ComboFix 07-12-02.7 - LIN0056 2007-12-04 22:25:02.4 - NTFSx86
Running from: C:\Documents and Settings\lin0056\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\lin0056\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\rkupginstaller.exe
C:\WINDOWS\system32\rlvknlg.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\rkupginstaller.exe
C:\WINDOWS\system32\scvhost.exe
C:\WINDOWS\system32\xlive
C:\WINDOWS\system32\xlive\sqmapi.dll
.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-04 19:54 . 2007-12-04 19:54 17,542 ---h-c--- C:\DriveIcon.ico
2007-12-04 19:50 . 2007-12-04 19:56 <DIR> d----c--- C:\Program Files\Bee Icons
2007-12-04 16:54 . 2007-12-04 16:55 <DIR> d----c--- C:\Program Files\AnyReader
2007-12-04 09:20 . 2007-12-04 09:20 <DIR> d----c--- C:\Program Files\VideoLAN
2007-12-04 09:15 . 2007-12-04 09:15 <DIR> d----c--- C:\Program Files\XviD
2007-12-04 09:08 . 2007-12-04 09:08 <DIR> d----c--- C:\Program Files\DScaler5
2007-12-04 08:58 . 2007-12-04 08:58 <DIR> d----c--- C:\Program Files\3ivx
2007-12-04 08:50 . 2007-12-04 15:38 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\DivX
2007-12-04 08:48 . 2007-09-29 03:07 129,784 -----c--- C:\WINDOWS\system32\pxafs.dll
2007-12-04 08:48 . 2007-09-29 03:07 9,464 -----c--- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-12-04 08:48 . 2007-09-29 03:07 9,336 -----c--- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-12-04 08:34 . 2007-12-04 08:48 <DIR> d----c--- C:\Program Files\DivX
2007-12-04 08:31 . 2007-12-04 08:31 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\Nokia Multimedia Player
2007-12-04 08:30 . 2007-12-04 08:31 54,156 --ah-c--- C:\WINDOWS\QTFont.qfn
2007-12-04 08:30 . 2007-12-04 08:31 1,409 --a--c--- C:\WINDOWS\QTFont.for
2007-12-04 00:36 . 2007-12-04 00:36 <DIR> d----c--- C:\Program Files\ElcomSoft
2007-12-04 00:17 . 2007-12-04 00:17 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\Leadertech
2007-12-03 23:25 . 2007-12-03 23:25 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Nokia
2007-12-03 23:23 . 2007-02-22 11:15 137,216 --a--c--- C:\WINDOWS\system32\drivers\nmwcd.sys
2007-12-03 23:23 . 2007-02-22 11:15 65,536 --a--c--- C:\WINDOWS\system32\nmwcdcocls.dll
2007-12-03 23:19 . 2007-12-03 23:21 <DIR> d----c--- C:\Documents and Settings\lin0056\Phone Browser
2007-12-03 22:36 . 2007-12-03 22:38 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\PC Suite
2007-12-03 22:35 . 2007-12-03 22:38 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\Nokia
2007-12-03 22:34 . 2007-12-03 22:35 <DIR> d----c--- C:\Program Files\DIFX
2007-12-03 22:34 . 2007-12-03 22:34 <DIR> d----c--- C:\Program Files\Common Files\PCSuite
2007-12-03 22:34 . 2007-12-03 23:42 <DIR> d----c--- C:\Program Files\Common Files\Nokia
2007-12-03 22:34 . 2007-12-03 23:19 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\PC Suite
2007-12-03 22:33 . 2007-12-03 22:33 <DIR> d----c--- C:\Program Files\PC Connectivity Solution
2007-12-03 22:33 . 2007-12-03 23:42 <DIR> d----c--- C:\Program Files\Nokia
2007-12-03 22:33 . 2007-02-22 11:15 90,624 --a--c--- C:\WINDOWS\system32\nmwcdcls.dll
2007-12-03 22:24 . 2007-12-03 22:24 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Installations
2007-12-03 22:21 . 2007-12-03 22:21 <DIR> d--hsc--- C:\WINDOWS\ftpcache
2007-12-03 22:02 . 2007-12-03 22:02 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\AdobeUM
2007-12-03 22:02 . 2007-12-03 22:02 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\AdobeAUM
2007-12-03 18:27 . 2007-12-03 18:56 <DIR> d----c--- C:\Program Files\Download Direct
2007-12-03 17:37 . 2007-12-03 17:37 <DIR> d--h-c--- C:\WINDOWS\system32\GroupPolicy
2007-12-03 17:23 . 2007-12-02 02:05 307,200 --a--c--- C:\WINDOWS\kopmet.dll
2007-12-03 17:23 . 2007-12-02 02:05 192,512 --a--c--- C:\WINDOWS\jetctrl.dll
2007-12-03 17:23 . 2007-12-02 02:05 147,456 --a--c--- C:\WINDOWS\nretcip.exe
2007-12-03 17:03 . 2007-12-03 17:04 <DIR> d----c--- C:\Program Files\RichVideoCodec
2007-12-03 11:21 . 2007-12-03 11:21 244 --ah-c--- C:\sqmnoopt00.sqm
2007-12-03 11:21 . 2007-12-03 11:21 232 --ah-c--- C:\sqmdata00.sqm
2007-12-03 06:25 . 2007-05-27 17:09 419,969 -r-h-c--- C:\WINDOWS\NetMSConfig.exe
2007-12-03 06:04 . 2007-12-03 06:05 <DIR> d----c--- C:\Program Files\Date Cracker 2000
2007-12-03 06:04 . 2007-12-03 06:04 73,216 --a--c--- C:\WINDOWS\temp.000
2007-12-02 22:53 . 2007-12-02 22:53 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-02 13:54 . 2007-12-02 14:15 <DIR> d----c--- C:\Program Files\TVAnts
2007-12-02 13:53 . 2007-12-02 13:53 <DIR> d----c--- C:\WINDOWS\uninstall\Satellite TV for PC Elite
2007-12-02 13:53 . 2007-12-02 13:53 <DIR> d----c--- C:\WINDOWS\uninstall
2007-12-02 13:53 . 2007-12-02 13:53 <DIR> d----c--- C:\Program Files\SatelliteTVforPC
2007-12-02 13:11 . 2007-12-02 13:11 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\TVU Networks
2007-12-02 10:56 . 2007-12-02 10:56 <DIR> d----c--- C:\Program Files\smr-usenet
2007-12-02 10:56 . 2001-03-29 01:38 69,632 --a--c--- C:\WINDOWS\system32\GkSui18.EXE
2007-12-02 09:45 . 2007-12-02 09:45 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\ZipZag
2007-12-02 09:44 . 2007-12-02 09:46 <DIR> d----c--- C:\Program Files\ZipZag
2007-12-01 20:20 . 2007-12-04 09:23 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\vlc
2007-12-01 20:17 . 2007-12-02 13:12 <DIR> d----c--- C:\Program Files\TVU Player
2007-12-01 16:35 . 2007-12-01 16:43 <DIR> d----c--- C:\WINDOWS\system32\dt
2007-12-01 16:29 . 2007-12-01 16:29 0 --a--c--- C:\WINDOWS\WB.ini
2007-12-01 15:48 . 2007-12-01 15:48 <DIR> d----c--- C:\WINDOWS\{hopper}
2007-12-01 15:48 . 2007-12-03 10:01 <DIR> d----c--- C:\Program Files\WiFi Hopper
2007-12-01 15:48 . 2006-05-31 02:36 21,376 --a--c--- C:\WINDOWS\system32\drivers\hopperp.sys
2007-12-01 15:14 . 2007-12-01 15:14 103 --a--c--- C:\WINDOWS\system32\msrcom.dat
2007-12-01 12:31 . 2001-06-11 22:15 115,016 --a--c--- C:\WINDOWS\system32\Msinet.ocx
2007-12-01 09:44 . 2007-12-01 09:44 <DIR> d----c--- C:\Program Files\Download Manager
2007-12-01 09:43 . 2007-12-01 11:23 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\IGN_DLM
2007-12-01 00:43 . 2007-12-01 00:43 479,298 --a--c--- C:\WINDOWS\system32\wbocx.ocx
2007-12-01 00:43 . 2007-12-01 00:43 172,032 --a--c--- C:\WINDOWS\system32\AniGIF.ocx
2007-12-01 00:43 . 2007-12-01 00:43 50,688 --a--c--- C:\WINDOWS\system32\wbhelp2.dll
2007-11-30 21:37 . 2007-11-30 21:37 <DIR> d----c--- C:\Program Files\GameSpot
2007-11-30 20:17 . 2007-11-30 20:17 <DIR> d----c--- C:\Program Files\Uconomix
2007-11-30 17:00 . 2007-11-30 17:18 <DIR> d----c--- C:\Program Files\Spyware Doctor
2007-11-30 17:00 . 2007-11-30 17:00 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\PC Tools
2007-11-30 17:00 . 2007-10-18 00:16 79,688 --a--c--- C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-30 17:00 . 2007-10-18 00:15 62,280 --a--c--- C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-30 17:00 . 2007-10-18 00:14 41,288 --a--c--- C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-30 17:00 . 2007-10-18 00:16 29,000 --a--c--- C:\WINDOWS\system32\drivers\kcom.sys
2007-11-30 16:59 . 2005-09-23 08:29 626,688 --a--c--- C:\WINDOWS\system32\msvcr80.dll
2007-11-30 13:40 . 2007-12-01 15:15 160,564,119 --a--c--- C:\WINDOWS\system32\mfccache.dll
2007-11-29 20:41 . 2007-11-29 20:58 <DIR> d----c--- C:\Program Files\Hide The IP
2007-11-29 20:28 . 2007-12-01 22:40 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\LimeWire
2007-11-29 20:27 . 2007-11-29 20:27 <DIR> d----c--- C:\Program Files\LimeWire
2007-11-29 18:52 . 2007-11-29 18:55 <DIR> d----c--- C:\Documents and Settings\lin0056\Application Data\XP Visual Tools
2007-11-29 18:50 . 2007-12-03 16:56 <DIR> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-29 12:49 . 2007-11-29 18:58 <DIR> d----c--- C:\Program Files\Common Files\Stardock
2007-11-29 11:52 . 2007-11-29 18:57 <DIR> d----c--- C:\Program Files\Stardock
2007-11-29 11:52 . 2007-07-11 15:06 42,672 --a--c--- C:\WINDOWS\system32\wbsys.dll
2007-11-29 11:52 . 2005-01-22 18:05 20,480 --a--c--- C:\WINDOWS\system32\wbload.dll
2007-11-29 08:57 . 2007-11-29 09:15 <DIR> d----c--- C:\Program Files\GameSpy Arcade
2007-11-28 15:16 . 2007-11-28 15:16 <DIR> d----c--- C:\WINDOWS\.jagex_cache_32
2007-11-24 19:16 . 2007-11-25 11:39 <DIR> d----c--- C:\Program Files\Halo Server
2007-11-24 16:41 . 2007-11-24 16:41 <DIR> d----c--- C:\Documents and Settings\LocalService\Application Data\Xfire
2007-11-24 09:34 . 2007-11-24 09:34 54 --a--c--- C:\WINDOWS\Composer.INI
2007-11-24 09:33 . 2007-11-28 20:54 <DIR> d----c--- C:\Program Files\Notation
2007-11-24 08:21 . 2007-11-24 08:21 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Musicnotes
2007-11-22 17:28 . 2007-11-22 17:44 <DIR> d----c--- C:\Documents and Settings\lin0056\DoctorWeb
2007-11-21 17:03 . 2007-11-22 17:22 <DIR> d----c--- C:\WINDOWS\system32\ActiveScan
2007-11-21 17:03 . 2007-11-22 16:22 30,590 --a--c--- C:\WINDOWS\system32\pavas.ico
2007-11-21 17:03 . 2007-11-22 16:22 2,550 --a--c--- C:\WINDOWS\system32\Uninstall.ico
2007-11-21 17:03 . 2007-11-22 16:22 1,406 --a--c--- C:\WINDOWS\system32\Help.ico
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 11:29 --------- dc----w C:\Program Files\Symantec AntiVirus
2007-12-04 08:54 106 -c-h--w C:\Program Files\desktop.ini
2007-12-03 14:28 --------- dc----w C:\Program Files\Common Files\Adobe
2007-12-02 19:04 249,856 -c----w C:\WINDOWS\Setup1.exe
2007-11-30 10:37 5,588 -c--a-w C:\Program Files\install.log
2007-11-22 06:14 --------- dc----w C:\Program Files\Windows Defender
2007-11-22 06:04 --------- dc----w C:\Program Files\Google
2007-11-22 06:04 --------- dc----w C:\Program Files\Digital Line Detect
2007-11-22 06:00 --------- dc----w C:\Program Files\Common Files\Symantec Shared
2007-11-09 11:58 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2007-11-08 01:18 --------- dc----w C:\Program Files\Windows Media Connect
2007-11-08 01:13 --------- dc----w C:\Program Files\Microsoft Works
2007-11-07 05:09 --------- dc----w C:\Program Files\Picasa2
2007-07-23 21:37 32,768 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
.
((((((((((((((((((((((((((((( snapshot@2007-11-16_20.38.52.82 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-05-30 02:44:18 11,776 -c--a-w C:\WINDOWS\{hopper}\snetcfg.exe
- 2007-10-29 07:56:19 136,192 -c--a-w C:\WINDOWS\catchme.exe
+ 2007-11-26 16:58:11 140,288 -c--a-w C:\WINDOWS\catchme.exe
+ 2006-08-23 21:28:54 141,424 -c--a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2007-03-05 02:57:46 325,240 -c--a-w C:\WINDOWS\Downloaded Program Files\DLMControl.dll
+ 2007-06-01 03:25:26 317,016 -c--a-w C:\WINDOWS\Downloaded Program Files\mnviewer.dll
+ 2006-05-30 15:36:54 21,376 -c--a-w C:\WINDOWS\inf\hopperp.sys
+ 2007-12-04 05:40:30 10,134 -c--a-r C:\WINDOWS\Installer\{066D65EA-ED53-44E4-A96A-F81B6E409D2E}\ARPPRODUCTICON.exe
+ 2007-12-03 12:23:50 3,262 -c--a-r C:\WINDOWS\Installer\{11964613-805F-432D-A12B-169554B793E7}\ARPPRODUCTICON.exe
+ 2007-12-03 10:59:43 65,536 -c--a-r C:\WINDOWS\Installer\{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}\ARPPRODUCTICON.exe
+ 2007-12-03 10:59:43 65,536 -c--a-r C:\WINDOWS\Installer\{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}\NewShortcut2_4BDFD2CE632942E498019B3D1F10D79B.exe
+ 2007-12-03 10:59:43 65,536 -c--a-r C:\WINDOWS\Installer\{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}\NewShortcut3_4BDFD2CE632942E498019B3D1F10D79B.exe
+ 2007-12-04 05:41:19 15,086 -c--a-r C:\WINDOWS\Installer\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\ARPPRODUCTICON.exe
+ 2007-12-04 05:41:19 216,358 -c--a-r C:\WINDOWS\Installer\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\EXTUI_UninstallPCSui_0F854AC05AF149EFBE65492233B7B5AD.exe
- 2007-11-08 01:18:14 12,288 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2007-11-30 02:49:27 12,288 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2007-11-08 01:18:14 135,168 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2007-11-30 02:49:26 135,168 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2007-11-08 01:18:14 11,264 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2007-11-30 02:49:27 11,264 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2007-11-08 01:18:14 27,136 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2007-11-30 02:49:27 27,136 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2007-11-08 01:18:14 4,096 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2007-11-30 02:49:27 4,096 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2007-11-08 01:18:15 794,624 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2007-11-30 02:49:27 794,624 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2007-11-08 01:18:14 249,856 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2007-11-30 02:49:26 249,856 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2007-11-08 01:18:15 23,040 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2007-11-30 02:49:27 23,040 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2007-11-08 01:18:14 286,720 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2007-11-30 02:49:26 286,720 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2007-11-08 01:18:13 409,600 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2007-11-30 02:49:26 409,600 -c--a-r C:\WINDOWS\Installer\{90120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2007-08-07 01:51:46 1,139,488 -c--a-w C:\WINDOWS\system32\3ivx.dll
+ 2007-08-07 01:51:52 324,320 -c--a-w C:\WINDOWS\system32\3ivxVfWCodec.dll
+ 2007-03-28 22:20:50 110,592 -c--a-w C:\WINDOWS\system32\ActiveScan\as.dll
+ 2006-10-05 05:15:26 233,472 -c--a-w C:\WINDOWS\system32\ActiveScan\ascontrol.dll
+ 2005-06-03 03:03:18 96,256 -c--a-w C:\WINDOWS\system32\ActiveScan\asmdat.dll
+ 2003-08-01 00:00:16 36,864 -c--a-w C:\WINDOWS\system32\ActiveScan\certdll.dll
+ 2005-05-20 02:42:44 86,016 -c--a-w C:\WINDOWS\system32\ActiveScan\instlsp.dll
+ 2006-02-16 07:20:20 4,608 -c--a-w C:\WINDOWS\system32\ActiveScan\memvfile.dll
+ 2005-10-25 07:08:32 348,160 -c--a-w C:\WINDOWS\system32\ActiveScan\msvcr71.dll
+ 2004-05-04 04:01:02 139,264 -c--a-w C:\WINDOWS\system32\ActiveScan\pavaleas.dll
+ 2006-07-14 02:04:10 45,056 -c--a-w C:\WINDOWS\system32\ActiveScan\pavdr.exe
+ 2006-04-09 23:50:02 159,832 -c--a-w C:\WINDOWS\system32\ActiveScan\pavexcom.dll
+ 2006-02-14 02:05:38 94,208 -c--a-w C:\WINDOWS\system32\ActiveScan\pavinas.dll
+ 2006-02-16 07:35:38 180,224 -c--a-w C:\WINDOWS\system32\ActiveScan\pavoe.dll
+ 2006-10-05 05:15:38 122,880 -c--a-w C:\WINDOWS\system32\ActiveScan\pavpz.dll
+ 2006-06-30 03:13:38 8,704 -c--a-w C:\WINDOWS\system32\ActiveScan\pfdnnt.exe
+ 2004-02-04 03:08:42 49,152 -c--a-w C:\WINDOWS\system32\ActiveScan\port32.dll
+ 2006-08-01 02:23:10 69,632 -c--a-w C:\WINDOWS\system32\ActiveScan\pscpu.dll
+ 2006-08-23 02:06:08 1,388,544 -c--a-w C:\WINDOWS\system32\ActiveScan\pskahk.dll
+ 2006-08-17 00:38:14 10,752 -c--a-w C:\WINDOWS\system32\ActiveScan\pskalloc.dll
+ 2006-09-04 00:49:54 61,440 -c--a-w C:\WINDOWS\system32\ActiveScan\pskas.dll
+ 2006-08-17 21:46:18 779,264 -c--a-w C:\WINDOWS\system32\ActiveScan\pskavs.dll
+ 2007-03-26 03:25:34 417,792 -c--a-w C:\WINDOWS\system32\ActiveScan\pskcmp.dll
+ 2006-08-08 23:42:24 90,112 -c--a-w C:\WINDOWS\system32\ActiveScan\pskfss.dll
+ 2006-07-18 23:55:58 208,896 -c--a-w C:\WINDOWS\system32\ActiveScan\pskhtml.dll
+ 2006-01-20 05:57:00 9,728 -c--a-w C:\WINDOWS\system32\ActiveScan\pskmas.dll
+ 2006-05-16 22:50:12 14,336 -c--a-w C:\WINDOWS\system32\ActiveScan\pskmdfs.dll
+ 2006-08-15 23:58:12 33,280 -c--a-w C:\WINDOWS\system32\ActiveScan\pskpack.dll
+ 2006-06-30 03:42:36 266,240 -c--a-w C:\WINDOWS\system32\ActiveScan\pskscs.dll
+ 2006-08-17 03:33:14 62,976 -c--a-w C:\WINDOWS\system32\ActiveScan\pskutil.dll
+ 2006-08-08 02:13:10 13,312 -c--a-w C:\WINDOWS\system32\ActiveScan\pskvfile.dll
+ 2006-08-17 21:53:08 69,632 -c--a-w C:\WINDOWS\system32\ActiveScan\pskvfs.dll
+ 2006-08-17 21:49:50 167,936 -c--a-w C:\WINDOWS\system32\ActiveScan\pskvm.dll
+ 2007-04-18 06:16:04 353,840 -c--a-w C:\WINDOWS\system32\ActiveScan\psscan.dll
+ 2007-01-22 03:42:48 35,328 -c--a-w C:\WINDOWS\system32\ActiveScan\rawvfile.dll
+ 1997-09-17 19:12:32 9,488 -c--a-w C:\WINDOWS\system32\ActiveScan\sporder.dll
+ 2006-02-28 06:23:40 69,632 -c--a-w C:\WINDOWS\system32\ActiveScan\tcpvfile.dll
+ 2006-08-02 01:39:06 73,728 -c--a-w C:\WINDOWS\system32\asuninst.exe
+ 2007-12-04 05:55:33 15,360 -c--a-w C:\WINDOWS\system32\BASSMOD.dll
+ 2006-12-01 05:30:01 6,201 -c--a-w C:\WINDOWS\system32\bpk.dat
+ 2005-12-07 01:31:00 202,752 -c--a-r C:\WINDOWS\system32\CddbCdda.dll
- 2007-04-17 05:45:28 92,504 -c--a-w C:\WINDOWS\system32\cdm.dll
+ 2007-04-16 11:45:28 92,504 -c--a-w C:\WINDOWS\system32\cdm.dll
+ 2004-06-04 15:34:36 86,016 -c--a-w C:\WINDOWS\system32\CNMCP6d.exe
+ 2004-06-07 05:00:00 116,736 -c--a-w C:\WINDOWS\system32\CNMLM6d.DLL
+ 2004-06-07 05:00:00 7,680 -c--a-w C:\WINDOWS\system32\CNMVS6d.DLL
+ 2007-09-28 16:05:40 739,840 -c--a-w C:\WINDOWS\system32\DivX.dll
+ 2007-09-28 16:05:40 823,296 -c--a-w C:\WINDOWS\system32\divx_xx07.dll
+ 2007-09-28 16:05:40 823,296 -c--a-w C:\WINDOWS\system32\divx_xx0c.dll
+ 2007-09-28 16:05:40 802,816 -c--a-w C:\WINDOWS\system32\divx_xx11.dll
+ 2007-09-28 16:08:18 156,992 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
+ 2007-09-28 16:07:54 524,288 -c--a-w C:\WINDOWS\system32\DivXsm.exe
+ 2007-08-07 01:52:58 25,312 -c--a-w C:\WINDOWS\system32\DivXVfWCodec.dll
+ 2007-09-28 16:05:08 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll
- 2007-04-17 05:45:28 92,504 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2007-04-16 11:45:28 92,504 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2004-08-03 12:01:26 25,856 -c--a-w C:\WINDOWS\system32\dllcache\usbprint.sys
- 2007-04-17 05:45:48 549,720 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
+ 2007-04-16 11:45:48 549,720 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2007-04-17 05:45:20 53,080 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2007-04-16 11:45:20 53,080 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2007-04-17 05:45:54 1,710,936 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-04-16 11:45:54 1,710,936 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2007-04-17 05:45:42 325,976 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2007-04-16 11:45:42 325,976 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
- 2007-04-17 05:47:36 33,624 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2007-04-16 11:47:36 33,624 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
- 2007-04-17 05:43:44 203,096 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-04-16 11:45:36 203,096 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-09-28 16:05:50 81,920 -c--a-w C:\WINDOWS\system32\dpl100.dll
+ 2007-09-28 16:05:42 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll
+ 2007-09-28 16:05:42 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll
+ 2007-09-28 16:05:44 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll
+ 2007-09-28 16:05:42 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll
+ 2007-09-28 16:05:42 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll
+ 2007-09-28 16:05:42 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll
- 2005-10-26 20:12:50 20,640 -c--a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
+ 2007-09-28 16:07:50 43,528 -c----w C:\WINDOWS\system32\drivers\pxhelp20.sys
- 2004-08-04 12:00:00 27,440 -c--a-w C:\WINDOWS\system32\drivers\secdrv.sys
+ 2003-09-09 04:30:32 11,376 -c--a-r C:\WINDOWS\system32\drivers\secdrv.sys
+ 2007-03-20 00:45:50 479,232 -c--a-w C:\WINDOWS\system32\drivers\UMDF\PCCSWpdDriver.dll
+ 2004-08-03 12:01:26 25,856 -c--a-w C:\WINDOWS\system32\drivers\usbprint.sys
- 2006-09-28 07:55:50 77,568 -c----w C:\WINDOWS\system32\drivers\WudfPf.sys
+ 2006-09-15 11:29:52 76,544 -c----w C:\WINDOWS\system32\drivers\WudfPf.sys
- 2006-09-28 08:00:34 82,944 -c----w C:\WINDOWS\system32\drivers\WudfRd.sys
+ 2006-09-15 11:30:10 82,688 -c----w C:\WINDOWS\system32\drivers\WudfRd.sys
+ 2007-02-22 00:15:56 137,216 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcd_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcd.sys
+ 2007-02-22 00:15:12 90,624 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcd_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdcls.dll
+ 2007-02-22 00:15:12 65,536 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcd_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdcocls.dll
+ 2007-02-22 00:15:14 8,320 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcdc_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdc.sys
+ 2007-02-22 00:15:14 12,288 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcdcj_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdcj.sys
+ 2007-02-22 00:15:14 12,288 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcdm2k_F3FA2468AF360A65811B287DD7A88CB715CF7275\nmwcdcm.sys
+ 2007-03-20 00:45:50 479,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\pccswpddri_039E7E24575DBAE6A389611AF28F4EB97729D33E\PCCSWpdDriver.dll
+ 2007-03-20 00:37:46 831,048 -c--a-w C:\WINDOWS\system32\DRVSTORE\pccswpddri_039E7E24575DBAE6A389611AF28F4EB97729D33E\WudfUpdate_01005.dll
+ 2007-09-28 16:05:50 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll
- 2007-11-10 22:23:46 5,427 -c--a-w C:\WINDOWS\system32\EGATHDRV.SYS
+ 2007-12-19 19:18:58 5,427 -c--a-w C:\WINDOWS\system32\EGATHDRV.SYS
- 2007-11-08 05:40:28 117,360 -c--a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-12-03 12:58:21 1,429,080 -c--a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-05-24 01:27:16 213,048 -c--a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 04:47:20 94,208 -c--a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 04:49:54 950,272 -c--a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-09-28 16:07:44 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
+ 2007-08-07 01:52:02 66,272 -c--a-w C:\WINDOWS\system32\libfaac.dll
- 2004-02-23 07:00:00 1,386,496 -c--a-w C:\WINDOWS\system32\msvbvm60.dll
+ 2004-02-23 09:42:40 1,386,496 -c--a-w C:\WINDOWS\system32\MSVBVM60.DLL
+ 2007-08-07 01:52:14 443,104 -c--a-w C:\WINDOWS\system32\OpenQuicktimeLib.dll
- 2007-11-08 22:18:04 71,302 -c--a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-03 13:15:38 71,302 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-08 22:18:04 439,598 -c--a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-03 13:15:38 439,598 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2006-12-01 05:31:53 4,204 -c--a-w C:\WINDOWS\system32\pk.bin
+ 2007-06-08 03:46:44 86,070 -c--a-w C:\WINDOWS\system32\pthreadVC2.dll
- 2005-08-12 21:27:22 405,504 -c--a-w C:\WINDOWS\system32\Px.dll
+ 2007-09-28 16:07:48 551,672 -c----w C:\WINDOWS\system32\Px.dll
- 2006-08-18 08:09:26 56,832 -c--a-w C:\WINDOWS\system32\pxcpya64.exe
+ 2007-09-28 16:07:48 66,296 -c----w C:\WINDOWS\system32\pxcpya64.exe
- 2006-08-18 08:09:26 108,544 -c--a-w C:\WINDOWS\system32\pxcpyi64.exe
+ 2007-09-28 16:07:48 120,056 -c----w C:\WINDOWS\system32\pxcpyi64.exe
- 2005-09-01 08:01:00 434,176 -c--a-w C:\WINDOWS\system32\pxdrv.dll
+ 2007-09-28 16:07:48 518,904 -c----w C:\WINDOWS\system32\pxdrv.dll
- 2006-08-18 08:09:26 57,344 -c--a-w C:\WINDOWS\system32\pxhpinst.exe
+ 2007-09-28 16:07:50 72,440 -c----w C:\WINDOWS\system32\pxhpinst.exe
- 2006-08-18 08:09:26 56,320 -c--a-w C:\WINDOWS\system32\pxinsa64.exe
+ 2007-09-28 16:07:48 64,760 -c----w C:\WINDOWS\system32\pxinsa64.exe
- 2006-08-18 08:09:26 109,056 -c--a-w C:\WINDOWS\system32\pxinsi64.exe
+ 2007-09-28 16:07:48 118,520 -c----w C:\WINDOWS\system32\pxinsi64.exe
- 2005-08-12 21:26:20 172,032 -c--a-w C:\WINDOWS\system32\PxMas.dll
+ 2007-09-28 16:07:50 187,128 -c----w C:\WINDOWS\system32\PxMas.dll
- 2005-08-12 21:30:48 1,196,032 -c--a-w C:\WINDOWS\system32\PxSFS.DLL
+ 2007-09-28 16:07:50 1,628,920 -c----w C:\WINDOWS\system32\PxSFS.DLL
- 2005-08-12 21:25:50 339,968 -c--a-w C:\WINDOWS\system32\PxWave.dll
+ 2007-09-28 16:07:50 379,640 -c----w C:\WINDOWS\system32\PxWave.dll
+ 2007-09-28 16:07:52 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll
- 2007-11-16 07:17:31 95,128 -c--a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2007-12-02 23:10:13 31,984 -c--a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2007-08-07 01:52:50 25,312 -c--a-w C:\WINDOWS\system32\SamsungVfWCodec.dll
+ 2006-12-01 05:19:49 24,576 -c--a-w C:\WINDOWS\system32\scvhosthk.dll
+ 2006-12-01 05:19:49 40,960 -c--a-w C:\WINDOWS\system32\scvhostwb.dll
- 2007-04-17 05:47:36 33,624 -c--a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.374\wups.dll
+ 2007-04-16 11:47:36 33,624 -c--a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.374\wups.dll
+ 2007-04-16 11:45:20 43,352 -c--a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.374\wups2.dll
- 2006-09-25 06:58:48 14,640 -c--a-w C:\WINDOWS\system32\spmsg.dll
+ 2006-09-15 16:02:34 14,640 -c----w C:\WINDOWS\system32\spmsg.dll
+ 2004-06-07 05:00:00 68,608 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMCP6d.DLL
+ 2004-06-07 05:00:00 153,600 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMD56d.DLL
+ 2004-06-07 05:00:00 397,824 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMDR6d.DLL
+ 2004-06-07 05:00:00 19,456 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMFU6d.DLL
+ 2004-06-07 05:10:00 22,528 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMOP6d.DLL
+ 2004-06-07 05:00:00 23,280 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMP06d.DAT
+ 2004-06-07 05:00:00 27,140 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMP16d.DAT
+ 2004-06-07 05:00:00 30,320 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMP26d.DAT
+ 2004-06-07 05:00:00 6,656 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMPI6d.DLL
+ 2004-06-07 05:00:00 80,896 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMPV6d.EXE
+ 2004-06-07 05:00:00 850,944 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMSB6d.DLL
+ 2004-06-07 05:00:00 8,704 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMSD6d.EXE
+ 2004-06-07 05:00:00 130,048 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMSM6d.EXE
+ 2004-06-07 05:00:00 6,656 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMSQ6d.EXE
+ 2004-06-07 05:00:00 110,592 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMSR6d.DLL
+ 2004-06-07 05:00:00 322,048 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMUB6d.DLL
+ 2004-06-07 05:00:00 1,571,840 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMUI6d.DLL
+ 2004-06-07 05:00:00 219,648 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMUR6d.DLL
+ 2004-06-07 05:00:00 6,656 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMW36d.DLL
+ 2007-01-10 12:05:15 94,274 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBHEALR.DLL
+ 2007-01-10 12:05:15 40,960 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBMMON.DLL
+ 2007-01-10 12:05:16 659,528 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPCDMC32.DLL
+ 2007-01-10 12:05:17 58,368 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPDOMON.DLL
+ 2007-01-10 12:05:22 1,202,688 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZ3A041.DLL
+ 2007-01-10 12:05:22 1,117,696 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZ6R041.DLL
+ 2007-01-10 12:05:22 570,368 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZEV041.DLL
+ 2007-01-10 12:05:22 61,952 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZPP041.DLL
+ 2007-01-10 12:05:22 433,664 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZSS041.DLL
+ 2007-01-10 12:05:22 2,337,280 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZST041.DLL
+ 2007-01-10 12:05:22 1,907,200 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZUI041.DLL
+ 2007-02-16 17:45:44 169,984 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\PCLXL.DLL
+ 2004-06-07 05:00:00 68,608 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMCP6d.DLL
+ 2004-06-07 05:00:00 153,600 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMD56d.DLL
+ 2004-06-07 05:00:00 397,824 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMDR6d.DLL
+ 2004-06-07 05:00:00 19,456 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMFU6d.DLL
+ 2004-06-07 05:10:00 22,528 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMOP6d.DLL
+ 2004-06-07 05:00:00 23,280 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMP06d.DAT
+ 2004-06-07 05:00:00 27,140 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMP16d.DAT
+ 2004-06-07 05:00:00 30,320 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMP26d.DAT
+ 2004-06-07 05:00:00 6,656 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMPI6d.DLL
+ 2004-06-07 05:00:00 80,896 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMPV6d.EXE
+ 2004-06-07 05:00:00 850,944 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMSB6d.DLL
+ 2004-06-07 05:00:00 8,704 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMSD6d.EXE
+ 2004-06-07 05:00:00 130,048 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMSM6d.EXE
+ 2004-06-07 05:00:00 6,656 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMSQ6d.EXE
+ 2004-06-07 05:00:00 110,592 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMSR6d.DLL
+ 2004-06-07 05:00:00 322,048 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMUB6d.DLL
+ 2004-06-07 05:00:00 1,571,840 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMUI6d.DLL
+ 2004-06-07 05:00:00 219,648 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMUR6d.DLL
+ 2004-06-07 05:00:00 6,656 -c--a-w C:\WINDOWS\system32\spool\drivers\w32x86\canonip500008f7\CNMW36d.DLL
+ 2004-06-07 05:00:00 17,920 -c--a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD6d.DLL
+ 2004-06-07 05:00:00 54,272 -c--a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP6d.DLL
+ 2007-09-28 16:07:44 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
+ 2007-03-21 09:54:16 77,312 -c--a-w C:\WINDOWS\system32\TWAIN_32.DLL
+ 2007-03-21 09:54:16 48,560 -c--a-w C:\WINDOWS\system32\TWUNK_16.EXE
+ 2007-03-21 09:54:16 69,632 -c--a-w C:\WINDOWS\system32\TWUNK_32.EXE
- 2005-08-12 08:00:00 28,672 -c--a-w C:\WINDOWS\system32\VXBLOCK.dll
+ 2007-09-28 16:07:48 88,824 -c----w C:\WINDOWS\system32\VXBLOCK.dll
+ 2006-01-18 06:22:42 807,032 -c--a-w C:\WINDOWS\system32\wmv9dmod.dll
- 2007-04-17 05:45:48 549,720 -c--a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-04-16 11:45:48 549,720 -c--a-w C:\WINDOWS\system32\wuapi.dll
- 2007-04-17 05:45:20 53,080 -c--a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-04-16 11:45:20 53,080 -c--a-w C:\WINDOWS\system32\wuauclt.exe
- 2007-04-17 05:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-04-16 11:45:54 1,710,936 -c--a-w C:\WINDOWS\system32\wuaueng.dll
- 2007-04-17 05:45:42 325,976 -c--a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-04-16 11:45:42 325,976 -c--a-w C:\WINDOWS\system32\wucltui.dll
- 2006-09-28 09:13:26 95,344 -c--a-w C:\WINDOWS\system32\WUDFCoinstaller.dll
+ 2006-09-15 12:30:16 87,040 -c--a-w C:\WINDOWS\system32\WUDFCoinstaller.dll
- 2006-09-28 07:56:38 146,432 -c--a-w C:\WINDOWS\system32\WudfHost.exe
+ 2006-09-15 12:30:06 142,848 -c--a-w C:\WINDOWS\system32\WudfHost.exe
- 2006-09-28 07:56:16 165,376 -c--a-w C:\WINDOWS\system32\WudfPlatform.dll
+ 2006-09-15 11:29:54 163,840 -c--a-w C:\WINDOWS\system32\WudfPlatform.dll
- 2006-09-28 07:56:14 55,808 -c--a-w C:\WINDOWS\system32\WudfSvc.dll
+ 2006-09-15 12:30:16 55,296 -c--a-w C:\WINDOWS\system32\WudfSvc.dll
+ 2007-03-20 00:37:46 831,048 -c--a-w C:\WINDOWS\system32\WudfUpdate_01005.dll
- 2006-09-28 07:56:38 316,416 -c--a-w C:\WINDOWS\system32\WUDFx.dll
+ 2006-09-15 12:30:16 308,224 -c--a-w C:\WINDOWS\system32\WUDFx.dll
- 2007-04-17 05:47:36 33,624 -c--a-w C:\WINDOWS\system32\wups.dll
+ 2007-04-16 11:47:36 33,624 -c--a-w C:\WINDOWS\system32\wups.dll
- 2007-04-17 05:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
+ 2007-04-16 11:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
- 2007-04-17 05:43:44 203,096 -c--a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-04-16 11:45:36 203,096 -c--a-w C:\WINDOWS\system32\wuweb.dll
+ 1999-11-18 14:00:00 284,032 -c--a-w C:\WINDOWS\system32\XceedZip.dll
+ 2004-09-04 21:58:04 679,936 -c--a-w C:\WINDOWS\system32\xvidcore.dll
+ 2004-09-04 21:59:50 155,648 -c--a-w C:\WINDOWS\system32\xvidvfw.dll
+ 2003-03-25 07:53:50 11,776 -c--a-w C:\WINDOWS\system32\ZPORT4AS.dll
+ 2007-12-04 11:32:07 16,384 -c--atw C:\WINDOWS\Temp\Perflib_Perfdata_348.dat
+ 2007-12-02 02:53:24 417,792 -c--a-w C:\WINDOWS\uninstall\Satellite TV for PC Elite\setup.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-09 17:36]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
"DSS"="C:\WINDOWS\NetMSConfig.exe" [2007-05-27 17:09]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 23:00]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 19:29]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2007-07-24 08:18:49]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2007-07-24 08:18:47]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-08-18 18:50:44]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="lsass.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
notifyf2.dll 2005-07-06 17:45 28672 C:\WINDOWS\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2005-12-01 14:16 24576 C:\WINDOWS\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2007-12-01 16:20 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Extension-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Extension-List\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\
0]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\1]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\2]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\3]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\4]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\5]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\
0]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\1]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\2]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\3]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\4]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\5]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Extension-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Extension-List\{00000000-0000-0000-0000-000000000000}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Extension-List\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\GPLink-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\GPLink-List\
0]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\GPLink-List\1]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\GPLink-List\2]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\GPO-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\GPO-List\
0]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\GPO-List\1]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\GPO-List\2]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Loopback-GPLink-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Loopback-GPO-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Scripts]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Scripts\Logoff]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Scripts\Logon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Scripts\Logon\
0]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1292428093-1757981266-682003330-35769\Scripts\Logon\
0\
0]
"Script"=stdlogon.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\Extension-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\Extension-List\{00000000-0000-0000-0000-000000000000}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\Extension-List\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\GPLink-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\GPLink-List\
0]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\GPO-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\GPO-List\
0]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\Loopback-GPLink-List]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-23451335-341113855-1709847394-500\Loopback-GPO-List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 23:46 57344 --a--c--- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
R0 Shockprf;Shockprf;C:\WINDOWS\system32\drivers\Shockprf.sys
R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS
R1 IBMTPCHK;IBMTPCHK;\??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys
R1 ShockMgr;ShockMgr;C:\WINDOWS\system32\drivers\ShockMgr.sys
R1 TPPWRIF;TPPWRIF;C:\WINDOWS\system32\drivers\Tppwrif.sys
R2 HopperP;WiFi Hopper;C:\WINDOWS\system32\DRIVERS\hopperp.sys
R2 ibmfilter;ibmfilter;\??\C:\WINDOWS\system32\drivers\ibmfilter.sys
R2 PrivateDisk;PrivateDisk;\??\C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\PrivateDiskM.sys
R2 smi2;smi2;\??\C:\Program Files\SMI2\smi2.sys
R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
R3 atmeltpm;atmeltpm;C:\WINDOWS\system32\DRIVERS\atmeltpm.sys
S3 EraserUtilDrv10733;EraserUtilDrv10733;\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10733.sys
S3 EraserUtilDrvI4;EraserUtilDrvI4;\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI4.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setup.exe /autorun
\Shell\directx\command - G:\DirectX\dxsetup.exe
\Shell\setup\command - G:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 01:06:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-04 11:33:59 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-11-19 05:59:01 C:\WINDOWS\Tasks\PMTask.job"
- C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-04 22:34:21
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-04 22:36:03 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-18 08:58
C:\ComboFix3.txt ... 2007-11-16 21:55
.
--- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 22:56, on 2007-12-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.balwynhs....u/home/home.bhs
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft....k/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.balwynhs.vic.edu.au:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.balwynhs.vic.edu.au;172.*;*.education.vic.gov.au;*.sofweb.vic.edu.au;*.vass.vi
c.edu.au;*.eduweb.vic.gov.au;*.edudev.vic.gov.au;*.edumail.vic.gov.au;*.otte.vic.
gov.au;*.icon.edu.vic.gov.au;*.ultranet.vic.edu.au;*.vcaa.vic.edu.au;<local>;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [DSS] C:\WINDOWS\NetMSConfig.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) -
http://www.fileplane...C_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1185221205500
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = balwynhs.vic.edu.au
O17 - HKLM\Software\..\Telephony: DomainName = balwynhs.vic.edu.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (file missing)
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe (file missing)
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe (file missing)