PDA

View Full Version : Win32.TDSS.rtk



Devil2U
2009-08-13, 07:53
So I had Spyboy S&D 1.6.2 running and it was the only app (AVG & Ad-aware failed) to locate the nasty Win32.TDSS.rtk
This forum looks like the place to go to get it removed and I thank you for your help in advance. Here is my HJ scan log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:41:02 PM, on 8/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yapta\YaptaClient.exe
C:\Program Files\USB Stress Panic Button\USB Stress Panic Button.exe
C:\Program Files\USB Electronic Scale\scale.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\kmw_run.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Wootalyzer\woot.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\ZyDAS Technology Corporation\ZyDAS Wireless LAN\ZDConfig.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\BOINC\boinc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\User\Desktop\troj removal\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 165.228.131.12:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O3 - Toolbar: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Yapta Tracker] C:\Program Files\Yapta\YaptaClient.exe /onstartup
O4 - HKLM\..\Run: [USB Stress Panic Button] C:\Program Files\USB Stress Panic Button\USB Stress Panic Button.exe -liuhong
O4 - HKLM\..\Run: [USB Electronic Scale] C:\Program Files\USB Electronic Scale\scale /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Free-1] "C:\Program Files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe"
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Advanced LAN Pump] C:\Program Files\SoftSolo\Advanced LAN Pump\alp.exe autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acronis†True†Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Wootalyzer] "C:\Program Files\Wootalyzer\woot.exe" /boot
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "d:\games\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [PMCLoader] C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Logo Calibration Loader.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe
O4 - Global Startup: ProfileReminder.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: ZDConfig.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS Wireless LAN\ZDConfig.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} (STCWeb Control) - STCWeb.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} (DyynoX Class) - http://stage.dyyno.com/tng/dyyno-client/DyynoCAB.1.0.0.25.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228473500921
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {79E54B26-46B9-40EF-BFDC-0B1BB0D68897} - http://www.piclens.com/shared/plinstll.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://67.114.242.171/activex/AxisCamControl.ocx
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp.coupons.com/r3302/GeneralElectric/Coupons.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.lan1.instantaction.com/download/iaplayer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15029/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\system32\DPWLEvHd.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\\agent.exe

--
End of file - 17257 bytes

Shaba
2009-08-16, 08:47
Hi Devil2U

Download gmer.zip (http://gmer.net/gmer.zip) and save to your desktop.
alternate download site (http://hype.free.googlepages.com/gmer.zip)

Unzip/extract the file to its own folder. (Click here (http://www.bleepingcomputer.com/tutorials/tutorial105.html) for information on how to do this if not sure. Win 2000 users click here (http://www.bleepingcomputer.com/tutorials/tutorial106.html).
When you have done this, disconnect from the Internet and close all running programs.
There is a small chance this application may crash your computer so save any work you have open.
Double-click on Gmer.exe to start the program.
Allow the gmer.sys driver to load if asked.
If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
Click on the Rootkit tab.
Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
Click on the "Scan" and wait for the scan to finish.
Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
Note: If you have any problems, try running GMER in SAFE MODE (http://www.bleepingcomputer.com/forums/tutorial61.html)"
Important! Please do not select the "Show all" checkbox during the scan..

Devil2U
2009-08-16, 10:55
Thanks Shada,
Here is my Gmer log (its quite long, so I had to split it up into multiple replyies):

GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-16 00:32:10
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

Code 8A4CAE80 ZwEnumerateKey
Code 8A4C8EF8 ZwFlushInstructionCache
Code 8A4CCE16 IofCallDriver
Code 8A4CDE2E IofCompleteRequest

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 8A4CCE1B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 8A4CDE33
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload B6A448AC 5 Bytes JMP 8B7FA1C8
? System32\Drivers\azf2egny.SYS The system cannot find the path specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[348] ntdll.dll!LdrLoadDll 7C9163C3 3 Bytes JMP 0092000A
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[348] ntdll.dll!LdrLoadDll + 4 7C9163C7 1 Byte [84]
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[448] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003C000A
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[664] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003C000A
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[944] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0071000A
.text ...

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EC0AD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EC0C1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EC0B9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EC1748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EC161E] sptd.sys

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 8BA491E8
Device \FileSystem\Fastfat \FatCdrom 88A297A0
Device \FileSystem\Udfs \UdfsCdRom 88EA57A0
Device \FileSystem\Udfs \UdfsDisk 88EA57A0
Device \Driver\nvata \Device\0000009c 8BABC1E8

AttachedDevice \Driver\Tcpip \Device\Ip NVTcp.sys (NVIDIA Networking Protocol Driver./NVIDIA Corporation)

Device \Driver\usbohci \Device\USBPDO-0 8B72E7A0
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8BABD1E8
Device \Driver\dmio \Device\DmControl\DmConfig 8BABD1E8
Device \Driver\dmio \Device\DmControl\DmPnP 8BABD1E8
Device \Driver\dmio \Device\DmControl\DmInfo 8BABD1E8
Device \Driver\usbehci \Device\USBPDO-1 8B8A87A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{26E1A150-2802-4612-A472-DFF76996295D} 895C87A0

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Ftdisk \Device\HarddiskVolume1 8BA4C1E8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)

Device \Driver\Ftdisk \Device\HarddiskVolume2 8BA4C1E8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys (Acronis Snapshot API/Acronis)

Device \Driver\Cdrom \Device\CdRom0 8B9BE708
Device \Driver\Ftdisk \Device\HarddiskVolume3 8BA4C1E8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 snapman.sys (Acronis Snapshot API/Acronis)

Device \Driver\Cdrom \Device\CdRom1 8B9BE708
Device \Driver\Ftdisk \Device\HarddiskVolume4 8BA4C1E8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 snapman.sys (Acronis Snapshot API/Acronis)

Device \Driver\Ftdisk \Device\HarddiskVolume5 8BA4C1E8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume5 snapman.sys (Acronis Snapshot API/Acronis)

Device \Driver\Ftdisk \Device\HarddiskVolume6 8BA4C1E8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume6 snapman.sys (Acronis Snapshot API/Acronis)

Device \Driver\PCI_NTPNP9532 \Device\00000069 sptd.sys
Device \Driver\Ftdisk \Device\HarddiskVolume7 8BA4C1E8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume7 snapman.sys (Acronis Snapshot API/Acronis)

Device \Driver\NetBT \Device\NetBt_Wins_Export 895C87A0
Device \Driver\Ftdisk \Device\HarddiskVolume8 8BA4C1E8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume8 snapman.sys (Acronis Snapshot API/Acronis)

Device \Driver\NetBT \Device\NetbiosSmb 895C87A0
Device \Driver\nvata \Device\00000094 8BABC1E8
Device \Driver\nvata \Device\00000095 8BABC1E8

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\nvata \Device\00000098 8BABC1E8
Device \Driver\usbohci \Device\USBFDO-0 8B72E7A0
Device \Driver\nvata \Device\00000099 8BABC1E8
Device \Driver\nvata \Device\NvAta0 8BABC1E8
Device \Driver\usbehci \Device\USBFDO-1 8B8A87A0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 895B61E8
Device \Driver\nvata \Device\NvAta1 8BABC1E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 895B61E8
Device \Driver\nvata \Device\NvAta2 8BABC1E8
Device \Driver\Ftdisk \Device\FtControl 8BA4C1E8
Device \Driver\fasttx2k \Device\Scsi\fasttx2k1Port5Path0Target0Lun0 8BA4A1E8
Device \Driver\azf2egny \Device\Scsi\azf2egny1Port6Path0Target1Lun0 8B8017A0
Device \Driver\fasttx2k \Device\Scsi\fasttx2k1Port5Path0Target4Lun0 8BA4A1E8
Device \Driver\fasttx2k \Device\Scsi\fasttx2k1 8BA4A1E8
Device \Driver\azf2egny \Device\Scsi\azf2egny1Port6Path0Target0Lun0 8B8017A0
Device \Driver\azf2egny \Device\Scsi\azf2egny1 8B8017A0
Device \FileSystem\Fastfat \Fat 88A297A0

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 88EDD7A0

---- Services - GMER 1.0.15 ----

Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] himpuhbi <-- ROOTKIT !!!
Service C:\WINDOWS\system32\drivers\SKYNETakaboykj.sys (*** hidden *** ) [SYSTEM] SKYNETytksrrpa <-- ROOTKIT !!!

Devil2U
2009-08-16, 10:57
---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xED 0x6C 0xF9 0xFD ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x88 0xCE 0x3C ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x85 0xAC 0x58 0x22 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x8C 0x66 0xD4 0x2A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x0D 0x88 0x65 0x91 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x88 0xCE 0x3C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x22 0xAC 0x36 0x0F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x1C 0xB2 0x8E 0xAA ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x0D 0x88 0x65 0x91 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x88 0xCE 0x3C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x22 0xAC 0x36 0x0F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x1C 0xB2 0x8E 0xAA ...
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi@DisplayName Support Helper
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi@Description Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\himpuhbi\Parameters@ServiceDll C:\WINDOWS\system32\abcaxurx.dll
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa@imagepath \systemroot\system32\drivers\SKYNETakaboykj.sys
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\main@aid 10096
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\main@sid 0
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETakaboykj.sys
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\modules@SKYNETcmd.dll \systemroot\system32\SKYNETiynmmxqg.dll
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\modules@SKYNETlog.dat \systemroot\system32\SKYNETnqjoejyx.dat
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\modules@SKYNETwsp.dll \systemroot\system32\SKYNETxagomjvi.dll
Reg HKLM\SYSTEM\ControlSet004\Services\SKYNETytksrrpa\modules@SKYNET.dat \systemroot\system32\SKYNETgogsjdxl.dat
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xED 0x6C 0xF9 0xFD ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x88 0xCE 0x3C ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x85 0xAC 0x58 0x22 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBA 0xD5 0x20 0x64 ...
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi@DisplayName Support Helper
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi@Type 32
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi@Start 2
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi@Description Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\himpuhbi\Parameters@ServiceDll C:\WINDOWS\system32\abcaxurx.dll
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa@start 1
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa@type 1
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa@group file system
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa@imagepath \systemroot\system32\drivers\SKYNETakaboykj.sys
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\main@aid 10096
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\main@sid 0
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETakaboykj.sys
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\modules@SKYNETcmd.dll \systemroot\system32\SKYNETiynmmxqg.dll
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\modules@SKYNETlog.dat \systemroot\system32\SKYNETnqjoejyx.dat
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\modules@SKYNETwsp.dll \systemroot\system32\SKYNETxagomjvi.dll
Reg HKLM\SYSTEM\ControlSet005\Services\SKYNETytksrrpa\modules@SKYNET.dat \systemroot\system32\SKYNETgogsjdxl.dat
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xED 0x6C 0xF9 0xFD ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x88 0xCE 0x3C ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x85 0xAC 0x58 0x22 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBA 0xD5 0x20 0x64 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi@DisplayName Support Helper
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi@Description Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\himpuhbi\Parameters@ServiceDll C:\WINDOWS\system32\abcaxurx.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa@imagepath \systemroot\system32\drivers\SKYNETakaboykj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETakaboykj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\modules@SKYNETcmd.dll \systemroot\system32\SKYNETiynmmxqg.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\modules@SKYNETlog.dat \systemroot\system32\SKYNETnqjoejyx.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\modules@SKYNETwsp.dll \systemroot\system32\SKYNETxagomjvi.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETytksrrpa\modules@SKYNET.dat \systemroot\system32\SKYNETgogsjdxl.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0

Devil2U
2009-08-16, 10:58
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xED 0x6C 0xF9 0xFD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x88 0xCE 0x3C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x85 0xAC 0x58 0x22 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBA 0xD5 0x20 0x64 ...
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi@DisplayName Support Helper
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi@Type 32
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi@Start 2
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi@Description Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\himpuhbi\Parameters@ServiceDll C:\WINDOWS\system32\abcaxurx.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa@imagepath \systemroot\system32\drivers\SKYNETakaboykj.sys
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\main@aid 10096
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\main@sid 0
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETakaboykj.sys
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\modules@SKYNETcmd.dll \systemroot\system32\SKYNETiynmmxqg.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\modules@SKYNETlog.dat \systemroot\system32\SKYNETnqjoejyx.dat
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\modules@SKYNETwsp.dll \systemroot\system32\SKYNETxagomjvi.dll
Reg HKLM\SYSTEM\ControlSet007\Services\SKYNETytksrrpa\modules@SKYNET.dat \systemroot\system32\SKYNETgogsjdxl.dat
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xED 0x6C 0xF9 0xFD ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x88 0xCE 0x3C ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x85 0xAC 0x58 0x22 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBA 0xD5 0x20 0x64 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xDF 0x20 0x58 0x62 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xF8 0x31 0x0F 0xA9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...

Devil2U
2009-08-16, 10:59
---- Files - GMER 1.0.15 ----

File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI(1)_files\child_e4817us.js 1505 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI(1)_files\ebaybase_e4817us.js 64452 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI(1)_files\VIShippingSection_e4811us.css 3989 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\170040220189.jpg 3418 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\170040225261.jpg 3818 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\170040231165.jpg 3522 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\170040235016.jpg 4132 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\bin_button.gif 763 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\iconStoresNW_20x20.gif 376 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\iframebody_e4833us.js 38788 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\iframefooter_tracking_e4833us.js 24944 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\imgStrsWidgtLftCnr_11x11.gif 861 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\imgStrsWidgtRtCnr_11x11.gif 174 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\merchiframe_e4833us.js 5384 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\ebay RIAD card sale\eBay New Promise FastTrak S150 TX2plus add on card - oem (item 170035660550 end time Oct-22-06 131519 PDT)_files\eBayISAPI_files\s.gif 49 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\AsusSetup.exe 503152 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\AsusSetup.ini 754 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\AsusSetup.exe 503152 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\AsusSetup.ini 809 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\AsusSetup.exe 503152 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\AsusSetup.ini 1848 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\English.ini 558 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\French.ini 554 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\German.ini 554 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\Japanese.ini 562 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\SChinese.ini 562 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\TChinese.ini 533 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\ENU\WINXP_~1.EXE 752368 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\AsusSetup.exe 503152 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\AsusSetup.ini 1848 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\English.ini 558 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\French.ini 554 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\German.ini 554 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\Japanese.ini 562 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\SChinese.ini 562 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\TChinese.ini 533 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\JPN\WINXP_~1.EXE 754928 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WinXP2K3x64\readme.txt 1325 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-CHT.exe 557808 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\AsusSetup.exe 503152 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\AsusSetup.ini 1833 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\English.ini 558 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\French.ini 554 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\German.ini 554 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-CHS.exe 557296 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-CSY.exe 563952 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-DEU.exe 563440 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-ENU.exe 557296 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-ESN.exe 563440 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-FRA.exe 563440 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-HUN.exe 564464 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-ITA.exe 562416 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-JPN.exe 559856 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-KOR.exe 558832 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-NLD.exe 563440 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-PLK.exe 564464 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-PTB.exe 562416 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-PTG.exe 562928 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-RUS.exe 563952 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-SVE.exe 562416 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Hotfix-TRK.exe 562416 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\Japanese.ini 562 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\QFE.exe 367616 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\readme.txt 1325 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\SChinese.ini 562 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\Microsoft_Hotfix\WS03\TChinese.ini 533 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\ADIDTS.sys 139776 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\ADIHdAud.inf 44045 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\ADIHdAud.sys 293888 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\AEAUDIO.sys 93952 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\mixer.ini 20330 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\PostProc.dll 28160 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\SMax4PNP.exe 868352 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\SMWDMIF.dll 303104 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SMAXWDM\W2K_XP\smx.cat 13685 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\cpsimp.chm 12189 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\digaudmb.chm 11264 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\DTS.chm 26004 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\EQ.chm 11416 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\micro.chm 11922 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\pnp.chm 13257 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\power.chm 17020 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\sensa.chm 11626 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\smax.chm 11330 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\smax4hlp.chm 21968 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Arabic\SPDIF.chm 10786 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\cpsimp.chm 13891 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\digaudmb.chm 11553 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\DTS.chm 26045 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\EQ.chm 11980 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\micro.chm 12326 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\pnp.chm 13721 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\power.chm 17596 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\sensa.chm 12181 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\smax.chm 11631 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\smax4hlp.chm 23576 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Brazil\SPDIF.chm 11004 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\cpsimp.chm 12385 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\digaudmb.chm 11446 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\DTS.chm 26005 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\EQ.chm 11726 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\micro.chm 12301 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\pnp.chm 13479 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\power.chm 17481 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\sensa.chm 11992 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\smax.chm 11500 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\smax4hlp.chm 22254 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Danish\SPDIF.chm 11028 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\cpsimp.chm 13545 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\digaudmb.chm 11438 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\DTS.chm 26016 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\EQ.chm 11778 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\micro.chm 13601 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\pnp.chm 13621 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\power.chm 17537 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\sensa.chm 11970 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\smax.chm 11492 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\smax4hlp.chm 22948 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Dutch\SPDIF.chm 11018 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\cpsimp.chm 12289 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\digaudmb.chm 11413 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\DTS.chm 25892 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\EQ.chm 11636 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\micro.chm 12160 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\pnp.chm 13345 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\power.chm 17356 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\sensa.chm 11866 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\smax.chm 11379 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\smax4hlp.chm 21000 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\English\SPDIF.chm 10994 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\cpsimp.chm 12485 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\digaudmb.chm 11495 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\DTS.chm 26028 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\EQ.chm 11746 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\micro.chm 12346 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\pnp.chm 13549 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\power.chm 17511 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\sensa.chm 12045 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\smax.chm 11553 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\smax4hlp.chm 23272 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Finnish\SPDIF.chm 11072 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\cpsimp.chm 12551 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\digaudmb.chm 11478 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\DTS.chm 26159 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\EQ.chm 11792 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\micro.chm 12493 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\pnp.chm 13761 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\power.chm 17708 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\sensa.chm 12304 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\smax.chm 11550 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\smax4hlp.chm 22694 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\French\SPDIF.chm 11024 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\cpsimp.chm 12697 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\digaudmb.chm 11456 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\DTS.chm 26196 bytes

Devil2U
2009-08-16, 11:01
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\EQ.chm 11992 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\micro.chm 12530 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\pnp.chm 13935 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\power.chm 17666 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\sensa.chm 12258 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\smax.chm 11496 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\smax4hlp.chm 22556 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\German\SPDIF.chm 11122 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\cpsimp.chm 13729 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\digaudmb.chm 11191 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\DTS.chm 25787 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\EQ.chm 11432 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\micro.chm 13564 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\pnp.chm 13107 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\power.chm 16915 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\sensa.chm 11547 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\smax.chm 11267 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\smax4hlp.chm 24304 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Hebrew\SPDIF.chm 10716 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\cpsimp.chm 12455 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\digaudmb.chm 11533 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\DTS.chm 26059 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\EQ.chm 11808 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\micro.chm 12438 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\pnp.chm 13581 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\power.chm 17648 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\sensa.chm 12217 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\smax.chm 11617 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\smax4hlp.chm 22216 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Italian\SPDIF.chm 11040 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\cpsimp.chm 12225 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\digaudmb.chm 11361 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\DTS.chm 25819 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\EQ.chm 11604 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\micro.chm 12113 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\pnp.chm 13131 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\power.chm 17536 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\sensa.chm 12084 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\smax.chm 11425 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\smax4hlp.chm 21718 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Japanese\SPDIF.chm 10852 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\cpsimp.chm 12695 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\digaudmb.chm 11843 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\DTS.chm 26135 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\EQ.chm 12026 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\micro.chm 12571 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\pnp.chm 13757 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\power.chm 17446 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\sensa.chm 12547 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\smax.chm 11889 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\smax4hlp.chm 22350 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Korean\SPDIF.chm 11340 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\cpsimp.chm 13597 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\digaudmb.chm 11522 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\DTS.chm 25979 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\EQ.chm 11738 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\micro.chm 12317 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\pnp.chm 13469 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\power.chm 17439 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\sensa.chm 11928 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\smax.chm 11574 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\smax4hlp.chm 22372 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Norweg\SPDIF.chm 11012 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\cpsimp.chm 12507 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\digaudmb.chm 11490 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\DTS.chm 26156 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\EQ.chm 11800 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\micro.chm 12478 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\pnp.chm 13643 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\power.chm 17772 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\sensa.chm 12222 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\smax.chm 11544 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\smax4hlp.chm 22384 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Polish\SPDIF.chm 11042 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\cpsimp.chm 12677 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\digaudmb.chm 11573 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\DTS.chm 26092 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\EQ.chm 11892 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\micro.chm 12478 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\pnp.chm 13729 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\power.chm 17820 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\sensa.chm 12310 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\smax.chm 11635 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\smax4hlp.chm 22818 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Russian\SPDIF.chm 11128 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\cpsimp.chm 12477 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\digaudmb.chm 11617 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\DTS.chm 25867 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\EQ.chm 11792 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\micro.chm 12148 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\pnp.chm 13393 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\power.chm 17242 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\sensa.chm 12083 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\smax.chm 11661 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\smax4hlp.chm 21872 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SimpChin\SPDIF.chm 11098 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\SMHelp.exe 28672 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\cpsimp.chm 13543 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\digaudmb.chm 11475 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\DTS.chm 26032 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\EQ.chm 11792 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\micro.chm 12343 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\pnp.chm 13599 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\power.chm 17860 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\sensa.chm 12194 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\smax.chm 11539 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\smax4hlp.chm 22988 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Spanish\SPDIF.chm 11038 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\cpsimp.chm 12473 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\digaudmb.chm 11516 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\DTS.chm 25971 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\EQ.chm 11872 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\micro.chm 12415 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\pnp.chm 13505 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\power.chm 17476 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\sensa.chm 11973 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\smax.chm 11588 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\smax4hlp.chm 22534 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Swedish\SPDIF.chm 10988 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\cpsimp.chm 13297 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\digaudmb.chm 11242 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\DTS.chm 25738 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\EQ.chm 11474 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\micro.chm 11955 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\pnp.chm 13209 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\power.chm 16985 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\sensa.chm 11704 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\smax.chm 11322 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\smax4hlp.chm 23040 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\Thai\SPDIF.chm 10784 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin 0 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\cpsimp.chm 12709 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\digaudmb.chm 11809 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\DTS.chm 26047 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\EQ.chm 12060 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\micro.chm 12630 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\pnp.chm 13771 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\power.chm 17292 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\sensa.chm 12361 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\smax.chm 11859 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\smax4hlp.chm 23300 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Help\TradChin\SPDIF.chm 11364 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Sys\placer.txt 20 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Comn\Wizards\SMax4Wiz.exe 925696 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Micro\Sys\MicTab.dll 192512 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Panel\Sys\ADIDTS.dll 1249280 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Panel\Sys\license.txt 5208 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Panel\Sys\SMax4.cpl 155648 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Panel\Sys\SMax4.exe 729088 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Panel\Sys\SMMedia.dll 1285632 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\Asus P5N32-E SLI Plus (Manual + Drivers)\NEW Computer build 6-2-07 (Drivers + BIOS)\SoundMAX_Audio_V51016110_32bit\32bit\2K_XP\SM_Panel\Sys\wdmioctl.dll 53248 bytes executable
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\arrow.png 169 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\emailButton.png 340 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\JSCookMenu.js 20671 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\printButton.png 305 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\sk_business3_01.jpg 24945 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\spacer.gif 43 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\template_css.css 9351 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\theme.css 8781 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\theme.js 2033 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\arrow.png 169 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\EMAILB~1.PNG 340 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\JSCookMenu.js 20671 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\PRINTB~1.PNG 305 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\SK_BUS~1.JPG 24945 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\spacer.gif 43 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\TEMPLA~1.CSS 9351 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\theme.css 8781 bytes
File C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\My Documents\LANm\Host PC Crap\Host PC Crap\hostpccrap\Acceptable Use\HostPC_com Everything you need for Direct Admin Hosting - DirectAdmin Servers & Directadmin support_f\theme.js 2033 bytes
File C:\WINDOWS\system32\drivers\SKYNETakaboykj.sys 69632 bytes <-- ROOTKIT !!!
File C:\WINDOWS\system32\SKYNETgogsjdxl.dat 91 bytes
File C:\WINDOWS\system32\SKYNETiynmmxqg.dll 44032 bytes
File C:\WINDOWS\system32\SKYNETnqjoejyx.dat 266969 bytes
File C:\WINDOWS\system32\SKYNETxagomjvi.dll 20480 bytes

---- EOF - GMER 1.0.15 ----

Shaba
2009-08-16, 12:33
We will continue with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
If you need help to disable your protection programs see here. (http://www.bleepingcomputer.com/forums/topic114351.html)

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.

Devil2U
2009-08-16, 22:42
Rancombo fix, it rebotted the comp, then did some work and made a logfile. Here it is:

ComboFix 09-08-10.06 - User 08/16/2009 12:20.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2529 [GMT -7:00]
Running from: c:\documents and settings\User\Desktop\troj removal\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\(null)id.tmp
c:\documents and settings\User\Local Settings\Temporary Internet Files\index.dat
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\emMON.exe
c:\windows\Installer\596866.msp
c:\windows\Installer\596979.msp
c:\windows\Installer\596986.msp
c:\windows\Installer\5969a9.msp
c:\windows\Installer\5969c4.msp
c:\windows\patch.exe
c:\windows\system32\drivers\SKYNETakaboykj.sys
c:\windows\system32\setup.exe.tmp
c:\windows\system32\SKYNETgogsjdxl.dat
c:\windows\system32\SKYNETiynmmxqg.dll
c:\windows\system32\SKYNETnqjoejyx.dat
c:\windows\system32\SKYNETxagomjvi.dll
c:\windows\Sysvxd.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SKYNETytksrrpa
-------\Legacy_SKYNETytksrrpa


((((((((((((((((((((((((( Files Created from 2009-07-16 to 2009-08-16 )))))))))))))))))))))))))))))))
.

2009-08-13 04:39 . 2009-08-13 04:39 -------- d-----w- c:\program files\ERUNT
2009-08-11 10:36 . 2009-08-11 10:36 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-11 05:27 . 2009-08-11 05:27 1962544 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-08-11 05:27 . 2009-08-12 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-11 05:27 . 2009-08-12 03:50 -------- d-----w- c:\program files\NOS
2009-08-07 12:12 . 2009-08-10 08:54 128712 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-03 06:28 . 2009-08-03 06:28 -------- d-----w- c:\program files\Microsoft
2009-07-27 01:29 . 2009-07-20 23:09 282624 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\NPDyyno@dyyno.com\Plugins\npDyyno.dll
2009-07-26 20:00 . 2009-01-17 02:08 296330688 ----a-w- C:\CoD4MW-1.6-PatchSetup.exe
2009-07-26 20:00 . 2009-01-17 02:06 39968152 ----a-w- C:\CoD4MW-1.6-1.7-PatchSetup.exe
2009-07-25 06:37 . 2009-07-25 06:37 4919296 ----a-w- c:\documents and settings\User\Application Data\GarageGames\IAPlayer\products\www_lan1_instantaction_com\102\install\Legions.exe
2009-07-25 06:37 . 2009-07-25 06:37 3727720 ----a-w- c:\documents and settings\User\Application Data\GarageGames\IAPlayer\products\www_lan1_instantaction_com\102\install\d3dx9_35.dll
2009-07-25 06:37 . 2009-07-25 06:37 369664 ----a-w- c:\documents and settings\User\Application Data\GarageGames\IAPlayer\products\www_lan1_instantaction_com\102\install\fmodex.dll
2009-07-25 06:31 . 2009-05-20 23:46 685376 ----a-w- c:\documents and settings\User\Application Data\GarageGames\IAPlayer\iaplugin.dll
2009-07-25 06:30 . 2009-07-25 06:30 -------- d-----w- c:\documents and settings\User\Application Data\GarageGames
2009-07-24 01:57 . 2009-07-24 01:57 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-07-21 17:48 . 2009-07-21 17:48 625728 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-16 19:19 . 2008-02-10 01:26 7304 ----a-w- c:\windows\TMP0001.TMP
2009-08-16 18:35 . 2007-06-10 03:58 -------- d-----w- c:\program files\BOINC
2009-08-16 18:35 . 2007-06-04 08:28 -------- d-----w- c:\documents and settings\User\Application Data\Skype
2009-08-16 18:33 . 2007-06-04 08:26 -------- d-----w- c:\documents and settings\User\Application Data\Xfire
2009-08-16 06:48 . 2008-04-07 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-12 05:39 . 2008-07-07 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-12 04:45 . 2007-07-30 17:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-12 04:39 . 2007-06-10 02:51 -------- d-----w- c:\program files\Download Manager
2009-08-12 04:39 . 2007-06-10 02:51 -------- d-----w- c:\documents and settings\User\Application Data\IGN_DLM
2009-08-12 03:53 . 2007-06-04 10:41 -------- d-----w- c:\documents and settings\User\Application Data\dvdcss
2009-08-11 09:48 . 2007-06-04 08:26 -------- d-s---w- c:\program files\Xfire
2009-08-04 05:00 . 2008-09-02 04:17 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-02 03:08 . 2007-06-25 00:09 138784 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-08-02 03:08 . 2007-06-25 00:09 111928 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-08-01 22:20 . 2007-06-04 22:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-27 01:45 . 2008-02-01 05:05 -------- d-----w- c:\documents and settings\User\Application Data\SoftSolo
2009-07-26 23:24 . 2009-01-28 06:32 347200 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\baseq3\cgamex86.dll
2009-07-26 23:24 . 2009-01-28 06:32 179264 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\baseq3\uix86.dll
2009-07-26 23:20 . 2009-01-28 06:31 874660 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\pb\pbcl.dll
2009-07-26 23:20 . 2009-01-28 06:31 57344 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\pb\pbag.dll
2009-07-26 23:20 . 2009-01-28 06:31 2657344 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\baseq3\quakelive.dll
2009-07-26 23:14 . 2007-11-11 11:10 2373712 ----a-w- c:\windows\system32\pbsvc.exe
2009-07-26 20:42 . 2007-05-24 22:56 75064 ----a-w- c:\windows\system32\pnkbstra.exe
2009-07-26 20:18 . 2007-08-03 02:02 22328 ----a-w- c:\documents and settings\User\Application Data\PnkBstrK.sys
2009-07-26 20:18 . 2007-08-03 02:02 22328 ----a-w- c:\documents and settings\User\Application Data\PnkBstrK.sys
2009-07-18 09:50 . 2009-06-27 07:48 -------- d-----w- c:\program files\XfireXO
2009-07-10 08:00 . 2008-07-07 03:48 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-06 21:01 . 2009-07-06 21:01 2373712 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\pbsvc.exe
2009-07-05 05:51 . 2009-07-05 05:51 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-07-04 07:56 . 2009-01-28 06:31 479232 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\pb\pbsv.dll
2009-07-03 17:09 . 2001-08-23 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-02 06:02 . 2009-07-02 06:02 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Xfire
2009-07-01 08:06 . 2009-07-01 08:05 -------- d-----w- c:\documents and settings\User\Application Data\wootalyzer
2009-07-01 08:05 . 2009-07-01 08:05 -------- d-----w- c:\program files\Wootalyzer
2009-07-01 02:19 . 2009-07-03 06:10 106496 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Plugins\npcoolirisplugin.dll
2009-07-01 02:19 . 2009-07-03 06:10 106496 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\npcoolirisplugin.dll
2009-07-01 02:19 . 2009-07-03 06:10 103424 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-07-01 02:19 . 2009-07-03 06:10 937984 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-07-01 02:19 . 2009-07-03 06:10 344064 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-07-01 02:19 . 2009-07-03 06:10 65536 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2009-07-01 02:19 . 2009-07-03 06:10 4734976 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\cooliris19.dll
2009-06-30 05:39 . 2007-06-14 20:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-30 05:05 . 2007-06-04 01:27 49960 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-30 05:02 . 2008-10-09 05:28 -------- d-----w- c:\program files\Windows Desktop Search
2009-06-30 04:52 . 2007-07-01 02:35 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-06-30 03:04 . 2009-06-30 03:03 -------- d-----w- c:\program files\Virtual Earth 3D
2009-06-27 07:48 . 2009-06-27 07:48 -------- d-----w- c:\program files\Conduit
2009-06-17 07:19 . 2009-06-17 07:19 0 ----a-w- c:\windows\popcreg.dat
2009-06-17 05:48 . 2007-06-13 08:30 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:36 . 2008-06-27 06:55 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-06-27 06:55 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-13 20:53 . 2007-11-17 03:45 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-13 20:36 . 2007-01-01 08:33 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-06-10 15:28 . 2009-06-10 15:28 3510272 ----a-w- c:\windows\system32\nvgames.dll
2009-06-10 15:28 . 2009-06-10 15:28 4022272 ----a-w- c:\windows\system32\nvdisps.dll
2009-06-10 15:28 . 2009-06-10 15:28 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-06-10 15:28 . 2009-06-10 15:28 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-06-10 15:28 . 2009-06-10 15:28 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-06-10 15:28 . 2009-06-10 15:28 13758464 ----a-w- c:\windows\system32\nvcpl.dll
2009-06-10 15:28 . 2009-06-10 15:28 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-06-10 13:03 . 2009-06-10 13:03 1580550 ----a-w- c:\windows\system32\nvdata.bin
2009-06-10 13:03 . 2009-06-10 13:03 1310720 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-06-10 13:03 . 2009-03-27 17:03 671744 ----a-w- c:\windows\system32\nvcuvid.dll
2009-06-10 13:03 . 2008-10-09 05:27 151552 ----a-w- c:\windows\system32\nvcodins.dll
2009-06-10 13:03 . 2008-10-09 05:27 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-06-10 13:03 . 2008-10-09 05:27 9998336 ----a-w- c:\windows\system32\nvoglnt.dll
2009-06-10 13:03 . 2008-10-09 05:27 815104 ----a-w- c:\windows\system32\nvapi.dll
2009-06-10 13:03 . 2008-10-09 05:27 8087712 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-06-10 13:03 . 2008-10-09 05:27 5908608 ----a-w- c:\windows\system32\nv4_disp.dll
2009-06-10 13:03 . 2007-12-05 09:41 1720320 ----a-w- c:\windows\system32\nvcuda.dll
2009-06-10 13:03 . 2007-06-04 08:22 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-06-07 08:20 . 2007-10-11 07:29 58 ----a-w- c:\windows\popcinfot.dat
2009-06-04 23:39 . 2007-06-04 22:06 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-03 19:09 . 2008-06-27 06:55 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 06:31 . 2009-06-02 06:31 9382061 ----a-w- C:\lab_test.zip
2009-05-25 07:24 . 2008-05-27 05:18 350208 ----a-w- c:\windows\system32\mssph.dll
2009-05-23 04:18 . 2009-05-23 04:18 390664 ----a-w- c:\documents and settings\User\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2007-10-16 04:15 . 2007-10-16 04:19 271312 ----a-w- c:\program files\vnc-4_1_2-x86_win32_viewer.exe
2007-05-10 21:45 . 2007-07-27 04:17 241664 ----a-w- c:\program files\DupFinder.exe
2004-10-13 19:49 . 2007-10-07 08:26 637440 ----a-w- c:\program files\netscan.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]
2009-07-18 09:50 2215960 ----a-w- c:\program files\XfireXO\tbXfi1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfi1.dll" [2009-07-18 2215960]

[HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}"= "c:\program files\XfireXO\tbXfi1.dll" [2009-07-18 2215960]

[HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wootalyzer"="c:\program files\Wootalyzer\woot.exe" [2009-03-26 374272]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-12 68856]
"Steam"="d:\games\steam\steam.exe" [2009-06-11 1217784]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-16 24264488]
"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2008-05-09 267536]
"PMCLoader"="c:\program files\Pinnacle\TVCenter Pro\PMCLoader.exe" [2008-05-14 644368]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-05 81920]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-05-15 1103216]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"AWMON"="c:\progra~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" [2005-05-25 517632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Electronic Scale"="c:\program files\USB Electronic Scale\scale" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Yapta Tracker"="c:\program files\Yapta\YaptaClient.exe" [2008-03-31 341296]
"USB Stress Panic Button"="c:\program files\USB Stress Panic Button\USB Stress Panic Button.exe" [2007-04-17 3452928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-14 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-23 136600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Free-1"="c:\program files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe" [2007-05-15 442368]
"DPAgnt"="c:\program files\DigitalPersona\Bin\DPAgnt.exe" [2006-10-09 807440]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-09-14 157592]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"Advanced LAN Pump"="c:\program files\SoftSolo\Advanced LAN Pump\alp.exe" [2006-04-01 1177600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"Acronis†True†Image Monitor"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2009-03-09 500561]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-03-09 65536]
"Ptipbmf"="ptipbmf.dll" - c:\windows\system32\ptipbmf.dll [2003-06-20 118784]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-06-10 1657376]
"kmw_run.exe"="kmw_run.exe" - c:\windows\system32\kmw_run.exe [2006-08-03 106496]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2006-08-11 18944]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2006-08-11 17920]

c:\documents and settings\User\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
BOINC Manager.lnk - c:\program files\BOINC\boincmgr.exe [2007-3-1 3604480]
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
Xfire.lnk - c:\program files\Xfire\xfire.exe [2009-7-23 3191696]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2007-9-9 1528880]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-1 805392]
Logo Calibration Loader.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe [2008-9-8 708608]
ProfileReminder.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe [2008-9-8 954368]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
ZDConfig.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS Wireless LAN\ZDConfig.exe [2007-7-30 184320]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DPWLN ]
2006-10-09 23:27 99856 ----a-w- c:\windows\system32\DPWLEvHd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 09:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-06 03:48 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPWDFLT scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"d:\\Games\\id Software\\Quake 4\\Quake4.exe"=
"d:\\Games\\Steam\\steamapps\\common\\defcon\\defcon.exe"=
"d:\\Games\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"d:\\Games\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"c:\\Program Files\\ViRC\\ViRC.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\WINDOWS\\system32\\pnkbstra.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\ElectricSheep.scr"=
"d:\\Games\\Raven Shield\\system\\RavenShield.eXe"=
"d:\\Games\\Raven Shield\\system\\UCC.exe"=
"d:\\Games\\Steam\\steamapps\\user\\source sdk base\\hl2.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"d:\\Games\\Steam\\steamapps\\user\\team fortress 2\\hl2.exe"=
"d:\\Games\\id Software\\Enemy Territory - QUAKE Wars\\etqwded.exe"=
"d:\\Games\\id Software\\Enemy Territory - QUAKE Wars\\etqw.exe"=
"d:\\Games\\Steam\\Steam.exe"=
"d:\\Games\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Games\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Games\\Steam\\steamapps\\user\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"d:\\Games\\Steam\\steamapps\\user\\synergy\\hl2.exe"=
"c:\\Documents and Settings\\User\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"d:\\Games\\Steam\\steamapps\\common\\savage 2 a tortured soul\\savage2.exe"=
"d:\\Games\\Sacred 2 - Fallen Angel\\system\\s2gs.exe"=
"d:\\Games\\Sacred 2 - Fallen Angel\\system\\sacred2.exe"=
"d:\\Games\\F.E.A.R. 2 SP Demo\\FEAR2SPDemo.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\Games\\Steam\\steamapps\\common\\quake\\Winquake.exe"=
"d:\\Games\\Steam\\steamapps\\common\\quake\\qwcl.exe"=
"d:\\Games\\Steam\\steamapps\\common\\quake\\Glquake.exe"=
"d:\\Games\\Steam\\steamapps\\common\\quake\\glqwcl.exe"=
"d:\\Games\\Steam\\steamapps\\common\\bejeweled deluxe\\WinBej.exe"=
"d:\\Games\\Steam\\steamapps\\common\\sam and max episode 4\\sammax104_drm.exe"=
"d:\\Games\\Steam\\steamapps\\common\\luxor 2\\Luxor2.exe"=
"d:\\Games\\Steam\\steamapps\\common\\reaxxion\\Reaxxion.exe"=
"d:\\Games\\Steam\\steamapps\\common\\prey\\prey.exe"=
"d:\\Games\\Steam\\steamapps\\common\\peggle deluxe\\Peggle.exe"=
"d:\\Games\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"d:\\Games\\Steam\\steamapps\\common\\flatout2\\FlatOut2.exe"=
"d:\\Games\\Steam\\steamapps\\common\\master levels of doom\\master.bat"=
"d:\\Games\\Steam\\steamapps\\common\\ultimate doom\\ultimate.bat"=
"d:\\Games\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"d:\\Games\\Steam\\steamapps\\common\\monster trucks nitro demo\\MonsterTrucksNitro.exe"=
"d:\\Games\\Steam\\steamapps\\common\\doom 2\\doom2.bat"=
"d:\\Games\\UT2XMP\\System\\U2XMP.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"d:\\Games\\Steam\\steamapps\\user\\age of chivalry\\hl2.exe"=
"d:\\Games\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"d:\\Games\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"d:\\Games\\Steam\\steamapps\\common\\the graveyard demo\\TheGraveyard.exe"=
"d:\\Games\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4X.exe"=
"d:\\Games\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4XDedicatedServer.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaws.exe"=
"c:\\WINDOWS\\system32\\javaws.exe"=
"d:\\Games\\Steam\\steamapps\\user\\diprip warm up\\hl2.exe"=
"d:\\Games\\Red Storm Entertainment\\RavenShield\\system\\RavenShield.exe"=
"d:\\Games\\Electronic Arts\\Crytek\\Crysis Wars\\Bin32\\Crysis.exe"=
"d:\\Games\\Steam\\steamapps\\common\\battleforge\\Bootstrapper.exe"=
"d:\\Games\\GRID\\GRID.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Games\\Steam\\steamapps\\common\\unreal tournament 3\\Binaries\\UT3.exe"=
"d:\\Games\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"=
"d:\\Games\\UT2004\\System\\UT2004.exe"=
"d:\\Games\\Steam\\steamapps\\user\\insurgency\\hl2.exe"=
"d:\\Games\\Quake\\FuhQuake\\fuhquake-gl.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Games\\Quake III Arena\\quake3.exe"=
"d:\\Games\\Steam\\steamapps\\user\\counter-strike source\\hl2.exe"=
"d:\\Games\\Steam\\steamapps\\common\\fallout 3\\FalloutLauncher.exe"=
"c:\\Program Files\\Xfire\\dppm_source.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"d:\\SteamStats\\SteamStats.exe"=
"d:\\Games\\Steam\\steamapps\\common\\defensegridtheawakening\\DefenseGrid.exe"=
"d:\\Games\\EA GAMES\\Battlefield 2\\BF2.exe"=
"d:\\Games\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/6/2008 8:48 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/24/2009 10:44 PM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/6/2008 8:48 PM 298776]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [9/8/2008 10:12 PM 14416]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [3/30/2009 4:28 PM 1533808]
R3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [9/16/2006 5:25 PM 35584]
R3 SaiH8000;SaiH8000;c:\windows\system32\drivers\SaiH8000.sys [7/30/2004 10:25 AM 136832]
R3 usbdpfp;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [9/16/2006 5:23 PM 47360]
S2 himpuhbi;Support Helper;c:\windows\system32\svchost.exe -k netsvcs [6/26/2008 11:55 PM 14336]
S3 BRDrxp32;BRDrxp32;\??\d:\games\BitRaider\BRDrxp32.sys --> d:\games\BitRaider\BRDrxp32.sys [?]
S3 i1;i1 Pro;c:\windows\system32\drivers\i1.sys [9/8/2008 10:12 PM 26045]
S3 SaiH0255;SaiH0255;c:\windows\system32\drivers\SaiH0255.sys [6/17/2005 6:41 PM 173568]
S3 TritonPC;TritonPC;\??\d:\games\BitRaider\TritonPC.sys --> d:\games\BitRaider\TritonPC.sys [?]
S3 XIRLINK;Veo PC Camera;c:\windows\system32\drivers\ucdnt.sys [7/4/2007 1:04 AM 899884]
S3 ZD1201U;ZyDAS ZD1201 IEEE 802.11b Wireless LAN Driver (USB);c:\windows\system32\drivers\ZD1201U.sys [7/30/2007 10:51 PM 38656]
S3 ZDNDIS5;ZDNDIS5 Protocol Driver;c:\windows\system32\ZDNDIS5.sys [7/30/2007 10:51 PM 16157]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
himpuhbi

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]

2009-08-16 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-06-04 23:27]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-NWEReboot - (no file)
HKLM-Run-MSWheel - (no file)


.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 165.228.131.12:80
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{0362b485-11fe-469c-ae98-42f478e581a0} - c:\program files\Yapta\YaptaSettings.exe
IE: {{0094A600-9BDD-4019-BAFE-487284F7D476} - {C3C07AD6-ACE9-43EE-A2AF-45BC13F6275F} - c:\program files\Yapta\YaptaSidebar.dll
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
Trusted Zone: turbotax.com
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - STCWeb.cab
DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} - hxxp://stage.dyyno.com/tng/dyyno-client/DyynoCAB.1.0.0.25.CAB
DPF: {79E54B26-46B9-40EF-BFDC-0B1BB0D68897} - hxxp://www.piclens.com/shared/plinstll.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\
FF - component: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\User\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\NPDyyno@dyyno.com\plugins\npDyyno.dll
FF - plugin: c:\documents and settings\User\Application Data\Mozilla\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\User\Local Settings\Application Data\HuluDesktop\instances\0.9.7.1\nphdplg.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Dyyno\Dyyno Player\npvlc.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npJoostPlugin.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-16 12:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet006\Services\himpuhbi]
"ServiceDll"="c:\windows\system32\abcaxurx.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1292428093-261478967-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:8f,b8,b7,02,e8,82,34,98,59,d2,0d,72,f9,3d,8a,49,07,09,17,a8,3a,63,0a,
96,fc,19,1f,ae,88,e1,53,ed,0d,d3,f8,2f,36,1a,10,54,2e,19,fa,3f,4e,c5,d7,4a,\
"??"=hex:25,65,bb,27,8b,92,55,34,10,3f,d9,49,2f,0e,31,37

[HKEY_USERS\S-1-5-21-1292428093-261478967-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:0d,0f,83,99,81,44,01,aa,52,e4,a6,d3,8b,96,a2,11,81,ab,10,c0,71,
a4,59,f9,a9,3e,a6,59,18,6a,99,ec,c3,2f,09,1f,b4,02,08,3e,6f,b9,09,2e,36,b9,\
"rkeysecu"=hex:39,8e,b4,03,43,b1,cb,7f,cd,57,48,f4,e3,f0,30,67

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,6a,7e,cb,fd,2c,
77,13,94,c8,28,51,af,b0,29,a3,98,ab,71,42,5f,31,da,53,7f,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,35,f4,a9,79,e8,
ad,64,7a,71,3b,04,66,8b,46,0d,96,ed,fe,e9,10,07,ec,15,7a,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,cc,72,b9,00,dc,
e5,04,1e,25,da,ec,7e,55,20,c9,26,34,26,05,7a,d5,08,b5,57,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,c3,6f,d5,3c,98,
9c,fe,53,3e,1e,9e,e0,57,5a,93,61,23,ae,c9,ef,c4,c7,be,33,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,a3,42,f6,91,
a5,bd,c0,cd,44,cd,b9,a6,33,6c,cd,06,26,74,ee,9f,f0,f3,cf,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,22,e5,37,ee,98,
33,bd,ed,b0,18,ed,a7,3f,8d,37,a4,98,8a,ed,55,3d,b9,fe,3c,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,b5,45,2e,50,f0,
5f,b9,b1,31,77,e1,ba,b1,f8,68,02,4d,8a,06,1b,c3,7b,62,ae,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,bf,cb,77,84,18,
52,07,ac,83,6c,56,8b,a0,85,96,ab,ff,d7,a3,2c,9e,03,11,22,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,6d,10,c1,29,e2,
49,d6,8a,51,fa,6e,91,28,9e,14,cc,7c,d2,57,2d,e7,f1,e6,c1,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,d1,fd,70,19,c2,
78,b5,0d,b1,cd,45,5a,a8,c4,f8,b9,8b,0e,9b,61,e6,55,bc,3c,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,a8,23,6b,19,b7,
44,90,a2,e3,0e,66,d5,eb,bc,2f,6b,6a,a1,51,34,50,47,1f,83,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,de,79,db,1f,ea,
84,c5,4a,fa,ea,66,7f,d4,3b,6b,70,bb,e8,40,50,f4,cb,d1,12,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1160)
c:\windows\system32\DPGINA.dll
c:\windows\system32\DPWLEvHd.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(1216)
c:\windows\DPPWDFLT.dll
c:\windows\system32\nvappfilter.dll
.
Completion time: 2009-08-16 12:29
ComboFix-quarantined-files.txt 2009-08-16 19:29

Pre-Run: 6,940,708,864 bytes free
Post-Run: 7,512,838,144 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
535

Devil2U
2009-08-16, 22:45
Fresh HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:44 PM, on 8/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.exe
C:\Documents and Settings\Paul Brown\Desktop\troj removal\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 165.228.131.12:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O3 - Toolbar: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Yapta Tracker] C:\Program Files\Yapta\YaptaClient.exe /onstartup
O4 - HKLM\..\Run: [USB Stress Panic Button] C:\Program Files\USB Stress Panic Button\USB Stress Panic Button.exe -liuhong
O4 - HKLM\..\Run: [USB Electronic Scale] C:\Program Files\USB Electronic Scale\scale /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Free-1] "C:\Program Files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe"
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Advanced LAN Pump] C:\Program Files\SoftSolo\Advanced LAN Pump\alp.exe autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acronis†True†Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [Wootalyzer] "C:\Program Files\Wootalyzer\woot.exe" /boot
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "d:\games\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [PMCLoader] C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Logo Calibration Loader.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe
O4 - Global Startup: ProfileReminder.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: ZDConfig.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS Wireless LAN\ZDConfig.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} (STCWeb Control) - STCWeb.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} (DyynoX Class) - http://stage.dyyno.com/tng/dyyno-client/DyynoCAB.1.0.0.25.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228473500921
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {79E54B26-46B9-40EF-BFDC-0B1BB0D68897} - http://www.piclens.com/shared/plinstll.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://67.114.242.171/activex/AxisCamControl.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.lan1.instantaction.com/download/iaplayer.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15029/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\system32\DPWLEvHd.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\\agent.exe

--
End of file - 15503 bytes

Shaba
2009-08-16, 22:58
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

http://img.bleepingcomputer.com/tutorials/hijackthis/uninstall-man.jpg

5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.

Devil2U
2009-08-17, 09:36
3DMark06
Acronis†True†Image
Ad-Aware SE Plus
Adobe AIR
Adobe AIR
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.2
Adobe Stock Photos 1.0
Advanced LAN Pump version 3.1
Age of Chivalry
Apple Mobile Device Support
Apple Software Update
Audiosurf
Avanquest update
AVG 8.5
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 1942: The Road To Rome
Battlefield 2(TM)
Battleforge Demo
Bejeweled Deluxe
Bing Maps 3D
Bioshock
BloodRayne 2
BOINC
Bonjour
Call of Duty - United Offensive
Call of Duty(R) - World at War(TM)
Call of Duty(R) - World at War(TM) 1.1 Patch
Call of Duty(R) - World at War(TM) 1.2 Patch
Call of Duty(R) - World at War(TM) 1.3 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
Call of Duty(TM) Game of the Year Edition
CDDRV_Installer
Compatibility Pack for the 2007 Office system
CoolDrive6
Creative Audio Console
Crysis Wars(R)
Crysis Wars(R)
Crysis Wars(R) Patch
Crysis Wars(R) Patch
Crysis(R)
CT-46-OTP
D.I.P.R.I.P. Warm Up
Dave's AV Screen Saver
DC++ 0.707
Defense Grid: The Awakening
DeLorme Street Atlas USA 2009
DesertCombat 0.7
DigitalPersona Password Manager 2.0.1
DING!
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Doom 2
Download Manager 2.3.6
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DyynoPlayer 0.8.6f
ElectricSheep 2.6.7b3
Enemy Territory - Quake Wars(TM)
Enemy Territory - QUAKE Wars(TM) 1.1 Patch
Enemy Territory - QUAKE Wars(TM) Beta 1.1 Patch
Enemy Territory - QUAKE Wars(TM) Beta 2 1.1 Patch
ERUNT 1.1j
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSTOOLS
essvatgt
Eye-One Match 3.6.2
F.E.A.R. 2 SP Demo
Fallout 3
ffdshow [rev 1523] [2007-10-09]
fflink
FlatOut2
Free-1 USB Phone V1.0.2.15
Google Earth
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Updater
GPGNet
GRID
Half-Life 2: Episode Two
Half-Life(R) 2
Hamachi 1.0.3.0
HD Tach version 3
HD Tune 2.53
Heavy Weapon Deluxe
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.0 (KB932471)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB932716-v2)
Hotfix for Windows XP (KB945060-v3)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
I-Fluid 1.0
Insurgency
iTunes
Java(TM) 6 Update 11
Java(TM) 6 Update 2
Java(TM) 6 Update 5
Joost (tm) 0.10.9
Kensington MouseWorks
KhalInstallWrapper
Kodak EasyShare software
Left 4 Dead
Logitech SetPoint
Luxor 2
Master Levels of Doom
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Live Add-in 1.4
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Video Screensaver
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Monster Trucks Nitro Demo
Motorola Driver Installation 3.4.0
Motorola Phone Tools
Mozilla Firefox (3.5.2)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
Nero 7 Premium
netbrdg
Next Generation Visualisations
Numbers
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA nTune
NVIDIA PhysX
NVIDIA Windows 95/98/ME/2000/XP Stereo Drivers
OfotoXMI
OpenAL
Pandora
Pandora
PeerGuardian 2.0
Peggle Deluxe
Peggle Extreme
Perfect Dark: Source Beta 1.0
PicLens for Internet Explorer
PL-2303 USB-to-Serial
Plants vs. Zombies
PoE:2 v1.8.0.0
Portal
PowerDVD
Project Reality v0.5.0.6
Project Reality v0.6.0.9
PunkBuster Services
Quake
Quake 4(TM)
Quake III Arena Point Release 1.32
Quake Live Internet Explorer Plugin
Quake Live Mozilla Plugin
QuickTime
RealPlayer
Reaxxion
Rhapsody Player Engine
Rocket Arena 3 1.76 (remove only)
Sacred 2
Safari
Sam and Max Episode 4
Savage 2: A Tortured Soul
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
SFR
SHASTA
Shutdown Monster 4.0.5.2
skin0001
SKINXSDK
Skypeô 4.0
SmartFTP Client
SmartFTP Client 2.5 Setup Files (remove only)
SmartFTP Client 3.0 Setup Files (remove only)
SoundFont Bank Manager
Source SDK Base
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SSL VPN Client
staticcr
Steam
Supreme Commander
SWAT 4
SWAT 4 - The Stetchkov Syndicate
Synergy
System Requirements Lab
Team Fortress 2
TeamSpeak 2 RC2
The Graveyard Demo
tooltips
TRACTION In-Game Radio Player 1.0 Beta
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2006
U2XMP Community Edition
Ultimate Doom
Unlocker 1.8.5
Unreal 2 Expanded Multiplayer
Unreal Tournament 3
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows XP (KB943729)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
USB Electronic Scale
USB Stress Panic Button V1.0.1
Ventrilo Client
Veo Connect
Veo Digital Studio
Visual IRC 2.0
VLC media player 0.9.9
VNC Free Edition 4.1.2
VPN Client
VPRINTOL
Vuze
WexTech AnswerWorks
Windows Imaging Component
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Presentation Foundation
Windows Search 4.0
Windows XP Service Pack 3
WinHTTrack Website Copier 3.41-3
WinRAR archiver
WIRELESS
Wootalyzer!
Xfire (remove only)
XfireXO Toolbar
Yapta
Zombie Subway
ZyDAS Wireless LAN - USB

Shaba
2009-08-17, 11:46
As per forum rules (http://forums.spybot.info/showthread.php?t=282), all P2P programs has to be uninstalled.

So please uninstall these:

DC++ 0.707
Vuze

Post back a fresh uninstall list afterwards, please.

Devil2U
2009-08-19, 04:12
3DMark06
Acronis†True†Image
Ad-Aware SE Plus
Adobe AIR
Adobe AIR
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.2
Adobe Stock Photos 1.0
Advanced LAN Pump version 3.1
Age of Chivalry
Apple Mobile Device Support
Apple Software Update
Audiosurf
Avanquest update
AVG 8.5
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 1942: The Road To Rome
Battlefield 2(TM)
Battleforge Demo
Bejeweled Deluxe
Bing Maps 3D
Bioshock
BloodRayne 2
BOINC
Bonjour
Call of Duty - United Offensive
Call of Duty(R) - World at War(TM)
Call of Duty(R) - World at War(TM) 1.1 Patch
Call of Duty(R) - World at War(TM) 1.2 Patch
Call of Duty(R) - World at War(TM) 1.3 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
Call of Duty(TM) Game of the Year Edition
CDDRV_Installer
Compatibility Pack for the 2007 Office system
CoolDrive6
Creative Audio Console
Crysis Wars(R)
Crysis Wars(R)
Crysis Wars(R) Patch
Crysis Wars(R) Patch
Crysis(R)
CT-46-OTP
D.I.P.R.I.P. Warm Up
Dave's AV Screen Saver
Defense Grid: The Awakening
DeLorme Street Atlas USA 2009
DesertCombat 0.7
DigitalPersona Password Manager 2.0.1
DING!
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Doom 2
Download Manager 2.3.6
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DyynoPlayer 0.8.6f
ElectricSheep 2.6.7b3
Enemy Territory - Quake Wars(TM)
Enemy Territory - QUAKE Wars(TM) 1.1 Patch
Enemy Territory - QUAKE Wars(TM) Beta 1.1 Patch
Enemy Territory - QUAKE Wars(TM) Beta 2 1.1 Patch
ERUNT 1.1j
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSTOOLS
essvatgt
Eye-One Match 3.6.2
F.E.A.R. 2 SP Demo
Fallout 3
ffdshow [rev 1523] [2007-10-09]
fflink
FlatOut2
Free-1 USB Phone V1.0.2.15
Google Earth
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Updater
GPGNet
GRID
Half-Life 2: Episode Two
Half-Life(R) 2
Hamachi 1.0.3.0
HD Tach version 3
HD Tune 2.53
Heavy Weapon Deluxe
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.0 (KB932471)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB932716-v2)
Hotfix for Windows XP (KB945060-v3)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
I-Fluid 1.0
Insurgency
iTunes
Java(TM) 6 Update 11
Java(TM) 6 Update 2
Java(TM) 6 Update 5
Joost (tm) 0.10.9
Kensington MouseWorks
KhalInstallWrapper
Kodak EasyShare software
Left 4 Dead
Logitech SetPoint
Luxor 2
Master Levels of Doom
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Live Add-in 1.4
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Video Screensaver
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Monster Trucks Nitro Demo
Motorola Driver Installation 3.4.0
Motorola Phone Tools
Mozilla Firefox (3.5.2)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
Nero 7 Premium
netbrdg
Next Generation Visualisations
Numbers
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA nTune
NVIDIA PhysX
NVIDIA Windows 95/98/ME/2000/XP Stereo Drivers
OfotoXMI
OpenAL
Pandora
Pandora
PeerGuardian 2.0
Peggle Deluxe
Peggle Extreme
Perfect Dark: Source Beta 1.0
PicLens for Internet Explorer
PL-2303 USB-to-Serial
Plants vs. Zombies
PoE:2 v1.8.0.0
Portal
PowerDVD
Project Reality v0.5.0.6
Project Reality v0.6.0.9
PunkBuster Services
Quake
Quake 4(TM)
Quake III Arena Point Release 1.32
Quake Live Internet Explorer Plugin
Quake Live Mozilla Plugin
QuickTime
RealPlayer
Reaxxion
Rhapsody Player Engine
Rocket Arena 3 1.76 (remove only)
Sacred 2
Safari
Sam and Max Episode 4
Savage 2: A Tortured Soul
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
SFR
SHASTA
Shutdown Monster 4.0.5.2
skin0001
SKINXSDK
Skypeô 4.0
SmartFTP Client
SmartFTP Client 2.5 Setup Files (remove only)
SmartFTP Client 3.0 Setup Files (remove only)
SoundFont Bank Manager
Source SDK Base
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SSL VPN Client
staticcr
Steam
Supreme Commander
SWAT 4
SWAT 4 - The Stetchkov Syndicate
Synergy
System Requirements Lab
Team Fortress 2
TeamSpeak 2 RC2
The Graveyard Demo
tooltips
TRACTION In-Game Radio Player 1.0 Beta
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2006
U2XMP Community Edition
Ultimate Doom
Unlocker 1.8.5
Unreal 2 Expanded Multiplayer
Unreal Tournament 3
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows XP (KB943729)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
USB Electronic Scale
USB Stress Panic Button V1.0.1
Ventrilo Client
Veo Connect
Veo Digital Studio
Visual IRC 2.0
VLC media player 0.9.9
VNC Free Edition 4.1.2
VPN Client
VPRINTOL
WexTech AnswerWorks
Windows Imaging Component
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Presentation Foundation
Windows Search 4.0
Windows XP Service Pack 3
WinHTTrack Website Copier 3.41-3
WinRAR archiver
WIRELESS
Wootalyzer!
Xfire (remove only)
XfireXO Toolbar
Yapta
Zombie Subway
ZyDAS Wireless LAN - USB

Shaba
2009-08-19, 06:59
Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


File::
%windir%\system32\drivers\svchost.exe

Folder::
c:\Program Files\DC++
c:\Program Files\Azureus

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=-
"c:\\Program Files\\Azureus\\Azureus.exe"=-
"%windir%\\system32\\drivers\\svchost.exe"=-


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Devil2U
2009-08-19, 09:48
When I drag the text file onto combofix, the app launches. When the command screen comes up, I get the folllowing message:

"Version_09-08-10.06
Current date is ~ ComboFix has expired
Click "Yes" to run in REDUCED FUNCTIONALITY mode
Click "No" to exit"

I assume I should click yes, but just wanted to check first.
Thanks.

Shaba
2009-08-19, 20:01
Please click no and download new combofix from link I gave you earlier.

Then do CFScript, please.

Devil2U
2009-08-23, 01:32
ComboFix 09-08-22.06 - User 08/22/2009 15:13.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2395 [GMT -7:00]
Running from: c:\documents and settings\User\Desktop\troj removal\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\troj removal\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Azureus
c:\program files\Azureus\hs_err_pid1540.log
c:\program files\Azureus\hs_err_pid1672.log
c:\program files\Azureus\hs_err_pid1684.log
c:\program files\Azureus\hs_err_pid1688.log
c:\program files\Azureus\hs_err_pid1864.log
c:\program files\Azureus\hs_err_pid2296.log
c:\program files\Azureus\hs_err_pid2540.log
c:\program files\Azureus\hs_err_pid2844.log
c:\program files\Azureus\hs_err_pid2848.log
c:\program files\Azureus\hs_err_pid2860.log
c:\program files\Azureus\hs_err_pid2912.log
c:\program files\Azureus\hs_err_pid2968.log
c:\program files\Azureus\hs_err_pid3004.log
c:\program files\Azureus\hs_err_pid3056.log
c:\program files\Azureus\hs_err_pid3104.log
c:\program files\Azureus\hs_err_pid3556.log
c:\program files\Azureus\hs_err_pid3732.log
c:\program files\Azureus\hs_err_pid3748.log
c:\program files\Azureus\hs_err_pid4028.log
c:\program files\Azureus\hs_err_pid4036.log
c:\program files\Azureus\hs_err_pid4068.log
c:\program files\Azureus\hs_err_pid4116.log
c:\program files\Azureus\hs_err_pid4212.log
c:\program files\Azureus\hs_err_pid428.log
c:\program files\Azureus\hs_err_pid4300.log
c:\program files\Azureus\hs_err_pid4396.log
c:\program files\Azureus\hs_err_pid4416.log
c:\program files\Azureus\hs_err_pid4456.log
c:\program files\Azureus\hs_err_pid4532.log
c:\program files\Azureus\hs_err_pid4536.log
c:\program files\Azureus\hs_err_pid4572.log
c:\program files\Azureus\hs_err_pid4612.log
c:\program files\Azureus\hs_err_pid4620.log
c:\program files\Azureus\hs_err_pid4748.log
c:\program files\Azureus\hs_err_pid4908.log
c:\program files\Azureus\hs_err_pid5104.log
c:\program files\Azureus\hs_err_pid5168.log
c:\program files\Azureus\hs_err_pid5192.log
c:\program files\Azureus\hs_err_pid5204.log
c:\program files\Azureus\hs_err_pid5212.log
c:\program files\Azureus\hs_err_pid5232.log
c:\program files\Azureus\hs_err_pid5304.log
c:\program files\Azureus\hs_err_pid5384.log
c:\program files\Azureus\hs_err_pid5428.log
c:\program files\Azureus\hs_err_pid5648.log
c:\program files\Azureus\hs_err_pid5680.log
c:\program files\Azureus\hs_err_pid5720.log
c:\program files\Azureus\hs_err_pid5860.log
c:\program files\Azureus\hs_err_pid5972.log
c:\program files\Azureus\hs_err_pid728.log
c:\program files\Azureus\hs_err_pid900.log
c:\program files\Azureus\plugins\azemp\azemp_1.9.0.jar
c:\program files\Azureus\plugins\azemp\azemp_1.9.0.zip
c:\program files\Azureus\plugins\azemp\azemp_1.9.6.jar
c:\program files\Azureus\plugins\azemp\azemp_1.9.6.zip
c:\program files\Azureus\plugins\azemp\azemp_2.0.16.jar
c:\program files\Azureus\plugins\azemp\azemp_2.0.16.zip
c:\program files\Azureus\plugins\azemp\azemp_2.0.32.jar
c:\program files\Azureus\plugins\azemp\azemp_2.0.32.zip
c:\program files\Azureus\plugins\azemp\azemp_2.1.02.jar
c:\program files\Azureus\plugins\azemp\azemp_2.1.02.zip
c:\program files\Azureus\plugins\azemp\azmplay.exe.bak
c:\program files\Azureus\plugins\azemp\cp1250-a.raw.bak
c:\program files\Azureus\plugins\azemp\cp1250-b.raw.bak
c:\program files\Azureus\plugins\azemp\font.desc.bak
c:\program files\Azureus\plugins\azemp\libInfoGetter.dll
c:\program files\Azureus\plugins\azemp\mplayer\config
c:\program files\Azureus\plugins\azemp\osd-mplayer-a.raw.bak
c:\program files\Azureus\plugins\azemp\osd-mplayer-b.raw.bak
c:\program files\Azureus\plugins\azemp\plugin.properties_1.9.0
c:\program files\Azureus\plugins\azemp\plugin.properties_1.9.6
c:\program files\Azureus\plugins\azemp\plugin.properties_2.0.16
c:\program files\Azureus\plugins\azemp\plugin.properties_2.0.32
c:\program files\Azureus\plugins\azemp\plugin.properties_2.1.02
c:\program files\Azureus\plugins\azupdater\azupdater_1.8.8.zip
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.8.jar
c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.8
c:\program files\Azureus\plugins\azupdater\Updater.jar.bak
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.1.7.jar
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.1.7.zip
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.17.jar
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.17.zip
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.2.jar
c:\program files\Azureus\plugins\azupnpav\azupnpav_0.2.2.zip
c:\program files\Azureus\plugins\azupnpav\plugin.properties_0.1.7
c:\program files\Azureus\plugins\azupnpav\plugin.properties_0.2.17
c:\program files\Azureus\plugins\azupnpav\plugin.properties_0.2.2
c:\windows\emMON.exe

.
((((((((((((((((((((((((( Files Created from 2009-07-22 to 2009-08-22 )))))))))))))))))))))))))))))))
.

2009-08-13 04:39 . 2009-08-13 04:39 -------- d-----w- c:\program files\ERUNT
2009-08-11 10:36 . 2009-08-11 10:36 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-11 05:27 . 2009-08-11 05:27 1962544 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-08-11 05:27 . 2009-08-12 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-11 05:27 . 2009-08-12 03:50 -------- d-----w- c:\program files\NOS
2009-08-07 12:12 . 2009-08-10 08:54 128712 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-03 06:28 . 2009-08-03 06:28 -------- d-----w- c:\program files\Microsoft
2009-07-27 01:29 . 2009-07-20 23:09 282624 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\NPDyyno@dyyno.com\Plugins\npDyyno.dll
2009-07-26 20:00 . 2009-01-17 02:08 296330688 ----a-w- C:\CoD4MW-1.6-PatchSetup.exe
2009-07-26 20:00 . 2009-01-17 02:06 39968152 ----a-w- C:\CoD4MW-1.6-1.7-PatchSetup.exe
2009-07-25 06:37 . 2009-07-25 06:37 4919296 ----a-w- c:\documents and settings\User\Application Data\GarageGames\IAPlayer\products\www_lan1_instantaction_com\102\install\Legions.exe
2009-07-25 06:37 . 2009-07-25 06:37 3727720 ----a-w- c:\documents and settings\User\Application Data\GarageGames\IAPlayer\products\www_lan1_instantaction_com\102\install\d3dx9_35.dll
2009-07-25 06:37 . 2009-07-25 06:37 369664 ----a-w- c:\documents and settings\User\Application Data\GarageGames\IAPlayer\products\www_lan1_instantaction_com\102\install\fmodex.dll
2009-07-25 06:31 . 2009-05-20 23:46 685376 ----a-w- c:\documents and settings\User\Application Data\GarageGames\IAPlayer\iaplugin.dll
2009-07-25 06:30 . 2009-07-25 06:30 -------- d-----w- c:\documents and settings\User\Application Data\GarageGames
2009-07-24 01:57 . 2009-07-24 01:57 41872 ----a-w- c:\windows\system32\xfcodec.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 22:10 . 2007-06-04 08:26 -------- d-----w- c:\documents and settings\User\Application Data\Xfire
2009-08-22 22:10 . 2007-06-10 03:58 -------- d-----w- c:\program files\BOINC
2009-08-22 22:10 . 2007-06-04 08:28 -------- d-----w- c:\documents and settings\User\Application Data\Skype
2009-08-22 21:56 . 2008-02-10 01:26 7304 ----a-w- c:\windows\TMP0001.TMP
2009-08-17 07:49 . 2008-04-07 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-12 05:39 . 2008-07-07 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-12 04:45 . 2007-07-30 17:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-12 04:39 . 2007-06-10 02:51 -------- d-----w- c:\program files\Download Manager
2009-08-12 04:39 . 2007-06-10 02:51 -------- d-----w- c:\documents and settings\User\Application Data\IGN_DLM
2009-08-12 03:53 . 2007-06-04 10:41 -------- d-----w- c:\documents and settings\User\Application Data\dvdcss
2009-08-11 09:48 . 2007-06-04 08:26 -------- d-s---w- c:\program files\Xfire
2009-08-04 05:00 . 2008-09-02 04:17 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-02 03:08 . 2007-06-25 00:09 138784 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-08-02 03:08 . 2007-06-25 00:09 111928 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-08-01 22:20 . 2007-06-04 22:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-27 01:45 . 2008-02-01 05:05 -------- d-----w- c:\documents and settings\User\Application Data\SoftSolo
2009-07-26 23:24 . 2009-01-28 06:32 347200 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\baseq3\cgamex86.dll
2009-07-26 23:24 . 2009-01-28 06:32 179264 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\baseq3\uix86.dll
2009-07-26 23:20 . 2009-01-28 06:31 874660 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\pb\pbcl.dll
2009-07-26 23:20 . 2009-01-28 06:31 57344 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\pb\pbag.dll
2009-07-26 23:20 . 2009-01-28 06:31 2657344 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\baseq3\quakelive.dll
2009-07-26 23:14 . 2007-11-11 11:10 2373712 ----a-w- c:\windows\system32\pbsvc.exe
2009-07-26 20:42 . 2007-05-24 22:56 75064 ----a-w- c:\windows\system32\pnkbstra.exe
2009-07-26 20:18 . 2007-08-03 02:02 22328 ----a-w- c:\documents and settings\User\Application Data\PnkBstrK.sys
2009-07-26 20:18 . 2007-08-03 02:02 22328 ----a-w- c:\documents and settings\User\Application Data\PnkBstrK.sys
2009-07-21 17:48 . 2009-07-21 17:48 625728 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
2009-07-18 09:50 . 2009-06-27 07:48 -------- d-----w- c:\program files\XfireXO
2009-07-10 08:00 . 2008-07-07 03:48 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-06 21:01 . 2009-07-06 21:01 2373712 ----a-w- c:\documents and settings\All Users\Application Data\id Software\QuakeLive\pbsvc.exe
2009-07-05 05:51 . 2009-07-05 05:51 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-07-04 07:56 . 2009-01-28 06:31 479232 ----a-w- c:\documents and settings\User\Application Data\id Software\quakelive\home\pb\pbsv.dll
2009-07-03 17:09 . 2001-08-23 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-01 08:06 . 2009-07-01 08:05 -------- d-----w- c:\documents and settings\User\Application Data\wootalyzer
2009-07-01 08:05 . 2009-07-01 08:05 -------- d-----w- c:\program files\Wootalyzer
2009-07-01 02:19 . 2009-07-03 06:10 106496 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Plugins\npcoolirisplugin.dll
2009-07-01 02:19 . 2009-07-03 06:10 106496 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\npcoolirisplugin.dll
2009-07-01 02:19 . 2009-07-03 06:10 103424 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-07-01 02:19 . 2009-07-03 06:10 937984 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-07-01 02:19 . 2009-07-03 06:10 344064 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-07-01 02:19 . 2009-07-03 06:10 65536 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2009-07-01 02:19 . 2009-07-03 06:10 4734976 ----a-w- c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\libs\cooliris19.dll
2009-06-30 05:39 . 2007-06-14 20:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-30 05:05 . 2007-06-04 01:27 49960 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-30 05:02 . 2008-10-09 05:28 -------- d-----w- c:\program files\Windows Desktop Search
2009-06-30 04:52 . 2007-07-01 02:35 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-06-30 03:04 . 2009-06-30 03:03 -------- d-----w- c:\program files\Virtual Earth 3D
2009-06-27 07:48 . 2009-06-27 07:48 -------- d-----w- c:\program files\Conduit
2009-06-17 07:19 . 2009-06-17 07:19 0 ----a-w- c:\windows\popcreg.dat
2009-06-17 05:48 . 2007-06-13 08:30 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:36 . 2008-06-27 06:55 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-06-27 06:55 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-13 20:53 . 2007-11-17 03:45 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-13 20:36 . 2007-01-01 08:33 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-06-10 15:28 . 2009-06-10 15:28 3510272 ----a-w- c:\windows\system32\nvgames.dll
2009-06-10 15:28 . 2009-06-10 15:28 4022272 ----a-w- c:\windows\system32\nvdisps.dll
2009-06-10 15:28 . 2009-06-10 15:28 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-06-10 15:28 . 2009-06-10 15:28 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-06-10 15:28 . 2009-06-10 15:28 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-06-10 15:28 . 2009-06-10 15:28 13758464 ----a-w- c:\windows\system32\nvcpl.dll
2009-06-10 15:28 . 2009-06-10 15:28 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-06-10 13:03 . 2009-06-10 13:03 1580550 ----a-w- c:\windows\system32\nvdata.bin
2009-06-10 13:03 . 2009-06-10 13:03 1310720 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-06-10 13:03 . 2009-03-27 17:03 671744 ----a-w- c:\windows\system32\nvcuvid.dll
2009-06-10 13:03 . 2008-10-09 05:27 151552 ----a-w- c:\windows\system32\nvcodins.dll
2009-06-10 13:03 . 2008-10-09 05:27 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-06-10 13:03 . 2008-10-09 05:27 9998336 ----a-w- c:\windows\system32\nvoglnt.dll
2009-06-10 13:03 . 2008-10-09 05:27 815104 ----a-w- c:\windows\system32\nvapi.dll
2009-06-10 13:03 . 2008-10-09 05:27 8087712 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-06-10 13:03 . 2008-10-09 05:27 5908608 ----a-w- c:\windows\system32\nv4_disp.dll
2009-06-10 13:03 . 2007-12-05 09:41 1720320 ----a-w- c:\windows\system32\nvcuda.dll
2009-06-10 13:03 . 2007-06-04 08:22 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-06-07 08:20 . 2007-10-11 07:29 58 ----a-w- c:\windows\popcinfot.dat
2009-06-04 23:39 . 2007-06-04 22:06 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-03 19:09 . 2008-06-27 06:55 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 06:31 . 2009-06-02 06:31 9382061 ----a-w- C:\lab_test.zip
2009-05-25 07:24 . 2008-05-27 05:18 350208 ----a-w- c:\windows\system32\mssph.dll
2007-10-16 04:15 . 2007-10-16 04:19 271312 ----a-w- c:\program files\vnc-4_1_2-x86_win32_viewer.exe
2007-05-10 21:45 . 2007-07-27 04:17 241664 ----a-w- c:\program files\DupFinder.exe
2004-10-13 19:49 . 2007-10-07 08:26 637440 ----a-w- c:\program files\netscan.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-08-16_19.27.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-22 21:57 . 2009-08-22 21:57 16384 c:\windows\Temp\Perflib_Perfdata_2d4.dat
+ 2009-08-22 21:56 . 2009-08-22 21:56 16384 c:\windows\Temp\Perflib_Perfdata_224.dat
+ 2009-08-19 01:23 . 2008-04-14 12:42 23552 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\wdmaud.drv
+ 2009-08-19 01:23 . 2008-04-14 12:42 53760 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\vfwwdm32.dll
+ 2009-08-19 01:23 . 2008-04-14 07:15 49408 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\stream.sys
+ 2009-08-19 01:23 . 2008-04-14 12:42 16896 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\msyuv.dll
+ 2009-08-19 01:23 . 2008-04-14 12:41 47616 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\iyuv_32.dll
+ 2009-08-19 01:23 . 2008-04-14 07:15 60160 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\drmk.sys
+ 2009-08-19 01:23 . 2008-04-14 07:16 11776 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\BdaSup.sys
+ 2009-08-19 01:23 . 2008-03-25 19:58 38656 c:\windows\system32\ReinstallBackups\0026\DriverFiles\emOEM.sys
+ 2009-08-19 01:23 . 2007-02-14 22:46 81920 c:\windows\system32\DRVSTORE\PCTVEMPV_2F7BD2C4E47BED8624A9FFC3F25FE600C17EEB60\PCLECoInst.dll
+ 2009-08-19 01:23 . 2008-07-09 20:49 65536 c:\windows\system32\DRVSTORE\PCTVEMPV_2F7BD2C4E47BED8624A9FFC3F25FE600C17EEB60\emMON.exe
+ 2009-08-19 01:23 . 2008-11-18 19:27 24576 c:\windows\system32\DRVSTORE\PCTVEMPA_2F7BD2C4E47BED8624A9FFC3F25FE600C17EEB60\emAudio.sys
+ 2009-08-19 01:23 . 2001-08-18 05:36 8192 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\tsbyuv.dll
+ 2009-08-19 01:23 . 2008-04-14 12:41 4096 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\ksuser.dll
+ 2009-08-19 01:23 . 2008-04-14 12:42 363520 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\PsisDecd.dll
+ 2009-08-19 01:23 . 2008-04-14 07:49 146048 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\portcls.sys
+ 2009-08-19 01:23 . 2008-04-14 12:42 294912 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\msh263.drv
+ 2009-08-19 01:23 . 2008-04-14 07:46 141056 c:\windows\system32\ReinstallBackups\0026\DriverFiles\i386\ks.sys
+ 2009-08-19 01:23 . 2008-03-25 19:58 476288 c:\windows\system32\ReinstallBackups\0026\DriverFiles\emBDA.sys
+ 2009-08-19 01:23 . 2008-07-09 20:49 444800 c:\windows\system32\DRVSTORE\PCTVyu_CD800DB0D7A6DBDC21EEEA1271EAC73865D7E409\dvb7700all.sys
+ 2009-08-19 01:23 . 2008-11-18 19:27 320128 c:\windows\system32\DRVSTORE\PCTVEMPV_2F7BD2C4E47BED8624A9FFC3F25FE600C17EEB60\emOEM.sys
+ 2009-08-19 01:23 . 2008-11-18 19:27 537856 c:\windows\system32\DRVSTORE\PCTVEMPV_2F7BD2C4E47BED8624A9FFC3F25FE600C17EEB60\emBDA.sys
+ 2008-09-10 07:29 . 2008-11-18 19:27 320128 c:\windows\system32\drivers\emOEM.sys
+ 2008-09-10 07:29 . 2008-11-18 19:27 537856 c:\windows\system32\drivers\emBDA.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]
2009-07-18 09:50 2215960 ----a-w- c:\program files\XfireXO\tbXfi1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfi1.dll" [2009-07-18 2215960]

[HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}"= "c:\program files\XfireXO\tbXfi1.dll" [2009-07-18 2215960]

[HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wootalyzer"="c:\program files\Wootalyzer\woot.exe" [2009-03-26 374272]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-12 68856]
"Steam"="d:\games\steam\steam.exe" [2009-06-11 1217784]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-16 24264488]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-05 81920]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-05-15 1103216]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"AWMON"="c:\progra~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" [2005-05-25 517632]
"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2008-11-18 226576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Electronic Scale"="c:\program files\USB Electronic Scale\scale" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Yapta Tracker"="c:\program files\Yapta\YaptaClient.exe" [2008-03-31 341296]
"USB Stress Panic Button"="c:\program files\USB Stress Panic Button\USB Stress Panic Button.exe" [2007-04-17 3452928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-14 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-23 136600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Free-1"="c:\program files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe" [2007-05-15 442368]
"DPAgnt"="c:\program files\DigitalPersona\Bin\DPAgnt.exe" [2006-10-09 807440]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-09-14 157592]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"Advanced LAN Pump"="c:\program files\SoftSolo\Advanced LAN Pump\alp.exe" [2006-04-01 1177600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"Acronis†True†Image Monitor"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2009-03-09 500561]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-03-09 65536]
"Ptipbmf"="ptipbmf.dll" - c:\windows\system32\ptipbmf.dll [2003-06-20 118784]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-06-10 1657376]
"kmw_run.exe"="kmw_run.exe" - c:\windows\system32\kmw_run.exe [2006-08-03 106496]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2006-08-11 18944]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2006-08-11 17920]

c:\documents and settings\User\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
BOINC Manager.lnk - c:\program files\BOINC\boincmgr.exe [2007-3-1 3604480]
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
Xfire.lnk - c:\program files\Xfire\xfire.exe [2009-7-23 3191696]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2007-9-9 1528880]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-1 805392]
Logo Calibration Loader.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe [2008-9-8 708608]
ProfileReminder.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe [2008-9-8 954368]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
ZDConfig.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS Wireless LAN\ZDConfig.exe [2007-7-30 184320]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DPWLN ]
2006-10-09 23:27 99856 ----a-w- c:\windows\system32\DPWLEvHd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 09:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-06 03:48 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPWDFLT scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"d:\\Games\\id Software\\Quake 4\\Quake4.exe"=
"d:\\Games\\Steam\\steamapps\\common\\defcon\\defcon.exe"=
"d:\\Games\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"d:\\Games\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"c:\\Program Files\\ViRC\\ViRC.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\pnkbstra.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\ElectricSheep.scr"=
"d:\\Games\\Raven Shield\\system\\RavenShield.eXe"=
"d:\\Games\\Raven Shield\\system\\UCC.exe"=
"d:\\Games\\Steam\\steamapps\\user\\source sdk base\\hl2.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"d:\\Games\\Steam\\steamapps\\user\\team fortress 2\\hl2.exe"=
"d:\\Games\\id Software\\Enemy Territory - QUAKE Wars\\etqwded.exe"=
"d:\\Games\\id Software\\Enemy Territory - QUAKE Wars\\etqw.exe"=
"d:\\Games\\Steam\\Steam.exe"=
"d:\\Games\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Games\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Games\\Steam\\steamapps\\user\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"d:\\Games\\Steam\\steamapps\\user\\synergy\\hl2.exe"=
"c:\\Documents and Settings\\User\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"d:\\Games\\Steam\\steamapps\\common\\savage 2 a tortured soul\\savage2.exe"=
"d:\\Games\\Sacred 2 - Fallen Angel\\system\\s2gs.exe"=
"d:\\Games\\Sacred 2 - Fallen Angel\\system\\sacred2.exe"=
"d:\\Games\\F.E.A.R. 2 SP Demo\\FEAR2SPDemo.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\Games\\Steam\\steamapps\\common\\quake\\Winquake.exe"=
"d:\\Games\\Steam\\steamapps\\common\\quake\\qwcl.exe"=
"d:\\Games\\Steam\\steamapps\\common\\quake\\Glquake.exe"=
"d:\\Games\\Steam\\steamapps\\common\\quake\\glqwcl.exe"=
"d:\\Games\\Steam\\steamapps\\common\\bejeweled deluxe\\WinBej.exe"=
"d:\\Games\\Steam\\steamapps\\common\\sam and max episode 4\\sammax104_drm.exe"=
"d:\\Games\\Steam\\steamapps\\common\\luxor 2\\Luxor2.exe"=
"d:\\Games\\Steam\\steamapps\\common\\reaxxion\\Reaxxion.exe"=
"d:\\Games\\Steam\\steamapps\\common\\prey\\prey.exe"=
"d:\\Games\\Steam\\steamapps\\common\\peggle deluxe\\Peggle.exe"=
"d:\\Games\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"d:\\Games\\Steam\\steamapps\\common\\flatout2\\FlatOut2.exe"=
"d:\\Games\\Steam\\steamapps\\common\\master levels of doom\\master.bat"=
"d:\\Games\\Steam\\steamapps\\common\\ultimate doom\\ultimate.bat"=
"d:\\Games\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"d:\\Games\\Steam\\steamapps\\common\\monster trucks nitro demo\\MonsterTrucksNitro.exe"=
"d:\\Games\\Steam\\steamapps\\common\\doom 2\\doom2.bat"=
"d:\\Games\\UT2XMP\\System\\U2XMP.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"d:\\Games\\Steam\\steamapps\\user\\age of chivalry\\hl2.exe"=
"d:\\Games\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"d:\\Games\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"d:\\Games\\Steam\\steamapps\\common\\the graveyard demo\\TheGraveyard.exe"=
"d:\\Games\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4X.exe"=
"d:\\Games\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4XDedicatedServer.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaws.exe"=
"c:\\WINDOWS\\system32\\javaws.exe"=
"d:\\Games\\Steam\\steamapps\\user\\diprip warm up\\hl2.exe"=
"d:\\Games\\Red Storm Entertainment\\RavenShield\\system\\RavenShield.exe"=
"d:\\Games\\Electronic Arts\\Crytek\\Crysis Wars\\Bin32\\Crysis.exe"=
"d:\\Games\\Steam\\steamapps\\common\\battleforge\\Bootstrapper.exe"=
"d:\\Games\\GRID\\GRID.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Games\\Steam\\steamapps\\common\\unreal tournament 3\\Binaries\\UT3.exe"=
"d:\\Games\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"=
"d:\\Games\\UT2004\\System\\UT2004.exe"=
"d:\\Games\\Steam\\steamapps\\user\\insurgency\\hl2.exe"=
"d:\\Games\\Quake\\FuhQuake\\fuhquake-gl.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Games\\Quake III Arena\\quake3.exe"=
"d:\\Games\\Steam\\steamapps\\user\\counter-strike source\\hl2.exe"=
"d:\\Games\\Steam\\steamapps\\common\\fallout 3\\FalloutLauncher.exe"=
"c:\\Program Files\\Xfire\\dppm_source.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"d:\\SteamStats\\SteamStats.exe"=
"d:\\Games\\Steam\\steamapps\\common\\defensegridtheawakening\\DefenseGrid.exe"=
"d:\\Games\\EA GAMES\\Battlefield 2\\BF2.exe"=
"d:\\Games\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/6/2008 8:48 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/24/2009 10:44 PM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/6/2008 8:48 PM 298776]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [9/8/2008 10:12 PM 14416]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [3/30/2009 4:28 PM 1533808]
R3 dpK0Bx01;Fingerprint Reader Filter Driver;c:\windows\system32\drivers\dpK0Bx01.sys [9/16/2006 5:25 PM 35584]
R3 SaiH8000;SaiH8000;c:\windows\system32\drivers\SaiH8000.sys [7/30/2004 10:25 AM 136832]
R3 usbdpfp;Fingerprint Reader Class Driver;c:\windows\system32\drivers\usbdpfp.sys [9/16/2006 5:23 PM 47360]
R3 ZDNDIS5;ZDNDIS5 Protocol Driver;c:\windows\system32\ZDNDIS5.sys [7/30/2007 10:51 PM 16157]
S2 himpuhbi;Support Helper;c:\windows\system32\svchost.exe -k netsvcs [6/26/2008 11:55 PM 14336]
S3 BRDrxp32;BRDrxp32;\??\d:\games\BitRaider\BRDrxp32.sys --> d:\games\BitRaider\BRDrxp32.sys [?]
S3 i1;i1 Pro;c:\windows\system32\drivers\i1.sys [9/8/2008 10:12 PM 26045]
S3 SaiH0255;SaiH0255;c:\windows\system32\drivers\SaiH0255.sys [6/17/2005 6:41 PM 173568]
S3 TritonPC;TritonPC;\??\d:\games\BitRaider\TritonPC.sys --> d:\games\BitRaider\TritonPC.sys [?]
S3 XIRLINK;Veo PC Camera;c:\windows\system32\drivers\ucdnt.sys [7/4/2007 1:04 AM 899884]
S3 ZD1201U;ZyDAS ZD1201 IEEE 802.11b Wireless LAN Driver (USB);c:\windows\system32\drivers\ZD1201U.sys [7/30/2007 10:51 PM 38656]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
himpuhbi

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]

2009-08-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-06-04 23:27]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 165.228.131.12:80
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{0362b485-11fe-469c-ae98-42f478e581a0} - c:\program files\Yapta\YaptaSettings.exe
IE: {{0094A600-9BDD-4019-BAFE-487284F7D476} - {C3C07AD6-ACE9-43EE-A2AF-45BC13F6275F} - c:\program files\Yapta\YaptaSidebar.dll
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
Trusted Zone: turbotax.com
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - STCWeb.cab
DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} - hxxp://stage.dyyno.com/tng/dyyno-client/DyynoCAB.1.0.0.25.CAB
DPF: {79E54B26-46B9-40EF-BFDC-0B1BB0D68897} - hxxp://www.piclens.com/shared/plinstll.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\
FF - component: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\h5eaa023.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-22 15:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet006\Services\himpuhbi]
"ServiceDll"="c:\windows\system32\abcaxurx.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1292428093-261478967-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:8f,b8,b7,02,e8,82,34,98,59,d2,0d,72,f9,3d,8a,49,07,09,17,a8,3a,63,0a,
96,fc,19,1f,ae,88,e1,53,ed,0d,d3,f8,2f,36,1a,10,54,2e,19,fa,3f,4e,c5,d7,4a,\
"??"=hex:25,65,bb,27,8b,92,55,34,10,3f,d9,49,2f,0e,31,37

[HKEY_USERS\S-1-5-21-1292428093-261478967-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:0d,0f,83,99,81,44,01,aa,52,e4,a6,d3,8b,96,a2,11,81,ab,10,c0,71,
a4,59,f9,a9,3e,a6,59,18,6a,99,ec,c3,2f,09,1f,b4,02,08,3e,6f,b9,09,2e,36,b9,\
"rkeysecu"=hex:39,8e,b4,03,43,b1,cb,7f,cd,57,48,f4,e3,f0,30,67

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,6a,7e,cb,fd,2c,
77,13,94,c8,28,51,af,b0,29,a3,98,ab,71,42,5f,31,da,53,7f,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,35,f4,a9,79,e8,
ad,64,7a,71,3b,04,66,8b,46,0d,96,ed,fe,e9,10,07,ec,15,7a,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,cc,72,b9,00,dc,
e5,04,1e,25,da,ec,7e,55,20,c9,26,34,26,05,7a,d5,08,b5,57,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,c3,6f,d5,3c,98,
9c,fe,53,3e,1e,9e,e0,57,5a,93,61,23,ae,c9,ef,c4,c7,be,33,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,a3,42,f6,91,
a5,bd,c0,cd,44,cd,b9,a6,33,6c,cd,06,26,74,ee,9f,f0,f3,cf,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,22,e5,37,ee,98,
33,bd,ed,b0,18,ed,a7,3f,8d,37,a4,98,8a,ed,55,3d,b9,fe,3c,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,b5,45,2e,50,f0,
5f,b9,b1,31,77,e1,ba,b1,f8,68,02,4d,8a,06,1b,c3,7b,62,ae,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,bf,cb,77,84,18,
52,07,ac,83,6c,56,8b,a0,85,96,ab,ff,d7,a3,2c,9e,03,11,22,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,6d,10,c1,29,e2,
49,d6,8a,51,fa,6e,91,28,9e,14,cc,7c,d2,57,2d,e7,f1,e6,c1,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,d1,fd,70,19,c2,
78,b5,0d,b1,cd,45,5a,a8,c4,f8,b9,8b,0e,9b,61,e6,55,bc,3c,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,a8,23,6b,19,b7,
44,90,a2,e3,0e,66,d5,eb,bc,2f,6b,6a,a1,51,34,50,47,1f,83,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,de,79,db,1f,ea,
84,c5,4a,fa,ea,66,7f,d4,3b,6b,70,bb,e8,40,50,f4,cb,d1,12,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1152)
c:\windows\system32\DPGINA.dll
c:\windows\system32\DPWLEvHd.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(1212)
c:\windows\DPPWDFLT.dll
c:\windows\system32\nvappfilter.dll
.
Completion time: 2009-08-22 15:20
ComboFix-quarantined-files.txt 2009-08-22 22:20
ComboFix2.txt 2009-08-16 19:29

Pre-Run: 7,665,291,264 bytes free
Post-Run: 7,617,265,664 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
605

Shaba
2009-08-23, 11:48
Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a fresh HijackThis log.

If you need a tutorial, see here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif)

Devil2U
2009-08-26, 08:56
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, August 25, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, August 23, 2009 22:03:11
Records in database: 2681757
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\
R:\

Scan statistics:
Objects scanned: 685325
Threats found: 13
Infected objects found: 30
Suspicious objects found: 0
Scan duration: 56:45:12


File name / Threat / Threats count
C:\Documents and Settings\User\old folder of my docs-delete when raid is stable\-----FROM OLD COMP\Desktop\mirc621.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1
C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\vnc-4_1_2-x86_win32_viewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog\ikony\51904.exe Infected: not-a-virus:AdWare.Win32.Quick.a 1
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog\ikony\51904.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog\ikony\51904.exe Infected: not-a-virus:AdWare.Win32.Gator.3103 1
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog\login\58443.exe Infected: not-a-virus:AdWare.Win32.Quick.a 1
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog\login\58443.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog\login\58443.exe Infected: not-a-virus:AdWare.Win32.Gator.3103 1
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog.rar Infected: not-a-virus:AdWare.Win32.Quick.a 2
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog.rar Infected: not-a-virus:AdWare.Win32.NewDotNet 2
D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls\prog.rar Infected: not-a-virus:AdWare.Win32.Gator.3103 2
E:\My Documents\-----FROM OLD COMP\Desktop\mirc621.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1
F:\NEW Computer build 6-2-07 (Drivers + BIOS)\vnc-4_1_2-x86_win32_viewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
K:\LANFest incoming\PHOTOSHOP\WIP\VNCInstallfiles\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b 1
K:\LANFest incoming\PHOTOSHOP\WIP\VNCInstallfiles\WinVNC.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.h 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\Binaries\Landgen.exe Infected: Virus.Win32.Virut.ce 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\Data\Wav\BankEditor.exe Infected: Virus.Win32.Virut.ce 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\Data\Wav\EDITOR\BANKEDITOR.EXE Infected: Virus.Win32.Virut.ce 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\FIX.EXE Infected: Virus.Win32.Virut.ce 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\worms2.exe Infected: Virus.Win32.Virut.ce 1
L:\DC++ Inbound\PC World Top 20 Free Apps\SpywareTerminatorSetup.exe Infected: not-a-virus:AdWare.Win32.AdWeb.k 1
L:\DC++ Inbound\PC World Top 20 Free Apps\SpywareTerminatorSetup.exe Infected: not-a-virus:AdWare.Win32.WebSearch.bv 1
L:\Share Filez 5\- Codec Stuff -\FRAPS\Fraps.v2.6.3\Fraps.v2.6.3.WinALL.Retail-D@S.exe Infected: Backdoor.Win32.Ciadoor.123.bk 1
L:\Share Filez 5\Download Accelerator\dap53.exe Infected: not-a-virus:AdWare.Win32.Dap.g 1
L:\Share Filez 5\mirc614.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.614 1
R:\My Documents\-----FROM OLD COMP\Desktop\mirc621.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1

Selected area has been scanned.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52:38 PM, on 8/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\kmw_run.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS Wireless LAN\ZDConfig.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\User\Desktop\troj removal\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 165.228.131.12:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O3 - Toolbar: XfireXO Toolbar - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Yapta Tracker] C:\Program Files\Yapta\YaptaClient.exe /onstartup
O4 - HKLM\..\Run: [USB Stress Panic Button] C:\Program Files\USB Stress Panic Button\USB Stress Panic Button.exe -liuhong
O4 - HKLM\..\Run: [USB Electronic Scale] C:\Program Files\USB Electronic Scale\scale /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Free-1] "C:\Program Files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe"
O4 - HKLM\..\Run: [DPAgnt] C:\Program Files\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Advanced LAN Pump] C:\Program Files\SoftSolo\Advanced LAN Pump\alp.exe autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acronis*True*Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [Wootalyzer] "C:\Program Files\Wootalyzer\woot.exe" /boot
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "d:\games\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Logo Calibration Loader.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe
O4 - Global Startup: ProfileReminder.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: ZDConfig.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS Wireless LAN\ZDConfig.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} (STCWeb Control) - STCWeb.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} (DyynoX Class) - http://stage.dyyno.com/tng/dyyno-client/DyynoCAB.1.0.0.25.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228473500921
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {79E54B26-46B9-40EF-BFDC-0B1BB0D68897} - http://www.piclens.com/shared/plinstll.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://67.114.242.171/activex/AxisCamControl.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.lan1.instantaction.com/download/iaplayer.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15029/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: DPWLN - C:\WINDOWS\system32\DPWLEvHd.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\\agent.exe

--
End of file - 16295 bytes

Shaba
2009-08-26, 14:24
You seem to have some real nasties there:

K:\LANFest incoming\Worms 2\Worms2\WORMS2\Binaries\Landgen.exe Infected: Virus.Win32.Virut.ce 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\Data\Wav\BankEditor.exe Infected: Virus.Win32.Virut.ce 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\Data\Wav\EDITOR\BANKEDITOR.EXE Infected: Virus.Win32.Virut.ce 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\FIX.EXE Infected: Virus.Win32.Virut.ce 1
K:\LANFest incoming\Worms 2\Worms2\WORMS2\worms2.exe Infected: Virus.Win32.Virut.ce 1

Gladly you haven't likey used them; otherwise it would have been reformat & reinstall.

Delete these:

D:\Share Filez 2\Movies, Video, Clips\Installers\Style XP v3.19 - Female + Male (full)+1000 Themes +1000 Boot Screens +1000 Walls
K:\LANFest incoming\Worms 2\Worms2\WORMS2
L:\DC++ Inbound\PC World Top 20 Free Apps\SpywareTerminatorSetup.exe Infected: not-a-virus:AdWare.Win32.WebSearch.bv 1
L:\Share Filez 5\- Codec Stuff -\FRAPS\Fraps.v2.6.3\Fraps.v2.6.3.WinALL.Retail-D@S.exe
L:\Share Filez 5\Download Accelerator\dap53.exe

Empty Recycle Bin.

Still problems?

Devil2U
2009-08-27, 07:27
Ok, I deleted the files/paths that you specified. Are there any scans that I should re-run at this point?

Also, I know it can be highly subjective, but what Antivirus/Spyware protection do you recommend? I have Spybot S&D (of course!), Ad-Aware SE Plus, and AVG Free 8.5. Anything to add or remove from the mix?

Thanks again for your help btw, this forum and the people who help support it are of great value to the online community. :bigthumb:

Shaba
2009-08-27, 08:18
No need unless you have some issues left.

I will give you some tips in my final instructions.

Are you ready for them? :)

Devil2U
2009-08-28, 09:02
Fire away! :flame:

Shaba
2009-08-28, 09:25
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Looking over your log, it seems you don't have any evidence of a third party firewall.

As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

1) Comodo (http://www.personalfirewall.comodo.com/download_firewall.html) (Uncheck during installation "Install COMODO Antivirus (Recommended)"!, "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage")
2) Online Armor (http://www.tallemu.com/online_armor_free.html)
3) PC Tools (http://www.pctools.com/firewall/download/)
4) Sunbelt/Kerio (http://www.sunbelt-software.com/Kerio-Download.cfm)
5) ZoneAlarm (http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za) (uncheck ZoneAlarm Spy Blocker during installation if you choose this one)

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

Please download JavaRa (http://sourceforge.net/project/downloading.php?groupname=javara&filename=JavaRa.zip&use_mirror=osdn) and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

Double-click on JavaRa.exe to start the program.
From the drop-down menu, choose English and click on Select.
JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
A logfile will pop up. Please save it to a convenient location.

Then download and install Java Runtime Environment (JRE) 6 Update 16 (http://java.sun.com/javase/downloads/index.jsp).

Now lets uninstall ComboFix:

Click START then RUN
Now type Combofix /u in the runbox and click OK

Next we remove all used tools.

Please download OTCleanIt (http://oldtimer.geekstogo.com/OTC.exe) and save it to desktop.

Double-click OTCleanIt.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software and keep your other programs up-to-date
Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector (http://secunia.com/software_inspector/)
F-secure Health Check (http://www.f-secure.com/weblog/archives/00001356.html)


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

Malwarebytes' Anti-Malware Setup Guide (http://www.lognrock.com/forum/index.php?showtopic=6926)

Malwarebytes' Anti-Malware Scanning Guide (http://www.lognrock.com/forum/index.php?showtopic=6913)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://forums.spybot.info/showthread.php?t=279)

Happy surfing and stay clean! :bigthumb:

Shaba
2009-09-05, 12:07
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.