This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help removing Trojan win32.delf.uc

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all, I hope you can help me :)

Yesterday my antivirus program AVG told me I've been infected with 4 trojans. I've run Super Anti Spyware, CCleaner, ComboFix, SDFix from safe mode, Adaware, Spybot, Combofix, Prevx trial version and Trojan Remover - they seem to have removed 3 of the trojans identified, but Spybot is still detecting win32.delf.uc on my computer. I've Googled mercilessly but cannot find a method to remove it.

Here is my Combofix log followed by HijackThis report. Please help me, I hate reinstalling Windows and I would really rather not resort to that, but I bank online and I can't pay any of my online bills if there's any chance my PC is compromised!

EDIT: Malwarebyte's Anti-Malware log posted as well.


ComboFix 08-09-16.05 - Anonymous Mute 2008-09-19 9:04:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.631 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\7.tmp
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.

2008-09-19 08:41 . 2008-09-19 08:41 d——– C:\Program Files\PrevxCSI
2008-09-19 08:41 . 2008-09-19 08:41 d——– C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-09-19 08:41 . 2008-09-19 08:41 17,408 –a—— C:\WINDOWS\system32\drivers\pxark.sys
2008-09-18 21:53 . 2008-09-18 22:03 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-18 21:52 . 2008-09-18 21:53 d——– C:\Program Files\Trojan Remover
2008-09-18 21:49 . 2006-05-25 15:52 162,304 –a—— C:\WINDOWS\system32\ztvunrar36.dll
2008-09-18 21:49 . 2003-02-02 20:06 153,088 –a—— C:\WINDOWS\system32\unrar3.dll
2008-09-18 21:49 . 2005-08-26 01:50 77,312 –a—— C:\WINDOWS\system32\ztvunace26.dll
2008-09-18 21:49 . 2002-03-06 01:00 75,264 –a—— C:\WINDOWS\system32\unacev2.dll
2008-09-18 21:49 . 2006-06-19 13:01 69,632 –a—— C:\WINDOWS\system32\ztvcabinet.dll
2008-09-18 21:48 . 2008-09-18 21:52 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Simply Super Software
2008-09-18 21:48 . 2008-09-18 21:48 d——– C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-09-18 21:40 . 2008-09-18 21:40 d——– C:\Documents and Settings\Administrator\Application Data\HPAppData
2008-09-18 21:06 . 2008-09-18 21:06 d——– C:\Program Files\Lavasoft
2008-09-18 21:06 . 2008-09-18 21:08 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-18 21:03 . 2008-09-18 21:03 88 –a—— C:\WINDOWS\system32\4.tmp
2008-09-18 21:03 . 2008-09-18 21:03 0 –a—— C:\WINDOWS\system32\8.tmp
2008-09-18 20:39 . 2008-09-18 20:39 d——– C:\WINDOWS\ERUNT
2008-09-18 20:02 . 2008-09-18 20:04 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-18 20:02 . 2008-09-18 20:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-18 19:51 . 2008-09-18 19:51 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Autoruns
2008-09-18 19:26 . 2008-09-18 19:26 d——– C:\Program Files\CCleaner
2008-09-18 18:36 . 2008-09-18 18:36 d——– C:\Downloads
2008-09-18 18:36 . 2008-09-18 18:37 d——– C:\Documents and Settings\Anonymous Mute\Application Data\GetRightToGo
2008-09-18 18:33 . 2008-09-18 18:33 135,896 –a—— C:\WINDOWS\system32\89.tmp
2008-09-18 18:33 . 2008-09-18 18:33 88 –a—— C:\WINDOWS\system32\86.tmp
2008-09-18 18:33 . 2008-09-18 18:33 0 –a—— C:\WINDOWS\system32\8A.tmp
2008-09-18 18:00 . 2008-09-18 18:00 135,896 –a—— C:\WINDOWS\system32\81.tmp
2008-09-18 18:00 . 2008-09-18 18:00 88 –a—— C:\WINDOWS\system32\7E.tmp
2008-09-18 18:00 . 2008-09-18 18:00 0 –a—— C:\WINDOWS\system32\82.tmp
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\WINDOWS\system32\wTR19
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\Temp\dax41
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\Temp
2008-09-18 17:10 . 2008-09-18 23:00 d–h—– C:\$AVG8.VAULT$
2008-09-17 10:18 . 2008-09-17 10:18 d——– C:\Program Files\iTunes
2008-09-17 10:18 . 2008-09-17 10:18 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Common Files\Apple
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Bonjour
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Apple Software Update
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-09-17 10:01 . 2008-09-17 10:01 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Apple Computer
2008-09-17 10:00 . 2008-09-17 10:18 d——– C:\Program Files\iPod
2008-09-17 10:00 . 2004-12-18 20:32 38,229 ——— C:\WINDOWS\system32\drivers\StMp3Rec.sys
2008-09-15 11:33 . 2008-09-15 11:33 d——– C:\Program Files\MSXML 4.0
2008-09-13 11:58 . 2008-09-13 11:58 d——– C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2008-09-12 18:04 . 2005-05-26 15:34 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2008-09-12 18:00 . 2008-09-12 18:00 d——– C:\Program Files\Microsoft Games
2008-09-09 12:33 . 2006-10-26 19:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2008-09-09 12:32 . 2008-09-09 12:32 d——– C:\Program Files\MSBuild
2008-09-09 12:32 . 2008-09-09 12:32 d——– C:\Program Files\Microsoft Works
2008-09-09 12:29 . 2008-09-09 12:31 d——– C:\WINDOWS\SHELLNEW
2008-09-09 12:28 . 2008-09-09 12:28 dr-h—– C:\MSOCache
2008-09-09 12:28 . 2008-09-15 11:37 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-09 12:11 . 2008-09-09 12:11 d——– C:\Program Files\uTorrent
2008-09-09 12:11 . 2008-09-18 18:42 d——– C:\Documents and Settings\Anonymous Mute\Application Data\uTorrent
2008-09-06 15:09 . 2008-09-06 15:09 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-09-01 14:10 . 2008-09-01 14:10 d——– C:\Program Files\Winamp Toolbar
2008-09-01 14:10 . 2008-09-01 14:10 d——– C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-09-01 14:09 . 2008-09-18 17:17 d——– C:\Program Files\Winamp Remote
2008-09-01 14:09 . 2008-09-01 14:12 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-08-29 21:53 . 2008-08-29 21:53 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Media Player Classic
2008-08-29 10:18 . 2008-08-29 10:18 87,336 –a—— C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 –a—— C:\WINDOWS\system32\dnssd.dll
2008-08-28 07:25 . 2008-08-28 07:42 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-26 16:33 . 2008-05-01 15:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-26 11:56 . 2008-09-19 09:03 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Affinegy
2008-08-26 11:51 . 2008-08-26 11:51 d——– C:\Program Files\WinPcap
2008-08-26 11:51 . 2008-05-26 16:09 27,072 –a—— C:\WINDOWS\system32\drivers\AFGSp50.sys
2008-08-26 11:50 . 2008-08-26 11:51 d——– C:\Program Files\Virgin Broadband Wireless
2008-08-26 11:50 . 2008-08-26 11:51 d——– C:\Documents and Settings\All Users\Application Data\Affinegy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 16:17 ——— d—–w C:\Program Files\QuickTime Alternative
2008-09-17 19:57 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\dvdcss
2008-09-17 09:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-12 17:04 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-12 16:58 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-09-01 13:11 ——— d—–w C:\Program Files\Winamp
2008-08-29 08:10 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 14:19 ——— d—–w C:\Program Files\Black Isle
2008-08-15 13:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-08-15 13:16 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\HP
2008-08-15 13:08 ——— d—–w C:\Program Files\HP
2008-08-15 13:08 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\HPAppData
2008-08-15 13:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-08-15 13:07 ——— d—–w C:\Program Files\Common Files\HP
2008-08-15 13:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-08-15 13:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2008-08-15 13:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-08-11 13:05 ——— d—–w C:\Program Files\Common Files\Motive
2008-08-11 13:04 ——— d—–w C:\Program Files\BroadJump
2008-07-25 08:49 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-07-25 08:49 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\SystemRequirementsLab
2008-07-23 17:55 ——— d—–w C:\Program Files\Bethesda Softworks
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 21:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-09 07:26 10,520 —-a-w C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 12:45 114,812 —-a-w C:\WINDOWS\UninstallFirefox.exe
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
.

——- Sigcheck ——-

2007-06-13 11:23 1040896 c8b31abad6ff805b8523518bbf30fa0e C:\WINDOWS\explorer.exe
2007-06-13 12:26 1040896 cc66b4f6687ce1ec4b6323699cdb7243 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2001-08-23 13:00 1008640 bb52d95207f2a62e74eadd95ea62fc99 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 00:56 1039872 437d3c266afcff71493da4d93b119f31 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2004-08-04 00:56 1039872 0c32b430255559c08ed248ffe150120f C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2008-04-14 01:12 1041408 ffafdb19d4d95d6a2642561f04cecf68 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe
2007-06-13 11:23 1040896 3e6e83b5857ad75b825d27f12348c92c C:\WINDOWS\system32\dllcache\explorer.exe

2001-08-23 13:00 20992 d251ecfb24c053d1fc02f089d549402b C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2004-08-04 00:56 23040 738656e6cd41ced9984620573b658a02 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-14 01:12 23040 5bdd0885c900a8abd194efe178c8efa8 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 00:56 23040 e273553dad628deee738df0b802005b4 C:\WINDOWS\system32\ctfmon.exe

2005-06-11 01:17 65536 2ed7b15f45085d1fdaed38d6dbda06e1 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2001-08-23 13:00 58880 9f3b98fc030ad21d7bb2cd2a971cdffa C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 00:56 65536 5282516d73a172fa7d6fb6173c7c4788 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2004-08-04 00:56 65536 df95c84584886ac4911b6a16f9c0a3ed C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-14 01:12 65536 e5dad9026407ec59da31f4f3c4b400c9 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\spoolsv.exe
2005-06-11 00:53 65536 329566c51f9b520a0b38b1186396859a C:\WINDOWS\system32\spoolsv.exe

2001-08-23 13:00 29184 581b86fc07cb97da3ebcfe8255ca43a5 C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2004-08-04 00:56 32256 013ce0a33c846a2e88dcfdeed04932c2 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-14 01:12 33792 896d1f6cfbaac70b94224b7045047ae1 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 00:56 32256 bd51869c20f259975070db33bfe88c57 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 1235736]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 385104]
"Wireless Manager"="C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 593920]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="C:\Program Files\QuickTime Alternative\QTTask.exe" [2008-09-06 421888]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-09-15 920144]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 23040]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Micronet Wireless Network Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Micronet Wireless Network Utility.lnk
backup=C:\WINDOWS\pss\Micronet Wireless Network Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SATARAID5.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SATARAID5.lnk
backup=C:\WINDOWS\pss\SATARAID5.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 00:56 23040 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2007-03-11 21:34 57344 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2008-05-16 14:01 13529088 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2008-05-16 14:01 86016 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
–a—— 2008-04-01 02:54 516096 C:\Program Files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2004-02-22 23:44 41073 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-08-04 00:02 44032 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2008-05-16 14:01 1638400 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra—— 2005-06-20 14:42 86016 C:\WINDOWS\soundman.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Black Isle\\Baldur's Gate\\BGMain2.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Black Isle\\BGII - SoA\\BGMain.exe"=
"C:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2005-02-12 16640]
R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-09-19 17408]
R0 Si3132r5;SiI-3132 SoftRaid 5 Controller;C:\WINDOWS\system32\DRIVERS\Si3132r5.sys [2005-04-19 181760]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 AffinegyService;AffinegyService;C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe [2008-05-26 151552]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 CSIScanner;CSIScanner;C:\Program Files\PrevxCSI\prevxcsi.exe [2008-09-19 618040]
R3 AFGSp50;AFGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AFGSp50.sys [2008-05-26 27072]
S3 AFGMp50;AFGMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AFGMp50.sys [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\autorun.exe
\Shell\directx\command - E:\DirectX9\dxsetup.exe
\Shell\setup\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Anonymous Mute\Application Data\Mozilla\Firefox\Profiles\hp1bb83z.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJPI142_04.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 09:08:06
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


C:\WINDOWS\TEMP\d50b34c8-8fa5-42ec-ac76-68510b73a734.tmp 0 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-09-19 9:10:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 08:09:57

Pre-Run: 92,568,535,040 bytes free
Post-Run: 92,500,774,912 bytes free

295 — E O F — 2008-09-15 10:37:32







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:45, on 19/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\system32\ipv6monl.dll
O2 - BHO: Rmn plugin - {47D92EB6-E52C-4cda-92A6-2369963F4913} - jetaccss.dll (file missing)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5E7C73D1-2855-4D62-94D4-1CB98B0221FF} - C:\WINDOWS\system32\crypt3.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Winamp; Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1215515032654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1215515372342
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

–
End of file - 7153 bytes






Malwarebytes' Anti-Malware 1.28
Database version: 1173
Windows 5.1.2600 Service Pack 2

19/09/2008 13:28:05
mbam-log-2008-09-19 (13-28-05).txt

Scan type: Quick Scan
Objects scanned: 47063
Time elapsed: 3 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{47d92eb6-e52c-4cda-92a6-2369963f4913} (Spyware.Banker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{36dbc179-a19f-48f2-b16a-6a3e19b42a87} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{36dbc179-a19f-48f2-b16a-6a3e19b42a87} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5e7c73d1-2855-4d62-94d4-1cb98b0221ff} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\wTR19 (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\jetaccss.dll (Spyware.Banker) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\crypt3.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wTR19\wTR191065.exe (Trojan.Agent) -> Quarantined and deleted successfully.
You shouldn't run ComboFix unless a helper tells you to

Plug your USB key in for this


Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/Help_removing_Trojan_win32_delf_uc_t95493.html

Collect::
C:\WINDOWS\system32\ipv6monl.dll
C:\WINDOWS\system32\crypt3.dll

File::
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\8.tmp
C:\WINDOWS\system32\89.tmp
C:\WINDOWS\system32\86.tmp
C:\WINDOWS\system32\8A.tmp
C:\WINDOWS\system32\81.tmp
C:\WINDOWS\system32\7E.tmp
C:\WINDOWS\system32\82.tmp
C:\WINDOWS\system32\wTR19
C:\Temp\dax41
E:\autorun.exe

KillAll::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

Sysrst::

Suspect::
Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions to copy/paste/send the requested file.
Hi, thank you very kindly for your reply :) Whether the trojan is fixed or not, thanks to you I have just discovered there's a Watchmen film coming out next year, which is good news at least!

I can't get my computer online at the moment, it might be the infection or it might be my dodgy wireless. I've copied the log file from my USB stick to my boyfriend's laptop to post:

ComboFix 08-09-16.05 - Anonymous Mute 2008-09-19 16:04:54.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.676 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Anonymous Mute\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.

2008-09-19 13:22 . 2008-09-19 13:22 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-19 13:22 . 2008-09-19 13:22 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Malwarebytes
2008-09-19 13:22 . 2008-09-19 13:22 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-19 13:22 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-19 13:22 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-19 13:21 . 2008-09-19 13:21 d——– C:\Program Files\Common Files\Download Manager
2008-09-19 13:03 . 2008-09-19 13:03 d——– C:\Program Files\ERUNT
2008-09-19 10:25 . 2008-09-19 10:25 d——– C:\Program Files\Trend Micro
2008-09-19 10:18 . 2008-09-19 10:18 0 –a—— C:\WINDOWS\system32\13.tmp
2008-09-19 10:17 . 2008-09-19 10:17 2,921 –a—— C:\WINDOWS\system32\rtc.dat
2008-09-19 10:17 . 2008-09-19 10:17 88 –a—— C:\WINDOWS\system32\F.tmp
2008-09-19 09:13 . 2008-09-19 16:02 d——– C:\Program Files\SUPERAntiSpyware
2008-09-19 09:13 . 2008-09-19 16:02 d——– C:\Documents and Settings\Anonymous Mute\Application Data\SUPERAntiSpyware.com
2008-09-19 09:13 . 2008-09-19 09:13 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-19 08:41 . 2008-09-19 09:12 d——– C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-09-18 21:53 . 2008-09-18 22:03 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-18 21:49 . 2006-05-25 15:52 162,304 –a—— C:\WINDOWS\system32\ztvunrar36.dll
2008-09-18 21:49 . 2003-02-02 20:06 153,088 –a—— C:\WINDOWS\system32\unrar3.dll
2008-09-18 21:49 . 2005-08-26 01:50 77,312 –a—— C:\WINDOWS\system32\ztvunace26.dll
2008-09-18 21:49 . 2002-03-06 01:00 75,264 –a—— C:\WINDOWS\system32\unacev2.dll
2008-09-18 21:49 . 2006-06-19 13:01 69,632 –a—— C:\WINDOWS\system32\ztvcabinet.dll
2008-09-18 21:48 . 2008-09-19 09:45 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Simply Super Software
2008-09-18 21:40 . 2008-09-18 21:40 d——– C:\Documents and Settings\Administrator\Application Data\HPAppData
2008-09-18 21:06 . 2008-09-18 21:06 d——– C:\Program Files\Lavasoft
2008-09-18 21:06 . 2008-09-18 21:08 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-18 20:39 . 2008-09-18 20:39 d——– C:\WINDOWS\ERUNT
2008-09-18 20:02 . 2008-09-18 20:04 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-18 20:02 . 2008-09-18 20:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-18 19:51 . 2008-09-19 16:02 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Autoruns
2008-09-18 19:26 . 2008-09-18 19:26 d——– C:\Program Files\CCleaner
2008-09-18 18:36 . 2008-09-18 18:36 d——– C:\Downloads
2008-09-18 18:36 . 2008-09-18 18:37 d——– C:\Documents and Settings\Anonymous Mute\Application Data\GetRightToGo
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\Temp\dax41
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\Temp
2008-09-18 17:10 . 2008-09-18 23:00 d–h—– C:\$AVG8.VAULT$
2008-09-17 10:18 . 2008-09-17 10:18 d——– C:\Program Files\iTunes
2008-09-17 10:18 . 2008-09-17 10:18 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Common Files\Apple
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Bonjour
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Apple Software Update
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-09-17 10:01 . 2008-09-17 10:01 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Apple Computer
2008-09-17 10:00 . 2008-09-17 10:18 d——– C:\Program Files\iPod
2008-09-17 10:00 . 2004-12-18 20:32 38,229 ——— C:\WINDOWS\system32\drivers\StMp3Rec.sys
2008-09-15 11:33 . 2008-09-15 11:33 d——– C:\Program Files\MSXML 4.0
2008-09-13 11:58 . 2008-09-13 11:58 d——– C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2008-09-12 18:04 . 2005-05-26 15:34 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2008-09-12 18:00 . 2008-09-12 18:00 d——– C:\Program Files\Microsoft Games
2008-09-09 12:33 . 2006-10-26 19:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2008-09-09 12:32 . 2008-09-09 12:32 d——– C:\Program Files\MSBuild
2008-09-09 12:32 . 2008-09-09 12:32 d——– C:\Program Files\Microsoft Works
2008-09-09 12:29 . 2008-09-09 12:31 d——– C:\WINDOWS\SHELLNEW
2008-09-09 12:28 . 2008-09-09 12:28 dr-h—– C:\MSOCache
2008-09-09 12:28 . 2008-09-15 11:37 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-09 12:11 . 2008-09-09 12:11 d——– C:\Program Files\uTorrent
2008-09-09 12:11 . 2008-09-18 18:42 d——– C:\Documents and Settings\Anonymous Mute\Application Data\uTorrent
2008-09-06 15:09 . 2008-09-06 15:09 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-09-01 14:10 . 2008-09-01 14:10 d——– C:\Program Files\Winamp Toolbar
2008-09-01 14:10 . 2008-09-01 14:10 d——– C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-09-01 14:09 . 2008-09-18 17:17 d——– C:\Program Files\Winamp Remote
2008-09-01 14:09 . 2008-09-01 14:12 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-08-29 21:53 . 2008-08-29 21:53 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Media Player Classic
2008-08-29 10:18 . 2008-08-29 10:18 87,336 –a—— C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 –a—— C:\WINDOWS\system32\dnssd.dll
2008-08-28 07:25 . 2008-08-28 07:42 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-26 16:33 . 2008-05-01 15:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-26 11:56 . 2008-09-19 15:59 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Affinegy
2008-08-26 11:51 . 2008-08-26 11:51 d——– C:\Program Files\WinPcap
2008-08-26 11:51 . 2008-05-26 16:09 27,072 –a—— C:\WINDOWS\system32\drivers\AFGSp50.sys
2008-08-26 11:50 . 2008-08-26 11:51 d——– C:\Program Files\Virgin Broadband Wireless
2008-08-26 11:50 . 2008-08-26 11:51 d——– C:\Documents and Settings\All Users\Application Data\Affinegy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 16:17 ——— d—–w C:\Program Files\QuickTime Alternative
2008-09-17 19:57 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\dvdcss
2008-09-17 09:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-12 17:04 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-12 16:58 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-09-01 13:11 ——— d—–w C:\Program Files\Winamp
2008-08-29 08:10 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 14:19 ——— d—–w C:\Program Files\Black Isle
2008-08-15 13:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-08-15 13:16 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\HP
2008-08-15 13:08 ——— d—–w C:\Program Files\HP
2008-08-15 13:08 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\HPAppData
2008-08-15 13:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-08-15 13:07 ——— d—–w C:\Program Files\Common Files\HP
2008-08-15 13:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-08-15 13:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2008-08-15 13:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-08-11 13:05 ——— d—–w C:\Program Files\Common Files\Motive
2008-08-11 13:04 ——— d—–w C:\Program Files\BroadJump
2008-07-25 08:49 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-07-25 08:49 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\SystemRequirementsLab
2008-07-23 17:55 ——— d—–w C:\Program Files\Bethesda Softworks
2008-07-08 12:45 114,812 —-a-w C:\WINDOWS\UninstallFirefox.exe
.

——- Sigcheck ——-

2007-06-13 11:23 1040896 c8b31abad6ff805b8523518bbf30fa0e C:\WINDOWS\explorer.exe
2007-06-13 12:26 1040896 cc66b4f6687ce1ec4b6323699cdb7243 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2001-08-23 13:00 1008640 bb52d95207f2a62e74eadd95ea62fc99 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 00:56 1039872 437d3c266afcff71493da4d93b119f31 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2004-08-04 00:56 1039872 0c32b430255559c08ed248ffe150120f C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2008-04-14 01:12 1041408 ffafdb19d4d95d6a2642561f04cecf68 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe
2007-06-13 11:23 1040896 3e6e83b5857ad75b825d27f12348c92c C:\WINDOWS\system32\dllcache\explorer.exe

2001-08-23 13:00 20992 d251ecfb24c053d1fc02f089d549402b C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2004-08-04 00:56 23040 738656e6cd41ced9984620573b658a02 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-14 01:12 23040 5bdd0885c900a8abd194efe178c8efa8 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 00:56 23040 e273553dad628deee738df0b802005b4 C:\WINDOWS\system32\ctfmon.exe

2005-06-11 01:17 65536 2ed7b15f45085d1fdaed38d6dbda06e1 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2001-08-23 13:00 58880 9f3b98fc030ad21d7bb2cd2a971cdffa C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 00:56 65536 5282516d73a172fa7d6fb6173c7c4788 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2004-08-04 00:56 65536 df95c84584886ac4911b6a16f9c0a3ed C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-14 01:12 65536 e5dad9026407ec59da31f4f3c4b400c9 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\spoolsv.exe
2005-06-11 00:53 65536 329566c51f9b520a0b38b1186396859a C:\WINDOWS\system32\spoolsv.exe

2001-08-23 13:00 29184 581b86fc07cb97da3ebcfe8255ca43a5 C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2004-08-04 00:56 32256 013ce0a33c846a2e88dcfdeed04932c2 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-14 01:12 33792 896d1f6cfbaac70b94224b7045047ae1 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 00:56 32256 bd51869c20f259975070db33bfe88c57 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2008-09-19_ 9.09.35.81 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 11:02:28 174,592 —-a-w C:\WINDOWS\erdnt\19-09-2008\ERDNT.EXE
+ 2008-09-19 12:04:20 3,522,560 —-a-w C:\WINDOWS\erdnt\19-09-2008\Users\00000001\NTUSER.DAT
+ 2008-09-19 12:04:20 20,480 —-a-w C:\WINDOWS\erdnt\19-09-2008\Users\00000002\UsrClass.dat
- 2008-08-07 15:27:04 174,592 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-08-07 15:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
- 2008-09-18 20:00:08 876,544 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-09-19 08:35:59 3,522,560 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
- 2008-09-18 20:00:08 8,192 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-09-19 08:35:59 20,480 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
- 2008-09-19 08:07:26 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-19 15:07:31 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-19 08:07:26 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-19 15:07:31 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-19 08:07:26 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-19 15:07:31 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.

2008-09-19 13:07 61440 C:\Documents and Settings\Anonymous Mute\Desktop\ATF-Cleaner.exe
2008-09-19 13:07 61440 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002946.exe

2008-09-19 09:03 6586904 C:\Documents and Settings\Anonymous Mute\Desktop\SUPERAntiSpywarePro.exe
2008-09-19 09:03 6586904 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002691.exe

2008-09-18 19:49 7472216 C:\Documents and Settings\Anonymous Mute\Desktop\trj671.exe
2008-09-18 19:49 7472216 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002689.exe

2008-09-18 21:52 7451712 C:\Documents and Settings\Anonymous Mute\Desktop\trsetup.exe
2008-09-18 21:52 7451712 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002688.exe

2008-09-19 08:10 568712 C:\Documents and Settings\Anonymous Mute\Desktop\WMIDiag.exe
2008-09-19 08:10 568712 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002687.exe

2002-09-17 01:25 4677703 C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
2002-09-17 01:25 4677703 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002708.exe
2002-09-17 01:25 4677703 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002862.exe

2002-12-04 11:03 62464 C:\Program Files\AMD\Athlon 64 Processor Driver\amdcon.exe
2002-12-04 11:03 62464 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002894.exe

2008-07-09 08:26 287000 C:\Program Files\AVG\AVG8\avgrsx.exe
2008-07-09 08:26 287000 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002645.exe
2008-07-09 08:26 287000 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003056.exe

2008-08-29 09:10 1235736 C:\Program Files\AVG\AVG8\avgtray.exe
2008-08-29 09:10 1235736 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002663.exe
2008-08-29 09:10 1235736 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003064.exe

2008-08-29 09:10 2813720 C:\Program Files\AVG\AVG8\avgui.exe
2008-08-29 09:10 2813720 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002730.exe

2008-08-29 07:47 641304 C:\Program Files\AVG\AVG8\avgupd.exe
2008-08-29 07:47 641304 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002903.exe
2008-08-29 07:47 641304 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003073.exe

2008-08-29 09:10 231704 C:\Program Files\AVG\AVG8\avgwdsvc.exe
2008-08-29 09:10 231704 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002657.exe
2008-08-29 09:10 231704 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003047.exe

2008-08-29 09:10 222488 C:\Program Files\AVG\AVG8\fixcfg.exe
2008-08-29 09:10 222488 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002904.exe
2008-08-29 09:10 222488 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003075.exe

2008-08-29 09:10 2546968 C:\Program Files\AVG\AVG8\setup.exe
2008-08-29 09:10 2546968 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002731.exe
2008-08-29 09:10 2546968 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002864.exe

2007-04-16 11:14 7557120 C:\Program Files\Bethesda Softworks\Oblivion\Oblivion.exe
2007-04-16 11:14 7557120 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002649.exe
2007-04-16 11:14 7557120 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002684.exe

2006-04-06 11:25 1671168 C:\Program Files\Bethesda Softworks\Oblivion\OblivionLauncher.exe
2006-04-06 11:25 1671168 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002732.exe

1999-04-21 13:07 710144 C:\Program Files\Black Isle\Baldur's Gate\Config.exe
1999-04-21 13:07 710144 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002734.exe

2001-05-04 15:05 4167743 C:\Program Files\Black Isle\BGII - SoA\ArcadeInstallBG2TOB101b.exe
2001-05-04 15:05 4167743 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002738.exe

2001-05-09 20:02 3471872 C:\Program Files\Black Isle\BGII - SoA\baldur.exe
2001-05-09 20:02 3471872 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002865.exe

2001-07-30 14:21 1448448 C:\Program Files\Black Isle\BGII - SoA\BGConfig.exe
2001-07-30 14:21 1448448 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002736.exe

2001-06-28 14:09 867328 C:\Program Files\Black Isle\BGII - SoA\CharView.exe
2001-06-28 14:09 867328 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002737.exe

2008-08-29 10:18 238888 C:\Program Files\Bonjour\mDNSResponder.exe
2008-08-29 10:18 238888 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002658.exe
2008-08-29 10:18 238888 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003048.exe

2003-01-27 17:16 385104 C:\Program Files\BroadJump\Client Foundation\CFD.exe
2003-01-27 17:16 385104 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002665.exe
2003-01-27 17:16 385104 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003065.exe

2008-08-22 18:26 1234160 C:\Program Files\CCleaner\CCleaner.exe
2008-08-22 18:26 1234160 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002866.exe

2008-09-10 16:50 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
2008-09-10 16:50 116040 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002656.exe
2008-09-10 16:50 116040 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003046.exe

2005-04-04 00:41 786432 C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriver.exe
2005-04-04 00:41 786432 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002773.exe

2001-08-23 13:00 47616 C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe
2001-08-23 13:00 47616 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002727.exe
2001-08-23 13:00 47616 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002994.exe

2006-10-26 20:12 87352 C:\Program Files\Common Files\Microsoft Shared\MSInfo\OINFOP12.EXE
2006-10-26 20:12 87352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002995.EXE

2005-12-10 15:57 133016 C:\Program Files\DAEMON Tools\daemon.exe
2005-12-10 15:57 133016 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002740.exe

2008-07-08 13:46 102294 C:\Program Files\DAEMON Tools\uninst.exe
2008-07-08 13:46 102294 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002741.exe

2005-10-20 12:04 48640 C:\Program Files\ERUNT\AUTOBACK.EXE
2005-10-20 12:04 38912 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002868.EXE

2005-10-20 12:00 168960 C:\Program Files\ERUNT\ERUNT.EXE
2005-10-20 12:00 168960 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002742.EXE
2005-10-20 12:00 168960 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002869.EXE

2005-10-20 12:03 151552 C:\Program Files\ERUNT\NTREGOPT.EXE
2005-10-20 12:03 151552 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002743.EXE
2005-10-20 12:03 151552 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002870.EXE

2004-06-27 01:00 77257 C:\Program Files\ERUNT\unins000.exe
2004-06-27 01:00 77257 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002744.exe
2004-06-27 01:00 77257 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002871.exe

2007-03-16 03:58 1099352 C:\Program Files\HP\Digital Imaging\{F5936267-D467-4e7b-8940-A7D9F0398EF3}\setup\hpzscr01.exe
2007-03-16 03:58 1099352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002762.exe
2007-03-16 03:58 1099352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002895.exe

2007-03-11 21:27 689752 C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
2007-03-11 21:27 689752 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002761.exe

2007-03-16 03:58 1099352 C:\Program Files\HP\Digital Imaging\devicemanagement\hpzscr01.exe
2007-03-16 03:58 1099352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002873.exe

2007-03-16 03:58 1099352 C:\Program Files\HP\Digital Imaging\esupport\hpzscr01.exe
2007-03-16 03:58 1099352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002875.exe

2007-03-16 03:58 1099352 C:\Program Files\HP\Digital Imaging\extcapuninstall\hpzscr01.exe
2007-03-16 03:58 1099352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002876.exe

2007-03-16 03:58 1099352 C:\Program Files\HP\Digital Imaging\photosmartessential\hpzscr01.exe
2007-03-16 03:58 1099352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002874.exe

2007-03-11 21:34 233472 C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbui.exe
2007-03-11 21:34 233472 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002757.exe

2007-03-11 21:34 57344 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
2007-03-11 21:34 57344 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003012.exe

2005-04-07 02:39 121064 C:\Program Files\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe
2005-04-07 02:39 121064 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002733.exe

2000-10-06 01:00 61952 C:\Program Files\InstallShield Installation Information\{B8C3B479-1716-11D5-968A-0050BA84F5F7}\Setup.exe
2000-10-06 01:00 61952 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002739.exe

2004-08-04 00:56 222208 C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe
2004-08-04 00:56 222208 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002988.exe

2004-08-04 00:56 94208 C:\Program Files\Internet Explorer\Connection Wizard\icwconn2.exe
2004-08-04 00:56 94208 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002989.exe

2004-08-04 00:56 32768 C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exe
2004-08-04 00:56 32768 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002990.exe

2001-08-23 13:00 81920 C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exe
2001-08-23 13:00 81920 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002991.exe

2004-08-04 00:56 28672 C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exe
2004-08-04 00:56 28672 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002992.exe

2001-08-23 13:00 24576 C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe
2001-08-23 13:00 24576 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002993.exe

2007-08-13 18:44 76800 C:\Program Files\Internet Explorer\iedw.exe
2007-08-13 18:44 76800 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002987.exe

2008-06-23 10:20 633344 C:\Program Files\Internet Explorer\iexplore.exe
2008-06-23 10:20 633344 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002695.exe
2008-06-23 10:20 633344 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003058.exe

2008-09-10 17:39 536872 C:\Program Files\iPod\bin\iPodService.exe
2008-09-10 17:39 536872 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002857.exe
2008-09-10 17:39 536872 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003074.exe

2005-03-22 23:36 47677440 C:\Program Files\iPod\iPod Updater 2005-03-23\iPod Updater 2005-03-23.exe
2005-03-22 23:36 47677440 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002765.exe

2008-09-10 17:40 289576 C:\Program Files\iTunes\iTunesHelper.exe
2008-09-10 17:40 289576 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002669.exe
2008-09-10 17:40 289576 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003022.exe

2004-02-22 23:44 41073 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
2004-02-22 23:44 41073 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003014.exe

2008-09-18 21:07 611664 C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
2008-09-18 21:07 611664 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002644.exe

2008-09-18 21:07 3165000 C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
2008-09-18 21:07 3165000 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002706.exe

2008-05-12 13:45 468312 C:\Program Files\Lavasoft\Ad-Aware\threatwork.exe
2008-05-12 13:45 468312 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002768.exe

2008-09-10 00:03 380080 C:\Program Files\Malwarebytes' Anti-Malware\mbam-dor.exe
2008-09-10 00:03 380080 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002881.exe

2008-09-10 00:03 1261232 C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
2008-09-10 00:03 1261232 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002770.exe
2008-09-10 00:03 1261232 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002882.exe

2008-09-10 00:03 118448 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
2008-09-10 00:03 110256 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002883.exe

2008-09-10 00:03 380592 C:\Program Files\Malwarebytes' Anti-Malware\mbamtrayctrl.exe
2008-09-10 00:03 372400 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002884.exe

2008-09-19 13:21 688816 C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe
2008-09-19 13:21 688816 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002771.exe
2008-09-19 13:21 688816 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002885.exe

2004-10-13 17:24 1701888 C:\Program Files\Messenger\msmsgs.exe
2004-10-13 17:24 1701888 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002714.exe
2004-10-13 17:24 1701888 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003085.exe

2007-08-07 09:22 9710464 C:\Program Files\Microsoft Games\Age of Empires III\age3.exe
2007-08-07 09:22 9710464 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002772.exe

2007-08-24 07:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
2007-08-24 07:00 33648 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002667.exe
2007-08-24 07:00 33648 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003067.exe

2007-04-19 14:49 1661280 C:\Program Files\Microsoft Office\PowerPoint Viewer\PPTVIEW.EXE
2007-04-19 14:49 1661280 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003087.EXE

2004-08-04 00:56 3563008 C:\Program Files\Movie Maker\moviemk.exe
2004-08-04 00:56 3563008 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002716.exe

2008-07-21 13:41 307712 C:\Program Files\Mozilla Firefox\firefox.exe
2008-07-21 13:41 307712 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002648.exe
2008-07-21 13:41 307712 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002940.exe

2008-07-21 13:41 507568 C:\Program Files\Mozilla Firefox\uninstall\helper.exe
2008-07-21 13:41 507568 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002947.exe

2001-08-23 13:00 50257 C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe
2001-08-23 13:00 50257 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002747.exe

2001-08-23 13:00 50255 C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe
2001-08-23 13:00 50255 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002748.exe

2001-08-23 13:00 50253 C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe
2001-08-23 13:00 50253 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002749.exe

2001-08-23 13:00 50254 C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe
2001-08-23 13:00 50254 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002750.exe

2001-08-23 13:00 50253 C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe
2001-08-23 13:00 50253 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002751.exe

2004-08-04 00:56 68096 C:\Program Files\Outlook Express\msimn.exe
2004-08-04 00:56 68096 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002696.exe

2004-08-04 00:56 53760 C:\Program Files\Outlook Express\wab.exe
2004-08-04 00:56 53760 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002699.exe

2008-09-06 15:09 421888 C:\Program Files\QuickTime Alternative\QTTask.exe
2008-09-06 15:09 421888 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002668.exe
2008-09-06 15:09 421888 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003068.exe

2005-11-18 01:00 670720 C:\Program Files\QuickTime Alternative\QuickTimePlayer.exe
2005-11-18 01:00 670720 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002887.exe

2008-07-08 13:40 694033 C:\Program Files\QuickTime Alternative\unins000.exe
2008-07-08 13:40 694033 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002786.exe

2008-04-22 10:18 4349952 C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe
2008-04-22 10:18 4349952 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002787.exe
2008-04-22 10:18 4349952 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002888.exe

2008-07-15 14:12 730510 C:\Program Files\Real Alternative\unins000.exe
2008-07-15 14:12 730510 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002788.exe

2008-07-07 09:42 4891472 C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
2008-07-07 09:42 4891472 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002893.exe

C:\Program Files\SUPERAntiSpyware\BootSafe.exe
2007-10-02 14:08 130360 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002858.exe
2007-10-02 14:08 130360 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002907.exe

C:\Program Files\SUPERAntiSpyware\SASINST.EXE
2008-03-12 11:29 32256 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002859.EXE
2008-03-12 11:29 32256 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002908.EXE

C:\Program Files\SUPERAntiSpyware\SSUpdate.exe
2008-09-03 14:07 167152 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002856.exe
2008-09-03 14:07 167152 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002909.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
2008-09-03 14:07 1584368 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002672.exe
2008-09-03 14:07 1584368 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002842.exe

2008-09-19 10:25 404480 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
2008-09-19 10:25 404480 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002756.exe
2008-09-19 10:25 404480 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002872.exe

2008-09-09 12:11 267056 C:\Program Files\uTorrent\uTorrent.exe
2008-09-09 12:11 267056 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002693.exe
2008-09-09 12:11 267056 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003024.exe

2008-06-03 21:44 103424 C:\Program Files\VideoLAN\VLC\vlc.exe
2008-06-03 21:44 103424 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002774.exe
2008-06-03 21:44 103424 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002889.exe

2008-05-26 16:09 57540 C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
2008-05-26 16:09 57540 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002700.exe
2008-05-26 16:09 57540 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003070.exe

2008-05-26 16:20 593920 C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe
2008-05-26 16:20 593920 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002666.exe
2008-05-26 16:20 593920 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003066.exe

2008-05-26 16:09 1107968 C:\Program Files\Virgin Broadband Wireless\wpa_supplicant.exe
2008-05-26 16:09 1107968 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003071.exe

2008-04-01 02:54 516096 C:\Program Files\Winamp Remote\bin\OrbTray.exe
2008-04-01 02:54 516096 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003013.exe

2008-09-01 14:10 64577 C:\Program Files\Winamp Toolbar\uninstall.exe
2008-09-01 14:10 64577 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002891.exe

2006-02-16 17:26 81920 C:\Program Files\Winamp\eMusic\EMusicClient.exe
2006-02-16 17:26 81920 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002694.exe
2006-02-16 17:26 81920 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002867.exe

2008-08-04 00:04 1345376 C:\Program Files\Winamp\winamp.exe
2008-08-04 00:04 1345376 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002890.exe

2008-08-04 00:02 44032 C:\Program Files\Winamp\winampa.exe
2008-08-04 00:02 44032 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003016.exe

2004-08-04 00:56 12319 C:\Program Files\Windows Media Player\mplayer2.exe
2004-08-04 00:56 12319 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002880.exe

2004-08-04 00:56 782336 C:\Program Files\Windows Media Player\setup_wm.exe
2004-08-04 00:56 782336 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003084.exe

2004-08-04 00:56 81920 C:\Program Files\Windows Media Player\wmplayer.exe
2004-08-04 00:56 81920 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002698.exe
2004-08-04 00:56 81920 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002948.exe

2004-08-04 00:56 222208 C:\Program Files\Windows NT\Accessories\wordpad.exe
2004-08-04 00:56 222208 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002717.exe

2001-08-23 13:00 35840 C:\Program Files\Windows NT\hypertrm.exe
2001-08-23 13:00 35840 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002719.exe

2004-08-04 00:56 288768 C:\Program Files\Windows NT\Pinball\pinball.exe
2004-08-04 00:56 288768 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002753.exe

2008-05-26 16:07 94208 C:\Program Files\WinPcap\rpcapd.exe
2008-05-26 16:07 94208 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002660.exe
2008-05-26 16:07 94208 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003052.exe

2005-04-22 15:08 890368 C:\Program Files\WinRAR\WinRAR.exe
2005-04-22 15:08 890368 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002892.exe

2005-06-11 01:17 65536 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-11 01:17 65536 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003097.exe

2007-06-13 12:26 1040896 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 12:26 1040896 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003092.exe

2004-08-04 00:56 65536 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2004-08-04 00:56 65536 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003098.exe

2004-08-04 00:56 1039872 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2004-08-04 00:56 1039872 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003093.exe

2007-06-13 11:23 1040896 C:\WINDOWS\explorer.exe
2007-06-13 11:23 1040896 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002674.exe
2007-06-13 11:23 1040896 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002980.exe

2005-05-27 00:22 18432 C:\WINDOWS\hh.exe
2005-05-27 00:22 18432 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002760.exe
2005-05-27 00:22 18432 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003082.exe

2004-08-04 00:56 217088 C:\WINDOWS\inf\unregmp2.exe
2004-08-04 00:56 217088 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003089.exe

2008-08-15 14:08 8854 C:\WINDOWS\Installer\{415CDA53-9100-476F-A7B2-476691E117C7}\Uninstall_Smart_Web__2DD09EA994C6415885A0C8BB7A14CB08.exe
2008-08-15 14:08 8854 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002764.exe

2008-09-17 10:18 102400 C:\WINDOWS\Installer\{41B9E2CF-0B3F-442A-B5B3-592A4A355634}\iTunesIco.exe
2008-09-17 10:18 102400 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002766.exe

2008-08-15 14:08 25214 C:\WINDOWS\Installer\{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}\ARPPRODUCTICON.exe
2008-08-15 14:08 25214 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002901.exe

2008-08-15 14:08 25214 C:\WINDOWS\Installer\{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}\hpqSSupply.exe
2008-08-15 14:08 25214 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002759.exe

2008-09-17 10:17 27136 C:\WINDOWS\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
2008-09-17 10:17 27136 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002709.exe

2008-09-12 18:04 69632 C:\WINDOWS\Installer\{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}\ARPPRODUCTICON.exe
2008-09-12 18:04 69632 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002877.exe

2008-08-15 14:08 25214 C:\WINDOWS\Installer\{8389382B-53BA-4A87-8854-91E3D80A5AC7}\NewShortcut1_8389382B53BA4A87885491E3D80A5AC7.exe
2008-08-15 14:08 25214 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002763.exe

2008-08-15 14:08 73728 C:\WINDOWS\Installer\{8C6027FD-53DC-446D-BB75-CACD7028A134}\ARPPRODUCTICON.exe
2008-08-15 14:08 73728 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002902.exe

2008-08-15 14:08 689720 C:\WINDOWS\Installer\{8C6027FD-53DC-446D-BB75-CACD7028A134}\HPSUShortcut_BB85ED9CAFC943BDB8DC258C3C7DF72E.exe
2008-08-15 14:08 689720 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002758.exe

2008-09-15 11:36 1165584 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
2008-09-15 11:36 1165584 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002775.exe

2008-09-15 11:36 20240 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
2008-09-15 11:36 20240 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002784.exe

2008-09-15 11:36 159504 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
2008-09-15 11:36 159504 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002777.exe

2008-09-15 11:36 184080 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
2008-09-15 11:36 184080 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002778.exe

2008-09-15 11:36 217864 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
2008-09-15 11:36 217864 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002783.exe

2008-09-15 11:36 35088 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
2008-09-15 11:36 35088 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002785.exe

2008-09-15 11:36 845584 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
2008-09-15 11:36 845584 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002779.exe

2008-09-15 11:36 922384 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
2008-09-15 11:36 922384 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002780.exe

2008-09-15 11:36 272648 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
2008-09-15 11:36 272648 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002781.exe

2008-09-15 11:36 888080 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
2008-09-15 11:36 888080 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002782.exe

2008-09-15 11:36 1172240 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
2008-09-15 11:36 1172240 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002650.exe
2008-09-15 11:36 1172240 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002776.exe

2008-09-12 08:31 49152 C:\WINDOWS\Installer\{90840409-6000-11D3-8CFE-0150048383C9}\xlvicon.exe
2008-09-12 08:31 49152 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002710.exe
2008-09-12 08:31 49152 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002898.exe

2008-09-12 08:31 49152 C:\WINDOWS\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\wrdvicon.exe
2008-09-12 08:31 49152 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002712.exe
2008-09-12 08:31 49152 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002899.exe

2008-07-08 13:41 40960 C:\WINDOWS\Installer\{90AF0409-6000-11D3-8CFE-0150048383C9}\ppvwicon.exe
2008-07-08 13:41 40960 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002711.exe
2008-07-08 13:41 40960 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002900.exe

C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF1.exe
2008-09-19 09:13 41984 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002928.exe

1998-10-29 16:45 314368 C:\WINDOWS\IsUninst.exe
1998-10-29 16:45 314368 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002735.exe

2006-10-12 12:09 264192 C:\WINDOWS\msagent\agentsvr.exe
2006-10-12 12:09 264192 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003090.exe

2004-08-04 00:56 154112 C:\WINDOWS\regedit.exe
2004-08-04 00:56 154112 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003031.exe

2004-08-04 00:56 23040 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2004-08-04 00:56 23040 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003096.exe

2004-08-04 00:56 1039872 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 00:56 1039872 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002767.exe
2004-08-04 00:56 1039872 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003094.exe

2004-08-04 00:56 65536 C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2004-08-04 00:56 65536 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003099.exe

2004-08-04 00:56 32256 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2004-08-04 00:56 32256 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003100.exe

2005-06-20 14:42 86016 C:\WINDOWS\soundman.exe
2005-06-20 14:42 86016 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002896.exe
2005-06-20 14:42 86016 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002964.exe

2004-08-04 00:56 191488 C:\WINDOWS\system32\accwiz.exe
2004-08-04 00:56 191488 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002718.exe
2004-08-04 00:56 191488 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002942.exe

2001-08-23 13:00 18944 C:\WINDOWS\system32\attrib.exe
2001-08-23 13:00 18944 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002959.exe

2001-08-23 13:00 88064 C:\WINDOWS\system32\charmap.exe
2001-08-23 13:00 88064 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002724.exe

2004-08-04 00:56 71680 C:\WINDOWS\system32\cleanmgr.exe
2004-08-04 00:56 71680 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002725.exe

2004-08-04 00:56 396288 C:\WINDOWS\system32\cmd.exe
2004-08-04 00:56 396288 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002675.exe
2004-08-04 00:56 396288 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003054.exe

2004-08-03 22:59 17408 C:\WINDOWS\system32\comsdupd.exe
2004-08-03 22:59 17408 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002943.exe
2004-08-03 22:59 17408 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002999.exe

2004-08-04 00:56 106496 C:\WINDOWS\system32\cscript.exe
2004-08-04 00:56 106496 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002984.exe

2004-08-04 00:56 23040 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 00:56 23040 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002671.exe
2004-08-04 00:56 23040 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002997.exe

2001-08-23 13:00 20634 C:\WINDOWS\system32\debug.exe
2001-08-23 13:00 20634 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003028.exe

2007-06-13 11:23 1040896 C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 11:23 1040896 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003095.exe

2001-08-23 13:00 16896 C:\WINDOWS\system32\find.exe
2001-08-23 13:00 16896 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002958.exe
2001-08-23 13:00 16896 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003005.exe

2004-08-04 00:56 34816 C:\WINDOWS\system32\findstr.exe
2004-08-04 00:56 34816 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002676.exe
2004-08-04 00:56 34816 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003061.exe

2006-08-21 10:14 30720 C:\WINDOWS\system32\fltmc.exe
2006-08-21 10:14 30720 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003088.exe

2001-08-23 13:00 62976 C:\WINDOWS\system32\freecell.exe
2001-08-23 13:00 62976 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002745.exe

2004-08-04 00:56 47104 C:\WINDOWS\system32\grpconv.exe
2004-08-04 00:56 47104 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002956.exe

2008-06-23 10:20 78336 C:\WINDOWS\system32\ie4uinit.exe
2008-06-23 10:20 78336 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003078.exe

2008-06-23 10:20 21504 C:\WINDOWS\system32\ieudinit.exe
2008-06-23 10:20 21504 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003079.exe

2004-08-04 00:56 157696 C:\WINDOWS\system32\imapi.exe
2004-08-04 00:56 157696 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002852.exe
2004-08-04 00:56 157696 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002983.exe

2004-08-04 00:56 63488 C:\WINDOWS\system32\ipconfig.exe
2004-08-04 00:56 63488 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002685.exe
2004-08-04 00:56 63488 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003059.exe

2004-08-04 00:56 522240 C:\WINDOWS\system32\logonui.exe
2004-08-04 00:56 522240 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003034.exe

2008-07-15 08:52 70264 C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
2008-07-15 08:52 70264 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002863.exe

2004-08-04 00:56 80384 C:\WINDOWS\system32\magnify.exe
2004-08-04 00:56 80384 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002703.exe

2004-08-04 00:56 822784 C:\WINDOWS\system32\mmc.exe
2004-08-04 00:56 822784 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002986.exe

2004-08-04 00:56 151040 C:\WINDOWS\system32\mobsync.exe
2004-08-04 00:56 151040 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002701.exe

2008-08-26 21:28 16208504 C:\WINDOWS\system32\MRT.exe
2008-08-26 21:28 16208504 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003080.exe

2001-08-23 13:00 134656 C:\WINDOWS\system32\mshearts.exe
2001-08-23 13:00 134656 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002746.exe

2005-05-04 14:45 86528 C:\WINDOWS\system32\msiexec.exe
2005-05-04 14:45 86528 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002769.exe
2005-05-04 14:45 86528 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003086.exe

2004-08-04 00:56 350720 C:\WINDOWS\system32\mspaint.exe
2004-08-04 00:56 350720 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002715.exe

2004-08-03 22:59 415232 C:\WINDOWS\system32\mstsc.exe
2004-08-03 22:59 415232 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002720.exe

2004-08-04 00:56 61440 C:\WINDOWS\system32\narrator.exe
2004-08-04 00:56 61440 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002704.exe

2004-08-04 00:56 132608 C:\WINDOWS\system32\net1.exe
2004-08-04 00:56 132608 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002998.exe

2004-08-04 00:56 76800 C:\WINDOWS\system32\notepad.exe
2004-08-04 00:56 76800 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002952.exe

2004-08-04 00:56 1207808 C:\WINDOWS\system32\ntbackup.exe
2004-08-04 00:56 1207808 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002723.exe

2007-02-28 09:38 2057600 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 09:38 2057600 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003030.exe
2007-02-28 09:38 2057600 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003081.exe

2007-02-28 10:10 2180352 C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 10:10 2180352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002647.exe
2007-02-28 10:10 2180352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003077.exe

2008-05-16 14:01 768544 C:\WINDOWS\system32\nvcplui.exe
2008-05-16 14:01 768544 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002860.exe

2008-05-16 14:01 168004 C:\WINDOWS\system32\nvsvc32.exe
2008-05-16 14:01 168004 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002659.exe
2008-05-16 14:01 168004 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003051.exe

2008-05-16 11:48 454656 C:\WINDOWS\system32\NVUNINST.EXE
2008-05-16 11:48 454656 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003008.EXE

2004-08-04 00:56 40960 C:\WINDOWS\system32\odbcad32.exe
2004-08-04 00:56 40960 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002729.exe

2004-08-04 00:56 223232 C:\WINDOWS\system32\osk.exe
2004-08-04 00:56 223232 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002705.exe

2004-08-04 00:56 25600 C:\WINDOWS\system32\ping.exe
2004-08-04 00:56 25600 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002961.exe

2001-08-23 13:00 19456 C:\WINDOWS\system32\rasautou.exe
2001-08-23 13:00 19456 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003000.exe

2004-08-04 00:56 43520 C:\WINDOWS\system32\rcimlby.exe
2004-08-04 00:56 43520 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002697.exe

2004-08-04 00:56 19456 C:\WINDOWS\system32\regsvr32.exe
2004-08-04 00:56 19456 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003001.exe

2004-08-04 00:56 388096 C:\WINDOWS\system32\Restore\rstrui.exe
2004-08-04 00:56 388096 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002728.exe

2001-08-23 13:00 27648 C:\WINDOWS\system32\route.exe
2001-08-23 13:00 27648 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002639.exe
2001-08-23 13:00 27648 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0002973.exe

2001-08-23 13:00 33280 C:\WINDOWS\system32\routemon.exe
2001-08-23 13:00 33280 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003004.exe

2004-08-04 00:56 40960 C:\WINDOWS\system32\rundll32.exe
2004-08-04 00:56 40960 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002664.exe
2004-08-04 00:56 40960 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003050.exe

2004-08-04 00:56 22016 C:\WINDOWS\system32\runonce.exe
2004-08-04 00:56 22016 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP5\A0002955.exe

2004-08-04 00:56 139264 C:\WINDOWS\system32\sndrec32.exe
2004-08-04 00:56 139264 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002721.exe

2001-08-23 13:00 146432 C:\WINDOWS\system32\sndvol32.exe
2001-08-23 13:00 146432 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002722.exe

2001-08-23 13:00 64512 C:\WINDOWS\system32\sol.exe
2001-08-23 13:00 64512 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002754.exe

2001-08-23 13:00 31232 C:\WINDOWS\system32\sort.exe
2001-08-23 13:00 31232 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002642.exe
2001-08-23 13:00 31232 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003062.exe

2004-08-04 00:56 546304 C:\WINDOWS\system32\spider.exe
2004-08-04 00:56 546304 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002755.exe

2004-08-04 00:56 19456 C:\WINDOWS\system32\spnpinst.exe
2004-08-04 00:56 19456 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003002.exe

2005-06-11 00:53 65536 C:\WINDOWS\system32\spoolsv.exe
2005-06-11 00:53 65536 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003027.exe
2005-06-11 00:53 65536 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003083.exe

2004-08-04 00:56 113664 C:\WINDOWS\system32\sysocmgr.exe
2004-08-04 00:56 113664 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003025.exe

2001-08-23 13:00 19968 C:\WINDOWS\system32\tcmsetup.exe
2001-08-23 13:00 19968 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003003.exe

2004-08-04 00:56 354816 C:\WINDOWS\system32\tourstart.exe
2004-08-04 00:56 354816 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002702.exe

2004-08-04 00:56 32256 C:\WINDOWS\system32\userinit.exe
2004-08-04 00:56 32256 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002673.exe
2004-08-04 00:56 32256 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003091.exe

2004-08-04 00:56 247808 C:\WINDOWS\system32\usmt\migwiz.exe
2004-08-04 00:56 247808 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002726.exe

2006-03-17 01:38 36352 C:\WINDOWS\system32\verclsid.exe
2006-03-17 01:38 36352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002846.exe
2006-03-17 01:38 36352 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003063.exe

2001-08-23 13:00 15872 C:\WINDOWS\system32\winhlp32.exe
2001-08-23 13:00 15872 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003026.exe

2001-08-23 13:00 127488 C:\WINDOWS\system32\winmine.exe
2001-08-23 13:00 127488 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002752.exe

2004-08-04 00:56 21504 C:\WINDOWS\system32\wscntfy.exe
2004-08-04 00:56 21504 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002643.exe
2004-08-04 00:56 21504 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002680.exe

2004-08-04 00:56 122880 C:\WINDOWS\system32\wscript.exe
2004-08-04 00:56 122880 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002651.exe
2004-08-04 00:56 122880 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002686.exe

2008-07-18 22:10 53448 C:\WINDOWS\system32\wuauclt.exe
2008-07-18 22:10 53448 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002861.exe
2008-07-18 22:10 53448 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003069.exe

2001-08-23 13:00 39936 C:\WINDOWS\system32\wupdmgr.exe
2001-08-23 13:00 39936 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP4\A0002707.exe

2004-08-04 00:56 38400 C:\WINDOWS\system32\xcopy.exe
2004-08-04 00:56 38400 {B26A1D7C-CE24-4EFF-8A4B-A3E113D05086}\RP6\A0003009.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 1235736]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 385104]
"Wireless Manager"="C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 593920]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="C:\Program Files\QuickTime Alternative\QTTask.exe" [2008-09-06 421888]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 23040]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Micronet Wireless Network Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Micronet Wireless Network Utility.lnk
backup=C:\WINDOWS\pss\Micronet Wireless Network Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SATARAID5.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SATARAID5.lnk
backup=C:\WINDOWS\pss\SATARAID5.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 00:56 23040 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2007-03-11 21:34 57344 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2008-05-16 14:01 13529088 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2008-05-16 14:01 86016 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
–a—— 2008-04-01 02:54 516096 C:\Program Files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2004-02-22 23:44 41073 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-08-04 00:02 44032 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2008-05-16 14:01 1638400 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra—— 2005-06-20 14:42 86016 C:\WINDOWS\soundman.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Black Isle\\Baldur's Gate\\BGMain2.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Black Isle\\BGII - SoA\\BGMain.exe"=
"C:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2005-02-12 16640]
R0 Si3132r5;SiI-3132 SoftRaid 5 Controller;C:\WINDOWS\system32\DRIVERS\Si3132r5.sys [2005-04-19 181760]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 AffinegyService;AffinegyService;C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe [2008-05-26 151552]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R3 AFGSp50;AFGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AFGSp50.sys [2008-05-26 27072]
S3 AFGMp50;AFGMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AFGMp50.sys [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 16:07:51
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\ComboFix\pv.cfexe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-09-19 16:10:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 15:10:38
ComboFix2.txt 2008-09-19 14:57:16
ComboFix3.txt 2008-09-19 08:10:08

Pre-Run: 93,105,135,616 bytes free
Post-Run: 93,033,869,312 bytes free

764 — E O F — 2008-09-15 10:37:32
Hello

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\13.tmp
C:\WINDOWS\system32\rtc.dat
C:\WINDOWS\system32\F.tmp

Folder::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Please do an online scan with Kaspersky WebScanner

Make sure you are using Internet Explorer for this. Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI