Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
HijackThis Log for reviewal, please if anyone has time. [RESOLVED], Pop up ads in IE, slower start up, desktop appearance off
geminis076
post Jan 7 2008, 03:53 PM
Post #1


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Hello, I just resolved an infection earlier in the year (well 2007), but unfortunately I share my computer with 2 others and LimeWire was recently downloaded >=| - has been uninstalled. Think it left a parting gift because some familiar things are starting to pop-up, like IE ads, slower start-up, and the desktop appearance is looking a little off. I'm working with FireFox, ads are coming up as Internet Explorer. Here's my log, hope someone can look it over, thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:52:14 PM, on 1/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Canon\BJPV\TVMon.exe
C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\DELL\HIGH SPEED INTERNET OFFERS\CONSUMER\STYLES\MPS\MORPHEUS\DOWNLOADS\DriveIcons\ImgIcon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes2\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\mrofinu1188.exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\kernel\kernel.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\eFax Messenger 4.1\J2GTray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 15\minimavis.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\DELL\HIGH SPEED INTERNET OFFERS\CONSUMER\STYLES\MPS\MORPHEUS\DOWNLOADS\DriveIcons\ImgIcon .exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon .exe
C:\Program Files\eFax Messenger 4.1\J2GDllCmd .exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP .exe
C:\Program Files\Canon\BJPV\TVMon .exe
C:\Program Files\BroadJump\Client Foundation\CFD .exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon .exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\mcafee.com\agent\mcagent .exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld .exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Media Experience\PCMService .exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray .exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
C:\Program Files\iTunes2\iTunesHelper .exe
C:\WINDOWS\mrofinu1188 .exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\Fonts\svchost .exe
C:\Program Files\kernel\kernel .exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
C:\WINDOWS\Fonts\svchost .exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F3 - REG:win.ini: load=C:\WINDOWS\system32\awvtu.exe
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [BJPD HID Control] C:\Program Files\Canon\BJPV\TVMon.exe
O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\DELL\HIGH SPEED INTERNET OFFERS\CONSUMER\STYLES\MPS\MORPHEUS\DOWNLOADS\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\DELL\HIGH SPEED INTERNET OFFERS\CONSUMER\STYLES\MPS\MORPHEUS\DOWNLOADS\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes2\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm .exe"
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kernel] C:\Program Files\kernel\kernel.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Personal Coach.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://img.member.yahoo.com/dl/atty/yinst_current.cab
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/assets/activ...ALStreaming.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-17.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._2/axofupld.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bmF0YWxpZQ\command.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\profsyz.html
O24 - Desktop Component 1: (no name) - http://www.vzwpix.com/mi/11230497_45874273...;border=2,0,0,0

--
End of file - 13240 bytes


Go to the top of the page
 
+Quote Post
5 Pages V  < 1 2 3 4 5 >  
Start new topic
Replies (30 - 44)
geminis076
post Jan 14 2008, 12:58 AM
Post #31


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Hi, did about 2 hours of browsing [well I had a little help tongue.gif] and 22 pop ups came in. Desktop appearance and reboot (from Combo Fix) still seem really good.
Go to the top of the page
 
+Quote Post
Stamper19
post Jan 14 2008, 07:24 AM
Post #32


Trusted Helper
Group Icon
Posts: 1,991
OS: Windows XP



That combofix log was cut off...can you try reposting?
Go to the top of the page
 
+Quote Post
geminis076
post Jan 14 2008, 05:11 PM
Post #33


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Hi. Sorry about that, I promise I am double checking things before posting. I only submit once I'm sure everything is there, so I'm not quite sure what's going on. Something seems to be changing between preview and submit, even then I thought I'd been checking the submitted post but I'll be more careful to double check things.

----------------------

Quick update: Okay, I see what's going on now. "Preview Post" does display everything, but for some reason once submitted the contents get cut off. I still thought I had been double checking the submitted posts, but I'll check thing more closely.

Here's part 1 :

ComboFix 08-01-09.2 - natalie 2008-01-13 20:17:40.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.187 [GMT -8:00]
Running from: C:\Documents and Settings\natalie\Desktop\Geeks_2_Go\ComboFix.exe
Command switches used :: C:\Documents and Settings\natalie\Desktop\Geeks_2_Go\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\inf\1394.INF
c:\windows\inf\1394.PNF
c:\windows\inf\1394VDBG.INF
c:\windows\inf\1394VDBG.PNF
c:\windows\inf\3DFXVS2K.INF
c:\windows\inf\3DFXVS2K.PNF
c:\windows\inf\61883.INF
c:\windows\inf\61883.PNF
c:\windows\inf\ACCESSOR.INF
c:\windows\inf\accessor.PNF
c:\windows\inf\ACERSCAN.INF
c:\windows\inf\ACERSCAN.PNF
c:\windows\inf\ACPI.INF
c:\windows\inf\acpi.PNF
c:\windows\inf\ADM_MULT.INF
c:\windows\inf\ADM_MULT.PNF
c:\windows\inf\ADM_PORT.INF
c:\windows\inf\ADM_PORT.PNF
c:\windows\inf\AGP.INF
c:\windows\inf\AGP.PNF
c:\windows\inf\AGTINST.INF
c:\windows\inf\AGTINST.PNF
c:\windows\inf\APCOMPAT.INF
c:\windows\inf\APCOMPAT.PNF
c:\windows\inf\APPMIG.INF
c:\windows\inf\APPMIG.PNF
c:\windows\inf\APPS.INF
c:\windows\inf\APPS.PNF
c:\windows\inf\ASYNCEQN.INF
c:\windows\inf\ASYNCEQN.PNF
c:\windows\inf\ATI1XWDM.INF
c:\windows\inf\ATI1XWDM.PNF
c:\windows\inf\ATIIXPAA.INF
c:\windows\inf\ATIIXPAA.PNF
c:\windows\inf\ATIIXPAG.INF
c:\windows\inf\ATIIXPAG.PNF
c:\windows\inf\ATIM128.INF
c:\windows\inf\ATIM128.PNF
c:\windows\inf\ATIMPAB.INF
c:\windows\inf\ATIMPAB.PNF
c:\windows\inf\ATIRAGE3.INF
c:\windows\inf\ATIRAGE3.PNF
c:\windows\inf\ATIVIDIN.INF
c:\windows\inf\ATIVIDIN.PNF
c:\windows\inf\ATIXPWDM.INF
c:\windows\inf\ATIXPWDM.PNF
c:\windows\inf\AU.INF
c:\windows\inf\AU.PNF
c:\windows\inf\AVC.INF
c:\windows\inf\AVC.PNF
c:\windows\inf\AVMISDN.INF
c:\windows\inf\AVMISDN.PNF
c:\windows\inf\AXANT5.INF
c:\windows\inf\AXANT5.PNF
c:\windows\inf\BANSHEE.INF
c:\windows\inf\BANSHEE.PNF
c:\windows\inf\BATTERY.INF
c:\windows\inf\BATTERY.PNF
c:\windows\inf\BDA.INF
c:\windows\inf\BDA.PNF
c:\windows\inf\BIOSINFO.INF
c:\windows\inf\BIOSINFO.PNF
c:\windows\inf\branches.inf
c:\windows\inf\branches.PNF
c:\windows\inf\BRMFCMDM.INF
c:\windows\inf\BRMFCMDM.PNF
c:\windows\inf\BRMFCMF.INF
c:\windows\inf\BRMFCMF.PNF
c:\windows\inf\BRMFCSTO.INF
c:\windows\inf\BRMFCSTO.PNF
c:\windows\inf\BRMFCUMD.INF
c:\windows\inf\BRMFCUMD.PNF
c:\windows\inf\BRMFCWIA.INF
c:\windows\inf\BRMFCWIA.PNF
c:\windows\inf\BRMFPORT.INF
c:\windows\inf\BRMFPORT.PNF
c:\windows\inf\BTH.INF
c:\windows\inf\BTH.PNF
c:\windows\inf\BTHPAN.INF
c:\windows\inf\BTHPAN.PNF
c:\windows\inf\BTHPRINT.INF
c:\windows\inf\BTHPRINT.PNF
c:\windows\inf\BTHSPP.INF
c:\windows\inf\BTHSPP.PNF
c:\windows\inf\CAMDSH20.INF
c:\windows\inf\CAMDSH20.PNF
c:\windows\inf\CAMVID20.INF
c:\windows\inf\CAMVID20.PNF
c:\windows\inf\CAMVID30.INF
c:\windows\inf\CAMVID30.PNF
c:\windows\inf\CCDECODE.INF
c:\windows\inf\CCDECODE.PNF
c:\windows\inf\CDROM.INF
c:\windows\inf\cdrom.PNF
c:\windows\inf\CERTCLAS.INF
c:\windows\inf\certclas.PNF
c:\windows\inf\codecs10.inf
c:\windows\inf\codecs10.PNF
c:\windows\inf\COMMUNIC.INF
c:\windows\inf\communic.PNF
c:\windows\inf\COMNT5.INF
c:\windows\inf\comnt5.PNF
c:\windows\inf\CORELIST.INF
c:\windows\inf\CORELIST.PNF
c:\windows\inf\CPU.INF
c:\windows\inf\cpu.PNF
c:\windows\inf\CTMAPORT.INF
c:\windows\inf\CTMAPORT.PNF
c:\windows\inf\CYCLAD-Z.INF
c:\windows\inf\CYCLAD-Z.PNF
c:\windows\inf\CYCLOM-Y.INF
c:\windows\inf\CYCLOM-Y.PNF
c:\windows\inf\CYYPORT.INF
c:\windows\inf\CYYPORT.PNF
c:\windows\inf\CYZPORT.INF
c:\windows\inf\CYZPORT.PNF
c:\windows\inf\DEFLTWK.INF
c:\windows\inf\defltwk.PNF
c:\windows\inf\DEVXPROP.INF
c:\windows\inf\DEVXPROP.PNF
c:\windows\inf\DFRG.INF
c:\windows\inf\DFRG.PNF
c:\windows\inf\DGAPORT.INF
c:\windows\inf\DGAPORT.PNF
c:\windows\inf\DGASYNC.INF
c:\windows\inf\DGASYNC.PNF
c:\windows\inf\DIGIASYN.INF
c:\windows\inf\DIGIASYN.PNF
c:\windows\inf\DIGIISDN.INF
c:\windows\inf\DIGIISDN.PNF
c:\windows\inf\DIGIMPS.INF
c:\windows\inf\DIGIMPS.PNF
c:\windows\inf\DIGIRP.INF
c:\windows\inf\DIGIRP.PNF
c:\windows\inf\DIGIRPRT.INF
c:\windows\inf\DIGIRPRT.PNF
c:\windows\inf\DIMAPS.INF
c:\windows\inf\DIMAPS.PNF
c:\windows\inf\DISK.INF
c:\windows\inf\disk.PNF
c:\windows\inf\DISPLAY.INF
c:\windows\inf\DISPLAY.PNF
c:\windows\inf\DIVAC.INF
c:\windows\inf\DIVAC.PNF
c:\windows\inf\DIVASRV.INF
c:\windows\inf\DIVASRV.PNF
c:\windows\inf\DOT4.INF
c:\windows\inf\DOT4.PNF
c:\windows\inf\DOT4PRT.INF
c:\windows\inf\DOT4PRT.PNF
c:\windows\inf\DRM.INF
c:\windows\inf\DRM.PNF
c:\windows\inf\DRM10.inf
c:\windows\inf\DRM10.PNF
c:\windows\inf\DRVINDEX.INF
c:\windows\inf\drvindex.PNF
c:\windows\inf\DSHOWEXT.INF
c:\windows\inf\DSHOWEXT.PNF
c:\windows\inf\DTCNT5.INF
c:\windows\inf\dtcnt5.PNF
c:\windows\inf\DVD.INF
c:\windows\inf\DVD.PNF
c:\windows\inf\DWUP.INF
c:\windows\inf\DWUP.PNF
c:\windows\inf\ENUM1394.INF
c:\windows\inf\ENUM1394.PNF
c:\windows\inf\EPCFW2K.INF
c:\windows\inf\EPCFW2K.PNF
c:\windows\inf\EPSNMFP.INF
c:\windows\inf\EPSNMFP.PNF
c:\windows\inf\EPSNSCAN.INF
c:\windows\inf\EPSNSCAN.PNF
c:\windows\inf\EPSTW2K.INF
c:\windows\inf\EPSTW2K.PNF
c:\windows\inf\EQNPORT.INF
c:\windows\inf\EQNPORT.PNF
c:\windows\inf\Erma.inf
c:\windows\inf\Erma.PNF
c:\windows\inf\FDC.INF
c:\windows\inf\FDC.PNF
c:\windows\inf\fhg.inf
c:\windows\inf\fhg.PNF
c:\windows\inf\FJTSCAN.INF
c:\windows\inf\FJTSCAN.PNF
c:\windows\inf\FLASH.INF
c:\windows\inf\FLASH.PNF
c:\windows\inf\FLPYDISK.INF
c:\windows\inf\FLPYDISK.PNF
c:\windows\inf\FLTMGR.INF
c:\windows\inf\FLTMGR.PNF
c:\windows\inf\FONT.INF
c:\windows\inf\FONT.PNF
c:\windows\inf\FP40EXT.INF
c:\windows\inf\fp40ext.PNF
c:\windows\inf\FSVGA.INF
c:\windows\inf\FSVGA.PNF
c:\windows\inf\FSVGAADD.INF
c:\windows\inf\FSVGAADD.PNF
c:\windows\inf\FSVGADEL.INF
c:\windows\inf\FSVGADEL.PNF
c:\windows\inf\FXSOCM.INF
c:\windows\inf\fxsocm.PNF
c:\windows\inf\G200.INF
c:\windows\inf\G200.PNF
c:\windows\inf\G400.INF
c:\windows\inf\G400.PNF
c:\windows\inf\GAMEPORT.INF
c:\windows\inf\GAMEPORT.PNF
c:\windows\inf\GAMES.INF
c:\windows\inf\games.PNF
c:\windows\inf\GENPRINT.INF
c:\windows\inf\GENPRINT.PNF
c:\windows\inf\HAL.INF
c:\windows\inf\hal.PNF
c:\windows\inf\HIDBTH.INF
c:\windows\inf\HIDBTH.PNF
c:\windows\inf\HidDigi.inf
c:\windows\inf\HidDigi.PNF
c:\windows\inf\HIDSERV.INF
c:\windows\inf\HIDSERV.PNF
c:\windows\inf\HPDIGWIA.INF
c:\windows\inf\HPDIGWIA.PNF
c:\windows\inf\HPOJSCAN.INF
c:\windows\inf\HPOJSCAN.PNF
c:\windows\inf\HPSCAN.INF
c:\windows\inf\HPSCAN.PNF
c:\windows\inf\I740NT5.INF
c:\windows\inf\I740NT5.PNF
c:\windows\inf\I81XNT5.INF
c:\windows\inf\I81XNT5.PNF
c:\windows\inf\IBMVCAP.INF
c:\windows\inf\IBMVCAP.PNF
c:\windows\inf\ICAM3.INF
c:\windows\inf\ICAM3.PNF
c:\windows\inf\ICAM4USB.INF
c:\windows\inf\ICAM4USB.PNF
c:\windows\inf\ICAM5USB.INF
c:\windows\inf\ICAM5USB.PNF
c:\windows\inf\ICMINST.INF
c:\windows\inf\ICMINST.PNF
c:\windows\inf\ICWNT5.INF
c:\windows\inf\ICWNT5.PNF
c:\windows\inf\IE.INF
c:\windows\inf\IE.PNF
c:\windows\inf\IEACCESS.INF
c:\windows\inf\ieaccess.PNF
c:\windows\inf\IERESET.INF
c:\windows\inf\IERESET.PNF
c:\windows\inf\IGAMES.INF
c:\windows\inf\igames.PNF
c:\windows\inf\IIS.INF
c:\windows\inf\iis.PNF
c:\windows\inf\IMAGE.INF
c:\windows\inf\IMAGE.PNF
c:\windows\inf\IMS.INF
c:\windows\inf\ims.PNF
c:\windows\inf\INFCACHE.1
c:\windows\inf\INPUT.INF
c:\windows\inf\INPUT.PNF
c:\windows\inf\INTL.INF
c:\windows\inf\INTL.PNF
c:\windows\inf\IRDAALIF.INF
c:\windows\inf\IRDAALIF.PNF
c:\windows\inf\IRDASMC.INF
c:\windows\inf\IRDASMC.PNF
c:\windows\inf\IRMK7W2K.INF
c:\windows\inf\IRMK7W2K.PNF
c:\windows\inf\IRNSC.INF
c:\windows\inf\IRNSC.PNF
c:\windows\inf\IRSTUSB.INF
c:\windows\inf\IRSTUSB.PNF
c:\windows\inf\IRTOS4MO.INF
c:\windows\inf\IRTOS4MO.PNF
c:\windows\inf\java.inf
c:\windows\inf\java.PNF
c:\windows\inf\KDK2X0.INF
c:\windows\inf\KDK2X0.PNF
c:\windows\inf\KDKSCAN.INF
c:\windows\inf\KDKSCAN.PNF
c:\windows\inf\KEYBOARD.INF
c:\windows\inf\KEYBOARD.PNF
c:\windows\inf\KODAK.INF
c:\windows\inf\KODAK.PNF
c:\windows\inf\KS.INF
c:\windows\inf\ks.PNF
c:\windows\inf\KSCAPTUR.INF
c:\windows\inf\KSCAPTUR.PNF
c:\windows\inf\KSFILTER.INF
c:\windows\inf\ksfilter.PNF
c:\windows\inf\LAYOUT.INF
c:\windows\inf\layout.PNF
c:\windows\inf\LEGCYDRV.INF
c:\windows\inf\LEGCYDRV.PNF
c:\windows\inf\LWNGMADI.INF
c:\windows\inf\LWNGMADI.PNF
c:\windows\inf\LWUSBHID.INF
c:\windows\inf\LWUSBHID.PNF
c:\windows\inf\MACHINE.INF
c:\windows\inf\machine.PNF
c:\windows\inf\MCHGR.INF
c:\windows\inf\MCHGR.PNF
c:\windows\inf\MDAC.INF
c:\windows\inf\MDAC.PNF
c:\windows\inf\MDM3COM.INF
c:\windows\inf\MDM3COM.PNF
c:\windows\inf\MDM3CPCM.INF
c:\windows\inf\MDM3CPCM.PNF
c:\windows\inf\MDM3MINI.INF
c:\windows\inf\MDM3MINI.PNF
c:\windows\inf\MDM5674A.INF
c:\windows\inf\MDM5674A.PNF
c:\windows\inf\MDM656N5.INF
c:\windows\inf\MDM656N5.PNF
c:\windows\inf\MDMADC.INF
c:\windows\inf\MDMADC.PNF
c:\windows\inf\MDMAIRTE.INF
c:\windows\inf\MDMAIRTE.PNF
c:\windows\inf\MDMAIWA.INF
c:\windows\inf\MDMAIWA.PNF
c:\windows\inf\MDMAIWA3.INF
c:\windows\inf\MDMAIWA3.PNF
c:\windows\inf\MDMAIWA4.INF
c:\windows\inf\MDMAIWA4.PNF
c:\windows\inf\MDMAIWA5.INF
c:\windows\inf\MDMAIWA5.PNF
c:\windows\inf\MDMAIWAT.INF
c:\windows\inf\MDMAIWAT.PNF
c:\windows\inf\MDMAR1.INF
c:\windows\inf\MDMAR1.PNF
c:\windows\inf\MDMARCH.INF
c:\windows\inf\MDMARCH.PNF
c:\windows\inf\MDMARN.INF
c:\windows\inf\MDMARN.PNF
c:\windows\inf\MDMATI.INF
c:\windows\inf\MDMATI.PNF
c:\windows\inf\MDMATM2K.INF
c:\windows\inf\MDMATM2K.PNF
c:\windows\inf\MDMATT.INF
c:\windows\inf\MDMATT.PNF
c:\windows\inf\MDMAUS.INF
c:\windows\inf\MDMAUS.PNF
c:\windows\inf\MDMBCMSM.INF
c:\windows\inf\MDMBCMSM.PNF
c:\windows\inf\MDMBOCA.INF
c:\windows\inf\MDMBOCA.PNF
c:\windows\inf\MDMBSB.INF
c:\windows\inf\MDMBSB.PNF
c:\windows\inf\MDMBTMDM.INF
c:\windows\inf\MDMBTMDM.PNF
c:\windows\inf\MDMBUG3.INF
c:\windows\inf\MDMBUG3.PNF
c:\windows\inf\MDMBW561.INF
c:\windows\inf\MDMBW561.PNF
c:\windows\inf\MDMC26A.INF
c:\windows\inf\MDMC26A.PNF
c:\windows\inf\MDMCDP.INF
c:\windows\inf\MDMCDP.PNF
c:\windows\inf\MDMCHIPV.INF
c:\windows\inf\MDMCHIPV.PNF
c:\windows\inf\MDMCM28.INF
c:\windows\inf\MDMCM28.PNF
c:\windows\inf\MDMCODEX.INF
c:\windows\inf\MDMCODEX.PNF
c:\windows\inf\MDMCOM1.INF
c:\windows\inf\MDMCOM1.PNF
c:\windows\inf\MDMCOMMU.INF
c:\windows\inf\MDMCOMMU.PNF
c:\windows\inf\MDMCOMP.INF
c:\windows\inf\MDMCOMP.PNF
c:\windows\inf\MDMCPQ.INF
c:\windows\inf\MDMCPQ.PNF
c:\windows\inf\MDMCPQ2.INF
c:\windows\inf\MDMCPQ2.PNF
c:\windows\inf\MDMCPV.INF
c:\windows\inf\MDMCPV.PNF
c:\windows\inf\MDMCRTIX.INF
c:\windows\inf\MDMCRTIX.PNF
c:\windows\inf\MDMCXSF2.INF
c:\windows\inf\MDMCXSF2.PNF
c:\windows\inf\MDMCXSFT.INF
c:\windows\inf\MDMCXSFT.PNF
c:\windows\inf\MDMDCM5.INF
c:\windows\inf\MDMDCM5.PNF
c:\windows\inf\MDMDCM6.INF
c:\windows\inf\MDMDCM6.PNF
c:\windows\inf\mdmdf56F.inf
c:\windows\inf\mdmdf56F.PNF
c:\windows\inf\MDMDGDEN.INF
c:\windows\inf\MDMDGDEN.PNF
c:\windows\inf\MDMDGITN.INF
c:\windows\inf\MDMDGITN.PNF
c:\windows\inf\MDMDIGI.INF
c:\windows\inf\MDMDIGI.PNF
c:\windows\inf\MDMDP2.INF
c:\windows\inf\MDMDP2.PNF
c:\windows\inf\MDMDSI.INF
c:\windows\inf\MDMDSI.PNF
c:\windows\inf\MDMDYNA.INF
c:\windows\inf\MDMDYNA.PNF
c:\windows\inf\MDMEIGER.INF
c:\windows\inf\MDMEIGER.PNF
c:\windows\inf\MDMELSA.INF
c:\windows\inf\MDMELSA.PNF
c:\windows\inf\MDMERIC.INF
c:\windows\inf\MDMERIC.PNF
c:\windows\inf\MDMERIC2.INF
c:\windows\inf\MDMERIC2.PNF
c:\windows\inf\MDMESS.INF
c:\windows\inf\MDMESS.PNF
c:\windows\inf\MDMETECH.INF
c:\windows\inf\MDMETECH.PNF
c:\windows\inf\MDMEXP.INF
c:\windows\inf\MDMEXP.PNF
c:\windows\inf\MDMFJ2.INF
c:\windows\inf\MDMFJ2.PNF
c:\windows\inf\MDMGATEW.INF
c:\windows\inf\MDMGATEW.PNF
c:\windows\inf\MDMGCS.INF
c:\windows\inf\MDMGCS.PNF
c:\windows\inf\MDMGEN.INF
c:\windows\inf\MDMGEN.PNF
c:\windows\inf\MDMGL001.INF
c:\windows\inf\MDMGL001.PNF
c:\windows\inf\MDMGL002.INF
c:\windows\inf\MDMGL002.PNF
c:\windows\inf\MDMGL003.INF
c:\windows\inf\MDMGL003.PNF
c:\windows\inf\MDMGL004.INF
c:\windows\inf\MDMGL004.PNF
c:\windows\inf\MDMGL005.INF
c:\windows\inf\MDMGL005.PNF
c:\windows\inf\MDMGL006.INF
c:\windows\inf\MDMGL006.PNF
c:\windows\inf\MDMGL007.INF
c:\windows\inf\MDMGL007.PNF
c:\windows\inf\MDMGL008.INF
c:\windows\inf\MDMGL008.PNF
c:\windows\inf\MDMGL009.INF
c:\windows\inf\MDMGL009.PNF
c:\windows\inf\MDMGL010.INF
c:\windows\inf\MDMGL010.PNF
c:\windows\inf\MDMGSM.INF
c:\windows\inf\MDMGSM.PNF
c:\windows\inf\MDMHAEU.INF
c:\windows\inf\MDMHAEU.PNF
c:\windows\inf\MDMHAMRW.INF
c:\windows\inf\MDMHAMRW.PNF
c:\windows\inf\MDMHANDY.INF
c:\windows\inf\MDMHANDY.PNF
c:\windows\inf\MDMHAY2.INF
c:\windows\inf\MDMHAY2.PNF
c:\windows\inf\MDMHAYES.INF
c:\windows\inf\MDMHAYES.PNF
c:\windows\inf\MDMINFOT.INF
c:\windows\inf\MDMINFOT.PNF
c:\windows\inf\MDMINTEL.INF
c:\windows\inf\MDMINTEL.PNF
c:\windows\inf\MDMIODAT.INF
c:\windows\inf\MDMIODAT.PNF
c:\windows\inf\MDMIRMDM.INF
c:\windows\inf\MDMIRMDM.PNF
c:\windows\inf\MDMISDN.INF
c:\windows\inf\MDMISDN.PNF
c:\windows\inf\MDMJF56E.INF
c:\windows\inf\MDMJF56E.PNF
c:\windows\inf\MDMKE.INF
c:\windows\inf\MDMKE.PNF
c:\windows\inf\MDMKORTX.INF
c:\windows\inf\MDMKORTX.PNF
c:\windows\inf\MDMLASAT.INF
c:\windows\inf\MDMLASAT.PNF
c:\windows\inf\MDMLASNO.INF
c:\windows\inf\MDMLASNO.PNF
c:\windows\inf\MDMLT3.INF
c:\windows\inf\MDMLT3.PNF
c:\windows\inf\MDMLTLEO.INF
c:\windows\inf\MDMLTLEO.PNF
c:\windows\inf\MDMLTSFT.INF
c:\windows\inf\MDMLTSFT.PNF
c:\windows\inf\MDMLUCNT.INF
c:\windows\inf\MDMLUCNT.PNF
c:\windows\inf\MDMMC288.INF
c:\windows\inf\MDMMC288.PNF
c:\windows\inf\MDMMCD.INF
c:\windows\inf\MDMMCD.PNF
c:\windows\inf\MDMMCOM.INF
c:\windows\inf\MDMMCOM.PNF
c:\windows\inf\MDMMCT.INF
c:\windows\inf\MDMMCT.PNF
c:\windows\inf\MDMMEGA.INF
c:\windows\inf\MDMMEGA.PNF
c:\windows\inf\MDMMETRI.INF
c:\windows\inf\MDMMETRI.PNF
c:\windows\inf\MDMMHRTZ.INF
c:\windows\inf\MDMMHRTZ.PNF
c:\windows\inf\MDMMHZA.INF
c:\windows\inf\MDMMHZA.PNF
c:\windows\inf\MDMMHZEL.INF
c:\windows\inf\MDMMHZEL.PNF
c:\windows\inf\MDMMHZK1.INF
c:\windows\inf\MDMMHZK1.PNF
c:\windows\inf\MDMMINIJ.INF
c:\windows\inf\MDMMINIJ.PNF
c:\windows\inf\MDMMOD.INF
c:\windows\inf\MDMMOD.PNF
c:\windows\inf\MDMMOTO.INF
c:\windows\inf\MDMMOTO.PNF
c:\windows\inf\MDMMOTO1.INF
c:\windows\inf\MDMMOTO1.PNF
c:\windows\inf\MDMMOTOU.INF
c:\windows\inf\MDMMOTOU.PNF
c:\windows\inf\MDMMTS.INF
c:\windows\inf\MDMMTS.PNF
c:\windows\inf\MDMNEUHS.INF
c:\windows\inf\MDMNEUHS.PNF
c:\windows\inf\Mdmnis1u.inf
c:\windows\inf\Mdmnis1u.PNF
c:\windows\inf\Mdmnis2u.inf
c:\windows\inf\Mdmnis2u.PNF
c:\windows\inf\Mdmnis3t.inf
c:\windows\inf\Mdmnis3t.PNF
c:\windows\inf\Mdmnis5t.inf
c:\windows\inf\Mdmnis5t.PNF
c:\windows\inf\MDMNOKIA.INF
c:\windows\inf\MDMNOKIA.PNF
c:\windows\inf\MDMNOVA.INF
c:\windows\inf\MDMNOVA.PNF
c:\windows\inf\MDMNTSTM.INF
c:\windows\inf\MDMNTSTM.PNF
c:\windows\inf\MDMNTT1.INF
c:\windows\inf\MDMNTT1.PNF
c:\windows\inf\MDMNTTD2.INF
c:\windows\inf\MDMNTTD2.PNF
c:\windows\inf\MDMNTTD6.INF
c:\windows\inf\MDMNTTD6.PNF
c:\windows\inf\MDMNTTME.INF
c:\windows\inf\MDMNTTME.PNF
c:\windows\inf\MDMNTTP.INF
c:\windows\inf\MDMNTTP.PNF
c:\windows\inf\MDMNTTP2.INF
c:\windows\inf\MDMNTTP2.PNF
c:\windows\inf\MDMNTTTE.INF
c:\windows\inf\MDMNTTTE.PNF
c:\windows\inf\MDMOLIC.INF
c:\windows\inf\MDMOLIC.PNF
c:\windows\inf\MDMOMRN3.INF
c:\windows\inf\MDMOMRN3.PNF
c:\windows\inf\MDMOPTN.INF
c:\windows\inf\MDMOPTN.PNF
c:\windows\inf\MDMOSI.INF
c:\windows\inf\MDMOSI.PNF
c:\windows\inf\MDMOSICE.INF
c:\windows\inf\MDMOSICE.PNF
c:\windows\inf\MDMPACE.INF
c:\windows\inf\MDMPACE.PNF
c:\windows\inf\MDMPBIT.INF
c:\windows\inf\MDMPBIT.PNF
c:\windows\inf\MDMPCTEL.INF
c:\windows\inf\MDMPCTEL.PNF
c:\windows\inf\MDMPENR.INF
c:\windows\inf\MDMPENR.PNF
c:\windows\inf\MDMPIN.INF
c:\windows\inf\MDMPIN.PNF
c:\windows\inf\MDMPN1.INF
c:\windows\inf\MDMPN1.PNF
c:\windows\inf\MDMPP.INF
c:\windows\inf\MDMPP.PNF
c:\windows\inf\MDMPSION.INF
c:\windows\inf\MDMPSION.PNF
c:\windows\inf\MDMRACAL.INF
c:\windows\inf\MDMRACAL.PNF
c:\windows\inf\MDMRISA.INF
c:\windows\inf\MDMRISA.PNF
c:\windows\inf\MDMROCK.INF
c:\windows\inf\MDMROCK.PNF
c:\windows\inf\MDMROCK3.INF
c:\windows\inf\MDMROCK3.PNF
c:\windows\inf\MDMROCK4.INF
c:\windows\inf\MDMROCK4.PNF
c:\windows\inf\MDMROCK5.INF
c:\windows\inf\MDMROCK5.PNF
c:\windows\inf\MDMRPCI.INF
c:\windows\inf\MDMRPCI.PNF
c:\windows\inf\MDMRPCIW.INF
c:\windows\inf\MDMRPCIW.PNF
c:\windows\inf\MDMSETUP.INF
c:\windows\inf\MDMSETUP.PNF
c:\windows\inf\MDMSGSML.INF
c:\windows\inf\MDMSGSML.PNF
c:\windows\inf\MDMSGSMU.INF
c:\windows\inf\MDMSGSMU.PNF
c:\windows\inf\MDMSIER.INF
c:\windows\inf\MDMSIER.PNF
c:\windows\inf\MDMSII64.INF
c:\windows\inf\MDMSII64.PNF
c:\windows\inf\MDMSIIL6.INF
c:\windows\inf\MDMSIIL6.PNF
c:\windows\inf\MDMSMART.INF
c:\windows\inf\MDMSMART.PNF
c:\windows\inf\MDMSONYU.INF
c:\windows\inf\MDMSONYU.PNF
c:\windows\inf\MDMSPQ28.INF
c:\windows\inf\MDMSPQ28.PNF
c:\windows\inf\MDMSUN1.INF
c:\windows\inf\MDMSUN1.PNF
c:\windows\inf\MDMSUN2.INF
c:\windows\inf\MDMSUN2.PNF
c:\windows\inf\MDMSUPR3.INF
c:\windows\inf\MDMSUPR3.PNF
c:\windows\inf\MDMSUPRA.INF
c:\windows\inf\MDMSUPRA.PNF
c:\windows\inf\MDMSUPRV.INF
c:\windows\inf\MDMSUPRV.PNF
c:\windows\inf\MDMTDK.INF
c:\windows\inf\MDMTDK.PNF
c:\windows\inf\MDMTDKJ2.INF
c:\windows\inf\MDMTDKJ2.PNF
c:\windows\inf\MDMTDKJ3.INF
c:\windows\inf\MDMTDKJ3.PNF
c:\windows\inf\MDMTDKJ4.INF
c:\windows\inf\MDMTDKJ4.PNF
c:\windows\inf\MDMTDKJ5.INF
c:\windows\inf\MDMTDKJ5.PNF
c:\windows\inf\MDMTDKJ6.INF
c:\windows\inf\MDMTDKJ6.PNF
c:\windows\inf\MDMTDKJ7.INF
c:\windows\inf\MDMTDKJ7.PNF
c:\windows\inf\MDMTEXAS.INF
c:\windows\inf\MDMTEXAS.PNF
c:\windows\inf\MDMTI.INF
c:\windows\inf\MDMTI.PNF
c:\windows\inf\MDMTOSH.INF
c:\windows\inf\MDMTOSH.PNF
c:\windows\inf\MDMTRON.INF
c:\windows\inf\MDMTRON.PNF
c:\windows\inf\MDMUSRF.INF
c:\windows\inf\MDMUSRF.PNF
c:\windows\inf\MDMUSRG.INF
c:\windows\inf\MDMUSRG.PNF
c:\windows\inf\MDMUSRGL.INF
c:\windows\inf\MDMUSRGL.PNF
c:\windows\inf\MDMUSRK1.INF
c:\windows\inf\MDMUSRK1.PNF
c:\windows\inf\MDMUSRSP.INF
c:\windows\inf\MDMUSRSP.PNF
c:\windows\inf\MDMVDOT.INF
c:\windows\inf\MDMVDOT.PNF
c:\windows\inf\MDMVV.INF
c:\windows\inf\MDMVV.PNF
c:\windows\inf\MDMWHQL0.INF
c:\windows\inf\MDMWHQL0.PNF
c:\windows\inf\MDMX5560.INF
c:\windows\inf\MDMX5560.PNF
c:\windows\inf\MDMXIRCC.INF
c:\windows\inf\MDMXIRCC.PNF
c:\windows\inf\MDMXIRMP.INF
c:\windows\inf\MDMXIRMP.PNF
c:\windows\inf\MDMZOOM.INF
c:\windows\inf\MDMZOOM.PNF
c:\windows\inf\MDMZYP.INF
c:\windows\inf\MDMZYP.PNF
c:\windows\inf\MDMZYXEL.INF
c:\windows\inf\MDMZYXEL.PNF
c:\windows\inf\MDMZYXLG.INF
c:\windows\inf\MDMZYXLG.PNF
c:\windows\inf\MEMCARD.INF
c:\windows\inf\MEMCARD.PNF
c:\windows\inf\MEMSTPCI.INF
c:\windows\inf\MEMSTPCI.PNF
c:\windows\inf\MF.INF
c:\windows\inf\MF.PNF
c:\windows\inf\MFCEM28.INF
c:\windows\inf\MFCEM28.PNF
c:\windows\inf\MFCEM33.INF
c:\windows\inf\MFCEM33.PNF
c:\windows\inf\MFCEM56.INF
c:\windows\inf\MFCEM56.PNF
c:\windows\inf\MFF56N5.INF
c:\windows\inf\MFF56N5.PNF
c:\windows\inf\MFLM.INF
c:\windows\inf\MFLM.PNF
c:\windows\inf\MFLM56.INF
c:\windows\inf\MFLM56.PNF
c:\windows\inf\MFMHZN5.INF
c:\windows\inf\MFMHZN5.PNF
c:\windows\inf\MFOSI5.INF
c:\windows\inf\MFOSI5.PNF
c:\windows\inf\MFSOCKET.INF
c:\windows\inf\MFSOCKET.PNF
c:\windows\inf\MFSUPRA.INF
c:\windows\inf\MFSUPRA.PNF
c:\windows\inf\MFX56NF.INF
c:\windows\inf\MFX56NF.PNF
c:\windows\inf\MGAU.INF
c:\windows\inf\MGAU.PNF
c:\windows\inf\MINIOC.INF
c:\windows\inf\MINIOC.PNF
c:\windows\inf\MMOPT.INF
c:\windows\inf\MMOPT.PNF
c:\windows\inf\MODEMCSA.INF
c:\windows\inf\modemcsa.PNF
c:\windows\inf\MONITOR.INF
c:\windows\inf\monitor.PNF
c:\windows\inf\MONITOR2.INF
c:\windows\inf\MONITOR2.PNF
c:\windows\inf\MONITOR3.INF
c:\windows\inf\MONITOR3.PNF
c:\windows\inf\MONITOR4.INF
c:\windows\inf\MONITOR4.PNF
c:\windows\inf\MONITOR5.INF
c:\windows\inf\MONITOR5.PNF
c:\windows\inf\MONITOR6.INF
c:\windows\inf\MONITOR6.PNF
c:\windows\inf\MONITOR7.INF
c:\windows\inf\MONITOR7.PNF
c:\windows\inf\MONITOR8.INF
c:\windows\inf\MONITOR8.PNF
c:\windows\inf\morphstb.PNF
c:\windows\inf\MOVIEMK.INF
c:\windows\inf\MOVIEMK.PNF
c:\windows\inf\MPCD10.inf
c:\windows\inf\MPCD10.PNF
c:\windows\inf\MPE.INF
c:\windows\inf\MPE.PNF
c:\windows\inf\MPLAYER2.INF
c:\windows\inf\MPLAYER2.PNF
c:\windows\inf\MPPRE10.inf
c:\windows\inf\MPPRE10.PNF
c:\windows\inf\MPSSTLN.INF
c:\windows\inf\MPSSTLN.PNF
c:\windows\inf\MPSTUB10.inf
c:\windows\inf\MPSTUB10.PNF
c:\windows\inf\MSCPQPA1.INF
c:\windows\inf\MSCPQPA1.PNF
c:\windows\inf\MSDV.INF
c:\windows\inf\MSDV.PNF
c:\windows\inf\MSHDC.INF
c:\windows\inf\mshdc.PNF
c:\windows\inf\MSINFO32.INF
c:\windows\inf\MSINFO32.PNF
c:\windows\inf\MSMOUSE.INF
c:\windows\inf\MSMOUSE.PNF
c:\windows\inf\MSMSCSI.INF
c:\windows\inf\MSMSCSI.PNF
c:\windows\inf\MSMSGS.INF
c:\windows\inf\msmsgs.PNF
c:\windows\inf\MSMUSB.INF
c:\windows\inf\MSMUSB.PNF
c:\windows\inf\MSNETMTG.INF
c:\windows\inf\MSNETMTG.PNF
c:\windows\inf\MSNIKE.INF
c:\windows\inf\MSNIKE.PNF
c:\windows\inf\MSNMSN.INF
c:\windows\inf\msnmsn.PNF
c:\windows\inf\MSOE50.INF
c:\windows\inf\MSOE50.PNF
c:\windows\inf\MSPORTS.INF
c:\windows\inf\msports.PNF
c:\windows\inf\MSRIO.INF
c:\windows\inf\MSRIO.PNF
c:\windows\inf\MSRIO8.INF
c:\windows\inf\MSRIO8.PNF
c:\windows\inf\MSTAPE.INF
c:\windows\inf\MSTAPE.PNF
c:\windows\inf\MSTASK.INF
c:\windows\inf\MSTASK.PNF
c:\windows\inf\MTXVIDEO.INF
c:\windows\inf\MTXVIDEO.PNF
c:\windows\inf\MULTIMED.INF
c:\windows\inf\multimed.PNF
c:\windows\inf\MULTIPRT.INF
c:\windows\inf\MULTIPRT.PNF
c:\windows\inf\MWAVMDM1.INF
c:\windows\inf\MWAVMDM1.PNF
c:\windows\inf\MWMBATAM.INF
c:\windows\inf\MWMBATAM.PNF
c:\windows\inf\MWREMOVE.INF
c:\windows\inf\MWREMOVE.PNF
c:\windows\inf\MWTPDSP.INF
c:\windows\inf\MWTPDSP.PNF
c:\windows\inf\MXBOARD.INF
c:\windows\inf\MXBOARD.PNF
c:\windows\inf\MXPORT.INF
c:\windows\inf\MXPORT.PNF
c:\windows\inf\MYMUSIC.INF
c:\windows\inf\MYMUSIC.PNF
c:\windows\inf\NABTSFEC.INF
c:\windows\inf\NABTSFEC.PNF
c:\windows\inf\NDISIP.INF
c:\windows\inf\NDISIP.PNF
c:\windows\inf\NDISUIO.INF
c:\windows\inf\NDISUIO.PNF
c:\windows\inf\NEO20XX.INF
c:\windows\inf\NEO20XX.PNF
c:\windows\inf\NET10.INF
c:\windows\inf\NET10.PNF
c:\windows\inf\NET1394.INF
c:\windows\inf\NET1394.PNF
c:\windows\inf\NET21X4.INF
c:\windows\inf\NET21X4.PNF
c:\windows\inf\NET3C556.INF
c:\windows\inf\NET3C556.PNF
c:\windows\inf\NET3C589.INF
c:\windows\inf\NET3C589.PNF
c:\windows\inf\NET3C985.INF
c:\windows\inf\NET3C985.PNF
c:\windows\inf\NET3SR.INF
c:\windows\inf\NET3SR.PNF
c:\windows\inf\NET5515N.INF
c:\windows\inf\NET5515N.PNF
c:\windows\inf\NET557.INF
c:\windows\inf\NET557.PNF
c:\windows\inf\NET559IB.INF
c:\windows\inf\NET559IB.PNF
c:\windows\inf\NET575NT.INF
c:\windows\inf\NET575NT.PNF
c:\windows\inf\NET650D.INF
c:\windows\inf\NET650D.PNF
c:\windows\inf\NET656C5.INF
c:\windows\inf\NET656C5.PNF
c:\windows\inf\NET656N5.INF
c:\windows\inf\NET656N5.PNF
c:\windows\inf\NET713.INF
c:\windows\inf\NET713.PNF
c:\windows\inf\NET83820.INF
c:\windows\inf\NET83820.PNF
c:\windows\inf\NET8511.INF
c:\windows\inf\NET8511.PNF
c:\windows\inf\NETALI.INF
c:\windows\inf\NETALI.PNF
c:\windows\inf\NETAMBI.INF
c:\windows\inf\NETAMBI.PNF
c:\windows\inf\NETAMD.INF
c:\windows\inf\NETAMD.PNF
c:\windows\inf\NETAMD2.INF
c:\windows\inf\NETAMD2.PNF
c:\windows\inf\NETAMDHL.INF
c:\windows\inf\NETAMDHL.PNF
c:\windows\inf\NETAN983.INF
c:\windows\inf\NETAN983.PNF
c:\windows\inf\NETANA.INF
c:\windows\inf\NETANA.PNF
c:\windows\inf\NETASP2K.INF
c:\windows\inf\NETASP2K.PNF
c:\windows\inf\NETAUNI.INF
c:\windows\inf\NETAUNI.PNF
c:\windows\inf\NETB57XP.INF
c:\windows\inf\NETB57XP.PNF
c:\windows\inf\NETBCM4E.INF
c:\windows\inf\NETBCM4E.PNF
c:\windows\inf\NETBCM4P.INF
c:\windows\inf\NETBCM4P.PNF
c:\windows\inf\NETBCM4U.INF
c:\windows\inf\NETBCM4U.PNF
c:\windows\inf\NETBEAC.INF
c:\windows\inf\netbeac.PNF
c:\windows\inf\NETBRDGM.INF
c:\windows\inf\NETBRDGM.PNF
c:\windows\inf\NETBRDGS.INF
c:\windows\inf\NETBRDGS.PNF
c:\windows\inf\NETBRZW.INF
c:\windows\inf\NETBRZW.PNF
c:\windows\inf\NETCB102.INF
c:\windows\inf\NETCB102.PNF
c:\windows\inf\NETCB325.INF
c:\windows\inf\NETCB325.PNF
c:\windows\inf\NETCBE.INF
c:\windows\inf\NETCBE.PNF
c:\windows\inf\NETCE2.INF
c:\windows\inf\NETCE2.PNF
c:\windows\inf\NETCE3.INF
c:\windows\inf\NETCE3.PNF
c:\windows\inf\NETCEM28.INF
c:\windows\inf\NETCEM28.PNF
c:\windows\inf\NETCEM33.INF
c:\windows\inf\NETCEM33.PNF
c:\windows\inf\NETCEM56.INF
c:\windows\inf\NETCEM56.PNF
c:\windows\inf\NETCICAP.INF
c:\windows\inf\NETCICAP.PNF
c:\windows\inf\NETCIS.INF
c:\windows\inf\NETCIS.PNF
c:\windows\inf\NETCLASS.INF
c:\windows\inf\NETCLASS.PNF
c:\windows\inf\NETCPQC.INF
c:\windows\inf\NETCPQC.PNF
c:\windows\inf\NETCPQG.INF
c:\windows\inf\NETCPQG.PNF
c:\windows\inf\NETCPQI.INF
c:\windows\inf\NETCPQI.PNF
c:\windows\inf\NETCPQMT.INF
c:\windows\inf\NETCPQMT.PNF
c:\windows\inf\NETCTMRK.INF
c:\windows\inf\NETCTMRK.PNF
c:\windows\inf\NETDAV.INF
c:\windows\inf\NETDAV.PNF
c:\windows\inf\NETDEFXA.INF
c:\windows\inf\NETDEFXA.PNF
c:\windows\inf\NETDF650.INF
c:\windows\inf\NETDF650.PNF
c:\windows\inf\NETDGDXB.INF
c:\windows\inf\NETDGDXB.PNF
c:\windows\inf\NETDLH5X.INF
c:\windows\inf\NETDLH5X.PNF
c:\windows\inf\NETDM.INF
c:\windows\inf\NETDM.PNF
c:\windows\inf\NETE1000.INF
c:\windows\inf\NETE1000.PNF
c:\windows\inf\NETE100I.INF
c:\windows\inf\NETE100I.PNF
c:\windows\inf\NETEJXMP.INF
c:\windows\inf\NETEJXMP.PNF
c:\windows\inf\NETEL515.INF
c:\windows\inf\NETEL515.PNF
c:\windows\inf\NETEL574.INF
c:\windows\inf\NETEL574.PNF
c:\windows\inf\NETEL5X9.INF
c:\windows\inf\NETEL5X9.PNF
c:\windows\inf\NETEL90A.INF
c:\windows\inf\NETEL90A.PNF
c:\windows\inf\NETEL90B.INF
c:\windows\inf\NETEL90B.PNF
c:\windows\inf\NETEL980.INF
c:\windows\inf\NETEL980.PNF
c:\windows\inf\NETEL99X.INF
c:\windows\inf\NETEL99X.PNF
c:\windows\inf\NETEPICN.INF
c:\windows\inf\NETEPICN.PNF
c:\windows\inf\NETEPRO.INF
c:\windows\inf\NETEPRO.PNF
c:\windows\inf\NETEPVCM.INF
c:\windows\inf\NETEPVCM.PNF
c:\windows\inf\NETEPVCP.INF
c:\windows\inf\NETEPVCP.PNF
c:\windows\inf\NETEX10.INF
c:\windows\inf\NETEX10.PNF
c:\windows\inf\NETF56N5.INF
c:\windows\inf\NETF56N5.PNF
c:\windows\inf\NETFA312.INF
c:\windows\inf\NETFA312.PNF
c:\windows\inf\NETFA410.INF
c:\windows\inf\NETFA410.PNF
c:\windows\inf\NETFJVI.INF
c:\windows\inf\NETFJVI.PNF
c:\windows\inf\NETFJVJ.INF
c:\windows\inf\NETFJVJ.PNF
c:\windows\inf\NETFORE.INF
c:\windows\inf\NETFORE.PNF
c:\windows\inf\NETFOREH.INF
c:\windows\inf\NETFOREH.PNF
c:\windows\inf\NETFW.INF
c:\windows\inf\NETFW.PNF
c:\windows\inf\NETGPC.INF
c:\windows\inf\NETGPC.PNF
c:\windows\inf\NETIAS.INF
c:\windows\inf\NETIAS.PNF
c:\windows\inf\NETIBM.INF
c:\windows\inf\NETIBM.PNF
c:\windows\inf\NETIBM2.INF
c:\windows\inf\NETIBM2.PNF
c:\windows\inf\NETIP6.INF
c:\windows\inf\NETIP6.PNF
c:\windows\inf\NETIPRIP.INF
c:\windows\inf\netiprip.PNF
c:\windows\inf\NETIRDA.INF
c:\windows\inf\NETIRDA.PNF
c:\windows\inf\NETIRSIR.INF
c:\windows\inf\NETIRSIR.PNF
c:\windows\inf\NETKLSI.INF
c:\windows\inf\NETKLSI.PNF
c:\windows\inf\NETKTC.INF
c:\windows\inf\NETKTC.PNF
c:\windows\inf\NETLANEM.INF
c:\windows\inf\NETLANEM.PNF
c:\windows\inf\NETLANEP.INF
c:\windows\inf\NETLANEP.PNF
c:\windows\inf\NETLM.INF
c:\windows\inf\NETLM.PNF
c:\windows\inf\NETLM56.INF
c:\windows\inf\NETLM56.PNF
c:\windows\inf\NETLNEV2.INF
c:\windows\inf\NETLNEV2.PNF
c:\windows\inf\NETLOOP.INF
c:\windows\inf\NETLOOP.PNF
c:\windows\inf\NETLPD.INF
c:\windows\inf\netlpd.PNF
c:\windows\inf\NETMADGE.INF
c:\windows\inf\NETMADGE.PNF
c:\windows\inf\NETMHZN5.INF
c:\windows\inf\NETMHZN5.PNF
c:\windows\inf\NETMSCLI.INF
c:\windows\inf\NETMSCLI.PNF
c:\windows\inf\NETNB.INF
c:\windows\inf\NETNB.PNF
c:\windows\inf\NETNF3.INF
c:\windows\inf\NETNF3.PNF
c:\windows\inf\NETNGR.INF
c:\windows\inf\NETNGR.PNF
c:\windows\inf\NETNM.INF
c:\windows\inf\NETNM.PNF
c:\windows\inf\NETNOVEL.INF
c:\windows\inf\NETNOVEL.PNF
c:\windows\inf\NETNWLNK.INF
c:\windows\inf\NETNWLNK.PNF
c:\windows\inf\NETOC.INF
c:\windows\inf\netoc.PNF
c:\windows\inf\NETOSI2C.INF
c:\windows\inf\NETOSI2C.PNF
c:\windows\inf\NETOSI5.INF
c:\windows\inf\NETOSI5.PNF
c:\windows\inf\NETPC100.INF
c:\windows\inf\NETPC100.PNF
c:\windows\inf\NETPNIC.INF
c:\windows\inf\NETPNIC.PNF
c:\windows\inf\NETPSA.INF
c:\windows\inf\netpsa.PNF
c:\windows\inf\NETPSCHD.INF
c:\windows\inf\NETPSCHD.PNF
c:\windows\inf\NETPWR2.INF
c:\windows\inf\NETPWR2.PNF
c:\windows\inf\NETRASA.INF
c:\windows\inf\netrasa.PNF
c:\windows\inf\NETRASS.INF
c:\windows\inf\NETRASS.PNF
c:\windows\inf\NETRAST.INF
c:\windows\inf\NETRAST.PNF
c:\windows\inf\NETRLW2K.INF
c:\windows\inf\NETRLW2K.PNF
c:\windows\inf\NETRNDIS.INF
c:\windows\inf\NETRNDIS.PNF
c:\windows\inf\NETRSVP.INF
c:\windows\inf\NETRSVP.PNF
c:\windows\inf\NETRTPNT.INF
c:\windows\inf\NETRTPNT.PNF
c:\windows\inf\NETRTSNT.INF
c:\windows\inf\NETRTSNT.PNF
c:\windows\inf\NETRWAN.INF
c:\windows\inf\NETRWAN.PNF
c:\windows\inf\NETSAP.INF
c:\windows\inf\NETSAP.PNF
c:\windows\inf\NETSERV.INF
c:\windows\inf\NETSERV.PNF
c:\windows\inf\NETSIS.INF
c:\windows\inf\NETSIS.PNF
c:\windows\inf\NETSK_FP.INF
c:\windows\inf\NETSK_FP.PNF
c:\windows\inf\NETSK98.INF
c:\windows\inf\NETSK98.PNF
c:\windows\inf\NETSLA30.INF
c:\windows\inf\NETSLA30.PNF
c:\windows\inf\NETSMC.INF
c:\windows\inf\NETSMC.PNF
c:\windows\inf\NETSNIP.INF
c:\windows\inf\NETSNIP.PNF
c:\windows\inf\NETSNMP.INF
c:\windows\inf\netsnmp.PNF
c:\windows\inf\NETTB155.INF
c:\windows\inf\NETTB155.PNF
c:\windows\inf\NETTCPIP.INF
c:\windows\inf\NETTCPIP.PNF
c:\windows\inf\NETTDKB.INF
c:\windows\inf\NETTDKB.PNF
c:\windows\inf\NETTIGER.INF
c:\windows\inf\NETTIGER.PNF
c:\windows\inf\NETTPRO.INF
c:\windows\inf\NETTPRO.PNF
c:\windows\inf\NETTPSMP.INF
c:\windows\inf\nettpsmp.PNF
c:\windows\inf\NETTUN.INF
c:\windows\inf\NETTUN.PNF
c:\windows\inf\NETUPNP.INF
c:\windows\inf\netupnp.PNF
c:\windows\inf\NETUPNPH.INF
c:\windows\inf\NETUPNPH.PNF
c:\windows\inf\NETVT86.INF
c:\windows\inf\NETVT86.PNF
c:\windows\inf\NETW840.INF
c:\windows\inf\NETW840.PNF
c:\windows\inf\NETW926.INF
c:\windows\inf\NETW926.PNF
c:\windows\inf\NETW940.INF
c:\windows\inf\NETW940.PNF
c:\windows\inf\NETWLAN.INF
c:\windows\inf\NETWLAN.PNF
c:\windows\inf\NETWLAN2.INF
c:\windows\inf\NETWLAN2.PNF
c:\windows\inf\NETWV48.INF
c:\windows\inf\NETWV48.PNF
c:\windows\inf\NETWZC.INF
c:\windows\inf\NETWZC.PNF
c:\windows\inf\NETX500.INF
c:\windows\inf\NETX500.PNF
c:\windows\inf\NETX56N5.INF
c:\windows\inf\NETX56N5.PNF
c:\windows\inf\NETXCPQ.INF
c:\windows\inf\NETXCPQ.PNF
c:\windows\inf\NTAPM.INF
c:\windows\inf\NTAPM.PNF
c:\windows\inf\NTGRIP.INF
c:\windows\inf\NTGRIP.PNF
c:\windows\inf\NTPRINT.INF
c:\windows\inf\NTPRINT.PNF
c:\windows\inf\NV3.INF
c:\windows\inf\NV3.PNF
c:\windows\inf\NV4_DISP.INF
c:\windows\inf\NV4_DISP.PNF
c:\windows\inf\NVCT.INF
c:\windows\inf\NVCT.PNF
c:\windows\inf\NVDM.INF
c:\windows\inf\NVDM.PNF
c:\windows\inf\NVTS.INF
c:\windows\inf\NVTS.PNF
c:\windows\inf\OEACCESS.INF
c:\windows\inf\oeaccess.PNF
c:\windows\inf\oem0.inf
c:\windows\inf\oem0.PNF
c:\windows\inf\oem1.inf
c:\windows\inf\oem1.PNF
c:\windows\inf\oem10.inf
c:\windows\inf\oem11.inf
c:\windows\inf\oem11.PNF
c:\windows\inf\oem12.inf
c:\windows\inf\oem12.PNF
c:\windows\inf\oem13.inf
c:\windows\inf\oem13.PNF
c:\windows\inf\oem14.inf
c:\windows\inf\oem14.PNF
c:\windows\inf\oem15.inf
c:\windows\inf\oem15.PNF
c:\windows\inf\oem16.inf
c:\windows\inf\oem16.PNF
c:\windows\inf\oem17.inf
c:\windows\inf\oem17.PNF
c:\windows\inf\oem18.inf
c:\windows\inf\oem18.PNF
c:\windows\inf\oem19.inf
c:\windows\inf\oem19.PNF
c:\windows\inf\oem2.inf
c:\windows\inf\oem2.PNF
c:\windows\inf\oem20.inf
c:\windows\inf\oem20.PNF
c:\windows\inf\oem21.inf
c:\windows\inf\oem21.PNF
c:\windows\inf\oem22.inf
c:\windows\inf\oem22.PNF
c:\windows\inf\oem23.inf
c:\windows\inf\oem24.inf
c:\windows\inf\oem24.PNF
c:\windows\inf\oem25.inf
c:\windows\inf\oem25.PNF
c:\windows\inf\oem26.inf
c:\windows\inf\oem26.PNF
c:\windows\inf\oem27.inf
c:\windows\inf\oem27.PNF
c:\windows\inf\oem28.inf
c:\windows\inf\oem28.PNF
c:\windows\inf\oem29.inf
c:\windows\inf\oem29.PNF
c:\windows\inf\oem3.inf
c:\windows\inf\oem3.PNF
c:\windows\inf\oem30.inf
c:\windows\inf\oem30.PNF
c:\windows\inf\oem31.inf
c:\windows\inf\oem31.PNF
c:\windows\inf\oem32.inf
c:\windows\inf\oem32.PNF
c:\windows\inf\oem33.inf
c:\windows\inf\oem33.PNF
c:\windows\inf\oem34.inf
c:\windows\inf\oem34.PNF
c:\windows\inf\oem35.inf
c:\windows\inf\oem36.inf
c:\windows\inf\oem36.PNF
c:\windows\inf\oem37.inf
c:\windows\inf\oem38.inf
c:\windows\inf\oem38.PNF
c:\windows\inf\oem39.inf
c:\windows\inf\oem39.PNF
c:\windows\inf\oem4.inf
c:\windows\inf\oem4.PNF
c:\windows\inf\oem5.inf
c:\windows\inf\oem5.PNF
c:\windows\inf\oem6.inf
c:\windows\inf\oem6.PNF
c:\windows\inf\oem7.inf
c:\windows\inf\oem7.PNF
c:\windows\inf\oem8.inf
c:\windows\inf\oem8.PNF
c:\windows\inf\oem9.inf
c:\windows\inf\oem9.PNF
c:\windows\inf\OOBE.INF
c:\windows\inf\OOBE.PNF
c:\windows\inf\OPTIONAL.INF
c:\windows\inf\optional.PNF
c:\windows\inf\OVCAM.INF
c:\windows\inf\OVCAM.PNF
c:\windows\inf\OVCOMP.INF
c:\windows\inf\OVCOMP.PNF
c:\windows\inf\OVSOUND.INF
c:\windows\inf\OVSOUND.PNF
c:\windows\inf\P2P.INF
c:\windows\inf\p2p.PNF
c:\windows\inf\PARHMSE.INF
c:\windows\inf\PARHMSE.PNF
c:\windows\inf\PCHEALTH.INF
c:\windows\inf\PCHEALTH.PNF
c:\windows\inf\PCMCIA.INF
c:\windows\inf\PCMCIA.PNF
c:\windows\inf\PERM2.INF
c:\windows\inf\PERM2.PNF
c:\windows\inf\PERM3.INF
c:\windows\inf\PERM3.PNF
c:\windows\inf\PHDSEXT.INF
c:\windows\inf\PHDSEXT.PNF
c:\windows\inf\PHIL1VID.INF
c:\windows\inf\PHIL1VID.PNF
c:\windows\inf\PHIL2VID.INF
c:\windows\inf\PHIL2VID.PNF
c:\windows\inf\PHILDEC.INF
c:\windows\inf\PHILDEC.PNF
c:\windows\inf\PHILTUNE.INF
c:\windows\inf\PHILTUNE.PNF
c:\windows\inf\PINBALL.INF
c:\windows\inf\pinball.PNF
c:\windows\inf\PMXMCRO.INF
c:\windows\inf\PMXMCRO.PNF
c:\windows\inf\PNPSCSI.INF
c:\windows\inf\PNPSCSI.PNF
c:\windows\inf\PPA.INF
c:\windows\inf\PPA.PNF
c:\windows\inf\PPA3.INF
c:\windows\inf\PPA3.PNF
c:\windows\inf\PRINTUPG.INF
c:\windows\inf\PRINTUPG.PNF
c:\windows\inf\PRTUPG9X.INF
c:\windows\inf\PRTUPG9X.PNF
c:\windows\inf\PS5333.INF
c:\windows\inf\PS5333.PNF
c:\windows\inf\PTPUSB.INF
c:\windows\inf\PTPUSB.PNF
c:\windows\inf\pxhelp20.inf
c:\windows\inf\pxhelp20.PNF
c:\windows\inf\QMGR.INF
c:\windows\inf\QMGR.PNF
c:\windows\inf\RAMDISK.INF
c:\windows\inf\RAMDISK.PNF
c:\windows\inf\RICOH.INF
c:\windows\inf\RICOH.PNF
c:\windows\inf\ROOTAU.INF
c:\windows\inf\rootau.PNF
c:\windows\inf\S3SAV3D.INF
c:\windows\inf\S3SAV3D.PNF
c:\windows\inf\S3SAV4.INF
c:\windows\inf\S3SAV4.PNF
c:\windows\inf\S3SAVMX.INF
c:\windows\inf\S3SAVMX.PNF
c:\windows\inf\S3TRIO3D.INF
c:\windows\inf\S3TRIO3D.PNF
c:\windows\inf\SAPI5.INF
c:\windows\inf\SAPI5.PNF
c:\windows\inf\SBP2.INF
c:\windows\inf\SBP2.PNF
c:\windows\inf\SCEREGVL.INF
c:\windows\inf\SCEREGVL.PNF
c:\windows\inf\SCSI.INF
c:\windows\inf\SCSI.PNF
c:\windows\inf\SCSIDEV.INF
c:\windows\inf\SCSIDEV.PNF
c:\windows\inf\SDBUS.INF
c:\windows\inf\SDBUS.PNF
c:\windows\inf\SDWNDR2K.INF
c:\windows\inf\SDWNDR2K.PNF
c:\windows\inf\SECDRV.INF
c:\windows\inf\SECDRV.PNF
c:\windows\inf\SECRECS.INF
c:\windows\inf\SECRECS.PNF
c:\windows\inf\SETUPQRY.INF
c:\windows\inf\setupqry.PNF
c:\windows\inf\SFFDISK.INF
c:\windows\inf\SFFDISK.PNF
c:\windows\inf\SGIU.INF
c:\windows\inf\SGIU.PNF
c:\windows\inf\SHELL.INF
c:\windows\inf\SHELL.PNF
c:\windows\inf\SHL_IMG.INF
c:\windows\inf\SHL_IMG.PNF
c:\windows\inf\SIS300I.INF
c:\windows\inf\SIS300I.PNF
c:\windows\inf\SIS6306.INF
c:\windows\inf\SIS6306.PNF
c:\windows\inf\SISGR.INF
c:\windows\inf\SISGR.PNF
c:\windows\inf\SISV6326.INF
c:\windows\inf\SISV6326.PNF
c:\windows\inf\SKINS.INF
c:\windows\inf\SKINS.PNF
c:\windows\inf\SLIP.INF
c:\windows\inf\SLIP.PNF
c:\windows\inf\SMARTCRD.INF
c:\windows\inf\SMARTCRD.PNF
c:\windows\inf\SMI.INF
c:\windows\inf\SMI.PNF
c:\windows\inf\SONYPVU1.INF
c:\windows\inf\SONYPVU1.PNF
c:\windows\inf\speer.inf
c:\windows\inf\speer.PNF
c:\windows\inf\SPX.INF
c:\windows\inf\SPX.PNF
c:\windows\inf\SPXPORTS.INF
c:\windows\inf\SPXPORTS.PNF
c:\windows\inf\SR.INF
c:\windows\inf\SR.PNF
c:\windows\inf\SRCHASST.INF
c:\windows\inf\SRCHASST.PNF
c:\windows\inf\SRUSBUSD.INF
c:\windows\inf\SRUSBUSD.PNF
c:\windows\inf\STALPORT.INF
c:\windows\inf\STALPORT.PNF
c:\windows\inf\STARTOC.INF
c:\windows\inf\startoc.PNF
c:\windows\inf\STI.INF
c:\windows\inf\STI.PNF
c:\windows\inf\STILLCAM.INF
c:\windows\inf\STILLCAM.PNF
c:\windows\inf\STREAMIP.INF
c:\windows\inf\STREAMIP.PNF
c:\windows\inf\SVCPACK.INF
c:\windows\inf\SVCPACK.PNF
c:\windows\inf\swflash.inf
c:\windows\inf\SWFLASH.PNF
c:\windows\inf\SWNT.INF
c:\windows\inf\SWNT.PNF
c:\windows\inf\SYSCOMP.INF
c:\windows\inf\SYSCOMP.PNF
c:\windows\inf\SYSOC.INF
c:\windows\inf\sysoc.PNF
c:\windows\inf\SYSSETUP.INF
c:\windows\inf\syssetup.PNF
c:\windows\inf\TAPE.INF
c:\windows\inf\TAPE.PNF
c:\windows\inf\TDIBTH.INF
c:\windows\inf\TDIBTH.PNF
c:\windows\inf\TGIU.INF
c:\windows\inf\TGIU.PNF
c:\windows\inf\TRID3D.INF
c:\windows\inf\TRID3D.PNF
c:\windows\inf\TRIDKB.INF
c:\windows\inf\TRIDKB.PNF
c:\windows\inf\TRIDXP.INF
c:\windows\inf\TRIDXP.PNF
c:\windows\inf\TSBVCAP.INF
c:\windows\inf\TSBVCAP.PNF
c:\windows\inf\TSHOOT.INF
c:\windows\inf\TSHOOT.PNF
c:\windows\inf\TSOC.INF
c:\windows\inf\tsoc.PNF
c:\windows\inf\UMAX.INF
c:\windows\inf\UMAX.PNF
c:\windows\inf\UMAXPP.INF
c:\windows\inf\UMAXPP.PNF
c:\windows\inf\UNKNOWN.INF
c:\windows\inf\UNKNOWN.PNF
c:\windows\inf\unregmp2.exe
c:\windows\inf\USB.INF
c:\windows\inf\USB.PNF
c:\windows\inf\USBPORT.INF
c:\windows\inf\usbport.PNF
c:\windows\inf\USBPRINT.INF
c:\windows\inf\USBPRINT.PNF
c:\windows\inf\USBSTOR.INF
c:\windows\inf\USBSTOR.PNF
c:\windows\inf\USBVIDEO.INF
c:\windows\inf\USBVIDEO.PNF


This post has been edited by geminis076: Jan 14 2008, 05:19 PM
Go to the top of the page
 
+Quote Post
geminis076
post Jan 14 2008, 05:21 PM
Post #34


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Here's part two:

c:\windows\inf\VGX.INF
c:\windows\inf\VGX.PNF
c:\windows\inf\VIAFIR2K.INF
c:\windows\inf\VIAFIR2K.PNF
c:\windows\inf\VOLSNAP.INF
c:\windows\inf\VOLSNAP.PNF
c:\windows\inf\VOLUME.INF
c:\windows\inf\volume.PNF
c:\windows\inf\WAB50.INF
c:\windows\inf\WAB50.PNF
c:\windows\inf\WAVE.INF
c:\windows\inf\wave.PNF
c:\windows\inf\WBEMOC.INF
c:\windows\inf\wbemoc.PNF
c:\windows\inf\WBEMSNMP.INF
c:\windows\inf\wbemsnmp.PNF
c:\windows\inf\WBFIRDMA.INF
c:\windows\inf\WBFIRDMA.PNF
c:\windows\inf\WCEUSBSH.INF
c:\windows\inf\WCEUSBSH.PNF
c:\windows\inf\WDMA_ALI.INF
c:\windows\inf\WDMA_ALI.PNF
c:\windows\inf\WDMA_AUR.INF
c:\windows\inf\WDMA_AUR.PNF
c:\windows\inf\WDMA_AVC.INF
c:\windows\inf\WDMA_AVC.PNF
c:\windows\inf\WDMA_AZT.INF
c:\windows\inf\WDMA_AZT.PNF
c:\windows\inf\WDMA_CSC.INF
c:\windows\inf\WDMA_CSC.PNF
c:\windows\inf\WDMA_CSF.INF
c:\windows\inf\WDMA_CSF.PNF
c:\windows\inf\WDMA_CTL.INF
c:\windows\inf\WDMA_CTL.PNF
c:\windows\inf\WDMA_CWR.INF
c:\windows\inf\WDMA_CWR.PNF
c:\windows\inf\WDMA_ENS.INF
c:\windows\inf\WDMA_ENS.PNF
c:\windows\inf\WDMA_ES2.INF
c:\windows\inf\WDMA_ES2.PNF
c:\windows\inf\WDMA_ES3.INF
c:\windows\inf\WDMA_ES3.PNF
c:\windows\inf\WDMA_ESS.INF
c:\windows\inf\WDMA_ESS.PNF
c:\windows\inf\WDMA_INT.INF
c:\windows\inf\WDMA_INT.PNF
c:\windows\inf\WDMA_M2E.INF
c:\windows\inf\WDMA_M2E.PNF
c:\windows\inf\WDMA_NE2.INF
c:\windows\inf\WDMA_NE2.PNF
c:\windows\inf\WDMA_NEO.INF
c:\windows\inf\WDMA_NEO.PNF
c:\windows\inf\WDMA_RIP.INF
c:\windows\inf\WDMA_RIP.PNF
c:\windows\inf\WDMA_SIS.INF
c:\windows\inf\WDMA_SIS.PNF
c:\windows\inf\WDMA_USB.INF
c:\windows\inf\WDMA_USB.PNF
c:\windows\inf\WDMA_VIA.INF
c:\windows\inf\WDMA_VIA.PNF
c:\windows\inf\WDMA_YM2.INF
c:\windows\inf\WDMA_YM2.PNF
c:\windows\inf\WDMA_YMH.INF
c:\windows\inf\WDMA_YMH.PNF
c:\windows\inf\WDMA10K1.INF
c:\windows\inf\WDMA10K1.PNF
c:\windows\inf\WDMAUDIO.INF
c:\windows\inf\WDMAUDIO.PNF
c:\windows\inf\WDMJOY.INF
c:\windows\inf\WDMJOY.PNF
c:\windows\inf\WFP0.INF
c:\windows\inf\WFP0.PNF
c:\windows\inf\WFP1.INF
c:\windows\inf\WFP1.PNF
c:\windows\inf\WFP2.INF
c:\windows\inf\WFP2.PNF
c:\windows\inf\WFP3.INF
c:\windows\inf\WFP3.PNF
c:\windows\inf\WFP4.INF
c:\windows\inf\WFP4.PNF
c:\windows\inf\WFP5.INF
c:\windows\inf\WFP5.PNF
c:\windows\inf\WFP6.INF
c:\windows\inf\WFP6.PNF
c:\windows\inf\WFP7.INF
c:\windows\inf\WFP7.PNF
c:\windows\inf\WFP8.INF
c:\windows\inf\WFP8.PNF
c:\windows\inf\WMACCESS.INF
c:\windows\inf\wmaccess.PNF
c:\windows\inf\WMDM.INF
c:\windows\inf\WMDM.PNF
c:\windows\inf\WMDM10.inf
c:\windows\inf\WMDM10.PNF
c:\windows\inf\WMFSDK.INF
c:\windows\inf\WMFSDK.PNF
c:\windows\inf\WMFSDK10.inf
c:\windows\inf\WMFSDK10.PNF
c:\windows\inf\WMP.INF
c:\windows\inf\WMP.PNF
c:\windows\inf\WMP10.inf
c:\windows\inf\WMP10.PNF
c:\windows\inf\wmplayer.adm
c:\windows\inf\WMPOCM.INF
c:\windows\inf\wmpocm.PNF
c:\windows\inf\WMSET10.inf
c:\windows\inf\WMSET10.PNF
c:\windows\inf\wmsetsdk.inf
c:\windows\inf\wmsetsdk.PNF
c:\windows\inf\WMTOUR.INF
c:\windows\inf\WMTOUR.PNF
c:\windows\inf\WORDPAD.INF
c:\windows\inf\wordpad.PNF
c:\windows\inf\wpd10.inf
c:\windows\inf\WPD10.PNF
c:\windows\inf\wpdmtp.inf
c:\windows\inf\wpdmtp.PNF
c:\windows\inf\WSH.INF
c:\windows\inf\WSH.PNF
c:\windows\inf\WSTCODEC.INF
c:\windows\inf\WSTCODEC.PNF
c:\windows\inf\WTV0.INF
c:\windows\inf\WTV0.PNF
c:\windows\inf\WTV1.INF
c:\windows\inf\WTV1.PNF
c:\windows\inf\WTV2.INF
c:\windows\inf\WTV2.PNF
c:\windows\inf\WTV3.INF
c:\windows\inf\WTV3.PNF
c:\windows\inf\WTV4.INF
c:\windows\inf\WTV4.PNF
c:\windows\inf\WTV5.INF
c:\windows\inf\WTV5.PNF
c:\windows\inf\wuau.adm
c:\windows\inf\XSCAN_XP.INF
c:\windows\inf\XSCAN_XP.PNF
c:\windows\inf . . . . failed to delete
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2007-12-14 to 2008-01-14 )))))))))))))))))))))))))))))))
.

2008-01-13 20:28 . 2008-01-13 20:28 <DIR> d-------- C:\WINDOWS\inf
2008-01-13 15:44 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SDTHOOK.SYS
2008-01-13 15:28 . 2008-01-13 16:44 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2008-01-13 15:28 . 2008-01-13 15:28 30,590 --a------ C:\WINDOWS\SYSTEM32\pavas.ico
2008-01-13 15:28 . 2008-01-13 15:28 2,550 --a------ C:\WINDOWS\SYSTEM32\Uninstall.ico
2008-01-13 15:28 . 2008-01-13 15:28 1,406 --a------ C:\WINDOWS\SYSTEM32\Help.ico
2008-01-12 00:26 . 2008-01-12 00:26 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-12 00:10 . 2008-01-12 00:11 <DIR> d-------- C:\Program Files\Java
2008-01-12 00:10 . 2008-01-12 00:10 <DIR> d-------- C:\Program Files\Common Files\Java
2008-01-10 19:04 . 2008-01-10 19:04 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-01-10 19:04 . 2008-01-10 19:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-10 17:31 . 2008-01-12 21:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-09 03:26 . 2008-01-09 03:26 129 --a------ C:\WINDOWS\SYSTEM32\MRT.INI
2008-01-08 14:58 . 2008-01-08 14:58 <DIR> d-------- C:\Deckard
2008-01-07 13:41 . 2008-01-08 21:19 94,208 --a------ C:\WINDOWS\SYSTEM32\igfxtray.exe
2008-01-06 23:26 . 2008-01-11 15:27 <DIR> d-------- C:\Program Files\kernel
2008-01-06 23:23 . 2008-01-06 23:23 86,016 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\httpp.sys
2008-01-06 23:23 . 2008-01-13 20:28 932 --------- C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk
2008-01-06 15:48 . 2008-01-06 18:42 <DIR> d-------- C:\Program Files\Incomplete
2008-01-06 15:42 . 2008-01-08 21:21 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-05 14:23 . 2008-01-05 14:23 <DIR> d-------- C:\Documents and Settings\natalie\Incomplete
2008-01-03 23:40 . 2008-01-03 23:40 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-01-03 23:39 . 2008-01-03 23:39 <DIR> d-------- C:\Program Files\Real
2007-12-26 21:25 . 2008-01-13 16:22 <DIR> d-------- C:\Program Files\iTunes2
2007-12-26 21:18 . 2007-12-26 21:18 <DIR> d----c--- C:\WINDOWS\SYSTEM32\DRVSTORE
2007-12-26 21:18 . 2007-12-26 21:18 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-12-26 21:18 . 2007-12-26 21:18 <DIR> d-------- C:\Program Files\Apple Software Update
2007-12-26 21:18 . 2007-12-26 21:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-12-26 21:18 . 2007-10-31 14:09 30,464 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbaapl.sys
2007-12-26 21:13 . 2007-12-26 21:14 54,330,664 --a------ C:\Program Files\iTunesSetup.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-14 00:31 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-01-14 00:21 --------- d-----w C:\Program Files\Google
2008-01-14 00:21 --------- d-----w C:\Program Files\eFax Messenger 4.1
2008-01-12 08:27 --------- d-----w C:\Documents and Settings\natalie\Application Data\SUPERAntiSpyware.com
2008-01-11 23:27 --------- d-----w C:\Program Files\QuickTime
2008-01-11 23:27 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-11 01:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-11 01:28 --------- d-----w C:\Documents and Settings\natalie\Application Data\Yahoo!
2008-01-08 07:34 10 ----a-w C:\Program Files\.autoreg
2008-01-08 07:19 --------- d-----w C:\Program Files\Corel
2008-01-07 07:28 --------- d-----w C:\Program Files\Ad-Aware
2008-01-07 07:23 246 ----a-w C:\Program Files\Common Files\lavul
2008-01-04 08:49 --------- d-----w C:\Documents and Settings\natalie\Application Data\uTorrent
2008-01-04 07:40 --------- d-----w C:\Program Files\Common Files\Real
2008-01-02 06:45 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-27 05:25 --------- d-----w C:\Program Files\iTunes
2007-12-27 05:25 --------- d-----w C:\Program Files\iPod
2007-11-25 08:01 --------- d-----w C:\Documents and Settings\natalie\Application Data\Snapfish
2007-11-24 07:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2007-11-24 07:31 --------- d-----w C:\Program Files\Kodak
2007-11-24 07:31 --------- d-----w C:\Program Files\Common Files\Kodak
2007-04-02 02:06 0 -c--a-w C:\Documents and Settings\natalie\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( snapshot_2008-01-11_15.33.51.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-24 16:28:54 141,424 ----a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
- 2008-01-11 23:23:11 245,760 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-14 04:17:16 245,760 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-11 23:23:11 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-14 04:17:16 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-11 23:23:11 249,856 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-14 04:17:16 249,856 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-11 23:23:11 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-14 04:17:16 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-11 23:23:12 6,184,960 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-14 04:17:17 6,184,960 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-11 23:23:12 339,968 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-14 04:17:17 339,968 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-12 08:27:12 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2008-01-12 08:27:12 18,944 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-01-12 08:27:12 65,024 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2007-03-29 17:20:50 110,592 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\as.dll
+ 2006-10-06 00:15:26 233,472 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\ascontrol.dll
+ 2005-06-03 22:03:18 96,256 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\asmdat.dll
+ 2003-08-01 19:00:16 36,864 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\certdll.dll
+ 2005-05-20 21:42:44 86,016 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\instlsp.dll
+ 2007-11-12 17:46:18 26,112 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\JID.dll
+ 2006-02-17 02:20:20 4,608 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\memvfile.dll
+ 2005-10-26 02:08:32 348,160 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\msvcr71.dll
+ 2007-11-26 19:10:36 61,440 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\NanoWrapper.dll
+ 2004-05-04 23:01:02 139,264 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavaleas.dll
+ 2006-07-14 21:04:10 45,056 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavdr.exe
+ 2006-04-10 18:50:02 159,832 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavexcom.dll
+ 2006-02-14 21:05:38 94,208 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavinas.dll
+ 2006-02-17 02:35:38 180,224 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavoe.dll
+ 2006-10-06 00:15:38 122,880 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavpz.dll
+ 2007-06-04 19:31:52 57,344 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavsddl.dll
+ 2006-06-30 22:13:38 8,704 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pfdnnt.exe
+ 2004-02-04 22:08:42 49,152 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\port32.dll
+ 2007-10-30 18:04:14 36,864 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\Prescan.dll
+ 2006-08-01 21:23:10 69,632 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pscpu.dll
+ 2007-11-21 18:00:06 376,832 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskahk.dll
+ 2007-10-31 21:05:06 32,768 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\PSKAHKPRESCAN.dll
+ 2006-08-17 19:38:14 10,752 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskalloc.dll
+ 2006-09-04 19:49:54 61,440 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskas.dll
+ 2006-08-18 16:46:18 779,264 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll
+ 2007-03-26 22:25:34 417,792 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskcmp.dll
+ 2006-08-09 18:42:24 90,112 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskfss.dll
+ 2006-07-19 18:55:58 208,896 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskhtml.dll
+ 2006-01-21 00:57:00 9,728 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmas.dll
+ 2006-05-17 17:50:12 14,336 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmdfs.dll
+ 2006-08-16 18:58:12 33,280 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskpack.dll
+ 2006-06-30 22:42:36 266,240 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskscs.dll
+ 2006-08-17 22:33:14 62,976 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskutil.dll
+ 2006-08-08 21:13:10 13,312 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfile.dll
+ 2006-08-18 16:53:08 69,632 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfs.dll
+ 2006-08-18 16:49:50 167,936 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvm.dll
+ 2007-10-18 17:30:16 105,472 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnahk.dll
+ 2007-11-23 22:29:08 10,752 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psndsk.dll
+ 2007-10-18 17:30:38 42,496 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnflg.dll
+ 2007-10-30 19:19:22 98,304 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnglknt.dll
+ 2007-08-22 16:52:00 20,272 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnhsh.dll
+ 2007-11-12 23:49:34 11,776 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnjidsign.dll
+ 2007-08-22 16:52:04 76,080 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnkrnl.dll
+ 2007-08-22 16:52:06 21,296 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psnmem.dll
+ 2007-10-04 23:26:28 28,672 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\PsnPen.dll
+ 2007-10-23 19:40:10 86,016 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psntuc.dll
+ 2007-05-24 19:27:36 27,136 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\PSNXprs.dll
+ 2007-04-19 01:16:04 353,840 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\psscan.dll
+ 2007-01-22 22:42:48 35,328 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\rawvfile.dll
+ 2007-06-08 17:44:36 8,576 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\RKPavProc.sys
+ 2007-06-05 18:56:40 44,928 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\sdthook.sys
+ 1997-09-18 14:12:32 9,488 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\sporder.dll
+ 2006-03-01 01:23:40 69,632 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\tcpvfile.dll
+ 2007-09-17 17:14:08 126,976 ----a-w C:\WINDOWS\SYSTEM32\ActiveScan\Tucan.dll
+ 2006-08-02 20:39:06 73,728 ----a-w C:\WINDOWS\SYSTEM32\asuninst.exe
- 2007-07-12 08:22:00 135,168 ----a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2007-12-14 08:57:22 135,168 ----a-w C:\WINDOWS\SYSTEM32\java.exe
- 2007-07-12 08:22:04 135,168 ----a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-12-14 08:57:24 135,168 ----a-w C:\WINDOWS\SYSTEM32\javaw.exe
- 2007-07-12 09:22:38 139,264 ----a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2007-12-14 09:59:16 139,264 ----a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2003-03-26 02:53:50 11,776 ----a-w C:\WINDOWS\SYSTEM32\ZPORT4AS.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm .exe" [ ]
"Yahoo! Pager"="1" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2008-01-09 13:40 1388544]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2008-01-09 13:40 221184]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2008-01-09 13:40 290816]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [ ]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29 303104]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05 212992]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [ ]
"BJPD HID Control"="C:\Program Files\Canon\BJPV\TVMon.exe" [2008-01-09 13:40 45056]
"eFax 4.1"="C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" [2008-01-09 13:40 107008]
"ADUserMon"="C:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [2008-01-09 13:40 147456]
"Iomega Drive Icons"="C:\DELL\HIGH SPEED INTERNET OFFERS\CONSUMER\STYLES\MPS\MORPHEUS\DOWNLOADS\DriveIcons\ImgIcon.exe" [2008-01-09 13:40 86016]
"Deskup"="C:\DELL\HIGH SPEED INTERNET OFFERS\CONSUMER\STYLES\MPS\MORPHEUS\DOWNLOADS\DriveIcons\deskup.exe" [2008-01-09 13:40 32768]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [ ]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2008-01-09 13:40 368706]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [ ]
"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2008-01-08 21:19 94208]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2008-01-09 13:40 131072]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2008-01-09 13:40 53248]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2008-01-09 13:40 57344]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2008-01-09 13:40 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes2\iTunesHelper.exe" [2008-01-09 13:40 267048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-09 13:40 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-14 17:10:07]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R1 httpp;httpp;C:\WINDOWS\system32\drivers\httpp.sys [2008-01-06 23:23]
S3 FilterService2;Canon BJ Hid Usb Filter Service2;C:\WINDOWS\system32\DRIVERS\bjhid2.sys [2003-06-17 01:43]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE31bus.sys [2006-05-01 03:56]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE31mdfl.sys [2006-05-01 03:57]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE31mdm.sys [2006-05-01 03:57]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE31mgmt.sys [2006-05-01 03:58]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS);C:\WINDOWS\system32\DRIVERS\se31nd5.sys [2006-05-01 03:56]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE31obex.sys [2006-05-01 03:59]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM);C:\WINDOWS\system32\DRIVERS\se31unic.sys [2006-05-01 03:56]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ebb7e7e-825d-11db-9882-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ebb7e80-825d-11db-9882-00038a000015}]
\Shell\AutoRun\command - G:\Autorun.exe /run
\Shell\Shell00\Command - G:\Autorun.exe /run
\Shell\Shell01\Command - G:\Autorun.exe /action
\Shell\Shell02\Command - G:\Autorun.exe /uninstall

.
Contents of the 'Scheduled Tasks' folder
"2008-01-09 16:10:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-12 02:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (1) (DH7D6961-natalie).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2008-01-12 02:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DH7D6961-natalie).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2007-07-03 06:13:44 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot\SpybotSD.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-13 20:29:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\WINDOWS\TEMP

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2008-01-13 20:34:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-14 04:34:35
ComboFix2.txt 2008-01-11 23:34:16
ComboFix3.txt 2008-01-11 02:29:34
ComboFix4.txt 2008-01-09 23:49:13
.
2008-01-10 01:54:41 --- E O F ---
Go to the top of the page
 
+Quote Post
Stamper19
post Jan 14 2008, 07:13 PM
Post #35


Trusted Helper
Group Icon
Posts: 1,991
OS: Windows XP



No worries at all about the post smile.gif

Things are looking pretty good. Lets just try two more things.

---------------------------------------------------

Lets delete some ill mannered files.

Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk

  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please "Copy" the results from the "Results" window (to the right) and then "Paste" them into your next reply on the forum. Reboot into Normal Mode.
---------------------------------------------------

Please re-run Deckards System Scanner (DSS), but using a slightly different procedure.
  • Click on Start, click on Run
  • Copy and paste the following in bold in the open window and then click OK
      "%userprofile%\desktop\dss.exe" /config
  • This will open up DSS configuration
  • Click on Check All
  • Click Scan
  • DSS will now run again
  • When finished, please post back both logs that open in notepad: Main txt and extra txt
Go to the top of the page
 
+Quote Post
geminis076
post Jan 14 2008, 09:55 PM
Post #36


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Hello. I ran into some issues lookaround.gif . With OTMoveIt, file move failed and I was asked to reboot to finish the move. I did reboot, but not sure where to find the results. OTMoveIt closed upon reboot, and did not reopen afterwards - not sure if it was suppose to. There is no log present in the 'results' window when re-opened, and I don't believe a .txt file was created on the desktop. I retried things to see what would happen, same as above happened. I checked the file path before clicking just to make sure it copied correctly, everything was fine.

I was not able to perform the DSS scan via Start & Run. When I copy the info into the window and click OK, which I also tried a few times and double checked to make sure things were correct, Windows is not able to find it. Here's what the message says:


Windows cannot find 'C:\Documents and Settings\natalie\desktop\dss.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click search.


I feel I did everything correctly, it's pretty simple and straight-forward. This time I did pay closer attention to postings and what got copied over, and things seemed right. Any suggestions, or other things to try?
Go to the top of the page
 
+Quote Post
Stamper19
post Jan 15 2008, 06:53 AM
Post #37


Trusted Helper
Group Icon
Posts: 1,991
OS: Windows XP



Not a big deal. Everything I had you do was really redundent to thing we have already done - just wanted to make sure of a couple of things.

Is your McAfee AntiVirus working and up to date? How are things running at this point?
Go to the top of the page
 
+Quote Post
geminis076
post Jan 15 2008, 12:23 PM
Post #38


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Hello. The start-up seems back to normal, internet connection and speed are good - never really affected, the desktop icon appearance is still back to normal. Still have pop up ads coming in, not as continiously as they were, they're coming in at a slower rate - depending on what I'm browsing for, when they do start I usually receive about 10 to 17 within about 10 minutes.

I haven't updated my McAfee yet, guess I'm hesitating because through Dell it would cost $70.00 to renew. I see Bestbuy sells McAfee VirusScan Plus for Windows for $40.00, but not sure if that includes a subscription or just the software. But $70.00 when broken down over the course of a year isn't that expensive, about $6.00 a month. Compared to free things you can get online, the difference is that McAfee is constantly running and searching? But it's still possible for things to get through right?, just makes things harder for the harmful stuff?
Go to the top of the page
 
+Quote Post
Stamper19
post Jan 15 2008, 03:53 PM
Post #39


Trusted Helper
Group Icon
Posts: 1,991
OS: Windows XP



We need to get that AntiVirus updated or replaced ASAP.

Avira OR AVG are good FREE antivirus programs. If you want to get rid of McAfee you can install either of the two, but not both.
Never install more than one antivirus scanner on your system! Several together can give problems and seriously decrease reliability!

As for the pop-ups, there are a lot of sites that can cause them without you necessarily being infected with malware. A good AntiSpyware or comprehensive internet security program (like you McAfee) will often block most of them. You should also install google toolbar. It helps to block pop-ups as well.

Let me know what you decide with the AntiVirus. Depending on your decision, we might have to get an AntiSpyware Program as well.
Go to the top of the page
 
+Quote Post
geminis076
post Jan 15 2008, 05:01 PM
Post #40


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Hi, I currently have AVG on my computer. I was asked to install it when I had my last infection in July, but haven't used it since. And since McAfee has long expired, haven't really used that for anything either. Not sure how helpful it is, but I usually use Lavasoft Ad-aware personal. Now that I'm checking things, I seem to have a few antivirus/spyware related items on my computer. Any suggestions on which to get rid of or keep? I'll list everything I have :

AVG 7.5
Lavasoft Ad-Aware
Yahoo Anti-Spy (haven't used)

and SuperAntiSpyware from this time, and McAfee. Actually I have the Google Toolbar installed in both IE and Firefox, but I just read that the blocking feature is only available for IE. In IE, it is currently on but IE is what's giving me problems, this time and last, so I mainly use Firefox and switch over to IE when required for installations or downloads.

If I renew with McAfee it probably wouldn't be very soon, at least not this month, I'll need to set aside a little $ first. I'll see if I can at least update it without having a subscription, but like I said it's been expired for a while, at least 1 year if not a little more, so I would be okay with uninstalling it.


Go to the top of the page
 
+Quote Post
Stamper19
post Jan 15 2008, 05:05 PM
Post #41


Trusted Helper
Group Icon
Posts: 1,991
OS: Windows XP



The AVG I sent you is AVG AntiVirus. The one you have is AVG AntiSpyware. I would download the AntiVirus version if you are going to get rid of McAfee. I would also keep AVG 7.5 and get rid of Lavasoft and Yahoo. You only need on resident anti spyware. You can keep SuperAntiSpyware and scan with it from time to time. It is different from AVG 7.5 in that is on demand, wheras AVG 7.5 is always running. Do you understand?
Go to the top of the page
 
+Quote Post
geminis076
post Jan 16 2008, 04:17 PM
Post #42


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Hello. Sorry I wasn't able to get back yesterday. I was finally able to locate my McAfee login information, and looks like it expired in Oct. 2005. I think I'll just go ahead and uninstall it, obviously I haven't been using it so I don't think I'll miss it much.

Yes, the information is clear. So I'll get rid of the others and keep the AVGs, I'll keep the SuperAntiSpyware too. System seems to be running okay, it froze last night but not sure if my issue is to blame since it happens every now and then. But did have to reboot. Lots of pop-up ads are still coming in though, sometimes the rate is slow, other times I'm bombarded with several at once (5 to 10+). They were very active yesterday, probably the most I've seen since this happened, they're very quiet at the moment. Google toolbar usually has about 30 on its list, and about 20 eventually make their way onto my desktop - mostly adult ads and contests. I've set the blocker setting to high, the adult ones are still persistent but maybe it's helped in slowing them down.

Go to the top of the page
 
+Quote Post
Stamper19
post Jan 16 2008, 05:25 PM
Post #43


Trusted Helper
Group Icon
Posts: 1,991
OS: Windows XP



No need to apologize smile.gif

There is definately still something hanging around on the system. Get the new AntiVirus installed and run a scan with it immediately. Post any logs or such associated with that scan. Perhaps it will nab whatever is left over. Once we get that done we'll see where we are at and what we want to do next smile.gif
Go to the top of the page
 
+Quote Post
geminis076
post Jan 17 2008, 02:42 AM
Post #44


Member
**
Posts: 41
From: Northern California
OS: Windows XP



Hi, I performed a scan with AVG Anti-Virus, there's a log but it's not something I can copy and paste. Here's a summary of what it found, if you have questions about anything let me know and I can type out details:

Object Summary:

* Scanned: 68226
* Threats found: 91
* Cleaned: 0
* Moved to vault: 1
* Deleted: 89
* Errors: 0

As for the 'Virus results', most of the object status is listed as 'deleted', I'll post the few that are labeled differently:

--------------------------------------------------------------------------------------
C:\Documents and Settings\natalie\Local Settings\Temporary Internet Files\Content.IE5\BJX070TG\2900229[1].htm

* Result: Virus found JS / Dowloader.Agent
* Status: Infected
--------------------------------------------------------------------------------------

C:\QooBox\Quarantine\catchme2008-01-09_154426.96.zip:\awvtu.dll

* Result: Trojan horse Generic9.AMGK
* Status: Infected, Embedded object, deleted
--------------------------------------------------------------------------------------

C:\QooBox\Quarantine\catchme2008-01-09_154426.96.zip

* Result: 'blank'
* Status: Moved to Vault, Archive


Hope this helps, thanks smile.gif .

Go to the top of the page
 
+Quote Post
Stamper19
post Jan 17 2008, 10:27 AM
Post #45


Trusted Helper
Group Icon
Posts: 1,991
OS: Windows XP



Hi geminis076,

Hard to tell from that if it got what was causing the issue. It is likely that most of the hits were quarantined files that we already killed, but who knows.. Let me know if you are still getting the popups. Also, we'll run a new kapersky scan along with one other.


----------------------------------------------------------------

Please clean out your temp files.

Please download ATF Cleaner by Atribune. If you already have it then skip to the next step. Also, you should run it for both explorer and firefox.
This program is for XP and Windows 2000 only
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

----------------------------------------------------------------

Click here to download AVG Anti Rootkit and save it to your desktop.

  • Double-click on the AVG_AntiRootkit_1.0.0.13.exe file to run it.
  • Click "I Agree" to agree to the EULA.
  • By default it will install to "G:\Program Files\GRISOFT\AVG Anti-Rootkit Beta".
  • Click "Next" to begin the installation then click "Install".
  • It will then ask you to reboot now to finish the installation.
  • Click "Finish" and your computer will reboot.
  • After it reboots, double-click on the AVG Anti-Rootkit Beta shortcut that is now on your desktop.
  • Click on the "Perform in-depth search" button to begin the scan.
  • The scan will take a while so be patient and let it complete.
  • When the scan is finished, click the "Save result to file" button.
  • Save the scan results to your desktop then come back here to copy and paste the results in your next reply to this thread.


----------------------------------------------------------------

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      Extended (if available otherwise Standard)
    • Scan Options:
      Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
      Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

----------------------------------------------------------------

Information to include in your next post:
  • AVG AntiRootKit Log
  • Kapersky Scan Log
  • Fresh HiJack This log
  • Let me know how the computer is running.
Go to the top of the page
 
+Quote Post

5 Pages V  < 1 2 3 4 5 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 11:53 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising