This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] pqlmq.exe removal?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For a awhile now my computer has had something wrong with it, games take up much more processing power than they should, firefox crashes constantly (once while typing this), and my computer has been crashing alot of late. I have run multiple scans to no avail, but in my startup I found pqlmq.exe which I hear is a trojan. What I want to know is, could it be causing this horrible computer problem, and how should I go about killing it? added rootrepeal, hijackthis. Edit: My computer seems to slowly be getting worse and worse…
Edit2: Crashing alot more, and one time the blue screen had a red square at the bottom left side…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:25:16 PM, on 12/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\IObit\Game Booster\GameBooster.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Grey\My Documents\Downloads\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\system32\logon.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [Spooler SubSystem App] C:\WINDOWS\system32\spooIsv.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Steam] "E:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "e:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [12CFG515-K641-55SF-N66P] C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556\pqlmq.exe
O4 - Startup: MagicDisc.lnk = E:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Application Data\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1256186676702
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 6801 bytes
Hi TopHatMan,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Well, the funny thing is, I had a friend help me out about an hour before your post and he had me do comboxfix, lots of recycler viruses. My computer seemed to be finally good again, but now its back to the same thing, however, I am pretty sure that it is clean. On boot, start bar and the bars next to it are broken and unresponsive, clicking bookmarks in firefox makes firefox freeze. I am not sure, but I think my comp may have RAM/Video driver issues, here's an error code I got from the last crash I had. 0x0000008e (0x00000005, 0x8054BBAD, 0xA964A9F0, 0x00000000). I also get alot of "The memory could not be 'read'" errors when playing games. Chkdsk perhaps? Any thoughts? Also thanks for the help.
Well, I can post the second log from the last run I had with it, the first one got "corrupted" when windows was booted afterwards.

ComboFix 09-12-21.08 - Administrator 12/23/2009 21:56:07.2.1 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.3090 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091223-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Grey\Local Settings\temp\~11F.tmp
c:\documents and settings\Grey\Local Settings\temp\~63.tmp

.
((((((((((((((((((((((((( Files Created from 2009-11-24 to 2009-12-24 )))))))))))))))))))))))))))))))
.

2009-12-24 02:25 . 2009-12-24 02:25 ——– d—–w- c:\windows\system32\xlive
2009-12-24 02:25 . 2009-12-24 02:25 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE
2009-12-23 05:16 . 2009-12-23 05:17 ——– d—–w- c:\documents and settings\Grey\Application Data\Stella
2009-12-23 04:43 . 2004-07-09 11:26 47104 -c–a-w- c:\windows\system32\dllcache\wstdecod.dll
2009-12-23 04:43 . 2004-07-09 11:26 1230336 -c–a-w- c:\windows\system32\dllcache\msvidctl.dll
2009-12-23 04:12 . 2009-12-23 04:12 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\ATI
2009-12-23 04:12 . 2009-12-23 04:12 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\ATI
2009-12-22 19:05 . 2009-12-22 19:07 ——– d—–w- c:\documents and settings\Administrator
2009-12-22 03:42 . 2009-12-22 03:43 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-18 04:08 . 2009-12-18 04:08 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-18 04:08 . 2009-12-18 04:08 ——– d—–w- c:\program files\NOS
2009-12-18 00:09 . 2009-12-18 00:09 152576 —-a-w- c:\documents and settings\Grey\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-18 00:09 . 2009-12-18 00:09 79488 —-a-w- c:\documents and settings\Grey\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-17 23:00 . 2009-12-17 23:00 ——– d—–w- c:\program files\IObit
2009-12-17 03:36 . 2009-11-24 23:49 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-17 03:36 . 2009-11-24 23:48 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-17 03:36 . 2009-11-24 23:47 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-17 03:36 . 2009-11-24 23:51 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-17 03:36 . 2009-11-24 23:50 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-17 03:36 . 2009-11-24 23:50 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-17 03:36 . 2009-11-24 23:50 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-17 03:36 . 2009-11-24 23:47 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-12-17 03:36 . 2009-11-24 23:54 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2009-12-17 01:47 . 2009-12-17 01:47 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-12-17 01:03 . 2009-10-29 07:45 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-17 01:03 . 2009-10-29 07:45 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-17 01:03 . 2009-10-29 07:45 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-12-17 01:03 . 2009-10-29 07:45 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-17 01:03 . 2009-10-29 07:45 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-12-17 01:03 . 2009-10-29 07:45 11069952 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-12-17 00:40 . 2009-12-17 00:40 ——– d—–w- c:\windows\system32\scripting
2009-12-17 00:40 . 2009-12-17 00:40 ——– d—–w- c:\windows\l2schemas
2009-12-17 00:40 . 2009-12-17 00:40 ——– d—–w- c:\windows\system32\en
2009-12-17 00:18 . 2009-12-17 00:18 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-17 00:16 . 2009-12-17 00:16 ——– d-sh–w- c:\documents and settings\Grey\PrivacIE
2009-12-17 00:15 . 2009-12-17 00:15 ——– d-sh–w- c:\documents and settings\Grey\IETldCache
2009-12-17 00:12 . 2009-12-17 01:39 ——– d—–w- c:\windows\ie8updates
2009-12-17 00:10 . 2009-12-17 00:11 ——– dc-h–w- c:\windows\ie8
2009-12-17 00:07 . 2009-10-02 04:44 92160 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-12-17 00:02 . 2009-12-17 00:02 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\SHOUTcast Radio Toolbar
2009-12-17 00:02 . 2009-12-17 00:02 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\Winamp Toolbar
2009-12-16 21:33 . 2009-12-16 21:33 ——– d—–w- c:\documents and settings\Grey\Application Data\Malwarebytes
2009-12-16 21:32 . 2009-12-03 23:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-16 21:32 . 2009-12-16 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-16 21:32 . 2009-12-16 21:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-16 21:32 . 2009-12-03 23:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-16 04:40 . 2009-12-16 04:40 ——– d—–w- C:\ERDNT
2009-12-15 05:14 . 2009-12-15 05:14 ——– d—–w- c:\windows\system32\DRVSTORE
2009-12-15 04:33 . 2009-12-15 04:33 10134 —-a-r- c:\documents and settings\Grey\Application Data\Microsoft\Installer\{7FAB9334-804D-34B7-BF98-7C8348CE81C1}\ARPPRODUCTICON.exe
2009-12-15 04:27 . 2009-12-21 19:17 ——– d—–w- c:\program files\ATI
2009-12-15 04:25 . 2009-12-15 04:25 ——– d—–w- C:\ATI
2009-12-15 03:44 . 2009-12-15 03:44 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\Identities
2009-12-14 01:25 . 2009-12-15 01:25 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-13 03:49 . 2009-12-13 03:49 ——– d—–w- c:\program files\SHOUTcast Radio Toolbar
2009-12-13 03:49 . 2009-12-13 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\SHOUTcast Radio Toolbar
2009-12-13 03:49 . 2009-12-13 03:49 ——– d—–w- c:\program files\Winamp Toolbar
2009-12-13 03:49 . 2009-12-13 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Winamp Toolbar
2009-12-13 02:21 . 2009-12-13 02:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Nexon
2009-12-12 18:34 . 2009-12-12 18:34 90112 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2009-12-12 18:34 . 2009-12-12 18:34 393216 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-12-12 18:34 . 2009-12-12 18:34 258352 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2009-12-12 18:34 . 2009-12-12 18:34 118784 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2009-12-12 18:34 . 2009-12-13 02:21 ——– d—–w- c:\documents and settings\All Users\Application Data\NexonUS
2009-12-12 18:34 . 2009-12-12 18:34 561152 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2009-12-12 18:34 . 2009-12-12 18:34 167936 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2009-12-10 04:21 . 2009-12-10 04:21 ——– d—–w- c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP
2009-12-08 00:19 . 2009-12-16 04:39 ——– d—–w- c:\program files\No-IP
2009-12-06 07:27 . 2009-12-06 07:27 ——– d—–w- c:\program files\GCFScape
2009-12-06 07:26 . 2009-12-06 07:27 ——– d—–w- c:\documents and settings\Grey\Application Data\Notepad++
2009-12-06 07:26 . 2009-12-06 07:27 ——– d—–w- c:\program files\Notepad++
2009-12-06 00:02 . 2009-12-06 00:02 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-12-05 23:43 . 2009-12-05 23:43 ——– d—–w- c:\program files\Adobe Media Player
2009-12-05 23:41 . 2009-12-05 23:41 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-05 23:35 . 2009-12-06 00:02 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\Adobe
2009-12-05 23:35 . 2009-12-05 23:35 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2009-12-05 23:33 . 2009-12-05 23:45 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-01 01:02 . 2009-12-01 01:02 171144 —-a-w- c:\windows\system32\xliveinstall.dll
2009-12-01 01:02 . 2009-12-01 01:02 72840 —-a-w- c:\windows\system32\xliveinstallhost.exe
2009-11-29 07:33 . 2009-11-29 07:33 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\Blizzard Entertainment
2009-11-29 05:50 . 2009-11-29 05:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-11-29 05:49 . 2009-11-29 05:49 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-11-29 05:48 . 2009-11-29 05:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-11-29 03:11 . 2009-12-18 01:17 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\PMB Files
2009-11-29 03:11 . 2009-12-13 02:20 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2009-11-29 03:10 . 2009-11-29 03:10 ——– d—–w- c:\program files\Pando Networks
2009-11-28 19:08 . 2009-11-28 19:08 ——– d—–w- c:\documents and settings\Grey\Application Data\TortoiseSVN
2009-11-28 18:14 . 2009-12-24 04:51 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\TSVNCache
2009-11-27 21:40 . 2009-11-27 21:40 ——– d—–w- c:\documents and settings\Grey\Application Data\Subversion
2009-11-27 21:29 . 2009-11-27 21:29 ——– d—–w- c:\program files\TortoiseSVN
2009-11-27 21:29 . 2009-11-27 21:29 ——– d—–w- c:\program files\Common Files\TortoiseOverlays
2009-11-27 04:46 . 2009-11-27 04:46 ——– d—–w- c:\documents and settings\Grey\Application Data\Ventrilo
2009-11-27 03:18 . 2009-11-27 03:18 ——– d—–w- c:\documents and settings\All Users\Application Data\GoldWave
2009-11-27 03:18 . 2009-09-26 16:00 496640 —-a-w- c:\documents and settings\All Users\Application Data\GoldWave\lame_enc.dll
2009-11-27 03:11 . 2009-11-27 03:11 ——– d—–w- c:\documents and settings\Grey\Application Data\AccurateRip
2009-11-27 03:11 . 2009-11-27 03:09 5640880 —-a-w- c:\windows\system32\SpoonUninstall.exe
2009-11-27 02:50 . 2004-12-03 01:20 1843200 —-a-w- c:\windows\system32\NCTAudioFile2.dll
2009-11-27 02:50 . 2004-12-03 01:11 315392 —-a-w- c:\windows\system32\NCTAudioPlayer2.dll
2009-11-27 02:50 . 2004-05-20 22:24 196608 —-a-w- c:\windows\system32\NCTWMAFile2.dll
2009-11-27 02:50 . 2002-01-05 22:37 344064 —-a-w- c:\windows\system32\msvcr70.dll
2009-11-25 20:10 . 2009-12-17 03:09 ——– d—–w- c:\program files\Common Files\Akamai

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-23 04:41 . 2009-10-22 05:11 ——– d—–w- c:\program files\ATI Technologies
2009-12-22 03:21 . 2009-10-22 03:38 ——– d—–r- c:\program files\Support.com
2009-12-19 20:39 . 2009-10-21 20:16 90112 —-a-w- c:\windows\DUMP8750.tmp
2009-12-18 00:10 . 2009-10-22 06:52 ——– d—–w- c:\program files\Java
2009-12-17 03:36 . 2009-10-23 08:44 ——– d—–w- c:\program files\Alwil Software
2009-12-17 03:13 . 2009-11-04 23:54 ——– d—–w- c:\documents and settings\Grey\Application Data\uTorrent
2009-12-17 01:21 . 2009-10-23 08:58 ——– d—–w- c:\program files\Google
2009-12-17 00:43 . 2009-10-22 02:28 76487 —-a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-12-15 05:14 . 2009-12-13 03:46 ——– d—–w- c:\program files\Winamp
2009-12-13 03:58 . 2009-12-13 03:46 ——– d—–w- c:\documents and settings\Grey\Application Data\Winamp
2009-11-07 07:16 . 2009-11-07 07:16 62304 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-06 17:59 . 2009-11-06 17:59 15406728 —-a-w- c:\windows\system32\xlive.dll
2009-11-06 17:59 . 2009-11-06 17:59 13642888 —-a-w- c:\windows\system32\xlivefnt.dll
2009-10-29 07:45 . 2006-06-23 17:33 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-27 01:46 . 2009-10-22 05:47 13104 —-a-w- c:\documents and settings\Grey\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-26 23:33 . 2009-10-22 03:33 ——– d—–w- c:\documents and settings\Grey\Application Data\U3
2009-10-26 23:00 . 2009-10-26 23:00 ——– d—–w- c:\program files\MSBuild
2009-10-26 23:00 . 2009-10-26 23:00 ——– d—–w- c:\program files\Reference Assemblies
2009-10-26 22:56 . 2009-10-26 22:56 ——– d—–w- c:\program files\MSXML 6.0
2009-10-25 17:25 . 2009-10-25 17:25 ——– d—–w- c:\program files\MSXML 4.0
2009-10-23 09:02 . 2009-10-23 09:02 152576 —-a-w- c:\documents and settings\Grey\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-22 05:50 . 2009-10-22 05:50 0 —-a-w- c:\windows\nsreg.dat
2009-10-22 05:29 . 2009-10-22 05:29 9158 —-a-r- c:\documents and settings\Grey\Application Data\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
2009-10-22 02:28 . 2009-10-22 02:28 558142 —-a-w- c:\windows\java\Packages\BLNR5VFT.ZIP
2009-10-22 02:28 . 2009-10-22 02:28 2678 —-a-w- c:\windows\java\Packages\Data\WVXJDZLF.DAT
2009-10-22 02:28 . 2009-10-22 02:28 2678 —-a-w- c:\windows\java\Packages\Data\EVR7JN7J.DAT
2009-10-22 02:28 . 2009-10-22 02:28 155995 —-a-w- c:\windows\java\Packages\JD7R13LR.ZIP
2009-10-22 02:28 . 2009-10-22 02:28 2678 —-a-w- c:\windows\java\Packages\Data\RB1VP775.DAT
2009-10-22 02:28 . 2009-10-22 02:28 2678 —-a-w- c:\windows\java\Packages\Data\E21NFXBN.DAT
2009-10-22 02:28 . 2009-10-22 02:28 2678 —-a-w- c:\windows\java\Packages\Data\73V5F1F1.DAT
2009-10-22 02:26 . 2009-10-22 02:26 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:54 . 2009-10-20 16:54 59992 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\English\setup.exe
2009-10-20 16:20 . 2004-08-04 06:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-05-14 09:13 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2002-09-03 16:55 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2002-09-03 16:54 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-11 11:17 . 2009-10-23 09:03 411368 —-a-w- c:\windows\system32\deploytk.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-12-22_19.18.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-09-23 08:35 . 2005-09-23 08:35 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2005-09-23 07:58 . 2005-09-23 07:58 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2005-09-23 08:16 . 2005-09-23 08:16 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2005-09-23 08:16 . 2005-09-23 08:16 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2005-09-23 06:49 . 2005-09-23 06:49 95744 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2009-12-23 04:41 . 2001-11-09 15:01 24064 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ativcoxx.dll
+ 2009-12-23 04:41 . 2007-11-02 03:22 17408 c:\windows\system32\ReinstallBackups\0000\DriverFiles\atitvo32.dll
+ 2009-12-23 04:41 . 2007-07-20 02:19 81920 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ATIODE.exe
+ 2009-12-23 04:41 . 2007-07-20 02:19 40960 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ATIODCLI.exe
+ 2009-12-23 04:41 . 2007-11-02 03:58 53248 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ATIDDC.DLL
+ 2009-12-23 04:41 . 2007-11-02 04:01 26112 c:\windows\system32\ReinstallBackups\0000\DriverFiles\Ati2mdxx.exe
+ 2009-12-23 04:41 . 2007-11-02 03:22 49152 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2erec.dll
+ 2009-12-23 04:41 . 2007-11-02 04:00 43520 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2edxx.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 46592 c:\windows\system32\dxdllreg.exe
- 2009-10-22 05:19 . 2002-12-12 06:14 46592 c:\windows\system32\dxdllreg.exe
+ 2009-12-23 04:42 . 2002-08-29 10:41 31744 c:\windows\system32\dllcache\pid.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 13312 c:\windows\system32\dllcache\msdmo.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 34304 c:\windows\system32\dllcache\mciqtz32.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 18432 c:\windows\system32\dllcache\dswave.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 79360 c:\windows\system32\dllcache\dpwsockx.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 80896 c:\windows\system32\dllcache\dpvsetup.exe
+ 2009-12-23 04:42 . 2002-12-12 07:14 19968 c:\windows\system32\dllcache\dpvacm.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 16896 c:\windows\system32\dllcache\dpnsvr.exe
+ 2009-12-23 04:42 . 2003-03-24 16:00 68096 c:\windows\system32\dllcache\dpnhupnp.dll
+ 2009-12-23 04:42 . 2003-03-24 16:00 32768 c:\windows\system32\dllcache\dpnhpast.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 77824 c:\windows\system32\dllcache\dpmodemx.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 28160 c:\windows\system32\dllcache\dplaysvr.exe
+ 2009-12-23 04:42 . 2002-12-12 07:14 98816 c:\windows\system32\dllcache\dmstyle.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 76800 c:\windows\system32\dllcache\dmscript.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 33280 c:\windows\system32\dllcache\dmloader.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 58368 c:\windows\system32\dllcache\dmcompos.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 27136 c:\windows\system32\dllcache\dmband.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 24064 c:\windows\system32\dllcache\ddrawex.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 64512 c:\windows\system32\dllcache\amstream.dll
- 2009-10-22 05:19 . 2004-07-09 10:26 47104 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\wstdecod.dll
+ 2009-10-22 05:19 . 2004-07-09 11:26 47104 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\wstdecod.dll
- 2009-10-22 05:19 . 2004-07-09 10:26 18688 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\wstcodec.sys
+ 2009-10-22 05:19 . 2004-07-09 11:26 18688 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\wstcodec.sys
- 2009-10-22 05:19 . 2004-07-09 10:26 14976 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\streamip.sys
+ 2009-10-22 05:19 . 2004-07-09 11:26 14976 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\streamip.sys
- 2009-10-22 05:19 . 2004-07-09 10:26 10880 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\slip.sys
+ 2009-10-22 05:19 . 2004-07-09 11:26 10880 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\slip.sys
- 2009-10-22 05:19 . 2004-07-09 10:26 10112 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\ndisip.sys
+ 2009-10-22 05:19 . 2004-07-09 11:26 10112 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\ndisip.sys
+ 2009-10-22 05:19 . 2004-07-09 11:26 83968 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\nabtsfec.sys
- 2009-10-22 05:19 . 2004-07-09 10:26 83968 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\nabtsfec.sys
+ 2009-10-22 05:19 . 2004-07-09 11:26 16896 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\msyuv.dll
- 2009-10-22 05:19 . 2004-07-09 10:26 16896 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\msyuv.dll
+ 2009-10-22 05:19 . 2004-07-09 11:26 15104 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\mpe.sys
- 2009-10-22 05:19 . 2004-07-09 10:26 15104 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\mpe.sys
- 2009-10-22 05:19 . 2004-07-09 10:26 16384 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\ccdecode.sys
+ 2009-10-22 05:19 . 2004-07-09 11:26 16384 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\ccdecode.sys
- 2009-10-22 05:19 . 2004-07-09 10:26 11392 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\bdasup.sys
+ 2009-10-22 05:19 . 2004-07-09 11:26 11392 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\bdasup.sys
+ 2009-10-22 05:19 . 2004-07-09 11:27 48512 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\stream.sys
- 2009-10-22 05:19 . 2004-07-09 10:27 48512 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\stream.sys
+ 2009-10-22 05:19 . 2002-12-12 07:14 13312 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\msdmo.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 13312 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\msdmo.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 34304 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mciqtz32.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 34304 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mciqtz32.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 18944 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\encapi.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 18944 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\encapi.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 46592 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe
- 2009-10-22 05:19 . 2002-12-12 06:14 46592 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe
+ 2009-10-22 05:19 . 2002-12-12 07:14 18432 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dswave.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 18432 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dswave.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 79360 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpwsockx.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 79360 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpwsockx.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 80896 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvsetup.exe
- 2009-10-22 05:19 . 2002-12-12 06:14 80896 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvsetup.exe
- 2009-10-22 05:19 . 2002-12-12 06:14 19968 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvacm.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 19968 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvacm.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 16896 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnsvr.exe
+ 2009-10-22 05:19 . 2002-12-12 07:14 16896 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnsvr.exe
+ 2009-10-22 05:19 . 2003-03-24 16:00 68096 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnhupnp.dll
- 2009-10-22 05:19 . 2003-03-24 15:00 68096 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnhupnp.dll
+ 2009-10-22 05:19 . 2003-03-24 16:00 32768 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnhpast.dll
- 2009-10-22 05:19 . 2003-03-24 15:00 32768 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnhpast.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 77824 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpmodemx.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 77824 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpmodemx.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 28160 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dplaysvr.exe
- 2009-10-22 05:19 . 2002-12-12 06:14 28160 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dplaysvr.exe
- 2009-10-22 05:19 . 2002-12-12 06:14 98816 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmstyle.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 98816 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmstyle.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 76800 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmscript.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 76800 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmscript.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 33280 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmloader.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 33280 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmloader.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 58368 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmcompos.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 58368 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmcompos.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 27136 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmband.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 27136 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmband.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 24064 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddrawex.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 24064 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddrawex.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 64512 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\amstream.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 64512 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\amstream.dll
+ 2009-12-23 04:43 . 2004-07-09 11:26 18688 c:\windows\Driver Cache\i386\wstcodec.sys
+ 2009-12-23 04:43 . 2004-07-09 11:26 14976 c:\windows\Driver Cache\i386\streamip.sys
+ 2009-12-23 04:43 . 2004-07-09 11:27 48512 c:\windows\Driver Cache\i386\stream.sys
+ 2009-12-23 04:43 . 2004-07-09 11:26 10880 c:\windows\Driver Cache\i386\slip.sys
+ 2009-12-23 04:42 . 2002-08-29 10:41 31744 c:\windows\Driver Cache\i386\pid.dll
+ 2009-12-23 04:43 . 2004-07-09 11:26 10112 c:\windows\Driver Cache\i386\ndisip.sys
+ 2009-12-23 04:43 . 2004-07-09 11:26 83968 c:\windows\Driver Cache\i386\nabtsfec.sys
+ 2009-12-23 04:43 . 2004-07-09 11:26 16896 c:\windows\Driver Cache\i386\msyuv.dll
+ 2009-12-23 04:43 . 2004-07-09 11:26 52096 c:\windows\Driver Cache\i386\msdv.sys
+ 2009-12-23 04:43 . 2004-07-09 11:26 15104 c:\windows\Driver Cache\i386\mpe.sys
+ 2009-12-23 04:43 . 2004-07-09 11:26 16384 c:\windows\Driver Cache\i386\ccdecode.sys
+ 2009-12-23 04:43 . 2004-07-09 11:26 11392 c:\windows\Driver Cache\i386\bdasup.sys
+ 2009-12-10 04:21 . 2009-12-24 04:33 86016 c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP\WiseCustomCalla.dll
- 2009-12-10 04:21 . 2009-12-10 04:21 86016 c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP\WiseCustomCalla.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 3072 c:\windows\system32\dllcache\dpnlobby.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 3072 c:\windows\system32\dllcache\dpnaddr.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 8192 c:\windows\system32\dllcache\d3d8thk.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 4096 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\swenum.sys
- 2009-10-22 05:19 . 2002-12-12 06:14 4096 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\swenum.sys
- 2009-10-22 05:19 . 2002-12-12 06:14 5504 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mstee.sys
+ 2009-10-22 05:19 . 2002-12-12 07:14 5504 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mstee.sys
- 2009-10-22 05:19 . 2001-08-23 11:00 4608 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mspqm.sys
+ 2009-10-22 05:19 . 2001-08-23 12:00 4608 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mspqm.sys
+ 2009-10-22 05:19 . 2002-12-12 07:14 5248 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mspclock.sys
- 2009-10-22 05:19 . 2002-12-12 06:14 5248 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mspclock.sys
+ 2009-10-22 05:19 . 2002-12-12 07:14 7424 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mskssrv.sys
- 2009-10-22 05:19 . 2002-12-12 06:14 7424 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mskssrv.sys
+ 2009-10-22 05:19 . 2002-12-12 07:14 4096 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ksuser.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 4096 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ksuser.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 3072 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnlobby.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 3072 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnlobby.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 3072 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnaddr.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 3072 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnaddr.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 8192 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3d8thk.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 8192 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3d8thk.dll
+ 2009-12-23 04:43 . 2002-12-12 07:14 4096 c:\windows\Driver Cache\i386\swenum.sys
+ 2009-12-23 04:43 . 2002-12-12 07:14 5504 c:\windows\Driver Cache\i386\mstee.sys
+ 2009-12-23 04:43 . 2001-08-23 12:00 4608 c:\windows\Driver Cache\i386\mspqm.sys
+ 2009-12-23 04:43 . 2002-12-12 07:14 5248 c:\windows\Driver Cache\i386\mspclock.sys
+ 2009-12-23 04:43 . 2002-12-12 07:14 7424 c:\windows\Driver Cache\i386\mskssrv.sys
+ 2009-12-23 04:43 . 2002-12-12 07:14 4096 c:\windows\Driver Cache\i386\ksuser.dll
+ 2009-11-06 17:59 . 2009-11-06 17:59 140936 c:\windows\system32\xlive\sqmapi.dll
+ 2009-12-23 04:41 . 2007-11-02 04:01 122880 c:\windows\system32\ReinstallBackups\0000\DriverFiles\Oemdspif.dll
+ 2009-12-23 04:41 . 2007-11-02 03:39 887724 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ativva6x.dat
+ 2009-12-23 04:41 . 2007-11-02 04:01 143360 c:\windows\system32\ReinstallBackups\0000\DriverFiles\atipdlxx.dll
+ 2009-12-23 04:41 . 2007-11-02 04:24 176128 c:\windows\system32\ReinstallBackups\0000\DriverFiles\atiok3x2.dll
+ 2009-12-23 04:41 . 2007-11-02 03:24 376832 c:\windows\system32\ReinstallBackups\0000\DriverFiles\atikvmag.dll
+ 2009-12-23 04:41 . 2007-11-02 03:35 307200 c:\windows\system32\ReinstallBackups\0000\DriverFiles\atiiiexx.dll
+ 2009-12-23 04:41 . 2007-09-14 13:03 157034 c:\windows\system32\ReinstallBackups\0000\DriverFiles\atiicdxx.dat
+ 2009-12-23 04:41 . 2007-11-02 04:10 364544 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ATIDEMGX.dll
+ 2009-12-23 04:41 . 2007-11-02 03:59 495616 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2evxx.exe
+ 2009-12-23 04:41 . 2007-11-02 04:00 122880 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2evxx.dll
+ 2009-12-23 04:41 . 2007-11-02 04:09 268288 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2dvag.dll
+ 2009-12-23 04:41 . 2007-11-02 03:16 499712 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2cqag.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 733184 c:\windows\system32\dllcache\qedwipes.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 470528 c:\windows\system32\dllcache\qdvd.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 316928 c:\windows\system32\dllcache\qdv.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 257024 c:\windows\system32\dllcache\qcap.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 974848 c:\windows\system32\dllcache\dxdiag.exe
+ 2009-12-23 04:42 . 2002-12-12 07:14 602624 c:\windows\system32\dllcache\dx7vb.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 381952 c:\windows\system32\dllcache\dsound.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 491520 c:\windows\system32\dllcache\dsdmoprp.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 186880 c:\windows\system32\dllcache\dsdmo.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 112128 c:\windows\system32\dllcache\dpvvox.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 381952 c:\windows\system32\dllcache\dpvoice.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 723968 c:\windows\system32\dllcache\dpnet.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 230400 c:\windows\system32\dllcache\dplayx.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 122880 c:\windows\system32\dllcache\dmusic.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 100864 c:\windows\system32\dllcache\dmsynth.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 181248 c:\windows\system32\dllcache\dmime.dll
+ 2009-12-23 04:42 . 2002-08-29 10:40 667648 c:\windows\system32\dllcache\dinput8.dll
+ 2009-12-23 04:42 . 2002-08-29 10:40 648704 c:\windows\system32\dllcache\dinput.dll
+ 2009-12-23 04:42 . 2003-05-30 16:00 132608 c:\windows\system32\dllcache\devenum.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 292864 c:\windows\system32\dllcache\ddraw.dll
+ 2009-12-23 04:42 . 2003-05-30 16:00 797184 c:\windows\system32\dllcache\d3dim700.dll
+ 2009-10-31 18:35 . 2009-09-05 00:29 453456 c:\windows\system32\d3dx10_42.dll
- 2009-10-31 18:35 . 2009-09-04 23:29 453456 c:\windows\system32\d3dx10_42.dll
- 2009-10-22 05:12 . 2007-11-02 03:05 593920 c:\windows\system32\ati2sgag.exe
+ 2009-10-22 05:12 . 2007-11-02 04:05 593920 c:\windows\system32\ati2sgag.exe
- 2009-10-22 05:19 . 2004-07-09 10:26 354816 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\psisdecd.dll
+ 2009-10-22 05:19 . 2004-07-09 11:26 354816 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\psisdecd.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 733184 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qedwipes.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 733184 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qedwipes.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 470528 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qdvd.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 470528 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qdvd.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 316928 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qdv.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 316928 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qdv.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 257024 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qcap.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 257024 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qcap.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 173056 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qasf.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 173056 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qasf.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 324096 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mswebdvd.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 324096 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mswebdvd.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 130304 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ks.sys
+ 2009-10-22 05:19 . 2002-12-12 07:14 130304 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ks.sys
- 2009-10-22 05:19 . 2004-07-09 10:27 974848 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdiag.exe
+ 2009-10-22 05:19 . 2004-07-09 11:27 974848 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdiag.exe
- 2009-10-22 05:19 . 2002-12-12 06:14 602624 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dx7vb.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 602624 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dx7vb.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 381952 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 381952 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 491520 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsdmoprp.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 491520 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsdmoprp.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 186880 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsdmo.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 186880 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsdmo.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 112128 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvvox.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 112128 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvvox.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 381952 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvoice.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 381952 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvoice.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 723968 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnet.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 723968 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnet.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 230400 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dplayx.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 230400 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dplayx.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 122880 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmusic.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 122880 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmusic.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 100864 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmsynth.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 100864 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmsynth.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 181248 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmime.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 181248 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmime.dll
- 2009-10-22 05:19 . 2003-05-30 15:00 132608 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\devenum.dll
+ 2009-10-22 05:19 . 2003-05-30 16:00 132608 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\devenum.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 292864 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddraw.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 292864 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddraw.dll
- 2009-10-22 05:19 . 2003-05-30 15:00 797184 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3dim700.dll
+ 2009-10-22 05:19 . 2003-05-30 16:00 797184 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3dim700.dll
+ 2009-12-23 04:45 . 2009-12-23 04:45 213504 c:\windows\Installer\4fcba.msi
+ 2009-12-24 02:25 . 2009-12-24 02:25 752128 c:\windows\Installer\224b99d.msi
+ 2009-12-24 02:25 . 2009-12-24 02:25 847872 c:\windows\Installer\224b997.msi
+ 2009-12-23 04:43 . 2004-07-09 11:26 354816 c:\windows\Driver Cache\i386\psisdecd.dll
+ 2009-12-23 04:43 . 2002-12-12 07:14 130304 c:\windows\Driver Cache\i386\ks.sys
- 2009-12-10 04:21 . 2009-12-10 04:21 111785 c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP\WiseCustomCalla6.dll
+ 2009-12-10 04:21 . 2009-12-24 04:33 111785 c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP\WiseCustomCalla6.dll
+ 2005-09-23 08:16 . 2005-09-23 08:16 1079808 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-23 08:16 . 2005-09-23 08:16 1093632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2009-12-23 04:41 . 2007-11-02 03:39 1602176 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ativvaxx.dll
+ 2009-12-23 04:41 . 2007-11-02 03:39 3107788 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ativvaxx.dat
+ 2009-12-23 04:41 . 2007-11-02 03:39 3107788 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ativva5x.dat
+ 2009-12-23 04:41 . 2007-11-02 04:57 9314304 c:\windows\system32\ReinstallBackups\0000\DriverFiles\atioglx2.dll
+ 2009-12-23 04:41 . 2007-11-02 03:50 3133728 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati3duag.dll
+ 2009-12-23 04:41 . 2007-11-02 05:52 2644480 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2mtag.sys
+ 2007-08-27 22:41 . 2007-08-27 22:41 1089440 c:\windows\system32\msidcrl40.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 1798144 c:\windows\system32\dllcache\qedit.dll
+ 2009-12-23 04:42 . 2003-05-30 16:00 1189888 c:\windows\system32\dllcache\dx8vb.dll
+ 2009-12-23 04:42 . 2002-12-12 07:14 1294336 c:\windows\system32\dllcache\dsound3d.dll
+ 2009-12-23 04:42 . 2004-07-09 11:27 1201152 c:\windows\system32\dllcache\d3d8.dll
- 2009-10-31 18:35 . 2009-09-04 23:29 1892184 c:\windows\system32\D3DX9_42.dll
+ 2009-10-31 18:35 . 2009-09-05 00:29 1892184 c:\windows\system32\D3DX9_42.dll
+ 2009-10-22 05:19 . 2004-07-09 11:26 1230336 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\msvidctl.dll
- 2009-10-22 05:19 . 2004-07-09 10:26 1230336 c:\windows\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\msvidctl.dll
+ 2009-10-22 05:19 . 2003-05-30 16:00 1962496 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\quartz.dll
- 2009-10-22 05:19 . 2003-05-30 15:00 1962496 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\quartz.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 1798144 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qedit.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 1798144 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qedit.dll
- 2009-10-22 05:19 . 2003-05-30 15:00 1189888 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dx8vb.dll
+ 2009-10-22 05:19 . 2003-05-30 16:00 1189888 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dx8vb.dll
+ 2009-10-22 05:19 . 2002-12-12 07:14 1294336 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound3d.dll
- 2009-10-22 05:19 . 2002-12-12 06:14 1294336 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound3d.dll
+ 2009-10-22 05:19 . 2004-07-09 11:27 1201152 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3d8.dll
- 2009-10-22 05:19 . 2004-07-09 10:27 1201152 c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3d8.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2005-11-19 1851392]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-12-03 429392]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2009-06-15 307200]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Grey^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\Grey\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 14:58 611712 —-a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2009-11-29 03:11 2923192 —-a-w- c:\program files\Pando Networks\Media Booster\PMB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
"idsvc"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Program Files\\Steam\\steamapps\\tophatman\\team fortress 2\\hl2.exe"=
"e:\\Program Files\\Steam\\steamapps\\tophatman\\garrysmod\\hl2.exe"=
"c:\\Documents and Settings\\Grey\\Desktop\\ROMS\\NESTCL95.EXE"=
"e:\\Program Files\\Steam\\steamapps\\common\\left 4 dead 2\\left4dead2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58759:TCP"= 58759:TCP:Pando Media Booster
"58759:UDP"= 58759:UDP:Pando Media Booster
"5353:TCP"= 5353:TCP:Adobe CSI CS4

S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12/16/2009 8:36 PM 114768]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/16/2009 8:36 PM 20560]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/16/2009 2:33 PM 276816]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/16/2009 2:32 PM 19160]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [12/16/2009 2:32 PM 38224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
——- Supplementary Scan ——-
.
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Grey\Application Data\Mozilla\Firefox\Profiles\o7mxmqb9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType;=tb50-ff-shoutcast-chromesbox-en-us&query;=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType;=tb50-ff-shoutcast-ab-en-us&query;=
FF - component: c:\documents and settings\Grey\Application Data\Mozilla\Firefox\Profiles\o7mxmqb9.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-23 22:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1935655697-1844823847-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d6,95,e5,59,90,0e,be,42,b5,be,72,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d6,95,e5,59,90,0e,be,42,b5,be,72,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(216)
c:\windows\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2009-12-23 22:04:47
ComboFix-quarantined-files.txt 2009-12-24 05:04
ComboFix2.txt 2009-12-22 19:22

Pre-Run: 44,014,596,096 bytes free
Post-Run: 44,044,914,688 bytes free

- - End Of File - - 9F409BF3E1EF055B7E736A88BD76A86A
ComboFix 09-12-24.02 - Grey 12/24/2009 21:13:41.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.3327.2956 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091224-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

Infected copy of c:\windows\system32\qmgr.dll was found and disinfected
Restored copy from - c:\windows\$NtUninstallKB842773$\qmgr.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-25 to 2009-12-25 )))))))))))))))))))))))))))))))
.

2009-12-25 03:15 . 2009-12-25 03:15 ——– d—–w- c:\documents and settings\All Users\Application Data\RegCure
2009-12-25 03:15 . 2009-12-25 03:24 ——– d—–w- c:\program files\RegCure
2009-12-24 23:22 . 2007-08-10 23:12 53248 —-a-w- c:\windows\system32\CSVer.dll
2009-12-24 23:22 . 2009-12-24 23:22 ——– d—–w- C:\Intel
2009-12-24 22:32 . 2009-12-24 22:32 ——– d—–w- c:\documents and settings\All Users\Application Data\RH_Backups
2009-12-24 22:07 . 2007-11-02 03:35 307200 —-a-r- c:\windows\system32\atiiiexx.dll
2009-12-24 20:38 . 2002-09-03 17:04 101376 -c–a-w- c:\windows\system32\dllcache\srusbusd.dll
2009-12-24 20:37 . 2002-09-03 16:24 10096640 -c–a-w- c:\windows\system32\dllcache\hwxcht.dll
2009-12-24 20:35 . 2002-09-03 17:04 106562 -c–a-w- c:\windows\system32\dllcache\srchctls.dll
2009-12-24 20:34 . 2002-09-03 16:34 742400 -c–a-w- c:\windows\system32\dllcache\helpctr.exe
2009-12-24 20:33 . 2002-09-03 16:52 272896 -c–a-w- c:\windows\system32\dllcache\pinball.exe
2009-12-24 20:32 . 2002-08-29 08:32 5888 —-a-w- c:\windows\system32\drivers\splitter.sys
2009-12-24 20:32 . 2001-08-17 20:59 50048 —-a-w- c:\windows\system32\drivers\DMusic.sys
2009-12-24 20:31 . 2002-08-29 08:27 56576 —-a-w- c:\windows\system32\drivers\redbook.sys
2009-12-24 20:29 . 2002-08-29 10:46 38024 —-a-w- c:\windows\system32\drivers\termdd.sys
2009-12-24 05:36 . 2009-12-24 05:36 ——– d—–w- c:\documents and settings\Grey\AdobeLicensingFilesBackup
2009-12-24 02:25 . 2009-12-24 02:25 ——– d—–w- c:\windows\system32\xlive
2009-12-24 02:25 . 2009-12-24 02:25 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE
2009-12-23 05:16 . 2009-12-23 05:17 ——– d—–w- c:\documents and settings\Grey\Application Data\Stella
2009-12-23 04:12 . 2009-12-23 04:12 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\ATI
2009-12-23 04:12 . 2009-12-23 04:12 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\ATI
2009-12-22 19:05 . 2009-12-22 19:07 ——– d—–w- c:\documents and settings\Administrator
2009-12-22 03:42 . 2009-12-24 23:41 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-18 04:08 . 2009-12-18 04:08 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-18 04:08 . 2009-12-18 04:08 ——– d—–w- c:\program files\NOS
2009-12-17 23:00 . 2009-12-17 23:00 ——– d—–w- c:\program files\IObit
2009-12-17 03:36 . 2009-11-24 23:49 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-17 03:36 . 2009-11-24 23:48 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-17 03:36 . 2009-11-24 23:47 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-17 03:36 . 2009-11-24 23:51 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-17 03:36 . 2009-11-24 23:50 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-17 03:36 . 2009-11-24 23:50 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-17 03:36 . 2009-11-24 23:50 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-17 03:36 . 2009-11-24 23:47 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-12-17 03:36 . 2009-11-24 23:54 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2009-12-17 01:47 . 2009-12-17 01:47 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-12-17 00:40 . 2009-12-17 00:40 ——– d—–w- c:\windows\system32\scripting
2009-12-17 00:40 . 2009-12-17 00:40 ——– d—–w- c:\windows\l2schemas
2009-12-17 00:40 . 2009-12-17 00:40 ——– d—–w- c:\windows\system32\en
2009-12-17 00:18 . 2009-12-17 00:18 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-17 00:16 . 2009-12-17 00:16 ——– d-sh–w- c:\documents and settings\Grey\PrivacIE
2009-12-17 00:15 . 2009-12-17 00:15 ——– d-sh–w- c:\documents and settings\Grey\IETldCache
2009-12-17 00:12 . 2009-12-17 01:39 ——– d—–w- c:\windows\ie8updates
2009-12-17 00:10 . 2009-12-17 00:11 ——– dc-h–w- c:\windows\ie8
2009-12-17 00:02 . 2009-12-17 00:02 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\SHOUTcast Radio Toolbar
2009-12-17 00:02 . 2009-12-17 00:02 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\Winamp Toolbar
2009-12-16 21:33 . 2009-12-16 21:33 ——– d—–w- c:\documents and settings\Grey\Application Data\Malwarebytes
2009-12-16 21:32 . 2009-12-03 23:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-16 21:32 . 2009-12-16 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-16 21:32 . 2009-12-16 21:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-16 21:32 . 2009-12-03 23:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-16 04:40 . 2009-12-16 04:40 ——– d—–w- C:\ERDNT
2009-12-15 05:14 . 2009-12-15 05:14 ——– dc—-w- c:\windows\system32\DRVSTORE
2009-12-15 04:27 . 2009-12-24 05:30 ——– d—–w- c:\program files\ATI
2009-12-15 04:25 . 2009-12-15 04:25 ——– d—–w- C:\ATI
2009-12-15 03:44 . 2009-12-15 03:44 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\Identities
2009-12-14 01:25 . 2009-12-15 01:25 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-13 03:49 . 2009-12-13 03:49 ——– d—–w- c:\program files\SHOUTcast Radio Toolbar
2009-12-13 03:49 . 2009-12-13 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\SHOUTcast Radio Toolbar
2009-12-13 03:49 . 2009-12-13 03:49 ——– d—–w- c:\program files\Winamp Toolbar
2009-12-13 03:49 . 2009-12-13 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Winamp Toolbar
2009-12-13 02:21 . 2009-12-13 02:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Nexon
2009-12-12 18:34 . 2009-12-13 02:21 ——– d—–w- c:\documents and settings\All Users\Application Data\NexonUS
2009-12-10 04:21 . 2009-12-10 04:21 ——– d—–w- c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP
2009-12-08 00:19 . 2009-12-16 04:39 ——– d—–w- c:\program files\No-IP
2009-12-06 07:27 . 2009-12-06 07:27 ——– d—–w- c:\program files\GCFScape
2009-12-06 07:26 . 2009-12-06 07:27 ——– d—–w- c:\documents and settings\Grey\Application Data\Notepad++
2009-12-06 07:26 . 2009-12-06 07:27 ——– d—–w- c:\program files\Notepad++
2009-12-06 00:02 . 2009-12-24 05:36 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-12-05 23:43 . 2009-12-05 23:43 ——– d—–w- c:\program files\Adobe Media Player
2009-12-05 23:41 . 2009-12-05 23:41 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-05 23:35 . 2009-12-06 00:02 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\Adobe
2009-12-05 23:35 . 2009-12-05 23:35 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2009-12-05 23:33 . 2009-12-05 23:45 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-01 01:02 . 2009-12-01 01:02 171144 —-a-w- c:\windows\system32\xliveinstall.dll
2009-12-01 01:02 . 2009-12-01 01:02 72840 —-a-w- c:\windows\system32\xliveinstallhost.exe
2009-11-29 07:33 . 2009-11-29 07:33 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\Blizzard Entertainment
2009-11-29 05:50 . 2009-11-29 05:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-11-29 05:49 . 2009-11-29 05:49 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-11-29 05:48 . 2009-11-29 05:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-11-29 03:11 . 2009-12-18 01:17 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\PMB Files
2009-11-29 03:11 . 2009-12-13 02:20 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2009-11-29 03:10 . 2009-11-29 03:10 ——– d—–w- c:\program files\Pando Networks
2009-11-28 19:08 . 2009-11-28 19:08 ——– d—–w- c:\documents and settings\Grey\Application Data\TortoiseSVN
2009-11-28 18:14 . 2009-12-25 04:22 ——– d—–w- c:\documents and settings\Grey\Local Settings\Application Data\TSVNCache
2009-11-27 21:40 . 2009-11-27 21:40 ——– d—–w- c:\documents and settings\Grey\Application Data\Subversion
2009-11-27 21:29 . 2009-11-27 21:29 ——– d—–w- c:\program files\TortoiseSVN
2009-11-27 21:29 . 2009-11-27 21:29 ——– d—–w- c:\program files\Common Files\TortoiseOverlays
2009-11-27 04:46 . 2009-11-27 04:46 ——– d—–w- c:\documents and settings\Grey\Application Data\Ventrilo
2009-11-27 03:18 . 2009-11-27 03:18 ——– d—–w- c:\documents and settings\All Users\Application Data\GoldWave
2009-11-27 03:11 . 2009-11-27 03:11 ——– d—–w- c:\documents and settings\Grey\Application Data\AccurateRip
2009-11-27 03:11 . 2009-11-27 03:09 5640880 —-a-w- c:\windows\system32\SpoonUninstall.exe
2009-11-27 02:50 . 2004-12-03 01:20 1843200 —-a-w- c:\windows\system32\NCTAudioFile2.dll
2009-11-27 02:50 . 2004-12-03 01:11 315392 —-a-w- c:\windows\system32\NCTAudioPlayer2.dll
2009-11-27 02:50 . 2004-05-20 22:24 196608 —-a-w- c:\windows\system32\NCTWMAFile2.dll
2009-11-27 02:50 . 2002-01-05 22:37 344064 —-a-w- c:\windows\system32\msvcr70.dll
2009-11-25 20:10 . 2009-12-17 03:09 ——– d—–w- c:\program files\Common Files\Akamai

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-24 20:36 . 2009-12-24 20:36 2678 —-a-w- c:\windows\java\Packages\Data\1VLBJ539.DAT
2009-12-24 20:36 . 2009-12-24 20:36 2678 —-a-w- c:\windows\java\Packages\Data\CF5VBHZT.DAT
2009-12-24 20:36 . 2009-12-24 20:36 2678 —-a-w- c:\windows\java\Packages\Data\W8Q1Z5BN.DAT
2009-12-24 20:36 . 2009-12-24 20:36 2678 —-a-w- c:\windows\java\Packages\Data\O3VJBDFZ.DAT
2009-12-24 20:36 . 2009-12-24 20:36 2678 —-a-w- c:\windows\java\Packages\Data\JRBZ9ZTR.DAT
2009-12-24 20:34 . 2009-10-22 02:26 23348 —-a-w- c:\windows\system32\emptyregdb.dat
2009-12-23 04:41 . 2009-10-22 05:11 ——– d—–w- c:\program files\ATI Technologies
2009-12-22 03:21 . 2009-10-22 03:38 ——– d—–r- c:\program files\Support.com
2009-12-19 20:39 . 2009-10-21 20:16 90112 —-a-w- c:\windows\DUMP8750.tmp
2009-12-18 00:10 . 2009-10-22 06:52 ——– d—–w- c:\program files\Java
2009-12-18 00:09 . 2009-12-18 00:09 152576 —-a-w- c:\documents and settings\Grey\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-18 00:09 . 2009-12-18 00:09 79488 —-a-w- c:\documents and settings\Grey\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-17 03:36 . 2009-10-23 08:44 ——– d—–w- c:\program files\Alwil Software
2009-12-17 03:13 . 2009-11-04 23:54 ——– d—–w- c:\documents and settings\Grey\Application Data\uTorrent
2009-12-17 01:21 . 2009-10-23 08:58 ——– d—–w- c:\program files\Google
2009-12-17 00:43 . 2009-10-22 02:28 76487 —-a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-12-15 05:14 . 2009-12-13 03:46 ——– d—–w- c:\program files\Winamp
2009-12-15 04:33 . 2009-12-15 04:33 10134 —-a-r- c:\documents and settings\Grey\Application Data\Microsoft\Installer\{7FAB9334-804D-34B7-BF98-7C8348CE81C1}\ARPPRODUCTICON.exe
2009-12-13 03:58 . 2009-12-13 03:46 ——– d—–w- c:\documents and settings\Grey\Application Data\Winamp
2009-12-12 18:34 . 2009-12-12 18:34 90112 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2009-12-12 18:34 . 2009-12-12 18:34 393216 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-12-12 18:34 . 2009-12-12 18:34 258352 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2009-12-12 18:34 . 2009-12-12 18:34 118784 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2009-12-12 18:34 . 2009-12-12 18:34 561152 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2009-12-12 18:34 . 2009-12-12 18:34 167936 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2009-11-07 07:16 . 2009-11-07 07:16 62304 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-06 17:59 . 2009-11-06 17:59 15406728 —-a-w- c:\windows\system32\xlive.dll
2009-11-06 17:59 . 2009-11-06 17:59 13642888 —-a-w- c:\windows\system32\xlivefnt.dll
2009-10-27 01:46 . 2009-10-22 05:47 13104 —-a-w- c:\documents and settings\Grey\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-26 23:33 . 2009-10-22 03:33 ——– d—–w- c:\documents and settings\Grey\Application Data\U3
2009-10-26 23:00 . 2009-10-26 23:00 ——– d—–w- c:\program files\MSBuild
2009-10-26 23:00 . 2009-10-26 23:00 ——– d—–w- c:\program files\Reference Assemblies
2009-10-26 22:56 . 2009-10-26 22:56 ——– d—–w- c:\program files\MSXML 6.0
2009-10-23 09:02 . 2009-10-23 09:02 152576 —-a-w- c:\documents and settings\Grey\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-22 05:50 . 2009-10-22 05:50 0 —-a-w- c:\windows\nsreg.dat
2009-10-22 05:29 . 2009-10-22 05:29 9158 —-a-r- c:\documents and settings\Grey\Application Data\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
2009-10-22 02:28 . 2009-10-22 02:28 558142 —-a-w- c:\windows\java\Packages\BLNR5VFT.ZIP
2009-10-22 02:28 . 2009-10-22 02:28 155995 —-a-w- c:\windows\java\Packages\JD7R13LR.ZIP
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:54 . 2009-10-20 16:54 59992 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\English\setup.exe
2009-10-20 16:20 . 2004-08-04 06:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-11 11:17 . 2009-10-23 09:03 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-26 16:00 . 2009-11-27 03:18 496640 —-a-w- c:\documents and settings\All Users\Application Data\GoldWave\lame_enc.dll
.

——- Sigcheck ——-

[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\wscntfy.exe
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\wscntfy.exe
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe

[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\xmlprov.dll
[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\xmlprov.dll
[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll

[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\ip6fw.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ip6fw.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{14f0d511-36a2-41ca-ae01-ba4f87282c97}"= "c:\program files\SHOUTcast Radio Toolbar\shoutcasttb.dll" [2008-09-17 1275176]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]

[HKEY_CLASSES_ROOT\clsid\{14f0d511-36a2-41ca-ae01-ba4f87282c97}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{8613efdf-b530-4b1d-b970-b09f99977813}]
[HKEY_CLASSES_ROOT\SHOUTcastTb.AOLTBSearch]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-14 01:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-12-03 429392]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Grey^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 14:58 611712 —-a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2009-11-29 03:11 2923192 —-a-w- c:\program files\Pando Networks\Media Booster\PMB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
"idsvc"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Grey\\Desktop\\ROMS\\NESTCL95.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58759:TCP"= 58759:TCP:Pando Media Booster
"58759:UDP"= 58759:UDP:Pando Media Booster
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12/16/2009 8:36 PM 114768]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/16/2009 8:36 PM 20560]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/16/2009 2:33 PM 276816]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/16/2009 2:32 PM 19160]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [12/16/2009 2:32 PM 38224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &SHOUTcast; Search - c:\documents and settings\All Users\Application Data\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Winamp; Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Grey\Application Data\Mozilla\Firefox\Profiles\o7mxmqb9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType;=tb50-ff-shoutcast-chromesbox-en-us&query;=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType;=tb50-ff-shoutcast-ab-en-us&query;=
FF - component: c:\documents and settings\Grey\Application Data\Mozilla\Firefox\Profiles\o7mxmqb9.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-24 21:22
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(524)
c:\windows\System32\ODBC32.dll
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\windows\System32\msctfime.ime
c:\windows\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'lsass.exe'(580)
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\windows\System32\dssenh.dll

- - - - - - - > 'explorer.exe'(816)
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\windows\System32\msctfime.ime
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\System32\msi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\windows\BCMSMMSG.exe
.
**************************************************************************
.
Completion time: 2009-12-24 21:27:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-25 04:27
ComboFix2.txt 2009-12-24 05:04
ComboFix3.txt 2009-12-22 19:22

Pre-Run: 42,389,000,192 bytes free
Post-Run: 42,364,936,192 bytes free

- - End Of File - - 9C0E5B02D08EA353B9714DA33702C396
TopHatMan,


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Alright, I'll edit this post when it's done, but until then.. :popcorn: Edit1: My comp crashed during it >_>
TopHatMan,

If you can't get it to run, do this one:

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
I think I am going to reinstall XP or upgrade to Windows 7 due to the fact my computer is really screwey, but thank you for all of your help. Sigh* Now to redownload C++ redis, firefox, sp3, flash, java, cs4's… ughhhhhhhhh
TopHatMan,

Here is some things to think about, even in a new install:


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI