This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Random sites keep popping up on their own

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think my troubles may be related to C:\windows\system32\v6.exe. Also something modified my hosts file and it blocked this site along with a bunch of other security sites (all of which came up when I was looking for info on v6.exe).
Here's my log

Logfile of HijackThis v1.99.1
Scan saved at 11:04:15 PM, on 2/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Turtle Beach\MontegoDDL\TBMontegoTray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SnapStream Media\Firefly\Firefly.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\v6.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hamachi\hamachi.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Tim Morea\Desktop\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5DDC8947-8CF7-44F3-8EEA-E1CB6FE92D40} - C:\WINDOWS\system32\ddayw.dll
O2 - BHO: (no name) - {A46AC0F4-8D72-4740-A3C9-0802649C8A2D} - C:\WINDOWS\system32\wvuurpo.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Turtle Beach Montego DDL] "C:\Program Files\Turtle Beach\MontegoDDL\TBMontegoTray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Firefly] C:\Program Files\SnapStream Media\Firefly\Firefly.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
O4 - HKCU\..\Run: [feedreader.exe] "C:\Program Files\FeedReader30\feedreader.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_7 -reboot 1
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save with Download Manager… - file://C:\Program Files\J River\Media Center 11\DMDownload.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1170751310718
O20 - Winlogon Notify: ddayw - C:\WINDOWS\system32\ddayw.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: winhoq32 - C:\WINDOWS\SYSTEM32\winhoq32.dll
O20 - Winlogon Notify: wvuurpo - C:\WINDOWS\SYSTEM32\wvuurpo.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe
Hello bytemyfoot and Welcome to TomCoyote,

STEP 1.
======
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
STEP 2.
======
Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please post the contents of C:\vundofix.txt, the ComboFix log, and a new HiJackThis log.
VundoFix V6.3.5

Checking Java version…

Sun Java not detected
Scan started at 11:23:03 AM 2/9/2007

Listing files found while scanning….

C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\system32\wyadd.bak1
C:\WINDOWS\system32\wyadd.bak2
C:\WINDOWS\system32\wyadd.ini
C:\WINDOWS\system32\wyadd.ini2
C:\WINDOWS\system32\wyadd.tmp

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\system32\ddayw.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\wyadd.bak1
C:\WINDOWS\system32\wyadd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\wyadd.bak2
C:\WINDOWS\system32\wyadd.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\wyadd.ini
C:\WINDOWS\system32\wyadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\wyadd.ini2
C:\WINDOWS\system32\wyadd.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\wyadd.tmp
C:\WINDOWS\system32\wyadd.tmp Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\system32\ddayw.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\wyadd.ini
C:\WINDOWS\system32\wyadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\wyadd.ini2
C:\WINDOWS\system32\wyadd.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…


"Tim Morea" - 07-02-09 11:38:53 Service Pack 2
ComboFix 07-02-08.2 - Running from: "C:\Documents and Settings\Tim Morea\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\svchost.exe


((((((((((((((((((((((((((((((( Files Created from 2007-01-09 to 2007-02-09 ))))))))))))))))))))))))))))))))))


2007-02-09 11:23 d——– C:\VundoFix Backups
2007-02-08 23:01 d——– C:\DOCUME~1\TIMMOR~1\WINDOWS
2007-02-08 14:15 d——– C:\Program Files\Last.fm
2007-02-07 23:09 d——– C:\DOCUME~1\TIMMOR~1\Bluetooth Software
2007-02-07 22:59 d——– C:\Program Files\WIDCOMM
2007-02-07 22:49 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-02-07 22:44 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Creative
2007-02-07 20:59 d——– C:\DOCUME~1\TIMMOR~1\Application Data\AdobeUM
2007-02-07 20:35 24,576 –a—— C:\WINDOWS\system32\CTWEBFUN.DLL
2007-02-07 20:35 d——– C:\Program Files\Creative
2007-02-07 20:29 5,504 –a—— C:\WINDOWS\system32\drivers\MSTEE.sys
2007-02-07 20:29 19,328 –a—— C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-02-07 20:29 15,360 –a—— C:\WINDOWS\system32\drivers\StreamIP.sys
2007-02-07 20:29 11,136 –a—— C:\WINDOWS\system32\drivers\SLIP.sys
2007-02-07 20:29 10,880 –a—— C:\WINDOWS\system32\drivers\NdisIP.sys
2007-02-07 20:28 85,376 –a—— C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-02-07 20:28 17,024 –a—— C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-02-07 20:27 53,760 –a—— C:\WINDOWS\system32\vfwwdm32.dll
2007-02-07 20:26 91,830 –a—— C:\WINDOWS\system32\drivers\P0630Vid.sys
2007-02-07 20:26 81,920 –a—— C:\WINDOWS\CtDrvIns.exe
2007-02-07 20:26 69,632 –a—— C:\WINDOWS\system32\P0630Sti.dll
2007-02-07 20:26 49,152 –a—— C:\WINDOWS\system32\P0630Hwx.dll
2007-02-07 20:26 36,864 –a—— C:\WINDOWS\system32\CTCamMgr.dll
2007-02-07 20:26 32,768 –a—— C:\WINDOWS\system32\P0630Pin.dll
2007-02-07 20:26 20,480 –a—— C:\WINDOWS\system32\P0630Srv.exe
2007-02-07 20:26 20,480 –a—— C:\WINDOWS\P0630Cfg.exe
2007-02-07 20:26 126,976 –a—— C:\WINDOWS\system32\P0630Vfw.dll
2007-02-07 20:26 1,125,376 –a—— C:\WINDOWS\system32\drivers\P0630Evx.sys
2007-02-07 20:26 d——– C:\Webcam Live!
2007-02-07 20:24 d——– C:\DOCUME~1\LOCALS~1\Application Data\X10 Commander
2007-02-07 20:20 155,648 —h—– C:\Program Files\Common Files\svchost.exe
2007-02-07 19:38 277,063 ——— C:\WINDOWS\system32\ddayw.dll
2007-02-07 19:31 46,592 –a—— C:\btujat.exe
2007-02-07 19:31 3,264 –a—— C:\fpwsvgd.exe
2007-02-07 19:31 18,432 –a—— C:\WINDOWS\system32\winhoq32.dll
2007-02-07 19:31 1,024 –a—— C:\swglxr.exe
2007-02-07 19:31 1,024 –a—— C:\srnv.exe
2007-02-07 19:31 1,024 –a—— C:\gdntgen.exe
2007-02-07 19:31 1,024 –a—— C:\dnvbkvi.exe
2007-02-07 18:55 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-02-07 18:55 d——– C:\Program Files\CyberLink
2007-02-07 18:55 d——– C:\DOCUME~1\TIMMOR~1\Application Data\CyberLink
2007-02-07 18:55 d——– C:\DOCUME~1\ALLUSE~1\Application Data\CyberLink
2007-02-07 18:24 d——– C:\DOCUME~1\TIMMOR~1\Application Data\GlobalSCAPE
2007-02-07 18:23 d——– C:\Program Files\GlobalSCAPE
2007-02-07 18:21 d——– C:\Program Files\SpamBayes
2007-02-07 18:21 d——– C:\DOCUME~1\TIMMOR~1\Application Data\SpamBayes
2007-02-07 17:38 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-02-07 17:38 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Adobe
2007-02-07 17:38 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe Systems
2007-02-07 17:37 d——– C:\Program Files\Common Files\Adobe
2007-02-07 17:30 5,504 ——— C:\WINDOWS\system32\drivers\imagedrv.sys
2007-02-07 17:30 476,320 –a—— C:\WINDOWS\system32\ImagXpr7.dll
2007-02-07 17:30 471,040 –a—— C:\WINDOWS\system32\ImagXRA7.dll
2007-02-07 17:30 262,144 –a—— C:\WINDOWS\system32\ImagXR7.dll
2007-02-07 17:30 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-02-07 17:30 125,184 ——— C:\WINDOWS\system32\drivers\imagesrv.sys
2007-02-07 17:30 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll
2007-02-07 17:30 1,568,768 –a—— C:\WINDOWS\system32\ImagX7.dll
2007-02-07 17:30 d——– C:\Program Files\Common Files\Ahead
2007-02-07 17:30 d——– C:\Program Files\Ahead
2007-02-07 17:29 6,016 –a—— C:\WINDOWS\system32\drivers\vnccom.SYS
2007-02-07 17:29 5,760 –a—— C:\WINDOWS\system32\vnchelp.dll
2007-02-07 17:29 4,736 –a—— C:\WINDOWS\system32\drivers\vncdrv.sys
2007-02-07 17:29 12,800 –a—— C:\WINDOWS\system32\vncdrv.dll
2007-02-07 17:29 d——– C:\Program Files\UltraVNC
2007-02-07 17:25 10,761 –a—— C:\WINDOWS\system32\drivers\x10uif.sys
2007-02-07 17:25 d——– C:\Program Files\Common Files\Snapstream
2007-02-07 17:25 d——– C:\DOCUME~1\ALLUSE~1\Application Data\SnapStream
2007-02-07 17:22 d——– C:\Program Files\SnapStream Media
2007-02-07 17:20 127,208 –a—— C:\WINDOWS\system32\mucltui.dll
2007-02-07 17:19 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2007-02-06 12:51 12,928 –a—— C:\WINDOWS\system32\drivers\Dot4Prt.sys
2007-02-06 12:50 23,808 –a—— C:\WINDOWS\system32\drivers\Dot4usb.sys
2007-02-06 12:50 207,360 –a—— C:\WINDOWS\system32\drivers\Dot4.sys
2007-02-06 12:34 208,896 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-02-06 12:34 208,896 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-02-06 12:34 d——– C:\WINDOWS\nview
2007-02-06 12:33 d——– C:\NVIDIA
2007-02-06 12:16 10,624 –a—— C:\WINDOWS\system32\drivers\gameenum.sys
2007-02-06 12:05 585,728 –a—— C:\WINDOWS\system32\AReadyLB.dll
2007-02-06 12:05 38 –a—— C:\WINDOWS\system32\dtirc.dll
2007-02-06 12:05 229,376 –a—— C:\WINDOWS\system32\AudDevicePlugin.dll
2007-02-06 12:05 d——– C:\Program Files\MSBuild
2007-02-06 12:05 d——– C:\Program Files\J River
2007-02-06 12:00 d——– C:\WINDOWS\system32\XPSViewer
2007-02-06 12:00 d——– C:\Program Files\Reference Assemblies
2007-02-06 11:59 14,048 –a—— C:\WINDOWS\system32\spmsg2.dll
2007-02-06 11:58 d——– C:\Program Files\GSpot
2007-02-06 11:57 d——– C:\WINDOWS\WBEM
2007-02-06 11:57 d——– C:\DOCUME~1\TIMMOR~1\Application Data\DivX
2007-02-06 11:54 121,856 –a—— C:\WINDOWS\system32\xmllite.dll
2007-02-06 11:54 d——– C:\WINDOWS\network diagnostic
2007-02-06 11:54 d——– C:\Program Files\InterVocative Software
2007-02-06 11:51 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Hamachi
2007-02-06 11:50 17,480 –a—— C:\WINDOWS\system32\drivers\hamachi.sys
2007-02-06 11:50 d——– C:\Program Files\Hamachi
2007-02-06 11:49 d——– C:\Program Files\Windows Media Connect 2
2007-02-06 11:49 d——– C:\Program Files\TaskSwitchXP
2007-02-06 11:49 d——– C:\Program Files\FLVPlayer
2007-02-06 11:48 d——– C:\Program Files\eMule
2007-02-06 11:47 36,624 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-02-06 11:47 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-02-06 11:47 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-02-06 11:47 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2007-02-06 11:47 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2007-02-06 11:47 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2007-02-06 11:47 d——– C:\WINDOWS\system32\LogFiles
2007-02-06 11:47 d——– C:\WINDOWS\system32\en-us
2007-02-06 11:47 d——– C:\WINDOWS\system32\drivers\UMDF
2007-02-06 11:47 d——– C:\Program Files\Google
2007-02-06 11:47 d——– C:\Program Files\DivX
2007-02-06 11:46 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Lavasoft
2007-02-06 11:45 d——– C:\Program Files\Lavasoft
2007-02-06 11:38 dr–s—- C:\WINDOWS\assembly
2007-02-06 11:38 d——– C:\WINDOWS\system32\URTTemp
2007-02-06 11:38 d——– C:\WINDOWS\Microsoft.NET
2007-02-06 11:34 36,352 –a—— C:\WINDOWS\system32\tsgqec.dll
2007-02-06 11:34 288,768 –a—— C:\WINDOWS\system32\rhttpaa.dll
2007-02-06 11:34 116,736 –a—— C:\WINDOWS\system32\aaclient.dll
2007-02-06 11:01 1,177 –a—— C:\WINDOWS\mozver.dat
2007-02-06 09:08 262,144 –a—— C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-02-06 03:58 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Windows Genuine Advantage
2007-02-06 03:33 d——– C:\Jenny
2007-02-06 03:30 d–h—– C:\WINDOWS\system32\GroupPolicy
2007-02-06 03:25 d——– C:\DOCUME~1\TIMMOR~1\Application Data\uTorrent
2007-02-06 03:24 d——– C:\Program Files\uTorrent
2007-02-06 03:04 d——– C:\Program Files\FeedReader30
2007-02-06 03:04 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Feedreader
2007-02-06 02:48 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-02-06 02:46 d——– C:\Program Files\Microsoft.NET
2007-02-06 02:46 d——– C:\Program Files\Microsoft Works
2007-02-06 02:46 d——– C:\Program Files\Microsoft ActiveSync
2007-02-06 02:46 d——– C:\Program Files\Common Files\L&H
2007-02-06 02:45 d——– C:\WINDOWS\SHELLNEW
2007-02-06 02:36 d——– C:\Program Files\Common Files\Voyetra
2007-02-06 02:23 82,944 –a—— C:\WINDOWS\system32\drivers\wdmaud.sys
2007-02-06 02:23 6,400 –a—— C:\WINDOWS\system32\drivers\splitter.sys
2007-02-06 02:23 52,864 –a—— C:\WINDOWS\system32\drivers\DMusic.sys
2007-02-06 02:22 917,504 –a—— C:\WINDOWS\system\cmids3d3.dll
2007-02-06 02:22 712,704 –a—— C:\WINDOWS\system32\Audio3D3.dll
2007-02-06 02:22 712,704 –a—— C:\WINDOWS\system32\a3d.dll
2007-02-06 02:22 7,552 –a—— C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-02-06 02:22 60,800 –a—— C:\WINDOWS\system32\drivers\sysaudio.sys
2007-02-06 02:22 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-02-06 02:22 54,272 –a—— C:\WINDOWS\system32\drivers\swmidi.sys
2007-02-06 02:22 5,376 –a—— C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-02-06 02:22 4,992 –a—— C:\WINDOWS\system32\drivers\MSPQM.sys
2007-02-06 02:22 4,096 –a—— C:\WINDOWS\system32\ksuser.dll
2007-02-06 02:22 32,768 –a—— C:\WINDOWS\system32\udaprop3.dll
2007-02-06 02:22 28,672 –a—— C:\WINDOWS\system32\cmrmdrv3.dll
2007-02-06 02:22 28,672 –a—— C:\WINDOWS\CmiPCIUninstall.exe
2007-02-06 02:22 241,664 –a—— C:\WINDOWS\system32\cmrmdrv3.exe
2007-02-06 02:22 2,944 –a—— C:\WINDOWS\system32\drivers\drmkaud.sys
2007-02-06 02:22 172,416 –a—— C:\WINDOWS\system32\drivers\kmixer.sys
2007-02-06 02:22 145,792 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-02-06 02:22 142,464 –a—— C:\WINDOWS\system32\drivers\aec.sys
2007-02-06 02:22 102,400 –a—— C:\WINDOWS\system32\cmudax3.DLL
2007-02-06 02:22 1,616,640 –a—— C:\WINDOWS\system32\drivers\cmudax3.sys
2007-02-06 02:22 d——– C:\Program Files\Turtle Beach
2007-02-06 02:22 d——– C:\DOCUME~1\ALLUSE~1\Application Data\InstallShield
2007-02-06 02:19 d——– C:\Program Files\Process Explorer
2007-02-06 02:18 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Apple Computer
2007-02-06 02:18 d——– C:\DOCUME~1\ALLUSE~1\Application Data\WinZip
2007-02-06 02:17 d——– C:\Program Files\Winamp
2007-02-06 02:17 d——– C:\Program Files\iTunes
2007-02-06 02:17 d——– C:\Program Files\iPod
2007-02-06 02:16 d——– C:\Program Files\Taskbar Shuffle
2007-02-06 02:16 d——– C:\Program Files\QuickTime
2007-02-06 02:16 d——– C:\Program Files\Apple Software Update
2007-02-06 02:15 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Apple Computer
2007-02-06 02:01 d——– C:\Program Files\MessengerMate
2007-02-06 01:58 d——– C:\Program Files\Viewpoint
2007-02-06 01:58 d——– C:\Program Files\AOD
2007-02-06 01:58 d——– C:\Program Files\AIM
2007-02-06 01:58 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Aim
2007-02-06 01:58 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Viewpoint
2007-02-06 01:57 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-02-06 01:57 0 –a—— C:\WINDOWS\nsreg.dat
2007-02-06 01:57 d–h—– C:\WINDOWS\$hf_mig$
2007-02-06 01:57 d——– C:\WINDOWS\system32\PreInstall
2007-02-06 01:56 d——– C:\Program Files\Mozilla Firefox
2007-02-06 01:55 d——– C:\Program Files\Intel
2007-02-06 01:53 d——– C:\WINDOWS\system32\ReinstallBackups
2007-02-06 01:52 d—s—- C:\DOCUME~1\TIMMOR~1\UserData
2007-02-06 01:50 24,064 –a—— C:\WINDOWS\system32\IntelNic.dll
2007-02-06 01:50 163,840 –a—— C:\WINDOWS\system32\e1000msg.dll
2007-02-06 01:50 163,840 –a—— C:\WINDOWS\system32\drivers\e1000325.sys
2007-02-06 01:50 126,976 –a—— C:\WINDOWS\system32\Prounstl.exe
2007-02-06 01:50 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-02-06 01:48 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2007-02-06 01:48 446,464 -ra—— C:\WINDOWS\system32\hhactivex.dll
2007-02-06 01:48 176,128 –a—— C:\WINDOWS\system32\RcdScan.dll
2007-02-06 01:48 d–h—– C:\Program Files\InstallShield Installation Information
2007-02-06 01:48 d——– C:\Dell
2007-02-06 01:47 13,632 ——— C:\WINDOWS\system32\drivers\omci.sys
2007-02-06 01:47 d——– C:\Program Files\Common Files\InstallShield
2007-02-06 01:36 87,808 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-02-06 01:36 107,696 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-02-06 01:35 d——– C:\WINDOWS\RegisteredPackages
2007-02-06 01:35 d——– C:\Program Files\Symantec AntiVirus
2007-02-06 01:35 d——– C:\Program Files\Symantec
2007-02-06 01:35 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Symantec
2007-02-06 01:34 d——– C:\Program Files\Common Files\Symantec Shared
2007-02-06 01:26 2,097,152 –ah—– C:\DOCUME~1\TIMMOR~1\NTUSER.DAT
2007-02-06 01:25 262,144 –ah—– C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-02-06 01:25 225,280 –ah—– C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-02-06 01:25 d——– C:\WINDOWS\SoftwareDistribution
2007-02-06 01:25 d——– C:\WINDOWS\Prefetch
2007-02-06 01:21 225,280 —h—– C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-02-06 01:21 112,128 –a—— C:\WINDOWS\system32\mapi32.dll
2007-02-06 01:21 0 -rahs—- C:\MSDOS.SYS
2007-02-06 01:21 0 -rahs—- C:\IO.SYS
2007-02-06 01:21 0 –a—— C:\CONFIG.SYS
2007-02-06 01:21 0 –a—— C:\AUTOEXEC.BAT
2007-02-06 01:21 d——– C:\WINDOWS\system32\xircom
2007-02-06 01:21 d——– C:\Program Files\microsoft frontpage
2007-02-06 01:20 dr——- C:\WINDOWS\Offline Web Pages
2007-02-06 01:20 d–hs—- C:\DOCUME~1\ALLUSE~1\DRM
2007-02-06 01:20 d–h—– C:\Program Files\WindowsUpdate
2007-02-06 01:20 d—s—- C:\WINDOWS\Downloaded Program Files
2007-02-06 01:19 81,920 –a—— C:\WINDOWS\system32\ils.dll
2007-02-06 01:19 8,192 –a—— C:\WINDOWS\system32\bitsprx2.dll
2007-02-06 01:19 73,472 –a—— C:\WINDOWS\system32\drivers\sr.sys
2007-02-06 01:19 7,168 –a—— C:\WINDOWS\system32\bitsprx3.dll
2007-02-06 01:19 69,632 –a—— C:\WINDOWS\system32\msconf.dll
2007-02-06 01:19 679,424 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-02-06 01:19 67,584 –a—— C:\WINDOWS\system32\srclient.dll
2007-02-06 01:19 64,512 –a—— C:\WINDOWS\system32\acctres.dll
2007-02-06 01:19 6,656 –a—— C:\WINDOWS\system32\wuauserv.dll
2007-02-06 01:19 48,128 –a—— C:\WINDOWS\system32\inetres.dll
2007-02-06 01:19 465,176 –a—— C:\WINDOWS\system32\wuapi.dll
2007-02-06 01:19 45,568 –a—— C:\WINDOWS\system32\safrslv.dll
2007-02-06 01:19 43,520 –a—— C:\WINDOWS\system32\safrcdlg.dll
2007-02-06 01:19 43,520 –a—— C:\WINDOWS\system32\racpldlg.dll
2007-02-06 01:19 41,240 –a—— C:\WINDOWS\system32\wups.dll
2007-02-06 01:19 382,464 –a—— C:\WINDOWS\system32\qmgr.dll
2007-02-06 01:19 34,560 –a—— C:\WINDOWS\system32\mnmdd.dll
2007-02-06 01:19 32,768 –a—— C:\WINDOWS\system32\mnmsrvc.exe
2007-02-06 01:19 32,768 –a—— C:\WINDOWS\system32\isrdbg32.dll
2007-02-06 01:19 29,696 –a—— C:\WINDOWS\system32\safrdm.dll
2007-02-06 01:19 28,672 –a—— C:\WINDOWS\system32\nmmkcert.dll
2007-02-06 01:19 252,928 –a—— C:\WINDOWS\system32\msoeacct.dll
2007-02-06 01:19 239,104 –a—— C:\WINDOWS\system32\srrstr.dll
2007-02-06 01:19 23,040 –a—— C:\WINDOWS\system32\fltmc.exe
2007-02-06 01:19 194,328 –a—— C:\WINDOWS\system32\wuaueng1.dll
2007-02-06 01:19 18,944 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-02-06 01:19 173,536 –a—— C:\WINDOWS\system32\wuweb.dll
2007-02-06 01:19 172,312 –a—— C:\WINDOWS\system32\wuauclt1.exe
2007-02-06 01:19 170,496 –a—— C:\WINDOWS\system32\srsvc.dll
2007-02-06 01:19 16,896 –a—— C:\WINDOWS\system32\fltlib.dll
2007-02-06 01:19 16,384 –a—— C:\WINDOWS\system32\icfgnt5.dll
2007-02-06 01:19 128,896 –a—— C:\WINDOWS\system32\drivers\fltmgr.sys
2007-02-06 01:19 127,256 –a—— C:\WINDOWS\system32\wucltui.dll
2007-02-06 01:19 124,184 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-02-06 01:19 12,288 –a—— C:\WINDOWS\system32\nmevtmsg.dll
2007-02-06 01:19 11,264 –a—— C:\WINDOWS\system32\atrace.dll
2007-02-06 01:19 105,984 –a—— C:\WINDOWS\system32\msoert2.dll
2007-02-06 01:19 1,343,768 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-02-06 01:19 d—s—- C:\WINDOWS\Tasks
2007-02-06 01:19 d——– C:\WINDOWS\system32\Restore
2007-02-06 01:19 d——– C:\WINDOWS\system32\Macromed
2007-02-06 01:19 d——– C:\WINDOWS\system32\DirectX
2007-02-06 01:19 d——– C:\WINDOWS\srchasst
2007-02-06 01:19 d——– C:\Program Files\Movie Maker
2007-02-06 01:19 d——– C:\Program Files\Common Files\MSSoap
2007-02-06 01:18 81,920 –a—— C:\WINDOWS\system32\isign32.dll
2007-02-06 01:18 73,728 –a—— C:\WINDOWS\system32\icwdial.dll
2007-02-06 01:18 65,536 –a—— C:\WINDOWS\system32\icwphbk.dll
2007-02-06 01:18 274,944 –a—— C:\WINDOWS\system32\mstask.dll
2007-02-06 01:18 274,432 –a—— C:\WINDOWS\system32\inetcfg.dll
2007-02-06 01:18 21,640 –a—— C:\WINDOWS\system32\emptyregdb.dat
2007-02-06 01:18 190,976 –a—— C:\WINDOWS\system32\schedsvc.dll
2007-02-06 01:18 12,288 –a—— C:\WINDOWS\system32\mstinit.exe
2007-02-06 01:17 97,792 –a—— C:\WINDOWS\system32\comrepl.dll
2007-02-06 01:17 956,416 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-02-06 01:17 93,696 –a—— C:\WINDOWS\system32\tscfgwmi.dll
2007-02-06 01:17 91,136 –a—— C:\WINDOWS\system32\mtxoci.dll
2007-02-06 01:17 9,728 –a—— C:\WINDOWS\system32\reset.exe
2007-02-06 01:17 87,176 –a—— C:\WINDOWS\system32\rdpwsx.dll
2007-02-06 01:17 85,504 –a—— C:\WINDOWS\system32\catsrvps.dll
2007-02-06 01:17 80,384 –a—— C:\WINDOWS\system32\charmap.exe
2007-02-06 01:17 73,216 –a—— C:\WINDOWS\system32\avwav.dll
2007-02-06 01:17 67,072 –a—— C:\WINDOWS\system32\rdshost.exe
2007-02-06 01:17 625,152 –a—— C:\WINDOWS\system32\catsrvut.dll
2007-02-06 01:17 62,464 –a—— C:\WINDOWS\system32\rdpclip.exe
2007-02-06 01:17 605,696 –a—— C:\WINDOWS\system32\getuname.dll
2007-02-06 01:17 600,576 –a—— C:\WINDOWS\system32\mstsc.exe
2007-02-06 01:17 60,416 –a—— C:\WINDOWS\system32\remotepg.dll
2007-02-06 01:17 60,416 –a—— C:\WINDOWS\system32\colbact.dll
2007-02-06 01:17 6,144 –a—— C:\WINDOWS\system32\msdtc.exe
2007-02-06 01:17 58,880 –a—— C:\WINDOWS\system32\msdtclog.dll
2007-02-06 01:17 58,880 –a—— C:\WINDOWS\system32\licwmi.dll
2007-02-06 01:17 56,832 –a—— C:\WINDOWS\system32\sol.exe
2007-02-06 01:17 56,320 –a—— C:\WINDOWS\system32\servdeps.dll
2007-02-06 01:17 55,296 –a—— C:\WINDOWS\system32\freecell.exe
2007-02-06 01:17 540,160 –a—— C:\WINDOWS\system32\comuid.dll
2007-02-06 01:17 54,272 –a—— C:\WINDOWS\system32\stclient.dll
2007-02-06 01:17 538,624 –a—— C:\WINDOWS\system32\spider.exe
2007-02-06 01:17 5,632 –a—— C:\WINDOWS\system32\write.exe
2007-02-06 01:17 5,120 –a—— C:\WINDOWS\system32\dcomcnfg.exe
2007-02-06 01:17 498,688 –a—— C:\WINDOWS\system32\clbcatq.dll
2007-02-06 01:17 44,544 –a—— C:\WINDOWS\system32\tscupgrd.exe
2007-02-06 01:17 44,544 –a—— C:\WINDOWS\system32\hticons.dll
2007-02-06 01:17 426,496 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-02-06 01:17 4,096 –a—— C:\WINDOWS\system32\rdpcfgex.dll
2007-02-06 01:17 4,096 –a—— C:\WINDOWS\system32\mtxex.dll
2007-02-06 01:17 38,912 –a—— C:\WINDOWS\system32\cfgbkend.dll
2007-02-06 01:17 35,328 –a—— C:\WINDOWS\system32\winchat.exe
2007-02-06 01:17 347,136 –a—— C:\WINDOWS\system32\hypertrm.dll
2007-02-06 01:17 343,040 –a—— C:\WINDOWS\system32\mspaint.exe
2007-02-06 01:17 33,792 –a—— C:\WINDOWS\system32\regini.exe
2007-02-06 01:17 295,424 –a—— C:\WINDOWS\system32\termsrv.dll
2007-02-06 01:17 25,600 –a—— C:\WINDOWS\system32\comaddin.dll
2007-02-06 01:17 25,088 –a—— C:\WINDOWS\system32\mtxlegih.dll
2007-02-06 01:17 227,840 –a—— C:\WINDOWS\system32\avtapi.dll
2007-02-06 01:17 225,792 –a—— C:\WINDOWS\system32\catsrv.dll
2007-02-06 01:17 22,016 –a—— C:\WINDOWS\system32\qwinsta.exe
2007-02-06 01:17 21,896 –a—— C:\WINDOWS\system32\drivers\tdtcp.sys
2007-02-06 01:17 20,992 –a—— C:\WINDOWS\system32\msg.exe
2007-02-06 01:17 20,480 –a—— C:\WINDOWS\system32\qprocess.exe
2007-02-06 01:17 20,480 –a—— C:\WINDOWS\system32\mtxdm.dll
2007-02-06 01:17 19,968 –a—— C:\WINDOWS\system32\rdpsnd.dll
2007-02-06 01:17 185,344 –a—— C:\WINDOWS\system32\cmprops.dll
2007-02-06 01:17 183,808 –a—— C:\WINDOWS\system32\accwiz.exe
2007-02-06 01:17 17,408 –a—— C:\WINDOWS\system32\mmfutil.dll
2007-02-06 01:17 161,280 –a—— C:\WINDOWS\system32\msdtcuiu.dll
2007-02-06 01:17 16,896 –a—— C:\WINDOWS\system32\tsshutdn.exe
2007-02-06 01:17 16,896 –a—— C:\WINDOWS\system32\qappsrv.exe
2007-02-06 01:17 16,384 –a—— C:\WINDOWS\system32\tskill.exe
2007-02-06 01:17 16,384 –a—— C:\WINDOWS\system32\avmeter.dll
2007-02-06 01:17 15,872 –a—— C:\WINDOWS\system32\rwinsta.exe
2007-02-06 01:17 15,872 –a—— C:\WINDOWS\system32\cdmodem.dll
2007-02-06 01:17 15,360 –a—— C:\WINDOWS\system32\logoff.exe
2007-02-06 01:17 147,968 –a—— C:\WINDOWS\system32\rdchost.dll
2007-02-06 01:17 147,456 –a—— C:\WINDOWS\system32\comsnap.dll
2007-02-06 01:17 140,800 –a—— C:\WINDOWS\system32\sessmgr.exe
2007-02-06 01:17 14,848 –a—— C:\WINDOWS\system32\tsdiscon.exe
2007-02-06 01:17 14,848 –a—— C:\WINDOWS\system32\tscon.exe
2007-02-06 01:17 14,848 –a—— C:\WINDOWS\system32\shadow.exe
2007-02-06 01:17 139,528 –a—— C:\WINDOWS\system32\drivers\rdpwd.sys
2007-02-06 01:17 138,752 –a—— C:\WINDOWS\system32\sndvol32.exe
2007-02-06 01:17 131,584 –a—— C:\WINDOWS\system32\sndrec32.exe
2007-02-06 01:17 13,824 –a—— C:\WINDOWS\system32\rdsaddin.exe
2007-02-06 01:17 126,976 –a—— C:\WINDOWS\system32\mshearts.exe
2007-02-06 01:17 123,392 –a—— C:\WINDOWS\system32\mplay32.exe
2007-02-06 01:17 12,040 –a—— C:\WINDOWS\system32\drivers\tdpipe.sys
2007-02-06 01:17 119,808 –a—— C:\WINDOWS\system32\winmine.exe
2007-02-06 01:17 114,688 –a—— C:\WINDOWS\system32\calc.exe
2007-02-06 01:17 110,080 –a—— C:\WINDOWS\system32\clbcatex.dll
2007-02-06 01:17 11,776 –a—— C:\WINDOWS\system32\xolehlp.dll
2007-02-06 01:17 11,264 –a—— C:\WINDOWS\system32\icaapi.dll
2007-02-06 01:17 102,912 –a—— C:\WINDOWS\system32\clipbrd.exe
2007-02-06 01:17 1,866,240 –a—— C:\WINDOWS\system32\mstscax.dll
2007-02-06 01:17 1,267,200 –a—— C:\WINDOWS\system32\comsvcs.dll
2007-02-06 01:17 1,161 –a—— C:\WINDOWS\system32\usrlogon.cmd
2007-02-06 01:17 d——– C:\WINDOWS\system32\MsDtc
2007-02-06 01:17 d——– C:\WINDOWS\system32\Com
2007-02-06 01:17 d——– C:\WINDOWS\Registration
2007-02-06 01:17 d——– C:\Program Files\Windows NT
2007-02-06 01:17 d——– C:\Program Files\Online Services
2007-02-06 01:17 d——– C:\Program Files\MSN Gaming Zone
2007-02-06 01:17 d——– C:\Program Files\Messenger
2007-02-06 01:16 40,840 –a—— C:\WINDOWS\system32\drivers\termdd.sys
2007-02-06 01:16 196,864 –a—— C:\WINDOWS\system32\drivers\rdpdr.sys
2007-02-05 20:12 57,472 –a—— C:\WINDOWS\system32\drivers\redbook.sys
2007-02-05 20:12 3,072 –a—— C:\WINDOWS\system32\drivers\audstub.sys
2007-02-05 20:11 6,400 –a—— C:\WINDOWS\system32\drivers\enum1394.sys
2007-02-05 20:11 4,527,488 –a—— C:\WINDOWS\system32\nv4_disp.dll
2007-02-05 20:11 3,994,624 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-02-05 20:10 74,240 –a—— C:\WINDOWS\system32\usbui.dll
2007-02-05 20:10 5,504 –a—— C:\WINDOWS\system32\drivers\intelide.sys
2007-02-05 20:10 42,368 –a—— C:\WINDOWS\system32\drivers\AGP440.SYS
2007-02-05 20:09 9,936 –a—— C:\WINDOWS\system\LZEXPAND.DLL
2007-02-05 20:09 9,008 –a—— C:\WINDOWS\system\VER.DLL
2007-02-05 20:09 85,020 –a—— C:\WINDOWS\system32\dgsetup.dll
2007-02-05 20:09 82,944 –a—— C:\WINDOWS\system\OLECLI.DLL
2007-02-05 20:09 8,704 –a—— C:\WINDOWS\system32\batt.dll
2007-02-05 20:09 8,192 -ra—— C:\WINDOWS\system32\kbdhept.dll
2007-02-05 20:09 74,752 –a—— C:\WINDOWS\system32\storprop.dll
2007-02-05 20:09 7,168 -ra—— C:\WINDOWS\system32\kbdcz.dll
2007-02-05 20:09 69,584 –a—— C:\WINDOWS\system\AVICAP.DLL
2007-02-05 20:09 69,120 –a—— C:\WINDOWS\NOTEPAD.EXE
2007-02-05 20:09 68,768 –a—— C:\WINDOWS\system\MMSYSTEM.DLL
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdycl.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdsl1.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdsl.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdpl.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdhu.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdhela3.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdcz2.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdcz1.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdcr.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\KBDAL.DLL
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdtuq.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdtuf.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdlv1.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdlv.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdhela2.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdgkl.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdest.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdro.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdpl1.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdmon.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdlt1.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdlt.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdkyr.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdhu1.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdhe319.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdhe220.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdhe.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdazel.dll
2007-02-05 20:09 5,120 –a—— C:\WINDOWS\system\SHELL.DLL
2007-02-05 20:09 32,816 –a—— C:\WINDOWS\system\COMMDLG.DLL
2007-02-05 20:09 24,661 –a—— C:\WINDOWS\system32\spxcoins.dll
2007-02-05 20:09 24,064 –a—— C:\WINDOWS\system\OLESVR.DLL
2007-02-05 20:09 19,200 –a—— C:\WINDOWS\system\TAPI.DLL
2007-02-05 20:09 176,157 –a—— C:\WINDOWS\system32\dgrpsetu.dll
2007-02-05 20:09 15,360 –a—— C:\WINDOWS\TASKMAN.EXE
2007-02-05 20:09 13,312 –a—— C:\WINDOWS\system32\irclass.dll
2007-02-05 20:09 126,912 –a—— C:\WINDOWS\system\MSVIDEO.DLL
2007-02-05 20:09 11,264 –a—— C:\WINDOWS\system32\drivers\irenum.sys
2007-02-05 20:09 109,456 –a—— C:\WINDOWS\system\AVIFILE.DLL
2007-02-05 20:09 103,424 –a—— C:\WINDOWS\system32\EqnClass.Dll
2007-02-05 20:09 dr——- C:\Program Files
2007-02-05 20:09 d–hs—- C:\WINDOWS\Installer
2007-02-05 20:09 d——– C:\Program Files\Common Files\SpeechEngines
2007-02-05 20:09 d——– C:\Program Files\Common Files\ODBC
2007-02-05 20:08 dr——- C:\DOCUME~1\ALLUSE~1\Documents
2007-02-05 20:08 d——– C:\WINDOWS\system32\CatRoot2
2007-02-05 20:08 d——– C:\WINDOWS\system32\CatRoot
2007-02-05 20:07 d——– C:\Documents and Settings
2007-02-05 20:02 dr-hsc— C:\WINDOWS\system32\dllcache
2007-02-05 20:02 dr–s—- C:\WINDOWS\Fonts
2007-02-05 20:02 dr——- C:\WINDOWS\Web
2007-02-05 20:02 d–h—– C:\WINDOWS\inf
2007-02-05 20:02 d——– C:\WINDOWS\WinSxS
2007-02-05 20:02 d——– C:\WINDOWS\twain_32
2007-02-05 20:02 d——– C:\WINDOWS\system32\wins
2007-02-05 20:02 d——– C:\WINDOWS\system32\wbem
2007-02-05 20:02 d——– C:\WINDOWS\system32\usmt
2007-02-05 20:02 d——– C:\WINDOWS\system32\spool
2007-02-05 20:02 d——– C:\WINDOWS\system32\ShellExt
2007-02-05 20:02 d——– C:\WINDOWS\system32\Setup
2007-02-05 20:02 d——– C:\WINDOWS\system32\ras
2007-02-05 20:02 d——– C:\WINDOWS\system32\oobe
2007-02-05 20:02 d——– C:\WINDOWS\system32\npp
2007-02-05 20:02 d——– C:\WINDOWS\system32\mui
2007-02-05 20:02 d——– C:\WINDOWS\system32\inetsrv
2007-02-05 20:02 d——– C:\WINDOWS\system32\IME
2007-02-05 20:02 d——– C:\WINDOWS\system32\icsxml
2007-02-05 20:02 d——– C:\WINDOWS\system32\ias
2007-02-05 20:02 d——– C:\WINDOWS\system32\export
2007-02-05 20:02 d——– C:\WINDOWS\system32\drivers\etc
2007-02-05 20:02 d——– C:\WINDOWS\system32\drivers\disdn
2007-02-05 20:02 d——– C:\WINDOWS\system32\drivers
2007-02-05 20:02 d——– C:\WINDOWS\system32\dhcp
2007-02-05 20:02 d——– C:\WINDOWS\system32\config
2007-02-05 20:02 d——– C:\WINDOWS\system32\3com_dmi
2007-02-05 20:02 d——– C:\WINDOWS\system32\3076
2007-02-05 20:02 d——– C:\WINDOWS\system32\2052
2007-02-05 20:02 d——– C:\WINDOWS\system32\1054
2007-02-05 20:02 d——– C:\WINDOWS\system32\1042
2007-02-05 20:02 d——– C:\WINDOWS\system32\1041
2007-02-05 20:02 d——– C:\WINDOWS\system32\1037
2007-02-05 20:02 d——– C:\WINDOWS\system32\1033
2007-02-05 20:02 d——– C:\WINDOWS\system32\1031
2007-02-05 20:02 d——– C:\WINDOWS\system32\1028
2007-02-05 20:02 d——– C:\WINDOWS\system32\1025
2007-02-05 20:02 d——– C:\WINDOWS\system32
2007-02-05 20:02 d——– C:\WINDOWS\system
2007-02-05 20:02 d——– C:\WINDOWS\security
2007-02-05 20:02 d——– C:\WINDOWS\Resources
2007-02-05 20:02 d——– C:\WINDOWS\repair
2007-02-05 20:02 d——– C:\WINDOWS\Provisioning
2007-02-05 20:02 d——– C:\WINDOWS\PeerNet
2007-02-05 20:02 d——– C:\WINDOWS\pchealth
2007-02-05 20:02 d——– C:\WINDOWS\mui
2007-02-05 20:02 d——– C:\WINDOWS\msapps
2007-02-05 20:02 d——– C:\WINDOWS\msagent
2007-02-05 20:02 d——– C:\WINDOWS\Media
2007-02-05 20:02 d——– C:\WINDOWS\java
2007-02-05 20:02 d——– C:\WINDOWS\ime
2007-02-05 20:02 d——– C:\WINDOWS\Help
2007-02-05 20:02 d——– C:\WINDOWS\ehome
2007-02-05 20:02 d——– C:\WINDOWS\Driver Cache
2007-02-05 20:02 d——– C:\WINDOWS\Debug
2007-02-05 20:02 d——– C:\WINDOWS\Cursors
2007-02-05 20:02 d——– C:\WINDOWS\Connection Wizard
2007-02-05 20:02 d——– C:\WINDOWS\Config
2007-02-05 20:02 d——– C:\WINDOWS\AppPatch
2007-02-05 20:02 d——– C:\WINDOWS\addins
2007-02-05 20:02 d——– C:\WINDOWS
2007-01-31 23:56 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-01-31 23:56 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-01-31 23:56 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-01-31 23:56 639,066 –a—— C:\WINDOWS\system32\DivX.dll
2007-01-31 16:27 524,288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-01-30 18:15 118,784 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-01-30 00:03 3,596,288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-01-30 00:03 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-01-30 00:03 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-01-29 23:56 73,728 –a—— C:\WINDOWS\system32\dpl100.dll
2007-01-29 23:56 593,920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2007-01-29 23:56 57,344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-01-29 23:56 53,248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-01-29 23:56 344,064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-01-29 23:56 294,912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-01-29 23:56 294,912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-01-29 23:56 196,608 –a—— C:\WINDOWS\system32\dtu100.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-08 14:16 127 –a—— C:\DOCUME~1\TIMMOR~1\Application Data\iscrobbler.ini
2007-02-07 18:16 ——– d—s—- C:\DOCUME~1\TIMMOR~1\Application Data\microsoft
2007-02-06 11:01 ——– d——– C:\DOCUME~1\TIMMOR~1\Application Data\macromedia
2007-02-06 01:56 ——– d——– C:\DOCUME~1\TIMMOR~1\Application Data\mozilla
2007-02-06 01:26 ——– d——– C:\DOCUME~1\TIMMOR~1\Application Data\identities
2007-02-05 20:08 62 –ahs—- C:\DOCUME~1\TIMMOR~1\Application Data\desktop.ini
2006-12-12 11:24 12288 –a—— C:\WINDOWS\system32\divxwmpexttype.dll
2006-11-27 03:45 60416 –a—— C:\WINDOWS\system32\tzchange.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Taskbar Shuffle"="C:\\Program Files\\Taskbar Shuffle\\taskbarshuffle.exe"
"feedreader.exe"="\"C:\\Program Files\\FeedReader30\\feedreader.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"TaskSwitchXP"="C:\\Program Files\\TaskSwitchXP\\TaskSwitchXP.exe"
"Creative WebCam Tray"="\"C:\\Program Files\\Creative\\Shared Files\\CamTray.exe\""
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Acrobat\\AdobeUpdateManager.exe AcPro7_0_7"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Turtle Beach Montego DDL"="\"C:\\Program Files\\Turtle Beach\\MontegoDDL\\TBMontegoTray.exe\""
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\isuspm.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"C-Media Mixer"="Mixer.exe /startup"
"UnlockerAssistant"="\"C:\\Program Files\\Unlocker\\UnlockerAssistant.exe\" -H"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"Firefly"="C:\\Program Files\\SnapStream Media\\Firefly\\Firefly.exe"
"WinVNC"="\"C:\\Program Files\\UltraVNC\\WinVNC.exe\" -servicehelper"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
@=""
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"LanguageShortcut"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"svchost.exe"="C:\\Program Files\\Common Files\\svchost.exe"

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
"Debugger"="\"C:\\PROGRAM FILES\\PROCESS EXPLORER\\PROCEXP.EXE\""
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddayw
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winhoq32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\wyadd.tmp 0 bytes

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1

********************************************************************

Completion time: 07-02-09 11:42:41


Logfile of HijackThis v1.99.1
Scan saved at 11:43:43 AM, on 2/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Turtle Beach\MontegoDDL\TBMontegoTray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SnapStream Media\Firefly\Firefly.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\FeedReader30\feedreader.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Documents and Settings\Tim Morea\Desktop\HJT.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {F34F19E3-D0DD-4A5E-A48B-C4938AD74159} - C:\WINDOWS\system32\ddayw.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Turtle Beach Montego DDL] "C:\Program Files\Turtle Beach\MontegoDDL\TBMontegoTray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Firefly] C:\Program Files\SnapStream Media\Firefly\Firefly.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
O4 - HKCU\..\Run: [feedreader.exe] "C:\Program Files\FeedReader30\feedreader.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_7
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save with Download Manager… - file://C:\Program Files\J River\Media Center 11\DMDownload.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1170751310718
O20 - Winlogon Notify: ddayw - C:\WINDOWS\system32\ddayw.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: winhoq32 - C:\WINDOWS\SYSTEM32\winhoq32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Servic
I noticed my HJT log got cut off. Here's the rest: O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing) O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe
STEP 1.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\SYSTEM32\winhoq32.dll



In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

Scan with HijackThis. Place a check against each of the following:
O2 - BHO: (no name) - {F34F19E3-D0DD-4A5E-A48B-C4938AD74159} - C:\WINDOWS\system32\ddayw.dll
O20 - Winlogon Notify: ddayw - C:\WINDOWS\system32\ddayw.dll
O20 - Winlogon Notify: winhoq32 - C:\WINDOWS\SYSTEM32\winhoq32.dll

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Post (reply) with a fresh HijackThis log and we will take another look.
Logfile of HijackThis v1.99.1
Scan saved at 5:24:52 PM, on 2/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Turtle Beach\MontegoDDL\TBMontegoTray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SnapStream Media\Firefly\Firefly.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\FeedReader30\feedreader.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hamachi\hamachi.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Tim Morea\Desktop\HJT.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Turtle Beach Montego DDL] "C:\Program Files\Turtle Beach\MontegoDDL\TBMontegoTray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Firefly] C:\Program Files\SnapStream Media\Firefly\Firefly.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
O4 - HKCU\..\Run: [feedreader.exe] "C:\Program Files\FeedReader30\feedreader.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_7
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save with Download Manager… - file://C:\Program Files\J River\Media Center 11\DMDownload.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1170751310718
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe

I should note that Symantec just just gave me a warning that it found and deleted another Vundo file.
Let's run another scan please.

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit.
  • Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________

Please post:
  • AVG Anti-spyware log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 7:11:48 PM 2/9/2007 + Scan result: C:\System Volume Information\_restore{978D90C2-E33F-434A-8312-D370C4C3BE34}\RP12\A0002907.exe -> Dropper.Agent.azk : Cleaned with backup (quarantined). C:\Program Files\Common Files\svchost.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{978D90C2-E33F-434A-8312-D370C4C3BE34}\RP12\A0004653.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{978D90C2-E33F-434A-8312-D370C4C3BE34}\RP15\A0006828.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{978D90C2-E33F-434A-8312-D370C4C3BE34}\RP18\A0009809.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{978D90C2-E33F-434A-8312-D370C4C3BE34}\RP18\A0009881.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{978D90C2-E33F-434A-8312-D370C4C3BE34}\RP19\A0009994.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{978D90C2-E33F-434A-8312-D370C4C3BE34}\RP19\A0010019.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{978D90C2-E33F-434A-8312-D370C4C3BE34}\RP19\A0010040.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\WINDOWS\svchost.exe -> Logger.Agent.or : Cleaned with backup (quarantined). :mozilla.557:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.74:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.75:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.76:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.77:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.78:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.79:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.80:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.81:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.82:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.83:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@buzznet.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. :mozilla.459:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.460:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.284:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.589:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.591:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.592:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.593:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.476:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.477:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.478:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.479:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.480:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. :mozilla.467:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.565:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.551:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.552:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.553:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.554:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.444:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.445:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.446:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.447:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.448:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.113:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.114:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.115:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.116:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.73:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.413:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Epilot : Cleaned. :mozilla.148:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.149:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.150:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.358:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.359:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.481:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.482:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.483:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.486:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.450:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned. :mozilla.174:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.242:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.243:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim [removed][1].txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.494:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.495:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.187:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.188:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.189:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.190:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.191:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.496:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.497:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.498:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.577:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.578:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.579:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.580:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.581:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.582:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim [removed]-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.278:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.279:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim [removed][2].txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.427:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Spylog : Cleaned. :mozilla.117:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.121:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.122:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.123:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.124:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.125:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.126:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.487:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.488:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.489:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.575:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.576:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.527:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.528:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.529:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.530:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.531:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.532:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.533:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.534:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim morea@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.130:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.540:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.541:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.287:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. C:\Documents and Settings\Tim Morea\Cookies\tim [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.567:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.568:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.569:C:\Documents and Settings\Tim Morea\Application Data\Mozilla\Firefox\Profiles\h0ztofxu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\dnvbkvi.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined). C:\gdntgen.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined). C:\srnv.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined). C:\swglxr.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined). C:\Program Files\WinRAR\Default.SFX -> Worm.Fujack.ac : Cleaned with backup (quarantined). ::Report end
Logfile of HijackThis v1.99.1
Scan saved at 7:15:31 PM, on 2/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Turtle Beach\MontegoDDL\TBMontegoTray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SnapStream Media\Firefly\Firefly.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\FeedReader30\feedreader.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hamachi\hamachi.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Tim Morea\Desktop\HJT.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Turtle Beach Montego DDL] "C:\Program Files\Turtle Beach\MontegoDDL\TBMontegoTray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Firefly] C:\Program Files\SnapStream Media\Firefly\Firefly.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
O4 - HKCU\..\Run: [feedreader.exe] "C:\Program Files\FeedReader30\feedreader.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_7
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save with Download Manager… - file://C:\Program Files\J River\Media Center 11\DMDownload.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1170751310718
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe
How's your ccmputer running now?

AVG Anti-Spyware cleaned or quarantined some files but there are two that I am suspicious of that had similar date.

Please show all files for your system.
You will need to reverse this process when all steps are done.


Submit File to Jotti
Please click on Jotti
Use the "Browse" button and locate the following file on your computer:
C:\btujat.exe
Click the "Submit" button.
Please copy and post (reply) with the results

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.

Please repeat the above for C:\fpwsvgd.exe
I haven't had any of the random popups in a long while, and everything seems to be running better. Also, no alerts from Symantec in a while too. There was no useful info in the Properties of either file. Here are the Jotti results: File: btujat.exe Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5 2eebb0b08803bb1d4227cea5e5b2c2cf Packers detected: PE_PATCH.UPX, UPX Scanner results Scan taken on 10 Feb 2007 02:02:01 (GMT) AntiVir Found HEUR/Malware ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found MemScan:Trojan.Downloader.Agent.AXX ClamAV Found nothing Dr.Web Found DLOADER.Trojan (probable variant) F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan-Clicker.Win32.Agent.is Fortinet Found W32/FAKEALERT.H!tr Kaspersky Anti-Virus Found Trojan-Clicker.Win32.Agent.is NOD32 Found probably unknown NewHeur_PE (probable variant) Norman Virus Control Found W32/Malware.JSJ VirusBuster Found nothing VBA32 Found nothing File: fpwsvgd.exe Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5 db7f05ad04f0b9c4a780d6e7460e5fec Packers detected: FSG Scanner results Scan taken on 10 Feb 2007 02:02:05 (GMT) AntiVir Found TR/Dldr.Small.agq.4 ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found DeepScan:Generic.Malware.dld!!.E4D80EF6 ClamAV Found Trojan.Downloader.Small-811 Dr.Web Found nothing F-Prot Antivirus Found Possibly a new variant of W32/new-malware!Maximus F-Secure Anti-Virus Found nothing Fortinet Found W32/Vixup.F!tr Kaspersky Anti-Virus Found nothing NOD32 Found Win32/TrojanDownloader.Small.AWA Norman Virus Control Found W32/DLoader.BZDL VirusBuster Found novirus:Packed/FSG VBA32 Found MalwareScope.Downloader.Small.1
Those files were bad. Let's get rid of them if you have not already.

Please set your system to show all files; please see here if you're unsure how to do this.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\btujat.exe
C:\fpwsvgd.exe

Exit Explorer, and reboot as normal afterwards.
I believe that we are almost done. But please post (reply) with a hijackthis log and run and post (reply) with another ComboFix log. I will review and then if everything looks fine, I will give you the final recommendations.
"Tim Morea" - 07-02-10 10:23:48 Service Pack 2
ComboFix 07-02-08.2 - Running from: "C:\Documents and Settings\Tim Morea\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2007-01-10 to 2007-02-10 ))))))))))))))))))))))))))))))))))


2007-02-09 18:00 524,288 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-02-09 17:56 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-09 17:56 d——– C:\Program Files\Grisoft
2007-02-09 17:18 d——– C:\!KillBox
2007-02-09 17:16 1,023,272 —hs—- C:\WINDOWS\system32\wyadd.bak2
2007-02-09 14:23 1,023,143 —hs—- C:\WINDOWS\system32\wyadd.ini2
2007-02-09 11:46 994 –a—— C:\DOCUME~1\TIMMOR~1\Purity.bat
2007-02-09 11:46 99,642 –a—— C:\DOCUME~1\TIMMOR~1\LIST-C.bat
2007-02-09 11:46 8,192 –a—— C:\DOCUME~1\TIMMOR~1\RestartIt.exe
2007-02-09 11:46 6,971 –a—— C:\DOCUME~1\TIMMOR~1\Qoo.bat
2007-02-09 11:46 42,891 –a—— C:\DOCUME~1\TIMMOR~1\ntp.exe
2007-02-09 11:46 39,184 –a—— C:\DOCUME~1\TIMMOR~1\Ntrights.exe
2007-02-09 11:46 38,400 –a—— C:\DOCUME~1\TIMMOR~1\moveex.exe
2007-02-09 11:46 28,160 –a—— C:\DOCUME~1\TIMMOR~1\catchme.exe
2007-02-09 11:46 26,112 –a—— C:\DOCUME~1\TIMMOR~1\nircmd.exe
2007-02-09 11:46 205,891 –a—— C:\DOCUME~1\TIMMOR~1\Creg.reg
2007-02-09 11:46 2,323 –a—— C:\DOCUME~1\TIMMOR~1\Look2Me.bat
2007-02-09 11:46 181,776 –a—— C:\DOCUME~1\TIMMOR~1\handle.exe
2007-02-09 11:46 140,800 –a—— C:\DOCUME~1\TIMMOR~1\swreg.exe
2007-02-09 11:23 d——– C:\VundoFix Backups
2007-02-08 23:01 d——– C:\DOCUME~1\TIMMOR~1\WINDOWS
2007-02-08 14:15 d——– C:\Program Files\Last.fm
2007-02-07 23:09 d——– C:\DOCUME~1\TIMMOR~1\Bluetooth Software
2007-02-07 22:59 d——– C:\Program Files\WIDCOMM
2007-02-07 22:49 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-02-07 22:44 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Creative
2007-02-07 20:59 d——– C:\DOCUME~1\TIMMOR~1\Application Data\AdobeUM
2007-02-07 20:35 24,576 –a—— C:\WINDOWS\system32\CTWEBFUN.DLL
2007-02-07 20:35 d——– C:\Program Files\Creative
2007-02-07 20:29 5,504 –a—— C:\WINDOWS\system32\drivers\MSTEE.sys
2007-02-07 20:29 19,328 –a—— C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-02-07 20:29 15,360 –a—— C:\WINDOWS\system32\drivers\StreamIP.sys
2007-02-07 20:29 11,136 –a—— C:\WINDOWS\system32\drivers\SLIP.sys
2007-02-07 20:29 10,880 –a—— C:\WINDOWS\system32\drivers\NdisIP.sys
2007-02-07 20:28 85,376 –a—— C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-02-07 20:28 17,024 –a—— C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-02-07 20:27 53,760 –a—— C:\WINDOWS\system32\vfwwdm32.dll
2007-02-07 20:26 91,830 –a—— C:\WINDOWS\system32\drivers\P0630Vid.sys
2007-02-07 20:26 81,920 –a—— C:\WINDOWS\CtDrvIns.exe
2007-02-07 20:26 69,632 –a—— C:\WINDOWS\system32\P0630Sti.dll
2007-02-07 20:26 49,152 –a—— C:\WINDOWS\system32\P0630Hwx.dll
2007-02-07 20:26 36,864 –a—— C:\WINDOWS\system32\CTCamMgr.dll
2007-02-07 20:26 32,768 –a—— C:\WINDOWS\system32\P0630Pin.dll
2007-02-07 20:26 20,480 –a—— C:\WINDOWS\system32\P0630Srv.exe
2007-02-07 20:26 20,480 –a—— C:\WINDOWS\P0630Cfg.exe
2007-02-07 20:26 126,976 –a—— C:\WINDOWS\system32\P0630Vfw.dll
2007-02-07 20:26 1,125,376 –a—— C:\WINDOWS\system32\drivers\P0630Evx.sys
2007-02-07 20:26 d——– C:\Webcam Live!
2007-02-07 20:24 d——– C:\DOCUME~1\LOCALS~1\Application Data\X10 Commander
2007-02-07 18:55 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-02-07 18:55 d——– C:\Program Files\CyberLink
2007-02-07 18:55 d——– C:\DOCUME~1\TIMMOR~1\Application Data\CyberLink
2007-02-07 18:55 d——– C:\DOCUME~1\ALLUSE~1\Application Data\CyberLink
2007-02-07 18:24 d——– C:\DOCUME~1\TIMMOR~1\Application Data\GlobalSCAPE
2007-02-07 18:23 d——– C:\Program Files\GlobalSCAPE
2007-02-07 18:21 d——– C:\Program Files\SpamBayes
2007-02-07 18:21 d——– C:\DOCUME~1\TIMMOR~1\Application Data\SpamBayes
2007-02-07 17:38 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-02-07 17:38 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Adobe
2007-02-07 17:38 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe Systems
2007-02-07 17:37 d——– C:\Program Files\Common Files\Adobe
2007-02-07 17:30 5,504 ——— C:\WINDOWS\system32\drivers\imagedrv.sys
2007-02-07 17:30 476,320 –a—— C:\WINDOWS\system32\ImagXpr7.dll
2007-02-07 17:30 471,040 –a—— C:\WINDOWS\system32\ImagXRA7.dll
2007-02-07 17:30 262,144 –a—— C:\WINDOWS\system32\ImagXR7.dll
2007-02-07 17:30 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-02-07 17:30 125,184 ——— C:\WINDOWS\system32\drivers\imagesrv.sys
2007-02-07 17:30 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll
2007-02-07 17:30 1,568,768 –a—— C:\WINDOWS\system32\ImagX7.dll
2007-02-07 17:30 d——– C:\Program Files\Common Files\Ahead
2007-02-07 17:30 d——– C:\Program Files\Ahead
2007-02-07 17:29 6,016 –a—— C:\WINDOWS\system32\drivers\vnccom.SYS
2007-02-07 17:29 5,760 –a—— C:\WINDOWS\system32\vnchelp.dll
2007-02-07 17:29 4,736 –a—— C:\WINDOWS\system32\drivers\vncdrv.sys
2007-02-07 17:29 12,800 –a—— C:\WINDOWS\system32\vncdrv.dll
2007-02-07 17:29 d——– C:\Program Files\UltraVNC
2007-02-07 17:25 10,761 –a—— C:\WINDOWS\system32\drivers\x10uif.sys
2007-02-07 17:25 d——– C:\Program Files\Common Files\Snapstream
2007-02-07 17:25 d——– C:\DOCUME~1\ALLUSE~1\Application Data\SnapStream
2007-02-07 17:22 d——– C:\Program Files\SnapStream Media
2007-02-07 17:20 127,208 –a—— C:\WINDOWS\system32\mucltui.dll
2007-02-07 17:19 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2007-02-06 12:51 12,928 –a—— C:\WINDOWS\system32\drivers\Dot4Prt.sys
2007-02-06 12:50 23,808 –a—— C:\WINDOWS\system32\drivers\Dot4usb.sys
2007-02-06 12:50 207,360 –a—— C:\WINDOWS\system32\drivers\Dot4.sys
2007-02-06 12:34 208,896 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-02-06 12:34 208,896 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-02-06 12:34 d——– C:\WINDOWS\nview
2007-02-06 12:33 d——– C:\NVIDIA
2007-02-06 12:16 10,624 –a—— C:\WINDOWS\system32\drivers\gameenum.sys
2007-02-06 12:05 585,728 –a—— C:\WINDOWS\system32\AReadyLB.dll
2007-02-06 12:05 38 –a—— C:\WINDOWS\system32\dtirc.dll
2007-02-06 12:05 229,376 –a—— C:\WINDOWS\system32\AudDevicePlugin.dll
2007-02-06 12:05 d——– C:\Program Files\MSBuild
2007-02-06 12:05 d——– C:\Program Files\J River
2007-02-06 12:00 d——– C:\WINDOWS\system32\XPSViewer
2007-02-06 12:00 d——– C:\Program Files\Reference Assemblies
2007-02-06 11:59 14,048 –a—— C:\WINDOWS\system32\spmsg2.dll
2007-02-06 11:58 d——– C:\Program Files\GSpot
2007-02-06 11:57 d——– C:\WINDOWS\WBEM
2007-02-06 11:57 d——– C:\DOCUME~1\TIMMOR~1\Application Data\DivX
2007-02-06 11:54 121,856 –a—— C:\WINDOWS\system32\xmllite.dll
2007-02-06 11:54 d——– C:\WINDOWS\network diagnostic
2007-02-06 11:54 d——– C:\Program Files\InterVocative Software
2007-02-06 11:51 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Hamachi
2007-02-06 11:50 17,480 –a—— C:\WINDOWS\system32\drivers\hamachi.sys
2007-02-06 11:50 d——– C:\Program Files\Hamachi
2007-02-06 11:49 d——– C:\Program Files\Windows Media Connect 2
2007-02-06 11:49 d——– C:\Program Files\TaskSwitchXP
2007-02-06 11:49 d——– C:\Program Files\FLVPlayer
2007-02-06 11:48 d——– C:\Program Files\eMule
2007-02-06 11:47 36,624 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-02-06 11:47 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-02-06 11:47 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-02-06 11:47 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2007-02-06 11:47 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2007-02-06 11:47 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2007-02-06 11:47 d——– C:\WINDOWS\system32\LogFiles
2007-02-06 11:47 d——– C:\WINDOWS\system32\en-us
2007-02-06 11:47 d——– C:\WINDOWS\system32\drivers\UMDF
2007-02-06 11:47 d——– C:\Program Files\Google
2007-02-06 11:47 d——– C:\Program Files\DivX
2007-02-06 11:46 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Lavasoft
2007-02-06 11:45 d——– C:\Program Files\Lavasoft
2007-02-06 11:38 dr–s—- C:\WINDOWS\assembly
2007-02-06 11:38 d——– C:\WINDOWS\system32\URTTemp
2007-02-06 11:38 d——– C:\WINDOWS\Microsoft.NET
2007-02-06 11:34 36,352 –a—— C:\WINDOWS\system32\tsgqec.dll
2007-02-06 11:34 288,768 –a—— C:\WINDOWS\system32\rhttpaa.dll
2007-02-06 11:34 116,736 –a—— C:\WINDOWS\system32\aaclient.dll
2007-02-06 11:01 1,836 –a—— C:\WINDOWS\mozver.dat
2007-02-06 09:08 262,144 –a—— C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-02-06 03:58 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Windows Genuine Advantage
2007-02-06 03:33 d——– C:\Jenny
2007-02-06 03:30 d–h—– C:\WINDOWS\system32\GroupPolicy
2007-02-06 03:25 d——– C:\DOCUME~1\TIMMOR~1\Application Data\uTorrent
2007-02-06 03:24 d——– C:\Program Files\uTorrent
2007-02-06 03:04 d——– C:\Program Files\FeedReader30
2007-02-06 03:04 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Feedreader
2007-02-06 02:48 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-02-06 02:46 d——– C:\Program Files\Microsoft.NET
2007-02-06 02:46 d——– C:\Program Files\Microsoft Works
2007-02-06 02:46 d——– C:\Program Files\Microsoft ActiveSync
2007-02-06 02:46 d——– C:\Program Files\Common Files\L&H
2007-02-06 02:45 d——– C:\WINDOWS\SHELLNEW
2007-02-06 02:36 d——– C:\Program Files\Common Files\Voyetra
2007-02-06 02:23 82,944 –a—— C:\WINDOWS\system32\drivers\wdmaud.sys
2007-02-06 02:23 6,400 –a—— C:\WINDOWS\system32\drivers\splitter.sys
2007-02-06 02:23 52,864 –a—— C:\WINDOWS\system32\drivers\DMusic.sys
2007-02-06 02:22 917,504 –a—— C:\WINDOWS\system\cmids3d3.dll
2007-02-06 02:22 712,704 –a—— C:\WINDOWS\system32\Audio3D3.dll
2007-02-06 02:22 712,704 –a—— C:\WINDOWS\system32\a3d.dll
2007-02-06 02:22 7,552 –a—— C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-02-06 02:22 60,800 –a—— C:\WINDOWS\system32\drivers\sysaudio.sys
2007-02-06 02:22 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-02-06 02:22 54,272 –a—— C:\WINDOWS\system32\drivers\swmidi.sys
2007-02-06 02:22 5,376 –a—— C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-02-06 02:22 4,992 –a—— C:\WINDOWS\system32\drivers\MSPQM.sys
2007-02-06 02:22 4,096 –a—— C:\WINDOWS\system32\ksuser.dll
2007-02-06 02:22 32,768 –a—— C:\WINDOWS\system32\udaprop3.dll
2007-02-06 02:22 28,672 –a—— C:\WINDOWS\system32\cmrmdrv3.dll
2007-02-06 02:22 28,672 –a—— C:\WINDOWS\CmiPCIUninstall.exe
2007-02-06 02:22 241,664 –a—— C:\WINDOWS\system32\cmrmdrv3.exe
2007-02-06 02:22 2,944 –a—— C:\WINDOWS\system32\drivers\drmkaud.sys
2007-02-06 02:22 172,416 –a—— C:\WINDOWS\system32\drivers\kmixer.sys
2007-02-06 02:22 145,792 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-02-06 02:22 142,464 –a—— C:\WINDOWS\system32\drivers\aec.sys
2007-02-06 02:22 102,400 –a—— C:\WINDOWS\system32\cmudax3.DLL
2007-02-06 02:22 1,616,640 –a—— C:\WINDOWS\system32\drivers\cmudax3.sys
2007-02-06 02:22 d——– C:\Program Files\Turtle Beach
2007-02-06 02:22 d——– C:\DOCUME~1\ALLUSE~1\Application Data\InstallShield
2007-02-06 02:19 d——– C:\Program Files\Process Explorer
2007-02-06 02:18 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Apple Computer
2007-02-06 02:18 d——– C:\DOCUME~1\ALLUSE~1\Application Data\WinZip
2007-02-06 02:17 d——– C:\Program Files\Winamp
2007-02-06 02:17 d——– C:\Program Files\iTunes
2007-02-06 02:17 d——– C:\Program Files\iPod
2007-02-06 02:16 d——– C:\Program Files\Taskbar Shuffle
2007-02-06 02:16 d——– C:\Program Files\QuickTime
2007-02-06 02:16 d——– C:\Program Files\Apple Software Update
2007-02-06 02:15 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Apple Computer
2007-02-06 02:01 d——– C:\Program Files\MessengerMate
2007-02-06 01:58 d——– C:\Program Files\Viewpoint
2007-02-06 01:58 d——– C:\Program Files\AOD
2007-02-06 01:58 d——– C:\Program Files\AIM
2007-02-06 01:58 d——– C:\DOCUME~1\TIMMOR~1\Application Data\Aim
2007-02-06 01:58 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Viewpoint
2007-02-06 01:57 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-02-06 01:57 0 –a—— C:\WINDOWS\nsreg.dat
2007-02-06 01:57 d–h—– C:\WINDOWS\$hf_mig$
2007-02-06 01:57 d——– C:\WINDOWS\system32\PreInstall
2007-02-06 01:56 d——– C:\Program Files\Mozilla Firefox
2007-02-06 01:55 d——– C:\Program Files\Intel
2007-02-06 01:53 d——– C:\WINDOWS\system32\ReinstallBackups
2007-02-06 01:52 d—s—- C:\DOCUME~1\TIMMOR~1\UserData
2007-02-06 01:50 24,064 –a—— C:\WINDOWS\system32\IntelNic.dll
2007-02-06 01:50 163,840 –a—— C:\WINDOWS\system32\e1000msg.dll
2007-02-06 01:50 163,840 –a—— C:\WINDOWS\system32\drivers\e1000325.sys
2007-02-06 01:50 126,976 –a—— C:\WINDOWS\system32\Prounstl.exe
2007-02-06 01:50 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-02-06 01:48 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2007-02-06 01:48 446,464 -ra—— C:\WINDOWS\system32\hhactivex.dll
2007-02-06 01:48 176,128 –a—— C:\WINDOWS\system32\RcdScan.dll
2007-02-06 01:48 d–h—– C:\Program Files\InstallShield Installation Information
2007-02-06 01:48 d——– C:\Dell
2007-02-06 01:47 13,632 ——— C:\WINDOWS\system32\drivers\omci.sys
2007-02-06 01:47 d——– C:\Program Files\Common Files\InstallShield
2007-02-06 01:36 87,808 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-02-06 01:36 107,696 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-02-06 01:35 d——– C:\WINDOWS\RegisteredPackages
2007-02-06 01:35 d——– C:\Program Files\Symantec AntiVirus
2007-02-06 01:35 d——– C:\Program Files\Symantec
2007-02-06 01:35 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Symantec
2007-02-06 01:34 d——– C:\Program Files\Common Files\Symantec Shared
2007-02-06 01:26 2,097,152 –ah—– C:\DOCUME~1\TIMMOR~1\NTUSER.DAT
2007-02-06 01:25 262,144 –ah—– C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-02-06 01:25 225,280 –ah—– C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-02-06 01:25 d——– C:\WINDOWS\SoftwareDistribution
2007-02-06 01:25 d——– C:\WINDOWS\Prefetch
2007-02-06 01:21 225,280 —h—– C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-02-06 01:21 112,128 –a—— C:\WINDOWS\system32\mapi32.dll
2007-02-06 01:21 0 -rahs—- C:\MSDOS.SYS
2007-02-06 01:21 0 -rahs—- C:\IO.SYS
2007-02-06 01:21 0 –a—— C:\CONFIG.SYS
2007-02-06 01:21 0 –a—— C:\AUTOEXEC.BAT
2007-02-06 01:21 d——– C:\WINDOWS\system32\xircom
2007-02-06 01:21 d——– C:\Program Files\microsoft frontpage
2007-02-06 01:20 dr——- C:\WINDOWS\Offline Web Pages
2007-02-06 01:20 d–hs—- C:\DOCUME~1\ALLUSE~1\DRM
2007-02-06 01:20 d–h—– C:\Program Files\WindowsUpdate
2007-02-06 01:20 d—s—- C:\WINDOWS\Downloaded Program Files
2007-02-06 01:19 81,920 –a—— C:\WINDOWS\system32\ils.dll
2007-02-06 01:19 8,192 –a—— C:\WINDOWS\system32\bitsprx2.dll
2007-02-06 01:19 73,472 –a—— C:\WINDOWS\system32\drivers\sr.sys
2007-02-06 01:19 7,168 –a—— C:\WINDOWS\system32\bitsprx3.dll
2007-02-06 01:19 69,632 –a—— C:\WINDOWS\system32\msconf.dll
2007-02-06 01:19 679,424 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-02-06 01:19 67,584 –a—— C:\WINDOWS\system32\srclient.dll
2007-02-06 01:19 64,512 –a—— C:\WINDOWS\system32\acctres.dll
2007-02-06 01:19 6,656 –a—— C:\WINDOWS\system32\wuauserv.dll
2007-02-06 01:19 48,128 –a—— C:\WINDOWS\system32\inetres.dll
2007-02-06 01:19 465,176 –a—— C:\WINDOWS\system32\wuapi.dll
2007-02-06 01:19 45,568 –a—— C:\WINDOWS\system32\safrslv.dll
2007-02-06 01:19 43,520 –a—— C:\WINDOWS\system32\safrcdlg.dll
2007-02-06 01:19 43,520 –a—— C:\WINDOWS\system32\racpldlg.dll
2007-02-06 01:19 41,240 –a—— C:\WINDOWS\system32\wups.dll
2007-02-06 01:19 382,464 –a—— C:\WINDOWS\system32\qmgr.dll
2007-02-06 01:19 34,560 –a—— C:\WINDOWS\system32\mnmdd.dll
2007-02-06 01:19 32,768 –a—— C:\WINDOWS\system32\mnmsrvc.exe
2007-02-06 01:19 32,768 –a—— C:\WINDOWS\system32\isrdbg32.dll
2007-02-06 01:19 29,696 –a—— C:\WINDOWS\system32\safrdm.dll
2007-02-06 01:19 28,672 –a—— C:\WINDOWS\system32\nmmkcert.dll
2007-02-06 01:19 252,928 –a—— C:\WINDOWS\system32\msoeacct.dll
2007-02-06 01:19 239,104 –a—— C:\WINDOWS\system32\srrstr.dll
2007-02-06 01:19 23,040 –a—— C:\WINDOWS\system32\fltmc.exe
2007-02-06 01:19 194,328 –a—— C:\WINDOWS\system32\wuaueng1.dll
2007-02-06 01:19 18,944 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-02-06 01:19 173,536 –a—— C:\WINDOWS\system32\wuweb.dll
2007-02-06 01:19 172,312 –a—— C:\WINDOWS\system32\wuauclt1.exe
2007-02-06 01:19 170,496 –a—— C:\WINDOWS\system32\srsvc.dll
2007-02-06 01:19 16,896 –a—— C:\WINDOWS\system32\fltlib.dll
2007-02-06 01:19 16,384 –a—— C:\WINDOWS\system32\icfgnt5.dll
2007-02-06 01:19 128,896 –a—— C:\WINDOWS\system32\drivers\fltmgr.sys
2007-02-06 01:19 127,256 –a—— C:\WINDOWS\system32\wucltui.dll
2007-02-06 01:19 124,184 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-02-06 01:19 12,288 –a—— C:\WINDOWS\system32\nmevtmsg.dll
2007-02-06 01:19 11,264 –a—— C:\WINDOWS\system32\atrace.dll
2007-02-06 01:19 105,984 –a—— C:\WINDOWS\system32\msoert2.dll
2007-02-06 01:19 1,343,768 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-02-06 01:19 d—s—- C:\WINDOWS\Tasks
2007-02-06 01:19 d——– C:\WINDOWS\system32\Restore
2007-02-06 01:19 d——– C:\WINDOWS\system32\Macromed
2007-02-06 01:19 d——– C:\WINDOWS\system32\DirectX
2007-02-06 01:19 d——– C:\WINDOWS\srchasst
2007-02-06 01:19 d——– C:\Program Files\Movie Maker
2007-02-06 01:19 d——– C:\Program Files\Common Files\MSSoap
2007-02-06 01:18 81,920 –a—— C:\WINDOWS\system32\isign32.dll
2007-02-06 01:18 73,728 –a—— C:\WINDOWS\system32\icwdial.dll
2007-02-06 01:18 65,536 –a—— C:\WINDOWS\system32\icwphbk.dll
2007-02-06 01:18 274,944 –a—— C:\WINDOWS\system32\mstask.dll
2007-02-06 01:18 274,432 –a—— C:\WINDOWS\system32\inetcfg.dll
2007-02-06 01:18 21,640 –a—— C:\WINDOWS\system32\emptyregdb.dat
2007-02-06 01:18 190,976 –a—— C:\WINDOWS\system32\schedsvc.dll
2007-02-06 01:18 12,288 –a—— C:\WINDOWS\system32\mstinit.exe
2007-02-06 01:17 97,792 –a—— C:\WINDOWS\system32\comrepl.dll
2007-02-06 01:17 956,416 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-02-06 01:17 93,696 –a—— C:\WINDOWS\system32\tscfgwmi.dll
2007-02-06 01:17 91,136 –a—— C:\WINDOWS\system32\mtxoci.dll
2007-02-06 01:17 9,728 –a—— C:\WINDOWS\system32\reset.exe
2007-02-06 01:17 87,176 –a—— C:\WINDOWS\system32\rdpwsx.dll
2007-02-06 01:17 85,504 –a—— C:\WINDOWS\system32\catsrvps.dll
2007-02-06 01:17 80,384 –a—— C:\WINDOWS\system32\charmap.exe
2007-02-06 01:17 73,216 –a—— C:\WINDOWS\system32\avwav.dll
2007-02-06 01:17 67,072 –a—— C:\WINDOWS\system32\rdshost.exe
2007-02-06 01:17 625,152 –a—— C:\WINDOWS\system32\catsrvut.dll
2007-02-06 01:17 62,464 –a—— C:\WINDOWS\system32\rdpclip.exe
2007-02-06 01:17 605,696 –a—— C:\WINDOWS\system32\getuname.dll
2007-02-06 01:17 600,576 –a—— C:\WINDOWS\system32\mstsc.exe
2007-02-06 01:17 60,416 –a—— C:\WINDOWS\system32\remotepg.dll
2007-02-06 01:17 60,416 –a—— C:\WINDOWS\system32\colbact.dll
2007-02-06 01:17 6,144 –a—— C:\WINDOWS\system32\msdtc.exe
2007-02-06 01:17 58,880 –a—— C:\WINDOWS\system32\msdtclog.dll
2007-02-06 01:17 58,880 –a—— C:\WINDOWS\system32\licwmi.dll
2007-02-06 01:17 56,832 –a—— C:\WINDOWS\system32\sol.exe
2007-02-06 01:17 56,320 –a—— C:\WINDOWS\system32\servdeps.dll
2007-02-06 01:17 55,296 –a—— C:\WINDOWS\system32\freecell.exe
2007-02-06 01:17 540,160 –a—— C:\WINDOWS\system32\comuid.dll
2007-02-06 01:17 54,272 –a—— C:\WINDOWS\system32\stclient.dll
2007-02-06 01:17 538,624 –a—— C:\WINDOWS\system32\spider.exe
2007-02-06 01:17 5,632 –a—— C:\WINDOWS\system32\write.exe
2007-02-06 01:17 5,120 –a—— C:\WINDOWS\system32\dcomcnfg.exe
2007-02-06 01:17 498,688 –a—— C:\WINDOWS\system32\clbcatq.dll
2007-02-06 01:17 44,544 –a—— C:\WINDOWS\system32\tscupgrd.exe
2007-02-06 01:17 44,544 –a—— C:\WINDOWS\system32\hticons.dll
2007-02-06 01:17 426,496 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-02-06 01:17 4,096 –a—— C:\WINDOWS\system32\rdpcfgex.dll
2007-02-06 01:17 4,096 –a—— C:\WINDOWS\system32\mtxex.dll
2007-02-06 01:17 38,912 –a—— C:\WINDOWS\system32\cfgbkend.dll
2007-02-06 01:17 35,328 –a—— C:\WINDOWS\system32\winchat.exe
2007-02-06 01:17 347,136 –a—— C:\WINDOWS\system32\hypertrm.dll
2007-02-06 01:17 343,040 –a—— C:\WINDOWS\system32\mspaint.exe
2007-02-06 01:17 33,792 –a—— C:\WINDOWS\system32\regini.exe
2007-02-06 01:17 295,424 –a—— C:\WINDOWS\system32\termsrv.dll
2007-02-06 01:17 25,600 –a—— C:\WINDOWS\system32\comaddin.dll
2007-02-06 01:17 25,088 –a—— C:\WINDOWS\system32\mtxlegih.dll
2007-02-06 01:17 227,840 –a—— C:\WINDOWS\system32\avtapi.dll
2007-02-06 01:17 225,792 –a—— C:\WINDOWS\system32\catsrv.dll
2007-02-06 01:17 22,016 –a—— C:\WINDOWS\system32\qwinsta.exe
2007-02-06 01:17 21,896 –a—— C:\WINDOWS\system32\drivers\tdtcp.sys
2007-02-06 01:17 20,992 –a—— C:\WINDOWS\system32\msg.exe
2007-02-06 01:17 20,480 –a—— C:\WINDOWS\system32\qprocess.exe
2007-02-06 01:17 20,480 –a—— C:\WINDOWS\system32\mtxdm.dll
2007-02-06 01:17 19,968 –a—— C:\WINDOWS\system32\rdpsnd.dll
2007-02-06 01:17 185,344 –a—— C:\WINDOWS\system32\cmprops.dll
2007-02-06 01:17 183,808 –a—— C:\WINDOWS\system32\accwiz.exe
2007-02-06 01:17 17,408 –a—— C:\WINDOWS\system32\mmfutil.dll
2007-02-06 01:17 161,280 –a—— C:\WINDOWS\system32\msdtcuiu.dll
2007-02-06 01:17 16,896 –a—— C:\WINDOWS\system32\tsshutdn.exe
2007-02-06 01:17 16,896 –a—— C:\WINDOWS\system32\qappsrv.exe
2007-02-06 01:17 16,384 –a—— C:\WINDOWS\system32\tskill.exe
2007-02-06 01:17 16,384 –a—— C:\WINDOWS\system32\avmeter.dll
2007-02-06 01:17 15,872 –a—— C:\WINDOWS\system32\rwinsta.exe
2007-02-06 01:17 15,872 –a—— C:\WINDOWS\system32\cdmodem.dll
2007-02-06 01:17 15,360 –a—— C:\WINDOWS\system32\logoff.exe
2007-02-06 01:17 147,968 –a—— C:\WINDOWS\system32\rdchost.dll
2007-02-06 01:17 147,456 –a—— C:\WINDOWS\system32\comsnap.dll
2007-02-06 01:17 140,800 –a—— C:\WINDOWS\system32\sessmgr.exe
2007-02-06 01:17 14,848 –a—— C:\WINDOWS\system32\tsdiscon.exe
2007-02-06 01:17 14,848 –a—— C:\WINDOWS\system32\tscon.exe
2007-02-06 01:17 14,848 –a—— C:\WINDOWS\system32\shadow.exe
2007-02-06 01:17 139,528 –a—— C:\WINDOWS\system32\drivers\rdpwd.sys
2007-02-06 01:17 138,752 –a—— C:\WINDOWS\system32\sndvol32.exe
2007-02-06 01:17 131,584 –a—— C:\WINDOWS\system32\sndrec32.exe
2007-02-06 01:17 13,824 –a—— C:\WINDOWS\system32\rdsaddin.exe
2007-02-06 01:17 126,976 –a—— C:\WINDOWS\system32\mshearts.exe
2007-02-06 01:17 123,392 –a—— C:\WINDOWS\system32\mplay32.exe
2007-02-06 01:17 12,040 –a—— C:\WINDOWS\system32\drivers\tdpipe.sys
2007-02-06 01:17 119,808 –a—— C:\WINDOWS\system32\winmine.exe
2007-02-06 01:17 114,688 –a—— C:\WINDOWS\system32\calc.exe
2007-02-06 01:17 110,080 –a—— C:\WINDOWS\system32\clbcatex.dll
2007-02-06 01:17 11,776 –a—— C:\WINDOWS\system32\xolehlp.dll
2007-02-06 01:17 11,264 –a—— C:\WINDOWS\system32\icaapi.dll
2007-02-06 01:17 102,912 –a—— C:\WINDOWS\system32\clipbrd.exe
2007-02-06 01:17 1,866,240 –a—— C:\WINDOWS\system32\mstscax.dll
2007-02-06 01:17 1,267,200 –a—— C:\WINDOWS\system32\comsvcs.dll
2007-02-06 01:17 1,161 –a—— C:\WINDOWS\system32\usrlogon.cmd
2007-02-06 01:17 d——– C:\WINDOWS\system32\MsDtc
2007-02-06 01:17 d——– C:\WINDOWS\system32\Com
2007-02-06 01:17 d——– C:\WINDOWS\Registration
2007-02-06 01:17 d——– C:\Program Files\Windows NT
2007-02-06 01:17 d——– C:\Program Files\Online Services
2007-02-06 01:17 d——– C:\Program Files\MSN Gaming Zone
2007-02-06 01:17 d——– C:\Program Files\Messenger
2007-02-06 01:16 40,840 –a—— C:\WINDOWS\system32\drivers\termdd.sys
2007-02-06 01:16 196,864 –a—— C:\WINDOWS\system32\drivers\rdpdr.sys
2007-02-05 20:12 57,472 –a—— C:\WINDOWS\system32\drivers\redbook.sys
2007-02-05 20:12 3,072 –a—— C:\WINDOWS\system32\drivers\audstub.sys
2007-02-05 20:11 6,400 –a—— C:\WINDOWS\system32\drivers\enum1394.sys
2007-02-05 20:11 4,527,488 –a—— C:\WINDOWS\system32\nv4_disp.dll
2007-02-05 20:11 3,994,624 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-02-05 20:10 74,240 –a—— C:\WINDOWS\system32\usbui.dll
2007-02-05 20:10 5,504 –a—— C:\WINDOWS\system32\drivers\intelide.sys
2007-02-05 20:10 42,368 –a—— C:\WINDOWS\system32\drivers\AGP440.SYS
2007-02-05 20:09 9,936 –a—— C:\WINDOWS\system\LZEXPAND.DLL
2007-02-05 20:09 9,008 –a—— C:\WINDOWS\system\VER.DLL
2007-02-05 20:09 85,020 –a—— C:\WINDOWS\system32\dgsetup.dll
2007-02-05 20:09 82,944 –a—— C:\WINDOWS\system\OLECLI.DLL
2007-02-05 20:09 8,704 –a—— C:\WINDOWS\system32\batt.dll
2007-02-05 20:09 8,192 -ra—— C:\WINDOWS\system32\kbdhept.dll
2007-02-05 20:09 74,752 –a—— C:\WINDOWS\system32\storprop.dll
2007-02-05 20:09 7,168 -ra—— C:\WINDOWS\system32\kbdcz.dll
2007-02-05 20:09 69,584 –a—— C:\WINDOWS\system\AVICAP.DLL
2007-02-05 20:09 69,120 –a—— C:\WINDOWS\NOTEPAD.EXE
2007-02-05 20:09 68,768 –a—— C:\WINDOWS\system\MMSYSTEM.DLL
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdycl.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdsl1.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdsl.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdpl.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdhu.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdhela3.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdcz2.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdcz1.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\kbdcr.dll
2007-02-05 20:09 6,656 -ra—— C:\WINDOWS\system32\KBDAL.DLL
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdtuq.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdtuf.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdlv1.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdlv.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdhela2.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdgkl.dll
2007-02-05 20:09 6,144 -ra—— C:\WINDOWS\system32\kbdest.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdro.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdpl1.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdmon.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdlt1.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdlt.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdkyr.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdhu1.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdhe319.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdhe220.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdhe.dll
2007-02-05 20:09 5,632 -ra—— C:\WINDOWS\system32\kbdazel.dll
2007-02-05 20:09 5,120 –a—— C:\WINDOWS\system\SHELL.DLL
2007-02-05 20:09 32,816 –a—— C:\WINDOWS\system\COMMDLG.DLL
2007-02-05 20:09 24,661 –a—— C:\WINDOWS\system32\spxcoins.dll
2007-02-05 20:09 24,064 –a—— C:\WINDOWS\system\OLESVR.DLL
2007-02-05 20:09 19,200 –a—— C:\WINDOWS\system\TAPI.DLL
2007-02-05 20:09 176,157 –a—— C:\WINDOWS\system32\dgrpsetu.dll
2007-02-05 20:09 15,360 –a—— C:\WINDOWS\TASKMAN.EXE
2007-02-05 20:09 13,312 –a—— C:\WINDOWS\system32\irclass.dll
2007-02-05 20:09 126,912 –a—— C:\WINDOWS\system\MSVIDEO.DLL
2007-02-05 20:09 11,264 –a—— C:\WINDOWS\system32\drivers\irenum.sys
2007-02-05 20:09 109,456 –a—— C:\WINDOWS\system\AVIFILE.DLL
2007-02-05 20:09 103,424 –a—— C:\WINDOWS\system32\EqnClass.Dll
2007-02-05 20:09 dr——- C:\Program Files
2007-02-05 20:09 d–hs—- C:\WINDOWS\Installer
2007-02-05 20:09 d——– C:\Program Files\Common Files\SpeechEngines
2007-02-05 20:09 d——– C:\Program Files\Common Files\ODBC
2007-02-05 20:08 dr——- C:\DOCUME~1\ALLUSE~1\Documents
2007-02-05 20:08 d——– C:\WINDOWS\system32\CatRoot2
2007-02-05 20:08 d——– C:\WINDOWS\system32\CatRoot
2007-02-05 20:07 d——– C:\Documents and Settings
2007-02-05 20:02 dr-hsc— C:\WINDOWS\system32\dllcache
2007-02-05 20:02 dr–s—- C:\WINDOWS\Fonts
2007-02-05 20:02 dr——- C:\WINDOWS\Web
2007-02-05 20:02 d–h—– C:\WINDOWS\inf
2007-02-05 20:02 d——– C:\WINDOWS\WinSxS
2007-02-05 20:02 d——– C:\WINDOWS\twain_32
2007-02-05 20:02 d——– C:\WINDOWS\system32\wins
2007-02-05 20:02 d——– C:\WINDOWS\system32\wbem
2007-02-05 20:02 d——– C:\WINDOWS\system32\usmt
2007-02-05 20:02 d——– C:\WINDOWS\system32\spool
2007-02-05 20:02 d——– C:\WINDOWS\system32\ShellExt
2007-02-05 20:02 d——– C:\WINDOWS\system32\Setup
2007-02-05 20:02 d——– C:\WINDOWS\system32\ras
2007-02-05 20:02 d——– C:\WINDOWS\system32\oobe
2007-02-05 20:02 d——– C:\WINDOWS\system32\npp
2007-02-05 20:02 d——– C:\WINDOWS\system32\mui
2007-02-05 20:02 d——– C:\WINDOWS\system32\inetsrv
2007-02-05 20:02 d——– C:\WINDOWS\system32\IME
2007-02-05 20:02 d——– C:\WINDOWS\system32\icsxml
2007-02-05 20:02 d——– C:\WINDOWS\system32\ias
2007-02-05 20:02 d——– C:\WINDOWS\system32\export
2007-02-05 20:02 d——– C:\WINDOWS\system32\drivers\etc
2007-02-05 20:02 d——– C:\WINDOWS\system32\drivers\disdn
2007-02-05 20:02 d——– C:\WINDOWS\system32\drivers
2007-02-05 20:02 d——– C:\WINDOWS\system32\dhcp
2007-02-05 20:02 d——– C:\WINDOWS\system32\config
2007-02-05 20:02 d——– C:\WINDOWS\system32\3com_dmi
2007-02-05 20:02 d——– C:\WINDOWS\system32\3076
2007-02-05 20:02 d——– C:\WINDOWS\system32\2052
2007-02-05 20:02 d——– C:\WINDOWS\system32\1054
2007-02-05 20:02 d——– C:\WINDOWS\system32\1042
2007-02-05 20:02 d——– C:\WINDOWS\system32\1041
2007-02-05 20:02 d——– C:\WINDOWS\system32\1037
2007-02-05 20:02 d——– C:\WINDOWS\system32\1033
2007-02-05 20:02 d——– C:\WINDOWS\system32\1031
2007-02-05 20:02 d——– C:\WINDOWS\system32\1028
2007-02-05 20:02 d——– C:\WINDOWS\system32\1025
2007-02-05 20:02 d——– C:\WINDOWS\system32
2007-02-05 20:02 d——– C:\WINDOWS\system
2007-02-05 20:02 d——– C:\WINDOWS\security
2007-02-05 20:02 d——– C:\WINDOWS\Resources
2007-02-05 20:02 d——– C:\WINDOWS\repair
2007-02-05 20:02 d——– C:\WINDOWS\Provisioning
2007-02-05 20:02 d——– C:\WINDOWS\PeerNet
2007-02-05 20:02 d——– C:\WINDOWS\pchealth
2007-02-05 20:02 d——– C:\WINDOWS\mui
2007-02-05 20:02 d——– C:\WINDOWS\msapps
2007-02-05 20:02 d——– C:\WINDOWS\msagent
2007-02-05 20:02 d——– C:\WINDOWS\Media
2007-02-05 20:02 d——– C:\WINDOWS\java
2007-02-05 20:02 d——– C:\WINDOWS\ime
2007-02-05 20:02 d——– C:\WINDOWS\Help
2007-02-05 20:02 d——– C:\WINDOWS\ehome
2007-02-05 20:02 d——– C:\WINDOWS\Driver Cache
2007-02-05 20:02 d——– C:\WINDOWS\Debug
2007-02-05 20:02 d——– C:\WINDOWS\Cursors
2007-02-05 20:02 d——– C:\WINDOWS\Connection Wizard
2007-02-05 20:02 d——– C:\WINDOWS\Config
2007-02-05 20:02 d——– C:\WINDOWS\AppPatch
2007-02-05 20:02 d——– C:\WINDOWS\addins
2007-02-05 20:02 d——– C:\WINDOWS
2007-01-31 23:56 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-01-31 23:56 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-01-31 23:56 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-01-31 23:56 639,066 –a—— C:\WINDOWS\system32\DivX.dll
2007-01-31 16:27 524,288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-01-30 18:15 118,784 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-01-30 00:03 3,596,288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-01-30 00:03 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-01-30 00:03 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-01-29 23:56 73,728 –a—— C:\WINDOWS\system32\dpl100.dll
2007-01-29 23:56 593,920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2007-01-29 23:56 57,344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-01-29 23:56 53,248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-01-29 23:56 344,064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-01-29 23:56 294,912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-01-29 23:56 294,912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-01-29 23:56 196,608 –a—— C:\WINDOWS\system32\dtu100.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-08 14:16 127 –a—— C:\DOCUME~1\TIMMOR~1\Application Data\iscrobbler.ini
2007-02-07 18:16 ——– d—s—- C:\DOCUME~1\TIMMOR~1\Application Data\microsoft
2007-02-06 11:01 ——– d——– C:\DOCUME~1\TIMMOR~1\Application Data\macromedia
2007-02-06 01:56 ——– d——– C:\DOCUME~1\TIMMOR~1\Application Data\mozilla
2007-02-06 01:26 ——– d——– C:\DOCUME~1\TIMMOR~1\Application Data\identities
2007-02-05 20:08 62 –ahs—- C:\DOCUME~1\TIMMOR~1\Application Data\desktop.ini
2006-12-12 11:24 12288 –a—— C:\WINDOWS\system32\divxwmpexttype.dll
2006-11-27 03:45 60416 –a—— C:\WINDOWS\system32\tzchange.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Taskbar Shuffle"="C:\\Program Files\\Taskbar Shuffle\\taskbarshuffle.exe"
"feedreader.exe"="\"C:\\Program Files\\FeedReader30\\feedreader.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"TaskSwitchXP"="C:\\Program Files\\TaskSwitchXP\\TaskSwitchXP.exe"
"Creative WebCam Tray"="\"C:\\Program Files\\Creative\\Shared Files\\CamTray.exe\""
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Acrobat\\AdobeUpdateManager.exe AcPro7_0_7"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Turtle Beach Montego DDL"="\"C:\\Program Files\\Turtle Beach\\MontegoDDL\\TBMontegoTray.exe\""
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\isuspm.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"C-Media Mixer"="Mixer.exe /startup"
"UnlockerAssistant"="\"C:\\Program Files\\Unlocker\\UnlockerAssistant.exe\" -H"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"Firefly"="C:\\Program Files\\SnapStream Media\\Firefly\\Firefly.exe"
"WinVNC"="\"C:\\Program Files\\UltraVNC\\WinVNC.exe\" -servicehelper"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
@=""
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"LanguageShortcut"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"svchost.exe"="C:\\WINDOWS\\svchost.exe"

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
"Debugger"="\"C:\\PROGRAM FILES\\PROCESS EXPLORER\\PROCEXP.EXE\""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-02-10 10:25:45

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI