All processes killed
========== OTL ==========
Prefs.js: {3A79CE83-F651-4E6B-866F-1C08B657CF13}:1.9.1 removed from extensions.enabledItems
File HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3A79CE83-F651-4E6B-866F-1C08B657CF13}: C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\{3A79CE83-F651-4E6B-866F-1C08B657CF13} not found.
C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\searchplugin folder moved successfully.
C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\META-INF folder moved successfully.
C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\lib folder moved successfully.
C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\defaults folder moved successfully.
C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components folder moved successfully.
C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\chrome folder moved successfully.
C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd} folder moved successfully.
C:\DOCUMENTS AND SETTINGS\KEITH LAWRENCE\LOCAL SETTINGS\APPLICATION DATA\{3A79CE83-F651-4E6B-866F-1C08B657CF13}\chrome\content folder moved successfully.
C:\DOCUMENTS AND SETTINGS\KEITH LAWRENCE\LOCAL SETTINGS\APPLICATION DATA\{3A79CE83-F651-4E6B-866F-1C08B657CF13}\chrome folder moved successfully.
C:\DOCUMENTS AND SETTINGS\KEITH LAWRENCE\LOCAL SETTINGS\APPLICATION DATA\{3A79CE83-F651-4E6B-866F-1C08B657CF13} folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}\ deleted successfully.
C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\ deleted successfully.
C:\Program Files\ZoneAlarm\tbZone.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}\ deleted successfully.
File C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}\ not found.
File C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}\ not found.
File C:\Program Files\ZoneAlarm\tbZone.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}\ not found.
File C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDesktop deleted successfully.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
C:\Documents and Settings\All Users\Application Data\VDPLtsHLVdsd.exe moved successfully.
C:\Documents and Settings\All Users\Application Data\wWrdTMJysnURH.exe moved successfully.
C:\Program Files\avg_free_stb_all_9_40_cnet.exe moved successfully.
C:\Program Files\mbam-setup.exe moved successfully.
C:\Program Files\spywareblastersetup42.exe moved successfully.
File move failed. C:\Program Files\sdsetup_aff.exe scheduled to be moved on reboot.
C:\Program Files\boost-speed-setup.exe moved successfully.
C:\Program Files\spywareblastersetup41.exe moved successfully.
File move failed. C:\Program Files\avg_free_stf_en_8_176a1399.exe scheduled to be moved on reboot.
C:\Documents and Settings\Keith Lawrence\My Documents\~WRL1943.tmp deleted successfully.
C:\Documents and Settings\Keith Lawrence\My Documents\~WRL2832.tmp deleted successfully.
C:\Documents and Settings\Keith Lawrence\My Documents\~WRL3148.tmp deleted successfully.
C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\031g7vv05gcak80b moved successfully.
C:\Documents and Settings\All Users\Application Data\031g7vv05gcak80b moved successfully.
C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\rpa.exe moved successfully.
File C:\Documents and Settings\All Users\Application Data\VDPLtsHLVdsd.exe not found.
File C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\031g7vv05gcak80b not found.
File C:\Documents and Settings\All Users\Application Data\031g7vv05gcak80b not found.
File C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\rpa.exe not found.
C:\WINDOWS\Iwakuvifukifuriz.dat moved successfully.
C:\WINDOWS\Mxevuyozewahatew.bin moved successfully.
C:\Program Files\SDFix.exe moved successfully.
C:\Program Files\tdsskiller.zip moved successfully.
C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\3b4272touB moved successfully.
C:\Program Files\activescan2_en.exe moved successfully.
C:\WINDOWS\is-JO5E9.exe moved successfully.
C:\Program Files\Download_SD6.0.0.362h-sdregnow-sdsetup.exe moved successfully.
C:\Program Files\dwpfix.reg moved successfully.
C:\Program Files\zaSetup_en.exe moved successfully.
C:\WINDOWS\jautoexp.dat moved successfully.
C:\WINDOWS\system32\drivers\YWvinNfI.dll moved successfully.
C:\WINDOWS\system32\drivers\tVvuFKIG.exe moved successfully.
C:\WINDOWS\system32\RSpvYQc.exe moved successfully.
C:\WINDOWS\Rfvcua.exe moved successfully.
C:\WINDOWS\system32\drivers\qGdqKN.dll moved successfully.
C:\WINDOWS\system32\NOCmjH.exe moved successfully.
C:\WINDOWS\system32\drivers\NMvhKd.exe moved successfully.
C:\WINDOWS\LyrgHddPL.exe moved successfully.
C:\WINDOWS\system32\drivers\kltHFd.dll moved successfully.
C:\WINDOWS\system32\drivers\JbkgnWbQ.exe moved successfully.
C:\WINDOWS\system32\drivers\ivtNLBYuD.exe moved successfully.
C:\WINDOWS\system32\drivers\iagtj.dll moved successfully.
C:\WINDOWS\system32\drivers\hxaHeFXJ.dll moved successfully.
C:\WINDOWS\gNYYVAgre.exe moved successfully.
C:\WINDOWS\system32\drivers\FjjGa.dll moved successfully.
C:\WINDOWS\system32\drivers\cBgYH.exe moved successfully.
C:\WINDOWS\system32\drivers\xDxALdsy.exe moved successfully.
C:\WINDOWS\tmcAbD.exe moved successfully.
C:\WINDOWS\system32\drivers\TkyEJgbc.dll moved successfully.
C:\WINDOWS\system32\tgatK.exe moved successfully.
C:\WINDOWS\system32\drivers\stvySWgP.dll moved successfully.
C:\WINDOWS\system32\ssTLEtQhy.exe moved successfully.
C:\WINDOWS\rLfAmtM.exe moved successfully.
C:\WINDOWS\system32\drivers\rJrVlvqt.exe moved successfully.
C:\WINDOWS\system32\REfgNhvH.exe moved successfully.
C:\WINDOWS\oTWWn.exe moved successfully.
C:\WINDOWS\system32\NElodklu.exe moved successfully.
C:\WINDOWS\system32\loXUYfRi.exe moved successfully.
C:\WINDOWS\system32\drivers\lmACB.dll moved successfully.
C:\WINDOWS\system32\kRWuT.exe moved successfully.
C:\WINDOWS\system32\drivers\jvaDjuW.dll moved successfully.
C:\WINDOWS\system32\JIKfetu.exe moved successfully.
C:\WINDOWS\iBkburqy.exe moved successfully.
C:\WINDOWS\system32\fojPnE.exe moved successfully.
C:\WINDOWS\dEAyAPKev.exe moved successfully.
C:\WINDOWS\dcVhPoW.exe moved successfully.
C:\WINDOWS\BOkcLUhq.exe moved successfully.
C:\Documents and Settings\All Users\Application Data\d4894a\Quarantine Items folder moved successfully.
C:\Documents and Settings\All Users\Application Data\d4894a\PSGSys folder moved successfully.
C:\Documents and Settings\All Users\Application Data\d4894a folder moved successfully.
C:\Documents and Settings\All Users\Application Data\PSZMRG folder moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
HOSTS file reset successfully
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Denise Lawrence
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Keith Lawrence
->Temp folder emptied: 1064322 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Mike
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Mike Lawrence
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Owner
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Sean
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Sean Lawrence
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Default User
User: Denise Lawrence
User: Keith Lawrence
->Flash cache emptied: 0 bytes
User: LocalService
User: Mike
->Flash cache emptied: 0 bytes
User: Mike Lawrence
User: NetworkService
User: Owner
User: Sean
->Flash cache emptied: 0 bytes
User: Sean Lawrence
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.26.1 log created on 07192011_222748
Files\Folders moved on Reboot...
File move failed. C:\Program Files\sdsetup_aff.exe scheduled to be moved on reboot.
File move failed. C:\Program Files\avg_free_stf_en_8_176a1399.exe scheduled to be moved on reboot.
Registry entries deleted on Reboot...
OTL logfile created on: 7/19/2011 10:39:55 PM - Run 4
OTL by OldTimer - Version 3.2.26.1 Folder = F:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.01 Mb Total Physical Memory | 652.91 Mb Available Physical Memory | 63.82% Memory free
1.39 Gb Paging File | 1.14 Gb Available in Paging File | 81.44% Paging File free
Paging file location(s): C:\pagefile.sys 500 1000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 128.00 Gb Total Space | 73.74 Gb Free Space | 57.61% Space Free | Partition Type: NTFS
Drive F: | 60.73 Mb Total Space | 12.90 Mb Free Space | 21.25% Space Free | Partition Type: FAT
Computer Name: KEITH-M9FXN5D74 | User Name: Keith Lawrence | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/07/10 08:14:48 | 000,579,584 | ---- | M] (OldTimer Tools) -- F:\OTL.exe
PRC - [2010/08/24 05:38:18 | 000,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2010/08/24 05:38:16 | 000,247,144 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2010/08/23 21:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2010/06/23 13:52:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2010/06/23 13:51:30 | 001,043,968 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2010/05/26 09:35:14 | 000,730,600 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
PRC - [2009/03/16 14:54:50 | 000,362,096 | ---- | M] (Auslogics) -- C:\Program Files\Auslogics\Auslogics BoostSpeed\BoostSpeed.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/31 15:55:42 | 000,098,304 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2005/03/09 21:50:18 | 000,020,992 | ---- | M] (
http://libusb-win32.sourceforge.net) -- C:\WINDOWS\system32\libusbd-nt.exe
PRC - [2003/08/29 20:05:35 | 000,360,448 | ---- | M] () -- C:\Program Files\SpywareGuard\sgmain.exe
PRC - [2003/08/29 12:14:56 | 000,233,472 | ---- | M] () -- C:\Program Files\SpywareGuard\sgbhp.exe
PRC - [2003/06/18 09:54:10 | 000,296,960 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\system32\drivers\KodakCCS.exe
========== Modules (SafeList) ========== MOD - [2011/07/10 08:14:48 | 000,579,584 | ---- | M] (OldTimer Tools) -- F:\OTL.exe
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (COMServer)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2010/09/01 15:52:56 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.) [Disabled | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus®
SRV - [2010/08/24 05:38:18 | 000,092,008 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010/08/23 21:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2010/06/23 13:52:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) [Auto | Start_Pending] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2010/05/26 09:35:18 | 000,493,032 | ---- | M] () [Auto | Stopped] -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe -- (IswSvc)
SRV - [2007/01/31 15:55:42 | 000,098,304 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2005/03/09 21:50:18 | 000,020,992 | ---- | M] (
http://libusb-win32.sourceforge.net) [Auto | Running] -- C:\WINDOWS\system32\libusbd-nt.exe -- (libusbd)
SRV - [2003/06/18 09:54:10 | 000,296,960 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\WINDOWS\system32\drivers\KodakCCS.exe -- (KodakCCS)
========== Driver Services (SafeList) ========== DRV - [2011/07/02 00:02:51 | 000,295,168 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtaa.sys -- (ati2mtaa)
DRV - [2010/05/26 09:35:10 | 000,026,352 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2010/05/13 10:02:32 | 000,532,224 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2009/06/30 10:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot)
DRV - [2008/09/29 18:47:18 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2008/05/05 22:30:40 | 000,104,704 | R--- | M] (Dynex ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2008/04/13 14:56:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2006/08/24 19:53:09 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2005/03/09 15:50:20 | 000,033,792 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\libusb0.sys -- (libusb0)
DRV - [2004/08/04 00:31:32 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/06/09 19:42:38 | 000,015,429 | R--- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Sacm2A.sys -- (USBCM)
DRV - [2003/06/18 09:53:08 | 000,138,485 | ---- | M] (Eastman Kodak Company) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ExportIt.sys -- (Exportit)
DRV - [2003/06/18 09:53:08 | 000,063,002 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DcPtp.sys -- (DcPTP)
DRV - [2003/06/18 09:53:08 | 000,061,568 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DcFpoint.sys -- (DcFpoint)
DRV - [2003/06/18 09:53:08 | 000,038,997 | ---- | M] (Eastman Kodak Company) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\DCFS2k.sys -- (DCFS2K)
DRV - [2003/06/18 09:53:08 | 000,036,826 | ---- | M] (Eastman Kodak Company) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\DcCam.sys -- (DcCam)
DRV - [2003/06/18 09:53:08 | 000,008,058 | ---- | M] (Eastman Kodak Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DcLps.sys -- (DcLps)
DRV - [2001/08/17 09:28:02 | 000,907,456 | ---- | M] (Conexant) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys -- (HCF_MSFT)
DRV - [2001/08/17 08:48:52 | 000,281,856 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mpaa.sys -- (ati2mpaa)
DRV - [2001/08/09 16:25:22 | 000,022,608 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wandrv.sys -- (wandrv)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.aol.com/IE - HKCU\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "
http://www.aol.com/"FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.227.0
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.91
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..network.proxy.ftp: ":0"
FF - prefs.js..network.proxy.gopher: ":0"
FF - prefs.js..network.proxy.http: ":0"
FF - prefs.js..network.proxy.no_proxies_on: "localhost"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: ":0"
FF - prefs.js..network.proxy.ssl: ":0"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=7: C:\Program Files\Google\Google Updater\1.4.681.27779\npCIDetect7.dll (Google)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3A79CE83-F651-4E6B-866F-1C08B657CF13}: C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\{3A79CE83-F651-4E6B-866F-1C08B657CF13}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/07 09:30:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/29 14:47:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/29 14:47:52 | 000,000,000 | ---D | M]
[2009/01/10 10:30:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Extensions
[2008/05/01 19:37:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Extensions\
[email protected][2011/07/10 12:22:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions
[2010/05/25 09:34:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/15 13:03:30 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus®)) -- C:\Documents and Settings\Keith Lawrence\Application Data\Mozilla\Firefox\Profiles\i5aydvc4.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/07/10 12:22:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/16 23:42:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\KEITH LAWRENCE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\I5AYDVC4.DEFAULT\EXTENSIONS\{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\KEITH LAWRENCE\LOCAL SETTINGS\APPLICATION DATA\{3A79CE83-F651-4E6B-866F-1C08B657CF13}
[2011/02/07 09:30:07 | 000,000,000 | ---D | M] (ZoneAlarm Security Engine) -- C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2010/09/16 23:41:41 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/09/16 23:41:41 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/12/25 22:24:10 | 000,024,673 | ---- | M] (Check Point Software Technologies Ltd.) -- C:\Program Files\mozilla firefox\plugins\NPZoneSB.dll
O1 HOSTS File: ([2011/07/19 22:29:35 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - File not found
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - File not found
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe ()
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Auslogics BoostSpeed 4] C:\Program Files\Auslogics\Auslogics BoostSpeed\BoostSpeed.exe (Auslogics)
O4 - HKCU..\Run: [Microsoft Works Update Detection] File not found
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Documents and Settings\Keith Lawrence\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B}
http://support.dell....iler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}
http://www.kaspersky...can_unicode.cab (CKAVWebScan Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71}
http://download.micr...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
http://download.mcaf...01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.micros...b?1162857106687 (MUWebControl Class)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C}
http://mediaplayer.w...ler/install.cab (Reg Error: Key error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
http://acs.pandasoft...free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073}
http://support.f-sec.../ols3/fscax.cab (F-Secure Online Scanner 3.0)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
http://download.mcaf...,26/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277}
http://office.micros...ntent/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper:
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/06 19:25:31 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{581c3128-db29-11dc-9747-0016b521fd25}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/07/13 23:21:31 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/07/13 22:43:19 | 004,149,767 | R--- | C] (Swearware) -- C:\ComboFix.exe
[2011/07/02 00:28:05 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/07/02 00:28:05 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/07/02 00:28:05 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/07/02 00:28:05 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/07/02 00:27:55 | 000,000,000 | --SD | C] -- C:\ABCD
[2011/07/02 00:05:27 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011/07/01 19:20:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Keith Lawrence\Recent
[2010/03/07 20:49:52 | 034,868,752 | ---- | C] (PC Tools ) -- C:\Program Files\sdsetup_aff.exe
[2009/01/07 19:36:23 | 054,157,776 | ---- | C] (AVG Technologies) -- C:\Program Files\avg_free_stf_en_8_176a1399.exe
[2008/10/15 14:27:09 | 000,015,429 | R--- | C] ( ) -- C:\WINDOWS\System32\drivers\Sacm2A.sys
========== Files - Modified Within 30 Days ========== [2011/07/19 22:43:00 | 000,000,412 | ---- | M] () -- C:\WINDOWS\tasks\Symantec NetDetect.job
[2011/07/19 22:33:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/07/19 22:29:35 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/07/19 22:21:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/07/13 08:37:48 | 004,149,767 | R--- | M] (Swearware) -- C:\ComboFix.exe
[2011/07/02 14:51:58 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/02 00:02:51 | 000,295,168 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2011/06/29 10:38:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/26 15:37:58 | 000,000,441 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
========== Files Created - No Company Name ========== [2011/07/02 00:46:30 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/02 00:28:05 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/07/02 00:28:05 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/07/02 00:28:05 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/07/02 00:28:05 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/07/01 22:22:57 | 000,002,445 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Streets & Trips 2002.lnk
[2011/07/01 22:22:57 | 000,001,934 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Money 2002.lnk
[2011/07/01 22:22:57 | 000,001,853 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN Explorer.lnk
[2011/07/01 22:22:57 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/07/01 22:22:57 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 7.0.lnk
[2011/07/01 22:22:57 | 000,001,687 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Solution Center.lnk
[2011/07/01 22:22:57 | 000,001,549 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works.lnk
[2011/07/01 22:22:57 | 000,001,535 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Picture It! Photo 2002.lnk
[2011/07/01 22:22:57 | 000,000,888 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Acrobat Reader 5.0.lnk
[2011/07/01 22:22:57 | 000,000,453 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\DellTouch.lnk
[2011/07/01 20:35:59 | 000,000,847 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/03/01 13:42:44 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\d3d9caps.dat
[2010/11/25 12:01:34 | 000,045,540 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/04/03 13:26:59 | 000,073,728 | R--- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010/03/24 19:16:42 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\prvlcl.dat
[2009/05/08 20:40:57 | 000,063,730 | ---- | C] () -- C:\Program Files\viewsonicinstruct_xp.pdf
[2009/05/08 20:40:29 | 000,000,088 | ---- | C] () -- C:\WINDOWS\VSWizard.ini
[2009/02/12 19:07:55 | 000,000,197 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/10/15 14:27:10 | 000,053,693 | R--- | C] () -- C:\WINDOWS\UNDPX2A.sys
[2008/10/15 14:27:09 | 000,135,168 | R--- | C] () -- C:\WINDOWS\UNDPX2A.exe
[2008/03/31 20:47:30 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\keydb.dll
[2008/03/31 20:47:29 | 000,302,592 | ---- | C] () -- C:\WINDOWS\System32\pgp.dll
[2008/03/31 20:47:29 | 000,070,656 | ---- | C] () -- C:\WINDOWS\System32\simple.dll
[2008/03/31 20:47:29 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\bn.dll
[2007/12/30 17:01:29 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2007/03/22 19:53:18 | 000,001,783 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/24 19:59:49 | 000,033,792 | ---- | C] () -- C:\WINDOWS\System32\drivers\libusb0.sys
[2006/11/05 10:12:40 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll
[2006/11/04 10:03:46 | 000,001,168 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/11/01 10:59:47 | 000,796,584 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/11/01 10:37:32 | 000,004,212 | ---- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2006/11/01 10:30:59 | 000,021,312 | ---- | C] () -- C:\WINDOWS\choice.exe
[2006/11/01 01:15:38 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/10/31 08:37:14 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/10/24 18:34:53 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.Keith Lawrence.ini
[2006/04/06 21:39:51 | 000,000,006 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/04/06 19:28:02 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/04/06 19:22:31 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/04/06 15:15:13 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/04/06 15:14:13 | 000,225,616 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/10/29 09:52:37 | 000,000,001 | ---- | C] () -- C:\WINDOWS\twainx.bin
[2005/10/02 15:00:48 | 001,138,643 | ---- | C] () -- C:\Program Files\CVS Camcorder Quickinstall v2.13.exe
[2005/08/09 12:53:27 | 000,000,001 | ---- | C] () -- C:\WINDOWS\imsins_.bin
[2005/03/19 14:04:55 | 000,000,002 | ---- | C] () -- C:\WINDOWS\twain.bin
[2005/02/12 15:02:36 | 000,001,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\papyjoy.sys
[2005/02/12 15:02:35 | 000,001,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\papycpu.sys
[2004/12/20 10:08:28 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004/12/20 10:03:26 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004/01/24 09:37:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2004/01/24 09:25:54 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVS5c.DLL
[2003/12/25 10:01:04 | 000,000,838 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2003/12/02 19:45:55 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2003/09/06 08:09:28 | 000,000,026 | ---- | C] () -- C:\WINDOWS\UP9ASP.INI
[2003/03/22 20:10:15 | 000,001,004 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2003/02/10 21:29:32 | 000,202,752 | ---- | C] () -- C:\WINDOWS\CDAC14BA.DLL
[2003/02/10 21:29:32 | 000,020,992 | ---- | C] () -- C:\WINDOWS\CDAC13BA.EXE
[2003/02/10 21:29:30 | 000,011,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\CdaC15BA.SYS
[2003/02/10 21:29:12 | 000,001,754 | ---- | C] () -- C:\WINDOWS\PERWIN02.INI
[2003/02/04 08:22:30 | 000,181,312 | ---- | C] () -- C:\WINDOWS\System32\ScsiAccess.EXE
[2002/05/16 16:44:21 | 000,000,372 | ---- | C] () -- C:\WINDOWS\KA.INI
[2002/04/21 09:15:32 | 000,065,536 | ---- | C] () -- C:\Documents and Settings\Keith Lawrence\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2002/04/08 16:26:39 | 000,000,856 | ---- | C] () -- C:\WINDOWS\Disney.ini
[2002/04/08 16:25:33 | 000,000,510 | ---- | C] () -- C:\WINDOWS\EReg515.dat
[2002/03/20 18:40:00 | 000,000,920 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2002/02/18 19:07:21 | 000,001,599 | ---- | C] () -- C:\WINDOWS\PERWIN01.INI
[2002/01/09 19:37:51 | 000,000,035 | ---- | C] () -- C:\WINDOWS\InfModM.ini
[2001/12/28 03:36:33 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2001/12/28 03:31:14 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2001/12/28 03:28:47 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\saverrc.dll
[2001/12/28 03:27:35 | 000,000,312 | ---- | C] () -- C:\WINDOWS\MMKEYBD.INI
[2001/12/28 03:27:35 | 000,000,269 | ---- | C] () -- C:\WINDOWS\MSIOSD.INI
[2001/12/28 03:27:33 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\msiosd32.dll
[2001/12/28 03:27:33 | 000,001,378 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2001/12/28 03:27:23 | 000,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2001/12/28 03:27:07 | 000,000,029 | ---- | C] () -- C:\WINDOWS\wgedit.ini
[2001/12/28 03:27:04 | 000,057,344 | ---- | C] () -- C:\WINDOWS\uninstBVRP.dll
[2001/12/28 03:25:19 | 000,040,960 | ---- | C] () -- C:\WINDOWS\uneng.exe
[2001/12/28 03:23:51 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2001/12/28 02:51:40 | 000,000,481 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2001/08/18 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/18 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/18 08:00:00 | 000,432,778 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/18 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/18 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/18 08:00:00 | 000,067,734 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/18 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/18 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/18 08:00:00 | 000,004,594 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/18 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001/08/10 14:14:16 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\ImapiRoxPS.dll
[2001/08/06 14:41:48 | 000,028,672 | ---- | C] () -- C:\WINDOWS\Nhksrv.exe
[2000/09/08 16:53:50 | 000,073,839 | ---- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll
[1997/11/17 17:13:16 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
========== Custom Scans ========== < MD5 for: LIBUSB0.SYS >[2005/03/09 15:50:20 | 000,033,792 | ---- | M] () MD5=E2F1DCF4A68CC6CF694FBFBA1842F4CD -- C:\Program Files\CamcorderKit020\Drivers\libusb-win32-device-bin-0.1.10.1\bin\libusb0.sys
[2005/03/09 15:50:20 | 000,033,792 | ---- | M] () MD5=E2F1DCF4A68CC6CF694FBFBA1842F4CD -- C:\Program Files\CVS Camcorder Quickinstall 2.13\libusb-win32-device-bin-0.1.10.1\bin\libusb0.sys
[2005/03/09 16:50:20 | 000,033,792 | ---- | M] () MD5=E2F1DCF4A68CC6CF694FBFBA1842F4CD -- C:\Program Files\LibUSB-Win32-0.1.10.1\libusb-win32-device-bin-0.1.10.1\libusb-win32-device-bin-0.1.10.1\bin\libusb0.sys
[2005/03/09 15:50:20 | 000,033,792 | ---- | M] () MD5=E2F1DCF4A68CC6CF694FBFBA1842F4CD -- C:\WINDOWS\system32\drivers\libusb0.sys
< MD5 for: SACM2A.SYS >[2004/06/09 19:42:38 | 000,015,429 | R--- | M] ( ) MD5=D21CDE1C635BCC5053463579EEE453CF -- C:\WINDOWS\system32\drivers\Sacm2A.sys
< MD5 for: SERIAL.SYS >[2006/11/01 01:19:30 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:serial.sys
[2006/11/06 23:05:58 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:serial.sys
[2008/09/22 08:17:31 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:serial.sys
[2006/11/01 01:19:30 | 012,091,533 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp1.cab:serial.sys
[2006/11/06 23:05:58 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:serial.sys
[2008/09/22 08:17:31 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:serial.sys
[2001/08/18 08:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=1A315877D2EFCC2D0FF892D6BDB845B5 -- C:\Boot Files\C_\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
[2001/08/18 08:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=1A315877D2EFCC2D0FF892D6BDB845B5 -- C:\I386\SERIAL.SYS
[2008/04/13 15:15:45 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=CCA207A8896D4C6A0C9CE29A4AE411A7 -- C:\WINDOWS\ServicePackFiles\i386\serial.sys
[2011/07/01 23:58:13 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=CCA207A8896D4C6A0C9CE29A4AE411A7 -- C:\WINDOWS\system32\drivers\serial.sys
[2004/08/04 02:15:52 | 000,064,896 | ---- | M] (Microsoft Corporation) MD5=CD9404D115A00D249F70A371B46D5A26 -- C:\WINDOWS\$NtServicePackUninstall$\serial.sys
< C:\ABCD\*.* /s >[2011/07/02 00:28:04 | 000,052,784 | ---- | M] () -- C:\ABCD\023.dat
[2010/11/26 15:07:20 | 000,002,181 | ---- | M] () -- C:\ABCD\023v.dat
[2010/02/12 13:55:28 | 000,000,660 | ---- | M] () -- C:\ABCD\023w7.dat
[2011/07/02 00:28:22 | 000,000,237 | ---- | M] () -- C:\ABCD\AppData.folder.dat
[2000/08/30 20:00:00 | 000,006,760 | ---- | M] () -- C:\ABCD\appinit.bad
[2009/07/13 11:09:30 | 000,000,602 | ---- | M] () -- C:\ABCD\asp.str
[2010/04/15 10:11:36 | 000,004,144 | ---- | M] () -- C:\ABCD\Assoc.cmd
[2011/07/02 00:28:28 | 000,039,748 | ---- | M] () -- C:\ABCD\attr.dat
[2008/04/13 20:12:12 | 000,012,288 | R--- | M] () -- C:\ABCD\ATTRIB.cfxxe
[2011/07/02 00:28:39 | 000,016,534 | ---- | M] () -- C:\ABCD\autorun_inf.dat
[2011/07/02 00:28:39 | 000,003,257 | ---- | M] () -- C:\ABCD\autorun_infB.dat
[2011/06/27 22:39:32 | 000,004,476 | ---- | M] () -- C:\ABCD\av.cmd
[2010/12/15 11:02:04 | 000,002,933 | ---- | M] () -- C:\ABCD\av.vbs
[2011/06/26 11:15:58 | 000,000,666 | ---- | M] () -- C:\ABCD\AWF.cmd
[2011/07/02 00:28:05 | 000,000,000 | ---- | M] () -- C:\ABCD\badclsid
[2011/06/10 12:01:50 | 000,005,024 | ---- | M] () -- C:\ABCD\Boot-Rk.cmd
[2011/05/30 12:39:20 | 000,008,412 | ---- | M] () -- C:\ABCD\Boot.bat
[2010/07/27 04:55:16 | 000,000,875 | ---- | M] () -- C:\ABCD\BootDrv.vbs
[2011/07/02 00:28:39 | 000,000,752 | ---- | M] () -- C:\ABCD\borlander_file.dat
[2011/07/02 00:28:39 | 000,000,242 | ---- | M] () -- C:\ABCD\borlander_folder.dat
[2011/06/28 19:08:50 | 000,062,820 | ---- | M] () -- C:\ABCD\c.bat
[2011/07/02 00:27:57 | 000,000,000 | ---- | M] () -- C:\ABCD\c.mrk
[2011/07/02 00:28:22 | 000,000,332 | ---- | M] () -- C:\ABCD\Cache.folder.dat
[2010/10/21 04:45:48 | 000,001,080 | ---- | M] () -- C:\ABCD\Catch-sub.cmd
[2009/04/17 05:37:10 | 000,147,456 | R--- | M] () -- C:\ABCD\catchme.cfxxe
[2011/07/02 00:27:57 | 000,000,094 | ---- | M] () -- C:\ABCD\CCS.bat
[2011/06/26 11:17:16 | 000,030,027 | ---- | M] () -- C:\ABCD\CF-Script.cmd
[2011/07/02 00:27:44 | 000,389,120 | R--- | M] () -- C:\ABCD\CF21197.cfxxe
[2011/07/02 00:28:46 | 000,008,192 | ---- | M] () -- C:\ABCD\cfdummy
[2011/07/02 00:28:39 | 004,476,317 | ---- | M] () -- C:\ABCD\Cfiles.dat
[2011/07/02 00:28:38 | 000,877,288 | ---- | M] () -- C:\ABCD\Cfolders.dat
[2011/07/02 00:27:49 | 000,000,019 | ---- | M] () -- C:\ABCD\CHCP.bat
[2011/07/02 00:28:40 | 000,861,514 | ---- | M] () -- C:\ABCD\ClistB.dat
[2011/07/01 15:26:24 | 000,268,592 | ---- | M] () -- C:\ABCD\clsid.c
[2011/07/02 00:28:05 | 000,000,000 | ---- | M] () -- C:\ABCD\clsid.dat
[2011/07/02 00:28:07 | 005,017,600 | ---- | M] () -- C:\ABCD\clsid.hiv
[2011/07/02 00:27:44 | 000,389,120 | ---- | M] () -- C:\ABCD\cmd.cfxxe
[2010/08/19 11:16:34 | 000,001,024 | ---- | M] () -- C:\ABCD\Combo-Fix.sys
[2011/06/03 05:38:18 | 000,007,725 | ---- | M] () -- C:\ABCD\Combobatch.bat
[2000/08/30 20:00:00 | 000,236,032 | R--- | M] () -- C:\ABCD\ComboFix-Download.cfxxe
[2011/07/02 00:28:24 | 000,003,692 | ---- | M] () -- C:\ABCD\ConEnv.sed
[2011/07/02 00:28:22 | 000,000,154 | ---- | M] () -- C:\ABCD\Cookies.folder.dat
[2011/06/26 11:26:26 | 000,018,983 | ---- | M] () -- C:\ABCD\Create.cmd
[2011/07/01 07:49:28 | 000,557,865 | ---- | M] () -- C:\ABCD\Creg.dat
[2011/05/07 07:01:04 | 000,003,697 | ---- | M] () -- C:\ABCD\CregC.cmd
[2010/04/17 05:21:48 | 000,000,472 | ---- | M] () -- C:\ABCD\CregC.dat
[2011/07/02 00:28:11 | 000,000,971 | ---- | M] () -- C:\ABCD\CregC_.dat
[2008/05/07 05:07:23 | 000,135,168 | R--- | M] () -- C:\ABCD\CSCRIPT.cfxxe
[2011/06/03 05:43:34 | 000,001,723 | ---- | M] () -- C:\ABCD\CSet.cmd
[2011/07/02 00:28:02 | 000,000,000 | ---- | M] () -- C:\ABCD\d-delA.dat
[2011/07/02 00:28:46 | 000,000,000 | ---- | M] () -- C:\ABCD\d-del_A.dat
[2011/06/06 05:52:50 | 000,101,376 | R--- | M] () -- C:\ABCD\dd.cfxxe
[2009/05/24 21:59:50 | 000,007,983 | ---- | M] () -- C:\ABCD\ddsDo.sed
[2011/05/07 07:25:14 | 000,001,948 | ---- | M] () -- C:\ABCD\DelClsid.bat
[2011/07/02 00:28:22 | 000,000,099 | ---- | M] () -- C:\ABCD\Desktop.folder.dat
[2011/07/02 00:27:57 | 000,000,113 | ---- | M] () -- C:\ABCD\desktop.ini
[2011/07/02 00:27:47 | 000,000,006 | ---- | M] () -- C:\ABCD\DisclaimED.dat
[2011/07/02 00:28:27 | 000,003,193 | ---- | M] () -- C:\ABCD\dll_whitelist.dat
[2011/07/02 00:28:27 | 000,020,472 | ---- | M] () -- C:\ABCD\dnd.dat
[2000/08/30 20:00:00 | 000,000,746 | ---- | M] () -- C:\ABCD\DPF.str
[2011/07/02 00:28:46 | 000,000,000 | ---- | M] () -- C:\ABCD\Drive.folder.dat
[2011/07/02 00:28:39 | 000,000,054 | ---- | M] () -- C:\ABCD\DriveFile.dat
[2011/07/02 00:28:46 | 000,000,000 | ---- | M] () -- C:\ABCD\Drives.dat
[2010/04/18 14:44:24 | 000,000,650 | ---- | M] () -- C:\ABCD\DrvRun.vbs
[2000/08/30 20:00:00 | 000,051,200 | R--- | M] () -- C:\ABCD\dumphive.cfxxe
[2000/08/30 20:00:00 | 000,000,303 | ---- | M] () -- C:\ABCD\embedded.sed
[2011/07/02 00:28:28 | 000,000,611 | ---- | M] () -- C:\ABCD\Env.sed
[2005/10/20 08:02:28 | 000,163,328 | ---- | M] () -- C:\ABCD\ERDNT.e_e
[2000/08/30 20:00:00 | 000,002,815 | ---- | M] () -- C:\ABCD\ERDNTDOS.LOC
[2000/08/30 20:00:00 | 000,003,275 | ---- | M] () -- C:\ABCD\ERDNTWIN.LOC
[2005/10/20 08:00:28 | 000,394,752 | R--- | M] () -- C:\ABCD\ERUNT.cfxxe
[2011/07/02 00:27:57 | 000,000,010 | ---- | M] () -- C:\ABCD\erunt.dat
[2000/08/30 20:00:00 | 000,004,090 | ---- | M] () -- C:\ABCD\ERUNT.LOC
[2011/05/13 14:56:48 | 000,015,016 | ---- | M] () -- C:\ABCD\Exe.reg
[2000/08/30 20:00:00 | 000,052,736 | R--- | M] () -- C:\ABCD\extract.cfxxe
[2011/07/02 00:28:22 | 000,000,155 | ---- | M] () -- C:\ABCD\Favorites.folder.dat
[2011/06/26 11:27:04 | 000,009,074 | ---- | M] () -- C:\ABCD\FD-SV.cmd
[2010/08/29 16:45:48 | 000,038,901 | ---- | M] () -- C:\ABCD\ffdefstr.dll
[2000/08/30 20:00:00 | 000,145,920 | R--- | M] () -- C:\ABCD\FileKill.cfxxe
[2011/07/01 15:26:24 | 000,003,186 | ---- | M] () -- C:\ABCD\files.pif
[2010/08/09 16:32:44 | 000,000,677 | ---- | M] () -- C:\ABCD\Fin.dat
[2011/06/26 11:29:46 | 000,034,183 | ---- | M] () -- C:\ABCD\FIND3M.bat
[2011/06/09 14:54:56 | 000,005,926 | ---- | M] () -- C:\ABCD\FIXLSP.bat
[2011/06/26 11:29:58 | 000,001,088 | ---- | M] () -- C:\ABCD\FKMGen.cmd
[2011/07/02 00:28:00 | 000,000,880 | ---- | M] () -- C:\ABCD\ForeignWht
[2011/07/02 00:28:19 | 000,000,000 | ---- | M] () -- C:\ABCD\f_system
[2011/07/02 00:28:25 | 000,000,000 | ---- | M] () -- C:\ABCD\Gateway
[2011/06/03 05:43:34 | 000,006,090 | ---- | M] () -- C:\ABCD\GetHive.cmd
[2011/07/02 00:28:39 | 000,016,089 | ---- | M] () -- C:\ABCD\GOLDUN.DAT
[2000/08/30 20:00:00 | 000,080,412 | R--- | M] () -- C:\ABCD\grep.cfxxe
[2000/08/30 20:00:00 | 000,015,360 | R--- | M] () -- C:\ABCD\gsar.cfxxe
[2008/11/18 01:15:14 | 000,417,136 | R--- | M] () -- C:\ABCD\handle.cfxxe
[2008/12/11 08:11:44 | 000,015,872 | R--- | M] () -- C:\ABCD\HDPEInfo.cfxxe
[2005/08/15 13:54:58 | 000,001,536 | R--- | M] () -- C:\ABCD\hidec.cfxxe
[2009/10/20 05:25:36 | 000,000,954 | ---- | M] () -- C:\ABCD\history.bat
[2011/07/02 00:28:22 | 000,000,199 | ---- | M] () -- C:\ABCD\History.folder.dat
[2009/04/20 00:56:28 | 000,060,416 | ---- | M] () -- C:\ABCD\iexplore.exe
[2000/08/30 20:00:00 | 000,001,057 | ---- | M] () -- C:\ABCD\image001.gif
[2010/09/04 19:07:30 | 000,000,224 | ---- | M] () -- C:\ABCD\Imefile.dat
[2011/03/08 21:49:06 | 000,001,374 | ---- | M] () -- C:\ABCD\katch.cmd
[2011/07/02 00:28:52 | 000,000,248 | ---- | M] () -- C:\ABCD\katchNT-OS
[2011/07/02 00:28:08 | 000,000,000 | ---- | M] () -- C:\ABCD\Keith Lawrence.user.cf
[2011/06/03 05:43:34 | 000,001,896 | ---- | M] () -- C:\ABCD\Kill-All.cmd
[2011/07/02 00:27:57 | 000,000,015 | ---- | M] () -- C:\ABCD\kmd.dat
[2011/06/29 14:38:30 | 000,250,104 | ---- | M] () -- C:\ABCD\Lang.bat
[2011/06/28 13:49:36 | 000,020,848 | ---- | M] () -- C:\ABCD\List-B.bat
[2011/06/30 10:47:50 | 000,251,375 | ---- | M] () -- C:\ABCD\List-C.bat
[2010/12/15 13:49:00 | 000,003,246 | ---- | M] () -- C:\ABCD\lnkread.vbs
[2011/07/02 00:28:22 | 000,000,226 | ---- | M] () -- C:\ABCD\LocalAppData.folder.dat
[2000/08/30 20:00:00 | 000,000,225 | ---- | M] () -- C:\ABCD\LocalService.dat
[2000/08/30 20:00:00 | 000,000,091 | ---- | M] () -- C:\ABCD\LocalServiceNetworkRestricted.dat
[2011/07/02 00:28:22 | 000,000,234 | ---- | M] () -- C:\ABCD\LocalSettings.folder.dat
[2000/08/30 20:00:00 | 000,000,198 | ---- | M] () -- C:\ABCD\LocalSystemNetworkRestricted.dat
[2009/10/24 18:11:34 | 000,184,320 | R--- | M] () -- C:\ABCD\mbr.cfxxe
[2010/08/28 23:30:24 | 000,002,141 | ---- | M] () -- C:\ABCD\mbr.chk
[2011/07/01 15:26:24 | 000,006,630 | ---- | M] () -- C:\ABCD\md5sum.pif
[2011/05/06 16:57:06 | 000,002,856 | ---- | M] () -- C:\ABCD\MoveIt.bat
[2000/08/30 20:00:00 | 000,011,264 | R--- | M] () -- C:\ABCD\mtee.cfxxe
[2011/07/02 00:27:47 | 000,000,164 | ---- | M] () -- C:\ABCD\MtPt00
[2011/07/02 00:28:22 | 000,000,124 | ---- | M] () -- C:\ABCD\Music.folder.dat
[2011/07/02 00:28:04 | 000,000,467 | ---- | M] () -- C:\ABCD\MWindows.dat
[2000/08/30 20:00:00 | 000,000,000 | ---- | M] () -- C:\ABCD\mynul.dat
[2011/07/02 00:28:46 | 000,008,523 | R--- | M] () -- C:\ABCD\ncmd.com
[2009/12/24 04:12:40 | 000,000,283 | ---- | M] () -- C:\ABCD\ndis_combofix.dat
[2011/06/26 11:33:26 | 000,065,283 | ---- | M] () -- C:\ABCD\ND_.bat
[2011/06/23 14:52:38 | 000,017,757 | ---- | M] () -- C:\ABCD\ND_64.bat
[2011/07/02 00:28:22 | 000,000,052 | ---- | M] () -- C:\ABCD\NetHood.folder.dat
[2010/04/14 06:21:30 | 000,000,520 | ---- | M] () -- C:\ABCD\netsvc.bad.dat
[2000/08/30 20:00:00 | 000,000,525 | ---- | M] () -- C:\ABCD\netsvc.dat
[2000/08/30 20:00:00 | 000,000,088 | ---- | M] () -- C:\ABCD\NetworkService.dat
[2009/04/20 00:56:28 | 000,060,416 | R--- | M] () -- C:\ABCD\NirCmd.cfxxe
[2009/04/20 00:56:28 | 000,060,416 | ---- | M] () -- C:\ABCD\NircmdB.exe
[2009/04/20 00:56:26 | 000,058,880 | R--- | M] () -- C:\ABCD\NirCmdC.cfxxe
[2009/04/20 00:56:28 | 000,060,416 | R--- | M] () -- C:\ABCD\NIRKMD.cfxxe
[2011/07/02 00:27:49 | 000,000,006 | ---- | M] () -- C:\ABCD\NlsLanguageDefault
[2011/07/02 00:28:27 | 000,000,176 | ---- | M] () -- C:\ABCD\notifykeys.dat
[2011/07/02 00:28:27 | 000,000,210 | ---- | M] () -- C:\ABCD\notifykeysB.dat
[2011/06/26 11:33:42 | 000,042,693 | ---- | M] () -- C:\ABCD\NT-OS.cmd
[2011/07/02 00:28:49 | 000,000,000 | ---- | M] () -- C:\ABCD\nt-osSvcDump00
[2011/07/02 00:28:49 | 000,000,003 | ---- | M] () -- C:\ABCD\NULL
[2011/07/02 00:28:13 | 000,000,083 | ---- | M] () -- C:\ABCD\OsId.txt
[2000/08/30 20:00:00 | 000,000,977 | ---- | M] () -- C:\ABCD\OSid.vbs
[2002/09/29 01:01:16 | 000,180,224 | R--- | M] () -- C:\ABCD\pausep.cfxxe
[2011/07/02 00:28:26 | 000,000,802 | ---- | M] () -- C:\ABCD\pend.txt
[2011/07/02 00:28:22 | 000,000,106 | ---- | M] () -- C:\ABCD\Personal.folder.dat
[2011/06/26 02:45:56 | 000,256,000 | R--- | M] () -- C:\ABCD\pev.cfxxe
[2011/01/27 21:28:38 | 000,102,400 | R--- | M] () -- C:\ABCD\pevb.cfxxe
[2011/07/02 00:28:22 | 000,000,130 | ---- | M] () -- C:\ABCD\Pictures.folder.dat
[2008/04/13 20:12:31 | 000,017,920 | R--- | M] () -- C:\ABCD\PING.cfxxe
[2009/07/05 15:51:10 | 000,002,992 | ---- | M] () -- C:\ABCD\Policies.dat
[2010/05/13 04:57:52 | 000,000,064 | ---- | M] () -- C:\ABCD\powp.dat
[2011/07/02 00:28:25 | 000,000,036 | ---- | M] () -- C:\ABCD\PreDIR
[2011/05/13 15:09:08 | 000,003,006 | ---- | M] () -- C:\ABCD\Prep.inf
[2011/07/02 00:28:22 | 000,000,108 | ---- | M] () -- C:\ABCD\PrintHood.folder.dat
[2011/07/02 00:28:22 | 000,000,271 | ---- | M] () -- C:\ABCD\Profiles.Folder.dat
[2011/07/02 00:28:22 | 000,000,327 | ---- | M] () -- C:\ABCD\Profiles.Folder.folder.dat
[2011/07/02 00:28:22 | 000,000,185 | ---- | M] () -- C:\ABCD\Programs.folder.dat
[2000/08/30 20:00:00 | 000,000,404 | ---- | M] () -- C:\ABCD\Purity.dat
[2006/03/02 23:42:40 | 000,073,728 | R--- | M] () -- C:\ABCD\PV.cfxxe
[2006/03/02 11:42:40 | 000,073,728 | ---- | M] () -- C:\ABCD\pv.com
[2011/07/02 00:27:44 | 000,000,056 | ---- | M] () -- C:\ABCD\rar_sfx.cmd
[2000/08/30 20:00:00 | 000,007,478 | ---- | M] () -- C:\ABCD\RCLink.dat
[2011/07/02 00:28:25 | 000,000,000 | ---- | M] () -- C:\ABCD\RcRdy
[2011/07/02 00:28:14 | 000,000,007 | ---- | M] () -- C:\ABCD\RcVer00
[2011/07/02 00:28:22 | 000,000,102 | ---- | M] () -- C:\ABCD\Recent.folder.dat
[2000/08/30 20:00:00 | 000,003,558 | ---- | M] () -- C:\ABCD\REGDACL.sed
[2000/08/30 20:00:00 | 000,009,203 | ---- | M] () -- C:\ABCD\RegDo.sed
[2010/09/16 16:03:32 | 000,001,153 | ---- | M] () -- C:\ABCD\region.dat
[2011/06/26 11:35:12 | 000,053,833 | ---- | M] () -- C:\ABCD\RegScan.cmd
[2011/07/02 00:28:05 | 000,146,432 | ---- | M] () -- C:\ABCD\REGT.cfxxe
[2011/07/02 00:27:54 | 000,000,073 | ---- | M] () -- C:\ABCD\Resident.txt
[2011/07/02 00:28:11 | 000,000,000 | ---- | M] () -- C:\ABCD\restore_pt.dat
[2009/05/01 10:26:10 | 000,000,587 | ---- | M] () -- C:\ABCD\restore_pt.vbs
[2009/11/14 17:35:16 | 000,000,442 | ---- | M] () -- C:\ABCD\Rkey.cmd
[2010/11/07 13:20:24 | 000,208,896 | R--- | M] () -- C:\ABCD\rmbr.cfxxe
[2000/08/30 20:00:00 | 000,000,820 | ---- | M] () -- C:\ABCD\rogues.dat
[2001/08/18 08:00:00 | 000,019,968 | R--- | M] () -- C:\ABCD\ROUTE.cfxxe
[2011/07/02 00:28:28 | 000,001,970 | ---- | M] () -- C:\ABCD\run.sed
[2000/08/30 20:00:00 | 000,000,287 | ---- | M] () -- C:\ABCD\run2.sed
[2009/06/09 23:38:44 | 000,000,030 | ---- | M] () -- C:\ABCD\Rust.str
[1999/11/10 12:00:00 | 000,038,400 | R--- | M] () -- C:\ABCD\s0rt.cfxxe
[2000/08/30 20:00:00 | 000,000,329 | ---- | M] () -- C:\ABCD\safeboot.dat
[2009/06/09 14:25:08 | 000,001,464 | ---- | M] () -- C:\ABCD\safeboot.def.dat
[2000/08/30 20:00:00 | 000,098,816 | R--- | M] () -- C:\ABCD\sed.cfxxe
[2011/07/02 00:28:22 | 000,000,102 | ---- | M] () -- C:\ABCD\SendTo.folder.dat
[2011/06/26 11:35:12 | 000,017,077 | ---- | M] () -- C:\ABCD\SetEnvmt.bat
[2011/07/02 00:28:21 | 000,007,302 | ---- | M] () -- C:\ABCD\SetPath.bat
[2000/08/30 20:00:00 | 000,066,172 | R--- | M] () -- C:\ABCD\setpath.cfxxe
[2011/07/02 00:27:47 | 000,002,845 | ---- | M] () -- C:\ABCD\setpath_N.cmd
[2006/06/10 14:42:26 | 000,049,152 | ---- | M] () -- C:\ABCD\SF.exe
[2011/07/02 00:27:52 | 000,000,014 | ---- | M] () -- C:\ABCD\sfx.cmd
[2011/06/23 14:52:38 | 000,004,634 | ---- | M] () -- C:\ABCD\SnapShot.cmd
[2011/06/23 14:52:38 | 000,002,147 | ---- | M] () -- C:\ABCD\SRestore.cmd
[2011/07/01 07:47:12 | 000,304,822 | ---- | M] () -- C:\ABCD\srizbi.md5
[2011/07/02 00:28:22 | 000,000,105 | ---- | M] () -- C:\ABCD\StartMenu.folder.dat
[2011/07/02 00:28:22 | 000,000,209 | ---- | M] () -- C:\ABCD\StartUp.folder.dat
[2011/07/02 00:27:55 | 000,000,002 | ---- | M] () -- C:\ABCD\Start_dat
[2011/06/26 11:35:12 | 000,020,667 | ---- | M] () -- C:\ABCD\SuppScan.cmd
[2000/08/30 20:00:00 | 000,002,176 | ---- | M] () -- C:\ABCD\SvcDrv.vbs
[2000/08/30 20:00:00 | 000,000,555 | ---- | M] () -- C:\ABCD\svchost.dat
[2010/11/27 01:12:00 | 000,000,749 | ---- | M] () -- C:\ABCD\svchost.vista.x64.dat
[2009/11/28 18:42:26 | 000,011,987 | ---- | M] () -- C:\ABCD\svc_wht.dat
[2000/08/30 20:00:00 | 000,518,144 | R--- | M] () -- C:\ABCD\swreg.cfxxe
[2000/08/30 20:00:00 | 000,406,528 | R--- | M] () -- C:\ABCD\swsc.cfxxe
[2000/08/30 20:00:00 | 000,212,480 | R--- | M] () -- C:\ABCD\swxcacls.cfxxe
[2011/07/02 00:28:20 | 000,002,187 | ---- | M] () -- C:\ABCD\SysPath.dat
[2000/08/30 20:00:00 | 000,000,276 | ---- | M] () -- C:\ABCD\system_ini.dat
[1999/11/09 20:00:00 | 000,035,328 | R--- | M] () -- C:\ABCD\tail.cfxxe
[2011/07/02 00:28:46 | 000,002,654 | ---- | M] () -- C:\ABCD\Temp.dat
[2011/07/02 00:28:22 | 000,000,103 | ---- | M] () -- C:\ABCD\Templates.folder.dat
[2009/10/30 01:26:54 | 000,000,633 | ---- | M] () -- C:\ABCD\toolbar.sed
[2011/07/02 00:28:27 | 000,000,606 | ---- | M] () -- C:\ABCD\unhand.dat
[2011/06/23 14:52:36 | 000,003,945 | ---- | M] () -- C:\ABCD\Update-CF.cmd
[2011/07/02 00:27:55 | 000,000,273 | ---- | M] () -- C:\ABCD\VerCF.bat
[2011/07/02 00:28:36 | 000,262,911 | ---- | M] () -- C:\ABCD\VikPev00
[2011/07/02 00:28:46 | 000,000,000 | ---- | M] () -- C:\ABCD\Vikpev01
[2011/06/22 04:40:30 | 000,003,819 | ---- | M] () -- C:\ABCD\VInfo
[2011/07/01 07:47:04 | 000,015,500 | ---- | M] () -- C:\ABCD\VInfo2
[2011/06/22 04:40:34 | 000,000,557 | ---- | M] () -- C:\ABCD\VINFO3
[2010/05/10 11:30:04 | 000,000,308 | ---- | M] () -- C:\ABCD\Vipev.dat
[2011/07/02 00:28:46 | 000,006,048 | ---- | M] () -- C:\ABCD\ViPev00
[2011/07/02 00:28:46 | 000,005,982 | ---- | M] () -- C:\ABCD\ViPev01
[2010/07/26 15:17:22 | 000,000,440 | ---- | M] () -- C:\ABCD\vistaMcode.dat
[2011/07/02 00:28:28 | 000,004,073 | ---- | M] () -- C:\ABCD\vRun_DLL
[2010/06/20 16:05:36 | 000,007,584 | ---- | M] () -- C:\ABCD\vun.dat
[2011/07/02 00:28:39 | 000,000,035 | ---- | M] () -- C:\ABCD\vundonames.dat
[2011/07/02 00:28:28 | 000,039,854 | ---- | M] () -- C:\ABCD\v_wht.dat
[2010/07/23 16:20:44 | 000,000,440 | ---- | M] () -- C:\ABCD\w7Mcode.dat
[2011/07/02 00:28:28 | 000,073,681 | ---- | M] () -- C:\ABCD\whiteAll.dat
[2011/07/02 00:28:27 | 000,017,933 | ---- | M] () -- C:\ABCD\whitedir.dat
[2011/07/02 00:28:27 | 000,001,137 | ---- | M] () -- C:\ABCD\whitedirCreated.dat
[2010/12/11 15:38:00 | 000,001,127 | ---- | M] () -- C:\ABCD\Wmi_rem.vbs
[2009/06/21 02:45:40 | 000,098,948 | ---- | M] () -- C:\ABCD\w_sock.dll
[2011/07/02 00:27:32 | 000,000,006 | ---- | M] () -- C:\ABCD\XP.mac
[2010/07/22 10:14:44 | 000,000,440 | ---- | M] () -- C:\ABCD\xpmcode.dat
[2011/05/23 10:36:40 | 000,061,815 | ---- | M] () -- C:\ABCD\xpreg.dat
[2010/02/02 06:41:38 | 000,013,090 | ---- | M] () -- C:\ABCD\XPSBoot.reg
[2000/08/30 20:00:00 | 000,023,773 | ---- | M] () -- C:\ABCD\zDomain.dat
[2011/07/02 00:28:04 | 000,049,886 | ---- | M] () -- C:\ABCD\zhsvc.dat
[2000/08/30 20:00:00 | 000,068,096 | R--- | M] () -- C:\ABCD\zip.cfxxe
[2011/07/02 00:28:47 | 000,000,000 | ---- | M] () -- C:\ABCD\Zlob01
[1 C:\ABCD\*.tmp files -> C:\ABCD\*.tmp -> ]
[2011/07/02 00:28:47 | 000,000,044 | ---- | M] () -- C:\ABCD\N_\10170
[2011/07/02 00:28:28 | 000,000,034 | ---- | M] () -- C:\ABCD\N_\12030
[2011/07/02 00:28:39 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\13026
[2011/07/02 00:28:47 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\13115
[2011/07/02 00:28:50 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\15690
[2011/07/02 00:28:46 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\16653
[2011/07/02 00:28:52 | 000,000,083 | ---- | M] () -- C:\ABCD\N_\16839
[2011/07/02 00:28:47 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\18499
[2011/07/02 00:28:26 | 000,000,295 | ---- | M] () -- C:\ABCD\N_\18563
[2011/07/02 00:28:47 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\19180
[2011/07/02 00:28:47 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\19251
[2011/07/02 00:28:48 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\19367
[2011/07/02 00:28:28 | 000,000,033 | ---- | M] () -- C:\ABCD\N_\20568
[2011/07/02 00:28:46 | 000,000,027 | ---- | M] () -- C:\ABCD\N_\22522
[2011/07/02 00:28:51 | 000,000,248 | ---- | M] () -- C:\ABCD\N_\23783
[2011/07/02 00:28:49 | 000,000,387 | ---- | M] () -- C:\ABCD\N_\24409
[2011/07/02 00:28:47 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\24690
[2011/07/02 00:28:46 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\25521
[2011/07/02 00:28:46 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\27505
[2011/07/02 00:28:26 | 000,000,099 | ---- | M] () -- C:\ABCD\N_\28652
[2011/07/02 00:28:47 | 000,000,337 | ---- | M] () -- C:\ABCD\N_\29808
[2011/07/02 00:28:50 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\2988
[2011/07/02 00:28:27 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\30543
[2011/07/02 00:28:28 | 000,000,024 | ---- | M] () -- C:\ABCD\N_\31075
[2011/07/02 00:28:49 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\31606
[2011/07/02 00:28:27 | 000,000,044 | ---- | M] () -- C:\ABCD\N_\8105
[2011/07/02 00:28:49 | 000,000,101 | ---- | M] () -- C:\ABCD\N_\8904
[2011/07/02 00:28:47 | 000,000,044 | ---- | M] () -- C:\ABCD\N_\899
[2011/07/02 00:28:46 | 000,000,000 | ---- | M] () -- C:\ABCD\N_\cfdummy00
[2011/07/02 00:28:26 | 000,000,057 | ---- | M] () -- C:\ABCD\N_\CmdLine00
< C:\WINDOWS\System32\drivers\*.dll >[2008/04/13 20:11:48 | 000,004,255 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv01nt5.dll
[2008/04/13 20:11:48 | 000,003,967 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv02nt5.dll
[2008/04/13 20:11:48 | 000,003,615 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv05nt5.dll
[2008/04/13 20:11:48 | 000,003,647 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv07nt5.dll
[2008/04/13 20:11:48 | 000,003,135 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv08nt5.dll
[2008/04/13 20:11:48 | 000,003,711 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv09nt5.dll
[2008/04/13 20:11:48 | 000,003,775 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv11nt5.dll
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aepYKNFms.dll
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ArQaqXi.dll
[2008/04/13 20:11:50 | 000,021,183 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv01nt5.dll
[2008/04/13 20:11:50 | 000,011,359 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv02nt5.dll
[2008/04/13 20:11:50 | 000,025,471 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv04nt5.dll
[2008/04/13 20:11:50 | 000,014,143 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv06nt5.dll
[2008/04/13 20:11:50 | 000,017,279 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv10nt5.dll
[2008/04/13 20:11:49 | 000,126,575 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aXCORJlYa.dll
[2008/04/13 20:11:48 | 000,194,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aXDJxdmGU.dll
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bDSvqf.dll
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bhYMvwrv.dll
[2008/04/13 20:11:48 | 000,176,239 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\BRdPjR.dll
[2008/04/13 20:11:48 | 000,068,719 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\BumRDu.dll
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\BwlhAVH.dll
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bwqtNo.dll
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\BysfxJl.dll
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\cchucW.dll
[2008/04/13 20:11:50 | 000,015,423 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2008/04/13 20:11:49 | 000,126,575 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\CPhgW.dll
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\cRdrTjgj.dll
[2008/04/13 20:11:48 | 000,136,815 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\CTqECAIjL.dll
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dGQvp.dll
[2008/04/13 20:11:49 | 000,065,647 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dPqtPpayu.dll
[2008/04/13 20:11:48 | 000,194,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\DrFtprmF.dll
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dvMnTsn.dll
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dYWAQEiHt.dll
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\EvFDmwAev.dll
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\eVWHqMXDO.dll
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\EwKDU.dll
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fBCfpfR.dll
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fnAMC.dll
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\FPjARxyF.dll
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fSPrWTDk.dll
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fWcNVgGgm.dll
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\GJMfS.dll
[2008/04/13 20:11:48 | 000,194,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hAvBnrrb.dll
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HdwItP.dll
[2004/01/29 10:08:23 | 000,033,391 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HwKqrTmmR.dll
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HwNtDCxO.dll
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\IAOKlGNA.dll
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\icnaR.dll
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\IKJFX.dll
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\itidBRwY.dll
[2008/04/13 20:11:49 | 000,065,647 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\jBOboVA.dll
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\jfruCN.dll
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\jYuCx.dll
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\KaSQYy.dll
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\KFeElLsAl.dll
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\klxkSOB.dll
[2008/04/13 20:11:48 | 000,098,927 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\LfwueAAh.dll
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\lKBdlS.dll
[2008/04/13 20:11:48 | 000,176,239 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\LnxkEbK.dll
[2001/08/18 08:00:00 | 000,065,758 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\LoIBfTpE.dll
[2008/04/13 20:11:48 | 000,068,719 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\lrcHhIxQs.dll
[2001/08/18 08:00:00 | 000,065,758 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\lRLkJl.dll
[2008/04/13 20:11:49 | 000,065,647 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mAbPV.dll
[2008/04/13 20:11:48 | 000,098,927 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mBPSU.dll
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MOcfeOiv.dll
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\NOjvgaN.dll
[2008/04/13 20:11:48 | 000,068,719 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\npMGmvraB.dll
[2008/04/13 20:11:49 | 000,065,647 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\OfxAh.dll
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\oRlAMBA.dll
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\PcuAsLYJ.dll
[2008/04/13 20:11:49 | 000,065,647 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\PfeLuj.dll
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\QwjooEu.dll
[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\QxnyJvUvG.dll
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rbrydtCV.dll
[2008/04/13 20:11:48 | 000,176,239 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rcHjjV.dll
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rcixu.dll
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\RGRnMjQUU.dll
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sgjcflBo.dll
[2008/04/13 20:12:05 | 000,003,901 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\siint5.dll
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sKTQPNh.dll
[2008/04/13 20:11:48 | 000,264,303 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\SKxCeM.dll
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sNdtDN.dll
[2008/04/13 20:11:48 | 000,194,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\srwQe.dll
[2008/04/13 20:11:48 | 000,068,719 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tcDCcyIdI.dll
[2008/04/13 20:11:48 | 000,264,303 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tgVWmJj.dll
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\TIXjusfKT.dll
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tJbdfIJ.dll
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tRAsFLvs.dll
[2008/04/13 20:11:48 | 000,136,815 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tSEXhaxq.dll
[2008/04/13 20:12:08 | 000,011,325 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\vchnt5.dll
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\WmppU.dll
[2008/04/13 20:11:49 | 000,126,575 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wnLYE.dll
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\woIgOG.dll
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\WrhIo.dll
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\WwDKqNE.dll
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\XFEHMNB.dll
[2008/04/13 20:11:48 | 000,264,303 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\xiMsbud.dll
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\XjreLOYI.dll
[2008/04/13 20:11:48 | 000,098,927 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\xlBlRc.dll
[2008/04/13 20:11:48 | 000,098,927 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\XLLHPKDHA.dll
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\XQBujxEMC.dll
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\XQEGhvF.dll
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\XttfyjQ.dll
[2008/04/13 20:11:48 | 000,194,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\YiaoXtd.dll
[2008/04/13 20:11:49 | 000,066,270 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\YIhEvRN.dll
[2008/04/13 20:11:48 | 000,098,927 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\yiYdWOAhO.dll
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\yKGjSLnq.dll
[2001/08/18 08:00:00 | 000,065,758 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ykXcONVH.dll
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\YldHrPg.dll
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\yPQvotn.dll
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\yvOakFRD.dll
< C:\WINDOWS\System32\drivers\*.exe >[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aJBWxC.exe
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aniuOXA.exe
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ApUqNoG.exe
[2008/04/13 20:11:48 | 000,176,239 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\axcjkRq.exe
[2008/04/13 20:11:48 | 000,176,239 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aySlGSAv.exe
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\BjiBM.exe
[2008/04/13 20:11:49 | 000,126,575 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\cAbgpliIe.exe
[2003/02/10 21:29:31 | 000,052,736 | ---- | M] (Macrovision) -- C:\WINDOWS\System32\drivers\CDAC11BA.EXE
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\cFPaOQVD.exe
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\CPfcTC.exe
[2001/08/18 08:00:00 | 000,065,758 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\cwgQJTJtf.exe
[2008/04/13 20:11:49 | 000,126,575 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\DJkuhpFm.exe
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\DRIFeOTjW.exe
[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\eNyCsj.exe
[2008/04/13 20:11:48 | 000,264,303 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\faTXv.exe
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fibAiHAh.exe
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\Foelhal.exe
[2004/01/29 10:08:23 | 000,033,391 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\FRQurbl.exe
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fYIEK.exe
[2008/04/13 20:11:49 | 000,066,270 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fYiqiE.exe
[2004/01/29 10:08:23 | 000,033,391 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gAWWT.exe
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\GgAlrRllS.exe
[2008/04/13 20:11:48 | 000,098,927 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gGjEC.exe
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gKLakkGL.exe
[2008/04/13 20:11:48 | 000,098,927 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gMqrn.exe
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\GQqSMh.exe
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gyyVFD.exe
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HbWAG.exe
[2008/04/13 20:11:48 | 000,194,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HffCEEaD.exe
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hfrvGg.exe
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HhvMYhYQh.exe
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HIVpWHSfp.exe
[2008/04/13 20:11:49 | 000,066,270 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HPJUDIpg.exe
[2008/04/13 20:11:48 | 000,098,927 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\HVOgfeb.exe
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hyaVSTT.exe
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ifcua.exe
[2008/04/13 20:11:49 | 000,065,647 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\IFHGpKcDh.exe
[2008/04/13 20:11:48 | 000,176,239 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\iOTAcbDo.exe
[2008/04/13 20:11:48 | 000,068,719 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\iPXnSK.exe
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\isOpIDa.exe
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ITniBxcFF.exe
[2001/08/18 08:00:00 | 000,065,758 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\IWTMvwtB.exe
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\JpYGTb.exe
[2008/04/13 20:11:48 | 000,264,303 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\KEwLR.exe
[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\KGPXUT.exe
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kkJpH.exe
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\KluuoVATv.exe
[2003/06/18 09:54:10 | 000,296,960 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\System32\drivers\KodakCCS.exe
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\KovUGo.exe
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\LBMlj.exe
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\LJjbARfB.exe
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\llUOfwU.exe
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\lsOcJOP.exe
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\LyObqLkJH.exe
[2008/04/13 20:11:48 | 000,136,815 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mcDTnvbn.exe
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MfYLxM.exe
[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mGubQCJa.exe
[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mIydP.exe
[2008/04/13 20:11:49 | 000,126,575 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mRKiK.exe
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\Mskic.exe
[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mwJkqA.exe
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mxbCLP.exe
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\NaChU.exe
[2008/04/13 20:11:48 | 000,194,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nlCYIFH.exe
[2008/04/13 20:11:48 | 000,176,239 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nOiBs.exe
[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nRulTX.exe
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nydkaqIm.exe
[2008/04/13 20:11:48 | 000,136,815 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\oIhuA.exe
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\OnqQnTkCQ.exe
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\opsSoqgf.exe
[2004/01/29 10:08:23 | 000,033,391 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\oULLRvYPH.exe
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\PsxrnrXN.exe
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\qbPAel.exe
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\QcQSKS.exe
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\qMOcUAhr.exe
[2009/03/08 05:32:56 | 000,073,327 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\RbrcSJYR.exe
[2008/04/13 20:11:48 | 000,194,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\RjvHSw.exe
[2001/08/18 08:00:00 | 000,065,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\RmkuDEVP.exe
[2008/04/13 20:11:48 | 000,068,719 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rpriw.exe
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\RRKcR.exe
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rsUmnPaJo.exe
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rTFYp.exe
[2008/04/13 20:11:48 | 000,136,815 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rUaEuwfuK.exe
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rYpBq.exe
[2008/04/13 20:11:49 | 000,018,031 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\saurspEkO.exe
[2008/04/13 20:11:49 | 000,229,999 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ScJRU.exe
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tJTHHOTr.exe
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\trGmgabF.exe
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\uHAnaxcxq.exe
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\vErbYEOD.exe
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\VNcQXVkFu.exe
[2008/04/13 20:11:48 | 000,264,303 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\VoFvO.exe
[2008/04/13 20:11:48 | 000,068,719 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\VQxmr.exe
[2001/08/18 08:00:00 | 000,103,535 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wBeqPQkn.exe
[2008/04/13 20:11:49 | 000,065,647 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wlgJS.exe
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\WybdIeH.exe
[2008/04/13 20:11:48 | 000,068,719 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\xdjTfMJXm.exe
[2006/10/18 22:47:08 | 000,007,791 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\xggsbToOf.exe
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\xJUsvfY.exe
[2008/04/13 20:11:48 | 000,176,239 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\xLuHKphs.exe
[2009/03/08 05:32:48 | 000,129,135 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\XWyki.exe
[2008/04/13 20:11:48 | 000,100,975 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\xXSVUHaAI.exe
[2001/08/18 08:00:00 | 000,130,159 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\YaDBbu.exe
[2009/02/09 08:10:48 | 000,618,095 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\yCeMCd.exe
[2001/08/18 08:00:00 | 000,026,735 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\yDqNSH.exe
[2008/04/13 20:11:49 | 000,065,647 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\YfUnq.exe
[2008/04/13 20:11:48 | 000,143,983 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ytmKWp.exe
[2008/04/13 20:11:48 | 000,116,335 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\yUcfMObj.exe
[2001/08/18 08:00:00 | 000,026,223 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\YVRDFnHbb.exe
========== Alternate Data Streams ========== @Alternate Data Stream - 3 bytes -> C:\ABCD\f_system:test
@Alternate Data Stream - 185 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
Michael,
I unplugged my internet cable - hope this stops the "evolution"...
This last actions seems to have brought the desktop back to a more normal looking state, so I think somehting is finally happengin.
I do keep getting a pop up box that says: Validation failed for C:\windows\system32/Zonelabs\vsmon.exe
Not sure what that is but thought I would mention it.
Thanks!!!!!!
Keith