I was out of town for a family emergency and didn't respond in time - so hoping this can be looked at again…
This is the last information I received from jpshortstuff. I've run all scans requested and posted three logs below:
Hi,
We are getting there. You have a fair few files lying in your Program Files directory, have you put these there?
1. Please open Notepad
* Click Start , then Run
* Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
CODE
file::
C:\sqmnoopt03.sqm
C:\sqmdata03.sqm
C:\sqmnoopt02.sqm
C:\sqmdata02.sqm
C:\sqmdata01.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt00.sqm
C:\sqmdata00.sqm
c:\windows\DUMP33ad.tmp
c:\windows\DUMP1b4e.tmp
C:\sqmdata19.sqm
C:\sqmnoopt19.sqm
C:\sqmdata18.sqm
C:\sqmnoopt18.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
C:\sqmdata16.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt15.sqm
C:\sqmdata15.sqm
c:\windows\system32\bftifgkkheftuvn.exe
c:\windows\system32\kxkfoghc.jqh
c:\WINDOWS\bgrqfetx.dll
Folder::
c:\Program Files\IntCodec
Driver::
KXKFOGHC
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}]
Registry::
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{860c2f6b-ca82-4282-9187-beccbb66f0af}]
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{892B88A3-DC94-4A1F-A75A-9AA50061A683}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{411F83B1-A0EC-4155-AF99-0137F5EFB270}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C6B1408-FC27-4864-9B5D-F70A93A789C4}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{4E3645AF-7A81-4F83-9B8C-1E4F930D873F}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{61032A65-2371-4C89-B5BB-DF73090FB5EA}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{66189AF2-7726-46E8-8628-0F95AB854792}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{7A2F6251-6C99-4DA5-9827-954EB45DCB82}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{82C6C396-DD7B-4CE5-B668-C0087D1F3A1F}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{853E0D78-F4C2-47CB-A3F5-A774DA60DFCD}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{94786C47-EB3F-4BD5-A66B-0D49E2C90541}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{9989A9BC-9828-467E-AF06-E3B279E6E97B}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{B2B3702A-5425-489E-A3AF-EDCCAFEBA019}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{D01D4AAB-22C5-427F-A941-C4B65A3D8A23}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{DDB0D689-FAE0-4165-9F7C-877602F9DD66}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{EB5CA3AF-26C1-467B-9A55-2820E0451AAB}]
[-HKEY_LOCAL_MACHINE\software\Classes\Interface\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}]
[-HKEY_LOCAL_MACHINE\System\ControlSet003\Services\KXKFOGHC]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
FileLook::
c:\program files\AOLDNLD.exe
c:\program files\LimeWireWin.exe
3. Save the above as CFScript.txt
4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
* Combofix.txt
* A new HijackThis log.
Please go to Kaspersky website and perform an online antivirus scan.
1. Read through the requirements and privacy statement and click on Accept button.
2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
3. When the downloads have finished, click on Settings.
4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases
5. Click on My Computer under Scan.
6. Once the scan is complete, it will display the results. Click on View Scan Report.
7. You will see a list of infected items there. Click on Save Report As….
8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
9. Please post this log in your next reply.
Let me know how things are running now.
ComboFix 09-04-22.02 - Family 04/21/2009 16:38.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.210 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Family\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmdata18.sqm
C:\sqmdata19.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
C:\sqmnoopt19.sqm
c:\windows\bgrqfetx.dll
c:\windows\DUMP1b4e.tmp
c:\windows\DUMP33ad.tmp
c:\windows\system32\bftifgkkheftuvn.exe
c:\windows\system32\kxkfoghc.jqh
.
((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.
2009-04-16 01:18 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 01:18 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 01:18 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 01:18 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 01:18 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 01:18 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 01:18 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 01:18 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 01:18 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 01:17 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 01:17 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 01:17 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\scripting
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\l2schemas
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\en
2009-04-14 22:34 . 2009-04-14 22:34 ——– d—–w c:\windows\system32\bits
2009-04-14 22:25 . 2009-04-14 22:35 ——– d—–w c:\windows\ServicePackFiles
2009-04-14 22:07 . 2009-04-14 22:07 ——– d—–w c:\windows\EHome
2009-04-10 19:49 . 2009-04-10 19:48 410984 —-a-w c:\windows\system32\deploytk.dll
2009-04-10 19:12 . 2009-04-10 19:12 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-10 19:11 . 2009-04-10 19:11 ——– d—–w c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com
2009-04-10 09:01 . 2009-04-16 09:07 1374 —-a-w c:\windows\imsins.BAK
2009-04-09 20:11 . 2009-04-09 20:15 ——– d—–w C:\fixwareout
2009-04-09 20:08 . 2004-07-17 17:35 67866 ——w c:\windows\system32\drivers\netwlan5.img
2009-04-09 20:07 . 2007-09-17 08:48 1261 ——w c:\windows\system32\pid.inf
2009-04-09 20:02 . 2009-04-09 20:02 ——– d—–w c:\documents and settings\Family\Local Settings\Application Data\Mozilla
2009-04-09 19:53 . 2009-02-06 11:08 2189056 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-09 19:53 . 2009-02-06 11:06 2145280 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-09 19:53 . 2009-02-06 10:32 2023936 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-09 19:53 . 2009-02-08 01:02 2066048 -c—-w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-09 19:51 . 2008-10-24 11:21 455296 -c—-w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-09 19:51 . 2008-12-11 10:57 333952 -c—-w c:\windows\system32\dllcache\srv.sys
2009-04-09 19:51 . 2008-04-11 19:04 691712 -c—-w c:\windows\system32\dllcache\inetcomm.dll
2009-04-09 19:50 . 2008-10-15 16:34 337408 -c—-w c:\windows\system32\dllcache\netapi32.dll
2009-04-09 19:10 . 2009-04-09 19:10 ——– d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\documents and settings\Family\Application Data\Malwarebytes
2009-04-09 18:57 . 2009-04-06 21:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-09 18:57 . 2009-04-06 21:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-09 17:15 . 2009-04-14 18:00 ——– d–h–w C:\$AVG8.VAULT$
2009-04-09 17:12 . 2009-04-09 17:12 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-09 17:12 . 2009-04-09 17:12 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-09 17:12 . 2009-04-09 17:12 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-09 17:12 . 2009-04-21 22:30 ——– d—–w c:\windows\system32\drivers\Avg
2009-04-09 17:11 . 2009-04-09 18:19 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-09 16:58 . 2009-04-21 22:28 54156 —ha-w c:\windows\QTFont.qfn
2009-04-09 16:58 . 2009-04-09 16:58 1409 —-a-w c:\windows\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-21 22:35 . 2004-11-05 22:08 36560 —-a-w c:\windows\system32\nvModes.dat
2009-04-21 22:27 . 2006-02-09 16:10 ——– d—–w c:\program files\Symantec AntiVirus
2009-04-15 21:21 . 2006-01-17 22:15 20272 —-a-w c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-14 22:38 . 2005-12-29 01:39 77423 —-a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-14 22:19 . 2004-08-12 14:02 250048 –sha-r C:\ntldr
2009-04-10 19:48 . 2006-01-10 21:26 ——– d—–w c:\program files\Java
2009-04-10 19:40 . 2009-04-10 19:11 ——– d—–w c:\program files\SUPERAntiSpyware
2009-04-10 19:11 . 2009-04-10 19:11 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-09 20:48 . 2009-04-09 20:48 ——– d—–w c:\program files\Trend Micro
2009-04-09 19:31 . 2009-04-09 19:31 ——– d—–w c:\program files\CCleaner
2009-04-09 19:28 . 2009-04-09 19:26 ——– d—–w c:\program files\Wise Registry Cleaner
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-09 17:27 . 2008-08-11 05:47 ——– d—–w c:\documents and settings\All Users\Application Data\services
2009-04-09 17:11 . 2009-04-09 17:11 ——– d—–w c:\program files\AVG
2009-03-30 01:24 . 2008-05-18 03:31 ——– d—–w c:\program files\Apple Software Update
2009-03-30 00:52 . 2006-03-01 22:11 ——– d—–w c:\program files\Google
2009-03-06 14:22 . 2004-08-12 14:03 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-12 14:09 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-12 13:58 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2004-08-12 13:59 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-12 14:04 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2004-08-12 14:02 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-12 13:55 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2004-08-12 14:09 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-08 01:02 . 2004-08-03 22:59 2066048 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-12 14:05 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2004-08-12 14:02 2189056 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-12 14:04 35328 —-a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2004-08-12 14:04 56832 —-a-w c:\windows\system32\secur32.dll
2008-08-06 19:30 . 2006-02-19 05:32 19496 —-a-w c:\documents and settings\Rob\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-12-17 17:22 . 2007-12-17 17:22 284 —-a-w c:\documents and settings\Family\Application Data\ViewerApp.dat
2007-12-03 00:38 . 2007-09-04 01:02 836 —-a-w c:\documents and settings\Rob\Application Data\ViewerApp.dat
2006-02-20 22:27 . 2006-02-20 22:27 114660 —-a-w c:\program files\AOLDNLD.exe
2006-01-13 00:44 . 2006-01-13 00:44 34816 —-a-w c:\program files\Minutes Mountain Area - 1-06.doc
2006-01-13 00:43 . 2006-01-13 00:43 36864 —-a-w c:\program files\ESS Equipment Inventory Sheet.doc
2006-01-11 21:28 . 2006-01-11 21:28 10626920 —-a-w c:\program files\RhapsodyReal.exe
2006-01-11 21:09 . 2006-01-11 21:10 774144 —-a-w c:\program files\RngInterstitial.dll
2006-01-11 21:09 . 2006-01-11 21:08 482328 —-a-w c:\program files\realarcade_comcast_stub.exe
2006-01-11 18:08 . 2006-01-11 18:07 20921040 —-a-w c:\program files\AdbeRdr705_enu_full.exe
2006-01-10 21:24 . 2006-01-10 21:24 359112 —-a-w c:\program files\LimeWireWin.exe
2006-01-10 21:19 . 2006-01-10 21:18 2625400 —-a-w c:\program files\comcast_photoshow_deluxe_4.exe
2003-04-22 17:46 . 2003-04-22 17:46 2719744 ——w c:\program files\aiodrv.msi
2003-04-22 17:42 . 2003-04-22 17:42 2588672 ——w c:\program files\aiosw.msi
2003-04-22 17:24 . 2003-04-22 17:24 16606 —-a-w c:\program files\hpomdl01.dat
2003-04-22 17:23 . 2003-04-22 17:23 267 —-a-w c:\program files\readme.html
2003-04-10 01:19 . 2003-04-10 01:19 2848 —-a-w c:\program files\hpound08.inf
2003-04-10 01:19 . 2003-04-10 01:19 14157 —-a-w c:\program files\hpousc08.inf
2003-04-10 01:00 . 2003-04-10 01:00 2889 —-a-w c:\program files\hpousb08.inf
2003-04-10 01:00 . 2003-04-10 01:00 4715 —-a-w c:\program files\hpoglu08.inf
2003-03-20 23:20 . 2003-03-20 23:20 22523 —-a-w c:\program files\HPZius12.cat
2003-03-20 23:20 . 2003-03-20 23:20 22082 —-a-w c:\program files\hpzist12.cat
2003-03-20 23:20 . 2003-03-20 23:20 24728 —-a-w c:\program files\HPZipr12.cat
2003-03-20 23:20 . 2003-03-20 23:20 22082 —-a-w c:\program files\HPZid412.cat
2003-03-20 23:20 . 2003-03-20 23:20 21641 —-a-w c:\program files\HPOunp08.cat
2003-03-20 23:20 . 2003-03-20 23:20 24285 —-a-w c:\program files\hposcu08.cat
2003-03-20 23:20 . 2003-03-20 23:20 205503 —-a-w c:\program files\hpoprn08.cat
2003-03-10 04:30 . 2003-03-10 04:30 3667 —-a-w c:\program files\hpzist12.inf
2003-03-10 04:30 . 2003-03-10 04:30 184320 —-a-w c:\program files\hpzscr07.dll
2003-03-10 04:30 . 2003-03-10 04:30 14285 —-a-w c:\program files\hpzius12.inf
2003-03-10 04:30 . 2003-03-10 04:30 10325 —-a-w c:\program files\hpzipr12.inf
2003-03-10 04:30 . 2003-03-10 04:30 63562 —-a-w c:\program files\hposcu08.inf
2003-03-10 04:30 . 2003-03-10 04:30 51266 —-a-w c:\program files\hpoprn08.inf
2003-03-10 04:30 . 2003-03-10 04:30 3898 —-a-w c:\program files\hpounp08.inf
2003-03-10 04:30 . 2003-03-10 04:30 33952 —-a-w c:\program files\hpzid412.inf
2003-03-10 04:30 . 2003-03-10 04:30 274432 —-a-w c:\program files\hpzglu07.exe
2003-03-10 04:30 . 2003-03-10 04:30 237568 —-a-w c:\program files\hpzc3212.dll
2003-03-10 04:30 . 2003-03-10 04:30 23186 —-a-w c:\program files\hpzcin06.ex_
2002-09-10 01:48 . 2002-09-10 01:48 22608 —-a-w c:\program files\usbprint.sys
2002-09-10 01:48 . 2002-09-10 01:48 12288 —-a-w c:\program files\usbmon.dll
2002-09-10 01:47 . 2002-09-10 01:47 254005 —-a-w c:\program files\msvcrt.dll
2002-09-10 01:47 . 2002-09-10 01:47 70656 —-a-w c:\program files\msvcirt.dll
2002-09-10 01:47 . 2002-09-10 01:47 55155 —-a-w c:\program files\hpzusb00.sy_
2002-09-10 01:47 . 2002-09-10 01:47 5705 —-a-w c:\program files\hpzuci02.dl_
2002-09-10 01:47 . 2002-09-10 01:47 25639 —-a-w c:\program files\hpzpom04.dl_
2002-09-10 01:47 . 2002-09-10 01:47 212992 —-a-w c:\program files\hpzpnp07.dll
2002-09-10 01:46 . 2002-09-10 01:46 49212 —-a-w c:\program files\hpzjvp01.dll
2002-09-10 01:46 . 2002-09-10 01:46 249913 —-a-w c:\program files\hpzjut01.dll
2002-09-10 01:46 . 2002-09-10 01:46 417849 —-a-w c:\program files\hpzjpp01.dll
2002-09-10 01:46 . 2002-09-10 01:46 28722 —-a-w c:\program files\hpzjlog.dll
2002-09-10 01:46 . 2002-09-10 01:46 52552 —-a-w c:\program files\hpziou01.dl_
2002-09-10 01:46 . 2002-09-10 01:46 46017 —-a-w c:\program files\hpzion00.sy_
2002-09-06 17:54 . 2002-09-06 17:54 995383 —-a-w c:\program files\MFC42.DLL
2008-09-30 22:09 . 2008-09-30 12:42 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008093020081001\index.dat
2008-10-05 03:21 . 2008-10-04 17:18 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100420081005\index.dat
2008-10-12 20:17 . 2008-10-12 19:22 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101220081013\index.dat
2008-10-26 21:52 . 2008-10-26 21:09 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102620081027\index.dat
2008-10-28 21:39 . 2008-10-28 12:39 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102820081029\index.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- c:\program files\AOLDNLD.exe —-
Company: America Online, Inc.
File Description: AOL Download Utility 2.0.6.1.1
File Version: 2.0.6.1.1
Product Name: AOL Download Utility
Copyright: Copyright c 2004-2005 - America Online, Inc. All Rights Reserved.
Original file name:
File Size: 114660
Created Time: 2006-02-20 22:27
Modified Time: 2006-02-20 22:27
Accessed Time: 2009-04-21 22:38
MD5: 6BD12A800DB1D0823FAF19D22D757182
SHA: AB3458A9B476BEE6823D8EEE95E2CEAFD1E9CF9F
c:\program files\LimeWireWin.exe – Unable to find file version info.
File Size: 359112
Created Time: 2006-01-10 21:24
Modified Time: 2006-01-10 21:24
Accessed Time: 2009-04-21 22:38
MD5: 4F9BC958677DCC3C9B9AC8DE250C4E06
SHA: 6FD3B2D8546B3B938DB7614773588F16BC05B97E
((((((((((((((((((((((((((((( SnapShot@2009-04-15_21.11.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-21 22:27 . 2009-04-21 22:27 16384 c:\windows\Temp\Perflib_Perfdata_7e0.dat
+ 2004-08-12 14:10 . 2008-05-09 10:53 90112 c:\windows\system32\wshext.dll
- 2004-08-12 14:10 . 2008-04-14 00:12 90112 c:\windows\system32\wshext.dll
+ 2006-08-30 18:57 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2006-08-30 18:57 . 2007-08-11 02:46 26488 c:\windows\system32\spupdsvc.exe
- 2006-08-30 18:57 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
+ 2006-08-30 18:57 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2004-08-12 14:03 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2004-08-12 14:03 . 2008-12-20 23:15 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-12 14:03 . 2009-04-16 14:23 61544 c:\windows\system32\perfc009.dat
- 2004-08-12 14:03 . 2009-04-14 23:38 61544 c:\windows\system32\perfc009.dat
+ 2005-12-29 01:35 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
- 2005-12-29 01:35 . 2008-04-14 00:12 91648 c:\windows\system32\mtxoci.dll
+ 2004-08-12 14:01 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2004-08-12 14:01 . 2008-04-14 00:12 66560 c:\windows\system32\mtxclu.dll
- 2006-08-23 06:31 . 2008-12-20 23:15 52224 c:\windows\system32\msfeedsbs.dll
+ 2006-08-23 06:31 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
- 2005-12-29 01:35 . 2008-04-14 00:11 58880 c:\windows\system32\msdtclog.dll
+ 2005-12-29 01:35 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
+ 2004-08-12 13:58 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2004-08-12 13:58 . 2008-12-20 23:15 27648 c:\windows\system32\jsproxy.dll
+ 2006-08-23 06:13 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
- 2006-08-23 06:13 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
- 2004-08-12 13:58 . 2008-12-20 23:15 44544 c:\windows\system32\iernonce.dll
+ 2004-08-12 13:58 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2004-08-12 13:57 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2004-08-12 13:57 . 2008-12-19 09:10 70656 c:\windows\system32\ie4uinit.exe
- 2006-08-23 06:10 . 2008-12-20 23:15 63488 c:\windows\system32\icardie.dll
+ 2006-08-23 06:10 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 90112 c:\windows\system32\dllcache\wshext.dll
+ 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll
+ 2004-08-12 14:04 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
+ 2004-08-12 14:03 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2004-08-12 14:03 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2007-11-11 17:56 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-11-11 17:56 . 2008-12-20 23:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2004-08-12 13:58 . 2008-12-20 23:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-12 13:58 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-11-11 17:56 . 2008-12-19 09:10 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-11-11 17:56 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2004-08-12 13:58 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
- 2004-08-12 13:58 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
- 2004-08-12 13:57 . 2008-12-19 09:10 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-12 13:57 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-11-11 17:56 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-11-11 17:56 . 2008-12-20 23:15 63488 c:\windows\system32\dllcache\icardie.dll
+ 2006-01-13 00:45 . 2009-04-16 09:02 23040 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 23040 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 27136 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 27136 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 11264 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 11264 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 12288 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 12288 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-16 09:07 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-16 09:07 . 2008-04-14 00:11 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-16 09:07 . 2008-12-19 09:10 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2006-01-13 00:45 . 2009-04-16 09:02 4096 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 4096 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2004-08-12 14:10 . 2008-05-08 11:24 155648 c:\windows\system32\wscript.exe
- 2004-08-12 14:10 . 2008-04-14 00:12 155648 c:\windows\system32\wscript.exe
+ 2004-08-12 14:09 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
- 2004-08-12 14:09 . 2008-04-14 00:12 354304 c:\windows\system32\winhttp.dll
- 2004-08-12 14:09 . 2008-12-20 23:15 233472 c:\windows\system32\webcheck.dll
+ 2004-08-12 14:09 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2005-12-29 01:35 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2005-12-29 01:35 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2005-12-29 01:35 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
+ 2004-08-12 14:08 . 2008-05-09 10:53 430080 c:\windows\system32\vbscript.dll
- 2004-08-12 14:08 . 2008-12-20 23:15 105984 c:\windows\system32\url.dll
+ 2004-08-12 14:08 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
- 2004-08-12 14:04 . 2008-04-14 00:12 172032 c:\windows\system32\scrrun.dll
+ 2004-08-12 14:04 . 2008-05-09 10:53 172032 c:\windows\system32\scrrun.dll
- 2004-08-12 14:04 . 2008-04-14 00:12 180224 c:\windows\system32\scrobj.dll
+ 2004-08-12 14:04 . 2008-05-09 10:53 180224 c:\windows\system32\scrobj.dll
+ 2004-08-12 14:03 . 2009-04-16 14:23 401908 c:\windows\system32\perfh009.dat
- 2004-08-12 14:03 . 2009-04-14 23:38 401908 c:\windows\system32\perfh009.dat
+ 2004-08-12 14:02 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2004-08-12 14:02 . 2008-12-20 23:15 102912 c:\windows\system32\occache.dll
- 2004-08-12 14:01 . 2008-12-20 23:15 671232 c:\windows\system32\mstime.dll
+ 2004-08-12 14:01 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
- 2004-08-12 14:01 . 2008-12-20 23:15 193024 c:\windows\system32\msrating.dll
+ 2004-08-12 14:01 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
+ 2004-08-12 14:00 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
- 2004-08-12 14:00 . 2008-12-20 23:15 477696 c:\windows\system32\mshtmled.dll
- 2006-08-23 06:31 . 2008-12-20 23:15 459264 c:\windows\system32\msfeeds.dll
+ 2006-08-23 06:31 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
+ 2005-12-29 01:35 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
- 2005-12-29 01:35 . 2008-04-14 00:11 161792 c:\windows\system32\msdtcuiu.dll
+ 2005-12-29 01:35 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
- 2005-12-29 01:35 . 2008-04-14 00:11 956928 c:\windows\system32\msdtctm.dll
+ 2005-12-29 01:35 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
+ 2004-08-12 13:58 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
- 2004-08-12 13:58 . 2008-04-14 00:11 989696 c:\windows\system32\kernel32.dll
- 2004-08-12 13:58 . 2008-04-14 00:11 512000 c:\windows\system32\jscript.dll
+ 2004-08-12 13:58 . 2008-05-09 10:53 512000 c:\windows\system32\jscript.dll
+ 2006-08-23 06:09 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
+ 2006-08-23 05:36 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
- 2006-08-23 05:36 . 2008-12-20 23:15 383488 c:\windows\system32\ieapfltr.dll
+ 2004-08-12 13:57 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2004-08-12 13:57 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 133120 c:\windows\system32\extmgr.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2008-05-08 11:24 . 2008-05-08 11:24 155648 c:\windows\system32\dllcache\wscript.exe
+ 2004-08-12 14:09 . 2009-03-03 00:18 826368 c:\windows\system32\dllcache\wininet.dll
- 2004-08-12 14:09 . 2008-12-20 23:15 826368 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
+ 2004-08-12 14:09 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
- 2004-08-12 14:09 . 2008-12-20 23:15 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 430080 c:\windows\system32\dllcache\vbscript.dll
- 2004-08-12 14:08 . 2008-12-20 23:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-12 14:08 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
- 2004-08-12 14:02 . 2008-12-20 23:15 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-12 14:02 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-12 14:01 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2004-08-12 14:01 . 2008-12-20 23:15 671232 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-12 14:01 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2004-08-12 14:01 . 2008-12-20 23:15 193024 c:\windows\system32\dllcache\msrating.dll
+ 2004-08-12 14:00 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2004-08-12 14:00 . 2008-12-20 23:15 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2007-11-11 17:56 . 2008-12-20 23:15 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-11-11 17:56 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 512000 c:\windows\system32\dllcache\jscript.dll
+ 2005-12-29 01:37 . 2009-02-28 04:54 636072 c:\windows\system32\dllcache\iexplore.exe
+ 2007-11-11 17:56 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-11-11 17:56 . 2008-12-20 23:15 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-11-11 17:56 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2004-08-12 13:57 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
- 2004-08-12 13:57 . 2008-12-19 05:23 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-12 13:57 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2004-08-12 13:57 . 2008-12-20 23:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-05-07 09:07 . 2008-05-07 09:07 135168 c:\windows\system32\dllcache\cscript.exe
- 2004-08-12 13:55 . 2008-12-20 23:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-12 13:55 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-12 13:56 . 2008-05-07 09:07 135168 c:\windows\system32\cscript.exe
+ 2004-08-12 13:55 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2004-08-12 13:55 . 2008-12-20 23:15 124928 c:\windows\system32\advpack.dll
+ 2006-01-13 00:45 . 2009-04-16 09:02 409600 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 409600 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 286720 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 286720 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 249856 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 249856 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 794624 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 794624 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-01-13 00:45 . 2009-04-10 09:09 135168 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2006-01-13 00:45 . 2009-04-16 09:02 135168 c:\windows\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-16 09:07 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-16 09:07 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-16 09:07 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-16 09:07 . 2008-12-20 23:15 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-16 09:07 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2004-08-12 14:08 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2004-08-12 14:08 . 2008-12-20 23:15 1160192 c:\windows\system32\urlmon.dll
- 2004-08-12 14:03 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2004-08-12 14:03 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
+ 2009-04-09 20:08 . 2008-09-10 01:14 1307648 c:\windows\system32\msxml6.dll
+ 2004-08-12 14:00 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2006-08-23 06:31 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2006-08-11 01:44 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
- 2006-08-11 01:44 . 2007-04-17 09:32 2455488 c:\windows\system32\ieapfltr.dat
- 2004-08-12 14:08 . 2008-12-20 23:15 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-12 14:08 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2009-04-09 20:08 . 2008-09-10 01:14 1307648 c:\windows\system32\dllcache\msxml6.dll
+ 2004-08-12 14:00 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2007-11-11 17:56 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
- 2007-11-11 17:56 . 2007-04-17 09:32 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2007-11-11 17:56 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-04-16 09:07 . 2008-12-20 23:15 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-16 09:07 . 2009-01-17 03:35 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-16 09:07 . 2008-12-20 23:15 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-16 09:07 . 2007-04-17 09:32 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2009-04-09 19:53 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2009-04-09 19:53 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-04-09 19:53 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-04-09 19:53 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-04-09 19:53 . 2009-02-08 01:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-04-09 19:53 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2009-04-09 19:53 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2006-09-05 01:43 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe" [2005-05-09 192512]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-10 1830128]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-19 86016]
"SigmaTel StacMon"="c:\program files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2004-04-29 90169]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 66680]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-09 1932568]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil9f.exe" [2008-03-25 218496]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-13 22:17 110592 —-a-w c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-09 17:12 10520 —-a-w c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140474985\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140474985\\ee\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2004-03-12 169192]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-09 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-09 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-10 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-02-17 55024]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-09 298264]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-03-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:34]
2009-04-21 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 18:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://qwest.live.com/
mStart Page = hxxp://qwest.live.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Family\Application Data\Mozilla\Firefox\Profiles\c85z28qn.default\
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-21 16:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{20E1148B-A9DB-4678-82AB-E3E72B0F2959}\1.0]
@DACL=(02 0000)
@="bgrqfetx"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(804)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\LgNotify.dll
.
Completion time: 2009-04-21 16:43
ComboFix-quarantined-files.txt 2009-04-21 22:43
ComboFix2.txt 2009-04-16 05:35
ComboFix3.txt 2009-04-15 21:16
Pre-Run: 18,670,415,872 bytes free
Post-Run: 18,720,776,192 bytes free
Current=3 Default=3 Failed=2 LastKnownGood=1 Sets=1,2,3,4
527 — E O F — 2009-04-16 09:08
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Tuesday, April 21, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, April 22, 2009 02:42:33
Records in database: 2067570
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 89203
Threat name: 21
Infected objects: 96
Suspicious objects: 0
Duration of the scan: 02:08:18
File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00A00000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00A00001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00B00000.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00B00001.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02F80000.VBN Infected: Trojan-Downloader.Win32.Zlob.aeg 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03E80000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04040000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04040001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04040002.VBN Infected: Trojan-Downloader.Win32.Zlob.aeg 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\040C0002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500001.VBN Infected: Trojan-Downloader.Win32.Zlob.agv 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500003.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04500004.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04540000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04680000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04800000.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04900000.VBN Infected: Trojan-Downloader.Win32.Agent.acd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C40000.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.clk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C40001.VBN Infected: Packed.Win32.Krap.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C40002.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.kit 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C40003.VBN Infected: Packed.Win32.Krap.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05600000.VBN Infected: Trojan-Downloader.Win32.Zlob.ahd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05600001.VBN Infected: Hoax.Win32.Renos.fh 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0003.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0004.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05BC0005.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06240000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740000.VBN Infected: Trojan-Downloader.Win32.VB.aeq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740001.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740002.VBN Infected: Trojan-Downloader.Win32.Small.cpt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740003.VBN Infected: Trojan-Downloader.Win32.Small.cjk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740004.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740005.VBN Infected: Trojan-Downloader.Win32.Small.dam 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740006.VBN Infected: Trojan-Downloader.Win32.Small.ciw 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740007.VBN Infected: Trojan-Downloader.Win32.Zlob.ael 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740008.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06740009.VBN Infected: Trojan-Downloader.Win32.Zlob.agv 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0674000A.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0674000B.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06A80000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06A80001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06E00000.VBN Infected: Trojan.Win32.Agent.qe 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06F00000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07280000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07280001.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07280002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07280003.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07500000.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07540000.VBN Infected: Trojan-Downloader.Win32.Zlob.aeg 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07640000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07940000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.ahd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0002.VBN Infected: Packed.Win32.Krap.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0003.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.kit 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0004.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.clk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0005.VBN Infected: Packed.Win32.Krap.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07AC0006.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.kit 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07B80000.VBN Infected: Trojan-Downloader.Win32.Zlob.ael 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07C40000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07E00000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08E00000.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.kit 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09640000.VBN Infected: Trojan-Downloader.Win32.Small.dam 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A200000.VBN Infected: Trojan.Win32.Vapsup.kew 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A5C0000.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A5C0001.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A780000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B740000.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B8C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B8C0001.VBN Infected: Trojan-Downloader.Win32.Zlob.aeg 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B8C0002.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BCC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0BCC0001.VBN Infected: Trojan-Downloader.Win32.Zlob.agv 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C080000.VBN Infected: Hoax.Win32.Renos.fh 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680000.VBN Infected: Trojan-Downloader.Win32.VB.aeq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680001.VBN Infected: Trojan-Downloader.Win32.VB.aeq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680002.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680003.VBN Infected: Trojan-Proxy.Win32.Lager.aq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680004.VBN Infected: Trojan-Downloader.Win32.Small.cpt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680005.VBN Infected: Trojan-Downloader.Win32.Small.cpt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680006.VBN Infected: Trojan-Downloader.Win32.Small.cjk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680008.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680009.VBN Infected: Packed.Win32.Tibs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C68000A.VBN Infected: Trojan-Downloader.Win32.Small.dam 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C68000B.VBN Infected: Trojan-Downloader.Win32.Small.dam 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C68000C.VBN Infected: Trojan-Downloader.Win32.Small.ciw 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C68000D.VBN Infected: Trojan-Downloader.Win32.Small.ciw 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F4C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.yt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F680000.VBN Infected: Trojan-Downloader.Win32.VB.aan 1
C:\WINDOWS\system32\ayonkyyu.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ewt 1
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:24:13 PM, on 4/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://qwest.live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Qwest Live - {3A97D3DF-91B6-4557-BCFB-381872254C87} -
http://qwest.live.com (file missing) (HKCU)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 9818 bytes