Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Slow Vista [CLOSED]


  • This topic is locked This topic is locked

#1
phala

phala

    New Member

  • Member
  • Pip
  • 2 posts
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:21:29 PM, on 4/29/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SYSTEM32\taskeng.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Windows\stsystra.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Bit Lord 1.1\BitLord.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061023
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061023
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [Generic Host Process for Win32 Services] svchosts.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\RunServices: [Generic Host Process for Win32 Services] svchosts.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O8 - Extra context menu item: &Search - ?p=ZNfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://xiah.gamescam...GamesCampus.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1166784807656
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/...O1.cab50727.cab
O16 - DPF: {A9FDC7FD-FE81-4910-8CF2-FA59EEFE11EC} (ZooInstaller Class) - http://www.zoo-games...ooInstaller.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecu...asyInstallX.CAB
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-sec...m/ols/fscax.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 10509 bytes
  • 0

Advertisements


#2
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there phala,

I am currently looking over you log and will be back with you soon.
  • 0

#3
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi again phala,

Please follow my instructions in the order they were given, if you come across something you don't understand or don't feel comfortable doing, don't hesitate to ask and I will get you sorted out :)

Step 1. Preperation

Some security programs with active monitoring processes are known to interfere with automatic scanners and can actually prevent HJT fixes from taking effect.

Please turn off or disable any of the following programs you may have, before running your preliminary scans and for the duration of your HJT cleanup.

Spybot S&D (Teatimer)

1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.

Disable SpySweeper

Courtesy of Askey127

If you have Spy Sweeper version 4:

* Open it, Click Options over on the left, then Program options
* Uncheck load at windows startup.
* Over to the left, Click shields and Uncheck all there.
* Uncheck home page shield.
* Uncheck automatically restore default without notification.
* Reboot your machine for the changes to take effect before running HJT.

+++++++++++++++++++++++++++++

If you have SpySweeper version 5:

To disable SpySweeper Shields

* Open SpySweeper.
* Click Shield Settings on the right

(or Shields on the left, depending what screen you're on).

* Click Internet Explorer and uncheck all items.
* Click Windows System and uncheck all items.
* Click Hosts File and uncheck all items.
* Click Startup Programs and uncheck all items.
* Close SpySweeper.

Reboot you computer, and ensure Spy Sweeper is disabled.

Step 2. Fixes

Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):
MyWebSearch
Please note any other programs that you don't recognize in that list in your next response.

Open notepad by going to START > RUN and type notepad.exe in the box that appears. In the window that pops up please copy and paste the following

@ECHO off
sc stop MyWebSearchService
sc delete MyWebSearchService
exit

In Notepad click on the "File" menu > Save As... Under "File name" type fix.bat and Change "Save as type" to All Files, save it to a place you will remember.
Posted Image

Double click on fix.bat.

Now please open HijackThis again and choose "Do a system scan only". Please put a check next to each of the following entries (if still present):

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)

O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)

O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

O8 - Extra context menu item: &Search - ?p=ZNfox000

O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe

Now please close all open windows except HJT and press "Fix checked".

Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present):C:\PROGRAM FILES\MYWEBSEARCH
Step 3. Running SDFix

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).

Step 4. Deckards' System Scanner

This line indicates that some startup items have been unchecked in msconfig, please re-check these items so I can see them in the log.
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

In your next reply

Please post Report.txt from step 3.
Please post main.txt and extra.txt from step 4.
  • 0

#4
phala

phala

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
Thanks for answering so quickly. :)

Report txt. Step3


System Report
*************

Run on Wed 04/30/2008 at 12:31 PM

Microsoft Windows [Version 6.0.6000]

Current user is not an administrator

Running Processes:

C:\Windows\system32\Dwm.exe [1684]
C:\Windows\Explorer.EXE [1720]
C:\Windows\SYSTEM32\taskeng.exe [1880]
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe [3584]
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [3596]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [3636]
C:\Program Files\Unlocker\UnlockerAssistant.exe [3644]
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe [3672]
C:\Windows\stsystra.exe [3704]
C:\Windows\System32\hkcmd.exe [3744]
C:\Windows\System32\igfxpers.exe [3756]
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe [3764]
C:\Program Files\Microsoft IntelliType Pro\itype.exe [3772]
C:\Program Files\Microsoft IntelliPoint\ipoint.exe [3828]
C:\Program Files\QuickTime\QTTask.exe [3864]
C:\Program Files\iTunes\iTunesHelper.exe [3888]
C:\Program Files\Windows Sidebar\sidebar.exe [3932]
C:\Program Files\Windows Media Player\wmpnscfg.exe [3940]
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe [1752]
C:\Windows\system32\igfxsrvc.exe [3432]


Drivers - Running:

ACPI
AFD
AFS2K
AsyncMac
Beep
bowser
cdrom
CLFS
crcdisk
DfsC
disk
DLABMFSM
DLABOIOM
DLACDBHM
DLADResM
DLAIFS_M
DLAOPIOM
DLAPoolM
DLARTL_M
DLAUDFAM
DLAUDF_M
Dot4
Dot4Print
dot4usb
DRVMCDB
DRVNDDM
DXGKrnl
e1express
Ecache
elagopro
elaunidr
fastfat
FileInfo
FltMgr
GEARAspiWDM
HDAudBus
HidUsb
HTTP
iaStor
iaStorV
igfx
intelppm
IpFilterDriver
iScsiPrt
kbdclass
kbdhid
KSecDD
lltdio
luafv
mcdbus
Modem
monitor
mouclass
mouhid
MountMgr
MpFilter
mpsdrv
MRxDAV
mrxsmb
mrxsmb10
mrxsmb20
Msfs
MSFWDrv
MSFWHLPR
msisadrv
mssmbios
Mup
NDIS
NdisTapi
NdisWan
NDProxy
NetBIOS
netbt
Npfs
nsiproxy
Ntfs
NuidFltr
Null
partmgr
pci
PEAUTH
pfc
PfModNT
Point32
PptpMiniport
PSched
PxHelp20
RasAcd
Rasl2tp
RasPppoe
rdbss
RDPCDD
RDPENCDD
rspndr
SASDIFSV
SASKUTIL
SCDEmu
secdrv
Smb
spldr
sptd
srv
srv2
srvnet
SSFS0BB9
SSHRMD
SSIDRV
SSKBFD
STHDA
swenum
Tcpip
tcpipreg
tdx
TermDD
tmlwf
tmwfp
tunmp
tunnel
umbus
usbccgp
usbehci
usbhub
usbprint
usbscan
USBSTOR
usbuhci
VgaSave
vmm
volmgr
volmgrx
volsnap
VPCNetS2
VSTHWBS2
VST_DPV
Wanarpv6
Wdf01000
winachsf
WUDFRd


Drivers - Stopped:

abp480n5
adp94xx
adpahci
adpu160m
adpu320
agp440
Aha154x
aic78u2
aic78xx
aliide
amdagp
amdide
AmdK7
AmdK8
amsint
arc
arcsas
asc
asc3350p
asc3550
atapi
blbdrive
BrFiltLo
BrFiltUp
Brserid
BrSerWdm
BrUsbMdm
BrUsbSer
BTHMODEM
cd20xrnt
cdfs
circlass
cmdide
Compbatt
Cpqarray
Crusoe
dac2w2k
dac960nt
dpti2o
drmkaud
DSproct
E1G60
EagleNT
elxstor
fdc
Filetrace
flpydisk
gagp30kx
grmnusb
HidBth
HidIr
HpCISSs
hpn
i2omp
i8042prt
ialm
iirsp
ini910u
intelide
IpInIp
IPMIDRV
IPNAT
IRENUM
isapnp
iteatapi
iteraid
LHidFilt
LHidKe
LMouFilt
LMouKE
LSI_FC
LSI_SAS
LSI_SCSI
megasas
monfilt
mpio
Mraid35x
msahci
msdsm
MSKSSRV
MSPCLOCK
MSPQM
MsRPC
MSTEE
NAL
NativeWifiP
Ndisuio
nfrd960
ntrigdigi
nvraid
nvstor
nv_agp
NwlnkFlt
NwlnkFwd
ohci1394
Parport
Parvdm
pciide
pcmcia
Processor
ql1080
Ql10wnt
ql12160
ql1240
ql1280
ql2300
ql40xx
QWAVEdrv
rdpdr
RDPWD
SASENUM
sbp2port
Serenum
Serial
sermouse
sffdisk
sffp_mmc
sffp_sd
sfloppy
sisagp
SiSRaid2
SiSRaid4
Sparrow
symc810
Symc8xx
Sym_hi
Sym_u3
Tcpip6
TDPIPE
TDTCP
TosIde
tssecsrv
uagp35
udfs
uliagpkx
uliahci
UlSata
ulsata2
ultra
usbcir
usbohci
vga
viaagp
ViaC7
viaide
vsmraid
WacomPen
Wanarp
Wd
WmiAcpi
WpdUsb
ws2ifsl
WudfPf


Services - Running:

AeLookupSvc
Appinfo
Apple
AudioEndpointBuilder
Audiosrv
BFE
BITS
Bonjour
Browser
Creative
Creative
CryptSvc
DcomLaunch
Dhcp
Dnscache
DPS
EMDMgmt
Eventlog
EventSystem
FDResPub
gpsvc
hidserv
hpqcxs08
hpqddsvc
IAANTMON
IKEEXT
iphlpsvc
iPod
KeyIso
KtmRm
LanmanServer
LanmanWorkstation
LicCtrlService
lmhosts
MDM
MMCSS
MpsSvc
msfwsvc
Net
Netman
netprofm
NlaSvc
nsi
PcaSvc
PlugPlay
Pml
PolicyAgent
ProfSvc
RasMan
RoxMediaDB9
RoxWatch9
RpcSs
SamSs
Schedule
seclogon
SENS
ShellHWDetection
slsvc
Spooler
SSDPSRV
StarWindServiceAE
stisvc
SysMain
TabletInputService
TapiSrv
TermService
Themes
TrkWks
upnphost
UxSms
W32Time
WdiSystemHost
WebClient
WebrootSpySweeperService
WerSvc
WinHttpAutoProxySvc
Winmgmt
WMPNetworkSvc
WPDBusEnum
wscsvc
WSearch
wuauserv
wudfsvc


Services - Stopped:

aawservice
Adobe
ALG
CertPropSvc
clr_optimization_v2.0.50727_32
COMSysApp
DFSR
Diskeeper
dot3svc
EapHost
fdPHost
FLEXnet
FontCache3.0.0.0
hkmsvc
IDriverT
idsvc
IPBusEnum
lltdsvc
MSDTC
MSiSCSI
msiserver
napagent
Nero
Netlogon
NetTcpPortSharing
NMIndexingService
p2pimsvc
p2psvc
pla
PNRPAutoReg
PNRPsvc
ProtectedStorage
QWAVE
RasAuto
RemoteAccess
RemoteRegistry
RpcLocator
SCardSvr
SCPolicySvc
SDRSVC
SessionEnv
SharedAccess
SLUINotify
SNMPTRAP
stllssvr
swprv
Symantec
TBS
THREADORDER
TrustedInstaller
UI0Detect
usprserv
vds
VSS
wcncsvc
WcsPlugInService
WdiServiceHost
Wecsvc
wercplsupport
WinDefend
WinRM
Wlansvc
WLSetupSvc
wmiApSrv
WPCSvc


Files Created/Modified - 60 Days:


C:\

Apr 30 2008 12:20:16p 2,987,855,872 A.SH. "C:\pagefile.sys"
Apr 7 2008 6:10:58a 0 A..H. "C:\ProgramData.LOG1"
Apr 7 2008 6:10:58a 0 A..H. "C:\ProgramData.LOG2"


C:\Windows\

Apr 30 2008 12:20:26p 67,584 A.S.. "C:\Windows\bootstat.dat"
Apr 23 2008 11:06:14a 1,645 A.... "C:\Windows\cdplayer.ini"
Apr 7 2008 2:33:48p 80 A.... "C:\Windows\DirectX.log"
Mar 27 2008 5:26:50p 96,577 A.... "C:\Windows\hpqins16.dat"
Apr 6 2008 8:37:22a 2,268 A.... "C:\Windows\LDPINST.LOG"
Apr 30 2008 6:13:32a 69 A.... "C:\Windows\NeroDigital.ini"
Apr 30 2008 11:52:26a 859,058 A.... "C:\Windows\ntbtlog.txt"
Apr 30 2008 5:14:30a 85,426 A.... "C:\Windows\PFRO.log"
Apr 24 2008 5:02:06p 1,409 A.... "C:\Windows\QTFont.for"
Apr 24 2008 5:02:06p 54,156 A..H. "C:\Windows\QTFont.qfn"
Apr 30 2008 12:19:04p 32,554 A.... "C:\Windows\SchedLgU.Txt"
Apr 30 2008 12:24:22p 1,880,599 A.... "C:\Windows\WindowsUpdate.log"
Apr 4 2008 2:15:20p 556 A.... "C:\Windows\wininit.ini"
Apr 22 2008 5:40:02a 2,266 A.... "C:\Windows\Debug\mrt.log"
Apr 22 2008 5:40:02a 1,158 A.... "C:\Windows\Debug\mrteng.log"
Apr 30 2008 12:20:24p 0 A.... "C:\Windows\Debug\PASSWD.LOG"
Mar 19 2008 4:39:20p 361 A.... "C:\Windows\Downloaded Program Files\GamesCampus.inf"
Apr 30 2008 5:17:18a 24,140 A.... "C:\Windows\inf\1394.PNF"
Apr 30 2008 5:17:46a 9,196 A.... "C:\Windows\inf\61883.PNF"
Apr 30 2008 5:19:00a 14,188 A.... "C:\Windows\inf\acpi.PNF"
Apr 30 2008 5:15:52a 13,892 A.... "C:\Windows\inf\adp94xx.PNF"
Apr 30 2008 5:17:14a 19,324 A.... "C:\Windows\inf\adpahci.PNF"
Apr 30 2008 5:16:12a 17,216 A.... "C:\Windows\inf\adpu160m.PNF"
Apr 30 2008 5:18:46a 16,660 A.... "C:\Windows\inf\adpu320.PNF"
Apr 30 2008 5:15:56a 72,032 A.... "C:\Windows\inf\af2vcap.PNF"
Apr 30 2008 5:18:04a 14,796 A.... "C:\Windows\inf\agp.PNF"
Apr 30 2008 5:18:40a 23,768 A.... "C:\Windows\inf\angel.PNF"
Apr 30 2008 5:18:46a 23,952 A.... "C:\Windows\inf\angel2.PNF"
Apr 30 2008 5:18:12a 23,080 A.... "C:\Windows\inf\angelusb.PNF"
Apr 30 2008 5:18:04a 16,184 A.... "C:\Windows\inf\arc.PNF"
Apr 30 2008 5:18:52a 21,356 A.... "C:\Windows\inf\arcsas.PNF"
Apr 30 2008 5:18:08a 450,672 A.... "C:\Windows\inf\atiilhag.PNF"
Apr 30 2008 5:18:16a 13,116 A.... "C:\Windows\inf\atiixpad.PNF"
Apr 30 2008 5:18:18a 129,768 A.... "C:\Windows\inf\atiixpag.PNF"
Apr 30 2008 5:18:22a 40,348 A.... "C:\Windows\inf\atiriolh.PNF"
Apr 30 2008 5:18:06a 11,904 A.... "C:\Windows\inf\avc.PNF"
Apr 30 2008 5:18:16a 47,536 A.... "C:\Windows\inf\avmisdnc.PNF"
Apr 30 2008 5:17:44a 12,724 A.... "C:\Windows\inf\battery.PNF"
Apr 30 2008 5:17:56a 11,460 A.... "C:\Windows\inf\bda.PNF"
Apr 30 2008 5:18:10a 5,340 A.... "C:\Windows\inf\blbdrive.PNF"
Apr 30 2008 5:18:10a 120,088 A.... "C:\Windows\inf\brmfcmdm.PNF"
Apr 30 2008 5:17:34a 93,576 A.... "C:\Windows\inf\brmfcmf.PNF"
Apr 30 2008 5:18:24a 11,048 A.... "C:\Windows\inf\brmfcsto.PNF"
Apr 30 2008 5:18:12a 10,936 A.... "C:\Windows\inf\brmfcumd.PNF"
Apr 30 2008 5:18:12a 257,252 A.... "C:\Windows\inf\brmfcwia.PNF"
Apr 30 2008 5:18:28a 33,512 A.... "C:\Windows\inf\brmfport.PNF"
Apr 30 2008 5:18:06a 39,712 A.... "C:\Windows\inf\bth.PNF"
Apr 30 2008 5:18:52a 10,212 A.... "C:\Windows\inf\bthpan.PNF"
Apr 30 2008 5:18:28a 7,112 A.... "C:\Windows\inf\bthprint.PNF"
Apr 30 2008 5:15:52a 6,796 A.... "C:\Windows\inf\bthspp.PNF"
Apr 30 2008 5:19:06a 9,992 A.... "C:\Windows\inf\cdrom.PNF"
Apr 30 2008 5:18:16a 17,952 A.... "C:\Windows\inf\circlass.PNF"
Apr 30 2008 5:18:24a 6,840 A.... "C:\Windows\inf\clusdisk.PNF"
Apr 30 2008 5:18:58a 27,112 A.... "C:\Windows\inf\cpu.PNF"
Apr 30 2008 5:17:34a 5,876 A.... "C:\Windows\inf\crcdisk.PNF"
Apr 30 2008 5:18:56a 19,728 A.... "C:\Windows\inf\cx88enc_ibv32.PNF"
Apr 30 2008 5:17:48a 12,112 A.... "C:\Windows\inf\cx88tune_ibv32.PNF"
Apr 30 2008 5:15:52a 31,816 A.... "C:\Windows\inf\cx88vid_ibv32.PNF"
Apr 30 2008 5:18:26a 14,736 A.... "C:\Windows\inf\cxavsaud_ibv32.PNF"
Apr 30 2008 5:18:26a 13,184 A.... "C:\Windows\inf\cxavxbar_ibv32.PNF"
Apr 30 2008 5:18:18a 38,212 A.... "C:\Windows\inf\cxfalcon_ibv32.PNF"
Apr 30 2008 5:18:16a 34,172 A.... "C:\Windows\inf\cxfalpal_ibv32.PNF"
Apr 30 2008 5:18:56a 31,764 A.... "C:\Windows\inf\cxraptor_fm1216mk5_ibv32.PNF"
Apr 30 2008 5:18:56a 31,636 A.... "C:\Windows\inf\cxraptor_fm1236mk5_ibv32.PNF"
Apr 30 2008 5:18:28a 33,644 A.... "C:\Windows\inf\cxraptor_philipstuv1236d_ibv32.PNF"
Apr 30 2008 5:16:52a 23,468 A.... "C:\Windows\inf\dc21x4vm.PNF"
Apr 30 2008 5:19:06a 15,440 A.... "C:\Windows\inf\disk.PNF"
Apr 30 2008 5:17:42a 10,140 A.... "C:\Windows\inf\display.PNF"
Apr 30 2008 5:17:38a 37,828 A.... "C:\Windows\inf\divacx86.PNF"
Apr 30 2008 5:17:44a 51,676 A.... "C:\Windows\inf\divasx86.PNF"
Apr 30 2008 5:18:46a 7,736 A.... "C:\Windows\inf\djsvs.PNF"
Apr 30 2008 5:18:32a 189,256 A.... "C:\Windows\inf\dot4.PNF"
Apr 30 2008 5:19:02a 35,800 A.... "C:\Windows\inf\dot4prt.PNF"
Apr 30 2008 5:17:48a 20,872 A.... "C:\Windows\inf\elxstor.PNF"
Apr 30 2008 5:15:52a 4,832 A.... "C:\Windows\inf\faxcn001.PNF"
Apr 30 2008 5:15:54a 4,724 A.... "C:\Windows\inf\faxcn002.PNF"
Apr 30 2008 5:18:00a 5,768 A.... "C:\Windows\inf\fdc.PNF"
Apr 30 2008 5:18:26a 9,188 A.... "C:\Windows\inf\flpydisk.PNF"
Apr 30 2008 5:18:22a 12,456 A.... "C:\Windows\inf\gameport.PNF"
Apr 30 2008 5:18:26a 6,128 A.... "C:\Windows\inf\genprint.PNF"
Apr 30 2008 5:19:18a 7,344 A.... "C:\Windows\inf\hal.PNF"
Apr 30 2008 5:18:48a 39,924 A.... "C:\Windows\inf\hcwpp2.PNF"
Apr 30 2008 5:19:14a 8,460 A.... "C:\Windows\inf\hdaudbus.PNF"
Apr 30 2008 5:17:34a 142,792 A.... "C:\Windows\inf\hdaudio.PNF"
Apr 30 2008 5:17:38a 57,140 A.... "C:\Windows\inf\hdaudss.PNF"
Apr 30 2008 5:18:50a 9,364 A.... "C:\Windows\inf\hidbth.PNF"
Apr 30 2008 5:17:28a 9,420 A.... "C:\Windows\inf\hiddigi.PNF"
Apr 30 2008 5:19:02a 19,912 A.... "C:\Windows\inf\hidserv.PNF"
Apr 30 2008 5:17:44a 21,572 A.... "C:\Windows\inf\hpcisss.PNF"
Apr 30 2008 5:16:12a 23,724 A.... "C:\Windows\inf\hpoa1nd.PNF"
Apr 30 2008 5:16:12a 19,464 A.... "C:\Windows\inf\hpoa1sd.PNF"
Apr 30 2008 5:16:54a 17,064 A.... "C:\Windows\inf\hpoa1so.PNF"
Apr 30 2008 5:16:58a 21,696 A.... "C:\Windows\inf\hpoa1ss.PNF"
Apr 30 2008 5:18:18a 29,544 A.... "C:\Windows\inf\hpojscan.PNF"
Apr 30 2008 5:18:40a 8,888 A.... "C:\Windows\inf\i2omp.PNF"
Apr 30 2008 5:16:52a 21,860 A.... "C:\Windows\inf\ialmnt5.PNF"
Apr 30 2008 5:19:10a 16,556 A.... "C:\Windows\inf\iastorv.PNF"
Apr 30 2008 5:18:40a 17,904 A.... "C:\Windows\inf\igdlh.PNF"
Apr 30 2008 5:18:46a 7,680 A.... "C:\Windows\inf\iirsp.PNF"
Apr 30 2008 5:18:48a 7,508 A.... "C:\Windows\inf\iirsp2.PNF"
Apr 30 2008 5:18:40a 22,056 A.... "C:\Windows\inf\image.PNF"
Apr 30 2008 5:18:56a 1,699,616 A.... "C:\Windows\inf\INFCACHE.1"
Apr 30 2008 5:18:56a 51,200 A.... "C:\Windows\inf\infpub.dat"
Apr 6 2008 8:50:32a 86,016 A.... "C:\Windows\inf\infstor.dat"
Apr 30 2008 5:18:56a 86,016 A.... "C:\Windows\inf\infstrng.dat"
Apr 30 2008 5:19:04a 158,804 A.... "C:\Windows\inf\input.PNF"
Apr 30 2008 5:17:44a 7,372 A.... "C:\Windows\inf\ipmidrv.PNF"
Apr 30 2008 5:18:44a 35,572 A.... "C:\Windows\inf\irnsc.PNF"
Apr 30 2008 5:17:46a 10,996 A.... "C:\Windows\inf\irstusb.PNF"
Apr 30 2008 5:19:20a 10,972 A.... "C:\Windows\inf\iscsi.PNF"
Apr 30 2008 5:18:14a 17,740 A.... "C:\Windows\inf\iteatapi.PNF"
Apr 30 2008 5:17:34a 21,276 A.... "C:\Windows\inf\iteraid.PNF"
Apr 30 2008 5:18:14a 85,200 A.... "C:\Windows\inf\keyboard.PNF"
Apr 30 2008 5:17:32a 127,644 A.... "C:\Windows\inf\ks.PNF"
Apr 30 2008 5:18:28a 50,004 A.... "C:\Windows\inf\kscaptur.PNF"
Apr 30 2008 5:18:26a 18,016 A.... "C:\Windows\inf\ksfilter.PNF"
Apr 30 2008 5:18:50a 11,852 A.... "C:\Windows\inf\lsi_fc.PNF"
Apr 30 2008 5:17:42a 15,628 A.... "C:\Windows\inf\lsi_sas.PNF"
Apr 30 2008 5:18:22a 10,656 A.... "C:\Windows\inf\lsi_scsi.PNF"
Apr 30 2008 5:18:58a 497,696 A.... "C:\Windows\inf\machine.PNF"
Apr 30 2008 5:18:40a 126,848 A.... "C:\Windows\inf\mchgr.PNF"
Apr 30 2008 5:18:32a 7,312 A.... "C:\Windows\inf\mcx2.PNF"
Apr 30 2008 5:16:12a 135,092 A.... "C:\Windows\inf\mdm3com.PNF"
Apr 30 2008 5:18:50a 64,132 A.... "C:\Windows\inf\mdm5674a.PNF"
Apr 30 2008 5:18:48a 19,868 A.... "C:\Windows\inf\mdmadc.PNF"
Apr 30 2008 5:17:34a 89,396 A.... "C:\Windows\inf\mdmagrm.PNF"
Apr 30 2008 5:17:38a 135,072 A.... "C:\Windows\inf\mdmagrs.PNF"
Apr 30 2008 5:18:16a 10,640 A.... "C:\Windows\inf\mdmairte.PNF"
Apr 30 2008 5:17:34a 32,876 A.... "C:\Windows\inf\mdmaiwa.PNF"
Apr 30 2008 5:17:48a 25,432 A.... "C:\Windows\inf\mdmaiwa3.PNF"
Apr 30 2008 5:17:48a 145,952 A.... "C:\Windows\inf\mdmaiwa4.PNF"
Apr 30 2008 5:17:48a 36,656 A.... "C:\Windows\inf\mdmaiwa5.PNF"
Apr 30 2008 5:18:16a 12,944 A.... "C:\Windows\inf\mdmaiwat.PNF"
Apr 30 2008 5:18:46a 20,692 A.... "C:\Windows\inf\mdmar1.PNF"
Apr 30 2008 5:17:32a 58,848 A.... "C:\Windows\inf\mdmarch.PNF"
Apr 30 2008 5:18:52a 21,588 A.... "C:\Windows\inf\mdmarn.PNF"
Apr 30 2008 5:18:50a 110,796 A.... "C:\Windows\inf\mdmati.PNF"
Apr 30 2008 5:17:50a 25,056 A.... "C:\Windows\inf\mdmatm2k.PNF"
Apr 30 2008 5:18:54a 29,656 A.... "C:\Windows\inf\mdmaus.PNF"
Apr 30 2008 5:17:30a 97,516 A.... "C:\Windows\inf\mdmboca.PNF"
Apr 30 2008 5:18:50a 33,640 A.... "C:\Windows\inf\mdmbsb.PNF"
Apr 30 2008 5:18:14a 60,760 A.... "C:\Windows\inf\mdmbtmdm.PNF"
Apr 30 2008 5:16:12a 13,756 A.... "C:\Windows\inf\mdmbug3.PNF"
Apr 30 2008 5:16:18a 36,164 A.... "C:\Windows\inf\mdmbw561.PNF"
Apr 30 2008 5:18:50a 30,772 A.... "C:\Windows\inf\mdmc26a.PNF"
Apr 30 2008 5:18:50a 16,992 A.... "C:\Windows\inf\mdmcdp.PNF"
Apr 30 2008 5:18:50a 138,924 A.... "C:\Windows\inf\mdmcm28.PNF"
Apr 30 2008 5:18:14a 36,028 A.... "C:\Windows\inf\mdmcodex.PNF"
Apr 30 2008 5:16:12a 61,504 A.... "C:\Windows\inf\mdmcom1.PNF"
Apr 30 2008 5:18:22a 12,944 A.... "C:\Windows\inf\mdmcommu.PNF"
Apr 30 2008 5:17:40a 16,976 A.... "C:\Windows\inf\mdmcomp.PNF"
Apr 30 2008 5:18:54a 202,392 A.... "C:\Windows\inf\mdmcpq.PNF"
Apr 30 2008 5:16:24a 66,320 A.... "C:\Windows\inf\mdmcpq2.PNF"
Apr 30 2008 5:18:54a 17,192 A.... "C:\Windows\inf\mdmcpv.PNF"
Apr 30 2008 5:18:28a 29,760 A.... "C:\Windows\inf\mdmcrtix.PNF"
Apr 30 2008 5:17:56a 153,640 A.... "C:\Windows\inf\mdmcxav3.PNF"
Apr 30 2008 5:18:00a 119,520 A.... "C:\Windows\inf\mdmcxhv3.PNF"
Apr 30 2008 5:19:06a 122,784 A.... "C:\Windows\inf\mdmcxpv3.PNF"
Apr 30 2008 5:16:10a 124,688 A.... "C:\Windows\inf\mdmdcm5.PNF"
Apr 30 2008 5:16:10a 48,508 A.... "C:\Windows\inf\mdmdcm6.PNF"
Apr 30 2008 5:17:32a 33,688 A.... "C:\Windows\inf\mdmdf56f.PNF"
Apr 30 2008 5:18:16a 27,852 A.... "C:\Windows\inf\mdmdgitn.PNF"
Apr 30 2008 5:18:48a 24,500 A.... "C:\Windows\inf\mdmdp2.PNF"
Apr 30 2008 5:18:52a 254,108 A.... "C:\Windows\inf\mdmdsi.PNF"
Apr 30 2008 5:17:36a 94,316 A.... "C:\Windows\inf\mdmdyna.PNF"
Apr 30 2008 5:18:10a 43,792 A.... "C:\Windows\inf\mdmeiger.PNF"
Apr 30 2008 5:17:34a 166,264 A.... "C:\Windows\inf\mdmelsa.PNF"
Apr 30 2008 5:17:34a 27,104 A.... "C:\Windows\inf\mdmeric.PNF"
Apr 30 2008 5:17:48a 38,824 A.... "C:\Windows\inf\mdmeric2.PNF"
Apr 30 2008 5:18:08a 93,912 A.... "C:\Windows\inf\mdmetech.PNF"
Apr 30 2008 5:18:46a 28,340 A.... "C:\Windows\inf\mdmfj2.PNF"
Apr 30 2008 5:18:18a 104,584 A.... "C:\Windows\inf\mdmgatew.PNF"
Apr 30 2008 5:18:50a 59,728 A.... "C:\Windows\inf\mdmgcs.PNF"
Apr 30 2008 5:18:50a 110,952 A.... "C:\Windows\inf\mdmgen.PNF"
Apr 30 2008 5:15:54a 106,912 A.... "C:\Windows\inf\mdmgl001.PNF"
Apr 30 2008 5:15:56a 123,224 A.... "C:\Windows\inf\mdmgl002.PNF"
Apr 30 2008 5:15:58a 101,632 A.... "C:\Windows\inf\mdmgl003.PNF"
Apr 30 2008 5:16:04a 1,542,176 A.... "C:\Windows\inf\mdmgl004.PNF"
Apr 30 2008 5:16:08a 112,948 A.... "C:\Windows\inf\mdmgl005.PNF"
Apr 30 2008 5:16:10a 143,940 A.... "C:\Windows\inf\mdmgl006.PNF"
Apr 30 2008 5:16:10a 219,952 A.... "C:\Windows\inf\mdmgl007.PNF"
Apr 30 2008 5:16:10a 79,672 A.... "C:\Windows\inf\mdmgl008.PNF"
Apr 30 2008 5:16:12a 225,460 A.... "C:\Windows\inf\mdmgl009.PNF"
Apr 30 2008 5:15:56a 150,520 A.... "C:\Windows\inf\mdmgl010.PNF"
Apr 30 2008 5:18:54a 41,848 A.... "C:\Windows\inf\mdmgsm.PNF"
Apr 30 2008 5:17:34a 10,216 A.... "C:\Windows\inf\mdmhaeu.PNF"
Apr 30 2008 5:18:14a 81,012 A.... "C:\Windows\inf\mdmhandy.PNF"
Apr 30 2008 5:16:14a 104,664 A.... "C:\Windows\inf\mdmhay2.PNF"
Apr 30 2008 5:18:20a 147,636 A.... "C:\Windows\inf\mdmhayes.PNF"
Apr 30 2008 5:18:22a 42,624 A.... "C:\Windows\inf\mdminfot.PNF"
Apr 30 2008 5:18:12a 42,396 A.... "C:\Windows\inf\mdmiodat.PNF"
Apr 30 2008 5:18:20a 132,900 A.... "C:\Windows\inf\mdmirmdm.PNF"
Apr 30 2008 5:17:38a 90,480 A.... "C:\Windows\inf\mdmisdn.PNF"
Apr 30 2008 5:17:34a 35,620 A.... "C:\Windows\inf\mdmjf56e.PNF"
Apr 30 2008 5:18:40a 14,916 A.... "C:\Windows\inf\mdmke.PNF"
Apr 30 2008 5:18:32a 16,484 A.... "C:\Windows\inf\mdmkortx.PNF"
Apr 30 2008 5:18:16a 28,164 A.... "C:\Windows\inf\mdmlasat.PNF"
Apr 30 2008 5:18:22a 59,340 A.... "C:\Windows\inf\mdmlasno.PNF"
Apr 30 2008 5:18:26a 50,188 A.... "C:\Windows\inf\mdmlucnt.PNF"
Apr 30 2008 5:16:14a 23,568 A.... "C:\Windows\inf\mdmmc288.PNF"
Apr 30 2008 5:18:50a 15,336 A.... "C:\Windows\inf\mdmmcd.PNF"
Apr 30 2008 5:17:36a 96,744 A.... "C:\Windows\inf\mdmmcom.PNF"
Apr 30 2008 5:18:54a 82,248 A.... "C:\Windows\inf\mdmmct.PNF"
Apr 30 2008 5:17:32a 23,408 A.... "C:\Windows\inf\mdmmega.PNF"
Apr 30 2008 5:18:22a 156,764 A.... "C:\Windows\inf\mdmmetri.PNF"
Apr 30 2008 5:18:32a 108,352 A.... "C:\Windows\inf\mdmmhrtz.PNF"
Apr 30 2008 5:18:22a 283,248 A.... "C:\Windows\inf\mdmmhzel.PNF"
Apr 30 2008 5:18:16a 13,968 A.... "C:\Windows\inf\mdmminij.PNF"
Apr 30 2008 5:18:52a 24,872 A.... "C:\Windows\inf\mdmmod.PNF"
Apr 30 2008 5:18:02a 27,708 A.... "C:\Windows\inf\mdmmoto1.PNF"
Apr 30 2008 5:18:30a 10,704 A.... "C:\Windows\inf\mdmmotou.PNF"
Apr 30 2008 5:18:30a 829,424 A.... "C:\Windows\inf\mdmmotsm.PNF"
Apr 30 2008 5:15:52a 122,596 A.... "C:\Windows\inf\mdmmts.PNF"
Apr 30 2008 5:18:24a 27,732 A.... "C:\Windows\inf\mdmneuhs.PNF"
Apr 30 2008 5:18:02a 14,088 A.... "C:\Windows\inf\mdmnis1u.PNF"
Apr 30 2008 5:18:02a 14,192 A.... "C:\Windows\inf\mdmnis2u.PNF"
Apr 30 2008 5:18:02a 13,244 A.... "C:\Windows\inf\mdmnis3t.PNF"
Apr 30 2008 5:18:04a 13,212 A.... "C:\Windows\inf\mdmnis5t.PNF"
Apr 30 2008 5:18:12a 82,256 A.... "C:\Windows\inf\mdmnokia.PNF"
Apr 30 2008 5:17:42a 28,680 A.... "C:\Windows\inf\mdmnova.PNF"
Apr 30 2008 5:17:08a 16,752 A.... "C:\Windows\inf\mdmntt1.PNF"
Apr 30 2008 5:18:00a 30,132 A.... "C:\Windows\inf\mdmnttd2.PNF"
Apr 30 2008 5:18:02a 30,140 A.... "C:\Windows\inf\mdmnttd6.PNF"
Apr 30 2008 5:18:26a 13,876 A.... "C:\Windows\inf\mdmnttme.PNF"
Apr 30 2008 5:17:46a 21,596 A.... "C:\Windows\inf\mdmnttp.PNF"
Apr 30 2008 5:18:06a 23,324 A.... "C:\Windows\inf\mdmnttp2.PNF"
Apr 30 2008 5:18:28a 13,812 A.... "C:\Windows\inf\mdmnttte.PNF"
Apr 30 2008 5:17:34a 36,956 A.... "C:\Windows\inf\mdmolic.PNF"
Apr 30 2008 5:18:02a 175,240 A.... "C:\Windows\inf\mdmomrn3.PNF"
Apr 30 2008 5:17:44a 14,424 A.... "C:\Windows\inf\mdmoptn.PNF"
Apr 30 2008 5:18:56a 66,556 A.... "C:\Windows\inf\mdmosi.PNF"
Apr 30 2008 5:17:32a 42,624 A.... "C:\Windows\inf\mdmpace.PNF"
Apr 30 2008 5:17:42a 121,228 A.... "C:\Windows\inf\mdmpenr.PNF"
Apr 30 2008 5:18:54a 27,156 A.... "C:\Windows\inf\mdmpin.PNF"
Apr 30 2008 5:18:48a 12,960 A.... "C:\Windows\inf\mdmpn1.PNF"
Apr 30 2008 5:18:44a 86,024 A.... "C:\Windows\inf\mdmpp.PNF"
Apr 30 2008 5:18:26a 20,484 A.... "C:\Windows\inf\mdmpsion.PNF"
Apr 30 2008 5:18:06a 115,484 A.... "C:\Windows\inf\mdmracal.PNF"
Apr 30 2008 5:17:40a 31,192 A.... "C:\Windows\inf\mdmrock.PNF"
Apr 30 2008 5:17:50a 78,104 A.... "C:\Windows\inf\mdmrock3.PNF"
Apr 30 2008 5:17:54a 95,860 A.... "C:\Windows\inf\mdmrock4.PNF"
Apr 30 2008 5:17:54a 179,108 A.... "C:\Windows\inf\mdmrock5.PNF"
Apr 30 2008 5:17:42a 64,756 A.... "C:\Windows\inf\mdmsier.PNF"
Apr 30 2008 5:17:40a 32,216 A.... "C:\Windows\inf\mdmsii64.PNF"
Apr 30 2008 5:18:26a 19,020 A.... "C:\Windows\inf\mdmsmart.PNF"
Apr 30 2008 5:18:34a 123,304 A.... "C:\Windows\inf\mdmsonyu.PNF"
Apr 30 2008 5:17:08a 14,900 A.... "C:\Windows\inf\mdmsun1.PNF"
Apr 30 2008 5:17:12a 47,424 A.... "C:\Windows\inf\mdmsun2.PNF"
Apr 30 2008 5:18:06a 66,516 A.... "C:\Windows\inf\mdmsupr3.PNF"
Apr 30 2008 5:18:28a 210,664 A.... "C:\Windows\inf\mdmsupra.PNF"
Apr 30 2008 5:18:34a 60,796 A.... "C:\Windows\inf\mdmsuprv.PNF"
Apr 30 2008 5:18:52a 101,592 A.... "C:\Windows\inf\mdmtdk.PNF"
Apr 30 2008 5:17:50a 37,836 A.... "C:\Windows\inf\mdmtdkj2.PNF"
Apr 30 2008 5:17:50a 39,220 A.... "C:\Windows\inf\mdmtdkj3.PNF"
Apr 30 2008 5:17:50a 33,524 A.... "C:\Windows\inf\mdmtdkj4.PNF"
Apr 30 2008 5:17:50a 42,076 A.... "C:\Windows\inf\mdmtdkj5.PNF"
Apr 30 2008 5:17:54a 23,712 A.... "C:\Windows\inf\mdmtdkj6.PNF"
Apr 30 2008 5:17:56a 29,764 A.... "C:\Windows\inf\mdmtdkj7.PNF"
Apr 30 2008 5:18:24a 23,284 A.... "C:\Windows\inf\mdmtexas.PNF"
Apr 30 2008 5:18:42a 80,380 A.... "C:\Windows\inf\mdmti.PNF"
Apr 30 2008 5:15:52a 51,404 A.... "C:\Windows\inf\mdmtkr.PNF"
Apr 30 2008 5:17:44a 32,576 A.... "C:\Windows\inf\mdmtron.PNF"
Apr 30 2008 5:17:44a 11,412 A.... "C:\Windows\inf\mdmusrf.PNF"
Apr 30 2008 5:17:44a 31,028 A.... "C:\Windows\inf\mdmusrg.PNF"
Apr 30 2008 5:18:28a 52,820 A.... "C:\Windows\inf\mdmusrgl.PNF"
Apr 30 2008 5:18:04a 108,408 A.... "C:\Windows\inf\mdmusrk1.PNF"
Apr 30 2008 5:18:34a 11,836 A.... "C:\Windows\inf\mdmusrsp.PNF"
Apr 30 2008 5:17:44a 9,840 A.... "C:\Windows\inf\mdmvdot.PNF"
Apr 30 2008 5:18:46a 37,716 A.... "C:\Windows\inf\mdmvv.PNF"
Apr 30 2008 5:18:00a 242,300 A.... "C:\Windows\inf\mdmwhql0.PNF"
Apr 30 2008 5:18:54a 96,944 A.... "C:\Windows\inf\mdmx5560.PNF"
Apr 30 2008 5:17:46a 195,308 A.... "C:\Windows\inf\mdmzoom.PNF"
Apr 30 2008 5:15:52a 119,160 A.... "C:\Windows\inf\mdmzyp.PNF"
Apr 30 2008 5:18:34a 174,596 A.... "C:\Windows\inf\mdmzyxel.PNF"
Apr 30 2008 5:18:34a 193,148 A.... "C:\Windows\inf\mdmzyxlg.PNF"
Apr 30 2008 5:17:34a 33,568 A.... "C:\Windows\inf\megasas.PNF"
Apr 30 2008 5:17:48a 6,680 A.... "C:\Windows\inf\megasas2.PNF"
Apr 30 2008 5:15:52a 8,032 A.... "C:\Windows\inf\memory.PNF"
Apr 30 2008 5:17:20a 5,992 A.... "C:\Windows\inf\mf.PNF"
Apr 30 2008 5:18:10a 14,576 A.... "C:\Windows\inf\modemcsa.PNF"
Apr 30 2008 5:19:02a 1,147,996 A.... "C:\Windows\inf\monitor.PNF"
Apr 30 2008 5:18:38a 8,524 A.... "C:\Windows\inf\mpio.PNF"
Apr 30 2008 5:17:40a 32,172 A.... "C:\Windows\inf\mraid35x.PNF"
Apr 30 2008 5:17:50a 25,096 A.... "C:\Windows\inf\mraid35x2.PNF"
Apr 30 2008 5:18:44a 6,780 A.... "C:\Windows\inf\msdri.PNF"
Apr 30 2008 5:18:44a 8,852 A.... "C:\Windows\inf\msdsm.PNF"
Apr 30 2008 5:18:40a 45,280 A.... "C:\Windows\inf\msdv.PNF"
Apr 30 2008 5:18:40a 71,480 A.... "C:\Windows\inf\mshdc.PNF"
Apr 30 2008 5:17:46a 86,072 A.... "C:\Windows\inf\msmouse.PNF"
Apr 30 2008 5:17:48a 43,372 A.... "C:\Windows\inf\msports.PNF"
Apr 30 2008 5:18:56a 29,268 A.... "C:\Windows\inf\mstape.PNF"
Apr 30 2008 5:18:34a 4,272 A.... "C:\Windows\inf\multiprt.PNF"
Apr 30 2008 5:18:56a 40,208 A.... "C:\Windows\inf\net44x32.PNF"
Apr 30 2008 5:18:42a 14,588 A.... "C:\Windows\inf\net8185.PNF"
Apr 30 2008 5:17:42a 48,972 A.... "C:\Windows\inf\netathr.PNF"
Apr 30 2008 5:17:46a 132,700 A.... "C:\Windows\inf\netb57vx.PNF"
Apr 30 2008 5:18:48a 33,104 A.... "C:\Windows\inf\netbc6.PNF"
Apr 30 2008 5:18:22a 4,208 A.... "C:\Windows\inf\netclass.PNF"
Apr 30 2008 5:19:08a 57,940 A.... "C:\Windows\inf\nete1e32.PNF"
Apr 30 2008 5:16:12a 77,228 A.... "C:\Windows\inf\nete1g32.PNF"
Apr 30 2008 5:17:34a 84,044 A.... "C:\Windows\inf\netefe32.PNF"
Apr 30 2008 5:18:44a 7,644 A.... "C:\Windows\inf\netft.PNF"
Apr 30 2008 5:17:34a 12,796 A.... "C:\Windows\inf\netirda.PNF"
Apr 30 2008 5:18:30a 31,592 A.... "C:\Windows\inf\netirsir.PNF"
Apr 30 2008 5:17:44a 9,384 A.... "C:\Windows\inf\netloop.PNF"
Apr 30 2008 5:17:42a 20,728 A.... "C:\Windows\inf\netmw13b.PNF"
Apr 30 2008 5:17:44a 115,356 A.... "C:\Windows\inf\netmyk01.PNF"
Apr 30 2008 5:18:54a 7,608 A.... "C:\Windows\inf\netnlb.PNF"
Apr 30 2008 5:17:44a 36,320 A.... "C:\Windows\inf\netnvm32.PNF"
Apr 30 2008 5:18:26a 8,564 A.... "C:\Windows\inf\netrndis.PNF"
Apr 30 2008 5:17:44a 203,936 A.... "C:\Windows\inf\netrtl32.PNF"
Apr 30 2008 5:17:46a 23,084 A.... "C:\Windows\inf\netrtx32.PNF"
Apr 30 2008 5:15:52a 42,604 A.... "C:\Windows\inf\netsis.PNF"
Apr 30 2008 5:19:16a 15,444 A.... "C:\Windows\inf\nettun.PNF"
Apr 30 2008 5:18:06a 12,800 A.... "C:\Windows\inf\netuli6x.PNF"
Apr 30 2008 5:17:46a 18,896 A.... "C:\Windows\inf\netvgx86.PNF"
Apr 30 2008 5:15:52a 48,784 A.... "C:\Windows\inf\netvt86.PNF"
Apr 30 2008 5:18:40a 74,880 A.... "C:\Windows\inf\netw2.PNF"
Apr 30 2008 5:18:40a 79,716 A.... "C:\Windows\inf\netw3.PNF"
Apr 30 2008 5:18:48a 11,884 A.... "C:\Windows\inf\nfrd960.PNF"
Apr 30 2008 5:17:48a 11,940 A.... "C:\Windows\inf\ntprint.PNF"
Apr 30 2008 5:18:40a 9,136 A.... "C:\Windows\inf\ntrigdigi.PNF"
Apr 30 2008 5:18:32a 14,304 A.... "C:\Windows\inf\nulhpopr.PNF"
Apr 30 2008 5:17:58a 52,076 A.... "C:\Windows\inf\nv4_disp.PNF"
Apr 30 2008 5:18:54a 14,384 A.... "C:\Windows\inf\nvraid.PNF"
Apr 30 2008 5:18:42a 26,564 A.... "C:\Windows\inf\nv_am.PNF"
Apr 30 2008 5:18:42a 49,388 A.... "C:\Windows\inf\nv_aw.PNF"
Apr 30 2008 5:18:42a 26,188 A.... "C:\Windows\inf\nv_bl.PNF"
Apr 30 2008 5:18:42a 27,540 A.... "C:\Windows\inf\nv_cp.PNF"
Apr 30 2008 5:18:42a 52,880 A.... "C:\Windows\inf\nv_dm.PNF"
Apr 30 2008 5:18:44a 23,652 A.... "C:\Windows\inf\nv_gw.PNF"
Apr 30 2008 5:18:42a 26,012 A.... "C:\Windows\inf\nv_io.PNF"
Apr 30 2008 5:18:42a 95,300 A.... "C:\Windows\inf\nv_lh.PNF"
Apr 30 2008 5:18:44a 25,396 A.... "C:\Windows\inf\nv_mo.PNF"
Apr 30 2008 5:18:42a 24,284 A.... "C:\Windows\inf\nv_qa.PNF"
Apr 30 2008 5:18:44a 25,960 A.... "C:\Windows\inf\nv_sm.PNF"
Apr 30 2008 5:18:46a 70,228 A.... "C:\Windows\inf\nv_sz.PNF"
Apr 30 2008 5:18:46a 71,128 A.... "C:\Windows\inf\nv_ts.PNF"
Apr 30 2008 5:18:30a 5,932 A.... "C:\Windows\inf\oem0.PNF"
Apr 30 2008 5:18:30a 95,680 A.... "C:\Windows\inf\oem1.PNF"
Apr 30 2008 5:18:34a 70,560 A.... "C:\Windows\inf\oem10.PNF"
Apr 30 2008 5:18:34a 13,244 A.... "C:\Windows\inf\oem11.PNF"
Apr 30 2008 5:18:34a 18,272 A.... "C:\Windows\inf\oem12.PNF"
Apr 30 2008 5:18:36a 14,756 A.... "C:\Windows\inf\oem13.PNF"
Apr 30 2008 5:19:10a 10,980 A.... "C:\Windows\inf\oem14.PNF"
Apr 1 2008 7:34:00p 2,951 A.... "C:\Windows\inf\oem15.inf"
Apr 30 2008 5:18:36a 8,860 A.... "C:\Windows\inf\oem15.PNF"
Apr 30 2008 5:18:36a 5,696 A.... "C:\Windows\inf\oem16.PNF"
Apr 30 2008 5:18:36a 6,516 A.... "C:\Windows\inf\oem17.PNF"
Apr 30 2008 5:18:36a 8,440 A.... "C:\Windows\inf\oem18.PNF"
Apr 30 2008 5:18:38a 6,368 A.... "C:\Windows\inf\oem19.PNF"
Apr 30 2008 5:18:30a 279,748 A.... "C:\Windows\inf\oem2.PNF"
Apr 30 2008 5:18:34a 9,168 A.... "C:\Windows\inf\oem20.PNF"
Apr 30 2008 5:18:36a 8,704 A.... "C:\Windows\inf\oem22.PNF"
Apr 30 2008 5:18:36a 6,320 A.... "C:\Windows\inf\oem23.PNF"
Apr 30 2008 5:18:36a 7,640 A.... "C:\Windows\inf\oem24.PNF"
Apr 30 2008 5:18:36a 6,596 A.... "C:\Windows\inf\oem25.PNF"
Apr 30 2008 5:19:40a 104,372 A.... "C:\Windows\inf\oem26.PNF"
Apr 30 2008 5:18:38a 9,876 A.... "C:\Windows\inf\oem27.PNF"
Apr 30 2008 5:19:18a 6,432 A.... "C:\Windows\inf\oem28.PNF"
Apr 30 2008 5:19:02a 223,432 A.... "C:\Windows\inf\oem3.PNF"
Apr 30 2008 5:19:16a 112,672 A.... "C:\Windows\inf\oem37.PNF"
Apr 30 2008 5:19:22a 7,068 A.... "C:\Windows\inf\oem38.PNF"
Apr 30 2008 5:18:38a 6,488 A.... "C:\Windows\inf\oem39.PNF"
Apr 30 2008 5:18:30a 16,780 A.... "C:\Windows\inf\oem4.PNF"
Mar 4 2008 9:18:44p 2,488 A.... "C:\Windows\inf\oem42.inf"
Apr 30 2008 5:18:36a 8,980 A.... "C:\Windows\inf\oem42.PNF"
Mar 16 2008 3:31:56p 2,073 A.... "C:\Windows\inf\oem43.inf"
Apr 30 2008 5:18:36a 8,156 A.... "C:\Windows\inf\oem43.PNF"
Apr 1 2008 7:34:46p 2,358 A.S.. "C:\Windows\inf\oem44.inf"
Apr 30 2008 5:18:36a 9,272 A.... "C:\Windows\inf\oem44.PNF"
Apr 4 2008 6:56:34p 25,518 A.... "C:\Windows\inf\oem45.inf"
Apr 30 2008 5:19:02a 42,652 A.... "C:\Windows\inf\oem45.PNF"
Apr 4 2008 6:57:12p 830 A.... "C:\Windows\inf\oem46.inf"
Apr 30 2008 5:18:38a 4,840 A.... "C:\Windows\inf\oem46.PNF"
Apr 4 2008 6:58:10p 6,923 A.... "C:\Windows\inf\oem47.inf"
Apr 30 2008 5:19:04a 14,280 A.... "C:\Windows\inf\oem47.PNF"
Apr 6 2008 8:49:26a 11,315 A.... "C:\Windows\inf\oem5.inf"
Apr 30 2008 5:19:06a 37,092 A.... "C:\Windows\inf\oem5.PNF"
Apr 30 2008 5:18:32a 6,600 A.... "C:\Windows\inf\oem6.PNF"
Apr 6 2008 8:50:30a 2,411 A.... "C:\Windows\inf\oem7.inf"
Apr 30 2008 5:18:32a 8,972 A.... "C:\Windows\inf\oem7.PNF"
Apr 30 2008 5:19:02a 12,124 A.... "C:\Windows\inf\oem8.PNF"
Apr 30 2008 5:19:42a 17,092 A.... "C:\Windows\inf\oem9.PNF"
Apr 30 2008 5:18:50a 84,896 A.... "C:\Windows\inf\pcmcia.PNF"
Apr 30 2008 5:17:34a 29,028 A.... "C:\Windows\inf\ph3xibc0.PNF"
Apr 30 2008 5:17:34a 28,876 A.... "C:\Windows\inf\ph3xibc1.PNF"
Apr 30 2008 5:17:34a 38,416 A.... "C:\Windows\inf\ph3xibc2.PNF"
Apr 30 2008 5:17:34a 27,756 A.... "C:\Windows\inf\ph3xibc3.PNF"
Apr 30 2008 5:17:34a 25,424 A.... "C:\Windows\inf\ph3xibc4.PNF"
Apr 30 2008 5:17:34a 21,812 A.... "C:\Windows\inf\ph3xibc5.PNF"
Apr 30 2008 5:17:34a 23,940 A.... "C:\Windows\inf\ph3xibc6.PNF"
Apr 30 2008 5:17:34a 29,608 A.... "C:\Windows\inf\ph3xibc7.PNF"
Apr 30 2008 5:17:36a 34,840 A.... "C:\Windows\inf\ph3xibc8.PNF"
Apr 30 2008 5:17:36a 28,624 A.... "C:\Windows\inf\ph3xibc9.PNF"
Apr 30 2008 5:17:48a 26,292 A.... "C:\Windows\inf\ph3xibc10.PNF"
Apr 30 2008 5:17:48a 38,992 A.... "C:\Windows\inf\ph3xibc11.PNF"
Apr 30 2008 5:17:48a 24,792 A.... "C:\Windows\inf\ph3xibc12.PNF"
Apr 30 2008 5:18:10a 17,516 A.... "C:\Windows\inf\ph6xib32c0.PNF"
Apr 30 2008 5:18:10a 17,716 A.... "C:\Windows\inf\ph6xib32c1.PNF"
Apr 30 2008 5:16:14a 7,936 A.... "C:\Windows\inf\prnao001.PNF"
Apr 30 2008 5:16:30a 216,224 A.... "C:\Windows\inf\prnbr001.PNF"
Apr 30 2008 5:16:06a 398,956 A.... "C:\Windows\inf\prnca001.PNF"
Apr 30 2008 5:16:12a 10,564 A.... "C:\Windows\inf\prnci001.PNF"
Apr 30 2008 5:16:10a 5,836 A.... "C:\Windows\inf\prndc001.PNF"
Apr 30 2008 5:16:14a 21,028 A.... "C:\Windows\inf\prndl001.PNF"
Apr 30 2008 5:16:34a 269,612 A.... "C:\Windows\inf\prnep001.PNF"
Apr 30 2008 5:16:56a 11,060 A.... "C:\Windows\inf\prnfu001.PNF"
Apr 30 2008 5:17:00a 38,228 A.... "C:\Windows\inf\prnfx001.PNF"
Apr 30 2008 5:16:12a 8,796 A.... "C:\Windows\inf\prnge001.PNF"
Apr 30 2008 5:16:56a 156,012 A.... "C:\Windows\inf\prngt001.PNF"
Apr 30 2008 5:16:52a 269,480 A.... "C:\Windows\inf\prnhp001.PNF"
Apr 30 2008 5:16:12a 17,760 A.... "C:\Windows\inf\prnib001.PNF"
Apr 30 2008 5:16:50a 117,244 A.... "C:\Windows\inf\prnin001.PNF"
Apr 30 2008 5:16:52a 26,396 A.... "C:\Windows\inf\prnkm001.PNF"
Apr 30 2008 5:16:52a 27,344 A.... "C:\Windows\inf\prnkn001.PNF"
Apr 30 2008 5:17:10a 48,360 A.... "C:\Windows\inf\prnky001.PNF"
Apr 30 2008 5:16:14a 136,496 A.... "C:\Windows\inf\prnle001.PNF"
Apr 30 2008 5:17:10a 114,496 A.... "C:\Windows\inf\prnlx001.PNF"
Apr 30 2008 5:16:48a 18,256 A.... "C:\Windows\inf\prnmi001.PNF"
Apr 30 2008 5:17:00a 13,200 A.... "C:\Windows\inf\prnmq001.PNF"
Apr 30 2008 5:17:06a 6,252 A.... "C:\Windows\inf\prnms002.PNF"
Apr 30 2008 5:16:24a 8,048 A.... "C:\Windows\inf\prnne001.PNF"
Apr 30 2008 5:17:04a 147,120 A.... "C:\Windows\inf\prnnr001.PNF"
Apr 30 2008 5:16:22a 15,028 A.... "C:\Windows\inf\prnoc001.PNF"
Apr 30 2008 5:16:28a 36,468 A.... "C:\Windows\inf\prnod001.PNF"
Apr 30 2008 5:16:54a 63,524 A.... "C:\Windows\inf\prnok001.PNF"
Apr 30 2008 5:16:56a 7,884 A.... "C:\Windows\inf\prnol001.PNF"
Apr 30 2008 5:16:16a 19,212 A.... "C:\Windows\inf\prnpa001.PNF"
Apr 30 2008 5:17:02a 6,988 A.... "C:\Windows\inf\prnqm001.PNF"
Apr 30 2008 5:16:36a 175,060 A.... "C:\Windows\inf\prnrc001.PNF"
Apr 30 2008 5:16:32a 48,864 A.... "C:\Windows\inf\prnsa001.PNF"
Apr 30 2008 5:16:56a 62,524 A.... "C:\Windows\inf\prnsh001.PNF"
Apr 30 2008 5:17:06a 11,468 A.... "C:\Windows\inf\prnso001.PNF"
Apr 30 2008 5:17:12a 6,796 A.... "C:\Windows\inf\prnss001.PNF"
Apr 30 2008 5:17:12a 18,392 A.... "C:\Windows\inf\prnst001.PNF"
Apr 30 2008 5:17:16a 150,028 A.... "C:\Windows\inf\prnsv001.PNF"
Apr 30 2008 5:16:46a 19,368 A.... "C:\Windows\inf\prnta001.PNF"
Apr 30 2008 5:17:02a 14,332 A.... "C:\Windows\inf\prntk001.PNF"
Apr 30 2008 5:17:04a 12,312 A.... "C:\Windows\inf\prnwi001.PNF"
Apr 30 2008 5:17:26a 233,364 A.... "C:\Windows\inf\prnxx001.PNF"
Apr 30 2008 5:15:52a 10,868 A.... "C:\Windows\inf\ps5333nu.PNF"
Apr 30 2008 5:18:34a 21,820 A.... "C:\Windows\inf\ql2300.PNF"
Apr 30 2008 5:18:46a 11,392 A.... "C:\Windows\inf\ql40xx.PNF"
Apr 30 2008 5:18:48a 4,480 A.... "C:\Windows\inf\ql40xx2.PNF"
Apr 30 2008 5:17:38a 8,580 A.... "C:\Windows\inf\ramdisk.PNF"
Apr 30 2008 5:18:42a 18,772 A.... "C:\Windows\inf\ricoh.PNF"
Apr 30 2008 5:18:48a 12,152 A.... "C:\Windows\inf\s3glhx.PNF"
Apr 30 2008 5:18:32a 7,100 A.... "C:\Windows\inf\sbp2.PNF"
Apr 30 2008 5:17:42a 77,036 A.... "C:\Windows\inf\scsidev.PNF"
Apr 30 2008 5:18:44a 13,908 A.... "C:\Windows\inf\sdbus.PNF"
Apr 28 2008 6:39:08p 14,864 A.... "C:\Windows\inf\setupapi.ev1"
Apr 28 2008 6:39:28p 26,872 A.... "C:\Windows\inf\setupapi.ev2"
Apr 28 2008 6:39:28p 86,016 A.... "C:\Windows\inf\setupapi.ev3"
Apr 30 2008 12:23:30p 128,363,679 A.... "C:\Windows\inf\setupapi.app.log"
Apr 28 2008 6:39:32p 8,904,582 A.... "C:\Windows\inf\setupapi.dev.log"
Apr 30 2008 5:17:36a 12,696 A.... "C:\Windows\inf\sffdisk.PNF"
Apr 30 2008 5:18:46a 25,628 A.... "C:\Windows\inf\sisgr.PNF"
Apr 30 2008 5:17:54a 8,716 A.... "C:\Windows\inf\sisraid2.PNF"
Apr 30 2008 5:17:56a 7,512 A.... "C:\Windows\inf\sisraid4.PNF"
Apr 30 2008 5:18:24a 36,480 A.... "C:\Windows\inf\smartcrd.PNF"
Apr 30 2008 5:18:18a 17,252 A.... "C:\Windows\inf\smscirda.PNF"
Apr 30 2008 5:18:12a 32,548 A.... "C:\Windows\inf\sti.PNF"
Apr 30 2008 5:18:06a 10,784 A.... "C:\Windows\inf\stusb2ir.PNF"
Apr 30 2008 5:17:34a 10,248 A.... "C:\Windows\inf\symc8xx.PNF"
Apr 30 2008 5:18:56a 9,592 A.... "C:\Windows\inf\sym_hi.PNF"
Apr 30 2008 5:18:48a 9,616 A.... "C:\Windows\inf\sym_u3.PNF"
Apr 30 2008 5:18:38a 83,928 A.... "C:\Windows\inf\tape.PNF"
Apr 30 2008 5:18:52a 10,944 A.... "C:\Windows\inf\tdibth.PNF"
Apr 30 2008 5:18:12a 11,824 A.... "C:\Windows\inf\tpm.PNF"
Apr 30 2008 5:18:22a 12,204 A.... "C:\Windows\inf\transfercable.PNF"
Apr 30 2008 5:18:46a 8,468 A.... "C:\Windows\inf\ts_generic.PNF"
Apr 30 2008 5:18:40a 11,216 A.... "C:\Windows\inf\ts_wpdmtp.PNF"
Apr 30 2008 5:17:34a 9,724 A.... "C:\Windows\inf\uliahci.PNF"
Apr 30 2008 5:18:56a 9,976 A.... "C:\Windows\inf\ulsata.PNF"
Apr 30 2008 5:16:58a 11,724 A.... "C:\Windows\inf\ulsata2.PNF"
Apr 30 2008 5:19:24a 9,188 A.... "C:\Windows\inf\umbus.PNF"
Apr 30 2008 5:17:48a 4,660 A.... "C:\Windows\inf\unknown.PNF"
Apr 30 2008 5:19:40a 67,896 A.... "C:\Windows\inf\usb.PNF"
Apr 30 2008 5:17:34a 7,128 A.... "C:\Windows\inf\usbccid.PNF"
Apr 30 2008 5:18:56a 33,112 A.... "C:\Windows\inf\usbcir.PNF"
Apr 30 2008 5:19:34a 89,752 A.... "C:\Windows\inf\usbport.PNF"
Apr 30 2008 5:19:42a 7,200 A.... "C:\Windows\inf\usbprint.PNF"
Apr 30 2008 5:19:42a 56,728 A.... "C:\Windows\inf\usbstor.PNF"
Apr 30 2008 5:18:24a 30,896 A.... "C:\Windows\inf\usbvideo.PNF"
Apr 30 2008 5:17:50a 12,564 A.... "C:\Windows\inf\viafir2k.PNF"
Apr 30 2008 5:19:32a 4,940 A.... "C:\Windows\inf\volsnap.PNF"
Apr 30 2008 5:19:28a 6,172 A.... "C:\Windows\inf\volume.PNF"
Apr 30 2008 5:17:42a 8,224 A.... "C:\Windows\inf\vsmraid.PNF"
Apr 30 2008 5:18:14a 8,992 A.... "C:\Windows\inf\v_mscdsc.PNF"
Apr 30 2008 5:18:38a 9,944 A.... "C:\Windows\inf\wave.PNF"
Apr 30 2008 5:18:48a 5,008 A.... "C:\Windows\inf\wceisvista.PNF"
Apr 30 2008 5:18:24a 7,252 A.... "C:\Windows\inf\wcerndis.PNF"
Apr 30 2008 5:18:26a 218,700 A.... "C:\Windows\inf\wceusbsh.PNF"
Apr 30 2008 5:17:32a 7,296 A.... "C:\Windows\inf\wd.PNF"
Apr 30 2008 5:18:22a 13,548 A.... "C:\Windows\inf\wdmaudio.PNF"
Apr 30 2008 5:18:16a 61,588 A.... "C:\Windows\inf\wdma_int.PNF"
Apr 30 2008 5:18:16a 86,668 A.... "C:\Windows\inf\wdma_usb.PNF"
Apr 30 2008 5:18:10a 59,428 A.... "C:\Windows\inf\wdma_via.PNF"
Apr 30 2008 5:15:58a 78,104 A.... "C:\Windows\inf\wiacn001.PNF"
Apr 30 2008 5:16:12a 17,840 A.... "C:\Windows\inf\wiahp001.PNF"
Apr 30 2008 5:18:48a 15,212 A.... "C:\Windows\inf\windowssideshowenhanceddriver.PNF"
Apr 30 2008 5:18:24a 50,460 A.... "C:\Windows\inf\winmobil.PNF"
Apr 30 2008 5:15:52a 5,492 A.... "C:\Windows\inf\winusb.PNF"
Apr 30 2008 5:18:46a 9,192 A.... "C:\Windows\inf\wpdfs.PNF"
Apr 30 2008 5:15:52a 18,788 A.... "C:\Windows\inf\wpdmtp.PNF"
Apr 30 2008 5:18:34a 6,340 A.... "C:\Windows\inf\wpdmtphw.PNF"
Apr 30 2008 5:17:42a 8,312 A.... "C:\Windows\inf\wpdrapi.PNF"
Apr 30 2008 5:18:34a 9,280 A.... "C:\Windows\inf\wsdprint.PNF"
Apr 30 2008 5:18:30a 10,864 A.... "C:\Windows\inf\wsdscdrv.PNF"
Apr 30 2008 5:18:40a 71,284 A.... "C:\Windows\inf\xcbda.PNF"
Apr 30 2008 5:18:40a 7,592 A.... "C:\Windows\inf\xnacc.PNF"
Apr 30 2008 5:17:46a 12,100 A.... "C:\Windows\inf\xrxscan.PNF"
Apr 30 2008 12:21:30p 2,640 A..H. "C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0"
Apr 30 2008 12:21:30p 2,640 A..H. "C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0"
Mar 31 2008 1:54:50p 28,672 A.... "C:\Windows\System32\f3PSSavr.scr"
Apr 22 2008 5:51:32a 2,772,272 A.... "C:\Windows\System32\FNTCACHE.DAT"
Mar 19 2008 4:38:22p 36,864 A.... "C:\Windows\System32\GamesCampus.ocx"
Apr 6 2008 7:41:10p 514,136 A.... "C:\Windows\System32\GDIPFONTCACHEV1.DAT"
Mar 19 2008 7:34:24p 6,242 A.... "C:\Windows\System32\jupdate-1.6.0_05-b13.log"
Apr 30 2008 12:20:56p 785 A.SH. "C:\Windows\System32\mmf.sys"
Apr 6 2008 1:56:20a 19,836,024 A.... "C:\Windows\System32\mrt.exe"
Apr 19 2008 12:03:00p 188 A.... "C:\Windows\System32\MsiExec.exe.log"
Apr 7 2008 8:11:54a 51,355 A.... "C:\Windows\System32\muzika.xm"
Apr 22 2008 8:43:18a 0 A.... "C:\Windows\System32\netsh"
Apr 29 2008 6:03:00p 113,704 A.... "C:\Windows\System32\perfc009.dat"
Apr 29 2008 6:03:00p 640,850 A.... "C:\Windows\System32\perfh009.dat"
Apr 29 2008 6:02:58p 748,116 A.... "C:\Windows\System32\PerfStringBackup.INI"
Mar 28 2008 11:37:26p 57,344 A.... "C:\Windows\System32\QuickTime.qts"
Mar 28 2008 11:37:26p 90,112 A.... "C:\Windows\System32\QuickTimeVR.qtx"
Feb 29 2008 12:16:40a 2,027,008 A.... "C:\Windows\System32\win32k.sys"
Apr 30 2008 12:20:40p 6 A..H. "C:\Windows\Tasks\SA.DAT"
Apr 30 2008 12:25:08p 436 A..H. "C:\Windows\Tasks\User_Feed_Synchronization-{A43368D4-F017-450C-A5B8-80F7A973BA3F}.job"
Apr 22 2008 5:47:26a 253 A.... "C:\Windows\winsxs\poqexec.log"
Apr 30 2008 11:55:42a 0 A.... "C:\Windows\Debug\UserMode\ChkAcc.bak"
Apr 30 2008 12:20:34p 0 A.... "C:\Windows\Debug\UserMode\ChkAcc.log"
Feb 29 2008 8:57:16a 10,099 ..... "C:\Windows\Debug\WIA\wiatrace.log"
Apr 26 2008 1:50:12p 95,040,000 A.... "C:\Windows\Downloaded Installations\{551FB0FF-3C57-497D-BD9C-89A393FF8E21}\Cal Ripken's Real Baseball.msi"
Apr 30 2008 10:49:56a 253,952 A.... "C:\Windows\ERDNT\dss\default"
Apr 30 2008 10:48:42a 220 A.... "C:\Windows\ERDNT\dss\README.txt"
Apr 30 2008 10:48:42a 61,440 A.... "C:\Windows\ERDNT\dss\sam"
Apr 30 2008 10:49:46a 41,639,936 A....
  • 0

#5
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there phala,

SDFix didn't produce the log I need, for it to do this you must logon to an account with administrative privileges, or ask someone who has them to run this tool for you. Please post the Deckards' System Scanner log as instructed in step 4 as well :) If you need any help don't hesitate to ask.
  • 0

#6
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP