I have managed to kill those processes and delete the folder now, but I would just like to know if I am clean.
Please let me know...
My OTL Results are below just in case as well as my RootReapel Report.
Thanks in advanced...
OTL logfile created on: 5/9/2012 10:29:50 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Fadil Shamir Khan\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.17 Mb Total Physical Memory | 304.60 Mb Available Physical Memory | 30.00% Memory free
2.39 Gb Paging File | 1.77 Gb Available in Paging File | 74.04% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27.94 Gb Total Space | 3.73 Gb Free Space | 13.35% Space Free | Partition Type: NTFS
Computer Name: FADIL-LAPTOP | User Name: Fadil Shamir Khan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2012/05/09 22:27:18 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\Downloads\OTL.exe
PRC - [2012/04/25 12:18:26 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/03/06 20:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/03/06 20:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/05/28 12:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol 120%\StarWind\StarWindServiceAE.exe
PRC - [2006/08/10 22:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
PRC - [2006/08/10 16:10:56 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
PRC - [2004/06/17 12:12:40 | 000,409,664 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\ZCfgSvc.exe
PRC - [2004/06/17 12:09:38 | 000,204,800 | ---- | M] (Intel) -- C:\WINDOWS\system32\1XConfig.exe
PRC - [2004/06/17 12:09:10 | 000,303,171 | ---- | M] (Intel Corporation ) -- C:\WINDOWS\system32\S24EvMon.exe
PRC - [2004/06/17 12:07:40 | 000,122,880 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\RegSrvc.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2012/05/09 15:16:26 | 001,756,160 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12050901\algo.dll
MOD - [2012/05/05 00:02:15 | 008,797,856 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
MOD - [2012/04/25 12:18:16 | 001,952,696 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012/01/08 09:41:12 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2010/07/04 17:32:38 | 000,010,752 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll
MOD - [2008/04/14 08:00:00 | 001,288,192 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2008/04/14 08:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2008/04/14 08:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2006/08/10 22:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
MOD - [2006/08/10 16:10:56 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
MOD - [2004/06/17 12:17:42 | 000,045,124 | ---- | M] () -- C:\WINDOWS\system32\LsaWrApi.dll
MOD - [2004/06/17 12:08:24 | 000,225,349 | ---- | M] () -- C:\WINDOWS\system32\C1XStngs.dll
MOD - [2004/05/28 10:13:10 | 000,057,344 | ---- | M] () -- C:\WINDOWS\ATK0100\CMSSC.dll
MOD - [2003/09/24 21:21:48 | 000,147,456 | ---- | M] () -- C:\WINDOWS\system32\ssleay32.dll
MOD - [2003/09/24 21:21:46 | 000,651,264 | ---- | M] () -- C:\WINDOWS\system32\libeay32.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/05/05 00:23:15 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/03/06 20:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Disabled | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2007/05/28 12:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol 120%\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2004/06/17 12:09:10 | 000,303,171 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\WINDOWS\system32\S24EvMon.exe -- (S24EventMonitor)
SRV - [2004/06/17 12:07:40 | 000,122,880 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\system32\RegSrvc.exe -- (RegSrvc)
SRV - [2003/04/29 14:29:54 | 000,139,264 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ss.sys -- (StreamSurge) StreamSurge Driver (miniport)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [File_System | Disabled | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - File not found [Kernel | Auto | Stopped] -- C:\Program Files\LogMeIn\x86\RaInfo.sys -- (LMIInfo)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\Belkin\F5D9050\BKNDIS5.SYS -- (BKNDIS5)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (alo6x4s9)
DRV - [2012/05/09 07:50:39 | 000,015,584 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2012/04/07 22:52:51 | 000,722,416 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2012/03/27 17:03:36 | 006,100,072 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2012/03/06 20:03:51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/03/06 20:03:38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/03/06 20:02:00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012/03/06 20:01:53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/03/06 20:01:39 | 000,095,704 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/03/06 20:01:30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/03/06 19:58:29 | 000,024,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/01/31 21:30:36 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2011/09/16 14:10:50 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2010/07/04 15:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2009/11/18 07:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/18 07:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/13 18:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2005/11/24 19:51:38 | 000,245,248 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt73.sys -- (RT73)
DRV - [2005/04/18 22:21:08 | 000,027,136 | ---- | M] (REDC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\risdptsk.sys -- (risdptsk)
DRV - [2005/02/17 23:07:48 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2005/01/17 22:43:00 | 001,036,928 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2005/01/17 22:43:00 | 000,702,592 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/01/17 22:43:00 | 000,163,328 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2004/12/06 15:51:10 | 000,051,328 | ---- | M] (REDC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2004/06/16 08:01:46 | 002,483,712 | ---- | M] (IntelŪ Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w70n51.sys -- (w70n51) Intel(R)
DRV - [2004/06/09 10:12:48 | 000,010,970 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2003/09/24 21:21:44 | 000,285,056 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2002/11/22 20:01:26 | 000,020,096 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\iqvw32.sys -- (NAL)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig#m_98"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/03 00:58:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/03/29 13:30:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Mozilla\Extensions
[2012/05/03 02:19:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Mozilla\Firefox\Profiles\l0rwv6fr.default\extensions
[2012/05/03 02:18:36 | 000,000,000 | ---D | M] (FB Photo Zoom) -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Mozilla\Firefox\Profiles\l0rwv6fr.default\extensions\fbpz@regisgaughan.com
[2012/04/25 12:18:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/04/20 20:39:37 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/04/25 12:18:28 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/03/30 17:50:33 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/03/30 17:50:33 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/05/03 04:42:02 | 000,002,186 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 3dns.adobe.com
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-1.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-5.adobe.com
O1 - Hosts: 127.0.0.1 hh-software.com
O1 - Hosts: 127.0.0.1 www.hh-software.com
O1 - Hosts: 25 more lines...
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe ()
O4 - HKLM..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ZCfgSvc.exe] C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol 120%\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [DriverMax_RESTART] C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9F4FD520-AB94-4BE4-8EE3-965204C1D57E}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\Sebring: DllName - (C:\WINDOWS\system32\LgNotify.dll) - C:\WINDOWS\system32\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/03/29 12:28:37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012/05/09 22:21:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\RootRepeal
[2012/05/09 08:01:51 | 000,000,000 | ---D | C] -- C:\f5d9050v3000
[2012/05/09 07:50:37 | 000,790,528 | ---- | C] (Motorola Inc.) -- C:\WINDOWS\System32\BCMWLCPL.CPL
[2012/05/09 07:50:05 | 000,144,776 | ---- | C] (Motorola Inc.) -- C:\WINDOWS\System32\BCMWLU00.EXE
[2012/05/09 07:50:05 | 000,057,344 | ---- | C] (Motorola Inc.) -- C:\WINDOWS\System32\BCMWLD2K.EXE
[2012/05/09 07:21:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Latest
[2012/05/08 18:24:57 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/05/08 18:03:00 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Recent
[2012/05/08 17:25:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Malwarebytes
[2012/05/08 17:24:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/05/06 15:25:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/05/06 15:22:26 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/05/06 15:21:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/05/03 17:18:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Maher Zain - Forgive Me 2012
[2012/05/03 00:58:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2012/05/03 00:56:23 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012/05/02 14:02:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Web & Graphic Desgin
[2012/05/02 14:02:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Notes
[2012/05/01 18:33:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinSCP
[2012/05/01 18:33:10 | 000,000,000 | ---D | C] -- C:\Program Files\WinSCP
[2012/04/29 10:30:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Cranium_Consulting_and_Cu
[2012/04/29 09:57:19 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2012/04/29 09:56:00 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/04/29 09:55:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2012/04/28 09:54:03 | 000,000,000 | ---D | C] -- C:\Program Files\Cyder
[2012/04/26 18:43:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2012/04/26 18:41:42 | 000,030,592 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIport.dll
[2012/04/26 18:41:40 | 000,083,360 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIRfsClientNP.dll
[2012/04/26 18:41:40 | 000,047,640 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\drivers\LMIRfsDriver.sys
[2012/04/26 18:40:55 | 000,087,424 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIinit.dll
[2012/04/26 18:39:21 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn
[2012/04/25 22:26:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2012/04/25 22:24:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2012/04/25 22:23:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2012/04/25 22:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2012/04/25 22:07:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2012/04/25 22:04:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/04/25 22:03:10 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012/04/25 20:11:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Apple Computer
[2012/04/25 15:26:30 | 000,359,016 | ---- | C] (Realtek Semiconductor Crop.) -- C:\WINDOWS\vncutil.exe
[2012/04/25 15:26:21 | 001,691,480 | ---- | C] (Creative) -- C:\WINDOWS\System32\drivers\Ambfilt.sys
[2012/04/25 15:26:19 | 000,129,640 | ---- | C] (Realtek Semiconductor) -- C:\WINDOWS\RtkAudioService.exe
[2012/04/25 15:20:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2012/04/25 15:20:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\iPhone Hacking
[2012/04/25 12:18:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/04/24 05:33:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Microsoft Help
[2012/04/24 05:32:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2012/04/24 05:21:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Alcohol 120%
[2012/04/24 05:20:24 | 000,000,000 | ---D | C] -- C:\Program Files\Alcohol 120%
[2012/04/23 20:57:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Unity
[2012/04/23 17:16:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\RockMelt
[2012/04/22 19:33:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/04/22 07:01:35 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2012/04/22 04:51:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/04/22 04:51:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Anvsoft
[2012/04/22 04:51:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Wedding Album Maker
[2012/04/22 04:48:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Start Menu\Programs\Wedding Album Maker Gold
[2012/04/22 04:48:13 | 000,000,000 | ---D | C] -- C:\Program Files\Wedding Album Maker Gold
[2012/04/22 04:39:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Cocoon Software
[2012/04/22 04:39:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\WDSetup
[2012/04/21 21:22:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Google
[2012/04/21 14:06:07 | 000,000,000 | ---D | C] -- C:\Program Files\WinHTTrack Website Copier
[2012/04/21 14:05:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\ApplicationHistory
[2012/04/21 13:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\Website Ripper Copier
[2012/04/21 13:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Start Menu\Programs\Website Ripper Copier
[2012/04/21 13:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\Website Ripper Copier
[2012/04/21 13:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Website Ripper Copier
[2012/04/21 13:30:39 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2012/04/21 13:30:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2012/04/21 13:30:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTemp
[2012/04/21 08:48:18 | 000,000,000 | ---D | C] -- C:\Program Files\Network Magic
[2012/04/21 08:42:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2012/04/21 04:35:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2012/04/20 20:40:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\.shsh
[2012/04/20 20:40:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012/04/20 20:40:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/04/20 20:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/04/20 19:56:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Sun
[2012/04/20 19:29:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\libimobiledevice
[2012/04/19 05:01:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\redsn0w
[2012/04/17 18:29:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Identities
[2012/04/17 18:27:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe
[2012/04/13 03:36:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\FileZilla
[2012/04/13 03:35:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Start Menu\Programs\FileZilla FTP Client
[2012/04/13 03:35:54 | 000,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012/05/09 22:22:01 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/05/09 22:07:03 | 000,000,908 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/09 21:28:47 | 000,000,904 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/09 21:28:12 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/09 09:04:47 | 000,035,894 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\irclogo.jpg
[2012/05/09 09:04:39 | 000,220,875 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Logo.psd
[2012/05/09 07:49:03 | 000,036,570 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sick.jpg
[2012/05/09 07:11:19 | 000,392,864 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/05/09 07:11:19 | 000,058,998 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/05/08 18:15:16 | 000,011,052 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\Registry Backup.reg
[2012/05/08 16:38:55 | 000,606,099 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\UntoldAdSenseFacts.pdf
[2012/05/08 16:00:04 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/08 03:30:47 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\winscp.rnd
[2012/05/06 15:51:35 | 000,081,006 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\bg.jpg
[2012/05/04 06:32:53 | 000,023,470 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sparktechtt.png
[2012/05/04 06:32:53 | 000,000,132 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Adobe PNG Format CS5 Prefs
[2012/05/04 06:31:12 | 000,401,016 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sparktechtt.psd
[2012/05/04 05:45:08 | 000,016,604 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\fixed_logo.png
[2012/05/04 05:44:59 | 000,134,370 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\hotshots logo.psd
[2012/05/03 04:42:02 | 000,002,186 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/05/02 19:07:58 | 000,001,145 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\CleanTemp.bat
[2012/04/30 12:02:57 | 002,347,656 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/04/25 20:52:34 | 000,000,740 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Microsoft\Internet Explorer\Quick Launch\Outlook Express.lnk
[2012/04/25 16:44:16 | 000,000,060 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\.NET Framework Checker.bat
[2012/04/25 16:39:43 | 000,000,212 | RHS- | M] () -- C:\boot.ini
[2012/04/23 19:37:19 | 000,020,428 | ---- | M] () -- C:\WINDOWS\System32\35.exe
[2012/04/23 09:07:51 | 000,008,704 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/22 18:55:47 | 000,001,456 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
[2012/04/22 06:40:30 | 000,000,028 | ---- | M] () -- C:\WINDOWS\v2d.INI
[2012/04/21 08:46:48 | 008,892,928 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012/05/09 09:04:47 | 000,035,894 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\irclogo.jpg
[2012/05/09 09:04:38 | 000,220,875 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Logo.psd
[2012/05/09 07:50:38 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2012/05/09 07:50:37 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2012/05/09 07:49:02 | 000,036,570 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sick.jpg
[2012/05/08 16:38:54 | 000,606,099 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\UntoldAdSenseFacts.pdf
[2012/05/06 15:51:33 | 000,081,006 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\bg.jpg
[2012/05/04 06:31:22 | 000,023,470 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sparktechtt.png
[2012/05/04 06:31:11 | 000,401,016 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sparktechtt.psd
[2012/05/04 05:45:07 | 000,016,604 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\fixed_logo.png
[2012/05/04 04:51:08 | 000,134,370 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\hotshots logo.psd
[2012/05/01 18:33:17 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\winscp.rnd
[2012/04/25 20:52:34 | 000,000,740 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Microsoft\Internet Explorer\Quick Launch\Outlook Express.lnk
[2012/04/25 16:44:16 | 000,000,060 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\.NET Framework Checker.bat
[2012/04/23 19:37:19 | 000,020,428 | ---- | C] () -- C:\WINDOWS\System32\35.exe
[2012/04/22 18:37:06 | 000,001,456 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
[2012/04/22 04:30:20 | 000,000,028 | ---- | C] () -- C:\WINDOWS\v2d.INI
[2012/04/21 08:46:45 | 008,892,928 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi
[2012/04/21 03:16:20 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/04/20 11:35:19 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Adobe PNG Format CS5 Prefs
[2012/04/08 05:55:45 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/07 22:54:08 | 000,162,634 | ---- | C] () -- C:\WINDOWS\FotoFusion Uninstaller.exe
[2012/03/30 01:52:18 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4670.dll
[2012/03/30 00:25:29 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2012/03/29 17:21:12 | 000,003,472 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/03/29 17:05:06 | 000,021,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTAIODAT.DAT
[2012/03/29 13:30:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2012/03/29 12:31:34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/03/29 12:25:08 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/03/29 12:18:21 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/03/29 12:16:51 | 002,347,656 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/29 10:46:58 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[color=#E56717]========== LOP Check ==========[/color]
[2012/04/22 04:51:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Anvsoft
[2012/03/29 16:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/03/30 18:33:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
[2012/04/21 19:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2012/04/22 04:59:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/03/29 13:24:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2012/04/08 18:45:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/22 19:33:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/04/22 04:39:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Cocoon Software
[2012/05/09 22:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\FileZilla
[2012/03/30 01:07:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\iolo
[2012/05/07 06:20:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\redsn0w
[2012/04/08 09:16:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/05/08 18:03:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\uTorrent
[2012/04/22 04:51:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Wedding Album Maker
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6C3B8FB5
< End of report >
ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2012/05/09 22:23 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== SSDT ------------------- #: 009 Function Name: NtAddBootEntry Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefdf8 #: 017 Function Name: NtAllocateVirtualMemory Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7ca5a #: 019 Function Name: NtAssignProcessToJobObject Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf085e #: 025 Function Name: NtClose Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1cd5d #: 035 Function Name: NtCreateEvent Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf52e4 #: 036 Function Name: NtCreateEventPair Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5330 #: 038 Function Name: NtCreateIoCompletion Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5422 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1c711 #: 043 Function Name: NtCreateMutant Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5252 #: 050 Function Name: NtCreateSection Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5374 #: 051 Function Name: NtCreateSemaphore Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf529a #: 054 Function Name: NtCreateTimer Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf53dc #: 061 Function Name: NtDeleteBootEntry Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefe44 #: 063 Function Name: NtDeleteKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d423 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d6d9 #: 068 Function Name: NtDuplicateObject Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf29a8 #: 071 Function Name: NtEnumerateKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d28e #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d0f9 #: 083 Function Name: NtFreeVirtualMemory Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7cb34 #: 097 Function Name: NtLoadDriver Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefad6 #: 109 Function Name: NtModifyBootEntry Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefe90 #: 111 Function Name: NtNotifyChangeKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf2d1c #: 112 Function Name: NtNotifyChangeMultipleKeys Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf0b02 #: 114 Function Name: NtOpenEvent Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf530e #: 115 Function Name: NtOpenEventPair Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5352 #: 117 Function Name: NtOpenIoCompletion Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5446 #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1ca6d #: 120 Function Name: NtOpenMutant Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5278 #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf2518 #: 125 Function Name: NtOpenSection Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf53ae #: 126 Function Name: NtOpenSemaphore Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf52c2 #: 128 Function Name: NtOpenThread Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf274c #: 131 Function Name: NtOpenTimer Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5400 #: 137 Function Name: NtProtectVirtualMemory Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7cca0 #: 160 Function Name: NtQueryKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1cf74 #: 163 Function Name: NtQueryObject Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf09ce #: 177 Function Name: NtQueryValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1cdc6 #: 192 Function Name: NtRenameKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d86b68 #: 204 Function Name: NtRestoreKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1bd84 #: 211 Function Name: NtSetBootEntryOrder Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefedc #: 212 Function Name: NtSetBootOptions Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9ceff28 #: 240 Function Name: NtSetSystemInformation Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefb46 #: 241 Function Name: NtSetSystemPowerState Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefcea #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d52a #: 249 Function Name: NtShutdownSystem Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefc92 #: 255 Function Name: NtSystemDebugControl Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefd5a #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7cd60 #: 268 Function Name: NtVdmControl Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9ceff74 #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7cbe0 Stealth Objects ------------------- Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_CREATE] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_CLOSE] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_POWER] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_PNP] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_CREATE] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_CLOSE] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_READ] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_SET_INFORMATION] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_SHUTDOWN] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_CLEANUP] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_PNP] Process: System Address: 0x85b6d500 Size: 121 ==EOF==

