

Computer Name: OWNER-753D2803F | User Name: Owner | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/04 17:49:59 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe

PRC - [2011/01/10 14:23:42 | 000,516,353 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\update.exe

PRC - [2011/01/10 14:23:41 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe

PRC - [2011/01/10 14:23:30 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe

PRC - [2011/01/10 14:23:29 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

PRC - [2011/01/07 01:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe

PRC - [2010/12/20 18:08:46 | 000,963,976 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware1\mbam.exe

PRC - [2010/12/05 16:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe

PRC - [2010/12/01 19:35:18 | 004,280,320 | ---- | M] (Google Inc.) -- C:\WINDOWS\system32\GPhotos.scr

PRC - [2010/11/25 09:49:46 | 000,517,448 | ---- | M] () -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe

PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe

PRC - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

PRC - [2010/04/28 06:44:02 | 000,704,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe

PRC - [2010/04/06 14:34:22 | 000,102,752 | ---- | M] (Microsoft Corp.) -- C:\Program Files\MSN\Toolbar\4.0.0412.0\mstbsvc.exe

PRC - [2010/03/24 16:36:02 | 000,883,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Temp\InstallManager_Sun_Sun.exe

PRC - [2010/03/18 15:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe

PRC - [2010/03/18 12:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe

PRC - [2010/01/14 21:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

PRC - [2008/04/14 03:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

========== Modules (SafeList) ==========

MOD - [2011/02/04 17:49:59 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe

MOD - [2010/08/23 08:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (HidServ)

SRV - File not found [Auto | Stopped] -- -- (AppMgmt)

SRV - [2011/01/10 14:23:41 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)

SRV - [2011/01/10 14:23:30 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)

SRV - [2010/11/25 09:49:46 | 000,517,448 | ---- | M] () [Auto | Running] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)

SRV - [2010/11/16 01:10:14 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)

SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)

SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)

SRV - [2010/04/28 06:44:02 | 000,704,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)

SRV - [2010/04/06 14:34:22 | 000,102,752 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\MSN\Toolbar\4.0.0412.0\mstbsvc.exe -- (mstbsvc)

SRV - [2010/03/18 15:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)

SRV - [2010/03/18 12:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)

SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2010/03/18 12:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)

========== Driver Services (SafeList) ==========

DRV - [2011/01/10 14:23:53 | 000,135,096 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)

DRV - [2011/01/10 14:23:53 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)

DRV - [2010/12/08 04:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)

DRV - [2010/11/12 13:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)

DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)

DRV - [2010/07/09 14:08:14 | 000,327,368 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\bdfsfltr.sys -- (bdfsfltr)

DRV - [2010/06/17 14:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)

DRV - [2010/06/17 14:27:12 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)

DRV - [2010/04/28 06:44:02 | 000,054,760 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)

DRV - [2010/03/04 20:07:31 | 000,028,352 | ---- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\MxlW2k.sys -- (MxlW2k)

DRV - [2010/02/11 04:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)

DRV - [2008/10/23 00:58:36 | 001,391,104 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)

DRV - [2008/04/14 03:00:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)

DRV - [2008/04/14 03:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)

DRV - [2008/04/14 03:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)

DRV - [2008/04/14 03:00:00 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)

DRV - [2008/04/14 00:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)

DRV - [2008/04/13 14:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)

DRV - [2008/02/25 11:54:56 | 000,105,088 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)

DRV - [2007/09/15 01:09:44 | 000,213,696 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)

DRV - [2007/04/16 21:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)

DRV - [2005/08/23 18:26:00 | 001,273,344 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)

DRV - [2005/04/04 08:25:36 | 000,160,768 | R--- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)

DRV - [2005/03/22 06:39:44 | 000,200,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWATI.sys -- (HSFHWATI)

DRV - [2005/03/22 06:39:42 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)

DRV - [2005/03/22 06:39:40 | 000,703,232 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)

DRV - [2005/03/15 15:14:52 | 000,346,496 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\camc6hal.sys -- (CAMCHALA)

DRV - [2005/03/15 15:14:52 | 000,037,760 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\camc6aud.sys -- (CAMCAUD)

DRV - [2005/03/10 13:09:02 | 000,024,704 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidKE.Sys -- (LHidKe)

DRV - [2005/03/10 13:08:56 | 000,069,504 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)

DRV - [2005/03/10 13:08:34 | 000,036,480 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidUsbK.sys -- (LHidUsbK)

DRV - [2005/03/10 13:08:26 | 000,053,632 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042mou.Sys -- (L8042mou)

DRV - [2005/03/10 13:08:16 | 000,013,056 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)

DRV - [2004/08/11 15:30:00 | 000,039,424 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)

DRV - [2004/04/14 06:36:50 | 000,007,432 | ---- | M] (Hewlett-Packard Company) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\eabfiltr.sys -- (eabfiltr)

DRV - [2003/12/25 16:48:14 | 000,010,752 | ---- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\iviaspi.sys -- (Iviaspi)

DRV - [2003/06/06 10:46:16 | 000,005,220 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EabUsb.sys -- (eabusb)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/sbcydsl/defa...//www.yahoo.com

IE - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/

IE - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.10:3128

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"

FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - prefs.js..extensions.enabledItems: {71328583-3CA7-4809-B4BA-570A85818FBB}:0.6.3

FF - prefs.js..extensions.enabledItems: {38abe53c-d79f-8e86-9673-57c449674c5e}:5.4.1

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22

FF - prefs.js..extensions.enabledItems: avg@igeared:6.011.025.001

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178

FF - prefs.js..extensions.enabledItems: ddfirefox@dynamitedata:1.3.0

FF - prefs.js..extensions.enabledItems: info@priceblink.com:2.1

FF - prefs.js..extensions.enabledItems: {72938f90-8d8a-11de-8a39-0800200c9a66}:1.3.5

FF - prefs.js..extensions.enabledItems: FFToolbar@bitdefender.com:2.0

FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4cb38761&v=6.011.025.001&i=26&tp=ab&iy=&ychte=us&lng=en-US&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/30 03:19:04 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2011/01/19 17:14:05 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\\FFToolbar@bitdefender.com: C:\Program Files\BitDefender\BitDefender 2011\bdaphffext\ [2011/01/27 07:28:07 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/22 01:34:19 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/22 11:15:46 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Thunderbird\Extensions\\bdThunderbird@bitdefender.com: C:\Program Files\BitDefender\BitDefender 2011\bdtbext\ [2011/01/27 07:26:36 | 000,000,000 | ---D | M]

[2010/03/17 18:11:13 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions

[2011/02/04 17:02:57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\extensions

[2010/04/24 16:35:00 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}(2)

[2010/06/14 12:46:14 | 000,000,000 | ---D | M] (Behind The *Asterisks* (EladKarako Mod)) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\extensions\{38abe53c-d79f-8e86-9673-57c449674c5e}

[2010/06/14 12:46:15 | 000,000,000 | ---D | M] (CacheViewer) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}

[2010/12/22 11:26:55 | 000,000,000 | ---D | M] (PriceTrace) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\extensions\{72938f90-8d8a-11de-8a39-0800200c9a66}

[2010/12/22 11:26:50 | 000,000,000 | ---D | M] ("Dynamite Deals") -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\extensions\ddfirefox@dynamitedata

[2010/12/22 11:26:52 | 000,000,000 | ---D | M] (PriceBlink) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\extensions\info@priceblink.com

[2010/12/22 11:26:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\extensions\staged-xpis

[2011/02/04 17:02:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2010/06/11 12:33:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

[2010/08/09 10:06:12 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

[2010/10/14 03:12:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

[2010/12/30 03:19:04 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX

[2011/01/19 17:14:05 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:id="avg@igeared" em:name="AVG Security Toolbar" em:version="6.011.025.001" em:displayname="AVG Security Toolbar" em:iconURL="chrome://tavgp/skin/logo.ico" em:creator="AVG Technologies" em:description="AVG Security Toolbar" em:homepageURL="http://www.avg.com" >) -- C:\PROGRAM FILES\AVG\AVG10\TOOLBAR\FIREFOX\AVG@IGEARED

[2011/01/27 07:28:07 | 000,000,000 | ---D | M] ("BitDefender Antiphishing Toolbar") -- C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2011\BDAPHFFEXT

[2010/06/11 12:32:53 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

[2010/02/26 17:00:31 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION

[2010/09/15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

[2010/10/06 22:26:49 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

O1 HOSTS File: ([2008/04/14 03:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Yahoo! Companion BHO) - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll (Yahoo! Inc.)

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()

O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()

O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()

O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()

O3 - HKLM\..\Toolbar: (Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll (Yahoo! Inc.)

O3 - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\..\Toolbar\ShellBrowser: (Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll (Yahoo! Inc.)

O3 - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\..\Toolbar\WebBrowser: (Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll (Yahoo! Inc.)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [AddressBookReminderApp] C:\Program Files\Nova Development\Print Artist Platinum\ReminderApp.exe ()

O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)

O4 - HKLM..\Run: [bDAgent] C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (BitDefender S.R.L.)

O4 - HKLM..\Run: [bitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe (BitDefender S.R.L.)

O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()

O4 - HKLM..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe (Hewlett-Packard )

O4 - HKLM..\Run: [Home Theater SchSvr] C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe (InterVideo Inc.)

O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)

O4 - HKLM..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)

O4 - HKLM..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)

O4 - HKLM..\Run: [WINREMOTE] C:\Program Files\InterVideo\Common\Bin\WinRemote.exe (InterVideo Inc.)

O4 - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)

O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)

O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()

O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()

O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)

O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)

O9 - Extra Button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll (Yahoo! Inc.)

O9 - Extra 'Tools' menuitem : Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll (Yahoo! Inc.)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

O15 - HKU\S-1-5-21-1085031214-1336601894-1417001333-1003\..Trusted Domains: microsoft.com ([office] https in Trusted sites)

O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office2010.microsoft.com/sites/prod...n/ieawsdc32.cab (Microsoft Office Template and Media Control)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5...heckControl.cab (Windows Genuine Advantage Validation Tool)

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)

O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)

O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/sit...b?1276232200515 (MUCatalogWebControl Class)

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/...can8/oscan8.cab (Reg Error: Key error.)

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/...lscbase6770.cab (Windows Live Safety Center Base Module)

O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22)

O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} http://download.yahoo.com/dl/installs/ymail/ymmapi.dll (YahooYMailTo Class)

O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_22)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()

O18 - Protocol\Handler\bw+0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw+0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw-0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw00 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw00s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw-0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw10 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw10s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw20 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw20s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw30 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw30s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw40 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw40s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw50 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw50s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw60 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw60s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw70 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw70s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw80 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw80s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw90 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bw90s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwa0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwa0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwb0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwb0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwc0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwc0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwd0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwd0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwe0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwe0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwf0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwf0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwg0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwg0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwh0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwh0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwi0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwi0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwj0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwj0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwk0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwk0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwl0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwl0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwm0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwm0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwn0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwn0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwo0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwo0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwp0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwp0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwq0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwq0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwr0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwr0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bws0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bws0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwt0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwt0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwu0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwu0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwv0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwv0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bww0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bww0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwx0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwx0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwy0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwy0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwz0 {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\bwz0s {533fa73a-3b92-495e-a106-e988f3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)

O18 - Protocol\Handler\offline-8876480 {533FA73A-3B92-495E-A106-E988F3464074} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )

O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop WallPaper: C:\Documents and Settings\Owner\My Documents\My Pictures\Treed Lane.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\My Documents\My Pictures\Treed Lane.bmp

O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010/05/23 13:14:23 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{09be0c06-2813-11df-ac2e-0014a519fd82}\Shell\AutoRun\command - "" = E:\setupSNK.exe

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2099/08/07 18:14:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\953CANON

[2098/09/15 23:29:03 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Owner\My Documents\Sample Pictures

[2011/02/04 17:49:56 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe

[2011/02/03 16:31:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\New Folder

[2011/02/03 15:25:12 | 000,000,000 | ---D | C] -- C:\Program Files\WOT

[2011/02/01 22:47:43 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2011/02/01 22:40:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\vdf_fusebundle

[2011/02/01 22:09:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Avira

[2011/02/01 22:05:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe

[2011/02/01 21:24:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avira

[2011/02/01 21:23:59 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys

[2011/02/01 21:23:55 | 000,135,096 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys

[2011/02/01 21:23:55 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys

[2011/02/01 21:23:55 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys

[2011/02/01 21:23:55 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys

[2011/02/01 21:23:54 | 000,000,000 | ---D | C] -- C:\Program Files\Avira

[2011/02/01 21:23:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira

[2011/01/31 22:11:52 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware1

[2011/01/31 22:07:22 | 007,734,240 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Owner\Desktop\mbam-setup1.exe

[2011/01/27 07:24:51 | 000,000,000 | ---D | C] -- C:\Program Files\BitDefender

[2011/01/24 13:31:10 | 000,000,000 | ---D | C] -- C:\Program Files\FileASSASSIN

[2011/01/24 13:31:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FileASSASSIN

[2011/01/22 22:34:19 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live Safety Center

[2011/01/19 23:04:46 | 000,000,000 | ---D | C] -- C:\Program Files\MSSOAP

[2011/01/19 22:17:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\BitDefender

[2011/01/19 22:16:19 | 000,327,368 | ---- | C] (BitDefender) -- C:\WINDOWS\System32\drivers\bdfsfltr.sys

[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[24 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/04 17:52:08 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3891B371-4764-4E88-93BB-89E9528A0B27}.job

[2011/02/04 17:49:59 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe

[2011/02/04 03:15:01 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\tasks\DataUpload.job

[2011/02/03 13:39:21 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\tasks\ConfigExec.job

[2011/02/03 13:39:16 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011/02/03 13:39:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011/02/03 13:39:10 | 1072,222,208 | -HS- | M] () -- C:\hiberfil.sys

[2011/02/02 02:22:36 | 003,822,803 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Tar Creek May 2011.JPG

[2011/02/01 22:31:45 | 039,643,354 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\vdf_fusebundle.zip

[2011/02/01 21:24:22 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk

[2011/02/01 20:42:36 | 000,000,962 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to xmas 2005 156.lnk

[2011/02/01 20:42:36 | 000,000,962 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to xmas 2005 152.lnk

[2011/02/01 20:42:36 | 000,000,962 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to xmas 2005 141.lnk

[2011/02/01 20:42:36 | 000,000,825 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to Trillium Price Sheet.lnk

[2011/02/01 20:42:35 | 000,001,425 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to IM000710.jpg.lnk

[2011/02/01 20:42:35 | 000,001,064 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to Red Barren and his Baby Girls.jpg.lnk

[2011/02/01 20:42:35 | 000,000,991 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to Mr Kwit, funny Irish girls.lnk

[2011/02/01 20:42:35 | 000,000,977 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to hot flash button.jpg.lnk

[2011/02/01 20:42:35 | 000,000,942 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to candy man.jpg.lnk

[2011/02/01 20:42:35 | 000,000,918 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to ninja.jpg.lnk

[2011/02/01 20:42:35 | 000,000,913 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to face.lnk

[2011/02/01 20:42:35 | 000,000,656 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to misc pics.lnk

[2011/02/01 20:42:32 | 000,001,090 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to 2005, 2006 115.lnk

[2011/02/01 20:42:32 | 000,001,047 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to 040806 Snow day at Frazier 012.lnk

[2011/02/01 20:42:32 | 000,000,977 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut to 010203040506 235.lnk

[2011/02/01 20:42:32 | 000,000,962 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Shortcut (2) to xmas 2005 141.lnk

[2011/02/01 20:42:32 | 000,000,897 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Fitz.lnk

[2011/02/01 20:42:31 | 000,000,741 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Downloaded Program Updates.lnk

[2011/01/31 22:11:57 | 000,000,791 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/01/31 22:07:22 | 007,734,240 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Owner\Desktop\mbam-setup1.exe

[2011/01/27 18:25:31 | 000,175,104 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\CAHSEE English Exam.ppt

[2011/01/27 13:40:59 | 000,380,928 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\ParentConnection_TwoPageInstructions_blank (2) (3).doc

[2011/01/27 07:30:06 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk

[2011/01/26 17:13:45 | 000,547,628 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011/01/26 17:13:45 | 000,104,044 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011/01/24 17:01:44 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011/01/24 13:31:10 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FileASSASSIN.lnk

[2011/01/24 01:47:37 | 000,003,739 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2011/01/24 00:03:00 | 000,087,189 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\bdinstall.bin

[2011/01/23 23:22:47 | 000,000,242 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Files named Malwarebytes'.fnd

[2011/01/22 02:20:27 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2011/01/22 00:38:16 | 000,315,560 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011/01/20 21:16:47 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat

[2011/01/20 20:45:37 | 000,000,016 | ---- | M] () -- C:\WINDOWS\System32\asdict.dat

[2011/01/19 23:52:39 | 000,000,415 | ---- | M] () -- C:\WINDOWS\System32\user_gensett.xml

[2011/01/18 19:37:59 | 000,045,277 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\2011 laws requiring esucation.odt

[2011/01/18 19:37:17 | 000,024,970 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\special days.odt

[2011/01/17 19:54:31 | 000,019,421 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\special education laws 2011.odt

[2011/01/17 17:45:44 | 000,116,600 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\zangle.pdf

[2011/01/17 06:02:10 | 000,021,608 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\stalker crmes.odt

[2011/01/17 05:04:58 | 000,049,152 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\education laws 2011.wps

[2011/01/17 05:04:58 | 000,018,630 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat

[2011/01/16 18:27:13 | 104,443,581 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm

[2011/01/10 14:23:53 | 000,135,096 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys

[2011/01/10 14:23:53 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys

[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[24 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/03 15:28:28 | 000,000,422 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3891B371-4764-4E88-93BB-89E9528A0B27}.job

[2011/02/02 02:22:35 | 003,822,803 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Tar Creek May 2011.JPG

[2011/02/01 22:31:37 | 039,643,354 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\vdf_fusebundle.zip

[2011/02/01 21:26:45 | 1072,222,208 | -HS- | C] () -- C:\hiberfil.sys

[2011/02/01 21:24:22 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk

[2011/01/27 18:25:30 | 000,175,104 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\CAHSEE English Exam.ppt

[2011/01/27 13:40:58 | 000,380,928 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\ParentConnection_TwoPageInstructions_blank (2) (3).doc

[2011/01/27 07:30:06 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk

[2011/01/24 13:31:10 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FileASSASSIN.lnk

[2011/01/23 23:22:41 | 000,000,242 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Files named Malwarebytes'.fnd

[2011/01/22 02:20:26 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\Owner\Start Menu\Programs\Internet Explorer

[2011/01/22 00:36:57 | 000,000,791 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/01/20 20:45:37 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\asdict.dat

[2011/01/19 23:52:39 | 000,000,415 | ---- | C] () -- C:\WINDOWS\System32\user_gensett.xml

[2011/01/19 22:16:19 | 000,087,189 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\bdinstall.bin

[2011/01/18 19:37:16 | 000,024,970 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\special days.odt

[2011/01/17 19:54:30 | 000,019,421 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\special education laws 2011.odt

[2011/01/17 17:45:43 | 000,116,600 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\zangle.pdf

[2011/01/17 06:02:08 | 000,021,608 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\stalker crmes.odt

[2011/01/17 05:04:57 | 000,049,152 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\education laws 2011.wps

[2011/01/17 05:04:01 | 000,045,277 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\2011 laws requiring esucation.odt

[2010/07/16 00:01:00 | 000,000,349 | ---- | C] () -- C:\WINDOWS\hegames.ini

[2010/07/13 15:09:33 | 000,348,400 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

[2010/07/08 09:37:14 | 000,101,544 | ---- | C] () -- C:\Program Files\Common Files\LinkInstaller.exe

[2010/06/23 19:12:31 | 000,000,056 | ---- | C] () -- C:\WINDOWS\WININIT.INI

[2010/06/15 16:55:58 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat

[2010/06/09 12:42:58 | 000,000,095 | ---- | C] () -- C:\WINDOWS\muveeapp.INI

[2010/05/23 13:07:06 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll

[2010/05/23 13:07:06 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll

[2010/05/23 13:07:06 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll

[2010/05/23 13:07:06 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll

[2010/05/23 13:07:06 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll

[2010/05/23 13:07:05 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll

[2010/05/13 09:36:41 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\big bad voodoo dady.txt

[2010/04/28 20:12:34 | 000,000,488 | ---- | C] () -- C:\Program Files\Shortcut to greenstreet.lnk

[2010/04/21 06:34:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\QSwitch.txt

[2010/04/06 09:30:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MSREGUSR.INI

[2010/03/25 17:13:29 | 000,018,630 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat

[2010/03/25 14:47:19 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini

[2010/03/25 14:44:10 | 000,000,058 | ---- | C] () -- C:\WINDOWS\EPSPRX595.ini

[2010/03/17 17:36:30 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS6y.DLL

[2010/03/17 17:34:31 | 000,000,398 | ---- | C] () -- C:\WINDOWS\System32\CNCMP60.INI

[2010/03/17 12:12:00 | 000,089,088 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/03/11 01:32:34 | 000,028,510 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini

[2010/03/08 22:35:43 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll

[2010/02/26 07:01:56 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2009/03/03 12:18:04 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll

[2009/01/05 14:44:10 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini

[2007/09/27 09:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini

[2007/09/27 09:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini

[2007/09/27 09:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini

[2007/01/31 13:50:32 | 000,913,408 | ---- | C] () -- C:\WINDOWS\System32\xreglib.dll

[2005/02/12 00:33:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini

[2000/04/12 11:24:10 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\LFFPX7.DLL

[1997/09/30 10:30:02 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\LFKODAK.DLL

========== LOP Check ==========

[2011/01/21 20:37:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.OWNER-753D2803F.000\Application Data\BitDefender

[2011/01/23 23:42:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.OWNER-753D2803F.001\Application Data\BitDefender

[2011/01/24 02:30:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.OWNER-753D2803F.001\Application Data\Windows Desktop Search

[2011/01/22 23:05:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.OWNER-753D2803F.001\Application Data\Windows Search

[2010/10/07 03:11:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar

[2010/12/06 15:44:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10

[2010/10/07 02:47:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9

[2010/10/07 03:09:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files

[2010/03/25 14:48:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON

[2010/06/05 18:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo

[2010/12/17 22:29:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData

[2010/05/23 13:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies

[2010/07/02 12:26:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nova Development

[2010/11/06 23:43:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2010/06/01 07:13:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

[2010/02/26 16:37:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}

[2010/08/12 12:03:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dillon\Application Data\Windows Desktop Search

[2010/06/09 07:27:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Aura DVD Copy

[2010/06/08 22:13:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Aura4You

[2010/10/07 14:40:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\AVG10

[2010/05/09 12:00:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\AVG9

[2010/04/28 20:51:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Canon

[2010/12/14 00:13:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics

[2010/10/06 22:28:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Foxit

[2010/06/28 04:47:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Hemera

[2010/03/19 19:06:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ieSpell

[2010/08/28 16:22:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Intervideo

[2010/06/09 12:42:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\muvee Technologies

[2010/07/12 00:53:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Nova Development

[2010/03/12 14:43:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\OpenOffice.org

[2010/10/11 14:34:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\QuickScan

[2010/04/06 02:19:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SmartDraw

[2010/05/18 02:45:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template

[2010/04/08 23:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\TeraCopy

[2010/05/04 09:46:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Windows Desktop Search

[2010/10/26 03:55:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Windows Live Writer

[2010/05/07 10:46:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Windows Search

[2011/02/03 13:39:21 | 000,000,616 | -H-- | M] () -- C:\WINDOWS\Tasks\ConfigExec.job

[2011/02/04 03:15:01 | 000,000,580 | -H-- | M] () -- C:\WINDOWS\Tasks\DataUpload.job

[2011/02/04 17:52:08 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{3891B371-4764-4E88-93BB-89E9528A0B27}.job

========== Purity Check ==========

========== Files - Unicode (All) ==========

[2011/01/24 00:03:00 | 000,000,000 | ---- | M] ()(C:\Documents and Settings\Owner\?????) -- C:\Documents and Settings\Owner\?????

[2011/01/23 23:40:11 | 000,000,000 | ---- | C] ()(C:\Documents and Settings\Owner\?????) -- C:\Documents and Settings\Owner\?????

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\ipxroute.exe:SummaryInformation

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\ImgCache.pvi:SummaryInformation

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\command.com:SummaryInformation

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\Desktop\signons.sqlite:SummaryInformation

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\Desktop\New Text Document.txt:SummaryInformation

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\Desktop\getmsg.exe:SummaryInformation

@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96D0C06F

< End of report >

Link to post
Share on other sites

I had no idea there was so much junk still left on my laptop :)

...And the other log file:

* * * * * * *

OTL Extras logfile created on: 2/4/2011 5:51:10 PM - Run 1

OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Owner\Desktop

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 326.00 Mb Available Physical Memory | 32.00% Memory free

2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 74.52 Gb Total Space | 10.20 Gb Free Space | 13.69% Space Free | Partition Type: NTFS

Computer Name: OWNER-753D2803F | User Name: Owner | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 1

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

"1394:TCP" = 1394:TCP:*:Disabled:1394 Net Adapter

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management

"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech)

"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox -- (Mozilla Corporation)

"C:\Program Files\Yahoo!\browser\YBrowser.exe" = C:\Program Files\Yahoo!\browser\YBrowser.exe:*:Enabled:SBC Yahoo! DSL -- (Yahoo!, Inc.)

"C:\Program Files\Blockland\Blockland.exe" = C:\Program Files\Blockland\Blockland.exe:*:Disabled:Blockland -- ()

"C:\Program Files\Logitech\SetPoint\LogitechConnect.exe" = C:\Program Files\Logitech\SetPoint\LogitechConnect.exe:*:Disabled:Connect Utility -- (Logitech)

"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe:*:Disabled:Desktop Messenger -- (Logitech)

"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes -- (Apple Inc.)

"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger -- (Logitech)

"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)

"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger

"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe" = C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe:*:Disabled:MSN -- (Microsoft Corporation)

"C:\Program Files\Yahoo!\Common\ypostinstdsl.exe" = C:\Program Files\Yahoo!\Common\ypostinstdsl.exe:*:Disabled:SBC Yahoo! DSL Utilities -- (Yahoo!, inc.)

"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Disabled:Windows Live Sync -- (Microsoft Corporation)

"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{02E22217-0E96-4C3F-B831-83AA942B7715}" = UserGuides

"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module

"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant

"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended

"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel

"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer

"{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGearStarter

"{1CA2E5E4-F4FE-44B4-95E9-77523FB95838}" = EPSON Stylus Photo RX595 Series Scanner Driver Update

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool

"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus

"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT

"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java 6 Update 22

"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime

"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint

"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager

"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support

"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform

"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{379F9A64-4317-477A-BBC5-35466F8476B5}" = OpenOffice.org 3.2

"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile

"{3FF3DD04-F386-46B0-97FC-B86238B65487}" = Canon MP Drivers 6.0

"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works

"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 1.01 A3

"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH

Link to post
Share on other sites

Hi again,

First of all, please click here and scroll down to "Uninstalling BitDefender using the uninstall tool". Follow the steps there.

TWO ANTIVIRUS PROGRAMS

---------------------------------------

I do not recommend that you have more than one anti virus product installed and running on your computer at a time. The reason for this is that if both products have their automatic (Real-Time) protection switched on, then those products which do not encrypt the virus strings within them can cause other anti virus products to cause "false alarms". It can also lead to a clash as both products fight for access to files which are opened again this is the resident/automatic protection. In general terms, the two programs may conflict and cause:

  • False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
  • System Performance Problems: Your system may lock up due to both products attempting to access the same file at the same time.

Therefore please go to add/remove in the control panel and remove either AVG or Avira. I recommend you to keep Avira, but in the end that choice is up to you. :)

COMBOFIX

---------------

Please download ComboFix from one of these locations:

Bleepingcomputer
ForoSpyware

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures.

Query_RC.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC_successful.gif

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\Combofix.txt in your next reply.

Link to post
Share on other sites

Get your best exasperated *sigh* ready. Unfortunately, I think you might be using it in a minute. And I apologize for any further inconvenience. :):):)

Please don't hate me.

I'll explain...

I copied the first report in its entirety (it showed "No Results" with a sad face at the bottom) but I think I may have screwed it up. When I tried to close the first scan "Report" a prompt came up with, "Are you sure?" :) I wasn't. I had the report copied so I thought it would be safe for me to look at another folder. It was full of interesting information but I thought I'd better close the one I had copied before I did anymore snooping.

When I went back to the "Report" tab, the report was gone! I figured, no biggie, I still had it copied. Tried to paste what I was sure would be the original contents I thought I copied under the "Report" tab. Instead, the contents of the "Driver" tab (the one I had just looked at) saved to the Desktop. :)

I hope that explanation made sense and that I haven't inadvertently sabotaged the key to the solution.

After I saved that to my desktop, I tried to save the contents or results from the other tabs but I was prompted with an, "Unable to Copy" or something similar.

*NOTE: There were several "Hooked" files under one of the tabs but it would not let me save a copy of the entire paged report or the individual files. If you need them, I can go back and manually type the details for you. That is, if they are still showing.

So, I will paste what I did get copied in the order copied. The first was under the "Driver" tab file from first scan. The second is the "Report" tab results from the second scan, which, by the way, was a lot faster than the first scan.

:)

Again, I apologize for making this more work than it ought to be and I do thank you for your time. :)

~Deb

* * * * * * *

RkU Version: 3.8.388.590, Type LE (SR2)

==============================================

OS Name: Windows XP

Version 5.1.2600 (Service Pack 3)

Number of processors #1

==============================================

>Drivers

==============================================

0xBF0B2000 C:\WINDOWS\System32\ati3duag.dll 2367488 bytes (ATI Technologies Inc. , ati3duag.dll)

0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2189952 bytes (Microsoft Corporation, NT Kernel & System)

0x804D7000 PnpManager 2189952 bytes

0x804D7000 RAW 2189952 bytes

0x804D7000 WMIxWDM 2189952 bytes

0xBF800000 Win32k 1855488 bytes

0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver)

0xF6CC7000 C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 1392640 bytes (Broadcom Corporation, Broadcom 802.11 Network Adapter wireless driver)

0xF6E88000 C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 1331200 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver)

0xF6AA6000 C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 1040384 bytes (Conexant Systems, Inc., HSF_DP driver)

0xF69E9000 C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 704512 bytes (Conexant Systems, Inc., HSF_CNXT driver)

0xBF2F4000 C:\WINDOWS\System32\ativvaxx.dll 643072 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver)

0xF7689000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)

0xEE57A000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)

0xF6963000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)

0xEE7A5000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)

0xEB614000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver)

0xF6C1C000 C:\WINDOWS\system32\drivers\camc6hal.sys 348160 bytes (Conexant Systems Inc., Conexant AmcHal Driver)

0xF772D000 bdfsfltr.sys 323584 bytes (BitDefender, BitDefender AntiVirus FS filter driver)

0xEE725000 C:\WINDOWS\system32\DRIVERS\avgtdix.sys 294912 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher)

0xEB7FC000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)

0xEE468000 C:\WINDOWS\system32\DRIVERS\avgldx86.sys 245760 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver)

0xEE76D000 C:\WINDOWS\system32\DRIVERS\tcpip6.sys 229376 bytes (Microsoft Corporation, IPv6 driver)

0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 225280 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver)

0xBF07D000 C:\WINDOWS\System32\atikvmag.dll 217088 bytes (ATI Technologies Inc., Virtual Command And Memory Manager)

0xF6E1B000 C:\WINDOWS\system32\DRIVERS\SynTP.sys 217088 bytes (Synaptics, Inc., Synaptics Touchpad Driver)

0xBF049000 C:\WINDOWS\System32\ati2cqag.dll 212992 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module)

0xF6BA4000 C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys 200704 bytes (Conexant Systems, Inc., HSFHWATI WDM driver)

0xF7814000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)

0xEBB5D000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)

0xF765C000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)

0xB8B4C000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)

0xEE5EA000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)

0xEE637000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)

0xF6C9F000 C:\WINDOWS\system32\drivers\tifm21.sys 163840 bytes (Texas Instruments, tifm21.sys)

0xEE4F6000 C:\WINDOWS\system32\DRIVERS\avipbb.sys 155648 bytes (Avira GmbH, Avira Driver for Security Enhancement)

0xEE6FF000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)

0xF6BF8000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))

0xF6E50000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)

0xF6BD5000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)

0xEE615000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)

0x806EE000 ACPI_HAL 131840 bytes

0x806EE000 C:\WINDOWS\system32\hal.dll 131840 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)

0xF778E000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)

0xF77C6000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)

0xF77E5000 pcmcia.sys 122880 bytes (Microsoft Corporation, PCMCIA Bus Driver)

0xF7642000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)

0xF6C71000 C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 106496 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver )

0xF77AE000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)

0xEE400000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes

0xF7716000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)

0xF69D2000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))

0xEBFB5000 C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys 90112 bytes (Microsoft Corporation, NWLINK2 IPX Protocol Driver)

0xEC1AB000 C:\WINDOWS\system32\DRIVERS\avgntflt.sys 86016 bytes (Avira GmbH, Avira Minifilter Driver)

0xEBD70000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)

0xF6C8B000 C:\WINDOWS\system32\DRIVERS\sdbus.sys 81920 bytes (Microsoft Corporation, SecureDigital Bus Driver)

0xF6E74000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)

0xEE7FE000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)

0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)

0xF777C000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)

0xEE569000 C:\WINDOWS\system32\DRIVERS\LMouKE.Sys 69632 bytes (Logitech, Inc., Logitech Filter Driver for Mouse Class.)

0xF7803000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)

0xF69C1000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)

0xEE6CF000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)

0xF79C3000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)

0xF79E3000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager)

0xF7943000 C:\WINDOWS\system32\DRIVERS\nwlnknb.sys 65536 bytes (Microsoft Corporation, NWLINK2 IPX Netbios Protocol Driver)

0xF7873000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)

0xF78D3000 Serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)

0xF79A3000 C:\WINDOWS\system32\DRIVERS\AmdK8.sys 61440 bytes (Advanced Micro Devices, AMD Processor Driver)

0xF7913000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client)

0xF7A13000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)

0xF6FCD000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)

0xF7AB3000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)

0xF7883000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)

0xEBA95000 C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys 57344 bytes (Microsoft Corporation, NWLINK2 SPX Protocol Driver)

0xF78C3000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)

0xF79D3000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)

0xF7A23000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)

0xF78A3000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)

0xEC298000 C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 49152 bytes (Microsoft Corporation, Family Safety Filter Driver (TDI))

0xF7A43000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)

0xF700D000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)

0xF79B3000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)

0xF7893000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)

0xF7A33000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)

0xF7A03000 C:\WINDOWS\system32\drivers\camc6aud.sys 40960 bytes (Conexant Systems Inc., Conexant WDM AC97 Audio Driver)

0xF7863000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)

0xF7A83000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)

0xF7A73000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)

0xF78E3000 AVGIDSEH.Sys 36864 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Helper Driver.)

0xF78B3000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)

0xF6FED000 C:\WINDOWS\System32\Drivers\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)

0xF7AD3000 C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 36864 bytes (Microsoft Corporation, IPv6 Windows Firewall Driver)

0xF6FFD000 C:\WINDOWS\System32\Drivers\LHidUsbK.Sys 36864 bytes (Logitech, Inc., Logitech USB Mouse Function Driver.)

0xF7A53000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)

0xF705D000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)

0xBA2D8000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)

0xF7903000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)

0xF7C23000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver)

0xF7B23000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)

0xF7BFB000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)

0xF7B43000 C:\WINDOWS\System32\Drivers\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)

0xF7B63000 C:\WINDOWS\system32\DRIVERS\LHidKE.Sys 28672 bytes (Logitech, Inc., Logitech HID Filter Driver.)

0xF7C03000 C:\WINDOWS\System32\Drivers\MxlW2k.SYS 28672 bytes (MusicMatch, Inc., MusicMatch Access Layer KMD)

0xF7AE3000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)

0xF7C0B000 C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)

0xF7C13000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)

0xF7C1B000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)

0xF7B33000 C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 24576 bytes (Avira GmbH, AVIRA SnapShot Driver)

0xF7B13000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)

0xF7B1B000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)

0xF7AEB000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)

0xF7C33000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)

0xF7AF3000 PxHelp20.sys 20480 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)

0xF7C3B000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)

0xF7C2B000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)

0xF7BF3000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver)

0xF7C53000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)

0xF7C7B000 C:\WINDOWS\system32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver)

0xF72D0000 C:\WINDOWS\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)

0xF72D4000 C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys 16384 bytes (Logitech, Inc., Logitech PS2 Keyboard Filter Driver.)

0xF72B4000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)

0xEC0D3000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)

0xF7C7F000 ACPIEC.sys 12288 bytes (Microsoft Corporation, ACPI Embedded Controller Driver)

0xF7C73000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)

0xF7C77000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)

0xF75D9000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)

0xF7D37000 C:\WINDOWS\system32\drivers\iviaspi.sys 12288 bytes (InterVideo, Inc., InterVideo ASPI Shell)

0xEB68C000 C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 12288 bytes (Conexant, Diagnostic Interface DRIVER)

0xF75E1000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver)

0xF72C4000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)

0xF75F9000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)

0xF7D2B000 C:\WINDOWS\system32\DRIVERS\tunmp.sys 12288 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)

0xF7D2F000 C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI)

0xF7DD1000 C:\Program Files\Avira\AntiVir Desktop\avgio.sys 8192 bytes (Avira GmbH, Avira AntiVir Support for Minifilter)

0xF7E0D000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)

0xF7DD9000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes

0xF7E13000 C:\WINDOWS\system32\drivers\EABFiltr.sys 8192 bytes (Hewlett-Packard Company, QLB PS/2 Keyboard filter driver)

0xF7E0B000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)

0xF7D63000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)

0xF7E0F000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)

0xF7E11000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)

0xF7E03000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)

0xF7DF9000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)

0xF7D65000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)

0xF7EA2000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)

0xF7E9B000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)

0xF7F6C000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)

0xF7E2C000 C:\WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 4096 bytes (Microsoft Corporation, ACPI Operation Registration Driver)

0xF7E2B000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)

==============================================

>Stealth

==============================================

Link to post
Share on other sites

Dang! I just realized, it's the same thing! :) I'll try again. I'll go ahead and post this in case there is any discernible difference to your trained eyes.

**************

RkU Version: 3.8.388.590, Type LE (SR2)

==============================================

OS Name: Windows XP

Version 5.1.2600 (Service Pack 3)

Number of processors #1

==============================================

>Drivers

==============================================

0xBF0B2000 C:\WINDOWS\System32\ati3duag.dll 2367488 bytes (ATI Technologies Inc. , ati3duag.dll)

0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2189952 bytes (Microsoft Corporation, NT Kernel & System)

0x804D7000 PnpManager 2189952 bytes

0x804D7000 RAW 2189952 bytes

0x804D7000 WMIxWDM 2189952 bytes

0xBF800000 Win32k 1855488 bytes

0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver)

0xF6CC7000 C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 1392640 bytes (Broadcom Corporation, Broadcom 802.11 Network Adapter wireless driver)

0xF6E88000 C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 1331200 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver)

0xF6AA6000 C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 1040384 bytes (Conexant Systems, Inc., HSF_DP driver)

0xF69E9000 C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 704512 bytes (Conexant Systems, Inc., HSF_CNXT driver)

0xBF2F4000 C:\WINDOWS\System32\ativvaxx.dll 643072 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver)

0xF7689000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)

0xEE57A000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)

0xF6963000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)

0xEE7A5000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)

0xEB614000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver)

0xF6C1C000 C:\WINDOWS\system32\drivers\camc6hal.sys 348160 bytes (Conexant Systems Inc., Conexant AmcHal Driver)

0xF772D000 bdfsfltr.sys 323584 bytes (BitDefender, BitDefender AntiVirus FS filter driver)

0xEE725000 C:\WINDOWS\system32\DRIVERS\avgtdix.sys 294912 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher)

0xEB7FC000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)

0xEE468000 C:\WINDOWS\system32\DRIVERS\avgldx86.sys 245760 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver)

0xEE76D000 C:\WINDOWS\system32\DRIVERS\tcpip6.sys 229376 bytes (Microsoft Corporation, IPv6 driver)

0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 225280 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver)

0xBF07D000 C:\WINDOWS\System32\atikvmag.dll 217088 bytes (ATI Technologies Inc., Virtual Command And Memory Manager)

0xF6E1B000 C:\WINDOWS\system32\DRIVERS\SynTP.sys 217088 bytes (Synaptics, Inc., Synaptics Touchpad Driver)

0xBF049000 C:\WINDOWS\System32\ati2cqag.dll 212992 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module)

0xF6BA4000 C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys 200704 bytes (Conexant Systems, Inc., HSFHWATI WDM driver)

0xF7814000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)

0xEBB5D000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)

0xF765C000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)

0xB8B4C000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)

0xEE5EA000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)

0xEE637000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)

0xF6C9F000 C:\WINDOWS\system32\drivers\tifm21.sys 163840 bytes (Texas Instruments, tifm21.sys)

0xEE4F6000 C:\WINDOWS\system32\DRIVERS\avipbb.sys 155648 bytes (Avira GmbH, Avira Driver for Security Enhancement)

0xEE6FF000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)

0xF6BF8000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))

0xF6E50000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)

0xF6BD5000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)

0xEE615000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)

0x806EE000 ACPI_HAL 131840 bytes

0x806EE000 C:\WINDOWS\system32\hal.dll 131840 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)

0xF778E000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)

0xF77C6000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)

0xF77E5000 pcmcia.sys 122880 bytes (Microsoft Corporation, PCMCIA Bus Driver)

0xF7642000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)

0xF6C71000 C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 106496 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver )

0xF77AE000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)

0xEE400000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes

0xF7716000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)

0xF69D2000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))

0xEBFB5000 C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys 90112 bytes (Microsoft Corporation, NWLINK2 IPX Protocol Driver)

0xEC1AB000 C:\WINDOWS\system32\DRIVERS\avgntflt.sys 86016 bytes (Avira GmbH, Avira Minifilter Driver)

0xEBD70000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)

0xF6C8B000 C:\WINDOWS\system32\DRIVERS\sdbus.sys 81920 bytes (Microsoft Corporation, SecureDigital Bus Driver)

0xF6E74000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)

0xEE7FE000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)

0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)

0xF777C000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)

0xEE569000 C:\WINDOWS\system32\DRIVERS\LMouKE.Sys 69632 bytes (Logitech, Inc., Logitech Filter Driver for Mouse Class.)

0xF7803000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)

0xF69C1000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)

0xEE6CF000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)

0xF79C3000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)

0xF79E3000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager)

0xF7943000 C:\WINDOWS\system32\DRIVERS\nwlnknb.sys 65536 bytes (Microsoft Corporation, NWLINK2 IPX Netbios Protocol Driver)

0xF7873000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)

0xF78D3000 Serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)

0xF79A3000 C:\WINDOWS\system32\DRIVERS\AmdK8.sys 61440 bytes (Advanced Micro Devices, AMD Processor Driver)

0xF7913000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client)

0xF7A13000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)

0xF6FCD000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)

0xF7AB3000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)

0xF7883000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)

0xEBA95000 C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys 57344 bytes (Microsoft Corporation, NWLINK2 SPX Protocol Driver)

0xF78C3000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)

0xF79D3000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)

0xF7A23000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)

0xF78A3000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)

0xEC298000 C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 49152 bytes (Microsoft Corporation, Family Safety Filter Driver (TDI))

0xF7A43000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)

0xF700D000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)

0xF79B3000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)

0xF7893000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)

0xF7A33000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)

0xF7A03000 C:\WINDOWS\system32\drivers\camc6aud.sys 40960 bytes (Conexant Systems Inc., Conexant WDM AC97 Audio Driver)

0xF7863000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)

0xF7A83000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)

0xF7A73000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)

0xF78E3000 AVGIDSEH.Sys 36864 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Helper Driver.)

0xF78B3000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)

0xF6FED000 C:\WINDOWS\System32\Drivers\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)

0xF7AD3000 C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 36864 bytes (Microsoft Corporation, IPv6 Windows Firewall Driver)

0xF6FFD000 C:\WINDOWS\System32\Drivers\LHidUsbK.Sys 36864 bytes (Logitech, Inc., Logitech USB Mouse Function Driver.)

0xF7A53000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)

0xF705D000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)

0xB8FB1000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)

0xF7903000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)

0xF7C23000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver)

0xF7B23000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)

0xF7BFB000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)

0xF7B43000 C:\WINDOWS\System32\Drivers\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)

0xF7B63000 C:\WINDOWS\system32\DRIVERS\LHidKE.Sys 28672 bytes (Logitech, Inc., Logitech HID Filter Driver.)

0xF7C03000 C:\WINDOWS\System32\Drivers\MxlW2k.SYS 28672 bytes (MusicMatch, Inc., MusicMatch Access Layer KMD)

0xF7AE3000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)

0xF7C0B000 C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)

0xF7C13000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)

0xF7C1B000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)

0xF7B33000 C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 24576 bytes (Avira GmbH, AVIRA SnapShot Driver)

0xF7B13000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)

0xF7B1B000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)

0xF7AEB000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)

0xF7C33000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)

0xF7AF3000 PxHelp20.sys 20480 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)

0xF7C3B000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)

0xF7C2B000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)

0xF7BF3000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver)

0xF7C53000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)

0xF7C7B000 C:\WINDOWS\system32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver)

0xF72D0000 C:\WINDOWS\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)

0xF72D4000 C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys 16384 bytes (Logitech, Inc., Logitech PS2 Keyboard Filter Driver.)

0xF72B4000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)

0xEC0D3000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)

0xF7C7F000 ACPIEC.sys 12288 bytes (Microsoft Corporation, ACPI Embedded Controller Driver)

0xF7C73000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)

0xF7C77000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)

0xF75D9000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)

0xF7D37000 C:\WINDOWS\system32\drivers\iviaspi.sys 12288 bytes (InterVideo, Inc., InterVideo ASPI Shell)

0xEB68C000 C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 12288 bytes (Conexant, Diagnostic Interface DRIVER)

0xF75E1000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver)

0xF72C4000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)

0xF75F9000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)

0xF7D2B000 C:\WINDOWS\system32\DRIVERS\tunmp.sys 12288 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)

0xF7D2F000 C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI)

0xF7DD1000 C:\Program Files\Avira\AntiVir Desktop\avgio.sys 8192 bytes (Avira GmbH, Avira AntiVir Support for Minifilter)

0xF7E0D000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)

0xF7DD9000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes

0xF7E13000 C:\WINDOWS\system32\drivers\EABFiltr.sys 8192 bytes (Hewlett-Packard Company, QLB PS/2 Keyboard filter driver)

0xF7E0B000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)

0xF7D63000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)

0xF7E0F000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)

0xF7E11000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)

0xF7E03000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)

0xF7DF9000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)

0xF7D65000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)

0xF7EA2000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)

0xF7E9B000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)

0xF7F6C000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)

0xF7E2C000 C:\WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 4096 bytes (Microsoft Corporation, ACPI Operation Registration Driver)

0xF7E2B000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)

==============================================

>Stealth

==============================================

Link to post
Share on other sites

Hi Elise,

Here is the file from the Combofix scan and (repair?).

Time for me to catch some Zzzzz's. I'll check back in awhile.

Thanks again. :)

~Deb

============================

C:\ Combofix.txt

ComboFix 11-01-31.02 - Owner 02/06/2011 3:03.1.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.500 [GMT -8:00]

Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe

AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}

FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\docume~1\Owner\LOCALS~1\Temp\IadHide5.dll

c:\documents and settings\Owner\Local Settings\Temp\IadHide5.dll

c:\documents and settings\Owner\System

c:\documents and settings\Owner\System\win_qs8.jqx

C:\Thumbs.db

c:\windows\system32\command.pif

c:\windows\system32\drivers\etc\lmhosts

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_CDSYS

((((((((((((((((((((((((( Files Created from 2011-01-06 to 2011-02-06 )))))))))))))))))))))))))))))))

.

2011-02-06 07:19 . 2011-02-06 07:19 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Microsoft_Corporation

2011-02-03 23:25 . 2011-02-03 23:25 -------- d-----w- c:\program files\WOT

2011-02-02 06:47 . 2011-02-02 06:47 -------- dc----w- C:\refridgertor

2011-02-02 06:09 . 2011-02-02 06:09 -------- d-----w- c:\documents and settings\Owner\Application Data\Avira

2011-02-02 05:23 . 2011-01-10 22:23 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2011-02-02 05:23 . 2011-01-10 22:23 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys

2011-02-02 05:23 . 2010-06-17 22:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys

2011-02-02 05:23 . 2010-06-17 22:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys

2011-02-02 05:23 . 2011-02-02 05:23 -------- d-----w- c:\program files\Avira

2011-02-02 05:23 . 2011-02-02 05:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira

2011-02-01 06:11 . 2011-02-05 10:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware1

2011-01-23 06:34 . 2011-01-23 06:48 -------- d-----w- c:\program files\Windows Live Safety Center

2011-01-22 07:42 . 2011-01-23 11:58 -------- d-----w- c:\documents and settings\Administrator.OWNER-753D2803F.001

2011-01-22 04:36 . 2011-01-24 18:33 -------- d-----w- c:\documents and settings\Administrator.OWNER-753D2803F.000

2011-01-20 07:04 . 2011-01-20 07:04 -------- d-----w- c:\program files\MSSOAP

2011-01-20 06:16 . 2011-01-24 08:03 87189 ----a-w- c:\documents and settings\All Users\Application Data\bdinstall.bin

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-12-21 02:09 . 2010-02-27 00:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-12-21 02:08 . 2010-02-27 00:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\system32\GPhotos.scr

2010-11-30 01:38 . 2010-11-30 01:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx

2010-11-30 01:38 . 2010-11-30 01:38 69632 ----a-w- c:\windows\system32\QuickTime.qts

2010-11-18 18:12 . 2010-02-26 23:31 81920 ----a-w- c:\windows\system32\isign32.dll

2010-11-16 09:10 . 2010-11-16 09:10 65328 ----a-w- c:\windows\apppatch\matsshim.dll

2010-11-09 14:52 . 2008-04-14 11:00 249856 ----a-w- c:\windows\system32\odbc32.dll

2010-07-08 17:37 . 2010-07-08 17:37 101544 ----a-w- c:\program files\Common Files\LinkInstaller.exe

.

------- Sigcheck -------

[-] 2010-01-27 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2010-03-05 32768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-03-10 28160]

"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 794624]

"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]

"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-02-17 233534]

"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1015808]

"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-06-14 233472]

"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-21 53248]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

"Home Theater SchSvr"="c:\program files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2005-06-14 106496]

"AddressBookReminderApp"="c:\program files\Nova Development\Print Artist Platinum\ReminderApp.exe" [2009-08-31 144672]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-18 421160]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-12-25 421888]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]

c:\documents and settings\Owner\Start Menu\Programs\Startup\

Event Reminder.lnk - c:\program files\Mindscape\PrintMaster\PMREMIND.EXE [2010-4-6 325632]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-6-23 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2010-3-4 450560]

Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-3-4 438272]

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\Yahoo!\\browser\\YBrowser.exe"=

"c:\\Program Files\\Blockland\\Blockland.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\Logitech\\SetPoint\\LogitechConnect.exe"=

"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LDMConf.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=

"c:\\WINDOWS\\system32\\sessmgr.exe"=

"c:\\Program Files\\MSN\\MSNCoreFiles\\Install\\msnsusii.exe"=

"c:\\Program Files\\Yahoo!\\Common\\ypostinstdsl.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"1394:TCP"= 1394:TCP:*:Disabled:1394 Net Adapter

"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

"AllowInboundEchoRequest"= 1 (0x1)

"AllowInboundTimestampRequest"= 1 (0x1)

"AllowInboundMaskRequest"= 1 (0x1)

"AllowInboundRouterRequest"= 1 (0x1)

"AllowOutboundDestinationUnreachable"= 1 (0x1)

"AllowOutboundSourceQuench"= 1 (0x1)

"AllowOutboundParameterProblem"= 1 (0x1)

"AllowOutboundTimeExceeded"= 1 (0x1)

"AllowRedirect"= 0 (0x0)

"AllowOutboundPacketTooBig"= 1 (0x1)

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2/1/2011 9:23 PM 135336]

R2 mstbsvc;MSN Toolbar Setup;c:\program files\MSN\Toolbar\4.0.0412.0\mstbsvc.exe [4/6/2010 2:34 PM 102752]

R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [5/23/2010 12:50 PM 200192]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]

S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [11/16/2010 1:10 AM 267568]

S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/14/2008 3:00 AM 14336]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

WINRM REG_MULTI_SZ WINRM

.

Contents of the 'Scheduled Tasks' folder

2010-12-21 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]

2011-02-06 c:\windows\Tasks\ConfigExec.job

- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-11-16 09:09]

2011-02-06 c:\windows\Tasks\DataUpload.job

- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-11-16 09:09]

2011-02-06 c:\windows\Tasks\User_Feed_Synchronization-{3891B371-4764-4E88-93BB-89E9528A0B27}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://google.com/

uInternet Settings,ProxyServer = 192.168.1.10:3128

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://rd.yahoo.com/customize/sbcydsl/defaults/su/*http://www.yahoo.com

IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM

IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM

Trusted Zone: microsoft.com\office

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\

FF - prefs.js: browser.search.selectedEngine - AVG Secure Search

FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cb38761&v=6.011.025.001&i=26&tp=ab&iy=&ychte=us&lng=en-US&q=

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

FF - Ext: Dynamite Deals: ddfirefox@dynamitedata - %profile%\extensions\ddfirefox@dynamitedata

FF - Ext: PriceBlink: info@priceblink.com - %profile%\extensions\info@priceblink.com

FF - Ext: Behind The *Asterisks* (EladKarako Mod): {38abe53c-d79f-8e86-9673-57c449674c5e} - %profile%\extensions\{38abe53c-d79f-8e86-9673-57c449674c5e}

FF - Ext: CacheViewer: {71328583-3CA7-4809-B4BA-570A85818FBB} - %profile%\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}

FF - Ext: PriceTrace: {72938f90-8d8a-11de-8a39-0800200c9a66} - %profile%\extensions\{72938f90-8d8a-11de-8a39-0800200c9a66}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff

.

- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

MSConfigStartUp-CTFMON - (no file)

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-02-06 03:20

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????6?0?1?8??????? ???B?????????????hLC? ??????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1085031214-1336601894-1417001333-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1085031214-1336601894-1417001333-1003\Software\Microsoft\VSTA\9.0\TaskList\Options\UNDONE]

@Denied: (Full) (Administrators)

"Priority"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1056)

c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(4016)

c:\windows\system32\WININET.dll

c:\program files\Logitech\SetPoint\lgscroll.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll

c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\Ati2evxx.exe

c:\windows\system32\Ati2evxx.exe

c:\windows\system32\netdde.exe

c:\windows\system32\msdtc.exe

c:\program files\Avira\AntiVir Desktop\avguard.exe

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe

c:\program files\Avira\AntiVir Desktop\avshadow.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\windows\system32\dllhost.exe

c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE

c:\program files\Windows Live\Family Safety\fsssvc.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\Motive\McciCMService.exe

c:\windows\system32\msiexec.exe

c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe

c:\windows\system32\sessmgr.exe

c:\windows\system32\locator.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\windows\system32\SearchIndexer.exe

c:\program files\Windows Media Player\WMPNetwk.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\windows\system32\wscntfy.exe

c:\program files\iPod\bin\iPodService.exe

c:\windows\TEMP\InstallManager_Sun_Sun.exe

c:\program files\HPQ\SHARED\HPQWMI.exe

.

**************************************************************************

.

Completion time: 2011-02-06 03:26:57 - machine was rebooted

ComboFix-quarantined-files.txt 2011-02-06 11:26

Pre-Run: 11,303,903,232 bytes free

Post-Run: 12,407,689,216 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /Execute=OptIn

- - End Of File - - 006F656F61103ED24CA69AF7117D62F1

Link to post
Share on other sites

Hi Elise.

Yes, I have the XP OS SP2 CD and the Application and Recovery CD that came with the laptop at the ready.

In the mean time the Avira AntiVir, Luke Filewalker scanned. I don't know if it offers any additional or helpful information that you haven't already seen, but it won't let me save the report. I realize that it states in the Malwarebytes Rules that we should not post what we are not asked to post so I'll copy and paste the warnings, errors, and if I can, the report into a PM, or draft in case it offers anything useful.

~Deb

Link to post
Share on other sites

Hi Again Elise,

Ugh! I just typed an entire explanation to have it vanish! I'll try again...

My computer would not run the sfc/scanner prompting an error stating it could not "find" sfc/scanner. I tried to execute it from command but it would not recognize the command. (I could have had the beginning of the command text wrong) Went back to the Start menu, clicked "Run" and tried again. Didn't work. Noticed that after I clicked "Run" from the Start Menu the word "Run" had been replaced by the word, "Search" so I typed "run sfc /scanner" in the box and it, or something started and prompted me for the XP SP3 Disk.

After inserting the XP CD as prompted (I have SP2, not SP3 on disk), I attempted to run Combofix as you prescribed. The original Combofix that I downloaded to my desktop was blocked, I assumed by the security program that rebooted with the computer after the first Combofix run, thinking, perhaps, it had been corrupted. So, I deleted it. I attempted to download the program again from the links you provided but was not taken to Bleeping Computer as I had been the first time. The program began downloading anyway and I couldn't cancel it. That seemed fishy so after it finished, I deleted that one too.

I tried the second link. I was taken to what looked like it could have been the right site but was immediately prompted with a "New Version" available. I tried to verify the web page. I couldn't be sure but it appeared to have similar text held by the redirected pages from a few days ago so I canceled it and an error message popped up referring to not being able to process outdated download and downloaded anyway. The download size was larger than the file originally indicated. I don't know if that's typical or not but it didn't seem right.

I deleted that one and went back to the Recycle Bin to retrieve the original Combofix download from Feb 5. Restored, unblocked, and ran it. Almost simultaneously, another ComboFix began to download followed by a prompt that my ComboFix appeared to be corrupt. I ran the original ComboFix again, or at least I think that's the one ran. I'm not so sure now though because like the first time, it unzipped a new restore point. A clear box quickly unzipped a dark, maroon colored bar horizontally across my screen with a bunch of files beginning with "Hiv" followed immediately by a dark blue bar unzipping below it. I remember the two bars unzipping before but I don't remember the dark red or maroon colors, nor the "Hiv" files. I fear I may have just made matters worse and prolonged this nightmare.

*Note: On 02/26/2010, my laptop was returned to me, clean from the shop after a costly repair due to another virus or malware attack.

Lately, every time I make a new document or a log is created, I am prompted with "Text in the Document Has Changed. Would you like to save the changes?" before I've even closed the file and upon closing any log or report that I open. I always click, "No" or "Don't Save Changes" unless I have actually changed something. Also, I am sharring files I don't want to share and am unable to unshare them with the option to make private shaded out. However, I have not checked this since the latest scan.

Since the scan, I notice that I now have "Windows PowerShell ISE" on the Start Menu.

There you have it - the gory details and the resulting report, (also gory) copied and pasted below:

================================================================================

===========

Link to post
Share on other sites

ComboFix 11-02-07.05 - Owner 02/08/2011 8:24.2.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.621 [GMT -8:00]

Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe

AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}

FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}

.

((((((((((((((((((((((((( Files Created from 2011-01-08 to 2011-02-08 )))))))))))))))))))))))))))))))

.

2011-02-08 14:08 . 2008-04-14 13:42 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll

2011-02-08 14:08 . 2001-08-18 06:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll

2011-02-08 14:08 . 2008-04-14 13:42 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll

2011-02-08 14:08 . 2001-08-18 06:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe

2011-02-08 14:08 . 2001-08-18 06:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe

2011-02-08 14:08 . 2001-08-18 06:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe

2011-02-08 14:08 . 2001-08-17 20:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys

2011-02-08 14:08 . 2008-04-14 06:04 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys

2011-02-08 14:08 . 2008-04-14 06:04 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys

2011-02-08 14:08 . 2008-04-14 13:42 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll

2011-02-08 14:07 . 2008-04-14 06:05 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys

2011-02-08 14:07 . 2001-08-17 20:12 34890 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys

2011-02-08 14:07 . 2001-08-17 21:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys

2011-02-08 14:07 . 2001-08-18 06:36 53760 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll

2011-02-08 14:05 . 2001-08-17 21:28 397502 -c--a-w- c:\windows\system32\dllcache\vpctcom.sys

2011-02-08 14:05 . 2001-08-17 21:28 604253 -c--a-w- c:\windows\system32\dllcache\vmodem.sys

2011-02-08 14:05 . 2001-08-17 20:14 249402 -c--a-w- c:\windows\system32\dllcache\vinwm.sys

2011-02-08 14:05 . 2001-08-17 21:49 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys

2011-02-08 14:05 . 2008-04-14 08:10 5376 -c--a-w- c:\windows\system32\dllcache\viaide.sys

2011-02-08 14:05 . 2008-04-14 08:06 42240 -c--a-w- c:\windows\system32\dllcache\viaagp.sys

2011-02-08 14:05 . 2008-04-14 13:42 11325 -c--a-w- c:\windows\system32\dllcache\vchnt5.dll

2011-02-08 14:05 . 2001-08-17 21:28 687999 -c--a-w- c:\windows\system32\dllcache\usrwdxjs.sys

2011-02-08 14:05 . 2001-08-17 21:28 765884 -c--a-w- c:\windows\system32\dllcache\usrti.sys

2011-02-08 14:05 . 2001-08-17 21:28 113762 -c--a-w- c:\windows\system32\dllcache\usrpda.sys

2011-02-08 14:05 . 2001-08-17 21:28 7556 -c--a-w- c:\windows\system32\dllcache\usroslba.sys

2011-02-08 14:05 . 2001-08-17 21:28 224802 -c--a-w- c:\windows\system32\dllcache\usr1807a.sys

2011-02-08 14:05 . 2001-08-17 21:28 794399 -c--a-w- c:\windows\system32\dllcache\usr1806v.sys

2011-02-08 14:03 . 2001-08-17 21:52 36736 -c--a-w- c:\windows\system32\dllcache\ultra.sys

2011-02-08 14:02 . 2001-08-17 21:51 4992 -c--a-w- c:\windows\system32\dllcache\toside.sys

2011-02-08 14:01 . 2001-08-17 21:52 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys

2011-02-08 14:00 . 2001-08-18 06:36 53248 -c--a-w- c:\windows\system32\dllcache\stlncoin.dll

2011-02-08 14:00 . 2001-08-17 20:18 285760 -c--a-w- c:\windows\system32\dllcache\stlnata.sys

2011-02-08 14:00 . 2001-08-17 21:51 16896 -c--a-w- c:\windows\system32\dllcache\stcusb.sys

2011-02-08 14:00 . 2001-08-17 20:11 48736 -c--a-w- c:\windows\system32\dllcache\srwlnd5.sys

2011-02-08 14:00 . 2008-04-14 11:00 101376 -c--a-w- c:\windows\system32\dllcache\OLD8D1.tmp

2011-02-08 14:00 . 2001-08-18 06:36 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll

2011-02-08 14:00 . 2001-08-18 06:36 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll

2011-02-08 14:00 . 2001-08-17 21:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys

2011-02-08 14:00 . 2001-08-18 06:36 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll

2011-02-08 14:00 . 2001-08-17 22:07 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys

2011-02-08 13:58 . 2001-08-17 21:57 6784 -c--a-w- c:\windows\system32\dllcache\smbhc.sys

2011-02-08 13:57 . 2001-08-17 22:56 252032 -c--a-w- c:\windows\system32\dllcache\sis300iv.dll

2011-02-08 13:57 . 2008-04-14 11:00 18944 -c--a-w- c:\windows\system32\dllcache\OLD819.tmp

2011-02-08 13:57 . 2001-08-17 20:50 101760 -c--a-w- c:\windows\system32\dllcache\sis300ip.sys

2011-02-08 13:57 . 2008-04-14 13:42 3901 -c--a-w- c:\windows\system32\dllcache\siint5.dll

2011-02-08 13:57 . 2001-07-21 22:29 161568 -c--a-w- c:\windows\system32\dllcache\sgsmusb.sys

2011-02-08 13:57 . 2001-07-21 22:29 18400 -c--a-w- c:\windows\system32\dllcache\sgsmld.sys

2011-02-08 13:57 . 2001-08-17 20:51 98080 -c--a-w- c:\windows\system32\dllcache\sgiulnt5.sys

2011-02-08 13:57 . 2001-08-18 06:36 386560 -c--a-w- c:\windows\system32\dllcache\sgiul50.dll

2011-02-08 13:57 . 2001-08-17 20:19 36480 -c--a-w- c:\windows\system32\dllcache\sfmanm.sys

2011-02-08 13:57 . 2001-08-17 21:53 6784 -c--a-w- c:\windows\system32\dllcache\serscan.sys

2011-02-08 13:55 . 2001-08-17 22:56 245632 -c--a-w- c:\windows\system32\dllcache\s3savmx.dll

2011-02-08 13:54 . 2001-08-17 20:19 30720 -c--a-w- c:\windows\system32\dllcache\rthwcls.sys

2011-02-08 13:54 . 2001-08-18 06:36 9216 -c--a-w- c:\windows\system32\dllcache\rsmgrstr.dll

2011-02-08 13:54 . 2001-08-17 20:19 3840 -c--a-w- c:\windows\system32\dllcache\rpfun.sys

2011-02-08 13:54 . 2008-04-14 08:10 79104 -c--a-w- c:\windows\system32\dllcache\rocket.sys

2011-02-08 13:54 . 2008-04-14 08:26 30592 -c--a-w- c:\windows\system32\dllcache\rndismpx.sys

2011-02-08 13:54 . 2001-08-17 20:12 37563 -c--a-w- c:\windows\system32\dllcache\rlnet5.sys

2011-02-08 13:54 . 2008-04-14 08:16 59136 -c--a-w- c:\windows\system32\dllcache\rfcomm.sys

2011-02-08 13:54 . 2001-08-18 06:36 86097 -c--a-w- c:\windows\system32\dllcache\reslog32.dll

2011-02-08 13:54 . 2001-08-18 06:36 23040 -c--a-w- c:\windows\system32\dllcache\OLD7A7.tmp

2011-02-08 13:54 . 2008-04-14 11:00 14848 -c--a-w- c:\windows\system32\dllcache\OLD7A3.tmp

2011-02-08 13:54 . 2008-04-14 07:53 13776 -c--a-w- c:\windows\system32\dllcache\recagent.sys

2011-02-08 13:52 . 2001-08-18 06:36 5632 -c--a-w- c:\windows\system32\dllcache\ptpusb.dll

2011-02-08 13:51 . 2001-08-17 22:07 5504 -c--a-w- c:\windows\system32\dllcache\perc2hib.sys

2011-02-08 13:50 . 2001-08-17 22:05 31872 -c--a-w- c:\windows\system32\dllcache\ovce.sys

2011-02-08 13:49 . 2001-08-17 21:47 9344 -c--a-w- c:\windows\system32\dllcache\ntapm.sys

2011-02-08 13:49 . 2001-08-17 21:53 7552 -c--a-w- c:\windows\system32\dllcache\nsmmc.sys

2011-02-08 13:49 . 2008-04-14 08:24 28672 -c--a-w- c:\windows\system32\dllcache\nscirda.sys

2011-02-08 13:49 . 2001-08-17 20:20 87040 -c--a-w- c:\windows\system32\dllcache\nm6wdm.sys

2011-02-08 13:49 . 2001-08-17 20:20 126080 -c--a-w- c:\windows\system32\dllcache\nm5a2wdm.sys

2011-02-08 13:49 . 2001-08-17 20:12 32840 -c--a-w- c:\windows\system32\dllcache\ngrpci.sys

2011-02-08 13:49 . 2008-04-14 06:05 132695 -c--a-w- c:\windows\system32\dllcache\netwlan5.sys

2011-02-08 13:49 . 2001-08-17 20:11 65278 -c--a-w- c:\windows\system32\dllcache\netflx3.sys

2011-02-08 13:49 . 2001-08-17 20:50 39264 -c--a-w- c:\windows\system32\dllcache\neo20xx.sys

2011-02-08 13:49 . 2001-08-18 06:36 60480 -c--a-w- c:\windows\system32\dllcache\neo20xx.dll

2011-02-08 13:49 . 2001-08-17 21:49 15872 -c--a-w- c:\windows\system32\dllcache\ne2000.sys

2011-02-08 13:49 . 2001-08-17 22:56 91488 -c--a-w- c:\windows\system32\dllcache\n9i3disp.dll

2011-02-08 13:47 . 2008-04-14 08:16 49024 -c--a-w- c:\windows\system32\dllcache\mstape.sys

2011-02-08 13:47 . 2001-08-17 21:48 12416 -c--a-w- c:\windows\system32\dllcache\msriffwv.sys

2011-02-08 13:47 . 2001-08-17 22:00 2944 -c--a-w- c:\windows\system32\dllcache\msmpu401.sys

2011-02-08 13:47 . 2008-04-14 11:00 1875968 -c--a-w- c:\windows\system32\dllcache\OLD68D.tmp

2011-02-08 13:47 . 2008-04-14 08:24 22016 -c--a-w- c:\windows\system32\dllcache\msircomm.sys

2011-02-08 13:47 . 2008-04-14 11:00 98304 -c--a-w- c:\windows\system32\dllcache\OLD68A.tmp

2011-02-08 13:47 . 2001-08-17 22:02 35200 -c--a-w- c:\windows\system32\dllcache\msgame.sys

2011-02-08 13:47 . 2001-08-17 21:48 6016 -c--a-w- c:\windows\system32\dllcache\msfsio.sys

2011-02-08 13:47 . 2008-04-14 08:16 51200 -c--a-w- c:\windows\system32\dllcache\msdv.sys

2011-02-08 13:46 . 2001-08-17 21:52 17280 -c--a-w- c:\windows\system32\dllcache\mraid35x.sys

2011-02-08 13:46 . 2008-04-14 08:16 15232 -c--a-w- c:\windows\system32\dllcache\mpe.sys

2011-02-08 13:46 . 2001-08-17 21:57 16128 -c--a-w- c:\windows\system32\dllcache\modemcsa.sys

2011-02-08 13:46 . 2001-08-17 21:52 6528 -c--a-w- c:\windows\system32\dllcache\miniqic.sys

2011-02-08 13:46 . 2008-04-14 11:00 34304 -c--a-w- c:\windows\system32\dllcache\OLD674.tmp

2011-02-08 13:46 . 2001-08-17 20:50 320384 -c--a-w- c:\windows\system32\dllcache\mgaum.sys

2011-02-08 13:46 . 2008-04-14 11:00 92416 -c--a-w- c:\windows\system32\dllcache\OLD66D.tmp

2011-02-08 13:46 . 2001-08-17 22:56 235648 -c--a-w- c:\windows\system32\dllcache\mgaud.dll

2011-02-08 13:46 . 2008-04-14 11:00 92032 -c--a-w- c:\windows\system32\dllcache\OLD66A.tmp

2011-02-08 13:46 . 2008-04-14 08:11 26112 -c--a-w- c:\windows\system32\dllcache\memstpci.sys

2011-02-08 13:46 . 2001-08-18 06:36 47616 -c--a-w- c:\windows\system32\dllcache\memgrp.dll

2011-02-08 13:46 . 2001-08-17 21:58 8320 -c--a-w- c:\windows\system32\dllcache\memcard.sys

2011-02-08 13:44 . 2001-08-17 21:51 15744 -c--a-w- c:\windows\system32\dllcache\lit220p.sys

2011-02-08 13:43 . 2001-08-17 22:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll

2011-02-08 13:42 . 2008-04-14 11:00 196665 -c--a-w- c:\windows\system32\dllcache\OLD560.tmp

2011-02-08 13:41 . 2001-08-17 20:11 28700 -c--a-w- c:\windows\system32\dllcache\ibmexmp.sys

2011-02-08 13:40 . 2001-08-17 21:28 57471 -c--a-w- c:\windows\system32\dllcache\hsf_samp.sys

2011-02-08 13:39 . 2001-08-18 06:36 119296 -c--a-w- c:\windows\system32\dllcache\hpdigwia.dll

2011-02-08 13:38 . 2008-04-14 11:00 11264 -c--a-w- c:\windows\system32\dllcache\OLD478.tmp

2011-02-08 13:37 . 2001-08-17 20:12 24618 -c--a-w- c:\windows\system32\dllcache\fa410nd5.sys

2011-02-08 13:36 . 2001-08-17 20:17 629952 -c--a-w- c:\windows\system32\dllcache\eqn.sys

2011-02-08 13:35 . 2001-08-17 22:07 20192 -c--a-w- c:\windows\system32\dllcache\dpti2o.sys

2011-02-08 13:34 . 2001-08-17 20:11 20928 -c--a-w- c:\windows\system32\dllcache\defpa.sys

2011-02-08 13:33 . 2001-08-17 20:11 39936 -c--a-w- c:\windows\system32\dllcache\cnxt1803.sys

2011-02-08 13:32 . 2001-08-17 21:51 13824 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys

2011-02-08 13:31 . 2001-08-17 20:49 26624 -c--a-w- c:\windows\system32\dllcache\ativxbar.sys

2011-02-08 13:30 . 2008-04-14 13:41 3967 -c--a-w- c:\windows\system32\dllcache\adv02nt5.dll

2011-02-08 13:29 . 2001-08-17 22:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll

2011-02-08 13:18 . 2011-02-08 13:18 -------- d-----r- C:\MSOCache

2011-02-06 11:20 . 2011-02-06 11:21 -------- d-----w- c:\program files\MSN Toolbar Installer

2011-02-06 07:19 . 2011-02-06 07:19 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Microsoft_Corporation

2011-02-03 23:25 . 2011-02-03 23:25 -------- d-----w- c:\program files\WOT

2011-02-02 06:47 . 2011-02-02 06:47 -------- dc----w- C:\refridgertor

2011-02-02 06:09 . 2011-02-02 06:09 -------- d-----w- c:\documents and settings\Owner\Application Data\Avira

2011-02-02 05:23 . 2011-01-10 22:23 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2011-02-02 05:23 . 2011-01-10 22:23 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys

2011-02-02 05:23 . 2010-06-17 22:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys

2011-02-02 05:23 . 2010-06-17 22:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-12-21 02:09 . 2010-02-27 00:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-12-21 02:08 . 2010-02-27 00:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\system32\GPhotos.scr

2010-11-30 01:38 . 2010-11-30 01:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx

2010-11-30 01:38 . 2010-11-30 01:38 69632 ----a-w- c:\windows\system32\QuickTime.qts

2010-11-18 18:12 . 2010-02-26 23:31 81920 ----a-w- c:\windows\system32\isign32.dll

2010-11-16 09:10 . 2010-11-16 09:10 65328 ----a-w- c:\windows\apppatch\matsshim.dll

2010-07-08 17:37 . 2010-07-08 17:37 101544 ----a-w- c:\program files\Common Files\LinkInstaller.exe

.

------- Sigcheck -------

[-] 2010-01-27 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

Link to post
Share on other sites

((((((((((((((((((((((((((((( SnapShot@2011-02-06_11.17.56 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-04-14 05:42 . 2008-04-14 11:00 52736 c:\windows\system32\dllcache\wzcsapi.dll

+ 2010-02-26 23:31 . 2009-08-07 03:24 53472 c:\windows\system32\dllcache\wuauclt.exe

+ 2011-02-08 14:06 . 2001-08-18 06:36 87040 c:\windows\system32\dllcache\wiafbdrv.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 13600 c:\windows\system32\dllcache\wfwnet.drv

- 2010-02-26 15:01 . 2008-04-14 11:00 13600 c:\windows\system32\dllcache\wfwnet.drv

- 2010-02-26 23:37 . 2008-04-14 11:00 31232 c:\windows\system32\dllcache\weitekp9.sys

+ 2010-02-26 23:37 . 2004-08-04 12:00 31232 c:\windows\system32\dllcache\weitekp9.sys

- 2010-02-26 23:37 . 2008-04-14 11:00 41600 c:\windows\system32\dllcache\weitekp9.dll

+ 2010-02-26 23:37 . 2004-08-04 12:00 41600 c:\windows\system32\dllcache\weitekp9.dll

+ 2011-02-08 14:06 . 2008-04-14 06:04 23615 c:\windows\system32\dllcache\wch7xxnt.sys

+ 2011-02-08 14:06 . 2008-04-14 08:15 31744 c:\windows\system32\dllcache\wceusbsh.sys

+ 2011-02-08 14:06 . 2001-08-17 20:10 35871 c:\windows\system32\dllcache\wbfirdma.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 25471 c:\windows\system32\dllcache\watv10nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 22271 c:\windows\system32\dllcache\watv06nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 33599 c:\windows\system32\dllcache\watv04nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 19551 c:\windows\system32\dllcache\watv02nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 29311 c:\windows\system32\dllcache\watv01nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 11935 c:\windows\system32\dllcache\wadv11nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 11871 c:\windows\system32\dllcache\wadv09nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 11295 c:\windows\system32\dllcache\wadv08nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 11807 c:\windows\system32\dllcache\wadv07nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 11775 c:\windows\system32\dllcache\wadv05nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 12127 c:\windows\system32\dllcache\wadv02nt.sys

+ 2011-02-08 14:06 . 2008-04-14 06:04 12415 c:\windows\system32\dllcache\wadv01nt.sys

+ 2011-02-08 14:06 . 2008-04-14 08:13 14208 c:\windows\system32\dllcache\wacompen.sys

+ 2011-02-08 14:06 . 2001-08-17 20:13 16925 c:\windows\system32\dllcache\w940nd.sys

+ 2011-02-08 14:06 . 2001-08-17 20:13 19016 c:\windows\system32\dllcache\w926nd.sys

+ 2011-02-08 14:06 . 2001-08-17 20:13 19528 c:\windows\system32\dllcache\w840nd.sys

- 2010-02-26 23:37 . 2008-04-14 11:00 48256 c:\windows\system32\dllcache\w32.dll

+ 2010-02-26 23:37 . 2004-08-04 12:00 48256 c:\windows\system32\dllcache\w32.dll

+ 2011-02-08 14:06 . 2001-08-17 21:28 64605 c:\windows\system32\dllcache\vvoice.sys

+ 2001-08-17 14:02 . 2008-04-14 11:00 58112 c:\windows\system32\dllcache\vdmindvd.sys

+ 2001-08-17 22:36 . 2008-04-14 11:00 45116 c:\windows\system32\dllcache\usrvoica.dll

+ 2001-08-17 22:36 . 2008-04-14 11:00 49209 c:\windows\system32\dllcache\usrv80a.dll

+ 2001-08-17 22:36 . 2008-04-14 11:00 41019 c:\windows\system32\dllcache\usrsvpia.dll

+ 2001-08-17 22:37 . 2008-04-14 11:00 69700 c:\windows\system32\dllcache\usrshuta.exe

+ 2001-08-17 22:36 . 2008-04-14 11:00 49211 c:\windows\system32\dllcache\usrsdpia.dll

+ 2001-08-17 22:36 . 2008-04-14 11:00 77883 c:\windows\system32\dllcache\usrrtosa.dll

+ 2001-08-17 22:37 . 2008-04-14 11:00 61508 c:\windows\system32\dllcache\usrprbda.exe

+ 2001-08-17 22:36 . 2008-04-14 11:00 53305 c:\windows\system32\dllcache\usrlbva.dll

+ 2001-08-17 22:36 . 2008-04-14 11:00 77890 c:\windows\system32\dllcache\usrdpa.dll

+ 2001-08-17 22:36 . 2008-04-14 11:00 61500 c:\windows\system32\dllcache\usrcntra.dll

+ 2011-02-08 14:04 . 2008-04-14 08:15 20608 c:\windows\system32\dllcache\usbuhci.sys

+ 2011-02-08 14:04 . 2008-04-14 08:15 26112 c:\windows\system32\dllcache\usbser.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 17152 c:\windows\system32\dllcache\usbohci.sys

+ 2008-04-14 00:15 . 2008-04-14 11:00 15872 c:\windows\system32\dllcache\usbintel.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 59520 c:\windows\system32\dllcache\usbhub.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 30208 c:\windows\system32\dllcache\usbehci.sys

+ 2008-04-14 00:15 . 2008-04-14 11:00 25728 c:\windows\system32\dllcache\usbcamd2.sys

+ 2008-04-14 00:15 . 2008-04-14 11:00 25600 c:\windows\system32\dllcache\usbcamd.sys

+ 2011-02-08 14:04 . 2008-04-14 08:26 12800 c:\windows\system32\dllcache\usb8023x.sys

+ 2011-02-08 14:04 . 2008-04-14 06:05 32384 c:\windows\system32\dllcache\usb101et.sys

+ 2011-02-08 14:04 . 2001-08-18 06:36 94720 c:\windows\system32\dllcache\umaxud32.dll

+ 2011-02-08 14:04 . 2001-08-18 06:36 28160 c:\windows\system32\dllcache\umaxu40.dll

+ 2011-02-08 14:04 . 2001-08-18 06:36 26624 c:\windows\system32\dllcache\umaxu22.dll

+ 2011-02-08 14:04 . 2001-08-18 06:36 69632 c:\windows\system32\dllcache\umaxu12.dll

+ 2011-02-08 14:04 . 2001-08-18 06:36 50688 c:\windows\system32\dllcache\umaxscan.dll

+ 2011-02-08 14:04 . 2001-08-17 21:58 22912 c:\windows\system32\dllcache\umaxpcls.sys

+ 2011-02-08 14:04 . 2001-08-18 06:36 50176 c:\windows\system32\dllcache\umaxp60.dll

+ 2011-02-08 14:04 . 2001-08-18 06:36 47616 c:\windows\system32\dllcache\umaxcam.dll

+ 2011-02-08 14:03 . 2008-04-14 08:06 44672 c:\windows\system32\dllcache\uagp35.sys

+ 2011-02-08 14:03 . 2001-08-17 21:48 11520 c:\windows\system32\dllcache\twotrack.sys

+ 2008-04-14 00:26 . 2008-04-14 11:00 12288 c:\windows\system32\dllcache\tunmp.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 14336 c:\windows\system32\dllcache\tsprof.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\tsprof.exe

+ 2001-08-17 14:06 . 2008-04-14 11:00 21376 c:\windows\system32\dllcache\tsbvcap.sys

+ 2011-02-08 14:03 . 2001-08-17 20:12 34375 c:\windows\system32\dllcache\tpro4.sys

+ 2011-02-08 14:03 . 2001-08-18 06:35 42496 c:\windows\system32\dllcache\tp4res.dll

+ 2011-02-08 14:03 . 2008-04-14 13:42 82944 c:\windows\system32\dllcache\tp4mon.exe

+ 2011-02-08 14:03 . 2001-08-18 06:36 31744 c:\windows\system32\dllcache\tp4.dll

+ 2001-08-17 14:01 . 2008-04-14 11:00 51712 c:\windows\system32\dllcache\tosdvd.sys

+ 2011-02-08 14:02 . 2001-08-17 20:10 28232 c:\windows\system32\dllcache\tos4mo.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 44032 c:\windows\system32\dllcache\tintlphr.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 44032 c:\windows\system32\dllcache\tintlphr.exe

+ 2011-02-08 14:02 . 2001-08-17 22:56 81408 c:\windows\system32\dllcache\tgiul50.dll

+ 2010-02-26 23:28 . 2008-04-14 13:43 40840 c:\windows\system32\dllcache\termdd.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 19464 c:\windows\system32\dllcache\tdspx.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 19464 c:\windows\system32\dllcache\tdspx.sys

+ 2011-02-08 14:02 . 2001-08-17 20:13 17129 c:\windows\system32\dllcache\tdkcd31.sys

+ 2011-02-08 14:02 . 2001-08-17 20:13 37961 c:\windows\system32\dllcache\tdk100b.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 21896 c:\windows\system32\dllcache\tdipx.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 21896 c:\windows\system32\dllcache\tdipx.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 13192 c:\windows\system32\dllcache\tdasync.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 13192 c:\windows\system32\dllcache\tdasync.sys

+ 2011-02-08 14:02 . 2001-08-17 21:49 30464 c:\windows\system32\dllcache\tbatm155.sys

+ 2011-02-08 14:01 . 2001-08-17 20:50 36640 c:\windows\system32\dllcache\t2r4mini.sys

+ 2011-02-08 14:01 . 2001-08-17 22:07 32640 c:\windows\system32\dllcache\symc8xx.sys

+ 2011-02-08 14:01 . 2001-08-17 22:07 16256 c:\windows\system32\dllcache\symc810.sys

+ 2011-02-08 14:01 . 2001-08-17 22:07 30688 c:\windows\system32\dllcache\sym_u3.sys

+ 2011-02-08 14:01 . 2001-08-17 22:07 28384 c:\windows\system32\dllcache\sym_hi.sys

+ 2011-02-08 14:01 . 2001-08-18 06:36 94293 c:\windows\system32\dllcache\sxports.dll

+ 2011-02-08 14:01 . 2001-08-18 06:36 10240 c:\windows\system32\dllcache\swpidflt.dll

+ 2011-02-08 14:01 . 2001-08-18 06:36 10240 c:\windows\system32\dllcache\swpdflt2.dll

+ 2011-02-08 14:01 . 2001-08-18 06:36 53760 c:\windows\system32\dllcache\sw_wheel.dll

+ 2011-02-08 14:01 . 2001-08-18 06:36 41472 c:\windows\system32\dllcache\sw_effct.dll

+ 2001-08-17 22:36 . 2008-04-14 11:00 72192 c:\windows\system32\dllcache\sprio800.dll

+ 2001-08-17 22:36 . 2008-04-14 11:00 70656 c:\windows\system32\dllcache\sprio600.dll

+ 2011-02-08 13:59 . 2001-08-17 20:51 37040 c:\windows\system32\dllcache\sonypi.sys

+ 2011-02-08 13:59 . 2001-08-17 20:51 20752 c:\windows\system32\dllcache\sonync.sys

+ 2008-04-14 00:16 . 2008-04-14 11:00 25344 c:\windows\system32\dllcache\sonydcam.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 10240 c:\windows\system32\dllcache\snmpstup.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 10240 c:\windows\system32\dllcache\snmpstup.dll

+ 2011-02-08 13:59 . 2001-08-17 20:51 58368 c:\windows\system32\dllcache\smiminib.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 15872 c:\windows\system32\dllcache\smierrsm.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 15872 c:\windows\system32\dllcache\smierrsm.dll

+ 2011-02-08 13:59 . 2001-08-17 20:12 25034 c:\windows\system32\dllcache\smcpwr2n.sys

+ 2011-02-08 13:59 . 2001-08-17 20:10 35913 c:\windows\system32\dllcache\smcirda.sys

+ 2011-02-08 13:59 . 2001-08-17 20:12 24576 c:\windows\system32\dllcache\smc8000n.sys

+ 2011-02-08 13:58 . 2008-04-14 08:06 16000 c:\windows\system32\dllcache\smbbatt.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 31744 c:\windows\system32\dllcache\smb6w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\smb6w.dll

+ 2011-02-08 13:58 . 2001-08-18 06:36 45568 c:\windows\system32\dllcache\smb3w.dll

+ 2011-02-08 13:58 . 2001-08-18 06:36 33792 c:\windows\system32\dllcache\smb0w.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 31744 c:\windows\system32\dllcache\sma3w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\sma3w.dll

+ 2011-02-08 13:58 . 2001-08-18 06:36 28672 c:\windows\system32\dllcache\sma0w.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 38912 c:\windows\system32\dllcache\sm9aw.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 38912 c:\windows\system32\dllcache\sm9aw.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 26624 c:\windows\system32\dllcache\sm93w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 26624 c:\windows\system32\dllcache\sm93w.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 26624 c:\windows\system32\dllcache\sm92w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 26624 c:\windows\system32\dllcache\sm92w.dll

+ 2011-02-08 13:58 . 2001-08-18 06:36 28160 c:\windows\system32\dllcache\sm91w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 26112 c:\windows\system32\dllcache\sm90w.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 26112 c:\windows\system32\dllcache\sm90w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 26112 c:\windows\system32\dllcache\sm8dw.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 26112 c:\windows\system32\dllcache\sm8dw.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 29184 c:\windows\system32\dllcache\sm8cw.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 29184 c:\windows\system32\dllcache\sm8cw.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 26112 c:\windows\system32\dllcache\sm8aw.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 26112 c:\windows\system32\dllcache\sm8aw.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 26112 c:\windows\system32\dllcache\sm89w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 26112 c:\windows\system32\dllcache\sm89w.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 30208 c:\windows\system32\dllcache\sm87w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 30208 c:\windows\system32\dllcache\sm87w.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 30208 c:\windows\system32\dllcache\sm81w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 30208 c:\windows\system32\dllcache\sm81w.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 25088 c:\windows\system32\dllcache\sm59w.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 25088 c:\windows\system32\dllcache\sm59w.dll

+ 2011-02-08 13:58 . 2008-04-14 07:53 13240 c:\windows\system32\dllcache\slwdmsup.sys

+ 2011-02-08 13:58 . 2008-04-14 13:42 73796 c:\windows\system32\dllcache\slserv.exe

+ 2011-02-08 13:58 . 2008-04-14 13:42 32866 c:\windows\system32\dllcache\slrundll.exe

+ 2011-02-08 13:58 . 2008-04-14 07:53 95424 c:\windows\system32\dllcache\slnthal.sys

+ 2011-02-08 13:58 . 2008-04-14 13:42 73832 c:\windows\system32\dllcache\slcoinst.dll

+ 2011-02-08 13:58 . 2008-04-14 06:05 63547 c:\windows\system32\dllcache\sla30nd5.sys

+ 2011-02-08 13:58 . 2001-08-17 20:12 91294 c:\windows\system32\dllcache\skfpwin.sys

+ 2011-02-08 13:58 . 2001-08-17 20:12 94698 c:\windows\system32\dllcache\sk98xwin.sys

+ 2011-02-08 13:58 . 2001-08-17 20:50 50432 c:\windows\system32\dllcache\sisv.sys

+ 2011-02-08 13:58 . 2008-04-14 06:05 32768 c:\windows\system32\dllcache\sisnic.sys

+ 2011-02-08 13:58 . 2008-04-14 08:06 40960 c:\windows\system32\dllcache\sisagp.sys

+ 2011-02-08 13:58 . 2001-08-17 20:50 68608 c:\windows\system32\dllcache\sis6306p.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 18944 c:\windows\system32\dllcache\simptcp.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 18944 c:\windows\system32\dllcache\simptcp.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 11392 c:\windows\system32\dllcache\sfloppy.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 11008 c:\windows\system32\dllcache\sffp_sd.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 11904 c:\windows\system32\dllcache\sffdisk.sys

+ 2011-02-08 13:56 . 2001-08-17 21:48 17664 c:\windows\system32\dllcache\sermouse.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 64512 c:\windows\system32\dllcache\serial.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 15744 c:\windows\system32\dllcache\serenum.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 79232 c:\windows\system32\dllcache\sdbus.sys

+ 2011-02-08 13:56 . 2008-04-14 08:15 11520 c:\windows\system32\dllcache\scsiscan.sys

+ 2011-02-08 13:56 . 2001-08-17 21:52 11648 c:\windows\system32\dllcache\scsiprnt.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 96384 c:\windows\system32\dllcache\scsiport.sys

+ 2011-02-08 13:56 . 2001-08-17 21:51 17280 c:\windows\system32\dllcache\scr111.sys

+ 2011-02-08 13:56 . 2001-08-17 21:51 16640 c:\windows\system32\dllcache\scmstcs.sys

+ 2011-02-08 13:56 . 2001-08-17 21:51 23936 c:\windows\system32\dllcache\sccmusbm.sys

+ 2011-02-08 13:56 . 2001-08-17 21:51 23936 c:\windows\system32\dllcache\sccmn50m.sys

+ 2011-02-08 13:56 . 2008-04-14 08:10 43904 c:\windows\system32\dllcache\sbp2port.sys

+ 2011-02-08 13:56 . 2001-08-17 20:50 75392 c:\windows\system32\dllcache\s3savmxm.sys

+ 2011-02-08 13:55 . 2001-08-17 20:50 77824 c:\windows\system32\dllcache\s3sav4m.sys

+ 2011-02-08 13:55 . 2001-08-17 20:50 61504 c:\windows\system32\dllcache\s3sav3dm.sys

+ 2011-02-08 13:55 . 2001-08-18 06:36 62496 c:\windows\system32\dllcache\s3mtrio.dll

+ 2011-02-08 13:55 . 2001-08-17 20:50 41216 c:\windows\system32\dllcache\s3mt3d.sys

+ 2011-02-08 13:55 . 2001-08-17 21:57 65664 c:\windows\system32\dllcache\s3legacy.sys

+ 2011-02-08 13:55 . 2001-08-18 06:36 82432 c:\windows\system32\dllcache\rwia450.dll

+ 2011-02-08 13:55 . 2001-08-18 06:36 79872 c:\windows\system32\dllcache\rwia430.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 79872 c:\windows\system32\dllcache\rwia330.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 79872 c:\windows\system32\dllcache\rwia330.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 79872 c:\windows\system32\dllcache\rwia001.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 79872 c:\windows\system32\dllcache\rwia001.dll

+ 2011-02-08 13:55 . 2008-04-14 13:42 29696 c:\windows\system32\dllcache\rw450ext.dll

+ 2011-02-08 13:55 . 2008-04-14 13:42 27648 c:\windows\system32\dllcache\rw430ext.dll

+ 2010-02-26 15:03 . 2008-04-13 22:05 20992 c:\windows\system32\dllcache\rtl8139.sys

+ 2011-02-08 13:55 . 2001-08-17 20:12 19017 c:\windows\system32\dllcache\rtl8029.sys

+ 2001-08-17 13:24 . 2008-04-14 11:00 12032 c:\windows\system32\dllcache\riodrv.sys

+ 2001-08-17 13:24 . 2008-04-14 11:00 12032 c:\windows\system32\dllcache\rio8drv.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 14848 c:\windows\system32\dllcache\register.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 14848 c:\windows\system32\dllcache\register.exe

+ 2010-02-26 15:04 . 2008-04-14 00:10 57600 c:\windows\system32\dllcache\redbook.sys

+ 2011-02-08 13:53 . 2001-08-17 21:51 19584 c:\windows\system32\dllcache\rasirda.sys

+ 2011-02-08 13:53 . 2001-08-18 06:36 41472 c:\windows\system32\dllcache\qvusd.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 16384 c:\windows\system32\dllcache\quser.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 16384 c:\windows\system32\dllcache\quser.exe

+ 2011-02-08 13:53 . 2001-08-17 21:52 49024 c:\windows\system32\dllcache\ql1280.sys

+ 2011-02-08 13:53 . 2001-08-17 21:52 40448 c:\windows\system32\dllcache\ql1240.sys

+ 2011-02-08 13:53 . 2001-08-17 21:52 45312 c:\windows\system32\dllcache\ql12160.sys

+ 2011-02-08 13:53 . 2001-08-17 21:52 33152 c:\windows\system32\dllcache\ql10wnt.sys

+ 2011-02-08 13:53 . 2001-08-17 21:52 40320 c:\windows\system32\dllcache\ql1080.sys

+ 2011-02-08 13:52 . 2001-08-18 06:36 35328 c:\windows\system32\dllcache\psisload.dll

+ 2011-02-08 13:52 . 2001-08-17 21:51 16128 c:\windows\system32\dllcache\pscr.sys

+ 2008-04-14 00:01 . 2008-04-14 11:00 35840 c:\windows\system32\dllcache\processr.sys

+ 2011-02-08 13:52 . 2008-04-14 08:11 17664 c:\windows\system32\dllcache\ppa3.sys

+ 2011-02-08 13:52 . 2001-08-17 21:53 17792 c:\windows\system32\dllcache\ppa.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 11264 c:\windows\system32\dllcache\pmxmcro.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 11264 c:\windows\system32\dllcache\pmxmcro.dll

+ 2008-04-14 05:42 . 2008-04-14 11:00 15360 c:\windows\system32\dllcache\pjlmon.dll

+ 2008-04-14 05:42 . 2008-04-14 11:00 35328 c:\windows\system32\dllcache\pid.dll

+ 2011-02-08 13:52 . 2001-08-17 22:07 19840 c:\windows\system32\dllcache\philtune.sys

+ 2011-02-08 13:52 . 2001-08-17 22:04 92416 c:\windows\system32\dllcache\phildec.sys

+ 2011-02-08 13:52 . 2001-08-17 22:04 75776 c:\windows\system32\dllcache\philcam1.sys

+ 2011-02-08 13:52 . 2001-08-18 06:36 16384 c:\windows\system32\dllcache\philcam1.dll

+ 2011-02-08 13:52 . 2008-04-14 08:14 28032 c:\windows\system32\dllcache\perm3.sys

+ 2011-02-08 13:52 . 2008-04-14 08:14 27904 c:\windows\system32\dllcache\perm2.sys

+ 2011-02-08 13:51 . 2001-08-17 22:07 27296 c:\windows\system32\dllcache\perc2.sys

+ 2011-02-08 13:51 . 2001-08-18 06:36 86016 c:\windows\system32\dllcache\pctspk.exe

+ 2011-02-08 13:51 . 2001-08-17 20:11 35328 c:\windows\system32\dllcache\pcntpci5.sys

+ 2011-02-08 13:51 . 2001-08-17 20:11 29769 c:\windows\system32\dllcache\pcntn5m.sys

+ 2011-02-08 13:51 . 2001-08-17 20:11 30282 c:\windows\system32\dllcache\pcntn5hl.sys

+ 2011-02-08 13:51 . 2001-08-17 20:12 26153 c:\windows\system32\dllcache\pcmlm56.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 24960 c:\windows\system32\dllcache\pciidex.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 68224 c:\windows\system32\dllcache\pci.sys

+ 2011-02-08 13:51 . 2008-04-14 06:05 29502 c:\windows\system32\dllcache\pca200e.sys

+ 2011-02-08 13:51 . 2001-08-17 20:12 30495 c:\windows\system32\dllcache\pc100nds.sys

+ 2008-04-14 00:10 . 2008-04-14 11:00 80128 c:\windows\system32\dllcache\parport.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\padrs412.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 14336 c:\windows\system32\dllcache\padrs412.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 36927 c:\windows\system32\dllcache\padrs411.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 36927 c:\windows\system32\dllcache\padrs411.dll

+ 2008-04-14 00:01 . 2008-04-14 11:00 42752 c:\windows\system32\dllcache\p3.sys

+ 2011-02-08 13:51 . 2001-08-18 06:36 41984 c:\windows\system32\dllcache\ovui2rc.dll

+ 2011-02-08 13:51 . 2001-08-18 06:36 44544 c:\windows\system32\dllcache\ovui2.dll

+ 2011-02-08 13:51 . 2001-08-17 22:05 25216 c:\windows\system32\dllcache\ovsound2.sys

+ 2011-02-08 13:51 . 2001-08-18 06:36 39424 c:\windows\system32\dllcache\ovcoms.exe

+ 2011-02-08 13:51 . 2001-08-18 06:36 20480 c:\windows\system32\dllcache\ovcomc.dll

+ 2011-02-08 13:50 . 2001-08-17 22:05 28032 c:\windows\system32\dllcache\ovcd.sys

+ 2011-02-08 13:50 . 2001-08-17 22:05 48000 c:\windows\system32\dllcache\ovcam2.sys

+ 2011-02-08 13:50 . 2001-08-17 22:05 25088 c:\windows\system32\dllcache\ovca.sys

+ 2011-02-08 13:50 . 2001-08-17 21:28 54186 c:\windows\system32\dllcache\otcsercb.sys

+ 2011-02-08 13:50 . 2001-08-17 20:12 43689 c:\windows\system32\dllcache\otceth5.sys

+ 2011-02-08 13:50 . 2001-08-17 20:12 27209 c:\windows\system32\dllcache\otc06x5.sys

+ 2011-02-08 13:50 . 2001-08-17 20:20 54528 c:\windows\system32\dllcache\opl3sax.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 61696 c:\windows\system32\dllcache\ohci1394.sys

+ 2011-02-08 13:50 . 2001-08-17 20:49 51552 c:\windows\system32\dllcache\ntgrip.sys

+ 2001-08-17 13:24 . 2008-04-14 11:00 12032 c:\windows\system32\dllcache\nikedrv.sys

+ 2008-04-14 00:21 . 2008-04-14 11:00 61824 c:\windows\system32\dllcache\nic1394.sys

+ 2008-04-14 00:26 . 2008-04-14 11:00 14592 c:\windows\system32\dllcache\ndisuio.sys

+ 2011-02-08 13:48 . 2001-08-17 20:50 27936 c:\windows\system32\dllcache\n9i3d.sys

+ 2011-02-08 13:48 . 2001-08-17 20:50 33088 c:\windows\system32\dllcache\n9i128v2.sys

+ 2011-02-08 13:48 . 2001-08-18 06:36 59104 c:\windows\system32\dllcache\n9i128v2.dll

+ 2011-02-08 13:48 . 2001-08-17 20:50 13664 c:\windows\system32\dllcache\n9i128.sys

+ 2011-02-08 13:48 . 2001-08-17 22:56 35392 c:\windows\system32\dllcache\n9i128.dll

+ 2011-02-08 13:48 . 2001-08-17 20:11 52255 c:\windows\system32\dllcache\n1000nt5.sys

+ 2011-02-08 13:48 . 2001-08-17 21:50 75520 c:\windows\system32\dllcache\mxport.sys

+ 2011-02-08 13:48 . 2001-08-17 21:49 19968 c:\windows\system32\dllcache\mxnic.sys

+ 2011-02-08 13:48 . 2001-08-18 06:36 19968 c:\windows\system32\dllcache\mxicfg.dll

+ 2011-02-08 13:48 . 2001-08-17 21:50 21888 c:\windows\system32\dllcache\mxcard.sys

+ 2011-02-08 13:48 . 2008-04-14 08:13 12672 c:\windows\system32\dllcache\mutohpen.sys

- 2009-11-27 17:11 . 2009-11-27 17:11 17920 c:\windows\system32\dllcache\msyuv.dll

+ 2008-04-14 05:42 . 2009-11-27 17:11 17920 c:\windows\system32\dllcache\msyuv.dll

+ 2008-04-14 00:06 . 2008-04-14 11:00 15488 c:\windows\system32\dllcache\mssmbios.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 98304 c:\windows\system32\dllcache\msir3jp.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 98304 c:\windows\system32\dllcache\msir3jp.dll

+ 2008-04-14 00:30 . 2008-04-14 11:00 30080 c:\windows\system32\dllcache\modem.sys

+ 2008-04-14 11:00 . 2004-08-04 12:00 34304 c:\windows\system32\dllcache\migisol.exe

- 2008-04-14 11:00 . 2008-04-14 11:00 34304 c:\windows\system32\dllcache\migisol.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 92416 c:\windows\system32\dllcache\mga.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 92416 c:\windows\system32\dllcache\mga.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 92032 c:\windows\system32\dllcache\mga.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 92032 c:\windows\system32\dllcache\mga.dll

+ 2008-04-14 00:06 . 2008-04-14 11:00 63744 c:\windows\system32\dllcache\mf.sys

- 2010-02-26 15:01 . 2008-04-14 11:00 28160 c:\windows\system32\dllcache\mciwave.drv

+ 2008-04-14 11:00 . 2008-04-14 11:00 28160 c:\windows\system32\dllcache\mciwave.drv

+ 2008-04-14 11:00 . 2008-04-14 11:00 73376 c:\windows\system32\dllcache\mciavi.drv

- 2010-02-26 15:01 . 2008-04-14 11:00 73376 c:\windows\system32\dllcache\mciavi.drv

+ 2011-02-08 13:45 . 2001-08-17 20:19 48768 c:\windows\system32\dllcache\maestro.sys

+ 2011-02-08 13:45 . 2001-08-18 06:36 58880 c:\windows\system32\dllcache\m3092dc.dll

+ 2011-02-08 13:45 . 2001-08-18 06:36 58368 c:\windows\system32\dllcache\m3091dc.dll

+ 2011-02-08 13:45 . 2001-08-17 20:49 22848 c:\windows\system32\dllcache\lwusbhid.sys

+ 2011-02-08 13:45 . 2008-04-14 06:09 20864 c:\windows\system32\dllcache\lwadihid.sys

+ 2011-02-08 13:45 . 2001-08-17 20:12 70730 c:\windows\system32\dllcache\lne100tx.sys

+ 2011-02-08 13:45 . 2001-08-17 20:12 20573 c:\windows\system32\dllcache\lne100.sys

+ 2011-02-08 13:45 . 2001-08-17 20:11 25065 c:\windows\system32\dllcache\lmndis3.sys

+ 2011-02-08 13:44 . 2008-04-14 08:10 34688 c:\windows\system32\dllcache\lbrtfdc.sys

+ 2011-02-08 13:44 . 2001-08-17 20:12 26442 c:\windows\system32\dllcache\lanepic5.sys

+ 2011-02-08 13:44 . 2001-08-17 20:12 19016 c:\windows\system32\dllcache\ktc111.sys

+ 2011-02-08 13:44 . 2001-08-18 06:36 37376 c:\windows\system32\dllcache\kousd.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 70656 c:\windows\system32\dllcache\korwbrkr.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 70656 c:\windows\system32\dllcache\korwbrkr.dll

+ 2011-02-08 13:44 . 2008-04-14 13:41 48640 c:\windows\system32\dllcache\kdsui.dll

+ 2011-02-08 13:44 . 2008-04-14 08:09 14592 c:\windows\system32\dllcache\kbdhid.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 18432 c:\windows\system32\dllcache\jupiw.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 18432 c:\windows\system32\dllcache\jupiw.dll

+ 2008-04-14 05:41 . 2009-11-27 16:07 48128 c:\windows\system32\dllcache\iyuv_32.dll

- 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\system32\dllcache\iyuv_32.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 37248 c:\windows\system32\dllcache\isapnp.sys

+ 2011-02-08 13:43 . 2001-08-17 21:49 26624 c:\windows\system32\dllcache\irstusb.sys

+ 2011-02-08 13:43 . 2001-08-17 21:51 18688 c:\windows\system32\dllcache\irsir.sys

+ 2011-02-08 13:43 . 2008-04-14 13:41 28160 c:\windows\system32\dllcache\irmon.dll

+ 2011-02-08 13:43 . 2001-08-17 21:49 23552 c:\windows\system32\dllcache\irmk7.sys

+ 2011-02-08 13:43 . 2008-04-14 08:24 88192 c:\windows\system32\dllcache\irda.sys

+ 2011-02-08 13:43 . 2001-08-17 20:12 45632 c:\windows\system32\dllcache\ip5515.sys

+ 2011-02-08 13:43 . 2001-08-18 06:36 90200 c:\windows\system32\dllcache\io8ports.dll

+ 2011-02-08 13:43 . 2001-08-17 21:50 38784 c:\windows\system32\dllcache\io8.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 36352 c:\windows\system32\dllcache\intelppm.sys

+ 2011-02-08 13:43 . 2001-08-17 21:47 13056 c:\windows\system32\dllcache\inport.sys

+ 2011-02-08 13:43 . 2001-08-17 21:52 16000 c:\windows\system32\dllcache\ini910u.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 59392 c:\windows\system32\dllcache\imscinst.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 59392 c:\windows\system32\dllcache\imscinst.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 59904 c:\windows\system32\dllcache\imkrinst.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 59904 c:\windows\system32\dllcache\imkrinst.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 45109 c:\windows\system32\dllcache\imjpuex.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 45109 c:\windows\system32\dllcache\imjpuex.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 57398 c:\windows\system32\dllcache\imjpdadm.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 57398 c:\windows\system32\dllcache\imjpdadm.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 44032 c:\windows\system32\dllcache\imekrmig.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 44032 c:\windows\system32\dllcache\imekrmig.exe

+ 2008-04-14 11:00 . 2008-04-14 11:00 42112 c:\windows\system32\dllcache\imapi.sys

+ 2011-02-08 13:42 . 2001-08-18 06:36 20480 c:\windows\system32\dllcache\icam5ext.dll

+ 2011-02-08 13:42 . 2001-08-18 06:36 45056 c:\windows\system32\dllcache\icam5com.dll

+ 2011-02-08 13:42 . 2001-08-18 06:36 61952 c:\windows\system32\dllcache\icam4ext.dll

+ 2011-02-08 13:42 . 2001-08-18 06:36 91136 c:\windows\system32\dllcache\icam4com.dll

+ 2011-02-08 13:42 . 2001-08-18 06:36 26624 c:\windows\system32\dllcache\icam3ext.dll

+ 2011-02-08 13:42 . 2001-08-17 22:06 38528 c:\windows\system32\dllcache\ibmvcap.sys

+ 2011-02-08 13:41 . 2001-08-17 20:49 58592 c:\windows\system32\dllcache\i740nt5.sys

+ 2011-02-08 13:41 . 2008-04-14 08:11 18560 c:\windows\system32\dllcache\i2omp.sys

+ 2011-02-08 13:41 . 2008-04-14 13:41 32285 c:\windows\system32\dllcache\hsfcisp2.dll

+ 2011-02-08 13:41 . 2001-08-17 21:28 50751 c:\windows\system32\dllcache\hsf_tone.sys

+ 2011-02-08 13:41 . 2001-08-17 21:28 73279 c:\windows\system32\dllcache\hsf_spkp.sys

+ 2011-02-08 13:41 . 2001-08-17 21:28 44863 c:\windows\system32\dllcache\hsf_soar.sys

+ 2011-02-08 13:40 . 2001-08-17 21:28 67167 c:\windows\system32\dllcache\hsf_bsc2.sys

+ 2011-02-08 13:40 . 2001-08-18 06:36 19456 c:\windows\system32\dllcache\hr1w.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 13312 c:\windows\system32\dllcache\hpsjmcro.dll

+ 2011-02-08 13:40 . 2001-08-17 22:07 25952 c:\windows\system32\dllcache\hpn.sys

+ 2011-02-08 13:40 . 2001-08-18 06:36 32768 c:\windows\system32\dllcache\hpgtmcro.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 68608 c:\windows\system32\dllcache\hpgt53tk.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 31232 c:\windows\system32\dllcache\hpgt42tk.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 93696 c:\windows\system32\dllcache\hpgt42.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 48128 c:\windows\system32\dllcache\hpgt33tk.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 89088 c:\windows\system32\dllcache\hpgt33.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 83968 c:\windows\system32\dllcache\hpgt21.dll

+ 2011-02-08 13:39 . 2008-04-14 13:41 21504 c:\windows\system32\dllcache\hidserv.dll

+ 2008-04-14 11:00 . 2008-04-14 08:15 24960 c:\windows\system32\dllcache\hidparse.sys

+ 2011-02-08 13:39 . 2008-04-14 08:15 19200 c:\windows\system32\dllcache\hidir.sys

+ 2008-04-14 11:00 . 2008-04-14 08:15 36864 c:\windows\system32\dllcache\hidclass.sys

+ 2011-02-08 13:39 . 2008-04-14 08:16 25600 c:\windows\system32\dllcache\hidbth.sys

+ 2011-02-08 13:39 . 2008-04-14 08:06 20352 c:\windows\system32\dllcache\hidbatt.sys

+ 2008-04-14 05:41 . 2008-04-14 11:00 20992 c:\windows\system32\dllcache\hid.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 36864 c:\windows\system32\dllcache\hanjadic.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 36864 c:\windows\system32\dllcache\hanjadic.dll

+ 2011-02-08 13:39 . 2008-04-14 08:10 28288 c:\windows\system32\dllcache\grserial.sys

+ 2011-02-08 13:39 . 2001-08-17 21:51 82304 c:\windows\system32\dllcache\grclass.sys

+ 2011-02-08 13:39 . 2001-08-17 21:51 17408 c:\windows\system32\dllcache\gpr400.sys

+ 2011-02-08 13:39 . 2008-04-14 08:15 59136 c:\windows\system32\dllcache\gckernel.sys

+ 2011-02-08 13:39 . 2008-04-14 08:15 10624 c:\windows\system32\dllcache\gameenum.sys

+ 2011-02-08 13:39 . 2008-04-14 08:06 46464 c:\windows\system32\dllcache\gagp30kx.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 11264 c:\windows\system32\dllcache\fxssend.exe

- 2010-02-26 23:35 . 2008-04-14 11:00 11264 c:\windows\system32\dllcache\fxssend.exe

+ 2010-02-26 23:35 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\fxsroute.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 31744 c:\windows\system32\dllcache\fxsroute.dll

+ 2011-02-08 13:38 . 2001-08-18 06:36 92160 c:\windows\system32\dllcache\fuusd.dll

+ 2001-08-17 13:57 . 2008-04-14 11:00 12160 c:\windows\system32\dllcache\fsvga.sys

+ 2011-02-08 13:38 . 2008-04-14 06:05 34173 c:\windows\system32\dllcache\forehe.sys

+ 2011-02-08 13:38 . 2001-08-18 06:36 71680 c:\windows\system32\dllcache\fnfilter.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 20480 c:\windows\system32\dllcache\flpydisk.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 14848 c:\windows\system32\dllcache\flattemp.exe

- 2010-02-26 23:35 . 2008-04-14 11:00 14848 c:\windows\system32\dllcache\flattemp.exe

+ 2011-02-08 13:38 . 2001-08-17 20:13 27165 c:\windows\system32\dllcache\fetnd5.sys

+ 2011-02-08 13:38 . 2001-08-17 20:10 22090 c:\windows\system32\dllcache\fem556n5.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 27392 c:\windows\system32\dllcache\fdc.sys

+ 2011-02-08 13:37 . 2001-08-17 20:12 16074 c:\windows\system32\dllcache\fa312nd5.sys

+ 2011-02-08 13:37 . 2001-08-17 20:11 11850 c:\windows\system32\dllcache\f3ab18xj.sys

+ 2011-02-08 13:37 . 2001-08-17 20:11 12362 c:\windows\system32\dllcache\f3ab18xi.sys

+ 2011-02-08 13:37 . 2001-08-17 20:12 16998 c:\windows\system32\dllcache\ex10.sys

- 2010-02-26 23:35 . 2008-04-14 11:00 25856 c:\windows\system32\dllcache\et4000.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 25856 c:\windows\system32\dllcache\et4000.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 45056 c:\windows\system32\dllcache\esunid.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 45056 c:\windows\system32\dllcache\esunid.dll

+ 2011-02-08 13:37 . 2001-08-18 06:36 45568 c:\windows\system32\dllcache\esunib.dll

+ 2011-02-08 13:37 . 2001-08-18 06:36 45568 c:\windows\system32\dllcache\esuni.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 57856 c:\windows\system32\dllcache\esuimgd.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 57856 c:\windows\system32\dllcache\esuimgd.dll

+ 2011-02-08 13:37 . 2001-08-18 06:36 34816 c:\windows\system32\dllcache\esuimg.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 31744 c:\windows\system32\dllcache\esucmd.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 31744 c:\windows\system32\dllcache\esucmd.dll

+ 2011-02-08 13:37 . 2001-08-18 06:36 43008 c:\windows\system32\dllcache\esucm.dll

+ 2011-02-08 13:37 . 2001-08-17 20:19 63360 c:\windows\system32\dllcache\ess.sys

+ 2011-02-08 13:37 . 2001-08-17 20:19 72192 c:\windows\system32\dllcache\es1969.sys

+ 2011-02-08 13:37 . 2001-08-17 20:19 40704 c:\windows\system32\dllcache\es1371mp.sys

+ 2011-02-08 13:37 . 2001-08-17 20:19 37120 c:\windows\system32\dllcache\es1370mp.sys

+ 2011-02-08 13:37 . 2001-08-18 06:36 61952 c:\windows\system32\dllcache\eqnloop.exe

+ 2011-02-08 13:37 . 2001-08-18 06:36 51200 c:\windows\system32\dllcache\eqnlogr.exe

+ 2011-02-08 13:37 . 2001-08-18 06:36 53248 c:\windows\system32\dllcache\eqndiag.exe

+ 2011-02-08 13:36 . 2001-08-17 20:12 18503 c:\windows\system32\dllcache\epro4.sys

+ 2011-02-08 13:36 . 2001-08-17 20:10 19996 c:\windows\system32\dllcache\em556n4.sys

+ 2011-02-08 13:36 . 2001-08-17 20:10 25159 c:\windows\system32\dllcache\elnk3.sys

+ 2011-02-08 13:36 . 2001-08-17 20:11 70174 c:\windows\system32\dllcache\el98xn5.sys

+ 2011-02-08 13:36 . 2001-08-17 20:11 66591 c:\windows\system32\dllcache\el90xbc5.sys

+ 2011-02-08 13:36 . 2001-08-17 20:11 77386 c:\windows\system32\dllcache\el656nd5.sys

+ 2011-02-08 13:36 . 2001-08-17 20:11 69194 c:\windows\system32\dllcache\el656cd5.sys

+ 2011-02-08 13:36 . 2001-08-17 20:10 26141 c:\windows\system32\dllcache\el589nd5.sys

+ 2011-02-08 13:36 . 2001-08-17 20:10 69692 c:\windows\system32\dllcache\el575nd5.sys

+ 2011-02-08 13:36 . 2001-08-17 20:10 24653 c:\windows\system32\dllcache\el574nd4.sys

+ 2011-02-08 13:36 . 2001-08-17 20:10 55999 c:\windows\system32\dllcache\el556nd5.sys

+ 2011-02-08 13:36 . 2001-08-17 20:10 44103 c:\windows\system32\dllcache\el515.sys

+ 2011-02-08 13:36 . 2001-08-17 20:12 19594 c:\windows\system32\dllcache\e100isa4.sys

+ 2011-02-08 13:36 . 2001-08-17 20:12 50719 c:\windows\system32\dllcache\e1000nt5.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 71168 c:\windows\system32\dllcache\dxg.sys

+ 2011-02-08 13:35 . 2001-08-17 20:12 28062 c:\windows\system32\dllcache\dp83820.sys

+ 2011-02-08 13:35 . 2001-08-17 21:47 23808 c:\windows\system32\dllcache\dot4usb.sys

+ 2011-02-08 13:35 . 2001-08-17 21:47 12928 c:\windows\system32\dllcache\dot4prt.sys

+ 2011-02-08 13:35 . 2001-08-17 20:11 29696 c:\windows\system32\dllcache\dm9pci5.sys

+ 2011-02-08 13:35 . 2001-08-17 20:11 26698 c:\windows\system32\dllcache\dlh5xnd5.sys

+ 2011-02-08 13:35 . 2001-08-18 06:36 29768 c:\windows\system32\dllcache\divasu.dll

+ 2011-02-08 13:35 . 2001-08-18 06:36 37962 c:\windows\system32\dllcache\divaprop.dll

+ 2011-02-08 13:35 . 2001-08-18 06:36 38985 c:\windows\system32\dllcache\disrvsu.dll

+ 2011-02-08 13:35 . 2001-08-18 06:36 31305 c:\windows\system32\dllcache\disrvpp.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 36352 c:\windows\system32\dllcache\disk.sys

+ 2011-02-08 13:35 . 2001-08-17 20:13 91305 c:\windows\system32\dllcache\dimaint.sys

+ 2011-02-08 13:35 . 2001-08-17 20:17 42432 c:\windows\system32\dllcache\digirlpt.sys

+ 2011-02-08 13:35 . 2001-08-17 20:14 21606 c:\windows\system32\dllcache\digiisdn.sys

+ 2011-02-08 13:35 . 2001-08-18 06:36 41046 c:\windows\system32\dllcache\digiisdn.dll

+ 2011-02-08 13:35 . 2001-08-17 20:17 90525 c:\windows\system32\dllcache\digifep5.sys

+ 2011-02-08 13:35 . 2001-08-17 20:13 37735 c:\windows\system32\dllcache\digiasyn.sys

+ 2011-02-08 13:35 . 2001-08-18 06:36 65622 c:\windows\system32\dllcache\digiasyn.dll

+ 2011-02-08 13:33 . 2001-08-18 06:36 32256 c:\windows\system32\dllcache\diapi2NT.dll

+ 2011-02-08 13:35 . 2001-08-17 20:17 29531 c:\windows\system32\dllcache\dgapci.sys

+ 2011-02-08 13:35 . 2001-08-17 20:11 24649 c:\windows\system32\dllcache\dfe650d.sys

+ 2011-02-08 13:35 . 2001-08-17 20:11 24648 c:\windows\system32\dllcache\dfe650.sys

+ 2011-02-08 13:35 . 2001-08-18 06:36 24064 c:\windows\system32\dllcache\devldr32.exe

+ 2011-02-08 13:34 . 2001-08-18 06:36 86016 c:\windows\system32\dllcache\dc240usd.dll

+ 2011-02-08 13:34 . 2001-08-17 20:12 63208 c:\windows\system32\dllcache\dc21x4.sys

+ 2011-02-08 13:34 . 2001-08-18 06:36 80896 c:\windows\system32\dllcache\dc210usd.dll

+ 2011-02-08 13:34 . 2001-08-18 06:36 25600 c:\windows\system32\dllcache\dc210_32.dll

+ 2011-02-08 13:34 . 2001-08-17 21:52 14720 c:\windows\system32\dllcache\dac960nt.sys

+ 2011-02-08 13:34 . 2001-08-18 06:36 27648 c:\windows\system32\dllcache\cyzports.dll

+ 2011-02-08 13:34 . 2001-08-17 21:50 49792 c:\windows\system32\dllcache\cyzport.sys

+ 2011-02-08 13:34 . 2001-08-18 06:36 27136 c:\windows\system32\dllcache\cyzcoins.dll

+ 2011-02-08 13:34 . 2001-08-18 06:36 27648 c:\windows\system32\dllcache\cyyports.dll

+ 2011-02-08 13:34 . 2001-08-17 21:50 50176 c:\windows\system32\dllcache\cyyport.sys

+ 2011-02-08 13:34 . 2001-08-18 06:36 28672 c:\windows\system32\dllcache\cyycoins.dll

+ 2011-02-08 13:34 . 2001-08-17 21:50 14848 c:\windows\system32\dllcache\cyclom-y.sys

+ 2011-02-08 13:34 . 2001-08-17 21:50 17152 c:\windows\system32\dllcache\cyclad-z.sys

+ 2011-02-08 13:34 . 2008-04-14 06:06 48640 c:\windows\system32\dllcache\cwrwdm.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 93952 c:\windows\system32\dllcache\cwcwdm.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 72832 c:\windows\system32\dllcache\cwbwdm.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 96256 c:\windows\system32\dllcache\ctlsb16.sys

+ 2008-04-14 00:01 . 2008-04-14 11:00 36736 c:\windows\system32\dllcache\crusoe.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 42112 c:\windows\system32\dllcache\crtaud.sys

- 2010-02-26 23:35 . 2008-04-14 11:00 18944 c:\windows\system32\dllcache\cprofile.exe

+ 2010-02-26 23:35 . 2004-08-04 12:00 18944 c:\windows\system32\dllcache\cprofile.exe

+ 2011-02-08 13:34 . 2001-08-17 20:11 60970 c:\windows\system32\dllcache\cpqtrnd5.sys

+ 2011-02-08 13:34 . 2001-08-17 20:13 21533 c:\windows\system32\dllcache\cpqndis5.sys

+ 2001-08-17 13:24 . 2008-04-14 11:00 11776 c:\windows\system32\dllcache\cpqdap01.sys

+ 2011-02-08 13:34 . 2001-08-17 21:52 14976 c:\windows\system32\dllcache\cpqarray.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 57399 c:\windows\system32\dllcache\cplexe.exe

- 2010-02-26 23:35 . 2008-04-14 11:00 57399 c:\windows\system32\dllcache\cplexe.exe

+ 2010-02-26 15:03 . 2008-04-14 00:06 10240 c:\windows\system32\dllcache\compbatt.sys

+ 2011-02-08 13:33 . 2001-08-18 06:36 44032 c:\windows\system32\dllcache\cnusd.dll

+ 2008-04-14 05:41 . 2008-04-14 11:00 47104 c:\windows\system32\dllcache\cnbjmon.dll

+ 2011-02-08 13:33 . 2001-08-17 21:51 20736 c:\windows\system32\dllcache\cmbp0wdm.sys

+ 2010-02-26 15:03 . 2008-04-14 00:06 13952 c:\windows\system32\dllcache\cmbatt.sys

+ 2011-02-08 13:33 . 2001-08-17 21:57 45696 c:\windows\system32\dllcache\cirrus.sys

+ 2011-02-08 13:33 . 2001-08-17 22:56 91264 c:\windows\system32\dllcache\cirrus.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 14336 c:\windows\system32\dllcache\chgusr.exe

- 2010-02-26 23:35 . 2008-04-14 11:00 14336 c:\windows\system32\dllcache\chgusr.exe

+ 2010-02-26 23:35 . 2004-08-04 12:00 15872 c:\windows\system32\dllcache\chgport.exe

- 2010-02-26 23:35 . 2008-04-14 11:00 15872 c:\windows\system32\dllcache\chgport.exe

- 2010-02-26 23:35 . 2008-04-14 11:00 13312 c:\windows\system32\dllcache\chglogon.exe

+ 2010-02-26 23:35 . 2004-08-04 12:00 13312 c:\windows\system32\dllcache\chglogon.exe

+ 2011-02-08 13:33 . 2008-04-14 13:41 15423 c:\windows\system32\dllcache\ch7xxnt5.dll

+ 2011-02-08 13:33 . 2001-08-17 20:13 49182 c:\windows\system32\dllcache\cem56n5.sys

+ 2011-02-08 13:33 . 2001-08-17 20:13 22044 c:\windows\system32\dllcache\cem33n5.sys

+ 2011-02-08 13:33 . 2001-08-17 20:13 22044 c:\windows\system32\dllcache\cem28n5.sys

+ 2011-02-08 13:33 . 2001-08-17 20:13 27164 c:\windows\system32\dllcache\ce3n5.sys

+ 2011-02-08 13:33 . 2001-08-17 20:13 21530 c:\windows\system32\dllcache\ce2n5.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 62976 c:\windows\system32\dllcache\cdrom.sys

+ 2008-04-14 11:00 . 2009-08-07 03:24 96480 c:\windows\system32\dllcache\cdm.dll

+ 2001-08-17 13:52 . 2008-04-14 11:00 18688 c:\windows\system32\dllcache\cdaudio.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 13952 c:\windows\system32\dllcache\cbidf2k.sys

+ 2011-02-08 13:33 . 2001-08-17 20:13 46108 c:\windows\system32\dllcache\cben5.sys

+ 2011-02-08 13:33 . 2001-08-17 20:12 39680 c:\windows\system32\dllcache\cb325.sys

+ 2011-02-08 13:33 . 2001-08-17 20:12 37916 c:\windows\system32\dllcache\cb102.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 54528 c:\windows\system32\dllcache\cap7146.sys

- 2010-02-26 23:35 . 2008-04-14 11:00 54528 c:\windows\system32\dllcache\cap7146.sys

+ 2011-02-08 13:33 . 2001-08-18 06:36 74240 c:\windows\system32\dllcache\camexo20.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 10752 c:\windows\system32\dllcache\c_iscii.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 10752 c:\windows\system32\dllcache\c_iscii.dll

+ 2011-02-08 13:32 . 2008-04-14 08:16 18944 c:\windows\system32\dllcache\bthusb.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 30208 c:\windows\system32\dllcache\bthserv.dll

+ 2011-02-08 13:32 . 2008-04-14 08:16 36480 c:\windows\system32\dllcache\bthprint.sys

+ 2011-02-08 13:32 . 2008-04-14 08:16 37888 c:\windows\system32\dllcache\bthmodem.sys

+ 2011-02-08 13:32 . 2008-04-14 08:16 17024 c:\windows\system32\dllcache\bthenum.sys

+ 2011-02-08 13:32 . 2001-08-17 20:11 31529 c:\windows\system32\dllcache\brzwlan.sys

+ 2011-02-08 13:32 . 2001-08-17 21:12 10368 c:\windows\system32\dllcache\brusbscn.sys

+ 2011-02-08 13:32 . 2001-08-17 21:12 11008 c:\windows\system32\dllcache\brusbmdm.sys

+ 2011-02-08 13:32 . 2001-08-17 21:12 60416 c:\windows\system32\dllcache\brserwdm.sys

+ 2011-02-08 13:32 . 2001-08-17 21:12 39552 c:\windows\system32\dllcache\brparwdm.sys

+ 2011-02-08 13:32 . 2001-08-18 06:36 41472 c:\windows\system32\dllcache\brmfusb.dll

+ 2011-02-08 13:32 . 2001-08-18 06:36 32256 c:\windows\system32\dllcache\brmfrsmg.exe

+ 2011-02-08 13:32 . 2001-08-18 06:36 29696 c:\windows\system32\dllcache\brmflpt.dll

+ 2011-02-08 13:32 . 2001-08-18 06:36 81408 c:\windows\system32\dllcache\brmfcwia.dll

+ 2011-02-08 13:32 . 2001-08-18 06:36 15360 c:\windows\system32\dllcache\brmfbidi.dll

+ 2011-02-08 13:32 . 2001-08-17 21:12 12160 c:\windows\system32\dllcache\brfiltlo.sys

+ 2011-02-08 13:32 . 2001-08-18 06:36 12800 c:\windows\system32\dllcache\brevif.dll

+ 2011-02-08 13:32 . 2001-08-18 06:36 19456 c:\windows\system32\dllcache\brbidiif.dll

+ 2011-02-08 13:32 . 2008-04-14 08:16 11776 c:\windows\system32\dllcache\bdasup.sys

+ 2011-02-08 13:32 . 2001-08-17 20:11 26568 c:\windows\system32\dllcache\bcm4e5.sys

+ 2011-02-08 13:32 . 2001-08-17 20:11 54271 c:\windows\system32\dllcache\bcm42xx5.sys

+ 2011-02-08 13:32 . 2001-08-17 20:11 66557 c:\windows\system32\dllcache\bcm42u.sys

+ 2010-02-26 15:03 . 2008-04-14 00:06 14208 c:\windows\system32\dllcache\battc.sys

+ 2011-02-08 13:32 . 2001-08-17 20:48 36128 c:\windows\system32\dllcache\banshee.sys

+ 2011-02-08 13:32 . 2001-08-17 20:11 96640 c:\windows\system32\dllcache\b57xp32.sys

+ 2011-02-08 13:32 . 2001-08-17 20:13 89952 c:\windows\system32\dllcache\b1cbase.sys

+ 2011-02-08 13:32 . 2001-08-17 20:19 36992 c:\windows\system32\dllcache\aztw2320.sys

+ 2011-02-08 13:32 . 2001-08-17 20:13 37568 c:\windows\system32\dllcache\avmwan.sys

+ 2011-02-08 13:32 . 2001-08-18 06:36 87552 c:\windows\system32\dllcache\avmcoxp.dll

+ 2011-02-08 13:32 . 2008-04-14 08:16 13696 c:\windows\system32\dllcache\avcstrm.sys

+ 2011-02-08 13:32 . 2001-08-17 22:01 36096 c:\windows\system32\dllcache\avcaudio.sys

+ 2011-02-08 13:32 . 2008-04-14 08:16 38912 c:\windows\system32\dllcache\avc.sys

+ 2011-02-08 13:32 . 2008-04-14 13:41 17279 c:\windows\system32\dllcache\atv10nt5.dll

+ 2011-02-08 13:32 . 2008-04-14 13:41 14143 c:\windows\system32\dllcache\atv06nt5.dll

+ 2011-02-08 13:32 . 2008-04-14 13:41 25471 c:\windows\system32\dllcache\atv04nt5.dll

+ 2011-02-08 13:32 . 2008-04-14 13:41 11359 c:\windows\system32\dllcache\atv02nt5.dll

+ 2011-02-08 13:32 . 2008-04-14 13:41 21183 c:\windows\system32\dllcache\atv01nt5.dll

+ 2011-02-08 13:31 . 2001-08-17 20:49 23552 c:\windows\system32\dllcache\atixbar.sys

+ 2011-02-08 13:31 . 2001-08-17 20:49 19456 c:\windows\system32\dllcache\ativttxx.sys

+ 2011-02-08 13:31 . 2008-04-14 13:41 32768 c:\windows\system32\dllcache\ativtmxx.dll

+ 2011-02-08 13:31 . 2001-08-17 20:49 17152 c:\windows\system32\dllcache\atitvsnd.sys

+ 2011-02-08 13:31 . 2001-08-17 20:49 17152 c:\windows\system32\dllcache\atitunep.sys

+ 2011-02-08 13:31 . 2001-08-17 20:49 26880 c:\windows\system32\dllcache\atirtsnd.sys

+ 2011-02-08 13:31 . 2001-08-17 20:49 49920 c:\windows\system32\dllcache\atirtcap.sys

+ 2011-02-08 13:31 . 2001-08-17 20:48 70528 c:\windows\system32\dllcache\atiragem.sys

+ 2011-02-08 13:31 . 2001-08-17 20:49 10240 c:\windows\system32\dllcache\atipcxxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 63488 c:\windows\system32\dllcache\atinxsxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 31744 c:\windows\system32\dllcache\atinxbxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 73216 c:\windows\system32\dllcache\atintuxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 13824 c:\windows\system32\dllcache\atinttxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 28672 c:\windows\system32\dllcache\atinsnxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 52224 c:\windows\system32\dllcache\atinraxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 14336 c:\windows\system32\dllcache\atinpdxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 13824 c:\windows\system32\dllcache\atinmdxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 57856 c:\windows\system32\dllcache\atinbtxx.sys

+ 2011-02-08 13:31 . 2001-08-17 20:49 75136 c:\windows\system32\dllcache\atimpae.sys

+ 2011-02-08 13:31 . 2001-08-18 06:36 37376 c:\windows\system32\dllcache\atievxx.exe

+ 2011-02-08 13:31 . 2001-08-17 20:49 46464 c:\windows\system32\dllcache\atibt829.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 34735 c:\windows\system32\dllcache\ati1xsxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 29455 c:\windows\system32\dllcache\ati1xbxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 36463 c:\windows\system32\dllcache\ati1tuxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 21343 c:\windows\system32\dllcache\ati1ttxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 26367 c:\windows\system32\dllcache\ati1snxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 63663 c:\windows\system32\dllcache\ati1rvxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 30671 c:\windows\system32\dllcache\ati1raxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 12047 c:\windows\system32\dllcache\ati1pdxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 11615 c:\windows\system32\dllcache\ati1mdxx.sys

+ 2011-02-08 13:31 . 2008-04-14 06:04 56623 c:\windows\system32\dllcache\ati1btxx.sys

+ 2011-02-08 13:31 . 2001-08-17 21:57 77568 c:\windows\system32\dllcache\ati.sys

+ 2011-02-08 13:31 . 2001-08-17 22:55 96128 c:\windows\system32\dllcache\ati.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 96512 c:\windows\system32\dllcache\atapi.sys

+ 2011-02-08 13:31 . 2001-08-17 20:12 97354 c:\windows\system32\dllcache\aspndis3.sys

+ 2011-02-08 13:31 . 2001-08-17 21:51 14848 c:\windows\system32\dllcache\asc3550.sys

+ 2011-02-08 13:31 . 2001-08-17 21:52 22400 c:\windows\system32\dllcache\asc3350p.sys

+ 2011-02-08 13:31 . 2001-08-17 21:52 26496 c:\windows\system32\dllcache\asc.sys

+ 2008-04-14 00:21 . 2008-04-14 11:00 60800 c:\windows\system32\dllcache\arp1394.sys

+ 2011-02-08 13:31 . 2008-04-14 06:05 36224 c:\windows\system32\dllcache\an983.sys

+ 2011-02-08 13:31 . 2001-08-17 21:52 12032 c:\windows\system32\dllcache\amsint.sys

+ 2008-04-14 00:01 . 2008-04-14 11:00 37760 c:\windows\system32\dllcache\amdk7.sys

+ 2008-04-14 00:01 . 2008-04-14 11:00 37376 c:\windows\system32\dllcache\amdk6.sys

+ 2011-02-08 13:31 . 2008-04-14 08:06 43008 c:\windows\system32\dllcache\amdagp.sys

+ 2011-02-08 13:31 . 2001-08-17 20:11 16969 c:\windows\system32\dllcache\amb8002.sys

+ 2011-02-08 13:31 . 2008-04-14 08:06 42752 c:\windows\system32\dllcache\alim1541.sys

+ 2011-02-08 13:31 . 2001-08-17 21:49 26624 c:\windows\system32\dllcache\alifir.sys

+ 2011-02-08 13:31 . 2001-08-17 20:11 27678 c:\windows\system32\dllcache\ali5261.sys

+ 2011-02-08 13:31 . 2001-08-17 22:07 56960 c:\windows\system32\dllcache\aic78xx.sys

+ 2011-02-08 13:31 . 2001-08-17 22:07 55168 c:\windows\system32\dllcache\aic78u2.sys

+ 2011-02-08 13:31 . 2001-08-17 21:52 12800 c:\windows\system32\dllcache\aha154x.sys

+ 2011-02-08 13:31 . 2008-04-14 08:06 44928 c:\windows\system32\dllcache\agpcpq.sys

+ 2011-02-08 13:31 . 2008-04-14 08:06 42368 c:\windows\system32\dllcache\agp440.sys

+ 2011-02-08 13:30 . 2001-08-17 20:11 46112 c:\windows\system32\dllcache\adptsf50.sys

+ 2011-02-08 13:30 . 2008-04-14 06:06 10880 c:\windows\system32\dllcache\admjoy.sys

+ 2011-02-08 13:30 . 2001-08-17 20:11 20160 c:\windows\system32\dllcache\adm8511.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 11648 c:\windows\system32\dllcache\acpiec.sys

+ 2011-02-08 13:30 . 2001-08-18 06:36 61440 c:\windows\system32\dllcache\acerscad.dll

+ 2011-02-08 13:30 . 2008-04-14 06:06 84480 c:\windows\system32\dllcache\ac97via.sys

+ 2011-02-08 13:30 . 2001-08-17 20:20 96256 c:\windows\system32\dllcache\ac97intc.sys

+ 2011-02-08 13:30 . 2001-08-17 21:52 23552 c:\windows\system32\dllcache\abp480n5.sys

+ 2011-02-08 13:30 . 2001-08-18 06:36 98304 c:\windows\system32\dllcache\a3d.dll

+ 2011-02-08 13:30 . 2001-08-17 22:55 38400 c:\windows\system32\dllcache\8514a.dll

+ 2011-02-08 13:30 . 2008-04-14 08:16 48128 c:\windows\system32\dllcache\61883.sys

+ 2011-02-08 13:30 . 2008-04-14 08:10 12288 c:\windows\system32\dllcache\4mmdat.sys

+ 2011-02-08 13:30 . 2001-08-17 22:06 11264 c:\windows\system32\dllcache\1394vdbg.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 53376 c:\windows\system32\dllcache\1394bus.sys

Link to post
Share on other sites

+ 2010-02-26 23:38 . 2011-02-08 12:43 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

- 2010-02-26 23:38 . 2010-02-26 23:38 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

+ 2010-02-26 23:38 . 2011-02-06 11:16 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

- 2010-02-26 23:38 . 2010-02-26 23:38 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

- 2010-02-26 23:38 . 2010-02-26 23:38 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2011-02-07 05:39 . 2011-02-06 11:16 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2011-02-08 14:06 . 2008-04-14 11:00 31232 c:\windows\LastGood\system32\dllcache\weitekp9.sys

+ 2011-02-08 14:06 . 2008-04-14 11:00 41600 c:\windows\LastGood\system32\dllcache\weitekp9.dll

+ 2011-02-08 14:06 . 2008-04-14 11:00 48256 c:\windows\LastGood\system32\dllcache\w32.dll

+ 2011-02-08 14:05 . 2008-04-14 11:00 86073 c:\windows\LastGood\system32\dllcache\voicesub.dll

+ 2011-02-08 14:04 . 2008-04-14 11:00 76288 c:\windows\LastGood\system32\dllcache\uniime.dll

+ 2011-02-08 14:03 . 2008-04-14 11:00 14336 c:\windows\LastGood\system32\dllcache\tsprof.exe

+ 2011-02-08 14:02 . 2008-04-14 11:00 10240 c:\windows\LastGood\system32\dllcache\tmigrate.dll

+ 2011-02-08 14:02 . 2008-04-14 11:00 44032 c:\windows\LastGood\system32\dllcache\tintlphr.exe

+ 2011-02-08 14:02 . 2008-04-14 11:00 19464 c:\windows\LastGood\system32\dllcache\tdspx.sys

+ 2011-02-08 14:02 . 2008-04-14 11:00 21896 c:\windows\LastGood\system32\dllcache\tdipx.sys

+ 2011-02-08 14:02 . 2008-04-14 11:00 13192 c:\windows\LastGood\system32\dllcache\tdasync.sys

+ 2011-02-08 13:30 . 2003-03-25 00:52 16384 c:\windows\LastGood\system32\dllcache\tcptsat.dll

+ 2011-02-08 13:30 . 2003-03-25 00:52 32827 c:\windows\LastGood\system32\dllcache\tcptest.exe

+ 2011-02-08 13:59 . 2008-04-14 11:00 39936 c:\windows\LastGood\system32\dllcache\snmpthrd.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 10240 c:\windows\LastGood\system32\dllcache\snmpstup.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 33280 c:\windows\LastGood\system32\dllcache\snmp.exe

+ 2011-02-08 13:59 . 2008-04-14 11:00 15872 c:\windows\LastGood\system32\dllcache\smierrsm.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 31744 c:\windows\LastGood\system32\dllcache\smb6w.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 31744 c:\windows\LastGood\system32\dllcache\sma3w.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 38912 c:\windows\LastGood\system32\dllcache\sm9aw.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 26624 c:\windows\LastGood\system32\dllcache\sm93w.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 26624 c:\windows\LastGood\system32\dllcache\sm92w.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 26112 c:\windows\LastGood\system32\dllcache\sm90w.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 26112 c:\windows\LastGood\system32\dllcache\sm8dw.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 29184 c:\windows\LastGood\system32\dllcache\sm8cw.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 26112 c:\windows\LastGood\system32\dllcache\sm8aw.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 26112 c:\windows\LastGood\system32\dllcache\sm89w.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 30208 c:\windows\LastGood\system32\dllcache\sm87w.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 30208 c:\windows\LastGood\system32\dllcache\sm81w.dll

+ 2011-02-08 13:58 . 2008-04-14 11:00 25088 c:\windows\LastGood\system32\dllcache\sm59w.dll

+ 2011-02-08 13:57 . 2008-04-14 11:00 18944 c:\windows\LastGood\system32\dllcache\simptcp.dll

+ 2011-02-08 13:30 . 2003-03-25 00:52 16437 c:\windows\LastGood\system32\dllcache\shtml.exe

+ 2011-02-08 13:30 . 2003-03-25 00:52 20536 c:\windows\LastGood\system32\dllcache\shtml.dll

+ 2011-02-08 13:55 . 2008-04-14 11:00 79872 c:\windows\LastGood\system32\dllcache\rwia330.dll

+ 2011-02-08 13:55 . 2008-04-14 11:00 79872 c:\windows\LastGood\system32\dllcache\rwia001.dll

+ 2011-02-08 13:55 . 2008-04-14 11:00 29184 c:\windows\LastGood\system32\dllcache\rw330ext.dll

+ 2011-02-08 13:55 . 2008-04-14 11:00 27648 c:\windows\LastGood\system32\dllcache\rw001ext.dll

+ 2011-02-08 13:54 . 2008-04-14 11:00 14848 c:\windows\LastGood\system32\dllcache\register.exe

+ 2011-02-08 13:53 . 2008-04-14 11:00 20736 c:\windows\LastGood\system32\dllcache\ramdisk.sys

+ 2011-02-08 13:53 . 2008-04-14 11:00 16384 c:\windows\LastGood\system32\dllcache\quser.exe

+ 2011-02-08 13:52 . 2008-04-14 11:00 11264 c:\windows\LastGood\system32\dllcache\pmxmcro.dll

+ 2011-02-08 13:52 . 2008-04-14 11:00 67584 c:\windows\LastGood\system32\dllcache\pmigrate.dll

+ 2011-02-08 13:52 . 2008-04-14 11:00 70144 c:\windows\LastGood\system32\dllcache\pintlphr.exe

+ 2011-02-08 13:52 . 2008-04-14 11:00 53760 c:\windows\LastGood\system32\dllcache\pintlcsd.dll

+ 2011-02-08 13:51 . 2008-04-14 11:00 15360 c:\windows\LastGood\system32\dllcache\padrs804.dll

+ 2011-02-08 13:51 . 2008-04-14 11:00 14336 c:\windows\LastGood\system32\dllcache\padrs412.dll

+ 2011-02-08 13:51 . 2008-04-14 11:00 36927 c:\windows\LastGood\system32\dllcache\padrs411.dll

+ 2011-02-08 13:51 . 2008-04-14 11:00 15872 c:\windows\LastGood\system32\dllcache\padrs404.dll

+ 2011-02-08 13:47 . 2008-04-14 11:00 40960 c:\windows\LastGood\system32\dllcache\msiregmv.exe

+ 2011-02-08 13:47 . 2008-04-14 11:00 98304 c:\windows\LastGood\system32\dllcache\msir3jp.dll

+ 2011-02-08 13:46 . 2008-04-14 11:00 34304 c:\windows\LastGood\system32\dllcache\migisol.exe

+ 2011-02-08 13:46 . 2008-04-14 11:00 92416 c:\windows\LastGood\system32\dllcache\mga.sys

+ 2011-02-08 13:46 . 2008-04-14 11:00 92032 c:\windows\LastGood\system32\dllcache\mga.dll

+ 2011-02-08 13:45 . 2008-04-14 11:00 18944 c:\windows\LastGood\system32\dllcache\lprmon.dll

+ 2011-02-08 13:45 . 2008-04-14 11:00 22528 c:\windows\LastGood\system32\dllcache\lpdsvc.dll

+ 2011-02-08 13:45 . 2008-04-14 11:00 33792 c:\windows\LastGood\system32\dllcache\lmmib2.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 70656 c:\windows\LastGood\system32\dllcache\korwbrkr.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 18432 c:\windows\LastGood\system32\dllcache\jupiw.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 35328 c:\windows\LastGood\system32\dllcache\iprip.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 59392 c:\windows\LastGood\system32\dllcache\imscinst.exe

+ 2011-02-08 13:43 . 2008-04-14 11:00 59904 c:\windows\LastGood\system32\dllcache\imkrinst.exe

+ 2011-02-08 13:43 . 2008-04-14 11:00 45109 c:\windows\LastGood\system32\dllcache\imjpuex.exe

+ 2011-02-08 13:42 . 2008-04-14 11:00 81976 c:\windows\LastGood\system32\dllcache\imjpdct.dll

+ 2011-02-08 13:42 . 2008-04-14 11:00 57398 c:\windows\LastGood\system32\dllcache\imjpdadm.exe

+ 2011-02-08 13:42 . 2008-04-14 11:00 44032 c:\windows\LastGood\system32\dllcache\imekrmig.exe

+ 2011-02-08 13:42 . 2008-04-14 11:00 86016 c:\windows\LastGood\system32\dllcache\imekrmbx.dll

+ 2011-02-08 13:39 . 2008-04-14 11:00 39936 c:\windows\LastGood\system32\dllcache\hostmib.dll

+ 2011-02-08 13:39 . 2008-04-14 11:00 36864 c:\windows\LastGood\system32\dllcache\hanjadic.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 11264 c:\windows\LastGood\system32\dllcache\fxssend.exe

+ 2011-02-08 13:38 . 2008-04-14 11:00 31744 c:\windows\LastGood\system32\dllcache\fxsroute.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 23552 c:\windows\LastGood\system32\dllcache\fxsmon.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 23552 c:\windows\LastGood\system32\dllcache\fxsext32.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 55296 c:\windows\LastGood\system32\dllcache\fxsevent.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 26624 c:\windows\LastGood\system32\dllcache\fxsdrv.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 72192 c:\windows\LastGood\system32\dllcache\fxscom.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 20538 c:\windows\LastGood\system32\dllcache\fpremadm.exe

+ 2011-02-08 13:29 . 2003-03-25 00:52 20541 c:\windows\LastGood\system32\dllcache\fpexedll.dll

+ 2011-02-08 13:38 . 2003-03-25 00:52 94208 c:\windows\LastGood\system32\dllcache\fpencode.dll

+ 2011-02-08 13:38 . 2003-03-25 00:52 20541 c:\windows\LastGood\system32\dllcache\fpadmdll.dll

+ 2011-02-08 13:38 . 2003-03-25 00:52 24632 c:\windows\LastGood\system32\dllcache\fpadmcgi.exe

+ 2011-02-08 13:29 . 2003-03-25 00:52 14608 c:\windows\LastGood\system32\dllcache\fp98sadm.exe

+ 2011-02-08 13:29 . 2003-03-25 00:52 49212 c:\windows\LastGood\system32\dllcache\fp4awebs.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 32826 c:\windows\LastGood\system32\dllcache\fp4avss.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 41020 c:\windows\LastGood\system32\dllcache\fp4avnb.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 49210 c:\windows\LastGood\system32\dllcache\fp4areg.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 82035 c:\windows\LastGood\system32\dllcache\fp4anscp.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 14848 c:\windows\LastGood\system32\dllcache\flattemp.exe

+ 2011-02-08 13:38 . 2001-08-17 20:10 22090 c:\windows\LastGood\system32\dllcache\fem556n5.sys

+ 2011-02-08 13:59 . 2001-08-18 06:36 12288 c:\windows\LastGood\system32\dllcache\EXCH_smtpctrs.dll

+ 2011-02-08 13:56 . 2001-08-18 06:36 26112 c:\windows\LastGood\system32\dllcache\EXCH_seos.dll

+ 2011-02-08 13:56 . 2001-08-18 06:36 57856 c:\windows\LastGood\system32\dllcache\EXCH_scripto.dll

+ 2011-02-08 13:54 . 2001-08-18 06:36 23040 c:\windows\LastGood\system32\dllcache\EXCH_regtrace.exe

+ 2011-02-08 13:50 . 2001-08-18 06:36 38912 c:\windows\LastGood\system32\dllcache\EXCH_ntfsdrv.dll

+ 2011-02-08 13:45 . 2001-08-18 06:36 65536 c:\windows\LastGood\system32\dllcache\EXCH_mailmsg.dll

+ 2011-02-08 13:38 . 2001-08-18 06:36 43520 c:\windows\LastGood\system32\dllcache\EXCH_fcachdll.dll

+ 2011-02-08 13:31 . 2001-08-18 06:36 45056 c:\windows\LastGood\system32\dllcache\EXCH_aqadmin.dll

+ 2011-02-08 13:37 . 2008-04-14 11:00 92160 c:\windows\LastGood\system32\dllcache\evntwin.exe

+ 2011-02-08 13:37 . 2008-04-14 11:00 24064 c:\windows\LastGood\system32\dllcache\evntcmd.exe

+ 2011-02-08 13:37 . 2008-04-14 11:00 25856 c:\windows\LastGood\system32\dllcache\et4000.sys

+ 2011-02-08 13:37 . 2008-04-14 11:00 45056 c:\windows\LastGood\system32\dllcache\esunid.dll

+ 2011-02-08 13:37 . 2008-04-14 11:00 57856 c:\windows\LastGood\system32\dllcache\esuimgd.dll

+ 2011-02-08 13:37 . 2008-04-14 11:00 31744 c:\windows\LastGood\system32\dllcache\esucmd.dll

+ 2011-02-08 13:36 . 2001-08-17 20:10 19996 c:\windows\LastGood\system32\dllcache\em556n4.sys

+ 2011-02-08 13:34 . 2008-04-14 11:00 18944 c:\windows\LastGood\system32\dllcache\cprofile.exe

+ 2011-02-08 13:34 . 2008-04-14 11:00 57399 c:\windows\LastGood\system32\dllcache\cplexe.exe

+ 2011-02-08 13:33 . 2008-04-14 11:00 56320 c:\windows\LastGood\system32\dllcache\chtskdic.dll

+ 2011-02-08 13:33 . 2008-04-14 11:00 97792 c:\windows\LastGood\system32\dllcache\chtmbx.dll

+ 2011-02-08 13:33 . 2008-04-14 11:00 14336 c:\windows\LastGood\system32\dllcache\chgusr.exe

+ 2011-02-08 13:33 . 2008-04-14 11:00 15872 c:\windows\LastGood\system32\dllcache\chgport.exe

+ 2011-02-08 13:33 . 2008-04-14 11:00 13312 c:\windows\LastGood\system32\dllcache\chglogon.exe

+ 2011-02-08 13:33 . 2008-04-14 11:00 54528 c:\windows\LastGood\system32\dllcache\cap7146.sys

+ 2011-02-08 13:33 . 2008-04-14 11:00 10752 c:\windows\LastGood\system32\dllcache\c_iscii.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 16439 c:\windows\LastGood\system32\dllcache\author.exe

+ 2011-02-08 13:29 . 2003-03-25 00:52 20540 c:\windows\LastGood\system32\dllcache\author.dll

+ 2011-02-08 13:31 . 2008-04-14 11:00 19456 c:\windows\LastGood\system32\dllcache\agt0804.dll

+ 2011-02-08 13:31 . 2008-04-14 11:00 19456 c:\windows\LastGood\system32\dllcache\agt0412.dll

+ 2011-02-08 13:31 . 2008-04-14 11:00 19456 c:\windows\LastGood\system32\dllcache\agt0411.dll

+ 2011-02-08 13:31 . 2008-04-14 11:00 19456 c:\windows\LastGood\system32\dllcache\agt040d.dll

+ 2011-02-08 13:31 . 2008-04-14 11:00 19456 c:\windows\LastGood\system32\dllcache\agt0404.dll

+ 2011-02-08 13:31 . 2008-04-14 11:00 19456 c:\windows\LastGood\system32\dllcache\agt0401.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 16439 c:\windows\LastGood\system32\dllcache\admin.exe

+ 2010-02-26 15:03 . 2008-04-14 00:06 8832 c:\windows\system32\dllcache\wmiacpi.sys

- 2010-02-26 15:01 . 2008-04-14 11:00 2176 c:\windows\system32\dllcache\vga.drv

+ 2008-04-14 11:00 . 2008-04-14 11:00 2176 c:\windows\system32\dllcache\vga.drv

- 2010-02-26 15:01 . 2008-04-14 11:00 9008 c:\windows\system32\dllcache\ver.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 9008 c:\windows\system32\dllcache\ver.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 4736 c:\windows\system32\dllcache\usbd.sys

- 2009-11-27 16:07 . 2009-11-27 16:07 8704 c:\windows\system32\dllcache\tsbyuv.dll

+ 2001-08-17 22:36 . 2009-11-27 16:07 8704 c:\windows\system32\dllcache\tsbyuv.dll

- 2010-02-26 15:01 . 2008-04-14 11:00 4048 c:\windows\system32\dllcache\timer.drv

+ 2008-04-14 11:00 . 2008-04-14 11:00 4048 c:\windows\system32\dllcache\timer.drv

- 2010-02-26 15:01 . 2008-04-14 11:00 3360 c:\windows\system32\dllcache\system.drv

+ 2008-04-14 11:00 . 2008-04-14 11:00 3360 c:\windows\system32\dllcache\system.drv

+ 2011-02-08 14:01 . 2001-08-17 22:02 3968 c:\windows\system32\dllcache\swusbflt.sys

+ 2008-04-14 00:09 . 2008-04-14 11:00 4352 c:\windows\system32\dllcache\swenum.sys

+ 2001-08-17 22:36 . 2008-04-14 11:00 8192 c:\windows\system32\dllcache\streamci.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 1744 c:\windows\system32\dllcache\sound.drv

- 2010-02-26 15:01 . 2008-04-14 11:00 1744 c:\windows\system32\dllcache\sound.drv

+ 2011-02-08 13:59 . 2001-08-17 21:56 7552 c:\windows\system32\dllcache\sonypvu1.sys

+ 2011-02-08 13:59 . 2001-08-17 21:53 9600 c:\windows\system32\dllcache\sonymc.sys

+ 2011-02-08 13:59 . 2008-04-14 08:10 7552 c:\windows\system32\dllcache\sonyait.sys

+ 2011-02-08 13:59 . 2001-08-17 21:53 7040 c:\windows\system32\dllcache\snyaitmc.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\smimsgif.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\smimsgif.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\smierrsy.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\smierrsy.dll

+ 2011-02-08 13:58 . 2008-04-14 08:06 6912 c:\windows\system32\dllcache\smbclass.sys

+ 2011-02-08 13:58 . 2008-04-14 08:06 5888 c:\windows\system32\dllcache\smbali.sys

+ 2011-02-08 13:56 . 2001-08-17 21:53 6912 c:\windows\system32\dllcache\seaddsmc.sys

+ 2011-02-08 13:53 . 2001-08-17 21:53 3328 c:\windows\system32\dllcache\qv2kux.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 9728 c:\windows\system32\dllcache\query.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 9728 c:\windows\system32\dllcache\query.exe

+ 2011-02-08 13:53 . 2008-04-14 08:10 6016 c:\windows\system32\dllcache\qic157.sys

+ 2011-02-08 13:52 . 2008-04-14 08:10 8832 c:\windows\system32\dllcache\powerfil.sys

+ 2011-02-08 13:52 . 2001-08-17 21:53 7168 c:\windows\system32\dllcache\pnrmc.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\pmxgl.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 6144 c:\windows\system32\dllcache\pmxgl.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 3328 c:\windows\system32\dllcache\pciide.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 3456 c:\windows\system32\dllcache\oprghdlr.sys

+ 2011-02-08 13:48 . 2001-08-18 06:36 7168 c:\windows\system32\dllcache\mxport.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 2032 c:\windows\system32\dllcache\mouse.drv

- 2010-02-26 15:01 . 2008-04-14 11:00 2032 c:\windows\system32\dllcache\mouse.drv

+ 2011-02-08 13:45 . 2001-08-17 21:52 7424 c:\windows\system32\dllcache\mammoth.sys

+ 2011-02-08 13:45 . 2008-04-14 08:10 7040 c:\windows\system32\dllcache\ltotape.sys

+ 2011-02-08 13:45 . 2001-08-17 21:53 4992 c:\windows\system32\dllcache\loop.sys

- 2010-02-26 15:01 . 2008-04-14 11:00 2000 c:\windows\system32\dllcache\keyboard.drv

+ 2008-04-14 11:00 . 2008-04-14 11:00 2000 c:\windows\system32\dllcache\keyboard.drv

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdvntc.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdvntc.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdusa.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdusa.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdurdu.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdurdu.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\kbdth3.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 6144 c:\windows\system32\dllcache\kbdth3.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 6144 c:\windows\system32\dllcache\kbdth2.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\kbdth2.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdth1.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdth1.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdth0.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdth0.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdsyr2.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdsyr2.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdsyr1.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdsyr1.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 7680 c:\windows\system32\dllcache\kbdnecnt.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 7680 c:\windows\system32\dllcache\kbdnecnt.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 9216 c:\windows\system32\dllcache\kbdnecat.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 9216 c:\windows\system32\dllcache\kbdnecat.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 7168 c:\windows\system32\dllcache\kbdnec95.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 7168 c:\windows\system32\dllcache\kbdnec95.dll

+ 2011-02-08 13:44 . 2001-08-18 06:36 8192 c:\windows\system32\dllcache\kbdkor.dll

+ 2011-02-08 13:44 . 2001-08-18 06:36 8704 c:\windows\system32\dllcache\kbdjpn.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdintel.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdintel.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdintam.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdintam.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\kbdinpun.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 6144 c:\windows\system32\dllcache\kbdinpun.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdinmar.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdinmar.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdinkan.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdinkan.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdinhin.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdinhin.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdinguj.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdinguj.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdindev.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdindev.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdheb.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdheb.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5120 c:\windows\system32\dllcache\kbdgeo.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5120 c:\windows\system32\dllcache\kbdgeo.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbdfa.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbdfa.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbddiv2.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbddiv2.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbddiv1.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbddiv1.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5120 c:\windows\system32\dllcache\kbdarmw.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5120 c:\windows\system32\dllcache\kbdarmw.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5120 c:\windows\system32\dllcache\kbdarme.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5120 c:\windows\system32\dllcache\kbdarme.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbda3.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbda3.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbda2.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbda2.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 5632 c:\windows\system32\dllcache\kbda1.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 5632 c:\windows\system32\dllcache\kbda1.dll

+ 2011-02-08 13:44 . 2008-04-14 13:39 6144 c:\windows\system32\dllcache\kbd106.dll

+ 2011-02-08 13:43 . 2001-08-17 22:55 6144 c:\windows\system32\dllcache\kbd101c.dll

+ 2011-02-08 13:43 . 2001-08-17 22:55 6144 c:\windows\system32\dllcache\kbd101b.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\kbd101a.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 6144 c:\windows\system32\dllcache\kbd101a.dll

+ 2011-02-08 13:43 . 2008-04-14 08:10 5504 c:\windows\system32\dllcache\intelide.sys

+ 2011-02-08 13:42 . 2001-08-18 06:34 9216 c:\windows\system32\dllcache\ibmsgnet.dll

+ 2011-02-08 13:41 . 2008-04-14 08:11 8576 c:\windows\system32\dllcache\i2omgmt.sys

+ 2011-02-08 13:40 . 2001-08-18 06:36 9759 c:\windows\system32\dllcache\hsf_inst.dll

+ 2011-02-08 13:40 . 2001-08-17 21:52 5760 c:\windows\system32\dllcache\hpt4qic.sys

+ 2011-02-08 13:39 . 2001-08-17 22:02 2688 c:\windows\system32\dllcache\hidswvd.sys

+ 2011-02-08 13:39 . 2001-08-17 22:02 8576 c:\windows\system32\dllcache\hidgame.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 7168 c:\windows\system32\dllcache\hccoin.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 6144 c:\windows\system32\dllcache\ftlx041e.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 6144 c:\windows\system32\dllcache\ftlx041e.dll

+ 2011-02-08 13:37 . 2001-08-17 21:52 7040 c:\windows\system32\dllcache\exabyte2.sys

+ 2010-02-26 15:03 . 2001-08-17 13:46 6400 c:\windows\system32\dllcache\enum1394.sys

+ 2011-02-08 13:36 . 2001-08-17 21:53 7296 c:\windows\system32\dllcache\elmsmc.sys

+ 2011-02-08 13:35 . 2001-08-17 21:47 8704 c:\windows\system32\dllcache\dot4scan.sys

+ 2011-02-08 13:35 . 2008-04-14 08:10 8320 c:\windows\system32\dllcache\dlttape.sys

+ 2011-02-08 13:35 . 2001-08-18 06:36 6216 c:\windows\system32\dllcache\divaci.dll

+ 2011-02-08 13:35 . 2001-08-18 06:36 6729 c:\windows\system32\dllcache\disrvci.dll

+ 2011-02-08 13:34 . 2001-08-17 21:52 7424 c:\windows\system32\dllcache\ddsmc.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 3584 c:\windows\system32\dllcache\cwcosnt5.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 3072 c:\windows\system32\dllcache\cwbmidi.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 3072 c:\windows\system32\dllcache\cwbase.sys

+ 2011-02-08 13:34 . 2001-08-18 06:36 4096 c:\windows\system32\dllcache\ctwdm32.dll

+ 2011-02-08 13:34 . 2001-08-17 20:19 3712 c:\windows\system32\dllcache\ctljystk.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 6912 c:\windows\system32\dllcache\ctlfacem.sys

+ 2011-02-08 13:33 . 2001-08-17 21:51 6656 c:\windows\system32\dllcache\cmdide.sys

+ 2011-02-08 13:33 . 2008-04-14 08:11 8192 c:\windows\system32\dllcache\changer.sys

- 2010-02-26 23:35 . 2008-04-14 11:00 9728 c:\windows\system32\dllcache\change.exe

+ 2010-02-26 23:35 . 2004-08-04 12:00 9728 c:\windows\system32\dllcache\change.exe

+ 2011-02-08 13:33 . 2001-08-17 21:52 7680 c:\windows\system32\dllcache\cd20xrnt.sys

- 2010-02-26 23:35 . 2008-04-14 11:00 6656 c:\windows\system32\dllcache\c_is2022.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 6656 c:\windows\system32\dllcache\c_is2022.dll

+ 2011-02-08 13:32 . 2001-08-18 06:36 9728 c:\windows\system32\dllcache\brserif.dll

+ 2011-02-08 13:32 . 2001-08-18 06:36 5120 c:\windows\system32\dllcache\brscnrsm.dll

+ 2011-02-08 13:32 . 2001-08-17 21:12 3168 c:\windows\system32\dllcache\brparimg.sys

+ 2011-02-08 13:32 . 2001-08-17 21:12 3968 c:\windows\system32\dllcache\brfiltup.sys

+ 2011-02-08 13:32 . 2001-08-17 21:12 2944 c:\windows\system32\dllcache\brfilt.sys

+ 2011-02-08 13:32 . 2001-08-18 06:36 9728 c:\windows\system32\dllcache\brcoinst.dll

+ 2010-02-26 15:05 . 2001-08-17 13:59 3072 c:\windows\system32\dllcache\audstub.sys

+ 2011-02-08 13:31 . 2001-08-17 20:49 9472 c:\windows\system32\dllcache\ativmdcd.sys

+ 2011-02-08 13:31 . 2001-08-17 21:47 6272 c:\windows\system32\dllcache\apmbatt.sys

+ 2011-02-08 13:31 . 2001-08-17 21:51 5248 c:\windows\system32\dllcache\aliide.sys

+ 2011-02-08 13:31 . 2008-04-14 13:41 3775 c:\windows\system32\dllcache\adv11nt5.dll

+ 2011-02-08 13:31 . 2008-04-14 13:41 3711 c:\windows\system32\dllcache\adv09nt5.dll

+ 2011-02-08 13:31 . 2008-04-14 13:41 3135 c:\windows\system32\dllcache\adv08nt5.dll

+ 2011-02-08 13:31 . 2008-04-14 13:41 3647 c:\windows\system32\dllcache\adv07nt5.dll

+ 2011-02-08 13:30 . 2008-04-14 13:41 3615 c:\windows\system32\dllcache\adv05nt5.dll

+ 2011-02-08 13:30 . 2008-04-14 13:41 4255 c:\windows\system32\dllcache\adv01nt5.dll

+ 2011-02-08 13:30 . 2001-08-17 21:53 7424 c:\windows\system32\dllcache\adicvls.sys

+ 2011-02-08 13:59 . 2008-04-14 11:00 8704 c:\windows\LastGood\system32\dllcache\snmptrap.exe

+ 2011-02-08 13:59 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\snmpmib.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\smimsgif.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\smierrsy.dll

+ 2011-02-08 13:53 . 2008-04-14 11:00 9728 c:\windows\LastGood\system32\dllcache\query.exe

+ 2011-02-08 13:52 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\pmxgl.dll

+ 2011-02-08 13:46 . 2008-04-14 11:00 7680 c:\windows\LastGood\system32\dllcache\migregdb.exe

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdvntc.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdusa.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdurdu.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\kbdth3.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\kbdth2.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdth1.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdth0.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdsyr2.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdsyr1.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 7680 c:\windows\LastGood\system32\dllcache\kbdnecnt.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 9216 c:\windows\LastGood\system32\dllcache\kbdnecat.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 7168 c:\windows\LastGood\system32\dllcache\kbdnec95.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\kbdlk41j.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 6656 c:\windows\LastGood\system32\dllcache\kbdlk41a.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdintel.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdintam.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\kbdinpun.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdinmar.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdinkan.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdinhin.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdinguj.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdindev.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 7168 c:\windows\LastGood\system32\dllcache\kbdibm02.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdheb.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5120 c:\windows\LastGood\system32\dllcache\kbdgeo.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbdfa.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbddiv2.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbddiv1.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\kbdax2.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5120 c:\windows\LastGood\system32\dllcache\kbdarmw.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5120 c:\windows\LastGood\system32\dllcache\kbdarme.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbda3.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbda2.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 5632 c:\windows\LastGood\system32\dllcache\kbda1.dll

+ 2011-02-08 13:44 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\kbd106n.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\kbd101a.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\kbd101.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 6656 c:\windows\LastGood\system32\dllcache\fxsres.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 8704 c:\windows\LastGood\system32\dllcache\fxsperf.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 6144 c:\windows\LastGood\system32\dllcache\ftlx041e.dll

+ 2011-02-08 13:37 . 2008-04-14 11:00 7168 c:\windows\LastGood\system32\dllcache\f3ahvoas.dll

+ 2011-02-08 13:59 . 2001-08-18 06:36 7168 c:\windows\LastGood\system32\dllcache\EXCH_snprfdll.dll

+ 2011-02-08 13:30 . 2001-08-18 06:36 5632 c:\windows\LastGood\system32\dllcache\EXCH_adsiisex.dll

+ 2011-02-08 13:33 . 2008-04-14 11:00 9728 c:\windows\LastGood\system32\dllcache\change.exe

+ 2011-02-08 13:33 . 2008-04-14 11:00 6656 c:\windows\LastGood\system32\dllcache\c_is2022.dll

+ 2008-04-14 05:42 . 2008-04-14 11:00 483840 c:\windows\system32\dllcache\wzcsvc.dll

+ 2010-02-26 23:31 . 2009-08-07 03:24 209632 c:\windows\system32\dllcache\wuweb.dll

+ 2010-02-26 23:31 . 2009-08-07 03:24 327896 c:\windows\system32\dllcache\wucltui.dll

+ 2010-02-26 23:31 . 2009-08-07 03:23 575704 c:\windows\system32\dllcache\wuapi.dll

+ 2008-04-14 11:00 . 2008-04-14 11:00 108032 c:\windows\system32\dllcache\wshbth.dll

+ 2011-02-08 14:06 . 2001-08-17 21:28 701386 c:\windows\system32\dllcache\wdhaalba.sys

+ 2001-08-17 22:36 . 2008-04-14 11:00 102457 c:\windows\system32\dllcache\usrv42a.dll

+ 2001-08-17 22:36 . 2008-04-14 11:00 323641 c:\windows\system32\dllcache\usrdtea.dll

+ 2011-02-08 14:04 . 2001-08-17 21:28 793598 c:\windows\system32\dllcache\usr1806.sys

+ 2011-02-08 14:04 . 2001-08-17 21:28 794654 c:\windows\system32\dllcache\usr1801.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 143872 c:\windows\system32\dllcache\usbport.sys

+ 2011-02-08 14:04 . 2001-08-18 06:36 211968 c:\windows\system32\dllcache\um54scan.dll

+ 2011-02-08 14:04 . 2001-08-18 06:36 216064 c:\windows\system32\dllcache\um34scan.dll

+ 2011-02-08 14:03 . 2001-08-17 20:51 166784 c:\windows\system32\dllcache\tridxpm.sys

+ 2011-02-08 14:03 . 2001-08-18 06:36 525568 c:\windows\system32\dllcache\tridxp.dll

+ 2011-02-08 14:03 . 2001-08-17 20:51 159232 c:\windows\system32\dllcache\tridkbm.sys

+ 2011-02-08 14:03 . 2001-08-17 22:56 440576 c:\windows\system32\dllcache\tridkb.dll

+ 2011-02-08 14:03 . 2001-08-17 20:51 222336 c:\windows\system32\dllcache\trid3dm.sys

+ 2011-02-08 14:03 . 2001-08-17 22:56 315520 c:\windows\system32\dllcache\trid3d.dll

+ 2011-02-08 14:02 . 2001-08-17 22:02 230912 c:\windows\system32\dllcache\tosdvd03.sys

+ 2011-02-08 14:02 . 2001-08-17 22:01 241664 c:\windows\system32\dllcache\tosdvd02.sys

+ 2011-02-08 14:02 . 2001-08-17 20:14 123995 c:\windows\system32\dllcache\tjisdn.sys

- 2010-02-26 23:36 . 2008-04-14 11:00 455168 c:\windows\system32\dllcache\tintsetp.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 455168 c:\windows\system32\dllcache\tintsetp.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 185344 c:\windows\system32\dllcache\thawbrkr.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 185344 c:\windows\system32\dllcache\thawbrkr.dll

+ 2011-02-08 14:02 . 2001-08-17 20:51 138528 c:\windows\system32\dllcache\tgiulnt5.sys

+ 2011-02-08 14:02 . 2008-04-14 08:10 149376 c:\windows\system32\dllcache\tffsport.sys

+ 2011-02-08 14:01 . 2001-08-17 22:56 172768 c:\windows\system32\dllcache\t2r4disp.dll

+ 2011-02-08 14:01 . 2001-08-17 21:50 103936 c:\windows\system32\dllcache\sx.sys

+ 2011-02-08 14:01 . 2001-08-18 06:36 155648 c:\windows\system32\dllcache\stlnprop.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 101376 c:\windows\system32\dllcache\srusbusd.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 101376 c:\windows\system32\dllcache\srusbusd.dll

+ 2011-02-08 13:59 . 2001-08-18 06:36 114688 c:\windows\system32\dllcache\sonypi.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 143422 c:\windows\system32\dllcache\softkey.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 143422 c:\windows\system32\dllcache\softkey.dll

+ 2011-02-08 13:59 . 2001-08-17 22:56 147200 c:\windows\system32\dllcache\smidispb.dll

+ 2011-02-08 13:58 . 2008-04-14 07:53 404990 c:\windows\system32\dllcache\slntamr.sys

+ 2011-02-08 13:58 . 2008-04-14 07:53 129535 c:\windows\system32\dllcache\slnt7554.sys

+ 2011-02-08 13:58 . 2008-04-14 13:42 188508 c:\windows\system32\dllcache\slgen.dll

+ 2011-02-08 13:58 . 2008-04-14 13:42 286792 c:\windows\system32\dllcache\slextspk.dll

+ 2011-02-08 13:58 . 2001-08-17 22:56 157696 c:\windows\system32\dllcache\sisv256.dll

+ 2011-02-08 13:58 . 2001-08-18 06:36 238592 c:\windows\system32\dllcache\sisgrv.dll

+ 2011-02-08 13:58 . 2001-08-17 20:50 104064 c:\windows\system32\dllcache\sisgrp.sys

+ 2011-02-08 13:58 . 2001-08-17 22:56 150144 c:\windows\system32\dllcache\sis6306v.dll

+ 2011-02-08 13:56 . 2001-08-18 06:36 495616 c:\windows\system32\dllcache\sblfx.dll

+ 2011-02-08 13:55 . 2001-08-17 22:56 198400 c:\windows\system32\dllcache\s3sav4.dll

+ 2011-02-08 13:55 . 2001-08-17 22:56 179264 c:\windows\system32\dllcache\s3sav3d.dll

+ 2011-02-08 13:55 . 2001-08-17 22:56 210496 c:\windows\system32\dllcache\s3mvirge.dll

+ 2011-02-08 13:55 . 2001-08-17 22:56 182272 c:\windows\system32\dllcache\s3mt3d.dll

+ 2011-02-08 13:55 . 2001-08-17 20:50 166720 c:\windows\system32\dllcache\s3m.sys

+ 2011-02-08 13:55 . 2008-04-14 06:04 166912 c:\windows\system32\dllcache\s3gnbm.sys

+ 2011-02-08 13:55 . 2008-04-14 13:42 397056 c:\windows\system32\dllcache\s3gnb.dll

+ 2010-02-26 23:28 . 2008-04-14 08:02 196224 c:\windows\system32\dllcache\rdpdr.sys

+ 2011-02-08 13:53 . 2001-08-17 21:28 714762 c:\windows\system32\dllcache\r2mdmkxx.sys

+ 2011-02-08 13:53 . 2001-08-17 21:28 899146 c:\windows\system32\dllcache\r2mdkxga.sys

+ 2011-02-08 13:53 . 2001-08-17 21:28 130942 c:\windows\system32\dllcache\ptserlv.sys

+ 2011-02-08 13:53 . 2001-08-17 21:28 112574 c:\windows\system32\dllcache\ptserlp.sys

+ 2011-02-08 13:53 . 2001-08-17 21:28 128286 c:\windows\system32\dllcache\ptserli.sys

+ 2011-02-08 13:53 . 2008-04-14 13:42 159232 c:\windows\system32\dllcache\ptpusd.dll

+ 2011-02-08 13:52 . 2008-04-14 13:42 363520 c:\windows\system32\dllcache\psisdecd.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 131584 c:\windows\system32\dllcache\pmxviceo.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 131584 c:\windows\system32\dllcache\pmxviceo.dll

+ 2011-02-08 13:52 . 2001-08-18 06:36 121344 c:\windows\system32\dllcache\phvfwext.dll

+ 2011-02-08 13:52 . 2001-08-17 22:04 173696 c:\windows\system32\dllcache\philcam2.sys

+ 2011-02-08 13:52 . 2008-04-14 13:40 259328 c:\windows\system32\dllcache\perm3dd.dll

+ 2011-02-08 13:52 . 2008-04-14 13:40 211584 c:\windows\system32\dllcache\perm2dll.dll

+ 2011-02-08 13:51 . 2008-04-14 05:42 169984 c:\windows\system32\dllcache\pcx500.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 120192 c:\windows\system32\dllcache\pcmcia.sys

+ 2011-02-08 13:51 . 2001-08-17 22:05 351616 c:\windows\system32\dllcache\ovcodek2.sys

+ 2011-02-08 13:51 . 2001-08-18 06:36 116736 c:\windows\system32\dllcache\ovcodec2.dll

+ 2011-02-08 13:50 . 2001-08-17 20:50 198144 c:\windows\system32\dllcache\nv3.sys

+ 2011-02-08 13:50 . 2001-08-18 06:36 123776 c:\windows\system32\dllcache\nv3.dll

+ 2011-02-08 13:50 . 2008-04-14 07:53 180360 c:\windows\system32\dllcache\ntmtlfax.sys

+ 2011-02-08 13:48 . 2001-08-17 20:11 128000 c:\windows\system32\dllcache\n100325.sys

+ 2010-02-26 23:36 . 2004-08-04 12:00 229439 c:\windows\system32\dllcache\multibox.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 229439 c:\windows\system32\dllcache\multibox.dll

+ 2011-02-08 13:48 . 2001-08-17 20:50 103296 c:\windows\system32\dllcache\mtxvideo.sys

+ 2011-02-08 13:48 . 2008-04-14 06:04 452736 c:\windows\system32\dllcache\mtxparhm.sys

+ 2011-02-08 13:48 . 2008-04-14 07:53 126686 c:\windows\system32\dllcache\mtlmnt5.sys

+ 2008-04-14 11:00 . 2010-02-24 13:11 455680 c:\windows\system32\dllcache\mrxsmb.sys

- 2010-02-26 23:51 . 2010-02-24 13:11 455680 c:\windows\system32\dllcache\mrxsmb.sys

+ 2001-08-17 22:36 . 2008-04-14 11:00 147968 c:\windows\system32\dllcache\mdwmdmsp.dll

+ 2011-02-08 13:45 . 2001-08-17 20:12 164586 c:\windows\system32\dllcache\mdgndis5.sys

+ 2011-02-08 13:45 . 2001-08-17 21:28 797500 c:\windows\system32\dllcache\ltsmt.sys

+ 2011-02-08 13:45 . 2001-08-17 21:28 802683 c:\windows\system32\dllcache\ltsm.sys

+ 2011-02-08 13:45 . 2008-04-14 07:53 420992 c:\windows\system32\dllcache\ltmdmntt.sys

+ 2011-02-08 13:45 . 2001-08-17 21:28 576746 c:\windows\system32\dllcache\ltmdmntl.sys

+ 2011-02-08 13:45 . 2008-04-14 07:53 606684 c:\windows\system32\dllcache\ltmdmnt.sys

+ 2011-02-08 13:45 . 2001-08-17 21:28 727786 c:\windows\system32\dllcache\ltck000c.sys

+ 2011-02-08 13:44 . 2008-04-14 13:41 253952 c:\windows\system32\dllcache\kdsusd.dll

+ 2011-02-08 13:43 . 2008-04-14 13:42 151552 c:\windows\system32\dllcache\irftp.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 471102 c:\windows\system32\dllcache\imskdic.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 471102 c:\windows\system32\dllcache\imskdic.dll

- 2010-02-26 23:36 . 2008-04-14 11:00 262200 c:\windows\system32\dllcache\imjputy.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 262200 c:\windows\system32\dllcache\imjputy.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 233527 c:\windows\system32\dllcache\imjprw.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 233527 c:\windows\system32\dllcache\imjprw.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 208952 c:\windows\system32\dllcache\imjpmig.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 208952 c:\windows\system32\dllcache\imjpmig.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 196665 c:\windows\system32\dllcache\imjpinst.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 196665 c:\windows\system32\dllcache\imjpinst.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 155705 c:\windows\system32\dllcache\imjpdsvr.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 155705 c:\windows\system32\dllcache\imjpdsvr.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 307257 c:\windows\system32\dllcache\imjpdct.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 307257 c:\windows\system32\dllcache\imjpdct.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 311359 c:\windows\system32\dllcache\imepadsv.exe

+ 2010-02-26 23:36 . 2004-08-04 12:00 311359 c:\windows\system32\dllcache\imepadsv.exe

- 2010-02-26 23:36 . 2008-04-14 11:00 102463 c:\windows\system32\dllcache\imepadsm.dll

+ 2010-02-26 23:36 . 2004-08-04 12:00 102463 c:\windows\system32\dllcache\imepadsm.dll

+ 2010-02-26 23:30 . 2011-01-24 16:42 638816 c:\windows\system32\dllcache\iexplore.exe

- 2010-02-26 23:30 . 2009-03-08 22:09 638816 c:\windows\system32\dllcache\iexplore.exe

+ 2011-02-08 13:42 . 2001-08-18 06:36 372824 c:\windows\system32\dllcache\iconf32.dll

+ 2011-02-08 13:42 . 2001-08-17 22:06 100992 c:\windows\system32\dllcache\icam5usb.sys

+ 2011-02-08 13:42 . 2001-08-17 22:06 154496 c:\windows\system32\dllcache\icam4usb.sys

+ 2011-02-08 13:42 . 2001-08-17 22:05 141056 c:\windows\system32\dllcache\icam3.sys

+ 2011-02-08 13:42 . 2001-08-17 20:12 109085 c:\windows\system32\dllcache\ibmtrp.sys

+ 2011-02-08 13:42 . 2001-08-17 20:12 100936 c:\windows\system32\dllcache\ibmtok.sys

+ 2011-02-08 13:41 . 2008-04-14 06:04 161020 c:\windows\system32\dllcache\i81xnt5.sys

+ 2011-02-08 13:41 . 2008-04-14 13:41 702845 c:\windows\system32\dllcache\i81xdnt5.dll

+ 2011-02-08 13:41 . 2001-08-17 22:56 353184 c:\windows\system32\dllcache\i740dnt5.dll

- 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys

+ 2008-04-14 11:00 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys

+ 2011-02-08 13:41 . 2008-04-14 07:53 685056 c:\windows\system32\dllcache\hsfcxts2.sys

+ 2011-02-08 13:41 . 2008-04-14 07:53 220032 c:\windows\system32\dllcache\hsfbs2s2.sys

+ 2011-02-08 13:41 . 2001-08-17 21:28 488383 c:\windows\system32\dllcache\hsf_v124.sys

+ 2011-02-08 13:40 . 2001-08-17 21:28 542879 c:\windows\system32\dllcache\hsf_msft.sys

+ 2011-02-08 13:40 . 2001-08-17 21:28 391199 c:\windows\system32\dllcache\hsf_k56k.sys

+ 2011-02-08 13:40 . 2001-08-17 21:28 115807 c:\windows\system32\dllcache\hsf_fsks.sys

+ 2011-02-08 13:40 . 2001-08-17 21:28 199711 c:\windows\system32\dllcache\hsf_faxx.sys

+ 2011-02-08 13:40 . 2001-08-17 21:28 289887 c:\windows\system32\dllcache\hsf_fall.sys

+ 2011-02-08 13:40 . 2001-08-17 21:28 150239 c:\windows\system32\dllcache\hsf_amos.sys

+ 2011-02-08 13:40 . 2001-08-18 06:36 324608 c:\windows\system32\dllcache\hpojwia.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 165888 c:\windows\system32\dllcache\hpgt53.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 126976 c:\windows\system32\dllcache\hpgt34tk.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 101376 c:\windows\system32\dllcache\hpgt34.dll

+ 2011-02-08 13:40 . 2001-08-18 06:36 123392 c:\windows\system32\dllcache\hpgt21tk.dll

+ 2011-02-08 13:39 . 2001-08-17 21:28 907456 c:\windows\system32\dllcache\hcf_msft.sys

+ 2011-02-08 13:39 . 2001-08-17 20:49 322432 c:\windows\system32\dllcache\g400m.sys

+ 2011-02-08 13:39 . 2001-08-17 20:49 320384 c:\windows\system32\dllcache\g200m.sys

+ 2011-02-08 13:39 . 2001-08-17 22:56 470144 c:\windows\system32\dllcache\g200d.dll

+ 2011-02-08 13:39 . 2001-08-17 20:15 454912 c:\windows\system32\dllcache\fxusbase.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 132608 c:\windows\system32\dllcache\fxsclntr.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 132608 c:\windows\system32\dllcache\fxsclntr.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 111104 c:\windows\system32\dllcache\fxscfgwz.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 111104 c:\windows\system32\dllcache\fxscfgwz.dll

+ 2011-02-08 13:38 . 2001-08-17 20:15 455296 c:\windows\system32\dllcache\fusbbase.sys

+ 2011-02-08 13:38 . 2001-08-17 20:15 455680 c:\windows\system32\dllcache\fus2base.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 125056 c:\windows\system32\dllcache\ftdisk.sys

+ 2011-02-08 13:38 . 2001-08-17 20:15 442240 c:\windows\system32\dllcache\fpnpbase.sys

+ 2011-02-08 13:38 . 2001-08-17 20:14 441728 c:\windows\system32\dllcache\fpcmbase.sys

+ 2011-02-08 13:38 . 2001-08-17 20:14 444416 c:\windows\system32\dllcache\fpcibase.sys

+ 2011-02-08 13:37 . 2008-04-14 06:06 137088 c:\windows\system32\dllcache\essm2e.sys

+ 2011-02-08 13:37 . 2001-08-17 21:28 347550 c:\windows\system32\dllcache\es56tpi.sys

+ 2011-02-08 13:37 . 2001-08-17 21:28 594238 c:\windows\system32\dllcache\es56hpi.sys

+ 2011-02-08 13:37 . 2001-08-17 21:28 595647 c:\windows\system32\dllcache\es56cvmp.sys

+ 2011-02-08 13:37 . 2001-08-17 20:19 174464 c:\windows\system32\dllcache\es198x.sys

+ 2011-02-08 13:36 . 2001-08-17 21:50 114944 c:\windows\system32\dllcache\epstw2k.sys

+ 2011-02-08 13:36 . 2001-08-17 21:50 144896 c:\windows\system32\dllcache\epcfw2k.sys

+ 2011-02-08 13:36 . 2001-08-17 20:19 283904 c:\windows\system32\dllcache\emu10k1m.sys

+ 2011-02-08 13:36 . 2001-08-17 20:11 171520 c:\windows\system32\dllcache\el99xn51.sys

+ 2011-02-08 13:36 . 2001-08-17 20:11 455199 c:\windows\system32\dllcache\el985n51.sys

+ 2011-02-08 13:36 . 2001-08-17 20:11 153631 c:\windows\system32\dllcache\el90xnd5.sys

+ 2011-02-08 13:36 . 2001-08-17 21:28 241206 c:\windows\system32\dllcache\el656se5.sys

+ 2011-02-08 13:36 . 2001-08-17 21:28 634134 c:\windows\system32\dllcache\el656ct5.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 514587 c:\windows\system32\dllcache\edb500.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 514587 c:\windows\system32\dllcache\edb500.dll

+ 2011-02-08 13:36 . 2001-08-17 20:12 117760 c:\windows\system32\dllcache\e100b325.sys

+ 2011-02-08 13:36 . 2001-08-17 20:20 334208 c:\windows\system32\dllcache\ds1wdm.sys

+ 2011-02-08 13:35 . 2008-04-14 08:09 206976 c:\windows\system32\dllcache\dot4.sys

+ 2011-02-08 13:35 . 2001-08-17 20:14 952007 c:\windows\system32\dllcache\diwan.sys

+ 2011-02-08 13:35 . 2001-08-18 06:36 236060 c:\windows\system32\dllcache\ditrace.exe

+ 2011-02-08 13:35 . 2001-08-18 06:36 614429 c:\windows\system32\dllcache\digiview.exe

+ 2011-02-08 13:35 . 2001-08-18 06:36 110621 c:\windows\system32\dllcache\digirlpt.dll

+ 2011-02-08 13:35 . 2001-08-18 06:36 102484 c:\windows\system32\dllcache\digiinf.dll

+ 2011-02-08 13:35 . 2001-08-18 06:36 159828 c:\windows\system32\dllcache\digihlc.dll

+ 2011-02-08 13:35 . 2001-08-18 06:36 229462 c:\windows\system32\dllcache\digifwrk.dll

+ 2011-02-08 13:35 . 2001-08-17 20:13 103044 c:\windows\system32\dllcache\digidxb.sys

+ 2011-02-08 13:35 . 2001-08-18 06:36 131156 c:\windows\system32\dllcache\digidbp.dll

+ 2011-02-08 13:33 . 2001-08-17 20:13 164923 c:\windows\system32\dllcache\diapi2.sys

+ 2011-02-08 13:35 . 2001-08-18 06:36 419357 c:\windows\system32\dllcache\dgconfig.dll

+ 2011-02-08 13:35 . 2001-08-18 06:36 256512 c:\windows\system32\dllcache\devcon32.dll

+ 2011-02-08 13:34 . 2001-08-18 06:36 110592 c:\windows\system32\dllcache\dc260usd.dll

+ 2011-02-08 13:34 . 2001-08-17 21:52 179584 c:\windows\system32\dllcache\dac2w2k.sys

+ 2011-02-08 13:34 . 2001-08-17 20:12 117760 c:\windows\system32\dllcache\d100ib5.sys

+ 2011-02-08 13:34 . 2001-08-17 20:19 111872 c:\windows\system32\dllcache\cwcspud.sys

+ 2011-02-08 13:34 . 2008-04-14 13:41 249856 c:\windows\system32\dllcache\ctmasetp.dll

+ 2011-02-08 13:34 . 2001-08-18 06:36 175104 c:\windows\system32\dllcache\csamsp.dll

+ 2011-02-08 13:34 . 2001-08-18 06:36 216064 c:\windows\system32\dllcache\cpscan.dll

+ 2011-02-08 13:33 . 2001-08-17 21:57 248064 c:\windows\system32\dllcache\cl546xm.sys

+ 2011-02-08 13:33 . 2001-08-17 22:56 170880 c:\windows\system32\dllcache\cl546x.dll

+ 2011-02-08 13:33 . 2001-08-17 22:56 111232 c:\windows\system32\dllcache\cl5465.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 480256 c:\windows\system32\dllcache\cintsetp.exe

- 2010-02-26 23:35 . 2008-04-14 11:00 480256 c:\windows\system32\dllcache\cintsetp.exe

+ 2001-08-17 14:02 . 2008-04-14 11:00 262528 c:\windows\system32\dllcache\cinemst2.sys

+ 2011-02-08 13:33 . 2001-08-17 22:02 272640 c:\windows\system32\dllcache\cinemclc.sys

+ 2011-02-08 13:33 . 2001-08-17 20:13 980034 c:\windows\system32\dllcache\cicap.sys

+ 2010-02-26 23:35 . 2004-08-04 12:00 838144 c:\windows\system32\dllcache\chtbrkr.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 838144 c:\windows\system32\dllcache\chtbrkr.dll

+ 2011-02-08 13:33 . 2001-08-17 21:28 714698 c:\windows\system32\dllcache\cbmdmkxx.sys

+ 2011-02-08 13:33 . 2008-04-14 13:41 121856 c:\windows\system32\dllcache\camext30.dll

+ 2011-02-08 13:33 . 2001-08-18 06:36 236032 c:\windows\system32\dllcache\camext20.dll

+ 2011-02-08 13:33 . 2001-08-17 22:04 171264 c:\windows\system32\dllcache\camdrv30.sys

+ 2011-02-08 13:33 . 2001-08-17 22:04 223232 c:\windows\system32\dllcache\camdrv21.sys

+ 2011-02-08 13:33 . 2001-08-17 22:05 314752 c:\windows\system32\dllcache\camdro21.sys

+ 2011-02-08 13:32 . 2008-04-14 08:21 101120 c:\windows\system32\dllcache\bthpan.sys

+ 2011-02-08 13:32 . 2001-08-18 06:36 102400 c:\windows\system32\dllcache\binlsvc.dll

+ 2011-02-08 13:32 . 2001-08-17 21:28 871388 c:\windows\system32\dllcache\bcmdm.sys

+ 2011-02-08 13:32 . 2001-08-17 22:56 342336 c:\windows\system32\dllcache\banshee.dll

+ 2011-02-08 13:32 . 2001-08-18 06:36 144384 c:\windows\system32\dllcache\avmenum.dll

+ 2005-08-04 03:47 . 2005-08-24 02:26 639872 c:\windows\system32\dllcache\ativvaxx.dll

- 2005-08-04 03:47 . 2005-08-04 03:47 639872 c:\windows\system32\dllcache\ativvaxx.dll

+ 2011-02-08 13:31 . 2001-08-17 22:56 104832 c:\windows\system32\dllcache\atiraged.dll

+ 2011-02-08 13:31 . 2008-04-14 06:04 104960 c:\windows\system32\dllcache\atinrvxx.sys

+ 2011-02-08 13:31 . 2001-08-17 20:48 281600 c:\windows\system32\dllcache\atimtai.sys

+ 2011-02-08 13:31 . 2001-08-17 20:48 289664 c:\windows\system32\dllcache\atimpab.sys

+ 2011-02-08 13:31 . 2001-08-17 22:56 268160 c:\windows\system32\dllcache\atidvai.dll

+ 2011-02-08 13:31 . 2001-08-17 22:56 137216 c:\windows\system32\dllcache\atidrae.dll

+ 2011-02-08 13:31 . 2001-08-17 22:55 382592 c:\windows\system32\dllcache\atidrab.dll

+ 2011-02-08 13:31 . 2008-04-14 13:41 870784 c:\windows\system32\dllcache\ati3d1ag.dll

+ 2011-02-08 13:31 . 2008-04-14 06:04 327040 c:\windows\system32\dllcache\ati2mtaa.sys

- 2005-08-04 04:10 . 2005-08-04 04:10 205312 c:\windows\system32\dllcache\ati2dvag.dll

+ 2005-08-04 04:10 . 2005-08-24 02:26 205312 c:\windows\system32\dllcache\ati2dvag.dll

+ 2011-02-08 13:31 . 2008-04-14 13:41 377984 c:\windows\system32\dllcache\ati2dvaa.dll

+ 2005-08-04 03:02 . 2005-08-24 02:26 212992 c:\windows\system32\dllcache\ati2cqag.dll

- 2005-08-04 03:02 . 2005-08-04 03:02 212992 c:\windows\system32\dllcache\ati2cqag.dll

+ 2011-02-08 13:30 . 2001-08-17 22:07 101888 c:\windows\system32\dllcache\adpu160m.sys

+ 2011-02-08 13:30 . 2001-08-17 20:19 747392 c:\windows\system32\dllcache\adm8830.sys

+ 2011-02-08 13:30 . 2001-08-17 20:19 553984 c:\windows\system32\dllcache\adm8820.sys

+ 2011-02-08 13:30 . 2001-08-17 20:19 584448 c:\windows\system32\dllcache\adm8810.sys

+ 2008-04-14 11:00 . 2008-04-14 11:00 187776 c:\windows\system32\dllcache\acpi.sys

+ 2011-02-08 13:30 . 2001-08-17 20:20 297728 c:\windows\system32\dllcache\ac97sis.sys

+ 2011-02-08 13:30 . 2008-04-14 06:06 231552 c:\windows\system32\dllcache\ac97ali.sys

+ 2011-02-08 13:30 . 2001-08-18 06:36 462848 c:\windows\system32\dllcache\a3dapi.dll

+ 2011-02-08 13:30 . 2001-08-17 20:48 148352 c:\windows\system32\dllcache\3dfxvsm.sys

+ 2011-02-08 13:30 . 2001-08-17 22:55 689216 c:\windows\system32\dllcache\3dfxvs.dll

+ 2011-02-08 13:30 . 2001-08-17 21:28 762780 c:\windows\system32\dllcache\3cwmcru.sys

+ 2011-02-08 14:05 . 2008-04-14 11:00 426041 c:\windows\LastGood\system32\dllcache\voicepad.dll

+ 2011-02-08 14:02 . 2008-04-14 11:00 455168 c:\windows\LastGood\system32\dllcache\tintsetp.exe

+ 2011-02-08 14:02 . 2008-04-14 11:00 185344 c:\windows\LastGood\system32\dllcache\thawbrkr.dll

+ 2011-02-08 14:00 . 2008-04-14 11:00 101376 c:\windows\LastGood\system32\dllcache\srusbusd.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 143422 c:\windows\LastGood\system32\dllcache\softkey.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 188416 c:\windows\LastGood\system32\dllcache\snmpsmir.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 358400 c:\windows\LastGood\system32\dllcache\snmpincl.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 259072 c:\windows\LastGood\system32\dllcache\snmpcl.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 456192 c:\windows\LastGood\system32\dllcache\smtpsvc.dll

+ 2011-02-08 13:59 . 2008-04-14 11:00 236544 c:\windows\LastGood\system32\dllcache\smi2smir.exe

+ 2011-02-08 13:52 . 2008-04-14 11:00 131584 c:\windows\LastGood\system32\dllcache\pmxviceo.dll

+ 2011-02-08 13:52 . 2008-04-14 11:00 175104 c:\windows\LastGood\system32\dllcache\pintlcsa.dll

+ 2011-02-08 13:48 . 2008-04-14 11:00 229439 c:\windows\LastGood\system32\dllcache\multibox.dll

+ 2011-02-08 13:48 . 2008-04-14 11:00 119808 c:\windows\LastGood\system32\dllcache\mtstocom.exe

+ 2011-02-08 13:43 . 2008-04-14 11:00 315455 c:\windows\LastGood\system32\dllcache\imskf.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 471102 c:\windows\LastGood\system32\dllcache\imskdic.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 102456 c:\windows\LastGood\system32\dllcache\imlang.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 274489 c:\windows\LastGood\system32\dllcache\imjputyc.dll

+ 2011-02-08 13:43 . 2008-04-14 11:00 262200 c:\windows\LastGood\system32\dllcache\imjputy.exe

+ 2011-02-08 13:43 . 2008-04-14 11:00 233527 c:\windows\LastGood\system32\dllcache\imjprw.exe

+ 2011-02-08 13:43 . 2008-04-14 11:00 208952 c:\windows\LastGood\system32\dllcache\imjpmig.exe

+ 2011-02-08 13:42 . 2008-04-14 11:00 196665 c:\windows\LastGood\system32\dllcache\imjpinst.exe

+ 2011-02-08 13:42 . 2008-04-14 11:00 155705 c:\windows\LastGood\system32\dllcache\imjpdsvr.exe

+ 2011-02-08 13:42 . 2008-04-14 11:00 307257 c:\windows\LastGood\system32\dllcache\imjpdct.exe

+ 2011-02-08 13:42 . 2008-04-14 11:00 716856 c:\windows\LastGood\system32\dllcache\imjpcus.dll

+ 2011-02-08 13:42 . 2008-04-14 11:00 368696 c:\windows\LastGood\system32\dllcache\imjpcic.dll

+ 2011-02-08 13:42 . 2008-04-14 11:00 811064 c:\windows\LastGood\system32\dllcache\imjp81k.dll

+ 2011-02-08 13:42 . 2008-04-14 11:00 311359 c:\windows\LastGood\system32\dllcache\imepadsv.exe

+ 2011-02-08 13:42 . 2008-04-14 11:00 102463 c:\windows\LastGood\system32\dllcache\imepadsm.dll

+ 2011-02-08 13:42 . 2008-04-14 11:00 106496 c:\windows\LastGood\system32\dllcache\imekrcic.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 400384 c:\windows\LastGood\system32\dllcache\fxsxp32.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 192512 c:\windows\LastGood\system32\dllcache\fxswzrd.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 154112 c:\windows\LastGood\system32\dllcache\fxsui.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 397312 c:\windows\LastGood\system32\dllcache\fxstiff.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 246272 c:\windows\LastGood\system32\dllcache\fxst30.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 267776 c:\windows\LastGood\system32\dllcache\fxssvc.exe

+ 2011-02-08 13:38 . 2008-04-14 11:00 562176 c:\windows\LastGood\system32\dllcache\fxsst.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 229376 c:\windows\LastGood\system32\dllcache\fxscover.exe

+ 2011-02-08 13:38 . 2008-04-14 11:00 285184 c:\windows\LastGood\system32\dllcache\fxscomex.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 132608 c:\windows\LastGood\system32\dllcache\fxsclntr.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 142848 c:\windows\LastGood\system32\dllcache\fxsclnt.exe

+ 2011-02-08 13:38 . 2008-04-14 11:00 111104 c:\windows\LastGood\system32\dllcache\fxscfgwz.dll

+ 2011-02-08 13:38 . 2008-04-14 11:00 451584 c:\windows\LastGood\system32\dllcache\fxsapi.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 208896 c:\windows\LastGood\system32\dllcache\fpmmcsat.dll

+ 2011-02-08 13:29 . 2004-05-13 08:39 598071 c:\windows\LastGood\system32\dllcache\fpmmc.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 188494 c:\windows\LastGood\system32\dllcache\fpcount.exe

+ 2011-02-08 13:29 . 2003-03-25 00:52 109328 c:\windows\LastGood\system32\dllcache\fp98swin.exe

+ 2011-02-08 13:29 . 2004-05-13 08:39 876653 c:\windows\LastGood\system32\dllcache\fp4awel.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 102509 c:\windows\LastGood\system32\dllcache\fp4atxt.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 147513 c:\windows\LastGood\system32\dllcache\fp4apws.dll

+ 2011-02-08 13:29 . 2004-05-13 08:39 184435 c:\windows\LastGood\system32\dllcache\fp4amsft.dll

+ 2011-02-08 13:37 . 2008-04-14 11:00 101888 c:\windows\LastGood\system32\dllcache\evntagnt.dll

+ 2011-02-08 13:36 . 2008-04-14 11:00 514587 c:\windows\LastGood\system32\dllcache\edb500.dll

+ 2011-02-08 13:33 . 2008-04-14 11:00 480256 c:\windows\LastGood\system32\dllcache\cintsetp.exe

+ 2011-02-08 13:33 . 2008-04-14 11:00 198656 c:\windows\LastGood\system32\dllcache\cintime.dll

+ 2011-02-08 13:33 . 2008-04-14 11:00 173568 c:\windows\LastGood\system32\dllcache\chtskf.dll

+ 2011-02-08 13:33 . 2008-04-14 11:00 838144 c:\windows\LastGood\system32\dllcache\chtbrkr.dll

+ 2011-02-08 13:29 . 2003-03-25 00:52 188480 c:\windows\LastGood\system32\dllcache\cfgwiz.exe

+ 2011-02-08 13:33 . 2008-04-14 11:00 218112 c:\windows\LastGood\system32\dllcache\c_g18030.dll

+ 2011-02-08 13:31 . 2008-04-14 11:00 331264 c:\windows\LastGood\system32\dllcache\aqueue.dll

+ 2010-02-26 23:31 . 2009-08-07 03:23 1929952 c:\windows\system32\dllcache\wuaueng.dll

+ 2011-02-08 13:50 . 2008-04-14 06:04 1897408 c:\windows\system32\dllcache\nv4_mini.sys

+ 2011-02-08 13:50 . 2008-04-14 13:42 4274816 c:\windows\system32\dllcache\nv4_disp.dll

- 2010-02-26 23:46 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe

+ 2008-04-14 11:00 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe

+ 2008-04-14 00:01 . 2010-04-27 13:05 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe

- 2009-02-08 03:02 . 2010-04-27 13:05 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe

+ 2011-02-08 13:48 . 2008-04-14 13:42 1737856 c:\windows\system32\dllcache\mtxparhd.dll

+ 2011-02-08 13:48 . 2008-04-14 07:53 1309184 c:\windows\system32\dllcache\mtlstrm.sys

+ 2010-02-26 23:28 . 2009-06-10 17:19 2066432 c:\windows\system32\dllcache\lhmstscx.dll

+ 2011-02-08 13:41 . 2008-04-14 07:53 1041536 c:\windows\system32\dllcache\hsfdpsp2.sys

+ 2011-02-08 13:39 . 2001-08-17 22:56 1733120 c:\windows\system32\dllcache\g400d.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 1677824 c:\windows\system32\dllcache\chsbrkr.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 1677824 c:\windows\system32\dllcache\chsbrkr.dll

+ 2005-08-04 03:54 . 2005-08-24 02:26 2365472 c:\windows\system32\dllcache\ati3duag.dll

- 2005-08-04 03:54 . 2005-08-04 03:54 2365472 c:\windows\system32\dllcache\ati3duag.dll

+ 2011-02-08 13:50 . 2010-04-27 13:05 2024448 c:\windows\LastGood\system32\dllcache\ntkrpamp.exe

+ 2011-02-08 13:29 . 2010-04-27 13:59 2146304 c:\windows\LastGood\system32\dllcache\ntkrnlmp.exe

+ 2011-02-08 13:33 . 2008-04-14 11:00 1677824 c:\windows\LastGood\system32\dllcache\chsbrkr.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 10129408 c:\windows\system32\dllcache\hwxkor.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 10129408 c:\windows\system32\dllcache\hwxkor.dll

+ 2010-02-26 23:35 . 2004-08-04 12:00 10096640 c:\windows\system32\dllcache\hwxcht.dll

- 2010-02-26 23:35 . 2008-04-14 11:00 10096640 c:\windows\system32\dllcache\hwxcht.dll

+ 2011-02-08 13:41 . 2008-04-14 11:00 10129408 c:\windows\LastGood\system32\dllcache\hwxkor.dll

+ 2011-02-08 13:41 . 2008-04-14 11:00 13463552 c:\windows\LastGood\system32\dllcache\hwxjpn.dll

+ 2011-02-08 13:41 . 2008-04-14 11:00 10096640 c:\windows\LastGood\system32\dllcache\hwxcht.dll

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2010-03-05 32768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-03-10 28160]

"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 794624]

"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]

"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-02-17 233534]

"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1015808]

"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-06-14 233472]

"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-21 53248]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

"Home Theater SchSvr"="c:\program files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2005-06-14 106496]

"AddressBookReminderApp"="c:\program files\Nova Development\Print Artist Platinum\ReminderApp.exe" [2009-08-31 144672]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-18 421160]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-12-25 421888]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]

c:\documents and settings\Owner\Start Menu\Programs\Startup\

Event Reminder.lnk - c:\program files\Mindscape\PrintMaster\PMREMIND.EXE [2010-4-6 325632]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-6-23 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2010-3-4 450560]

Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-3-4 438272]

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\Yahoo!\\browser\\YBrowser.exe"=

"c:\\Program Files\\Blockland\\Blockland.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\Logitech\\SetPoint\\LogitechConnect.exe"=

"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LDMConf.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=

"c:\\WINDOWS\\system32\\sessmgr.exe"=

"c:\\Program Files\\MSN\\MSNCoreFiles\\Install\\msnsusii.exe"=

"c:\\Program Files\\Yahoo!\\Common\\ypostinstdsl.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"1394:TCP"= 1394:TCP:*:Disabled:1394 Net Adapter

"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

"AllowInboundEchoRequest"= 1 (0x1)

"AllowInboundTimestampRequest"= 1 (0x1)

"AllowInboundMaskRequest"= 1 (0x1)

"AllowInboundRouterRequest"= 1 (0x1)

"AllowOutboundDestinationUnreachable"= 1 (0x1)

"AllowOutboundSourceQuench"= 1 (0x1)

"AllowOutboundParameterProblem"= 1 (0x1)

"AllowOutboundTimeExceeded"= 1 (0x1)

"AllowRedirect"= 0 (0x0)

"AllowOutboundPacketTooBig"= 1 (0x1)

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2/1/2011 9:23 PM 135336]

R2 mstbsvc;MSN Toolbar Setup;c:\program files\MSN\Toolbar\4.0.0412.0\mstbsvc.exe [4/6/2010 2:34 PM 102752]

R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [5/23/2010 12:50 PM 200192]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]

S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [11/16/2010 1:10 AM 267568]

S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/14/2008 3:00 AM 14336]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

WINRM REG_MULTI_SZ WINRM

.

Contents of the 'Scheduled Tasks' folder

2011-02-08 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]

2011-02-06 c:\windows\Tasks\ConfigExec.job

- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-11-16 09:09]

2011-02-08 c:\windows\Tasks\DataUpload.job

- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-11-16 09:09]

2011-02-08 c:\windows\Tasks\User_Feed_Synchronization-{3891B371-4764-4E88-93BB-89E9528A0B27}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://google.com/

uInternet Settings,ProxyServer = 192.168.1.10:3128

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://rd.yahoo.com/customize/sbcydsl/defaults/su/*http://www.yahoo.com

IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM

IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM

Trusted Zone: microsoft.com\office

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrun3lhv.default\

FF - prefs.js: browser.search.selectedEngine - AVG Secure Search

FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cb38761&v=6.011.025.001&i=26&tp=ab&iy=&ychte=us&lng=en-US&q=

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

FF - Ext: Dynamite Deals: ddfirefox@dynamitedata - %profile%\extensions\ddfirefox@dynamitedata

FF - Ext: PriceBlink: info@priceblink.com - %profile%\extensions\info@priceblink.com

FF - Ext: Behind The *Asterisks* (EladKarako Mod): {38abe53c-d79f-8e86-9673-57c449674c5e} - %profile%\extensions\{38abe53c-d79f-8e86-9673-57c449674c5e}

FF - Ext: CacheViewer: {71328583-3CA7-4809-B4BA-570A85818FBB} - %profile%\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}

FF - Ext: PriceTrace: {72938f90-8d8a-11de-8a39-0800200c9a66} - %profile%\extensions\{72938f90-8d8a-11de-8a39-0800200c9a66}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-02-08 08:33

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????6?0?1?8??????? ???B?????????????hLC? ??????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1085031214-1336601894-1417001333-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1085031214-1336601894-1417001333-1003\Software\Microsoft\VSTA\9.0\TaskList\Options\UNDONE]

@Denied: (Full) (Administrators)

"Priority"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1056)

c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2140)

c:\windows\system32\WININET.dll

c:\program files\Logitech\SetPoint\lgscroll.dll

c:\windows\system32\ieframe.dll

c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll

.

Completion time: 2011-02-08 08:37:13

ComboFix-quarantined-files.txt 2011-02-08 16:36

ComboFix2.txt 2011-02-06 11:26

Pre-Run: 11,126,775,808 bytes free

Post-Run: 11,347,558,400 bytes free

- - End Of File - - 3FEC9F224A0A51D9EF157FC667D19423

Link to post
Share on other sites

Hi, don't worry, the report is so long because you ran SFC.

UPLOAD A FILE

--------------------

We need to check a file. Please click this link VirusTotal

When the page has finished loading, click the Choose file button and navigate to the following file and click Send file.

c:\windows\system32\sfcfiles.dll

If you get the message that the file has already been scanned before, please click Reanalyse file now.

Please post back the results of the scan in your next post.

Please let me know how things are running now.

Link to post
Share on other sites

Hi Elise,

Okay, the file you requested is in the following post. While browsing for the file, I noticed a boatload of extra files that I haven't a clue about. I'm not savvy on what belongs and what doesn't but these do not look familiar. Also, many files seem to be duplicating.

As far as the way my computer runs, while browsing IE, a prompt or error message pops up stating that the page is not able to load properly or that the web page is missing information or is not supported (or something like that). I've just been clicking the red box with the "X" and it seems to go okay until I open another page.

This error does not come up when I am in this forum or from the page you linked me to. There are several files that look unfamiliar and suspicious with properties of "read only" and in some cases "hidden". There was one called "Deborah's_Fancy_Dress_zip" that appeared on the desktop that (according to the properties) was created 9/25/2010. When I "explored" the four files within, they were listed as Avira files but I didn't download that anti virus program (that I can recall) until you linked me to it here. I deleted it and another file popped up. Hopefully I didn't make things worse.

Additionally, upon clicking the Start Menu in my "Recent Documents" folder, the following document appears on top of the one that I've copied and pasted for you below. The doc name: rs_resetpagesyncpolicy.psd1

And another file that doesn't look right and shows up on the start menu in the same section as IE, Firefox, ATT, etc., is this one: OOo_3.2.1_Win_x86_install_en-US.exe

created 9/25/2010

Haven't a clue where or why I acquired it.

I do not want to trust any transactions on line because when I was being redirected last week, I tried navigating to secure sites via inserting https in the search bar. Still, the URLs had extra junk attached. When I tried to verify the source, I saw code written to replace all instances of https with http and I could not edit the source.

I apologize if I am bombarding you with useless, extraneous information. I'm just trying to help figure this mess out and grasping at straws.

Finally there is a MBAM Bugfix file on my desktop from around the time everything went haywire. I had to rename Malwarebytes in order to navigate here. I am still using that "door".

Thanks again for your help, Elise. I realize I'm most likely a nightmare and envision the experts here having a good laugh or roll of the eyes on my posts here. FYI: I want to pay you something for services and purchase the Malwarebytes program when I am sure everything is secure but the system still feels (looks) funky.

Thanks Again,

~Deb

Link to post
Share on other sites

1 VT Community user(s) with a total of 841 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.

File name: sfcfiles.dll

Submission date: 2011-02-10 20:53:33 (UTC)

Current status: queued queued analysing finished

Result: 0/ 41 (0.0%)

VT Community

goodware

Safety score: 100.0%

Compact Print results

Antivirus Version Last Update Result

AhnLab-V3 2011.02.06.00 2011.02.06 -

AntiVir 7.11.3.40 2011.02.10 -

Antiy-AVL 2.0.3.7 2011.02.10 -

Avast 4.8.1351.0 2011.02.10 -

Avast5 5.0.677.0 2011.02.10 -

AVG 10.0.0.1190 2011.02.10 -

BitDefender 7.2 2011.02.10 -

CAT-QuickHeal 11.00 2011.02.10 -

ClamAV 0.96.4.0 2011.02.10 -

Commtouch 5.2.11.5 2011.02.10 -

Comodo 7645 2011.02.10 -

DrWeb 5.0.2.03300 2011.02.10 -

eSafe 7.0.17.0 2011.02.10 -

eTrust-Vet 36.1.8151 2011.02.10 -

F-Prot 4.6.2.117 2011.02.04 -

F-Secure 9.0.16160.0 2011.02.10 -

Fortinet 4.2.254.0 2011.02.10 -

GData 21 2011.02.10 -

Ikarus T3.1.1.97.0 2011.02.10 -

Jiangmin 13.0.900 2011.02.10 -

K7AntiVirus 9.83.3813 2011.02.10 -

McAfee 5.400.0.1158 2011.02.10 -

McAfee-GW-Edition 2010.1C 2011.02.08 -

Microsoft 1.6502 2011.02.10 -

NOD32 5863 2011.02.10 -

Norman 6.07.03 2011.02.10 -

nProtect 2011-01-27.01 2011.02.02 -

Panda 10.0.3.5 2011.02.10 -

PCTools 7.0.3.5 2011.02.10 -

Prevx 3.0 2011.02.10 -

Rising 23.44.03.05 2011.02.10 -

Sophos 4.61.0 2011.02.10 -

SUPERAntiSpyware 4.40.0.1006 2011.02.10 -

Symantec 20101.3.0.103 2011.02.10 -

TheHacker 6.7.0.1.126 2011.02.10 -

TrendMicro 9.200.0.1012 2011.02.10 -

TrendMicro-HouseCall 9.200.0.1012 2011.02.10 -

VBA32 3.12.14.3 2011.02.10 -

VIPRE 8374 2011.02.10 -

ViRobot 2011.2.10.4303 2011.02.10 -

VirusBuster 13.6.193.0 2011.02.10 -

Additional informationShow all

MD5 : 362bc5af8eaf712832c58cc13ae05750

SHA1 : c8c2d44f34115f27f10bc435dd986d4eff00fe3f

SHA256: 8b9ef2f37266e7dcb4ebfc0e3f0065f6f5cc0d9555d7589ce8b5ca42cd158fc4

ssdeep: 3072:uUeP8F3PH/mvTKurhqCaDfzqdKfD+P7KbLxvmzmeXuNrR4:ur8Fymfzqn4Lxvmzp

File size : 1614848 bytes

First seen: 2009-05-04 06:25:13

Last seen : 2011-02-10 20:53:33

TrID:

Win32 Executable Generic (68.0%)

Generic Win/DOS Executable (15.9%)

DOS Executable Generic (15.9%)

Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)

sigcheck:

publisher....: Microsoft Corporation

copyright....: © Microsoft Corporation. All rights reserved.

product......: Microsoft_ Windows_ Operating System

description..: Windows 2000 System File Checker

original name:

internal name:

file version.: 5.1.2600.5512 (xpsp.080413-2111)

comments.....: n/a

signers......: -

signing date.: -

verified.....: Unsigned

PEInfo: PE structure information

[[ basic data ]]

entrypointaddress: 0x120D

timedatestamp....: 0x48025222 (Sun Apr 13 18:34:10 2008)

machinetype......: 0x14c (I386)

[[ 4 section(s) ]]

name, viradd, virsiz, rawdsiz, ntropy, md5

.text, 0x1000, 0xCBF, 0xE00, 5.90, d3fe89394e3542961bec08f951a2b772

.data, 0x2000, 0x17E730, 0x17E800, 3.28, 2e54b06118c98cf9da49ccc14783dee2

.rsrc, 0x181000, 0x408, 0x600, 2.49, 6ad33d817c21d5547a4921c76c19efff

.reloc, 0x182000, 0xA230, 0xA400, 5.76, 31a909823c459f02f7ee7c2c9f09fc93

[[ 1 import(s) ]]

ntdll.dll: LdrDisableThreadCalloutsForDll, NtClose, NtQueryValueKey, NtOpenKey, RtlInitUnicodeString, RtlGetVersion, NtTerminateProcess, RtlUnhandledExceptionFilter, RtlUnwind, NtQueryVirtualMemory

[[ 1 export(s) ]]

SfcGetFiles

ExifTool:

file metadata

CharacterSet: Unicode

CodeSize: 3584

CompanyName: Microsoft Corporation

EntryPoint: 0x120d

FileDescription: Windows 2000 System File Checker

FileFlagsMask: 0x003f

FileOS: Windows NT 32-bit

FileSize: 1577 kB

FileSubtype: 0

FileType: Win32 DLL

FileVersion: 5.1.2600.5512 (xpsp.080413-2111)

FileVersionNumber: 5.1.2600.5512

ImageVersion: 5.1

InitializedDataSize: 1610240

InternalName:

LanguageCode: English (U.S.)

LinkerVersion: 7.1

MIMEType: application/octet-stream

MachineType: Intel 386 or later, and compatibles

OSVersion: 5.1

ObjectFileType: Executable application

PEType: PE32

ProductVersionNumber: 5.1.2600.5512

Subsystem: Windows command line

SubsystemVersion: 4.1

Tag26005512: D

TimeStamp: 2008:04:13 20:34:10+02:00

UninitializedDataSize: 0

filesdll: j%ProductName

icrosoftCorporationAllrightsreserved: B OriginalFilename

lesdll: .LegalCopyright

rosoftWindowsOperatingSystem: @ProductVersion

VT Community

1

User:Cecilia

Reputation:841 credits

Comment date:2010-09-24 13:57:44 (UTC)

Windows XP

Tags: Goodware,

Link to post
Share on other sites

There are a bunch of updates from Microsoft that want to download. Adobe Auto update failed (though I didn't realize it was scheduled) Is it okay to turn my auto-updates and firewall back on yet? I did update Malwarebytes but have not run any scans other than those that you instructed me to run and the auto-run through Avira that automatically started when the system re-booted on Feb 7.

I did not post the results of that Avira Antivir file (way too many pages) but the results follow:

End of the scan: Monday, February 07, 2011 01:04

Used time: 2:20:32 Hour(s)

The scan has been done completely.

13429 Scanned directories

589316 Files were scanned

0 Viruses and/or unwanted programs were found

0 Files were classified as suspicious

0 files were deleted

0 Viruses and unwanted programs were repaired

0 Files were moved to quarantine

0 Files were renamed

81 Files cannot be scanned

589235 Files not concerned

6335 Archives were scanned

63 Warnings

2440 Notes

473653 Objects were scanned with rootkit scan

7 Hidden objects were found

New Control Panel Extention : C:\WINDOWS\system32\wscui.cpl

Is this typical?

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.