Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

web redirect - fake antivirus pop ups - super slow


  • Please log in to reply

#91
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
Avira AntiVir Personal
Report file date: Friday, January 07, 2011 16:20

Scanning for 2331556 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : SYSTEMAX

Version information:
BUILD.DAT : 10.0.0.609 31824 Bytes 12/13/2010 09:43:00
AVSCAN.EXE : 10.0.3.5 435368 Bytes 12/13/2010 15:39:56
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 19:57:04
LUKE.DLL : 10.0.3.2 104296 Bytes 12/13/2010 15:40:06
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/11/2010 06:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 16:05:36
VBASE001.VDF : 7.11.0.0 13342208 Bytes 12/14/2010 21:18:35
VBASE002.VDF : 7.11.0.1 2048 Bytes 12/14/2010 21:18:35
VBASE003.VDF : 7.11.0.2 2048 Bytes 12/14/2010 21:18:35
VBASE004.VDF : 7.11.0.3 2048 Bytes 12/14/2010 21:18:36
VBASE005.VDF : 7.11.0.4 2048 Bytes 12/14/2010 21:18:36
VBASE006.VDF : 7.11.0.5 2048 Bytes 12/14/2010 21:18:36
VBASE007.VDF : 7.11.0.6 2048 Bytes 12/14/2010 21:18:36
VBASE008.VDF : 7.11.0.7 2048 Bytes 12/14/2010 21:18:36
VBASE009.VDF : 7.11.0.8 2048 Bytes 12/14/2010 21:18:37
VBASE010.VDF : 7.11.0.9 2048 Bytes 12/14/2010 21:18:37
VBASE011.VDF : 7.11.0.10 2048 Bytes 12/14/2010 21:18:37
VBASE012.VDF : 7.11.0.11 2048 Bytes 12/14/2010 21:18:37
VBASE013.VDF : 7.11.0.52 128000 Bytes 12/16/2010 21:18:39
VBASE014.VDF : 7.11.0.91 226816 Bytes 12/20/2010 21:18:41
VBASE015.VDF : 7.11.0.122 136192 Bytes 12/21/2010 21:18:43
VBASE016.VDF : 7.11.0.156 122880 Bytes 12/24/2010 21:18:44
VBASE017.VDF : 7.11.0.185 146944 Bytes 12/27/2010 21:18:46
VBASE018.VDF : 7.11.0.228 132608 Bytes 12/30/2010 21:18:48
VBASE019.VDF : 7.11.1.5 148480 Bytes 1/3/2011 21:15:37
VBASE020.VDF : 7.11.1.6 2048 Bytes 1/3/2011 21:15:37
VBASE021.VDF : 7.11.1.7 2048 Bytes 1/3/2011 21:15:37
VBASE022.VDF : 7.11.1.8 2048 Bytes 1/3/2011 21:15:38
VBASE023.VDF : 7.11.1.9 2048 Bytes 1/3/2011 21:15:38
VBASE024.VDF : 7.11.1.10 2048 Bytes 1/3/2011 21:15:38
VBASE025.VDF : 7.11.1.11 2048 Bytes 1/3/2011 21:15:38
VBASE026.VDF : 7.11.1.12 2048 Bytes 1/3/2011 21:15:38
VBASE027.VDF : 7.11.1.13 2048 Bytes 1/3/2011 21:15:39
VBASE028.VDF : 7.11.1.14 2048 Bytes 1/3/2011 21:15:39
VBASE029.VDF : 7.11.1.15 2048 Bytes 1/3/2011 21:15:39
VBASE030.VDF : 7.11.1.16 2048 Bytes 1/3/2011 21:15:40
VBASE031.VDF : 7.11.1.35 145920 Bytes 1/6/2011 00:14:12
Engineversion : 8.2.4.140
AEVDF.DLL : 8.1.2.1 106868 Bytes 12/13/2010 15:39:51
AESCRIPT.DLL : 8.1.3.52 1282426 Bytes 1/7/2011 00:14:35
AESCN.DLL : 8.1.7.2 127349 Bytes 12/13/2010 15:39:50
AESBX.DLL : 8.1.3.2 254324 Bytes 12/13/2010 15:39:50
AERDL.DLL : 8.1.9.2 635252 Bytes 12/13/2010 15:39:50
AEPACK.DLL : 8.2.4.7 512375 Bytes 1/2/2011 21:19:11
AEOFFICE.DLL : 8.1.1.10 201084 Bytes 12/13/2010 15:39:49
AEHEUR.DLL : 8.1.2.64 3154294 Bytes 1/7/2011 00:14:31
AEHELP.DLL : 8.1.16.0 246136 Bytes 12/13/2010 15:39:42
AEGEN.DLL : 8.1.5.1 397683 Bytes 1/7/2011 00:14:15
AEEMU.DLL : 8.1.3.0 393589 Bytes 12/13/2010 15:39:42
AECORE.DLL : 8.1.19.0 196984 Bytes 12/13/2010 15:39:41
AEBB.DLL : 8.1.1.0 53618 Bytes 12/13/2010 15:39:41
AVWINLL.DLL : 10.0.0.0 19304 Bytes 12/13/2010 15:39:56
AVPREF.DLL : 10.0.0.0 44904 Bytes 12/13/2010 15:39:54
AVREP.DLL : 10.0.0.8 62209 Bytes 6/17/2010 21:27:13
AVREG.DLL : 10.0.3.2 53096 Bytes 12/13/2010 15:39:54
AVSCPLR.DLL : 10.0.3.2 84328 Bytes 12/13/2010 15:39:56
AVARKT.DLL : 10.0.22.6 231784 Bytes 12/13/2010 15:39:52
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 12/13/2010 15:39:53
SQLITE3.DLL : 3.6.19.0 355688 Bytes 6/17/2010 21:27:22
AVSMTP.DLL : 10.0.0.17 63848 Bytes 12/13/2010 15:39:56
NETNT.DLL : 10.0.0.0 11624 Bytes 6/17/2010 21:27:21
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 20:10:20
RCTEXT.DLL : 10.0.58.0 97128 Bytes 12/13/2010 15:40:20

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Friday, January 07, 2011 16:20

Starting search for hidden objects.
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc\Config\Standalone\drivelist
[NOTE] The registry entry is invisible.

The scan of running processes will be started
Scan process 'msdtc.exe' - '42' Module(s) have been scanned
Scan process 'dllhost.exe' - '61' Module(s) have been scanned
Scan process 'dllhost.exe' - '47' Module(s) have been scanned
Scan process 'vssvc.exe' - '50' Module(s) have been scanned
Scan process 'avscan.exe' - '72' Module(s) have been scanned
Scan process 'avcenter.exe' - '63' Module(s) have been scanned
Scan process 'svchost.exe' - '36' Module(s) have been scanned
Scan process 'alg.exe' - '35' Module(s) have been scanned
Scan process 'uphclean.exe' - '7' Module(s) have been scanned
Scan process 'svchost.exe' - '41' Module(s) have been scanned
Scan process 'hpqSTE08.exe' - '80' Module(s) have been scanned
Scan process 'QBCFMonitorService.exe' - '33' Module(s) have been scanned
Scan process 'HPZipm12.exe' - '21' Module(s) have been scanned
Scan process 'PhxVtSvr.exe' - '6' Module(s) have been scanned
Scan process 'PhxPsSvr.exe' - '6' Module(s) have been scanned
Scan process 'avshadow.exe' - '26' Module(s) have been scanned
Scan process 'MDM.EXE' - '22' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '21' Module(s) have been scanned
Scan process 'avguard.exe' - '53' Module(s) have been scanned
Scan process 'hpqimzone.exe' - '91' Module(s) have been scanned
Scan process 'rapimgr.exe' - '44' Module(s) have been scanned
Scan process 'hpqtra08.exe' - '79' Module(s) have been scanned
Scan process 'Wcescomm.exe' - '46' Module(s) have been scanned
Scan process 'msmsgs.exe' - '45' Module(s) have been scanned
Scan process 'LinksysAgent.exe' - '101' Module(s) have been scanned
Scan process 'MsnMsgr.Exe' - '107' Module(s) have been scanned
Scan process 'ctfmon.exe' - '27' Module(s) have been scanned
Scan process 'avgnt.exe' - '47' Module(s) have been scanned
Scan process 'Explorer.EXE' - '109' Module(s) have been scanned
Scan process 'svchost.exe' - '36' Module(s) have been scanned
Scan process 'sched.exe' - '45' Module(s) have been scanned
Scan process 'spoolsv.exe' - '58' Module(s) have been scanned
Scan process 'svchost.exe' - '43' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'svchost.exe' - '170' Module(s) have been scanned
Scan process 'svchost.exe' - '41' Module(s) have been scanned
Scan process 'svchost.exe' - '54' Module(s) have been scanned
Scan process 'lsass.exe' - '60' Module(s) have been scanned
Scan process 'services.exe' - '36' Module(s) have been scanned
Scan process 'winlogon.exe' - '69' Module(s) have been scanned
Scan process 'csrss.exe' - '12' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!
Master boot sector HD5
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '1840' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\Downloads\Noise Ninja Standalone 5 Cracked\Setup.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163376.exe
[DETECTION] Is the TR/Agent.15616.B Trojan
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163389.exe
[DETECTION] Is the TR/Gendal.15616.G Trojan
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163394.exe
[DETECTION] Is the TR/Agent.15616.E Trojan
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163397.exe
[DETECTION] Is the TR/Gendal.15616.H Trojan
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163499.EXE
[DETECTION] Is the TR/Drop.Agent.qgq.2 Trojan

Beginning disinfection:
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163499.EXE
[DETECTION] Is the TR/Drop.Agent.qgq.2 Trojan
[NOTE] The file was moved to the quarantine directory under the name '471a75bf.qua'.
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163397.exe
[DETECTION] Is the TR/Gendal.15616.H Trojan
[NOTE] The file was moved to the quarantine directory under the name '5f8d5a18.qua'.
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163394.exe
[DETECTION] Is the TR/Agent.15616.E Trojan
[NOTE] The file was moved to the quarantine directory under the name '0dd200f0.qua'.
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163389.exe
[DETECTION] Is the TR/Gendal.15616.G Trojan
[NOTE] The file was moved to the quarantine directory under the name '6be54f32.qua'.
C:\System Volume Information\_restore{6742B4A6-3600-42DD-A01B-B908D2B25349}\RP1360\A0163376.exe
[DETECTION] Is the TR/Agent.15616.B Trojan
[NOTE] The file was moved to the quarantine directory under the name '2e61620c.qua'.
C:\Downloads\Noise Ninja Standalone 5 Cracked\Setup.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '51b95018.qua'.


End of the scan: Friday, January 07, 2011 19:50
Used time: 1:24:52 Hour(s)

The scan has been done completely.

10847 Scanned directories
424254 Files were scanned
6 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
6 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
424248 Files not concerned
7931 Archives were scanned
0 Warnings
6 Notes
635358 Objects were scanned with rootkit scan
1 Hidden objects were found
  • 0

Advertisements


#92
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
OTL logfile created on: 1/7/2011 8:47:05 PM - Run 4
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\Tim Oakley\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 543.00 Mb Available Physical Memory | 54.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 222.65 Gb Total Space | 36.03 Gb Free Space | 16.18% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: SYSTEMAX | User Name: Tim Oakley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/12/28 16:44:22 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tim Oakley\Desktop\OTL.exe
PRC - [2010/12/13 08:40:07 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010/12/13 08:39:54 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/12/13 08:39:54 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/09/13 20:02:44 | 000,399,872 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\Program Files\UPHClean\uphclean.exe
PRC - [2010/01/14 21:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008/09/10 21:37:36 | 000,024,576 | ---- | M] (Intuit) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/08/09 00:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2007/03/15 18:16:42 | 000,454,784 | ---- | M] (Linksys, a Division of Cisco Systems, Inc.) -- C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
PRC - [2006/11/13 12:39:52 | 001,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PRC - [2006/04/05 17:14:04 | 000,040,960 | ---- | M] (Phoenix Technologies Ltd.) -- C:\WINDOWS\system32\PhxPsSvr.exe
PRC - [2006/02/10 07:56:12 | 000,479,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
PRC - [2005/12/14 12:40:12 | 000,053,248 | ---- | M] (Phoenix Technologies Ltd.) -- C:\WINDOWS\system32\PhxVtSvr.exe


========== Modules (SafeList) ==========

MOD - [2010/12/28 16:44:22 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tim Oakley\Desktop\OTL.exe
MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/12/13 08:40:07 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/12/13 08:39:54 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/09/13 20:02:44 | 000,399,872 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Auto | Running] -- C:\Program Files\UPHClean\uphclean.exe -- (UPHClean)
SRV - [2008/09/10 21:37:36 | 000,024,576 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2008/08/08 20:10:46 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2008/01/02 17:34:00 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007/10/25 14:27:54 | 000,266,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc)
SRV - [2007/08/09 00:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2006/04/05 17:14:04 | 000,040,960 | ---- | M] (Phoenix Technologies Ltd.) [Auto | Running] -- C:\WINDOWS\system32\PhxPsSvr.exe -- (PhnxPsaService)
SRV - [2006/01/04 23:06:02 | 000,163,840 | ---- | M] (Alex Feinman) [On_Demand | Stopped] -- C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe -- (Imapi Helper)
SRV - [2005/12/14 12:40:12 | 000,053,248 | ---- | M] (Phoenix Technologies Ltd.) [Auto | Running] -- C:\WINDOWS\system32\PhxVtSvr.exe -- (PhnxVaultService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\TIMOAK~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/12/13 08:40:21 | 000,135,096 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/12/13 08:40:21 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/06/17 14:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/17 14:27:12 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008/04/13 11:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 11:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 11:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 09:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/03/22 12:57:14 | 000,028,672 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\elagopro.sys -- (elagopro)
DRV - [2007/03/22 12:57:14 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\elaunidr.sys -- (elaunidr)
DRV - [2007/01/20 00:11:07 | 000,031,644 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2006/06/14 11:56:40 | 000,247,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2006/04/03 06:51:06 | 000,199,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel®
DRV - [2006/03/21 12:37:44 | 000,047,488 | ---- | M] (Phoenix Technologies Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\phnxvcd.sys -- (PhnxVcd)
DRV - [2006/03/20 12:06:04 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2005/12/02 15:43:22 | 000,008,832 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\FBAPI.sys -- (FBAPI)
DRV - [2005/12/02 13:38:04 | 000,041,728 | ---- | M] (Sonic Focus, Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sfng32.sys -- (sfng32)
DRV - [2005/10/18 14:47:10 | 000,008,320 | ---- | M] (Phoenix Technologies Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\ptpd.sys -- (ptpd)
DRV - [2005/06/07 15:13:02 | 000,042,240 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\DCDisk.sys -- (DCDisk)
DRV - [2005/03/31 18:58:00 | 000,450,400 | R--- | M] (D-Link Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\A3AB.sys -- (A3AB) D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB)
DRV - [2004/09/29 16:35:30 | 000,219,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2004/09/29 16:34:24 | 000,702,592 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004/09/29 16:33:50 | 001,036,928 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004/08/03 21:31:20 | 000,036,224 | ---- | M] (ADMtek Incorporated.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\an983.sys -- (AN983)
DRV - [2004/08/03 20:29:28 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2003/08/13 00:27:00 | 000,002,304 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\Machnm32.sys -- (Machnm32)
DRV - [2001/08/17 12:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 12:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 12:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 12:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 12:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 11:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 11:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 11:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 11:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 11:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 11:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 11:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 11:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 11:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 11:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2001/08/17 10:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

FF - HKLM\software\mozilla\Firefox\Extensions\\{3F174225-6496-4A74-B549-C4358CE3B826}: C:\Documents and Settings\Tim Oakley\Local Settings\Application Data\{3F174225-6496-4A74-B549-C4358CE3B826}\ [2010/08/30 21:58:56 | 000,000,000 | ---D | M]

[2009/08/23 11:52:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\Mozilla\Extensions
[2009/08/23 11:52:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\Mozilla\Extensions\[email protected]

O1 HOSTS File: ([2010/12/29 10:05:58 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKCU..\Run: [EasyLinkAdvisor] C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\Wcescomm.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1159453796765 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} https://mail.pcaengs...emote/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.aka...vex-2.2.1.6.cab (DownloadManager Control)
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tim Oakley\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tim Oakley\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/28 06:29:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/07 20:14:52 | 000,000,000 | --SD | C] -- C:\george3
[2011/01/07 19:49:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/01/05 22:39:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/01/05 22:37:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/01/05 22:37:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tim Oakley\Desktop\Dial-a-fix-v0.60.0.24
[2011/01/05 22:35:46 | 000,000,000 | ---D | C] -- C:\Program Files\UPHClean
[2011/01/05 19:12:35 | 000,116,224 | ---- | C] (Xerox) -- C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2011/01/05 19:12:31 | 000,023,040 | ---- | C] (Xerox Corporation) -- C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2011/01/05 19:12:09 | 000,099,865 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\xlog.exe
[2011/01/05 19:12:05 | 000,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys
[2011/01/05 19:11:36 | 000,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys
[2011/01/05 19:11:32 | 000,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2011/01/05 19:11:25 | 000,771,581 | ---- | C] (Rockwell) -- C:\WINDOWS\System32\dllcache\winacisa.sys
[2011/01/05 19:11:10 | 000,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2011/01/05 19:10:58 | 000,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys
[2011/01/05 19:10:55 | 000,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys
[2011/01/05 19:10:51 | 000,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys
[2011/01/05 19:10:46 | 000,064,605 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vvoice.sys
[2011/01/05 19:10:42 | 000,397,502 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vpctcom.sys
[2011/01/05 19:10:39 | 000,604,253 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\vmodem.sys
[2011/01/05 19:10:35 | 000,249,402 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\vinwm.sys
[2011/01/05 19:10:23 | 000,765,884 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usrti.sys
[2011/01/05 19:10:09 | 000,794,399 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806v.sys
[2011/01/05 19:10:06 | 000,793,598 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806.sys
[2011/01/05 19:10:03 | 000,794,654 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1801.sys
[2011/01/05 19:09:59 | 000,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys
[2011/01/05 19:09:41 | 000,050,688 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\umaxscan.dll
[2011/01/05 19:09:28 | 000,211,968 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um54scan.dll
[2011/01/05 19:09:25 | 000,216,064 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um34scan.dll
[2011/01/05 19:09:16 | 000,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys
[2011/01/05 19:09:13 | 000,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll
[2011/01/05 19:09:09 | 000,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys
[2011/01/05 19:09:06 | 000,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll
[2011/01/05 19:09:03 | 000,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys
[2011/01/05 19:09:00 | 000,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll
[2011/01/05 19:08:34 | 000,123,995 | ---- | C] (Tiger Jet Network) -- C:\WINDOWS\System32\dllcache\tjisdn.sys
[2011/01/05 19:08:30 | 000,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2011/01/05 19:08:26 | 000,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll
[2011/01/05 19:08:25 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys
[2011/01/05 19:08:22 | 000,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2011/01/05 19:08:19 | 000,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys
[2011/01/05 19:08:07 | 000,036,640 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2011/01/05 19:08:04 | 000,172,768 | ---- | C] (Number Nine Visual Technology) -- C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2011/01/05 19:07:37 | 000,155,648 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnprop.dll
[2011/01/05 19:07:34 | 000,053,248 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlncoin.dll
[2011/01/05 19:07:31 | 000,285,760 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnata.sys
[2011/01/05 19:07:28 | 000,016,896 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys
[2011/01/05 19:07:24 | 000,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2011/01/05 19:06:43 | 000,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys
[2011/01/05 19:06:39 | 000,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll
[2011/01/05 19:06:36 | 000,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2011/01/05 19:06:33 | 000,035,913 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys
[2011/01/05 19:06:30 | 000,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys
[2011/01/05 19:06:08 | 000,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2011/01/05 19:06:05 | 000,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys
[2011/01/05 19:06:02 | 000,094,698 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2011/01/05 19:05:55 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys
[2011/01/05 19:05:31 | 000,161,568 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2011/01/05 19:05:28 | 000,018,400 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmld.sys
[2011/01/05 19:05:25 | 000,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2011/01/05 19:05:22 | 000,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll
[2011/01/05 19:05:01 | 000,017,280 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys
[2011/01/05 19:04:55 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2011/01/05 19:04:52 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2011/01/05 19:04:39 | 000,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2011/01/05 19:04:36 | 000,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll
[2011/01/05 19:04:33 | 000,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2011/01/05 19:04:30 | 000,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2011/01/05 19:04:28 | 000,210,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2011/01/05 19:04:25 | 000,062,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2011/01/05 19:04:22 | 000,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2011/01/05 19:04:19 | 000,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2011/01/05 19:04:16 | 000,166,720 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3m.sys
[2011/01/05 19:04:10 | 000,082,432 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia450.dll
[2011/01/05 19:04:08 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia430.dll
[2011/01/05 19:04:06 | 000,029,696 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw450ext.dll
[2011/01/05 19:04:05 | 000,027,648 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw430ext.dll
[2011/01/05 19:03:54 | 000,009,216 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2011/01/05 19:03:48 | 000,079,104 | ---- | C] (Comtrol Corporation) -- C:\WINDOWS\System32\dllcache\rocket.sys
[2011/01/05 19:03:45 | 000,037,563 | ---- | C] (RadioLAN) -- C:\WINDOWS\System32\dllcache\rlnet5.sys
[2011/01/05 19:03:42 | 000,086,097 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\reslog32.dll
[2011/01/05 19:03:31 | 000,714,762 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2011/01/05 19:03:28 | 000,899,146 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2011/01/05 19:03:16 | 000,130,942 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlv.sys
[2011/01/05 19:03:13 | 000,112,574 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlp.sys
[2011/01/05 19:03:10 | 000,128,286 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserli.sys
[2011/01/05 19:02:59 | 000,016,128 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\pscr.sys
[2011/01/05 19:02:19 | 000,086,016 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\pctspk.exe
[2011/01/05 19:02:08 | 000,026,153 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2011/01/05 19:02:07 | 000,029,502 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\pca200e.sys
[2011/01/05 19:02:04 | 000,030,495 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pc100nds.sys
[2011/01/05 19:01:30 | 000,054,186 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otcsercb.sys
[2011/01/05 19:01:27 | 000,043,689 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otceth5.sys
[2011/01/05 19:01:24 | 000,027,209 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otc06x5.sys
[2011/01/05 19:01:21 | 000,054,528 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\opl3sax.sys
[2011/01/05 19:01:07 | 000,051,552 | ---- | C] (Kensington Technology Group) -- C:\WINDOWS\System32\dllcache\ntgrip.sys
[2011/01/05 18:50:26 | 000,087,040 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2011/01/05 18:50:23 | 000,126,080 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2011/01/05 18:50:18 | 000,132,695 | ---- | C] (802.11b) -- C:\WINDOWS\System32\dllcache\netwlan5.sys
[2011/01/05 18:50:11 | 000,039,264 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.sys
[2011/01/05 18:50:09 | 000,060,480 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.dll
[2011/01/05 18:50:02 | 000,091,488 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2011/01/05 18:50:00 | 000,027,936 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3d.sys
[2011/01/05 18:49:57 | 000,033,088 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2011/01/05 18:49:54 | 000,059,104 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2011/01/05 18:49:52 | 000,013,664 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.sys
[2011/01/05 18:49:49 | 000,035,392 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.dll
[2011/01/05 18:49:41 | 000,075,520 | ---- | C] (Moxa Technologies Co., Ltd.) -- C:\WINDOWS\System32\dllcache\mxport.sys
[2011/01/05 18:49:39 | 000,007,168 | ---- | C] (Moxa Technologies Co., Ltd) -- C:\WINDOWS\System32\dllcache\mxport.dll
[2011/01/05 18:49:36 | 000,019,968 | ---- | C] (Macronix International Co., Ltd. ) -- C:\WINDOWS\System32\dllcache\mxnic.sys
[2011/01/05 18:49:34 | 000,019,968 | ---- | C] (Moxa Technologies Co., Ltd) -- C:\WINDOWS\System32\dllcache\mxicfg.dll
[2011/01/05 18:49:31 | 000,021,888 | ---- | C] (Moxa Technologies Co., Ltd.) -- C:\WINDOWS\System32\dllcache\mxcard.sys
[2011/01/05 18:48:34 | 000,164,586 | ---- | C] (Madge Networks Ltd) -- C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2011/01/05 18:48:16 | 000,797,500 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltsmt.sys
[2011/01/05 18:48:14 | 000,802,683 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\ltsm.sys
[2011/01/05 18:48:13 | 000,420,992 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2011/01/05 18:48:10 | 000,606,684 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2011/01/05 18:48:10 | 000,576,746 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2011/01/05 18:48:08 | 000,727,786 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ltck000c.sys
[2011/01/05 18:48:00 | 000,070,730 | ---- | C] (Linksys Group, Inc.) -- C:\WINDOWS\System32\dllcache\lne100tx.sys
[2011/01/05 18:47:58 | 000,020,573 | ---- | C] (The Linksts Group ) -- C:\WINDOWS\System32\dllcache\lne100.sys
[2011/01/05 18:47:56 | 000,025,065 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\lmndis3.sys
[2011/01/05 18:47:53 | 000,015,744 | ---- | C] (Litronic Industries) -- C:\WINDOWS\System32\dllcache\lit220p.sys
[2011/01/05 18:47:50 | 000,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys
[2011/01/05 18:47:47 | 000,019,016 | ---- | C] (Kingston Technology Company ) -- C:\WINDOWS\System32\dllcache\ktc111.sys
[2011/01/05 18:47:05 | 000,023,552 | ---- | C] (MKNet Corporation) -- C:\WINDOWS\System32\dllcache\irmk7.sys
[2011/01/05 18:46:38 | 000,372,824 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\iconf32.dll
[2011/01/05 18:45:18 | 000,068,608 | ---- | C] (Avisioin) -- C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2011/01/05 18:45:09 | 000,126,976 | ---- | C] (Hewlett Packard) -- C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2011/01/05 18:44:47 | 000,028,288 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grserial.sys
[2011/01/05 18:44:45 | 000,082,304 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grclass.sys
[2011/01/05 18:44:43 | 000,017,408 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\gpr400.sys
[2011/01/05 18:44:32 | 000,454,912 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fxusbase.sys
[2011/01/05 18:44:23 | 000,455,296 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fusbbase.sys
[2011/01/05 18:44:21 | 000,455,680 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fus2base.sys
[2011/01/05 18:44:18 | 000,442,240 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2011/01/05 18:44:16 | 000,441,728 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2011/01/05 18:44:14 | 000,444,416 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcibase.sys
[2011/01/05 18:44:13 | 000,034,173 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\forehe.sys
[2011/01/05 18:44:00 | 000,024,618 | ---- | C] (NETGEAR) -- C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2011/01/05 18:43:57 | 000,011,850 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2011/01/05 18:43:55 | 000,012,362 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2011/01/05 18:42:45 | 000,334,208 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2011/01/05 18:42:42 | 000,028,062 | ---- | C] (National Semiconductor Coproration) -- C:\WINDOWS\System32\dllcache\dp83820.sys
[2011/01/05 18:42:35 | 000,029,696 | ---- | C] (CNet Technology, Inc. ) -- C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2011/01/05 18:42:34 | 000,026,698 | ---- | C] (D-Link Corporation) -- C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2011/01/05 18:42:33 | 000,952,007 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diwan.sys
[2011/01/05 18:42:28 | 000,236,060 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\ditrace.exe
[2011/01/05 18:42:27 | 000,038,985 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvsu.dll
[2011/01/05 18:42:26 | 000,031,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvpp.dll
[2011/01/05 18:42:25 | 000,006,729 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvci.dll
[2011/01/05 18:42:24 | 000,091,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\dimaint.sys
[2011/01/05 18:42:06 | 000,024,649 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650d.sys
[2011/01/05 18:42:05 | 000,024,648 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650.sys
[2011/01/05 18:42:01 | 000,020,928 | ---- | C] (Digital Networks, LLC) -- C:\WINDOWS\System32\dllcache\defpa.sys
[2011/01/05 18:41:43 | 000,048,640 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2011/01/05 18:41:42 | 000,093,952 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2011/01/05 18:41:41 | 000,111,872 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcspud.sys
[2011/01/05 18:41:40 | 000,003,584 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2011/01/05 18:41:39 | 000,072,832 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2011/01/05 18:41:38 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2011/01/05 18:41:37 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbase.sys
[2011/01/05 18:41:35 | 000,249,856 | ---- | C] (Comtrol® Corporation) -- C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2011/01/05 18:41:29 | 000,216,064 | ---- | C] (COMPAQ Inc.) -- C:\WINDOWS\System32\dllcache\cpscan.dll
[2011/01/05 18:41:19 | 000,020,736 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2011/01/05 18:41:12 | 000,980,034 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\cicap.sys
[2011/01/05 18:41:07 | 000,049,182 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem56n5.sys
[2011/01/05 18:41:06 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem33n5.sys
[2011/01/05 18:41:06 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem28n5.sys
[2011/01/05 18:41:05 | 000,027,164 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce3n5.sys
[2011/01/05 18:41:04 | 000,021,530 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce2n5.sys
[2011/01/05 18:41:03 | 000,714,698 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2011/01/05 18:41:02 | 000,046,108 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cben5.sys
[2011/01/05 18:41:02 | 000,039,680 | ---- | C] (Silicom Ltd.) -- C:\WINDOWS\System32\dllcache\cb325.sys
[2011/01/05 18:41:01 | 000,037,916 | ---- | C] (Fast Ethernet Controller Provider) -- C:\WINDOWS\System32\dllcache\cb102.sys
[2011/01/05 18:40:59 | 000,032,256 | ---- | C] (Eicon Technology Corporation) -- C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2011/01/05 18:40:58 | 000,164,923 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diapi2.sys
[2011/01/05 18:40:28 | 000,031,529 | ---- | C] (BreezeCOM) -- C:\WINDOWS\System32\dllcache\brzwlan.sys
[2011/01/05 18:40:27 | 000,011,008 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2011/01/05 18:40:27 | 000,010,368 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbscn.sys
[2011/01/05 18:40:26 | 000,060,416 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brserwdm.sys
[2011/01/05 18:40:26 | 000,009,728 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brserif.dll
[2011/01/05 18:40:25 | 000,005,120 | ---- | C] (Brother Industries,Ltd.) -- C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2011/01/05 18:40:24 | 000,039,552 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparwdm.sys
[2011/01/05 18:40:24 | 000,003,168 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparimg.sys
[2011/01/05 18:40:22 | 000,041,472 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfusb.dll
[2011/01/05 18:40:22 | 000,032,256 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2011/01/05 18:40:21 | 000,029,696 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmflpt.dll
[2011/01/05 18:40:20 | 000,015,360 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2011/01/05 18:40:19 | 000,012,160 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2011/01/05 18:40:19 | 000,003,968 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltup.sys
[2011/01/05 18:40:18 | 000,012,800 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brevif.dll
[2011/01/05 18:40:18 | 000,002,944 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brfilt.sys
[2011/01/05 18:40:17 | 000,009,728 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brcoinst.dll
[2011/01/05 18:40:16 | 000,019,456 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brbidiif.dll
[2011/01/05 18:40:13 | 000,871,388 | ---- | C] (BCM) -- C:\WINDOWS\System32\dllcache\bcmdm.sys
[2011/01/05 18:40:10 | 000,036,128 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.sys
[2011/01/05 18:40:09 | 000,342,336 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.dll
[2011/01/05 18:40:08 | 000,089,952 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\b1cbase.sys
[2011/01/05 18:40:08 | 000,036,992 | ---- | C] (Aztech Systems Ltd) -- C:\WINDOWS\System32\dllcache\aztw2320.sys
[2011/01/05 18:40:07 | 000,037,568 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmwan.sys
[2011/01/05 18:40:06 | 000,144,384 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmenum.dll
[2011/01/05 18:40:06 | 000,087,552 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2011/01/05 18:39:49 | 000,097,354 | ---- | C] (Bay Networks, Inc.) -- C:\WINDOWS\System32\dllcache\aspndis3.sys
[2011/01/05 18:39:46 | 000,016,969 | ---- | C] (AmbiCom, Inc.) -- C:\WINDOWS\System32\dllcache\amb8002.sys
[2011/01/05 18:39:39 | 000,046,112 | ---- | C] (Adaptec, Inc ) -- C:\WINDOWS\System32\dllcache\adptsf50.sys
[2011/01/05 18:39:38 | 000,010,880 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\admjoy.sys
[2011/01/05 18:39:37 | 000,747,392 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8830.sys
[2011/01/05 18:39:37 | 000,553,984 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8820.sys
[2011/01/05 18:39:36 | 000,584,448 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8810.sys
[2011/01/05 18:39:35 | 000,061,440 | ---- | C] (Color Flatbed Scanner) -- C:\WINDOWS\System32\dllcache\acerscad.dll
[2011/01/05 18:39:33 | 000,462,848 | ---- | C] (Aureal Inc.) -- C:\WINDOWS\System32\dllcache\a3dapi.dll
[2011/01/05 18:39:32 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\dllcache\a3d.dll
[2011/01/05 18:39:31 | 000,689,216 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2011/01/05 18:39:31 | 000,148,352 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2011/01/05 18:39:30 | 000,762,780 | ---- | C] (3Com, Inc.) -- C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2011/01/04 09:26:41 | 004,177,272 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\Tim Oakley\Desktop\procexp.exe
[2011/01/03 18:56:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tim Oakley\Application Data\Avira
[2011/01/03 18:55:16 | 005,473,272 | ---- | C] (OPSWAT, Inc.) -- C:\Documents and Settings\Tim Oakley\Desktop\AppRemover.exe
[2011/01/02 14:14:44 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/01/02 14:14:42 | 000,135,096 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/01/02 14:14:42 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/01/02 14:14:42 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/01/02 14:14:42 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/01/02 14:14:41 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/01/02 14:14:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2010/12/29 20:51:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/12/29 20:46:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tim Oakley\Local Settings\Application Data\Temp
[2010/12/29 20:46:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/12/29 18:25:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tim Oakley\Desktop\tdsskiller
[2010/12/29 17:09:39 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/12/29 16:23:07 | 000,061,440 | ---- | C] ( ) -- C:\Documents and Settings\Tim Oakley\Desktop\VEW.exe
[2010/12/29 15:54:33 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/12/29 14:57:55 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/12/29 14:57:55 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/12/29 14:57:55 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/12/29 14:57:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/12/29 14:57:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/12/29 14:35:40 | 001,086,304 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Documents and Settings\Tim Oakley\Desktop\avg_remover_stf_x86_2011_1165.exe
[2010/12/29 10:41:49 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Tim Oakley\Desktop\mbam-setup-1.50.1.1100.exe
[2010/12/29 10:34:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tim Oakley\Desktop\New Folder (2)
[2010/12/29 10:13:52 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/12/29 10:04:01 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/12/28 16:44:35 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tim Oakley\Desktop\OTL.exe
[2004/09/08 09:47:52 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\RCCOLLAB.DLL

========== Files - Modified Within 30 Days ==========

[2011/01/07 20:56:00 | 000,000,894 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/07 20:55:05 | 002,205,157 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\IceSword122en.zip
[2011/01/07 20:12:54 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/07 20:12:24 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2011/01/07 20:12:23 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/07 20:12:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/07 20:12:19 | 1063,247,872 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/07 19:55:30 | 004,150,017 | R--- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\george3.exe
[2011/01/05 22:39:58 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/01/05 22:39:58 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/01/05 22:37:07 | 000,335,992 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\Dial-a-fix-v0.60.0.24.zip
[2011/01/05 22:34:57 | 000,430,080 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\UPHClean-Setup.msi
[2011/01/05 16:14:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/04 09:26:47 | 000,624,128 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\dds.scr
[2011/01/04 09:26:41 | 004,177,272 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\Tim Oakley\Desktop\procexp.exe
[2011/01/03 19:00:04 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/01/03 18:55:16 | 005,473,272 | ---- | M] (OPSWAT, Inc.) -- C:\Documents and Settings\Tim Oakley\Desktop\AppRemover.exe
[2011/01/02 23:26:55 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/01/02 23:26:50 | 000,444,832 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/01/02 23:26:50 | 000,072,582 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/01/02 14:14:58 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2011/01/02 12:32:53 | 059,325,912 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\avira_antivir_personal_en.exe
[2010/12/31 09:57:46 | 000,089,088 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\mbr.exe
[2010/12/30 17:21:55 | 000,001,566 | ---- | M] () -- C:\junk
[2010/12/30 13:54:39 | 051,515,288 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\setup_av_free.exe
[2010/12/30 03:16:24 | 000,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/29 21:29:05 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/12/29 20:52:48 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/12/29 20:52:48 | 000,001,791 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/29 20:51:41 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010/12/29 20:51:41 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2010/12/29 17:50:44 | 001,232,020 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\tdsskiller.zip
[2010/12/29 17:50:22 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\MBRCheck.exe
[2010/12/29 16:33:24 | 003,999,590 | R--- | M] () -- C:\Documents and Settings\Tim Oakley\Desktop\george2.exe
[2010/12/29 16:23:07 | 000,061,440 | ---- | M] ( ) -- C:\Documents and Settings\Tim Oakley\Desktop\VEW.exe
[2010/12/29 15:54:46 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2010/12/29 14:35:22 | 001,086,304 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Documents and Settings\Tim Oakley\Desktop\avg_remover_stf_x86_2011_1165.exe
[2010/12/29 10:40:54 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Tim Oakley\Desktop\mbam-setup-1.50.1.1100.exe
[2010/12/29 10:05:58 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010/12/28 16:44:22 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tim Oakley\Desktop\OTL.exe
[2010/12/13 08:40:21 | 000,135,096 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010/12/13 08:40:21 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys

========== Files Created - No Company Name ==========

[2011/01/05 22:37:06 | 000,335,992 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\Dial-a-fix-v0.60.0.24.zip
[2011/01/05 22:34:56 | 000,430,080 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\UPHClean-Setup.msi
[2011/01/05 19:12:30 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2011/01/05 19:12:27 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2011/01/05 19:03:05 | 000,033,280 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisrndr.ax
[2011/01/05 19:03:02 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisdecd.dll
[2011/01/05 18:49:03 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2011/01/05 18:47:43 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2011/01/05 18:46:45 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2011/01/05 18:45:16 | 000,165,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt53.dll
[2011/01/05 18:45:11 | 000,093,696 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt42.dll
[2011/01/05 18:45:07 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt34.dll
[2011/01/05 18:45:03 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt33.dll
[2011/01/05 18:44:59 | 000,083,968 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt21.dll
[2011/01/05 18:44:48 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2011/01/05 18:42:32 | 000,029,768 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divasu.dll
[2011/01/05 18:42:31 | 000,037,962 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaprop.dll
[2011/01/05 18:42:30 | 000,006,216 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaci.dll
[2011/01/05 18:40:01 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys
[2011/01/05 18:40:01 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys
[2011/01/05 18:40:00 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys
[2011/01/05 18:40:00 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2011/01/05 18:39:59 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2011/01/05 18:39:59 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys
[2011/01/05 18:39:58 | 000,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys
[2011/01/05 18:39:58 | 000,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2011/01/05 18:39:56 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2011/01/05 18:39:52 | 000,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys
[2011/01/04 09:26:44 | 000,624,128 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\dds.scr
[2011/01/02 14:14:58 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2011/01/02 12:32:53 | 059,325,912 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\avira_antivir_personal_en.exe
[2010/12/31 09:57:45 | 000,089,088 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\mbr.exe
[2010/12/30 18:28:07 | 000,007,570 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\reset.log
[2010/12/30 17:21:54 | 000,001,566 | ---- | C] () -- C:\junk
[2010/12/30 16:55:37 | 000,002,801 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\junk.txt
[2010/12/30 13:09:46 | 004,150,017 | R--- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\george3.exe
[2010/12/29 20:52:48 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/12/29 20:52:48 | 000,001,791 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/29 20:51:41 | 000,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2010/12/29 20:51:41 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2010/12/29 20:46:38 | 000,000,894 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/29 20:46:38 | 000,000,890 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/29 17:50:36 | 001,232,020 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\tdsskiller.zip
[2010/12/29 17:50:22 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\MBRCheck.exe
[2010/12/29 17:01:01 | 051,515,288 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\setup_av_free.exe
[2010/12/29 16:33:24 | 003,999,590 | R--- | C] () -- C:\Documents and Settings\Tim Oakley\Desktop\george2.exe
[2010/12/29 15:54:45 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/12/29 15:54:37 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2010/12/29 14:57:55 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/12/29 14:57:55 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/12/29 14:57:55 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/12/29 14:57:55 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/12/29 14:57:55 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/12/29 14:39:00 | 1063,247,872 | -HS- | C] () -- C:\hiberfil.sys
[2009/08/26 19:09:55 | 000,000,095 | ---- | C] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2008/10/12 17:42:52 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmsbfn32.dll
[2008/10/12 17:41:41 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2007/06/09 16:31:25 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Application Data\$_hpcst$.hpc
[2007/03/26 15:53:37 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/10 20:57:23 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/03/03 18:20:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2007/02/07 21:25:54 | 000,208,384 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/07 19:04:30 | 000,000,848 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/02/07 18:19:58 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Tim Oakley\Local Settings\Application Data\fusioncache.dat
[2007/02/06 17:56:13 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2007/02/06 17:53:32 | 000,001,334 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/01/29 22:03:40 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/01/29 06:33:45 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/01/29 06:21:41 | 000,042,240 | ---- | C] () -- C:\WINDOWS\System32\drivers\DCDisk.sys
[2007/01/29 06:21:40 | 000,014,074 | ---- | C] () -- C:\WINDOWS\System32\drivers\exdisk.sys
[2007/01/29 06:21:38 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\RitShell.dll
[2007/01/29 06:21:37 | 000,008,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\FBAPI.sys
[2007/01/29 06:21:31 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\phnxPsa.ini
[2007/01/29 06:21:25 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\PhxVtUsr.dll
[2007/01/29 06:21:25 | 000,002,304 | ---- | C] () -- C:\WINDOWS\System32\Machnm32.sys
[2007/01/29 06:21:25 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\phnxVaul.ini
[2007/01/29 05:54:04 | 000,000,503 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/12/12 09:24:42 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/09/28 06:22:25 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/10/14 03:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 03:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 03:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005/10/14 03:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005/10/14 03:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005/10/14 03:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005/10/14 03:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/07/31 15:08:44 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\lttls13n.dll
[2002/07/31 15:08:30 | 000,708,608 | ---- | C] () -- C:\WINDOWS\System32\ltcry13n.dll
[2002/07/31 15:08:14 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\lfkodak.dll
[2002/07/31 15:08:10 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll

========== LOP Check ==========

[2009/08/26 19:09:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2007/04/21 06:50:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fellowes
[2007/07/16 21:09:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\River Past G5
[2008/10/12 17:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/08/31 17:49:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2010/11/28 12:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/11/29 20:10:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YNAB
[2007/10/16 20:55:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\Alien Skin
[2010/02/27 12:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\AnvSoft
[2007/03/10 04:39:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\BitTorrent
[2008/10/12 18:36:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\Canon
[2007/12/29 19:29:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\Fisher-Price
[2010/08/26 19:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\ICQ
[2007/02/11 09:16:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\ICQLite
[2007/12/12 22:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\ieSpell
[2008/05/09 15:14:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\Opera
[2007/01/29 06:21:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\Recover Pro
[2007/07/16 21:01:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\River Past G5
[2008/10/12 17:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\ScanSoft
[2007/06/02 04:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim Oakley\Application Data\Snapfish
[2011/01/07 20:12:24 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 155 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB1B13D8

< End of report >
  • 0

#93
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
Message Hooks

C:\program files\antivir desktop\avgnt.exe
c:\program files\windowslive\messenger\msnmsgr.exe
c:\windows\explorer.exe
c:\windows\system32\ctfmon.exe
c:\program files\HP\digital imaging\bin\hpqimzone.exe
C:\program files\HP\digital Imaging\bin\hpqtra08.exe
C:\program files\microsoft activesync\wcescomm.exe
C:\program files\linksys Easylink Advisor\Linksysagent.exe





SSDT

Unknown (i wrote down the whole line of data if anything else would help out)
Unknown (i wrote down the whole line of data if anything else would help out)
Unknown (i wrote down the whole line of data if anything else would help out)
\??\c:\windows\system32\drivers\uphcleanhlp.sys

STARTUP

Nothing was red



WIN32

Nothing was red




PROCESSES

Nothing was red

Edited by Big O, 07 January 2011 - 10:48 PM.

  • 0

#94
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
Process:

System Idle Process
System
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\PhxVtSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\PhxPsSvr.exe
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Documents and Settings\Tim Oakley\Desktop\IceSword122en\IceSword122en\IceSword.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\alg.exe
  • 0

#95
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
Started Service:

Service Name:ALG Display Name:Application Layer Gateway Service
Service Name:AntiVirSchedulerService Display Name:Avira AntiVir Scheduler
Service Name:AntiVirService Display Name:Avira AntiVir Guard
Service Name:Apple Mobile Device Display Name:Apple Mobile Device
Service Name:AudioSrv Display Name:Windows Audio
Service Name:BITS Display Name:Background Intelligent Transfer Service
Service Name:Browser Display Name:Computer Browser
Service Name:COMSysApp Display Name:COM+ System Application
Service Name:CryptSvc Display Name:CryptSvc
Service Name:DcomLaunch Display Name:DCOM Server Process Launcher
Service Name:Dhcp Display Name:DHCP Client
Service Name:dmserver Display Name:Logical Disk Manager
Service Name:Dnscache Display Name:DNS Client
Service Name:ERSvc Display Name:Error Reporting Service
Service Name:Eventlog Display Name:Event Log
Service Name:EventSystem Display Name:COM+ Event System
Service Name:FastUserSwitchingCompatibility Display Name:Fast User Switching Compatibility
Service Name:helpsvc Display Name:Help and Support
Service Name:HidServ Display Name:HID Input Service
Service Name:HTTPFilter Display Name:HTTP SSL
Service Name:lanmanserver Display Name:Server
Service Name:lanmanworkstation Display Name:Workstation
Service Name:LmHosts Display Name:TCP/IP NetBIOS Helper
Service Name:MDM Display Name:Machine Debug Manager
Service Name:MSDTC Display Name:Distributed Transaction Coordinator
Service Name:Netman Display Name:Network Connections
Service Name:Nla Display Name:Network Location Awareness (NLA)
Service Name:PhnxPsaService Display Name:Phoenix PSA Service
Service Name:PhnxVaultService Display Name:Phoenix Vault Service
Service Name:PlugPlay Display Name:Plug and Play
Service Name:Pml Driver HPZ12 Display Name:Pml Driver HPZ12
Service Name:PolicyAgent Display Name:IPSEC Services
Service Name:ProtectedStorage Display Name:Protected Storage
Service Name:QBCFMonitorService Display Name:QBCFMonitorService
Service Name:RasMan Display Name:Remote Access Connection Manager
Service Name:RemoteRegistry Display Name:Remote Registry
Service Name:RpcSs Display Name:Remote Procedure Call (RPC)
Service Name:SamSs Display Name:Security Accounts Manager
Service Name:Schedule Display Name:Task Scheduler
Service Name:seclogon Display Name:Secondary Logon
Service Name:SENS Display Name:System Event Notification
Service Name:SharedAccess Display Name:Windows Firewall/Internet Connection Sharing (ICS)
Service Name:ShellHWDetection Display Name:Shell Hardware Detection
Service Name:Spooler Display Name:Print Spooler
Service Name:srservice Display Name:System Restore Service
Service Name:SSDPSRV Display Name:SSDP Discovery Service
Service Name:stisvc Display Name:Windows Image Acquisition (WIA)
Service Name:TapiSrv Display Name:Telephony
Service Name:TermService Display Name:Terminal Services
Service Name:Themes Display Name:Themes
Service Name:TrkWks Display Name:Distributed Link Tracking Client
Service Name:UPHClean Display Name:User Profile Hive Cleanup
Service Name:W32Time Display Name:Windows Time
Service Name:winmgmt Display Name:Windows Management Instrumentation
Service Name:wscsvc Display Name:Security Center
Service Name:wuauserv Display Name:Automatic Updates
Service Name:WZCSVC Display Name:Wireless Zero Configuration
  • 0

#96
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
Startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
avgnt
"C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
EasyLinkAdvisor
"C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Power2GoExpress
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
MSMSGS
"C:\Program Files\Messenger\msmsgs.exe" /background

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
H/PC Connection Agent
"C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
desktop.ini


C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Photosmart Premier Fast Start.lnk
C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Remark£º)

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
QuickBooks Update Agent.lnk
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Remark£ºQuickBooks Update Agent)

C:\Documents and Settings\Tim Oakley\Start Menu\Programs\Startup
desktop.ini
  • 0

#97
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
The file that Avira found was in your downloads folder so must have been downloaded in the past and the latest Avira update enabled it to catch it.

What exactly do you mean here:

"Unknown (i wrote down the whole line of data if anything else would help out)"

Copy the text in the code box below by highlighting and then Ctrl + c :



:OTL
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - File not found

:Commands
[PURITY]
[EMPTYTEMP]

 


Run OTL by right clicking and Run As Administrator then paste the above in the box where it says Custom Scans/Fixes. Verify that you got it all then hit RUN FIX.

Copy and past the log it creates into a Reply.


Are you using this Phoenix stuff?
Service Name:PhnxPsaService Display Name:Phoenix PSA Service
Service Name:PhnxVaultService Display Name:Phoenix Vault Service

Ron
  • 0

#98
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts

What exactly do you mean here:
"Unknown (i wrote down the whole line of data if anything else would help out)"


Step 4 : Click the SSDT tab and check for red colored entries. If there are any, write down the KModule name

the KModule name column for that item(s) just said unknown. I wrote down all the other column values incase you needed them.

-----------------------------------------

Avira found it in a file from 18 months ago!

-----------------------------------------

Never used the Phoenix stuff, must have been bundled with the system when I bought it.

-----------------------------------------


I've never logged in/on as Administrator before, it didn't like a blank password and I couldn't guess what it might be.

Edited by Big O, 07 January 2011 - 11:11 PM.

  • 0

#99
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter\ deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 825314 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 575588 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Tim Oakley
->Temp folder emptied: 2024961 bytes
->Temporary Internet Files folder emptied: 36817228 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 6299769 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 1830 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 505 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 44.00 mb


OTL by OldTimer - Version 3.2.18.0 log created on 01072011_221218

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\Tim Oakley\Local Settings\Temp\~DF454F.tmp not found!
File\Folder C:\Documents and Settings\Tim Oakley\Local Settings\Temp\~DF4569.tmp not found!
File\Folder C:\Documents and Settings\Tim Oakley\Local Settings\Temp\~DF45DD.tmp not found!
File\Folder C:\Documents and Settings\Tim Oakley\Local Settings\Temp\~DF45F7.tmp not found!
File\Folder C:\Documents and Settings\Tim Oakley\Local Settings\Temp\~DF463B.tmp not found!
File\Folder C:\Documents and Settings\Tim Oakley\Local Settings\Temp\~DF4655.tmp not found!
C:\Documents and Settings\Tim Oakley\Local Settings\Temporary Internet Files\Content.IE5\V91TQYP2\like[1].htm moved successfully.
C:\Documents and Settings\Tim Oakley\Local Settings\Temporary Internet Files\Content.IE5\V91TQYP2\xd_proxy[1].htm moved successfully.
C:\Documents and Settings\Tim Oakley\Local Settings\Temporary Internet Files\Content.IE5\1ZICO1T9\page__st__90__gopid__1952350[1].htm moved successfully.

Registry entries deleted on Reboot...
  • 0

#100
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Oops. Gave you the Vista version. You don't need to Run As Administrator for XP.

Did you buy the machine used? Since you do have admin right you should be able to go into Control Panel, User Accounts and change the password on Administrator.

If you don't use it then uninstall Phoenix Recover Pro 6 and run mbrcheck again. My mbr guru tells me that it makes changes to the mbr.

Ron
  • 0

Advertisements


#101
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Your PM sounds like someone may have a backdoor on your PC.

Start, Run, cmd, OK and type:

netstat -an > \junk.txt

This may let me see if a program is listening when it shouldn't be.

For more protection: Download, Save and Install Online Armor (free version)
http://www.online-ar...-armor-free.php

This is a two way firewall so you will have to grant permission to programs before they are allowed to go out to the internet. It's pretty easy to use tho.

IceSword doesn't work on Vista so I can't play with it but run it again and go back to the unknown line and right click and see if there is an option to delete or stop it.

Ron
  • 0

#102
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
Active Connections

Proto Local Address Foreign Address State
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:990 0.0.0.0:0 LISTENING
TCP 0.0.0.0:2869 0.0.0.0:0 LISTENING
TCP 0.0.0.0:8019 0.0.0.0:0 LISTENING
TCP 127.0.0.1:1032 0.0.0.0:0 LISTENING
TCP 127.0.0.1:5679 0.0.0.0:0 LISTENING
TCP 127.0.0.1:7438 0.0.0.0:0 LISTENING
TCP 127.0.0.1:27015 0.0.0.0:0 LISTENING
TCP 192.168.33.101:139 0.0.0.0:0 LISTENING
TCP 192.168.33.101:1212 208.43.44.138:80 TIME_WAIT
TCP 192.168.33.101:1214 208.43.44.138:80 TIME_WAIT
TCP 192.168.33.101:2869 192.168.33.1:1127 TIME_WAIT
TCP 192.168.33.101:2869 192.168.33.1:1128 TIME_WAIT
UDP 0.0.0.0:445 *:*
UDP 0.0.0.0:500 *:*
UDP 0.0.0.0:4500 *:*
UDP 127.0.0.1:123 *:*
UDP 127.0.0.1:1146 *:*
UDP 127.0.0.1:1250 *:*
UDP 127.0.0.1:1252 *:*
UDP 127.0.0.1:1900 *:*
UDP 192.168.33.101:123 *:*
UDP 192.168.33.101:137 *:*
UDP 192.168.33.101:138 *:*
UDP 192.168.33.101:1900 *:*
  • 0

#103
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
2am Avira found something. A0175844.exe (TR/Dropper.Gen) and moved it to quarantine
  • 0

#104
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
When I right click on the red line (SSDT) it only gives me the options to refresh or restore.
  • 0

#105
Big O

Big O

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x000001fc

Kernel Drivers (total 187):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E4000 \WINDOWS\system32\hal.dll
0xF7A6E000 \WINDOWS\system32\KDCOM.DLL
0xF797E000 \WINDOWS\system32\BOOTVID.dll
0xF743F000 ACPI.sys
0xF7A70000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF742E000 pci.sys
0xF756E000 isapnp.sys
0xF7B36000 pciide.sys
0xF77EE000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF7A72000 aliide.sys
0xF7A74000 cmdide.sys
0xF7A76000 toside.sys
0xF7A78000 viaide.sys
0xF7A7A000 intelide.sys
0xF757E000 MountMgr.sys
0xF740F000 ftdisk.sys
0xF7A7C000 dmload.sys
0xF73E9000 dmio.sys
0xF77F6000 PartMgr.sys
0xF758E000 VolSnap.sys
0xF7982000 cpqarray.sys
0xF73D1000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF731A000 iaStor.sys
0xF7302000 atapi.sys
0xF7986000 aha154x.sys
0xF77FE000 sparrow.sys
0xF798A000 symc810.sys
0xF759E000 aic78xx.sys
0xF798E000 dac960nt.sys
0xF75AE000 ql10wnt.sys
0xF7992000 amsint.sys
0xF7806000 asc.sys
0xF7996000 asc3550.sys
0xF780E000 mraid35x.sys
0xF7816000 i2omp.sys
0xF799A000 ini910u.sys
0xF75BE000 ql1240.sys
0xF75CE000 aic78u2.sys
0xF781E000 symc8xx.sys
0xF7826000 sym_hi.sys
0xF782E000 sym_u3.sys
0xF7836000 ABP480N5.SYS
0xF783E000 asc3350p.sys
0xF7A7E000 cd20xrnt.sys
0xF75DE000 ultra.sys
0xF72E9000 adpu160m.sys
0xF7846000 dpti2o.sys
0xF75EE000 ql1080.sys
0xF75FE000 ql1280.sys
0xF760E000 ql12160.sys
0xF784E000 perc2.sys
0xF7A80000 perc2hib.sys
0xF7856000 hpn.sys
0xF799E000 cbidf2k.sys
0xF72BD000 dac2w2k.sys
0xF72A6000 viamraid.sys
0xF761E000 disk.sys
0xF762E000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7286000 fltmgr.sys
0xF7274000 sr.sys
0xF763E000 PxHelp20.sys
0xF725D000 KSecDD.sys
0xF71D0000 Ntfs.sys
0xF71A3000 NDIS.sys
0xF764E000 uagp35.sys
0xF765E000 sisagp.sys
0xF766E000 viaagp.sys
0xF767E000 ohci1394.sys
0xF768E000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xF7189000 Mup.sys
0xF769E000 alim1541.sys
0xF76AE000 amdagp.sys
0xF76BE000 agp440.sys
0xF76CE000 agpCPQ.sys
0xF76FE000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xF6139000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF5F63000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
0xF5F4F000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF5F27000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF5EF6000 \SystemRoot\system32\DRIVERS\e1e5132.sys
0xF795E000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF5ED2000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF7966000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF5E64000 \SystemRoot\system32\DRIVERS\A3AB.sys
0xF5E2E000 \SystemRoot\system32\DRIVERS\HSFHWBS2.sys
0xF5E0B000 \SystemRoot\system32\DRIVERS\ks.sys
0xF5D0D000 \SystemRoot\system32\DRIVERS\HSF_DP.sys
0xF5C61000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
0xF796E000 \SystemRoot\System32\Drivers\Modem.SYS
0xF5C4D000 \SystemRoot\system32\DRIVERS\parport.sys
0xF6129000 \SystemRoot\system32\DRIVERS\serial.sys
0xF708C000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF6119000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF6109000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF60F9000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF7088000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xF7B70000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF60E9000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF7080000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF5C36000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF60D9000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF60C9000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7976000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF5C25000 \SystemRoot\system32\DRIVERS\psched.sys
0xF60B9000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7866000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF788E000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF5BF5000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF77CE000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7896000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF789E000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7AE2000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF5B97000 \SystemRoot\system32\DRIVERS\update.sys
0xF7A26000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF7179000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xAA63D000 \SystemRoot\system32\drivers\sthda.sys
0xAA619000 \SystemRoot\system32\drivers\portcls.sys
0xF7169000 \SystemRoot\system32\drivers\drmk.sys
0xF7159000 \SystemRoot\system32\drivers\sfng32.sys
0xF7149000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7AE6000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF7A4A000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xF7A3A000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xF78B6000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xF7A3E000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF7119000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xF78BE000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF78CE000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xF7AE8000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7BE9000 \SystemRoot\System32\Drivers\Null.SYS
0xF7AEA000 \SystemRoot\System32\Drivers\Beep.SYS
0xF78DE000 \SystemRoot\System32\drivers\vga.sys
0xF7AEC000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7AEE000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF78E6000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF78EE000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF7A4E000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xAA53B000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xAA4E2000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xAA4BA000 \SystemRoot\system32\DRIVERS\netbt.sys
0xAA494000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xAA472000 \SystemRoot\System32\drivers\afd.sys
0xF70F9000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF70E9000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF76EE000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xF78F6000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0xF78FE000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0xAA447000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xAA3AF000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF770E000 \SystemRoot\System32\Drivers\Fips.SYS
0xF771E000 \SystemRoot\System32\Drivers\DCDisk.SYS
0xAA339000 \SystemRoot\system32\DRIVERS\avipbb.sys
0xF7AF2000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0xAA43B000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xAA433000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xF7906000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xF790E000 \SystemRoot\system32\DRIVERS\HPZius12.sys
0xF6A9A000 \SystemRoot\system32\DRIVERS\HPZid412.sys
0xAA42F000 \SystemRoot\system32\DRIVERS\HPZipr12.sys
0xF6A8A000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xAA2F9000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7AF6000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xAA3AB000 \SystemRoot\System32\drivers\Dxapi.sys
0xF7926000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7C9F000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF021000 \SystemRoot\System32\ialmdnt5.dll
0xBF012000 \SystemRoot\System32\ialmrnt5.dll
0xBF043000 \SystemRoot\System32\ialmdev5.DLL
0xBF07C000 \SystemRoot\System32\ialmdd5.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xAA154000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0xF793E000 \SystemRoot\system32\DRIVERS\elagopro.sys
0xAA1E1000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA9E1F000 \SystemRoot\system32\drivers\wdmaud.sys
0xA9FAC000 \SystemRoot\system32\drivers\sysaudio.sys
0xA9DA4000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF7AA4000 \SystemRoot\system32\DRIVERS\elaunidr.sys
0xF7C1D000 \??\C:\WINDOWS\system32\Machnm32.sys
0xA9872000 \SystemRoot\system32\DRIVERS\srv.sys
0xA99CA000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xA9776000 \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys
0xA93A9000 \SystemRoot\System32\Drivers\HTTP.sys
0xAA5CE000 \??\C:\DOCUME~1\TIMOAK~1\LOCALS~1\Temp\mbr.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 41):
0 System Idle Process
4 System
812 C:\WINDOWS\system32\smss.exe
864 csrss.exe
888 C:\WINDOWS\system32\winlogon.exe
932 C:\WINDOWS\system32\services.exe
944 C:\WINDOWS\system32\lsass.exe
1132 C:\WINDOWS\system32\svchost.exe
1180 svchost.exe
1220 C:\WINDOWS\system32\svchost.exe
1332 svchost.exe
1412 svchost.exe
1568 C:\WINDOWS\system32\spoolsv.exe
1680 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1900 svchost.exe
2004 C:\WINDOWS\explorer.exe
288 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
300 C:\WINDOWS\system32\ctfmon.exe
312 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
320 C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
400 C:\Program Files\Messenger\msmsgs.exe
412 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
472 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
500 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
548 C:\PROGRA~1\MICROS~4\rapimgr.exe
1076 C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
1916 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
1992 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
256 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
1984 C:\WINDOWS\system32\HPZipm12.exe
368 C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
1316 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
1500 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
1880 C:\WINDOWS\system32\svchost.exe
2076 C:\Program Files\UPHClean\uphclean.exe
2200 C:\WINDOWS\system32\wuauclt.exe
2720 wmiprvse.exe
3396 alg.exe
2344 C:\WINDOWS\system32\svchost.exe
3188 C:\WINDOWS\system32\wuauclt.exe
3472 C:\Documents and Settings\Tim Oakley\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: WDCWD2500JS-00NCB1, Rev: 10.02E02

Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Windows 98 MBR code detected
SHA1: 48F01D7E76A0F3C038D08611E3FDC0EE4EF9FD3E


Done!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP