Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 36

Thread: Zlob / SmitFraud - am I clean?

  1. #11
    Junior Member
    Join Date
    Mar 2009
    Posts
    21

    Default TotalVirus resuts part 3

    c:\windows\system32\ntoskrnl.exe

    File ntoskrnl.exe received on 03.07.2009 19:16:51 (CET)Antivirus Version Last Update Result
    a-squared 4.0.0.101 2009.03.07 -
    AhnLab-V3 5.0.0.2 2009.02.27 -
    AntiVir 7.9.0.105 2009.03.07 -
    Authentium 5.1.0.4 2009.03.06 -
    Avast 4.8.1335.0 2009.03.06 -
    AVG 8.0.0.237 2009.03.06 -
    BitDefender 7.2 2009.03.07 -
    CAT-QuickHeal 10.00 2009.03.07 -
    ClamAV 0.94.1 2009.03.06 -
    Comodo 1035 2009.03.07 -
    DrWeb 4.44.0.09170 2009.03.07 -
    eSafe 7.0.17.0 2009.03.05 -
    eTrust-Vet 31.6.6386 2009.03.06 -
    F-Prot 4.4.4.56 2009.03.06 -
    F-Secure 8.0.14470.0 2009.03.07 -
    Fortinet 3.117.0.0 2009.03.07 -
    GData 19 2009.03.07 -
    Ikarus T3.1.1.45.0 2009.03.07 -
    K7AntiVirus 7.10.663 2009.03.07 -
    Kaspersky 7.0.0.125 2009.03.07 -
    McAfee 5546 2009.03.07 -
    McAfee+Artemis 5546 2009.03.07 -
    Microsoft 1.4405 2009.03.07 -
    NOD32 3917 2009.03.07 -
    Norman 6.00.06 2009.03.06 -
    nProtect 2009.1.8.0 2009.03.07 -
    Panda 10.0.0.10 2009.03.07 -
    PCTools 4.4.2.0 2009.03.07 -
    Prevx1 V2 2009.03.07 -
    Rising 21.19.42.00 2009.03.06 -
    SecureWeb-Gateway 6.7.6 2009.03.07 -
    Sophos 4.39.0 2009.03.07 -
    Sunbelt 3.2.1858.2 2009.03.07 -
    Symantec 1.4.4.12 2009.03.07 -
    TheHacker 6.3.2.7.275 2009.03.07 -
    TrendMicro 8.700.0.1004 2009.03.06 -
    ViRobot 2009.3.7.1639 2009.03.07 -
    VirusBuster 4.5.11.0 2009.03.07 -

    Additional information
    File size: 2137600 bytes
    MD5...: e6679c3023b17d8b78946bc5df53fa20
    SHA1..: 503bff92ca22e164a2cefcb1bf53e6674b2d967f
    SHA256: a09e918bdc21c49a0e660743326827529b0e3d775e069737872623252e077378
    SHA512: be11a5f87a45742b3c76b9c0d1b6e740375a56ec723000cc5391c056bbf309f9<BR>40b6289f4d9097af60e53e6f5b8e50e656588588078940e94bf6da7b71dcdbd9
    ssdeep: 24576:9rV8crCAda0Q4En37xt6lOwsUmExj+yiLFWf/shDflFz/r6QFv/qXHEsCH<BR>Egj8vw:luUCwi4MZFW8hDz3JHtrEJrPb10/N<BR>
    PEiD..: -
    TrID..: File type identification<BR>OS/2 Executable (generic) (52.8%)<BR>Win32 Executable Generic (32.0%)<BR>Generic Win/DOS Executable (7.5%)<BR>DOS Executable Generic (7.5%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x1e8927<BR>timedatestamp.....: 0x45e550ef (Wed Feb 28 09:52:47 2007)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 21 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x74f95 0x75000 6.62 ca1b6845f8d9803fdc6046511c3025c6<BR>POOLMI 0x76000 0x12b8 0x1400 6.12 2b163ea6f0abe707d6ba66523b2c1ba6<BR>MISYSPTE 0x78000 0x6f0 0x800 5.83 ee4d7bc8e01b3f920b665ad999b7d271<BR>POOLCODE 0x79000 0x156a 0x1600 6.40 60bd68f876d2312b851f588c416139dc<BR>.data 0x7b000 0x18a88 0x7c00 1.18 582c7a0aac9c1bd4514c1c4e8c4147b6<BR>PAGE 0x94000 0xf7d0c 0xf7e00 6.66 2e51c821b977f15345df0e55e536b192<BR>PAGELK 0x18c000 0xe6f5 0xe800 6.72 8c9875f4f4fd0e4305f26c8ebd02cbc7<BR>PAGEVRFY 0x19b000 0xf1e9 0xf200 6.66 43320f8094dc51fc7f1bed657e647d0c<BR>PAGEWMI 0x1ab000 0x1708 0x1800 6.42 2f003005ee0f33080ce3151aa25331b6<BR>PAGEKD 0x1ad000 0x40ea 0x4200 6.43 45655fe737a1a455c59809b238962a2d<BR>PAGESPEC 0x1b2000 0xc3f 0xe00 5.94 24421124ea9b491a8fc72bd53ae037df<BR>PAGEHDLS 0x1b3000 0x1dd8 0x1e00 6.21 4450513b34d8549247256cb31d8b54fe<BR>.edata 0x1b5000 0xb57d 0xb600 6.03 093cc09e494c30ac767c34e9e279caec<BR>PAGEDATA 0x1c1000 0x1558 0x1600 2.67 5fa614d57be5f13ed621f0f44eb1abe0<BR>PAGEKD 0x1c3000 0xc021 0xc200 0.00 7918c5dffee06af202fa23fa0bacc79f<BR>PAGECONS 0x1d0000 0x18c 0x200 2.24 a999faa59232bc82993afb59cdec99d9<BR>PAGEVRFC 0x1d1000 0x3449 0x3600 5.21 0ed4f2969f2ac90bf1cde4667e047cb9<BR>PAGEVRFD 0x1d5000 0x648 0x800 2.31 337d078159ce0260c9a0be44f8361560<BR>INIT 0x1d6000 0x2e762 0x2e800 6.51 09f489545d24296e7dbb437bb54460d2<BR>.rsrc 0x205000 0x10708 0x10800 5.29 36bfeb6205afdf9a457bc21c979a8dc5<BR>.reloc 0x216000 0xfce8 0xfe00 6.77 e68d8a53447756407526fbf321482646<BR><BR>( 3 imports ) <BR>&gt; BOOTVID.dll: VidInitialize, VidDisplayString, VidSetTextColor, VidSolidColorFill, VidBitBlt, VidBufferToScreenBlt, VidScreenToBufferBlt, VidResetDisplay, VidCleanUp, VidSetScrollRegion<BR>&gt; HAL.dll: KfRaiseIrql, KfLowerIrql, HalInitSystem, HalReportResourceUsage, HalAllProcessorsStarted, HalQueryRealTimeClock, HalAllocateAdapterChannel, KeRaiseIrqlToDpcLevel, KeStallExecutionProcessor, HalTranslateBusAddress, KeQueryPerformanceCounter, HalGetBusDataByOffset, HalSetBusDataByOffset, HalReturnToFirmware, READ_PORT_UCHAR, READ_PORT_USHORT, READ_PORT_ULONG, WRITE_PORT_UCHAR, WRITE_PORT_USHORT, WRITE_PORT_ULONG, HalInitializeProcessor, HalCalibratePerformanceCounter, HalSetRealTimeClock, KeAcquireQueuedSpinLockRaiseToSynch, HalHandleNMI, HalBeginSystemInterrupt, HalEndSystemInterrupt, HalGetInterruptVector, HalSystemVectorDispatchEntry, HalDisableSystemInterrupt, HalEnableSystemInterrupt, KeRaiseIrqlToSynchLevel, KeRaiseIrql, KeLowerIrql, HalClearSoftwareInterrupt, HalRequestIpi, HalStartNextProcessor, KeReleaseSpinLock, KeAcquireSpinLock, ExTryToAcquireFastMutex, KeAcquireSpinLockRaiseToSynch, KeTryToAcquireQueuedSpinLock, KeFlushWriteBuffer, HalReadDmaCounter, IoMapTransfer, IoFreeMapRegisters, IoFreeAdapterChannel, IoFlushAdapterBuffers, HalFreeCommonBuffer, HalAllocateCommonBuffer, HalAllocateCrashDumpRegisters, HalGetAdapter, HalSetTimeIncrement, HalGetEnvironmentVariable, HalSetEnvironmentVariable, KeGetCurrentIrql, HalRequestSoftwareInterrupt, KeAcquireInStackQueuedSpinLock, KeReleaseInStackQueuedSpinLock, ExAcquireFastMutex, ExReleaseFastMutex, KfAcquireSpinLock, KfReleaseSpinLock, KeAcquireQueuedSpinLock, KeAcquireInStackQueuedSpinLockRaiseToSynch, KeReleaseQueuedSpinLock, HalStopProfileInterrupt, HalSetProfileInterval, HalStartProfileInterrupt<BR>&gt; KDCOM.dll: KdSendPacket, KdD0Transition, KdD3Transition, KdReceivePacket, KdDebuggerInitialize0, KdSave, KdDebuggerInitialize1, KdRestore<BR><BR>( 1486 exports ) <BR>CcCanIWrite, CcCopyRead, CcCopyWrite, CcDeferWrite, CcFastCopyRead, CcFastCopyWrite, CcFastMdlReadWait, CcFastReadNotPossible, CcFastReadWait, CcFlushCache, CcGetDirtyPages, CcGetFileObjectFromBcb, CcGetFileObjectFromSectionPtrs, CcGetFlushedValidData, CcGetLsnForFileObject, CcInitializeCacheMap, CcIsThereDirtyData, CcMapData, CcMdlRead, CcMdlReadComplete, CcMdlWriteAbort, CcMdlWriteComplete, CcPinMappedData, CcPinRead, CcPrepareMdlWrite, CcPreparePinWrite, CcPurgeCacheSection, CcRemapBcb, CcRepinBcb, CcScheduleReadAhead, CcSetAdditionalCacheAttributes, CcSetBcbOwnerPointer, CcSetDirtyPageThreshold, CcSetDirtyPinnedData, CcSetFileSizes, CcSetLogHandleForFile, CcSetReadAheadGranularity, CcUninitializeCacheMap, CcUnpinData, CcUnpinDataForThread, CcUnpinRepinnedBcb, CcWaitForCurrentLazyWriterActivity, CcZeroData, CmRegisterCallback, CmUnRegisterCallback, DbgBreakPoint, DbgBreakPointWithStatus, DbgLoadImageSymbols, DbgPrint, DbgPrintEx, DbgPrintReturnControlC, DbgPrompt, DbgQueryDebugFilterState, DbgSetDebugFilterState, ExAcquireFastMutexUnsafe, ExAcquireResourceExclusiveLite, ExAcquireResourceSharedLite, ExAcquireRundownProtection, ExAcquireRundownProtectionEx, ExAcquireSharedStarveExclusive, ExAcquireSharedWaitForExclusive, ExAllocateFromPagedLookasideList, ExAllocatePool, ExAllocatePoolWithQuota, ExAllocatePoolWithQuotaTag, ExAllocatePoolWithTag, ExAllocatePoolWithTagPriority, ExConvertExclusiveToSharedLite, ExCreateCallback, ExDeleteNPagedLookasideList, ExDeletePagedLookasideList, ExDeleteResourceLite, ExDesktopObjectType, ExDisableResourceBoostLite, ExEnumHandleTable, ExEventObjectType, ExExtendZone, ExFreePool, ExFreePoolWithTag, ExFreeToPagedLookasideList, ExGetCurrentProcessorCounts, ExGetCurrentProcessorCpuUsage, ExGetExclusiveWaiterCount, ExGetPreviousMode, ExGetSharedWaiterCount, ExInitializeNPagedLookasideList, ExInitializePagedLookasideList, ExInitializeResourceLite, ExInitializeRundownProtection, ExInitializeZone, ExInterlockedAddLargeInteger, ExInterlockedAddLargeStatistic, ExInterlockedAddUlong, ExInterlockedCompareExchange64, ExInterlockedDecrementLong, ExInterlockedExchangeUlong, ExInterlockedExtendZone, ExInterlockedFlushSList, ExInterlockedIncrementLong, ExInterlockedInsertHeadList, ExInterlockedInsertTailList, ExInterlockedPopEntryList, ExInterlockedPopEntrySList, ExInterlockedPushEntryList, ExInterlockedPushEntrySList, ExInterlockedRemoveHeadList, ExIsProcessorFeaturePresent, ExIsResourceAcquiredExclusiveLite, ExIsResourceAcquiredSharedLite, ExLocalTimeToSystemTime, ExNotifyCallback, ExQueryPoolBlockSize, ExQueueWorkItem, ExRaiseAccessViolation, ExRaiseDatatypeMisalignment, ExRaiseException, ExRaiseHardError, ExRaiseStatus, ExReInitializeRundownProtection, ExRegisterCallback, ExReinitializeResourceLite, ExReleaseFastMutexUnsafe, ExReleaseResourceForThreadLite, ExReleaseResourceLite, ExReleaseRundownProtection, ExReleaseRundownProtectionEx, ExRundownCompleted, ExSemaphoreObjectType, ExSetResourceOwnerPointer, ExSetTimerResolution, ExSystemExceptionFilter, ExSystemTimeToLocalTime, ExUnregisterCallback, ExUuidCreate, ExVerifySuite, ExWaitForRundownProtectionRelease, ExWindowStationObjectType, ExfAcquirePushLockExclusive, ExfAcquirePushLockShared, ExfInterlockedAddUlong, ExfInterlockedCompareExchange64, ExfInterlockedInsertHeadList, ExfInterlockedInsertTailList, ExfInterlockedPopEntryList, ExfInterlockedPushEntryList, ExfInterlockedRemoveHeadList, ExfReleasePushLock, Exfi386InterlockedDecrementLong, Exfi386InterlockedExchangeUlong, Exfi386InterlockedIncrementLong, Exi386InterlockedDecrementLong, Exi386InterlockedExchangeUlong, Exi386InterlockedIncrementLong, FsRtlAcquireFileExclusive, FsRtlAddLargeMcbEntry, FsRtlAddMcbEntry, FsRtlAddToTunnelCache, FsRtlAllocateFileLock, FsRtlAllocatePool, FsRtlAllocatePoolWithQuota, FsRtlAllocatePoolWithQuotaTag, FsRtlAllocatePoolWithTag, FsRtlAllocateResource, FsRtlAreNamesEqual, FsRtlBalanceReads, FsRtlCheckLockForReadAccess, FsRtlCheckLockForWriteAccess, FsRtlCheckOplock, FsRtlCopyRead, FsRtlCopyWrite, FsRtlCreateSectionForDataScan, FsRtlCurrentBatchOplock, FsRtlDeleteKeyFromTunnelCache, FsRtlDeleteTunnelCache, FsRtlDeregisterUncProvider, FsRtlDissectDbcs, FsRtlDissectName, FsRtlDoesDbcsContainWildCards, FsRtlDoesNameContainWildCards, FsRtlFastCheckLockForRead, FsRtlFastCheckLockForWrite, FsRtlFastUnlockAll, FsRtlFastUnlockAllByKey, FsRtlFastUnlockSingle, FsRtlFindInTunnelCache, FsRtlFreeFileLock, FsRtlGetFileSize, FsRtlGetNextFileLock, FsRtlGetNextLargeMcbEntry, FsRtlGetNextMcbEntry, FsRtlIncrementCcFastReadNoWait, FsRtlIncrementCcFastReadNotPossible, FsRtlIncrementCcFastReadResourceMiss, FsRtlIncrementCcFastReadWait, FsRtlInitializeFileLock, FsRtlInitializeLargeMcb, FsRtlInitializeMcb, FsRtlInitializeOplock, FsRtlInitializeTunnelCache, FsRtlInsertPerFileObjectContext, FsRtlInsertPerStreamContext, FsRtlIsDbcsInExpression, FsRtlIsFatDbcsLegal, FsRtlIsHpfsDbcsLegal, FsRtlIsNameInExpression, FsRtlIsNtstatusExpected, FsRtlIsPagingFile, FsRtlIsTotalDeviceFailure, FsRtlLegalAnsiCharacterArray, FsRtlLookupLargeMcbEntry, FsRtlLookupLastLargeMcbEntry, FsRtlLookupLastLargeMcbEntryAndIndex, FsRtlLookupLastMcbEntry, FsRtlLookupMcbEntry, FsRtlLookupPerFileObjectContext, FsRtlLookupPerStreamContextInternal, FsRtlMdlRead, FsRtlMdlReadComplete, FsRtlMdlReadCompleteDev, FsRtlMdlReadDev, FsRtlMdlWriteComplete, FsRtlMdlWriteCompleteDev, FsRtlNormalizeNtstatus, FsRtlNotifyChangeDirectory, FsRtlNotifyCleanup, FsRtlNotifyFilterChangeDirectory, FsRtlNotifyFilterReportChange, FsRtlNotifyFullChangeDirectory, FsRtlNotifyFullReportChange, FsRtlNotifyInitializeSync, FsRtlNotifyReportChange, FsRtlNotifyUninitializeSync, FsRtlNotifyVolumeEvent, FsRtlNumberOfRunsInLargeMcb, FsRtlNumberOfRunsInMcb, FsRtlOplockFsctrl, FsRtlOplockIsFastIoPossible, FsRtlPostPagingFileStackOverflow, FsRtlPostStackOverflow, FsRtlPrepareMdlWrite, FsRtlPrepareMdlWriteDev, FsRtlPrivateLock, FsRtlProcessFileLock, FsRtlRegisterFileSystemFilterCallbacks, FsRtlRegisterUncProvider, FsRtlReleaseFile, FsRtlRemoveLargeMcbEntry, FsRtlRemoveMcbEntry, FsRtlRemovePerFileObjectContext, FsRtlRemovePerStreamContext, FsRtlResetLargeMcb, FsRtlSplitLargeMcb, FsRtlSyncVolumes, FsRtlTeardownPerStreamContexts, FsRtlTruncateLargeMcb, FsRtlTruncateMcb, FsRtlUninitializeFileLock, FsRtlUninitializeLargeMcb, FsRtlUninitializeMcb, FsRtlUninitializeOplock, HalDispatchTable, HalExamineMBR, HalPrivateDispatchTable, HeadlessDispatch, InbvAcquireDisplayOwnership, InbvCheckDisplayOwnership, InbvDisplayString, InbvEnableBootDriver, InbvEnableDisplayString, InbvInstallDisplayStringFilter, InbvIsBootDriverInstalled, InbvNotifyDisplayOwnershipLost, InbvResetDisplay, InbvSetScrollRegion, InbvSetTextColor, InbvSolidColorFill, InitSafeBootMode, InterlockedCompareExchange, InterlockedDecrement, InterlockedExchange, InterlockedExchangeAdd, InterlockedIncrement, InterlockedPopEntrySList, InterlockedPushEntrySList, IoAcquireCancelSpinLock, IoAcquireRemoveLockEx, IoAcquireVpbSpinLock, IoAdapterObjectType, IoAllocateAdapterChannel, IoAllocateController, IoAllocateDriverObjectExtension, IoAllocateErrorLogEntry, IoAllocateIrp, IoAllocateMdl, IoAllocateWorkItem, IoAssignDriveLetters, IoAssignResources, IoAttachDevice, IoAttachDeviceByPointer, IoAttachDeviceToDeviceStack, IoAttachDeviceToDeviceStackSafe, IoBuildAsynchronousFsdRequest, IoBuildDeviceIoControlRequest, IoBuildPartialMdl, IoBuildSynchronousFsdRequest, IoCallDriver, IoCancelFileOpen, IoCancelIrp, IoCheckDesiredAccess, IoCheckEaBufferValidity, IoCheckFunctionAccess, IoCheckQuerySetFileInformation, IoCheckQuerySetVolumeInformation, IoCheckQuotaBufferValidity, IoCheckShareAccess, IoCompleteRequest, IoConnectInterrupt, IoCreateController, IoCreateDevice, IoCreateDisk, IoCreateDriver, IoCreateFile, IoCreateFileSpecifyDeviceObjectHint, IoCreateNotificationEvent, IoCreateStreamFileObject, IoCreateStreamFileObjectEx, IoCreateStreamFileObjectLite, IoCreateSymbolicLink, IoCreateSynchronizationEvent, IoCreateUnprotectedSymbolicLink, IoCsqInitialize, IoCsqInsertIrp, IoCsqRemoveIrp, IoCsqRemoveNextIrp, IoDeleteController, IoDeleteDevice, IoDeleteDriver, IoDeleteSymbolicLink, IoDetachDevice, IoDeviceHandlerObjectSize, IoDeviceHandlerObjectType, IoDeviceObjectType, IoDisconnectInterrupt, IoDriverObjectType, IoEnqueueIrp, IoEnumerateDeviceObjectList, IoEnumerateRegisteredFiltersList, IoFastQueryNetworkAttributes, IoFileObjectType, IoForwardAndCatchIrp, IoForwardIrpSynchronously, IoFreeController, IoFreeErrorLogEntry, IoFreeIrp, IoFreeMdl, IoFreeWorkItem, IoGetAttachedDevice, IoGetAttachedDeviceReference, IoGetBaseFileSystemDeviceObject, IoGetBootDiskInformation, IoGetConfigurationInformation, IoGetCurrentProcess, IoGetDeviceAttachmentBaseRef, IoGetDeviceInterfaceAlias, IoGetDeviceInterfaces, IoGetDeviceObjectPointer, IoGetDeviceProperty, IoGetDeviceToVerify, IoGetDiskDeviceObject, IoGetDmaAdapter, IoGetDriverObjectExtension, IoGetFileObjectGenericMapping, IoGetInitialStack, IoGetLowerDeviceObject, IoGetRelatedDeviceObject, IoGetRequestorProcess, IoGetRequestorProcessId, IoGetRequestorSessionId, IoGetStackLimits, IoGetTopLevelIrp, IoInitializeCrashDump, IoInitializeIrp, IoInitializeRemoveLockEx, IoInitializeTimer, IoInvalidateDeviceRelations, IoInvalidateDeviceState, IoIsFileOriginRemote, IoIsOperationSynchronous, IoIsSystemThread, IoIsValidNameGraftingBuffer, IoIsWdmVersionAvailable, IoMakeAssociatedIrp, IoOpenDeviceInterfaceRegistryKey, IoOpenDeviceRegistryKey, IoPageRead, IoPnPDeliverServicePowerNotification, IoQueryDeviceDescription, IoQueryFileDosDeviceName, IoQueryFileInformation, IoQueryVolumeInformation, IoQueueThreadIrp, IoQueueWorkItem, IoRaiseHardError, IoRaiseInformationalHardError, IoReadDiskSignature, IoReadOperationCount, IoReadPartitionTable, IoReadPartitionTableEx, IoReadTransferCount, IoRegisterBootDriverReinitialization, IoRegisterDeviceInterface, IoRegisterDriverReinitialization, IoRegisterFileSystem, IoRegisterFsRegistrationChange, IoRegisterLastChanceShutdownNotification, IoRegisterPlugPlayNotification, IoRegisterShutdownNotification, IoReleaseCancelSpinLock, IoReleaseRemoveLockAndWaitEx, IoReleaseRemoveLockEx, IoReleaseVpbSpinLock, IoRemoveShareAccess, IoReportDetectedDevice, IoReportHalResourceUsage, IoReportResourceForDetection, IoReportResourceUsage, IoReportTargetDeviceChange, IoReportTargetDeviceChangeAsynchronous, IoRequestDeviceEject, IoReuseIrp, IoSetCompletionRoutineEx, IoSetDeviceInterfaceState, IoSetDeviceToVerify, IoSetFileOrigin, IoSetHardErrorOrVerifyDevice, IoSetInformation, IoSetIoCompletion, IoSetPartitionInformation, IoSetPartitionInformationEx, IoSetShareAccess, IoSetStartIoAttributes, IoSetSystemPartition, IoSetThreadHardErrorMode, IoSetTopLevelIrp, IoStartNextPacket, IoStartNextPacketByKey, IoStartPacket, IoStartTimer, IoStatisticsLock, IoStopTimer, IoSynchronousInvalidateDeviceRelations, IoSynchronousPageWrite, IoThreadToProcess, IoUnregisterFileSystem, IoUnregisterFsRegistrationChange, IoUnregisterPlugPlayNotification, IoUnregisterShutdownNotification, IoUpdateShareAccess, IoValidateDeviceIoControlAccess, IoVerifyPartitionTable, IoVerifyVolume, IoVolumeDeviceToDosName, IoWMIAllocateInstanceIds, IoWMIDeviceObjectToInstanceName, IoWMIExecuteMethod, IoWMIHandleToInstanceName, IoWMIOpenBlock, IoWMIQueryAllData, IoWMIQueryAllDataMultiple, IoWMIQuerySingleInstance, IoWMIQuerySingleInstanceMultiple, IoWMIRegistrationControl, IoWMISetNotificationCallback, IoWMISetSingleInstance, IoWMISetSingleItem, IoWMISuggestInstanceName, IoWMIWriteEvent, IoWriteErrorLogEntry, IoWriteOperationCount, IoWritePartitionTable, IoWritePartitionTableEx, IoWriteTransferCount, IofCallDriver, IofCompleteRequest, KdDebuggerEnabled, KdDebuggerNotPresent, KdDisableDebugger, KdEnableDebugger, KdEnteredDebugger, KdPollBreakIn, KdPowerTransition, Ke386CallBios, Ke386IoSetAccessProcess, Ke386QueryIoAccessMap, Ke386SetIoAccessMap, KeAcquireInStackQueuedSpinLockAtDpcLevel, KeAcquireInterruptSpinLock, KeAcquireSpinLockAtDpcLevel, KeAddSystemServiceTable, KeAreApcsDisabled, KeAttachProcess, KeBugCheck, KeBugCheckEx, KeCancelTimer, KeCapturePersistentThreadState, KeClearEvent, KeConnectInterrupt, KeDcacheFlushCount, KeDelayExecutionThread, KeDeregisterBugCheckCallback, KeDeregisterBugCheckReasonCallback, KeDetachProcess, KeDisconnectInterrupt, KeEnterCriticalRegion, KeEnterKernelDebugger, KeFindConfigurationEntry, KeFindConfigurationNextEntry, KeFlushEntireTb, KeFlushQueuedDpcs, KeGetCurrentThread, KeGetPreviousMode, KeGetRecommendedSharedDataAlignment, KeI386AbiosCall, KeI386AllocateGdtSelectors, KeI386Call16BitCStyleFunction, KeI386Call16BitFunction, KeI386FlatToGdtSelector, KeI386GetLid, KeI386MachineType, KeI386ReleaseGdtSelectors, KeI386ReleaseLid, KeI386SetGdtSelector, KeIcacheFlushCount, KeInitializeApc, KeInitializeDeviceQueue, KeInitializeDpc, KeInitializeEvent, KeInitializeInterrupt, KeInitializeMutant, KeInitializeMutex, KeInitializeQueue, KeInitializeSemaphore, KeInitializeSpinLock, KeInitializeTimer, KeInitializeTimerEx, KeInsertByKeyDeviceQueue, KeInsertDeviceQueue, KeInsertHeadQueue, KeInsertQueue, KeInsertQueueApc, KeInsertQueueDpc, KeIsAttachedProcess, KeIsExecutingDpc, KeLeaveCriticalRegion, KeLoaderBlock, KeNumberProcessors, KeProfileInterrupt, KeProfileInterruptWithSource, KePulseEvent, KeQueryActiveProcessors, KeQueryInterruptTime, KeQueryPriorityThread, KeQueryRuntimeThread, KeQuerySystemTime, KeQueryTickCount, KeQueryTimeIncrement, KeRaiseUserException, KeReadStateEvent, KeReadStateMutant, KeReadStateMutex, KeReadStateQueue, KeReadStateSemaphore, KeReadStateTimer, KeRegisterBugCheckCallback, KeRegisterBugCheckReasonCallback, KeReleaseInStackQueuedSpinLockFromDpcLevel, KeReleaseInterruptSpinLock, KeReleaseMutant, KeReleaseMutex, KeReleaseSemaphore, KeReleaseSpinLockFromDpcLevel, KeRemoveByKeyDeviceQueue, KeRemoveByKeyDeviceQueueIfBusy, KeRemoveDeviceQueue, KeRemoveEntryDeviceQueue, KeRemoveQueue, KeRemoveQueueDpc, KeRemoveSystemServiceTable, KeResetEvent, KeRestoreFloatingPointState, KeRevertToUserAffinityThread, KeRundownQueue, KeSaveFloatingPointState, KeSaveStateForHibernate, KeServiceDescriptorTable, KeSetAffinityThread, KeSetBasePriorityThread, KeSetDmaIoCoherency, KeSetEvent, KeSetEventBoostPriority, KeSetIdealProcessorThread, KeSetImportanceDpc, KeSetKernelStackSwapEnable, KeSetPriorityThread, KeSetProfileIrql, KeSetSystemAffinityThread, KeSetTargetProcessorDpc, KeSetTimeIncrement, KeSetTimeUpdateNotifyRoutine, KeSetTimer, KeSetTimerEx, KeStackAttachProcess, KeSynchronizeExecution, KeTerminateThread, KeTickCount, KeUnstackDetachProcess, KeUpdateRunTime, KeUpdateSystemTime, KeUserModeCallback, KeWaitForMultipleObjects, KeWaitForMutexObject, KeWaitForSingleObject, KefAcquireSpinLockAtDpcLevel, KefReleaseSpinLockFromDpcLevel, Kei386EoiHelper, KiAcquireSpinLock, KiBugCheckData, KiCoprocessorError, KiDeliverApc, KiDispatchInterrupt, KiEnableTimerWatchdog, KiIpiServiceRoutine, KiReleaseSpinLock, KiUnexpectedInterrupt, Kii386SpinOnSpinLock, LdrAccessResource, LdrEnumResources, LdrFindResourceDirectory_U, LdrFindResource_U, LpcPortObjectType, LpcRequestPort, LpcRequestWaitReplyPort, LsaCallAuthenticationPackage, LsaDeregisterLogonProcess, LsaFreeReturnBuffer, LsaLogonUser, LsaLookupAuthenticationPackage, LsaRegisterLogonProcess, Mm64BitPhysicalAddress, MmAddPhysicalMemory, MmAddVerifierThunks, MmAdjustWorkingSetSize, MmAdvanceMdl, MmAllocateContiguousMemory, MmAllocateContiguousMemorySpecifyCache, MmAllocateMappingAddress, MmAllocateNonCachedMemory, MmAllocatePagesForMdl, MmBuildMdlForNonPagedPool, MmCanFileBeTruncated, MmCommitSessionMappedView, MmCreateMdl, MmCreateSection, MmDisableModifiedWriteOfSection, MmFlushImageSection, MmForceSectionClosed, MmFreeContiguousMemory, MmFreeContiguousMemorySpecifyCache, MmFreeMappingAddress, MmFreeNonCachedMemory, MmFreePagesFromMdl, MmGetPhysicalAddress, MmGetPhysicalMemoryRanges, MmGetSystemRoutineAddress, MmGetVirtualForPhysical, MmGrowKernelStack, MmHighestUserAddress, MmIsAddressValid, MmIsDriverVerifying, MmIsNonPagedSystemAddressValid, MmIsRecursiveIoFault, MmIsThisAnNtAsSystem, MmIsVerifierEnabled, MmLockPagableDataSection, MmLockPagableImageSection, MmLockPagableSectionByHandle, MmMapIoSpace, MmMapLockedPages, MmMapLockedPagesSpecifyCache, MmMapLockedPagesWithReservedMapping, MmMapMemoryDumpMdl, MmMapUserAddressesToPage, MmMapVideoDisplay, MmMapViewInSessionSpace, MmMapViewInSystemSpace, MmMapViewOfSection, MmMarkPhysicalMemoryAsBad, MmMarkPhysicalMemoryAsGood, MmPageEntireDriver, MmPrefetchPages, MmProbeAndLockPages, MmProbeAndLockProcessPages, MmProbeAndLockSelectedPages, MmProtectMdlSystemAddress, MmQuerySystemSize, MmRemovePhysicalMemory, MmResetDriverPaging, MmSectionObjectType, MmSecureVirtualMemory, MmSetAddressRangeModified, MmSetBankedSection, MmSizeOfMdl, MmSystemRangeStart, MmTrimAllSystemPagableMemory, MmUnlockPagableImageSection, MmUnlockPages, MmUnmapIoSpace, MmUnmapLockedPages, MmUnmapReservedMapping, MmUnmapVideoDisplay, MmUnmapViewInSessionSpace, MmUnmapViewInSystemSpace, MmUnmapViewOfSection, MmUnsecureVirtualMemory, MmUserProbeAddress, NlsAnsiCodePage, NlsLeadByteInfo, NlsMbCodePageTag, NlsMbOemCodePageTag, NlsOemCodePage, NlsOemLeadByteInfo, NtAddAtom, NtAdjustPrivilegesToken, NtAllocateLocallyUniqueId, NtAllocateUuids, NtAllocateVirtualMemory, NtBuildNumber, NtClose, NtConnectPort, NtCreateEvent, NtCreateFile, NtCreateSection, NtDeleteAtom, NtDeleteFile, NtDeviceIoControlFile, NtDuplicateObject, NtDuplicateToken, NtFindAtom, NtFreeVirtualMemory, NtFsControlFile, NtGlobalFlag, NtLockFile, NtMakePermanentObject, NtMapViewOfSection, NtNotifyChangeDirectoryFile, NtOpenFile, NtOpenProcess, NtOpenProcessToken, NtOpenProcessTokenEx, NtOpenThread, NtOpenThreadToken, NtOpenThreadTokenEx, NtQueryDirectoryFile, NtQueryEaFile, NtQueryInformationAtom, NtQueryInformationFile, NtQueryInformationProcess, NtQueryInformationThread, NtQueryInformationToken, NtQueryQuotaInformationFile, NtQuerySecurityObject, NtQuerySystemInformation, NtQueryVolumeInformationFile, NtReadFile, NtRequestPort, NtRequestWaitReplyPort, NtSetEaFile, NtSetEvent, NtSetInformationFile, NtSetInformationProcess, NtSetInformationThread, NtSetQuotaInformationFile, NtSetSecurityObject, NtSetVolumeInformationFile, NtShutdownSystem, NtTraceEvent, NtUnlockFile, NtVdmControl, NtWaitForSingleObject, NtWriteFile, ObAssignSecurity, ObCheckCreateObjectAccess, ObCheckObjectAccess, ObCloseHandle, ObCreateObject, ObCreateObjectType, ObDereferenceObject, ObDereferenceSecurityDescriptor, ObFindHandleForObject, ObGetObjectSecurity, ObInsertObject, ObLogSecurityDescriptor, ObMakeTemporaryObject, ObOpenObjectByName, ObOpenObjectByPointer, ObQueryNameString, ObQueryObjectAuditingByHandle, ObReferenceObjectByHandle, ObReferenceObjectByName, ObReferenceObjectByPointer, ObReferenceSecurityDescriptor, ObReleaseObjectSecurity, ObSetHandleAttributes, ObSetSecurityDescriptorInfo, ObSetSecurityObjectByPointer, ObfDereferenceObject, ObfReferenceObject, PfxFindPrefix, PfxInitialize, PfxInsertPrefix, PfxRemovePrefix, PoCallDriver, PoCancelDeviceNotify, PoQueueShutdownWorkItem, PoRegisterDeviceForIdleDetection, PoRegisterDeviceNotify, PoRegisterSystemState, PoRequestPowerIrp, PoRequestShutdownEvent, PoSetHiberRange, PoSetPowerState, PoSetSystemState, PoShutdownBugCheck, PoStartNextPowerIrp, PoUnregisterSystemState, ProbeForRead, ProbeForWrite, PsAssignImpersonationToken, PsChargePoolQuota, PsChargeProcessNonPagedPoolQuota, PsChargeProcessPagedPoolQuota, PsChargeProcessPoolQuota, PsCreateSystemProcess, PsCreateSystemThread, PsDereferenceImpersonationToken, PsDereferencePrimaryToken, PsDisableImpersonation, PsEstablishWin32Callouts, PsGetContextThread, PsGetCurrentProcess, PsGetCurrentProcessId, PsGetCurrentProcessSessionId, PsGetCurrentThread, PsGetCurrentThreadId, PsGetCurrentThreadPreviousMode, PsGetCurrentThreadStackBase, PsGetCurrentThreadStackLimit, PsGetJobLock, PsGetJobSessionId, PsGetJobUIRestrictionsClass, PsGetProcessCreateTimeQuadPart, PsGetProcessDebugPort, PsGetProcessExitProcessCalled, PsGetProcessExitStatus, PsGetProcessExitTime, PsGetProcessId, PsGetProcessImageFileName, PsGetProcessInheritedFromUniqueProcessId, PsGetProcessJob, PsGetProcessPeb, PsGetProcessPriorityClass, PsGetProcessSectionBaseAddress, PsGetProcessSecurityPort, PsGetProcessSessionId, PsGetProcessWin32Process, PsGetProcessWin32WindowStation, PsGetThreadFreezeCount, PsGetThreadHardErrorsAreDisabled, PsGetThreadId, PsGetThreadProcess, PsGetThreadProcessId, PsGetThreadSessionId, PsGetThreadTeb, PsGetThreadWin32Thread, PsGetVersion, PsImpersonateClient, PsInitialSystemProcess, PsIsProcessBeingDebugged, PsIsSystemThread, PsIsThreadImpersonating, PsIsThreadTerminating, PsJobType, PsLookupProcessByProcessId, PsLookupProcessThreadByCid, PsLookupThreadByThreadId, PsProcessType, PsReferenceImpersonationToken, PsReferencePrimaryToken, PsRemoveCreateThreadNotifyRoutine, PsRemoveLoadImageNotifyRoutine, PsRestoreImpersonation, PsReturnPoolQuota, PsReturnProcessNonPagedPoolQuota, PsReturnProcessPagedPoolQuota, PsRevertThreadToSelf, PsRevertToSelf, PsSetContextThread, PsSetCreateProcessNotifyRoutine, PsSetCreateThreadNotifyRoutine, PsSetJobUIRestrictionsClass, PsSetLegoNotifyRoutine, PsSetLoadImageNotifyRoutine, PsSetProcessPriorityByClass, PsSetProcessPriorityClass, PsSetProcessSecurityPort, PsSetProcessWin32Process, PsSetProcessWindowStation, PsSetThreadHardErrorsAreDisabled, PsSetThreadWin32Thread, PsTerminateSystemThread, PsThreadType, READ_REGISTER_BUFFER_UCHAR, READ_REGISTER_BUFFER_ULONG, READ_REGISTER_BUFFER_USHORT, READ_REGISTER_UCHAR, READ_REGISTER_ULONG, READ_REGISTER_USHORT, RtlAbsoluteToSelfRelativeSD, RtlAddAccessAllowedAce, RtlAddAccessAllowedAceEx, RtlAddAce, RtlAddAtomToAtomTable, RtlAddRange, RtlAllocateHeap, RtlAnsiCharToUnicodeChar, RtlAnsiStringToUnicodeSize, RtlAnsiStringToUnicodeString, RtlAppendAsciizToString, RtlAppendStringToString, RtlAppendUnicodeStringToString, RtlAppendUnicodeToString, RtlAreAllAccessesGranted, RtlAreAnyAccessesGranted, RtlAreBitsClear, RtlAreBitsSet, RtlAssert, RtlCaptureContext, RtlCaptureStackBackTrace, RtlCharToInteger, RtlCheckRegistryKey, RtlClearAllBits, RtlClearBit, RtlClearBits, RtlCompareMemory, RtlCompareMemoryUlong, RtlCompareString, RtlCompareUnicodeString, RtlCompressBuffer, RtlCompressChunks, RtlConvertLongToLargeInteger, RtlConvertSidToUnicodeString, RtlConvertUlongToLargeInteger, RtlCopyLuid, RtlCopyRangeList, RtlCopySid, RtlCopyString, RtlCopyUnicodeString, RtlCreateAcl, RtlCreateAtomTable, RtlCreateHeap, RtlCreateRegistryKey, RtlCreateSecurityDescriptor, RtlCreateSystemVolumeInformationFolder, RtlCreateUnicodeString, RtlCustomCPToUnicodeN, RtlDecompressBuffer, RtlDecompressChunks, RtlDecompressFragment, RtlDelete, RtlDeleteAce, RtlDeleteAtomFromAtomTable, RtlDeleteElementGenericTable, RtlDeleteElementGenericTableAvl, RtlDeleteNoSplay, RtlDeleteOwnersRanges, RtlDeleteRange, RtlDeleteRegistryValue, RtlDescribeChunk, RtlDestroyAtomTable, RtlDestroyHeap, RtlDowncaseUnicodeString, RtlEmptyAtomTable, RtlEnlargedIntegerMultiply, RtlEnlargedUnsignedDivide, RtlEnlargedUnsignedMultiply, RtlEnumerateGenericTable, RtlEnumerateGenericTableAvl, RtlEnumerateGenericTableLikeADirectory, RtlEnumerateGenericTableWithoutSplaying, RtlEnumerateGenericTableWithoutSplayingAvl, RtlEqualLuid, RtlEqualSid, RtlEqualString, RtlEqualUnicodeString, RtlExtendedIntegerMultiply, RtlExtendedLargeIntegerDivide, RtlExtendedMagicDivide, RtlFillMemory, RtlFillMemoryUlong, RtlFindClearBits, RtlFindClearBitsAndSet, RtlFindClearRuns, RtlFindFirstRunClear, RtlFindLastBackwardRunClear, RtlFindLeastSignificantBit, RtlFindLongestRunClear, RtlFindMessage, RtlFindMostSignificantBit, RtlFindNextForwardRunClear, RtlFindRange, RtlFindSetBits, RtlFindSetBitsAndClear, RtlFindUnicodePrefix, RtlFormatCurrentUserKeyPath, RtlFreeAnsiString, RtlFreeHeap, RtlFreeOemString, RtlFreeRangeList, RtlFreeUnicodeString, RtlGUIDFromString, RtlGenerate8dot3Name, RtlGetAce, RtlGetCallersAddress, RtlGetCompressionWorkSpaceSize, RtlGetDaclSecurityDescriptor, RtlGetDefaultCodePage, RtlGetElementGenericTable, RtlGetElementGenericTableAvl, RtlGetFirstRange, RtlGetGroupSecurityDescriptor, RtlGetNextRange, RtlGetNtGlobalFlags, RtlGetOwnerSecurityDescriptor, RtlGetSaclSecurityDescriptor, RtlGetSetBootStatusData, RtlGetVersion, RtlHashUnicodeString, RtlImageDirectoryEntryToData, RtlImageNtHeader, RtlInitAnsiString, RtlInitCodePageTable, RtlInitString, RtlInitUnicodeString, RtlInitializeBitMap, RtlInitializeGenericTable, RtlInitializeGenericTableAvl, RtlInitializeRangeList, RtlInitializeSid, RtlInitializeUnicodePrefix, RtlInsertElementGenericTable, RtlInsertElementGenericTableAvl, RtlInsertElementGenericTableFull, RtlInsertElementGenericTableFullAvl, RtlInsertUnicodePrefix, RtlInt64ToUnicodeString, RtlIntegerToChar, RtlIntegerToUnicode, RtlIntegerToUnicodeString, RtlInvertRangeList, RtlIpv4AddressToStringA, RtlIpv4AddressToStringExA, RtlIpv4AddressToStringExW, RtlIpv4AddressToStringW, RtlIpv4StringToAddressA, RtlIpv4StringToAddressExA, RtlIpv4StringToAddressExW, RtlIpv4StringToAddressW, RtlIpv6AddressToStringA, RtlIpv6AddressToStringExA, RtlIpv6AddressToStringExW, RtlIpv6AddressToStringW, RtlIpv6StringToAddressA, RtlIpv6StringToAddressExA, RtlIpv6StringToAddressExW, RtlIpv6StringToAddressW, RtlIsGenericTableEmpty, RtlIsGenericTableEmptyAvl, RtlIsNameLegalDOS8Dot3, RtlIsRangeAvailable, RtlIsValidOemCharacter, RtlLargeIntegerAdd, RtlLargeIntegerArithmeticShift, RtlLargeIntegerDivide, RtlLargeIntegerNegate, RtlLargeIntegerShiftLeft, RtlLargeIntegerShiftRight, RtlLargeIntegerSubtract, RtlLengthRequiredSid, RtlLengthSecurityDescriptor, RtlLengthSid, RtlLockBootStatusData, RtlLookupAtomInAtomTable, RtlLookupElementGenericTable, RtlLookupElementGenericTableAvl, RtlLookupElementGenericTableFull, RtlLookupElementGenericTableFullAvl, RtlMapGenericMask, RtlMapSecurityErrorToNtStatus, RtlMergeRangeLists, RtlMoveMemory, RtlMultiByteToUnicodeN, RtlMultiByteToUnicodeSize, RtlNextUnicodePrefix, RtlNtStatusToDosError, RtlNtStatusToDosErrorNoTeb, RtlNumberGenericTableElements, RtlNumberGenericTableElementsAvl, RtlNumberOfClearBits, RtlNumberOfSetBits, RtlOemStringToCountedUnicodeString, RtlOemStringToUnicodeSize, RtlOemStringToUnicodeString, RtlOemToUnicodeN, RtlPinAtomInAtomTable, RtlPrefetchMemoryNonTemporal, RtlPrefixString, RtlPrefixUnicodeString, RtlQueryAtomInAtomTable, RtlQueryRegistryValues, RtlQueryTimeZoneInformation, RtlRaiseException, RtlRandom, RtlRandomEx, RtlRealPredecessor, RtlRealSuccessor, RtlRemoveUnicodePrefix, RtlReserveChunk, RtlSecondsSince1970ToTime, RtlSecondsSince1980ToTime, RtlSelfRelativeToAbsoluteSD, RtlSelfRelativeToAbsoluteSD2, RtlSetAllBits, RtlSetBit, RtlSetBits, RtlSetDaclSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlSetOwnerSecurityDescriptor, RtlSetSaclSecurityDescriptor, RtlSetTimeZoneInformation, RtlSizeHeap, RtlSplay, RtlStringFromGUID, RtlSubAuthorityCountSid, RtlSubAuthoritySid, RtlSubtreePredecessor, RtlSubtreeSuccessor, RtlTestBit, RtlTimeFieldsToTime, RtlTimeToElapsedTimeFields, RtlTimeToSecondsSince1970, RtlTimeToSecondsSince1980, RtlTimeToTimeFields, RtlTraceDatabaseAdd, RtlTraceDatabaseCreate, RtlTraceDatabaseDestroy, RtlTraceDatabaseEnumerate, RtlTraceDatabaseFind, RtlTraceDatabaseLock, RtlTraceDatabaseUnlock, RtlTraceDatabaseValidate, RtlUlongByteSwap, RtlUlonglongByteSwap, RtlUnicodeStringToAnsiSize, RtlUnicodeStringToAnsiString, RtlUnicodeStringToCountedOemString, RtlUnicodeStringToInteger, RtlUnicodeStringToOemSize, RtlUnicodeStringToOemString, RtlUnicodeToCustomCPN, RtlUnicodeToMultiByteN, RtlUnicodeToMultiByteSize, RtlUnicodeToOemN, RtlUnlockBootStatusData, RtlUnwind, RtlUpcaseUnicodeChar, RtlUpcaseUnicodeString, RtlUpcaseUnicodeStringToAnsiString, RtlUpcaseUnicodeStringToCountedOemString, RtlUpcaseUnicodeStringToOemString, RtlUpcaseUnicodeToCustomCPN, RtlUpcaseUnicodeToMultiByteN, RtlUpcaseUnicodeToOemN, RtlUpperChar, RtlUpperString, RtlUshortByteSwap, RtlValidRelativeSecurityDescriptor, RtlValidSecurityDescriptor, RtlValidSid, RtlVerifyVersionInfo, RtlVolumeDeviceToDosName, RtlWalkFrameChain, RtlWriteRegistryValue, RtlZeroHeap, RtlZeroMemory, RtlxAnsiStringToUnicodeSize, RtlxOemStringToUnicodeSize, RtlxUnicodeStringToAnsiSize, RtlxUnicodeStringToOemSize, SeAccessCheck, SeAppendPrivileges, SeAssignSecurity, SeAssignSecurityEx, SeAuditHardLinkCreation, SeAuditingFileEvents, SeAuditingFileEventsWithContext, SeAuditingFileOrGlobalEvents, SeAuditingHardLinkEvents, SeAuditingHardLinkEventsWithContext, SeCaptureSecurityDescriptor, SeCaptureSubjectContext, SeCloseObjectAuditAlarm, SeCreateAccessState, SeCreateClientSecurity, SeCreateClientSecurityFromSubjectContext, SeDeassignSecurity, SeDeleteAccessState, SeDeleteObjectAuditAlarm, SeExports, SeFilterToken, SeFreePrivileges, SeImpersonateClient, SeImpersonateClientEx, SeLockSubjectContext, SeMarkLogonSessionForTerminationNotification, SeOpenObjectAuditAlarm, SeOpenObjectForDeleteAuditAlarm, SePrivilegeCheck, SePrivilegeObjectAuditAlarm, SePublicDefaultDacl, SeQueryAuthenticationIdToken, SeQueryInformationToken, SeQuerySecurityDescriptorInfo, SeQuerySessionIdToken, SeRegisterLogonSessionTerminatedRoutine, SeReleaseSecurityDescriptor, SeReleaseSubjectContext, SeSetAccessStateGenericMapping, SeSetSecurityDescriptorInfo, SeSetSecurityDescriptorInfoEx, SeSinglePrivilegeCheck, SeSystemDefaultDacl, SeTokenImpersonationLevel, SeTokenIsAdmin, SeTokenIsRestricted, SeTokenIsWriteRestricted, SeTokenObjectType, SeTokenType, SeUnlockSubjectContext, SeUnregisterLogonSessionTerminatedRoutine, SeValidSecurityDescriptor, VerSetConditionMask, VfFailDeviceNode, VfFailDriver, VfFailSystemBIOS, VfIsVerificationEnabled, WRITE_REGISTER_BUFFER_UCHAR, WRITE_REGISTER_BUFFER_ULONG, WRITE_REGISTER_BUFFER_USHORT, WRITE_REGISTER_UCHAR, WRITE_REGISTER_ULONG, WRITE_REGISTER_USHORT, WmiFlushTrace, WmiGetClock, WmiQueryTrace, WmiQueryTraceInformation, WmiStartTrace, WmiStopTrace, WmiTraceMessage, WmiTraceMessageVa, WmiUpdateTrace, XIPDispatch, ZwAccessCheckAndAuditAlarm, ZwAddBootEntry, ZwAdjustPrivilegesToken, ZwAlertThread, ZwAllocateVirtualMemory, ZwAssignProcessToJobObject, ZwCancelIoFile, ZwCancelTimer, ZwClearEvent, ZwClose, ZwCloseObjectAuditAlarm, ZwConnectPort, ZwCreateDirectoryObject, ZwCreateEvent, ZwCreateFile, ZwCreateJobObject, ZwCreateKey, ZwCreateSection, ZwCreateSymbolicLinkObject, ZwCreateTimer, ZwDeleteBootEntry, ZwDeleteFile, ZwDeleteKey, ZwDeleteValueKey, ZwDeviceIoControlFile, ZwDisplayString, ZwDuplicateObject, ZwDuplicateToken, ZwEnumerateBootEntries, ZwEnumerateKey, ZwEnumerateValueKey, ZwFlushInstructionCache, ZwFlushKey, ZwFlushVirtualMemory, ZwFreeVirtualMemory, ZwFsControlFile, ZwInitiatePowerAction, ZwIsProcessInJob, ZwLoadDriver, ZwLoadKey, ZwMakeTemporaryObject, ZwMapViewOfSection, ZwNotifyChangeKey, ZwOpenDirectoryObject, ZwOpenEvent, ZwOpenFile, ZwOpenJobObject, ZwOpenKey, ZwOpenProcess, ZwOpenProcessToken, ZwOpenProcessTokenEx, ZwOpenSection, ZwOpenSymbolicLinkObject, ZwOpenThread, ZwOpenThreadToken, ZwOpenThreadTokenEx, ZwOpenTimer, ZwPowerInformation, ZwPulseEvent, ZwQueryBootEntryOrder, ZwQueryBootOptions, ZwQueryDefaultLocale, ZwQueryDefaultUILanguage, ZwQueryDirectoryFile, ZwQueryDirectoryObject, ZwQueryEaFile, ZwQueryFullAttributesFile, ZwQueryInformationFile, ZwQueryInformationJobObject, ZwQueryInformationProcess, ZwQueryInformationThread, ZwQueryInformationToken, ZwQueryInstallUILanguage, ZwQueryKey, ZwQueryObject, ZwQuerySection, ZwQuerySecurityObject, ZwQuerySymbolicLinkObject, ZwQuerySystemInformation, ZwQueryValueKey, ZwQueryVolumeInformationFile, ZwReadFile, ZwReplaceKey, ZwRequestWaitReplyPort, ZwResetEvent, ZwRestoreKey, ZwSaveKey, ZwSaveKeyEx, ZwSetBootEntryOrder, ZwSetBootOptions, ZwSetDefaultLocale, ZwSetDefaultUILanguage, ZwSetEaFile, ZwSetEvent, ZwSetInformationFile, ZwSetInformationJobObject, ZwSetInformationObject, ZwSetInformationProcess, ZwSetInformationThread, ZwSetSecurityObject, ZwSetSystemInformation, ZwSetSystemTime, ZwSetTimer, ZwSetValueKey, ZwSetVolumeInformationFile, ZwTerminateJobObject, ZwTerminateProcess, ZwTranslateFilePath, ZwUnloadDriver, ZwUnloadKey, ZwUnmapViewOfSection, ZwWaitForMultipleObjects, ZwWaitForSingleObject, ZwWriteFile, ZwYieldExecution, _CIcos, _CIsin, _CIsqrt, _abnormal_termination, _alldiv, _alldvrm, _allmul, _alloca_probe, _allrem, _allshl, _allshr, _aulldiv, _aulldvrm, _aullrem, _aullshr, _except_handler2, _except_handler3, _global_unwind2, _itoa, _itow, _local_unwind2, _purecall, _snprintf, _snwprintf, _stricmp, _strlwr, _strnicmp, _strnset, _strrev, _strset, _strupr, _vsnprintf, _vsnwprintf, _wcsicmp, _wcslwr, _wcsnicmp, _wcsnset, _wcsrev, _wcsupr, atoi, atol, isdigit, islower, isprint, isspace, isupper, isxdigit, mbstowcs, mbtowc, memchr, memcpy, memmove, memset, qsort, rand, sprintf, srand, strcat, strchr, strcmp, strcpy, strlen, strncat, strncmp, strncpy, strrchr, strspn, strstr, swprintf, tolower, toupper, towlower, towupper, vDbgPrintEx, vDbgPrintExWithPrefix, vsprintf, wcscat, wcschr, wcscmp, wcscpy, wcscspn, wcslen, wcsncat, wcsncmp, wcsncpy, wcsrchr, wcsspn, wcsstr, wcstombs, wctomb<BR>

    ========================================================================================


    c:\windows\explorer.exe:

    File explorer.exe received on 03.07.2009 19:21:56 (CET)Antivirus Version Last Update Result
    a-squared 4.0.0.101 2009.03.07 -
    AhnLab-V3 5.0.0.2 2009.02.27 -
    AntiVir 7.9.0.105 2009.03.07 -
    Authentium 5.1.0.4 2009.03.06 -
    Avast 4.8.1335.0 2009.03.06 -
    AVG 8.0.0.237 2009.03.06 -
    BitDefender 7.2 2009.03.07 -
    CAT-QuickHeal 10.00 2009.03.07 -
    ClamAV 0.94.1 2009.03.06 -
    Comodo 1035 2009.03.07 -
    DrWeb 4.44.0.09170 2009.03.07 -
    eSafe 7.0.17.0 2009.03.05 -
    eTrust-Vet 31.6.6386 2009.03.06 -
    F-Prot 4.4.4.56 2009.03.06 -
    F-Secure 8.0.14470.0 2009.03.07 -
    Fortinet 3.117.0.0 2009.03.07 -
    GData 19 2009.03.07 -
    Ikarus T3.1.1.45.0 2009.03.07 -
    K7AntiVirus 7.10.663 2009.03.07 -
    Kaspersky 7.0.0.125 2009.03.07 -
    McAfee 5546 2009.03.07 -
    McAfee+Artemis 5546 2009.03.07 -
    Microsoft 1.4405 2009.03.07 -
    NOD32 3917 2009.03.07 -
    Norman 6.00.06 2009.03.06 -
    nProtect 2009.1.8.0 2009.03.07 -
    Panda 10.0.0.10 2009.03.07 -
    PCTools 4.4.2.0 2009.03.07 -
    Prevx1 V2 2009.03.07 -
    Rising 21.19.42.00 2009.03.06 -
    SecureWeb-Gateway 6.7.6 2009.03.07 -
    Sophos 4.39.0 2009.03.07 -
    Sunbelt 3.2.1858.2 2009.03.07 -
    Symantec 1.4.4.12 2009.03.07 -
    TheHacker 6.3.2.7.275 2009.03.07 -
    TrendMicro 8.700.0.1004 2009.03.06 -
    VBA32 3.12.10.1 2009.03.07 -
    ViRobot 2009.3.7.1639 2009.03.07 -
    VirusBuster 4.5.11.0 2009.03.07 -

    Additional information
    File size: 1033216 bytes
    MD5...: 97bd6515465659ff8f3b7be375b2ea87
    SHA1..: 972307a3ef93680afdd03603df20f2241047a934
    SHA256: 8b48dd5eb2a7f8ec8b607b1b0c9cbf7278b401024347971cbb6d0c9530d1c295
    SHA512: 780c42f6aa8fce6826059bf892b1b10dbe9380aec3155dd72506c965355bf10b<BR>4e8a43d7132a90f5c99ecfab3d42127a5e836d9b39b80b806ba00d038bc3f1d1
    ssdeep: 12288:NRFHBdIwCDrA6hWVz0v/1oHWr2Rkf8I+skzaz1/g/J/vHyM:NzhOwCDE6h<BR>COLakf8I+sko1/g/J//y<BR>
    PEiD..: -
    TrID..: File type identification<BR>Win32 Executable MS Visual C++ (generic) (65.2%)<BR>Win32 Executable Generic (14.7%)<BR>Win32 Dynamic Link Library (generic) (13.1%)<BR>Generic Win/DOS Executable (3.4%)<BR>DOS Executable Generic (3.4%)
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x1a8ce<BR>timedatestamp.....: 0x466fc588 (Wed Jun 13 10:23:04 2007)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x44ad9 0x44c00 6.36 7de882aa0da62b155286cb91c8f0fbd9<BR>.data 0x46000 0x1db4 0x1800 1.30 25fdde5ea7a06e94390eb8773b825a55<BR>.rsrc 0x48000 0xb2278 0xb2400 6.63 b82ace172bfa53b11b99e63c7ac67c26<BR>.reloc 0xfb000 0x3720 0x3800 6.76 924c25a2a1584ac973811d65894c44fa<BR><BR>( 13 imports ) <BR>&gt; ADVAPI32.dll: RegSetValueW, RegEnumKeyExW, GetUserNameW, RegNotifyChangeKeyValue, RegEnumValueW, RegQueryValueExA, RegOpenKeyExA, RegEnumKeyW, RegCloseKey, RegCreateKeyW, RegQueryInfoKeyW, RegOpenKeyExW, RegQueryValueExW, RegCreateKeyExW, RegSetValueExW, RegDeleteValueW, RegQueryValueW<BR>&gt; BROWSEUI.dll: -, -, -, -<BR>&gt; GDI32.dll: GetStockObject, CreatePatternBrush, OffsetViewportOrgEx, GetLayout, CombineRgn, CreateDIBSection, GetTextExtentPoint32W, StretchBlt, SetTextColor, CreateRectRgn, GetClipRgn, IntersectClipRect, GetViewportOrgEx, SetViewportOrgEx, SelectClipRgn, PatBlt, GetBkColor, CreateCompatibleDC, CreateCompatibleBitmap, OffsetWindowOrgEx, DeleteDC, SetBkColor, BitBlt, ExtTextOutW, GetTextExtentPointW, GetClipBox, GetObjectW, CreateRectRgnIndirect, SetBkMode, CreateFontIndirectW, DeleteObject, GetTextMetricsW, SelectObject, GetDeviceCaps, TranslateCharsetInfo, SetStretchBltMode<BR>&gt; KERNEL32.dll: GetSystemDirectoryW, CreateThread, CreateJobObjectW, ExitProcess, SetProcessShutdownParameters, ReleaseMutex, CreateMutexW, SetPriorityClass, GetCurrentProcess, GetStartupInfoW, GetCommandLineW, SetErrorMode, LeaveCriticalSection, EnterCriticalSection, ResetEvent, LoadLibraryExA, CompareFileTime, GetSystemTimeAsFileTime, SetThreadPriority, GetCurrentThreadId, GetThreadPriority, GetCurrentThread, GetUserDefaultLangID, Sleep, GetBinaryTypeW, GetModuleHandleExW, SystemTimeToFileTime, GetLocalTime, GetCurrentProcessId, GetEnvironmentVariableW, UnregisterWait, GlobalGetAtomNameW, GetFileAttributesW, MoveFileW, lstrcmpW, LoadLibraryExW, FindClose, FindNextFileW, FindFirstFileW, lstrcmpiA, SetEvent, AssignProcessToJobObject, GetDateFormatW, GetTimeFormatW, FlushInstructionCache, lstrcpynW, GetSystemWindowsDirectoryW, SetLastError, GetProcessHeap, HeapFree, HeapReAlloc, HeapSize, HeapAlloc, GetUserDefaultLCID, ReadProcessMemory, OpenProcess, InterlockedCompareExchange, LoadLibraryA, QueryPerformanceCounter, UnhandledExceptionFilter, SetUnhandledExceptionFilter, VirtualFree, VirtualAlloc, ResumeThread, TerminateProcess, TerminateThread, GetSystemDefaultLCID, GetLocaleInfoW, CreateEventW, GetLastError, RegisterWaitForSingleObject, OpenEventW, WaitForSingleObject, GetTickCount, ExpandEnvironmentStringsW, GetModuleFileNameW, GetPrivateProfileStringW, lstrcmpiW, CreateProcessW, FreeLibrary, GetWindowsDirectoryW, LocalAlloc, CreateFileW, DeviceIoControl, LocalFree, GetQueuedCompletionStatus, CreateIoCompletionPort, SetInformationJobObject, CloseHandle, LoadLibraryW, GetModuleHandleW, ActivateActCtx, DeactivateActCtx, DelayLoadFailureHook, GetProcAddress, DeleteCriticalSection, CreateEventA, HeapDestroy, InitializeCriticalSection, GetFileAttributesExW, MulDiv, lstrlenW, InterlockedDecrement, InterlockedIncrement, GlobalAlloc, InterlockedExchange, GetModuleHandleA, GetVersionExA, GlobalFree, GetProcessTimes, lstrcpyW, GetLongPathNameW, InitializeCriticalSectionAndSpinCount<BR>&gt; msvcrt.dll: _itow, free, memmove, realloc, _except_handler3, malloc, _ftol, _vsnwprintf<BR>&gt; ntdll.dll: RtlNtStatusToDosError, NtQueryInformationProcess<BR>&gt; ole32.dll: CoFreeUnusedLibraries, RegisterDragDrop, CreateBindCtx, RevokeDragDrop, CoInitializeEx, CoUninitialize, OleInitialize, CoRevokeClassObject, CoRegisterClassObject, CoMarshalInterThreadInterfaceInStream, CoCreateInstance, OleUninitialize, DoDragDrop<BR>&gt; OLEAUT32.dll: -, -<BR>&gt; SHDOCVW.dll: -, -, -<BR>&gt; SHELL32.dll: -, SHGetFolderPathW, -, -, -, -, -, ExtractIconExW, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, ShellExecuteExW, -, -, -, -, -, -, -, SHBindToParent, -, -, -, SHParseDisplayName, -, -, -, -, -, -, SHGetSpecialFolderLocation, -, -, -, -, SHGetSpecialFolderPathW, -, -, -, -, -, SHChangeNotify, SHGetDesktopFolder, SHAddToRecentDocs, -, -, -, DuplicateIcon, -, -, -, -, -, -, -, -, SHUpdateRecycleBinIcon, SHGetFolderLocation, SHGetPathFromIDListA, -, -, -, -, -, -, -, SHGetPathFromIDListW, -, -, -<BR>&gt; SHLWAPI.dll: StrCpyNW, -, -, -, -, StrRetToBufW, StrRetToStrW, -, -, -, -, SHQueryValueExW, PathIsNetworkPathW, -, AssocCreate, -, -, -, -, -, StrCatW, StrCpyW, -, -, -, -, -, -, -, SHGetValueW, -, StrCmpNIW, PathRemoveBlanksW, PathRemoveArgsW, PathFindFileNameW, StrStrIW, PathGetArgsW, -, StrToIntW, SHRegGetBoolUSValueW, SHRegWriteUSValueW, SHRegCloseUSKey, SHRegCreateUSKeyW, SHRegGetUSValueW, SHSetValueW, -, PathAppendW, PathUnquoteSpacesW, -, -, PathQuoteSpacesW, -, SHSetThreadRef, SHCreateThreadRef, -, -, -, PathCombineW, -, -, -, SHStrDupW, PathIsPrefixW, PathParseIconLocationW, AssocQueryKeyW, -, AssocQueryStringW, StrCmpW, -, -, -, -, -, -, -, -, SHRegQueryUSValueW, SHRegOpenUSKeyW, SHRegSetUSValueW, PathIsDirectoryW, PathFileExistsW, PathGetDriveNumberW, -, StrChrW, PathFindExtensionW, -, -, PathRemoveFileSpecW, PathStripToRootW, -, -, -, SHOpenRegStream2W, -, -, -, StrDupW, SHDeleteValueW, StrCatBuffW, SHDeleteKeyW, StrCmpIW, -, -, wnsprintfW, -, StrCmpNW, -, -<BR>&gt; USER32.dll: TileWindows, GetDoubleClickTime, GetSystemMetrics, GetSysColorBrush, AllowSetForegroundWindow, LoadMenuW, GetSubMenu, RemoveMenu, SetParent, GetMessagePos, CheckDlgButton, EnableWindow, GetDlgItemInt, SetDlgItemInt, CopyIcon, AdjustWindowRectEx, DrawFocusRect, DrawEdge, ExitWindowsEx, WindowFromPoint, SetRect, AppendMenuW, LoadAcceleratorsW, LoadBitmapW, SendNotifyMessageW, SetWindowPlacement, CheckMenuItem, EndDialog, SendDlgItemMessageW, MessageBeep, GetActiveWindow, PostQuitMessage, MoveWindow, GetDlgItem, RemovePropW, GetClassNameW, GetDCEx, SetCursorPos, ChildWindowFromPoint, ChangeDisplaySettingsW, RegisterHotKey, UnregisterHotKey, SetCursor, SendMessageTimeoutW, GetWindowPlacement, LoadImageW, SetWindowRgn, IntersectRect, OffsetRect, EnumDisplayMonitors, RedrawWindow, SubtractRect, TranslateAcceleratorW, WaitMessage, InflateRect, CallWindowProcW, GetDlgCtrlID, SetCapture, LockSetForegroundWindow, CopyRect, SystemParametersInfoW, FindWindowW, CreatePopupMenu, GetMenuDefaultItem, DestroyMenu, GetShellWindow, EnumChildWindows, GetWindowLongW, SendMessageW, RegisterWindowMessageW, GetKeyState, MonitorFromRect, MonitorFromPoint, RegisterClassW, SetPropW, GetWindowLongA, SetWindowLongW, FillRect, GetCursorPos, PtInRect, MessageBoxW, LoadStringW, ReleaseDC, GetDC, EnumDisplaySettingsExW, EnumDisplayDevicesW, PostMessageW, DispatchMessageW, TranslateMessage, GetMessageW, PeekMessageW, BeginPaint, EndPaint, SetWindowTextW, GetAsyncKeyState, InvalidateRect, GetWindow, ShowWindowAsync, TrackPopupMenuEx, UpdateWindow, DestroyIcon, IsRectEmpty, SetActiveWindow, GetSysColor, DrawTextW, IsHungAppWindow, SetTimer, GetMenuItemID, TrackPopupMenu, EndTask, SendMessageCallbackW, GetClassLongW, LoadIconW, OpenInputDesktop, CloseDesktop, SetScrollPos, ShowWindow, BringWindowToTop, GetDesktopWindow, CascadeWindows, CharUpperBuffW, SwitchToThisWindow, InternalGetWindowText, GetScrollInfo, GetMenuItemCount, ModifyMenuW, CreateWindowExW, DialogBoxParamW, MsgWaitForMultipleObjects, CharNextA, RegisterClipboardFormatW, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, PrintWindow, SetClassLongW, GetPropW, GetNextDlgGroupItem, GetNextDlgTabItem, ChildWindowFromPointEx, IsChild, NotifyWinEvent, TrackMouseEvent, GetCapture, GetAncestor, CharUpperW, SetWindowLongA, DrawCaption, InsertMenuW, IsWindowEnabled, GetMenuState, LoadCursorW, GetParent, IsDlgButtonChecked, DestroyWindow, EnumWindows, IsWindowVisible, GetClientRect, UnionRect, EqualRect, GetWindowThreadProcessId, GetForegroundWindow, KillTimer, GetClassInfoExW, DefWindowProcW, RegisterClassExW, GetIconInfo, SetScrollInfo, GetLastActivePopup, SetForegroundWindow, IsWindow, GetSystemMenu, IsIconic, IsZoomed, EnableMenuItem, SetMenuDefaultItem, MonitorFromWindow, GetMonitorInfoW, GetWindowInfo, GetFocus, SetFocus, MapWindowPoints, ScreenToClient, ClientToScreen, GetWindowRect, SetWindowPos, DeleteMenu, GetMenuItemInfoW, SetMenuItemInfoW, CharNextW<BR>&gt; UxTheme.dll: GetThemeBackgroundContentRect, GetThemeBool, GetThemePartSize, DrawThemeParentBackground, OpenThemeData, DrawThemeBackground, GetThemeTextExtent, DrawThemeText, CloseThemeData, SetWindowTheme, GetThemeBackgroundRegion, -, GetThemeMargins, GetThemeColor, GetThemeFont, GetThemeRect, IsAppThemed<BR><BR>( 0 exports ) <BR>
    ThreatExpert info: &lt;a href='http://www.threatexpert.com/report.aspx?md5=97bd6515465659ff8f3b7be375b2ea87' target='_blank'&gt;http://www.threatexpert.com/report.a...ea87&lt;/a&gt;

    ========================================================================================

    c:\windows\system32\spoolsv.exe:

    File spoolsv.exe received on 03.07.2009 19:22:30 (CET)Antivirus Version Last Update Result
    a-squared 4.0.0.101 2009.03.07 -
    AhnLab-V3 5.0.0.2 2009.02.27 -
    AntiVir 7.9.0.105 2009.03.07 -
    Authentium 5.1.0.4 2009.03.06 -
    Avast 4.8.1335.0 2009.03.06 -
    AVG 8.0.0.237 2009.03.06 -
    BitDefender 7.2 2009.03.07 -
    CAT-QuickHeal 10.00 2009.03.07 -
    ClamAV 0.94.1 2009.03.06 -
    Comodo 1035 2009.03.07 -
    DrWeb 4.44.0.09170 2009.03.07 -
    eSafe 7.0.17.0 2009.03.05 -
    eTrust-Vet 31.6.6386 2009.03.06 -
    F-Prot 4.4.4.56 2009.03.06 -
    F-Secure 8.0.14470.0 2009.03.07 -
    Fortinet 3.117.0.0 2009.03.07 -
    GData 19 2009.03.07 -
    Ikarus T3.1.1.45.0 2009.03.07 -
    K7AntiVirus 7.10.663 2009.03.07 -
    Kaspersky 7.0.0.125 2009.03.07 -
    McAfee 5546 2009.03.07 -
    McAfee+Artemis 5546 2009.03.07 -
    Microsoft 1.4405 2009.03.07 -
    NOD32 3917 2009.03.07 -
    Norman 6.00.06 2009.03.06 -
    nProtect 2009.1.8.0 2009.03.07 -
    Panda 10.0.0.10 2009.03.07 -
    PCTools 4.4.2.0 2009.03.07 -
    Prevx1 V2 2009.03.07 -
    Rising 21.19.42.00 2009.03.06 -
    SecureWeb-Gateway 6.7.6 2009.03.07 -
    Sophos 4.39.0 2009.03.07 -
    Sunbelt 3.2.1858.2 2009.03.07 -
    Symantec 1.4.4.12 2009.03.07 -
    TheHacker 6.3.2.7.275 2009.03.07 -
    TrendMicro 8.700.0.1004 2009.03.06 -
    VBA32 3.12.10.1 2009.03.07 -
    ViRobot 2009.3.7.1639 2009.03.07 -
    VirusBuster 4.5.11.0 2009.03.07 -

    Additional information
    File size: 57856 bytes
    MD5...: da81ec57acd4cdc3d4c51cf3d409af9f
    SHA1..: 7047ed8bd91f3e57972483feaa56e3499cd8c668
    SHA256: 521257429493f31516ede549869efa4b7a262f6a69ea1e82a9c875456c10e702
    SHA512: e8c16e68a8844a5eeb1d6e8a1aecb01972a26fb67c111ddc8b32c5368ec8681b<BR>f8d248042be9ab87ee2d98404d62dcd88990d527ba66ffdf77d6f0f7f5c92394
    ssdeep: 768:HE4EVpgSav2lAMm1yMvsC0C+H8O+j8f1b1mDV3D+JMig/FrVJigo:egSrlAM<BR>mxUCxOUVQgd+go<BR>
    PEiD..: -
    TrID..: File type identification<BR>Win64 Executable Generic (59.6%)<BR>Win32 Executable MS Visual C++ (generic) (26.2%)<BR>Win32 Executable Generic (5.9%)<BR>Win32 Dynamic Link Library (generic) (5.2%)<BR>Generic Win/DOS Executable (1.3%)
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x461b<BR>timedatestamp.....: 0x42aa27fc (Fri Jun 10 23:53:32 2005)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 3 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0xba70 0xbc00 5.93 70ace146704d1e88dc38fe6de39d5234<BR>.data 0xd000 0x13b4 0x1400 2.24 0fa5684c132ff9a6ade42f1de6a4ea4b<BR>.rsrc 0xf000 0xc78 0xe00 6.19 a897c19712dda21ea8ae94d31e1fdb1f<BR><BR>( 6 imports ) <BR>&gt; ADVAPI32.dll: SetServiceStatus, RegQueryValueExW, AllocateAndInitializeSid, FreeSid, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetLengthSid, InitializeAcl, AddAccessAllowedAce, AddAccessDeniedAce, GetAce, SetSecurityDescriptorDacl, GetSecurityDescriptorLength, MakeSelfRelativeSD, RegDisablePredefinedCache, RegOpenKeyExW, RegCloseKey, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW<BR>&gt; GDI32.dll: bMakePathNameW, GdiInitSpool, GdiGetSpoolMessage<BR>&gt; KERNEL32.dll: GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, GetCurrentProcessId, SetUnhandledExceptionFilter, GetModuleHandleA, GetCurrentThreadId, GetTickCount, UnhandledExceptionFilter, QueryPerformanceCounter, FreeLibrary, InterlockedExchange, GetModuleHandleW, GetLastError, ExitThread, CloseHandle, WaitForSingleObject, CreateEventW, CreateThread, ExitProcess, Sleep, OpenEventW, LoadLibraryA, InitializeCriticalSection, LocalFree, LocalAlloc, SetEvent, LeaveCriticalSection, EnterCriticalSection, SetLastError, OpenProcess, InterlockedIncrement, RaiseException, InterlockedDecrement, GetProcAddress, GetSystemDirectoryW<BR>&gt; msvcrt.dll: __initenv, _exit, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _controlfp, _XcptFilter, wcsrchr, wcslen, _c_exit, _stricmp, _wcsnicmp, _except_handler3<BR>&gt; ntdll.dll: RtlValidRelativeSecurityDescriptor<BR>&gt; RPCRT4.dll: RpcServerRegisterIf2, I_RpcBindingIsClientLocal, I_RpcSessionStrictContextHandle, RpcRaiseException, RpcImpersonateClient, RpcRevertToSelf, NdrServerCall2, RpcServerUseProtseqEpA, I_RpcSsDontSerializeContext, RpcMgmtSetServerStackSize, RpcServerListen<BR><BR>( 12 exports ) <BR>YDriverUnloadComplete, YEndDocPrinter, YFlushPrinter, YGetPrinter, YGetPrinterDriver2, YGetPrinterDriverDirectory, YReadPrinter, YSeekPrinter, YSetJob, YSetPort, YSplReadPrinter, YWritePrinter<BR>
    ThreatExpert info: &lt;a href='http://www.threatexpert.com/report.aspx?md5=da81ec57acd4cdc3d4c51cf3d409af9f' target='_blank'&gt;http://www.threatexpert.com/report.a...af9f&lt;/a&gt;

    ========================================================================================

  2. #12
    Junior Member
    Join Date
    Mar 2009
    Posts
    21

    Default TotalVirus results part 4 - the final frontier?

    c:\windows\system32\kernel32.dll:

    File kernel32.dll_ received on 03.07.2009 19:23:23 (CET)Antivirus Version Last Update Result
    a-squared 4.0.0.101 2009.03.07 -
    AhnLab-V3 5.0.0.2 2009.02.27 -
    AntiVir 7.9.0.105 2009.03.07 -
    Authentium 5.1.0.4 2009.03.06 -
    Avast 4.8.1335.0 2009.03.06 -
    AVG 8.0.0.237 2009.03.06 -
    BitDefender 7.2 2009.03.07 -
    CAT-QuickHeal 10.00 2009.03.07 -
    ClamAV 0.94.1 2009.03.06 -
    Comodo 1035 2009.03.07 -
    DrWeb 4.44.0.09170 2009.03.07 -
    eSafe 7.0.17.0 2009.03.05 -
    eTrust-Vet 31.6.6386 2009.03.06 -
    F-Prot 4.4.4.56 2009.03.06 -
    F-Secure 8.0.14470.0 2009.03.07 -
    Fortinet 3.117.0.0 2009.03.07 -
    GData 19 2009.03.07 -
    Ikarus T3.1.1.45.0 2009.03.07 -
    K7AntiVirus 7.10.663 2009.03.07 -
    Kaspersky 7.0.0.125 2009.03.07 -
    McAfee 5546 2009.03.07 -
    McAfee+Artemis 5546 2009.03.07 -
    Microsoft 1.4405 2009.03.07 -
    NOD32 3917 2009.03.07 -
    Norman 6.00.06 2009.03.06 -
    nProtect 2009.1.8.0 2009.03.07 -
    Panda 10.0.0.10 2009.03.07 -
    PCTools 4.4.2.0 2009.03.07 -
    Prevx1 V2 2009.03.07 -
    Rising 21.19.42.00 2009.03.06 -
    SecureWeb-Gateway 6.7.6 2009.03.07 -
    Sophos 4.39.0 2009.03.07 -
    Sunbelt 3.2.1858.2 2009.03.07 -
    Symantec 1.4.4.12 2009.03.07 -
    TheHacker 6.3.2.7.275 2009.03.07 -
    TrendMicro 8.700.0.1004 2009.03.06 -
    VBA32 3.12.10.1 2009.03.07 -
    ViRobot 2009.3.7.1639 2009.03.07 -
    VirusBuster 4.5.11.0 2009.03.07 -

    Additional information
    File size: 984576 bytes
    MD5...: a01f9ca902a88f7ced06884174d6419d
    SHA1..: 968953e88a3ca6920346cbc7baff8f81375b1a35
    SHA256: 7693f343ef828d10b748314ea8fbf8ade015447d76408278ece06e17489733e5
    SHA512: fdec386da1d3334a97151dafe4cc52dc8239ed8310536e39d419b5fef4573a7e<BR>a46c3b9266d9949741ba7d00319164e8e3e989bfea4321d9f5ff03a04a3499e5
    ssdeep: 12288:1raWXzXtBd47xbFL0rYGWAvuViTZ3sH4:4BFQrcAvuVitcY<BR>
    PEiD..: -
    TrID..: File type identification<BR>Win32 EXE PECompact compressed (generic) (36.1%)<BR>Win32 Executable MS Visual C++ (generic) (32.8%)<BR>Win 9x/ME Control Panel applet (13.5%)<BR>Win32 Executable Generic (7.4%)<BR>Win32 Dynamic Link Library (generic) (6.5%)
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0xb5ae<BR>timedatestamp.....: 0x46239bd5 (Mon Apr 16 15:52:53 2007)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x82111 0x82200 6.67 7a5d54edc093ecf62412b0810215b7b1<BR>.data 0x84000 0x43a0 0x2400 0.59 812f89bacee15996f8a2ae3eab48f42b<BR>.rsrc 0x89000 0x65ee8 0x66000 3.39 14e8ab72e8445c8106fec6f9f7acc9ef<BR>.reloc 0xef000 0x5bec 0x5c00 6.64 99c4e30af015bfb0ecf448d27654df37<BR><BR>( 1 imports ) <BR>&gt; ntdll.dll: _wcsnicmp, NtFsControlFile, NtCreateFile, RtlAllocateHeap, RtlFreeHeap, NtOpenFile, NtQueryInformationFile, NtQueryEaFile, RtlLengthSecurityDescriptor, NtQuerySecurityObject, NtSetEaFile, NtSetSecurityObject, NtSetInformationFile, CsrClientCallServer, NtDeviceIoControlFile, NtClose, RtlInitUnicodeString, wcscspn, RtlUnicodeToMultiByteSize, wcslen, _memicmp, memmove, NtQueryValueKey, NtOpenKey, NtFlushKey, NtSetValueKey, NtCreateKey, RtlNtStatusToDosError, RtlFreeUnicodeString, RtlDnsHostNameToComputerName, wcsncpy, RtlUnicodeStringToAnsiString, RtlxUnicodeStringToAnsiSize, NlsMbCodePageTag, RtlAnsiStringToUnicodeString, RtlInitAnsiString, RtlCreateUnicodeStringFromAsciiz, wcschr, wcsstr, RtlPrefixString, _wcsicmp, RtlGetFullPathName_U, RtlGetCurrentDirectory_U, NtQueryInformationProcess, RtlUnicodeStringToOemString, RtlReleasePebLock, RtlEqualUnicodeString, RtlAcquirePebLock, RtlFreeAnsiString, RtlSetCurrentDirectory_U, RtlTimeToTimeFields, NtSetSystemTime, RtlTimeFieldsToTime, NtQuerySystemInformation, RtlSetTimeZoneInformation, NtSetSystemInformation, RtlCutoverTimeToSystemTime, _allmul, DbgBreakPoint, RtlFreeSid, RtlSetDaclSecurityDescriptor, RtlCreateSecurityDescriptor, RtlAddAccessAllowedAce, RtlCreateAcl, RtlLengthSid, RtlAllocateAndInitializeSid, DbgPrint, NtOpenProcess, CsrGetProcessId, DbgUiDebugActiveProcess, DbgUiConnectToDbg, DbgUiIssueRemoteBreakin, NtSetInformationDebugObject, DbgUiGetThreadDebugObject, NtQueryInformationThread, DbgUiConvertStateChangeStructure, DbgUiWaitStateChange, DbgUiContinue, DbgUiStopDebugging, RtlDosPathNameToNtPathName_U, RtlIsDosDeviceName_U, RtlCreateAtomTable, NtAddAtom, RtlAddAtomToAtomTable, NtFindAtom, RtlLookupAtomInAtomTable, NtDeleteAtom, RtlDeleteAtomFromAtomTable, NtQueryInformationAtom, RtlQueryAtomInAtomTable, RtlOemStringToUnicodeString, RtlMultiByteToUnicodeN, RtlUnicodeToMultiByteN, RtlMultiByteToUnicodeSize, RtlPrefixUnicodeString, RtlLeaveCriticalSection, RtlEnterCriticalSection, NtEnumerateValueKey, RtlIsTextUnicode, NtReadFile, NtAllocateVirtualMemory, NtUnlockFile, NtLockFile, RtlAppendUnicodeStringToString, RtlAppendUnicodeToString, RtlCopyUnicodeString, NtFreeVirtualMemory, NtWriteFile, RtlCreateUnicodeString, RtlFormatCurrentUserKeyPath, RtlGetLongestNtPathLength, NtDuplicateObject, NtQueryKey, NtEnumerateKey, NtDeleteValueKey, RtlEqualString, CsrFreeCaptureBuffer, CsrCaptureMessageString, CsrAllocateCaptureBuffer, strncpy, RtlCharToInteger, RtlUpcaseUnicodeChar, RtlUpcaseUnicodeString, CsrAllocateMessagePointer, NtQueryObject, wcscmp, RtlCompareMemory, NtQueryDirectoryObject, NtQuerySymbolicLinkObject, NtOpenSymbolicLinkObject, NtOpenDirectoryObject, NtCreateIoCompletion, NtSetIoCompletion, NtRemoveIoCompletion, NtSetInformationProcess, NtQueryDirectoryFile, RtlDeleteCriticalSection, NtNotifyChangeDirectoryFile, NtWaitForSingleObject, RtlInitializeCriticalSection, NtQueryVolumeInformationFile, NtFlushBuffersFile, RtlDeactivateActivationContextUnsafeFast, RtlActivateActivationContextUnsafeFast, NtCancelIoFile, NtReadFileScatter, NtWriteFileGather, wcscpy, NtOpenSection, NtMapViewOfSection, NtFlushVirtualMemory, RtlFlushSecureMemoryCache, NtUnmapViewOfSection, NtCreateSection, NtQueryFullAttributesFile, swprintf, NtQueryAttributesFile, RtlDetermineDosPathNameType_U, NtRaiseHardError, NtQuerySystemEnvironmentValueEx, RtlGUIDFromString, NtSetSystemEnvironmentValueEx, RtlInitString, RtlUnlockHeap, RtlSetUserValueHeap, RtlFreeHandle, RtlAllocateHandle, RtlLockHeap, RtlSizeHeap, RtlGetUserInfoHeap, RtlReAllocateHeap, RtlIsValidHandle, RtlCompactHeap, RtlImageNtHeader, NtProtectVirtualMemory, NtQueryVirtualMemory, NtLockVirtualMemory, NtUnlockVirtualMemory, NtFlushInstructionCache, NtAllocateUserPhysicalPages, NtFreeUserPhysicalPages, NtMapUserPhysicalPages, NtMapUserPhysicalPagesScatter, NtGetWriteWatch, NtResetWriteWatch, NtSetInformationObject, CsrNewThread, CsrClientConnectToServer, RtlCreateTagHeap, LdrSetDllManifestProber, RtlSetThreadPoolStartFunc, RtlEncodePointer, _stricmp, wcscat, RtlCreateHeap, RtlDestroyHeap, RtlExtendHeap, RtlQueryTagHeap, RtlUsageHeap, RtlValidateHeap, RtlGetProcessHeaps, RtlWalkHeap, RtlSetHeapInformation, RtlQueryHeapInformation, RtlInitializeHandleTable, RtlExtendedLargeIntegerDivide, NtCreateMailslotFile, RtlFormatMessage, RtlFindMessage, LdrUnloadDll, LdrUnloadAlternateResourceModule, LdrDisableThreadCalloutsForDll, strchr, LdrGetDllHandle, LdrUnlockLoaderLock, LdrAddRefDll, RtlComputePrivatizedDllName_U, RtlPcToFileHeader, LdrLockLoaderLock, RtlGetVersion, RtlVerifyVersionInfo, LdrEnumerateLoadedModules, RtlUnicodeStringToInteger, LdrLoadAlternateResourceModule, RtlDosApplyFileIsolationRedirection_Ustr, LdrLoadDll, LdrGetProcedureAddress, LdrFindResource_U, LdrAccessResource, LdrFindResourceDirectory_U, RtlImageDirectoryEntryToData, _strcmpi, NtSetInformationThread, NtOpenThreadToken, NtCreateNamedPipeFile, RtlDefaultNpAcl, RtlDosSearchPath_Ustr, RtlInitUnicodeStringEx, RtlQueryEnvironmentVariable_U, RtlAnsiCharToUnicodeChar, RtlIntegerToChar, NtSetVolumeInformationFile, RtlIsNameLegalDOS8Dot3, NtQueryPerformanceCounter, sprintf, NtPowerInformation, NtInitiatePowerAction, NtSetThreadExecutionState, NtRequestWakeupLatency, NtGetDevicePowerState, NtIsSystemResumeAutomatic, NtRequestDeviceWakeup, NtCancelDeviceWakeupRequest, NtWriteVirtualMemory, LdrShutdownProcess, NtTerminateProcess, RtlRaiseStatus, RtlSetEnvironmentVariable, RtlExpandEnvironmentStrings_U, NtReadVirtualMemory, RtlCompareUnicodeString, RtlQueryRegistryValues, NtCreateJobSet, NtCreateJobObject, NtIsProcessInJob, RtlEqualSid, RtlSubAuthoritySid, RtlInitializeSid, NtQueryInformationToken, NtOpenProcessToken, NtResumeThread, NtAssignProcessToJobObject, CsrCaptureMessageMultiUnicodeStringsInPlace, NtCreateThread, NtCreateProcessEx, LdrQueryImageFileExecutionOptions, RtlDestroyEnvironment, NtQuerySection, NtQueryInformationJobObject, RtlGetNativeSystemInformation, RtlxAnsiStringToUnicodeSize, NtOpenEvent, NtQueryEvent, NtTerminateThread, wcsrchr, NlsMbOemCodePageTag, RtlxUnicodeStringToOemSize, NtAdjustPrivilegesToken, RtlImpersonateSelf, wcsncmp, RtlDestroyProcessParameters, RtlCreateProcessParameters, RtlInitializeCriticalSectionAndSpinCount, NtSetEvent, NtClearEvent, NtPulseEvent, NtCreateSemaphore, NtOpenSemaphore, NtReleaseSemaphore, NtCreateMutant, NtOpenMutant, NtReleaseMutant, NtSignalAndWaitForSingleObject, NtWaitForMultipleObjects, NtDelayExecution, NtCreateTimer, NtOpenTimer, NtSetTimer, NtCancelTimer, NtCreateEvent, RtlCopyLuid, strrchr, _vsnwprintf, RtlReleaseActivationContext, RtlActivateActivationContextEx, RtlQueryInformationActivationContext, NtOpenThread, LdrShutdownThread, RtlFreeThreadActivationContextStack, NtGetContextThread, NtSetContextThread, NtSuspendThread, RtlRaiseException, RtlDecodePointer, towlower, RtlClearBits, RtlFindClearBitsAndSet, RtlAreBitsSet, NtQueueApcThread, NtYieldExecution, RtlRegisterWait, RtlDeregisterWait, RtlDeregisterWaitEx, RtlQueueWorkItem, RtlSetIoCompletionCallback, RtlCreateTimerQueue, RtlCreateTimer, RtlUpdateTimer, RtlDeleteTimer, RtlDeleteTimerQueueEx, CsrIdentifyAlertableThread, RtlApplicationVerifierStop, _alloca_probe, RtlDestroyQueryDebugBuffer, RtlQueryProcessDebugInformation, RtlCreateQueryDebugBuffer, RtlCreateEnvironment, RtlFreeOemString, strstr, toupper, isdigit, atol, tolower, NtOpenJobObject, NtTerminateJobObject, NtSetInformationJobObject, RtlAddRefActivationContext, RtlZombifyActivationContext, RtlActivateActivationContext, RtlDeactivateActivationContext, RtlGetActiveActivationContext, DbgPrintEx, LdrDestroyOutOfProcessImage, LdrAccessOutOfProcessResource, LdrFindCreateProcessManifest, LdrCreateOutOfProcessImage, RtlNtStatusToDosErrorNoTeb, RtlpApplyLengthFunction, RtlGetLengthWithoutLastFullDosOrNtPathElement, RtlpEnsureBufferSize, RtlMultiAppendUnicodeStringBuffer, _snwprintf, RtlCreateActivationContext, RtlFindActivationContextSectionString, RtlFindActivationContextSectionGuid, _allshl, RtlNtPathNameToDosPathName, RtlUnhandledExceptionFilter, CsrCaptureMessageBuffer, NtQueryInstallUILanguage, NtQueryDefaultUILanguage, wcspbrk, RtlOpenCurrentUser, RtlGetDaclSecurityDescriptor, NtCreateDirectoryObject, _wcslwr, _wtol, RtlIntegerToUnicodeString, NtQueryDefaultLocale, _strlwr, RtlUnwind<BR><BR>( 949 exports ) <BR>ActivateActCtx, AddAtomA, AddAtomW, AddConsoleAliasA, AddConsoleAliasW, AddLocalAlternateComputerNameA, AddLocalAlternateComputerNameW, AddRefActCtx, AddVectoredExceptionHandler, AllocConsole, AllocateUserPhysicalPages, AreFileApisANSI, AssignProcessToJobObject, AttachConsole, BackupRead, BackupSeek, BackupWrite, BaseCheckAppcompatCache, BaseCleanupAppcompatCache, BaseCleanupAppcompatCacheSupport, BaseDumpAppcompatCache, BaseFlushAppcompatCache, BaseInitAppcompatCache, BaseInitAppcompatCacheSupport, BaseProcessInitPostImport, BaseQueryModuleData, BaseUpdateAppcompatCache, BasepCheckWinSaferRestrictions, Beep, BeginUpdateResourceA, BeginUpdateResourceW, BindIoCompletionCallback, BuildCommDCBA, BuildCommDCBAndTimeoutsA, BuildCommDCBAndTimeoutsW, BuildCommDCBW, CallNamedPipeA, CallNamedPipeW, CancelDeviceWakeupRequest, CancelIo, CancelTimerQueueTimer, CancelWaitableTimer, ChangeTimerQueueTimer, CheckNameLegalDOS8Dot3A, CheckNameLegalDOS8Dot3W, CheckRemoteDebuggerPresent, ClearCommBreak, ClearCommError, CloseConsoleHandle, CloseHandle, CloseProfileUserMapping, CmdBatNotification, CommConfigDialogA, CommConfigDialogW, CompareFileTime, CompareStringA, CompareStringW, ConnectNamedPipe, ConsoleMenuControl, ContinueDebugEvent, ConvertDefaultLocale, ConvertFiberToThread, ConvertThreadToFiber, CopyFileA, CopyFileExA, CopyFileExW, CopyFileW, CopyLZFile, CreateActCtxA, CreateActCtxW, CreateConsoleScreenBuffer, CreateDirectoryA, CreateDirectoryExA, CreateDirectoryExW, CreateDirectoryW, CreateEventA, CreateEventW, CreateFiber, CreateFiberEx, CreateFileA, CreateFileMappingA, CreateFileMappingW, CreateFileW, CreateHardLinkA, CreateHardLinkW, CreateIoCompletionPort, CreateJobObjectA, CreateJobObjectW, CreateJobSet, CreateMailslotA, CreateMailslotW, CreateMemoryResourceNotification, CreateMutexA, CreateMutexW, CreateNamedPipeA, CreateNamedPipeW, CreateNlsSecurityDescriptor, CreatePipe, CreateProcessA, CreateProcessInternalA, CreateProcessInternalW, CreateProcessInternalWSecure, CreateProcessW, CreateRemoteThread, CreateSemaphoreA, CreateSemaphoreW, CreateSocketHandle, CreateTapePartition, CreateThread, CreateTimerQueue, CreateTimerQueueTimer, CreateToolhelp32Snapshot, CreateVirtualBuffer, CreateWaitableTimerA, CreateWaitableTimerW, DeactivateActCtx, DebugActiveProcess, DebugActiveProcessStop, DebugBreak, DebugBreakProcess, DebugSetProcessKillOnExit, DecodePointer, DecodeSystemPointer, DefineDosDeviceA, DefineDosDeviceW, DelayLoadFailureHook, DeleteAtom, DeleteCriticalSection, DeleteFiber, DeleteFileA, DeleteFileW, DeleteTimerQueue, DeleteTimerQueueEx, DeleteTimerQueueTimer, DeleteVolumeMountPointA, DeleteVolumeMountPointW, DeviceIoControl, DisableThreadLibraryCalls, DisconnectNamedPipe, DnsHostnameToComputerNameA, DnsHostnameToComputerNameW, DosDateTimeToFileTime, DosPathToSessionPathA, DosPathToSessionPathW, DuplicateConsoleHandle, DuplicateHandle, EncodePointer, EncodeSystemPointer, EndUpdateResourceA, EndUpdateResourceW, EnterCriticalSection, EnumCalendarInfoA, EnumCalendarInfoExA, EnumCalendarInfoExW, EnumCalendarInfoW, EnumDateFormatsA, EnumDateFormatsExA, EnumDateFormatsExW, EnumDateFormatsW, EnumLanguageGroupLocalesA, EnumLanguageGroupLocalesW, EnumResourceLanguagesA, EnumResourceLanguagesW, EnumResourceNamesA, EnumResourceNamesW, EnumResourceTypesA, EnumResourceTypesW, EnumSystemCodePagesA, EnumSystemCodePagesW, EnumSystemGeoID, EnumSystemLanguageGroupsA, EnumSystemLanguageGroupsW, EnumSystemLocalesA, EnumSystemLocalesW, EnumTimeFormatsA, EnumTimeFormatsW, EnumUILanguagesA, EnumUILanguagesW, EnumerateLocalComputerNamesA, EnumerateLocalComputerNamesW, EraseTape, EscapeCommFunction, ExitProcess, ExitThread, ExitVDM, ExpandEnvironmentStringsA, ExpandEnvironmentStringsW, ExpungeConsoleCommandHistoryA, ExpungeConsoleCommandHistoryW, ExtendVirtualBuffer, FatalAppExitA, FatalAppExitW, FatalExit, FileTimeToDosDateTime, FileTimeToLocalFileTime, FileTimeToSystemTime, FillConsoleOutputAttribute, FillConsoleOutputCharacterA, FillConsoleOutputCharacterW, FindActCtxSectionGuid, FindActCtxSectionStringA, FindActCtxSectionStringW, FindAtomA, FindAtomW, FindClose, FindCloseChangeNotification, FindFirstChangeNotificationA, FindFirstChangeNotificationW, FindFirstFileA, FindFirstFileExA, FindFirstFileExW, FindFirstFileW, FindFirstVolumeA, FindFirstVolumeMountPointA, FindFirstVolumeMountPointW, FindFirstVolumeW, FindNextChangeNotification, FindNextFileA, FindNextFileW, FindNextVolumeA, FindNextVolumeMountPointA, FindNextVolumeMountPointW, FindNextVolumeW, FindResourceA, FindResourceExA, FindResourceExW, FindResourceW, FindVolumeClose, FindVolumeMountPointClose, FlushConsoleInputBuffer, FlushFileBuffers, FlushInstructionCache, FlushViewOfFile, FoldStringA, FoldStringW, FormatMessageA, FormatMessageW, FreeConsole, FreeEnvironmentStringsA, FreeEnvironmentStringsW, FreeLibrary, FreeLibraryAndExitThread, FreeResource, FreeUserPhysicalPages, FreeVirtualBuffer, GenerateConsoleCtrlEvent, GetACP, GetAtomNameA, GetAtomNameW, GetBinaryType, GetBinaryTypeA, GetBinaryTypeW, GetCPFileNameFromRegistry, GetCPInfo, GetCPInfoExA, GetCPInfoExW, GetCalendarInfoA, GetCalendarInfoW, GetComPlusPackageInstallStatus, GetCommConfig, GetCommMask, GetCommModemStatus, GetCommProperties, GetCommState, GetCommTimeouts, GetCommandLineA, GetCommandLineW, GetCompressedFileSizeA, GetCompressedFileSizeW, GetComputerNameA, GetComputerNameExA, GetComputerNameExW, GetComputerNameW, GetConsoleAliasA, GetConsoleAliasExesA, GetConsoleAliasExesLengthA, GetConsoleAliasExesLengthW, GetConsoleAliasExesW, GetConsoleAliasW, GetConsoleAliasesA, GetConsoleAliasesLengthA, GetConsoleAliasesLengthW, GetConsoleAliasesW, GetConsoleCP, GetConsoleCharType, GetConsoleCommandHistoryA, GetConsoleCommandHistoryLengthA, GetConsoleCommandHistoryLengthW, GetConsoleCommandHistoryW, GetConsoleCursorInfo, GetConsoleCursorMode, GetConsoleDisplayMode, GetConsoleFontInfo, GetConsoleFontSize, GetConsoleHardwareState, GetConsoleInputExeNameA, GetConsoleInputExeNameW, GetConsoleInputWaitHandle, GetConsoleKeyboardLayoutNameA, GetConsoleKeyboardLayoutNameW, GetConsoleMode, GetConsoleNlsMode, GetConsoleOutputCP, GetConsoleProcessList, GetConsoleScreenBufferInfo, GetConsoleSelectionInfo, GetConsoleTitleA, GetConsoleTitleW, GetConsoleWindow, GetCurrencyFormatA, GetCurrencyFormatW, GetCurrentActCtx, GetCurrentConsoleFont, GetCurrentDirectoryA, GetCurrentDirectoryW, GetCurrentProcess, GetCurrentProcessId, GetCurrentThread, GetCurrentThreadId, GetDateFormatA, GetDateFormatW, GetDefaultCommConfigA, GetDefaultCommConfigW, GetDefaultSortkeySize, GetDevicePowerState, GetDiskFreeSpaceA, GetDiskFreeSpaceExA, GetDiskFreeSpaceExW, GetDiskFreeSpaceW, GetDllDirectoryA, GetDllDirectoryW, GetDriveTypeA, GetDriveTypeW, GetEnvironmentStrings, GetEnvironmentStringsA, GetEnvironmentStringsW, GetEnvironmentVariableA, GetEnvironmentVariableW, GetExitCodeProcess, GetExitCodeThread, GetExpandedNameA, GetExpandedNameW, GetFileAttributesA, GetFileAttributesExA, GetFileAttributesExW, GetFileAttributesW, GetFileInformationByHandle, GetFileSize, GetFileSizeEx, GetFileTime, GetFileType, GetFirmwareEnvironmentVariableA, GetFirmwareEnvironmentVariableW, GetFullPathNameA, GetFullPathNameW, GetGeoInfoA, GetGeoInfoW, GetHandleContext, GetHandleInformation, GetLargestConsoleWindowSize, GetLastError, GetLinguistLangSize, GetLocalTime, GetLocaleInfoA, GetLocaleInfoW, GetLogicalDriveStringsA, GetLogicalDriveStringsW, GetLogicalDrives, GetLongPathNameA, GetLongPathNameW, GetMailslotInfo, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleA, GetModuleHandleExA, GetModuleHandleExW, GetModuleHandleW, GetNamedPipeHandleStateA, GetNamedPipeHandleStateW, GetNamedPipeInfo, GetNativeSystemInfo, GetNextVDMCommand, GetNlsSectionName, GetNumaAvailableMemory, GetNumaAvailableMemoryNode, GetNumaHighestNodeNumber, GetNumaNodeProcessorMask, GetNumaProcessorMap, GetNumaProcessorNode, GetNumberFormatA, GetNumberFormatW, GetNumberOfConsoleFonts, GetNumberOfConsoleInputEvents, GetNumberOfConsoleMouseButtons, GetOEMCP, GetOverlappedResult, GetPriorityClass, GetPrivateProfileIntA, GetPrivateProfileIntW, GetPrivateProfileSectionA, GetPrivateProfileSectionNamesA, GetPrivateProfileSectionNamesW, GetPrivateProfileSectionW, GetPrivateProfileStringA, GetPrivateProfileStringW, GetPrivateProfileStructA, GetPrivateProfileStructW, GetProcAddress, GetProcessAffinityMask, GetProcessHandleCount, GetProcessHeap, GetProcessHeaps, GetProcessId, GetProcessIoCounters, GetProcessPriorityBoost, GetProcessShutdownParameters, GetProcessTimes, GetProcessVersion, GetProcessWorkingSetSize, GetProfileIntA, GetProfileIntW, GetProfileSectionA, GetProfileSectionW, GetProfileStringA, GetProfileStringW, GetQueuedCompletionStatus, GetShortPathNameA, GetShortPathNameW, GetStartupInfoA, GetStartupInfoW, GetStdHandle, GetStringTypeA, GetStringTypeExA, GetStringTypeExW, GetStringTypeW, GetSystemDefaultLCID, GetSystemDefaultLangID, GetSystemDefaultUILanguage, GetSystemDirectoryA, GetSystemDirectoryW, GetSystemInfo, GetSystemPowerStatus, GetSystemRegistryQuota, GetSystemTime, GetSystemTimeAdjustment, GetSystemTimeAsFileTime, GetSystemTimes, GetSystemWindowsDirectoryA, GetSystemWindowsDirectoryW, GetSystemWow64DirectoryA, GetSystemWow64DirectoryW, GetTapeParameters, GetTapePosition, GetTapeStatus, GetTempFileNameA, GetTempFileNameW, GetTempPathA, GetTempPathW, GetThreadContext, GetThreadIOPendingFlag, GetThreadLocale, GetThreadPriority, GetThreadPriorityBoost, GetThreadSelectorEntry, GetThreadTimes, GetTickCount, GetTimeFormatA, GetTimeFormatW, GetTimeZoneInformation, GetUserDefaultLCID, GetUserDefaultLangID, GetUserDefaultUILanguage, GetUserGeoID, GetVDMCurrentDirectories, GetVersion, GetVersionExA, GetVersionExW, GetVolumeInformationA, GetVolumeInformationW, GetVolumeNameForVolumeMountPointA, GetVolumeNameForVolumeMountPointW, GetVolumePathNameA, GetVolumePathNameW, GetVolumePathNamesForVolumeNameA, GetVolumePathNamesForVolumeNameW, GetWindowsDirectoryA, GetWindowsDirectoryW, GetWriteWatch, GlobalAddAtomA, GlobalAddAtomW, GlobalAlloc, GlobalCompact, GlobalDeleteAtom, GlobalFindAtomA, GlobalFindAtomW, GlobalFix, GlobalFlags, GlobalFree, GlobalGetAtomNameA, GlobalGetAtomNameW, GlobalHandle, GlobalLock, GlobalMemoryStatus, GlobalMemoryStatusEx, GlobalReAlloc, GlobalSize, GlobalUnWire, GlobalUnfix, GlobalUnlock, GlobalWire, Heap32First, Heap32ListFirst, Heap32ListNext, Heap32Next, HeapAlloc, HeapCompact, HeapCreate, HeapCreateTagsW, HeapDestroy, HeapExtend, HeapFree, HeapLock, HeapQueryInformation, HeapQueryTagW, HeapReAlloc, HeapSetInformation, HeapSize, HeapSummary, HeapUnlock, HeapUsage, HeapValidate, HeapWalk, InitAtomTable, InitializeCriticalSection, InitializeCriticalSectionAndSpinCount, InitializeSListHead, InterlockedCompareExchange, InterlockedDecrement, InterlockedExchange, InterlockedExchangeAdd, InterlockedFlushSList, InterlockedIncrement, InterlockedPopEntrySList, InterlockedPushEntrySList, InvalidateConsoleDIBits, IsBadCodePtr, IsBadHugeReadPtr, IsBadHugeWritePtr, IsBadReadPtr, IsBadStringPtrA, IsBadStringPtrW, IsBadWritePtr, IsDBCSLeadByte, IsDBCSLeadByteEx, IsDebuggerPresent, IsProcessInJob, IsProcessorFeaturePresent, IsSystemResumeAutomatic, IsValidCodePage, IsValidLanguageGroup, IsValidLocale, IsValidUILanguage, IsWow64Process, LCMapStringA, LCMapStringW, LZClose, LZCloseFile, LZCopy, LZCreateFileW, LZDone, LZInit, LZOpenFileA, LZOpenFileW, LZRead, LZSeek, LZStart, LeaveCriticalSection, LoadLibraryA, LoadLibraryExA, LoadLibraryExW, LoadLibraryW, LoadModule, LoadResource, LocalAlloc, LocalCompact, LocalFileTimeToFileTime, LocalFlags, LocalFree, LocalHandle, LocalLock, LocalReAlloc, LocalShrink, LocalSize, LocalUnlock, LockFile, LockFileEx, LockResource, MapUserPhysicalPages, MapUserPhysicalPagesScatter, MapViewOfFile, MapViewOfFileEx, Module32First, Module32FirstW, Module32Next, Module32NextW, MoveFileA, MoveFileExA, MoveFileExW, MoveFileW, MoveFileWithProgressA, MoveFileWithProgressW, MulDiv, MultiByteToWideChar, NlsConvertIntegerToString, NlsGetCacheUpdateCount, NlsResetProcessLocale, NumaVirtualQueryNode, OpenConsoleW, OpenDataFile, OpenEventA, OpenEventW, OpenFile, OpenFileMappingA, OpenFileMappingW, OpenJobObjectA, OpenJobObjectW, OpenMutexA, OpenMutexW, OpenProcess, OpenProfileUserMapping, OpenSemaphoreA, OpenSemaphoreW, OpenThread, OpenWaitableTimerA, OpenWaitableTimerW, OutputDebugStringA, OutputDebugStringW, PeekConsoleInputA, PeekConsoleInputW, PeekNamedPipe, PostQueuedCompletionStatus, PrepareTape, PrivCopyFileExW, PrivMoveFileIdentityW, Process32First, Process32FirstW, Process32Next, Process32NextW, ProcessIdToSessionId, PulseEvent, PurgeComm, QueryActCtxW, QueryDepthSList, QueryDosDeviceA, QueryDosDeviceW, QueryInformationJobObject, QueryMemoryResourceNotification, QueryPerformanceCounter, QueryPerformanceFrequency, QueryWin31IniFilesMappedToRegistry, QueueUserAPC, QueueUserWorkItem, RaiseException, ReadConsoleA, ReadConsoleInputA, ReadConsoleInputExA, ReadConsoleInputExW, ReadConsoleInputW, ReadConsoleOutputA, ReadConsoleOutputAttribute, ReadConsoleOutputCharacterA, ReadConsoleOutputCharacterW, ReadConsoleOutputW, ReadConsoleW, ReadDirectoryChangesW, ReadFile, ReadFileEx, ReadFileScatter, ReadProcessMemory, RegisterConsoleIME, RegisterConsoleOS2, RegisterConsoleVDM, RegisterWaitForInputIdle, RegisterWaitForSingleObject, RegisterWaitForSingleObjectEx, RegisterWowBaseHandlers, RegisterWowExec, ReleaseActCtx, ReleaseMutex, ReleaseSemaphore, RemoveDirectoryA, RemoveDirectoryW, RemoveLocalAlternateComputerNameA, RemoveLocalAlternateComputerNameW, RemoveVectoredExceptionHandler, ReplaceFile, ReplaceFileA, ReplaceFileW, RequestDeviceWakeup, RequestWakeupLatency, ResetEvent, ResetWriteWatch, RestoreLastError, ResumeThread, RtlCaptureContext, RtlCaptureStackBackTrace, RtlFillMemory, RtlMoveMemory, RtlUnwind, RtlZeroMemory, ScrollConsoleScreenBufferA, ScrollConsoleScreenBufferW, SearchPathA, SearchPathW, SetCPGlobal, SetCalendarInfoA, SetCalendarInfoW, SetClientTimeZoneInformation, SetComPlusPackageInstallStatus, SetCommBreak, SetCommConfig, SetCommMask, SetCommState, SetCommTimeouts, SetComputerNameA, SetComputerNameExA, SetComputerNameExW, SetComputerNameW, SetConsoleActiveScreenBuffer, SetConsoleCP, SetConsoleCommandHistoryMode, SetConsoleCtrlHandler, SetConsoleCursor, SetConsoleCursorInfo, SetConsoleCursorMode, SetConsoleCursorPosition, SetConsoleDisplayMode, SetConsoleFont, SetConsoleHardwareState, SetConsoleIcon, SetConsoleInputExeNameA, SetConsoleInputExeNameW, SetConsoleKeyShortcuts, SetConsoleLocalEUDC, SetConsoleMaximumWindowSize, SetConsoleMenuClose, SetConsoleMode, SetConsoleNlsMode, SetConsoleNumberOfCommandsA, SetConsoleNumberOfCommandsW, SetConsoleOS2OemFormat, SetConsoleOutputCP, SetConsolePalette, SetConsoleScreenBufferSize, SetConsoleTextAttribute, SetConsoleTitleA, SetConsoleTitleW, SetConsoleWindowInfo, SetCriticalSectionSpinCount, SetCurrentDirectoryA, SetCurrentDirectoryW, SetDefaultCommConfigA, SetDefaultCommConfigW, SetDllDirectoryA, SetDllDirectoryW, SetEndOfFile, SetEnvironmentVariableA, SetEnvironmentVariableW, SetErrorMode, SetEvent, SetFileApisToANSI, SetFileApisToOEM, SetFileAttributesA, SetFileAttributesW, SetFilePointer, SetFilePointerEx, SetFileShortNameA, SetFileShortNameW, SetFileTime, SetFileValidData, SetFirmwareEnvironmentVariableA, SetFirmwareEnvironmentVariableW, SetHandleContext, SetHandleCount, SetHandleInformation, SetInformationJobObject, SetLastConsoleEventActive, SetLastError, SetLocalPrimaryComputerNameA, SetLocalPrimaryComputerNameW, SetLocalTime, SetLocaleInfoA, SetLocaleInfoW, SetMailslotInfo, SetMessageWaitingIndicator, SetNamedPipeHandleState, SetPriorityClass, SetProcessAffinityMask, SetProcessPriorityBoost, SetProcessShutdownParameters, SetProcessWorkingSetSize, SetStdHandle, SetSystemPowerState, SetSystemTime, SetSystemTimeAdjustment, SetTapeParameters, SetTapePosition, SetTermsrvAppInstallMode, SetThreadAffinityMask, SetThreadContext, SetThreadExecutionState, SetThreadIdealProcessor, SetThreadLocale, SetThreadPriority, SetThreadPriorityBoost, SetThreadUILanguage, SetTimeZoneInformation, SetTimerQueueTimer, SetUnhandledExceptionFilter, SetUserGeoID, SetVDMCurrentDirectories, SetVolumeLabelA, SetVolumeLabelW, SetVolumeMountPointA, SetVolumeMountPointW, SetWaitableTimer, SetupComm, ShowConsoleCursor, SignalObjectAndWait, SizeofResource, Sleep, SleepEx, SuspendThread, SwitchToFiber, SwitchToThread, SystemTimeToFileTime, SystemTimeToTzSpecificLocalTime, TerminateJobObject, TerminateProcess, TerminateThread, TermsrvAppInstallMode, Thread32First, Thread32Next, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, Toolhelp32ReadProcessMemory, TransactNamedPipe, TransmitCommChar, TrimVirtualBuffer, TryEnterCriticalSection, TzSpecificLocalTimeToSystemTime, UTRegister, UTUnRegister, UnhandledExceptionFilter, UnlockFile, UnlockFileEx, UnmapViewOfFile, UnregisterConsoleIME, UnregisterWait, UnregisterWaitEx, UpdateResourceA, UpdateResourceW, VDMConsoleOperation, VDMOperationStarted, ValidateLCType, ValidateLocale, VerLanguageNameA, VerLanguageNameW, VerSetConditionMask, VerifyConsoleIoHandle, VerifyVersionInfoA, VerifyVersionInfoW, VirtualAlloc, VirtualAllocEx, VirtualBufferExceptionHandler, VirtualFree, VirtualFreeEx, VirtualLock, VirtualProtect, VirtualProtectEx, VirtualQuery, VirtualQueryEx, VirtualUnlock, WTSGetActiveConsoleSessionId, WaitCommEvent, WaitForDebugEvent, WaitForMultipleObjects, WaitForMultipleObjectsEx, WaitForSingleObject, WaitForSingleObjectEx, WaitNamedPipeA, WaitNamedPipeW, WideCharToMultiByte, WinExec, WriteConsoleA, WriteConsoleInputA, WriteConsoleInputVDMA, WriteConsoleInputVDMW, WriteConsoleInputW, WriteConsoleOutputA, WriteConsoleOutputAttribute, WriteConsoleOutputCharacterA, WriteConsoleOutputCharacterW, WriteConsoleOutputW, WriteConsoleW, WriteFile, WriteFileEx, WriteFileGather, WritePrivateProfileSectionA, WritePrivateProfileSectionW, WritePrivateProfileStringA, WritePrivateProfileStringW, WritePrivateProfileStructA, WritePrivateProfileStructW, WriteProcessMemory, WriteProfileSectionA, WriteProfileSectionW, WriteProfileStringA, WriteProfileStringW, WriteTapemark, ZombifyActCtx, _hread, _hwrite, _lclose, _lcreat, _llseek, _lopen, _lread, _lwrite, lstrcat, lstrcatA, lstrcatW, lstrcmp, lstrcmpA, lstrcmpW, lstrcmpi, lstrcmpiA, lstrcmpiW, lstrcpy, lstrcpyA, lstrcpyW, lstrcpyn, lstrcpynA, lstrcpynW, lstrlen, lstrlenA, lstrlenW<BR>
    ThreatExpert info: &lt;a href='http://www.threatexpert.com/report.aspx?md5=a01f9ca902a88f7ced06884174d6419d' target='_blank'&gt;http://www.threatexpert.com/report.a...419d&lt;/a&gt;

    ========================================================================================

    "Thats all folks" - for now........................

  3. #13
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    OK, those appear to be fine.

    Open notepad and copy/paste the text in the codebox below into it:

    Code:
    File::
    c:\windows\system32\ce0a43a8bb.ax
    c:\windows\system32\lspvag.dll
    
    Folder::
    c:\documents and settings\Tim\Application Data\FrostWire
    c:\program files\uTorrent
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
    
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=-
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  4. #14
    Junior Member
    Join Date
    Mar 2009
    Posts
    21

    Post Next ComboFix log (after running script)

    ComboFix 09-03-06.02 - Tim 2009-03-07 18:58:37.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1385 [GMT 0:00]
    Running from: c:\documents and settings\Tim\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Tim\My Documents\Viruscure309\CFScript.txt
    AV: avast! antivirus 4.8.1229 [VPS 090306-0] *On-access scanning disabled* (Updated)
    * Created a new restore point

    FILE ::
    c:\windows\system32\ce0a43a8bb.ax
    c:\windows\system32\lspvag.dll
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Tim\Application Data\FrostWire
    c:\documents and settings\Tim\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
    c:\documents and settings\Tim\Application Data\FrostWire\checkandupdate.txt
    c:\documents and settings\Tim\Application Data\FrostWire\createtimes.cache
    c:\documents and settings\Tim\Application Data\FrostWire\downloads.dat
    c:\documents and settings\Tim\Application Data\FrostWire\fileurns.bak
    c:\documents and settings\Tim\Application Data\FrostWire\fileurns.cache
    c:\documents and settings\Tim\Application Data\FrostWire\filters.props
    c:\documents and settings\Tim\Application Data\FrostWire\frostwire.props
    c:\documents and settings\Tim\Application Data\FrostWire\gnutella.net
    c:\documents and settings\Tim\Application Data\FrostWire\installation.props
    c:\documents and settings\Tim\Application Data\FrostWire\intent.props
    c:\documents and settings\Tim\Application Data\FrostWire\library.dat
    c:\documents and settings\Tim\Application Data\FrostWire\mojito.props
    c:\documents and settings\Tim\Application Data\FrostWire\questions.props
    c:\documents and settings\Tim\Application Data\FrostWire\responses.cache
    c:\documents and settings\Tim\Application Data\FrostWire\simpp.xml
    c:\documents and settings\Tim\Application Data\FrostWire\six.exe
    c:\documents and settings\Tim\Application Data\FrostWire\spam.dat
    c:\documents and settings\Tim\Application Data\FrostWire\tables.props
    c:\documents and settings\Tim\Application Data\FrostWire\themes\frostwirePro_theme.fwtp
    c:\documents and settings\Tim\Application Data\FrostWire\themes\frostwirePro_theme\theme.txt
    c:\documents and settings\Tim\Application Data\FrostWire\themes\frostwirePro_theme\version.txt
    c:\documents and settings\Tim\Application Data\FrostWire\ttrees.cache
    c:\documents and settings\Tim\Application Data\FrostWire\ttroot.cache
    c:\documents and settings\Tim\Application Data\FrostWire\version.xml
    c:\documents and settings\Tim\Application Data\FrostWire\xml\data\audio.sxml2
    c:\documents and settings\Tim\Application Data\FrostWire\xml\data\video.sxml2
    c:\program files\uTorrent
    c:\program files\uTorrent\uTorrent.exe
    c:\windows\system32\ce0a43a8bb.ax
    c:\windows\system32\lspvag.dll

    .
    ((((((((((((((((((((((((( Files Created from 2009-02-07 to 2009-03-07 )))))))))))))))))))))))))))))))
    .

    2009-03-05 21:22 . 2009-03-05 21:22 <DIR> d-------- c:\program files\ERUNT
    2009-03-04 21:52 . 2009-03-04 21:52 5,120 --a------ c:\windows\system32\PerfStringBackup.TMP
    2009-03-03 18:28 . 2009-03-03 18:28 <DIR> d-------- C:\spoolerlogs
    2009-03-01 15:51 . 2009-03-01 15:51 <DIR> d-------- c:\documents and settings\Tim\Client Security Solution
    2009-03-01 13:25 . 2009-03-01 13:25 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2009-03-01 13:03 . 2009-03-01 13:03 <DIR> d-------- c:\documents and settings\Tim\Application Data\Malwarebytes
    2009-03-01 13:02 . 2009-03-01 13:02 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
    2009-03-01 13:02 . 2009-03-01 13:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-01 13:02 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-01 13:02 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2009-03-01 11:46 . 2009-03-01 11:46 <DIR> d-------- c:\program files\CCleaner
    2009-03-01 11:45 . 2009-03-01 12:27 <DIR> d-------- c:\program files\RogueRemover FREE
    2009-02-22 13:35 . 2009-02-22 13:36 <DIR> d-------- C:\dafa597003857db9f9e7da
    2009-02-22 13:34 . 2009-02-22 13:42 <DIR> d-------- c:\windows\system32\drivers\UMDF
    2009-02-20 20:37 . 2009-02-20 20:37 244 --ah----- C:\sqmnoopt01.sqm
    2009-02-20 20:37 . 2009-02-20 20:37 244 --ah----- C:\sqmnoopt00.sqm
    2009-02-20 20:37 . 2009-02-20 20:37 232 --ah----- C:\sqmdata01.sqm
    2009-02-20 20:37 . 2009-02-20 20:37 232 --ah----- C:\sqmdata00.sqm
    2009-02-12 20:06 . 2009-02-12 20:06 <DIR> d-------- c:\windows\SQLTools9_KB960089_ENU
    2009-02-12 20:01 . 2009-02-12 20:01 <DIR> d-------- c:\windows\SQL9_KB960089_ENU

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-05 22:07 --------- d-----w c:\program files\a-squared Free
    2009-03-05 20:41 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-03-05 20:39 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-03-05 20:39 --------- d-----w c:\program files\SpywareBlaster
    2009-03-05 20:17 --------- d-----w c:\program files\Spybot
    2009-03-05 04:28 --------- d-----w c:\documents and settings\Administrator\Application Data\InstallShield
    2009-03-04 21:55 --------- d--h--w c:\program files\InstallShield Installation Information
    2009-03-04 21:53 --------- d-----w c:\program files\CONEXANT
    2009-03-04 21:52 --------- d-----w c:\program files\Common Files\Nikon
    2009-03-04 21:42 --------- d-----w c:\program files\Windows Media Connect 2
    2009-03-04 21:42 --------- d-----w c:\program files\NetWaiting
    2009-03-04 21:41 --------- d-----w c:\program files\Digital Line Detect
    2009-03-04 21:41 --------- d-----w c:\program files\Common Files\SureThing Shared
    2009-03-04 21:41 --------- d-----w c:\program files\Common Files\snp2uvc
    2009-03-04 21:40 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-03-04 21:36 --------- d-----w c:\program files\WinTV
    2009-03-04 21:36 --------- d-----w c:\program files\vtplus
    2009-03-04 21:36 --------- d-----w c:\program files\PTLens
    2009-03-04 21:36 --------- d-----w c:\program files\Network Stumbler
    2009-03-04 21:36 --------- d-----w c:\program files\Mp3TagToolsv12
    2009-03-04 21:36 --------- d-----w c:\program files\Microsoft Works
    2009-03-04 21:35 --------- d-----w c:\program files\Microsoft ActiveSync
    2009-03-04 21:35 --------- d-----w c:\program files\Dan Elwell's Broadband Speed Test
    2009-03-04 21:34 --------- d-----w c:\program files\cdex_151
    2009-03-04 21:34 --------- d-----w c:\program files\Bonjour
    2009-03-04 21:34 --------- d-----w c:\program files\Better File Rename
    2009-03-04 21:32 --------- d-----w c:\program files\Dicom viewer
    2009-03-04 21:32 --------- d-----w c:\program files\7-Zip
    2009-03-04 21:32 --------- d-----w c:\documents and settings\Tim\Application Data\OfficeUpdate12
    2009-03-04 21:31 --------- d-----w c:\program files\TomTom HOME 2
    2009-03-04 21:31 --------- d-----w c:\program files\Kontiki
    2009-03-04 21:30 --------- d-----w c:\documents and settings\Tim\Application Data\uTorrent
    2009-03-04 21:30 --------- d-----w c:\documents and settings\All Users\Application Data\Lenovo
    2009-03-04 21:30 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
    2009-02-25 22:24 --------- d-----w c:\program files\Microsoft Silverlight
    2009-02-04 11:05 --------- d-----w c:\program files\FrostWire
    2009-02-01 13:29 --------- d-----w c:\program files\Windows Live Safety Center
    2009-01-20 11:54 --------- d-----w c:\documents and settings\Tim\Application Data\Microsoft Games
    2009-01-20 11:49 --------- d-----w c:\program files\Microsoft Games
    2009-01-20 10:20 --------- d-----w c:\program files\Common Files\Windows Live
    2009-01-19 21:44 --------- d-----w c:\program files\American Conquest
    2008-10-20 10:15 604 ---ha-w c:\program files\STLL Notifier
    2008-10-11 09:46 0 ---ha-w c:\documents and settings\All Users\Application Data\PKP_DLbz.DAT
    2008-03-12 06:07 32,768 --sh--w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
    2008-05-09 06:58 32,768 --sh--w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050820080509\index.dat
    2008-05-09 07:07 32,768 --sh--w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050920080510\index.dat
    2008-09-21 22:18 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092120080922\index.dat
    2008-10-11 09:35 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101120081012\index.dat
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-03-07_15.07.02.90 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2007-07-31 02:18:40 33,624 ------w c:\windows\system32\dllcache\wups.dll
    + 2008-10-16 14:08:58 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
    - 2007-07-31 02:18:40 33,624 ------w c:\windows\system32\wups.dll
    + 2008-10-16 14:08:58 34,328 ----a-w c:\windows\system32\wups.dll
    - 2007-07-31 02:19:12 43,352 ------w c:\windows\system32\wups2.dll
    + 2008-10-16 14:09:44 43,544 ----a-w c:\windows\system32\wups2.dll
    + 2009-03-07 19:03:34 16,384 ----atw c:\windows\temp\Perflib_Perfdata_244.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-06-10 311296]
    "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2008-06-10 208896]
    "TPFNF7"="c:\progra~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-03-26 59680]
    "TrackPointSrv"="c:\program files\Lenovo\TrackPoint\tp4serv.exe" [2008-03-04 92960]
    "TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 66928]
    "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-06-05 242976]
    "TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
    "AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
    "AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 419376]
    "LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [2007-07-12 124256]
    "cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2007-08-03 2630968]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
    "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-05 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-05 166424]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-05 137752]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-13 185632]
    "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
    "TpShocks"="TpShocks.exe" [2008-06-06 c:\windows\system32\TpShocks.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
    "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
    2006-09-06 15:37 34344 c:\program files\Lenovo\HOTKEY\notifyf2.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
    2007-12-14 15:36 28672 c:\program files\Lenovo\HOTKEY\tphklock.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
    2008-07-04 23:57 32768 c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ scecli ACGina

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    "DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Kontiki\\KService.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "20001:UDP"= 20001:UDP:MicroSAN
    "80:TCP"= 80:TCP:Web

    R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2008-05-14 114728]
    R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-05-14 19496]
    R0 ZetSFD;ZetSFD;c:\windows\system32\drivers\ZetSFD.sys [2008-05-08 12800]
    R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2008-03-12 11520]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-08 78416]
    R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2008-03-12 4224]
    R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2008-03-12 4442]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-05-08 20560]
    R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 29183504]
    R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [2008-08-10 94208]
    R2 SFSZ;DataPlow SFS for Zetera Storage Devices;c:\windows\system32\drivers\sfsz.sys [2008-05-08 345984]
    R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-07-12 569344]
    R2 Z-SANService;Z-SAN Service;c:\program files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe [2008-05-08 376891]
    R3 Tp4Track;PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [2007-05-10 22568]
    R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-05-22 30336]
    R3 ZetBus;Zetera Virtual Bus;c:\windows\system32\drivers\ZetBus.sys [2008-05-08 15488]
    R3 ZetMPD;ZetMPD;c:\windows\system32\drivers\ZetMPD.sys [2008-05-08 5120]
    S3 RDID1057;EDIROL UA-1EX;c:\windows\system32\drivers\Rdwm1057.sys [2008-05-11 139905]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bcd9601b-4f6d-11dd-b392-001cbfaf2eb9}]
    \Shell\AutoRun\command - J:\InstallTomTomHOME.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-07 c:\windows\Tasks\PMTask.job
    - c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-06-10 00:40]

    2009-02-28 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
    - c:\program files\Spybot\SpybotSD.exe [2009-01-26 15:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.co.uk/
    uInternet Settings,ProxyOverride = *.local
    IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} - file:///H:/Dicom%20viewer/CDVIEWER/CdViewer.cab
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-07 19:14:30
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1336)
    c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
    c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
    c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
    c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
    c:\program files\Lenovo\HOTKEY\tphklock.dll

    - - - - - - - > 'lsass.exe'(1392)
    c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
    c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
    c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
    c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
    c:\program files\ThinkPad\ConnectUtilities\ACON.dll
    c:\program files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
    c:\program files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
    c:\program files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
    c:\program files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
    c:\program files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\ibmpmsvc.exe
    c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\windows\system32\brss01a.exe
    c:\windows\system32\IPSSVC.EXE
    c:\program files\a-squared Free\a2service.exe
    c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
    c:\windows\system32\PSIService.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    c:\windows\system32\TPHDEXLG.exe
    c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
    c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
    c:\program files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    c:\windows\system32\wdfmgr.exe
    c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
    c:\program files\Lenovo\System Update\SUService.exe
    c:\program files\Common Files\Lenovo\Logger\logmon.exe
    c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    c:\windows\system32\igfxext.exe
    c:\windows\system32\igfxsrvc.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Lenovo\HOTKEY\TPONSCR.exe
    c:\program files\Lenovo\ZOOM\TpScrex.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\taskmgr.exe
    .
    **************************************************************************
    .
    Completion time: 2009-03-07 19:19:53 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-03-07 19:19:50
    ComboFix2.txt 2009-03-07 15:08:17

    Pre-Run: 13,602,119,680 bytes free
    Post-Run: 13,589,676,032 bytes free

    307

  5. #15
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please post also a fresh hijackthis log
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #16
    Junior Member
    Join Date
    Mar 2009
    Posts
    21

    Default Fresh HijackThis Log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:37:12, on 07/03/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\PSIService.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\WINDOWS\System32\TPHDEXLG.exe
    C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
    C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    C:\Program Files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe
    C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    c:\program files\lenovo\system update\suservice.exe
    C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
    C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe
    C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
    C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Lenovo\Zoom\TpScrex.exe
    C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
    C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcrobatInfo.exe
    C:\Documents and Settings\Tim\My Documents\Viruscure309\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TPFNF7] C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe /r
    O4 - HKLM\..\Run: [TrackPointSrv] C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1210274366609
    O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///H:/Dicom%20viewer/CDVIEWER/CdViewer.cab
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
    O23 - Service: Power Manager DBC Service - Unknown owner - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
    O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
    O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
    O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    O23 - Service: Z-SAN Service (Z-SANService) - Zetera Corporation - C:\Program Files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe

    --
    End of file - 14120 bytes

  7. #17
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Open notepad and copy/paste the text in the codebox below into it:

    Code:
    Folder::
    c:\documents and settings\Tim\Application Data\uTorrent
    c:\program files\FrostWire
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #18
    Junior Member
    Join Date
    Mar 2009
    Posts
    21

    Default Next log from combofix - HJ next.....

    ComboFix 09-03-06.02 - Tim 2009-03-07 20:12:25.3 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1346 [GMT 0:00]
    Running from: c:\documents and settings\Tim\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Tim\My Documents\Viruscure309\CFScript.txt
    AV: avast! antivirus 4.8.1229 [VPS 090306-0] *On-access scanning disabled* (Updated)
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Tim\Application Data\uTorrent
    c:\documents and settings\Tim\Application Data\uTorrent\Adobe Acrobat 8 Professional.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Adobe lightbox.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Adobe Photoshop CS3 Extended + Crack.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\dht.dat
    c:\documents and settings\Tim\Application Data\uTorrent\dht.dat.old
    c:\documents and settings\Tim\Application Data\uTorrent\Dragon_Naturally_Speaking_v9_2CDs.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Dragon_NaturallySpeaking_Preferred_10_original_no-serial.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Garmin Mapsource Topo GB v2 [RAGDOLL].torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Garmin Mapsource Topo Great Britain v2 [FULL] by RAGDOLL.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Guitar Pro 5.2 + complete RSE packs.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Guitar Pro 5.2 Incl Key (with complete RSE packs).torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Leadtools.Package.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Pendulum - 2005 - Hold Your Colour [FLAC].torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Pendulum - In Silico (2008).1.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Pendulum - In Silico (2008).torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Pendulum - In Silico FLAC (2008 ).torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Pendulum - In Silico.1.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Pendulum - In Silico.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Pendulum -Hold Your Colour[KRG] gadge007.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\PowerISO.v4.1.Incl.Keymaker-AGAiN.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\resume.dat
    c:\documents and settings\Tim\Application Data\uTorrent\resume.dat.old
    c:\documents and settings\Tim\Application Data\uTorrent\rss.dat
    c:\documents and settings\Tim\Application Data\uTorrent\rss.dat.old
    c:\documents and settings\Tim\Application Data\uTorrent\settings.dat
    c:\documents and settings\Tim\Application Data\uTorrent\settings.dat.old
    c:\documents and settings\Tim\Application Data\uTorrent\Sex.and.the.City.The Movie.XviD-DiAMOND.avi.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Sex.and.the.City.The.Movie.2008.TS.ENG.XViD-TFE.avi.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Sex.And.The.City.TS.PROPER.XViD-nDn.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Sibelius 5 Hybrid DVD (working keygen).rar.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Sibelius 5.1 English.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Sibelius 5.2 Update for Windows - from Sibelius 5.1.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Sibelius.Software.Sibelius.v5.0.HYBRID.DVDR-DYNAMiCS.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Simpsons Season 13 - Complete [rl].torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Sony.Soundforge.8.Inc.Keygen.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\TomTom Mobile Navigator v6.010 & Maps of Western Europe [Multilanguage XScale WM2003][www.torrentspain.com].nrg.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Tomtom_V660_Maps.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Ultimate boot DVD Windows XP Pro-Home Editions SP3 Retail-Corporate X86 (8 in 1).torrent
    c:\documents and settings\Tim\Application Data\uTorrent\utorrent.lng
    c:\documents and settings\Tim\Application Data\uTorrent\Vista_Recovery_Disc.iso.torrent
    c:\documents and settings\Tim\Application Data\uTorrent\Windows XP Home Edition with Service Pack 3 Retail (x86) Original.torrent
    c:\program files\FrostWire
    c:\program files\FrostWire\aopalliance.jar
    c:\program files\FrostWire\clink.jar
    c:\program files\FrostWire\commons-codec-1.3.jar
    c:\program files\FrostWire\commons-logging.jar
    c:\program files\FrostWire\daap.jar
    c:\program files\FrostWire\EULA.txt
    c:\program files\FrostWire\forms.jar
    c:\program files\FrostWire\foxtrot.jar
    c:\program files\FrostWire\FrostWire.exe
    c:\program files\FrostWire\FrostWire.ico
    c:\program files\FrostWire\FrostWire.jar
    c:\program files\FrostWire\gettext-commons.jar
    c:\program files\FrostWire\GPL2.txt
    c:\program files\FrostWire\guice-1.0.jar
    c:\program files\FrostWire\hashes
    c:\program files\FrostWire\httpclient-4.0-alpha3.jar
    c:\program files\FrostWire\httpcore-4.0-beta2.jar
    c:\program files\FrostWire\httpcore-nio-4.0-beta2.jar
    c:\program files\FrostWire\httpcore-niossl-4.0-alpha7.jar
    c:\program files\FrostWire\icu4j.jar
    c:\program files\FrostWire\inspection.props
    c:\program files\FrostWire\jaudiotagger.jar
    c:\program files\FrostWire\jcraft.jar
    c:\program files\FrostWire\jdic.dll
    c:\program files\FrostWire\jdic.jar
    c:\program files\FrostWire\jdic_stub.jar
    c:\program files\FrostWire\jflac.jar
    c:\program files\FrostWire\jl.jar
    c:\program files\FrostWire\jmdns.jar
    c:\program files\FrostWire\jogg.jar
    c:\program files\FrostWire\jorbis.jar
    c:\program files\FrostWire\jython.jar
    c:\program files\FrostWire\launch.properties
    c:\program files\FrostWire\log.txt
    c:\program files\FrostWire\log4j.jar
    c:\program files\FrostWire\log4j.properties
    c:\program files\FrostWire\looks.jar
    c:\program files\FrostWire\lw-all.jar
    c:\program files\FrostWire\messages.jar
    c:\program files\FrostWire\mp3spi.jar
    c:\program files\FrostWire\onion-common.jar
    c:\program files\FrostWire\onion-fec.jar
    c:\program files\FrostWire\pmf.ico
    c:\program files\FrostWire\ProgressTabs.jar
    c:\program files\FrostWire\seenMessages.dat
    c:\program files\FrostWire\SystemUtilities.dll
    c:\program files\FrostWire\SystemUtilitiesA.dll
    c:\program files\FrostWire\themes.jar
    c:\program files\FrostWire\tray.dll
    c:\program files\FrostWire\tritonus.jar
    c:\program files\FrostWire\Uninstall.exe
    c:\program files\FrostWire\vorbisspi.jar

    .
    ((((((((((((((((((((((((( Files Created from 2009-02-07 to 2009-03-07 )))))))))))))))))))))))))))))))
    .

    2009-03-07 20:01 . 2009-03-07 20:08 1,355 --a------ c:\windows\imsins.BAK
    2009-03-05 21:22 . 2009-03-05 21:22 <DIR> d-------- c:\program files\ERUNT
    2009-03-04 21:52 . 2009-03-04 21:52 5,120 --a------ c:\windows\system32\PerfStringBackup.TMP
    2009-03-03 18:28 . 2009-03-03 18:28 <DIR> d-------- C:\spoolerlogs
    2009-03-01 15:51 . 2009-03-01 15:51 <DIR> d-------- c:\documents and settings\Tim\Client Security Solution
    2009-03-01 13:25 . 2009-03-01 13:25 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2009-03-01 13:03 . 2009-03-01 13:03 <DIR> d-------- c:\documents and settings\Tim\Application Data\Malwarebytes
    2009-03-01 13:02 . 2009-03-01 13:02 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
    2009-03-01 13:02 . 2009-03-01 13:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-01 13:02 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-01 13:02 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2009-03-01 11:46 . 2009-03-01 11:46 <DIR> d-------- c:\program files\CCleaner
    2009-03-01 11:45 . 2009-03-01 12:27 <DIR> d-------- c:\program files\RogueRemover FREE
    2009-02-22 13:35 . 2009-02-22 13:36 <DIR> d-------- C:\dafa597003857db9f9e7da
    2009-02-22 13:34 . 2009-02-22 13:42 <DIR> d-------- c:\windows\system32\drivers\UMDF
    2009-02-20 20:37 . 2009-02-20 20:37 244 --ah----- C:\sqmnoopt01.sqm
    2009-02-20 20:37 . 2009-02-20 20:37 244 --ah----- C:\sqmnoopt00.sqm
    2009-02-20 20:37 . 2009-02-20 20:37 232 --ah----- C:\sqmdata01.sqm
    2009-02-20 20:37 . 2009-02-20 20:37 232 --ah----- C:\sqmdata00.sqm
    2009-02-12 20:06 . 2009-02-12 20:06 <DIR> d-------- c:\windows\SQLTools9_KB960089_ENU
    2009-02-12 20:01 . 2009-02-12 20:01 <DIR> d-------- c:\windows\SQL9_KB960089_ENU

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-05 22:07 --------- d-----w c:\program files\a-squared Free
    2009-03-05 20:41 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-03-05 20:39 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-03-05 20:39 --------- d-----w c:\program files\SpywareBlaster
    2009-03-05 20:17 --------- d-----w c:\program files\Spybot
    2009-03-05 04:28 --------- d-----w c:\documents and settings\Administrator\Application Data\InstallShield
    2009-03-04 21:55 --------- d--h--w c:\program files\InstallShield Installation Information
    2009-03-04 21:53 --------- d-----w c:\program files\CONEXANT
    2009-03-04 21:52 --------- d-----w c:\program files\Common Files\Nikon
    2009-03-04 21:42 --------- d-----w c:\program files\Windows Media Connect 2
    2009-03-04 21:42 --------- d-----w c:\program files\NetWaiting
    2009-03-04 21:41 --------- d-----w c:\program files\Digital Line Detect
    2009-03-04 21:41 --------- d-----w c:\program files\Common Files\SureThing Shared
    2009-03-04 21:41 --------- d-----w c:\program files\Common Files\snp2uvc
    2009-03-04 21:40 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-03-04 21:36 --------- d-----w c:\program files\WinTV
    2009-03-04 21:36 --------- d-----w c:\program files\vtplus
    2009-03-04 21:36 --------- d-----w c:\program files\PTLens
    2009-03-04 21:36 --------- d-----w c:\program files\Network Stumbler
    2009-03-04 21:36 --------- d-----w c:\program files\Mp3TagToolsv12
    2009-03-04 21:36 --------- d-----w c:\program files\Microsoft Works
    2009-03-04 21:35 --------- d-----w c:\program files\Microsoft ActiveSync
    2009-03-04 21:35 --------- d-----w c:\program files\Dan Elwell's Broadband Speed Test
    2009-03-04 21:34 --------- d-----w c:\program files\cdex_151
    2009-03-04 21:34 --------- d-----w c:\program files\Bonjour
    2009-03-04 21:34 --------- d-----w c:\program files\Better File Rename
    2009-03-04 21:32 --------- d-----w c:\program files\Dicom viewer
    2009-03-04 21:32 --------- d-----w c:\program files\7-Zip
    2009-03-04 21:32 --------- d-----w c:\documents and settings\Tim\Application Data\OfficeUpdate12
    2009-03-04 21:31 --------- d-----w c:\program files\TomTom HOME 2
    2009-03-04 21:31 --------- d-----w c:\program files\Kontiki
    2009-03-04 21:30 --------- d-----w c:\documents and settings\All Users\Application Data\Lenovo
    2009-03-04 21:30 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
    2009-02-25 22:24 --------- d-----w c:\program files\Microsoft Silverlight
    2009-02-01 13:29 --------- d-----w c:\program files\Windows Live Safety Center
    2009-01-20 11:54 --------- d-----w c:\documents and settings\Tim\Application Data\Microsoft Games
    2009-01-20 11:49 --------- d-----w c:\program files\Microsoft Games
    2009-01-20 10:20 --------- d-----w c:\program files\Common Files\Windows Live
    2009-01-19 21:44 --------- d-----w c:\program files\American Conquest
    2008-10-20 10:15 604 ---ha-w c:\program files\STLL Notifier
    2008-10-11 09:46 0 ---ha-w c:\documents and settings\All Users\Application Data\PKP_DLbz.DAT
    2008-03-12 06:07 32,768 --sh--w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
    2008-05-09 06:58 32,768 --sh--w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050820080509\index.dat
    2008-05-09 07:07 32,768 --sh--w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050920080510\index.dat
    2008-09-21 22:18 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092120080922\index.dat
    2008-10-11 09:35 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101120081012\index.dat
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-03-07_15.07.02.90 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-10-03 09:57:49 247,326 ----a-w c:\windows\$hf_mig$\KB954600\SP2QFE\strmdll.dll
    + 2008-10-03 10:02:42 247,326 ----a-w c:\windows\$hf_mig$\KB954600\SP3GDR\strmdll.dll
    + 2008-09-04 16:32:52 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP2QFE\msxml3.dll
    + 2008-09-04 17:15:04 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3GDR\msxml3.dll
    + 2008-10-22 09:47:25 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP2QFE\tzchange.exe
    + 2008-10-23 10:06:59 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3GDR\tzchange.exe
    + 2008-10-23 12:36:14 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3GDR\gdi32.dll
    + 2008-08-14 10:04:36 138,496 ----a-w c:\windows\$hf_mig$\KB956803\SP3GDR\afd.sys
    + 2008-08-14 10:09:26 2,145,280 ----a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlmp.exe
    + 2008-08-14 09:33:16 2,066,048 ----a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
    + 2008-08-14 09:33:16 2,023,936 ----a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrpamp.exe
    + 2008-08-14 10:11:02 2,189,184 ----a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
    + 2008-10-24 11:25:29 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP2QFE\mrxsmb.sys
    + 2008-10-24 11:21:09 455,296 ----a-w c:\windows\$hf_mig$\KB957097\SP3GDR\mrxsmb.sys
    + 2008-10-15 16:53:28 339,456 ----a-w c:\windows\$hf_mig$\KB958644\SP2QFE\netapi32.dll
    + 2008-10-15 16:34:24 337,408 ----a-w c:\windows\$hf_mig$\KB958644\SP3GDR\netapi32.dll
    + 2008-12-11 10:24:44 333,184 ----a-w c:\windows\$hf_mig$\KB958687\SP2QFE\srv.sys
    + 2008-12-11 10:57:09 333,952 ----a-w c:\windows\$hf_mig$\KB958687\SP3GDR\srv.sys
    + 2008-06-17 19:02:19 8,461,312 ----a-w c:\windows\$hf_mig$\KB967715\SP3GDR\shell32.dll
    + 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB938464$\spcustom.dll
    + 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB938464$\spmsg.dll
    + 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB938464$\spuninst.exe
    + 2007-11-30 11:20:44 755,576 -c----w c:\windows\$NtUninstallKB938464$\update.exe
    + 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB938464$\updspapi.dll
    + 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB946648$\spcustom.dll
    + 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB946648$\spmsg.dll
    + 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB946648$\spuninst.exe
    + 2007-11-30 11:20:44 755,576 -c----w c:\windows\$NtUninstallKB946648$\update.exe
    + 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB946648$\updspapi.dll
    + 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB950974$\spcustom.dll
    + 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB950974$\spmsg.dll
    + 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB950974$\spuninst.exe
    + 2007-11-30 12:39:18 755,576 -c----w c:\windows\$NtUninstallKB950974$\update.exe
    + 2007-11-30 12:39:19 382,840 -c----w c:\windows\$NtUninstallKB950974$\updspapi.dll
    + 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB951066$\spcustom.dll
    + 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB951066$\spmsg.dll
    + 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB951066$\spuninst.exe
    + 2007-12-03 15:25:31 755,576 -c----w c:\windows\$NtUninstallKB951066$\update.exe
    + 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB951066$\updspapi.dll
    + 2007-11-30 11:18:51 26,488 -c----w c:\windows\$NtUninstallKB952287$\spcustom.dll
    + 2007-11-30 11:18:51 17,272 -c----w c:\windows\$NtUninstallKB952287$\spmsg.dll
    + 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB952287$\spuninst.exe
    + 2007-11-30 11:18:51 755,576 -c----w c:\windows\$NtUninstallKB952287$\update.exe
    + 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB952287$\updspapi.dll
    + 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB952954$\spcustom.dll
    + 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB952954$\spmsg.dll
    + 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB952954$\spuninst.exe
    + 2007-11-30 12:39:22 755,576 -c----w c:\windows\$NtUninstallKB952954$\update.exe
    + 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB952954$\updspapi.dll
    + 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB954600$\spcustom.dll
    + 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB954600$\spmsg.dll
    + 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB954600$\spuninst.exe
    - 2008-04-14 00:12:07 246,814 -c----w c:\windows\$NtUninstallKB954600$\strmdll.dll
    + 2006-08-21 08:52:08 246,814 -c----w c:\windows\$NtUninstallKB954600$\strmdll.dll
    + 2007-11-30 11:18:51 755,576 -c----w c:\windows\$NtUninstallKB954600$\update.exe
    + 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB954600$\updspapi.dll
    - 2008-04-14 00:12:01 1,104,896 -c----w c:\windows\$NtUninstallKB955069$\msxml3.dll
    + 2007-06-26 06:08:16 1,104,896 -c----w c:\windows\$NtUninstallKB955069$\msxml3.dll
    + 2007-11-30 11:18:51 26,488 -c----w c:\windows\$NtUninstallKB955069$\spcustom.dll
    + 2007-11-30 11:18:51 17,272 -c----w c:\windows\$NtUninstallKB955069$\spmsg.dll
    + 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB955069$\spuninst.exe
    + 2007-11-30 11:18:51 755,576 -c----w c:\windows\$NtUninstallKB955069$\update.exe
    + 2008-07-09 13:08:38 382,840 -c----w c:\windows\$NtUninstallKB955069$\updspapi.dll
    + 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB955839$\spcustom.dll
    + 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB955839$\spmsg.dll
    + 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB955839$\spuninst.exe
    - 2008-04-14 00:12:38 60,416 -c----w c:\windows\$NtUninstallKB955839$\tzchange.exe
    + 2007-11-13 11:31:11 60,416 -c----w c:\windows\$NtUninstallKB955839$\tzchange.exe
    + 2007-11-30 12:39:22 755,576 -c----w c:\windows\$NtUninstallKB955839$\update.exe
    + 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB955839$\updspapi.dll
    - 2008-04-14 00:11:54 285,184 -c----w c:\windows\$NtUninstallKB956802$\gdi32.dll
    + 2008-02-20 06:52:43 282,624 -c----w c:\windows\$NtUninstallKB956802$\gdi32.dll
    + 2008-07-08 13:02:01 26,488 -c----w c:\windows\$NtUninstallKB956802$\spcustom.dll
    + 2008-07-08 13:02:01 17,272 -c----w c:\windows\$NtUninstallKB956802$\spmsg.dll
    + 2008-07-08 13:02:02 231,288 -c----w c:\windows\$NtUninstallKB956802$\spuninst.exe
    + 2008-07-09 07:38:29 755,576 -c----w c:\windows\$NtUninstallKB956802$\update.exe
    + 2008-07-09 07:38:37 382,840 -c----w c:\windows\$NtUninstallKB956802$\updspapi.dll
    - 2008-06-20 11:40:08 138,496 -c----w c:\windows\$NtUninstallKB956803$\afd.sys
    + 2008-06-20 10:44:08 138,368 -c----w c:\windows\$NtUninstallKB956803$\afd.sys
    + 2007-11-30 11:18:51 26,488 -c----w c:\windows\$NtUninstallKB956803$\spcustom.dll
    + 2007-11-30 11:18:51 17,272 -c----w c:\windows\$NtUninstallKB956803$\spmsg.dll
    + 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB956803$\spuninst.exe
    + 2007-11-30 11:18:51 755,576 -c----w c:\windows\$NtUninstallKB956803$\update.exe
    + 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB956803$\updspapi.dll
    + 2007-02-28 09:53:04 2,137,600 -c----w c:\windows\$NtUninstallKB956841$\ntkrnlmp.exe
    - 2008-04-13 18:31:21 2,023,936 -c----w c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
    + 2007-02-28 09:15:59 2,017,280 -c----w c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
    + 2007-02-28 09:15:59 2,017,280 -c----w c:\windows\$NtUninstallKB956841$\ntkrpamp.exe
    - 2008-04-13 19:24:37 2,145,280 -c----w c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
    + 2007-02-28 09:53:04 2,137,600 -c----w c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
    + 2007-11-30 11:18:51 26,488 -c----w c:\windows\$NtUninstallKB956841$\spcustom.dll
    + 2007-11-30 11:18:51 17,272 -c----w c:\windows\$NtUninstallKB956841$\spmsg.dll
    + 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB956841$\spuninst.exe
    + 2007-11-30 11:18:51 755,576 -c----w c:\windows\$NtUninstallKB956841$\update.exe
    + 2008-07-09 07:38:37 382,840 -c----w c:\windows\$NtUninstallKB956841$\updspapi.dll
    - 2008-04-13 19:17:01 456,576 -c----w c:\windows\$NtUninstallKB957097$\mrxsmb.sys
    + 2006-05-05 09:41:45 453,120 -c----w c:\windows\$NtUninstallKB957097$\mrxsmb.sys
    + 2008-07-08 13:02:01 26,488 -c----w c:\windows\$NtUninstallKB957097$\spcustom.dll
    + 2008-07-08 13:02:01 17,272 -c----w c:\windows\$NtUninstallKB957097$\spmsg.dll
    + 2008-07-08 13:02:02 231,288 -c----w c:\windows\$NtUninstallKB957097$\spuninst.exe
    + 2008-07-08 13:02:04 755,576 -c----w c:\windows\$NtUninstallKB957097$\update.exe
    + 2008-07-08 13:02:12 382,840 -c----w c:\windows\$NtUninstallKB957097$\updspapi.dll
    - 2008-04-14 00:12:01 337,408 -c----w c:\windows\$NtUninstallKB958644$\netapi32.dll
    + 2006-08-17 12:28:27 332,288 -c----w c:\windows\$NtUninstallKB958644$\netapi32.dll
    + 2007-11-30 11:18:51 26,488 -c----w c:\windows\$NtUninstallKB958644$\spcustom.dll
    + 2007-11-30 11:18:51 17,272 -c----w c:\windows\$NtUninstallKB958644$\spmsg.dll
    + 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB958644$\spuninst.exe
    + 2007-11-30 11:18:51 755,576 -c----w c:\windows\$NtUninstallKB958644$\update.exe
    + 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB958644$\updspapi.dll
    + 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB958687$\spcustom.dll
    + 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB958687$\spmsg.dll
    + 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB958687$\spuninst.exe
    - 2008-09-08 10:41:42 333,824 -c----w c:\windows\$NtUninstallKB958687$\srv.sys
    + 2006-08-14 10:34:41 332,928 -c----w c:\windows\$NtUninstallKB958687$\srv.sys
    + 2007-11-30 11:18:51 755,576 -c----w c:\windows\$NtUninstallKB958687$\update.exe
    + 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB958687$\updspapi.dll
    + 2008-07-09 07:38:24 26,488 -c----w c:\windows\$NtUninstallKB960715$\spcustom.dll
    + 2008-07-09 07:38:24 17,272 -c----w c:\windows\$NtUninstallKB960715$\spmsg.dll
    + 2008-07-09 07:38:25 231,288 -c----w c:\windows\$NtUninstallKB960715$\spuninst.exe
    + 2008-11-15 17:18:04 755,576 -c----w c:\windows\$NtUninstallKB960715$\update.exe
    + 2008-07-09 07:38:37 382,840 -c----w c:\windows\$NtUninstallKB960715$\updspapi.dll
    - 2008-04-14 00:12:05 8,461,312 -c----w c:\windows\$NtUninstallKB967715$\shell32.dll
    + 2007-10-26 03:34:01 8,460,288 -c----w c:\windows\$NtUninstallKB967715$\shell32.dll
    + 2008-07-09 07:38:24 26,488 -c----w c:\windows\$NtUninstallKB967715$\spcustom.dll
    + 2008-07-09 07:38:24 17,272 -c----w c:\windows\$NtUninstallKB967715$\spmsg.dll
    + 2008-07-09 07:38:25 231,288 -c----w c:\windows\$NtUninstallKB967715$\spuninst.exe
    + 2008-07-09 07:38:29 755,576 -c----w c:\windows\$NtUninstallKB967715$\update.exe
    + 2008-07-09 07:38:37 382,840 -c----w c:\windows\$NtUninstallKB967715$\updspapi.dll
    + 2007-10-29 10:04:03 350,720 -c----w c:\windows\$NtUninstallKB967715$\xpsp3res.dll
    - 2006-05-05 09:41:45 453,120 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
    + 2008-10-24 11:10:42 453,632 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
    - 2007-02-28 09:53:04 2,137,600 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
    + 2008-08-14 09:55:01 2,142,720 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
    - 2007-02-28 09:15:56 2,059,392 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
    + 2008-08-14 09:18:44 2,062,976 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
    - 2007-02-28 09:15:59 2,017,280 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
    + 2008-08-14 09:18:46 2,020,864 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
    - 2007-02-28 09:55:14 2,182,144 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
    + 2008-08-14 09:57:20 2,185,984 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
    - 2008-10-16 20:38:34 124,928 -c----w c:\windows\ie7updates\KB961260-IE7\advpack.dll
    + 2008-04-23 04:16:28 124,928 -c----w c:\windows\ie7updates\KB961260-IE7\advpack.dll
    - 2008-10-16 20:38:34 347,136 -c----w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
    + 2008-04-23 04:16:28 347,136 -c----w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
    - 2008-10-16 20:38:34 214,528 -c----w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
    + 2008-04-23 04:16:28 214,528 -c----w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
    - 2008-10-16 20:38:35 133,120 -c----w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
    + 2008-04-23 04:16:28 133,120 -c----w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
    - 2008-10-16 20:38:35 63,488 -c----w c:\windows\ie7updates\KB961260-IE7\icardie.dll
    + 2008-04-23 04:16:28 63,488 -c----w c:\windows\ie7updates\KB961260-IE7\icardie.dll
    - 2008-10-16 13:11:09 70,656 -c----w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
    + 2008-04-22 07:39:58 70,656 -c----w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
    - 2008-10-16 20:38:35 153,088 -c----w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
    + 2008-04-23 04:16:28 153,088 -c----w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
    - 2008-10-16 20:38:35 230,400 -c----w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
    + 2008-04-23 04:16:28 230,400 -c----w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
    - 2008-10-15 07:04:53 161,792 -c----w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
    + 2008-04-20 05:07:51 161,792 -c----w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
    - 2008-10-16 20:38:35 383,488 -c----w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
    + 2008-04-23 04:16:28 383,488 -c----w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
    - 2008-10-16 20:38:35 384,512 -c----w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
    + 2008-04-23 04:16:28 384,512 -c----w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
    - 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
    + 2008-04-23 04:16:28 6,066,176 -c----w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
    - 2008-10-16 20:38:37 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
    + 2008-04-23 04:16:28 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
    - 2008-10-16 20:38:37 267,776 -c----w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
    + 2008-04-23 04:16:28 267,776 -c----w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
    - 2008-10-16 13:11:09 13,824 -c----w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
    + 2008-04-22 07:39:58 13,824 -c----w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
    - 2008-10-15 07:06:26 633,632 -c----w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
    + 2008-04-22 07:40:18 625,664 -c----w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
    - 2008-10-16 20:38:37 27,648 -c----w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
    + 2008-04-23 04:16:28 27,648 -c----w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
    - 2008-10-16 20:38:37 459,264 -c----w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
    + 2008-04-23 04:16:28 459,264 -c----w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
    - 2008-10-16 20:38:37 52,224 -c----w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
    + 2008-04-23 04:16:28 52,224 -c----w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
    - 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
    + 2008-04-23 21:16:30 3,591,680 -c----w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
    - 2008-10-16 20:38:38 477,696 -c----w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
    + 2008-04-23 04:16:28 478,208 -c----w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
    - 2008-10-16 20:38:38 193,024 -c----w c:\windows\ie7updates\KB961260-IE7\msrating.dll
    + 2008-04-23 04:16:28 193,024 -c----w c:\windows\ie7updates\KB961260-IE7\msrating.dll
    - 2008-10-16 20:38:39 671,232 -c----w c:\windows\ie7updates\KB961260-IE7\mstime.dll
    + 2008-04-23 04:16:28 671,232 -c----w c:\windows\ie7updates\KB961260-IE7\mstime.dll
    - 2008-10-16 20:38:39 102,912 -c----w c:\windows\ie7updates\KB961260-IE7\occache.dll
    + 2008-04-23 04:16:28 102,912 -c----w c:\windows\ie7updates\KB961260-IE7\occache.dll
    - 2008-10-16 20:38:39 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
    + 2008-04-23 04:16:28 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
    + 2007-03-06 01:22:34 22,752 -c----w c:\windows\ie7updates\KB961260-IE7\spcustom.dll
    + 2007-03-06 01:22:36 14,048 -c----w c:\windows\ie7updates\KB961260-IE7\spmsg.dll
    + 2007-03-06 01:22:41 213,216 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst.exe
    + 2007-03-06 01:22:59 716,000 -c----w c:\windows\ie7updates\KB961260-IE7\update.exe
    + 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB961260-IE7\updspapi.dll
    - 2008-10-16 20:38:39 105,984 -c----w c:\windows\ie7updates\KB961260-IE7\url.dll
    + 2008-04-23 04:16:28 105,984 -c----w c:\windows\ie7updates\KB961260-IE7\url.dll
    - 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
    + 2008-04-23 04:16:29 1,159,680 -c----w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
    - 2008-10-16 20:38:39 233,472 -c----w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
    + 2008-04-23 04:16:29 233,472 -c----w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
    - 2008-10-16 20:38:40 826,368 -c----w c:\windows\ie7updates\KB961260-IE7\wininet.dll
    + 2008-04-23 04:16:29 826,368 -c----w c:\windows\ie7updates\KB961260-IE7\wininet.dll
    - 2008-11-12 20:01:03 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
    + 2009-03-07 20:01:16 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
    - 2008-05-27 18:22:18 38,240 ------r c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    + 2009-03-07 20:08:56 38,240 ----a-r c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    - 2008-07-09 22:37:36 593,920 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\accicons.exe
    + 2009-03-07 20:08:15 593,920 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\accicons.exe
    - 2008-07-09 22:37:36 12,288 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    + 2009-03-07 20:08:15 12,288 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2008-07-09 22:37:36 86,016 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\inficon.exe
    + 2009-03-07 20:08:15 86,016 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\inficon.exe
    - 2008-07-09 22:37:36 135,168 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\misc.exe
    + 2009-03-07 20:08:15 135,168 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2008-07-09 22:37:36 11,264 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    + 2009-03-07 20:08:15 11,264 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2008-07-09 22:37:36 27,136 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    + 2009-03-07 20:08:15 27,136 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    - 2008-07-09 22:37:36 4,096 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2009-03-07 20:08:15 4,096 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    - 2008-07-09 22:37:36 794,624 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\outicon.exe
    + 2009-03-07 20:08:15 794,624 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\outicon.exe
    - 2008-07-09 22:37:36 249,856 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\pptico.exe
    + 2009-03-07 20:08:15 249,856 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\pptico.exe
    - 2008-07-09 22:37:36 61,440 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\pubs.exe
    + 2009-03-07 20:08:15 61,440 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\pubs.exe
    - 2008-07-09 22:37:36 23,040 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    + 2009-03-07 20:08:15 23,040 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    - 2008-07-09 22:37:36 286,720 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    + 2009-03-07 20:08:15 286,720 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    - 2008-07-09 22:37:36 409,600 ------r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2009-03-07 20:08:14 409,600 ----a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    - 2008-04-23 04:16:28 124,928 ------w c:\windows\system32\advpack.dll
    + 2008-12-20 23:15:11 124,928 ----a-w c:\windows\system32\advpack.dll
    + 2008-09-17 15:29:12 20,040 ----a-w c:\windows\system32\config\systemprofile\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
    - 2008-04-23 04:16:28 124,928 ------w c:\windows\system32\dllcache\advpack.dll
    + 2008-12-20 23:15:11 124,928 ------w c:\windows\system32\dllcache\advpack.dll
    - 2008-06-20 10:44:08 138,368 ------w c:\windows\system32\dllcache\afd.sys
    + 2008-08-14 09:48:52 138,368 ------w c:\windows\system32\dllcache\afd.sys
    - 2008-04-23 04:16:28 347,136 ------w c:\windows\system32\dllcache\dxtmsft.dll
    + 2008-12-20 23:15:12 347,136 ------w c:\windows\system32\dllcache\dxtmsft.dll
    - 2008-04-23 04:16:28 214,528 ------w c:\windows\system32\dllcache\dxtrans.dll
    + 2008-12-20 23:15:13 214,528 ------w c:\windows\system32\dllcache\dxtrans.dll
    - 2008-04-23 04:16:28 133,120 ------w c:\windows\system32\dllcache\extmgr.dll
    + 2008-12-20 23:15:13 133,120 ------w c:\windows\system32\dllcache\extmgr.dll
    - 2008-02-20 06:52:43 282,624 ------w c:\windows\system32\dllcache\gdi32.dll
    + 2008-10-23 12:51:04 284,160 ------w c:\windows\system32\dllcache\gdi32.dll
    - 2008-04-23 04:16:28 63,488 ------w c:\windows\system32\dllcache\icardie.dll
    + 2008-12-20 23:15:13 63,488 ------w c:\windows\system32\dllcache\icardie.dll
    - 2008-04-22 07:39:58 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
    + 2008-12-19 09:10:15 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
    - 2008-04-23 04:16:28 153,088 ------w c:\windows\system32\dllcache\ieakeng.dll
    + 2008-12-20 23:15:14 153,088 ------w c:\windows\system32\dllcache\ieakeng.dll
    - 2008-04-23 04:16:28 230,400 ------w c:\windows\system32\dllcache\ieaksie.dll
    + 2008-12-20 23:15:14 230,400 ------w c:\windows\system32\dllcache\ieaksie.dll
    - 2008-04-20 05:07:51 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
    + 2008-12-19 05:23:56 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
    - 2008-04-23 04:16:28 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
    + 2008-12-20 23:15:15 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
    - 2008-04-23 04:16:28 384,512 ------w c:\windows\system32\dllcache\iedkcs32.dll
    + 2008-12-20 23:15:16 384,512 ------w c:\windows\system32\dllcache\iedkcs32.dll
    - 2008-04-23 04:16:28 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
    + 2008-12-20 23:15:21 6,066,688 ------w c:\windows\system32\dllcache\ieframe.dll
    - 2008-04-23 04:16:28 44,544 ------w c:\windows\system32\dllcache\iernonce.dll
    + 2008-12-20 23:15:21 44,544 ------w c:\windows\system32\dllcache\iernonce.dll
    - 2008-04-23 04:16:28 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
    + 2008-12-20 23:15:22 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
    - 2008-04-22 07:39:58 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
    + 2008-12-19 09:10:15 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
    - 2008-04-22 07:40:18 625,664 ------w c:\windows\system32\dllcache\iexplore.exe
    + 2008-12-19 05:25:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe
    - 2007-08-21 06:15:44 683,520 ------w c:\windows\system32\dllcache\inetcomm.dll
    + 2008-04-11 18:50:43 683,520 ------w c:\windows\system32\dllcache\inetcomm.dll
    - 2008-04-23 04:16:28 27,648 ------w c:\windows\system32\dllcache\jsproxy.dll
    + 2008-12-20 23:15:23 27,648 ------w c:\windows\system32\dllcache\jsproxy.dll
    - 2005-01-28 21:44:28 96,768 ------w c:\windows\system32\dllcache\logagent.exe
    + 2008-06-10 05:52:04 96,768 ------w c:\windows\system32\dllcache\logagent.exe
    - 2006-05-05 09:41:45 453,120 ------w c:\windows\system32\dllcache\mrxsmb.sys
    + 2008-10-24 11:10:42 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys
    - 2008-04-23 04:16:28 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
    + 2008-12-20 23:15:23 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
    - 2008-04-23 04:16:28 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
    + 2008-12-20 23:15:24 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
    - 2008-04-23 21:16:30 3,591,680 ------w c:\windows\system32\dllcache\mshtml.dll
    + 2009-01-16 21:35:14 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
    - 2008-04-23 04:16:28 478,208 ------w c:\windows\system32\dllcache\mshtmled.dll
    + 2008-12-20 23:15:30 477,696 ------w c:\windows\system32\dllcache\mshtmled.dll
    - 2008-04-23 04:16:28 193,024 ------w c:\windows\system32\dllcache\msrating.dll
    + 2008-12-20 23:15:31 193,024 ------w c:\windows\system32\dllcache\msrating.dll
    - 2008-04-23 04:16:28 671,232 ------w c:\windows\system32\dllcache\mstime.dll
    + 2008-12-20 23:15:32 671,232 ------w c:\windows\system32\dllcache\mstime.dll
    - 2007-06-26 06:08:16 1,104,896 ------w c:\windows\system32\dllcache\msxml3.dll
    + 2008-09-04 16:42:02 1,106,944 ------w c:\windows\system32\dllcache\msxml3.dll
    - 2006-08-17 12:28:27 332,288 ------w c:\windows\system32\dllcache\netapi32.dll
    + 2008-10-15 16:57:55 332,800 ------w c:\windows\system32\dllcache\netapi32.dll
    - 2007-02-28 09:53:04 2,137,600 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
    + 2008-08-14 09:55:01 2,142,720 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
    - 2007-02-28 09:15:56 2,059,392 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
    + 2008-08-14 09:18:44 2,062,976 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
    - 2007-02-28 09:15:59 2,017,280 ------w c:\windows\system32\dllcache\ntkrpamp.exe
    + 2008-08-14 09:18:46 2,020,864 ------w c:\windows\system32\dllcache\ntkrpamp.exe
    - 2007-02-28 09:55:14 2,182,144 ------w c:\windows\system32\dllcache\ntoskrnl.exe
    + 2008-08-14 09:57:20 2,185,984 ------w c:\windows\system32\dllcache\ntoskrnl.exe
    - 2008-04-23 04:16:28 102,912 ------w c:\windows\system32\dllcache\occache.dll
    + 2008-12-20 23:15:38 102,912 ------w c:\windows\system32\dllcache\occache.dll
    - 2008-04-23 04:16:28 44,544 ------w c:\windows\system32\dllcache\pngfilt.dll
    + 2008-12-20 23:15:38 44,544 ------w c:\windows\system32\dllcache\pngfilt.dll
    - 2007-10-26 03:34:01 8,460,288 ------w c:\windows\system32\dllcache\shell32.dll
    + 2008-07-03 13:03:29 8,460,800 ------w c:\windows\system32\dllcache\shell32.dll
    - 2006-08-14 10:34:41 332,928 ------w c:\windows\system32\dllcache\srv.sys
    + 2008-12-11 11:57:21 333,184 ------w c:\windows\system32\dllcache\srv.sys
    - 2006-08-21 08:52:08 246,814 ------w c:\windows\system32\dllcache\strmdll.dll
    + 2008-10-03 10:15:47 247,326 ------w c:\windows\system32\dllcache\strmdll.dll
    - 2008-04-23 04:16:28 105,984 ------w c:\windows\system32\dllcache\url.dll
    + 2008-12-20 23:15:39 105,984 ------w c:\windows\system32\dllcache\url.dll
    - 2008-04-23 04:16:29 1,159,680 ------w c:\windows\system32\dllcache\urlmon.dll
    + 2008-12-20 23:15:40 1,160,192 ------w c:\windows\system32\dllcache\urlmon.dll
    - 2008-04-23 04:16:29 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
    + 2008-12-20 23:15:40 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
    - 2008-04-23 04:16:29 826,368 ------w c:\windows\system32\dllcache\wininet.dll
    + 2008-12-20 23:15:41 826,368 ------w c:\windows\system32\dllcache\wininet.dll
    - 2005-01-28 21:44:28 1,027,072 ------w c:\windows\system32\dllcache\wmnetmgr.dll
    + 2008-06-10 06:28:36 1,028,096 ------w c:\windows\system32\dllcache\WMNetmgr.dll
    - 2006-12-07 05:29:34 2,374,472 ------w c:\windows\system32\dllcache\wmvcore.dll
    + 2008-06-10 07:07:24 2,376,760 ------w c:\windows\system32\dllcache\WMVCore.dll
    - 2007-07-31 02:18:40 33,624 ------w c:\windows\system32\dllcache\wups.dll
    + 2008-10-16 14:08:58 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
    - 2008-06-20 10:44:08 138,368 ------w c:\windows\system32\drivers\afd.sys
    + 2008-08-14 09:48:52 138,368 ------w c:\windows\system32\drivers\afd.sys
    - 2006-05-05 09:41:45 453,120 ------w c:\windows\system32\drivers\mrxsmb.sys
    + 2008-10-24 11:10:42 453,632 ------w c:\windows\system32\drivers\mrxsmb.sys
    - 2006-08-14 10:34:41 332,928 ------w c:\windows\system32\drivers\srv.sys
    + 2008-12-11 11:57:21 333,184 ------w c:\windows\system32\drivers\srv.sys
    - 2008-04-23 04:16:28 347,136 ------w c:\windows\system32\dxtmsft.dll
    + 2008-12-20 23:15:12 347,136 ------w c:\windows\system32\dxtmsft.dll
    - 2008-04-23 04:16:28 214,528 ------w c:\windows\system32\dxtrans.dll
    + 2008-12-20 23:15:13 214,528 ------w c:\windows\system32\dxtrans.dll
    - 2005-07-26 04:39:46 243,200 ------w c:\windows\system32\es.dll
    + 2008-07-07 20:32:22 253,952 ----a-w c:\windows\system32\es.dll
    - 2008-04-23 04:16:28 133,120 ------w c:\windows\system32\extmgr.dll
    + 2008-12-20 23:15:13 133,120 ------w c:\windows\system32\extmgr.dll
    - 2008-02-20 06:52:43 282,624 ------w c:\windows\system32\gdi32.dll
    + 2008-10-23 12:51:04 284,160 ----a-w c:\windows\system32\gdi32.dll
    - 2008-04-23 04:16:28 63,488 ------w c:\windows\system32\icardie.dll
    + 2008-12-20 23:15:13 63,488 ----a-w c:\windows\system32\icardie.dll
    - 2008-04-22 07:39:58 70,656 ------w c:\windows\system32\ie4uinit.exe
    + 2008-12-19 09:10:15 70,656 ------w c:\windows\system32\ie4uinit.exe
    - 2008-04-23 04:16:28 153,088 ------w c:\windows\system32\ieakeng.dll
    + 2008-12-20 23:15:14 153,088 ------w c:\windows\system32\ieakeng.dll
    - 2008-04-23 04:16:28 230,400 ------w c:\windows\system32\ieaksie.dll
    + 2008-12-20 23:15:14 230,400 ------w c:\windows\system32\ieaksie.dll
    - 2008-04-20 05:07:51 161,792 ------w c:\windows\system32\ieakui.dll
    + 2008-12-19 05:23:56 161,792 ------w c:\windows\system32\ieakui.dll
    - 2008-04-23 04:16:28 383,488 ------w c:\windows\system32\ieapfltr.dll
    + 2008-12-20 23:15:15 383,488 ----a-w c:\windows\system32\ieapfltr.dll
    - 2008-04-23 04:16:28 384,512 ------w c:\windows\system32\iedkcs32.dll
    + 2008-12-20 23:15:16 384,512 ------w c:\windows\system32\iedkcs32.dll
    - 2008-04-23 04:16:28 6,066,176 ------w c:\windows\system32\ieframe.dll
    + 2008-12-20 23:15:21 6,066,688 ----a-w c:\windows\system32\ieframe.dll
    - 2008-04-23 04:16:28 44,544 ------w c:\windows\system32\iernonce.dll
    + 2008-12-20 23:15:21 44,544 ------w c:\windows\system32\iernonce.dll
    - 2008-04-23 04:16:28 267,776 ------w c:\windows\system32\iertutil.dll
    + 2008-12-20 23:15:22 267,776 ----a-w c:\windows\system32\iertutil.dll
    - 2008-04-22 07:39:58 13,824 ------w c:\windows\system32\ieudinit.exe
    + 2008-12-19 09:10:15 13,824 ------w c:\windows\system32\ieudinit.exe
    - 2007-08-21 06:15:44 683,520 ------w c:\windows\system32\inetcomm.dll
    + 2008-04-11 18:50:43 683,520 ------w c:\windows\system32\inetcomm.dll
    - 2008-04-23 04:16:28 27,648 ------w c:\windows\system32\jsproxy.dll
    + 2008-12-20 23:15:23 27,648 ----a-w c:\windows\system32\jsproxy.dll
    - 2005-01-28 21:44:28 96,768 ------w c:\windows\system32\logagent.exe
    + 2008-06-10 05:52:04 96,768 ------w c:\windows\system32\logagent.exe
    - 2005-06-29 01:46:00 74,240 ------w c:\windows\system32\mscms.dll
    + 2008-06-24 16:23:05 74,240 ----a-w c:\windows\system32\mscms.dll
    - 2008-04-23 04:16:28 459,264 ------w c:\windows\system32\msfeeds.dll
    + 2008-12-20 23:15:23 459,264 ----a-w c:\windows\system32\msfeeds.dll
    - 2008-04-23 04:16:28 52,224 ------w c:\windows\system32\msfeedsbs.dll
    + 2008-12-20 23:15:24 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
    - 2008-04-23 21:16:30 3,591,680 ------w c:\windows\system32\mshtml.dll
    + 2009-01-16 21:35:14 3,594,752 ----a-w c:\windows\system32\mshtml.dll
    - 2008-04-23 04:16:28 478,208 ------w c:\windows\system32\mshtmled.dll
    + 2008-12-20 23:15:30 477,696 ----a-w c:\windows\system32\mshtmled.dll
    - 2008-04-23 04:16:28 193,024 ------w c:\windows\system32\msrating.dll
    + 2008-12-20 23:15:31 193,024 ------w c:\windows\system32\msrating.dll
    - 2008-04-23 04:16:28 671,232 ------w c:\windows\system32\mstime.dll
    + 2008-12-20 23:15:32 671,232 ------w c:\windows\system32\mstime.dll
    - 2007-06-26 06:08:16 1,104,896 ------w c:\windows\system32\msxml3.dll
    + 2008-09-04 16:42:02 1,106,944 ----a-w c:\windows\system32\msxml3.dll
    - 2007-05-08 14:03:04 1,275,392 ------w c:\windows\system32\msxml4.dll
    + 2008-09-30 16:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    - 2007-05-15 14:43:10 1,320,800 ------w c:\windows\system32\msxml6.dll
    + 2008-08-29 20:06:44 1,350,664 ----a-w c:\windows\system32\msxml6.dll
    - 2006-08-17 12:28:27 332,288 ------w c:\windows\system32\netapi32.dll
    + 2008-10-15 16:57:55 332,800 ----a-w c:\windows\system32\netapi32.dll
    - 2007-02-28 09:15:59 2,017,280 ------w c:\windows\system32\ntkrnlpa.exe
    + 2008-08-14 09:18:46 2,020,864 ------w c:\windows\system32\ntkrnlpa.exe
    - 2007-02-28 09:53:04 2,137,600 ------w c:\windows\system32\ntoskrnl.exe
    + 2008-08-14 09:55:01 2,142,720 ------w c:\windows\system32\ntoskrnl.exe
    - 2008-04-23 04:16:28 102,912 ------w c:\windows\system32\occache.dll
    + 2008-12-20 23:15:38 102,912 ------w c:\windows\system32\occache.dll
    - 2008-04-23 04:16:28 44,544 ------w c:\windows\system32\pngfilt.dll
    + 2008-12-20 23:15:38 44,544 ----a-w c:\windows\system32\pngfilt.dll
    - 2007-10-26 03:34:01 8,460,288 ------w c:\windows\system32\shell32.dll
    + 2008-07-03 13:03:29 8,460,800 ----a-w c:\windows\system32\shell32.dll
    - 2006-08-21 08:52:08 246,814 ------w c:\windows\system32\strmdll.dll
    + 2008-10-03 10:15:47 247,326 ------w c:\windows\system32\strmdll.dll
    - 2007-11-13 11:31:11 60,416 ------w c:\windows\system32\tzchange.exe
    + 2008-10-22 09:47:07 62,976 ------w c:\windows\system32\tzchange.exe
    - 2008-04-23 04:16:28 105,984 ------w c:\windows\system32\url.dll
    + 2008-12-20 23:15:39 105,984 ----a-w c:\windows\system32\url.dll
    - 2008-04-23 04:16:29 1,159,680 ------w c:\windows\system32\urlmon.dll
    + 2008-12-20 23:15:40 1,160,192 ----a-w c:\windows\system32\urlmon.dll
    - 2008-04-23 04:16:29 233,472 ------w c:\windows\system32\webcheck.dll
    + 2008-12-20 23:15:40 233,472 ----a-w c:\windows\system32\webcheck.dll
    - 2008-04-23 04:16:29 826,368 ------w c:\windows\system32\wininet.dll
    + 2008-12-20 23:15:41 826,368 ----a-w c:\windows\system32\wininet.dll
    - 2005-01-28 21:44:28 1,027,072 ------w c:\windows\system32\wmnetmgr.dll
    + 2008-06-10 06:28:36 1,028,096 ------w c:\windows\system32\WMNetmgr.dll
    - 2006-12-07 05:29:34 2,374,472 ------w c:\windows\system32\wmvcore.dll
    + 2008-06-10 07:07:24 2,376,760 ------w c:\windows\system32\WMVCore.dll
    - 2007-07-31 02:18:40 33,624 ------w c:\windows\system32\wups.dll
    + 2008-10-16 14:08:58 34,328 ----a-w c:\windows\system32\wups.dll
    - 2007-07-31 02:19:12 43,352 ------w c:\windows\system32\wups2.dll
    + 2008-10-16 14:09:44 43,544 ----a-w c:\windows\system32\wups2.dll
    - 2007-10-29 10:04:03 350,720 ------w c:\windows\system32\xpsp3res.dll
    + 2008-02-15 09:06:21 351,744 ----a-w c:\windows\system32\xpsp3res.dll
    + 2009-03-07 20:17:17 16,384 ----atw c:\windows\temp\Perflib_Perfdata_294.dat
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-06-10 311296]
    "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2008-06-10 208896]
    "TPFNF7"="c:\progra~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-03-26 59680]
    "TrackPointSrv"="c:\program files\Lenovo\TrackPoint\tp4serv.exe" [2008-03-04 92960]
    "TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 66928]
    "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-06-05 242976]
    "TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
    "AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
    "AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 419376]
    "LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [2007-07-12 124256]
    "cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2007-08-03 2630968]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
    "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-05 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-05 166424]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-05 137752]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-13 185632]
    "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
    "TpShocks"="TpShocks.exe" [2008-06-06 c:\windows\system32\TpShocks.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
    "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
    2006-09-06 15:37 34344 c:\program files\Lenovo\HOTKEY\notifyf2.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
    2007-12-14 15:36 28672 c:\program files\Lenovo\HOTKEY\tphklock.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
    2008-07-04 23:57 32768 c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ scecli ACGina

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    "DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Kontiki\\KService.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "20001:UDP"= 20001:UDP:MicroSAN
    "80:TCP"= 80:TCP:Web

    R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2008-05-14 114728]
    R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-05-14 19496]
    R0 ZetSFD;ZetSFD;c:\windows\system32\drivers\ZetSFD.sys [2008-05-08 12800]
    R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2008-03-12 11520]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-08 78416]
    R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2008-03-12 4224]
    R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2008-03-12 4442]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-05-08 20560]
    R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 29183504]
    R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [2008-08-10 94208]
    R2 SFSZ;DataPlow SFS for Zetera Storage Devices;c:\windows\system32\drivers\sfsz.sys [2008-05-08 345984]
    R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-07-12 569344]
    R2 Z-SANService;Z-SAN Service;c:\program files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe [2008-05-08 376891]
    R3 Tp4Track;PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [2007-05-10 22568]
    R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-05-22 30336]
    R3 ZetBus;Zetera Virtual Bus;c:\windows\system32\drivers\ZetBus.sys [2008-05-08 15488]
    R3 ZetMPD;ZetMPD;c:\windows\system32\drivers\ZetMPD.sys [2008-05-08 5120]
    S3 RDID1057;EDIROL UA-1EX;c:\windows\system32\drivers\Rdwm1057.sys [2008-05-11 139905]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bcd9601b-4f6d-11dd-b392-001cbfaf2eb9}]
    \Shell\AutoRun\command - J:\InstallTomTomHOME.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-07 c:\windows\Tasks\PMTask.job
    - c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-06-10 00:40]

    2009-02-28 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
    - c:\program files\Spybot\SpybotSD.exe [2009-01-26 15:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.co.uk/
    uInternet Settings,ProxyOverride = *.local
    IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} - file:///H:/Dicom%20viewer/CDVIEWER/CdViewer.cab
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-07 20:19:28
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1348)
    c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
    c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
    c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
    c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
    c:\program files\Lenovo\HOTKEY\tphklock.dll

    - - - - - - - > 'lsass.exe'(1404)
    c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
    c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
    c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
    c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
    c:\program files\ThinkPad\ConnectUtilities\ACON.dll
    c:\program files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
    c:\program files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
    c:\program files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
    c:\program files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
    c:\program files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\ibmpmsvc.exe
    c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\windows\system32\brss01a.exe
    c:\windows\system32\IPSSVC.EXE
    c:\program files\a-squared Free\a2service.exe
    c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
    c:\windows\system32\PSIService.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    c:\windows\system32\TPHDEXLG.exe
    c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
    c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
    c:\program files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    c:\windows\system32\wdfmgr.exe
    c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
    c:\program files\Lenovo\System Update\SUService.exe
    c:\program files\Common Files\Lenovo\Logger\logmon.exe
    c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Lenovo\HOTKEY\TPONSCR.exe
    c:\program files\Lenovo\ZOOM\TpScrex.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\taskmgr.exe
    .
    **************************************************************************
    .
    Completion time: 2009-03-07 20:25:06 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-03-07 20:25:03
    ComboFix2.txt 2009-03-07 19:19:54
    ComboFix3.txt 2009-03-07 15:08:17

    Pre-Run: 12,985,663,488 bytes free
    Post-Run: 13,040,414,720 bytes free

    786 --- E O F --- 2009-03-07 20:09:04

  9. #19
    Junior Member
    Join Date
    Mar 2009
    Posts
    21

    Default Next HJT log (Are you remembering to eat enough?)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:28:33, on 07/03/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\PSIService.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\WINDOWS\System32\TPHDEXLG.exe
    C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
    C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    C:\Program Files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe
    C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    c:\program files\lenovo\system update\suservice.exe
    C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
    C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe
    C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
    C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Lenovo\Zoom\TpScrex.exe
    C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
    C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Tim\My Documents\Viruscure309\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TPFNF7] C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe /r
    O4 - HKLM\..\Run: [TrackPointSrv] C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1210274366609
    O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///H:/Dicom%20viewer/CDVIEWER/CdViewer.cab
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
    O23 - Service: Power Manager DBC Service - Unknown owner - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
    O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
    O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
    O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
    O23 - Service: Z-SAN Service (Z-SANService) - Zetera Corporation - C:\Program Files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe

    --
    End of file - 14223 bytes

  10. #20
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    1. Please download this tool from Microsoft.
    2. Double click on MGADiag.exe to run it.
    3. Click Continue.
    4. The program will run. It takes a while to finish the diagnosis, please be patient.
    5. Once done, click on Copy.
    6. Open Notepad and paste the contents in. Save this file and post it in your next reply.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •