Don'tThrowStonesAtTheKing
Topic Starter
Hello there.
My computer was just hijacked!
This is what happened. My settings have almost gone back to system restore. It's like this "problem" added a User over My User. It cleaned up my desktop by putting the XP default Wallpaper and cleaned up some of the desktop icons. It's hiding all of my Documents/Pictures/Music. I was able to find the files by doing a search. The space on my hard drive is the same.
For example:
C:\Documents and Settings\TEMP\My Documents\My Music
C:\Documents and Settings\TEMP\My Documents\My Pictures
TEMP was never there.
I did find this in the Control Panel:
It's a shortcut that reads: Detectar automaticame nte el pue (That was never there before)
I am not able to open this shorcut nor delete.
I ran AVG Free Edition and it told me there were no infections.
I then ran a Norton Online Virus Scan and they told me that these were the infected problems:
1.) Trojan Guarder (I removed the program
I recieved the program from www.download.com
(I rescanned after I removed the program and it's gone)
2.) C:\WINDOWS\system32\WinSecure.003 is infected with Spyware.Ardakey
I also found by searching on my own:
C:\WINDOWS\system32\WinSecure.001
C:\WINDOWS\system32\WinSecure.002
C:\WINDOWS\system32\WinSecure.004
C:\WINDOWS\system32\WinSecure.005
C:\WINDOWS\system32\WinSecure.006
C:\WINDOWS\system32\WinSecure.007
C:\WINDOWS\system32\WinSecure
C:\WINDOWS\system32\Firewall.exe
I ran Kaspersky Online File Virus Scanner http://www.kaspersky.com/scanforvirus.
This is the report:
WinSecure.001 Clean!
WinSecure.002 Clean!
WinSecure.003 infected by not-a-virus:Monitor.Win32.Ardamax.f
WinSecure.004 Trojan-Spy.Win32.Ardamax.b
WinSecure.005 (It would't load online to check for some reason)
WinSecure.006 infected by not-a-virus:Monitor.Win32.Ardamax.24
WinSecure.007 infected by not-a-virus:Monitor.Win32.Ardamax.24
WinSecure.exe - infected by not-a-virus:Monitor.Win32.Ardamax.24
Firewall.exe (It said it was infected, but I can't find the file anymore after I rebooted)
Kaspersky Anti-Virus Personal (Updated) only read:
WinSecure.004 Trojan-Spy.Win32.Ardamax.b, object could not be disinfected!
It did not read the rest of the infected files like the online version did.
I also ran McAfee Anti-Spyware and cleaned up some some files, mostly cookies, but left the dectected Winsecure.004 alone.
Now my laptop is acting really slow and it took 20 min. to boot up. I don't know if this is due to low hard drive space or what. When it first booted it was under 200mb. Then while I was uninstalling MSN Messenger it went up to 1.5GB. Now it's somehow at 1.37GB. I am working with a 12GB hard drive. Also, after the reboot it deleted all new files that were on the desktop. Is this becuase of the Trojan?
The last 2 days I have been backing up files, trying to figure out what's wrong, trying to fix things, and scanning. My mind is dead tired from this problem.
I want to format my hard drive and reinstall after this is all said and done with, but I have read where this problem has came back after reformating.
Your time and help is much appreciated to get this problem fixed!
-James
My computer was just hijacked!
This is what happened. My settings have almost gone back to system restore. It's like this "problem" added a User over My User. It cleaned up my desktop by putting the XP default Wallpaper and cleaned up some of the desktop icons. It's hiding all of my Documents/Pictures/Music. I was able to find the files by doing a search. The space on my hard drive is the same.
For example:
C:\Documents and Settings\TEMP\My Documents\My Music
C:\Documents and Settings\TEMP\My Documents\My Pictures
TEMP was never there.
I did find this in the Control Panel:
It's a shortcut that reads: Detectar automaticame nte el pue (That was never there before)
I am not able to open this shorcut nor delete.
I ran AVG Free Edition and it told me there were no infections.
I then ran a Norton Online Virus Scan and they told me that these were the infected problems:
1.) Trojan Guarder (I removed the program
I recieved the program from www.download.com
(I rescanned after I removed the program and it's gone)
2.) C:\WINDOWS\system32\WinSecure.003 is infected with Spyware.Ardakey
I also found by searching on my own:
C:\WINDOWS\system32\WinSecure.001
C:\WINDOWS\system32\WinSecure.002
C:\WINDOWS\system32\WinSecure.004
C:\WINDOWS\system32\WinSecure.005
C:\WINDOWS\system32\WinSecure.006
C:\WINDOWS\system32\WinSecure.007
C:\WINDOWS\system32\WinSecure
C:\WINDOWS\system32\Firewall.exe
I ran Kaspersky Online File Virus Scanner http://www.kaspersky.com/scanforvirus.
This is the report:
WinSecure.001 Clean!
WinSecure.002 Clean!
WinSecure.003 infected by not-a-virus:Monitor.Win32.Ardamax.f
WinSecure.004 Trojan-Spy.Win32.Ardamax.b
WinSecure.005 (It would't load online to check for some reason)
WinSecure.006 infected by not-a-virus:Monitor.Win32.Ardamax.24
WinSecure.007 infected by not-a-virus:Monitor.Win32.Ardamax.24
WinSecure.exe - infected by not-a-virus:Monitor.Win32.Ardamax.24
Firewall.exe (It said it was infected, but I can't find the file anymore after I rebooted)
Kaspersky Anti-Virus Personal (Updated) only read:
WinSecure.004 Trojan-Spy.Win32.Ardamax.b, object could not be disinfected!
It did not read the rest of the infected files like the online version did.
I also ran McAfee Anti-Spyware and cleaned up some some files, mostly cookies, but left the dectected Winsecure.004 alone.
Now my laptop is acting really slow and it took 20 min. to boot up. I don't know if this is due to low hard drive space or what. When it first booted it was under 200mb. Then while I was uninstalling MSN Messenger it went up to 1.5GB. Now it's somehow at 1.37GB. I am working with a 12GB hard drive. Also, after the reboot it deleted all new files that were on the desktop. Is this becuase of the Trojan?
The last 2 days I have been backing up files, trying to figure out what's wrong, trying to fix things, and scanning. My mind is dead tired from this problem.
I want to format my hard drive and reinstall after this is all said and done with, but I have read where this problem has came back after reformating.
Your time and help is much appreciated to get this problem fixed!
-James
Logfile of HijackThis v1.99.1
Scan saved at 3:24:11 AM, on 8/25/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\cleanmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/mash2/en-us/redir.asp?langid=1&affid=0-109&installtype=force&systempopup=true
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - (no file)
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - Global Startup: Start Firewall.lnk = C:\WINDOWS\system32\net.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by113fd.bay113.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152853102653
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab?796939bd6aa3287dc0c5c335a09367f8f59234827c767582019153778fcb5e90163aebe2f2c3bd1861ee134eb6055e01f1cbf8ba60456ad2f730291a50e52c39089eb1f0deba:3558a28c0544b455f9e2a8f7bf4ca3f5
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15021/CTPID.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - ms-its:mhtml:file://c:\nesunew.mht!http://adgate.info/zscript/winfix.chm::/SystemDoctor2006FreeInstall.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
—– Root —————————– Volume in drive C is Local Disk Volume Serial Number is 9485-EAB3 Directory of C:\ 08/25/2006 03:29 AM 43 filelist.txt 08/25/2006 01:13 AM 124,125 PollSt.txt 08/25/2006 01:13 AM 130 Pollog.txt 08/25/2006 01:12 AM 805,306,368 pagefile.sys 08/24/2006 01:48 PM 232 sqmdata12.sqm 08/24/2006 01:48 PM 244 sqmnoopt14.sqm 08/24/2006 01:48 PM 232 sqmdata11.sqm 08/24/2006 01:48 PM 244 sqmnoopt13.sqm 08/24/2006 01:48 PM 232 sqmdata10.sqm 08/24/2006 01:48 PM 244 sqmnoopt12.sqm 08/24/2006 01:47 PM 244 sqmnoopt11.sqm 08/24/2006 01:47 PM 232 sqmdata09.sqm 08/24/2006 01:47 PM 232 sqmdata08.sqm 08/24/2006 01:47 PM 244 sqmnoopt10.sqm 08/24/2006 01:46 PM 232 sqmdata07.sqm 08/24/2006 01:46 PM 244 sqmnoopt09.sqm 08/24/2006 06:42 AM 244 sqmnoopt08.sqm 08/24/2006 06:42 AM 232 sqmdata06.sqm 08/24/2006 06:42 AM 244 sqmnoopt07.sqm 08/24/2006 06:42 AM 232 sqmdata05.sqm 08/24/2006 06:42 AM 244 sqmnoopt06.sqm 08/24/2006 06:42 AM 232 sqmdata04.sqm 08/24/2006 06:42 AM 232 sqmdata03.sqm 08/24/2006 06:42 AM 244 sqmnoopt05.sqm 08/24/2006 06:41 AM 244 sqmnoopt04.sqm 08/24/2006 06:41 AM 232 sqmdata02.sqm 08/24/2006 06:41 AM 244 sqmnoopt03.sqm 08/24/2006 06:41 AM 232 sqmdata01.sqm 08/24/2006 06:41 AM 244 sqmnoopt02.sqm 08/24/2006 06:41 AM 232 sqmdata00.sqm 08/12/2006 01:06 AM 51,133 avi_log.txt 08/08/2006 02:17 PM 146 YServer.txt 07/26/2006 02:46 AM 11,886,031 AVG7QT.DAT —– System ————————— Volume in drive C is Local Disk Volume Serial Number is 9485-EAB3 Directory of C:\WINDOWS\system32 08/25/2006 01:16 AM 12,980 wpa.dbl 08/24/2006 05:01 PM 0 sys_dll.dll 08/16/2006 10:16 AM 176,167 rmoc3260.dll 08/16/2006 10:15 AM 5,632 pndx5032.dll 08/16/2006 10:15 AM 6,656 pndx5016.dll 08/08/2006 12:07 AM 952 KGyGaAvL.sys 08/04/2006 11:37 AM 73,728 dpl100.dll 08/04/2006 11:37 AM 196,608 dtu100.dll 08/02/2006 09:22 PM 8,255,912 MRT.exe 07/27/2006 09:23 PM 45,056 sstunst2.exe 07/26/2006 10:05 PM 3,596,288 qt-dx331.dll —– Prefetch ————————- Volume in drive C is Local Disk Volume Serial Number is 9485-EAB3 Directory of C:\WINDOWS\Prefetch 08/25/2006 03:29 AM 5,406 FIND.EXE-0EC32F1E.pf 08/25/2006 03:29 AM 8,742 CMD.EXE-087B4001.pf 08/25/2006 03:24 AM 13,744 NOTEPAD.EXE-336351A9.pf 08/25/2006 03:22 AM 17,090 HIJACKTHIS.EXE-2AF68D7A.pf 08/25/2006 03:21 AM 14,382 HIJACKTHIS_SFX.EXE-31600EB1.pf 08/25/2006 03:21 AM 33,726 SFLAUNCHER.EXE-13F9EAE1.pf 08/25/2006 02:38 AM 25,118 EXPLORER.EXE-082F38A9.pf 08/25/2006 02:34 AM 17,028 KILLBOX.EXE-2DE8B7B7.pf 08/25/2006 02:27 AM 25,074 WORDPAD.EXE-24533991.pf 08/25/2006 02:24 AM 78,136 LOGON.SCR-151EFAEA.pf 08/25/2006 02:11 AM 102,546 IEXPLORE.EXE-27122324.pf 08/25/2006 02:06 AM 23,604 STARTOPT.EXE-0CAFDDEA.pf 08/25/2006 02:05 AM 37,360 KAV.EXE-11323A12.pf 08/25/2006 01:57 AM 71,710 MSIEXEC.EXE-2F8A8CAE.pf 08/25/2006 01:45 AM 10,738 RUNDLL32.EXE-451FC2C0.pf 08/25/2006 01:44 AM 12,340 IMAPI.EXE-0BF740A4.pf 08/25/2006 01:40 AM 25,264 RUNDLL32.EXE-1C320F03.pf 08/25/2006 01:36 AM 15,112 CLEANMGR.EXE-1F86EA8E.pf 08/25/2006 01:32 AM 33,868 AVGCC.EXE-36A38F59.pf 08/25/2006 01:32 AM 8,482 NET1.EXE-029B9DB4.pf 08/25/2006 01:31 AM 19,288 SYNTPENH.EXE-315D3ABC.pf 08/25/2006 01:31 AM 6,152 NET.EXE-01A53C2F.pf 08/25/2006 01:31 AM 9,696 MSMSGS.EXE-2B6052DE.pf 08/25/2006 01:31 AM 31,670 MCUPDATE.EXE-19916285.pf 08/25/2006 01:31 AM 12,728 REALSCHED.EXE-3282FD31.pf 08/25/2006 01:31 AM 10,528 JUSCHED.EXE-1B0C526D.pf 08/25/2006 01:30 AM 11,298 SYNTPLPR.EXE-28BB9F3B.pf 08/25/2006 01:27 AM 17,058 MCINFO.EXE-35A0A279.pf 08/25/2006 01:27 AM 19,636 MASVMAP.EXE-0336EF27.pf 08/25/2006 01:26 AM 16,106 MCUPDATE.EXE-2A2835B2.pf 08/25/2006 01:24 AM 4,806 RUNDLL32.EXE-33D7466C.pf 08/25/2006 01:24 AM 27,420 RUNDLL32.EXE-137CCEC6.pf 08/25/2006 01:23 AM 22,352 REGSVR32.EXE-25EEFE2F.pf 08/25/2006 01:23 AM 31,196 WUAUCLT.EXE-399A8E72.pf 08/25/2006 01:22 AM 13,584 SETUP50.EXE-362FF7C9.pf 08/25/2006 01:22 AM 7,626 RUNDLL32.EXE-26FFB538.pf 08/25/2006 01:22 AM 7,528 RUNDLL32.EXE-18E3301D.pf 08/25/2006 01:16 AM 21,518 IE4UINIT.EXE-169A5A39.pf 08/25/2006 01:16 AM 19,028 USERINIT.EXE-30B18140.pf 08/25/2006 01:15 AM 7,996 ATI2EVXX.EXE-19D16EB9.pf 08/25/2006 01:14 AM 29,530 WMIPRVSE.EXE-28F301A9.pf 08/25/2006 01:14 AM 38,626 SVCHOST.EXE-3530F672.pf 08/25/2006 01:14 AM 13,128 BCMWLTRY.EXE-34CCE601.pf 08/25/2006 01:14 AM 6,676 WDFMGR.EXE-2CF4013B.pf 08/25/2006 01:14 AM 6,720 WLTRYSVC.EXE-03AFDF18.pf 08/25/2006 01:14 AM 14,338 MCTSKSHD.EXE-2B7872B6.pf 08/25/2006 01:14 AM 34,706 MASSRV.EXE-11AD80C6.pf 08/25/2006 01:14 AM 7,688 MCDETECT.EXE-2BF18DA4.pf 08/25/2006 01:14 AM 44,236 KPF4GUI.EXE-03046928.pf 08/25/2006 01:14 AM 33,438 KPF4SS.EXE-258C1604.pf 08/25/2006 01:14 AM 440,530 NTOSBOOT-B00DFAAD.pf 08/25/2006 12:58 AM 24,968 LOGONUI.EXE-0AF22957.pf 08/25/2006 12:55 AM 57,290 DUMPREP.EXE-1B46F901.pf 08/25/2006 12:55 AM 21,886 TASKMGR.EXE-20256C55.pf 08/25/2006 12:48 AM 70,230 AOLLOAD.EXE-11F701E6.pf 08/25/2006 12:46 AM 43,500 NOTEPAD.EXE-189578DA.pf 08/25/2006 12:42 AM 40,012 SET945.TMP-2CD04332.pf 08/25/2006 12:42 AM 22,752 RUNDLL32.EXE-3EBA3A9F.pf 08/25/2006 12:41 AM 74,996 RUNDLL32.EXE-35BB92D4.pf 08/25/2006 12:40 AM 51,894 HIJACKTHIS.EXE-37EAAAD9.pf 08/25/2006 12:35 AM 52,326 MMC.EXE-04908CDF.pf 08/25/2006 12:32 AM 25,370 ATF-CLEANER[1].EXE-3660EDBD.pf 08/25/2006 12:25 AM 13,306 AU_.EXE-3826AF49.pf 08/25/2006 12:25 AM 15,470 UNINSTALL.EXE-2BEA3490.pf 08/25/2006 12:25 AM 79,852 DRWTSN32.EXE-2B4B52AC.pf 08/25/2006 12:25 AM 104,734 DWWIN.EXE-30875ADC.pf 08/25/2006 12:05 AM 9,352 PATCH_PERS_5.0.388_390_TO_5.0-23558BB5.pf 08/24/2006 11:03 PM 41,796 RUNDLL32.EXE-2F00B100.pf 08/24/2006 10:56 PM 29,486 MSPAINT.EXE-11CBB631.pf 08/24/2006 10:54 PM 22,424 SET8E6.TMP-0F5CA92A.pf 08/24/2006 10:54 PM 20,346 LUINIT.EXE-341D8E4A.pf 08/24/2006 10:52 PM 48,076 LUCOMS~1.EXE-02DB5950.pf 08/24/2006 10:52 PM 24,122 ALUSCHEDULERSVC.EXE-07C29CF3.pf 08/24/2006 10:50 PM 34,504 LSETUP.EXE-32559C46.pf 08/24/2006 09:06 PM 33,874 KAVSVC.EXE-2BCA33C4.pf 08/24/2006 09:03 PM 15,518 MCAPPINS.EXE-0F56E6E4.pf 08/24/2006 08:59 PM 19,346 MCUPDUI.EXE-27129637.pf 08/24/2006 08:59 PM 41,606 MCUPDMGR.EXE-2963FAB2.pf 08/24/2006 08:58 PM 61,940 MGHTML.EXE-31D79FA5.pf 08/24/2006 08:58 PM 24,514 MASCON.EXE-31A994E2.pf 08/24/2006 08:57 PM 12,616 MCREGWIZ.EXE-28685653.pf 08/24/2006 08:57 PM 5,380 MASALERT.EXE-0F3087E0.pf 08/24/2006 08:56 PM 25,942 MCAGENT.EXE-03DA6B71.pf 08/24/2006 08:56 PM 24,600 MASUPD.EXE-214F8309.pf 08/24/2006 08:54 PM 9,520 MASALERT.EXE-070950BA.pf 08/24/2006 08:54 PM 12,118 MASCON.EXE-22E3A9EF.pf 08/24/2006 08:54 PM 16,400 MCTSKSHD.EXE-19986105.pf 08/24/2006 08:54 PM 12,864 MCUPDMGR.EXE-21452C82.pf 08/24/2006 08:53 PM 11,178 MCAGENT.EXE-168D195B.pf 08/24/2006 08:52 PM 32,018 MCAPPINS.EXE-2F440A1D.pf 08/24/2006 08:52 PM 19,548 EULA.EXE-13D3A8C8.pf 08/24/2006 08:52 PM 14,186 SETUP.EXE-07E62BB2.pf 08/24/2006 08:51 PM 39,862 GLB7EE.TMP-36360422.pf 08/24/2006 08:51 PM 23,878 MAS2_167_EN-US_42_TRIAL30CNET-2263B265.pf 08/24/2006 08:02 PM 10,000 RUNDLL32.EXE-284D667F.pf 08/24/2006 07:58 PM 33,124 WMPLAYER.EXE-18DDEFA3.pf 08/24/2006 07:45 PM 36,210 AIM.EXE-061FD532.pf 08/24/2006 07:35 PM 54,894 FIREWALL.EXE-353DEDA6.pf 08/24/2006 07:03 PM 48,368 KASPERSKY ANTI-VIRUS PRO 5.0.-17F8A5A2.pf 08/24/2006 07:02 PM 114,122 WINRAR.EXE-39C6DAD9.pf 08/24/2006 06:22 PM 43,096 RUNDLL32.EXE-26DA8C9B.pf 08/24/2006 05:24 PM 68,776 SPYBOTSD.EXE-1344276B.pf 08/24/2006 05:24 PM 11,584 UPDATE.EXE-131667C7.pf 08/24/2006 05:21 PM 20,328 TEATIMER.EXE-1F57E47A.pf 08/24/2006 05:21 PM 18,644 SPYBOTSD_INCLUDES.EXE-01D5BD1E.pf 08/24/2006 05:19 PM 13,428 IS-JTAVS.TMP-2C6D549C.pf 08/24/2006 05:19 PM 23,060 SPYBOTSD14.EXE-06DA7ADD.pf 08/24/2006 05:15 PM 62,250 AVGW.EXE-00A2F684.pf 08/24/2006 05:01 PM 11,290 _IU14D2N.TMP-2B3F57B7.pf 08/24/2006 05:01 PM 12,312 UNINS000.EXE-26543A36.pf 08/24/2006 05:00 PM 12,568 TROJAN GUARDER.EXE-15F7BC4B.pf 08/24/2006 04:58 PM 10,880 RUNDLL32.EXE-163BB7C1.pf 08/24/2006 03:27 PM 45,610 HELPSVC.EXE-2878DDA2.pf 08/24/2006 02:58 PM 237,740 Layout.ini 08/24/2006 02:12 PM 11,614 CANCELAUTOPLAY.EXE-2B84EB76.pf 08/24/2006 02:12 PM 32,448 BURNINGSTUDIO.EXE-119D61FF.pf 08/24/2006 01:47 PM 68,462 MSNMSGR.EXE-366A1A81.pf 08/24/2006 01:45 PM 99,740 AEXPLORE.EXE-1EDD4A67.pf 08/24/2006 01:45 PM 25,980 AOLLAUNCH.EXE-1D76DCDC.pf 08/24/2006 01:42 PM 7,048 AOLSP SCHEDULER.EXE-0BD51486.pf 08/24/2006 01:42 PM 59,186 AOLSOFTWARE.EXE-199F51A0.pf 08/24/2006 01:41 PM 19,054 MSN_SL.EXE-15D1842E.pf 08/24/2006 06:49 AM 88,104 WMPLAYER.EXE-18DDEFA2.pf 08/23/2006 06:45 PM 93,774 SSSTARS.SCR-2D6FC20D.pf 126 File(s) 4,405,366 bytes 0 Dir(s) 1,457,401,856 bytes free —– Windows ————————– Volume in drive C is Local Disk Volume Serial Number is 9485-EAB3 Directory of C:\WINDOWS 08/25/2006 01:58 AM 172,785 setupapi.log 08/25/2006 01:36 AM 167,460 setupact.log 08/25/2006 01:24 AM 1,193,819 WindowsUpdate.log 08/25/2006 01:22 AM 1,859 OEWABLog.txt 08/25/2006 01:14 AM 0 0.log 08/25/2006 01:14 AM 159 wiadebug.log 08/25/2006 01:14 AM 49 wiaservc.log 08/25/2006 01:13 AM 2,048 bootstat.dat 08/25/2006 01:02 AM 32,502 SchedLgU.Txt 08/24/2006 05:37 AM 376 ODBC.INI 08/24/2006 03:14 AM 27,416 wmsetup.log 08/22/2006 12:39 AM 16,920 svcpack.log —– Tasks —————————- Volume in drive C is Local Disk Volume Serial Number is 9485-EAB3 Directory of C:\WINDOWS\tasks 08/25/2006 01:13 AM 6 SA.DAT 08/24/2006 08:56 PM 368 McAfee AntiSpyware.job 08/23/2001 08:00 AM 4 FOLDER.TSX 08/23/2001 08:00 AM 65 desktop.ini 4 File(s) 443 bytes 0 Dir(s) 1,457,393,664 bytes free —– Temp —————————– Volume in drive C is Local Disk Volume Serial Number is 9485-EAB3 Directory of C:\DOCUME~1\TEMP~1.THE\LOCALS~1\Temp 08/25/2006 03:22 AM 16,384 ~DF8F13.tmp 08/25/2006 01:35 AM 203 jusched.log 2 File(s) 16,587 bytes 0 Dir(s) 1,457,393,664 bytes free