DDS (Ver_09-03-16.01) - NTFSx86
Run by David at 20:33:32.62 on Wed 10/07/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1201 [GMT -6:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated)
FW: McAfee Personal Firewall *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Bill\Application Data\svcst.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\srcssc.exe
C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
C:\Documents and Settings\Bill\Application Data\seres.exe
svchost.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee\msc\mcshell.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Bill\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.sirius.com/siriusinternetradio
uInternet Settings,ProxyOverride = <local>;*.local
mWinlogon: Userinit=userinit.exe
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Download Manager Browser Helper Object: {19c8e43b-07b3-49cb-bffc-6777b593e6f8} - c:\progra~1\common~1\fluxdvd\downlo~1\XEBDLH~1.DLL
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [calc] rundll32.exe c:\docume~1\bill\ntuser.dll,_IWMPEvents@0
uRun: [mserv] c:\documents and settings\bill\application data\svcst.exe
uRun: [svchost] c:\documents and settings\bill\application data\svcst.exe
uRun: [ttool] c:\windows\srcssc.exe
mRun: [CTSysVol] c:\program files\creative\sbaudigy2zs\surround mixer\CTSysVol.exe /r
mRun: [CTDVDDET] c:\program files\creative\sbaudigy2zs\dvdaudio\CTDVDDet.EXE
mRun: [SBDrvDet] c:\program files\creative\sb drive det\SBDrvDet.exe /r
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [M-Audio Taskbar Icon] c:\windows\system32\M-AudioTaskBarIcon.exe
mRun: [calc] rundll32.exe c:\windows\system32\calc.dll,_IWMPEvents@0
StartupFolder: c:\documents and settings\bill\start menu\programs\startup\mhbupd32.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg311t\wlancfg5.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
Trusted Zone: aol.com\free
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {00000161-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaud.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [2004-7-19 26112]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-12 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-10-7 206256]
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2004-7-29 138780]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-9 214024]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2004-7-29 46779]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-4-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-4-28 72944]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1028432]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-2-25 210216]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-2-25 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-2-25 144704]
R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\pfmodnt.sys [2007-4-10 16168]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-2-1 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-2-1 35272]
S2 sfx;sfx;c:\windows\system32\SvchoSt.ExE -k sfx [2006-2-28 14336]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\commonfx.sys --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\ctaudfx.sys --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\cterfxfx.sys --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\ctsblfx.sys --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 KORGUMDS;KORG USB-MIDI Driver for Windows XP;c:\windows\system32\drivers\KORGUMDS.SYS [2006-8-25 14976]
S3 MAUSBFT;Service for M-Audio Fast Track USB (WDM);c:\windows\system32\drivers\mausbft.sys [2009-9-26 132096]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-4-28 38496]
S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-2-25 606736]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-2-1 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-2-1 40552]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-4-28 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-10-7 348752]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-10-7 1097096]
=============== Created Last 30 ================
2009-10-07 20:15 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
2009-10-07 20:14 7,396 a------- c:\windows\system32\drivers\pctcore.cat
2009-10-07 20:14 206,256 a------- c:\windows\system32\drivers\PCTCore.sys
2009-10-07 20:14 86,888 a------- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-07 20:14 <DIR> --d----- c:\program files\common files\PC Tools
2009-10-07 20:14 64,392 a------- c:\windows\system32\drivers\pctplsg.sys
2009-10-07 20:13 <DIR> --d----- c:\program files\Spyware Doctor
2009-10-07 20:13 <DIR> --d----- c:\docume~1\bill\applic~1\PC Tools
2009-10-07 20:13 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
2009-10-07 19:45 <DIR> --d----- c:\program files\AntivirusPro_2010
2009-10-07 19:45 233,584 a------- c:\docume~1\bill\applic~1\lizkavd.exe
2009-10-07 19:40 58,368 a------- c:\windows\srcssc.exe
2009-10-07 19:40 276,480 a------- c:\docume~1\bill\applic~1\svcst.exe
2009-10-07 19:40 <DIR> --dsh--- c:\windows\system32\twain_32
2009-10-07 19:40 276,480 a------- c:\docume~1\bill\applic~1\seres.exe
2009-10-07 19:34 4,958,588 -------- c:\windows\{00000001-00000000-00000009-00001102-00000004-20021102}.BAK
2009-10-07 17:38 <DIR> --dsh--- c:\windows\system32\twain32
2009-09-26 11:26 <DIR> --d----- c:\docume~1\alluse~1\applic~1\M-Audio
2009-09-26 11:25 132,096 a------- c:\windows\system32\drivers\mausbft.sys
2009-09-26 11:25 245,248 a------- c:\windows\system32\M-AudioFastTrackControlPanelApplet.cpl
2009-09-26 11:25 244,224 a------- c:\windows\system32\M-AudioProducerUSBControlPanelApplet.cpl
2009-09-26 11:25 124,800 a------- c:\windows\system32\drivers\mausbpr.sys
2009-09-26 11:25 356,864 a------- c:\windows\system32\M-AudioTaskBarIcon.exe
2009-09-26 11:25 2,424,066 a------- c:\windows\system32\madiousb.dll
2009-09-26 11:25 244,736 a------- c:\windows\system32\M-AudioMicroControlPanelApplet.cpl
2009-09-26 11:25 124,800 a------- c:\windows\system32\drivers\mausbmr.sys
2009-09-26 11:25 21,504 a------- c:\windows\system32\mausbasio.dll
2009-09-26 11:23 <DIR> --d----- c:\program files\M-Audio
2009-09-26 11:07 75,375 a------- c:\windows\system32\mausbasio.bqj
2009-09-24 17:42 <DIR> --d----- c:\program files\iPod
2009-09-24 17:42 <DIR> --d----- c:\program files\iTunes
2009-09-10 21:44 45,056 a---h--- c:\windows\system32\mlfcache.dat
2009-09-10 18:14 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-10 18:13 <DIR> --d----- c:\program files\Bonjour
==================== Find3M ====================
2009-08-28 19:42 2,065,696 a------- c:\windows\system32\usbaaplrc.dll
2009-08-28 19:42 40,448 a------- c:\windows\system32\drivers\usbaapl.sys
2009-08-05 03:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 13:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2005-09-20 10:05 456,768 ac------ c:\windows\inf\wg311t\WG311T13.sys
2004-10-19 18:58 35,232 ac------ c:\windows\inf\wg311t\ME_INST.EXE
2004-10-19 18:58 26,112 ac------ c:\windows\inf\wg311t\install.exe
============= FINISH: 20:36:32.55 ===============
-------------
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/07 20:52
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAA955000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79C7000 Size: 8192 File Visible: No Signed: -
Status: -
Name: giveio.sys
Image Path: giveio.sys
Address: 0xF7A50000 Size: 1664 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA8061000 Size: 49152 File Visible: No Signed: -
Status: -
Name: speedfan.sys
Image Path: speedfan.sys
Address: 0xF798F000 Size: 5248 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: Volume C:\
Status: MBR Rootkit Detected!
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\scandisk.dll
Status: Invisible to the Windows API!
Path: C:\scandisk.lnk
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Bill\ntuser.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\calc.dll
Status: Invisible to the Windows API!
Path: c:\windows\temp\sqlite_1peirez3e23lyiy
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\sqlite_cahglna2czly66j
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\sqlite_gncsbxmjrkp7ucl
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\sqlite_sxhpcakvwr9odd9
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\sqlite_ukicbeiwjdwd2v3
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\sqlite_xf9dcm4ylysmp5e
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\sqlite_xrpkuiexatixxwb
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcafee_i07wz4nmyol8pae
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcafee_iugi8bf1kz2dwmz
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcmsc_4i7rktysuz0zyf5
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcmsc_kzfqvh4qclqazy1
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcmsc_ru83guxkk4vcfe3
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: C:\Documents and Settings\Bill\Start Menu\Programs\Startup\scandisk.dll
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Bill\Start Menu\Programs\Startup\scandisk.lnk
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0567.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0524.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0497.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0498.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0499.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0500.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0501.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0509.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0510.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0511.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0512.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0515.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0516.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0517.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0519.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0520.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0521.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0522.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0525.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0527.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0539.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0541.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0542.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0544.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0545.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0546.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0555.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0556.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0557.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0558.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0561.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0562.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0564.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0566.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0568.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0571.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0572.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0574.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0575.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0576.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0577.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0578.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0579.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0580.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0581.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0582.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0583.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0584.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0585.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0586.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0587.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0589.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0591.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0592.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0593.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0594.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0595.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0596.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0597.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0599.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0600.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0601.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0602.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0604.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0605.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0606.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0607.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0608.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0610.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0611.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0612.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0613.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0614.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0615.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0616.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0617.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0618.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0619.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0621.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0622.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0623.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0624.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0625.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0627.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0629.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0631.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0632.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0634.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0635.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0637.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0638.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0640.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0641.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0642.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0643.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0644.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0650.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0651.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0652.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0653.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0654.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0655.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0657.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0658.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0660.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0661.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0662.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0664.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0665.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0666.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0668.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0669.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0670.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0672.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0674.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0675.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0676.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0677.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0678.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0680.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0683.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0684.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0685.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0686.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0687.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0688.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0690.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0691.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0692.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0693.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0694.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0695.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0696.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0698.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0699.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0701.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0703.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0704.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0706.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0707.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0708.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0709.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0713.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0715.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0716.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0717.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0718.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0721.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0724.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0729.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0730.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0738.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0744.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0746.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0747.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0748.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0749.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0750.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0751.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0752.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0753.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0754.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0755.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0756.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0757.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0758.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0759.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest Trip\100_0760.JPG
Status: Could not get file information (Error 0xc0000008)
Path: C:\Documents and Settings\HelpAssistant\My Documents\My Pictures\Northwest TripSSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "PCTCore.sys" at address 0xf7978d72
#: 047 Function Name: NtCreateProcess
Status: Hooked by "PCTCore.sys" at address 0xf79599a6
#: 048 Function Name: NtCreateProcessEx
Status: Hooked by "PCTCore.sys" at address 0xf7959b98
#: 063 Function Name: NtDeleteKey
Status: Hooked by "PCTCore.sys" at address 0xf7979568
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "PCTCore.sys" at address 0xf7979820
#: 119 Function Name: NtOpenKey
Status: Hooked by "PCTCore.sys" at address 0xf7977a80
#: 192 Function Name: NtRenameKey
Status: Hooked by "PCTCore.sys" at address 0xf7979c8a
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "PCTCore.sys" at address 0xf7959656
Stealth Objects
-------------------
Object: Hidden Handle [Index: 2692, Type: Event]
Process: services.exe (PID: 1032) Address: 0x862e1e88 Size: -
Object: Hidden Code [Driver: ACPI, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88305d40 Size: 708
==EOF==