I have managed to kill those processes and delete the folder now, but I would just like to know if I am clean.
Please let me know...
My OTL Results are below just in case as well as my RootReapel Report.
Thanks in advanced...
OTL logfile created on: 5/9/2012 10:29:50 PM - Run 1 OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Fadil Shamir Khan\My Documents\Downloads Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1015.17 Mb Total Physical Memory | 304.60 Mb Available Physical Memory | 30.00% Memory free 2.39 Gb Paging File | 1.77 Gb Available in Paging File | 74.04% Paging File free Paging file location(s): C:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 27.94 Gb Total Space | 3.73 Gb Free Space | 13.35% Space Free | Partition Type: NTFS Computer Name: FADIL-LAPTOP | User Name: Fadil Shamir Khan | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/05/09 22:27:18 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\Downloads\OTL.exe PRC - [2012/04/25 12:18:26 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012/03/06 20:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012/03/06 20:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2008/04/14 08:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/05/28 12:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol 120%\StarWind\StarWindServiceAE.exe PRC - [2006/08/10 22:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe PRC - [2006/08/10 16:10:56 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe PRC - [2004/06/17 12:12:40 | 000,409,664 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\ZCfgSvc.exe PRC - [2004/06/17 12:09:38 | 000,204,800 | ---- | M] (Intel) -- C:\WINDOWS\system32\1XConfig.exe PRC - [2004/06/17 12:09:10 | 000,303,171 | ---- | M] (Intel Corporation ) -- C:\WINDOWS\system32\S24EvMon.exe PRC - [2004/06/17 12:07:40 | 000,122,880 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\RegSrvc.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012/05/09 15:16:26 | 001,756,160 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12050901\algo.dll MOD - [2012/05/05 00:02:15 | 008,797,856 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll MOD - [2012/04/25 12:18:16 | 001,952,696 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2012/01/08 09:41:12 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll MOD - [2010/07/04 17:32:38 | 000,010,752 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll MOD - [2008/04/14 08:00:00 | 001,288,192 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll MOD - [2008/04/14 08:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll MOD - [2008/04/14 08:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2006/08/10 22:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe MOD - [2006/08/10 16:10:56 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe MOD - [2004/06/17 12:17:42 | 000,045,124 | ---- | M] () -- C:\WINDOWS\system32\LsaWrApi.dll MOD - [2004/06/17 12:08:24 | 000,225,349 | ---- | M] () -- C:\WINDOWS\system32\C1XStngs.dll MOD - [2004/05/28 10:13:10 | 000,057,344 | ---- | M] () -- C:\WINDOWS\ATK0100\CMSSC.dll MOD - [2003/09/24 21:21:48 | 000,147,456 | ---- | M] () -- C:\WINDOWS\system32\ssleay32.dll MOD - [2003/09/24 21:21:46 | 000,651,264 | ---- | M] () -- C:\WINDOWS\system32\libeay32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012/05/05 00:23:15 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/03/06 20:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Disabled | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2007/05/28 12:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol 120%\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE) SRV - [2004/06/17 12:09:10 | 000,303,171 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\WINDOWS\system32\S24EvMon.exe -- (S24EventMonitor) SRV - [2004/06/17 12:07:40 | 000,122,880 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\system32\RegSrvc.exe -- (RegSrvc) SRV - [2003/04/29 14:29:54 | 000,139,264 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ss.sys -- (StreamSurge) StreamSurge Driver (miniport) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [File_System | Disabled | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - File not found [Kernel | Auto | Stopped] -- C:\Program Files\LogMeIn\x86\RaInfo.sys -- (LMIInfo) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\Belkin\F5D9050\BKNDIS5.SYS -- (BKNDIS5) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (alo6x4s9) DRV - [2012/05/09 07:50:39 | 000,015,584 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x) DRV - [2012/04/07 22:52:51 | 000,722,416 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2012/03/27 17:03:36 | 006,100,072 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2012/03/06 20:03:51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012/03/06 20:03:38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012/03/06 20:02:00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012/03/06 20:01:53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012/03/06 20:01:39 | 000,095,704 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012/03/06 20:01:30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012/03/06 19:58:29 | 000,024,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012/01/31 21:30:36 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP) DRV - [2011/09/16 14:10:50 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver) DRV - [2010/07/04 15:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5) DRV - [2009/11/18 07:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009/11/18 07:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2008/04/13 18:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C) DRV - [2005/11/24 19:51:38 | 000,245,248 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt73.sys -- (RT73) DRV - [2005/04/18 22:21:08 | 000,027,136 | ---- | M] (REDC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\risdptsk.sys -- (risdptsk) DRV - [2005/02/17 23:07:48 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2005/01/17 22:43:00 | 001,036,928 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP) DRV - [2005/01/17 22:43:00 | 000,702,592 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2005/01/17 22:43:00 | 000,163,328 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL) DRV - [2004/12/06 15:51:10 | 000,051,328 | ---- | M] (REDC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk) DRV - [2004/06/16 08:01:46 | 002,483,712 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w70n51.sys -- (w70n51) Intel(R) DRV - [2004/06/09 10:12:48 | 000,010,970 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans) DRV - [2003/09/24 21:21:44 | 000,285,056 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX) DRV - [2002/11/22 20:01:26 | 000,020,096 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\iqvw32.sys -- (NAL) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig#m_98" FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/03 00:58:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/29 13:30:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Mozilla\Extensions [2012/05/03 02:19:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Mozilla\Firefox\Profiles\l0rwv6fr.default\extensions [2012/05/03 02:18:36 | 000,000,000 | ---D | M] (FB Photo Zoom) -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Mozilla\Firefox\Profiles\l0rwv6fr.default\extensions\[email protected] [2012/04/25 12:18:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012/04/20 20:39:37 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2012/04/25 12:18:28 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012/03/30 17:50:33 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2012/03/30 17:50:33 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml O1 HOSTS File: ([2012/05/03 04:42:02 | 000,002,186 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com O1 - Hosts: 127.0.0.1 adobeereg.com O1 - Hosts: 127.0.0.1 activate.adobe.com O1 - Hosts: 127.0.0.1 practivate.adobe.com O1 - Hosts: 127.0.0.1 ereg.adobe.com O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com O1 - Hosts: 127.0.0.1 wip3.adobe.com O1 - Hosts: 127.0.0.1 activate-sea.adobe.com O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com O1 - Hosts: 127.0.0.1 3dns.adobe.com O1 - Hosts: 127.0.0.1 3dns-1.adobe.com O1 - Hosts: 127.0.0.1 3dns-2.adobe.com O1 - Hosts: 127.0.0.1 3dns-3.adobe.com O1 - Hosts: 127.0.0.1 3dns-4.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-1.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-4.adobe.com O1 - Hosts: 127.0.0.1 adobe-dns-5.adobe.com O1 - Hosts: 127.0.0.1 hh-software.com O1 - Hosts: 127.0.0.1 www.hh-software.com O1 - Hosts: 25 more lines... O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe () O4 - HKLM..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe (Intel(R) Corporation) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [ZCfgSvc.exe] C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation) O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol 120%\axcmd.exe (Alcohol Soft Development Team) O4 - HKCU..\Run: [DriverMax_RESTART] C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe (Innovative Solutions) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9F4FD520-AB94-4BE4-8EE3-965204C1D57E}: DhcpNameServer = 192.168.1.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.) O20 - Winlogon\Notify\Sebring: DllName - (C:\WINDOWS\system32\LgNotify.dll) - C:\WINDOWS\system32\LgNotify.dll (Intel Corporation) O24 - Desktop WallPaper: C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012/03/29 12:28:37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/05/09 22:21:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\RootRepeal [2012/05/09 08:01:51 | 000,000,000 | ---D | C] -- C:\f5d9050v3000 [2012/05/09 07:50:37 | 000,790,528 | ---- | C] (Motorola Inc.) -- C:\WINDOWS\System32\BCMWLCPL.CPL [2012/05/09 07:50:05 | 000,144,776 | ---- | C] (Motorola Inc.) -- C:\WINDOWS\System32\BCMWLU00.EXE [2012/05/09 07:50:05 | 000,057,344 | ---- | C] (Motorola Inc.) -- C:\WINDOWS\System32\BCMWLD2K.EXE [2012/05/09 07:21:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Latest [2012/05/08 18:24:57 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012/05/08 18:03:00 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Recent [2012/05/08 17:25:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Malwarebytes [2012/05/08 17:24:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2012/05/06 15:25:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes [2012/05/06 15:22:26 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012/05/06 15:21:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012/05/03 17:18:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Maher Zain - Forgive Me 2012 [2012/05/03 00:58:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime [2012/05/03 00:56:23 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime [2012/05/02 14:02:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Web & Graphic Desgin [2012/05/02 14:02:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Notes [2012/05/01 18:33:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinSCP [2012/05/01 18:33:10 | 000,000,000 | ---D | C] -- C:\Program Files\WinSCP [2012/04/29 10:30:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Cranium_Consulting_and_Cu [2012/04/29 09:57:19 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update [2012/04/29 09:56:00 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2012/04/29 09:55:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple [2012/04/28 09:54:03 | 000,000,000 | ---D | C] -- C:\Program Files\Cyder [2012/04/26 18:43:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution [2012/04/26 18:41:42 | 000,030,592 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIport.dll [2012/04/26 18:41:40 | 000,083,360 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIRfsClientNP.dll [2012/04/26 18:41:40 | 000,047,640 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\drivers\LMIRfsDriver.sys [2012/04/26 18:40:55 | 000,087,424 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\LMIinit.dll [2012/04/26 18:39:21 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn [2012/04/25 22:26:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office [2012/04/25 22:24:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works [2012/04/25 22:23:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio [2012/04/25 22:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER [2012/04/25 22:07:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW [2012/04/25 22:04:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office [2012/04/25 22:03:10 | 000,000,000 | RH-D | C] -- C:\MSOCache [2012/04/25 20:11:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Apple Computer [2012/04/25 15:26:30 | 000,359,016 | ---- | C] (Realtek Semiconductor Crop.) -- C:\WINDOWS\vncutil.exe [2012/04/25 15:26:21 | 001,691,480 | ---- | C] (Creative) -- C:\WINDOWS\System32\drivers\Ambfilt.sys [2012/04/25 15:26:19 | 000,129,640 | ---- | C] (Realtek Semiconductor) -- C:\WINDOWS\RtkAudioService.exe [2012/04/25 15:20:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel [2012/04/25 15:20:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\iPhone Hacking [2012/04/25 12:18:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla [2012/04/24 05:33:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Microsoft Help [2012/04/24 05:32:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help [2012/04/24 05:21:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Alcohol 120% [2012/04/24 05:20:24 | 000,000,000 | ---D | C] -- C:\Program Files\Alcohol 120% [2012/04/23 20:57:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Unity [2012/04/23 17:16:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\RockMelt [2012/04/22 19:33:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2012/04/22 07:01:35 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF [2012/04/22 04:51:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP [2012/04/22 04:51:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Anvsoft [2012/04/22 04:51:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Wedding Album Maker [2012/04/22 04:48:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Start Menu\Programs\Wedding Album Maker Gold [2012/04/22 04:48:13 | 000,000,000 | ---D | C] -- C:\Program Files\Wedding Album Maker Gold [2012/04/22 04:39:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Cocoon Software [2012/04/22 04:39:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\WDSetup [2012/04/21 21:22:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Google [2012/04/21 14:06:07 | 000,000,000 | ---D | C] -- C:\Program Files\WinHTTrack Website Copier [2012/04/21 14:05:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\ApplicationHistory [2012/04/21 13:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\Website Ripper Copier [2012/04/21 13:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Start Menu\Programs\Website Ripper Copier [2012/04/21 13:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\Website Ripper Copier [2012/04/21 13:32:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Website Ripper Copier [2012/04/21 13:30:39 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly [2012/04/21 13:30:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET [2012/04/21 13:30:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTemp [2012/04/21 08:48:18 | 000,000,000 | ---D | C] -- C:\Program Files\Network Magic [2012/04/21 08:42:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun [2012/04/21 04:35:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth [2012/04/20 20:40:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\.shsh [2012/04/20 20:40:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun [2012/04/20 20:40:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2012/04/20 20:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2012/04/20 19:56:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Sun [2012/04/20 19:29:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\libimobiledevice [2012/04/19 05:01:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\redsn0w [2012/04/17 18:29:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Identities [2012/04/17 18:27:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe [2012/04/13 03:36:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\FileZilla [2012/04/13 03:35:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Fadil Shamir Khan\Start Menu\Programs\FileZilla FTP Client [2012/04/13 03:35:54 | 000,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/05/09 22:22:01 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012/05/09 22:07:03 | 000,000,908 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012/05/09 21:28:47 | 000,000,904 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012/05/09 21:28:12 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/05/09 09:04:47 | 000,035,894 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\irclogo.jpg [2012/05/09 09:04:39 | 000,220,875 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Logo.psd [2012/05/09 07:49:03 | 000,036,570 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sick.jpg [2012/05/09 07:11:19 | 000,392,864 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012/05/09 07:11:19 | 000,058,998 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012/05/08 18:15:16 | 000,011,052 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\Registry Backup.reg [2012/05/08 16:38:55 | 000,606,099 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\UntoldAdSenseFacts.pdf [2012/05/08 16:00:04 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/05/08 03:30:47 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\winscp.rnd [2012/05/06 15:51:35 | 000,081,006 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\bg.jpg [2012/05/04 06:32:53 | 000,023,470 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sparktechtt.png [2012/05/04 06:32:53 | 000,000,132 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Adobe PNG Format CS5 Prefs [2012/05/04 06:31:12 | 000,401,016 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sparktechtt.psd [2012/05/04 05:45:08 | 000,016,604 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\fixed_logo.png [2012/05/04 05:44:59 | 000,134,370 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\hotshots logo.psd [2012/05/03 04:42:02 | 000,002,186 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2012/05/02 19:07:58 | 000,001,145 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\CleanTemp.bat [2012/04/30 12:02:57 | 002,347,656 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012/04/25 20:52:34 | 000,000,740 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Microsoft\Internet Explorer\Quick Launch\Outlook Express.lnk [2012/04/25 16:44:16 | 000,000,060 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\.NET Framework Checker.bat [2012/04/25 16:39:43 | 000,000,212 | RHS- | M] () -- C:\boot.ini [2012/04/23 19:37:19 | 000,020,428 | ---- | M] () -- C:\WINDOWS\System32\35.exe [2012/04/23 09:07:51 | 000,008,704 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/04/22 18:55:47 | 000,001,456 | ---- | M] () -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs [2012/04/22 06:40:30 | 000,000,028 | ---- | M] () -- C:\WINDOWS\v2d.INI [2012/04/21 08:46:48 | 008,892,928 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012/05/09 09:04:47 | 000,035,894 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\irclogo.jpg [2012/05/09 09:04:38 | 000,220,875 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\Logo.psd [2012/05/09 07:50:38 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe [2012/05/09 07:50:37 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE [2012/05/09 07:49:02 | 000,036,570 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sick.jpg [2012/05/08 16:38:54 | 000,606,099 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\UntoldAdSenseFacts.pdf [2012/05/06 15:51:33 | 000,081,006 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\My Documents\bg.jpg [2012/05/04 06:31:22 | 000,023,470 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sparktechtt.png [2012/05/04 06:31:11 | 000,401,016 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\sparktechtt.psd [2012/05/04 05:45:07 | 000,016,604 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\fixed_logo.png [2012/05/04 04:51:08 | 000,134,370 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\hotshots logo.psd [2012/05/01 18:33:17 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\winscp.rnd [2012/04/25 20:52:34 | 000,000,740 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Microsoft\Internet Explorer\Quick Launch\Outlook Express.lnk [2012/04/25 16:44:16 | 000,000,060 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Desktop\.NET Framework Checker.bat [2012/04/23 19:37:19 | 000,020,428 | ---- | C] () -- C:\WINDOWS\System32\35.exe [2012/04/22 18:37:06 | 000,001,456 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs [2012/04/22 04:30:20 | 000,000,028 | ---- | C] () -- C:\WINDOWS\v2d.INI [2012/04/21 08:46:45 | 008,892,928 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\atscie.msi [2012/04/21 03:16:20 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk [2012/04/20 11:35:19 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Adobe PNG Format CS5 Prefs [2012/04/08 05:55:45 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\Fadil Shamir Khan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/04/07 22:54:08 | 000,162,634 | ---- | C] () -- C:\WINDOWS\FotoFusion Uninstaller.exe [2012/03/30 01:52:18 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4670.dll [2012/03/30 00:25:29 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll [2012/03/29 17:21:12 | 000,003,472 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2012/03/29 17:05:06 | 000,021,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTAIODAT.DAT [2012/03/29 13:30:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2012/03/29 12:31:34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2012/03/29 12:25:08 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2012/03/29 12:18:21 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2012/03/29 12:16:51 | 002,347,656 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011/12/29 10:46:58 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll [color=#E56717]========== LOP Check ==========[/color] [2012/04/22 04:51:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Anvsoft [2012/03/29 16:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software [2012/03/30 18:33:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo [2012/04/21 19:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe [2012/04/22 04:59:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2012/03/29 13:24:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip [2012/04/08 18:45:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2012/04/22 19:33:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2012/04/22 04:39:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Cocoon Software [2012/05/09 22:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\FileZilla [2012/03/30 01:07:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\iolo [2012/05/07 06:20:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\redsn0w [2012/04/08 09:16:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2012/05/08 18:03:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\uTorrent [2012/04/22 04:51:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fadil Shamir Khan\Application Data\Wedding Album Maker [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6C3B8FB5 < End of report >
ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2012/05/09 22:23 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== SSDT ------------------- #: 009 Function Name: NtAddBootEntry Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefdf8 #: 017 Function Name: NtAllocateVirtualMemory Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7ca5a #: 019 Function Name: NtAssignProcessToJobObject Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf085e #: 025 Function Name: NtClose Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1cd5d #: 035 Function Name: NtCreateEvent Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf52e4 #: 036 Function Name: NtCreateEventPair Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5330 #: 038 Function Name: NtCreateIoCompletion Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5422 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1c711 #: 043 Function Name: NtCreateMutant Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5252 #: 050 Function Name: NtCreateSection Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5374 #: 051 Function Name: NtCreateSemaphore Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf529a #: 054 Function Name: NtCreateTimer Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf53dc #: 061 Function Name: NtDeleteBootEntry Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefe44 #: 063 Function Name: NtDeleteKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d423 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d6d9 #: 068 Function Name: NtDuplicateObject Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf29a8 #: 071 Function Name: NtEnumerateKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d28e #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d0f9 #: 083 Function Name: NtFreeVirtualMemory Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7cb34 #: 097 Function Name: NtLoadDriver Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefad6 #: 109 Function Name: NtModifyBootEntry Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefe90 #: 111 Function Name: NtNotifyChangeKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf2d1c #: 112 Function Name: NtNotifyChangeMultipleKeys Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf0b02 #: 114 Function Name: NtOpenEvent Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf530e #: 115 Function Name: NtOpenEventPair Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5352 #: 117 Function Name: NtOpenIoCompletion Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5446 #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1ca6d #: 120 Function Name: NtOpenMutant Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5278 #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf2518 #: 125 Function Name: NtOpenSection Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf53ae #: 126 Function Name: NtOpenSemaphore Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf52c2 #: 128 Function Name: NtOpenThread Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf274c #: 131 Function Name: NtOpenTimer Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf5400 #: 137 Function Name: NtProtectVirtualMemory Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7cca0 #: 160 Function Name: NtQueryKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1cf74 #: 163 Function Name: NtQueryObject Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cf09ce #: 177 Function Name: NtQueryValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1cdc6 #: 192 Function Name: NtRenameKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d86b68 #: 204 Function Name: NtRestoreKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1bd84 #: 211 Function Name: NtSetBootEntryOrder Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefedc #: 212 Function Name: NtSetBootOptions Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9ceff28 #: 240 Function Name: NtSetSystemInformation Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefb46 #: 241 Function Name: NtSetSystemPowerState Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefcea #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9d1d52a #: 249 Function Name: NtShutdownSystem Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefc92 #: 255 Function Name: NtSystemDebugControl Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9cefd5a #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7cd60 #: 268 Function Name: NtVdmControl Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSnx.SYS" at address 0xa9ceff74 #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa9d7cbe0 Stealth Objects ------------------- Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x863d91f8 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_CREATE] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_CLOSE] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_POWER] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: alo6x4s9???????????????, IRP_MJ_PNP] Process: System Address: 0x861ce500 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP] Process: System Address: 0x861cd1f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP] Process: System Address: 0x86324500 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP] Process: System Address: 0x8636d1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP] Process: System Address: 0x860a51f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP] Process: System Address: 0x861de1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP] Process: System Address: 0x8605b1f8 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_CREATE] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_CLOSE] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_READ] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_SET_INFORMATION] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_SHUTDOWN] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_CLEANUP] Process: System Address: 0x85b6d500 Size: 121 Object: Hidden Code [Driver: Cdfs????FsWrap, IRP_MJ_PNP] Process: System Address: 0x85b6d500 Size: 121 ==EOF==