Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cyber Security rogue?


  • This topic is locked This topic is locked
26 replies to this topic

#1 wingguy69

wingguy69

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:04:05 AM

Posted 28 January 2010 - 07:23 PM

Let me thank you up front for any and all attention you give to this matter.
Your efforts are greatly appreciated.

At this point all I can tell you is Internet Explorer and Firefox both take me to random pages when I click on a link from a Google or Yahoo search. When I click on a link from an e-mail in Eudora, more often than not, I get a blank page in one window, and the actual linked page in a second window.
I don't know if this related but after 2yrs of constant nagging from Windows Update, I decided to finally let XP install SP3 today. It took me the better part of the day to uninstall it so my computer would boot up again.

I've inclded the dds.txt, attach.txt, and ark.txt as directed.



DDS (Ver_09-12-01.01) - NTFSx86
Run by Maloy at 17:35:35.67 on Thu 01/28/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.263.1033.18.3070.2166 [GMT -6:00]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\srvany.exe
C:\pvsw\bin\w3dbsmgr.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
G:\downloaded programs\dds\dds.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\adobe acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SpyHunter Security Suite] c:\program files\enigma software group\spyhunter\SpyHunter3.exe
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
StartupFolder: c:\docume~1\maloy\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareblaster\spywareblaster.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~2.lnk - c:\program files\labcenter electronics\proteus 7 demonstration\bin\UDSCHED.EXE
uPolicies-explorer: NoSMMyDocs = 01000000
uPolicies-explorer: NoSMMyPictures = 01000000
uPolicies-explorer: NoNetworkConnections = 01000000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Microsoft XML Parser for Java
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.5/installer.exe
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
TCP: {7A8CD992-36C5-4AB6-B294-D0CCC5D59C39} = 208.1.86.66,208.1.87.130
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: iFzTe - {C4D8E09A-6E72-4A30-AFE5-7254AC02731F} - No File
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\qualcomm\eudora\EuShlExt.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\maloy\applic~1\mozilla\firefox\profiles\frc1vqlo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================


==================== Find3M ====================

2008-10-02 13:51:30 18 --sh--w- c:\windows\WINPROD.DLL

============= FINISH: 17:38:23.18 ===============


Attached Files



BC AdBot (Login to Remove)

 


#2 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:10:05 AM

Posted 06 February 2010 - 06:56 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE



Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#3 wingguy69

wingguy69
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:04:05 AM

Posted 09 February 2010 - 10:46 AM

Hi Schrauber,

Thank you for your response, sorry for the delay in my reply.
gmer took a looooong time to scan.
Since my initial post the following have occurred:

Several times a day Avira Antivirus would find -
"Virus or unwanted program 'HTML/Infected.WebPage.Gen [virus]'
detected in file 'C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\Y6DQW22T\2[1].php."
At least once a day for the last week Windows pops up the following message: "DCOMServer process launcher service terminated unexpectedly Windows is shutting down"
Upon which I would have 60 seconds to save my work and exit all programs, or risk losing data; then windows would promptly shut down.

First thing yesterday morning, just before receiving the e-mail notification of your response to my initial post, I ran rkill and then MalwareBytes as recommended in the bleepingcomputer Malware removal Guide for the Cyber Security rogue.
Malwarebytes found two instances of Malware.Packer.Gen (See following MBAM log snippet)
...Files Infected:
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\IAAFBU1G\update[1].exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\pdfupd.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully...

I've included dds.txt & gmer.txt, and attached attach.txt.
So what's next?


DDS (Ver_09-12-01.01) - NTFSx86
Run by Maloy at 11:23:13.32 on Mon 02/08/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.263.1033.18.3070.2255 [GMT -6:00]

AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\Explorer.EXE
C:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
C:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\srvany.exe
C:\pvsw\bin\w3dbsmgr.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
G:\downloaded programs\dds\dds.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\lowsec.exe,
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\adobe acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SpyHunter Security Suite] c:\program files\enigma software group\spyhunter\SpyHunter3.exe
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\maloy\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareblaster\spywareblaster.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~2.lnk - c:\program files\labcenter electronics\proteus 7 demonstration\bin\UDSCHED.EXE
uPolicies-explorer: NoSMMyDocs = 01000000
uPolicies-explorer: NoSMMyPictures = 01000000
uPolicies-explorer: NoNetworkConnections = 01000000
dPolicies-explorer: DisallowRun = 1 (0x1)
dPolicies-disallowrun: 1 = opera.exe
dPolicies-disallowrun: 2 = firefox.exe
dPolicies-disallowrun: 3 = chrome.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Microsoft XML Parser for Java
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.5/installer.exe
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
TCP: {7A8CD992-36C5-4AB6-B294-D0CCC5D59C39} = 208.1.86.66,208.1.87.130
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: iFzTe - {C4D8E09A-6E72-4A30-AFE5-7254AC02731F} - No File
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\qualcomm\eudora\EuShlExt.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\maloy\applic~1\mozilla\firefox\profiles\frc1vqlo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================


==================== Find3M ====================

2008-10-02 13:51:30 18 --sh--w- c:\windows\WINPROD.DLL

============= FINISH: 11:25:38.45 ===============




GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-09 08:21:36
Windows 5.1.2600 Service Pack 2
Running: 0j5w0o85.exe; Driver: C:\DOCUME~1\Maloy\LOCALS~1\Temp\awldapod.sys


---- System - GMER 1.0.15 ----

SSDT AC2C043E ZwCreateKey
SSDT AC2C0434 ZwCreateThread
SSDT AC2C0443 ZwDeleteKey
SSDT AC2C044D ZwDeleteValueKey
SSDT AC2C0452 ZwLoadKey
SSDT AC2C0420 ZwOpenProcess
SSDT AC2C0425 ZwOpenThread
SSDT AC2C045C ZwReplaceKey
SSDT AC2C0457 ZwRestoreKey
SSDT AC2C0448 ZwSetValueKey
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAE2BD0B0]

---- Kernel code sections - GMER 1.0.15 ----

? plmegxp.sys The system cannot find the file specified. !
.rsrc C:\WINDOWS\system32\drivers\iaStor.sys entry point in ".rsrc" section [0xF7BDC024]
init C:\WINDOWS\system32\DRIVERS\mohfilt.sys entry point in "init" section [0xB84E3760]
init C:\WINDOWS\System32\Drivers\PEDRV.SYS entry point in "init" section [0xA1DDEE00]

---- User code sections - GMER 1.0.15 ----

.reloc C:\WINDOWS\Explorer.EXE[528] C:\WINDOWS\Explorer.EXE section is executable [0x010FB000, 0x4000, 0x62000060]
.rsrc C:\WINDOWS\system32\winlogon.exe[816] C:\WINDOWS\system32\winlogon.exe section is executable [0x01076000, 0xA000, 0x60000060]
.rsrc C:\WINDOWS\system32\svchost.exe[1120] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x1000, 0x60000060]
.text C:\WINDOWS\system32\svchost.exe[1120] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 00B6000A
.rsrc C:\WINDOWS\system32\svchost.exe[1240] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x1000, 0x60000060]
.rsrc C:\WINDOWS\System32\svchost.exe[1340] C:\WINDOWS\System32\svchost.exe section is executable [0x01005000, 0x1000, 0x60000060]
.rsrc C:\WINDOWS\system32\svchost.exe[1396] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x1000, 0x60000060]
.rsrc C:\WINDOWS\system32\svchost.exe[1596] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x1000, 0x60000060]
.rsrc C:\WINDOWS\System32\svchost.exe[1880] C:\WINDOWS\System32\svchost.exe section is executable [0x01005000, 0x1000, 0x60000060]
.rsrc C:\WINDOWS\system32\svchost.exe[1960] C:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x1000, 0x60000060]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\Rundll32.exe[100] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\Explorer.EXE [USER32.dll!EndDialog] 02D154E1
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\Explorer.EXE [USER32.dll!TranslateMessage] 02D15F49
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 02D159DA
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 02D158C5
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 02D15860
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 02D1582E
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 02D15C9F
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 02D15F49
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 02D154E1
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 02D15F49
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 02D154E1
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 02D154E1
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 02D15F49
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 02D15C9F
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 02D154E1
IAT C:\WINDOWS\Explorer.EXE[528] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 02D159DA
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[784] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001454E1
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[796] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[840] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\services.exe [ntdll.dll!NtQueryDirectoryFile] 00CF59DA
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00CF59DA
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00CF58C5
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00CF5860
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00CF582E
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 00CF54E1
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00CF5C9F
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00CF5F49
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 00CF54E1
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00CF5F49
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00CF5C9F
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 00CF54E1
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00CF5F49
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 00CF54E1
IAT C:\WINDOWS\system32\services.exe[864] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00CF59DA
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00EB59DA
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00EB58C5
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00EB5860
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00EB582E
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\LSASRV.dll [ntdll.dll!LdrLoadDll] 00EB58C5
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00EB59DA
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrLoadDll] 00EB58C5
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrGetProcedureAddress] 00EB5860
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00EB5C9F
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00EB5F49
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 00EB54E1
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00EB5F49
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00EB5C9F
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 00EB54E1
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00EB5F49
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 00EB54E1
IAT C:\WINDOWS\system32\lsass.exe[876] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 00EB54E1
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[984] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\system32\svchost.exe[1120] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00B9582E
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1128] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[1208] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[1224] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00B659DA
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00B658C5
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00B65860
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00B6582E
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00B65C9F
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00B65F49
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 00B654E1
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00B65F49
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00B65C9F
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 00B654E1
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00B65F49
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 00B654E1
IAT C:\WINDOWS\system32\svchost.exe[1240] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 00B654E1
IAT C:\WINDOWS\system32\svchost.exe[1240] @ c:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00B659DA
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00FD59DA
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00FD58C5
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00FD5860
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00FD582E
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00FD5C9F
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00FD5F49
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 00FD54E1
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00FD5F49
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00FD5C9F
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 00FD54E1
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00FD5F49
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 00FD54E1
IAT C:\WINDOWS\System32\svchost.exe[1340] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 00FD54E1
IAT C:\WINDOWS\System32\svchost.exe[1340] @ c:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00FD59DA
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\srvany.exe[1376] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1500] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Java\jre6\bin\jqs.exe[1744] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 016A59DA
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 016A58C5
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 016A5860
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 016A582E
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 016A59DA
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 016A54E1
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 016A5F49
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 016A5C9F
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 016A54E1
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 016A5F49
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 016A54E1
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 016A5C9F
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 016A5F49
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1872] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 016A54E1
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\svchost.exe[1880] @ C:\WINDOWS\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 01EA59DA
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01EA58C5
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01EA5860
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 01EA582E
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 01EA54E1
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01EA5F49
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01EA5C9F
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 01EA54E1
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01EA5F49
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 01EA54E1
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 01EA5C9F
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 01EA5F49
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 01EA59DA
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1896] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 01EA54E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2036] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001354E1
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\pvsw\bin\w3dbsmgr.exe[2076] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2196] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2232] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 000858C5
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00085860
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0008582E
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\ctfmon.exe[2436] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2452] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2488] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2536] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2668] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[2712] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2804] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[3036] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 000858C5
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00085860
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0008582E
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[3304] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3724] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\alg.exe[4024] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 004054E1

---- Devices - GMER 1.0.15 ----

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device -> \Driver\iaStor \Device\Harddisk0\DR0 8B186841

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\SYSTEM32\lowsec.exe 105472 bytes executable
File C:\WINDOWS\SYSTEM32\winsys 0 bytes
File C:\WINDOWS\SYSTEM32\winsys\wdc.dll 221230 bytes
File C:\WINDOWS\SYSTEM32\winsys\wdl.dll 0 bytes
File C:\WINDOWS\SYSTEM32\winsys\wdl.dll.lll 335 bytes
File C:\WINDOWS\system32\drivers\iaStor.sys suspicious modification

---- EOF - GMER 1.0.15 ----

Attached Files



#4 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:10:05 AM

Posted 09 February 2010 - 03:25 PM

Hello, wingguy69
Welcome to the Bleeping Computer Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favourites. Alternatively, you can click the button at the top bar of this topic and Track this Topic. The topics you are tracking can be found here.

Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just post back here so that we know you're still here.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.




Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



--------------------------------------------------------------------

Double click on the renamed Combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#5 wingguy69

wingguy69
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:04:05 AM

Posted 09 February 2010 - 04:31 PM

Hi Tom,

Here's the ComboFix Log.
It found rootkit activity and needed to re-boot.
Avira popped up 3 messages after the reboot.
I checked ignore for each of them.

Also after the second reboot while ComboFix was telling me not to start any programs while it prepared my log, all of my security software was reloading from the reboot.
I Hope this didn't taint the scan.



ComboFix 10-02-09.01 - Maloy 02/09/2010 15:05:25.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.263.1033.18.3070.2489 [GMT -6:00]
Running from: c:\documents and settings\Maloy\Desktop\schrauber.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\au3305adc.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe

Infected copy of c:\windows\system32\drivers\iaStor.sys was found and disinfected
Restored copy from - Kitty ate it tongue.gif
Infected copy of c:\windows\system32\lsass.exe was found and disinfected
Restored copy from - c:\i386\LSASS.EXE

Infected copy of c:\windows\system32\svchost.exe was found and disinfected
Restored copy from - c:\i386\SVCHOST.EXE

Infected copy of c:\windows\system32\spoolsv.exe was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_IPFW
-------\Legacy_IPRIP
-------\Legacy_IP_FW
-------\Legacy_sysrest.sys
-------\Service_Iprip


((((((((((((((((((((((((( Files Created from 2010-01-09 to 2010-02-09 )))))))))))))))))))))))))))))))
.

2010-02-08 02:28 . 2010-02-09 21:15 -------- d-sh--w- c:\windows\system32\winsys
2010-01-28 21:41 . 2010-01-28 21:41 -------- d-----w- c:\documents and settings\Maloy\Local Settings\Application Data\SupportSoft
2010-01-28 21:39 . 2010-01-28 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\SupportSoft
2010-01-28 21:39 . 2010-01-28 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PCDr
2010-01-28 21:37 . 2010-01-28 21:38 -------- d-----w- c:\program files\Dell Support Center
2010-01-28 21:37 . 2010-01-28 21:37 -------- d-----w- c:\program files\Common Files\supportsoft
2010-01-28 17:08 . 2010-01-28 17:08 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-28 14:48 . 2010-01-28 11:02 -------- d-----w- c:\windows\system32\scripting
2010-01-28 14:48 . 2010-01-28 11:02 -------- d-----w- c:\windows\system32\en
2010-01-28 14:48 . 2010-01-28 11:02 -------- d-----w- c:\windows\system32\bits
2010-01-28 14:48 . 2010-01-28 11:02 -------- d-----w- c:\windows\l2schemas
2010-01-28 14:43 . 2004-08-04 11:00 37376 ----a-w- c:\windows\system32\drivers\amdk7.sys
2010-01-27 19:36 . 2010-01-27 19:36 -------- d-----w- c:\program files\Lavasoft
2010-01-27 18:18 . 2010-01-27 18:18 52224 ----a-w- c:\documents and settings\Maloy\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-27 18:18 . 2010-02-09 14:54 117760 ----a-w- c:\documents and settings\Maloy\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-27 18:18 . 2010-01-27 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-27 18:18 . 2010-01-27 18:18 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-27 18:18 . 2010-01-27 18:18 -------- d-----w- c:\documents and settings\Maloy\Application Data\SUPERAntiSpyware.com
2010-01-27 17:25 . 2010-01-27 17:25 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-09 21:16 . 2007-10-31 18:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-09 14:53 . 2009-04-20 13:56 -------- d-----w- c:\program files\SpywareBlaster
2010-02-06 20:52 . 2007-08-10 13:37 -------- d-----w- c:\program files\Google
2010-02-05 22:49 . 2005-01-04 20:42 -------- d-----w- c:\documents and settings\Maloy\Application Data\AdobeUM
2010-02-02 18:35 . 1980-01-01 06:00 250368 ----a-w- c:\windows\system32\drivers\iaStor.sys
2010-01-29 17:59 . 2007-11-16 17:06 -------- d--h--r- c:\documents and settings\Maloy\Application Data\Microchip
2010-01-28 21:48 . 2004-12-22 05:07 135656 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-28 21:42 . 2004-12-22 04:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2010-01-28 19:55 . 2004-08-11 23:25 88907 ----a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2010-01-27 19:36 . 2005-02-24 20:11 -------- d-----w- c:\documents and settings\Maloy\Application Data\Lavasoft
2010-01-27 18:16 . 2007-10-31 18:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-27 17:42 . 2005-02-24 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-27 17:25 . 2010-01-06 14:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-13 21:23 . 2008-12-01 23:17 -------- d-----w- c:\program files\Apollo DVD Copy
2010-01-08 17:49 . 2010-01-08 17:49 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
2010-01-07 22:07 . 2010-01-06 14:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2010-01-06 14:55 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 14:44 . 2010-01-06 14:44 -------- d-----w- c:\program files\ERUNT
2010-01-01 23:46 . 2010-01-01 23:46 -------- d-----w- c:\documents and settings\Maloy\Application Data\com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1
2010-01-01 23:46 . 2010-01-01 23:46 -------- d-----w- c:\program files\YNAB 3
2010-01-01 23:46 . 2010-01-01 23:46 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-01 23:45 . 2010-01-01 23:46 38784 ----a-w- c:\documents and settings\Maloy\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-01 20:05 . 2008-12-01 23:18 -------- d-----w- c:\documents and settings\Maloy\Application Data\dvdcss
2009-12-31 14:46 . 2005-02-24 20:30 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-21 19:14 . 2004-08-04 11:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-07 14:28 . 2009-07-02 17:31 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2007-10-11 16:24 . 2007-10-11 16:23 385 ----a-w- c:\program files\DeaInstall.log
2007-10-09 13:43 . 2007-10-09 13:43 190 ----a-w- c:\program files\Common Files\psasetup.log
2008-10-02 13:51 . 2008-10-02 13:51 18 --sh--w- c:\windows\WINPROD.DLL
.

------- Sigcheck -------

[-] 2008-06-17 . 481ADDBB21037489EACFCB308B1BE2B0 . 505856 . . [5.1.2600.2180] . . c:\windows\SYSTEM32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-14 1688872]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"P17Helper"="P17.dll" [2004-06-10 60928]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 151552]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-11-16 127035]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-09-20 4583424]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-09-20 86016]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-12-09 866200]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-12-22 98304]

c:\documents and settings\Maloy\Start Menu\Programs\Startup\
SpywareBlaster.lnk - c:\program files\SpywareBlaster\spywareblaster.exe [2009-4-20 1340944]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Update Scheduler for Proteus Demonstration 7.lnk - c:\program files\Labcenter Electronics\Proteus 7 Demonstration\BIN\UDSCHED.EXE [2007-6-26 66076]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
"NoNetworkConnections"= 01000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= opera.exe
"2"= firefox.exe
"3"= chrome.exe

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2006-08-17 86016]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\lowsec.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-05-28 17:32 87352 ----a-w- c:\windows\SYSTEM32\LMIinit.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Update Scheduler for Proteus Professional 7.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Update Scheduler for Proteus Professional 7.lnk
backup=c:\windows\pss\Update Scheduler for Proteus Professional 7.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ROY

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeVersionCue]
2003-10-13 22:24 1732608 ----a-w- c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 ----a-w- c:\program files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-10-12 22:54 57344 ------w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2006-01-17 18:03 53248 ----a-w- c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2006-01-17 18:03 135168 ----a-w- c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 ----a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-12-03 19:21 2213160 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 19:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
2007-07-09 21:51 2577120 ----a-w- c:\program files\PCPitstop\Optimize\PCPOptimize.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCPitstop Optimize Registration Reminder]
2007-07-09 21:51 897752 ----a-w- c:\program files\PCPitstop\Optimize\Reminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2004-12-22 05:06 98304 ----a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2004-12-22 05:05 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ROY\EPSON Stylus Photo 1400 Series]
2006-10-11 10:01 143360 ----a-w- c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIBUA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2004-01-07 07:01 110592 ----a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WScheduler]
2007-06-26 01:19 75264 ----a-w- c:\progra~1\SYSTEM~1\WScheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FastUserSwitchingCompatibility"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"MSSQLServerADHelper"=3 (0x3)
"MSSQL$AUTODESKVAULT"=2 (0x2)
"gusvc"=3 (0x3)
"DSBrokerService"=3 (0x3)
"CbEvtSvc"=2 (0x2)
"AdobeVersionCue"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"Iprip"=2 (0x2)
"CiSvc"=3 (0x3)
"WZCSVC"=2 (0x2)
"rpcapd"=3 (0x3)
"MpfService"=2 (0x2)
"mnmsrvc"=3 (0x3)
"McSysmon"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
"SQLAgent$AUTODESKVAULT"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Freescale\\CodeWarrior for ColdFire V7.1\\bin\\IDE.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"g:\\BeltWay\\bwserver.exe"=
"c:\\Documents and Settings\\Maloy\\Desktop\\BW Server 2.02\\BW Server 2.02\\winxp\\bwserver.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:*:Disabled:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:*:Disabled:Peer Name Resolution Protocol (PNRP)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7/2/2009 11:31 AM 108289]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\SYSTEM32\DRIVERS\LMIRfsDriver.sys [4/23/2008 7:26 AM 45848]
R2 PEDRV;P&E Microcomputer System PCI Driver.;c:\windows\SYSTEM32\DRIVERS\pedrv.sys [8/3/2000 1:25 PM 23296]
R2 Pervasive.SQL Workgroup Engine;Pervasive.SQL Workgroup Engine;c:\windows\SYSTEM32\srvany.exe [10/9/2007 7:22 AM 8192]
R2 VICHW11;P&E BDM Cable Driver II;c:\windows\SYSTEM32\DRIVERS\vichw11.sys [10/2/1998 9:20 AM 5200]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
S1 tcyazfq;tcyazfq;c:\windows\SYSTEM32\uwzfqas.sys [6/13/2008 3:41 PM 0]
S2 gupdate1c9f36ec79a4c60;Google Update Service (gupdate1c9f36ec79a4c60);c:\program files\Google\Update\GoogleUpdate.exe [6/22/2009 1:22 PM 133104]
S2 lmiinfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys --> c:\program files\LogMeIn\x86\RaInfo.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\SYSTEM32\DRIVERS\npf.sys [8/2/2005 3:10 PM 32512]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 5:28 PM 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\SYSTEM32\DRIVERS\RsFx0102.sys [7/10/2008 2:49 AM 242712]
S4 SQLAgent$AUTODESKVAULT;SQLAgent$AUTODESKVAULT;c:\program files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlagent.EXE [5/3/2005 8:42 PM 323584]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/10/2008 5:28 PM 369688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 19:21]

2010-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 19:21]
.
.
------- Supplementary Scan -------
.
uStart Page = www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
TCP: {7A8CD992-36C5-4AB6-B294-D0CCC5D59C39} = 208.1.86.66,208.1.87.130
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Maloy\Application Data\Mozilla\Firefox\Profiles\frc1vqlo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

SSODL-iFzTe-{C4D8E09A-6E72-4A30-AFE5-7254AC02731F} - (no file)
Notify-dimsntfy - (no file)
MSConfigStartUp-LogMeIn GUI - c:\program files\LogMeIn\x86\LogMeInSystray.exe
MSConfigStartUp-nwiz - nwiz.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-09 15:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\*}*! ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\*/*& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\*q* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\ *"! ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\(*V*9 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\(* 0 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\0*{* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\0* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\8*G*0 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\8*& & ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\@*>*0 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\@*|* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\@** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\h**& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\H*'* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\H**& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\h** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\h*}! ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\p*,*& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\P*x* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\p**! ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\x*y* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\X** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\X**& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\x*" 9 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\*,*& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(816)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll

- - - - - - - > 'lsass.exe'(872)
c:\windows\system32\wininet.dll

- - - - - - - > 'explorer.exe'(3288)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
c:\program files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\pvsw\bin\w3dbsmgr.exe
c:\windows\system32\tcpsvcs.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\Rundll32.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
.
**************************************************************************
.
Completion time: 2010-02-09 15:23:03 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-09 21:23

Pre-Run: 7,811,690,496 bytes free
Post-Run: 7,792,164,864 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - AB95D68E2259A640E051CC47605CB561


#6 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:10:05 AM

Posted 10 February 2010 - 01:25 PM

Hi,


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
Registry::
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"=-
"2"=-
"3"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,"

File::
c:\windows\system32\lowsec.exe


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#7 wingguy69

wingguy69
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:04:05 AM

Posted 10 February 2010 - 02:48 PM

Hi Tom,

A couple things I noticed during the scan:
When ComboFix launched, the first thing in the DOS window said "not enough main memory to complete the sort"
Also, after "Completed Stage2" I got a Windows error pop-up " PEV.cfxxe has encountered a problem and needs to close. Please tell Microsoft about this problem."
I clicked on "Do Not Send" and the scan continued.
Finally, at the end while ComboFix was preparing a log, I got the "not enough main memory to complete the sort" message again.



ComboFix 10-02-09.01 - Maloy 02/10/2010 13:12:04.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.263.1033.18.3070.2421 [GMT -6:00]
Running from: c:\documents and settings\Maloy\Desktop\schrauber.exe
Command switches used :: c:\documents and settings\Maloy\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 13:51 . 2008-10-02 13:51 18 --sh--w- c:\windows\WINPROD.DLL
.

------- Sigcheck -------

[-] 2008-06-17 . 481ADDBB21037489EACFCB308B1BE2B0 . 505856 . . [5.1.2600.2180] . . c:\windows\SYSTEM32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-14 1688872]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"P17Helper"="P17.dll" [2004-06-10 60928]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 151552]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-11-16 127035]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-09-20 4583424]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-09-20 86016]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-12-09 866200]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-12-22 98304]

c:\documents and settings\Maloy\Start Menu\Programs\Startup\
SpywareBlaster.lnk - c:\program files\SpywareBlaster\spywareblaster.exe [2009-4-20 1340944]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Update Scheduler for Proteus Demonstration 7.lnk - c:\program files\Labcenter Electronics\Proteus 7 Demonstration\BIN\UDSCHED.EXE [2007-6-26 66076]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
"NoNetworkConnections"= 01000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2006-08-17 86016]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\lowsec.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-05-28 17:32 87352 ----a-w- c:\windows\SYSTEM32\LMIinit.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Update Scheduler for Proteus Professional 7.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Update Scheduler for Proteus Professional 7.lnk
backup=c:\windows\pss\Update Scheduler for Proteus Professional 7.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeVersionCue]
2003-10-13 22:24 1732608 ----a-w- c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 ----a-w- c:\program files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-10-12 22:54 57344 ------w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2006-01-17 18:03 53248 ----a-w- c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2006-01-17 18:03 135168 ----a-w- c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 ----a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-12-03 19:21 2213160 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 19:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
2007-07-09 21:51 2577120 ----a-w- c:\program files\PCPitstop\Optimize\PCPOptimize.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCPitstop Optimize Registration Reminder]
2007-07-09 21:51 897752 ----a-w- c:\program files\PCPitstop\Optimize\Reminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2004-12-22 05:06 98304 ----a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2004-12-22 05:05 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2004-01-07 07:01 110592 ----a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WScheduler]
2007-06-26 01:19 75264 ----a-w- c:\progra~1\SYSTEM~1\WScheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FastUserSwitchingCompatibility"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"MSSQLServerADHelper"=3 (0x3)
"MSSQL$AUTODESKVAULT"=2 (0x2)
"gusvc"=3 (0x3)
"DSBrokerService"=3 (0x3)
"CbEvtSvc"=2 (0x2)
"AdobeVersionCue"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"Iprip"=2 (0x2)
"CiSvc"=3 (0x3)
"WZCSVC"=2 (0x2)
"rpcapd"=3 (0x3)
"MpfService"=2 (0x2)
"mnmsrvc"=3 (0x3)
"McSysmon"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
"SQLAgent$AUTODESKVAULT"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Freescale\\CodeWarrior for ColdFire V7.1\\bin\\IDE.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"g:\\BeltWay\\bwserver.exe"=
"c:\\Documents and Settings\\Maloy\\Desktop\\BW Server 2.02\\BW Server 2.02\\winxp\\bwserver.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:*:Disabled:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:*:Disabled:Peer Name Resolution Protocol (PNRP)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)


R1 tcyazfq;tcyazfq;c:\windows\system32\uwzfqas.sys [2008-06-23 0]
R2 gupdate1c9f36ec79a4c60;Google Update Service (gupdate1c9f36ec79a4c60);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 133104]
R2 lmiinfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x]
R2 Pervasive.SQL Workgroup Engine;Pervasive.SQL Workgroup Engine;c:\windows\system32\srvany.exe [2006-12-19 8192]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
R4 LMIRfsClientNP;LMIRfsClientNP; [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
R4 RsFx0102;RsFx0102 Driver;c:\windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
R4 SQLAgent$AUTODESKVAULT;SQLAgent$AUTODESKVAULT;c:\program files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlagent.EXE [2005-05-04 323584]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-01-05 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-01-05 74480]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 45848]
S2 PEDRV;P&E Microcomputer System PCI Driver.; [x]
S2 VICHW11;P&E BDM Cable Driver II; [x]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-01-05 7408]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 19:21]

2010-02-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 19:21]
.
.
------- Supplementary Scan -------
.
uStart Page = www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
TCP: {7A8CD992-36C5-4AB6-B294-D0CCC5D59C39} = 208.1.86.66,208.1.87.130
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Maloy\Application Data\Mozilla\Firefox\Profiles\frc1vqlo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-10 13:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\*}*! ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\*/*& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\*q* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\ *"! ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\(*V*9 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\(* 0 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\0*{* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\0* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\8*G*0 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\8*& & ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\@*>*0 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\@*|* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\@** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\h**& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\H*'* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\H**& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\h** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\h*}! ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\p*,*& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\P*x* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\p**! ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\x*y* ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\X** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\X**& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\x*" 9 ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\** ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"

[HKEY_USERS\S-1-5-21-352764416-3222979780-1902511108-1005\Software\Labcenter Electronics\ARES\6\*,*& ]
"Type Column"="No"
"Category Column"="No"
"Sub-category Column"="No"
"Manufacturer Column"="No"
"Library Column"="Yes"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(816)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll

- - - - - - - > 'lsass.exe'(872)
c:\windows\system32\wininet.dll

- - - - - - - > 'explorer.exe'(656)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2010-02-10 13:27:04
ComboFix-quarantined-files.txt 2010-02-10 19:26
ComboFix2.txt 2010-02-09 21:23

Pre-Run: 7,806,410,752 bytes free
Post-Run: 7,750,389,760 bytes free

- - End Of File - - 00292FF50055F8903A348982FAB1EDFB


#8 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:10:05 AM

Posted 11 February 2010 - 02:53 PM

Hi,

PLease post back with a fresh Gmer logfile.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#9 wingguy69

wingguy69
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:04:05 AM

Posted 12 February 2010 - 12:06 PM

Hi Tom,

I started GMER yesterday afternoon upon receiving your last reply.
It finished in about 30min.
I've included the log from this scan but I don't think it's complete. No FILES section.
I was a bit curious about how fast the scan finished (30min) because the previous GMER scan lasted over 7 hours.
I started that first scan at noon, I checked it at 7pm and it was still running, so I let it go and the next morning I checked at 8:30am, it was finished and I sent you the log.
So when this scan stopped after only 30min. I thought something might be amiss.

Since I was fairly sure this scan was incomplete I decided to run GMER again.
I started the scan at around 3:00pm yesterday and it was still running when I checked it this morning at 8:30am
Is that normal?
Anyway, I needed to use the computer so I had to cancel that scan.

UNLESS you instruct me differently before this evening (approximately 4:00pm[GMT-6]), I will start GMER again at that time, let it run until it finishes, and send you that log.
Again, this scan I've included here is from the 30min. scan which appears to have skipped the FILES section.



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-11 14:31:58
Windows 5.1.2600 Service Pack 2
Running: 0j5w0o85.exe; Driver: C:\DOCUME~1\Maloy\LOCALS~1\Temp\awldapod.sys


---- System - GMER 1.0.15 ----

SSDT B2EFB626 ZwCreateKey
SSDT B2EFB61C ZwCreateThread
SSDT B2EFB62B ZwDeleteKey
SSDT B2EFB635 ZwDeleteValueKey
SSDT B2EFB63A ZwLoadKey
SSDT B2EFB608 ZwOpenProcess
SSDT B2EFB60D ZwOpenThread
SSDT B2EFB644 ZwReplaceKey
SSDT B2EFB63F ZwRestoreKey
SSDT B2EFB630 ZwSetValueKey
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAE10C0B0]

---- Kernel code sections - GMER 1.0.15 ----

init C:\WINDOWS\system32\DRIVERS\mohfilt.sys entry point in "init" section [0xF77BA760]
init C:\WINDOWS\System32\Drivers\PEDRV.SYS entry point in "init" section [0xA17CBE00]

---- User code sections - GMER 1.0.15 ----

.rsrc C:\WINDOWS\system32\winlogon.exe[812] C:\WINDOWS\system32\winlogon.exe section is executable [0x01076000, 0xA000, 0x60000060]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Java\jre6\bin\jqs.exe[292] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\Explorer.EXE [USER32.dll!EndDialog] 02BD54E1
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\Explorer.EXE [USER32.dll!TranslateMessage] 02BD5F49
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 02BD59DA
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 02BD58C5
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 02BD5860
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 02BD582E
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 02BD5C9F
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 02BD5F49
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 02BD54E1
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 02BD5F49
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!EndDialog] 02BD54E1
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 02BD54E1
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 02BD5F49
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 02BD5C9F
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 02BD54E1
IAT C:\WINDOWS\Explorer.EXE[416] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 02BD59DA
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[652] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\services.exe [ntdll.dll!NtQueryDirectoryFile] 00A759DA
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00A759DA
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00A758C5
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00A75860
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00A7582E
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 00A754E1
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00A75C9F
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00A75F49
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 00A754E1
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00A75F49
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00A75C9F
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 00A754E1
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00A75F49
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00A759DA
IAT C:\WINDOWS\system32\services.exe[856] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 00A754E1
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00B759DA
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00B758C5
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00B75860
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00B7582E
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\LSASRV.dll [ntdll.dll!LdrLoadDll] 00B758C5
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00B759DA
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrLoadDll] 00B758C5
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrGetProcedureAddress] 00B75860
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00B75C9F
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00B75F49
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 00B754E1
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00B75F49
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00B75C9F
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 00B754E1
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00B75F49
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 00B754E1
IAT C:\WINDOWS\system32\lsass.exe[868] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 00B754E1
IAT C:\WINDOWS\system32\svchost.exe[1128] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 007B582E
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 000858C5
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00085860
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0008582E
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[1204] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00A259DA
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00A258C5
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00A25860
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00A2582E
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00A25C9F
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00A25F49
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 00A254E1
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00A25F49
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00A25C9F
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 00A254E1
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00A25F49
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 00A254E1
IAT C:\WINDOWS\system32\svchost.exe[1208] @ c:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00A259DA
IAT C:\WINDOWS\system32\svchost.exe[1208] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 00A254E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe[1232] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\srvany.exe[1252] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 004054E1
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001354E1
IAT C:\pvsw\bin\w3dbsmgr.exe[1280] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00E559DA
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00E558C5
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00E55860
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00E5582E
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00E55C9F
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00E55F49
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 00E554E1
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00E55F49
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00E55C9F
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 00E554E1
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00E55F49
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 00E554E1
IAT C:\WINDOWS\System32\svchost.exe[1308] @ c:\windows\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00E559DA
IAT C:\WINDOWS\System32\svchost.exe[1308] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 00E554E1
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\WINDOWS\system32\CTsvcCDA.EXE[1488] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 014659DA
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 014658C5
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01465860
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0146582E
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 014659DA
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 014654E1
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01465F49
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01465C9F
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 014654E1
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01465F49
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 014654E1
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 01465C9F
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 01465F49
IAT C:\Program Files\Avira\AntiVir Desktop\sched.exe[1692] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 014654E1
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 01B959DA
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 01B958C5
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 01B95860
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 01B9582E
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 01B954E1
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 01B95F49
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 01B95C9F
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 01B954E1
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 01B95F49
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 01B959DA
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 01B954E1
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 01B95C9F
IAT C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1712] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 01B95F49
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\svchost.exe[1848] @ C:\WINDOWS\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Google\Update\GoogleUpdate.exe[1892] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1908] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1992] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\tcpsvcs.exe[2064] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2152] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2204] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\MsPMSPSv.exe[2284] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\system32\Rundll32.exe[2368] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe[2424] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001454E1
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[2440] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe[2460] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2492] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNetwk.exe[2504] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2576] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 000858C5
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00085860
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0008582E
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\wuauclt.exe[2596] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001458C5
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00145860
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0014582E
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00145C9F
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00145F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001459DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe[2652] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001454E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1
IAT C:\Program Files\Windows Media Player\WMPNSCFG.exe[2860] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 000858C5
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00085860
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0008582E
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00085C9F
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00085F49
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 000854E1
IAT C:\WINDOWS\system32\ctfmon.exe[3008] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 000859DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 001358C5
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00135860
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0013582E
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00135C9F
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00135F49
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 001359DA
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 001354E1
IAT C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[3772] @ C:\WINDOWS\system32\userenv.dll [USER32.dll!EndDialog] 001354E1
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 004058C5
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00405860
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 0040582E
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 004059DA
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00405C9F
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00405F49
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\USERENV.dll [USER32.dll!EndDialog] 004054E1
IAT C:\WINDOWS\System32\alg.exe[4048] @ C:\WINDOWS\system32\wininet.dll [USER32.dll!EndDialog] 004054E1

---- Devices - GMER 1.0.15 ----

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

---- EOF - GMER 1.0.15 ----



#10 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:10:05 AM

Posted 13 February 2010 - 01:12 PM

Hi,

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
  • Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

  • If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
  • When it is done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents of that file here.

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#11 wingguy69

wingguy69
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:04:05 AM

Posted 15 February 2010 - 10:23 AM

Hi Tom,
Here is the Kaspersky log.


09:01:09:750 3744 TDSS rootkit removing tool 2.2.3 Feb 4 2010 14:34:00
09:01:09:750 3744 ================================================================================
09:01:09:750 3744 SystemInfo:

09:01:09:750 3744 OS Version: 5.1.2600 ServicePack: 2.0
09:01:09:750 3744 Product type: Workstation
09:01:09:750 3744 ComputerName: ENGINEERING2
09:01:09:750 3744 UserName: Maloy
09:01:09:750 3744 Windows directory: C:\WINDOWS
09:01:09:750 3744 Processor architecture: Intel x86
09:01:09:750 3744 Number of processors: 2
09:01:09:750 3744 Page size: 0x1000
09:01:09:750 3744 Boot type: Normal boot
09:01:09:750 3744 ================================================================================
09:01:09:765 3744 UnloadDriverW: NtUnloadDriver error 2
09:01:09:765 3744 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
09:01:09:765 3744 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
09:01:09:765 3744 UtilityInit: KLMD drop and load success
09:01:09:765 3744 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010)
09:01:09:765 3744 UtilityInit: KLMD open success
09:01:09:765 3744 UtilityInit: Initialize success
09:01:09:765 3744
09:01:09:765 3744 Scanning Services ...
09:01:09:765 3744 CreateRegParser: Registry parser init started
09:01:09:765 3744 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
09:01:09:765 3744 CreateRegParser: DisableWow64Redirection error
09:01:09:765 3744 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
09:01:09:765 3744 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
09:01:09:765 3744 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
09:01:09:765 3744 wfopen_ex: Trying to KLMD file open
09:01:09:765 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
09:01:09:765 3744 wfopen_ex: File opened ok (Flags 2)
09:01:09:765 3744 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: B64E40
09:01:09:765 3744 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
09:01:09:765 3744 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
09:01:09:765 3744 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
09:01:09:765 3744 wfopen_ex: Trying to KLMD file open
09:01:09:765 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
09:01:09:765 3744 wfopen_ex: File opened ok (Flags 2)
09:01:09:765 3744 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: B64D30
09:01:09:765 3744 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
09:01:09:765 3744 CreateRegParser: EnableWow64Redirection error
09:01:09:765 3744 CreateRegParser: RegParser init completed
09:01:09:828 3744 GetAdvancedServicesInfo: Raw services enum returned 407 services
09:01:09:828 3744 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
09:01:09:828 3744 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
09:01:09:828 3744
09:01:09:828 3744 Scanning Kernel memory ...
09:01:09:828 3744 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
09:01:09:828 3744 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8A8DE960
09:01:09:828 3744 DetectCureTDL3: KLMD_GetDeviceObjectList returned 9 DevObjects
09:01:09:828 3744
09:01:09:828 3744 DetectCureTDL3: DEVICE_OBJECT: 89D82030
09:01:09:828 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89D82030
09:01:09:828 3744 KLMD_ReadMem: Trying to ReadMemory 0x89D82030[0x38]
09:01:09:828 3744 DetectCureTDL3: DRIVER_OBJECT: 8A8DE960
09:01:09:828 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DE960[0xA8]
09:01:09:828 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1CA6EF0[0x18]
09:01:09:828 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
09:01:09:828 3744 DetectCureTDL3: IrpHandler (0) addr: F76BDC30
09:01:09:828 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (2) addr: F76BDC30
09:01:09:828 3744 DetectCureTDL3: IrpHandler (3) addr: F76B7D9B
09:01:09:828 3744 DetectCureTDL3: IrpHandler (4) addr: F76B7D9B
09:01:09:828 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (9) addr: F76B8366
09:01:09:828 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (14) addr: F76B844D
09:01:09:828 3744 DetectCureTDL3: IrpHandler (15) addr: F76BBFC3
09:01:09:828 3744 DetectCureTDL3: IrpHandler (16) addr: F76B8366
09:01:09:828 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (22) addr: F76B9EF3
09:01:09:828 3744 DetectCureTDL3: IrpHandler (23) addr: F76BEA24
09:01:09:828 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:828 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:828 3744 TDL3_FileDetect: Processing driver: Disk
09:01:09:828 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:828 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:843 3744 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
09:01:09:843 3744
09:01:09:843 3744 DetectCureTDL3: DEVICE_OBJECT: 89D83030
09:01:09:843 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89D83030
09:01:09:843 3744 KLMD_ReadMem: Trying to ReadMemory 0x89D83030[0x38]
09:01:09:843 3744 DetectCureTDL3: DRIVER_OBJECT: 8A8DE960
09:01:09:843 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DE960[0xA8]
09:01:09:843 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1CA6EF0[0x18]
09:01:09:843 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
09:01:09:843 3744 DetectCureTDL3: IrpHandler (0) addr: F76BDC30
09:01:09:843 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (2) addr: F76BDC30
09:01:09:843 3744 DetectCureTDL3: IrpHandler (3) addr: F76B7D9B
09:01:09:843 3744 DetectCureTDL3: IrpHandler (4) addr: F76B7D9B
09:01:09:843 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (9) addr: F76B8366
09:01:09:843 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (14) addr: F76B844D
09:01:09:843 3744 DetectCureTDL3: IrpHandler (15) addr: F76BBFC3
09:01:09:843 3744 DetectCureTDL3: IrpHandler (16) addr: F76B8366
09:01:09:843 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (22) addr: F76B9EF3
09:01:09:843 3744 DetectCureTDL3: IrpHandler (23) addr: F76BEA24
09:01:09:843 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:843 3744 TDL3_FileDetect: Processing driver: Disk
09:01:09:843 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:843 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:843 3744 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
09:01:09:843 3744
09:01:09:843 3744 DetectCureTDL3: DEVICE_OBJECT: 89C2B478
09:01:09:843 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89C2B478
09:01:09:843 3744 DetectCureTDL3: DEVICE_OBJECT: 8A2AC198
09:01:09:843 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A2AC198
09:01:09:843 3744 DetectCureTDL3: DEVICE_OBJECT: 8A2B19D8
09:01:09:843 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A2B19D8
09:01:09:843 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A2B19D8[0x38]
09:01:09:843 3744 DetectCureTDL3: DRIVER_OBJECT: 89C1DF38
09:01:09:843 3744 KLMD_ReadMem: Trying to ReadMemory 0x89C1DF38[0xA8]
09:01:09:843 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1C9D418[0x1E]
09:01:09:843 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
09:01:09:843 3744 DetectCureTDL3: IrpHandler (0) addr: ADAA3218
09:01:09:843 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (2) addr: ADAA3218
09:01:09:843 3744 DetectCureTDL3: IrpHandler (3) addr: ADAA323C
09:01:09:843 3744 DetectCureTDL3: IrpHandler (4) addr: ADAA323C
09:01:09:843 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (9) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (14) addr: ADAA3180
09:01:09:843 3744 DetectCureTDL3: IrpHandler (15) addr: ADA9E9E6
09:01:09:843 3744 DetectCureTDL3: IrpHandler (16) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (22) addr: ADAA25F0
09:01:09:843 3744 DetectCureTDL3: IrpHandler (23) addr: ADAA0A6E
09:01:09:843 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:843 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:843 3744 KLMD_ReadMem: Trying to ReadMemory 0xADA9FF26[0x400]
09:01:09:843 3744 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
09:01:09:843 3744 TDL3_FileDetect: Processing driver: USBSTOR
09:01:09:843 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
09:01:09:843 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
09:01:09:859 3744 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
09:01:09:859 3744
09:01:09:859 3744 DetectCureTDL3: DEVICE_OBJECT: 89BFA030
09:01:09:859 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89BFA030
09:01:09:859 3744 DetectCureTDL3: DEVICE_OBJECT: 89C56ED0
09:01:09:859 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89C56ED0
09:01:09:859 3744 DetectCureTDL3: DEVICE_OBJECT: 89BEEEA0
09:01:09:859 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89BEEEA0
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0x89BEEEA0[0x38]
09:01:09:859 3744 DetectCureTDL3: DRIVER_OBJECT: 89C1DF38
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0x89C1DF38[0xA8]
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1C9D418[0x1E]
09:01:09:859 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
09:01:09:859 3744 DetectCureTDL3: IrpHandler (0) addr: ADAA3218
09:01:09:859 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (2) addr: ADAA3218
09:01:09:859 3744 DetectCureTDL3: IrpHandler (3) addr: ADAA323C
09:01:09:859 3744 DetectCureTDL3: IrpHandler (4) addr: ADAA323C
09:01:09:859 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (9) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (14) addr: ADAA3180
09:01:09:859 3744 DetectCureTDL3: IrpHandler (15) addr: ADA9E9E6
09:01:09:859 3744 DetectCureTDL3: IrpHandler (16) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (22) addr: ADAA25F0
09:01:09:859 3744 DetectCureTDL3: IrpHandler (23) addr: ADAA0A6E
09:01:09:859 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0xADA9FF26[0x400]
09:01:09:859 3744 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
09:01:09:859 3744 TDL3_FileDetect: Processing driver: USBSTOR
09:01:09:859 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
09:01:09:859 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
09:01:09:859 3744 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
09:01:09:859 3744
09:01:09:859 3744 DetectCureTDL3: DEVICE_OBJECT: 8A8DC4D8
09:01:09:859 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A8DC4D8
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DC4D8[0x38]
09:01:09:859 3744 DetectCureTDL3: DRIVER_OBJECT: 8A8DE960
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DE960[0xA8]
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1CA6EF0[0x18]
09:01:09:859 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
09:01:09:859 3744 DetectCureTDL3: IrpHandler (0) addr: F76BDC30
09:01:09:859 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (2) addr: F76BDC30
09:01:09:859 3744 DetectCureTDL3: IrpHandler (3) addr: F76B7D9B
09:01:09:859 3744 DetectCureTDL3: IrpHandler (4) addr: F76B7D9B
09:01:09:859 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (9) addr: F76B8366
09:01:09:859 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (14) addr: F76B844D
09:01:09:859 3744 DetectCureTDL3: IrpHandler (15) addr: F76BBFC3
09:01:09:859 3744 DetectCureTDL3: IrpHandler (16) addr: F76B8366
09:01:09:859 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (22) addr: F76B9EF3
09:01:09:859 3744 DetectCureTDL3: IrpHandler (23) addr: F76BEA24
09:01:09:859 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:859 3744 TDL3_FileDetect: Processing driver: Disk
09:01:09:859 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:859 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:859 3744 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
09:01:09:859 3744
09:01:09:859 3744 DetectCureTDL3: DEVICE_OBJECT: 8A8DC8A0
09:01:09:859 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A8DC8A0
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DC8A0[0x38]
09:01:09:859 3744 DetectCureTDL3: DRIVER_OBJECT: 8A8DE960
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DE960[0xA8]
09:01:09:859 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1CA6EF0[0x18]
09:01:09:859 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
09:01:09:859 3744 DetectCureTDL3: IrpHandler (0) addr: F76BDC30
09:01:09:859 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (2) addr: F76BDC30
09:01:09:859 3744 DetectCureTDL3: IrpHandler (3) addr: F76B7D9B
09:01:09:859 3744 DetectCureTDL3: IrpHandler (4) addr: F76B7D9B
09:01:09:859 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (9) addr: F76B8366
09:01:09:859 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:859 3744 DetectCureTDL3: IrpHandler (14) addr: F76B844D
09:01:09:859 3744 DetectCureTDL3: IrpHandler (15) addr: F76BBFC3
09:01:09:875 3744 DetectCureTDL3: IrpHandler (16) addr: F76B8366
09:01:09:875 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (22) addr: F76B9EF3
09:01:09:875 3744 DetectCureTDL3: IrpHandler (23) addr: F76BEA24
09:01:09:875 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:875 3744 TDL3_FileDetect: Processing driver: Disk
09:01:09:875 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:875 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:875 3744 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
09:01:09:875 3744
09:01:09:875 3744 DetectCureTDL3: DEVICE_OBJECT: 8A8DCC68
09:01:09:875 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A8DCC68
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DCC68[0x38]
09:01:09:875 3744 DetectCureTDL3: DRIVER_OBJECT: 8A8DE960
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DE960[0xA8]
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1CA6EF0[0x18]
09:01:09:875 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
09:01:09:875 3744 DetectCureTDL3: IrpHandler (0) addr: F76BDC30
09:01:09:875 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (2) addr: F76BDC30
09:01:09:875 3744 DetectCureTDL3: IrpHandler (3) addr: F76B7D9B
09:01:09:875 3744 DetectCureTDL3: IrpHandler (4) addr: F76B7D9B
09:01:09:875 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (9) addr: F76B8366
09:01:09:875 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (14) addr: F76B844D
09:01:09:875 3744 DetectCureTDL3: IrpHandler (15) addr: F76BBFC3
09:01:09:875 3744 DetectCureTDL3: IrpHandler (16) addr: F76B8366
09:01:09:875 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (22) addr: F76B9EF3
09:01:09:875 3744 DetectCureTDL3: IrpHandler (23) addr: F76BEA24
09:01:09:875 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:875 3744 TDL3_FileDetect: Processing driver: Disk
09:01:09:875 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:875 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:875 3744 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
09:01:09:875 3744
09:01:09:875 3744 DetectCureTDL3: DEVICE_OBJECT: 8A8DC030
09:01:09:875 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A8DC030
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DC030[0x38]
09:01:09:875 3744 DetectCureTDL3: DRIVER_OBJECT: 8A8DE960
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0x8A8DE960[0xA8]
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1CA6EF0[0x18]
09:01:09:875 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
09:01:09:875 3744 DetectCureTDL3: IrpHandler (0) addr: F76BDC30
09:01:09:875 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (2) addr: F76BDC30
09:01:09:875 3744 DetectCureTDL3: IrpHandler (3) addr: F76B7D9B
09:01:09:875 3744 DetectCureTDL3: IrpHandler (4) addr: F76B7D9B
09:01:09:875 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (9) addr: F76B8366
09:01:09:875 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (14) addr: F76B844D
09:01:09:875 3744 DetectCureTDL3: IrpHandler (15) addr: F76BBFC3
09:01:09:875 3744 DetectCureTDL3: IrpHandler (16) addr: F76B8366
09:01:09:875 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (22) addr: F76B9EF3
09:01:09:875 3744 DetectCureTDL3: IrpHandler (23) addr: F76BEA24
09:01:09:875 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:875 3744 TDL3_FileDetect: Processing driver: Disk
09:01:09:875 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:875 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
09:01:09:875 3744 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
09:01:09:875 3744
09:01:09:875 3744 DetectCureTDL3: DEVICE_OBJECT: 8B1EE030
09:01:09:875 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8B1EE030
09:01:09:875 3744 DetectCureTDL3: DEVICE_OBJECT: 8B23D030
09:01:09:875 3744 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8B23D030
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0x8B23D030[0x38]
09:01:09:875 3744 DetectCureTDL3: DRIVER_OBJECT: 8B1E4F38
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0x8B1E4F38[0xA8]
09:01:09:875 3744 KLMD_ReadMem: Trying to ReadMemory 0xE1CAE698[0x1C]
09:01:09:875 3744 DetectCureTDL3: DRIVER_OBJECT name: \Driver\iaStor, Driver Name: iaStor
09:01:09:875 3744 DetectCureTDL3: IrpHandler (0) addr: F7B2C0B8
09:01:09:875 3744 DetectCureTDL3: IrpHandler (1) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (2) addr: F7B2C0B8
09:01:09:875 3744 DetectCureTDL3: IrpHandler (3) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (4) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (5) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (6) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (7) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (8) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (9) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (10) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (11) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (12) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (13) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (14) addr: F7B2FEBC
09:01:09:875 3744 DetectCureTDL3: IrpHandler (15) addr: F7B30184
09:01:09:875 3744 DetectCureTDL3: IrpHandler (16) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (17) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (18) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (19) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (20) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (21) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (22) addr: F7B34B62
09:01:09:875 3744 DetectCureTDL3: IrpHandler (23) addr: F7B34CC2
09:01:09:875 3744 DetectCureTDL3: IrpHandler (24) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (25) addr: 804F9709
09:01:09:875 3744 DetectCureTDL3: IrpHandler (26) addr: 804F9709
09:01:09:875 3744 TDL3_FileDetect: Processing driver: iaStor
09:01:09:875 3744 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\iaStor.sys
09:01:09:875 3744 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\iaStor.sys
09:01:09:906 3744 TDL3_FileDetect: C:\WINDOWS\system32\drivers\iaStor.sys - Verdict: Clean
09:01:09:906 3744
09:01:09:906 3744 Completed
09:01:09:906 3744
09:01:09:906 3744 Results:
09:01:09:906 3744 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
09:01:09:906 3744 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
09:01:09:906 3744 File objects infected / cured / cured on reboot: 0 / 0 / 0
09:01:09:906 3744
09:01:09:906 3744 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
09:01:09:906 3744 UtilityDeinit: KLMD(ARK) unloaded successfully


#12 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:10:05 AM

Posted 15 February 2010 - 11:40 AM

Hi,


Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.



  1. Please download OTL from one of the following mirrors:
  2. Save it to your desktop.
  3. Double click on the icon on your desktop.
  4. Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    safebootminimal
    safebootnetwork
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  5. Push the Quick Scan button.
  6. Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#13 wingguy69

wingguy69
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:04:05 AM

Posted 15 February 2010 - 03:39 PM

Hi Tom,
A little light reading for you...

Malwarebytes' Anti-Malware 1.44
Database version: 3741
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

2/15/2010 2:04:55 PM
mbam-log-2010-02-15 (14-04-55).txt

Scan type: Quick Scan
Objects scanned: 138900
Time elapsed: 5 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Temp\F.tmp (Spyware.Zbot) -> Quarantined and deleted successfully.








OTL logfile created on: 2/15/2010 2:16:36 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\Maloy\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 3072 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 7.08 Gb Free Space | 14.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 19.52 Gb Total Space | 11.57 Gb Free Space | 59.26% Space Free | Partition Type: FAT32
Drive G: | 77.36 Gb Total Space | 0.96 Gb Free Space | 1.24% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Z: | 71.48 Gb Total Space | 48.71 Gb Free Space | 68.15% Space Free | Partition Type: NTFS

Computer Name: ENGINEERING2
Current User Name: Maloy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/02/15 14:13:49 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Maloy\Desktop\OTL.exe
PRC - [2009/08/05 07:34:49 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/06/22 13:21:39 | 000,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2009/06/03 14:46:38 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/06/03 14:46:38 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009/03/09 04:19:15 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/03/02 12:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008/07/10 17:28:06 | 040,999,448 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
PRC - [2008/07/10 02:49:44 | 000,098,840 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2007/12/13 18:10:56 | 001,688,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2007/12/13 18:10:56 | 000,447,784 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
PRC - [2007/06/13 05:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/12/19 13:14:42 | 000,008,192 | ---- | M] () -- C:\WINDOWS\SYSTEM32\srvany.exe
PRC - [2006/10/18 20:05:26 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2006/09/29 11:39:20 | 000,151,552 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2006/09/29 11:38:50 | 000,081,920 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2006/05/18 16:50:58 | 000,106,546 | ---- | M] () -- C:\pvsw\bin\w3dbsmgr.exe
PRC - [2006/03/09 15:35:20 | 000,049,152 | ---- | M] ( ) -- C:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe
PRC - [2006/03/09 12:23:56 | 000,040,960 | ---- | M] (Autodesk Inc) -- C:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
PRC - [2004/11/16 00:05:00 | 000,127,035 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
PRC - [2004/09/20 15:09:00 | 000,127,043 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SYSTEM32\nvsvc32.exe
PRC - [2004/08/04 05:00:00 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\TCPSVCS.EXE
PRC - [2004/03/04 09:30:48 | 000,311,296 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\SYSTEM32\LEXBCES.EXE
PRC - [2004/03/04 09:26:20 | 000,174,592 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\SYSTEM32\LEXPPS.EXE
PRC - [2003/09/17 10:43:36 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
PRC - [2000/06/26 07:44:20 | 000,053,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\MsPMSPSv.exe
PRC - [1999/12/13 09:01:00 | 000,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE


========== Modules (SafeList) ==========

MOD - [2010/02/15 14:13:49 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Maloy\Desktop\OTL.exe
MOD - [2006/08/25 09:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 05:00:00 | 001,852,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\AppPatch\acgenral.dll
MOD - [2004/08/04 05:00:00 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\msacm32.dll
MOD - [2004/08/04 05:00:00 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\shimeng.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/08/05 07:34:49 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009/06/22 13:21:39 | 000,133,104 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c9f36ec79a4c60) Google Update Service (gupdate1c9f36ec79a4c60)
SRV - [2009/06/03 14:46:38 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)
SRV - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009/03/09 04:19:15 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2008/07/10 17:28:06 | 040,999,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS)
SRV - [2008/07/10 17:28:06 | 000,369,688 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE -- (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS)
SRV - [2008/07/10 17:28:04 | 000,047,128 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE -- (MSSQLServerADHelper100)
SRV - [2008/07/10 02:49:44 | 000,098,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008/07/10 02:49:34 | 000,258,072 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)
SRV - [2007/12/13 18:10:56 | 000,447,784 | ---- | M] (Nero AG) [On_Demand | Running] -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2007/12/03 13:21:24 | 000,869,672 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3)
SRV - [2007/07/03 15:09:40 | 000,072,704 | ---- | M] (Autodesk) [On_Demand | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2007/03/07 14:47:46 | 000,076,848 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2006/12/19 13:14:42 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\WINDOWS\SYSTEM32\srvany.exe -- (Pervasive.SQL Workgroup Engine)
SRV - [2006/09/29 11:38:50 | 000,081,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2006/03/09 15:35:20 | 000,049,152 | ---- | M] ( ) [Auto | Running] -- C:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe -- (Autodesk EDM Server)
SRV - [2006/03/09 12:23:56 | 000,040,960 | ---- | M] (Autodesk Inc) [Auto | Running] -- C:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe -- (Autodesk Data Management Job Dispatch)
SRV - [2005/08/02 15:18:49 | 000,086,016 | ---- | M] (CACE Technologies) [Disabled | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2005/05/03 23:04:28 | 009,150,464 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlservr.exe -- (MSSQL$AUTODESKVAULT)
SRV - [2005/05/03 20:42:56 | 000,323,584 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlagent.EXE -- (SQLAgent$AUTODESKVAULT)
SRV - [2005/02/24 20:08:27 | 000,068,096 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2004/10/22 02:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004/09/20 15:09:00 | 000,127,043 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\SYSTEM32\nvsvc32.exe -- (NVSvc)
SRV - [2004/08/04 05:00:00 | 000,086,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2004/08/04 05:00:00 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\SYSTEM32\TCPSVCS.EXE -- (SimpTcp)
SRV - [2004/03/04 09:30:48 | 000,311,296 | ---- | M] (Lexmark International, Inc.) [Auto | Running] -- C:\WINDOWS\SYSTEM32\LEXBCES.EXE -- (LexBceS)
SRV - [2003/10/13 16:24:14 | 000,061,440 | ---- | M] (Adobe Sytems) [Disabled | Stopped] -- C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe -- (AdobeVersionCue)
SRV - [2000/06/26 07:44:20 | 000,053,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\SYSTEM32\MsPMSPSv.exe -- (WMDM PMSP Service)
SRV - [1999/12/13 09:01:00 | 000,044,032 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE -- (Creative Service for CDROM Access)
SRV - [1998/06/05 23:00:00 | 000,034,036 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\VARPC.EXE -- (Visual Studio Analyzer RPC bridge)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/12 09:43:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/07 10:41:33 | 000,000,000 | ---D | M]

[2009/11/24 16:14:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Mozilla\Extensions
[2010/02/12 09:37:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Mozilla\Firefox\Profiles\frc1vqlo.default\extensions
[2009/11/24 16:13:09 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/02/09 15:17:31 | 000,000,022 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Update Scheduler for Proteus Demonstration 7.lnk = C:\Program Files\Labcenter Electronics\Proteus 7 Demonstration\BIN\UDSCHED.EXE ()
O4 - Startup: C:\Documents and Settings\Maloy\Start Menu\Programs\Startup\SpywareBlaster.lnk = C:\Program Files\SpywareBlaster\spywareblaster.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKLM\..Trusted Domains: 64 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 338 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\lowsec.exe) - C:\WINDOWS\SYSTEM32\lowsec.exe ()
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Maloy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Maloy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/29 11:19:31 | 000,000,136 | ---- | M] () - C:\Autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2004/08/11 17:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.OLD -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2009/01/16 08:24:07 | 000,000,000 | ---D | M]
NetSvcs: Iprip - C:\WINDOWS\SYSTEM32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Reg Error: Value error.
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Reg Error: Value error.
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: nm - C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys (Microsoft Corporation)
SafeBootNet: nm.sys - C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys (Microsoft Corporation)
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Reg Error: Value error.
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Reg Error: Value error.
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (57424288273137664)

========== Files/Folders - Created Within 14 Days ==========

[2010/02/15 14:13:48 | 000,549,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Maloy\Desktop\OTL.exe
[2010/02/15 14:05:56 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Maloy\Recent
[2010/02/15 13:47:43 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/15 13:47:33 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/15 13:44:59 | 005,115,824 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Maloy\Desktop\mbam-setup.exe
[2010/02/15 13:39:57 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/02/15 08:59:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Maloy\Desktop\tdsskiller
[2010/02/10 13:09:45 | 000,000,000 | ---D | C] -- C:\schrauber8560s
[2010/02/09 14:58:02 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/02/09 14:55:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/02/09 14:55:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/02/09 14:55:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/02/09 14:55:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/02/09 14:55:25 | 000,000,000 | ---D | C] -- C:\schrauber
[2010/02/09 14:54:32 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/02/07 20:28:53 | 000,000,000 | -HSD | C] -- C:\WINDOWS\System32\winsys
[2010/02/04 14:34:32 | 000,175,880 | ---- | C] (Kaspersky Lab) -- C:\Documents and Settings\Maloy\Desktop\TDSSKiller.exe
[2010/01/28 11:15:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/12/08 08:36:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2009/11/03 08:08:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Temp
[2009/06/24 07:05:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/06/22 13:22:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/07/15 15:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2008/07/15 15:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
[2007/07/03 15:18:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\assembly
[2006/10/10 11:10:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\ApplicationHistory
[2005/10/21 13:17:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\AdobeUM
[2005/10/21 12:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2005/10/21 12:22:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2005/02/10 16:42:56 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2004/12/21 22:41:12 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2004/12/21 22:41:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[1980/01/01 00:00:00 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Maloy\*.tmp files -> C:\Documents and Settings\Maloy\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/02/15 14:15:04 | 019,136,512 | -H-- | M] () -- C:\Documents and Settings\Maloy\NTUSER.DAT
[2010/02/15 14:13:49 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Maloy\Desktop\OTL.exe
[2010/02/15 14:07:36 | 000,007,275 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/02/15 14:07:26 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/15 14:07:16 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/02/15 14:07:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/02/15 14:06:01 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Maloy\NTUSER.INI
[2010/02/15 14:05:57 | 025,679,510 | -H-- | M] () -- C:\Documents and Settings\Maloy\Local Settings\Application Data\IconCache.db
[2010/02/15 13:47:46 | 000,000,711 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/15 13:45:02 | 005,115,824 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Maloy\Desktop\mbam-setup.exe
[2010/02/15 13:24:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/15 08:55:50 | 000,152,714 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\tdsskiller.zip
[2010/02/12 15:17:35 | 000,240,128 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\Time.xls
[2010/02/10 15:33:09 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/02/10 15:27:01 | 000,137,728 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\Tims Scale application data.xls
[2010/02/10 13:22:48 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/02/09 15:17:31 | 000,000,022 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2010/02/09 14:58:12 | 000,000,281 | RHS- | M] () -- C:\BOOT.INI
[2010/02/09 14:48:06 | 003,852,756 | R--- | M] () -- C:\Documents and Settings\Maloy\Desktop\schrauber.exe
[2010/02/08 12:06:14 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe
[2010/02/05 14:48:48 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010/02/05 13:44:15 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/02/04 14:34:32 | 000,175,880 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\Maloy\Desktop\TDSSKiller.exe
[2010/02/04 08:39:53 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2010/02/02 15:00:54 | 000,110,798 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\ABI_BB_vs_Rugged_TCO.pdf
[2010/02/02 14:55:45 | 002,688,737 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\bwmanual2009.pdf
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Maloy\*.tmp files -> C:\Documents and Settings\Maloy\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/15 13:47:46 | 000,000,711 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/15 08:58:28 | 000,152,714 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\tdsskiller.zip
[2010/02/09 14:58:11 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/02/09 14:58:05 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/02/09 14:55:49 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/02/09 14:55:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/02/09 14:55:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/02/09 14:55:49 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/02/09 14:55:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/02/09 14:48:06 | 003,852,756 | R--- | C] () -- C:\Documents and Settings\Maloy\Desktop\schrauber.exe
[2010/02/08 12:16:26 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe
[2010/02/04 08:39:53 | 000,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2010/02/04 08:39:53 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2010/02/02 15:00:54 | 000,110,798 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\ABI_BB_vs_Rugged_TCO.pdf
[2010/02/02 14:55:45 | 002,688,737 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\bwmanual2009.pdf
[2009/03/23 12:44:22 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\MPMapTrace.dll
[2009/03/23 12:09:28 | 000,364,544 | ---- | C] () -- C:\WINDOWS\System32\mpPathan.dll
[2009/03/17 08:31:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2008/12/01 17:17:39 | 000,000,067 | ---- | C] () -- C:\WINDOWS\Apollo DVD Copy.INI
[2008/10/02 07:51:30 | 000,000,018 | -HS- | C] () -- C:\WINDOWS\WINPROD.DLL
[2008/07/09 07:27:50 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/13 15:41:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\uwzfqas.sys
[2008/04/17 13:36:40 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/03/18 16:18:42 | 000,000,180 | ---- | C] () -- C:\WINDOWS\ImgTool.INI
[2007/10/11 10:23:42 | 000,000,385 | ---- | C] () -- C:\Program Files\DeaInstall.log
[2007/10/09 07:46:22 | 000,000,184 | ---- | C] () -- C:\WINDOWS\bti.ini
[2007/10/09 07:43:41 | 000,000,190 | ---- | C] () -- C:\Program Files\Common Files\psasetup.log
[2007/10/09 07:43:29 | 000,043,760 | ---- | C] () -- C:\WINDOWS\System32\nwlocale.dll
[2007/09/17 10:27:42 | 000,000,075 | ---- | C] () -- C:\WINDOWS\hdkctnts.ini
[2007/09/17 10:26:50 | 000,000,165 | ---- | C] () -- C:\WINDOWS\HOFFMAN.Ini
[2007/08/09 11:08:04 | 000,008,784 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/07/03 15:18:27 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\fusioncache.dat
[2006/12/13 15:03:14 | 000,074,240 | ---- | C] () -- C:\WINDOWS\System32\zlibwapi.dll
[2006/11/16 14:34:53 | 000,000,032 | ---- | C] () -- C:\WINDOWS\concentr.ini
[2006/11/16 14:34:31 | 000,000,058 | ---- | C] () -- C:\WINDOWS\webica.ini
[2006/10/22 12:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 12:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/10/10 16:07:36 | 000,000,126 | ---- | C] () -- C:\WINDOWS\CTWave32.ini
[2006/07/11 11:13:45 | 000,000,041 | ---- | C] () -- C:\WINDOWS\System32\aefdfed1_s.dll
[2005/11/11 15:24:12 | 000,000,114 | ---- | C] () -- C:\WINDOWS\SRCEDIT.INI
[2005/11/08 14:52:24 | 000,000,137 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2005/09/02 09:37:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\csmain.INI
[2005/09/02 09:37:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\esmain.INI
[2005/09/02 09:36:37 | 000,003,422 | ---- | C] () -- C:\WINDOWS\DS300.INI
[2005/09/01 10:29:12 | 000,159,744 | ---- | C] () -- C:\WINDOWS\_isusr32.dll
[2005/09/01 10:29:09 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\ush2.dll
[2005/09/01 10:29:09 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\_isusr2k.dll
[2005/08/02 15:24:01 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2005/03/19 16:21:47 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\Maloy\Application Data\PFP120JPR.{PB
[2005/03/19 16:21:47 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\Maloy\Application Data\PFP120JCM.{PB
[2005/02/24 13:35:29 | 000,002,452 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/02/24 13:35:29 | 000,000,185 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2005/02/24 13:35:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2005/02/23 10:00:51 | 000,000,832 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/02/23 09:08:27 | 000,006,996 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2005/01/19 15:59:28 | 000,016,896 | ---- | C] () -- C:\Documents and Settings\Maloy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/19 15:41:02 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Maloy\Local Settings\Application Data\fusioncache.dat
[2005/01/19 15:34:38 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2004/12/21 23:07:47 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/12/21 23:02:48 | 000,000,331 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/12/21 22:58:53 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2004/12/21 22:58:45 | 000,003,278 | ---- | C] () -- C:\WINDOWS\System32\LudaP17.ini
[2004/12/21 22:58:45 | 000,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2004/12/21 22:58:40 | 000,000,072 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2004/12/21 22:41:42 | 000,000,517 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/09/15 22:03:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/11 17:25:56 | 000,000,890 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/05/12 19:56:36 | 000,634,880 | ---- | C] () -- C:\WINDOWS\System32\pemicro_serialcm2.dll
[2004/02/10 13:08:00 | 000,000,373 | ---- | C] () -- C:\WINDOWS\System32\dlbccoin.ini
[2002/11/13 13:40:22 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbcvs.dll
[2002/02/19 18:48:16 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\lxaxlcnp.dll
[2000/09/18 16:50:28 | 000,202,752 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2000/08/03 13:25:12 | 000,023,296 | ---- | C] () -- C:\WINDOWS\System32\pedrv.sys
[2000/08/03 13:25:12 | 000,023,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\pedrv.sys
[1999/01/22 12:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/10/02 09:20:46 | 000,005,200 | ---- | C] () -- C:\WINDOWS\System32\drivers\vichw11.sys
[1998/06/09 23:00:00 | 000,015,120 | ---- | C] () -- C:\WINDOWS\System32\REPUTIL.DLL
[1998/05/17 23:00:00 | 000,014,017 | ---- | C] () -- C:\WINDOWS\JAUTOEXP.INI
[1998/04/24 00:00:00 | 000,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI
[1998/01/11 19:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL
[1996/05/29 16:20:04 | 000,035,072 | ---- | C] () -- C:\WINDOWS\System32\SENDKEY.DLL
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\GIVEIO.SYS
[1980/01/01 00:00:00 | 000,060,928 | ---- | C] () -- C:\WINDOWS\System32\P17.dll
[1980/01/01 00:00:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\P17CPI.dll

========== LOP Check ==========

[2007/07/03 15:17:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2010/01/08 11:49:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/02/21 15:26:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2005/04/13 13:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lic
[2008/06/23 07:13:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2006/01/23 13:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MCAA81.tmp
[2006/01/23 13:10:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MCAA9C.tmp
[2006/01/23 13:12:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MCAAAE.tmp
[2010/01/28 15:39:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCDr
[2009/07/14 09:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Processor Expert
[2005/02/24 13:49:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBT
[2010/01/28 15:39:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/02/15 14:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/06/16 15:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/12/31 12:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YNAB
[2007/07/05 14:25:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Autodesk
[2009/10/05 08:46:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Blitware
[2010/01/01 17:46:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1
[2008/11/25 09:10:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Ethereal
[2006/11/16 14:38:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\ICAClient
[2005/01/07 08:24:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Leadertech
[2009/02/12 15:15:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Learn2.com
[2010/01/29 11:59:20 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Maloy\Application Data\Microchip
[2005/05/03 14:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Musicmatch
[2009/01/05 10:12:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Opera
[2009/08/20 10:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Processor Expert
[2009/09/24 08:11:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Safrad
[2007/12/05 12:34:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Viewpoint

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2004/08/04 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2004/08/03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\I386\AGP440.SYS
[2004/08/03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\SYSTEM32\DLLCACHE\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2004/08/04 05:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\I386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\SYSTEM32\DLLCACHE\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0013\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2004/08/04 05:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\I386\EVENTLOG.DLL
[2004/08/04 05:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004/08/04 05:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\SYSTEM32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2006/09/29 12:16:20 | 000,495,896 | ---- | M] (Intel Corporation) MD5=C212BE4F068A02E54EB0CF6F5B23569B -- C:\Program Files\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys
[2006/09/29 10:59:58 | 000,250,368 | ---- | M] (Intel Corporation) MD5=E9F704CA833BD24BFAA3B4A59707633A -- C:\Program Files\Intel\Intel Matrix Storage Manager\Driver\iaStor.sys
[2010/02/02 12:35:30 | 000,250,368 | ---- | M] (Intel Corporation) MD5=E9F704CA833BD24BFAA3B4A59707633A -- C:\WINDOWS\SYSTEM32\DRIVERS\iaStor.sys
[2004/03/23 12:13:58 | 000,467,200 | ---- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 -- C:\DRIVERS\STORAGE\SATA\ONBOARD\IASTOR.SYS
[2004/03/23 12:13:58 | 000,467,200 | ---- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 -- C:\I386\iaStor.sys
[2004/03/23 12:13:58 | 000,467,200 | ---- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0016\DriverFiles\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2009/02/06 12:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 12:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 05:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\I386\NETLOGON.DLL
[2004/08/04 05:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004/08/04 05:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\SYSTEM32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 05:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\I386\SCECLI.DLL
[2004/08/04 05:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2004/08/04 05:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\SYSTEM32\scecli.dll

< %systemroot%\*. /mp /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BF268CC
< End of report >







OTL Extras logfile created on: 2/15/2010 2:16:36 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\Maloy\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 3072 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 7.08 Gb Free Space | 14.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 19.52 Gb Total Space | 11.57 Gb Free Space | 59.26% Space Free | Partition Type: FAT32
Drive G: | 77.36 Gb Total Space | 0.96 Gb Free Space | 1.24% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Z: | 71.48 Gb Total Space | 48.71 Gb Free Space | 68.15% Space Free | Partition Type: NTFS

Computer Name: ENGINEERING2
Current User Name: Maloy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Opera\opera.exe" File not found
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with Paint Shop Pro Studio] -- "C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\\Paint Shop Pro Studio.exe" "/Browse" "%L" (Jasc Software, Inc.)
Directory [Command] -- cmd.exe /k cd %1 (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3587:TCP" = 3587:TCP:*:Disabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Disabled:Peer Name Resolution Protocol (PNRP)
"10243:TCP" = 10243:TCP:LocalSubNet:Disabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Disabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Disabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Disabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Disabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Disabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Freescale\CodeWarrior for ColdFire V7.1\bin\IDE.exe" = C:\Program Files\Freescale\CodeWarrior for ColdFire V7.1\bin\IDE.exe:*:Enabled:Integrated Development Environment -- (Freescale Semiconductor, Inc.)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer -- (RealNetworks, Inc.)
"G:\BeltWay\bwserver.exe" = G:\BeltWay\bwserver.exe:*:Disabled:bwserver -- ()
"C:\Documents and Settings\Maloy\Desktop\BW Server 2.02\BW Server 2.02\winxp\bwserver.exe" = C:\Documents and Settings\Maloy\Desktop\BW Server 2.02\BW Server 2.02\winxp\bwserver.exe:*:Disabled:bwserver -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Disc 2
"{01958032-9877-4118-B87F-9EFA74B3F15F}" =
"{03CE1BCB-03F5-4C6A-B37E-69799AA3C544}" = SpyHunter
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{051B4A23-7503-4B9B-88BC-C1FB5CA0C591}" = Dynamic C Version 9.50
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{10046F0C-A6C1-4CEE-A212-3198241FD567}" = Proteus Demonstration
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{13C4E8F0-B747-4C7C-9090-884832F9F90A}" = Proteus Professional
"{17B66E83-1BC9-11D5-A54A-0090278A1BB8}" = Microsoft FrontPage Client - English
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1D9151C2-FBDB-48B9-B3BF-69A8274820D6}" = Autodesk Data Management Server 5
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{29D3773E-54F4-23C2-D523-236A4453B845}_is1" = FileAlyzer 2
"{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3A461BE1-48C0-4C23-8609-685360DC84E0}" = Eudora
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3E9C2FED-BBEE-4461-BA56-A082EF1D8805}" = MPLAB C for PIC24 MCUs - Evaluation
"{416DFEDD-9F1B-4EFC-AF70-FCA891AE0251}" =
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}" = Jasc Paint Shop Photo Album 5
"{435E969D-867E-4364-8E74-3DC8A69C5BDB}" =
"{44564479-0533-4542-8D5A-4937EA4BFBAC}" = MPLAB Tools v8.30
"{44DC86A0-248D-11D6-9BAF-0090271AF8A4}" =
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}" =
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{5757AE1A-1DB4-4898-9806-09F77FBD5E57}" = MSDN Library for Visual Studio .NET 2003
"{5783F2D7-0103-0409-0000-0060B0CE6BBA}" = Mechanical Desktop 6
"{5783F2D7-0303-0409-0002-0060B0CE6BBA}" = Mechanical Desktop 2005
"{5783F2D7-5003-0409-0002-0060B0CE6BBA}" = Autodesk Mechanical Desktop 2007
"{57EC955B-E2D2-A726-1E32-C343757F2021}" = YNAB 3
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}" =
"{5FCCD531-1B38-4A94-924C-127F722F1033}" = Nero 8 Trial
"{625BD732-ACDF-4552-BF22-98EBB413B6F3}" = McAfee Shredder
"{66AD7DB8-8C6A-454F-9DA3-330E8CA0BF95}" = Dynamic C Version 10.21
"{67AEFC4C-69E4-11D7-85F4-00E018013273}" =
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.3
"{68619F14-5C1E-11D5-A3B4-0050BADA2C1B}" = ABC Config Tool
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6E179C77-7335-458D-9537-4F4EAC0181ED}" = Photo Click
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7148F0A8-6813-11D6-A77B-00B0D0142060}" = Java 2 Runtime Environment, SE v1.4.2_06
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7201B853-5833-11D6-A285-00A0CC51B2FE}" =
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}" = Jasc Paint Shop Pro Studio, Dell Editon
"{78D944D7-A97B-4004-AB0A-B5AD06839940}" = My Way Search Assistant
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7A900EAB-DA37-4554-AF19-9C337476D05D}" =
"{7CFAEC66-BA0E-4076-AAA5-2BE29153E6DF}" = Microsoft XML Parser
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F4DD591-1100-0409-0000-7107D70F3DB4}" = Autodesk Inventor 11
"{7F4DD591-9000-0409-0000-7107D70F3DB4}" = Autodesk Inventor 9
"{80E250A2-2633-4EE4-A14A-987149F8F895}" = X-CTU
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CF5C176-FE64-416D-B116-7660CCDC6812}" = MPLAB Tools v8.20a
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch Jukebox
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91A4AD99-69CE-4745-97B7-0E0DFBECFDE5}" =
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{96870DA0-924E-4BD7-8134-4C340A31C9AE}" = .NET Compact Framework-based Serial Communications Sample
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
"{9ED71778-0E56-4760-9FC6-2C29D75100C5}" = Radioshack USB-to-Serial cable
"{A1185190-514F-11D6-A285-00A0CC51B2FE}" =
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}" = Dell Media Experience
"{AC157741-3285-4D6A-B934-9174587A3493}" =
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-1033-0000-7760-000000000001}" =
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{ADDA68BC-CDA9-11D7-925B-00D0B792205A}" = Dynamic C Version 8.10
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B023185F-F1EF-4F97-B0BD-AE6D802226D1}" = NVIDIA WDM Drivers
"{B297AFDF-8483-4D90-9694-C978347C8736}" = DacEasy Version 15
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{BC944C49-FD30-42AD-A11D-03E3C89F2604}" = CodeWarrior Development Studio for ColdFire Architectures v7.1
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C175CA84-4BF1-4232-AD79-43BF732F4FAE}" = Dynamic C Version 9.10
"{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}" =
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CDE4CC8B-134B-421E-943C-90799E56F664}" = Dell Media Experience Update
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB481CC-F57C-4397-81A0-DADD22257047}" = Sound Blaster Live! 24-bit
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D2C1BEFD-4CA8-48D0-925E-7DD1FB5F9C98}" = Proteus Professional
"{D3E4251D-8364-4698-B0E0-A7C799384403}" =
"{D4D24FE5-FAB3-4FE2-AFFC-623955F4DF3A}" = Visual Studio.NET Baseline - English
"{D52ECEBC-9B20-41A5-81C4-A62DE2367419}" = Adobe Creative Suite
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D8C0330E-C815-4C6F-9BFD-0FD570155790}" = Pervasive.SQL 9 SP2 Workgroup for Windows (9.5)
"{D9D937B0-E842-4130-9588-B948E876904A}" = Microsoft SQL Server 2008 Native Client
"{DD622B1D-A78E-3FE8-9C8C-246F5764B0D0}" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}" =
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (AUTODESKVAULT)
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E4649873-53F6-4578-83A8-5695B44E4B7B}" = Dynamic C Version 10.05
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E89D78B8-28F7-412F-8B26-C684739CBBDC}" = Palm Desktop
"{EA82FF50-E258-4DFE-839B-8F26A01A34A7}" = Microsoft Tool Web Package:WntIpcfg.exe
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" =
"{F0620409-8B20-48A0-ACA0-09D5FC90D316}" = Visual Basic .NET Standard 2003 - English
"{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F3CA9611-CD42-4562-ADAB-A554CF8E17F1}" = Microsoft WSE 2.0 SP3 Runtime
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F865C2FE-25E7-11D6-9BAF-0090271AF8A4}" =
"{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}" =
"{FC06516F-3793-4A46-8CDD-CB84586A2794}" = Dynamic C Version 9.52
"{FC0DD8AE-3DC0-11D7-AB2D-0090271A23A2}" =
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF15534E-277C-45F3-8EA5-F97BDB9F41C8}" = Flowcode V3
"23C892DBF52DDAF3C9BD2BB6E9805E79FCD09A67" = Windows Driver Package - FTDI CDM Driver Package (05/19/2006 2.00.00)
"A2E63BDAC649E514867CB43CE0B4F9DB111206C2" = Windows Driver Package - FTDI CDM Driver Package (05/19/2006 2.00.00)
"activescan 2.0" = Panda ActiveScan 2.0
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"AddressBook" =
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Apollo DVD Copy_is1" = Apollo DVD Copy 4.5.2
"Application Maestro Modules v1.03" = Application Maestro Modules v1.03
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"Autodesk Learning Assistance" = Autodesk Learning Assistance
"AvantGo Client" =
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Branding" =
"CCleaner" = CCleaner (remove only)
"ColdFire Init" = ColdFire Init
"com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1" = YNAB 3
"Connection Manager" =
"Creative MediaSource" =
"Creative MediaSource Detector" =
"Creative MediaSource Player Skin Pack" =
"Creative MiniDisc Center" =
"Creative Restore Defaults" =
"Creative WaveStudio" =
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Photo Printer 720" = Dell Photo Printer 720
"DEVCTRL2" =
"Diagnostics3" =
"DirectAnimation" =
"DirectDrawEx" =
"DirectSOFT32 - Programming" = DirectSOFT32 - Programming
"dlatray.exe" =
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"EAX" =
"ELECTRA_is1" = ELECTRA 1.5.5
"EQUALIZER" =
"ERUNT_is1" = ERUNT 1.1j
"Ethereal" = Ethereal 0.10.13
"Fontcore" =
"HijackThis" = HijackThis 2.0.2
"HTPE3" = HyperTerminal Private Edition v6.3
"HyperTerminal Private Edition" =
"ICW" =
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"ie8" = Windows Internet Explorer 8
"IEData" =
"InstallShield Uninstall Information" =
"InstallShield_{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"InstallShield_{44564479-0533-4542-8D5A-4937EA4BFBAC}" = MPLAB Tools v8.30
"InstallShield_{8CF5C176-FE64-416D-B116-7660CCDC6812}" = MPLAB Tools v8.20a
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"Jasc Paint Shop Pro Studio GDI+ Patch" = Jasc Paint Shop Pro Studio GDI+ Patch
"Jasc Paint Shop Pro Studio.01 , Dell Edition Patch" = Jasc Paint Shop Pro Studio.01 , Dell Edition Patch
"Java Web Start" = Java Web Start
"Karen's Calculator" = Karen's Calculator
"Macro Express 3" = Macro Express 3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MDTAMA" = Mechanical Desktop 6 Migration Assistance
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Developer Network - Visual Studio 6.0a" = MSDN Library - Visual Studio 6.0a
"Microsoft Interactive Training" =
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual Basic 2008 Express Edition with SP1 - ENU" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"Mobile Application Link" =
"MobileOptionPack" =
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"MsJavaVM" =
"NETCommOCX" = NETCommOCX
"NetMeeting" =
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OutlookExpress" =
"PC Pitstop Optimize_is1" = PC Pitstop Optimize 1.5
"PCHealth" =
"Pervasive System Analyzer" = Pervasive System Analyzer
"Punch! Home Design - Platinum" = Punch! Home Design - Platinum
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"RealVNC_is1" = VNC Free Edition 4.1.3
"RecordNow.exe" =
"SchedulingAgent" =
"SFBM" =
"SGTRAY.EXE" =
"SHARP AR-351/355/451/455 Series PCL Printer Driver" = SHARP AR-351/355/451/455 Series PCL Printer Driver
"Shockwave" =
"Sound Blaster Live! 24-bit" =
"Sound Blaster Live! 24-bit Windows Drivers" =
"SPEAKER" =
"SpywareBlaster_is1" = SpywareBlaster 4.2
"ST6UNST #1" = Lawn Configuration Program
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SURMIXER" =
"SystemRequirementsLab" = System Requirements Lab
"Utility Software" = Utility Software
"Visual Basic .NET Standard 2003 - English" = Microsoft Visual Basic .NET Standard 2003 - English
"Visual Studio 6.0 Enterprise Edition" = Microsoft Visual Studio 6.0 Enterprise Edition
"WebPost" = Microsoft Web Publishing Wizard 1.53
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows Scheduler_is1" = System Scheduler 3.73
"WinHex" = WinHex
"WinPcapInst" = WinPcap 3.1
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YNAB_Pro_is1" = YNAB Pro version 1.4.2.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/13/2010 1:32:47 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:33:47 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:34:47 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:35:47 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:36:48 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:37:48 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:38:48 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:39:48 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:40:49 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

Error - 2/13/2010 1:41:49 PM | Computer Name = ENGINEERING2 | Source = Autodesk Data Management Job Dispatch | ID = 0
Description = Authentication failed for user: JobUser: 108

[ System Events ]
Error - 2/15/2010 10:33:41 AM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3

Error - 2/15/2010 10:33:41 AM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The Upload Manager service failed to start due to the following error:
%%1079

Error - 2/15/2010 10:33:41 AM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 2/15/2010 3:38:53 PM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3

Error - 2/15/2010 3:38:53 PM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The Upload Manager service failed to start due to the following error:
%%1079

Error - 2/15/2010 3:38:53 PM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 2/15/2010 4:07:49 PM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3

Error - 2/15/2010 4:07:50 PM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The Upload Manager service failed to start due to the following error:
%%1079

Error - 2/15/2010 4:07:50 PM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 2/15/2010 4:08:05 PM | Computer Name = ENGINEERING2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
hpn
i2omp
ini910u
IntelIde
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde


< End of report >


#14 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:10:05 AM

Posted 16 February 2010 - 02:37 PM

Hi,

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    CODE
    :OTL
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\lowsec.exe) - C:\WINDOWS\SYSTEM32\lowsec.exe ()
    O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
    [2010/02/07 20:28:53 | 000,000,000 | -HSD | C] -- C:\WINDOWS\System32\winsys
  • Then click the Run Fix button at the top
  • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
  • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
================================Follow up scan=================================
  • Double click on OTL to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open one notepad window. OTL.Txt a This is saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#15 wingguy69

wingguy69
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:04:05 AM

Posted 16 February 2010 - 03:13 PM

Hi Tom,

========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\WINDOWS\system32\lowsec.exe deleted successfully.
File move failed. C:\WINDOWS\System32\lowsec.exe scheduled to be moved on reboot.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy\ deleted successfully.
Folder move failed. C:\WINDOWS\System32\winsys scheduled to be moved on reboot.

OTL by OldTimer - Version 3.1.28.0 log created on 02162010_135513

Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\System32\lowsec.exe scheduled to be moved on reboot.
Folder move failed. C:\WINDOWS\System32\winsys scheduled to be moved on reboot.

Registry entries deleted on Reboot...





OTL logfile created on: 2/16/2010 2:04:59 PM - Run 2
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\Maloy\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 79.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 3072 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 7.05 Gb Free Space | 14.43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 19.52 Gb Total Space | 11.57 Gb Free Space | 59.26% Space Free | Partition Type: FAT32
Drive G: | 77.36 Gb Total Space | 0.96 Gb Free Space | 1.24% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ENGINEERING2
Current User Name: Maloy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Maloy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Nero AG)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\srvany.exe ()
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\pvsw\bin\w3dbsmgr.exe ()
PRC - C:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe ( )
PRC - C:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe (Autodesk Inc)
PRC - C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\WINDOWS\SYSTEM32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SYSTEM32\TCPSVCS.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\SYSTEM32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\SYSTEM32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Maloy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\AppPatch\acgenral.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\msacm32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\shimeng.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (gupdate1c9f36ec79a4c60) Google Update Service (gupdate1c9f36ec79a4c60) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) -- C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS) -- C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE (Microsoft Corporation)
SRV - (MSSQLServerADHelper100) -- C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE (Microsoft Corporation)
SRV - (SQLWriter) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (NMIndexingService) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Nero AG)
SRV - (Nero BackItUp Scheduler 3) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Nero AG)
SRV - (Autodesk Licensing Service) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (DSBrokerService) -- C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (Pervasive.SQL Workgroup Engine) -- C:\WINDOWS\SYSTEM32\srvany.exe ()
SRV - (IAANTMON) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Autodesk EDM Server) -- C:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe ( )
SRV - (Autodesk Data Management Job Dispatch) -- C:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe (Autodesk Inc)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (MSSQL$AUTODESKVAULT) -- C:\Program Files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$AUTODESKVAULT) -- C:\Program Files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlagent.EXE (Microsoft Corporation)
SRV - (Adobe LM Service) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ()
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (NVSvc) -- C:\WINDOWS\SYSTEM32\nvsvc32.exe (NVIDIA Corporation)
SRV - (p2pgasvc) -- C:\WINDOWS\SYSTEM32\p2pgasvc.dll (Microsoft Corporation)
SRV - (SimpTcp) -- C:\WINDOWS\SYSTEM32\TCPSVCS.EXE (Microsoft Corporation)
SRV - (LexBceS) -- C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (AdobeVersionCue) -- C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe (Adobe Sytems)
SRV - (WMDM PMSP Service) -- C:\WINDOWS\SYSTEM32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (Creative Service for CDROM Access) -- C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE (Creative Technology Ltd)
SRV - (Visual Studio Analyzer RPC bridge) -- C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\VARPC.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (iaStor) -- C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avgntflt) -- C:\WINDOWS\SYSTEM32\DRIVERS\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (Pcouffin) -- C:\WINDOWS\SYSTEM32\DRIVERS\Pcouffin.sys (VSO Software)
DRV - (RsFx0102) -- C:\WINDOWS\SYSTEM32\DRIVERS\RsFx0102.sys (Microsoft Corporation)
DRV - (tcyazfq) -- C:\WINDOWS\SYSTEM32\uwzfqas.sys ()
DRV - (Tcpip6) -- C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (LMIRfsClientNP) -- C:\WINDOWS\SYSTEM32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver) -- C:\WINDOWS\SYSTEM32\DRIVERS\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (Secdrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (lmimirr) -- C:\WINDOWS\SYSTEM32\DRIVERS\lmimirr.sys (LogMeIn, Inc.)
DRV - (WinDriver6) -- C:\WINDOWS\SYSTEM32\DRIVERS\windrvr6.sys (Jungo)
DRV - (dsunidrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (NPF) -- C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys (CACE Technologies)
DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ASCTRM) -- C:\WINDOWS\SYSTEM32\DRIVERS\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (wceusbsh) -- C:\WINDOWS\SYSTEM32\DRIVERS\wceusbsh.sys (Microsoft Corporation)
DRV - (drvmcdb) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) -- C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) -- C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) -- C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) -- C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) -- C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) -- C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) -- C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) -- C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) -- C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) -- C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (Ser2pl) -- C:\WINDOWS\SYSTEM32\DRIVERS\ser2pl.sys (Ranioshack Corporation)
DRV - (nv) -- C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nm) -- C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys (Microsoft Corporation)
DRV - (Ptilink) -- C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
DRV - (amdagp) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (sscdbhk5) -- C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (P17) -- C:\WINDOWS\SYSTEM32\DRIVERS\P17.sys (Creative Technology Ltd.)
DRV - (b57w2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (PalmUSBD) -- C:\WINDOWS\SYSTEM32\DRIVERS\PalmUSBD.sys (Palm, Inc.)
DRV - (IntelC52) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (ctsfm2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PfModNT) -- C:\WINDOWS\SYSTEM32\DRIVERS\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (omci) -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Sparrow) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B) Intel® -- C:\WINDOWS\SYSTEM32\DRIVERS\E100B325.SYS (Intel Corporation)
DRV - (PEDRV) -- C:\WINDOWS\SYSTEM32\DRIVERS\pedrv.sys ()
DRV - (VICHW11) -- C:\WINDOWS\SYSTEM32\DRIVERS\vichw11.sys ()
DRV - (GIVEIO) -- C:\WINDOWS\SYSTEM32\DRIVERS\GIVEIO.SYS ()


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/09 07:20:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/01/19 08:08:49 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/12 09:43:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/07 10:41:33 | 000,000,000 | ---D | M]

[2009/11/24 16:14:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Mozilla\Extensions
[2009/11/24 16:14:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Maloy\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/02/16 10:14:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Maloy\Application Data\Mozilla\Firefox\Profiles\frc1vqlo.default\extensions
[2009/11/25 08:25:47 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Maloy\Application Data\Mozilla\Firefox\Profiles\frc1vqlo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/24 16:13:09 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/01/07 10:41:30 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/01/07 10:41:29 | 000,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/01/07 10:41:30 | 000,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2010/01/07 10:41:30 | 000,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009/11/02 19:16:17 | 000,001,394 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2009/11/02 19:16:17 | 000,002,193 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2009/11/02 19:16:17 | 000,001,534 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2009/11/02 19:16:17 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2009/11/02 19:16:17 | 000,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2009/11/02 19:16:17 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2009/11/02 19:16:17 | 000,000,792 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2010/02/09 15:17:31 | 000,000,022 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\SYSTEM32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Update Scheduler for Proteus Demonstration 7.lnk = C:\Program Files\Labcenter Electronics\Proteus 7 Demonstration\BIN\UDSCHED.EXE ()
O4 - Startup: C:\Documents and Settings\Maloy\Start Menu\Programs\Startup\SpywareBlaster.lnk = C:\Program Files\SpywareBlaster\spywareblaster.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\shdocvw.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\SYSTEM32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\SYSTEM32\pnrpnsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\SYSTEM32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\SYSTEM32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\SYSTEM32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 64 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 338 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\SYSTEM32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\SYSTEM32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\SYSTEM32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\SYSTEM32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\lowsec.exe) - C:\WINDOWS\SYSTEM32\lowsec.exe ()
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SYSTEM32\stobject.dll (Microsoft Corporation)
O21 - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\SYSTEM32\upnpui.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\SYSTEM32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\SYSTEM32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Maloy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Maloy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/29 11:19:31 | 000,000,136 | ---- | M] () - C:\Autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2004/08/11 17:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.OLD -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/02/16 13:56:44 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Maloy\Recent
[2010/02/16 13:55:13 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/02/15 14:13:48 | 000,549,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Maloy\Desktop\OTL.exe
[2010/02/15 13:47:43 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/15 13:47:33 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/15 13:44:59 | 005,115,824 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Maloy\Desktop\mbam-setup.exe
[2010/02/15 13:39:57 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/02/15 08:59:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Maloy\Desktop\tdsskiller
[2010/02/10 13:09:45 | 000,000,000 | ---D | C] -- C:\schrauber8560s
[2010/02/09 14:58:02 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/02/09 14:55:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/02/09 14:55:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/02/09 14:55:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/02/09 14:55:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/02/09 14:55:25 | 000,000,000 | ---D | C] -- C:\schrauber
[2010/02/09 14:54:32 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/02/07 20:28:53 | 000,000,000 | -HSD | C] -- C:\WINDOWS\System32\winsys
[2010/02/04 14:34:32 | 000,175,880 | ---- | C] (Kaspersky Lab) -- C:\Documents and Settings\Maloy\Desktop\TDSSKiller.exe
[2010/01/28 15:41:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Maloy\Local Settings\Application Data\SupportSoft
[2010/01/28 15:39:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/01/28 15:39:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PCDr
[2010/01/28 15:37:02 | 000,000,000 | ---D | C] -- C:\Program Files\Dell Support Center
[2010/01/28 15:37:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\supportsoft
[2010/01/28 14:10:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010/01/28 11:15:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/01/28 08:48:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2010/01/28 08:48:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2010/01/28 08:48:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2010/01/28 08:48:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2010/01/28 08:44:03 | 000,086,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml6r.dll
[2010/01/28 08:44:01 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\asr_pfu.exe
[2010/01/28 08:44:01 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\secedit.exe
[2010/01/28 08:44:01 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spiisupd.exe
[2010/01/28 08:44:00 | 002,113,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dxdiagn.dll
[2010/01/28 08:44:00 | 001,689,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3d9.dll
[2010/01/28 08:44:00 | 000,937,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winbrand.dll
[2010/01/28 08:44:00 | 000,848,384 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\ir41_32.ax
[2010/01/28 08:44:00 | 000,755,200 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\ir50_32.dll
[2010/01/28 08:44:00 | 000,716,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecs.dll
[2010/01/28 08:44:00 | 000,438,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpob2res.dll
[2010/01/28 08:44:00 | 000,412,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\photometadatahandler.dll
[2010/01/28 08:44:00 | 000,407,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstsc.exe
[2010/01/28 08:44:00 | 000,380,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irprops.cpl
[2010/01/28 08:44:00 | 000,352,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecsext.dll
[2010/01/28 08:44:00 | 000,351,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp3res.dll
[2010/01/28 08:44:00 | 000,338,432 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\ir41_qcx.dll
[2010/01/28 08:44:00 | 000,312,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\p2pgraph.dll
[2010/01/28 08:44:00 | 000,276,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmphoto.dll
[2010/01/28 08:44:00 | 000,200,192 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\ir50_qc.dll
[2010/01/28 08:44:00 | 000,199,680 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\iac25_32.ax
[2010/01/28 08:44:00 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fsquirt.exe
[2010/01/28 08:44:00 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp1res.dll
[2010/01/28 08:44:00 | 000,183,808 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\ir50_qcx.dll
[2010/01/28 08:44:00 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sbeio.dll
[2010/01/28 08:44:00 | 000,154,624 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\ivfsrc.ax
[2010/01/28 08:44:00 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wscui.cpl
[2010/01/28 08:44:00 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mssap.dll
[2010/01/28 08:44:00 | 000,120,320 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\ir41_qc.dll
[2010/01/28 08:44:00 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdadiag.dll
[2010/01/28 08:44:00 | 000,116,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\p2p.dll
[2010/01/28 08:44:00 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bthprops.cpl
[2010/01/28 08:44:00 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\p2pnetsh.dll
[2010/01/28 08:44:00 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\p2pgasvc.dll
[2010/01/28 08:44:00 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\firewall.cpl
[2010/01/28 08:44:00 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\blastcln.exe
[2010/01/28 08:44:00 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fwcfg.dll
[2010/01/28 08:44:00 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\btpanui.dll
[2010/01/28 08:44:00 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xmlprovi.dll
[2010/01/28 08:44:00 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\powercfg.exe
[2010/01/28 08:44:00 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sdhcinst.dll
[2010/01/28 08:44:00 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\verclsid.exe
[2010/01/28 08:44:00 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netsetup.cpl
[2010/01/28 08:44:00 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bthci.dll
[2010/01/28 08:44:00 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\encapi.dll
[2010/01/28 08:44:00 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winshfhc.dll
[2010/01/28 08:44:00 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\auditusr.exe
[2010/01/28 08:44:00 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
[2010/01/28 08:44:00 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmsetacl.dll
[2010/01/28 08:44:00 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spnpinst.exe
[2010/01/28 08:44:00 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smbinst.exe
[2010/01/28 08:44:00 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx2.dll
[2010/01/28 08:44:00 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsmsno.dll
[2010/01/28 08:44:00 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsmsfi.dll
[2010/01/28 08:44:00 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdukx.dll
[2010/01/28 08:44:00 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdno1.dll
[2010/01/28 08:44:00 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdfi1.dll
[2010/01/28 08:44:00 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hccoin.dll
[2010/01/28 08:44:00 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx3.dll
[2010/01/28 08:44:00 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdinmal.dll
[2010/01/28 08:44:00 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdinben.dll
[2010/01/28 08:44:00 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmlt48.dll
[2010/01/28 08:44:00 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmlt47.dll
[2010/01/28 08:44:00 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdinbe1.dll
[2010/01/28 08:44:00 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmaori.dll
[2010/01/28 08:44:00 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dsprpres.dll
[2010/01/28 08:43:57 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpcdll.dll
[2010/01/28 08:43:57 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pidgen.dll
[2010/01/28 08:43:56 | 002,897,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp2res.dll
[2010/01/28 08:43:56 | 002,897,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsp2res.dll
[2010/01/28 08:43:56 | 000,539,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msftedit.dll
[2010/01/28 08:43:56 | 000,539,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msftedit.dll
[2010/01/28 08:43:56 | 000,263,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\http.sys
[2010/01/28 08:43:56 | 000,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spra041e.dll
[2010/01/28 08:43:56 | 000,078,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sdbus.sys
[2010/01/28 08:43:56 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pnrpnsp.dll
[2010/01/28 08:43:56 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\twext.dll
[2010/01/28 08:43:56 | 000,029,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ip6fw.sys
[2010/01/28 08:43:56 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\httpapi.dll
[2010/01/28 08:43:56 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpapi.dll
[2010/01/28 08:43:56 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltlib.dll
[2010/01/28 08:43:55 | 001,200,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntbackup.exe
[2010/01/28 08:43:55 | 000,596,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wsecedit.dll
[2010/01/28 08:43:55 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\gpedit.dll
[2010/01/28 08:43:55 | 000,382,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qmgr.dll
[2010/01/28 08:43:55 | 000,352,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winhttp.dll
[2010/01/28 08:43:55 | 000,295,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\appmgr.dll
[2010/01/28 08:43:55 | 000,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
[2010/01/28 08:43:55 | 000,259,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tracerpt.exe
[2010/01/28 08:43:55 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\gptext.dll
[2010/01/28 08:43:55 | 000,163,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nwrdr.sys
[2010/01/28 08:43:55 | 000,163,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nwrdr.sys
[2010/01/28 08:43:55 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bootcfg.exe
[2010/01/28 08:43:55 | 000,128,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltmgr.sys
[2010/01/28 08:43:55 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\schtasks.exe
[2010/01/28 08:43:55 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\gpresult.exe
[2010/01/28 08:43:55 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fde.dll
[2010/01/28 08:43:55 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\adsnw.dll
[2010/01/28 08:43:55 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rsnotify.exe
[2010/01/28 08:43:55 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mqlogmgr.dll
[2010/01/28 08:43:55 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tlntsess.exe
[2010/01/28 08:43:55 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tlntsess.exe
[2010/01/28 08:43:55 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eventtriggers.exe
[2010/01/28 08:43:55 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\strmfilt.dll
[2010/01/28 08:43:55 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\strmfilt.dll
[2010/01/28 08:43:55 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fdeploy.dll
[2010/01/28 08:43:55 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tasklist.exe
[2010/01/28 08:43:55 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\taskkill.exe
[2010/01/28 08:43:55 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\systeminfo.exe
[2010/01/28 08:43:55 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\openfiles.exe
[2010/01/28 08:43:55 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nwwks.dll
[2010/01/28 08:43:55 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nwwks.dll
[2010/01/28 08:43:55 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nwapi32.dll
[2010/01/28 08:43:55 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nwapi32.dll
[2010/01/28 08:43:55 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tlntadmn.exe
[2010/01/28 08:43:55 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\logman.exe
[2010/01/28 08:43:55 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\driverquery.exe
[2010/01/28 08:43:55 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cipher.exe
[2010/01/28 08:43:55 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\getmac.exe
[2010/01/28 08:43:55 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eventcreate.exe
[2010/01/28 08:43:55 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\asr_fmt.exe
[2010/01/28 08:43:55 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax
[2010/01/28 08:43:55 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vidcap.ax
[2010/01/28 08:43:55 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\efsadu.dll
[2010/01/28 08:43:55 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltmc.exe
[2010/01/28 08:43:55 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltmc.exe
[2010/01/28 08:43:55 | 000,015,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mssmbios.sys
[2010/01/28 08:43:55 | 000,012,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sffdisk.sys
[2010/01/28 08:43:55 | 000,011,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sffp_sd.sys
[2010/01/28 08:43:55 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\proxycfg.exe
[2010/01/28 08:43:55 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tlntsvrp.dll
[2010/01/28 08:43:55 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuauserv.dll
[2010/01/28 08:43:52 | 001,852,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\acgenral.dll
[2010/01/28 08:43:52 | 000,876,653 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awel.dll
[2010/01/28 08:43:52 | 000,598,071 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmc.dll
[2010/01/28 08:43:52 | 000,470,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
[2010/01/28 08:43:52 | 000,256,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agentsvr.exe
[2010/01/28 08:43:52 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2010/01/28 08:43:52 | 000,188,494 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpcount.exe
[2010/01/28 08:43:52 | 000,188,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2010/01/28 08:43:52 | 000,184,435 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2010/01/28 08:43:52 | 000,147,513 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4apws.dll
[2010/01/28 08:43:52 | 000,109,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98swin.exe
[2010/01/28 08:43:52 | 000,102,509 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2010/01/28 08:43:52 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\directdb.dll
[2010/01/28 08:43:52 | 000,082,035 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2010/01/28 08:43:52 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agentdpv.dll
[2010/01/28 08:43:52 | 000,049,212 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2010/01/28 08:43:52 | 000,049,210 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4areg.dll
[2010/01/28 08:43:52 | 000,044,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agpcpq.sys
[2010/01/28 08:43:52 | 000,043,008 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\drivers\amdagp.sys
[2010/01/28 08:43:52 | 000,043,008 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\dllcache\amdagp.sys
[2010/01/28 08:43:52 | 000,042,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\alim1541.sys
[2010/01/28 08:43:52 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agentdp2.dll
[2010/01/28 08:43:52 | 000,042,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agp440.sys
[2010/01/28 08:43:52 | 000,041,020 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2010/01/28 08:43:52 | 000,032,826 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avss.dll
[2010/01/28 08:43:52 | 000,024,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpadmcgi.exe
[2010/01/28 08:43:52 | 000,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpexedll.dll
[2010/01/28 08:43:52 | 000,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpadmdll.dll
[2010/01/28 08:43:52 | 000,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.dll
[2010/01/28 08:43:52 | 000,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.dll
[2010/01/28 08:43:52 | 000,020,538 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpremadm.exe
[2010/01/28 08:43:52 | 000,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.exe
[2010/01/28 08:43:52 | 000,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.exe
[2010/01/28 08:43:52 | 000,014,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2010/01/28 08:43:51 | 004,190,352 | ---- | C] (Microsoft) -- C:\WINDOWS\System32\dllcache\luna.mst
[2010/01/28 08:43:51 | 003,555,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/01/28 08:43:51 | 002,180,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2010/01/28 08:43:51 | 002,136,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2010/01/28 08:43:51 | 002,057,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2010/01/28 08:43:51 | 002,015,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2010/01/28 08:43:51 | 000,743,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/01/28 08:43:51 | 000,562,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsst.dll
[2010/01/28 08:43:51 | 000,536,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msado15.dll
[2010/01/28 08:43:51 | 000,452,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsapi.dll
[2010/01/28 08:43:51 | 000,200,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadox.dll
[2010/01/28 08:43:51 | 000,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadomd.dll
[2010/01/28 08:43:51 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msjro.dll
[2010/01/28 08:43:51 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msimn.exe
[2010/01/28 08:43:50 | 001,352,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cimwin32.dll
[2010/01/28 08:43:50 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab32.dll
[2010/01/28 08:43:50 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tourstrt.exe
[2010/01/28 08:43:50 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemcomn.dll
[2010/01/28 08:43:50 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\framedyn.dll
[2010/01/28 08:43:50 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wabimp.dll
[2010/01/28 08:43:50 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemcons.dll
[2010/01/28 08:43:50 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2010/01/28 08:43:50 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemsvc.dll
[2010/01/28 08:43:50 | 000,042,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\viaagp.sys
[2010/01/28 08:43:50 | 000,041,088 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\sisagp.sys
[2010/01/28 08:43:50 | 000,041,088 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisagp.sys
[2010/01/28 08:43:50 | 000,032,827 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptest.exe
[2010/01/28 08:43:50 | 000,020,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shtml.dll
[2010/01/28 08:43:50 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemprox.dll
[2010/01/28 08:43:50 | 000,016,437 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shtml.exe
[2010/01/28 08:43:50 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptsat.dll
[2010/01/28 08:43:50 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sffp_mmc.sys
[2010/01/28 08:43:49 | 001,033,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2010/01/28 08:43:49 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\winhlp32.exe
[2010/01/28 08:43:49 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winhlp32.exe
[2010/01/28 08:43:49 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiutils.dll
[2010/01/28 08:43:49 | 000,050,688 | ---- | C] (Twain Working Group) -- C:\WINDOWS\twain_32.dll
[2010/01/28 08:43:49 | 000,050,688 | ---- | C] (Twain Working Group) -- C:\WINDOWS\System32\dllcache\twain_32.dll
[2010/01/28 08:43:48 | 002,067,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cdosys.dll
[2010/01/28 08:43:48 | 001,023,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\browseui.dll
[2010/01/28 08:43:48 | 000,625,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\catsrvut.dll
[2010/01/28 08:43:48 | 000,625,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrvut.dll
[2010/01/28 08:43:48 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\autofmt.exe
[2010/01/28 08:43:48 | 000,285,696 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\dllcache\atmfd.dll
[2010/01/28 08:43:48 | 000,285,696 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\atmfd.dll
[2010/01/28 08:43:48 | 000,263,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\adsnt.dll
[2010/01/28 08:43:48 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\catsrv.dll
[2010/01/28 08:43:48 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrv.dll
[2010/01/28 08:43:48 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\activeds.dll
[2010/01/28 08:43:48 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\activeds.dll
[2010/01/28 08:43:48 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\accwiz.exe
[2010/01/28 08:43:48 | 000,175,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\adsldp.dll
[2010/01/28 08:43:48 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdfview.dll
[2010/01/28 08:43:48 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adsldpc.dll
[2010/01/28 08:43:48 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\adsldpc.dll
[2010/01/28 08:43:48 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\capesnpn.dll
[2010/01/28 08:43:48 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\apphelp.dll
[2010/01/28 08:43:48 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\asctrls.ocx
[2010/01/28 08:43:48 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclui.dll
[2010/01/28 08:43:48 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aclui.dll
[2010/01/28 08:43:48 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\actxprxy.dll
[2010/01/28 08:43:48 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\actxprxy.dll
[2010/01/28 08:43:48 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\6to4svc.dll
[2010/01/28 08:43:48 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ahui.exe
[2010/01/28 08:43:48 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrvps.dll
[2010/01/28 08:43:48 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avifil32.dll
[2010/01/28 08:43:48 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avifil32.dll
[2010/01/28 08:43:48 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browsewm.dll
[2010/01/28 08:43:48 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\access.cpl
[2010/01/28 08:43:48 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\adsmsext.dll
[2010/01/28 08:43:48 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\asycfilt.dll
[2010/01/28 08:43:48 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\browselc.dll
[2010/01/28 08:43:48 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browselc.dll
[2010/01/28 08:43:48 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cabinet.dll
[2010/01/28 08:43:48 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cabinet.dll
[2010/01/28 08:43:48 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\authz.dll
[2010/01/28 08:43:48 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\basesrv.dll
[2010/01/28 08:43:48 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\camocx.dll
[2010/01/28 08:43:48 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\alg.exe
[2010/01/28 08:43:48 | 000,030,208 | ---- | C] (Adobe Systems) -- C:\WINDOWS\System32\dllcache\atmlib.dll
[2010/01/28 08:43:48 | 000,030,208 | ---- | C] (Adobe Systems) -- C:\WINDOWS\System32\atmlib.dll
[2010/01/28 08:43:48 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batmeter.dll
[2010/01/28 08:43:48 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\at.exe
[2010/01/28 08:43:48 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bidispl.dll
[2010/01/28 08:43:48 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\autolfn.exe
[2010/01/28 08:43:48 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\attrib.exe
[2010/01/28 08:43:48 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\atmadm.exe
[2010/01/28 08:43:48 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batt.dll
[2010/01/28 08:43:48 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\actmovie.exe
[2010/01/28 08:43:47 | 001,267,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsvcs.dll
[2010/01/28 08:43:47 | 001,179,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3d8.dll
[2010/01/28 08:43:47 | 001,054,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\danim.dll
[2010/01/28 08:43:47 | 001,054,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\danim.dll
[2010/01/28 08:43:47 | 000,825,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\d3dim700.dll
[2010/01/28 08:43:47 | 000,825,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dim700.dll
[2010/01/28 08:43:47 | 000,792,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comres.dll
[2010/01/28 08:43:47 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[2010/01/28 08:43:47 | 000,540,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comuid.dll
[2010/01/28 08:43:47 | 000,512,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cryptui.dll
[2010/01/28 08:43:47 | 000,498,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\clbcatq.dll
[2010/01/28 08:43:47 | 000,457,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\certmgr.dll
[2010/01/28 08:43:47 | 000,345,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\confmsp.dll
[2010/01/28 08:43:47 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmdial32.dll
[2010/01/28 08:43:47 | 000,326,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cscui.dll
[2010/01/28 08:43:47 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\compstui.dll
[2010/01/28 08:43:47 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\certcli.dll
[2010/01/28 08:43:47 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmprops.dll
[2010/01/28 08:43:47 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\credui.dll
[2010/01/28 08:43:47 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsnap.dll
[2010/01/28 08:43:47 | 000,110,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clbcatex.dll
[2010/01/28 08:43:47 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cic.dll
[2010/01/28 08:43:47 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clipbrd.exe
[2010/01/28 08:43:47 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cscdll.dll
[2010/01/28 08:43:47 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cscript.exe
[2010/01/28 08:43:47 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comrepl.dll
[2010/01/28 08:43:47 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cliconfg.dll
[2010/01/28 08:43:47 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cryptdlg.dll
[2010/01/28 08:43:47 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ciodm.dll
[2010/01/28 08:43:47 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ciodm.dll
[2010/01/28 08:43:47 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cleanmgr.exe
[2010/01/28 08:43:47 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cryptnet.dll
[2010/01/28 08:43:47 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmstp.exe
[2010/01/28 08:43:47 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\colbact.dll
[2010/01/28 08:43:47 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\colbact.dll
[2010/01/28 08:43:47 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clusapi.dll
[2010/01/28 08:43:47 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cryptext.dll
[2010/01/28 08:43:47 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cnbjmon.dll
[2010/01/28 08:43:47 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmdl32.exe
[2010/01/28 08:43:47 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmutil.dll
[2010/01/28 08:43:47 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmmon32.exe
[2010/01/28 08:43:47 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cfgbkend.dll
[2010/01/28 08:43:47 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cryptdll.dll
[2010/01/28 08:43:47 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cryptdll.dll
[2010/01/28 08:43:47 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\conime.exe
[2010/01/28 08:43:47 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comaddin.dll
[2010/01/28 08:43:47 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cliconfg.rll
[2010/01/28 08:43:47 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cliconfg.exe
[2010/01/28 08:43:47 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cfgmgr32.dll
[2010/01/28 08:43:47 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cfgmgr32.dll
[2010/01/28 08:43:47 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmcfg32.dll
[2010/01/28 08:43:47 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3d8thk.dll
[2010/01/28 08:43:46 | 000,640,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dbghelp.dll
[2010/01/28 08:43:46 | 000,375,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpnet.dll
[2010/01/28 08:43:46 | 000,370,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dhcpmon.dll
[2010/01/28 08:43:46 | 000,367,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dsound.dll
[2010/01/28 08:43:46 | 000,367,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dsound.dll
[2010/01/28 08:43:46 | 000,282,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\devmgr.dll
[2010/01/28 08:43:46 | 000,273,920 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\System32\dmdlgs.dll
[2010/01/28 08:43:46 | 000,266,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ddraw.dll
[2010/01/28 08:43:46 | 000,266,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ddraw.dll
[2010/01/28 08:43:46 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dplayx.dll
[2010/01/28 08:43:46 | 000,212,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpvoice.dll
[2010/01/28 08:43:46 | 000,200,704 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\System32\dmdskmgr.dll
[2010/01/28 08:43:46 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dsdmo.dll
[2010/01/28 08:43:46 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dinput8.dll
[2010/01/28 08:43:46 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmime.dll
[2010/01/28 08:43:46 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\diskpart.exe
[2010/01/28 08:43:46 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dinput.dll
[2010/01/28 08:43:46 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dinput.dll
[2010/01/28 08:43:46 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\daxctle.ocx
[2010/01/28 08:43:46 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\datime.dll
[2010/01/28 08:43:46 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dnsapi.dll
[2010/01/28 08:43:46 | 000,123,904 | ---- | C] (Microsoft Corp. and Executive Software International, Inc.) -- C:\WINDOWS\System32\dfrgui.dll
[2010/01/28 08:43:46 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpvvox.dll
[2010/01/28 08:43:46 | 000,111,104 | ---- | C] (Microsoft) -- C:\WINDOWS\System32\dgnet.dll
[2010/01/28 08:43:46 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dbnetlib.dll
[2010/01/28 08:43:46 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmstyle.dll
[2010/01/28 08:43:46 | 000,104,960 | ---- | C] (Microsoft Corp. and Executive Software International, Inc.) -- C:\WINDOWS\System32\dllcache\dfrgntfs.exe
[2010/01/28 08:43:46 | 000,104,960 | ---- | C] (Microsoft Corp. and Executive Software International, Inc.) -- C:\WINDOWS\System32\dfrgntfs.exe
[2010/01/28 08:43:46 | 000,104,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmusic.dll
[2010/01/28 08:43:46 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmsynth.dll
[2010/01/28 08:43:46 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dskquota.dll
[2010/01/28 08:43:46 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dskquota.dll
[2010/01/28 08:43:46 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\diantz.exe
[2010/01/28 08:43:46 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpvsetup.exe
[2010/01/28 08:43:46 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmscript.dll
[2010/01/28 08:43:46 | 000,082,432 | ---- | C] (Microsoft Corp. and Executive Software International, Inc.) -- C:\WINDOWS\System32\dfrgfat.exe
[2010/01/28 08:43:46 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dsdmoprp.dll
[2010/01/28 08:43:46 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmcompos.dll
[2010/01/28 08:43:46 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpnhupnp.dll
[2010/01/28 08:43:46 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpnhupnp.dll
[2010/01/28 08:43:46 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpwsockx.dll
[2010/01/28 08:43:46 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dataclen.dll
[2010/01/28 08:43:46 | 000,052,224 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\System32\dmutil.dll
[2010/01/28 08:43:46 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\docprop2.dll
[2010/01/28 08:43:46 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dnsrslvr.dll
[2010/01/28 08:43:46 | 000,045,083 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dispex.dll
[2010/01/28 08:43:46 | 000,045,083 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dispex.dll
[2010/01/28 08:43:46 | 000,038,912 | ---- | C] (Microsoft Corp. and Executive Software International, Inc.) -- C:\WINDOWS\System32\dfrgsnap.dll
[2010/01/28 08:43:46 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmloader.dll
[2010/01/28 08:43:46 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpnhpast.dll
[2010/01/28 08:43:46 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dplaysvr.exe
[2010/01/28 08:43:46 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ddeshare.exe
[2010/01/28 08:43:46 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmband.dll
[2010/01/28 08:43:46 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dbnmpntw.dll
[2010/01/28 08:43:46 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ddrawex.dll
[2010/01/28 08:43:46 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ddrawex.dll
[2010/01/28 08:43:46 | 000,025,088 | ---- | C] (Microsoft Corp. and Executive Software International, Inc.) -- C:\WINDOWS\System32\dllcache\defrag.exe
[2010/01/28 08:43:46 | 000,025,088 | ---- | C] (Microsoft Corp. and Executive Software International, Inc.) -- C:\WINDOWS\System32\defrag.exe
[2010/01/28 08:43:46 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dbmsrpcn.dll
[2010/01/28 08:43:46 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\davclnt.dll
[2010/01/28 08:43:46 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\davclnt.dll
[2010/01/28 08:43:46 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpmodemx.dll
[2010/01/28 08:43:46 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpvacm.dll
[2010/01/28 08:43:46 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpnsvr.exe
[2010/01/28 08:43:46 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ds32gt.dll
[2010/01/28 08:43:46 | 000,015,872 | ---- | C] (Microsoft Corp.) -- C:\WINDOWS\System32\dmremote.exe
[2010/01/28 08:43:46 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drprov.dll
[2010/01/28 08:43:46 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drprov.dll
[2010/01/28 08:43:46 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dciman32.dll
[2010/01/28 08:43:46 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dciman32.dll
[2010/01/28 08:43:46 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dcomcnfg.exe
[2010/01/28 08:43:46 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpnlobby.dll
[2010/01/28 08:43:46 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpnaddr.dll
[2010/01/28 08:43:45 | 001,298,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dxdiag.exe
[2010/01/28 08:43:45 | 001,294,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dsound3d.dll
[2010/01/28 08:43:45 | 001,227,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dx8vb.dll
[2010/01/28 08:43:45 | 001,082,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\esent.dll
[2010/01/28 08:43:45 | 001,082,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\esent.dll
[2010/01/28 08:43:45 | 000,619,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dx7vb.dll
[2010/01/28 08:43:45 | 000,614,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\h323msp.dll
[2010/01/28 08:43:45 | 000,546,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hhctrl.ocx
[2010/01/28 08:43:45 | 000,546,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hhctrl.ocx
[2010/01/28 08:43:45 | 000,380,957 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\expsrv.dll
[2010/01/28 08:43:45 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hnetcfg.dll
[2010/01/28 08:43:45 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hnetcfg.dll
[2010/01/28 08:43:45 | 000,337,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\filemgmt.dll
[2010/01/28 08:43:45 | 000,330,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hnetwiz.dll
[2010/01/28 08:43:45 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\duser.dll
[2010/01/28 08:43:45 | 000,304,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\duser.dll
[2010/01/28 08:43:45 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gdi32.dll
[2010/01/28 08:43:45 | 000,265,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\h323.tsp
[2010/01/28 08:43:45 | 000,265,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\h323.tsp
[2010/01/28 08:43:45 | 000,254,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icm32.dll
[2010/01/28 08:43:45 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\es.dll
[2010/01/28 08:43:45 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eudcedit.exe
[2010/01/28 08:43:45 | 000,183,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\els.dll
[2010/01/28 08:43:45 | 000,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dwwin.exe
[2010/01/28 08:43:45 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hdwwiz.cpl
[2010/01/28 08:43:45 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hotplug.dll
[2010/01/28 08:43:45 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dsprop.dll
[2010/01/28 08:43:45 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dssenh.dll
[2010/01/28 08:43:45 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dssenh.dll
[2010/01/28 08:43:45 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\glu32.dll
[2010/01/28 08:43:45 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\exts.dll
[2010/01/28 08:43:45 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\idq.dll
[2010/01/28 08:43:45 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iasrad.dll
[2010/01/28 08:43:45 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iexpress.exe
[2010/01/28 08:43:45 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fldrclnr.dll
[2010/01/28 08:43:45 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fontsub.dll
[2010/01/28 08:43:45 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fontsub.dll
[2010/01/28 08:43:45 | 000,080,384 | ---- | C] (Radius Inc.) -- C:\WINDOWS\System32\iccvid.dll
[2010/01/28 08:43:45 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\faultrep.dll
[2010/01/28 08:43:45 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwdial.dll
[2010/01/28 08:43:45 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hlink.dll
[2010/01/28 08:43:45 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hlink.dll
[2010/01/28 08:43:45 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwphbk.dll
[2010/01/28 08:43:45 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eventlog.dll
[2010/01/28 08:43:45 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\extrac32.exe
[2010/01/28 08:43:45 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\htui.dll
[2010/01/28 08:43:45 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hhsetup.dll
[2010/01/28 08:43:45 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\grpconv.exe
[2010/01/28 08:43:45 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hidphone.tsp
[2010/01/28 08:43:45 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidphone.tsp
[2010/01/28 08:43:45 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\findstr.exe
[2010/01/28 08:43:45 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\feclient.dll
[2010/01/28 08:43:45 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hid.dll
[2010/01/28 08:43:45 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fontview.exe
[2010/01/28 08:43:45 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dswave.dll
[2010/01/28 08:43:45 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dvdupgrd.exe
[2010/01/28 08:43:45 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\help.exe
[2010/01/28 08:43:45 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icaapi.dll
[2010/01/28 08:43:45 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\gpkrsrc.dll
[2010/01/28 08:43:45 | 000,009,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\framebuf.dll
[2010/01/28 08:43:45 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\forcedos.exe
[2010/01/28 08:43:45 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icmp.dll
[2010/01/28 08:43:44 | 001,192,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcndmgr.dll
[2010/01/28 08:43:44 | 001,028,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc42.dll
[2010/01/28 08:43:44 | 001,028,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/01/28 08:43:44 | 000,927,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc40u.dll
[2010/01/28 08:43:44 | 000,927,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/01/28 08:43:44 | 000,815,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmc.exe
[2010/01/28 08:43:44 | 000,683,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcomm.dll
[2010/01/28 08:43:44 | 000,586,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mlang.dll
[2010/01/28 08:43:44 | 000,586,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mlang.dll
[2010/01/28 08:43:44 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logonui.exe
[2010/01/28 08:43:44 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\licdll.dll
[2010/01/28 08:43:44 | 000,384,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsmsnap.dll
[2010/01/28 08:43:44 | 000,349,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsecsnp.dll
[2010/01/28 08:43:44 | 000,331,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipnathlp.dll
[2010/01/28 08:43:44 | 000,330,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ippromon.dll
[2010/01/28 08:43:44 | 000,298,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kerberos.dll
[2010/01/28 08:43:44 | 000,290,816 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\l3codeca.acm
[2010/01/28 08:43:44 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcfg.dll
[2010/01/28 08:43:44 | 000,221,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\localsec.dll
[2010/01/28 08:43:44 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\logon.scr
[2010/01/28 08:43:44 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iprtrmgr.dll
[2010/01/28 08:43:44 | 000,163,840 | ---- | C] (America Online) -- C:\WINDOWS\System32\jgdw400.dll
[2010/01/28 08:43:44 | 000,163,840 | ---- | C] (America Online) -- C:\WINDOWS\System32\dllcache\jgdw400.dll
[2010/01/28 08:43:44 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\itircl.dll
[2010/01/28 08:43:44 | 000,154,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipmontr.dll
[2010/01/28 08:43:44 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\keymgr.dll
[2010/01/28 08:43:44 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\initpki.dll
[2010/01/28 08:43:44 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ifmon.dll
[2010/01/28 08:43:44 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
[2010/01/28 08:43:44 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksproxy.ax
[2010/01/28 08:43:44 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\intl.cpl
[2010/01/28 08:43:44 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\input.dll
[2010/01/28 08:43:44 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mdminst.dll
[2010/01/28 08:43:44 | 000,110,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imm32.dll
[2010/01/28 08:43:44 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\loadperf.dll
[2010/01/28 08:43:44 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iphlpapi.dll
[2010/01/28 08:43:44 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iphlpapi.dll
[2010/01/28 08:43:44 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kswdmcap.ax
[2010/01/28 08:43:44 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kswdmcap.ax
[2010/01/28 08:43:44 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\makecab.exe
[2010/01/28 08:43:44 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mciavi32.dll
[2010/01/28 08:43:44 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\isign32.dll
[2010/01/28 08:43:44 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ils.dll
[2010/01/28 08:43:44 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetpp.dll
[2010/01/28 08:43:44 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\magnify.exe
[2010/01/28 08:43:44 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\magnify.exe
[2010/01/28 08:43:44 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcbase.dll
[2010/01/28 08:43:44 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\joy.cpl
[2010/01/28 08:43:44 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kstvtune.ax
[2010/01/28 08:43:44 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kstvtune.ax
[2010/01/28 08:43:44 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\miglibnt.dll
[2010/01/28 08:43:44 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipv6mon.dll
[2010/01/28 08:43:44 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\licwmi.dll
[2010/01/28 08:43:44 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipconfig.exe
[2010/01/28 08:43:44 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ixsso.dll
[2010/01/28 08:43:44 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipv6.exe
[2010/01/28 08:43:44 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetres.dll
[2010/01/28 08:43:44 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iyuv_32.dll
[2010/01/28 08:43:44 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksxbar.ax
[2010/01/28 08:43:44 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksxbar.ax
[2010/01/28 08:43:44 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mf3216.dll
[2010/01/28 08:43:44 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mf3216.dll
[2010/01/28 08:43:44 | 000,036,921 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\imeshare.dll
[2010/01/28 08:43:44 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iprip.dll
[2010/01/28 08:43:44 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iprip.dll
[2010/01/28 08:43:44 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kmddsp.tsp
[2010/01/28 08:43:44 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kmddsp.tsp
[2010/01/28 08:43:44 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetmib1.dll
[2010/01/28 08:43:44 | 000,032,768 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\isrdbg32.dll
[2010/01/28 08:43:44 | 000,027,648 | ---- | C] (Johnson-Grace Company) -- C:\WINDOWS\System32\jgpl400.dll
[2010/01/28 08:43:44 | 000,027,648 | ---- | C] (Johnson-Grace Company) -- C:\WINDOWS\System32\dllcache\jgpl400.dll
[2010/01/28 08:43:44 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mciwave.dll
[2010/01/28 08:43:44 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipxroute.exe
[2010/01/28 08:43:44 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mciseq.dll
[2010/01/28 08:43:44 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfcsubs.dll
[2010/01/28 08:43:44 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfcsubs.dll
[2010/01/28 08:43:44 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipxwan.dll
[2010/01/28 08:43:44 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\linkinfo.dll
[2010/01/28 08:43:44 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\linkinfo.dll
[2010/01/28 08:43:44 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mimefilt.dll
[2010/01/28 08:43:44 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\midimap.dll
[2010/01/28 08:43:44 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmfutil.dll
[2010/01/28 08:43:44 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipconf.tsp
[2010/01/28 08:43:44 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipconf.tsp
[2010/01/28 08:43:44 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsink.ax
[2010/01/28 08:43:44 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipsink.ax
[2010/01/28 08:43:44 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetppui.dll
[2010/01/28 08:43:44 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mcastmib.dll
[2010/01/28 08:43:44 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\localui.dll
[2010/01/28 08:43:44 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\lprhelp.dll
[2010/01/28 08:43:44 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\igmpagnt.dll
[2010/01/28 08:43:44 | 000,007,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kd1394.dll
[2010/01/28 08:43:44 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnec.dll
[2010/01/28 08:43:44 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll
[2010/01/28 08:43:44 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksuser.dll
[2010/01/28 08:43:43 | 001,386,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvbvm60.dll
[2010/01/28 08:43:43 | 000,994,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msgina.dll
[2010/01/28 08:43:43 | 000,994,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msgina.dll
[2010/01/28 08:43:43 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtctm.dll
[2010/01/28 08:43:43 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtctm.dll
[2010/01/28 08:43:43 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcprx.dll
[2010/01/28 08:43:43 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtcprx.dll
[2010/01/28 08:43:43 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp60.dll
[2010/01/28 08:43:43 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msvcp60.dll
[2010/01/28 08:43:43 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msvcrt.dll
[2010/01/28 08:43:43 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mspaint.exe
[2010/01/28 08:43:43 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspaint.exe
[2010/01/28 08:43:43 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msctf.dll
[2010/01/28 08:43:43 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstask.dll
[2010/01/28 08:43:43 | 000,262,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mpg4ds32.ax
[2010/01/28 08:43:43 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoeacct.dll
[2010/01/28 08:43:43 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msadds32.ax
[2010/01/28 08:43:43 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\moricons.dll
[2010/01/28 08:43:43 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moricons.dll
[2010/01/28 08:43:43 | 000,195,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msutb.dll
[2010/01/28 08:43:43 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcuiu.dll
[2010/01/28 08:43:43 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtcuiu.dll
[2010/01/28 08:43:43 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msimtf.dll
[2010/01/28 08:43:43 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msimtf.dll
[2010/01/28 08:43:43 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\modemui.dll
[2010/01/28 08:43:43 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\modemui.dll
[2010/01/28 08:43:43 | 000,151,583 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msjint40.dll
[2010/01/28 08:43:43 | 000,151,583 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msjint40.dll
[2010/01/28 08:43:43 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdart.dll
[2010/01/28 08:43:43 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msorcl32.dll
[2010/01/28 08:43:43 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mobsync.exe
[2010/01/28 08:43:43 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mobsync.exe
[2010/01/28 08:43:43 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mplay32.exe
[2010/01/28 08:43:43 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstlsapi.dll
[2010/01/28 08:43:43 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoert2.dll
[2010/01/28 08:43:43 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msscript.ocx
[2010/01/28 08:43:43 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mprapi.dll
[2010/01/28 08:43:43 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mscms.dll
[2010/01/28 08:43:43 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mscms.dll
[2010/01/28 08:43:43 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msacm32.dll
[2010/01/28 08:43:43 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msacm32.dll
[2010/01/28 08:43:43 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msscds32.ax
[2010/01/28 08:43:43 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msconf.dll
[2010/01/28 08:43:43 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msctfp.dll
[2010/01/28 08:43:43 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcrt40.dll
[2010/01/28 08:43:43 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mpr.dll
[2010/01/28 08:43:43 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtclog.dll
[2010/01/28 08:43:43 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtclog.dll
[2010/01/28 08:43:43 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msasn1.dll
[2010/01/28 08:43:43 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcirt.dll
[2010/01/28 08:43:43 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msvcirt.dll
[2010/01/28 08:43:43 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msident.dll
[2010/01/28 08:43:43 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msprivs.dll
[2010/01/28 08:43:43 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mscpxl32.dll
[2010/01/28 08:43:43 | 000,034,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mnmdd.dll
[2010/01/28 08:43:43 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mspatcha.dll
[2010/01/28 08:43:43 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspatcha.dll
[2010/01/28 08:43:43 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msorc32r.dll
[2010/01/28 08:43:43 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\more.com
[2010/01/28 08:43:43 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstinit.exe
[2010/01/28 08:43:43 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdatsrc.tlb
[2010/01/28 08:43:43 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mscpx32r.dll
[2010/01/28 08:43:43 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msrle32.dll
[2010/01/28 08:43:43 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msidle.dll
[2010/01/28 08:43:43 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msimg32.dll
[2010/01/28 08:43:43 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msafd.dll
[2010/01/28 08:43:42 | 001,285,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ole32.dll
[2010/01/28 08:43:42 | 000,701,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml2.dll
[2010/01/28 08:43:42 | 000,622,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netcfgx.dll
[2010/01/28 08:43:42 | 000,506,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml.dll
[2010/01/28 08:43:42 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntmsmgr.dll
[2010/01/28 08:43:42 | 000,407,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netlogon.dll
[2010/01/28 08:43:42 | 000,332,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netapi32.dll
[2010/01/28 08:43:42 | 000,329,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netsetup.exe
[2010/01/28 08:43:42 | 000,285,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\objsel.dll
[2010/01/28 08:43:42 | 000,278,559 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcjt32.dll
[2010/01/28 08:43:42 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oakley.dll
[2010/01/28 08:43:42 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oakley.dll
[2010/01/28 08:43:42 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nusrmgr.cpl
[2010/01/28 08:43:42 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbc32.dll
[2010/01/28 08:43:42 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\odbc32.dll
[2010/01/28 08:43:42 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\newdev.dll
[2010/01/28 08:43:42 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netui1.dll
[2010/01/28 08:43:42 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netui1.dll
[2010/01/28 08:43:42 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mswsock.dll
[2010/01/28 08:43:42 | 000,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mswebdvd.dll
[2010/01/28 08:43:42 | 000,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2010/01/28 08:43:42 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntmsdba.dll
[2010/01/28 08:43:42 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbctrac.dll
[2010/01/28 08:43:42 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntshrui.dll
[2010/01/28 08:43:42 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netid.dll
[2010/01/28 08:43:42 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcconf.dll
[2010/01/28 08:43:42 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\net1.exe
[2010/01/28 08:43:42 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oledlg.dll
[2010/01/28 08:43:42 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oledlg.dll
[2010/01/28 08:43:42 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\offfilt.dll
[2010/01/28 08:43:42 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvfw32.dll
[2010/01/28 08:43:42 | 000,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msvfw32.dll
[2010/01/28 08:43:42 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntmarta.dll
[2010/01/28 08:43:42 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oleprn.dll
[2010/01/28 08:43:42 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbccp32.dll
[2010/01/28 08:43:42 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nlhtml.dll
[2010/01/28 08:43:42 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcint.dll
[2010/01/28 08:43:42 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\odbcint.dll
[2010/01/28 08:43:42 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxoci.dll
[2010/01/28 08:43:42 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtxoci.dll
[2010/01/28 08:43:42 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mydocs.dll
[2010/01/28 08:43:42 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netsh.exe
[2010/01/28 08:43:42 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netui0.dll
[2010/01/28 08:43:42 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netui0.dll
[2010/01/28 08:43:42 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\olecli32.dll
[2010/01/28 08:43:42 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\olecli32.dll
[2010/01/28 08:43:42 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msw3prt.dll
[2010/01/28 08:43:42 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcconf.exe
[2010/01/28 08:43:42 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\notepad.exe
[2010/01/28 08:43:42 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdsapi.dll
[2010/01/28 08:43:42 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxclu.dll
[2010/01/28 08:43:42 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtxclu.dll
[2010/01/28 08:43:42 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbccu32.dll
[2010/01/28 08:43:42 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbccr32.dll
[2010/01/28 08:43:42 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ocmanage.dll
[2010/01/28 08:43:42 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ndptsp.tsp
[2010/01/28 08:43:42 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndptsp.tsp
[2010/01/28 08:43:42 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\npptools.dll
[2010/01/28 08:43:42 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\narrator.exe
[2010/01/28 08:43:42 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\narrator.exe
[2010/01/28 08:43:42 | 000,053,279 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcji32.dll
[2010/01/28 08:43:42 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntlanman.dll
[2010/01/28 08:43:42 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntlanman.dll
[2010/01/28 08:43:42 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\net.exe
[2010/01/28 08:43:42 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntmsapi.dll
[2010/01/28 08:43:42 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netstat.exe
[2010/01/28 08:43:42 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ncobjapi.dll
[2010/01/28 08:43:42 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ncobjapi.dll
[2010/01/28 08:43:42 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbccp32.cpl
[2010/01/28 08:43:42 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcad32.exe
[2010/01/28 08:43:42 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmmkcert.dll
[2010/01/28 08:43:42 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxlegih.dll
[2010/01/28 08:43:42 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcbcp.dll
[2010/01/28 08:43:42 | 000,020,511 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odtext32.dll
[2010/01/28 08:43:42 | 000,020,511 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oddbse32.dll
[2010/01/28 08:43:42 | 000,020,510 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odpdx32.dll
[2010/01/28 08:43:42 | 000,020,510 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odfox32.dll
[2010/01/28 08:43:42 | 000,020,510 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odexl32.dll
[2010/01/28 08:43:42 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxdm.dll
[2010/01/28 08:43:42 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nddenb32.dll
[2010/01/28 08:43:42 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nddeapi.dll
[2010/01/28 08:43:42 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msyuv.dll
[2010/01/28 08:43:42 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbc32gt.dll
[2010/01/28 08:43:42 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntvdmd.dll
[2010/01/28 08:43:42 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcp32r.dll
[2010/01/28 08:43:42 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netrap.dll
[2010/01/28 08:43:42 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netrap.dll
[2010/01/28 08:43:42 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nddeapir.exe
[2010/01/28 08:43:42 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxex.dll
[2010/01/28 08:43:41 | 001,435,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\query.dll
[2010/01/28 08:43:41 | 001,435,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\query.dll
[2010/01/28 08:43:41 | 000,713,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\opengl32.dll
[2010/01/28 08:43:41 | 000,433,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\riched20.dll
[2010/01/28 08:43:41 | 000,433,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\riched20.dll
[2010/01/28 08:43:41 | 000,397,824 | ---- | C] (Microsoft) -- C:\WINDOWS\System32\regwizc.dll
[2010/01/28 08:43:41 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pdh.dll
[2010/01/28 08:43:41 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\osk.exe
[2010/01/28 08:43:41 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\osk.exe
[2010/01/28 08:43:41 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasppp.dll
[2010/01/28 08:43:41 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasppp.dll
[2010/01/28 08:43:41 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasmans.dll
[2010/01/28 08:43:41 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdchost.dll
[2010/01/28 08:43:41 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\powercfg.cpl
[2010/01/28 08:43:41 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rastls.dll
[2010/01/28 08:43:41 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rastls.dll
[2010/01/28 08:43:41 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\progman.exe
[2010/01/28 08:43:41 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\polstore.dll
[2010/01/28 08:43:41 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rcbdyctl.dll
[2010/01/28 08:43:41 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\psbase.dll
[2010/01/28 08:43:41 | 000,087,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpwsx.dll
[2010/01/28 08:43:41 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\olepro32.dll
[2010/01/28 08:43:41 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\proctexe.ocx
[2010/01/28 08:43:41 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\remotesp.tsp
[2010/01/28 08:43:41 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\raschap.dll
[2010/01/28 08:43:41 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\raschap.dll
[2010/01/28 08:43:41 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\osuninst.dll
[2010/01/28 08:43:41 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdshost.exe
[2010/01/28 08:43:41 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pautoenr.dll
[2010/01/28 08:43:41 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpclip.exe
[2010/01/28 08:43:41 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\resutils.dll
[2010/01/28 08:43:41 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\packager.exe
[2010/01/28 08:43:41 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasphone.exe
[2010/01/28 08:43:41 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\reg.exe
[2010/01/28 08:43:41 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\proquota.exe
[2010/01/28 08:43:41 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\regapi.dll
[2010/01/28 08:43:41 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\regapi.dll
[2010/01/28 08:43:41 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\racpldlg.dll
[2010/01/28 08:43:41 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pstorec.dll
[2010/01/28 08:43:41 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pstorec.dll
[2010/01/28 08:43:41 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rcimlby.exe
[2010/01/28 08:43:41 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rcimlby.exe
[2010/01/28 08:43:41 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pid.dll
[2010/01/28 08:43:41 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\perfproc.dll
[2010/01/28 08:43:41 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pstorsvc.dll
[2010/01/28 08:43:41 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\profmap.dll
[2010/01/28 08:43:41 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\perfdisk.dll
[2010/01/28 08:43:41 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\perfos.dll
[2010/01/28 08:43:41 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\psapi.dll
[2010/01/28 08:43:41 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rcp.exe
[2010/01/28 08:43:41 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qprocess.exe
[2010/01/28 08:43:41 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpsnd.dll
[2010/01/28 08:43:41 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qmgrprxy.dll
[2010/01/28 08:43:41 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qmgrprxy.dll
[2010/01/28 08:43:41 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ping.exe
[2010/01/28 08:43:41 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\powrprof.dll
[2010/01/28 08:43:41 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rassapi.dll
[2010/01/28 08:43:41 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\perfnet.dll
[2010/01/28 08:43:41 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\perfmon.exe
[2010/01/28 08:43:41 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pjlmon.dll
[2010/01/28 08:43:41 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rexec.exe
[2010/01/28 08:43:41 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdsaddin.exe
[2010/01/28 08:43:41 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\regsvr32.exe
[2010/01/28 08:43:41 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasadhlp.dll
[2010/01/28 08:43:41 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasadhlp.dll
[2010/01/28 08:43:40 | 008,454,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
[2010/01/28 08:43:40 | 001,580,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sfcfiles.dll
[2010/01/28 08:43:40 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shdocvw.dll
[2010/01/28 08:43:40 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2010/01/28 08:43:40 | 000,549,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shdoclc.dll
[2010/01/28 08:43:40 | 000,549,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shdoclc.dll
[2010/01/28 08:43:40 | 000,474,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shlwapi.dll
[2010/01/28 08:43:40 | 000,438,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shimgvw.dll
[2010/01/28 08:43:40 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smlogcfg.dll
[2010/01/28 08:43:40 | 000,313,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\scesrv.dll
[2010/01/28 08:43:40 | 000,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\scecli.dll
[2010/01/28 08:43:40 | 000,171,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sccsccp.dll
[2010/01/28 08:43:40 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\scrobj.dll
[2010/01/28 08:43:40 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rsaenh.dll
[2010/01/28 08:43:40 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rsaenh.dll
[2010/01/28 08:43:40 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scrrun.dll
[2010/01/28 08:43:40 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sfc_os.dll
[2010/01/28 08:43:40 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sfc_os.dll
[2010/01/28 08:43:40 | 000,134,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shsvcs.dll
[2010/01/28 08:43:40 | 000,098,304 | ---- | C] (Schlumberger Technology Corporation) -- C:\WINDOWS\System32\slbiop.dll
[2010/01/28 08:43:40 | 000,086,016 | ---- | C] (Sipro Lab Telecom Inc.) -- C:\WINDOWS\System32\sl_anet.acm
[2010/01/28 08:43:40 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shrpubw.exe
[2010/01/28 08:43:40 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sdbinst.exe
[2010/01/28 08:43:40 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rtcshare.exe
[2010/01/28 08:43:40 | 000,070,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sigverif.exe
[2010/01/28 08:43:40 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\scarddlg.dll
[2010/01/28 08:43:40 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shgina.dll
[2010/01/28 08:43:40 | 000,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shgina.dll
[2010/01/28 08:43:40 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shimeng.dll
[2010/01/28 08:43:40 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shimeng.dll
[2010/01/28 08:43:40 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\servdeps.dll
[2010/01/28 08:43:40 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\secur32.dll
[2010/01/28 08:43:40 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrslv.dll
[2010/01/28 08:43:40 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rtutils.dll
[2010/01/28 08:43:40 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rtutils.dll
[2010/01/28 08:43:40 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrcdlg.dll
[2010/01/28 08:43:40 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shmgrate.exe
[2010/01/28 08:43:40 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sens.dll
[2010/01/28 08:43:40 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rundll32.exe
[2010/01/28 08:43:40 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rtipxmib.dll
[2010/01/28 08:43:40 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sethc.exe
[2010/01/28 08:43:40 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrdm.dll
[2010/01/28 08:43:40 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sendcmsg.dll
[2010/01/28 08:43:40 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\skeys.exe
[2010/01/28 08:43:40 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shfolder.dll
[2010/01/28 08:43:40 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shfolder.dll
[2010/01/28 08:43:40 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\setup.exe
[2010/01/28 08:43:40 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sclgntfy.dll
[2010/01/28 08:43:40 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shutdown.exe
[2010/01/28 08:43:40 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rsmps.dll
[2010/01/28 08:43:40 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\simpdata.tlb
[2010/01/28 08:43:40 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rsh.exe
[2010/01/28 08:43:40 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\runonce.exe
[2010/01/28 08:43:40 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sigtab.dll
[2010/01/28 08:43:40 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\scrnsave.scr
[2010/01/28 08:43:40 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scrnsave.scr
[2010/01/28 08:43:40 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sensapi.dll
[2010/01/28 08:43:40 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sensapi.dll
[2010/01/28 08:43:40 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\security.dll
[2010/01/28 08:43:40 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\security.dll
[2010/01/28 08:43:40 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sfc.dll
[2010/01/28 08:43:40 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sfc.dll
[2010/01/28 08:43:39 | 000,858,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tapi3.dll
[2010/01/28 08:43:39 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sxs.dll
[2010/01/28 08:43:39 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sxs.dll
[2010/01/28 08:43:39 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ss3dfo.scr
[2010/01/28 08:43:39 | 000,679,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sstext3d.scr
[2010/01/28 08:43:39 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sspipes.scr
[2010/01/28 08:43:39 | 000,538,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spider.exe
[2010/01/28 08:43:39 | 000,442,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sqlsrv32.dll
[2010/01/28 08:43:39 | 000,393,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ssflwbox.scr
[2010/01/28 08:43:39 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srrstr.dll
[2010/01/28 08:43:39 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srrstr.dll
[2010/01/28 08:43:39 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sysmon.ocx
[2010/01/28 08:43:39 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\snmpsnap.dll
[2010/01/28 08:43:39 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tapi32.dll
[2010/01/28 08:43:39 | 000,181,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tapi32.dll
[2010/01/28 08:43:39 | 000,180,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sqlunirl.dll
[2010/01/28 08:43:39 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sti_ci.dll
[2010/01/28 08:43:39 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndrec32.exe
[2010/01/28 08:43:39 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\t2embed.dll
[2010/01/28 08:43:39 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\t2embed.dll
[2010/01/28 08:43:39 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sysocmgr.exe
[2010/01/28 08:43:39 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sqlsrv32.rll
[2010/01/28 08:43:39 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storprop.dll
[2010/01/28 08:43:39 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spoolss.dll
[2010/01/28 08:43:39 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sti.dll
[2010/01/28 08:43:39 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sti.dll
[2010/01/28 08:43:39 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\synceng.dll
[2010/01/28 08:43:39 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stclient.dll
[2010/01/28 08:43:39 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ssmypics.scr
[2010/01/28 08:43:39 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ssdpapi.dll
[2010/01/28 08:43:39 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sort.exe
[2010/01/28 08:43:39 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ssmarque.scr
[2010/01/28 08:43:39 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ssbezier.scr
[2010/01/28 08:43:39 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ssmyst.scr
[2010/01/28 08:43:39 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\snmpapi.dll
[2010/01/28 08:43:39 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stdole2.tlb
[2010/01/28 08:43:39 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\stdole2.tlb
[2010/01/28 08:43:39 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stimon.exe
[2010/01/28 08:43:39 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ssstars.scr
[2010/01/28 08:43:38 | 000,764,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winntbbu.dll
[2010/01/28 08:43:38 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\userenv.dll
[2010/01/28 08:43:38 | 000,577,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2010/01/28 08:43:38 | 000,463,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wiadefui.dll
[2010/01/28 08:43:38 | 000,433,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wiaacmgr.exe
[2010/01/28 08:43:38 | 000,430,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vssapi.dll
[2010/01/28 08:43:38 | 000,385,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\themeui.dll
[2010/01/28 08:43:38 | 000,358,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\termmgr.dll
[2010/01/28 08:43:38 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tourstart.exe
[2010/01/28 08:43:38 | 000,333,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiaservc.dll
[2010/01/28 08:43:38 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmstream.dll
[2010/01/28 08:43:38 | 000,292,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winsrv.dll
[2010/01/28 08:43:38 | 000,292,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winsrv.dll
[2010/01/28 08:43:38 | 000,278,559 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmv8ds32.ax
[2010/01/28 08:43:38 | 000,264,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wow32.dll
[2010/01/28 08:43:38 | 000,258,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmvds32.ax
[2010/01/28 08:43:38 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uxtheme.dll
[2010/01/28 08:43:38 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wavemsp.dll
[2010/01/28 08:43:38 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\unimdm.tsp
[2010/01/28 08:43:38 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\unimdm.tsp
[2010/01/28 08:43:38 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\upnphost.dll
[2010/01/28 08:43:38 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wintrust.dll
[2010/01/28 08:43:38 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winmm.dll
[2010/01/28 08:43:38 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wldap32.dll
[2010/01/28 08:43:38 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\webvw.dll
[2010/01/28 08:43:38 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\upnp.dll
[2010/01/28 08:43:38 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\upnp.dll
[2010/01/28 08:43:38 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wiadss.dll
[2010/01/28 08:43:38 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiadss.dll
[2010/01/28 08:43:38 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmsdmoe.dll
[2010/01/28 08:43:38 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wiavideo.dll
[2010/01/28 08:43:38 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\txflog.dll
[2010/01/28 08:43:38 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winscard.dll
[2010/01/28 08:43:38 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshom.ocx
[2010/01/28 08:43:38 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\timedate.cpl
[2010/01/28 08:43:38 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscfgwmi.dll
[2010/01/28 08:43:38 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tscfgwmi.dll
[2010/01/28 08:43:38 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ws2_32.dll
[2010/01/28 08:43:38 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\telnet.exe
[2010/01/28 08:43:38 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\telnet.exe
[2010/01/28 08:43:38 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usbui.dll
[2010/01/28 08:43:38 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbui.dll
[2010/01/28 08:43:38 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\unimdmat.dll
[2010/01/28 08:43:38 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\unimdmat.dll
[2010/01/28 08:43:38 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshext.dll
[2010/01/28 08:43:38 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wextract.exe
[2010/01/28 08:43:38 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wdigest.dll
[2010/01/28 08:43:38 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winsta.dll
[2010/01/28 08:43:38 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winsta.dll
[2010/01/28 08:43:38 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vfwwdm32.dll
[2010/01/28 08:43:38 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2010/01/28 08:43:38 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vdmredir.dll
[2010/01/28 08:43:38 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\utilman.exe
[2010/01/28 08:43:38 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\utilman.exe
[2010/01/28 08:43:38 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpmon.dll
[2010/01/28 08:43:38 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\umandlg.dll
[2010/01/28 08:43:38 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umandlg.dll
[2010/01/28 08:43:38 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winipsec.dll
[2010/01/28 08:43:38 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpnpinst.exe
[2010/01/28 08:43:38 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpabaln.exe
[2010/01/28 08:43:38 | 000,030,749 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vbajet32.dll
[2010/01/28 08:43:38 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vbisurf.ax
[2010/01/28 08:43:38 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshcon.dll
[2010/01/28 08:43:38 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vdmdbg.dll
[2010/01/28 08:43:38 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vdmdbg.dll
[2010/01/28 08:43:38 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\udhisapi.dll
[2010/01/28 08:43:38 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wdmaud.drv
[2010/01/28 08:43:38 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ws2help.dll
[2010/01/28 08:43:38 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\version.dll
[2010/01/28 08:43:38 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\watchdog.sys
[2010/01/28 08:43:38 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winrnr.dll
[2010/01/28 08:43:38 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usbmon.dll
[2010/01/28 08:43:38 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\upnpcont.exe
[2010/01/28 08:43:38 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpmib.dll
[2010/01/28 08:43:38 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wship6.dll
[2010/01/28 08:43:38 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wship6.dll
[2010/01/28 08:43:38 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\uniplat.dll
[2010/01/28 08:43:38 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uniplat.dll
[2010/01/28 08:43:38 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\verifier.dll
[2010/01/28 08:43:38 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tracert.exe
[2010/01/28 08:43:38 | 000,012,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsddd.dll
[2010/01/28 08:43:38 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshrm.dll
[2010/01/28 08:43:38 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tree.com
[2010/01/28 08:43:38 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmi.dll
[2010/01/28 08:43:38 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmi.dll
[2010/01/28 08:43:38 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winver.exe
[2010/01/28 08:43:37 | 000,986,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kernel32.dll
[2010/01/28 08:43:37 | 000,724,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\lsasrv.dll
[2010/01/28 08:43:37 | 000,724,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll
[2010/01/28 08:43:37 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/01/28 08:43:37 | 000,602,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\autoconv.exe
[2010/01/28 08:43:37 | 000,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cmd.exe
[2010/01/28 08:43:37 | 000,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.exe
[2010/01/28 08:43:37 | 000,378,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wzcdlg.dll
[2010/01/28 08:43:37 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\localspl.dll
[2010/01/28 08:43:37 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\localspl.dll
[2010/01/28 08:43:37 | 000,337,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zipfldr.dll
[2010/01/28 08:43:37 | 000,276,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comdlg32.dll
[2010/01/28 08:43:37 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imagehlp.dll
[2010/01/28 08:43:37 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\desk.cpl
[2010/01/28 08:43:37 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\desk.cpl
[2010/01/28 08:43:37 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msv1_0.dll
[2010/01/28 08:43:37 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dhcpcsvc.dll
[2010/01/28 08:43:37 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactsrv.dll
[2010/01/28 08:43:37 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xactsrv.dll
[2010/01/28 08:43:37 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nslookup.exe
[2010/01/28 08:43:37 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wzcsapi.dll
[2010/01/28 08:43:37 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wstdecod.dll
[2010/01/28 08:43:37 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wsnmp32.dll
[2010/01/28 08:43:37 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ftp.exe
[2010/01/28 08:43:37 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\csrsrv.dll
[2010/01/28 08:43:37 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xcopy.exe
[2010/01/28 08:43:37 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\format.com
[2010/01/28 08:43:37 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wsock32.dll
[2010/01/28 08:43:37 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wsock32.dll
[2010/01/28 08:43:37 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshtcpip.dll
[2010/01/28 08:43:37 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshtcpip.dll
[2010/01/28 08:43:37 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wtsapi32.dll
[2010/01/28 08:43:37 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wtsapi32.dll
[2010/01/28 08:43:37 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cacls.exe
[2010/01/28 08:43:37 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mgmtapi.dll
[2010/01/28 08:43:37 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xolehlp.dll
[2010/01/28 08:43:36 | 001,850,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys
[2010/01/28 08:43:36 | 001,850,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
[2010/01/28 08:43:36 | 000,984,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\syssetup.dll
[2010/01/28 08:43:36 | 000,983,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\setupapi.dll
[2010/01/28 08:43:36 | 000,657,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasdlg.dll
[2010/01/28 08:43:36 | 000,657,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasdlg.dll
[2010/01/28 08:43:36 | 000,560,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printui.dll
[2010/01/28 08:43:36 | 000,550,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oleaut32.dll
[2010/01/28 08:43:36 | 000,419,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntvdm.exe
[2010/01/28 08:43:36 | 000,415,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\samsrv.dll
[2010/01/28 08:43:36 | 000,316,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\untfs.dll
[2010/01/28 08:43:36 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ulib.dll
[2010/01/28 08:43:36 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasapi32.dll
[2010/01/28 08:43:36 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasapi32.dll
[2010/01/28 08:43:36 | 000,187,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\acpi.sys
[2010/01/28 08:43:36 | 000,179,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxdav.sys
[2010/01/28 08:43:36 | 000,172,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kmixer.sys
[2010/01/28 08:43:36 | 000,168,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\schannel.dll
[2010/01/28 08:43:36 | 000,153,344 | ---- | C] (Microsoft Corp., Veritas Software) -- C:\WINDOWS\System32\dllcache\dmio.sys
[2010/01/28 08:43:36 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winspool.drv
[2010/01/28 08:43:36 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\winspool.drv
[2010/01/28 08:43:36 | 000,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastfat.sys
[2010/01/28 08:43:36 | 000,142,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aec.sys
[2010/01/28 08:43:36 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nwprovau.dll
[2010/01/28 08:43:36 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nwprovau.dll
[2010/01/28 08:43:36 | 000,140,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ks.sys
[2010/01/28 08:43:36 | 000,140,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ks.sys
[2010/01/28 08:43:36 | 000,138,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\afd.sys
[2010/01/28 08:43:36 | 000,134,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipnat.sys
[2010/01/28 08:43:36 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wkssvc.dll
[2010/01/28 08:43:36 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\win32spl.dll
[2010/01/28 08:43:36 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srvsvc.dll
[2010/01/28 08:43:36 | 000,095,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\atapi.sys
[2010/01/28 08:43:36 | 000,092,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksecdd.sys
[2010/01/28 08:43:36 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntprint.dll
[2010/01/28 08:43:36 | 000,071,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxg.sys
[2010/01/28 08:43:36 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\samlib.dll
[2010/01/28 08:43:36 | 000,063,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mf.sys
[2010/01/28 08:43:36 | 000,063,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdfs.sys
[2010/01/28 08:43:36 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasman.dll
[2010/01/28 08:43:36 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rasman.dll
[2010/01/28 08:43:36 | 000,060,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys
[2010/01/28 08:43:36 | 000,060,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmk.sys
[2010/01/28 08:43:36 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rastapi.dll
[2010/01/28 08:43:36 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rastapi.dll
[2010/01/28 08:43:36 | 000,055,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atmlane.sys
[2010/01/28 08:43:36 | 000,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dmusic.sys
[2010/01/28 08:43:36 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\classpnp.sys
[2010/01/28 08:43:36 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\classpnp.sys
[2010/01/28 08:43:36 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpmonui.dll
[2010/01/28 08:43:36 | 000,042,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mountmgr.sys
[2010/01/28 08:43:36 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rshx32.dll
[2010/01/28 08:43:36 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\perfctrs.dll
[2010/01/28 08:43:36 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\olecnv32.dll
[2010/01/28 08:43:36 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\olecnv32.dll
[2010/01/28 08:43:36 | 000,036,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\amdk6.sys
[2010/01/28 08:43:36 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\disk.sys
[2010/01/28 08:43:36 | 000,036,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidclass.sys
[2010/01/28 08:43:36 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isapnp.sys
[2010/01/28 08:43:36 | 000,030,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\modem.sys
[2010/01/28 08:43:36 | 000,024,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidparse.sys
[2010/01/28 08:43:36 | 000,018,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\i2omp.sys
[2010/01/28 08:43:36 | 000,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ccdecode.sys
[2010/01/28 08:43:36 | 000,014,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\diskdump.sys
[2010/01/28 08:43:36 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\savedump.exe
[2010/01/28 08:43:36 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntlsapi.dll
[2010/01/28 08:43:36 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntlsapi.dll
[2010/01/28 08:43:36 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\intelide.sys
[2010/01/28 08:43:36 | 000,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmkaud.sys
[2010/01/28 08:43:35 | 002,136,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntoskrnl.exe
[2010/01/28 08:43:35 | 002,015,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntkrnlpa.exe
[2010/01/28 08:43:35 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntfs.sys
[2010/01/28 08:43:35 | 000,453,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2010/01/28 08:43:35 | 000,364,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\update.sys
[2010/01/28 08:43:35 | 000,360,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip.sys
[2010/01/28 08:43:35 | 000,333,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
[2010/01/28 08:43:35 | 000,225,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tcpip6.sys
[2010/01/28 08:43:35 | 000,225,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip6.sys
[2010/01/28 08:43:35 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rmcast.sys
[2010/01/28 08:43:35 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rmcast.sys
[2010/01/28 08:43:35 | 000,182,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndis.sys
[2010/01/28 08:43:35 | 000,174,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdbss.sys
[2010/01/28 08:43:35 | 000,145,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\portcls.sys
[2010/01/28 08:43:35 | 000,145,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\portcls.sys
[2010/01/28 08:43:35 | 000,142,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbport.sys
[2010/01/28 08:43:35 | 000,142,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbport.sys
[2010/01/28 08:43:35 | 000,134,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hal.dll
[2010/01/28 08:43:35 | 000,107,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mup.sys
[2010/01/28 08:43:35 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\scsiport.sys
[2010/01/28 08:43:35 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiport.sys
[2010/01/28 08:43:35 | 000,088,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nwlnkipx.sys
[2010/01/28 08:43:35 | 000,085,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nabtsfec.sys
[2010/01/28 08:43:35 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wdmaud.sys
[2010/01/28 08:43:35 | 000,079,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\videoprt.sys
[2010/01/28 08:43:35 | 000,073,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sr.sys
[2010/01/28 08:43:35 | 000,068,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pci.sys
[2010/01/28 08:43:35 | 000,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sysaudio.sys
[2010/01/28 08:43:35 | 000,057,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbhub.sys
[2010/01/28 08:43:35 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swmidi.sys
[2010/01/28 08:43:35 | 000,052,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\volsnap.sys
[2010/01/28 08:43:35 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\stream.sys
[2010/01/28 08:43:35 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\stream.sys
[2010/01/28 08:43:35 | 000,040,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nmnt.sys
[2010/01/28 08:43:35 | 000,034,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netbios.sys
[2010/01/28 08:43:35 | 000,030,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\npfs.sys
[2010/01/28 08:43:35 | 000,030,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismp.sys
[2010/01/28 08:43:35 | 000,026,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/01/28 08:43:35 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys
[2010/01/28 08:43:35 | 000,025,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sonydcam.sys
[2010/01/28 08:43:35 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\pciidex.sys
[2010/01/28 08:43:35 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pciidex.sys
[2010/01/28 08:43:35 | 000,023,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbcamd2.sys
[2010/01/28 08:43:35 | 000,023,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbcamd.sys
[2010/01/28 08:43:35 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbuhci.sys
[2010/01/28 08:43:35 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wstcodec.sys
[2010/01/28 08:43:35 | 000,019,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfs.sys
[2010/01/28 08:43:35 | 000,018,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\partmgr.sys
[2010/01/28 08:43:35 | 000,018,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tdi.sys
[2010/01/28 08:43:35 | 000,018,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdi.sys
[2010/01/28 08:43:35 | 000,016,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbintel.sys
[2010/01/28 08:43:35 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\streamip.sys
[2010/01/28 08:43:35 | 000,014,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tape.sys
[2010/01/28 08:43:35 | 000,012,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023.sys
[2010/01/28 08:43:35 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\slip.sys
[2010/01/28 08:43:35 | 000,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndisip.sys
[2010/01/28 08:43:35 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mskssrv.sys
[2010/01/28 08:43:35 | 000,006,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\splitter.sys
[2010/01/28 08:43:35 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstee.sys
[2010/01/28 08:43:35 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\viaide.sys
[2010/01/28 08:43:35 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspclock.sys
[2010/01/28 08:43:35 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspqm.sys
[2010/01/27 13:36:44 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/01/27 12:18:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/01/27 12:18:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Maloy\Application Data\SUPERAntiSpyware.com
[2010/01/27 12:18:04 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/01/18 08:41:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\pic 32
[2009/12/08 08:36:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2009/11/03 08:08:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Temp
[2009/06/24 07:05:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/06/22 13:22:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/07/15 15:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2008/07/15 15:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
[2007/07/03 15:18:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\assembly
[2006/10/10 11:10:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\ApplicationHistory
[2005/10/21 13:17:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\AdobeUM
[2005/10/21 12:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2005/10/21 12:22:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2005/02/10 16:42:56 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2004/12/21 22:41:12 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2004/12/21 22:41:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[1980/01/01 00:00:00 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Maloy\*.tmp files -> C:\Documents and Settings\Maloy\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/02/16 14:03:05 | 019,136,512 | -H-- | M] () -- C:\Documents and Settings\Maloy\NTUSER.DAT
[2010/02/16 14:00:08 | 000,007,275 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/02/16 13:57:57 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/16 13:57:54 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/02/16 13:57:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/02/16 13:56:48 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Maloy\NTUSER.INI
[2010/02/16 13:56:44 | 002,115,736 | -H-- | M] () -- C:\Documents and Settings\Maloy\Local Settings\Application Data\IconCache.db
[2010/02/16 13:24:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/15 16:43:59 | 000,240,128 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\Time.xls
[2010/02/15 14:13:49 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Maloy\Desktop\OTL.exe
[2010/02/15 13:47:46 | 000,000,711 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/15 13:45:02 | 005,115,824 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Maloy\Desktop\mbam-setup.exe
[2010/02/15 08:55:50 | 000,152,714 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\tdsskiller.zip
[2010/02/10 15:33:09 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/02/10 15:27:01 | 000,137,728 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\Tims Scale application data.xls
[2010/02/10 13:22:48 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/02/09 15:17:31 | 000,000,022 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2010/02/09 14:58:12 | 000,000,281 | RHS- | M] () -- C:\BOOT.INI
[2010/02/09 14:48:06 | 003,852,756 | R--- | M] () -- C:\Documents and Settings\Maloy\Desktop\schrauber.exe
[2010/02/08 12:06:14 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe
[2010/02/05 14:48:48 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010/02/05 13:44:15 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/02/04 14:34:32 | 000,175,880 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\Maloy\Desktop\TDSSKiller.exe
[2010/02/04 08:39:53 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2010/02/02 15:00:54 | 000,110,798 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\ABI_BB_vs_Rugged_TCO.pdf
[2010/02/02 14:55:45 | 002,688,737 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\bwmanual2009.pdf
[2010/02/02 12:35:30 | 000,250,368 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\drivers\iaStor.sys
[2010/01/28 15:39:08 | 000,001,980 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/01/28 14:11:57 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/01/28 14:11:57 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/01/28 14:09:03 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/01/28 13:58:35 | 000,250,032 | ---- | M] () -- C:\ntldr
[2010/01/28 13:34:44 | 000,541,992 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/01/27 13:36:45 | 000,000,856 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
[2010/01/27 13:29:34 | 000,001,749 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\HijackThis.lnk
[2010/01/27 13:12:14 | 002,919,582 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\taskmgr.bmp
[2010/01/27 12:18:06 | 000,000,795 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/01/22 14:07:38 | 000,002,351 | ---- | M] () -- C:\Documents and Settings\Maloy\Desktop\Adobe Acrobat 6.0 Professional.lnk
[2010/01/20 14:00:59 | 000,000,832 | ---- | M] () -- C:\WINDOWS\dellstat.ini
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Maloy\*.tmp files -> C:\Documents and Settings\Maloy\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/15 13:47:46 | 000,000,711 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/15 08:58:28 | 000,152,714 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\tdsskiller.zip
[2010/02/09 14:58:11 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/02/09 14:58:05 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/02/09 14:55:49 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/02/09 14:55:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/02/09 14:55:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/02/09 14:55:49 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/02/09 14:55:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/02/09 14:48:06 | 003,852,756 | R--- | C] () -- C:\Documents and Settings\Maloy\Desktop\schrauber.exe
[2010/02/08 12:16:26 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\0j5w0o85.exe
[2010/02/04 08:39:53 | 000,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2010/02/04 08:39:53 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2010/02/02 15:00:54 | 000,110,798 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\ABI_BB_vs_Rugged_TCO.pdf
[2010/02/02 14:55:45 | 002,688,737 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\bwmanual2009.pdf
[2010/01/28 15:39:08 | 000,001,980 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/01/28 08:44:36 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010/01/28 08:44:01 | 000,239,616 | ---- | C] () -- C:\WINDOWS\System32\wstrenderer.ax
[2010/01/28 08:44:01 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\wstpager.ax
[2010/01/28 08:44:00 | 000,118,272 | ---- | C] () -- C:\WINDOWS\System32\mpeg2data.ax
[2010/01/28 08:43:56 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\vbicodec.ax
[2010/01/28 08:43:56 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vbicodec.ax
[2010/01/28 08:43:55 | 000,764,868 | ---- | C] () -- C:\WINDOWS\System32\dllcache\apph_sp.sdb
[2010/01/28 08:43:52 | 000,217,118 | ---- | C] () -- C:\WINDOWS\System32\dllcache\apphelp.sdb
[2010/01/28 08:43:52 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2010/01/28 08:43:49 | 000,460,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\micross.ttf
[2010/01/28 08:43:49 | 000,383,140 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tahoma.ttf
[2010/01/28 08:43:49 | 000,355,436 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tahomabd.ttf
[2010/01/28 08:43:47 | 000,252,928 | ---- | C] () -- C:\WINDOWS\System32\dllcache\compatui.dll
[2010/01/28 08:43:46 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\dllcache\devenum.dll
[2010/01/28 08:43:46 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2010/01/28 08:43:45 | 000,498,742 | ---- | C] () -- C:\WINDOWS\System32\dllcache\dxmasf.dll
[2010/01/28 08:43:43 | 000,844,314 | ---- | C] () -- C:\WINDOWS\System32\msdxm.ocx
[2010/01/28 08:43:43 | 000,148,992 | ---- | C] () -- C:\WINDOWS\System32\mpg2splt.ax
[2010/01/28 08:43:43 | 000,014,336 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdmo.dll
[2010/01/28 08:43:42 | 000,004,310 | ---- | C] () -- C:\WINDOWS\System32\odbcconf.rsp
[2010/01/28 08:43:41 | 001,290,752 | ---- | C] () -- C:\WINDOWS\System32\dllcache\quartz.dll
[2010/01/28 08:43:37 | 000,249,270 | ---- | C] () -- C:\WINDOWS\System32\locale.nls
[2010/01/28 08:43:37 | 000,249,270 | ---- | C] () -- C:\WINDOWS\System32\dllcache\locale.nls
[2010/01/28 08:43:37 | 000,009,424 | ---- | C] () -- C:\WINDOWS\System32\dllcache\drvmain.sdb
[2010/01/28 08:43:36 | 000,105,472 | R--- | C] () -- C:\WINDOWS\System32\lowsec.exe
[2010/01/28 08:43:36 | 000,022,040 | ---- | C] () -- C:\WINDOWS\System32\sorttbls.nls
[2010/01/28 08:43:36 | 000,022,040 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sorttbls.nls
[2010/01/28 08:43:35 | 000,250,032 | ---- | C] () -- C:\ntldr
[2010/01/27 13:36:45 | 000,000,856 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware SE Personal.lnk
[2010/01/27 13:29:34 | 000,001,749 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\HijackThis.lnk
[2010/01/27 13:12:14 | 002,919,582 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\taskmgr.bmp
[2010/01/27 12:18:06 | 000,000,795 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/01/22 14:07:38 | 000,002,351 | ---- | C] () -- C:\Documents and Settings\Maloy\Desktop\Adobe Acrobat 6.0 Professional.lnk
[2009/03/23 12:44:22 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\MPMapTrace.dll
[2009/03/23 12:09:28 | 000,364,544 | ---- | C] () -- C:\WINDOWS\System32\mpPathan.dll
[2009/03/17 08:31:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2008/12/01 17:17:39 | 000,000,067 | ---- | C] () -- C:\WINDOWS\Apollo DVD Copy.INI
[2008/10/02 07:51:30 | 000,000,018 | -HS- | C] () -- C:\WINDOWS\WINPROD.DLL
[2008/07/09 07:27:50 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/13 15:41:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\uwzfqas.sys
[2008/04/17 13:36:40 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/03/18 16:18:42 | 000,000,180 | ---- | C] () -- C:\WINDOWS\ImgTool.INI
[2007/10/11 10:23:42 | 000,000,385 | ---- | C] () -- C:\Program Files\DeaInstall.log
[2007/10/09 07:46:22 | 000,000,184 | ---- | C] () -- C:\WINDOWS\bti.ini
[2007/10/09 07:43:41 | 000,000,190 | ---- | C] () -- C:\Program Files\Common Files\psasetup.log
[2007/10/09 07:43:29 | 000,043,760 | ---- | C] () -- C:\WINDOWS\System32\nwlocale.dll
[2007/09/17 10:27:42 | 000,000,075 | ---- | C] () -- C:\WINDOWS\hdkctnts.ini
[2007/09/17 10:26:50 | 000,000,165 | ---- | C] () -- C:\WINDOWS\HOFFMAN.Ini
[2007/08/09 11:08:04 | 000,008,784 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/07/03 15:18:27 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\fusioncache.dat
[2006/12/13 15:03:14 | 000,074,240 | ---- | C] () -- C:\WINDOWS\System32\zlibwapi.dll
[2006/11/16 14:34:53 | 000,000,032 | ---- | C] () -- C:\WINDOWS\concentr.ini
[2006/11/16 14:34:31 | 000,000,058 | ---- | C] () -- C:\WINDOWS\webica.ini
[2006/10/22 12:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 12:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/10/10 16:07:36 | 000,000,126 | ---- | C] () -- C:\WINDOWS\CTWave32.ini
[2006/07/11 11:13:45 | 000,000,041 | ---- | C] () -- C:\WINDOWS\System32\aefdfed1_s.dll
[2005/11/11 15:24:12 | 000,000,114 | ---- | C] () -- C:\WINDOWS\SRCEDIT.INI
[2005/11/08 14:52:24 | 000,000,137 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2005/09/02 09:37:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\csmain.INI
[2005/09/02 09:37:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\esmain.INI
[2005/09/02 09:36:37 | 000,003,422 | ---- | C] () -- C:\WINDOWS\DS300.INI
[2005/09/01 10:29:12 | 000,159,744 | ---- | C] () -- C:\WINDOWS\_isusr32.dll
[2005/09/01 10:29:09 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\ush2.dll
[2005/09/01 10:29:09 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\_isusr2k.dll
[2005/08/02 15:24:01 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2005/03/19 16:21:47 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\Maloy\Application Data\PFP120JPR.{PB
[2005/03/19 16:21:47 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\Maloy\Application Data\PFP120JCM.{PB
[2005/02/24 13:35:29 | 000,002,452 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/02/24 13:35:29 | 000,000,185 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2005/02/24 13:35:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2005/02/23 10:00:51 | 000,000,832 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/02/23 09:08:27 | 000,006,996 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2005/01/19 15:59:28 | 000,016,896 | ---- | C] () -- C:\Documents and Settings\Maloy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/19 15:41:02 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Maloy\Local Settings\Application Data\fusioncache.dat
[2005/01/19 15:34:38 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2004/12/21 23:07:47 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/12/21 23:02:48 | 000,000,331 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/12/21 22:58:53 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2004/12/21 22:58:45 | 000,003,278 | ---- | C] () -- C:\WINDOWS\System32\LudaP17.ini
[2004/12/21 22:58:45 | 000,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2004/12/21 22:58:40 | 000,000,072 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2004/12/21 22:41:42 | 000,000,517 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/09/15 22:03:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/11 17:25:56 | 000,000,890 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/05/12 19:56:36 | 000,634,880 | ---- | C] () -- C:\WINDOWS\System32\pemicro_serialcm2.dll
[2004/02/10 13:08:00 | 000,000,373 | ---- | C] () -- C:\WINDOWS\System32\dlbccoin.ini
[2002/11/13 13:40:22 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbcvs.dll
[2002/02/19 18:48:16 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\lxaxlcnp.dll
[2000/09/18 16:50:28 | 000,202,752 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2000/08/03 13:25:12 | 000,023,296 | ---- | C] () -- C:\WINDOWS\System32\pedrv.sys
[2000/08/03 13:25:12 | 000,023,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\pedrv.sys
[1999/01/22 12:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/10/02 09:20:46 | 000,005,200 | ---- | C] () -- C:\WINDOWS\System32\drivers\vichw11.sys
[1998/06/09 23:00:00 | 000,015,120 | ---- | C] () -- C:\WINDOWS\System32\REPUTIL.DLL
[1998/05/17 23:00:00 | 000,014,017 | ---- | C] () -- C:\WINDOWS\JAUTOEXP.INI
[1998/04/24 00:00:00 | 000,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI
[1998/01/11 19:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL
[1996/05/29 16:20:04 | 000,035,072 | ---- | C] () -- C:\WINDOWS\System32\SENDKEY.DLL
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\GIVEIO.SYS
[1980/01/01 00:00:00 | 000,060,928 | ---- | C] () -- C:\WINDOWS\System32\P17.dll
[1980/01/01 00:00:00 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\P17CPI.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3BF268CC
< End of report >





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users