Thanks for the reply Blade.
Here are the logs
First Hijack This
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:26:38 AM, on 3/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
E:\Utils\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.news.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 8498 bytes
And now ComboFix log
ComboFix 09-01-01.02 - Andrew 2009-01-03 9:17:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1634 [GMT 11:00]
Running from: e:\utils\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: ActiveArmor Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\eguhajoh.ini
c:\windows\system32\medidobu.dll
c:\windows\system32\omesirem.ini
c:\windows\system32\ubodidem.ini
.
((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.
2009-01-01 17:54 . 2009-01-01 17:59 <DIR> d-------- c:\documents and settings\Kate\Application Data\Smilebox
2009-01-01 13:45 . 2009-01-01 13:45 49 --a------ c:\windows\NeroDigital.ini
2008-12-31 16:03 . 2008-12-31 16:08 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Image Zone Express
2008-12-31 07:51 . 2008-12-31 08:06 <DIR> d-------- c:\documents and settings\Kate\Application Data\Image Zone Express
2008-12-28 17:15 . 2008-12-28 17:15 <DIR> d-------- C:\VundoFix Backups
2008-12-28 17:15 . 2008-12-28 20:46 269 --a------ c:\windows\wininit.ini
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-12-28 16:10 . 2008-12-28 16:44 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-28 16:10 . 2008-12-28 17:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-28 09:07 . 2008-12-28 09:26 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Ventrilo
2008-12-28 09:06 . 2008-12-28 09:06 <DIR> d-------- c:\program files\Ventrilo
2008-12-28 09:06 . 2008-12-28 09:06 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-28 09:06 . 2008-12-28 09:06 262 --a------ c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2008-12-28 09:00 . 2008-12-28 09:00 <DIR> d-------- c:\windows\system32\Lang
2008-12-28 09:00 . 2008-12-28 09:00 940,794 --a------ c:\windows\system32\LoopyMusic.wav
2008-12-28 09:00 . 2008-12-28 09:00 146,650 --a------ c:\windows\system32\BuzzingBee.wav
2008-12-28 08:13 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2008-12-27 20:29 . 2008-12-27 21:18 <DIR> d-------- c:\documents and settings\Andrew\Application Data\FrostWire
2008-12-27 08:12 . 2008-12-27 08:12 0 --ah----- c:\windows\SwSys2.bmp
2008-12-27 08:12 . 2008-12-27 08:12 0 --ah----- c:\windows\SwSys1.bmp
2008-12-26 22:23 . 2008-12-26 22:23 <DIR> d-------- c:\program files\SystemRequirementsLab
2008-12-25 22:14 . 2008-12-25 22:14 <DIR> d-------- c:\documents and settings\Kate\Application Data\muvee Technologies
2008-12-25 22:14 . 2008-12-25 22:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\muvee Technologies
2008-12-25 22:09 . 2008-12-25 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ultima_T15
2008-12-25 22:09 . 2008-12-25 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\EnterNHelp
2008-12-25 22:09 . 2008-12-25 22:14 20 ---h----- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2008-12-25 22:07 . 2008-12-25 22:07 <DIR> d-------- c:\documents and settings\Kate\Application Data\Nikon
2008-12-25 22:07 . 2006-05-26 12:03 4,644,864 -ra------ c:\windows\system32\NkNEFPlugin.dll
2008-12-25 22:07 . 2003-03-19 13:28 2,179,072 --a------ c:\windows\system32\mfc71d.dll
2008-12-25 22:07 . 2002-01-06 06:48 974,848 --a------ c:\windows\system32\mfc70.dll
2008-12-25 22:07 . 2003-03-19 12:04 765,952 --a------ c:\windows\system32\msvcp71d.dll
2008-12-25 22:07 . 2003-03-19 12:03 544,768 --a------ c:\windows\system32\msvcr71d.dll
2008-12-25 22:07 . 2002-01-05 20:40 487,424 --a------ c:\windows\system32\msvcp70.dll
2008-12-25 22:07 . 2002-01-06 05:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\program files\Nikon
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\program files\Common Files\muvee Technologies
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nikon
2008-12-25 22:06 . 2006-04-28 14:39 495,616 -ra------ c:\windows\system32\DRAGNKL1.dll
2008-12-25 22:06 . 2006-04-28 15:05 180,224 -ra------ c:\windows\system32\Strato4.dll
2008-12-25 22:06 . 2006-04-28 15:04 180,224 -ra------ c:\windows\system32\picn1120.dll
2008-12-25 22:06 . 2006-04-28 15:04 155,648 -ra------ c:\windows\system32\picn1020.dll
2008-12-25 22:06 . 2006-04-28 15:08 110,592 -ra------ c:\windows\system32\RCSigProc.dll
2008-12-25 22:06 . 2006-04-28 15:08 76,800 -ra------ c:\windows\system32\RedEye.dll
2008-12-25 22:05 . 2008-12-25 22:05 <DIR> d-------- c:\program files\ArcSoft
2008-12-25 22:05 . 1995-08-01 04:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2008-12-25 22:04 . 2008-12-25 22:07 <DIR> d-------- c:\program files\Common Files\Nikon
2008-12-20 14:35 . 2005-02-28 20:10 205,824 --a------ c:\windows\pw32a.dll
2008-12-20 08:34 . 2008-12-20 08:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2008-12-17 21:16 . 2008-12-17 21:16 <DIR> d-------- c:\documents and settings\Kate\Application Data\Apple Computer
2008-12-16 12:59 . 2008-12-20 12:55 <DIR> d-------- c:\documents and settings\Jacob\Application Data\AVGTOOLBAR
2008-12-15 21:32 . 2008-12-15 21:32 <DIR> d-------- c:\documents and settings\Jacob\Application Data\HP
2008-12-15 21:31 . 2008-12-15 21:31 <DIR> d-------- c:\documents and settings\Jacob
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam\Application Data\HP
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam\Application Data\AVGTOOLBAR
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam
2008-12-15 21:30 . 2008-04-14 23:00 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-15 18:51 . 2008-12-15 18:51 <DIR> d-------- c:\documents and settings\Andrew\Application Data\CyberLink
2008-12-15 18:40 . 2008-12-15 18:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Cyberlink
2008-12-15 18:40 . 2006-06-04 15:48 198,144 --------- c:\windows\system32\_psisdecd.dll
2008-12-15 18:39 . 2008-12-15 18:39 <DIR> d-------- c:\program files\CyberLink
2008-12-15 18:39 . 2006-06-04 15:48 44,544 --a------ c:\windows\system32\msxml4a.dll
2008-12-14 16:20 . 2008-12-14 16:20 <DIR> d-------- c:\program files\Bagpipe Player
2008-12-14 16:20 . 1998-12-23 20:23 6,112 --a------ c:\windows\system32\drivers\genport2.sys
2008-12-14 16:20 . 1998-12-23 19:20 6,112 --a------ c:\windows\system32\drivers\genport.sys
2008-12-14 16:20 . 2008-12-14 16:20 0 --a------ c:\windows\PROTOCOL.INI
2008-12-14 16:19 . 2008-12-14 16:19 <DIR> d-------- c:\documents and settings\Andrew\WINDOWS
2008-12-14 16:19 . 1999-03-23 09:12 299,520 --a------ c:\windows\uninst.exe
2008-12-14 16:12 . 2008-12-14 16:12 98,304 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-14 15:55 . 2008-12-14 15:55 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2008-12-14 09:26 . 2008-12-14 09:26 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-14 09:26 . 2008-12-14 09:26 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-14 09:20 . 2008-12-14 09:20 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Leadertech
2008-12-14 09:13 . 2008-12-22 08:14 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools Pro
2008-12-14 09:13 . 2008-12-14 09:13 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools
2008-12-14 09:12 . 2008-12-23 19:42 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2008-12-14 09:12 . 2008-12-14 09:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2008-12-14 09:11 . 2008-12-14 09:12 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-12-14 09:08 . 2008-12-14 09:15 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools Lite
2008-12-14 09:08 . 2008-12-14 09:08 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-12-14 09:00 . 2008-12-14 09:26 <DIR> d-------- c:\program files\Java
2008-12-14 09:00 . 2008-12-14 09:00 <DIR> d-------- c:\program files\Common Files\Java
2008-12-14 08:59 . 2008-12-14 08:59 <DIR> d-------- c:\program files\MSXML 4.0
2008-12-13 21:50 . 2008-12-31 07:47 <DIR> d-------- c:\documents and settings\Kate\Application Data\HP
2008-12-13 21:50 . 2008-12-26 16:51 <DIR> d-------- c:\documents and settings\Kate\Application Data\AVGTOOLBAR
2008-12-13 21:40 . 2008-12-13 21:45 <DIR> d-------- c:\documents and settings\Andrew\Application Data\HP
2008-12-13 18:10 . 2008-12-13 18:10 <DIR> d--hs---- c:\documents and settings\Andrew\UserData
2008-12-13 15:28 . 2008-12-16 20:10 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Apple Computer
2008-12-13 14:52 . 2008-12-13 22:30 <DIR> d-------- c:\documents and settings\Andrew\Application Data\AVGTOOLBAR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 22:12 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-29 06:07 --------- d-----w c:\program files\Ahead
2008-12-29 06:05 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-25 11:06 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-15 07:39 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-13 10:46 --------- d-----w c:\program files\Fellowes
2008-12-13 10:46 --------- d-----w c:\documents and settings\All Users\Application Data\Fellowes
2008-12-13 10:39 --------- d-----w c:\program files\HP
2008-12-13 10:39 --------- d-----w c:\program files\Common Files\HP
2008-12-13 10:39 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-12-13 10:38 --------- d-----w c:\program files\Hewlett-Packard
2008-12-13 10:37 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2008-12-13 07:45 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-13 04:37 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2008-12-13 04:36 --------- d-----w c:\program files\Essentials Codec Pack
2008-12-13 04:32 --------- d-----w c:\program files\Common Files\Ahead
2008-12-13 04:28 --------- d-----w c:\program files\QuickTime
2008-12-13 04:28 --------- d-----w c:\program files\iTunes
2008-12-13 04:28 --------- d-----w c:\program files\iPod
2008-12-13 04:28 --------- d-----w c:\program files\Bonjour
2008-12-13 04:28 --------- d-----w c:\program files\Apple Software Update
2008-12-13 04:28 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-13 04:27 --------- d-----w c:\program files\Common Files\Apple
2008-12-13 04:27 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-12-13 04:23 --------- d-----w c:\program files\Common Files\Adobe
2008-12-13 04:10 --------- d-----w c:\program files\Windows Media Connect 2
2008-12-13 03:52 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-12-13 03:52 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys
2008-12-13 03:52 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-12-13 03:52 --------- d-----w c:\program files\AVG
2008-12-13 03:47 --------- d-----w c:\program files\Realtek Sound Manager
2008-12-13 03:47 --------- d-----w c:\program files\AvRack
2008-12-13 03:46 --------- d-----w c:\program files\Realtek AC97
2008-12-13 03:46 --------- d-----w c:\program files\NVIDIA Corporation
2008-12-13 02:53 --------- d-----w c:\program files\microsoft frontpage
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 03:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 03:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 03:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 03:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 03:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 03:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 03:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 03:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-09-30 270336]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-24 5537792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-02-24 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-14 1261336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\update.exe" [2007-04-09 303104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"MediaFace Integration"="c:\program files\Fellowes\MediaFACE 4.0\SetHook.exe" [2004-07-01 53248]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-14 136600]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2008-04-03 151552]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2005-02-24 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-12-25 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Games\\THQ\\Pandemic Studios\\Full Spectrum Warrior\\Launcher.locked"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-13 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-13 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-13 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-13 76040]
R2 GenPort;GenPort;c:\windows\system32\drivers\GenPort.sys [2008-12-14 6112]
R2 GenPort2;GenPort2;c:\windows\system32\drivers\GenPort2.sys [2008-12-14 6112]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{284db057-c917-11dd-b930-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{75db271f-8fd9-404d-b492-9cb7b90c031f} - c:\windows\system32\podoposi.dll
HKLM-Run-duwukuzeko - c:\windows\system32\zodewujo.dll
HKLM-Run-CPMb773a633 - c:\windows\system32\guzapamu.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.news.com.au/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyOverride = *.local
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab
c:\windows\Downloaded Program Files\sysreqlab.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-03 09:21:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(780)
c:\windows\system32\nvappfilter.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\rundll32.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\nvsvc32.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-01-03 9:23:54 - machine was rebooted [Andrew]
ComboFix-quarantined-files.txt 2009-01-02 22:23:51
Pre-Run: 44,075,245,568 bytes free
Post-Run: 44,929,490,944 bytes free
280 --- E O F --- 2008-12-17 23:27:37
Hi again.
Ive done what you asked and run the scanes as well. Kaspersky said I ahd no infections and the scan log was empty and not able to be saved. Ive had to split the post as the text of the scans exceeds the post character limit.
Here is the Combo fix scan
ComboFix 09-01-01.02 - Andrew 2009-01-03 21:09:10.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1554 [GMT 11:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: ActiveArmor Firewall *enabled*
* Created a new restore point
FILE ::
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Andrew\Application Data\FrostWire
c:\documents and settings\Andrew\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
c:\documents and settings\Andrew\Application Data\FrostWire\checkandupdate.txt
c:\documents and settings\Andrew\Application Data\FrostWire\createtimes.cache
c:\documents and settings\Andrew\Application Data\FrostWire\downloads.dat
c:\documents and settings\Andrew\Application Data\FrostWire\fileurns.bak
c:\documents and settings\Andrew\Application Data\FrostWire\fileurns.cache
c:\documents and settings\Andrew\Application Data\FrostWire\filters.props
c:\documents and settings\Andrew\Application Data\FrostWire\frostwire.props
c:\documents and settings\Andrew\Application Data\FrostWire\gnutella.net
c:\documents and settings\Andrew\Application Data\FrostWire\installation.props
c:\documents and settings\Andrew\Application Data\FrostWire\intent.props
c:\documents and settings\Andrew\Application Data\FrostWire\library.dat
c:\documents and settings\Andrew\Application Data\FrostWire\mojito.props
c:\documents and settings\Andrew\Application Data\FrostWire\questions.props
c:\documents and settings\Andrew\Application Data\FrostWire\responses.cache
c:\documents and settings\Andrew\Application Data\FrostWire\simpp.xml
c:\documents and settings\Andrew\Application Data\FrostWire\spam.dat
c:\documents and settings\Andrew\Application Data\FrostWire\tables.props
c:\documents and settings\Andrew\Application Data\FrostWire\themes\frostwirePro_theme.fwtp
c:\documents and settings\Andrew\Application Data\FrostWire\themes\frostwirePro_theme\theme.txt
c:\documents and settings\Andrew\Application Data\FrostWire\themes\frostwirePro_theme\version.txt
c:\documents and settings\Andrew\Application Data\FrostWire\ttrees.cache
c:\documents and settings\Andrew\Application Data\FrostWire\ttroot.cache
c:\documents and settings\Andrew\Application Data\FrostWire\version.xml
c:\documents and settings\Andrew\Application Data\FrostWire\xml\data\audio.sxml2
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
.
((((((((((((((((((((((((( Files Created from 2008-12-03 to 2009-01-03 )))))))))))))))))))))))))))))))
.
2009-01-03 21:07 . 2009-01-03 09:10 2,888,937 -ra------ C:\ComboFix.exe
2009-01-03 21:05 . 2009-01-03 21:05 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-01-03 21:04 . 2009-01-03 21:04 <DIR> d-------- c:\program files\Common Files\Adobe
2009-01-03 19:43 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-01-03 19:43 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-01-03 19:43 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-01-03 15:33 . 2009-01-03 15:33 <DIR> d-------- c:\windows\system32\GroupPolicy
2009-01-03 15:33 . 2009-01-03 15:33 <DIR> d-------- c:\program files\Windows Desktop Search
2009-01-03 15:33 . 2009-01-03 15:33 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Windows Desktop Search
2009-01-03 14:13 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2009-01-03 14:12 . 2009-01-03 14:12 <DIR> d-------- c:\program files\MSBuild
2009-01-03 14:12 . 2009-01-03 14:12 <DIR> d-------- c:\program files\Microsoft Works
2009-01-03 14:11 . 2009-01-03 14:11 <DIR> d-------- c:\program files\Microsoft.NET
2009-01-03 14:10 . 2009-01-03 14:10 <DIR> d-------- c:\program files\Microsoft Visual Studio 8
2009-01-03 14:09 . 2009-01-03 14:12 <DIR> d-------- c:\windows\SHELLNEW
2009-01-03 14:09 . 2009-01-03 14:09 <DIR> dr-h----- C:\MSOCache
2009-01-03 14:09 . 2009-01-03 14:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-03 13:25 . 2009-01-03 13:25 <DIR> d-------- c:\windows\Logs
2009-01-03 13:25 . 2009-01-03 13:25 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Turbine
2009-01-03 13:25 . 2007-03-12 16:42 3,495,784 --a------ c:\windows\system32\d3dx9_33.dll
2009-01-03 10:10 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2009-01-03 10:09 . 2009-01-03 10:09 <DIR> d-------- c:\windows\system32\URTTEMP
2009-01-01 17:54 . 2009-01-01 17:59 <DIR> d-------- c:\documents and settings\Kate\Application Data\Smilebox
2009-01-01 13:45 . 2009-01-03 19:14 49 --a------ c:\windows\NeroDigital.ini
2008-12-31 16:03 . 2008-12-31 16:08 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Image Zone Express
2008-12-31 07:51 . 2008-12-31 08:06 <DIR> d-------- c:\documents and settings\Kate\Application Data\Image Zone Express
2008-12-28 17:15 . 2008-12-28 17:15 <DIR> d-------- C:\VundoFix Backups
2008-12-28 17:15 . 2008-12-28 20:46 269 --a------ c:\windows\wininit.ini
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-12-28 16:10 . 2008-12-28 16:44 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-28 16:10 . 2008-12-28 17:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-28 09:07 . 2008-12-28 09:26 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Ventrilo
2008-12-28 09:06 . 2008-12-28 09:06 <DIR> d-------- c:\program files\Ventrilo
2008-12-28 09:06 . 2008-12-28 09:06 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-28 09:06 . 2008-12-28 09:06 262 --a------ c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2008-12-28 09:00 . 2008-12-28 09:00 <DIR> d-------- c:\windows\system32\Lang
2008-12-28 09:00 . 2008-12-28 09:00 940,794 --a------ c:\windows\system32\LoopyMusic.wav
2008-12-28 09:00 . 2008-12-28 09:00 146,650 --a------ c:\windows\system32\BuzzingBee.wav
2008-12-28 08:13 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2008-12-26 22:23 . 2008-12-26 22:23 <DIR> d-------- c:\program files\SystemRequirementsLab
2008-12-25 22:14 . 2008-12-25 22:14 <DIR> d-------- c:\documents and settings\Kate\Application Data\muvee Technologies
2008-12-25 22:14 . 2008-12-25 22:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\muvee Technologies
2008-12-25 22:09 . 2008-12-25 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ultima_T15
2008-12-25 22:09 . 2008-12-25 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\EnterNHelp
2008-12-25 22:09 . 2008-12-25 22:14 20 ---h----- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2008-12-25 22:07 . 2008-12-25 22:07 <DIR> d-------- c:\documents and settings\Kate\Application Data\Nikon
2008-12-25 22:07 . 2006-05-26 12:03 4,644,864 -ra------ c:\windows\system32\NkNEFPlugin.dll
2008-12-25 22:07 . 2003-03-19 13:28 2,179,072 --a------ c:\windows\system32\mfc71d.dll
2008-12-25 22:07 . 2002-01-06 06:48 974,848 --a------ c:\windows\system32\mfc70.dll
2008-12-25 22:07 . 2003-03-19 12:04 765,952 --a------ c:\windows\system32\msvcp71d.dll
2008-12-25 22:07 . 2003-03-19 12:03 544,768 --a------ c:\windows\system32\msvcr71d.dll
2008-12-25 22:07 . 2002-01-05 20:40 487,424 --a------ c:\windows\system32\msvcp70.dll
2008-12-25 22:07 . 2002-01-06 05:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\program files\Nikon
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\program files\Common Files\muvee Technologies
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nikon
2008-12-25 22:06 . 2006-04-28 14:39 495,616 -ra------ c:\windows\system32\DRAGNKL1.dll
2008-12-25 22:06 . 2006-04-28 15:05 180,224 -ra------ c:\windows\system32\Strato4.dll
2008-12-25 22:06 . 2006-04-28 15:04 180,224 -ra------ c:\windows\system32\picn1120.dll
2008-12-25 22:06 . 2006-04-28 15:04 155,648 -ra------ c:\windows\system32\picn1020.dll
2008-12-25 22:06 . 2006-04-28 15:08 110,592 -ra------ c:\windows\system32\RCSigProc.dll
2008-12-25 22:06 . 2006-04-28 15:08 76,800 -ra------ c:\windows\system32\RedEye.dll
2008-12-25 22:05 . 2008-12-25 22:05 <DIR> d-------- c:\program files\ArcSoft
2008-12-25 22:05 . 1995-08-01 04:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2008-12-25 22:04 . 2008-12-25 22:07 <DIR> d-------- c:\program files\Common Files\Nikon
2008-12-20 14:35 . 2005-02-28 20:10 205,824 --a------ c:\windows\pw32a.dll
2008-12-20 08:34 . 2008-12-20 08:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2008-12-17 21:16 . 2008-12-17 21:16 <DIR> d-------- c:\documents and settings\Kate\Application Data\Apple Computer
2008-12-16 12:59 . 2008-12-20 12:55 <DIR> d-------- c:\documents and settings\Jacob\Application Data\AVGTOOLBAR
2008-12-15 21:32 . 2008-12-15 21:32 <DIR> d-------- c:\documents and settings\Jacob\Application Data\HP
2008-12-15 21:31 . 2008-12-15 21:31 <DIR> d-------- c:\documents and settings\Jacob
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam\Application Data\HP
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam\Application Data\AVGTOOLBAR
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam
2008-12-15 21:30 . 2008-04-14 23:00 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-15 18:51 . 2008-12-15 18:51 <DIR> d-------- c:\documents and settings\Andrew\Application Data\CyberLink
2008-12-15 18:40 . 2008-12-15 18:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Cyberlink
2008-12-15 18:40 . 2006-06-04 15:48 198,144 --------- c:\windows\system32\_psisdecd.dll
2008-12-15 18:39 . 2008-12-15 18:39 <DIR> d-------- c:\program files\CyberLink
2008-12-15 18:39 . 2006-06-04 15:48 44,544 --a------ c:\windows\system32\msxml4a.dll
2008-12-14 16:20 . 2008-12-14 16:20 <DIR> d-------- c:\program files\Bagpipe Player
2008-12-14 16:20 . 1998-12-23 20:23 6,112 --a------ c:\windows\system32\drivers\genport2.sys
2008-12-14 16:20 . 1998-12-23 19:20 6,112 --a------ c:\windows\system32\drivers\genport.sys
2008-12-14 16:20 . 2008-12-14 16:20 0 --a------ c:\windows\PROTOCOL.INI
2008-12-14 16:19 . 2008-12-14 16:19 <DIR> d-------- c:\documents and settings\Andrew\WINDOWS
2008-12-14 16:19 . 1999-03-23 09:12 299,520 --a------ c:\windows\uninst.exe
2008-12-14 16:12 . 2008-12-14 16:12 98,304 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-14 15:55 . 2008-12-14 15:55 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2008-12-14 09:26 . 2008-12-14 09:26 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-14 09:26 . 2008-12-14 09:26 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-14 09:20 . 2008-12-14 09:20 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Leadertech
2008-12-14 09:13 . 2008-12-22 08:14 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools Pro
2008-12-14 09:13 . 2008-12-14 09:13 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools
2008-12-14 09:12 . 2008-12-23 19:42 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2008-12-14 09:12 . 2008-12-14 09:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2008-12-14 09:11 . 2008-12-14 09:12 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-12-14 09:08 . 2008-12-14 09:15 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools Lite
2008-12-14 09:08 . 2008-12-14 09:08 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-12-14 09:00 . 2008-12-14 09:26 <DIR> d-------- c:\program files\Java
2008-12-14 09:00 . 2008-12-14 09:00 <DIR> d-------- c:\program files\Common Files\Java
2008-12-14 08:59 . 2008-12-14 08:59 <DIR> d-------- c:\program files\MSXML 4.0
2008-12-13 21:50 . 2008-12-31 07:47 <DIR> d-------- c:\documents and settings\Kate\Application Data\HP
2008-12-13 21:50 . 2008-12-26 16:51 <DIR> d-------- c:\documents and settings\Kate\Application Data\AVGTOOLBAR
2008-12-13 21:40 . 2008-12-13 21:45 <DIR> d-------- c:\documents and settings\Andrew\Application Data\HP
2008-12-13 18:10 . 2008-12-13 18:10 <DIR> d--hs---- c:\documents and settings\Andrew\UserData
2008-12-13 15:28 . 2008-12-16 20:10 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Apple Computer
2008-12-13 14:52 . 2008-12-13 22:30 <DIR> d-------- c:\documents and settings\Andrew\Application Data\AVGTOOLBAR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 22:12 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-29 06:07 --------- d-----w c:\program files\Ahead
2008-12-29 06:05 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-25 11:06 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-15 07:39 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-13 10:46 --------- d-----w c:\program files\Fellowes
2008-12-13 10:46 --------- d-----w c:\documents and settings\All Users\Application Data\Fellowes
2008-12-13 10:39 --------- d-----w c:\program files\HP
2008-12-13 10:39 --------- d-----w c:\program files\Common Files\HP
2008-12-13 10:39 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-12-13 10:38 --------- d-----w c:\program files\Hewlett-Packard
2008-12-13 10:37 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2008-12-13 07:45 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-13 04:37 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2008-12-13 04:36 --------- d-----w c:\program files\Essentials Codec Pack
2008-12-13 04:32 --------- d-----w c:\program files\Common Files\Ahead
2008-12-13 04:28 --------- d-----w c:\program files\QuickTime
2008-12-13 04:28 --------- d-----w c:\program files\iTunes
2008-12-13 04:28 --------- d-----w c:\program files\iPod
2008-12-13 04:28 --------- d-----w c:\program files\Bonjour
2008-12-13 04:28 --------- d-----w c:\program files\Apple Software Update
2008-12-13 04:28 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-13 04:27 --------- d-----w c:\program files\Common Files\Apple
2008-12-13 04:27 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-12-13 04:10 --------- d-----w c:\program files\Windows Media Connect 2
2008-12-13 03:52 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-12-13 03:52 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys
2008-12-13 03:52 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-12-13 03:52 --------- d-----w c:\program files\AVG
2008-12-13 03:47 --------- d-----w c:\program files\Realtek Sound Manager
2008-12-13 03:47 --------- d-----w c:\program files\AvRack
2008-12-13 03:46 --------- d-----w c:\program files\Realtek AC97
2008-12-13 03:46 --------- d-----w c:\program files\NVIDIA Corporation
2008-12-13 02:53 --------- d-----w c:\program files\microsoft frontpage
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 03:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 03:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 03:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 03:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 03:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 03:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 03:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 03:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-03_ 9.23.10.67 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-02 23:09:22 7,680 ----a-w c:\windows\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2009-01-03 03:12:40 110,592 ----a-w c:\windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2009-01-02 23:09:20 12,288 ----a-w c:\windows\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2009-01-02 23:09:23 33,792 ----a-w c:\windows\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2009-01-03 03:12:40 65,536 ----a-w c:\windows\assembly\GAC\dao\10.0.4504.0__31bf3856ad364e35\DAO.DLL
+ 2009-01-03 03:12:41 4,608 ----a-w c:\windows\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\extensibility.dll
+ 2009-01-03 03:12:39 1,215,328 ----a-w c:\windows\assembly\GAC\IACore\1.7.6223.0__31bf3856ad364e35\IACore.dll
+ 2009-01-03 03:12:39 82,784 ----a-w c:\windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
+ 2009-01-02 23:10:30 8,192 ----a-w c:\windows\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-01-02 23:10:31 32,768 ----a-w c:\windows\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
+ 2009-01-02 23:09:24 4,608 ----a-w c:\windows\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2009-01-03 03:12:37 31,560 ----a-w c:\windows\assembly\GAC\ipdmctrl\11.0.0.0__71e9bce111e9429c\IPDMCTRL.DLL
+ 2009-01-02 23:09:24 26,112 ----a-w c:\windows\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2009-01-02 23:10:51 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-01-02 23:10:51 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-01-02 23:10:52 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-01-02 23:10:48 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:49 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:50 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:50 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:50 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:50 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:51 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:52 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:52 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-01-02 23:10:52 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-01-02 23:10:52 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-01-02 23:10:52 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-01-02 23:10:51 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-01-02 23:10:34 720,896 ----a-w c:\windows\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-01-03 03:12:40 8,007,680 ----a-w c:\windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
+ 2009-01-03 03:12:37 16,712 ----a-w c:\windows\assembly\GAC\Microsoft.Office.InfoPath.Permission\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Permission.dll
+ 2009-01-03 03:11:56 80,696 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Access.Dao\12.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll
+ 2009-01-03 03:12:19 1,612,592 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Access.dll
+ 2009-01-03 03:12:19 1,276,720 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2009-01-03 03:12:19 150,320 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2009-01-03 03:12:37 404,296 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath.SemiTrust\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.SemiTrust.dll
+ 2009-01-03 03:12:20 88,896 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-01-03 03:12:20 146,232 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll
+ 2009-01-03 03:12:32 17,208 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll
+ 2009-01-03 03:12:20 920,376 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
+ 2009-01-03 03:12:20 35,648 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2009-01-03 03:12:20 248,632 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2009-01-03 03:12:20 232,248 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Publisher.dll
+ 2009-01-03 03:12:19 20,280 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-01-03 03:12:20 781,104 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-01-03 03:12:40 13,312 ----a-w c:\windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll
+ 2009-01-03 03:12:19 371,496 ----a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
+ 2009-01-03 03:12:20 64,288 ----a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-01-02 23:09:20 28,672 ----a-w c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-01-02 23:10:31 299,008 ----a-w c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-01-02 23:09:20 6,144 ----a-w c:\windows\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2009-01-02 23:09:20 11,264 ----a-w c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2009-01-02 23:09:20 32,768 ----a-w c:\windows\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2009-01-02 23:09:20 6,656 ----a-w c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2009-01-03 03:12:40 229,376 ----a-w c:\windows\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
+ 2009-01-02 23:09:24 1,564,672 ----a-w c:\windows\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
+ 2009-01-03 03:12:40 4,096 ----a-w c:\windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2009-01-03 03:12:19 416,544 ----a-w c:\windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-01-03 03:11:55 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.dll
+ 2009-01-03 03:11:56 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2009-01-03 03:12:24 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2009-01-03 03:12:37 12,616 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-01-03 03:12:37 12,616 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll
+ 2009-01-03 03:12:33 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
+ 2009-01-03 03:12:32 12,632 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2009-01-03 03:12:33 12,112 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2009-01-03 03:12:35 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.dll
+ 2009-01-03 03:12:29 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2009-01-03 03:12:36 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2009-01-03 03:12:29 12,080 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2009-01-03 03:12:29 11,544 ----a-w c:\windows\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
+ 2009-01-02 23:10:33 32,768 ----a-w c:\windows\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
+ 2009-01-03 03:12:40 16,384 ----a-w c:\windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2009-01-02 23:09:25 77,824 ----a-w c:\windows\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2009-01-02 23:10:32 303,104 ----a-w c:\windows\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-01-02 23:10:33 1,294,336 ----a-w c:\windows\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
+ 2009-01-02 23:10:30 1,703,936 ----a-w c:\windows\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-01-02 23:10:34 90,112 ----a-w c:\windows\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-01-02 23:09:25 65,536 ----a-w c:\windows\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2009-01-02 23:10:32 466,944 ----a-w c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2009-01-02 23:10:31 241,664 ----a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2009-01-02 23:10:31 66,560 ----a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2009-01-02 23:10:33 372,736 ----a-w c:\windows\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-01-02 23:10:34 241,664 ----a-w c:\windows\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-01-02 23:10:32 323,584 ----a-w c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-01-02 23:10:31 131,072 ----a-w c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-01-02 23:10:32 77,824 ----a-w c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-01-02 23:10:33 126,976 ----a-w c:\windows\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-01-02 23:10:30 819,200 ----a-w c:\windows\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2009-01-02 23:10:31 57,344 ----a-w c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-01-02 23:10:31 573,440 ----a-w c:\windows\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-01-02 23:10:34 1,257,472 ----a-w c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-01-02 23:10:31 2,052,096 ----a-w c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-01-02 23:10:33 1,339,392 ----a-w c:\windows\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.XML.dll
+ 2009-01-02 23:10:35 1,224,704 ----a-w c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2009-01-03 03:12:37 118,112 ----a-w c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2009-01-03 03:12:43 367,400 ----a-w c:\windows\assembly\GAC_32\Microsoft.VisualStudio.Tools.Applications.InteropAdapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll
+ 2009-01-03 03:12:37 609,104 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2009-01-03 03:12:37 43,840 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.FormControl\12.0.0.0__71e9bce111e9429c\microsoft.office.infopath.formcontrol.dll
+ 2009-01-03 03:12:37 39,728 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Vsta\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Vsta.dll
+ 2009-01-03 03:12:37 60,200 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.dll
+ 2009-01-03 03:12:39 211,736 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.dll
+ 2009-01-03 03:12:39 105,248 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll
+ 2009-01-03 03:12:39 330,520 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Blueprints\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll
+ 2009-01-03 03:12:39 39,712 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll
+ 2009-01-03 03:12:39 39,704 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.dll
+ 2009-01-03 03:12:39 72,472 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.DesignTime\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll
+ 2009-01-03 03:12:39 47,832 ----a-w c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2009-01-03 03:12:39 39,624 ----a-w c:\windows\assembly\GAC_MSIL\System.AddIn\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.dll
+ 2009-01-02 23:10:44 61,440 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_f8d253ab\CustomMarshalers.dll
+ 2009-01-02 23:11:02 3,379,200 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_596e4449\mscorlib.dll
+ 2009-01-02 23:10:58 1,466,368 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_4503235e\System.Design.dll
+ 2009-01-02 23:10:46 90,112 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_3dbb04d0\System.Drawing.Design.dll
+ 2009-01-02 23:10:59 835,584 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_783b79a7\System.Drawing.dll
+ 2009-01-02 23:10:53 3,014,656 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_9404abe4\System.Windows.Forms.dll
+ 2009-01-02 23:10:56 2,088,960 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_6cfe2999\System.Xml.dll
+ 2009-01-02 23:10:43 1,953,792 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_7a56fb16\System.dll
+ 2009-01-03 03:09:38 217,864 ----a-r c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-01-03 03:13:50 1,165,584 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-01-03 03:13:50 20,240 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-01-03 03:13:50 159,504 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-01-03 03:13:50 184,080 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-01-03 03:13:50 217,864 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-01-03 03:13:50 18,704 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-01-03 03:13:50 35,088 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-01-03 03:13:50 845,584 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-01-03 03:13:50 922,384 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-01-03 03:13:50 272,648 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-01-03 03:13:50 888,080 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-01-03 03:13:50 1,172,240 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2007-12-12 04:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
+ 2005-03-18 05:23:10 53,248 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2005-03-18 05:23:10 12,800 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2005-03-18 05:23:14 473,600 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2004-09-29 01:38:58 2,676,224 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 05:23:10 145,920 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2005-03-18 05:23:10 159,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2005-03-18 05:23:14 364,544 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2005-03-18 05:23:12 178,176 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2005-03-18 05:23:14 223,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2004-12-01 04:53:06 2,846,720 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-05 08:32:54 563,712 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 06:23:14 567,296 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-05-26 04:15:56 576,000 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 06:21:34 577,024 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-09-28 03:11:52 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 06:20:50 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2003-02-20 15:59:44 16,896 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
+ 2003-02-20 16:55:06 94,208 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
+ 2003-02-20 16:02:16 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
+ 2003-02-20 18:04:20 155,648 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-20 20:24:08 7,680 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
+ 2003-02-20 18:00:36 98,304 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\alink.dll
+ 2003-02-20 08:19:42 24,576 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2004-07-14 14:49:16 258,048 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-20 08:19:22 40,960 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
+ 2004-07-14 14:49:18 20,480 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2004-07-14 14:49:26 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2004-07-14 14:49:22 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2002-07-29 00:11:50 219,136 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2003-02-20 20:24:10 94,208 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
+ 2003-02-20 20:24:32 49,152 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
+ 2004-07-14 13:32:22 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2004-07-15 00:23:28 49,152 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2004-07-15 00:23:44 626,688 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2003-02-20 20:24:34 12,288 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
+ 2003-02-20 20:24:36 33,792 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
+ 2003-02-20 17:12:24 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
+ 2003-02-20 23:21:40 524,288 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2003-02-20 08:16:32 798,720 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2004-07-14 13:24:30 282,624 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-10-08 03:30:14 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\gacutil.exe
+ 2003-02-20 20:24:38 7,680 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
+ 2004-07-15 03:31:00 8,192 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2004-07-15 03:31:04 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2003-02-20 20:24:40 4,608 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
+ 2004-07-14 13:35:30 196,608 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2003-02-20 20:24:42 15,872 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
+ 2003-02-20 08:22:24 40,960 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
+ 2003-02-20 20:24:44 26,112 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
+ 2003-02-20 20:24:52 40,960 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
+ 2004-07-15 03:28:58 720,896 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2004-07-15 03:28:56 299,008 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2003-02-20 20:24:54 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
+ 2003-02-20 20:25:02 6,144 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
+ 2003-02-20 20:24:58 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
+ 2003-02-20 20:25:06 11,264 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2003-02-20 20:25:02 6,656 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
+ 2004-07-15 03:28:50 49,152 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2004-07-15 03:28:50 49,152 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2003-02-20 20:25:06 1,564,672 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
+ 2004-07-14 13:32:44 86,016 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2004-07-14 13:32:46 233,472 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2003-02-20 08:09:14 86,016 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2004-07-14 13:25:06 315,392 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2004-07-14 13:33:04 102,400 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2004-07-15 03:29:02 2,138,112 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-20 07:43:52 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2003-02-20 08:06:34 65,536 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
+ 2004-07-14 13:33:22 143,360 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2004-07-14 13:33:24 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2003-02-20 08:09:18 77,824 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2004-07-14 13:26:52 2,510,848 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2003-02-20 08:09:24 9,216 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
+ 2004-07-14 13:28:34 2,502,656 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2003-02-20 17:42:22 348,160 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2003-02-20 08:18:34 20,480 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
+ 2003-02-20 07:43:36 22,528 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\MUI\0409\mscorsecr.dll
+ 2004-08-10 05:20:00 106,496 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2003-02-20 08:09:46 73,728 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\ngen.exe
+ 2004-07-14 13:34:50 94,208 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2003-02-20 20:25:24 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
+ 2004-07-15 03:28:48 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2003-02-20 20:25:30 12,288 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
+ 2003-02-20 08:09:34 253,952 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2003-02-20 08:09:34 122,880 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2004-07-14 13:35:04 319,488 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-20 20:26:38 77,824 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
+ 2004-07-15 03:32:00 1,294,336 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2004-07-15 03:31:14 303,104 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2004-07-15 03:29:02 1,703,936 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2004-07-15 03:28:54 90,112 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2004-07-15 03:31:16 1,224,704 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2003-02-20 20:26:48 65,536 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
+ 2004-07-15 03:28:58 466,944 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2004-07-15 03:28:56 241,664 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2004-07-14 13:35:12 66,560 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2004-07-15 03:31:58 372,736 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2004-07-15 03:31:12 241,664 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2004-07-15 03:28:58 323,584 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2004-07-15 03:31:54 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2004-07-15 03:28:52 77,824 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2004-07-15 03:28:54 126,976 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2004-07-15 03:29:00 1,257,472 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2004-07-15 03:28:58 819,200 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2004-07-15 03:28:52 57,344 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2004-07-15 03:31:16 573,440 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2004-07-15 03:32:02 2,052,096 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2004-07-15 03:29:00 1,339,392 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2004-06-22 02:51:38 53,248 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
+ 2004-07-15 00:23:20 737,280 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2004-07-14 21:15:14 1,032,192 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2004-07-14 15:11:56 31,744 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2005-02-05 08:45:26 2,222,800 ----a-w c:\windows\system32\d3dx9_24.dll
+ 2005-03-18 06:19:58 2,337,488 ----a-w c:\windows\system32\d3dx9_25.dll
+ 2005-12-05 07:09:18 2,323,664 ----a-w c:\windows\system32\d3dx9_28.dll
- 2008-04-14 12:00:00 29,696 -c--a-w c:\windows\system32\dllcache\mimefilt.dll
+ 2008-03-07 17:02:08 29,696 -c--a-w c:\windows\system32\dllcache\mimefilt.dll
- 2008-04-14 12:00:00 98,304 -c--a-w c:\windows\system32\dllcache\nlhtml.dll
+ 2008-03-07 17:02:08 98,304 -c--a-w c:\windows\system32\dllcache\nlhtml.dll
- 2008-04-14 12:00:00 192,000 -c--a-w c:\windows\system32\dllcache\offfilt.dll
+ 2008-03-07 17:02:08 192,000 -c--a-w c:\windows\system32\dllcache\offfilt.dll
+ 2006-10-26 03:10:08 1,190,688 ----a-w c:\windows\system32\FM20.DLL
+ 2006-10-26 03:10:06 33,088 ----a-w c:\windows\system32\FM20ENU.DLL
- 2008-12-25 11:08:30 106,216 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-03 09:59:51 278,944 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2006-10-26 02:45:04 207,360 ----a-w c:\windows\system32\INKED.DLL
- 2008-04-14 12:00:00 29,696 ----a-w c:\windows\system32\mimefilt.dll
+ 2008-03-07 17:02:08 29,696 ----a-w c:\windows\system32\mimefilt.dll
+ 2008-05-26 11:17:44 34,816 ------w c:\windows\system32\msscb.dll
+ 2008-05-26 11:17:26 60,416 ------w c:\windows\system32\msscntrs.dll
+ 2008-05-26 11:17:38 11,776 ------w c:\windows\system32\msshooks.dll
+ 2008-05-26 11:18:34 231,936 ------w c:\windows\system32\msshsq.dll
+ 2008-05-26 11:17:26 87,552 ------w c:\windows\system32\mssitlb.dll
+ 2008-05-26 11:18:26 350,208 ------w c:\windows\system32\mssph.dll
+ 2008-05-26 11:18:56 203,776 ------w c:\windows\system32\mssphtb.dll
+ 2008-05-26 11:17:28 32,768 ------w c:\windows\system32\mssprxy.dll
+ 2008-05-26 11:21:26 1,418,240 ------w c:\windows\system32\mssrch.dll
+ 2006-07-23 23:50:38 125,744 ----a-w c:\windows\system32\MSSTDFMT.DLL
+ 2008-05-26 11:18:42 44,032 ------w c:\windows\system32\msstrc.dll
+ 2003-02-20 07:43:36 4,096 ----a-w c:\windows\system32\mui\0409\mscoreer.dll
- 2008-04-14 12:00:00 98,304 ----a-w c:\windows\system32\nlhtml.dll
+ 2008-03-07 17:02:08 98,304 ----a-w c:\windows\system32\nlhtml.dll
+ 2008-05-26 11:19:36 273,408 ------w c:\windows\system32\oeph.dll
+ 2008-05-26 11:19:16 11,264 ------w c:\windows\system32\oephRes.dll
- 2008-04-14 12:00:00 192,000 ----a-w c:\windows\system32\offfilt.dll
+ 2008-03-07 17:02:08 192,000 ----a-w c:\windows\system32\offfilt.dll
- 2008-12-26 11:22:46 58,596 ----a-w c:\windows\system32\perfc009.dat
+ 2009-01-03 04:33:17 70,184 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-26 11:22:46 392,296 ----a-w c:\windows\system32\perfh009.dat
+ 2009-01-03 04:33:17 424,572 ----a-w c:\windows\system32\perfh009.dat
+ 2008-05-26 11:18:08 71,680 ------w c:\windows\system32\propdefs.dll
+ 2008-05-26 11:17:48 754,176 ------w c:\windows\system32\propsys.dll
+ 2008-05-26 11:18:32 38,400 ------w c:\windows\system32\rtffilt.dll
+ 2006-07-23 23:50:40 39,728 ----a-w c:\windows\system32\SCP32.DLL
+ 2008-05-26 11:17:56 87,552 ------w c:\windows\system32\searchfilterhost.exe
+ 2008-05-26 11:18:44 439,808 ------w c:\windows\system32\searchindexer.exe
+ 2008-05-26 11:18:18 184,832 ------w c:\windows\system32\searchprotocolhost.exe
+ 2006-10-26 08:56:16 864,080 ----a-w c:\windows\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2006-10-26 08:56:14 67,408 ----a-w c:\windows\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2006-10-26 08:56:16 864,080 ----a-w c:\windows\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2006-10-26 08:56:14 67,408 ----a-w c:\windows\system32\spool\drivers\w32x86\msonpui.dll
+ 2006-10-26 08:56:12 33,104 ----a-w c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
- 2006-09-25 06:58:48 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2007-09-26 23:46:30 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2008-05-26 11:17:30 301,568 ------w c:\windows\system32\srchadmin.dll
+ 2008-05-26 10:59:40 106,605 ------w c:\windows\system32\structuredqueryschema.bin
+ 2008-05-26 10:59:42 18,904 ------w c:\windows\system32\structuredqueryschematrivial.bin
+ 2008-05-26 11:21:08 1,582,592 ------w c:\windows\system32\tquery.dll
+ 2008-05-26 11:19:20 97,792 ------w c:\windows\system32\UncCplExt.dll
+ 2008-05-26 11:19:22 143,872 ------w c:\windows\system32\UncDMS.dll
+ 2008-05-26 11:19:28 108,032 ------w c:\windows\system32\UncNE.dll
+ 2008-05-26 11:19:28 131,072 ------w c:\windows\system32\UncPH.dll
+ 2008-05-26 11:19:26 2,048 ------w c:\windows\system32\UncRes.dll
+ 2003-02-20 18:16:08 49,152 ----a-w c:\windows\system32\URTTEMP\regtlib.exe
+ 2006-07-23 23:50:40 47,920 ----a-w c:\windows\system32\VBAME.DLL
+ 2006-10-26 02:45:04 293,376 ----a-w c:\windows\system32\WISPTIS.EXE
+ 2005-12-05 07:07:30 61,136 ----a-w c:\windows\system32\xinput9_1_0.dll
+ 2008-05-26 11:18:34 56,320 ------w c:\windows\system32\xmlfilter.dll
+ 2009-01-03 10:00:07 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_744.dat
+ 2005-09-22 12:49:12 95,744 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2005-09-22 14:16:02 1,093,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2005-09-22 14:16:06 1,079,808 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-22 14:16:08 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2005-09-22 14:16:10 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2005-09-22 13:58:06 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2005-09-22 13:58:06 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2005-09-22 13:58:06 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2005-09-22 13:58:06 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2005-09-22 13:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2005-09-22 13:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2005-09-22 13:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2005-09-22 13:58:06 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2005-09-22 13:58:06 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2005-09-22 14:35:10 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-09-30 270336]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-24 5537792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-02-24 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-14 1261336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\update.exe" [2007-04-09 303104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"MediaFace Integration"="c:\program files\Fellowes\MediaFACE 4.0\SetHook.exe" [2004-07-01 53248]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-14 136600]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2008-04-03 151552]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2005-02-24 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Andrew\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-12-25 118784]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Games\\THQ\\Pandemic Studios\\Full Spectrum Warrior\\Launcher.locked"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-13 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-13 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-13 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-13 76040]
R2 GenPort;GenPort;c:\windows\system32\drivers\GenPort.sys [2008-12-14 6112]
R2 GenPort2;GenPort2;c:\windows\system32\drivers\GenPort2.sys [2008-12-14 6112]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{284db057-c917-11dd-b930-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.news.com.au/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab
c:\windows\Downloaded Program Files\sysreqlab.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-03 21:10:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(804)
c:\windows\system32\nvappfilter.dll
.
Completion time: 2009-01-03 21:11:08
ComboFix-quarantined-files.txt 2009-01-03 10:11:03
ComboFix2.txt 2009-01-02 22:23:55
Pre-Run: 41,593,163,776 bytes free
Post-Run: 42,452,430,848 bytes free
646 --- E O F --- 2008-12-17 23:27:37
The HJT scan is on the next post