Here you go! Thanks . . .
ComboFix 09-02-12.03 - Don 2009-02-13 2:03:09.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1015.518 [GMT -5:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: Norton AntiVirus *On-access scanning disabled* (Outdated)
AV: Windows Live OneCare Antivirus *On-access scanning disabled* (Outdated)
FW: Windows Live OneCare Firewall *enabled*
* Created a new restore point
FILE ::
c:\windows\Tasks\znqcdnkl.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Azureus
c:\documents and settings\All Users\Application Data\Azureus\azCID.txt
c:\documents and settings\Brittany\Application Data\LimeWire
c:\documents and settings\Brittany\Application Data\LimeWire\414splashfree.png
c:\documents and settings\Brittany\Application Data\LimeWire\active.mojito
c:\documents and settings\Brittany\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Brittany\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Brittany\Application Data\LimeWire\downloads.dat
c:\documents and settings\Brittany\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Brittany\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Brittany\Application Data\LimeWire\filters.props
c:\documents and settings\Brittany\Application Data\LimeWire\gnutella.net
c:\documents and settings\Brittany\Application Data\LimeWire\installation.props
c:\documents and settings\Brittany\Application Data\LimeWire\library.dat
c:\documents and settings\Brittany\Application Data\LimeWire\limewire.props
c:\documents and settings\Brittany\Application Data\LimeWire\mojito.props
c:\documents and settings\Brittany\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Brittany\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Brittany\Application Data\LimeWire\promotion\promodb.lck
c:\documents and settings\Brittany\Application Data\LimeWire\promotion\promodb.log
c:\documents and settings\Brittany\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Brittany\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Brittany\Application Data\LimeWire\questions.props
c:\documents and settings\Brittany\Application Data\LimeWire\responses.cache
c:\documents and settings\Brittany\Application Data\LimeWire\simpp.xml
c:\documents and settings\Brittany\Application Data\LimeWire\spam.dat
c:\documents and settings\Brittany\Application Data\LimeWire\tables.props
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\
01_star.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\
02_star.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\
03_star.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\
04_star.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\
05_star.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\logo.png
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\notsearching.png
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\searching.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\splash.png
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\splashpro.png
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Brittany\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Brittany\Application Data\LimeWire\ttree.cache
c:\documents and settings\Brittany\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Brittany\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Brittany\Application Data\LimeWire\version.xml
c:\documents and settings\Brittany\Application Data\LimeWire\versions.props
c:\documents and settings\Brittany\Application Data\LimeWire\xml\data\audio.sxml2
c:\documents and settings\Brittany\Application Data\LimeWire\xml\data\delete_me
c:\documents and settings\Brittany\Application Data\LimeWire\xml\misc\application.gif
c:\documents and settings\Brittany\Application Data\LimeWire\xml\misc\audio.gif
c:\documents and settings\Brittany\Application Data\LimeWire\xml\misc\document.gif
c:\documents and settings\Brittany\Application Data\LimeWire\xml\misc\image.gif
c:\documents and settings\Brittany\Application Data\LimeWire\xml\misc\video.gif
c:\documents and settings\Brittany\Application Data\LimeWire\xml\schemas\application.xsd
c:\documents and settings\Brittany\Application Data\LimeWire\xml\schemas\audio.xsd
c:\documents and settings\Brittany\Application Data\LimeWire\xml\schemas\document.xsd
c:\documents and settings\Brittany\Application Data\LimeWire\xml\schemas\image.xsd
c:\documents and settings\Brittany\Application Data\LimeWire\xml\schemas\video.xsd
c:\documents and settings\Don\Application Data\Azureus
c:\documents and settings\Don\Application Data\Azureus\.certs
c:\documents and settings\Don\Application Data\Azureus\.keystore
c:\documents and settings\Don\Application Data\Azureus\.lock
c:\documents and settings\Don\Application Data\Azureus\active\
0483AC0DCFD4E79ED5DAD3394BCCDEE4EECDE87C.dat
c:\documents and settings\Don\Application Data\Azureus\active\
0483AC0DCFD4E79ED5DAD3394BCCDEE4EECDE87C.dat.bak
c:\documents and settings\Don\Application Data\Azureus\active\cache.dat
c:\documents and settings\Don\Application Data\Azureus\azureus.config
c:\documents and settings\Don\Application Data\Azureus\azureus.config.bak
c:\documents and settings\Don\Application Data\Azureus\azureus.statistics
c:\documents and settings\Don\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\Don\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Don\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Don\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Don\Application Data\Azureus\dht\general.dat
c:\documents and settings\Don\Application Data\Azureus\dht\version.dat
c:\documents and settings\Don\Application Data\Azureus\downloads.config
c:\documents and settings\Don\Application Data\Azureus\downloads.config.bak
c:\documents and settings\Don\Application Data\Azureus\friends.config
c:\documents and settings\Don\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Don\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\MetaSearch_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\Subscriptions_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\v3.ads_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\v3.CMsgr_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\v3.emp_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\v3.Friends_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\v3.MD_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\v3.PMsgr_1.log
c:\documents and settings\Don\Application Data\Azureus\logs\v3.Stream_1.log
c:\documents and settings\Don\Application Data\Azureus\media\azpd\ASB2YDOP2TTZ5VO22M4UXTG64TXM32D4.azpd
c:\documents and settings\Don\Application Data\Azureus\metasearch.config
c:\documents and settings\Don\Application Data\Azureus\metasearch.config.bak
c:\documents and settings\Don\Application Data\Azureus\net\pm_20115.dat
c:\documents and settings\Don\Application Data\Azureus\net\pm_default.dat
c:\documents and settings\Don\Application Data\Azureus\sidebarauto.config
c:\documents and settings\Don\Application Data\Azureus\subs\8DE6E5753F5ADF094F49.vuze
c:\documents and settings\Don\Application Data\Azureus\subs\95B34C1A1F40931D0972.vuze
c:\documents and settings\Don\Application Data\Azureus\subs\C812A6FF933B4196A2B4.vuze
c:\documents and settings\Don\Application Data\Azureus\subscriptions.config
c:\documents and settings\Don\Application Data\Azureus\subscriptions.config.bak
c:\documents and settings\Don\Application Data\Azureus\tables.config
c:\documents and settings\Don\Application Data\Azureus\tables.config.bak
c:\documents and settings\Don\Application Data\Azureus\timingstats.dat
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU4991.tmp
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU4992.tmp
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU4993.tmp
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU4994.tmp
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU4995.tmp
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU4996.tmp
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU4997.tmp
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU4998.tmp
c:\documents and settings\Don\Application Data\Azureus\tmp\AZU5000.tmp
c:\documents and settings\Don\Application Data\Azureus\torrents\AZU4999.tmp
c:\documents and settings\Don\Application Data\Azureus\tracker.config
c:\documents and settings\Don\Application Data\Azureus\tracker.config.bak
c:\documents and settings\Don\Application Data\Azureus\unsentdata.config
c:\documents and settings\Don\Application Data\Azureus\v3.Friends.dat
c:\documents and settings\Don\Application Data\Azureus\v3.Friends.dat.bak
c:\documents and settings\Don\Application Data\Azureus\VuzeActivities.config
c:\documents and settings\Don\Application Data\Azureus\VuzeActivities.config.bak
c:\documents and settings\Don\Application Data\LimeWire
c:\documents and settings\Don\Application Data\LimeWire\active.mojito
c:\documents and settings\Don\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Don\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Don\Application Data\LimeWire\downloads.dat
c:\documents and settings\Don\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Don\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Don\Application Data\LimeWire\filters.props
c:\documents and settings\Don\Application Data\LimeWire\gnutella.net
c:\documents and settings\Don\Application Data\LimeWire\installation.props
c:\documents and settings\Don\Application Data\LimeWire\library.dat
c:\documents and settings\Don\Application Data\LimeWire\limewire.props
c:\documents and settings\Don\Application Data\LimeWire\mojito.props
c:\documents and settings\Don\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Don\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Don\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Don\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Don\Application Data\LimeWire\questions.props
c:\documents and settings\Don\Application Data\LimeWire\responses.cache
c:\documents and settings\Don\Application Data\LimeWire\simpp.xml
c:\documents and settings\Don\Application Data\LimeWire\spam.dat
c:\documents and settings\Don\Application Data\LimeWire\tables.props
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\
01_star.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\
02_star.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\
03_star.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\
04_star.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\
05_star.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Don\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Don\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Don\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Don\Application Data\LimeWire\version.xml
c:\documents and settings\Don\Application Data\LimeWire\versions.props
c:\documents and settings\Don\Application Data\LimeWire\xml\data\audio.sxml2
c:\documents and settings\Don\Application Data\LimeWire\xml\data\video.sxml2
c:\program files\Vuze
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.zip
c:\program files\Vuze\plugins\azemp\azmplay.exe.bak
c:\program files\Vuze\plugins\azemp\cp1250-a.raw.bak
c:\program files\Vuze\plugins\azemp\cp1250-b.raw.bak
c:\program files\Vuze\plugins\azemp\font.desc.bak
c:\program files\Vuze\plugins\azemp\mplayer\config
c:\program files\Vuze\plugins\azemp\osd-mplayer-a.raw.bak
c:\program files\Vuze\plugins\azemp\osd-mplayer-b.raw.bak
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.32
.
((((((((((((((((((((((((( Files Created from 2009-01-13 to 2009-02-13 )))))))))))))))))))))))))))))))
.
2009-02-13 01:59 . 2009-02-13 01:59 2,921,379 -ra------ C:\ComboFix.exe
2009-02-10 18:34 . 2009-02-10 18:34 <DIR> d-------- C:\TELEMARKETING_files
2009-02-10 18:34 . 2009-02-10 18:34 4,140 --a------ C:\TELEMARKETING.htm
2009-02-10 02:42 . 2009-02-10 02:42 197 --a------ c:\windows\system32\MRT.INI
2009-02-08 12:21 . 2009-02-08 13:00 <DIR> d-------- C:\Sansa
2009-02-06 19:19 . 2009-02-06 19:19 <DIR> d-------- c:\program files\ERUNT
2009-02-05 10:49 . 2009-02-05 10:49 1,056 --a------ C:\Export
2009-02-03 23:13 . 2009-02-03 23:13 <DIR> d-------- c:\program files\The Weather Channel FW
2009-02-03 21:26 . 2009-02-03 21:26 <DIR> d-------- c:\program files\Common Files\xing shared
2009-02-03 21:23 . 2009-02-03 21:23 <DIR> d-------- c:\program files\Real
2009-02-03 19:12 . 2009-02-03 19:12 13,408 --a------ C:\2008_Federal_FAFSA.pdf
2009-02-03 00:51 . 2009-02-03 00:51 4,863 --a------ C:\Export (1).QIF
2009-02-03 00:50 . 2009-02-05 10:49 1,056 --a------ C:\Export.QIF
2009-02-03 00:45 . 2009-02-03 00:45 2,073 --a------ C:\Export.CSV
2009-02-02 23:43 . 2009-02-02 23:43 2,402,775 --a------ C:\mycheckbook-setup.exe
2009-01-31 13:12 . 2009-01-31 13:10 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-01-28 19:13 . 2009-01-28 19:13 <DIR> d-------- c:\program files\Opera
2009-01-15 14:31 . 2009-01-15 14:31 40,960 --a------ c:\windows\system32\jqgehrdy.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-13 05:35 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-11 21:49 --------- d-----w c:\program files\eMule
2009-02-04 02:26 --------- d-----w c:\program files\Common Files\Real
2009-02-04 02:25 --------- d-----w c:\program files\Common Files\csshare
2009-02-03 04:56 --------- d-----w c:\program files\Document
2009-02-02 07:09 --------- d-----w c:\program files\icuii
2009-01-31 18:10 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-31 18:10 --------- d-----w c:\program files\Java
2009-01-13 20:47 --------- d-----w c:\documents and settings\Brittany\Application Data\DivX
2009-01-08 02:19 --------- d-----w c:\documents and settings\Joseph\Application Data\DivX
2009-01-07 05:22 --------- d-----w c:\program files\DivX
2009-01-01 03:07 129,024 ----a-w c:\windows\system32\poegsmvl.dll
2009-01-01 03:07 129,024 ----a-w c:\windows\system32\ayyrxu.dll
2009-01-01 03:01 72,704 ----a-w c:\windows\system32\wqcgxcjp.dll
2008-12-31 03:01 129,024 ----a-w c:\windows\system32\torbwg.dll
2008-12-31 03:01 129,024 ----a-w c:\windows\system32\qhgadedb.dll
2008-12-31 02:57 72,704 ----a-w c:\windows\system32\efokwrsu.dll
2008-12-29 16:04 129,024 ----a-w c:\windows\system32\qzsybu.dll
2008-12-29 16:04 129,024 ----a-w c:\windows\system32\irdanupy.dll
2008-12-29 16:01 72,704 ----a-w c:\windows\system32\xputtpes.dll
2008-12-28 23:04 129,024 ----a-w c:\windows\system32\sdokxcfl.dll
2008-12-28 23:04 129,024 ----a-w c:\windows\system32\jknrlx.dll
2008-12-27 20:33 129,024 ----a-w c:\windows\system32\exwcvfus.dll
2008-12-27 20:33 129,024 ----a-w c:\windows\system32\bqvfbz.dll
2008-12-27 20:30 72,704 ----a-w c:\windows\system32\xfeyalsm.dll
2008-12-26 13:49 129,024 ----a-w c:\windows\system32\zqywsc.dll
2008-12-26 13:49 129,024 ----a-w c:\windows\system32\vwhvjmuf.dll
2008-12-26 13:46 72,704 ----a-w c:\windows\system32\yqswdjnu.dll
2008-12-24 02:03 72,704 ----a-w c:\windows\system32\kojovxka.dll
2008-12-23 01:43 72,704 ----a-w c:\windows\system32\knasyfvv.dll
2008-12-22 01:27 129,024 ----a-w c:\windows\system32\xmhnmu.dll
2008-12-22 01:27 129,024 ----a-w c:\windows\system32\krtwvgwd.dll
2008-12-22 01:24 72,704 ----a-w c:\windows\system32\qmjbhtdy.dll
2008-12-20 23:19 72,704 ----a-w c:\windows\system32\ujdpgwqm.dll
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-20 05:09 --------- d-----w c:\program files\Common Files\Adobe
2008-12-19 23:28 72,704 ----a-w c:\windows\system32\njdguxcj.dll
2008-12-18 23:24 129,024 ----a-w c:\windows\system32\injjbe.dll
2008-12-18 23:24 129,024 ----a-w c:\windows\system32\eekrqtsh.dll
2008-12-17 23:21 129,024 ----a-w c:\windows\system32\rpzawh.dll
2008-12-17 23:21 129,024 ----a-w c:\windows\system32\ltfyhcqm.dll
2008-12-17 04:39 72,704 ----a-w c:\windows\system32\gjxuogmp.dll
2008-12-17 04:36 129,024 ----a-w c:\windows\system32\filueu.dll
2008-12-17 04:36 129,024 ----a-w c:\windows\system32\brvpajhp.dll
2008-12-16 04:55 --------- d-----w c:\program files\Trend Micro
2008-12-16 03:21 72,704 ----a-w c:\windows\system32\bupchmyf.dll
2008-12-15 05:06 129,024 ----a-w c:\windows\system32\djvdywbc.dll
2008-12-15 02:08 129,024 ----a-w c:\windows\system32\plrspw.dll
2008-12-15 02:08 129,024 ----a-w c:\windows\system32\dwjfkpeu.dll
2008-12-15 01:53 34,816 ------w c:\windows\system32\fccywwtR.dll
2008-12-11 00:33 86,016 ----a-w c:\windows\system32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\system32\dtu100.dll
2008-12-09 02:28 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w c:\windows\system32\dpu11.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-02-10_ 1.59.48.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-11-2009\ERDNT.EXE
+ 2009-02-11 21:27:44 8,470,528 ----a-w c:\windows\ERDNT\AutoBackup\2-11-2009\Users\
00000001\NTUSER.DAT
+ 2009-02-11 21:27:45 274,432 ----a-w c:\windows\ERDNT\AutoBackup\2-11-2009\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2-13-2009\ERDNT.EXE
+ 2009-02-13 05:52:50 8,470,528 ----a-w c:\windows\ERDNT\AutoBackup\2-13-2009\Users\
00000001\NTUSER.DAT
+ 2009-02-13 05:52:51 274,432 ----a-w c:\windows\ERDNT\AutoBackup\2-13-2009\Users\
00000002\UsrClass.dat
+ 2008-10-17 07:08:40 3,593,216 -c----w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:34 124,928 -c----w c:\windows\ie7updates\KB961260-IE7\advpack.dll
+ 2008-10-16 20:38:34 347,136 -c----w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 -c----w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-10-16 20:38:35 133,120 -c----w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-10-16 20:38:35 63,488 -c----w c:\windows\ie7updates\KB961260-IE7\icardie.dll
+ 2008-10-16 13:11:09 70,656 -c----w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-10-16 20:38:35 153,088 -c----w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-10-16 20:38:35 230,400 -c----w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-10-15 07:04:53 161,792 -c----w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-10-16 20:38:35 383,488 -c----w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-10-16 20:38:35 384,512 -c----w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-10-16 20:38:37 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-10-16 20:38:37 267,776 -c----w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-10-16 13:11:09 13,824 -c----w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-10-15 07:06:26 633,632 -c----w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-10-16 20:38:37 27,648 -c----w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-10-16 20:38:37 459,264 -c----w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-10-16 20:38:37 52,224 -c----w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-10-16 20:38:38 477,696 -c----w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-10-16 20:38:38 193,024 -c----w c:\windows\ie7updates\KB961260-IE7\msrating.dll
+ 2008-10-16 20:38:39 671,232 -c----w c:\windows\ie7updates\KB961260-IE7\mstime.dll
+ 2008-10-16 20:38:39 102,912 -c----w c:\windows\ie7updates\KB961260-IE7\occache.dll
+ 2008-10-16 20:38:39 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:39 105,984 -c----w c:\windows\ie7updates\KB961260-IE7\url.dll
+ 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-10-16 20:38:39 233,472 -c----w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-10-16 20:38:40 826,368 -c----w c:\windows\ie7updates\KB961260-IE7\wininet.dll
- 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2008-12-20 23:15:11 124,928 ----a-w c:\windows\system32\advpack.dll
- 2009-02-10 06:00:04 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-10 07:00:14 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-10 06:00:04 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-10 07:00:14 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-10 06:00:08 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009021020090211\index.dat
+ 2009-02-10 07:00:23 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009021020090211\index.dat
- 2009-02-10 06:00:04 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-10 07:00:14 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-10-16 20:38:34 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:11 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
- 2008-10-16 20:38:34 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
- 2008-10-16 20:38:35 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:13 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
- 2008-10-16 20:38:35 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:13 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
- 2008-10-16 13:11:09 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
- 2008-10-16 20:38:35 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
+ 2008-12-19 05:23:56 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
- 2008-10-16 20:38:35 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 -c----w c:\windows\system32\dllcache\ieframe.dll
- 2008-10-16 20:38:37 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:21 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
- 2008-10-16 20:38:37 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
- 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
- 2008-10-15 07:06:26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe
+ 2008-12-19 05:25:25 634,024 -c----w c:\windows\system32\dllcache\iexplore.exe
- 2008-10-16 20:38:37 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
- 2008-10-16 20:38:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
- 2008-10-16 20:38:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-10-17 07:08:40 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 -c----w c:\windows\system32\dllcache\mshtml.dll
- 2008-10-16 20:38:38 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
- 2008-10-16 20:38:38 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:31 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
- 2008-10-16 20:38:39 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
- 2008-10-16 20:38:39 102,912 -c----w c:\windows\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 -c----w c:\windows\system32\dllcache\occache.dll
- 2008-10-16 20:38:39 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
- 2008-08-28 10:04:17 333,056 -c----w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 11:57:21 333,184 -c----w c:\windows\system32\dllcache\srv.sys
- 2008-10-16 20:38:39 105,984 -c----w c:\windows\system32\dllcache\url.dll
+ 2008-12-20 23:15:39 105,984 -c----w c:\windows\system32\dllcache\url.dll
- 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll
- 2008-10-16 20:38:39 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
- 2008-10-16 20:38:40 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:41 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
- 2008-08-28 10:04:17 333,056 ----a-w c:\windows\system32\drivers\srv.sys
+ 2008-12-11 11:57:21 333,184 ----a-w c:\windows\system32\drivers\srv.sys
- 2008-10-16 20:38:34 347,136 ------w c:\windows\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 ------w c:\windows\system32\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 ------w c:\windows\system32\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 ------w c:\windows\system32\dxtrans.dll
- 2008-10-16 20:38:35 133,120 ------w c:\windows\system32\extmgr.dll
+ 2008-12-20 23:15:13 133,120 ------w c:\windows\system32\extmgr.dll
- 2008-10-16 20:38:35 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2008-12-20 23:15:13 63,488 ----a-w c:\windows\system32\icardie.dll
- 2008-10-16 13:11:09 70,656 ------w c:\windows\system32\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 ------w c:\windows\system32\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 ------w c:\windows\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 ------w c:\windows\system32\ieakeng.dll
- 2008-10-16 20:38:35 230,400 ------w c:\windows\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 ------w c:\windows\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 ------w c:\windows\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 ------w c:\windows\system32\ieakui.dll
- 2008-10-16 20:38:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 ------w c:\windows\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 ------w c:\windows\system32\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\system32\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 ----a-w c:\windows\system32\ieframe.dll
- 2008-10-16 20:38:37 44,544 ------w c:\windows\system32\iernonce.dll
+ 2008-12-20 23:15:21 44,544 ------w c:\windows\system32\iernonce.dll
- 2008-10-16 20:38:37 267,776 ----a-w c:\windows\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 ----a-w c:\windows\system32\ieudinit.exe
- 2008-10-16 20:38:37 27,648 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-10-05 03:16:26 235,936 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
- 2008-01-19 08:42:40 74,649 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-02-10 07:25:49 88,590 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-02-03 23:21:12 21,244,864 ----a-w c:\windows\system32\MRT.exe
- 2008-10-16 20:38:37 459,264 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 ----a-w c:\windows\system32\msfeeds.dll
- 2008-10-16 20:38:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
- 2008-10-17 07:08:40 3,593,216 ----a-w c:\windows\system32\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 ----a-w c:\windows\system32\mshtml.dll
- 2008-10-16 20:38:38 477,696 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 ----a-w c:\windows\system32\mshtmled.dll
- 2008-10-16 20:38:38 193,024 ------w c:\windows\system32\msrating.dll
+ 2008-12-20 23:15:31 193,024 ------w c:\windows\system32\msrating.dll
- 2008-10-16 20:38:39 671,232 ------w c:\windows\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 ------w c:\windows\system32\mstime.dll
- 2008-10-16 20:38:39 102,912 ------w c:\windows\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 ------w c:\windows\system32\occache.dll
- 2008-10-16 20:38:39 44,544 ------w c:\windows\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 ------w c:\windows\system32\pngfilt.dll
- 2007-07-27 14:41:40 16,760 ------w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll
- 2008-10-16 20:38:39 105,984 ----a-w c:\windows\system32\url.dll
+ 2008-12-20 23:15:39 105,984 ----a-w c:\windows\system32\url.dll
- 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 ----a-w c:\windows\system32\urlmon.dll
- 2008-10-16 20:38:39 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2009-02-13 05:30:18 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_418.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [2000-07-13 28739]
"Google Update"="c:\documents and settings\Don\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-06 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-12-12 71328]
"NAV CfgWiz"="c:\program files\Common Files\Symantec Shared\CfgWiz.exe" [2003-08-15 124096]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2006-06-06 202032]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2006-05-28 100056]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-31 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-03 185896]
c:\documents and settings\Don\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinCinema Manager.lnk - c:\program files\Sandisk\Common\Bin\WinCinemaMgr.exe [2007-11-25 303104]
Google Updater.lnk.disabled [2007-08-13 920]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSMPSVC]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Aim6"="c:\program files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"SoundMan"=SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 MPSHLPR;MPSHLPR;c:\windows\system32\drivers\mpshlpr.sys [2006-02-09 107008]
R2 MPSDrv;MPSDrv;c:\windows\system32\drivers\mpsdrv.sys [2006-02-09 83200]
R2 mpssvc;Microsoft Protection Service;c:\program files\Microsoft Windows OneCare Live\Firewall\mpssvc.exe [2006-02-09 838888]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-02-26 24652]
S3 PciTest;WinMTA PCI Service;c:\windows\system32\drivers\pcitest.sys [2004-05-10 6912]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f81e8f3-9253-11dd-9353-00038a000015}]
\Shell\AutoRun\command - e:\system\viewer\FlipVideoforPC.exe
\Shell\Flip Video for PC\command - e:\system\viewer\FlipVideoforPC.exe
.
Contents of the 'Scheduled Tasks' folder
2008-09-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-02-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-826549902-1532422000-2314379556-1007.job
- c:\documents and settings\Don\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-06 00:33]
2009-02-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-826549902-1532422000-2314379556-1008.job
- c:\documents and settings\Brittany\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-22 13:25]
2005-03-28 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Cindy.job
- c:\progra~1\NORTON~1\NAVW32.EXE [2003-12-04 17:22]
2009-02-07 c:\windows\Tasks\Norton AntiVirus - Scan my computer.job
- c:\progra~1\NORTON~1\Navw32.exe [2003-12-04 17:22]
2009-02-13 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-06-18 20:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.emachines.com/
uInternet Connection Wizard,ShellNext = hxxp://www.viewpoint.com/landing/v37b.html
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://ll.g.gametap.com/static/cab_headless/GameTapWebUpdater.cab
FF - ProfilePath - c:\documents and settings\Don\Application Data\Mozilla\Firefox\Profiles\g0x035vn.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - component: c:\documents and settings\Don\Application Data\Mozilla\Firefox\Profiles\g0x035vn.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll
FF - component: c:\documents and settings\Don\Application Data\Mozilla\Firefox\Profiles\g0x035vn.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayFormSubmitObserver.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit13113.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstrlnk.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-13 02:08:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-02-13 2:11:51
ComboFix-quarantined-files.txt 2009-02-13 07:11:28
ComboFix2.txt 2009-02-10 07:02:25
Pre-Run: 3,827,396,608 bytes free
Post-Run: 3,805,011,968 bytes free
570 --- E O F --- 2009-02-11 22:03:19
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:14:07 AM, on 2/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\mpssvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Don\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Don\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\Don\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.viewpoint.com/landing/v37b.html
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Don\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: WinCinema Manager.lnk = C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Google Updater.lnk.disabled
O9 - Extra button: Launch PicLens - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\PicLens.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) -
https://www.windowsonecare.com/install/cli/1.0.0971.10/WinSSWebAgent.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} (GameTap Web Updater) -
http://ll.g.gametap.com/static/cab_headless/GameTapWebUpdater.cab
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) -
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8891 bytes