Thanks again,
It's a job to handle PCANDIS5.SYS, AVG keeps grabbing hold of it !
....searching registry:-
....found keys -
HKCU\Software\Microsoft\Wwindows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\ \C:\WINDOWS\system32\PCANDIS5.sys
HKCU\Software\Microsoft\Wwindows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\sys\C:\WINDOWS\system32\PCANDIS5.sys
..... all seems to be okay ?
Key Name:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\
Class Name: <NO CLASS>
Last Write Time: 6/28/2008 - 1:50 PM
Value 0
Name: a
Type: REG_SZ
Data: C:\WINDOWS\system32\PCANDIS5.sys
etc. ...recently handled files ?
Key Name: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCANDIS5
Class Name: <NO CLASS>
Last Write Time: 6/28/2008 - 9:57 AM
Value 0
Name: Type
Type: REG_DWORD
Data: 0x1
Value 1
Name: Start
Type: REG_DWORD
Data: 0x3
Value 2
Name: ErrorControl
Type: REG_DWORD
Data: 0x1
Value 3
Name: ImagePath
Type: REG_EXPAND_SZ
Data: \??\C:\WINDOWS\system32\PCANDIS5.SYS
Value 4
Name: DisplayName
Type: REG_SZ
Data: PCANDIS5 NDIS Protocol Driver
Value 5
Name: Group
Type: REG_SZ
Data: PNP_TDI
Key Name:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCANDIS5\Security
Class Name: <NO CLASS>
Last Write Time: 5/6/2008 - 11:09 PM
Value 0
Name: Security
Type: REG_BINARY
Data:
00000000 01 00 14 80 90 00 00 00 - 9c 00 00 00 14 00 00 00
.................
00000010 30 00 00 00 02 00 1c 00 - 01 00 00 00 02 80 14 00
0...............
00000020 ff 01 0f 00 01 01 00 00 - 00 00 00 01 00 00 00 00
ÿ...............
00000030 02 00 60 00 04 00 00 00 - 00 00 14 00 fd 01 02 00
...`.........ý...
00000040 01 01 00 00 00 00 00 05 - 12 00 00 00 00 00 18 00
.................
00000050 ff 01 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ÿ...........
....
00000060 20 02 00 00 00 00 14 00 - 8d 01 02 00 01 01 00 00
................
00000070 00 00 00 05 0b 00 00 00 - 00 00 18 00 fd 01 02 00
.............ý...
00000080 01 02 00 00 00 00 00 05 - 20 00 00 00 23 02 00 00 ........
....#...
00000090 01 01 00 00 00 00 00 05 - 12 00 00 00 01 01 00 00
.................
000000a0 00 00 00 05 12 00 00 00 - ........
Key Name:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCANDIS5\Enum
Class Name: <NO CLASS>
Last Write Time: 6/28/2008 - 9:57 AM
Value 0
Name: 0
Type: REG_SZ
Data: Root\LEGACY_PCANDIS5\0000
Value 1
Name: Count
Type: REG_DWORD
Data: 0x1
Value 2
Name: NextInstance
Type: REG_DWORD
Data: 0x1
....NEXT
Key Name: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\PCANDIS5
Class Name: <NO CLASS>
Last Write Time: 6/28/2008 - 9:57 AM
Value 0
Name: Type
Type: REG_DWORD
Data: 0x1
Value 1
Name: Start
Type: REG_DWORD
Data: 0x3
Value 2
Name: ErrorControl
Type: REG_DWORD
Data: 0x1
Value 3
Name: ImagePath
Type: REG_EXPAND_SZ
Data: \??\C:\WINDOWS\system32\PCANDIS5.SYS
Value 4
Name: DisplayName
Type: REG_SZ
Data: PCANDIS5 NDIS Protocol Driver
Value 5
Name: Group
Type: REG_SZ
Data: PNP_TDI
Key Name:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\PCANDIS5\Security
Class Name: <NO CLASS>
Last Write Time: 5/6/2008 - 11:09 PM
Value 0
Name: Security
Type: REG_BINARY
Data:
00000000 01 00 14 80 90 00 00 00 - 9c 00 00 00 14 00 00 00
.................
00000010 30 00 00 00 02 00 1c 00 - 01 00 00 00 02 80 14 00
0...............
00000020 ff 01 0f 00 01 01 00 00 - 00 00 00 01 00 00 00 00
ÿ...............
00000030 02 00 60 00 04 00 00 00 - 00 00 14 00 fd 01 02 00
...`.........ý...
00000040 01 01 00 00 00 00 00 05 - 12 00 00 00 00 00 18 00
.................
00000050 ff 01 0f 00 01 02 00 00 - 00 00 00 05 20 00 00 00 ÿ...........
....
00000060 20 02 00 00 00 00 14 00 - 8d 01 02 00 01 01 00 00
................
00000070 00 00 00 05 0b 00 00 00 - 00 00 18 00 fd 01 02 00
.............ý...
00000080 01 02 00 00 00 00 00 05 - 20 00 00 00 23 02 00 00 ........
....#...
00000090 01 01 00 00 00 00 00 05 - 12 00 00 00 01 01 00 00
.................
000000a0 00 00 00 05 12 00 00 00 - ........
....even though I haven't a clue as to what all this lot is, Upnp seems to be
cropping up !
....recently I switched off Upnp, ...perphaps I should switch it back on !
....I think I give up !
regards, Richard