This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Ongoing problem description and HJT log

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Where to start? I realized that I had a problem back in August when I was going to do a system restore and found all the restore points wiped out.

The first thing I did back then was to turn off system restore…no point in having it on as it was obviously compromised.

I immediately did scans with HJT, AVG AV, Spybot Search & Destroy, AdAware, and CCleaner (I run CCleaner several times a wekk so this was just to give me an uncluttered view of what might be going on.).

During this, I found that I couldn't update AVG or Microsoft Windows and Office, that the auto-updaters were turned off, and that I could not turn them back on again. A friend that is professionally in tech support suggested that I go to TrendMicro's site and run HouseCall. The scan found active spyware and greyware, however, there was one it couldn't fix and could not provide any information on it or how to remove it.

Possible_SCRDL

C:\Documents and Settings\The Cat\Local Settings\Temporary Internet Files\Content.IE5\IKZ91XPU\xpsp2install[1].htm



I tend to try and help myself before asking for help…that's usually my last resort. There was "weird" stuff on the HJT log that looked suspicious to me. So I browsed several help forums trying to find anything that resembled my problem. I noted in one that there was an issue where HJT wouldn't be able to pick up all the problems because they were tailoring to hide from certain "fix" software. It was suggested to rename the executable, which I did. Found even more strange 'stuff'. At this point I realized I was over my head and would need help. Posted all this information as well as letting them know that there were several "fix" sites that I could not access and posted a HJT log.

Based on the following it was determined that I had a variation of the Vundo rootkit. I was directed to use Malwarebyte's AntiMalware with excellent directions on how to go about doing so and letting the program fix the problem.



O20 - AppInit_DLLs: avgrsstx.dll zfshzt.dll xvgaxg.dll uqrzdo.dll wfhdxn.dll

O20 - Winlogon Notify: byXPFUKb - C:\WINDOWS\SYSTEM32\byXPFUKb.dll



I did that and then posted another HJT log. While waiting for an answer, I ran a Combofix scan just to see how it worked – only ran the scan didn't do anything other than post to ask if the scan log would be helpful.

This was back on September 1st and 2nd. I have yet to hear back from them. Another thing I did while I was waiting was to go to Runscanner.net and run a scan there as well. The report is no longer there, so you can't see the results even if you wanted to. But I did post the URL in the forum.

When I didn't hear back, I fixed as much as I could and posted another HJT log asking if it was clear yet. That was September 6th. Still haven't heard back.

Anyway, it seemed as though my machine was working better and no recent scans show anything other than cookies and some adware that is easily taken care of. However, it seems that every website I go to has the indication that there are errors on the page. Now one or two, I would assume that the website actually do have issues, but all of them just didn't make sense. Even this forum gives me the "Done, but with errors on page" message. I have looked at the Downloaded Program Files folder where the ActiveX files are stored looking over the properties and found that whereever there is a dependency listed, it doesn't mention what the dependency is only that it's damaged.

I also know that the suspicious .dll files prior to fixing anything were in the System32 folder, therefore, last night I looked through the folder and found 5 more randomly named .dll files where I had thought that this problem had been fixed. They have to be coming from somewhere and apparently that somewhere has not been fixed yet.

So here is my most current HJT log. I would like to note that there is a running process that is visible in task manager that isn't being picked up by HJT. It's an instance of iexplorer.exe running when there is no browser open.

Additionally, while I had had some sites in my "trusted zones" I found that HJT was hanging up on "015 Trusted Zone Enumeration" thus I removed them from the zone. Apparently it made no difference because HJT is still hanging up there. It's only for a few minutes and eventually gets past it, but it never used to do that before.

I hope this wasn't too much information. I thought it might be better to give too much than not enough, however, I did try not to give so much that it would be confusing.



Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 8:05:12 PM, on 9/26/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Boot mode: Normal



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\netdde.exe

C:\WINDOWS\system32\CTHELPER.EXE

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\Program Files\support.com\bin\tgcmd.exe

C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE

C:\Program Files\D4\D4.exe

C:\Program Files\Microsoft IntelliType Pro\itype.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\MXOALDR.EXE

C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\CTsvcCDA.EXE

C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\WINDOWS\system32\HPZipm12.exe

C:\Program Files\Dantz\Retrospect\retrorun.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Trend Micro\HijackThis\THJ.exe



R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R3 - URLSearchHook: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll

O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll

O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server

O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE

O4 - HKLM\..\Run: [Dimension4] C:\Program Files\D4\D4.exe

O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"

O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE

O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"

O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe

O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm

O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html

O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm

O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll

O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll

O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB

O16 - DPF: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab?v=13,0,0831,02

O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab

O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab

O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.67.cab

O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab

O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab

O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab

O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.microsoftvirtuallabs.com/virtua…iveXClient1.cab

O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab

O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.53.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149296841921

O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab

O16 - DPF: {7D492D61-303A-45C3-8A55-63449339943D} (CPlayFirstNightShiftControl Object) - http://www.shockwave.com/content/nightshif…Web.1.0.0.5.cab

O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab

O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab

O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab70018.cab

O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn.com/binframework/v10/…gr.cab31267.cab

O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab

O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://www.shockwave.com/content/zenerchi/…eb.1.0.0.10.cab

O16 - DPF: {BCF9A64D-1440-4404-863C-F5DF2B99F798} (MSN Games - Catan Online) - http://zone.msn.com/bingame/zpagames/zpa_catan.cab55579.cab

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab

O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.32.17/ttinst.cab

O16 - DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} (CPlayFirstPetShopHopControl Object) - http://www.shockwave.com/content/petshopho…eb.1.0.0.17.cab

O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/A…ersion=1,0,0,10

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab

O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab

O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab

O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab

O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE

O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe

O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe

O23 - Service: Turbine Network Service - Live (LiveTurbineNetworkService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe



–

End of file - 13963 bytes
[external image: Posted Image]


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

Open Notepad, click on Format and uncheck Word Wrap.

Next:

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hello LDTate. Thank you for the welcome and thank you for your assistance. Most appreciated.

I have to correct one of the things I said earlier. I paid better attention and it is not on every page that I'm getting the "Done, but with errors on page." message. For example, on the WTT home page I'm not receiving an error message, but I am receiving it on the forums pages.

On the forum index page these are the listed errors:
Line: 44
Char: 3
Error: Object expected
Conde: 0
URL: http://forums.whatthetech.come/forums.html

Line: 48
Char: 3
Error: Object expected
Conde: 0
URL: http://forums.whatthetech.come/forums.html

Line: 51
Char: 3
Error: Object expected
Conde: 0
URL: http://forums.whatthetech.come/forums.html

Line: 799
Char: 1
Error: Object expected
Conde: 0
URL: http://forums.whatthetech.come/forums.html

On this thread's page these are the listed errors:
Line: 46
Char: 3
Error: Object expected
Conde: 0
URL: http://forums.whatthetech.come/Ongoing_pro…log_t95665.html

Line: 50
Char: 3
Error: Object expected
Conde: 0
URL: http://forums.whatthetech.come/Ongoing_pro…log_t95665.html

Line: 53
Char: 3
Error: Object expected
Conde: 0
URL: http://forums.whatthetech.come/Ongoing_pro…log_t95665.html

Line: 958
Char: 1
Error: Object expected
Conde: 0
URL: http://forums.whatthetech.come/Ongoing_pro…log_t95665.html

Don't know if this helps. Thought that maybe if you knew what errors I was getting you might be able to use a comparison to determine what the problem is with my browser (IE7).

MBAM Log

Malwarebytes' Anti-Malware 1.28
Database version: 1220
Windows 5.1.2600 Service Pack 2

9/28/2008 2:38:35 PM
mbam-log-2008-09-28 (14-38-35).txt

Scan type: Quick Scan
Objects scanned: 62714
Time elapsed: 7 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Broken.SecurityProviders) -> Bad: (msapsspc.dll schannel.dll digest.dll msnsspc.dll) Good: (msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("%1" %*) Good: ("%1" /S) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\S***\Local Settings\Temp\5e2e_appcompat.txt (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.
C:\Documents and Settings\S***\Local Settings\Temp\893_appcompat.txt (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.
C:\Documents and Settings\S***\Local Settings\Temp\9c67_appcompat.txt (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.
C:\Documents and Settings\S***\Local Settings\Temp\fefe_appcompat.txt (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.

*I changed the folders' names because S*** is my daughter (and that was her real name), but she has not been on this machine since July 9th. I've run MBAM since then and it had cleared everything of her's back then. Kind of strange that there sre still issues with her account. Additionally, I use CCleaner on average every other day. On Friday when I ran it, there were quite a few items listed from S***'s files. This just seems really strange to me mostly because there hadn't been any items from her files since I cleaned everything after she moved out.

HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:50:04 PM, on 9/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Webshots\webshots.scr
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Trend Micro\HijackThis\THJ.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [Dimension4] C:\Program Files\D4\D4.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab?v=13,0,0831,02
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.67.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.microsoftvirtuallabs.com/virtua…iveXClient1.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.53.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149296841921
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {7D492D61-303A-45C3-8A55-63449339943D} (CPlayFirstNightShiftControl Object) - http://www.shockwave.com/content/nightshif…Web.1.0.0.5.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab70018.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn.com/binframework/v10/…gr.cab31267.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://www.shockwave.com/content/zenerchi/…eb.1.0.0.10.cab
O16 - DPF: {BCF9A64D-1440-4404-863C-F5DF2B99F798} (MSN Games - Catan Online) - http://zone.msn.com/bingame/zpagames/zpa_catan.cab55579.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.32.17/ttinst.cab
O16 - DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} (CPlayFirstPetShopHopControl Object) - http://www.shockwave.com/content/petshopho…eb.1.0.0.17.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/A…ersion=1,0,0,10
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe
O23 - Service: Turbine Network Service - Live (LiveTurbineNetworkService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

–
End of file - 13985 bytes

HJT is still hanging up on the trusted zone enumeration. I keep seeing the Logitech QCdriver in the runnng processes. Is this a necessary thing? I had thought I got everything Logitech off this machine. At one time there was a Logitech wireless keyboard but that has since been replaced with the Microsoft one. There was also a logitech web cam, but that is no longer present either. So don't understand why there is still a Logitech process running. Particularly since I asked Logitech for an uninstall program because I was having so much difficulty uninstalling the programs.

Aside from the errors on the pages, my machine hasn't been acting badly. I get some errors on closing programs but don't know if that applies since MBAM just fixed a couple issues, but since they're in S***'s files, don't know if that will change anything - actually don't know if this qualifies as a problem. Pages sometimes load slower than at others but I usually attribute that to time of day traffic and how many graphics the pages have on them. Not having a timer I counted the seconds between the time I open the browser to the time it actually loads; it's approximately 6 seconds. On the other hand, it's taking approximtely 5 minutes for machine to boot up. AVG and the S&D Teatimer seem to be taking longer to load and hog resources - and that just started recently. The only reason I know it's these two programs is through the Task Manager. I couldn't understand why it was taking so long all of a sudden so checked and these two alternately use up to 100% of the CPU at start up. Don't know if this qualifies as a problem either.

What clued me in that there seemed to still be a problem was the frequency of page errors One or two pages, I'd assume it was the sites; but I'm getting way too many, thus I'm thinking it has to be me; that is why I was looking around and found the random .dll files and all the ActiveX dependency files being damaged.


Let me know if you need anything else.

Oh, I have a question that I've been meaning to ask. Since I am using IE7 not IE5, is there a reason that CCleaner reports temporary internet files this way: C:\Documents and Settings\TheCat\Local Settings\Temporary Internet Files\Content.IE5\…

Thanks again.

Cat
Most of the cleaner programs like CCleaner and ATF cleaner need to be run under each user login.

Lets dig deeper and see what we find.

Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net

2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Give it atleast 20-30 minutes to finish if needed.
I have a favor to ask as well. Last time I ran ComboFix (still have the log if you want to see it), it found Kazaa and WinMX still installed on this machine. I had thought I uninstalled them but I must not have :oops:- they're uninstalled now :). Anyway, I know that when you uninstall programs there are still bits left behind in the registry and elsewhere. If you find anything like that, could you please let me know where so I can get rid of it?

This used to be someone else's machine. It's taken a while but I've been slowly cleaning it up. Which reminds me, there were 4 accounts on this machine at one time. I've deleted 2 of them - they were my grandkids accounts. My daughter's I left because she still has "stuff" that she wants; however, I did run CCleaner (but not MBAM) on each account separately and in safe mode just to make sure. This is why I find it strange that I'm still getting "stuff' from the accounts every now and then.

Interestingly, when ComboFix started to scan, the AVG scanning icon popped into my system tray and sits there yet. I did disable the resident shield and when I checked the user interface, it wasn't/isn't actually scanning. I haven't rebooted so it may go away when i do that. Another strange thing happened; after I read your instructions when I closed the browser, I had another instance of it open up with "blank page" on the title bar. Not only that, but tab after new tab kept opening in it and I could not close the browser window until I used the task manager to end task. I wasn't able to duplicate it, so not sure if it's an isolated incident or not. Additionally, when I ran HJT, I got an error message (didn't copy it down - sorry) and it's still hanging up on the trusted zone enumeration.

Here's the ComboFix log:

ComboFix 08-09-27.06 - TheCat 2008-09-28 18:38:31.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.573 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\SYSTEM32\hlijsbxc.ini
C:\WINDOWS\system32\iyvpworx.ini

.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.

2008-09-28 14:21 . 2008-09-28 14:22 d——– C:\ATF Cleaner
2008-09-27 14:39 . 2008-09-28 18:30 4,932,601 –a—— C:\WINDOWS\{00000004-00000000-00000001-00001102-00000004-20061102}.BAK
2008-09-27 04:13 . 2008-09-27 04:13 d——– C:\Program Files\ERUNT
2008-09-26 02:22 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-09-23 23:05 . 2008-09-23 23:56 d——– C:\Documents and Settings\TheCat\Application Data\ForgottenRiddles2
2008-09-23 16:11 . 2008-09-23 16:11 d——– C:\Documents and Settings\TheCat\Application Data\Windows Desktop Search
2008-09-23 13:56 . 2008-09-28 14:41 11,564 –a—— C:\WINDOWS\SYSTEM32\DVCState-{00000004-00000000-00000001-00001102-00000004-20061102}.rfx
2008-09-23 13:32 . 2008-09-23 13:32 d——– C:\Program Files\MSBuild
2008-09-23 13:30 . 2008-09-23 14:13 d——– C:\WINDOWS\SYSTEM32\XPSViewer
2008-09-23 13:29 . 2008-09-23 13:29 d——– C:\Program Files\Reference Assemblies
2008-09-23 13:28 . 2008-09-23 13:28 d——– C:\1cd346d3b5488ae6c87b278d14
2008-09-23 13:16 . 2008-09-23 13:16 d——– C:\Program Files\MSXML 6.0
2008-09-23 13:12 . 2006-11-13 02:02 288,768 ——— C:\WINDOWS\SYSTEM32\rhttpaa.dll
2008-09-23 13:12 . 2006-11-13 02:02 116,736 ——— C:\WINDOWS\SYSTEM32\aaclient.dll
2008-09-23 13:12 . 2006-11-13 02:02 36,352 ——— C:\WINDOWS\SYSTEM32\tsgqec.dll
2008-09-19 05:23 . 2008-09-19 05:23 d——– C:\Program Files\Intel Corporation
2008-09-19 04:25 . 2008-09-19 04:25 d——– C:\Documents and Settings\All Users\Application Data\Turbine
2008-09-19 04:24 . 2008-09-19 04:36 d——– C:\Program Files\Turbine
2008-09-19 03:08 . 2008-09-19 03:08 d——– C:\Temp\gwn-ingamecinematic01
2008-09-19 03:04 . 2008-09-19 03:04 75,306,615 –a—— C:\Temp\gwn-ingamecinematic01.zip
2008-09-16 18:57 . 2008-09-16 19:19 d——– C:\Documents and Settings\TheCat\Application Data\Righteous Kill
2008-09-15 01:27 . 2008-09-15 01:28 d——– C:\Program Files\NCSoft
2008-09-13 08:46 . 1999-09-10 07:06 45,056 –a—— C:\WINDOWS\SYSTEM32\wnaspi32.dll
2008-09-13 08:46 . 1999-09-10 07:06 25,244 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aspi32.sys
2008-09-13 08:46 . 1999-09-10 07:06 5,600 –a—— C:\WINDOWS\SYSTEM\winaspi.dll
2008-09-13 08:46 . 1999-09-10 07:06 4,672 –a—— C:\WINDOWS\SYSTEM\wowpost.exe
2008-09-13 07:55 . 2008-09-13 07:55 d——– C:\Documents and Settings\TheCat\Application Data\Ahead
2008-09-12 19:48 . 2008-09-12 19:48 d——– C:\Documents and Settings\All Users\Application Data\PCPitstop
2008-09-12 06:12 . 2008-09-12 06:12 d——– C:\Documents and Settings\TheCat\Application Data\AppDataLow
2008-09-06 00:22 . 2008-09-06 00:22 d——– C:\Program Files\AntiRootkit
2008-09-03 04:13 . 2008-09-05 04:41 d——– C:\Documents and Settings\TheCat\Application Data\SPORE Creature Creator
2008-09-03 04:11 . 2008-09-03 04:11 d——– C:\ProgramData
2008-09-03 04:10 . 2008-09-03 04:14 2,436 –a—— C:\WINDOWS\SYSTEM32\ealregsnapshot1.reg
2008-09-03 04:09 . 2008-09-03 06:11 d——– C:\Program Files\Electronic Arts
2008-09-02 18:32 . 2008-09-02 18:32 d——– C:\Documents and Settings\All Users\Application Data\TheRace_dev
2008-09-02 16:37 . 2008-09-02 16:37 d——– C:\Program Files\runscanner
2008-09-01 16:39 . 2008-09-06 05:51 d——– C:\Program Files\FontList
2008-09-01 13:17 . 2008-09-01 15:10 d——– C:\Program Files\ZonedOut
2008-09-01 03:54 . 2008-09-28 18:44 18,720,800 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2008-09-01 03:54 . 2008-09-28 14:41 218,372 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
2008-09-01 03:51 . 2008-09-01 03:51 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-09-01 03:51 . 2008-07-09 09:05 75,248 –a—— C:\WINDOWS\zllsputility.exe
2008-09-01 03:51 . 2008-09-01 03:52 4,212 —h—– C:\WINDOWS\SYSTEM32\zllictbl.dat
2008-09-01 03:50 . 2008-09-01 03:50 d——– C:\Program Files\Zone Labs
2008-09-01 03:48 . 2008-09-28 18:36 d——– C:\WINDOWS\Internet Logs
2008-08-31 23:38 . 2008-09-28 14:27 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-31 23:38 . 2008-08-31 23:38 d——– C:\Documents and Settings\TheCat\Application Data\Malwarebytes
2008-08-31 23:38 . 2008-08-31 23:38 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-31 23:38 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-08-31 23:38 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-08-31 17:56 . 2008-08-31 17:56 d——– C:\Program Files\IceSword122en
2008-08-31 13:15 . 2008-08-31 13:15 d——– C:\VundoFix Backups
2008-08-31 12:35 . 2008-08-31 12:49 d——– C:\Program Files\KillBox
2008-08-31 12:31 . 2008-08-31 13:09 d——– C:\Program Files\bholist
2008-08-31 10:08 . 2008-08-31 10:08 d——– C:\Program Files\ibprocman
2008-08-31 10:05 . 2008-08-31 10:05 d——– C:\Program Files\cwshredder
2008-08-31 10:00 . 2008-08-31 10:00 d——– C:\Program Files\InterMute
2008-08-31 09:57 . 2008-08-31 09:57 d——– C:\Program Files\Startup List
2008-08-30 08:35 . 2004-12-26 18:57 1,599 –a—— C:\Remote Assistance.lnk
2008-08-30 08:35 . 2004-12-26 18:57 234 –ahs—- C:\DESKTOP.INI
2008-08-30 04:39 . 2008-08-30 04:39 d——– C:\Program Files\Uniblue
2008-08-30 04:39 . 2008-08-30 04:39 d——– C:\Documents and Settings\TheCat\Application Data\Uniblue
2008-08-30 04:38 . 2008-08-30 04:39 d–h-c— C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}
2008-08-29 23:56 . 2008-09-01 03:43 d——– C:\WINDOWS\SYSTEM32\CatRoot_bak
2008-08-29 19:37 . 2007-08-01 22:47 102,664 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
2008-08-29 07:10 . 2008-08-29 07:10 1,434,037 –ahs—- C:\WINDOWS\SYSTEM32\ubtmmund.tmp
2008-08-29 02:27 . 2008-08-29 08:54 d——– C:\Documents and Settings\TheCat\.housecall6.6
2008-08-29 01:40 . 2008-08-29 19:06 347 –ahs—- C:\WINDOWS\SYSTEM32\badgNXyb.ini
2008-08-28 15:17 . 2008-08-28 15:17 d——– C:\Program Files\MySpace
2008-08-28 15:17 . 2008-08-28 15:17 d——– C:\Documents and Settings\TheCat\Application Data\MySpace

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 22:22 ——— d—–w C:\Program Files\AdvancedSearchbar
2008-09-27 18:36 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-27 07:28 ——— d—–w C:\Program Files\CCleaner
2008-09-26 06:23 ——— d—–w C:\Program Files\Java
2008-09-26 00:47 ——— d—–w C:\Program Files\Yahoo!
2008-09-23 23:21 ——— d—–w C:\Program Files\Shockwave.com
2008-09-23 20:11 ——— d—–w C:\Program Files\Windows Desktop Search
2008-09-23 18:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-23 17:14 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-23 17:14 ——— d—–w C:\Program Files\ATI Technologies
2008-09-17 12:02 ——— d—–w C:\Documents and Settings\TheCat\Application Data\Gamelab
2008-09-16 08:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-09-15 18:03 ——— d—–w C:\Program Files\MSN Messenger
2008-09-15 18:03 ——— d—–w C:\Program Files\Messenger Plus! Live
2008-09-15 05:26 ——— d—–w C:\Documents and Settings\TheCat\Application Data\GetRightToGo
2008-09-14 18:49 1,831,985 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-09-13 13:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Retrospect
2008-09-13 12:50 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-09-12 23:47 ——— d—–w C:\Program Files\PCPitstop
2008-09-06 09:51 ——— d—–w C:\Program Files\Outpost Kaloki
2008-09-06 09:51 ——— d—–w C:\Program Files\3dmaze
2008-09-06 07:38 1,453,568 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-09-01 22:11 1,369,088 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-09-01 04:40 ——— d—–w C:\Program Files\Lavasoft
2008-09-01 04:40 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-31 16:45 ——— d—–w C:\Program Files\_ArcadeDownloadFolder
2008-08-31 16:23 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-08-30 07:49 ——— d—–w C:\Program Files\Windows Live Safety Center
2008-08-30 01:56 561,152 —-a-w C:\WINDOWS\SYSTEM32\ati2evxx.exe
2008-08-29 03:47 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-29 03:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-28 22:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-26 21:32 ——— d—–w C:\Documents and Settings\TheCat\Application Data\PlayFirst
2008-08-26 21:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-08-25 18:31 524,288 —-a-w C:\WINDOWS\opuc.dll
2008-08-12 22:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-08-11 04:12 ——— d—–w C:\Documents and Settings\TheCat\Application Data\Ancient Quest of Saqqarah__shockwave
2008-08-07 07:17 ——— d—–w C:\Documents and Settings\TheCat\Application Data\Shockwave
2008-08-06 05:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-07-28 22:21 ——— d—–w C:\Program Files\IrfanView
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\SYSTEM32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\SYSTEM32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\SYSTEM32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\SYSTEM32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\SYSTEM32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\SYSTEM32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
2008-07-19 02:07 270,880 —-a-w C:\WINDOWS\SYSTEM32\mucltui.dll
2008-07-19 02:07 210,976 —-a-w C:\WINDOWS\SYSTEM32\muweb.dll
2008-07-09 13:05 1,086,952 —-a-w C:\WINDOWS\SYSTEM32\zpeng24.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\SYSTEM32\es.dll
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\SYSTEM32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\SYSTEM32\ATIDEMGX.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\SYSTEM32\ATIDEMGX(3).dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\SYSTEM32\ATIDEMGX(2).dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\SYSTEM32\ati2dvag.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\SYSTEM32\ati2dvag(4).dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\SYSTEM32\ati2dvag(3).dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\SYSTEM32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\SYSTEM32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\SYSTEM32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\SYSTEM32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\SYSTEM32\ati2evxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\SYSTEM32\ati2evxx(4).dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\SYSTEM32\ati2evxx(3).dll
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\SYSTEM32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\SYSTEM32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\SYSTEM32\ati3duag.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\SYSTEM32\ati3duag(4).dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\SYSTEM32\ati3duag(3).dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\SYSTEM32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\SYSTEM32\ativvaxx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\SYSTEM32\ativvaxx(4).dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\SYSTEM32\ativvaxx(3).dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\SYSTEM32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\SYSTEM32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\SYSTEM32\atiadlxx.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\SYSTEM32\atiadlxx(3).dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\SYSTEM32\atiadlxx(2).dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\SYSTEM32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\SYSTEM32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\SYSTEM32\ati2cqag.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\SYSTEM32\ati2cqag(4).dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\SYSTEM32\ati2cqag(3).dll
2008-07-04 01:05 593,920 —-a-w C:\WINDOWS\SYSTEM32\ati2sgag.exe
2008-07-02 12:18 10,520 —-a-w C:\WINDOWS\SYSTEM32\avgrsstx.dll
2008-06-09 17:10 20 -c-h–w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2008-06-09 17:10 20 -c-h–w C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2008-03-04 21:16 2,696 -c–a-w C:\Documents and Settings\TheCat\Application Data\mindhabits.dat
2008-01-16 15:39 32 -c–a-r C:\Documents and Settings\All Users\hash.dat
2005-06-20 16:50 4,535 -c–a-w C:\Program Files\export.htm
2005-06-20 16:50 223,714 -c–a-w C:\Program Files\export.zip
2005-02-04 15:18 376,656 -c–a-w C:\Program Files\musicmatch_installer.exe
2004-08-27 00:36 141 -c–a-w C:\Program Files\pcdocrx_order.html
2003-11-03 05:38 792 -c–a-w C:\Program Files\INSTALL.LOG
2003-03-10 04:22 23,357 -c-h–w C:\Program Files\folder.htt
.

((((((((((((((((((((((((((((( snapshot@2008-08-31_19.40.08.04 )))))))))))))))))))))))))))))))))))))))))
.
- 2003-09-23 14:50:32 154,320 -c–a-w C:\WINDOWS\DASAct.dll
+ 2007-01-30 19:06:18 151,048 —-a-w C:\WINDOWS\DASAct.dll
- 2003-09-23 14:50:28 64,200 -c–a-w C:\WINDOWS\DASShp.dll
+ 2007-01-30 19:06:14 60,944 —-a-w C:\WINDOWS\DASShp.dll
+ 2008-03-24 23:33:02 1,527,056 —-a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\FP_AX_CAB_INSTALLER.exe
- 2006-06-29 17:20:14 278,528 -c–a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gpcontrol.dll
+ 2006-11-01 18:00:16 278,528 —-a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gpcontrol.dll
- 2005-04-29 21:24:18 155,648 -c–a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\zylomgamesplayer.dll
+ 2006-08-29 18:17:22 161,976 —-a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\zylomgamesplayer.dll
+ 2008-03-24 23:33:02 1,527,056 —-a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
- 2006-08-31 20:55:34 187,688 -c–a-w C:\WINDOWS\Downloaded Program Files\ImportAx.dll
+ 2007-04-09 18:28:10 189,816 —-a-w C:\WINDOWS\Downloaded Program Files\ImportAx.dll
+ 2003-12-08 14:14:20 86,016 —-a-w C:\WINDOWS\Downloaded Program Files\pcpConnCheck.dll
+ 2008-09-12 23:47:52 366,808 —-a-w C:\WINDOWS\Downloaded Program Files\pcpitstop2.dll
+ 2005-10-20 16:02:28 163,328 —-a-w C:\WINDOWS\erdnt\9-27-2008\ERDNT.EXE
+ 2008-09-27 10:10:03 13,414,400 —-a-w C:\WINDOWS\erdnt\9-27-2008\Users\00000001\ntuser.dat
+ 2008-09-27 10:10:03 155,648 —-a-w C:\WINDOWS\erdnt\9-27-2008\Users\00000002\UsrClass.dat
+ 2007-08-24 07:37:00 399,232 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\MOC.EXE
+ 2007-09-15 01:45:58 16,901,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\MSO.DLL
+ 2007-10-02 23:51:22 8,436,776 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\OARTCONV.DLL
+ 2007-08-29 04:19:24 1,654,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\OGL.DLL
+ 2007-08-29 04:16:22 846,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\OICE.EXE
+ 2007-08-29 03:22:36 579,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACACEDAO.DLL
+ 2007-08-24 09:17:04 165,256 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACCWIZ.DLL
+ 2007-08-29 03:22:30 1,754,536 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACECORE.DLL
+ 2007-08-29 03:22:36 579,008 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEDAO.DLL
+ 2007-08-29 03:22:38 50,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEERR.DLL
+ 2007-08-29 03:22:40 193,992 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEES.DLL
+ 2007-08-24 07:46:10 341,440 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEEXCH.DLL
+ 2007-08-24 07:46:14 632,248 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEEXCL.DLL
+ 2007-08-24 07:46:16 210,368 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACELTS.DLL
+ 2007-08-24 07:46:18 281,992 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEODBC.DLL
+ 2007-08-24 07:46:20 17,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEODDBS.DLL
+ 2007-08-24 07:46:22 17,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEODEXL.DLL
+ 2007-08-24 07:46:22 17,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEODPDX.DLL
+ 2007-08-24 07:46:22 17,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEODTXT.DLL
+ 2007-08-29 03:22:44 390,600 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEOLEDB.DLL
+ 2007-08-24 07:46:28 394,688 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEPDE.DLL
+ 2007-08-24 07:46:30 263,616 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACER2X.DLL
+ 2007-08-24 07:46:32 292,288 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACER3X.DLL
+ 2007-08-24 07:46:34 58,760 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACERCLR.DLL
+ 2007-08-24 07:46:38 554,440 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEREP.DLL
+ 2007-08-24 07:46:40 226,744 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACETXT.DLL
+ 2007-08-29 04:52:12 201,664 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEWSS.DLL
+ 2007-08-24 07:46:44 374,200 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ACEXBE.DLL
+ 2007-08-29 04:53:12 402,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\CDLMSO.DLL
+ 2007-08-24 07:45:50 208,256 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\CLVIEW.EXE
+ 2007-08-24 09:38:36 67,952 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\COLLIMP.DLL
+ 2007-08-24 07:36:26 192,400 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\CONTACTPICKER.DLL
+ 2007-08-24 07:18:14 442,208 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\DWDCW20.DLL
+ 2007-08-24 07:18:18 437,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\DWTRIG20.EXE
+ 2007-08-23 05:03:38 1,195,888 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\FM20.DLL
+ 2007-08-23 05:19:06 78,728 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\FORM.DLL
+ 2007-08-25 23:11:44 1,685,896 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\FPSRVUTL.DLL
+ 2007-08-29 03:45:00 985,496 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\FPWEC.DLL
+ 2007-10-02 23:45:34 2,530,864 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\GRAPH.EXE
+ 2007-08-24 07:36:58 175,968 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\IEAWSDC.DLL
+ 2007-10-06 00:31:06 5,287,984 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\IPEDITOR.DLL
+ 2007-08-24 07:39:38 796,032 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MDIGRAPH.DLL
+ 2007-08-24 07:39:40 277,416 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MDIINK.DLL
+ 2007-08-29 04:45:54 831,856 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MEDCAT.DLL
+ 2007-08-29 03:13:52 10,367,352 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSACCESS.EXE
+ 2007-08-24 09:17:48 69,520 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSAEXP30.DLL
+ 2007-08-29 04:52:02 120,704 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSCONV97.DLL
+ 2007-08-29 03:20:06 163,712 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSOCF.DLL
+ 2007-08-29 03:20:12 17,304 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSOCFU.DLL
+ 2007-09-06 21:55:08 431,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSODCW.DLL
+ 2007-08-24 09:50:10 29,576 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSOEURO.DLL
+ 2007-08-28 00:20:14 6,637,960 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSORES.DLL
+ 2007-08-29 04:18:20 439,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSORUN.DLL
+ 2007-08-24 07:39:54 1,060,264 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSPCORE.DLL
+ 2007-08-24 07:40:00 775,576 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSPFILT.DLL
+ 2007-08-24 07:40:16 674,664 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSQRY32.EXE
+ 2007-08-23 05:12:20 507,768 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSSOAP30.DLL
+ 2007-08-29 04:45:58 835,952 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSTORDB.EXE
+ 2007-08-29 04:46:06 542,568 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\MSTORES.DLL
+ 2007-08-24 07:37:50 68,464 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\NAME.DLL
+ 2007-10-06 00:44:24 14,168,600 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\OART.DLL
+ 2007-09-02 05:55:16 235,456 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ODEPLOY.EXE
+ 2007-08-29 04:37:40 7,039,888 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\OFFOWC.DLL
+ 2007-08-24 08:06:28 277,384 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\OIS.EXE
+ 2007-08-24 08:06:32 1,000,848 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\OISAPP.DLL
+ 2007-08-24 08:06:38 288,152 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\OISGRAPH.DLL
+ 2007-08-29 04:39:14 542,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\ORGCHART.EXE
+ 2007-09-02 05:55:54 6,540,656 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\OSETUP.DLL
+ 2007-06-07 23:51:00 465,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\OUTLFLTR.DLL
+ 2007-09-06 21:50:34 485,232 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\PORTCONN.DLL
+ 2007-08-29 04:38:22 2,016,656 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\PPTVIEW.EXE
+ 2007-08-23 05:19:06 79,784 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\PSOM.DLL
+ 2007-08-24 09:50:10 41,832 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\REFEDIT.DLL
+ 2007-08-23 05:19:08 22,416 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\REVERSE.DLL
+ 2007-09-06 21:55:22 505,752 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\SELFCERT.EXE
+ 2007-09-02 05:55:34 442,240 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\SETUP.EXE
+ 2007-08-24 09:17:54 505,240 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\SOA.DLL
+ 2007-06-07 23:51:00 125,320 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\SSGEN.DLL
+ 2007-08-29 03:28:26 2,330,024 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\STSLIST.DLL
+ 2007-08-23 05:19:08 32,608 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\THOCRAPI.DLL
+ 2007-08-23 05:19:08 129,936 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\TWCUTCHR.DLL
+ 2007-08-23 05:19:10 90,504 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\TWCUTLIN.DLL
+ 2007-08-23 05:19:10 60,800 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\TWLAY32.DLL
+ 2007-08-23 05:19:12 30,096 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\TWORIENT.DLL
+ 2007-08-23 05:19:14 54,152 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\TWRECE.DLL
+ 2007-08-23 05:19:14 22,416 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\TWRECS.DLL
+ 2007-08-23 05:19:16 79,776 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\TWSTRUCT.DLL
+ 2007-06-28 00:58:12 2,585,936 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\VBE6.DLL
+ 2007-08-24 11:10:14 1,846,160 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\VVIEWDWG.DLL
+ 2007-08-24 11:10:28 3,735,424 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\VVIEWER.DLL
+ 2007-08-23 05:19:18 1,198,496 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\XIMAGE3B.DLL
+ 2007-08-23 05:19:20 535,448 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6215\XPAGE3C.DLL
+ 2008-09-13 12:48:04 49,152 —-a-r C:\WINDOWS\Installer\{3EC91FDF-FE9A-43D5-96C4-8A9C24372500}\NewShortcut1_3EC91FDFFE9A43D596C48A9C24372500.exe
+ 2008-09-13 12:48:04 49,152 —-a-r C:\WINDOWS\Installer\{3EC91FDF-FE9A-43D5-96C4-8A9C24372500}\NewShortcut4_3EC91FDFFE9A43D596C48A9C24372500.exe
+ 2008-09-13 12:48:04 49,152 —-a-r C:\WINDOWS\Installer\{3EC91FDF-FE9A-43D5-96C4-8A9C24372500}\NewShortcut5_3EC91FDFFE9A43D596C48A9C24372500.exe
+ 2008-09-13 12:48:04 49,152 —-a-r C:\WINDOWS\Installer\{3EC91FDF-FE9A-43D5-96C4-8A9C24372500}\NewShortcut6_3EC91FDFFE9A43D596C48A9C24372500.exe
- 2008-08-15 17:02:11 35,600 —-a-r C:\WINDOWS\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2008-09-23 18:30:13 35,600 —-a-r C:\WINDOWS\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2008-04-10 00:37:28 217,864 -c–a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-09-10 00:09:46 217,864 —-a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2007-02-12 09:56:08 35,088 -c–a-r C:\WINDOWS\Installer\{90120000-00B2-0409-0000-0000000FF1CE}\expxic.exe
+ 2008-09-10 00:08:08 35,088 —-a-r C:\WINDOWS\Installer\{90120000-00B2-0409-0000-0000000FF1CE}\expxic.exe
- 2008-08-15 17:05:40 1,165,584 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-09-23 18:31:08 1,165,584 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
- 2008-08-15 17:05:40 20,240 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-09-23 18:31:09 20,240 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-08-15 17:05:40 217,864 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2008-09-23 18:31:09 217,864 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
- 2008-08-15 17:05:40 18,704 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-09-23 18:31:09 18,704 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-08-15 17:05:40 35,088 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-09-23 18:31:09 35,088 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-08-15 17:05:40 845,584 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-09-23 18:31:08 845,584 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2008-08-15 17:05:40 922,384 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-09-23 18:31:08 922,384 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2008-08-15 17:05:40 272,648 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-09-23 18:31:09 272,648 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2008-08-15 17:05:40 888,080 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-09-23 18:31:09 888,080 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-08-15 17:05:40 1,172,240 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-09-23 18:31:08 1,172,240 —-a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2007-03-08 02:31:17 38,240 -c–a-r C:\WINDOWS\Installer\{95120000-0038-0409-0000-0000000FF1CE}\TZMoveIcon.exe
+ 2008-09-23 18:29:32 38,240 —-a-r C:\WINDOWS\Installer\{95120000-0038-0409-0000-0000000FF1CE}\TZMoveIcon.exe
+ 2008-09-13 13:09:45 81,920 —-a-r C:\WINDOWS\Installer\{C4354214-B919-4C8F-84EB-4F9B84ACC02C}\_57A2994DE390_4C8A_90AC_B1E5FEF5B415.exe
+ 2008-09-13 13:09:45 5,222 —-a-r C:\WINDOWS\Installer\{C4354214-B919-4C8F-84EB-4F9B84ACC02C}\retroico.exe
+ 2008-09-03 08:14:50 7,598 —-a-r C:\WINDOWS\Installer\{EF7E931D-DC84-471B-8DB6-A83358095474}\ARPPRODUCTICON.exe
+ 2008-09-03 08:14:50 7,598 —-a-r C:\WINDOWS\Installer\{EF7E931D-DC84-471B-8DB6-A83358095474}\ead_desktop_shortcut_F557710133CC471182353A95BCD49DB0.exe
+ 2008-09-03 08:14:50 7,598 —-a-r C:\WINDOWS\Installer\{EF7E931D-DC84-471B-8DB6-A83358095474}\ead_startmenu_shortc_F557710133CC471182353A95BCD49DB0.exe
+ 2006-11-07 08:06:47 16,832 ——w C:\WINDOWS\Installer\tsclientmsitrans\tscinst.vbs
+ 2006-11-07 08:06:47 12,451 ——w C:\WINDOWS\Installer\tsclientmsitrans\tscuinst.vbs
+ 2006-10-30 08:06:24 74,012 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\baseline.dat
+ 2003-04-07 22:09:48 118,784 —-a-w C:\WINDOWS\MXOALDR.EXE
+ 2002-12-16 18:49:38 282,624 —-a-w C:\WINDOWS\MXONTTRY.EXE
- 2003-11-13 23:54:00 65,536 -c–a-w C:\WINDOWS\SYSTEM32\a3d.dll
+ 2007-04-09 16:32:58 34,816 —-a-w C:\WINDOWS\SYSTEM32\a3d.dll
- 2003-11-14 00:16:00 53,248 -c–a-w C:\WINDOWS\SYSTEM32\AC3API.DLL
+ 2007-04-09 16:32:46 27,648 —-a-w C:\WINDOWS\SYSTEM32\ac3api.dll
+ 2007-04-09 15:25:36 48,400 —-a-w C:\WINDOWS\SYSTEM32\AddCat.exe
- 2008-03-19 23:36:22 202,168 —-a-w C:\WINDOWS\SYSTEM32\Adobe\Director\SwDir.dll
+ 2008-08-06 20:30:48 202,168 —-a-w C:\WINDOWS\SYSTEM32\Adobe\Director\SwDir.dll
+ 2008-08-06 20:31:08 67,000 —-a-w C:\WINDOWS\SYSTEM32\Adobe\Director\SwDnld.exe
+ 2007-04-12 12:10:28 105,728 —-a-w C:\WINDOWS\SYSTEM32\APOMgrH.dll
- 2003-11-14 00:02:00 114,688 —-a-w C:\WINDOWS\SYSTEM32\commonfx.dll
+ 2007-04-18 12:59:40 98,600 —-a-w C:\WINDOWS\SYSTEM32\COMMONFX.DLL
+ 2007-04-09 16:22:04 205,312 —-a-w C:\WINDOWS\SYSTEM32\ct_oal.dll
+ 2007-04-09 16:29:30 10,752 —-a-w C:\WINDOWS\SYSTEM32\Ct20xspi.dll
+ 2007-04-12 12:10:26 164,608 —-a-w C:\WINDOWS\SYSTEM32\CT20XUT.DLL
+ 2003-11-14 00:19:00 57,344 —-a-w C:\WINDOWS\SYSTEM32\CTAGENT(2).DLL
- 2003-11-14 00:19:00 57,344 —-a-w C:\WINDOWS\SYSTEM32\CTAGENT.DLL
+ 2007-04-09 16:32:30 8,704 —-a-w C:\WINDOWS\SYSTEM32\ctagent.dll
+ 2007-04-09 15:25:04 444,928 —-a-w C:\WINDOWS\SYSTEM32\CTAPO32.dll
- 2003-11-14 00:04:00 126,976 -c–a-w C:\WINDOWS\SYSTEM32\CTASIO.DLL
+ 2007-04-09 16:22:02 79,872 —-a-w C:\WINDOWS\SYSTEM32\ctasio.dll
- 2004-07-13 15:53:00 585,728 —-a-w C:\WINDOWS\SYSTEM32\ctaudfx.dll
+ 2007-04-12 12:10:16 546,048 —-a-w C:\WINDOWS\SYSTEM32\CTAUDFX.DLL
- 2004-08-12 21:52:00 140,643 -c–a-w C:\WINDOWS\SYSTEM32\ctbas2w.dat
+ 2007-04-09 16:21:28 149,838 —-a-w C:\WINDOWS\SYSTEM32\ctbas2w.dat
+ 2007-04-09 16:33:50 43,520 —-a-w C:\WINDOWS\SYSTEM32\CTBurst.dll
+ 2007-04-09 16:33:36 86,016 —-a-w C:\WINDOWS\SYSTEM32\ctcoinst.dll
- 2004-08-03 22:54:00 53,932 —-a-w C:\WINDOWS\SYSTEM32\ctdaught.dat
+ 2007-04-09 16:19:20 53,932 —-a-w C:\WINDOWS\SYSTEM32\ctdaught.dat
- 2003-11-14 00:17:00 327,680 —-a-w C:\WINDOWS\SYSTEM32\CTDC0000.DLL
+ 2007-04-09 16:32:20 227,840 —-a-w C:\WINDOWS\SYSTEM32\ctdc0000.dll
+ 2004-08-12 21:43:00 462,848 —-a-w C:\WINDOWS\SYSTEM32\CTDC0001(2).DLL
- 2004-08-12 21:43:00 462,848 —-a-w C:\WINDOWS\SYSTEM32\CTDC0001.DLL
+ 2007-04-09 16:32:22 335,872 —-a-w C:\WINDOWS\SYSTEM32\ctdc0001.dll
+ 2003-11-14 00:18:00 139,264 —-a-w C:\WINDOWS\SYSTEM32\CTDCIFCE(2).DLL
- 2003-11-14 00:18:00 139,264 —-a-w C:\WINDOWS\SYSTEM32\CTDCIFCE.DLL
+ 2007-04-09 16:32:22 131,072 —-a-w C:\WINDOWS\SYSTEM32\ctdcifce.dll
+ 2007-04-09 16:32:20 10,240 —-a-w C:\WINDOWS\SYSTEM32\ctdcres.dll
+ 2007-04-09 16:24:30 46,273 —-a-w C:\WINDOWS\SYSTEM32\ctdnlstr.dat
+ 2003-11-14 00:04:00 110,592 —-a-w C:\WINDOWS\SYSTEM32\CTDPROXY(2).DLL
- 2003-11-14 00:04:00 110,592 —-a-w C:\WINDOWS\SYSTEM32\CTDPROXY.DLL
+ 2007-04-09 16:22:00 76,800 —-a-w C:\WINDOWS\SYSTEM32\ctdproxy.dll
+ 2007-04-09 16:33:36 163,328 —-a-w C:\WINDOWS\SYSTEM32\ctdvinst.dll
+ 2007-04-12 12:10:18 168,192 —-a-w C:\WINDOWS\SYSTEM32\CTEAPSFX.DLL
+ 2007-04-09 16:22:04 50,176 —-a-w C:\WINDOWS\SYSTEM32\ctedasio.dll
+ 2007-04-12 12:10:20 280,320 —-a-w C:\WINDOWS\SYSTEM32\CTEDSPFX.DLL
+ 2007-04-12 12:10:22 128,768 —-a-w C:\WINDOWS\SYSTEM32\CTEDSPIO.DLL
+ 2007-04-12 12:10:22 323,328 —-a-w C:\WINDOWS\SYSTEM32\CTEDSPSY.DLL
- 2003-11-14 00:03:00 36,864 -c–a-w C:\WINDOWS\SYSTEM32\CTEMUPIA.DLL
+ 2007-04-09 16:24:06 110,080 —-a-w C:\WINDOWS\SYSTEM32\ctemupia.dll
+ 2007-04-12 12:10:20 94,976 —-a-w C:\WINDOWS\SYSTEM32\CTERFXFX.DLL
+ 2007-04-12 12:10:24 1,317,632 —-a-w C:\WINDOWS\SYSTEM32\CTEXFIFX.DLL
+ 2004-03-11 15:50:00 28,672 —-a-w C:\WINDOWS\SYSTEM32\CTHELPER(2).EXE
- 2004-03-11 15:50:00 28,672 —-a-w C:\WINDOWS\SYSTEM32\CTHELPER.EXE
+ 2007-04-09 16:32:32 19,456 —-a-w C:\WINDOWS\SYSTEM32\CtHelper.exe
+ 2007-04-12 12:10:26 66,816 —-a-w C:\WINDOWS\SYSTEM32\CTHWIUT.DLL
+ 2005-06-16 14:17:16 71,680 —-a-w C:\WINDOWS\SYSTEM32\ctmmactl.dll
- 2003-11-14 00:19:00 28,672 -c–a-w C:\WINDOWS\SYSTEM32\CTMMEP.DLL
+ 2007-04-09 16:32:28 12,800 —-a-w C:\WINDOWS\SYSTEM32\ctmmep.dll
+ 2003-11-14 00:04:00 159,744 —-a-w C:\WINDOWS\SYSTEM32\CTOSUSER(2).DLL
- 2003-11-14 00:04:00 159,744 —-a-w C:\WINDOWS\SYSTEM32\CTOSUSER.DLL
+ 2007-04-09 16:21:50 137,728 —-a-w C:\WINDOWS\SYSTEM32\ctosuser.dll
+ 2007-04-09 16:32:30 56,832 —-a-w C:\WINDOWS\SYSTEM32\CTpcmcia.dll
+ 2007-04-09 15:25:26 45,568 —-a-w C:\WINDOWS\SYSTEM32\ctppld.dll
+ 2007-04-09 16:32:24 9,216 —-a-w C:\WINDOWS\SYSTEM32\ctpres.dll
+ 2006-11-14 13:01:30 58,104 —-a-w C:\WINDOWS\SYSTEM32\ctpxinst.exe
- 2004-08-12 21:52:00 264,466 -c–a-w C:\WINDOWS\SYSTEM32\ctsbas2w.dat
+ 2007-04-09 16:19:44 274,587 —-a-w C:\WINDOWS\SYSTEM32\ctsbas2w.dat
- 2003-11-14 00:04:00 606,208 —-a-w C:\WINDOWS\SYSTEM32\ctsblfx.dll
+ 2007-04-12 12:10:16 560,384 —-a-w C:\WINDOWS\SYSTEM32\CTSBLFX.DLL
- 2003-11-14 00:18:00 118,784 -c–a-w C:\WINDOWS\SYSTEM32\CTSCAL.DLL
+ 2007-04-09 16:32:22 78,336 —-a-w C:\WINDOWS\SYSTEM32\ctscal.dll
+ 2005-06-30 11:24:14 121,856 —-a-w C:\WINDOWS\SYSTEM32\ctsfinst.dll
+ 2003-11-14 00:20:00 45,056 —-a-w C:\WINDOWS\SYSTEM32\CTSPKHLP(2).DLL
- 2003-11-14 00:20:00 45,056 —-a-w C:\WINDOWS\SYSTEM32\CTSPKHLP.DLL
+ 2007-04-09 16:32:30 45,568 —-a-w C:\WINDOWS\SYSTEM32\ctspkhlp.dll
+ 2007-04-09 16:19:20 313,207 —-a-w C:\WINDOWS\SYSTEM32\ctstatic.dat
- 2003-11-14 00:18:00 106,496 -c–a-w C:\WINDOWS\SYSTEM32\CTTHXCAL.DLL
+ 2007-04-09 16:32:24 69,632 —-a-w C:\WINDOWS\SYSTEM32\ctthxcal.dll
+ 2007-04-09 16:32:34 35,840 —-a-w C:\WINDOWS\SYSTEM32\CTxfiBtn.dll
+ 2007-04-09 16:32:32 19,968 —-a-w C:\WINDOWS\SYSTEM32\Ctxfihlp.exe
+ 2007-04-09 16:29:30 43,520 —-a-w C:\WINDOWS\SYSTEM32\Ctxfireg.exe
+ 2007-04-09 16:29:28 934,400 —-a-w C:\WINDOWS\SYSTEM32\CTxfispi.exe
+ 2007-04-09 16:32:34 46,592 —-a-w C:\WINDOWS\SYSTEM32\CTxfiSpk.dll
+ 2007-04-09 16:19:28 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CT0060W.DAT
+ 2007-04-09 16:19:20 26,783 —-a-w C:\WINDOWS\SYSTEM32\Data\ctd20x.dat
+ 2007-04-09 16:19:36 201,502 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEAPSW.DAT
+ 2007-04-09 16:19:58 374,041 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEDSP2W.DAT
+ 2007-04-09 16:20:00 348,425 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEDSPHW.DAT
+ 2007-04-09 16:19:58 294,775 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEDSPKW.DAT
+ 2007-04-09 16:19:58 294,775 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEDSPLW.DAT
+ 2007-04-09 16:20:00 330,665 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEDSPPW.DAT
+ 2007-04-09 16:20:00 270,927 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEDSPTW.DAT
+ 2007-04-09 16:20:00 270,927 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEDSPUW.DAT
+ 2007-04-09 16:19:50 374,041 —-a-w C:\WINDOWS\SYSTEM32\Data\CTEDSPW.DAT
+ 2007-04-09 16:19:28 235,259 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0060W.DAT
+ 2007-04-09 16:19:30 235,259 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0061W.DAT
+ 2007-04-09 16:19:38 289,409 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0070W.DAT
+ 2007-04-09 16:19:38 289,409 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0073W.DAT
+ 2007-04-09 16:19:38 276,738 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0090W.DAT
+ 2007-04-09 16:19:42 275,169 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0091W.DAT
+ 2007-04-09 16:19:40 276,738 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0092W.DAT
+ 2007-04-09 16:19:44 274,587 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0095W.DAT
+ 2007-04-09 16:19:28 235,259 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0100W.DAT
+ 2007-04-09 16:19:30 235,259 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0101W.DAT
+ 2007-04-09 16:19:30 235,259 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0102W.DAT
+ 2007-04-09 16:19:32 235,259 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0103W.DAT
+ 2007-04-09 16:19:32 235,259 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0105W.DAT
+ 2007-04-09 16:19:26 232,158 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0150W.DAT
+ 2007-04-09 16:19:40 275,427 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0161W.DAT
+ 2007-04-09 16:19:40 276,738 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0162W.DAT
+ 2007-04-09 16:19:32 235,259 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0170W.DAT
+ 2007-04-09 16:19:32 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP017AW.DAT
+ 2007-04-09 16:19:34 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP017BW.DAT
+ 2007-04-09 16:19:34 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP017CW.DAT
+ 2007-04-09 16:19:34 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP017DW.DAT
+ 2007-04-09 16:19:34 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP017EW.DAT
+ 2007-04-09 16:19:34 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP017FW.DAT
+ 2007-04-09 16:19:36 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP017GW.DAT
+ 2007-04-09 16:19:36 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP017HW.DAT
+ 2007-04-09 16:19:40 275,169 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0191W.DAT
+ 2007-04-09 16:19:40 276,738 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0192W.DAT
+ 2007-04-09 16:19:30 236,189 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0221W.DAT
+ 2007-04-09 16:19:30 236,189 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0222W.DAT
+ 2007-04-09 16:19:42 277,159 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0230W.DAT
+ 2007-04-09 16:19:42 275,816 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0231W.DAT
+ 2007-04-09 16:19:42 277,159 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0232W.DAT
+ 2007-04-09 16:19:42 275,517 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0238W.DAT
+ 2007-04-09 16:19:44 319,070 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0240W.DAT
+ 2007-04-09 16:19:46 319,730 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0242W.DAT
+ 2007-04-09 16:19:46 318,800 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0243W.DAT
+ 2007-04-09 16:19:46 319,730 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0244W.DAT
+ 2007-04-09 16:19:46 318,254 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0245W.DAT
+ 2007-04-09 16:19:48 319,730 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0246W.DAT
+ 2007-04-09 16:19:48 318,341 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0249W.DAT
+ 2007-04-09 16:19:48 318,254 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0280W.DAT
+ 2007-04-09 16:19:50 318,254 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0320W.DAT
+ 2007-04-09 16:19:50 323,640 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0350W.DAT
+ 2007-04-09 16:19:50 321,529 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0352W.DAT
+ 2007-04-09 16:19:54 322,194 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0355W.DAT
- 2004-08-02 17:35:00 310,521 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0358W.DAT
+ 2007-04-09 16:19:52 321,552 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0358W.DAT
+ 2007-04-09 16:19:52 320,622 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0359W.DAT
+ 2007-04-09 16:19:52 320,076 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0360W.DAT
+ 2007-04-09 16:19:54 320,076 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0380W.DAT
+ 2007-04-09 16:19:56 319,757 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0400W.DAT
+ 2007-04-09 16:21:28 264,130 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0460W.DAT
+ 2007-04-09 16:21:32 264,130 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0462W.DAT
+ 2007-04-09 16:21:28 264,060 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0463W.DAT
+ 2007-04-09 16:21:30 264,130 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0464W.DAT
+ 2007-04-09 16:21:30 264,130 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0465W.DAT
+ 2007-04-09 16:21:28 264,130 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0466W.DAT
+ 2007-04-09 16:21:30 264,130 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0468W.DAT
+ 2007-04-09 16:21:30 264,130 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0469W.DAT
+ 2007-04-09 16:21:30 263,802 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP046AW.DAT
+ 2007-04-09 16:21:30 263,802 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP046BW.DAT
+ 2007-04-09 16:21:30 263,802 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP046CW.DAT
+ 2007-04-09 16:20:44 232,116 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0530L.DAT
+ 2007-04-09 16:20:02 321,377 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0530W.DAT
+ 2007-04-09 16:21:28 232,116 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0531L.DAT
+ 2007-04-09 16:20:46 321,377 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0531W.DAT
+ 2007-04-09 16:21:28 264,388 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0550W.DAT
+ 2007-04-09 16:21:32 264,060 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP055AW.DAT
+ 2007-04-09 16:19:56 319,757 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0600W.DAT
+ 2007-04-09 16:19:56 319,757 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0610W.DAT
+ 2007-04-09 16:19:58 319,757 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0669W.DAT
+ 2007-04-09 16:21:32 345,761 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0678W.DAT
+ 2007-04-09 16:21:28 345,761 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0679W.DAT
+ 2007-04-09 16:21:30 265,966 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0730W.DAT
+ 2007-04-09 16:21:32 265,966 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP073AW.DAT
+ 2007-04-09 16:21:30 263,543 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0760W.DAT
+ 2007-04-09 16:21:32 269,402 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0773W.DAT
+ 2007-04-09 16:21:32 268,778 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP0930W.DAT
+ 2007-04-09 16:19:22 233,684 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP1140W.DAT
+ 2007-04-09 16:19:20 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4620W.DAT
+ 2007-04-09 16:19:22 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4670W.DAT
+ 2007-04-09 16:19:22 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4760W.DAT
+ 2007-04-09 16:19:24 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4780W.DAT
+ 2007-04-09 16:19:26 232,158 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4790W.DAT
+ 2007-04-09 16:19:38 267,599 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4820W.DAT
+ 2007-04-09 16:19:24 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4830W.DAT
+ 2007-04-09 16:19:24 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4831W.DAT
+ 2007-04-09 16:19:26 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4832W.DAT
+ 2007-04-09 16:19:26 232,158 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4840W.DAT
+ 2007-04-09 16:19:22 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4850W.DAT
+ 2007-04-09 16:19:22 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4870W.DAT
+ 2007-04-09 16:19:24 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4871W.DAT
+ 2007-04-09 16:19:24 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4872W.DAT
+ 2007-04-09 16:19:24 233,024 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4875W.DAT
+ 2007-04-09 16:19:26 232,158 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4890W.DAT
+ 2007-04-09 16:19:28 232,158 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4891W.DAT
+ 2007-04-09 16:19:28 232,158 —-a-w C:\WINDOWS\SYSTEM32\Data\CTP4893W.DAT
+ 2007-04-09 16:19:30 235,142 —-a-w C:\WINDOWS\SYSTEM32\Data\CTPDXW.DAT
+ 2007-04-09 16:19:22 233,684 —-a-w C:\WINDOWS\SYSTEM32\Data\CTPM002W.DAT
+ 2007-04-09 16:19:20 2,091 —-a-w C:\WINDOWS\SYSTEM32\Data\cts20x.dat
+ 2007-04-09 16:19:02 48,640 —-a-w C:\WINDOWS\SYSTEM32\devreg.dll
- 2003-11-13 23:54:00 65,536 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\a3d.dll
+ 2007-04-09 16:32:58 34,816 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\a3d.dll
- 2008-06-20 10:44:38 138,368 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\afd.sys
+ 2004-08-04 12:00:00 138,496 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\afd.sys
- 2007-07-30 23:19:20 92,504 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
+ 2008-07-19 02:10:48 94,920 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
- 2008-06-20 17:41:10 148,992 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dnsapi.dll
+ 2008-02-20 05:32:43 148,992 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dnsapi.dll
+ 2004-08-04 03:08:00 60,288 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\drmk.sys
- 2004-08-04 12:00:00 123,904 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\guitrn.dll
+ 2005-04-28 19:16:29 133,120 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\guitrn.dll
- 2004-08-04 04:15:22 140,928 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\ks.sys
+ 2004-08-04 03:15:22 140,928 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\ks.sys
- 2004-08-04 12:00:00 19,968 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\log.dll
+ 2005-04-28 19:16:29 19,968 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\log.dll
- 2004-08-04 12:00:00 201,216 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\migism.dll
+ 2005-04-28 19:16:29 274,432 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\migism.dll
- 2004-08-04 12:00:00 103,424 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\migload.exe
+ 2005-04-28 00:12:58 103,424 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\migload.exe
- 2004-08-04 12:00:00 240,128 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\migwiz.exe
+ 2005-04-28 00:12:57 245,248 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\migwiz.exe
- 2006-09-15 12:36:32 29,696 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mimefilt.dll
+ 2008-03-07 16:56:41 29,696 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mimefilt.dll
- 2008-06-20 17:41:10 245,248 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mswsock.dll
+ 2004-08-04 12:00:00 245,248 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mswsock.dll
- 2006-09-15 12:36:32 98,304 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\nlhtml.dll
+ 2008-03-07 16:56:41 98,304 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\nlhtml.dll
- 2006-09-15 12:36:32 192,000 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\offfilt.dll
+ 2008-03-07 16:56:41 192,000 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\offfilt.dll
+ 2004-08-04 03:15:50 145,792 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\portcls.sys
- 2004-08-04 12:00:00 202,752 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\script.dll
+ 2005-04-28 19:16:29 215,552 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\script.dll
+ 2004-08-04 03:08:04 48,640 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\stream.sys
- 2004-08-04 12:00:00 168,960 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\sysmod.dll
+ 2005-04-28 19:16:29 193,024 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\sysmod.dll
- 2008-06-20 10:45:13 360,320 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
+ 2007-10-30 17:20:55 360,064 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
- 2008-06-20 09:52:06 225,920 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip6.sys
+ 2006-08-16 09:37:30 225,664 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip6.sys
- 2007-07-30 23:19:36 549,720 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
+ 2008-07-19 02:09:44 563,912 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
- 2007-07-30 23:19:16 53,080 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
+ 2008-07-19 02:10:42 53,448 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
- 2007-07-30 23:19:42 1,712,984 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
+ 2008-07-19 02:09:42 1,811,656 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
- 2007-07-30 23:19:32 325,976 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
+ 2008-07-19 02:09:46 325,832 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
- 2007-07-30 23:18:40 33,624 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
+ 2008-07-19 02:10:20 36,552 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
- 2007-07-30 23:19:28 203,096 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
+ 2008-07-19 02:09:44 205,000 -c–a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
- 2008-06-20 17:41:10 148,992 —-a-w C:\WINDOWS\SYSTEM32\dnsapi.dll
+ 2008-02-20 05:32:43 148,992 —-a-w C:\WINDOWS\SYSTEM32\dnsapi.dll
- 2008-06-20 10:44:38 138,368 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\afd.sys
+ 2004-08-04 12:00:00 138,496 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\afd.sys
- 2007-07-11 18:37:26 6,272 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\AWRTPD.sys
+ 2008-04-29 15:19:50 12,960 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\Awrtpd.sys
- 2007-08-07 17:58:08 8,320 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\AWRTRD.sys
+ 2008-04-29 15:19:54 15,648 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\Awrtrd.sys
- 2004-07-13 16:09:00 645,360 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctac32k.sys
+ 2007-04-10 08:19:30 511,272 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctac32k.sys
- 2004-08-06 16:43:00 366,384 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctaud2k.sys
+ 2007-04-10 08:20:38 520,488 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctaud2k.sys
- 2003-11-13 02:11:00 333,600 -c–a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctdvda2k.sys
+ 2007-04-10 08:21:06 347,128 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctdvda2k.sys
- 2004-07-13 16:11:00 178,672 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys
+ 2007-04-10 09:59:04 126,760 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys
- 2004-07-13 16:11:00 6,096 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctprxy2k.sys
+ 2007-04-10 08:25:46 14,632 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctprxy2k.sys
- 2004-07-13 16:12:00 130,288 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys
+ 2007-04-10 10:00:24 157,480 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys
- 2004-08-04 12:00:00 60,288 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\drmk.sys
+ 2004-08-04 03:08:00 60,288 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\drmk.sys
- 2004-07-13 16:13:00 145,488 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\emupia2k.sys
+ 2007-04-10 08:28:36 92,968 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\emupia2k.sys
- 2004-08-12 21:40:00 904,752 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ha10kx2k.sys
+ 2007-04-10 08:29:10 797,992 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ha10kx2k.sys
+ 2007-04-10 10:03:12 1,164,072 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ha20x2k.sys
- 2004-07-13 16:15:00 148,432 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\haP16v2k.sys
+ 2007-04-10 08:31:18 163,112 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\haP16v2k.sys
+ 2007-04-10 08:32:06 189,736 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\haP17v2k.sys
- 2005-10-21 23:52:48 21,568 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\HPZius12.sys
+ 2005-10-22 11:22:48 21,568 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\HPZius12.sys
+ 2007-07-19 19:10:28 127,768 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\klif.sys
- 2004-08-04 04:15:22 140,928 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ks.sys
+ 2004-08-04 03:15:22 140,928 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\ks.sys
+ 2003-04-14 20:00:40 32,512 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\MXOFX.SYS
- 2007-08-07 17:56:58 9,344 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\NSDriver.sys
+ 2008-04-29 15:20:00 15,648 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\NSDriver.sys
- 2004-08-06 23:29:00 6,656 -c–a-w C:\WINDOWS\SYSTEM32\DRIVERS\pfmodnt.sys
+ 2007-04-10 08:32:34 16,168 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\pfmodnt.sys
- 2004-08-04 12:00:00 145,792 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\portcls.sys
+ 2004-08-04 03:15:50 145,792 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\portcls.sys
- 2004-08-04 12:00:00 48,640 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\stream.sys
+ 2004-08-04 03:08:04 48,640 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\stream.sys
- 2008-06-20 10:45:13 360,320 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys
+ 2007-10-30 17:20:55 360,064 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys
- 2008-06-20 09:52:06 225,920 -c–a-w C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys
+ 2006-08-16 09:37:30 225,664 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys
- 2001-07-11 16:51:00 77,824 -c–a-w C:\WINDOWS\SYSTEM32\EAXAC3.DLL
+ 2001-07-11 06:51:00 77,824 —-a-w C:\WINDOWS\SYSTEM32\eaxac3.dll
+ 2007-04-09 16:19:18 5,120 —-a-w C:\WINDOWS\SYSTEM32\enlocstr.exe
- 2008-04-10 00:14:45 499,440 —-a-w C:\WINDOWS\SYSTEM32\FNTCACHE.DAT
+ 2008-09-23 18:16:07 499,440 —-a-w C:\WINDOWS\SYSTEM32\FNTCACHE.DAT
+ 2008-05-29 15:16:52 633,344 ——w C:\WINDOWS\SYSTEM32\gpprefcl.dll
+ 2005-10-25 08:57:28 286,720 -c–a-w C:\WINDOWS\SYSTEM32\HPZc3212(2).dll
+ 2007-04-09 16:33:38 11,776 —-a-w C:\WINDOWS\SYSTEM32\inres.dll
- 2006-12-15 06:30:58 49,248 -c–a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2008-06-10 05:21:01 135,168 —-a-w C:\WINDOWS\SYSTEM32\java.exe
- 2006-12-15 06:31:06 53,346 -c–a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2008-06-10 05:21:04 135,168 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
- 2006-12-15 08:09:14 127,078 -c–a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2008-06-10 06:32:34 139,264 —-a-w C:\WINDOWS\SYSTEM32\javaws.exe
- 2003-03-14 15:33:00 53,248 -c–a-w C:\WINDOWS\SYSTEM32\KILLAPPS.EXE
+ 2007-04-09 16:19:16 10,240 —-a-w C:\WINDOWS\SYSTEM32\killapps.exe
+ 2004-08-04 06:56:44 4,096 —-a-w C:\WINDOWS\SYSTEM32\ksuser(2).dll
- 2007-10-11 18:12:48 1,468,968 —-a-w C:\WINDOWS\SYSTEM32\LegitCheckControl.dll
+ 2008-03-20 22:06:36 1,480,232 —-a-w C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
+ 2008-07-09 13:05:08 796,048 —-a-w C:\WINDOWS\SYSTEM32\libeay32_0.9.6l.dll
- 2007-12-14 16:32:52 12,632 —-a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
+ 2008-05-16 15:58:04 12,632 —-a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
+ 2008-01-07 16:26:46 181,672 -c–a-w C:\WINDOWS\SYSTEM32\Macromed\Director\swdir_bckup.dll
+ 2008-03-25 02:32:44 218,496 —-a-r C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashUtil9f.exe
- 2008-02-04 13:26:47 74,137 —-a-w C:\WINDOWS\SYSTEM32\Macromed\Flash\uninstall_activeX.exe
+ 2008-09-26 06:51:59 74,649 —-a-w C:\WINDOWS\SYSTEM32\Macromed\Flash\uninstall_activeX.exe
- 2006-09-15 12:36:32 29,696 -c–a-w C:\WINDOWS\SYSTEM32\mimefilt.dll
+ 2008-03-07 16:56:41 29,696 —-a-w C:\WINDOWS\SYSTEM32\mimefilt.dll
- 2008-08-05 18:11:01 15,888,504 -c–a-w C:\WINDOWS\SYSTEM32\MRT.exe
+ 2008-08-26 20:28:12 16,208,504 -c–a-w C:\WINDOWS\SYSTEM32\MRT.exe
+ 2008-05-27 02:17:44 34,816 ——w C:\WINDOWS\SYSTEM32\msscb.dll
+ 2008-05-27 02:17:26 60,416 ——w C:\WINDOWS\SYSTEM32\msscntrs.dll
+ 2008-05-27 02:17:38 11,776 ——w C:\WINDOWS\SYSTEM32\msshooks.dll
+ 2008-05-27 02:18:34 231,936 ——w C:\WINDOWS\SYSTEM32\msshsq.dll
+ 2008-05-27 02:17:26 87,552 ——w C:\WINDOWS\SYSTEM32\mssitlb.dll
+ 2008-05-27 02:18:26 350,208 ——w C:\WINDOWS\SYSTEM32\mssph.dll
+ 2008-05-27 02:18:56 203,776 ——w C:\WINDOWS\SYSTEM32\mssphtb.dll
+ 2008-05-27 02:17:28 32,768 ——w C:\WINDOWS\SYSTEM32\mssprxy.dll
+ 2008-05-27 02:21:26 1,418,240 ——w C:\WINDOWS\SYSTEM32\mssrch.dll
+ 2008-05-27 02:18:42 44,032 ——w C:\WINDOWS\SYSTEM32\msstrc.dll
- 2004-08-04 11:00:00 407,552 -c–a-w C:\WINDOWS\SYSTEM32\MSTSC.EXE
+ 2006-11-07 08:06:47 600,576 —-a-w C:\WINDOWS\SYSTEM32\mstsc.exe
- 2004-08-04 11:00:00 655,360 -c–a-w C:\WINDOWS\SYSTEM32\MSTSCAX.DLL
+ 2006-11-13 06:02:58 1,866,240 —-a-w C:\WINDOWS\SYSTEM32\mstscax.dll
- 2008-06-20 17:41:10 245,248 —-a-w C:\WINDOWS\SYSTEM32\mswsock.dll
+ 2004-08-04 12:00:00 245,248 —-a-w C:\WINDOWS\SYSTEM32\mswsock.dll
+ 2006-12-04 18:37:58 1,317,648 —-a-w C:\WINDOWS\SYSTEM32\msxml6.dll
+ 2006-10-05 08:31:10 79,872 —-a-w C:\WINDOWS\SYSTEM32\msxml6r.dll
+ 2003-04-01 23:02:46 3,072 —-a-w C:\WINDOWS\SYSTEM32\MXOCOINS.dll
+ 2002-12-16 18:49:38 12,382 —-a-w C:\WINDOWS\SYSTEM32\MXOUI32.DLL
+ 2003-01-17 14:50:06 98,394 —-a-w C:\WINDOWS\SYSTEM32\MXOUN.EXE
- 2006-09-15 12:36:32 98,304 -c–a-w C:\WINDOWS\SYSTEM32\nlhtml.dll
+ 2008-03-07 16:56:41 98,304 —-a-w C:\WINDOWS\SYSTEM32\nlhtml.dll
+ 2006-11-23 04:55:48 782,336 —-a-w C:\WINDOWS\SYSTEM32\OALInst.exe
+ 2008-05-27 02:19:36 273,408 ——w C:\WINDOWS\SYSTEM32\oeph.dll
+ 2008-05-27 02:19:16 11,264 ——w C:\WINDOWS\SYSTEM32\oephRes.dll
- 2006-09-15 12:36:32 192,000 -c–a-w C:\WINDOWS\SYSTEM32\offfilt.dll
+ 2008-03-07 16:56:41 192,000 —-a-w C:\WINDOWS\SYSTEM32\offfilt.dll
- 2007-03-05 17:34:28 676,224 -c–a-w C:\WINDOWS\SYSTEM32\OGACheckControl.DLL
+ 2008-02-04 22:23:10 693,792 —-a-w C:\WINDOWS\SYSTEM32\OGACheckControl.DLL
- 2008-05-12 01:52:14 73,534 —-a-w C:\WINDOWS\SYSTEM32\PERFC009.DAT
+ 2008-09-23 20:11:11 95,422 —-a-w C:\WINDOWS\SYSTEM32\PERFC009.DAT
- 2008-05-12 01:52:14 429,838 —-a-w C:\WINDOWS\SYSTEM32\PERFH009.DAT
+ 2008-09-23 20:11:11 507,222 —-a-w C:\WINDOWS\SYSTEM32\PERFH009.DAT
+ 2003-11-14 00:05:00 114,688 —-a-w C:\WINDOWS\SYSTEM32\PIAPROXY(2).DLL
- 2003-11-14 00:05:00 114,688 —-a-w C:\WINDOWS\SYSTEM32\PIAPROXY.DLL
+ 2007-04-09 16:21:42 81,920 —-a-w C:\WINDOWS\SYSTEM32\piaproxy.dll
+ 2008-05-27 02:18:08 71,680 ——w C:\WINDOWS\SYSTEM32\propdefs.dll
+ 2008-05-27 02:17:48 754,176 ——w C:\WINDOWS\SYSTEM32\propsys.dll
+ 2007-04-09 16:32:32 37,888 —-a-w C:\WINDOWS\SYSTEM32\psconv.exe
+ 2007-04-09 16:32:36 38,400 —-a-w C:\WINDOWS\SYSTEM32\readreg.exe
- 2001-06-28 17:05:00 36,864 -c–a-w C:\WINDOWS\SYSTEM32\REGPLIB.EXE
+ 2007-04-09 16:21:44 48,128 —-a-w C:\WINDOWS\SYSTEM32\regplib.exe
+ 2005-10-21 23:52:48 21,568 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0018\DriverFiles\drivers\dot4\Win2000\HPZius12.sys
+ 2005-10-25 08:57:28 286,720 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0018\DriverFiles\HPZc3212.dll
+ 2004-08-12 21:52:00 140,643 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0022\DriverFiles\Win2K_XP\ctbas2w.dat
+ 2004-08-03 22:54:00 53,932 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0022\DriverFiles\Win2K_XP\ctdaught.dat
+ 2003-11-26 18:29:00 127,226 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0022\DriverFiles\Win2K_XP\ctdlang.dat
+ 2004-08-12 21:52:00 264,466 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0022\DriverFiles\Win2K_XP\ctsbas2w.dat
+ 2003-04-07 22:09:48 118,784 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0029\DriverFiles\MXOALDR.EXE
+ 2003-04-01 23:02:46 3,072 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0029\DriverFiles\MXOCOINS.dll
+ 2003-04-14 20:00:40 32,512 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0029\DriverFiles\MXOFX.SYS
+ 2002-12-16 18:49:38 282,624 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0029\DriverFiles\MXONTTRY.EXE
+ 2002-12-16 18:49:38 12,382 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0029\DriverFiles\MXOUI32.DLL
+ 2003-01-17 14:50:06 98,394 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0029\DriverFiles\MXOUN.EXE
+ 2003-11-13 23:54:00 65,536 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Common\a3d.dll
+ 2003-11-14 00:02:00 114,688 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Common\commonfx.dll
+ 2004-07-13 15:53:00 585,728 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Common\ctaudfx.dll
+ 2003-11-14 00:04:00 606,208 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Common\ctsblfx.dll
+ 2001-08-17 20:35:00 36,864 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Common\sfman32.dll
+ 2004-08-04 12:00:00 60,288 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\i386\drmk.sys
+ 2004-08-04 04:15:22 140,928 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\i386\ks.sys
+ 2004-08-04 06:56:44 4,096 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\i386\ksuser.dll
+ 2004-08-04 12:00:00 145,792 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\i386\portcls.sys
+ 2004-08-04 12:00:00 48,640 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\i386\stream.sys
+ 2004-08-04 12:00:00 23,552 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\i386\wdmaud.drv
+ 2004-07-13 16:09:00 645,360 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctac32k.sys
+ 2004-08-06 16:43:00 366,384 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctaud2k.sys
+ 2007-04-09 16:21:28 149,838 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctbas2w.dat
+ 2007-04-09 16:19:20 53,932 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctdaught.dat
+ 2003-11-26 18:29:00 127,226 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctdlang.dat
+ 2003-11-13 02:11:00 333,600 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctdvda2k.sys
+ 2004-07-13 16:11:00 178,672 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctoss2k.sys
+ 2004-07-13 16:11:00 6,096 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctprxy2k.sys
+ 2007-04-09 16:19:44 274,587 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctsbas2w.dat
+ 2004-07-13 16:12:00 130,288 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ctsfm2k.sys
+ 2004-07-13 16:13:00 145,488 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\emupia2k.sys
+ 2004-08-12 21:40:00 904,752 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\ha10kx2k.sys
+ 2004-07-13 16:15:00 148,432 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\haP16v2k.sys
+ 2004-08-06 23:29:00 6,656 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0030\DriverFiles\Win2K_XP\pfmodnt.sys
+ 2005-10-21 23:58:58 16,496 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0031\DriverFiles\drivers\dot4\Win2000\HPZipr12.sys
+ 2005-10-21 23:58:52 49,920 —-a-w C:\WINDOWS\SYSTEM32\ReinstallBackups\0032\DriverFiles\drivers\dot4\Win2000\HPZid412.sys
- 2008-08-29 03:42:19 463,944 -c–a-w C:\WINDOWS\SYSTEM32\Restore\rstrlog.dat
+ 2008-09-23 18:14:51 1,111,880 -c–a-w C:\WINDOWS\SYSTEM32\Restore\rstrlog.dat
+ 2008-05-27 02:18:32 38,400 ——w C:\WINDOWS\SYSTEM32\rtffilt.dll
+ 2008-05-27 02:17:56 87,552 ——w C:\WINDOWS\SYSTEM32\searchfilterhost.exe
+ 2008-05-27 02:18:44 439,808 ——w C:\WINDOWS\SYSTEM32\searchindexer.exe
+ 2008-05-27 02:18:18 184,832 ——w C:\WINDOWS\SYSTEM32\searchprotocolhost.exe
+ 2007-02-15 19:22:26 688,000 —-a-w C:\WINDOWS\SYSTEM32\SelfHelpControl.DLL
- 2001-08-17 20:35:00 36,864 -c–a-w C:\WINDOWS\SYSTEM32\sfman32.dll
+ 2007-04-09 16:21:48 22,528 —-a-w C:\WINDOWS\SYSTEM32\sfman32.dll
- 2003-11-14 00:05:00 172,032 -c–a-w C:\WINDOWS\SYSTEM32\SFMS32.DLL
+ 2007-04-09 16:21:46 130,048 —-a-w C:\WINDOWS\SYSTEM32\sfms32.dll
+ 2008-07-19 02:10:20 36,552 —-a-w C:\WINDOWS\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.784\wups.dll
+ 2008-07-19 02:10:40 45,768 —-a-w C:\WINDOWS\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.784\wups2.dll
- 2006-09-25 21:58:48 23,856 —-a-w C:\WINDOWS\SYSTEM32\spupdsvc.exe
+ 2007-10-05 19:42:10 23,856 —-a-w C:\WINDOWS\SYSTEM32\spupdsvc.exe
+ 2008-05-27 02:17:30 301,568 ——w C:\WINDOWS\SYSTEM32\srchadmin.dll
+ 2008-05-27 01:59:40 106,605 ——w C:\WINDOWS\SYSTEM32\structuredqueryschema.bin
+ 2008-05-27 01:59:42 18,904 ——w C:\WINDOWS\SYSTEM32\structuredqueryschematrivial.bin
+ 2008-05-27 02:21:08 1,582,592 ——w C:\WINDOWS\SYSTEM32\tquery.dll
+ 2008-05-27 02:19:20 97,792 ——w C:\WINDOWS\SYSTEM32\UncCplExt.dll
+ 2008-05-27 02:19:22 143,872 ——w C:\WINDOWS\SYSTEM32\UncDMS.dll
+ 2008-05-27 02:19:28 108,032 ——w C:\WINDOWS\SYSTEM32\UncNE.dll
+ 2008-05-27 02:19:28 131,072 ——w C:\WINDOWS\SYSTEM32\UncPH.dll
+ 2008-05-27 02:19:26 2,048 ——w C:\WINDOWS\SYSTEM32\UncRes.dll
- 2004-01-07 17:21:24 237,936 -c–a-w C:\WINDOWS\SYSTEM32\unicows.dll
+ 2008-02-01 07:21:04 245,408 —-a-w C:\WINDOWS\SYSTEM32\unicows.dll
+ 2005-04-27 23:15:36 17,920 ——w C:\WINDOWS\SYSTEM32\USMT\cobramsg.dll
- 2004-08-04 12:00:00 123,904 -c–a-w C:\WINDOWS\SYSTEM32\USMT\guitrn.dll
+ 2005-04-28 19:16:29 133,120 —-a-w C:\WINDOWS\SYSTEM32\USMT\guitrn.dll
+ 2005-04-28 19:16:29 115,200 ——w C:\WINDOWS\SYSTEM32\USMT\guitrna.dll
- 2004-08-04 12:00:00 4,096 -c–a-w C:\WINDOWS\SYSTEM32\USMT\iconlib.dll
+ 2005-04-27 23:15:45 2,560 —-a-w C:\WINDOWS\SYSTEM32\USMT\iconlib.dll
- 2004-08-04 12:00:00 19,968 -c–a-w C:\WINDOWS\SYSTEM32\USMT\log.dll
+ 2005-04-28 19:16:29 19,968 —-a-w C:\WINDOWS\SYSTEM32\USMT\log.dll
- 2004-08-04 12:00:00 201,216 -c–a-w C:\WINDOWS\SYSTEM32\USMT\migism.dll
+ 2005-04-28 19:16:29 274,432 —-a-w C:\WINDOWS\SYSTEM32\USMT\migism.dll
+ 2005-04-28 16:16:30 261,120 ——w C:\WINDOWS\SYSTEM32\USMT\migisma.dll
- 2004-08-04 12:00:00 103,424 -c–a-w C:\WINDOWS\SYSTEM32\USMT\migload.exe
+ 2005-04-28 00:12:58 103,424 —-a-w C:\WINDOWS\SYSTEM32\USMT\migload.exe
- 2004-08-04 12:00:00 240,128 -c–a-w C:\WINDOWS\SYSTEM32\USMT\migwiz.exe
+ 2005-04-28 00:12:57 245,248 —-a-w C:\WINDOWS\SYSTEM32\USMT\migwiz.exe
+ 2005-04-28 00:12:57 241,152 ——w C:\WINDOWS\SYSTEM32\USMT\migwiza.exe
- 2004-08-04 12:00:00 202,752 -c–a-w C:\WINDOWS\SYSTEM32\USMT\script.dll
+ 2005-04-28 19:16:29 215,552 —-a-w C:\WINDOWS\SYSTEM32\USMT\script.dll
+ 2005-04-28 19:16:29 199,680 ——w C:\WINDOWS\SYSTEM32\USMT\scripta.dll
- 2004-08-04 12:00:00 168,960 -c–a-w C:\WINDOWS\SYSTEM32\USMT\sysmod.dll
+ 2005-04-28 19:16:29 193,024 —-a-w C:\WINDOWS\SYSTEM32\USMT\sysmod.dll
+ 2005-04-28 19:16:29 173,568 ——w C:\WINDOWS\SYSTEM32\USMT\sysmoda.dll
+ 2008-07-09 13:05:10 83,432 —-a-w C:\WINDOWS\SYSTEM32\vsdata.dll
+ 2008-07-09 13:05:22 394,952 —-a-w C:\WINDOWS\SYSTEM32\vsdatant.sys
+ 2008-07-09 13:05:10 157,160 —-a-w C:\WINDOWS\SYSTEM32\vsinit.dll
+ 2008-07-09 13:05:10 103,912 —-a-w C:\WINDOWS\SYSTEM32\vsmonapi.dll
+ 2008-07-09 13:05:10 275,944 —-a-w C:\WINDOWS\SYSTEM32\vspubapi.dll
+ 2008-07-09 13:05:10 71,144 —-a-w C:\WINDOWS\SYSTEM32\vsregexp.dll
+ 2008-07-09 13:05:12 472,552 —-a-w C:\WINDOWS\SYSTEM32\vsutil.dll
+ 2008-07-09 13:05:12 46,568 —-a-w C:\WINDOWS\SYSTEM32\vswmi.dll
+ 2008-07-09 13:05:12 99,816 —-a-w C:\WINDOWS\SYSTEM32\vsxml.dll
+ 2004-08-04 12:00:00 23,552 —-a-w C:\WINDOWS\SYSTEM32\wdmaud(2).drv
+ 2007-04-10 19:00:46 236,928 —-a-w C:\WINDOWS\SYSTEM32\WgaLogon(3).dll
+ 2007-04-10 19:00:46 236,928 —-a-w C:\WINDOWS\SYSTEM32\WgaLogon(4).dll
- 2006-10-19 01:47:20 295,936 —-a-w C:\WINDOWS\SYSTEM32\wmpeffects.dll
+ 2008-06-24 22:12:58 295,936 —-a-w C:\WINDOWS\SYSTEM32\wmpeffects.dll
+ 2008-05-27 02:18:34 56,320 ——w C:\WINDOWS\SYSTEM32\xmlfilter.dll
+ 2008-07-09 13:05:12 83,432 —-a-w C:\WINDOWS\SYSTEM32\zlcomm.dll
+ 2008-07-09 13:05:12 71,144 —-a-w C:\WINDOWS\SYSTEM32\zlcommdb.dll
+ 2008-07-09 13:05:06 370,208 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\av.dll
+ 2007-05-31 04:03:30 65,248 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\bases\aphish.dat
+ 2006-06-30 18:47:36 21,568 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2007-05-31 04:03:30 1,628 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\bases\pdmkl.dat
+ 2007-05-31 04:03:16 77,824 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-31 04:03:16 110,592 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-31 04:03:16 331,776 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-31 04:03:16 38,400 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\FSSync.dll
+ 2006-09-20 03:12:14 208,960 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\inv.dll
+ 2007-12-03 18:53:58 282,624 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\kave.dll
+ 2006-12-19 22:13:52 1,093,632 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\libeay32.dll
+ 2007-05-31 04:03:20 548,864 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-31 04:03:20 626,688 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\msvcr80.dll
+ 2007-05-31 04:03:18 184,320 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\prloader.dll
+ 2007-05-31 04:03:22 90,112 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\prremote.dll
+ 2007-12-03 18:53:58 139,264 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\ScanningProcess.exe
+ 2006-12-19 22:13:52 200,704 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\ssleay32.dll
+ 2008-07-09 13:05:06 99,816 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\camupd.dll
+ 2004-01-30 16:35:08 813,568 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\dbghelp.dll
+ 2008-07-09 13:05:08 128,480 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\fbl.dll
+ 2008-07-09 13:05:08 38,376 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\featuremap.dll
+ 2008-07-09 13:05:08 321,016 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\imsecure.dll
+ 2008-07-09 13:05:24 288,144 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2008-09-01 08:15:08 152,976 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\licenseui.zip.dll
+ 2008-07-09 13:05:24 26,000 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\zlsvc.zip.dll
+ 2008-07-09 13:05:24 1,361,296 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\zpy.zip.dll
+ 2008-07-09 13:05:24 71,056 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\zui.zip.dll
+ 2008-07-09 13:06:26 30,184 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2008-07-09 13:06:26 30,216 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
+ 2008-02-27 07:10:26 714,208 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\qrbase.dll
+ 2008-02-27 07:10:28 792,032 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\qrsrecl.dll
+ 2008-07-09 13:05:08 173,544 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\scheduler.dll
+ 2008-01-21 12:34:36 7,603,688 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\spyware.dat
+ 2008-02-27 07:10:32 1,504,736 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\srescan.dll
+ 2008-02-27 07:10:44 51,176 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\srescan.sys
+ 2008-07-09 13:05:10 456,168 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\ssleay32.dll
+ 2008-07-09 13:06:26 214,528 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2008-07-09 13:06:30 3,266,040 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2006-09-05 00:59:14 503,875 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\upd_core.dll
+ 2007-10-11 20:50:32 832,984 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\updating.dll
+ 2008-07-09 13:05:18 144,936 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\updclient.exe
+ 2007-01-11 21:31:06 286,787 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\updtrsdk.dll
+ 2008-07-09 13:05:10 108,008 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsavpro.dll
+ 2008-07-09 13:05:10 83,432 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsdb.dll
+ 2008-07-09 13:05:18 75,304 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
+ 2008-07-09 13:05:10 2,029,032 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsmondll.dll
+ 2008-07-09 13:05:12 1,361,384 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsruledb.dll
+ 2008-07-09 13:05:12 239,080 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsvault.dll
+ 2008-01-21 12:34:36 7,603,688 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlasdbup.dat
+ 2008-07-09 13:05:12 177,640 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlparser.dll
+ 2008-07-09 13:05:12 79,344 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlquarantine.dll
+ 2008-07-09 13:05:14 382,440 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlsre.dll
+ 2008-07-09 13:05:14 120,296 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlupdate.dll
+ 2008-09-28 18:43:34 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_568.dat
- 2003-09-23 14:50:28 35,520 -c–a-w C:\WINDOWS\UDHID.dll
+ 2007-01-30 18:52:50 28,755 —-a-w C:\WINDOWS\UDHID.dll
+ 2008-04-15 17:54:19 1,724,416 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-09-28 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"tgcmd"="C:\Program Files\support.com\bin\tgcmd.exe" [2002-04-24 1544192]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 98304]
"Dimension4"="C:\Program Files\D4\D4.exe" [2004-02-04 200704]
"itype"="c:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-28 1235736]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"MXO Auto Loader"="C:\WINDOWS\MXOALDR.EXE" [2003-04-07 118784]
"CTHelper"="CTHELPER.EXE" [2007-04-09 C:\WINDOWS\SYSTEM32\CtHelper.exe]

C:\Documents and Settings\TheCat\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-06-03 45056]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP53"= SP5X_32.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"VIDC.SP59"= SP5X_32.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^STK02N 2.2 PNP Monitor.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\STK02N 2.2 PNP Monitor.lnk.disabled
backup=C:\WINDOWS\pss\STK02N 2.2 PNP Monitor.lnk.disabledCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=C:\WINDOWS\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^TheCat^Start Menu^Programs^Startup^Block Tards.lnk]
path=C:\Documents and Settings\TheCat\Start Menu\Programs\Startup\Block Tards.lnk
backup=C:\WINDOWS\pss\Block Tards.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
–a–c— 2003-06-18 03:00 45056 C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
–a–c— 2003-05-21 20:37 229437 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
–a–c— 2004-08-23 20:19 57344 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
–a—— 2007-03-15 17:16 454784 C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Metrics]
–a–c— 2004-01-16 14:11 368640 C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a–c— 2004-12-14 12:07 176128 C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb12.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
–a—— 2003-05-21 15:30 45056 C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
—–c— 2004-09-24 17:22 1916928 C:\Program Files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 C:\WINDOWS\SYSTEM32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
–a–c— 2004-04-11 22:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2004-11-17 05:41 77824 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
——— 2008-08-18 18:41 1832272 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Mechanic Popup Stopper]
–a—— 2004-10-26 16:39 592896 C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Mechanic Registry Compact Handler]
–a—— 2004-10-26 16:39 2919424 C:\Program Files\iolo\System Mechanic 5\SysMech5.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=3 (0x3)
"usnjsvc"=3 (0x3)
"MDM"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"C:\\Program Files\\D4\\D4.exe"=
"C:\\Program Files\\support.com\\bin\\tgcmd.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"C:\\Program Files\\Real\\RealArcade\\RNArcade.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\DAP\\DAP.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\NeverwinterNights\\NWN\\nwmain.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\WINDOWS\\SYSTEM32\\mmc.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-28 97928]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-28 231704]
R3 P1050VID;Creative WebCam Pro eX (Video);C:\WINDOWS\system32\DRIVERS\P1050Wnt.sys [2003-01-02 179853]
S3 GameConsoleService;GameConsoleService;C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe [2008-01-29 165416]
S3 KMW_KBD;Kensington Input Devices Class filter driver;C:\WINDOWS\system32\DRIVERS\KMW_KBD.sys [ ]
S3 KMW_USB;Kensington MouseWorks USB filter driver;C:\WINDOWS\system32\DRIVERS\KMW_USB.sys [ ]
S3 LiveTurbineMessageService;Turbine Message Service - Live;C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe [2008-08-18 249856]
S3 LiveTurbineNetworkService;Turbine Network Service - Live;C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe [2008-08-18 212992]
S3 LVBulk;LVBulk Service;C:\WINDOWS\system32\DRIVERS\LVBulk.sys [2001-09-24 10261]
S3 PID_0900_V;Logitech ClickSmart 310(PID_0900_V);C:\WINDOWS\system32\DRIVERS\LV551AV.sys [2001-09-24 217271]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 12672]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-(Default) - (no file)
WebBrowser-{015E82AA-5CA3-405D-BD84-2DA318655450} - (no file)


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/ig?hl=en
R0 -: HKLM-Main,Window Title = Microsoft Internet Explorer
R0 -: HKLM-Main,Search Bar =
O8 -: &Clean; Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 -: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm
O8 -: &Google; Search
O8 -: &Translate; English Word
O8 -: Backward Links
O8 -: Cached Snapshot of Page
O8 -: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 -: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm
O8 -: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 -: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 -: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 -: Similar Pages
O8 -: Translate Page into English

O16 -: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F} - hxxps://favorites.live.com/cab/ImportAx.cab?v=13,0,0831,02
C:\WINDOWS\Downloaded Program Files\ImportAx.inf
C:\WINDOWS\Downloaded Program Files\ImportAx.dll

O16 -: {7D492D61-303A-45C3-8A55-63449339943D} - hxxp://www.shockwave.com/content/nightshiftcode/sis/NightShiftCodeWeb.1.0.0.5.cab
C:\WINDOWS\Downloaded Program Files\NightShiftCodeWeb.1.0.0.5.inf
C:\WINDOWS\Downloaded Program Files\NightShiftCodeWeb.1.0.0.5.dll

O16 -: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} - hxxp://www.shockwave.com/content/zenerchi/sis/ZenerchiWeb.1.0.0.10.cab
C:\WINDOWS\Downloaded Program Files\zenerchi.1.0.0.10.inf
C:\WINDOWS\Downloaded Program Files\zenerchi.1.0.0.10.dll

O16 -: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game02.zylom.com/activex/zylomgamesplayer.cab
C:\WINDOWS\Downloaded Program Files\ZylomGamesPlayer.inf
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\zylomgamesplayer.dll

O16 -: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} - hxxp://www.shockwave.com/content/petshophop/sis/petshophopweb.1.0.0.17.cab
C:\WINDOWS\Downloaded Program Files\PetShopHopWeb.1.0.0.17.inf
C:\WINDOWS\Downloaded Program Files\PetShopHopWeb.1.0.0.17.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 18:44:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-09-28 18:46:21
ComboFix-quarantined-files.txt 2008-09-28 22:46:10
ComboFix2.txt 2008-08-31 23:41:33

Pre-Run: 231,933,595,648 bytes free
Post-Run: 231,923,871,744 bytes free

1050 — E O F — 2008-09-23 18:31:10

Here's the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:22:22 PM, on 9/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\THJ.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [Dimension4] C:\Program Files\D4\D4.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Clean; Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab?v=13,0,0831,02
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.67.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.microsoftvirtuallabs.com/virtua…iveXClient1.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.53.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149296841921
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {7D492D61-303A-45C3-8A55-63449339943D} (CPlayFirstNightShiftControl Object) - http://www.shockwave.com/content/nightshif…Web.1.0.0.5.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab70018.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn.com/binframework/v10/…gr.cab31267.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://www.shockwave.com/content/zenerchi/…eb.1.0.0.10.cab
O16 - DPF: {BCF9A64D-1440-4404-863C-F5DF2B99F798} (MSN Games - Catan Online) - http://zone.msn.com/bingame/zpagames/zpa_catan.cab55579.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.32.17/ttinst.cab
O16 - DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} (CPlayFirstPetShopHopControl Object) - http://www.shockwave.com/content/petshopho…eb.1.0.0.17.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/A…ersion=1,0,0,10
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe
O23 - Service: Turbine Network Service - Live (LiveTurbineNetworkService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

–
End of file - 13677 bytes

Thank you again. Very much appreciated.
You need To disable TeaTimer, it can stop our fix.

The best way is to do both, Right click the system tray icon and shut down. This will reset TT's registry snapshot. Then, open spybot in advanced mode and turn it off. When cleaning is done, open Spybot in advanced mode to turn back on. Once fix is completed in the all clear post!!



Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\Temp\gwn-ingamecinematic01.zip
C:\WINDOWS\SYSTEM32\ubtmmund.tmp
C:\WINDOWS\SYSTEM32\badgNXyb.ini
C:\WINDOWS\system32\DRIVERS\LV551AV.sys

Folder::
C:\Temp\gwn-ingamecinematic01
C:\Program Files\runscanner
C:\VundoFix Backups

Driver::
LV551AV

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
When I launched HijackThis I received the following error message (rememberred to copy it down this time):

An unexpected error has occured at procedure: modRegistry_IniGetString(sFile=system.ini, sSection=boot, sValue=Shell)
Error #5 - Invalid procedure call or argument

Windows version: Windows NT 5.01.2600
MSIE version: 7.05730.11
HijackThis version: 2.0.2

It hung up even worse on the trusted zone enumeration. There was a whiteout of the entire box for a good 5 minutes. Now I have to say thaat the only reason I'm saying it's the trusted zone enumeration is because that is what's on the title bar when it hangs up.

Apparently ComboFix triggers the AVG scanning icon. I does however go away on reboot.

I'm still getting the "Done, but with errors on page," on this and other sites. i.e., Castlecops forum - no errors; Speedtest.net - errors; Safer Networking Forums - errors; Lavasoft Forums - no errors; PC Pitstop - errors on every page. Don't know if that helps or not.

Here's the ComboFix log:

ComboFix 08-09-27.06 - TheCat 2008-09-28 20:53:59.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.463 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\TheCat\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Temp\gwn-ingamecinematic01.zip
C:\WINDOWS\SYSTEM32\badgNXyb.ini
C:\WINDOWS\system32\DRIVERS\LV551AV.sys
C:\WINDOWS\SYSTEM32\ubtmmund.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\runscanner
C:\Program Files\runscanner\RunScanner.exe
C:\Temp\gwn-ingamecinematic01
C:\Temp\gwn-ingamecinematic01.zip
C:\Temp\gwn-ingamecinematic01\Nightfall_in_game_cinematic.wmv
C:\VundoFix Backups
C:\WINDOWS\SYSTEM32\badgNXyb.ini
C:\WINDOWS\system32\DRIVERS\LV551AV.sys
C:\WINDOWS\SYSTEM32\ubtmmund.tmp

.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-29 )))))))))))))))))))))))))))))))
.

2008-09-28 14:21 . 2008-09-28 14:22 d——– C:\ATF Cleaner
2008-09-27 14:39 . 2008-09-28 20:51 4,932,601 –a—— C:\WINDOWS\{00000004-00000000-00000001-00001102-00000004-20061102}.BAK
2008-09-27 04:13 . 2008-09-27 04:13 d——– C:\Program Files\ERUNT
2008-09-26 02:22 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-09-23 23:05 . 2008-09-23 23:56 d——– C:\Documents and Settings\TheCat\Application Data\ForgottenRiddles2
2008-09-23 16:11 . 2008-09-23 16:11 d——– C:\Documents and Settings\TheCat\Application Data\Windows Desktop Search
2008-09-23 13:56 . 2008-09-28 20:06 11,564 –a—— C:\WINDOWS\SYSTEM32\DVCState-{00000004-00000000-00000001-00001102-00000004-20061102}.rfx
2008-09-23 13:32 . 2008-09-23 13:32 d——– C:\Program Files\MSBuild
2008-09-23 13:30 . 2008-09-23 14:13 d——– C:\WINDOWS\SYSTEM32\XPSViewer
2008-09-23 13:29 . 2008-09-23 13:29 d——– C:\Program Files\Reference Assemblies
2008-09-23 13:28 . 2008-09-23 13:28 d——– C:\1cd346d3b5488ae6c87b278d14
2008-09-23 13:16 . 2008-09-23 13:16 d——– C:\Program Files\MSXML 6.0
2008-09-23 13:12 . 2006-11-13 02:02 288,768 ——— C:\WINDOWS\SYSTEM32\rhttpaa.dll
2008-09-23 13:12 . 2006-11-13 02:02 116,736 ——— C:\WINDOWS\SYSTEM32\aaclient.dll
2008-09-23 13:12 . 2006-11-13 02:02 36,352 ——— C:\WINDOWS\SYSTEM32\tsgqec.dll
2008-09-19 05:23 . 2008-09-19 05:23 d——– C:\Program Files\Intel Corporation
2008-09-19 04:25 . 2008-09-19 04:25 d——– C:\Documents and Settings\All Users\Application Data\Turbine
2008-09-19 04:24 . 2008-09-19 04:36 d——– C:\Program Files\Turbine
2008-09-16 18:57 . 2008-09-16 19:19 d——– C:\Documents and Settings\TheCat\Application Data\Righteous Kill
2008-09-15 01:27 . 2008-09-15 01:28 d——– C:\Program Files\NCSoft
2008-09-13 08:46 . 1999-09-10 07:06 45,056 –a—— C:\WINDOWS\SYSTEM32\wnaspi32.dll
2008-09-13 08:46 . 1999-09-10 07:06 25,244 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aspi32.sys
2008-09-13 08:46 . 1999-09-10 07:06 5,600 –a—— C:\WINDOWS\SYSTEM\winaspi.dll
2008-09-13 08:46 . 1999-09-10 07:06 4,672 –a—— C:\WINDOWS\SYSTEM\wowpost.exe
2008-09-13 07:55 . 2008-09-13 07:55 d——– C:\Documents and Settings\TheCat\Application Data\Ahead
2008-09-12 19:48 . 2008-09-12 19:48 d——– C:\Documents and Settings\All Users\Application Data\PCPitstop
2008-09-12 06:12 . 2008-09-12 06:12 d——– C:\Documents and Settings\TheCat\Application Data\AppDataLow
2008-09-06 00:22 . 2008-09-06 00:22 d——– C:\Program Files\AntiRootkit
2008-09-03 04:13 . 2008-09-05 04:41 d——– C:\Documents and Settings\TheCat\Application Data\SPORE Creature Creator
2008-09-03 04:11 . 2008-09-03 04:11 d——– C:\ProgramData
2008-09-03 04:10 . 2008-09-03 04:14 2,436 –a—— C:\WINDOWS\SYSTEM32\ealregsnapshot1.reg
2008-09-03 04:09 . 2008-09-03 06:11 d——– C:\Program Files\Electronic Arts
2008-09-02 18:32 . 2008-09-02 18:32 d——– C:\Documents and Settings\All Users\Application Data\TheRace_dev
2008-09-01 16:39 . 2008-09-06 05:51 d——– C:\Program Files\FontList
2008-09-01 13:17 . 2008-09-01 15:10 d——– C:\Program Files\ZonedOut
2008-09-01 03:54 . 2008-09-28 20:59 18,849,824 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2008-09-01 03:54 . 2008-09-28 20:06 220,820 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
2008-09-01 03:51 . 2008-09-01 03:51 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-09-01 03:51 . 2008-07-09 09:05 75,248 –a—— C:\WINDOWS\zllsputility.exe
2008-09-01 03:51 . 2008-09-01 03:52 4,212 —h—– C:\WINDOWS\SYSTEM32\zllictbl.dat
2008-09-01 03:50 . 2008-09-01 03:50 d——– C:\Program Files\Zone Labs
2008-09-01 03:48 . 2008-09-28 20:47 d——– C:\WINDOWS\Internet Logs
2008-08-31 23:38 . 2008-09-28 14:27 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-31 23:38 . 2008-08-31 23:38 d——– C:\Documents and Settings\TheCat\Application Data\Malwarebytes
2008-08-31 23:38 . 2008-08-31 23:38 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-31 23:38 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-08-31 23:38 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-08-31 17:56 . 2008-08-31 17:56 d——– C:\Program Files\IceSword122en
2008-08-31 12:35 . 2008-08-31 12:49 d——– C:\Program Files\KillBox
2008-08-31 12:31 . 2008-08-31 13:09 d——– C:\Program Files\bholist
2008-08-31 10:08 . 2008-08-31 10:08 d——– C:\Program Files\ibprocman
2008-08-31 10:05 . 2008-08-31 10:05 d——– C:\Program Files\cwshredder
2008-08-31 10:00 . 2008-08-31 10:00 d——– C:\Program Files\InterMute
2008-08-31 09:57 . 2008-08-31 09:57 d——– C:\Program Files\Startup List
2008-08-30 08:35 . 2004-12-26 18:57 1,599 –a—— C:\Remote Assistance.lnk
2008-08-30 08:35 . 2004-12-26 18:57 234 –ahs—- C:\DESKTOP.INI
2008-08-30 04:39 . 2008-08-30 04:39 d——– C:\Program Files\Uniblue
2008-08-30 04:39 . 2008-08-30 04:39 d——– C:\Documents and Settings\TheCat\Application Data\Uniblue
2008-08-30 04:38 . 2008-08-30 04:39 d–h-c— C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}
2008-08-29 23:56 . 2008-09-01 03:43 d——– C:\WINDOWS\SYSTEM32\CatRoot_bak
2008-08-29 19:37 . 2007-08-01 22:47 102,664 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
2008-08-29 02:27 . 2008-08-29 08:54 d——– C:\Documents and Settings\TheCat\.housecall6.6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-29 00:07 3,653,085 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-09-28 22:22 ——— d—–w C:\Program Files\AdvancedSearchbar
2008-09-27 18:36 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-27 07:28 ——— d—–w C:\Program Files\CCleaner
2008-09-26 06:23 ——— d—–w C:\Program Files\Java
2008-09-26 00:47 ——— d—–w C:\Program Files\Yahoo!
2008-09-23 23:21 ——— d—–w C:\Program Files\Shockwave.com
2008-09-23 20:11 ——— d—–w C:\Program Files\Windows Desktop Search
2008-09-23 18:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-23 17:14 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-23 17:14 ——— d—–w C:\Program Files\ATI Technologies
2008-09-17 12:02 ——— d—–w C:\Documents and Settings\TheCat\Application Data\Gamelab
2008-09-16 08:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-09-15 18:03 ——— d—–w C:\Program Files\MSN Messenger
2008-09-15 18:03 ——— d—–w C:\Program Files\Messenger Plus! Live
2008-09-15 05:26 ——— d—–w C:\Documents and Settings\TheCat\Application Data\GetRightToGo
2008-09-13 13:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Retrospect
2008-09-13 12:50 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-09-12 23:47 ——— d—–w C:\Program Files\PCPitstop
2008-09-06 09:51 ——— d—–w C:\Program Files\Outpost Kaloki
2008-09-06 09:51 ——— d—–w C:\Program Files\3dmaze
2008-09-06 07:38 1,453,568 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-09-01 22:11 1,369,088 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-09-01 04:40 ——— d—–w C:\Program Files\Lavasoft
2008-09-01 04:40 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-31 16:45 ——— d—–w C:\Program Files\_ArcadeDownloadFolder
2008-08-31 16:23 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-08-30 07:49 ——— d—–w C:\Program Files\Windows Live Safety Center
2008-08-30 01:56 561,152 —-a-w C:\WINDOWS\SYSTEM32\ati2evxx.exe
2008-08-29 03:47 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-29 03:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-28 22:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-28 19:17 ——— d—–w C:\Program Files\MySpace
2008-08-28 19:17 ——— d—–w C:\Documents and Settings\TheCat\Application Data\MySpace
2008-08-26 21:32 ——— d—–w C:\Documents and Settings\TheCat\Application Data\PlayFirst
2008-08-26 21:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-08-25 18:31 524,288 —-a-w C:\WINDOWS\opuc.dll
2008-08-12 22:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-08-11 04:12 ——— d—–w C:\Documents and Settings\TheCat\Application Data\Ancient Quest of Saqqarah__shockwave
2008-08-07 07:17 ——— d—–w C:\Documents and Settings\TheCat\Application Data\Shockwave
2008-08-06 05:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-07-28 22:21 ——— d—–w C:\Program Files\IrfanView
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\SYSTEM32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\SYSTEM32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\SYSTEM32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\SYSTEM32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\SYSTEM32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\SYSTEM32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
2008-07-19 02:07 270,880 —-a-w C:\WINDOWS\SYSTEM32\mucltui.dll
2008-07-19 02:07 210,976 —-a-w C:\WINDOWS\SYSTEM32\muweb.dll
2008-07-09 13:05 1,086,952 —-a-w C:\WINDOWS\SYSTEM32\zpeng24.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\SYSTEM32\es.dll
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\SYSTEM32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\SYSTEM32\ATIDEMGX.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\SYSTEM32\ATIDEMGX(3).dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\SYSTEM32\ATIDEMGX(2).dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\SYSTEM32\ati2dvag.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\SYSTEM32\ati2dvag(4).dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\SYSTEM32\ati2dvag(3).dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\SYSTEM32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\SYSTEM32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\SYSTEM32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\SYSTEM32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\SYSTEM32\ati2evxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\SYSTEM32\ati2evxx(4).dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\SYSTEM32\ati2evxx(3).dll
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\SYSTEM32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\SYSTEM32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\SYSTEM32\ati3duag.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\SYSTEM32\ati3duag(4).dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\SYSTEM32\ati3duag(3).dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\SYSTEM32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\SYSTEM32\ativvaxx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\SYSTEM32\ativvaxx(4).dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\SYSTEM32\ativvaxx(3).dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\SYSTEM32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\SYSTEM32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\SYSTEM32\atiadlxx.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\SYSTEM32\atiadlxx(3).dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\SYSTEM32\atiadlxx(2).dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\SYSTEM32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\SYSTEM32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\SYSTEM32\ati2cqag.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\SYSTEM32\ati2cqag(4).dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\SYSTEM32\ati2cqag(3).dll
2008-07-04 01:05 593,920 —-a-w C:\WINDOWS\SYSTEM32\ati2sgag.exe
2008-07-02 12:18 10,520 —-a-w C:\WINDOWS\SYSTEM32\avgrsstx.dll
2008-06-09 17:10 20 -c-h–w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2008-06-09 17:10 20 -c-h–w C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2008-03-04 21:16 2,696 -c–a-w C:\Documents and Settings\TheCat\Application Data\mindhabits.dat
2008-01-16 15:39 32 -c–a-r C:\Documents and Settings\All Users\hash.dat
2005-06-20 16:50 4,535 -c–a-w C:\Program Files\export.htm
2005-06-20 16:50 223,714 -c–a-w C:\Program Files\export.zip
2005-02-04 15:18 376,656 -c–a-w C:\Program Files\musicmatch_installer.exe
2004-08-27 00:36 141 -c–a-w C:\Program Files\pcdocrx_order.html
2003-11-03 05:38 792 -c–a-w C:\Program Files\INSTALL.LOG
2003-03-10 04:22 23,357 -c-h–w C:\Program Files\folder.htt
.

((((((((((((((((((((((((((((( snapshot_2008-09-28_18.45.31.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-29 00:07:57 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_2f4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-09-28 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"tgcmd"="C:\Program Files\support.com\bin\tgcmd.exe" [2002-04-24 1544192]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 98304]
"Dimension4"="C:\Program Files\D4\D4.exe" [2004-02-04 200704]
"itype"="c:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-28 1235736]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"MXO Auto Loader"="C:\WINDOWS\MXOALDR.EXE" [2003-04-07 118784]
"CTHelper"="CTHELPER.EXE" [2007-04-09 C:\WINDOWS\SYSTEM32\CtHelper.exe]

C:\Documents and Settings\TheCat\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-06-03 45056]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP53"= SP5X_32.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"VIDC.SP59"= SP5X_32.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^STK02N 2.2 PNP Monitor.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\STK02N 2.2 PNP Monitor.lnk.disabled
backup=C:\WINDOWS\pss\STK02N 2.2 PNP Monitor.lnk.disabledCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=C:\WINDOWS\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^TheCat^Start Menu^Programs^Startup^Block Tards.lnk]
path=C:\Documents and Settings\TheCat\Start Menu\Programs\Startup\Block Tards.lnk
backup=C:\WINDOWS\pss\Block Tards.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
–a–c— 2003-06-18 03:00 45056 C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
–a–c— 2003-05-21 20:37 229437 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
–a–c— 2004-08-23 20:19 57344 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
–a—— 2007-03-15 17:16 454784 C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Metrics]
–a–c— 2004-01-16 14:11 368640 C:\Program Files\HP\Personal Printing Solutions Product Research\HP Product Research.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a–c— 2004-12-14 12:07 176128 C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb12.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
–a—— 2003-05-21 15:30 45056 C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
—–c— 2004-09-24 17:22 1916928 C:\Program Files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 C:\WINDOWS\SYSTEM32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
–a–c— 2004-04-11 22:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2004-11-17 05:41 77824 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
——— 2008-08-18 18:41 1832272 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Mechanic Popup Stopper]
–a—— 2004-10-26 16:39 592896 C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Mechanic Registry Compact Handler]
–a—— 2004-10-26 16:39 2919424 C:\Program Files\iolo\System Mechanic 5\SysMech5.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=3 (0x3)
"usnjsvc"=3 (0x3)
"MDM"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"C:\\Program Files\\D4\\D4.exe"=
"C:\\Program Files\\support.com\\bin\\tgcmd.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"C:\\Program Files\\Real\\RealArcade\\RNArcade.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\DAP\\DAP.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\NeverwinterNights\\NWN\\nwmain.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\WINDOWS\\SYSTEM32\\mmc.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-28 97928]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-28 231704]
R3 P1050VID;Creative WebCam Pro eX (Video);C:\WINDOWS\system32\DRIVERS\P1050Wnt.sys [2003-01-02 179853]
S3 GameConsoleService;GameConsoleService;C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe [2008-01-29 165416]
S3 KMW_KBD;Kensington Input Devices Class filter driver;C:\WINDOWS\system32\DRIVERS\KMW_KBD.sys [ ]
S3 KMW_USB;Kensington MouseWorks USB filter driver;C:\WINDOWS\system32\DRIVERS\KMW_USB.sys [ ]
S3 LiveTurbineMessageService;Turbine Message Service - Live;C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe [2008-08-18 249856]
S3 LiveTurbineNetworkService;Turbine Network Service - Live;C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe [2008-08-18 212992]
S3 LVBulk;LVBulk Service;C:\WINDOWS\system32\DRIVERS\LVBulk.sys [2001-09-24 10261]
S3 PID_0900_V;Logitech ClickSmart 310(PID_0900_V);C:\WINDOWS\system32\DRIVERS\LV551AV.sys [ ]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 12672]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-(Default) - (no file)



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 20:59:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-09-28 21:01:18
ComboFix-quarantined-files.txt 2008-09-29 01:00:59
ComboFix2.txt 2008-09-28 22:46:23
ComboFix3.txt 2008-08-31 23:41:33

Pre-Run: 231,865,556,992 bytes free
Post-Run: 231,830,237,184 bytes free

341 — E O F — 2008-09-23 18:31:10

Here's the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:33:30 PM, on 9/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\THJ.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [Dimension4] C:\Program Files\D4\D4.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Clean; Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab?v=13,0,0831,02
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.67.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.microsoftvirtuallabs.com/virtua…iveXClient1.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.53.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149296841921
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {7D492D61-303A-45C3-8A55-63449339943D} (CPlayFirstNightShiftControl Object) - http://www.shockwave.com/content/nightshif…Web.1.0.0.5.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab70018.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn.com/binframework/v10/…gr.cab31267.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://www.shockwave.com/content/zenerchi/…eb.1.0.0.10.cab
O16 - DPF: {BCF9A64D-1440-4404-863C-F5DF2B99F798} (MSN Games - Catan Online) - http://zone.msn.com/bingame/zpagames/zpa_catan.cab55579.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.32.17/ttinst.cab
O16 - DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} (CPlayFirstPetShopHopControl Object) - http://www.shockwave.com/content/petshopho…eb.1.0.0.17.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/A…ersion=1,0,0,10
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe
O23 - Service: Turbine Network Service - Live (LiveTurbineNetworkService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

–
End of file - 13718 bytes

Once again, thank you. :)
Lets try this:

1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Zone Labs\ZoneAlarm

Reboot and see how things are
sigh
HijackThis hung up the same as last time. There are still errors on the pages that I was using to check. And it was definitely unhappy about uninstalling ZoneAlarm - - froze up very nicely :)

Is it possible that it has something to do with the ActiveX controls? What would happen if I removed all of them from the DPF folder? Wouldn't I just pick them up again as needed when I went to whichever site I got them from? And could I do this through HJT by checking them to be fixed?

Here's the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:07:22 PM, on 9/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\THJ.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [Dimension4] C:\Program Files\D4\D4.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab?v=13,0,0831,02
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.67.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.microsoftvirtuallabs.com/virtua…iveXClient1.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.53.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149296841921
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {7D492D61-303A-45C3-8A55-63449339943D} (CPlayFirstNightShiftControl Object) - http://www.shockwave.com/content/nightshif…Web.1.0.0.5.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab70018.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn.com/binframework/v10/…gr.cab31267.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://www.shockwave.com/content/zenerchi/…eb.1.0.0.10.cab
O16 - DPF: {BCF9A64D-1440-4404-863C-F5DF2B99F798} (MSN Games - Catan Online) - http://zone.msn.com/bingame/zpagames/zpa_catan.cab55579.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.32.17/ttinst.cab
O16 - DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} (CPlayFirstPetShopHopControl Object) - http://www.shockwave.com/content/petshopho…eb.1.0.0.17.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/A…ersion=1,0,0,10
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe
O23 - Service: Turbine Network Service - Live (LiveTurbineNetworkService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe

–
End of file - 13392 bytes

thank you for your patience
Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
WildGames <–Unless you use it
Logitech


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F} (FavImport Class) - https://favorites.live.com/cab/ImportAx.cab?v=13,0,0831,02
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.67.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.microsoftvirtuallabs.com/virtua…iveXClient1.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.53.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149296841921
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {7D492D61-303A-45C3-8A55-63449339943D} (CPlayFirstNightShiftControl Object) - http://www.shockwave.com/content/nightshif…Web.1.0.0.5.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab70018.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn.com/binframework/v10/…gr.cab31267.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://www.shockwave.com/content/zenerchi/…eb.1.0.0.10.cab
O16 - DPF: {BCF9A64D-1440-4404-863C-F5DF2B99F798} (MSN Games - Catan Online) - http://zone.msn.com/bingame/zpagames/zpa_catan.cab55579.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.32.17/ttinst.cab
O16 - DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} (CPlayFirstPetShopHopControl Object) - http://www.shockwave.com/content/petshopho…eb.1.0.0.17.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/A…ersion=1,0,0,10
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll

Close ALL windows and browsers except HijackThis and click "Fix checked"



Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
On the bright side, my machine is faster than it's been in a while. HJT is still hanging up on the trusted zone enumeration. I thought I had it figured out for a second. I had at one time had HJT ignore the items in my trusted zone. Although, when I cleared them out through my internet options, I also deleted them from the ignore list…or at least I tried to. Today I found them in the ignore list again. I thought maybe this was causing a conflict, so I deleted them again. Twice I deleted them and scanned again and they kept showing up. Finally on the third time they stayed out of there. I even uninstalled and downloaded HJt from TrendMicro again. Still doesn't help.

On the ActiveX controls.
Fixed what you said to fix. Still getting the erors message. I even went into my internet options and rsest everythng to the default settings. As I'm sure you know, CCleaner has a registry issues scanner. On a whim, I ran that (WOW!!) and these are the ActiveX issues it found. (i know these are probably left overs from what we have done, but there are a couple items that I think are worth asking you about. I did convert the report to text, but it's really long. If you want to see it I can put it up as an attachment if you would like.) (Oh. I didn't do anything with any of the issues. Am being very good - you have no idea how difficult that is for me lol)

ActiveX/COM Issue activex.PlayFirstPiratePoppersControl - {49E67060-2C0D-415e-94C7-52A49F73B2F1} HKCR\activex.PlayFirstPiratePoppersControl
ActiveX/COM Issue activex.PlayFirstPiratePoppersControl.1 - {49E67060-2C0D-415e-94C7-52A49F73B2F1} HKCR\activex.PlayFirstPiratePoppersControl.1
ActiveX/COM Issue MailFileAtt - {00020D05-0000-0000-C000-000000000046} HKCR\MailFileAtt
ActiveX/COM Issue mapifvbx.object - {41116C00-8B90-101B-96CD-00AA003B14FC} HKCR\mapifvbx.object
ActiveX/COM Issue mapifvbx.object.1 - {41116C00-8B90-101B-96CD-00AA003B14FC} HKCR\mapifvbx.object.1
ActiveX/COM Issue Microsoft.wlsc.WebTransport - {74870B39-2651-4A6C-A59B-2F66602FDC67} HKCR\Microsoft.wlsc.WebTransport
ActiveX/COM Issue Microsoft.wlsc.WebTransport.1 - {74870B39-2651-4A6C-A59B-2F66602FDC67} HKCR\Microsoft.wlsc.WebTransport.1
ActiveX/COM Issue wdsShell.WDSCalendar - {10935444-7CC4-483B-9FDB-37560F5F3BBF2} HKCR\wdsShell.WDSCalendar
ActiveX/COM Issue InProcServer32\C:\PROGRA~1\Logitech\QuickCam\Ltocx12n.ocx HKCR\CLSID\{00120005-B1BA-11CE-ABC6-F5B2E79D9E3F}
ActiveX/COM Issue InProcServer32\C:\PROGRA~1\Logitech\QuickCam\Ltocx12n.ocx HKCR\CLSID\{00120007-B1BA-11CE-ABC6-F5B2E79D9E3F}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\ltscr12n.ocx HKCR\CLSID\{00120070-B1BA-11CE-ABC6-F5B2E79D9E3F}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\ltscr12n.ocx HKCR\CLSID\{00120074-B1BA-11CE-ABC6-F5B2E79D9E3F}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\ltscr12n.ocx HKCR\CLSID\{00120075-B1BA-11CE-ABC6-F5B2E79D9E3F}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\ltscr12n.ocx HKCR\CLSID\{00120076-B1BA-11CE-ABC6-F5B2E79D9E3F}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\ltscr12n.ocx HKCR\CLSID\{00120077-B1BA-11CE-ABC6-F5B2E79D9E3F}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\LVUI2.dll HKCR\CLSID\{0932B8A4-BBB4-4bc0-A8AB-91C626950C75}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\LVUI2.dll HKCR\CLSID\{09AC4892-81B7-4d39-B235-8F0DB0DAF4F8}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\LVUI2.dll HKCR\CLSID\{1159F2AF-F989-4d11-8B34-9550029269BB}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\kbnanw.dll HKCR\CLSID\{2ac44a58-074e-4173-91ce-17e18b843055}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\LIU_PROD.dll HKCR\CLSID\{36B4D77E-1B50-43cd-952A-87A4EF495336}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\Update.dll HKCR\CLSID\{3933DE4F-3551-11D3-AB53-00A0C976D016}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\Twain_32\QuickCam\Decal.dll HKCR\CLSID\{40C66A14-DECA-4F56-AEA0-A7F85B8EA775}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\Twain_32\QuickCam\lvdesa.dll HKCR\CLSID\{42973F66-DF88-43E9-82B0-E870A544BAD1}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\dsuman.dll HKCR\CLSID\{49b12cad-e181-4376-a746-0edbd9f7e389}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\LVUI2.dll HKCR\CLSID\{4C8DD17E-7079-4c7e-96E5-A7AFDB12F132}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\ltscr12n.ocx HKCR\CLSID\{4EC1EB8E-04D3-8210-E9D2-C82735E22224}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\LVUI2.dll HKCR\CLSID\{517539A3-905F-4755-9F94-D91B095A07CC}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\LVUI2.dll HKCR\CLSID\{5872C980-0AAF-4cdb-A62D-4F453DA2EFAD}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\LVUI2.dll HKCR\CLSID\{5A710052-328F-4836-DE07-8A14C7337D2D}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\FileMenu.dll HKCR\CLSID\{770C5382-5451-AD78-E63D-5CE6F36814CE}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\Radar.dll HKCR\CLSID\{790A7560-575F-5BD4-68D7-193E490D5A21}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\Twain_32\QuickCam\HVideoSP.dll HKCR\CLSID\{7C863C24-EC80-4F2C-A200-2AE419010F5E}
ActiveX/COM Issue LocalServer32\C:\PROGRA~1\Logitech\QuickCam\Editor.exe HKCR\CLSID\{99C87860-702F-47F7-8221-E1B6DA6E3524}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\Downloaded Program Files\StagingUI.ocx HKCR\CLSID\{9DBB0C5B-F279-ADE5-8D44-1701D9427E0F}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\Edit.dll HKCR\CLSID\{BDBD6BB1-E859-96EF-2502-455BE936B821}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\LIU_UPD.dll HKCR\CLSID\{CD7DA9CA-09DF-4f47-A140-20FCAAC659D5}
ActiveX/COM Issue InProcServer32\C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mlfoshim.dll HKCR\CLSID\{DD777EF2-30CE-4afd-AC19-EBC1F5976C82}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\LVUI2.dll HKCR\CLSID\{DE7371F4-4CCD-47cd-B12B-8887C9125895}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\ltscr12n.ocx HKCR\CLSID\{DE7D27C2-F994-CA1A-7FE0-ADCD5C5477E5}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\Twain_32\QuickCam\HPortal.dll HKCR\CLSID\{E16BE35A-C958-416d-BA06-6A03DF227C6A}
ActiveX/COM Issue InProcServer32\C:\Program Files\Logitech\QuickCam\LVMAVI.dll HKCR\CLSID\{E9AEE625-5EC8-11d3-AB53-00A0C976D016}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\fxdgxl.dll HKCR\CLSID\{ebedff9d-cf67-4e88-acb0-4d027d318a85}
ActiveX/COM Issue LocalServer32\C:\WINDOWS\Twain_32\QuickCam\HVideoS.exe HKCR\CLSID\{F6638FF8-D15E-4e90-8191-1AEB8DFBC4DB}

Here's the most current HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:05:20 PM, on 9/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\D4\D4.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R3 - URLSearchHook: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dimension4] C:\Program Files\D4\D4.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Turbine Message Service - Live (LiveTurbineMessageService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe
O23 - Service: Turbine Network Service - Live (LiveTurbineNetworkService) - Turbine, Inc. - C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe

–
End of file - 8228 bytes

Like I said, at least it's running faster than it has been. That's a good thing. :)
The only thing I see in your trusted zones is this one and that should be fine. O15 - ESC Trusted Zone: http://*.update.microsoft.com Those ActiveX/COM I'd get rid of.
Funny, that 015 shows up in the report but not on the scan. Weird. But that was all I had there anyway, just msn sites. I was just on MySpace and the error there appears to be with java. I just updated java and supposedly removed all the old java "stuff" with JavaRa, but I see a few references to other java versions. Specifically these from the registry issues log: Installer Reference Issue C:\Program Files\Common Files\Java\Update\Base Images\j2re1.4.2-b28 HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders Installer Reference Issue C:\Program Files\Java\j2re1.4.2_03 HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders Installer Reference Issue C:\Program Files\Java\jre1.5.0_06\bin HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders Installer Reference Issue C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_09.b03 HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders Installer Reference Issue C:\Program Files\Java\jre1.5.0_09\bin HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders Installer Reference Issue C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_11.b03 HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders I suppose I could uninstall java and then go to Sun's site and download a clean copy and reinstall it. Maybe that will help. At least it can't hurt. It looks like the rootkit itself is probably gone, at least I don't see anything suspicious in the System32 folder (thank you ever so much for that!!!), but I don't know enough to say whether it did the damage to java or if it came in through there. Have no idea. These are the times when I wish I knew more about the inner workings of my machine. I really hate bugging anyone about it, but I've done enough damage working on my own before that I don't want to go through all that again. I really hate disturbing you and you've been so patient. I truly appreciate it.
I would look in Add/Remove programs for the old Java programs. I don't really don't like removing from the registry unless I'm 100% sure it needs to be removed.
This is my last canned post for Java. It might be outdated but if you go to the website you'll see the latest version.
Updating Java:
Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says Java Runtime Environment (JRE) 6 Update 7
    The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on 6-windowsi586-p.exe to install the newest version.
Once installed you can test to see that it is in fact installed
Sun Java Test
http://www.java.com/en/download/installed.jsp

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI