This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware (url.adtrgt) issue / HJT log included

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Alright, so I am keeping AntiVir (of course), HJT and Malwarebytes. So I noticed this with the searching function: the search for aaphyy was quick, just like it was when searching for aaphyy.dll. However, if I put a space before the "a," the search takes considerably longer. I don't know if this makes a difference. I am cleaning up some disk space right now.
I did everything and my computer's still running at the same (slower) speed. Checking my email is taking so long that I stopped halfway.
Let me have a fresh HJT log and also work through the following:

Download gmer.zip from here and save it to your Desktop.
You will need to unzip it before you run it.

To do this: Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


Double click gmer.exe to begin:
  • If you get a message about "system modification", click Yes and work through the rest of the instructions.
  • Ensure that the Rootkit Tab at the top is selected.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
  • Click the Scan button on the right.
  • When the scan has completed, (you'll have time for a snack and a cuppa!), click the Copy button underneath - this will save the report to your Clipboard.
  • Paste it into Notepad (Start > All Programs > Accessories > Notepad) and save it somewhere convenient.
  • Click the >>> Tab at the top and select the Autostart Tab.
  • Click the Scan button on the right - this one should only take seconds to complete.
  • Save the log as before.
Copy and paste both reports into your next reply - you may need to post them separately.
The Preview option may show the whole logs being posted, but they sometimes get cut down when the actual post is made, so check the post once it is completed.
Okay, here are all the logs:

HJT:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:07:36 PM, on 1/17/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM\aim.exe
D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\spyware\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://register.resnet.stonybrook.edu/wpad.dat
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\spyware\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\spyware\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\spyware\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - AppInit_DLLs: aaphyy.dll bssuqa.dll
O20 - Winlogon Notify: !SASWinLogon - D:\spyware\SASWINLO.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 5123 bytes


gmer (rootkit):



GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-17 23:04:14
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT F7B0F3FC ZwCreateThread
SSDT F7B0F3E8 ZwOpenProcess
SSDT F7B0F3ED ZwOpenThread
SSDT F7B0F3F7 ZwTerminateProcess
SSDT F7B0F3F2 ZwWriteVirtualMemory

—- EOF - GMER 1.0.14 —-


gmer (autostart):



GMER 1.0.14.14536 - http://www.gmer.net
Autostart scan 2009-01-17 23:05:27
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
!SASWinLogon@DLLName = D:\spyware\SASWINLO.DLL
WgaLogon@DLLName = WgaLogon.dll

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs = aaphyy.dll bssuqa.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AntiVirScheduler@ = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe"
AntiVirService@ = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe"
JavaQuickStarterService@ = "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
NVSvc@ = %SystemRoot%\system32\nvsvc32.exe
WUSB54Gv42SVC@ = "C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv42.exe"

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@BCMSMMSGBCMSMMSG.exe = BCMSMMSG.exe
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
@nwiznwiz.exe /installquiet = nwiz.exe /installquiet
@SunJavaUpdateSched"C:\Program Files\Java\jre6\bin\jusched.exe" = "C:\Program Files\Java\jre6\bin\jusched.exe"
@iTunesHelper"C:\Program Files\iTunes\iTunesHelper.exe" = "C:\Program Files\iTunes\iTunesHelper.exe"
@avgnt"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@AIMC:\Program Files\AIM\aim.exe -cnetwait.odl /*file not found*/ = C:\Program Files\AIM\aim.exe -cnetwait.odl /*file not found*/
@MSMSGS"C:\Program Files\Messenger\msmsgs.exe" /background = "C:\Program Files\Messenger\msmsgs.exe" /background
@PopUpStopperFreeEdition"D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" = "D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL
@{0561EC90-CE54-4f0c-9C55-E226110A740C} /*Haali Column Provider*/C:\WINDOWS\system32\mmfinfo.dll = C:\WINDOWS\system32\mmfinfo.dll
@{E4D8441D-F89C-4b5c-90AC-A857E1768F1F} /*Haali Matroska Thumbnail Exctractor*/(null) =
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/C:\Program Files\iTunes\iTunesMiniPlayer.dll = C:\Program Files\iTunes\iTunesMiniPlayer.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Program Files\Real\RealPlayer\rpshell.dll = C:\Program Files\Real\RealPlayer\rpshell.dll
@{DEE12703-6333-4D4E-8F34-738C4DCC2E04} /*RecordNow! SendToExt*/C:\Program Files\Sonic\RecordNow!\shlext.dll = C:\Program Files\Sonic\RecordNow!\shlext.dll
@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} /*Shell Extension for Malware scanning*/C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Web Folders*/ = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Shell Extension for Malware scanning@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{CA8ACAFA-5FBB-467B-B348-90DD488DE003} = D:\SASCTXMN.DLL /*file not found*/

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers@{CA8ACAFA-5FBB-467B-B348-90DD488DE003} = D:\SASCTXMN.DLL /*file not found*/

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
MBAMShlExt@{57CE581A-0CB6-4266-9CA0-19364C90A0B3} = D:\Malwarebytes' Anti-Malware\mbamext.dll
Shell Extension for Malware scanning@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{53707962-6F74-2D53-2644-206D7942484F}D:\spyware\SPYBOT~1\SDHelper.dll = D:\spyware\SPYBOT~1\SDHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre6\bin\ssv.dll = C:\Program Files\Java\jre6\bin\ssv.dll
@{AA58ED58-01DD-4d91-8333-CF10577473F7}c:\program files\google\googletoolbar1.dll = c:\program files\google\googletoolbar1.dll
@{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll = C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
@{DBC80044-A445-435b-BC74-9C25C1C588A9}C:\Program Files\Java\jre6\bin\jp2ssv.dll = C:\Program Files\Java\jre6\bin\jp2ssv.dll
@{E7E6F031-17CE-4C07-BC86-EABFE594F69C}C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll = C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

HKCU\Control Panel\[removed] = C:\WINDOWS\system32\scrnsave.scr

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.msn.com/ = http://www.msn.com/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll

HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = C:\WINDOWS\system32\wiascr.dll

—- EOF - GMER 1.0.14 —-
Delete your copy of ComboFix and then download a fresh copy from one of the links under Using ComboFix - here.
You'll also need to follow the instructions to disable your AV, found here.

Copy and paste the following into Notepad (Start > All Programs > Accessories > Notepad):

File::
c:\windows\system32\ffkuz.dll

Folder::
c:\documents and settings\Zena.ZENA-2CE3E9C195\xrt_collect.zip

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0a2b742-bafe-11db-9020-000f1f208d76}]


Save it to your Desktop with the following filename: CFScript
Drag and drop CFScript.txt onto your copy of Combofix and let it do it's thing.
Once it has finished, make sure that your AV is re-enabled before you go back online. If you are unsure, just reboot your PC.
Let me have the log produced, as before, as well as a fresh HJT log and a description of how the PC is behaving.
Okay, here are the requested logs:

CF:


ComboFix 09-01-18.01 - Zena 2009-01-18 23:02:13.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.515 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Zena.ZENA-2CE3E9C195\Desktop\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\windows\system32\ffkuz.dll
.

((((((((((((((((((((((((( Files Created from 2008-12-19 to 2009-01-19 )))))))))))))))))))))))))))))))
.

2009-01-17 22:05 . 2009-01-17 22:05 250 –a—— c:\windows\gmer.ini
2009-01-16 23:14 . 2009-01-16 23:14 d——– c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\wsInspector
2009-01-13 15:44 . 2009-01-13 15:44 d——– c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\Malwarebytes
2009-01-13 15:44 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-13 15:44 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-13 15:43 . 2009-01-13 15:43 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-12 16:44 . 2009-01-12 16:44 d——– c:\program files\Avira
2009-01-12 16:44 . 2009-01-12 16:44 d——– c:\documents and settings\All Users\Application Data\Avira
2009-01-09 17:55 . 2009-01-09 17:55 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-09 17:54 . 2009-01-12 16:39 d——– c:\program files\Symantec
2008-12-28 02:57 . 2008-12-28 02:57 d——– c:\documents and settings\All Users\Application Data\Last.fm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-17 01:54 ——— d—–w c:\program files\Viewpoint
2009-01-17 01:54 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-01-17 01:52 ——— d—–w c:\program files\Lavasoft
2009-01-17 01:52 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-01-17 01:52 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-13 20:38 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-12 21:39 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-12 21:39 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-01-09 22:55 ——— d—–w c:\program files\Java
2008-12-28 07:57 ——— d—–w c:\program files\iTunes
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-05 22:09 ——— d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-05 22:03 ——— d—–w c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\SUPERAntiSpyware.com
2008-12-05 15:07 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-08_15.54.53.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-02-25 01:35:06 14,048 —-a-w c:\windows\$hf_mig$\KB894391\spmsg.dll
+ 2005-02-25 00:35:06 14,048 —-a-w c:\windows\$hf_mig$\KB894391\spmsg.dll
- 2005-02-25 01:35:06 209,632 —-a-w c:\windows\$hf_mig$\KB894391\spuninst.exe
+ 2005-02-25 00:35:06 209,632 —-a-w c:\windows\$hf_mig$\KB894391\spuninst.exe
- 2005-02-25 01:35:06 22,240 —-a-w c:\windows\$hf_mig$\KB894391\update\spcustom.dll
+ 2005-02-25 00:35:06 22,240 —-a-w c:\windows\$hf_mig$\KB894391\update\spcustom.dll
- 2005-02-25 01:35:06 718,048 —-a-w c:\windows\$hf_mig$\KB894391\update\update.exe
+ 2005-02-25 00:35:06 718,048 —-a-w c:\windows\$hf_mig$\KB894391\update\update.exe
- 2005-02-25 01:35:08 371,936 —-a-w c:\windows\$hf_mig$\KB894391\update\updspapi.dll
+ 2005-02-25 00:35:08 371,936 —-a-w c:\windows\$hf_mig$\KB894391\update\updspapi.dll
+ 2007-12-04 18:29:10 551,936 —-a-w c:\windows\$hf_mig$\KB943055\SP2QFE\oleaut32.dll
+ 2007-03-06 01:22:36 14,048 —-a-w c:\windows\$hf_mig$\KB943055\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w c:\windows\$hf_mig$\KB943055\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w c:\windows\$hf_mig$\KB943055\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w c:\windows\$hf_mig$\KB943055\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB943055\update\updspapi.dll
+ 2008-02-20 05:19:35 147,968 —-a-w c:\windows\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
+ 2008-02-20 18:49:36 45,568 —-a-w c:\windows\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
+ 2007-03-06 01:22:36 14,048 —-a-w c:\windows\$hf_mig$\KB945553\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w c:\windows\$hf_mig$\KB945553\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w c:\windows\$hf_mig$\KB945553\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w c:\windows\$hf_mig$\KB945553\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB945553\update\updspapi.dll
+ 2007-12-18 09:38:59 179,712 —-a-w c:\windows\$hf_mig$\KB946026\SP2QFE\mrxdav.sys
+ 2007-03-06 01:22:36 14,048 —-a-w c:\windows\$hf_mig$\KB946026\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w c:\windows\$hf_mig$\KB946026\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w c:\windows\$hf_mig$\KB946026\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w c:\windows\$hf_mig$\KB946026\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB946026\update\updspapi.dll
+ 2006-02-15 00:22:26 142,464 ——w c:\windows\Driver Cache\i386\aec.sys
+ 2006-03-17 00:33:10 262,784 ——w c:\windows\Driver Cache\i386\http.sys
+ 2006-06-14 08:47:45 172,416 ——w c:\windows\Driver Cache\i386\kmixer.sys
+ 2006-06-14 08:47:46 6,400 ——w c:\windows\Driver Cache\i386\splitter.sys
+ 2006-06-14 09:00:45 82,944 ——w c:\windows\Driver Cache\i386\wdmaud.sys
- 2006-02-28 12:00:00 1,032,192 —-a-w c:\windows\explorer.exe
+ 2007-06-13 10:23:07 1,033,216 —-a-w c:\windows\explorer.exe
+ 2009-01-18 03:05:38 884,736 —-a-w c:\windows\gmer.dll
+ 2009-01-18 03:05:22 811,008 —-a-w c:\windows\gmer.exe
- 2006-02-28 12:00:00 10,752 —-a-w c:\windows\hh.exe
+ 2005-05-26 23:22:01 10,752 —-a-w c:\windows\hh.exe
- 2006-02-28 12:00:00 41,984 —-a-w c:\windows\msagent\agentdp2.dll
+ 2006-10-12 14:02:52 42,496 —-a-w c:\windows\msagent\agentdp2.dll
- 2006-02-28 12:00:00 58,880 —-a-w c:\windows\msagent\agentdpv.dll
+ 2007-03-09 13:46:24 57,344 —-a-w c:\windows\msagent\agentdpv.dll
- 2006-02-28 12:00:00 256,512 —-a-w c:\windows\msagent\agentsvr.exe
+ 2006-10-12 11:09:53 256,512 —-a-w c:\windows\msagent\agentsvr.exe
- 2000-08-31 13:00:00 28,672 —-a-w c:\windows\NIRCMD.exe
+ 2000-08-31 13:00:00 29,696 —-a-w c:\windows\NIRCMD.exe
- 2006-02-28 12:00:00 56,832 —-a-w c:\windows\system32\authz.dll
+ 2005-03-02 18:09:29 56,832 —-a-w c:\windows\system32\authz.dll
- 2006-02-28 12:00:00 229,888 —-a-w c:\windows\system32\catsrv.dll
+ 2005-07-26 04:39:42 225,792 —-a-w c:\windows\system32\catsrv.dll
- 2006-02-28 12:00:00 628,224 —-a-w c:\windows\system32\catsrvut.dll
+ 2005-07-26 04:39:43 625,152 —-a-w c:\windows\system32\catsrvut.dll
- 2006-02-28 12:00:00 2,067,968 —-a-w c:\windows\system32\cdosys.dll
+ 2005-09-10 01:53:41 2,067,968 —-a-w c:\windows\system32\cdosys.dll
- 2006-02-28 12:00:00 69,120 —-a-w c:\windows\system32\ciodm.dll
+ 2006-06-22 05:06:29 69,120 —-a-w c:\windows\system32\ciodm.dll
- 2006-02-28 12:00:00 110,080 —-a-w c:\windows\system32\clbcatex.dll
+ 2005-07-26 04:39:43 110,080 —-a-w c:\windows\system32\clbcatex.dll
- 2006-02-28 12:00:00 501,248 —-a-w c:\windows\system32\clbcatq.dll
+ 2005-07-26 04:39:43 498,688 —-a-w c:\windows\system32\clbcatq.dll
- 2006-02-28 12:00:00 62,464 —-a-w c:\windows\system32\colbact.dll
+ 2005-07-26 04:39:43 60,416 —-a-w c:\windows\system32\colbact.dll
- 2006-02-28 12:00:00 195,584 —-a-w c:\windows\system32\Com\comadmin.dll
+ 2005-07-26 04:39:44 195,072 —-a-w c:\windows\system32\Com\comadmin.dll
- 2006-02-28 12:00:00 611,328 —-a-w c:\windows\system32\comctl32.dll
+ 2006-08-25 15:45:58 617,472 —-a-w c:\windows\system32\comctl32.dll
- 2006-02-28 12:00:00 82,432 —-a-w c:\windows\system32\comrepl.dll
+ 2005-07-26 04:39:44 97,792 —-a-w c:\windows\system32\comrepl.dll
- 2006-02-28 12:00:00 1,251,840 —-a-w c:\windows\system32\comsvcs.dll
+ 2005-07-26 04:39:44 1,267,200 —-a-w c:\windows\system32\comsvcs.dll
- 2006-02-28 12:00:00 540,160 —-a-w c:\windows\system32\comuid.dll
+ 2005-07-26 04:39:45 540,160 —-a-w c:\windows\system32\comuid.dll
- 2006-02-28 12:00:00 111,104 —-a-w c:\windows\system32\dhcpcsvc.dll
+ 2006-05-19 12:59:41 111,616 —-a-w c:\windows\system32\dhcpcsvc.dll
- 2006-02-28 12:00:00 41,984 -c–a-w c:\windows\system32\dllcache\agentdp2.dll
+ 2006-10-12 14:02:52 42,496 -c–a-w c:\windows\system32\dllcache\agentdp2.dll
- 2006-02-28 12:00:00 58,880 -c–a-w c:\windows\system32\dllcache\agentdpv.dll
+ 2007-03-09 13:46:24 57,344 -c–a-w c:\windows\system32\dllcache\agentdpv.dll
- 2006-02-28 12:00:00 256,512 -c–a-w c:\windows\system32\dllcache\agentsvr.exe
+ 2006-10-12 11:09:53 256,512 -c–a-w c:\windows\system32\dllcache\agentsvr.exe
- 2006-02-28 12:00:00 56,832 -c–a-w c:\windows\system32\dllcache\authz.dll
+ 2005-03-02 18:09:29 56,832 -c–a-w c:\windows\system32\dllcache\authz.dll
- 2006-02-28 12:00:00 229,888 -c–a-w c:\windows\system32\dllcache\catsrv.dll
+ 2005-07-26 04:39:42 225,792 -c–a-w c:\windows\system32\dllcache\catsrv.dll
- 2006-02-28 12:00:00 628,224 -c–a-w c:\windows\system32\dllcache\catsrvut.dll
+ 2005-07-26 04:39:43 625,152 -c–a-w c:\windows\system32\dllcache\catsrvut.dll
- 2006-02-28 12:00:00 2,067,968 -c–a-w c:\windows\system32\dllcache\cdosys.dll
+ 2005-09-10 01:53:41 2,067,968 -c–a-w c:\windows\system32\dllcache\cdosys.dll
- 2006-02-28 12:00:00 69,120 -c–a-w c:\windows\system32\dllcache\ciodm.dll
+ 2006-06-22 05:06:29 69,120 -c–a-w c:\windows\system32\dllcache\ciodm.dll
- 2006-02-28 12:00:00 110,080 -c–a-w c:\windows\system32\dllcache\clbcatex.dll
+ 2005-07-26 04:39:43 110,080 -c–a-w c:\windows\system32\dllcache\clbcatex.dll
- 2006-02-28 12:00:00 501,248 -c–a-w c:\windows\system32\dllcache\clbcatq.dll
+ 2005-07-26 04:39:43 498,688 -c–a-w c:\windows\system32\dllcache\clbcatq.dll
- 2006-02-28 12:00:00 62,464 -c–a-w c:\windows\system32\dllcache\colbact.dll
+ 2005-07-26 04:39:43 60,416 -c–a-w c:\windows\system32\dllcache\colbact.dll
- 2006-02-28 12:00:00 195,584 -c–a-w c:\windows\system32\dllcache\comadmin.dll
+ 2005-07-26 04:39:44 195,072 -c–a-w c:\windows\system32\dllcache\comadmin.dll
- 2006-02-28 12:00:00 611,328 -c–a-w c:\windows\system32\dllcache\comctl32.dll
+ 2006-08-25 15:45:58 617,472 -c–a-w c:\windows\system32\dllcache\comctl32.dll
- 2006-02-28 12:00:00 82,432 -c–a-w c:\windows\system32\dllcache\comrepl.dll
+ 2005-07-26 04:39:44 97,792 -c–a-w c:\windows\system32\dllcache\comrepl.dll
- 2006-02-28 12:00:00 1,251,840 -c–a-w c:\windows\system32\dllcache\comsvcs.dll
+ 2005-07-26 04:39:44 1,267,200 -c–a-w c:\windows\system32\dllcache\comsvcs.dll
- 2006-02-28 12:00:00 540,160 -c–a-w c:\windows\system32\dllcache\comuid.dll
+ 2005-07-26 04:39:45 540,160 -c–a-w c:\windows\system32\dllcache\comuid.dll
- 2006-02-28 12:00:00 111,104 -c–a-w c:\windows\system32\dllcache\dhcpcsvc.dll
+ 2006-05-19 12:59:41 111,616 -c–a-w c:\windows\system32\dllcache\dhcpcsvc.dll
- 2006-02-28 12:00:00 81,408 -c–a-w c:\windows\system32\dllcache\directdb.dll
+ 2007-05-16 15:12:00 86,528 -c–a-w c:\windows\system32\dllcache\directdb.dll
- 2006-02-28 12:00:00 45,568 -c–a-w c:\windows\system32\dllcache\dnsrslvr.dll
+ 2008-02-20 05:32:43 45,568 -c–a-w c:\windows\system32\dllcache\dnsrslvr.dll
- 2006-02-28 12:00:00 498,205 -c–a-w c:\windows\system32\dllcache\dxmasf.dll
+ 2006-08-22 09:05:26 498,742 -c–a-w c:\windows\system32\dllcache\dxmasf.dll
- 2006-02-28 12:00:00 1,082,368 -c–a-w c:\windows\system32\dllcache\esent.dll
+ 2005-10-20 22:20:03 1,082,368 -c–a-w c:\windows\system32\dllcache\esent.dll
- 2006-02-28 12:00:00 1,032,192 -c–a-w c:\windows\system32\dllcache\explorer.exe
+ 2007-06-13 10:23:07 1,033,216 -c–a-w c:\windows\system32\dllcache\explorer.exe
- 2006-02-28 12:00:00 16,896 -c–a-w c:\windows\system32\dllcache\fltlib.dll
+ 2006-08-21 12:21:06 16,896 -c–a-w c:\windows\system32\dllcache\fltlib.dll
- 2006-02-28 12:00:00 22,528 -c–a-w c:\windows\system32\dllcache\fltmc.exe
+ 2006-08-21 09:14:58 23,040 -c–a-w c:\windows\system32\dllcache\fltmc.exe
- 2006-02-28 12:00:00 124,800 -c–a-w c:\windows\system32\dllcache\fltmgr.sys
+ 2006-08-21 09:14:58 128,896 -c–a-w c:\windows\system32\dllcache\fltmgr.sys
- 2006-02-28 12:00:00 79,360 -c–a-w c:\windows\system32\dllcache\fontsub.dll
+ 2005-10-17 21:14:45 80,896 -c–a-w c:\windows\system32\dllcache\fontsub.dll
- 2006-02-28 12:00:00 10,752 -c–a-w c:\windows\system32\dllcache\hh.exe
+ 2005-05-26 23:22:01 10,752 -c–a-w c:\windows\system32\dllcache\hh.exe
- 2006-02-28 12:00:00 38,912 -c–a-w c:\windows\system32\dllcache\hhsetup.dll
+ 2005-05-27 02:04:27 41,472 -c–a-w c:\windows\system32\dllcache\hhsetup.dll
- 2006-02-28 12:00:00 77,850 -c–a-w c:\windows\system32\dllcache\hlink.dll
+ 2006-07-21 08:24:43 72,704 -c–a-w c:\windows\system32\dllcache\hlink.dll
- 2006-02-28 12:00:00 253,952 -c–a-w c:\windows\system32\dllcache\icm32.dll
+ 2005-06-29 01:46:00 254,976 -c–a-w c:\windows\system32\dllcache\icm32.dll
- 2006-02-28 12:00:00 94,720 -c–a-w c:\windows\system32\dllcache\iphlpapi.dll
+ 2006-05-19 12:59:41 94,720 -c–a-w c:\windows\system32\dllcache\iphlpapi.dll
- 2006-02-28 12:00:00 134,912 -c–a-w c:\windows\system32\dllcache\ipnat.sys
+ 2004-09-29 22:28:37 134,912 -c–a-w c:\windows\system32\dllcache\ipnat.sys
- 2006-02-28 12:00:00 143,872 -c–a-w c:\windows\system32\dllcache\itircl.dll
+ 2005-05-27 02:04:27 155,136 -c–a-w c:\windows\system32\dllcache\itircl.dll
- 2006-02-28 12:00:00 134,144 -c–a-w c:\windows\system32\dllcache\itss.dll
+ 2005-05-27 02:04:27 137,216 -c–a-w c:\windows\system32\dllcache\itss.dll
+ 2006-06-01 18:47:07 163,840 -c—-w c:\windows\system32\dllcache\jgdw400.dll
+ 2006-06-01 18:47:07 27,648 -c—-w c:\windows\system32\dllcache\jgpl400.dll
- 2006-02-28 12:00:00 294,400 -c–a-w c:\windows\system32\dllcache\kerberos.dll
+ 2005-06-15 17:49:30 295,936 -c–a-w c:\windows\system32\dllcache\kerberos.dll
- 2006-02-28 12:00:00 983,552 -c–a-w c:\windows\system32\dllcache\kernel32.dll
+ 2007-04-16 15:52:53 984,576 -c–a-w c:\windows\system32\dllcache\kernel32.dll
+ 2006-06-14 08:47:45 172,416 -c—-w c:\windows\system32\dllcache\kmixer.sys
- 2006-02-28 12:00:00 18,944 -c–a-w c:\windows\system32\dllcache\linkinfo.dll
+ 2005-09-01 01:41:53 19,968 -c–a-w c:\windows\system32\dllcache\linkinfo.dll
- 2006-02-28 12:00:00 721,920 -c–a-w c:\windows\system32\dllcache\lsasrv.dll
+ 2007-11-07 09:26:56 721,920 -c–a-w c:\windows\system32\dllcache\lsasrv.dll
- 2006-02-28 12:00:00 39,936 -c–a-w c:\windows\system32\dllcache\mf3216.dll
+ 2007-03-08 15:36:28 40,960 -c–a-w c:\windows\system32\dllcache\mf3216.dll
- 2006-02-28 12:00:00 924,432 -c–a-w c:\windows\system32\dllcache\mfc40u.dll
+ 2006-11-01 19:17:45 927,504 -c–a-w c:\windows\system32\dllcache\mfc40u.dll
- 2006-02-28 12:00:00 1,024,000 -c–a-w c:\windows\system32\dllcache\mfc42u.dll
+ 2006-10-14 08:13:25 981,760 -c–a-w c:\windows\system32\dllcache\mfc42u.dll
- 2006-02-28 12:00:00 7,680 -c–a-w c:\windows\system32\dllcache\migregdb.exe
+ 2005-07-25 23:46:57 7,680 -c–a-w c:\windows\system32\dllcache\migregdb.exe
- 2006-02-28 12:00:00 72,960 -c–a-w c:\windows\system32\dllcache\mqac.sys
+ 2007-07-06 10:05:47 72,960 -c–a-w c:\windows\system32\dllcache\mqac.sys
- 2006-02-28 12:00:00 138,240 -c–a-w c:\windows\system32\dllcache\mqad.dll
+ 2007-07-06 12:46:59 138,240 -c–a-w c:\windows\system32\dllcache\mqad.dll
- 2006-02-28 12:00:00 47,104 -c–a-w c:\windows\system32\dllcache\mqdscli.dll
+ 2007-07-06 12:46:59 47,104 -c–a-w c:\windows\system32\dllcache\mqdscli.dll
- 2006-02-28 12:00:00 16,896 -c–a-w c:\windows\system32\dllcache\mqise.dll
+ 2007-07-06 12:46:59 16,896 -c–a-w c:\windows\system32\dllcache\mqise.dll
- 2006-02-28 12:00:00 660,992 -c–a-w c:\windows\system32\dllcache\mqqm.dll
+ 2007-07-06 12:46:59 660,992 -c–a-w c:\windows\system32\dllcache\mqqm.dll
- 2006-02-28 12:00:00 177,152 -c–a-w c:\windows\system32\dllcache\mqrt.dll
+ 2007-07-06 12:46:59 177,152 -c–a-w c:\windows\system32\dllcache\mqrt.dll
- 2006-02-28 12:00:00 95,744 -c–a-w c:\windows\system32\dllcache\mqsec.dll
+ 2007-07-06 12:46:59 95,744 -c–a-w c:\windows\system32\dllcache\mqsec.dll
- 2006-02-28 12:00:00 48,640 -c–a-w c:\windows\system32\dllcache\mqupgrd.dll
+ 2007-07-06 12:46:59 48,640 -c–a-w c:\windows\system32\dllcache\mqupgrd.dll
- 2006-02-28 12:00:00 471,552 -c–a-w c:\windows\system32\dllcache\mqutil.dll
+ 2007-07-06 12:46:59 471,552 -c–a-w c:\windows\system32\dllcache\mqutil.dll
- 2006-02-28 12:00:00 181,248 -c–a-w c:\windows\system32\dllcache\mrxdav.sys
+ 2007-12-18 09:51:35 179,584 -c–a-w c:\windows\system32\dllcache\mrxdav.sys
- 2006-02-28 12:00:00 143,360 -c–a-w c:\windows\system32\dllcache\msadco.dll
+ 2006-03-23 05:44:21 143,360 -c–a-w c:\windows\system32\dllcache\msadco.dll
- 2006-02-28 12:00:00 536,576 -c–a-w c:\windows\system32\dllcache\msado15.dll
+ 2006-12-26 13:07:23 536,576 -c–a-w c:\windows\system32\dllcache\msado15.dll
- 2006-02-28 12:00:00 180,224 -c–a-w c:\windows\system32\dllcache\msadomd.dll
+ 2006-12-26 13:07:23 180,224 -c–a-w c:\windows\system32\dllcache\msadomd.dll
- 2006-02-28 12:00:00 200,704 -c–a-w c:\windows\system32\dllcache\msadox.dll
+ 2006-12-26 13:07:23 200,704 -c–a-w c:\windows\system32\dllcache\msadox.dll
- 2006-02-28 12:00:00 425,472 -c–a-w c:\windows\system32\dllcache\msdtcprx.dll
+ 2006-03-01 19:42:42 426,496 -c–a-w c:\windows\system32\dllcache\msdtcprx.dll
- 2006-02-28 12:00:00 949,248 -c–a-w c:\windows\system32\dllcache\msdtctm.dll
+ 2006-03-01 19:42:42 956,416 -c–a-w c:\windows\system32\dllcache\msdtctm.dll
- 2006-02-28 12:00:00 161,280 -c–a-w c:\windows\system32\dllcache\msdtcuiu.dll
+ 2006-03-01 19:42:42 161,280 -c–a-w c:\windows\system32\dllcache\msdtcuiu.dll
- 2006-02-28 12:00:00 537,088 -c–a-w c:\windows\system32\dllcache\msftedit.dll
+ 2006-11-27 14:54:06 539,136 -c–a-w c:\windows\system32\dllcache\msftedit.dll
- 2006-02-28 12:00:00 2,804,224 -c–a-w c:\windows\system32\dllcache\msi.dll
+ 2005-05-04 19:45:32 2,890,240 -c–a-w c:\windows\system32\dllcache\msi.dll
- 2006-02-28 12:00:00 77,312 -c–a-w c:\windows\system32\dllcache\msiexec.exe
+ 2005-05-04 19:45:36 78,848 -c–a-w c:\windows\system32\dllcache\msiexec.exe
- 2006-02-28 12:00:00 331,264 -c–a-w c:\windows\system32\dllcache\msihnd.dll
+ 2005-05-04 19:45:36 271,360 -c–a-w c:\windows\system32\dllcache\msihnd.dll
- 2006-02-28 12:00:00 884,736 -c–a-w c:\windows\system32\dllcache\msimsg.dll
+ 2005-05-04 19:45:36 884,736 -c–a-w c:\windows\system32\dllcache\msimsg.dll
- 2006-02-28 12:00:00 44,032 -c–a-w c:\windows\system32\dllcache\msisip.dll
+ 2005-05-04 19:45:36 15,360 -c–a-w c:\windows\system32\dllcache\msisip.dll
- 2006-02-28 12:00:00 102,400 -c–a-w c:\windows\system32\dllcache\msjro.dll
+ 2006-12-26 13:07:23 102,400 -c–a-w c:\windows\system32\dllcache\msjro.dll
- 2006-02-28 12:00:00 1,311,232 -c–a-w c:\windows\system32\dllcache\msoe.dll
+ 2007-05-16 15:12:08 1,314,816 -c–a-w c:\windows\system32\dllcache\msoe.dll
- 2006-02-28 12:00:00 66,560 -c–a-w c:\windows\system32\dllcache\mtxclu.dll
+ 2006-03-01 19:42:42 66,560 -c–a-w c:\windows\system32\dllcache\mtxclu.dll
- 2006-02-28 12:00:00 90,112 -c–a-w c:\windows\system32\dllcache\mtxoci.dll
+ 2006-03-01 19:42:42 91,136 -c–a-w c:\windows\system32\dllcache\mtxoci.dll
- 2006-02-28 12:00:00 198,144 -c–a-w c:\windows\system32\dllcache\netman.dll
+ 2005-08-22 18:29:46 197,632 -c–a-w c:\windows\system32\dllcache\netman.dll
- 2006-02-28 12:00:00 364,544 -c–a-w c:\windows\system32\dllcache\npdsplay.dll
+ 2005-11-29 21:27:06 364,544 -c–a-w c:\windows\system32\dllcache\npdsplay.dll
- 2006-02-28 12:00:00 574,592 -c–a-w c:\windows\system32\dllcache\ntfs.sys
+ 2007-02-09 11:10:35 574,464 -c–a-w c:\windows\system32\dllcache\ntfs.sys
- 2006-02-28 12:00:00 58,880 -c–a-w c:\windows\system32\dllcache\nwapi32.dll
+ 2006-10-13 12:35:12 64,000 -c–a-w c:\windows\system32\dllcache\nwapi32.dll
- 2006-02-28 12:00:00 144,384 -c–a-w c:\windows\system32\dllcache\nwprovau.dll
+ 2006-10-13 12:35:12 142,336 -c–a-w c:\windows\system32\dllcache\nwprovau.dll
- 2006-02-28 12:00:00 163,584 -c–a-w c:\windows\system32\dllcache\nwrdr.sys
+ 2006-10-13 10:23:15 163,584 -c–a-w c:\windows\system32\dllcache\nwrdr.sys
- 2006-02-28 12:00:00 64,000 -c–a-w c:\windows\system32\dllcache\nwwks.dll
+ 2006-10-13 12:35:12 65,536 -c–a-w c:\windows\system32\dllcache\nwwks.dll
- 2006-02-28 12:00:00 1,281,536 -c–a-w c:\windows\system32\dllcache\ole32.dll
+ 2005-07-26 04:39:48 1,285,120 -c–a-w c:\windows\system32\dllcache\ole32.dll
- 2006-02-28 12:00:00 553,472 -c–a-w c:\windows\system32\dllcache\oleaut32.dll
+ 2007-12-04 18:38:13 550,912 -c–a-w c:\windows\system32\dllcache\oleaut32.dll
- 2006-02-28 12:00:00 68,608 -c–a-w c:\windows\system32\dllcache\olecli32.dll
+ 2005-07-26 04:39:48 74,752 -c–a-w c:\windows\system32\dllcache\olecli32.dll
- 2006-02-28 12:00:00 34,304 -c–a-w c:\windows\system32\dllcache\olecnv32.dll
+ 2005-07-26 04:39:49 37,888 -c–a-w c:\windows\system32\dllcache\olecnv32.dll
- 2006-02-28 12:00:00 117,760 -c–a-w c:\windows\system32\dllcache\oledlg.dll
+ 2006-10-16 16:15:00 122,880 -c–a-w c:\windows\system32\dllcache\oledlg.dll
- 2006-02-28 12:00:00 1,435,648 -c–a-w c:\windows\system32\dllcache\query.dll
+ 2006-06-22 05:06:30 1,435,648 -c–a-w c:\windows\system32\dllcache\query.dll
- 2006-02-28 12:00:00 8,192 -c–a-w c:\windows\system32\dllcache\rasadhlp.dll
+ 2006-06-26 17:37:10 8,192 -c–a-w c:\windows\system32\dllcache\rasadhlp.dll
- 2006-02-28 12:00:00 174,080 -c–a-w c:\windows\system32\dllcache\rasmans.dll
+ 2006-06-22 10:47:18 181,248 -c–a-w c:\windows\system32\dllcache\rasmans.dll
- 2006-02-28 12:00:00 176,512 -c–a-w c:\windows\system32\dllcache\rdbss.sys
+ 2006-05-05 09:47:57 174,592 -c–a-w c:\windows\system32\dllcache\rdbss.sys
- 2006-02-28 12:00:00 139,400 -c–a-w c:\windows\system32\dllcache\rdpwd.sys
+ 2005-06-10 04:09:46 139,528 -c–a-w c:\windows\system32\dllcache\rdpwd.sys
- 2006-02-28 12:00:00 431,616 -c–a-w c:\windows\system32\dllcache\riched20.dll
+ 2006-11-27 14:54:06 433,152 -c–a-w c:\windows\system32\dllcache\riched20.dll
- 2006-02-28 12:00:00 581,120 -c–a-w c:\windows\system32\dllcache\rpcrt4.dll
+ 2007-07-09 13:09:42 584,192 -c–a-w c:\windows\system32\dllcache\rpcrt4.dll
- 2006-02-28 12:00:00 395,776 -c–a-w c:\windows\system32\dllcache\rpcss.dll
+ 2005-07-26 04:39:49 397,824 -c–a-w c:\windows\system32\dllcache\rpcss.dll
- 2006-02-28 12:00:00 144,896 -c–a-w c:\windows\system32\dllcache\schannel.dll
+ 2007-04-25 14:21:15 144,896 -c–a-w c:\windows\system32\dllcache\schannel.dll
- 2006-02-28 12:00:00 8,384,000 -c–a-w c:\windows\system32\dllcache\shell32.dll
+ 2007-10-26 03:36:51 8,454,656 -c–a-w c:\windows\system32\dllcache\shell32.dll
- 2006-02-28 12:00:00 134,656 -c–a-w c:\windows\system32\dllcache\shsvcs.dll
+ 2006-12-19 21:52:18 134,656 -c–a-w c:\windows\system32\dllcache\shsvcs.dll
+ 2006-06-14 08:47:46 6,400 -c—-w c:\windows\system32\dllcache\splitter.sys
- 2006-02-28 12:00:00 57,856 -c–a-w c:\windows\system32\dllcache\spoolsv.exe
+ 2005-06-10 23:53:32 57,856 -c–a-w c:\windows\system32\dllcache\spoolsv.exe
- 2008-08-28 10:04:17 333,056 -c–a-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 11:57:21 333,184 -c–a-w c:\windows\system32\dllcache\srv.sys
- 2006-02-28 12:00:00 96,768 -c–a-w c:\windows\system32\dllcache\srvsvc.dll
+ 2004-12-07 19:32:34 96,768 -c–a-w c:\windows\system32\dllcache\srvsvc.dll
- 2006-02-28 12:00:00 713,216 -c–a-w c:\windows\system32\dllcache\sxs.dll
+ 2006-10-19 13:56:32 713,216 -c–a-w c:\windows\system32\dllcache\sxs.dll
- 2006-02-28 12:00:00 210,432 -c–a-w c:\windows\system32\dllcache\t2embed.dll
+ 2005-10-17 21:14:46 118,272 -c–a-w c:\windows\system32\dllcache\t2embed.dll
- 2006-02-28 12:00:00 246,272 -c–a-w c:\windows\system32\dllcache\tapisrv.dll
+ 2005-07-08 16:27:56 249,344 -c–a-w c:\windows\system32\dllcache\tapisrv.dll
- 2006-02-28 12:00:00 75,264 -c–a-w c:\windows\system32\dllcache\telnet.exe
+ 2005-05-10 23:45:48 75,776 -c–a-w c:\windows\system32\dllcache\telnet.exe
- 2006-02-28 12:00:00 101,376 -c–a-w c:\windows\system32\dllcache\txflog.dll
+ 2005-07-26 04:39:49 101,376 -c–a-w c:\windows\system32\dllcache\txflog.dll
- 2006-02-28 12:00:00 118,272 -c–a-w c:\windows\system32\dllcache\umpnpmgr.dll
+ 2005-08-23 03:35:42 123,392 -c–a-w c:\windows\system32\dllcache\umpnpmgr.dll
- 2006-02-28 12:00:00 209,408 -c–a-w c:\windows\system32\dllcache\update.sys
+ 2007-04-23 10:32:54 364,160 -c–a-w c:\windows\system32\dllcache\update.sys
- 2006-02-28 12:00:00 185,344 -c–a-w c:\windows\system32\dllcache\upnphost.dll
+ 2007-02-05 20:17:02 185,344 -c–a-w c:\windows\system32\dllcache\upnphost.dll
- 2006-02-28 12:00:00 577,024 -c–a-w c:\windows\system32\dllcache\user32.dll
+ 2007-03-08 15:36:28 577,536 -c–a-w c:\windows\system32\dllcache\user32.dll
- 2006-02-28 12:00:00 848,384 -c–a-w c:\windows\system32\dllcache\vgx.dll
+ 2007-06-26 15:13:22 851,968 -c–a-w c:\windows\system32\dllcache\vgx.dll
- 2006-02-28 12:00:00 504,832 -c–a-w c:\windows\system32\dllcache\wab32.dll
+ 2007-05-16 15:12:12 510,976 -c–a-w c:\windows\system32\dllcache\wab32.dll
- 2006-02-28 12:00:00 84,992 -c–a-w c:\windows\system32\dllcache\wabimp.dll
+ 2007-05-16 15:12:15 85,504 -c–a-w c:\windows\system32\dllcache\wabimp.dll
+ 2006-06-14 09:00:45 82,944 -c—-w c:\windows\system32\dllcache\wdmaud.sys
- 2006-02-28 12:00:00 67,584 -c–a-w c:\windows\system32\dllcache\webclnt.dll
+ 2006-01-04 03:35:05 68,096 -c–a-w c:\windows\system32\dllcache\webclnt.dll
- 2006-02-28 12:00:00 333,312 -c–a-w c:\windows\system32\dllcache\wiaservc.dll
+ 2006-12-19 18:16:47 333,824 -c–a-w c:\windows\system32\dllcache\wiaservc.dll
- 2006-02-28 12:00:00 290,816 -c–a-w c:\windows\system32\dllcache\winsrv.dll
+ 2007-03-17 13:43:01 292,864 -c–a-w c:\windows\system32\dllcache\winsrv.dll
- 2006-02-28 12:00:00 132,096 -c–a-w c:\windows\system32\dllcache\wkssvc.dll
+ 2006-08-17 12:28:27 132,096 -c–a-w c:\windows\system32\dllcache\wkssvc.dll
- 2006-02-28 12:00:00 230,400 -c–a-w c:\windows\system32\dllcache\wmasf.dll
+ 2007-10-27 21:39:20 230,912 -c–a-w c:\windows\system32\dllcache\wmasf.dll
- 2006-02-28 12:00:00 4,874,240 -c–a-w c:\windows\system32\dllcache\wmp.dll
+ 2007-04-30 07:22:16 4,734,976 -c–a-w c:\windows\system32\dllcache\wmp.dll
- 2006-02-28 12:00:00 11,776 -c–a-w c:\windows\system32\dllcache\xolehlp.dll
+ 2006-03-01 19:42:42 11,776 -c–a-w c:\windows\system32\dllcache\xolehlp.dll
- 2006-02-28 12:00:00 45,568 —-a-w c:\windows\system32\dnsrslvr.dll
+ 2008-02-20 05:32:43 45,568 —-a-w c:\windows\system32\dnsrslvr.dll
- 2006-02-28 12:00:00 142,464 —-a-w c:\windows\system32\drivers\aec.sys
+ 2006-02-15 00:22:26 142,464 —-a-w c:\windows\system32\drivers\aec.sys
+ 2008-05-09 17:15:51 45,376 —-a-w c:\windows\system32\drivers\avgntdd.sys
+ 2008-01-21 22:11:28 22,336 —-a-w c:\windows\system32\drivers\avgntmgr.sys
+ 2008-10-30 15:21:03 75,072 —-a-w c:\windows\system32\drivers\avipbb.sys
- 2006-02-28 12:00:00 124,800 —-a-w c:\windows\system32\drivers\fltMgr.sys
+ 2006-08-21 09:14:58 128,896 —-a-w c:\windows\system32\drivers\fltmgr.sys
+ 2009-01-18 03:05:38 85,969 —-a-w c:\windows\system32\drivers\gmer.sys
- 2006-02-28 12:00:00 263,040 —-a-w c:\windows\system32\drivers\http.sys
+ 2006-03-17 00:33:10 262,784 —-a-w c:\windows\system32\drivers\http.sys
- 2006-02-28 12:00:00 134,912 —-a-w c:\windows\system32\drivers\ipnat.sys
+ 2004-09-29 22:28:37 134,912 —-a-w c:\windows\system32\drivers\ipnat.sys
- 2006-02-28 12:00:00 171,776 —-a-w c:\windows\system32\drivers\kmixer.sys
+ 2006-06-14 08:47:45 172,416 —-a-w c:\windows\system32\drivers\kmixer.sys
- 2006-02-28 12:00:00 72,960 —-a-w c:\windows\system32\drivers\mqac.sys
+ 2007-07-06 10:05:47 72,960 —-a-w c:\windows\system32\drivers\mqac.sys
- 2006-02-28 12:00:00 181,248 —-a-w c:\windows\system32\drivers\mrxdav.sys
+ 2007-12-18 09:51:35 179,584 —-a-w c:\windows\system32\drivers\mrxdav.sys
- 2006-02-28 12:00:00 574,592 —-a-w c:\windows\system32\drivers\ntfs.sys
+ 2007-02-09 11:10:35 574,464 —-a-w c:\windows\system32\drivers\ntfs.sys
- 2006-02-28 12:00:00 163,584 —-a-w c:\windows\system32\drivers\nwrdr.sys
+ 2006-10-13 10:23:15 163,584 —-a-w c:\windows\system32\drivers\nwrdr.sys
- 2006-02-28 12:00:00 176,512 —-a-w c:\windows\system32\drivers\rdbss.sys
+ 2006-05-05 09:47:57 174,592 —-a-w c:\windows\system32\drivers\rdbss.sys
- 2006-02-28 12:00:00 139,400 —-a-w c:\windows\system32\drivers\rdpwd.sys
+ 2005-06-10 04:09:46 139,528 —-a-w c:\windows\system32\drivers\rdpwd.sys
- 2006-02-28 12:00:00 27,440 —-a-w c:\windows\system32\drivers\secdrv.sys
+ 2007-11-13 10:25:53 20,480 —-a-w c:\windows\system32\drivers\secdrv.sys
- 2004-08-04 04:07:48 6,400 —-a-w c:\windows\system32\drivers\splitter.sys
+ 2006-06-14 08:47:46 6,400 —-a-w c:\windows\system32\drivers\splitter.sys
+ 2007-03-01 14:34:22 28,352 —-a-w c:\windows\system32\drivers\ssmdrv.sys
- 2006-02-28 12:00:00 209,408 —-a-w c:\windows\system32\drivers\update.sys
+ 2007-04-23 10:32:54 364,160 —-a-w c:\windows\system32\drivers\update.sys
- 2006-02-28 12:00:00 82,944 —-a-w c:\windows\system32\drivers\wdmaud.sys
+ 2006-06-14 09:00:45 82,944 —-a-w c:\windows\system32\drivers\wdmaud.sys
- 2006-02-28 12:00:00 498,205 —-a-w c:\windows\system32\dxmasf.dll
+ 2006-08-22 09:05:26 498,742 —-a-w c:\windows\system32\dxmasf.dll
- 2006-02-28 12:00:00 1,082,368 —-a-w c:\windows\system32\esent.dll
+ 2005-10-20 22:20:03 1,082,368 —-a-w c:\windows\system32\esent.dll
- 2006-02-28 12:00:00 16,896 —-a-w c:\windows\system32\fltlib.dll
+ 2006-08-21 12:21:06 16,896 —-a-w c:\windows\system32\fltlib.dll
- 2006-02-28 12:00:00 22,528 —-a-w c:\windows\system32\fltMc.exe
+ 2006-08-21 09:14:58 23,040 —-a-w c:\windows\system32\fltmc.exe
- 2006-02-28 12:00:00 79,360 —-a-w c:\windows\system32\fontsub.dll
+ 2005-10-17 21:14:45 80,896 —-a-w c:\windows\system32\fontsub.dll
- 2006-02-28 12:00:00 38,912 —-a-w c:\windows\system32\hhsetup.dll
+ 2005-05-27 02:04:27 41,472 —-a-w c:\windows\system32\hhsetup.dll
- 2006-02-28 12:00:00 77,850 —-a-w c:\windows\system32\hlink.dll
+ 2006-07-21 08:24:43 72,704 —-a-w c:\windows\system32\hlink.dll
- 2006-02-28 12:00:00 345,088 —-a-w c:\windows\system32\hypertrm.dll
+ 2004-11-17 17:41:24 347,136 —-a-w c:\windows\system32\hypertrm.dll
- 2006-02-28 12:00:00 253,952 —-a-w c:\windows\system32\icm32.dll
+ 2005-06-29 01:46:00 254,976 —-a-w c:\windows\system32\icm32.dll
- 2006-02-28 12:00:00 94,720 —-a-w c:\windows\system32\iphlpapi.dll
+ 2006-05-19 12:59:41 94,720 —-a-w c:\windows\system32\iphlpapi.dll
- 2006-02-28 12:00:00 143,872 —-a-w c:\windows\system32\itircl.dll
+ 2005-05-27 02:04:27 155,136 —-a-w c:\windows\system32\itircl.dll
- 2006-02-28 12:00:00 134,144 —-a-w c:\windows\system32\itss.dll
+ 2005-05-27 02:04:27 137,216 —-a-w c:\windows\system32\itss.dll
- 2008-06-10 06:21:01 135,168 —-a-w c:\windows\system32\java.exe
+ 2009-01-09 22:55:06 144,792 —-a-w c:\windows\system32\java.exe
- 2008-06-10 06:21:04 135,168 —-a-w c:\windows\system32\javaw.exe
+ 2009-01-09 22:55:06 144,792 —-a-w c:\windows\system32\javaw.exe
- 2008-06-10 07:32:34 139,264 —-a-w c:\windows\system32\javaws.exe
+ 2009-01-09 22:55:06 148,888 —-a-w c:\windows\system32\javaws.exe
- 2006-02-28 12:00:00 144,896 —-a-w c:\windows\system32\jgdw400.dll
+ 2006-06-01 18:47:07 163,840 —-a-w c:\windows\system32\jgdw400.dll
- 2006-02-28 12:00:00 42,496 —-a-w c:\windows\system32\jgpl400.dll
+ 2006-06-01 18:47:07 27,648 —-a-w c:\windows\system32\jgpl400.dll
- 2006-02-28 12:00:00 294,400 —-a-w c:\windows\system32\kerberos.dll
+ 2005-06-15 17:49:30 295,936 —-a-w c:\windows\system32\kerberos.dll
- 2006-02-28 12:00:00 983,552 —-a-w c:\windows\system32\kernel32.dll
+ 2007-04-16 15:52:53 984,576 —-a-w c:\windows\system32\kernel32.dll
- 2006-02-28 12:00:00 18,944 —-a-w c:\windows\system32\linkinfo.dll
+ 2005-09-01 01:41:53 19,968 —-a-w c:\windows\system32\linkinfo.dll
- 2006-02-28 12:00:00 721,920 —-a-w c:\windows\system32\lsasrv.dll
+ 2007-11-07 09:26:56 721,920 —-a-w c:\windows\system32\lsasrv.dll
- 2006-02-28 12:00:00 39,936 —-a-w c:\windows\system32\mf3216.dll
+ 2007-03-08 15:36:28 40,960 —-a-w c:\windows\system32\mf3216.dll
- 2006-02-28 12:00:00 924,432 —-a-w c:\windows\system32\mfc40u.dll
+ 2006-11-01 19:17:45 927,504 —-a-w c:\windows\system32\mfc40u.dll
- 2006-02-28 12:00:00 1,024,000 —-a-w c:\windows\system32\mfc42u.dll
+ 2006-10-14 08:13:25 981,760 —-a-w c:\windows\system32\mfc42u.dll
- 2006-02-28 12:00:00 138,240 —-a-w c:\windows\system32\mqad.dll
+ 2007-07-06 12:46:59 138,240 —-a-w c:\windows\system32\mqad.dll
- 2006-02-28 12:00:00 47,104 —-a-w c:\windows\system32\mqdscli.dll
+ 2007-07-06 12:46:59 47,104 —-a-w c:\windows\system32\mqdscli.dll
- 2006-02-28 12:00:00 16,896 —-a-w c:\windows\system32\mqise.dll
+ 2007-07-06 12:46:59 16,896 —-a-w c:\windows\system32\mqise.dll
- 2006-02-28 12:00:00 660,992 —-a-w c:\windows\system32\mqqm.dll
+ 2007-07-06 12:46:59 660,992 —-a-w c:\windows\system32\mqqm.dll
- 2006-02-28 12:00:00 177,152 —-a-w c:\windows\system32\mqrt.dll
+ 2007-07-06 12:46:59 177,152 —-a-w c:\windows\system32\mqrt.dll
- 2006-02-28 12:00:00 95,744 —-a-w c:\windows\system32\mqsec.dll
+ 2007-07-06 12:46:59 95,744 —-a-w c:\windows\system32\mqsec.dll
- 2006-02-28 12:00:00 48,640 —-a-w c:\windows\system32\mqupgrd.dll
+ 2007-07-06 12:46:59 48,640 —-a-w c:\windows\system32\mqupgrd.dll
- 2006-02-28 12:00:00 471,552 —-a-w c:\windows\system32\mqutil.dll
+ 2007-07-06 12:46:59 471,552 —-a-w c:\windows\system32\mqutil.dll
- 2008-12-09 23:24:37 17,593,280 —-a-w c:\windows\system32\MRT.exe
+ 2009-01-10 01:35:28 20,853,704 —-a-w c:\windows\system32\MRT.exe
- 2006-02-28 12:00:00 425,472 —-a-w c:\windows\system32\msdtcprx.dll
+ 2006-03-01 19:42:42 426,496 —-a-w c:\windows\system32\msdtcprx.dll
- 2006-02-28 12:00:00 949,248 —-a-w c:\windows\system32\msdtctm.dll
+ 2006-03-01 19:42:42 956,416 —-a-w c:\windows\system32\msdtctm.dll
- 2006-02-28 12:00:00 161,280 —-a-w c:\windows\system32\msdtcuiu.dll
+ 2006-03-01 19:42:42 161,280 —-a-w c:\windows\system32\msdtcuiu.dll
- 2006-02-28 12:00:00 537,088 —-a-w c:\windows\system32\msftedit.dll
+ 2006-11-27 14:54:06 539,136 —-a-w c:\windows\system32\msftedit.dll
- 2006-02-28 12:00:00 2,804,224 —-a-w c:\windows\system32\msi.dll
+ 2005-05-04 19:45:32 2,890,240 —-a-w c:\windows\system32\msi.dll
- 2006-02-28 12:00:00 77,312 —-a-w c:\windows\system32\msiexec.exe
+ 2005-05-04 19:45:36 78,848 —-a-w c:\windows\system32\msiexec.exe
- 2006-02-28 12:00:00 331,264 —-a-w c:\windows\system32\msihnd.dll
+ 2005-05-04 19:45:36 271,360 —-a-w c:\windows\system32\msihnd.dll
- 2006-02-28 12:00:00 884,736 —-a-w c:\windows\system32\msimsg.dll
+ 2005-05-04 19:45:36 884,736 —-a-w c:\windows\system32\msimsg.dll
- 2006-02-28 12:00:00 44,032 —-a-w c:\windows\system32\msisip.dll
+ 2005-05-04 19:45:36 15,360 —-a-w c:\windows\system32\msisip.dll
- 2006-02-28 12:00:00 66,560 —-a-w c:\windows\system32\mtxclu.dll
+ 2006-03-01 19:42:42 66,560 —-a-w c:\windows\system32\mtxclu.dll
- 2006-02-28 12:00:00 90,112 —-a-w c:\windows\system32\mtxoci.dll
+ 2006-03-01 19:42:42 91,136 —-a-w c:\windows\system32\mtxoci.dll
- 2006-02-28 12:00:00 198,144 —-a-w c:\windows\system32\netman.dll
+ 2005-08-22 18:29:46 197,632 —-a-w c:\windows\system32\netman.dll
- 2006-02-28 12:00:00 58,880 —-a-w c:\windows\system32\nwapi32.dll
+ 2006-10-13 12:35:12 64,000 —-a-w c:\windows\system32\nwapi32.dll
- 2006-02-28 12:00:00 144,384 —-a-w c:\windows\system32\nwprovau.dll
+ 2006-10-13 12:35:12 142,336 —-a-w c:\windows\system32\nwprovau.dll
- 2006-02-28 12:00:00 64,000 —-a-w c:\windows\system32\nwwks.dll
+ 2006-10-13 12:35:12 65,536 —-a-w c:\windows\system32\nwwks.dll
- 2006-02-28 12:00:00 1,281,536 —-a-w c:\windows\system32\ole32.dll
+ 2005-07-26 04:39:48 1,285,120 —-a-w c:\windows\system32\ole32.dll
- 2006-02-28 12:00:00 553,472 —-a-w c:\windows\system32\oleaut32.dll
+ 2007-12-04 18:38:13 550,912 —-a-w c:\windows\system32\oleaut32.dll
- 2006-02-28 12:00:00 68,608 —-a-w c:\windows\system32\olecli32.dll
+ 2005-07-26 04:39:48 74,752 —-a-w c:\windows\system32\olecli32.dll
- 2006-02-28 12:00:00 34,304 —-a-w c:\windows\system32\olecnv32.dll
+ 2005-07-26 04:39:49 37,888 —-a-w c:\windows\system32\olecnv32.dll
- 2006-02-28 12:00:00 117,760 —-a-w c:\windows\system32\oledlg.dll
+ 2006-10-16 16:15:00 122,880 —-a-w c:\windows\system32\oledlg.dll
- 2008-11-02 21:17:46 40,394 —-a-w c:\windows\system32\perfc009.dat
+ 2009-01-14 21:04:26 40,394 —-a-w c:\windows\system32\perfc009.dat
- 2008-11-02 21:17:46 312,172 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-14 21:04:26 312,172 —-a-w c:\windows\system32\perfh009.dat
- 2006-02-28 12:00:00 1,435,648 —-a-w c:\windows\system32\query.dll
+ 2006-06-22 05:06:30 1,435,648 —-a-w c:\windows\system32\query.dll
- 2006-02-28 12:00:00 8,192 —-a-w c:\windows\system32\rasadhlp.dll
+ 2006-06-26 17:37:10 8,192 —-a-w c:\windows\system32\rasadhlp.dll
- 2006-02-28 12:00:00 174,080 —-a-w c:\windows\system32\rasmans.dll
+ 2006-06-22 10:47:18 181,248 —-a-w c:\windows\system32\rasmans.dll
- 2006-02-28 12:00:00 431,616 —-a-w c:\windows\system32\riched20.dll
+ 2006-11-27 14:54:06 433,152 —-a-w c:\windows\system32\riched20.dll
- 2006-02-28 12:00:00 581,120 —-a-w c:\windows\system32\rpcrt4.dll
+ 2007-07-09 13:09:42 584,192 —-a-w c:\windows\system32\rpcrt4.dll
- 2006-02-28 12:00:00 395,776 —-a-w c:\windows\system32\rpcss.dll
+ 2005-07-26 04:39:49 397,824 —-a-w c:\windows\system32\rpcss.dll
- 2006-02-28 12:00:00 144,896 —-a-w c:\windows\system32\schannel.dll
+ 2007-04-25 14:21:15 144,896 —-a-w c:\windows\system32\schannel.dll
- 2006-02-28 12:00:00 8,384,000 —-a-w c:\windows\system32\shell32.dll
+ 2007-10-26 03:36:51 8,454,656 —-a-w c:\windows\system32\shell32.dll
- 2006-02-28 12:00:00 134,656 —-a-w c:\windows\system32\shsvcs.dll
+ 2006-12-19 21:52:18 134,656 —-a-w c:\windows\system32\shsvcs.dll
- 2007-11-30 12:39:22 17,272 ——w c:\windows\system32\spmsg.dll
+ 2007-07-27 14:41:40 16,760 ——w c:\windows\system32\spmsg.dll
- 2006-02-28 12:00:00 57,856 —-a-w c:\windows\system32\spoolsv.exe
+ 2005-06-10 23:53:32 57,856 —-a-w c:\windows\system32\spoolsv.exe
- 2005-06-28 14:21:34 22,752 —-a-w c:\windows\system32\spupdsvc.exe
+ 2005-06-28 15:21:34 22,752 —-a-w c:\windows\system32\spupdsvc.exe
- 2006-02-28 12:00:00 96,768 —-a-w c:\windows\system32\srvsvc.dll
+ 2004-12-07 19:32:34 96,768 —-a-w c:\windows\system32\srvsvc.dll
- 2006-02-28 12:00:00 713,216 —-a-w c:\windows\system32\sxs.dll
+ 2006-10-19 13:56:32 713,216 —-a-w c:\windows\system32\sxs.dll
- 2006-02-28 12:00:00 210,432 —-a-w c:\windows\system32\t2embed.dll
+ 2005-10-17 21:14:46 118,272 —-a-w c:\windows\system32\t2embed.dll
- 2006-02-28 12:00:00 246,272 —-a-w c:\windows\system32\tapisrv.dll
+ 2005-07-08 16:27:56 249,344 —-a-w c:\windows\system32\tapisrv.dll
- 2006-02-28 12:00:00 75,264 —-a-w c:\windows\system32\telnet.exe
+ 2005-05-10 23:45:48 75,776 —-a-w c:\windows\system32\telnet.exe
- 2006-02-28 12:00:00 101,376 —-a-w c:\windows\system32\txflog.dll
+ 2005-07-26 04:39:49 101,376 —-a-w c:\windows\system32\txflog.dll
- 2006-02-28 12:00:00 118,272 —-a-w c:\windows\system32\umpnpmgr.dll
+ 2005-08-23 03:35:42 123,392 —-a-w c:\windows\system32\umpnpmgr.dll
- 2006-02-28 12:00:00 185,344 —-a-w c:\windows\system32\upnphost.dll
+ 2007-02-05 20:17:02 185,344 —-a-w c:\windows\system32\upnphost.dll
- 2006-02-28 12:00:00 577,024 —-a-w c:\windows\system32\user32.dll
+ 2007-03-08 15:36:28 577,536 —-a-w c:\windows\system32\user32.dll
- 2006-02-28 12:00:00 67,584 —-a-w c:\windows\system32\webclnt.dll
+ 2006-01-04 03:35:05 68,096 —-a-w c:\windows\system32\webclnt.dll
- 2006-02-28 12:00:00 333,312 —-a-w c:\windows\system32\wiaservc.dll
+ 2006-12-19 18:16:47 333,824 —-a-w c:\windows\system32\wiaservc.dll
- 2006-02-28 12:00:00 290,816 —-a-w c:\windows\system32\winsrv.dll
+ 2007-03-17 13:43:01 292,864 —-a-w c:\windows\system32\winsrv.dll
- 2006-02-28 12:00:00 132,096 —-a-w c:\windows\system32\wkssvc.dll
+ 2006-08-17 12:28:27 132,096 —-a-w c:\windows\system32\wkssvc.dll
- 2006-02-28 12:00:00 230,400 —-a-w c:\windows\system32\wmasf.dll
+ 2007-10-27 21:39:20 230,912 —-a-w c:\windows\system32\wmasf.dll
- 2006-02-28 12:00:00 4,874,240 —-a-w c:\windows\system32\wmp.dll
+ 2007-04-30 07:22:16 4,734,976 —-a-w c:\windows\system32\wmp.dll
- 2006-02-28 12:00:00 11,776 —-a-w c:\windows\system32\xolehlp.dll
+ 2006-03-01 19:42:42 11,776 —-a-w c:\windows\system32\xolehlp.dll
+ 2009-01-19 03:52:47 16,384 —-atw c:\windows\temp\Perflib_Perfdata_764.dat
+ 2006-08-25 15:45:55 1,054,208 —-a-w c:\windows\WinSxS\InstallTemp\16486435\comctl32.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\program files\AIM\aim.exe" [2005-08-05 67160]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"PopUpStopperFreeEdition"="d:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" [2003-04-29 524288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-01-08 4866048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-09 136600]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-06-14 278528]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
"nwiz"="nwiz.exe" [2004-01-08 c:\windows\system32\nwiz.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-08 13:49 356352 d:\spyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= DivXa32.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 SASDIFSV;SASDIFSV;d:\spyware\sasdifsv.sys [2008-11-17 8944]
R4 WUSB54Gv42SVC;WUSB54Gv42SVC;c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [2008-09-19 53307]
S1 SASKUTIL;SASKUTIL;\??\d:\saskutil.sys –> d:\SASKUTIL.sys [?]
S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\drivers\PhTVTune.sys [2006-09-15 53536]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys –> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 SASENUM;SASENUM;\??\d:\sasenum.sys –> d:\SASENUM.SYS [?]
.
- - - - ORPHANS REMOVED - - - -

Notify-NavLogon - (no file)


.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\Mozilla\Firefox\Profiles\6ygmzspj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-18 23:05:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(628)
d:\spyware\SASWINLO.DLL
.
Completion time: 2009-01-18 23:09:00
ComboFix-quarantined-files.txt 2009-01-19 04:08:11
ComboFix2.txt 2009-01-08 20:56:46

Pre-Run: 2,155,724,800 bytes free
Post-Run: 2,143,006,720 bytes free

626 — E O F — 2009-01-18 03:03:34



HJT:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:12:02 PM, on 1/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\AIM\aim.exe
D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\spyware\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://register.resnet.stonybrook.edu/wpad.dat
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\spyware\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\spyware\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\spyware\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: !SASWinLogon - D:\spyware\SASWINLO.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 5080 bytes


Things are still running slower than they were before. Checking my email on Yahoo is quicker than it is on Juno, but things are still slower, in general. All the sites that I normally visit (email, Facebook, etc.) all take longer to load than they would usually. Thank you for all your help so far with everything!
I'm starting to run out of options. I can't identify anything malicious on your computer and the various scanners are coming back clean. This doesn't meant that you don't have something nasty onboard, but it doesn't mean you do either.
The fact that you spent some time online without adequate anti-virus protection could have resulted in something you picked up messing with your system before being removed. If this is the case, there isn't a lot I can do about it. The only way to sort things out would be to reformat and reinstall.

We'll try one last look.
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
That's so strange that nothing can be pinpointed as a cause for things acting slow(er), but I guess the silver lining is that nothing seems to be wrong. Here are the logs:

RSIT log:


Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-01-21 00:34:21
Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (14%) free of 14 GB
Total RAM: 767 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:33 AM, on 1/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\AIM\aim.exe
D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Zena.ZENA-2CE3E9C195\Desktop\RSIT.exe
D:\spyware\Zena.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://register.resnet.stonybrook.edu/wpad.dat
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\spyware\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\spyware\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\spyware\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: !SASWinLogon - D:\spyware\SASWINLO.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 5126 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D; IE Protection - D:\spyware\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-09 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [2007-06-19 325048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-09 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-09 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google; - c:\program files\google\googletoolbar1.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"=C:\WINDOWS\BCMSMMSG.exe [2003-08-29 122880]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2004-01-08 4866048]
"nwiz"=nwiz.exe /installquiet []
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-09 136600]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2006-06-14 278528]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AIM"=C:\Program Files\AIM\aim.exe [2005-08-05 67160]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
"PopUpStopperFreeEdition"=D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe [2003-04-29 524288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
D:\spyware\SASWINLO.DLL [2009-01-08 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\DC++\DCPlusPlus.exe"="C:\Program Files\DC++\DCPlusPlus.exe:*:Disabled:DC++"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2009-01-21 00:34:21 —-D—- C:\rsit
2009-01-18 23:09:02 —-A—- C:\ComboFix.txt
2009-01-17 22:05:42 —-A—- C:\WINDOWS\gmer.ini
2009-01-17 22:05:38 —-A—- C:\WINDOWS\gmer_uninstall.cmd
2009-01-17 22:05:38 —-A—- C:\WINDOWS\gmer.dll
2009-01-17 22:05:37 —-A—- C:\WINDOWS\gmer.exe
2009-01-16 23:14:21 —-D—- C:\Documents and Settings\Zena.ZENA-2CE3E9C195\Application Data\wsInspector
2009-01-15 02:03:09 —-HDC—- C:\WINDOWS\$NtUninstallKB958687$
2009-01-14 00:58:56 —-HDC—- C:\WINDOWS\$NtUninstallKB899587$
2009-01-14 00:58:39 —-HDC—- C:\WINDOWS\$NtUninstallKB927779$
2009-01-14 00:58:20 —-HDC—- C:\WINDOWS\$NtUninstallKB927802$
2009-01-14 00:57:59 —-HDC—- C:\WINDOWS\$NtUninstallKB943460$
2009-01-14 00:57:43 —-HDC—- C:\WINDOWS\$NtUninstallKB885835$
2009-01-14 00:57:26 —-HDC—- C:\WINDOWS\$NtUninstallKB885836$
2009-01-14 00:57:08 —-HDC—- C:\WINDOWS\$NtUninstallKB937894$
2009-01-14 00:56:46 —-HDC—- C:\WINDOWS\$NtUninstallKB928255$
2009-01-14 00:56:26 —-HDC—- C:\WINDOWS\$NtUninstallKB911927$
2009-01-14 00:56:10 —-HDC—- C:\WINDOWS\$NtUninstallKB901017$
2009-01-14 00:55:54 —-HDC—- C:\WINDOWS\$NtUninstallKB899591$
2009-01-14 00:55:36 —-HDC—- C:\WINDOWS\$NtUninstallKB933729$
2009-01-14 00:55:22 —-HDC—- C:\WINDOWS\$NtUninstallKB920685$
2009-01-14 00:55:01 —-HDC—- C:\WINDOWS\$NtUninstallKB893756$
2009-01-14 00:54:46 —-HDC—- C:\WINDOWS\$NtUninstallKB923980$
2009-01-14 00:54:28 —-HDC—- C:\WINDOWS\$NtUninstallKB911280$
2009-01-14 00:54:10 —-HDC—- C:\WINDOWS\$NtUninstallKB911562$
2009-01-14 00:53:56 —-HDC—- C:\WINDOWS\$NtUninstallKB938828$
2009-01-14 00:53:40 —-HDC—- C:\WINDOWS\$NtUninstallKB924667$
2009-01-14 00:53:22 —-HDC—- C:\WINDOWS\$NtUninstallKB896423$
2009-01-14 00:53:08 —-HDC—- C:\WINDOWS\$NtUninstallKB900485$
2009-01-14 00:52:42 —-HDC—- C:\WINDOWS\$NtUninstallKB924270$
2009-01-14 00:52:29 —-HDC—- C:\WINDOWS\$NtUninstallKB931261$
2009-01-14 00:51:32 —-HDC—- C:\WINDOWS\$NtUninstallKB873339$
2009-01-14 00:51:15 —-HDC—- C:\WINDOWS\$NtUninstallKB936357$
2009-01-14 00:50:59 —-HDC—- C:\WINDOWS\$NtUninstallKB946026$
2009-01-14 00:50:44 —-HDC—- C:\WINDOWS\$NtUninstallKB896358$
2009-01-14 00:49:48 —-HDC—- C:\WINDOWS\$NtUninstallKB910437$
2009-01-14 00:48:57 —-HDC—- C:\WINDOWS\$NtUninstallKB925902$
2009-01-14 00:48:40 —-HDC—- C:\WINDOWS\$NtUninstallKB929123$
2009-01-14 00:48:22 —-HDC—- C:\WINDOWS\$NtUninstallKB920670$
2009-01-14 00:48:09 —-HDC—- C:\WINDOWS\$NtUninstallKB891781$
2009-01-14 00:47:55 —-HDC—- C:\WINDOWS\$NtUninstallKB918439$
2009-01-14 00:47:32 —-HDC—- C:\WINDOWS\$NtUninstallKB902400$
2009-01-14 00:47:08 —-HDC—- C:\WINDOWS\$NtUninstallKB890046$
2009-01-14 00:46:54 —-HDC—- C:\WINDOWS\$NtUninstallKB926436$
2009-01-14 00:46:39 —-HDC—- C:\WINDOWS\$NtUninstallKB920872$
2009-01-14 00:46:15 —-HDC—- C:\WINDOWS\$NtUninstallKB930178$
2009-01-14 00:46:02 —-HDC—- C:\WINDOWS\$NtUninstallKB914388$
2009-01-14 00:45:49 —-HDC—- C:\WINDOWS\$NtUninstallKB941569$
2009-01-14 00:44:53 —-HDC—- C:\WINDOWS\$NtUninstallKB905414$
2009-01-14 00:44:38 —-HDC—- C:\WINDOWS\$NtUninstallKB932168$
2009-01-14 00:44:25 —-HDC—- C:\WINDOWS\$NtUninstallKB901214$
2009-01-14 00:44:10 —-HDC—- C:\WINDOWS\$NtUninstallKB923191$
2009-01-14 00:43:55 —-HDC—- C:\WINDOWS\$NtUninstallKB922582$
2009-01-14 00:43:35 —-HDC—- C:\WINDOWS\$NtUninstallKB918118$
2009-01-14 00:43:21 —-HDC—- C:\WINDOWS\$NtUninstallKB926255$
2009-01-14 00:43:06 —-HDC—- C:\WINDOWS\$NtUninstallKB888302$
2009-01-14 00:42:52 —-HDC—- C:\WINDOWS\$NtUninstallKB900725$
2009-01-14 00:42:35 —-HDC—- C:\WINDOWS\$NtUninstallKB938127$
2009-01-14 00:42:23 —-HDC—- C:\WINDOWS\$NtUninstallKB920213$
2009-01-14 00:42:08 —-HDC—- C:\WINDOWS\$NtUninstallKB935840$
2009-01-14 00:41:54 —-HDC—- C:\WINDOWS\$NtUninstallKB943485$
2009-01-14 00:41:41 —-HDC—- C:\WINDOWS\$NtUninstallKB945553$
2009-01-14 00:41:28 —-HDC—- C:\WINDOWS\$NtUninstallKB886185$
2009-01-14 00:41:16 —-HDC—- C:\WINDOWS\$NtUninstallKB916595$
2009-01-14 00:41:04 —-HDC—- C:\WINDOWS\$NtUninstallKB930916$
2009-01-14 00:40:45 —-HDC—- C:\WINDOWS\$NtUninstallKB908531$
2009-01-14 00:40:32 —-HDC—- C:\WINDOWS\$NtUninstallKB905749$
2009-01-14 00:40:18 —-HDC—- C:\WINDOWS\$NtUninstallKB913580$
2009-01-14 00:40:06 —-HDC—- C:\WINDOWS\$NtUninstallKB896428$
2009-01-14 00:39:54 —-HDC—- C:\WINDOWS\$NtUninstallKB935839$
2009-01-14 00:39:43 —-HDC—- C:\WINDOWS\$NtUninstallKB943055$
2009-01-14 00:39:27 —-HDC—- C:\WINDOWS\$NtUninstallKB894391$
2009-01-14 00:39:16 —-HDC—- C:\WINDOWS\$NtUninstallKB908519$
2009-01-14 00:39:01 —-HDC—- C:\WINDOWS\$NtUninstallKB920683$
2009-01-14 00:38:48 —-HDC—- C:\WINDOWS\$NtUninstallKB914389$
2009-01-14 00:38:35 —-HDC—- C:\WINDOWS\$NtUninstallKB944653$
2009-01-14 00:38:24 —-HDC—- C:\WINDOWS\$NtUninstallKB890859$
2009-01-14 00:37:59 —-HDC—- C:\WINDOWS\$NtUninstallKB928843$
2009-01-13 15:44:17 —-D—- C:\Documents and Settings\Zena.ZENA-2CE3E9C195\Application Data\Malwarebytes
2009-01-13 15:43:59 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-13 08:30:30 —-HDC—- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2009-01-12 16:44:04 —-D—- C:\Program Files\Avira
2009-01-12 16:44:04 —-D—- C:\Documents and Settings\All Users\Application Data\Avira
2009-01-09 17:55:32 —-A—- C:\WINDOWS\system32\javaws.exe
2009-01-09 17:55:32 —-A—- C:\WINDOWS\system32\javaw.exe
2009-01-09 17:55:32 —-A—- C:\WINDOWS\system32\java.exe
2009-01-09 17:55:32 —-A—- C:\WINDOWS\system32\deploytk.dll
2009-01-09 17:54:47 —-D—- C:\Program Files\Symantec
2009-01-09 00:04:06 —-D—- C:\WINDOWS\temp
2009-01-08 15:41:00 —-A—- C:\Boot.bak
2009-01-08 15:40:51 —-RASHD—- C:\cmdcons
2009-01-08 15:39:14 —-A—- C:\WINDOWS\zip.exe
2009-01-08 15:39:14 —-A—- C:\WINDOWS\VFIND.exe
2009-01-08 15:39:14 —-A—- C:\WINDOWS\SWXCACLS.exe
2009-01-08 15:39:14 —-A—- C:\WINDOWS\SWSC.exe
2009-01-08 15:39:14 —-A—- C:\WINDOWS\SWREG.exe
2009-01-08 15:39:14 —-A—- C:\WINDOWS\sed.exe
2009-01-08 15:39:14 —-A—- C:\WINDOWS\NIRCMD.exe
2009-01-08 15:39:14 —-A—- C:\WINDOWS\grep.exe
2009-01-08 15:39:14 —-A—- C:\WINDOWS\fdsv.exe
2009-01-08 15:30:53 —-D—- C:\WINDOWS\ERDNT
2009-01-08 15:30:53 —-D—- C:\Qoobox
2008-12-28 02:57:16 —-D—- C:\Documents and Settings\All Users\Application Data\Last.fm

======List of files/folders modified in the last 1 months======

2009-01-21 00:33:17 —-D—- C:\Program Files\Mozilla Firefox
2009-01-20 14:50:20 —-D—- C:\WINDOWS\Prefetch
2009-01-20 06:40:14 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-01-19 00:28:09 —-D—- C:\WINDOWS\system32\drivers
2009-01-18 23:09:05 —-D—- C:\WINDOWS\system32
2009-01-18 23:09:04 —-D—- C:\WINDOWS
2009-01-18 23:05:16 —-A—- C:\WINDOWS\system.ini
2009-01-18 23:04:40 —-D—- C:\WINDOWS\AppPatch
2009-01-18 23:04:40 —-D—- C:\Program Files\Common Files
2009-01-18 23:02:23 —-D—- C:\WINDOWS\system32\CatRoot2
2009-01-17 22:05:01 —-D—- C:\WINDOWS\system32\CatRoot
2009-01-17 22:04:54 —-D—- C:\WINDOWS\system32\CatRoot_bak
2009-01-17 22:04:53 —-HD—- C:\WINDOWS\inf
2009-01-16 20:54:02 —-D—- C:\Program Files\Viewpoint
2009-01-16 20:54:02 —-D—- C:\Documents and Settings\All Users\Application Data\Viewpoint
2009-01-16 20:53:39 —-SHD—- C:\WINDOWS\Installer
2009-01-16 20:52:08 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2009-01-16 20:52:08 —-D—- C:\Config.Msi
2009-01-16 20:52:02 —-D—- C:\Program Files\Lavasoft
2009-01-16 20:52:02 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-01-15 02:03:25 —-RSHDC—- C:\WINDOWS\system32\dllcache
2009-01-15 02:02:16 —-HD—- C:\WINDOWS\$hf_mig$
2009-01-14 19:40:19 —-RD—- C:\Program Files
2009-01-14 16:04:24 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-14 16:01:58 —-D—- C:\WINDOWS\msagent
2009-01-14 00:59:03 —-A—- C:\WINDOWS\imsins.BAK
2009-01-14 00:49:38 —-D—- C:\Program Files\Windows Media Player
2009-01-14 00:48:44 —-D—- C:\Program Files\Outlook Express
2009-01-14 00:48:44 —-D—- C:\Program Files\Common Files\System
2009-01-14 00:47:42 —-D—- C:\WINDOWS\system32\Com
2009-01-13 15:38:37 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-12 16:39:56 —-D—- C:\Program Files\Common Files\Symantec Shared
2009-01-12 16:39:52 —-D—- C:\Documents and Settings\All Users\Application Data\Symantec
2009-01-10 12:34:40 —-D—- C:\Documents and Settings\Zena.ZENA-2CE3E9C195\Application Data\Mozilla
2009-01-09 20:35:28 —-A—- C:\WINDOWS\system32\MRT.exe
2009-01-09 17:55:01 —-D—- C:\Program Files\Java
2009-01-08 15:49:28 —-D—- C:\WINDOWS\system32\config
2009-01-08 15:47:21 —-D—- C:\Temp
2009-01-08 15:41:00 —-RASH—- C:\boot.ini
2009-01-08 13:13:03 —-A—- C:\WINDOWS\system32\3f856b28-.txt
2008-12-28 02:57:15 —-D—- C:\Program Files\iTunes

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-02-28 36096]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 SASDIFSV;SASDIFSV; \??\D:\spyware\SASDIFSV.SYS []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-09-19 20747]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2006-02-28 60800]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2003-05-15 43136]
R3 BCMModem;BCM V.92 56K Modem; C:\WINDOWS\system32\DRIVERS\BCMSM.sys [2003-08-29 1101696]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2006-02-28 14080]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2005-02-02 14408]
R3 GTNDIS5;GTNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\GTNDIS5.SYS []
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2006-02-28 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-01-08 1378636]
R3 STAC97;Audio Driver (WDM) - SigmaTel CODEC; C:\WINDOWS\system32\drivers\stac97.sys [2004-05-12 258704]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-02-28 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-02-28 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-02-28 20480]
R3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver; C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2005-10-17 245376]
S1 SASKUTIL;SASKUTIL; \??\D:\SASKUTIL.sys []
S3 Cap7134;Cap7134 Capture; C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2006-09-15 366464]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2006-02-28 10880]
S3 PhTVTune;Cap7134 TVTuner; C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2006-09-15 53536]
S3 RimUsb;BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys []
S3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2006-02-28 5888]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\wg111v2.sys []
S3 SASENUM;SASENUM; \??\D:\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2006-02-28 11136]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2006-02-28 15360]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2006-02-28 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-02-28 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-09 152984]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2004-01-08 77824]
R3 iPodService;iPodService; C:\Program Files\iPod\bin\iPodService.exe [2006-06-14 323584]
S2 WUSB54Gv42SVC;WUSB54Gv42SVC; C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [2005-07-04 53307]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-06-08 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]

—————–EOF—————–



RSIT info:


info.txt logfile of random's system information tool 1.05 2009-01-21 00:35:07

======Uninstall list======

–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Download Manager 2.0 (Remove Only)–>"C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Flash Player 10 Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Photoshop 7.0–>C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Reader 7.0.7–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70700000002}
Adobe Shockwave Player 11–>C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Advanced X Video Converter–>"C:\Program Files\XVideoConverter\unins000.exe"
AOL Instant Messenger–>C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
AVerTV–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{8DF56C91-281F-4C15-B954-F45FDC919568} /l1033
Avira AntiVir Personal - Free Antivirus–>C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
BCM V.92 56K Modem–>C:\WINDOWS\BCMSMU.exe quiet
Broadcom 440x 10/100 Integrated Controller–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{52504CE6-E909-4113-B232-4AFEC6543A61} /l1033
Cole2k Media - Codec Pack (Standard)–>C:\WINDOWS\system32\C2MP\Uninst.exe
DC++ 0.699–>"C:\Program Files\DC++\uninstall.exe"
Dell ResourceCD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DivX–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
ESPN RunTime–>C:\Program Files\ESPNRunTime\DIGSvcUninstall.exe /brand=ESPN
Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
HijackThis 2.0.2–>"D:\spyware\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
iPod for Windows 2006-06-28–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BD57EA4D-026E-4F08-9B93-080E282B81FE} /l1033
iTunes–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{54C0D94A-F467-4ABC-9D02-6E58748668D4} /l1033
J2SE Runtime Environment 5.0 Update 11–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 6–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Jasc Paint Shop Photo Album–>MsiExec.exe /I{B76D4A7F-FF11-4420-947C-C3AD624B9DBA}
Java™ 6 Update 11–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java™ 6 Update 3–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Last.fm 1.5.2.38918–>"D:\Last.fm\unins000.exe"
Linksys Wireless-G USB Network Adapter–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C7EEF2B9-8C16-4A04-B98D-B1A952A47E55}\setup.exe" -l0x9
Malwarebytes' Anti-Malware–>"D:\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Office 2000 Professional–>MsiExec.exe /I{00010409-78E1-11D2-B60F-006097C998E7}
Microsoft Silverlight–>MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Mozilla Firefox (3.0.5)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN–>C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
NVIDIA Windows 2000/XP Display Drivers–>rundll32.exe C:\WINDOWS\system32\nvinstnt.dll,NvUninstallNT4 nvdm.inf
Office Key 8.3 Demo–>C:\Program Files\Passware\demos\un-offkeyd.exe
OpenOffice.org Installer 1.0–>MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
Pop-Up Stopper Free Edition–>D:\PROGRA~1\PANICW~1\POP-UP~1\UNWISE.EXE D:\PROGRA~1\PANICW~1\POP-UP~1\INSTALL.LOG
QuickTime–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{C21D5524-A970-42FA-AC8A-59B8C7CDCA31} /l1033
RealPlayer–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
ScanToWeb–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}\setup.exe" ADDREMOVEDLG
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB890046)–>"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)–>"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)–>"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)–>"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)–>"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)–>"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)–>"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)–>"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)–>"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)–>"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)–>"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)–>"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)–>"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)–>"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)–>"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)–>"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913580)–>"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)–>"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)–>"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)–>"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)–>"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)–>"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)–>"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)–>"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)–>"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)–>"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923980)–>"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)–>"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)–>"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)–>"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)–>"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)–>"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)–>"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)–>"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)–>"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)–>"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)–>"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)–>"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)–>"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)–>"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)–>"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)–>"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)–>"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB937894)–>"C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938127)–>"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943055)–>"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943460)–>"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943485)–>"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944338-v2)–>"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)–>"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB945553)–>"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946026)–>"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)–>"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956390)–>"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958215)–>"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960714)–>"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Shockwave–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
SigmaTel AC97 Audio Drivers–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7959721D-8268-4565-9E0E-C41A9F4848A9}\setup.exe" -l0x9 -nodialog -uninstall
Sonic RecordNow!–>MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Spybot - Search & Destroy–>"D:\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.1–>"D:\SpywareBlaster\unins000.exe"
SUPERAntiSpyware Free Edition–>MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Update for Windows XP (KB894391)–>"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Update for Windows XP (KB900485)–>"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Update for Windows XP (KB908531)–>"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)–>"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB911280)–>"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)–>"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920872)–>"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)–>"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)–>"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB936357)–>"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)–>"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Viewpoint Media Player–>C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Genuine Advantage v1.3.0254.0–>MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Installer 3.1 (KB893803)–>"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows XP Hotfix - KB873339–>C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835–>C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836–>C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB886185–>C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302–>C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859–>"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781–>C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe

======Hosts File======

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

======Security center information======

AV: Avira AntiVir PersonalEdition

System event log

Computer Name: ZENA-2CE3E9C195
Event Code: 4201
Message: The system detected that network adapter \DEVICE\TCPIP_{FC4218C4-3708-4266-8D53-2E9A6B866C64} was connected to the network,
and has initiated normal operation over the network adapter.

Record Number: 57460
Source Name: Tcpip
Time Written: 20090109020304.000000-300
Event Type: information
User:

Computer Name: ZENA-2CE3E9C195
Event Code: 4201
Message: The system detected that network adapter \DEVICE\TCPIP_{FC4218C4-3708-4266-8D53-2E9A6B866C64} was connected to the network,
and has initiated normal operation over the network adapter.

Record Number: 57459
Source Name: Tcpip
Time Written: 20090109015104.000000-300
Event Type: information
User:

Computer Name: ZENA-2CE3E9C195
Event Code: 4201
Message: The system detected that network adapter \DEVICE\TCPIP_{FC4218C4-3708-4266-8D53-2E9A6B866C64} was connected to the network,
and has initiated normal operation over the network adapter.

Record Number: 57458
Source Name: Tcpip
Time Written: 20090109013904.000000-300
Event Type: information
User:

Computer Name: ZENA-2CE3E9C195
Event Code: 4201
Message: The system detected that network adapter \DEVICE\TCPIP_{FC4218C4-3708-4266-8D53-2E9A6B866C64} was connected to the network,
and has initiated normal operation over the network adapter.

Record Number: 57457
Source Name: Tcpip
Time Written: 20090109012704.000000-300
Event Type: information
User:

Computer Name: ZENA-2CE3E9C195
Event Code: 4201
Message: The system detected that network adapter \DEVICE\TCPIP_{FC4218C4-3708-4266-8D53-2E9A6B866C64} was connected to the network,
and has initiated normal operation over the network adapter.

Record Number: 57456
Source Name: Tcpip
Time Written: 20090109011504.000000-300
Event Type: information
User:

Application event log

Computer Name: ZENA-2CE3E9C195
Event Code: 35
Message:
Record Number: 7610
Source Name: ccEvtMgr
Time Written: 20080715001813.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: ZENA-2CE3E9C195
Event Code: 34
Message:
Record Number: 7609
Source Name: ccEvtMgr
Time Written: 20080715001812.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: ZENA-2CE3E9C195
Event Code: 0
Message:
Record Number: 7608
Source Name: Viewpoint Manager Service
Time Written: 20080715001812.000000-240
Event Type: information
User:

Computer Name: ZENA-2CE3E9C195
Event Code: 35
Message:
Record Number: 7607
Source Name: ccSetMgr
Time Written: 20080715001812.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: ZENA-2CE3E9C195
Event Code: 34
Message:
Record Number: 7606
Source Name: ccSetMgr
Time Written: 20080715001811.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

—————–EOF—————–
Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
  • Read the Information panel and then click Accept.
  • Allow the ActiveX download if necessary.
  • Both the anti-virus engine and database will need to be downloaded, which may take a little time.
  • Once this has been completed, select My Computer from the Scan section on the left hand side.
  • Put the kettle on!
  • Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
    Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
  • When the scan has completed, click View scan report at the bottom.
  • Click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
I got a message saying that my system doesn't meet the requirements for the scan, so I checked the program help info. From what it states there, I believe that I have all the requirements on my computer, so I'm unsure as to what I should do. Am I overlooking something?
I just tried the website on Firefox and it didn't give me any error messages, but I know you said IE is preferred for the scan. Should I try the scan in Firefox instead?
It's possible that the security settings that you have for IE are causing the issue. Given that it works in FF, i'd go with that rather than configuring IE. Lots of online things are optimised for IE because all PC owners running Windows have it, and sometimes alternative browsers don't have the same support.
Alright, here are the requested logs:


Kaspersky:


——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, January 25, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, January 25, 2009 04:06:18
Records in database: 1701544
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 40729
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 01:21:59

No malware has been detected. The scan area is clean.

The selected area was scanned.


HJT:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16:55 AM, on 1/26/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\AIM\aim.exe
D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\spyware\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://register.resnet.stonybrook.edu/wpad.dat
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\spyware\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\spyware\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\spyware\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: !SASWinLogon - D:\spyware\SASWINLO.DLL
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 5080 bytes


My computer is still running slower. I've noticed that with most of the websites, the lower left hand corner of the screen says "Waiting for ad.doubleclicker" a lot. I've done some searches on Google and sometimes when I click a link it doesn't open the page and the address gets forwarded to ad.doubleclicker.net or some variation of that address. I was searching for a blog yesterday on Google and I click the link and it didn't open and instead the address was ad4.doubleclicker.net instead of xyz.blogspot.com. I click the back button and tried the link again and it opened the second time. Is this normal? I've never had this happen prior to the spyware issues…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI